==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe [81336 2014-12-31] (Intel Corporation)
HKLM\...\Run: [ASUSPRP] => C:\Program Files\ASUS\APRP\APRP.EXE [3216032 2013-09-05] (ASUSTek Computer Inc.)
HKLM\...\Run: [RtkNGUI] => C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe [2653912 2013-07-16] (Realtek Semiconductor)
HKLM\...\Run: [ControlCenter4] => C:\Program Files\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] => C:\Program Files\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle Corporation)
HKU\S-1-5-21-48903865-4041566842-226505006-1001\...\Run: [GoogleChromeAutoLaunch_C9B322562CECB97BE12471C4C78F3635] => C:\Program Files\Google\Chrome\Application\chrome.exe [1458008 2018-06-22] (Google Inc.)
HKU\S-1-5-21-48903865-4041566842-226505006-1001\...\Run: [4399GameHall] => C:\Users\Quan\AppData\Local\4399\4399GameHall\4399GameHall.exe
HKU\S-1-5-21-48903865-4041566842-226505006-1001\...\Run: [uTorrent] => C:\Users\Quan\AppData\Roaming\uTorrent\uTorrent.exe [1984184 2018-07-20] (BitTorrent Inc.)
HKU\S-1-5-21-48903865-4041566842-226505006-1001\...\Run: [Web Companion] => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe [7717480 2018-07-20] (Lavasoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2018-02-11]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.681\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Quan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Nexon Launcher.lnk [2018-07-10]
ShortcutTarget: Nexon Launcher.lnk -> C:\Program Files\Nexon\Nexon Launcher\nexon_launcher.exe ()
Startup: C:\Users\Quan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-04-07]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
GroupPolicy: Restriction ? <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0cf5a1fd-95b7-41c8-bf4f-66aaad4bcf83}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{40a6eca6-797a-43d6-94b7-d2f9655a7ec3}: [DhcpNameServer] 13.6.0.99
Tcpip\..\Interfaces\{f92562d8-a64b-4ba8-bdbf-5a6db852a0ca}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-48903865-4041566842-226505006-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB
HKU\S-1-5-21-48903865-4041566842-226505006-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://
www.lenovo.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-48903865-4041566842-226505006-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_181\bin\ssv.dll [2018-07-18] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-07-18] (Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2018-03-28] (Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-07-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-07-18] (Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-01-10] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-48903865-4041566842-226505006-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Quan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2018-05-12] (Unity Technologies ApS)
Chrome:
=======
CHR DefaultProfile: Default
CHR DefaultSearchURL: Default -> hxxps://defaultsearch.co/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> Adaware Secure
CHR Profile: C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default [2018-07-21]
CHR Extension: (Google Translate) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2018-05-06]
CHR Extension: (Docs) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-01]
CHR Extension: (Google Drive) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (Skype Calling) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2015-11-06]
CHR Extension: (YouTube) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-21]
CHR Extension: (Honey) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-07-15]
CHR Extension: (Nimbus Screenshot & Screen Video Recorder) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpconcjcammlapcogcnnelfmaeghhagj [2018-06-08]
CHR Extension: (Google Search) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Tampermonkey) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-07-20]
CHR Extension: (Google Docs Offline) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (ScriptMonkey) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lblbnlfhhblmfconjalikamamlgoobbe [2018-07-20]
CHR Extension: (Skype) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-01]
CHR Extension: (Google Drawings) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkaakpdehdafacodkgkpghoibnmamcme [2017-12-17]
CHR Extension: (Google Hangouts) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2018-05-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Gmail) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-08]
CHR Profile: C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-06-30]
CHR Extension: (Slides) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-01]
CHR Extension: (PaperCut Software) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\alhngdkjgnedakdlnamimgfihgkmenbh [2017-12-01]
CHR Extension: (Docs) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-01]
CHR Extension: (Google Drive) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-12-01]
CHR Extension: (YouTube) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-12-01]
CHR Extension: (Aww) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ceojjgdcmdmcpiplcnbbbjfgplhledhj [2017-12-01]
CHR Extension: (Tampermonkey) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-07-20]
CHR Extension: (Sheets) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-01]
CHR Extension: (Polarr Photo Editor Extension) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fhggacdeldojnpbgknpipalghlkbcimk [2018-05-21]
CHR Extension: (Google Docs Offline) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-12-01]
CHR Extension: (Nyoogle - Custom Logo for Google) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ginfoagmgomhccdaclfbbbhfjgmphkph [2017-12-01]
CHR Extension: (Prodigy Math Game) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hndgjbjghbnahgfhcmhkkoibbgdemlia [2017-12-01]
CHR Extension: (Pixlr Editor) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmaknaampgiegkcjlimdiidlhopknpk [2017-12-01]
CHR Extension: (G Suite Training) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\idkloemkmldbemijiamdiolojbffnjlh [2018-05-17]
CHR Extension: (Read&Write for Google Chrome™) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\inoeonmfapjbbkmdafoankkfajkcphgd [2018-06-09]
CHR Extension: (ScriptMonkey) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lblbnlfhhblmfconjalikamamlgoobbe [2018-07-20]
CHR Extension: (Game Emulator Extension) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ldjojcoddnmdmhmannginfnebckohcac [2018-05-17]
CHR Extension: (SketchUp for Schools) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lfhlekccjamfkfmjgnpbdjpecanfbjkl [2018-03-28]
CHR Extension: (Skype) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-01]
CHR Extension: (Google Classroom) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfhehppjhmmnlfbbopchdfldgimhfhfk [2017-12-01]
CHR Extension: (Browser Pets) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mhgallfjacflgalnbpcpmnfibodgbdkc [2018-03-28]
CHR Extension: (Google Drawings) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mkaakpdehdafacodkgkpghoibnmamcme [2017-12-01]
CHR Extension: (Sumopaint - Online Image Editor) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mlfedaecajcncfkjfllofcfcjfhiopim [2018-06-18]
CHR Extension: (Awesome Screenshot: Screen Video Recorder) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nlipoenfbbikpbjkfpfillcgkoblgpmj [2018-06-18]
CHR Extension: (Animate Images) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nlkcmaaodnfcjhadligkpdlgkpkjneni [2017-12-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (Flat for Education - Music notation editor) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nomkpimaohgaamiipecibpchogmfhgba [2017-12-01]
CHR Extension: (Gmail) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-12-01]
CHR Extension: (Chrome Media Router) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-09]
CHR Extension: (Snapverter) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\plebojnaihkfjkkpgaemcjpnkmcpleih [2017-12-01]
CHR Profile: C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2 [2018-03-17]
CHR Extension: (Slides) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-01]
CHR Extension: (PaperCut Software) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\alhngdkjgnedakdlnamimgfihgkmenbh [2017-12-01]
CHR Extension: (Docs) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-01]
CHR Extension: (Google Drive) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-12-01]
CHR Extension: (YouTube) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-12-01]
CHR Extension: (Aww) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ceojjgdcmdmcpiplcnbbbjfgplhledhj [2017-12-01]
CHR Extension: (Tampermonkey) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-07-20]
CHR Extension: (Sheets) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-01]
CHR Extension: (Polarr Plugin: Edit Any Photo on the Internet) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fhggacdeldojnpbgknpipalghlkbcimk [2017-12-01]
CHR Extension: (Google Docs Offline) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-12-02]
CHR Extension: (Nyoogle - Custom Logo for Google) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ginfoagmgomhccdaclfbbbhfjgmphkph [2017-12-01]
CHR Extension: (Prodigy Math Game) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\hndgjbjghbnahgfhcmhkkoibbgdemlia [2017-12-01]
CHR Extension: (Pixlr Editor) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\icmaknaampgiegkcjlimdiidlhopknpk [2017-12-01]
CHR Extension: (G Suite Training) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\idkloemkmldbemijiamdiolojbffnjlh [2017-12-17]
CHR Extension: (Read&Write for Google Chrome™) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\inoeonmfapjbbkmdafoankkfajkcphgd [2017-12-01]
CHR Extension: (Grammarly for Chrome) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-01-16]
CHR Extension: (Adorable Hamster Pet) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\khmhiilheedbaffkfhjjodneogdaehfa [2017-12-01]
CHR Extension: (ScriptMonkey) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lblbnlfhhblmfconjalikamamlgoobbe [2018-07-20]
CHR Extension: (Skype) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-01]
CHR Extension: (Google Classroom) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mfhehppjhmmnlfbbopchdfldgimhfhfk [2017-12-01]
CHR Extension: (Browser Pets) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mhgallfjacflgalnbpcpmnfibodgbdkc [2017-12-01]
CHR Extension: (Google Drawings) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mkaakpdehdafacodkgkpghoibnmamcme [2017-12-01]
CHR Extension: (Sumo Paint) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mlfedaecajcncfkjfllofcfcjfhiopim [2017-12-01]
CHR Extension: (Awesome Screenshot: Screen Video Recorder) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nlipoenfbbikpbjkfpfillcgkoblgpmj [2018-01-13]
CHR Extension: (Animate Images) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nlkcmaaodnfcjhadligkpdlgkpkjneni [2017-12-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-12-01]
CHR Extension: (Flat for Education - Music notation editor) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nomkpimaohgaamiipecibpchogmfhgba [2017-12-01]
CHR Extension: (Gmail) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-12-01]
CHR Extension: (Chrome Media Router) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-15]
CHR Extension: (Snapverter) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\plebojnaihkfjkkpgaemcjpnkmcpleih [2017-12-01]
CHR Extension: (Wolf Theme) - C:\Users\Quan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pnncgdlhhlohgiokcchmaodpmbpcopai [2017-12-01]
CHR Profile: C:\Users\Quan\AppData\Local\Google\Chrome\User Data\System Profile [2018-03-28]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Asus WebStorage Windows Service; C:\Program Files\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe [71680 2013-08-16] (ASUS Cloud Corporation) [File not signed]
S2 BcmBtRSupport; C:\WINDOWS\system32\BtwRSupportService.exe [1677016 2015-04-09] (Broadcom Corporation.)
R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe [2054360 2017-12-12] (Microsoft Corporation)
S3 cphs; C:\WINDOWS\system32\IntelCpHeciSvc.exe [290224 2015-11-05] (Intel Corporation)
R2 DptfParticipantProcessorService; C:\WINDOWS\system32\DptfParticipantProcessorService.exe [83384 2014-12-31] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\WINDOWS\system32\DptfPolicyCriticalService.exe [97208 2014-12-31] (Intel Corporation)
R2 DptfPolicyLpmService; C:\WINDOWS\system32\DptfPolicyLpmService.exe [90552 2014-12-31] (Intel Corporation)
S3 ICCS; C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [169752 2012-04-24] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [283568 2015-11-05] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4753104 2018-05-09] (Malwarebytes)
R2 WCAssistantService; C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [25704 2018-07-20] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [277760 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23264 2016-11-19] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AsusHID; C:\WINDOWS\System32\drivers\AsusHID.sys [64312 2013-09-04] (ASUS Corporation)
R3 AsusSGDrv; C:\WINDOWS\system32\DRIVERS\AsusSGDrv.sys [119784 2015-08-27] (ASUS Corporation)
R3 BCMSDH43XX; C:\WINDOWS\system32\DRIVERS\bcmdhd63.sys [304344 2013-10-16] (Broadcom Corp)
R3 BthMini; C:\WINDOWS\System32\Drivers\BTHMINI.sys [23040 2015-07-10] (Microsoft Corporation)
S3 btwampfl; C:\WINDOWS\System32\drivers\btwampfl.sys [162560 2015-04-09] (Broadcom Corporation.)
R3 BtwSerialBus; C:\WINDOWS\System32\drivers\BtwSerialBus.sys [139520 2015-04-09] (Broadcom Corporation.)
R3 camera; C:\WINDOWS\system32\DRIVERS\camera.sys [334848 2013-08-22] (Intel Corporation)
R3 CM3218x; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [161792 2015-07-10] (Microsoft Corporation)
R3 CPLMACPI; C:\WINDOWS\system32\DRIVERS\CPLMACPI.sys [25040 2015-07-08] (Capella Microsystems, Inc.)
S3 DptfDevAmbient; C:\WINDOWS\System32\drivers\DptfDevAmbient.sys [44472 2014-12-31] (Intel Corporation)
R3 DptfDevDBPT; C:\WINDOWS\System32\drivers\DptfDevPower.sys [25528 2014-12-31] (Intel Corporation)
R3 DptfDevDisplay; C:\WINDOWS\System32\drivers\DptfDevDisplay.sys [28088 2014-12-31] (Intel Corporation)
R3 DptfDevGen; C:\WINDOWS\System32\drivers\DptfDevGen.sys [36280 2014-12-31] (Intel Corporation)
R3 DptfDevProc; C:\WINDOWS\System32\drivers\DptfDevProc.sys [80824 2014-12-31] (Intel Corporation)
R3 DptfManager; C:\WINDOWS\System32\drivers\DptfManager.sys [182200 2014-12-31] (Intel Corporation)
R3 GpioVirtual; C:\WINDOWS\System32\drivers\iaiogpiovirtual.sys [17408 2013-08-21] (Intel Corporation)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsHIDSwitch.sys [17416 2015-05-13] (ASUS)
S3 iaiospi; C:\WINDOWS\System32\drivers\iaiospi.sys [50688 2013-08-23] (Intel Corporation)
R3 iaiouart; C:\WINDOWS\System32\drivers\iaiouart.sys [88064 2013-08-21] (Intel Corporation)
S3 iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [505192 2013-08-08] (Intel Corporation)
S3 intaud_WaveExtensible; C:\WINDOWS\system32\drivers\intelaud.sys [44096 2015-07-20] (Intel Corporation)
R3 IntelSST; C:\WINDOWS\system32\drivers\isstrtc.sys [242176 2013-08-26] (Intel(R) Corporation)
R3 INVN_MotionApps; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [161792 2015-07-10] (Microsoft Corporation)
R3 iwdbus; C:\WINDOWS\System32\drivers\iwdbus.sys [35392 2015-07-20] (Intel Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [220896 2018-07-21] (Malwarebytes)
R0 MBI; C:\WINDOWS\System32\drivers\MBI.sys [21456 2013-08-21] (Intel Corporation)
R3 MT9M114; C:\WINDOWS\System32\drivers\MT9M114.sys [38400 2013-08-22] (Intel Corporation)
S3 NMgamingmsFltr; C:\WINDOWS\system32\drivers\NMgamingms.sys [9472 2009-07-24] (Primax Ltd)
R3 PMIC; C:\WINDOWS\System32\drivers\PMIC.sys [46592 2013-08-21] (Intel Corporation)
R3 rtii2sac; C:\WINDOWS\system32\DRIVERS\rtii2sac.sys [263936 2015-05-21] (Realtek Semiconductor Corp.)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [23040 2017-10-10] (The OpenVPN Project)
R3 TXEI; C:\WINDOWS\System32\drivers\TXEI.sys [76304 2013-08-03] (Intel Corporation)
S3 UdeCx; C:\WINDOWS\System32\drivers\udecx.sys [31744 2015-07-10] ()
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [37400 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [245600 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [97632 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-07-21 21:22 - 2018-07-21 21:22 - 000029274 _____ C:\Users\Quan\Downloads\FRST.txt
2018-07-21 21:21 - 2018-07-21 21:22 - 000000000 ____D C:\FRST
2018-07-21 21:21 - 2018-07-21 21:21 - 000000000 ____D C:\Users\Quan\Downloads\FRST-OlderVersion
2018-07-21 21:20 - 2018-07-21 21:21 - 001773056 _____ (Farbar) C:\Users\Quan\Downloads\FRST.exe
2018-07-21 19:57 - 2018-07-21 19:57 - 000016148 _____ C:\WINDOWS\system32\QZHENG168_Quan_HistoryPrediction.bin
2018-07-21 19:48 - 2018-07-21 19:48 - 000000000 ____D C:\Users\Quan\AppData\LocalLow\uTorrent
2018-07-20 13:48 - 2018-07-21 19:49 - 000001332 _____ C:\Users\Quan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ReadingModeWatchDogShortcut.lnk
2018-07-20 12:41 - 2018-07-20 12:41 - 000001897 _____ C:\Users\Quan\Downloads\niche_a_genetics_survival_game_wings_and_whale-hi2u.torrent
2018-07-20 12:38 - 2018-07-20 12:38 - 000000341 _____ C:\Users\Quan\Downloads\niche_a_genetics_survival_game_wings_and_whale-hi2u_PQ4ST0.torrent
2018-07-20 12:19 - 2018-07-20 12:25 - 633474551 _____ C:\Users\Quan\Downloads\niche (1).rar
2018-07-20 11:37 - 2018-07-20 12:48 - 000000000 ____D C:\Program Files\Niche a genetics survival game
2018-07-20 11:25 - 2018-07-20 11:25 - 000000000 ____D C:\Users\Quan\AppData\Roaming\WinThruster
2018-07-20 10:30 - 2018-07-20 12:41 - 000000000 ____D C:\Users\Quan\Downloads\Niche.A.Genetics.Survival.Game.Wings.and.Whale-HI2U
2018-07-20 10:30 - 2018-07-20 10:30 - 000000002 _____ C:\Users\Quan\AppData\Local\imw.ini
2018-07-20 10:24 - 2018-07-20 10:24 - 000002681 _____ C:\Users\Quan\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2018-07-20 10:24 - 2018-07-20 10:24 - 000000000 ____D C:\Users\Quan\AppData\Roaming\Lavasoft
2018-07-20 10:24 - 2018-07-20 10:24 - 000000000 ____D C:\Users\Quan\AppData\Local\Lavasoft
2018-07-20 10:24 - 2018-07-20 10:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2018-07-20 10:24 - 2018-07-20 10:24 - 000000000 ____D C:\ProgramData\Lavasoft
2018-07-20 10:24 - 2018-07-20 10:24 - 000000000 ____D C:\Program Files\Lavasoft
2018-07-20 10:23 - 2018-07-21 21:19 - 000000000 ____D C:\Users\Quan\AppData\Roaming\uTorrent
2018-07-19 20:20 - 2018-07-19 20:20 - 000001277 _____ C:\Users\Public\Desktop\MediBang Paint Pro.lnk
2018-07-19 20:20 - 2018-07-19 20:20 - 000000000 ____D C:\Users\Quan\AppData\Local\Medibang
2018-07-19 20:20 - 2018-07-19 20:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medibang
2018-07-19 20:20 - 2018-07-18 16:48 - 000600272 _____ C:\WINDOWS\system32\MdpThumb32.dll
2018-07-19 20:19 - 2018-07-19 20:19 - 000000000 ____D C:\Program Files\Medibang
2018-07-19 20:18 - 2018-07-19 20:19 - 035660816 _____ (Medibang ) C:\Users\Quan\Downloads\MediBangPaintProSetup-17.0-32bit.exe
2018-07-18 19:20 - 2018-07-18 19:20 - 000150224 _____ C:\WINDOWS\Minidump\071818-28046-01.dmp
2018-07-18 12:59 - 2018-07-18 13:00 - 000000000 ____D C:\Program Files\Common Files\Oracle
2018-07-18 12:56 - 2018-07-18 12:56 - 000000000 ____D C:\Program Files\Common Files\Java
2018-07-13 08:53 - 2018-07-14 08:49 - 000000000 ____D C:\WINDOWS\UpdateAssistant
2018-07-10 17:59 - 2018-07-10 17:59 - 000000000 ____D C:\Users\Quan\AppData\Roaming\Python
2018-07-10 17:58 - 2018-07-13 11:34 - 000000000 ____D C:\Users\Quan\AppData\Roaming\NexonLauncher
2018-07-10 17:58 - 2018-07-10 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
2018-07-10 17:58 - 2018-07-10 17:58 - 000000000 ____D C:\Program Files\Nexon
2018-07-10 17:58 - 2018-07-10 17:58 - 000000000 _____ C:\end
2018-07-10 09:41 - 2018-07-21 17:42 - 000220896 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-07-09 17:31 - 2018-07-09 17:32 - 000000000 ___HD C:\$WINDOWS.~BT
2018-07-05 11:00 - 2018-07-05 11:00 - 000000000 ____D C:\Users\Quan\AppData\Local\Bluestacks
2018-06-29 13:19 - 2018-06-29 13:19 - 000000000 ____D C:\Users\Quan\AppData\Roaming\SYSTEMAX Software Development
2018-06-29 13:19 - 2018-06-29 13:19 - 000000000 ____D C:\ProgramData\SYSTEMAX Software Development
2018-06-29 13:18 - 2018-06-29 13:18 - 000000622 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PaintTool SAI Ver.1.lnk
2018-06-24 17:17 - 2018-06-24 17:18 - 000000000 ____D C:\AdwCleaner
2018-06-24 17:16 - 2018-07-10 09:40 - 000129248 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae.sys
2018-06-24 17:16 - 2018-06-24 17:17 - 007372496 _____ (Malwarebytes) C:\Users\Quan\Downloads\adwcleaner_7.2.0.exe
2018-06-24 17:16 - 2018-06-24 17:16 - 000002091 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-06-24 17:16 - 2018-06-24 17:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-06-24 17:16 - 2018-06-24 17:16 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-06-24 17:16 - 2018-06-24 17:16 - 000000000 ____D C:\Program Files\Malwarebytes
2018-06-22 16:06 - 2018-06-22 16:06 - 000000000 ____D C:\Users\Quan\AppData\Roaming\com.lunime.gachaversepc
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-07-21 21:15 - 2015-07-10 04:28 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-21 21:15 - 2015-07-10 04:28 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-07-21 21:15 - 2014-01-08 20:34 - 000000000 ____D C:\Users\Quan\AppData\Local\Packages
2018-07-21 19:49 - 2015-11-05 09:59 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2018-07-21 19:48 - 2015-11-04 15:57 - 000000000 __SHD C:\Users\Quan\IntelGraphicsProfiles
2018-07-21 17:42 - 2015-07-20 19:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-07-21 17:41 - 2015-07-10 02:59 - 000786432 ___SH C:\WINDOWS\system32\config\BBI
2018-07-21 17:34 - 2015-11-04 14:41 - 000000000 ____D C:\Users\Quan
2018-07-21 17:04 - 2015-11-04 14:36 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-07-20 13:57 - 2015-07-10 04:27 - 000000000 ____D C:\WINDOWS\INF
2018-07-20 12:10 - 2017-12-01 20:55 - 000000000 ____D C:\Users\Quan\Desktop\Kylan
2018-07-20 11:57 - 2014-01-08 20:36 - 000000000 __RDO C:\Users\Quan\SkyDrive
2018-07-19 19:55 - 2015-07-10 04:28 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-07-19 08:50 - 2015-11-04 17:49 - 000002358 _____ C:\Users\Quan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-07-18 19:20 - 2015-11-05 09:58 - 000000000 ____D C:\WINDOWS\Minidump
2018-07-18 13:00 - 2014-04-23 15:51 - 000000000 ____D C:\Program Files\Java
2018-07-18 12:59 - 2014-07-21 14:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-07-18 12:53 - 2014-07-21 14:44 - 000096632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2018-07-16 18:02 - 2014-01-09 20:41 - 000480888 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-07-10 18:31 - 2014-01-10 13:34 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-07-10 18:03 - 2014-01-10 13:34 - 131626216 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-07-10 16:17 - 2015-07-10 04:28 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-07-09 17:31 - 2018-05-25 07:53 - 000000000 __SHD C:\OSRSS
2018-07-09 17:31 - 2017-12-17 09:57 - 000000000 ____D C:\WINDOWS\Panther
2018-06-27 12:02 - 2018-01-23 21:50 - 000105952 _____ (Microsoft Corporation) C:\WINDOWS\system32\osrss.dll
2018-06-26 16:17 - 2014-01-08 21:43 - 000002249 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-24 17:08 - 2018-02-11 20:52 - 000000000 ____D C:\ProgramData\McAfee Security Scan
==================== Files in the root of some directories =======
2015-07-10 04:25 - 2015-07-10 04:25 - 000058368 ____N (Microsoft Corporation) C:\Users\Quan\MiiniNBAeH.exe
2015-07-10 04:25 - 2015-07-10 04:25 - 000180736 ____N (Microsoft Corporation) C:\Users\Quan\AppData\Roaming\AnEB.exe
2015-07-10 04:25 - 2015-07-10 04:25 - 000058368 ____N (Microsoft Corporation) C:\Users\Quan\AppData\Roaming\zbEIkooQJeZ.exe
2018-07-20 10:30 - 2018-07-20 10:30 - 000000002 _____ () C:\Users\Quan\AppData\Local\imw.ini
Some files in TEMP:
====================
2018-05-03 17:55 - 2018-05-03 17:55 - 000007224 _____ () C:\Users\Quan\AppData\Local\Temp\BullseyeCoverage-2-x86.dll
2018-02-01 08:54 - 2018-02-01 08:54 - 000290304 _____ (Microsoft Corporation) C:\Users\Quan\AppData\Local\Temp\CakeTubeSdk.Windows.Service.subinacl.exe
2017-09-08 12:04 - 2017-09-08 12:04 - 001856576 _____ (Oracle Corporation) C:\Users\Quan\AppData\Local\Temp\jre-8u151-windows-au.exe
2017-12-19 23:57 - 2017-12-19 23:57 - 001864256 _____ (Oracle Corporation) C:\Users\Quan\AppData\Local\Temp\jre-8u161-windows-au.exe
2018-05-01 17:11 - 2018-05-01 17:11 - 001884616 _____ (Oracle Corporation) C:\Users\Quan\AppData\Local\Temp\jre-8u171-windows-au.exe
2018-07-18 12:49 - 2018-07-18 12:49 - 001906040 _____ (Oracle Corporation) C:\Users\Quan\AppData\Local\Temp\jre-8u181-windows-au.exe
2018-07-20 10:24 - 2018-07-20 10:24 - 000355224 _____ (Lavasoft) C:\Users\Quan\AppData\Local\Temp\offer-FB4BFE09-89FC-4F4D-B3CD-D0B093DEF7816.exe
2018-05-28 16:42 - 2017-11-27 04:50 - 002458736 _____ () C:\Users\Quan\AppData\Local\Temp\Uninstall.exe
2018-07-21 09:07 - 2018-07-21 09:08 - 000958776 _____ (adaware) C:\Users\Quan\AppData\Local\Temp\WCU009.exe
2016-10-18 12:38 - 2018-01-25 21:21 - 006242320 _____ (Microsoft Corporation) C:\Users\Quan\AppData\Local\Temp\Windows10Upgrade.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-11-04 14:35
==================== End of FRST.txt ============================