Hi! I need help. Please.
I was video editing on my PC last night and my program was running slow so I restarted. Got notification that a program called escalated privileges file operation daemon was preventing restart. Looked it up and results seemed like this was not a good thing. From here started trying to clean up files and found C:\ProgramData\ProductData that will not uninstall. Noticed the same on my laptop (they were connected through network and chrome browser, other computers on the home network don't have this, chrome sync disabled now). Been reading similar issues on some forums attempting to fix but nothing is working. PC also has new file C:\ProgramData\boost_interprocess (8kb) which I am unsure what it is. Ran FRST and think I may need fix file.
I ran a few programs based on other forums and will post txt log files
1. Junkware removal took - JRT which removed ProductData but it just reappears after a few minutes.
2. Rogue Killer - rk - found only Honey PuP, removed
3. Malwarebytes (updated), nothing detected, restarted pc
4. Adw cleaner - nothing found, ran basic repair, restarted.
5. FRST 64
Similar results on laptop but this is only for my PC right now to keep things simple
Thank you,
Caro
--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Enterprise x64
Ran by Caro (Administrator) on 2020-12-06 at 10:36:33.33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 1
Successfully deleted: C:\ProgramData\productdata (Folder)
Registry: 1
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2020-12-06 at 10:41:08.25
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
RogueKiller Anti-Malware V14.8.0.0 (x64) [Nov 17 2020] (Premium) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.18363) 64 bits
Started in : Normal mode
User : Caro [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20200213_081045, Driver : Loaded
Mode : Standard Scan, Delete -- Date : 2020/12/06 12:33:46 (Duration : 00:14:24)
Switches : -minimize
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Gen0 (Potentially Malicious)] Honey -- bmnlcjabgnpnenekpadlanbbkooimhnj -> Deleted
Malwarebytes
www.malwarebytes.com
-Log Details-
Scan Date: 12/6/20
Scan Time: 12:38 PM
Log File: d1b08580-37e9-11eb-938b-e0d55e6ea072.json
-Software Information-
Version: 4.2.3.96
Components Version: 1.0.1122
Update Package Version: 1.0.33973
License: Trial
-System Information-
OS: Windows 10 (Build 18362.1198)
CPU: x64
File System: NTFS
User: DESKTOP-PSDRESQ\Caro
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 323869
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 3 min, 15 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 0
(No malicious items detected)
Registry Value: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 0
(No malicious items detected)
File: 0
(No malicious items detected)
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)
# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build: 10-08-2020
# Database: 2020-09-29.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 12-06-2020
# Duration: 00:00:54
# OS: Windows 10 Pro
# Scanned: 31837
# Detected: 0
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
***** [ Files ] *****
No malicious files found.
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
No malicious registry entries found.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Hosts File Entries ] *****
No malicious hosts file entries found.
***** [ Preinstalled Software ] *****
No Preinstalled Software found.
AdwCleaner[S00].txt - [1609 octets] - [05/12/2020 11:23:46]
AdwCleaner[C00].txt - [1803 octets] - [05/12/2020 12:35:17]
AdwCleaner[S01].txt - [1615 octets] - [06/12/2020 11:25:31]
AdwCleaner[C01].txt - [1765 octets] - [06/12/2020 11:31:03]
AdwCleaner_Debug.log - [68 octets] - [06/12/2020 12:47:30]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S02].txt ##########
# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build: 10-08-2020
# Database: 2020-09-29.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 12-06-2020
# Duration: 00:00:01
# OS: Windows 10 Pro
# Cleaned: 0
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
No malicious folders cleaned.
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
No malicious registry entries cleaned.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [1609 octets] - [05/12/2020 11:23:46]
AdwCleaner[C00].txt - [1803 octets] - [05/12/2020 12:35:17]
AdwCleaner[S01].txt - [1615 octets] - [06/12/2020 11:25:31]
AdwCleaner[C01].txt - [1765 octets] - [06/12/2020 11:31:03]
AdwCleaner_Debug.log - [68 octets] - [06/12/2020 12:47:30]
AdwCleaner[S02].txt - [1709 octets] - [06/12/2020 12:48:33]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C02].txt ##########
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-12-2020
Ran by Caro (administrator) on DESKTOP-PSDRESQ (Gigabyte Technology Co., Ltd. AB350N-Gaming WIFI) (06-12-2020 12:55:13)
Running from C:\Users\Caro\Desktop\FRST
Loaded Profiles: Caro
Platform: Windows 10 Pro Version 1909 18363.1198 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\Adobe Installer.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud Helper.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe <4>
(Adobe Inc. -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\CCLibrary.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AdobeNotificationClient_2.0.1.8_x86__enpm4xejd91yc\AdobeNotificationClient.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0326224.inf_amd64_54f142d34a8acc18\B323593\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0326224.inf_amd64_54f142d34a8acc18\B323593\atiesrxx.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(ASUSTEK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel(R) Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Caro\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2009.4.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\commsapps.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\HxAccounts.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\AuthHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\PickerHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1190_none_1716e3ef2a15f08c\TiWorker.exe
(Node.js Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(Node.js Foundation -> Node.js) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\libs\node.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5ad622f7ea43f50a\Display.NvContainer\NVDisplay.Container.exe <2>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9235936 2017-11-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [331064 2020-10-16] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-10-26] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2095672 2020-10-06] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [114824 2020-10-07] (Adobe Inc. -> )
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5866032 2020-11-18] (Adobe Inc. -> Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [11219376 2020-12-05] (Support.com Inc -> SUPERAntiSpyware)
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\Run: [CCXProcess] => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [677512 2020-11-05] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe [5491248 2020-11-18] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [5491248 2020-11-18] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\MountPoints2: {1f0fef9e-5a4b-11e8-b960-8ca982ff9587} - "D:\UI.exe"
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [65496 2020-10-22] (Adobe Inc. -> Adobe Systems Inc)
HKLM\...\Print\Monitors\HP CC11 Status Monitor: C:\WINDOWS\system32\hpinkstsCC11LM.dll [391992 2019-03-15] (HP Inc -> HP Inc.)
HKLM\...\Print\Monitors\HP CE11 Status Monitor: C:\WINDOWS\system32\hpinkstsCE11LM.dll [393352 2017-03-20] (Hewlett Packard -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.88\Installer\chrmstp.exe [2020-12-02] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {053BCB64-EFFD-4B0C-A6E3-9D1C548AC083} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-05-08] (Google Inc -> Google Inc.)
Task: {07F19A41-BE43-4770-B475-E38F8829A46C} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0C83218A-5CD6-43A8-B91F-0814E107F087} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3787304 2019-05-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1568A3F6-6BE0-442A-97AE-2593521EF59F} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [972176 2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {1D7656BB-B74B-4696-89AC-4C0584167F3F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [972176 2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {3DE0D252-113B-41F0-980D-EA87D56FCCF7} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-02-27] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {3F054FBB-58BA-4CE3-8FD6-7D05A2D181AE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
Task: {4BAFFEE6-1486-4602-9918-0A8A21AB118F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [899056 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4F5550B4-38B3-4333-8590-CF77EB07B263} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe
Task: {72C85641-E1E2-47E5-9DA4-AD3D3C6A26B3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-05-08] (Google Inc -> Google Inc.)
Task: {776AE28A-F40F-4187-8BD7-FE2D70CA14F4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {8E968E6C-4203-493C-B5CB-FB1322EC7234} - System32\Tasks\GPU Tweak II => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [12793856 2019-07-05] (ASUSTEK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
Task: {9BCE3AC9-79F7-4DA4-8674-4F728E086F93} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A3BE0BBE-AE80-4A91-AAC2-13A2D1423744} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {B7796DE6-1063-4B5E-AF53-3214A12C8E01} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C66E2AFB-AC70-41A5-B9D5-FA6611E9387C} - System32\Tasks\Adobe Uninstaller => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [431160 2020-10-06] (Adobe Inc. -> Adobe Inc.)
Task: {CCDE8FB7-C13F-4DD0-8EE3-7E88A6067F05} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D4CCE032-2C87-40C1-AA19-4C2A52E4C9B4} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-02-27] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {DE759EB7-9336-411E-8861-09A2E83819D6} - System32\Tasks\Power_a17007 => C:\Program Files\Cold Turkey\CTServiceInstaller.exe
Task: {E21283F0-32D4-4199-8BDF-CB77AAF073AE} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-PSDRESQ-Caro => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {F8115776-354B-447F-B009-B2DE90048CA5} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648504 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FAAE8DA3-E857-4521-8C0C-43A56FC953AE} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [899056 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 64.71.255.204 64.71.255.198
Tcpip\..\Interfaces\{fa7b2c5c-fd19-4705-aba8-17553d47644d}: [DhcpNameServer] 64.71.255.204 64.71.255.198
FireFox:
========
FF DefaultProfile: rc7p17am.default
FF ProfilePath: C:\Users\Caro\AppData\Roaming\Zotero\Zotero\Profiles\rc7p17am.default [2019-04-22]
FF Extension: (No Name) - C:\Program Files (x86)\Zotero\extensions\zoteroOpenOfficeIntegration@zotero.org [not found]
FF Extension: (No Name) - C:\Program Files (x86)\Zotero\extensions\zoteroWinWordIntegration@zotero.org [not found]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2020-07-30]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2020-10-06] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2018-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-11-18] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-11-18] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2020-10-06] (Adobe Inc. -> Adobe Systems)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default [2020-12-06]
CHR DefaultSearchKeyword: Default -> mcafee
CHR DefaultSuggestURL: Default -> hxxps://ca.search.yahoo.com/sugg/gossip/gossip-ca-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms}
CHR Extension: (Slides) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-08]
CHR Extension: (Docs) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-08]
CHR Extension: (Google Drive) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24]
CHR Extension: (YouTube) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-08]
CHR Extension: (Adobe Acrobat) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-08-21]
CHR Extension: (Zotero Connector) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekhagklcjbdpajgpjgmbionohlpdbjgc [2020-10-28]
CHR Extension: (Sheets) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-08]
CHR Extension: (Google Docs Offline) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-23]
CHR Extension: (Google Calendar) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich [2020-06-11]
CHR Extension: (Keywords Everywhere - Keyword Tool) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbapdpeemoojbophdfndmlgdhppljgmp [2020-12-05]
CHR Extension: (Norton Safe Search as default for Chrome) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbmobhkkblcgdifigjglcjneplefbkmh [2020-08-26]
CHR Extension: (Grammarly for Chrome) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2020-11-23]
CHR Extension: (Google Keep Chrome Extension) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2020-12-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-24]
CHR Extension: (Chrome Media Router) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-11-23]
CHR Profile: C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-12-05]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-30] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [170056 2020-11-03] (Adobe Inc. -> Adobe Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [852024 2020-10-06] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3739728 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3511376 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2020-09-24] (Apple Inc. -> Apple Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe [384000 2019-03-22] (ASUSTEK COMPUTER INC. -> ASUSTeK Computer Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3052944 2020-07-14] (Microsoft Corporation -> Microsoft Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-26] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-26] (ESET, spol. s r.o. -> ESET)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7269976 2020-12-05] (Malwarebytes Inc -> Malwarebytes)
S2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [13666872 2020-11-17] (Adlice -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6153048 2020-11-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2020-12-04] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2020-12-04] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 BEService; "C:\Program Files (x86)\Common Files\BattlEye\BEService.exe" [X]
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [X]
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5ad622f7ea43f50a\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5ad622f7ea43f50a\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2017-04-14] (ASUSTeK Computer Inc. -> )
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [160992 2020-10-26] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [109360 2020-10-26] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15288 2020-10-22] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [190464 2020-10-26] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [43720 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [70048 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [107784 2020-10-26] (ESET, spol. s r.o. -> ESET)
S3 gdrv; C:\Windows\gdrv.sys [26192 2018-05-17] (Giga-Byte Technology -> Windows (R) Server 2003 DDK provider)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [34064 2019-01-22] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-12-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-12-05] (Malwarebytes Inc -> Malwarebytes)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2018-02-01] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2020-12-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [429296 2020-12-04] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [70896 2020-12-04] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-12-06 12:42 - 2020-12-06 12:52 - 000000000 ___DC C:\Users\Caro\Desktop\PC Scan Reports
2020-12-06 12:11 - 2020-12-06 12:22 - 000000000 ____D C:\ProgramData\RogueKiller
2020-12-06 12:11 - 2020-12-06 12:11 - 000000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2020-12-06 12:11 - 2020-12-06 12:11 - 000000899 _____ C:\ProgramData\Desktop\RogueKiller.lnk
2020-12-06 12:11 - 2020-12-06 12:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2020-12-06 12:11 - 2020-12-06 12:11 - 000000000 ____D C:\Program Files\RogueKiller
2020-12-06 12:08 - 2020-12-06 12:08 - 040473968 _____ (Adlice Software ) C:\Users\Caro\Downloads\setup.exe
2020-12-06 11:31 - 2020-12-06 11:31 - 000000000 ____D C:\WINDOWS\Panther
2020-12-06 11:08 - 2020-12-06 12:55 - 000000000 ____D C:\FRST
2020-12-06 11:07 - 2020-12-06 11:13 - 000000000 ___DC C:\Users\Caro\Desktop\FRST
2020-12-06 11:03 - 2020-12-06 11:06 - 002288640 _____ (Farbar) C:\Users\Caro\Downloads\FRST64.exe
2020-12-06 10:41 - 2020-12-06 10:41 - 000000744 ____C C:\Users\Caro\Desktop\JRT.txt
2020-12-06 10:36 - 2020-12-06 10:36 - 001790024 _____ (Malwarebytes) C:\Users\Caro\Downloads\JRT.exe
2020-12-05 14:24 - 2020-12-05 15:59 - 000000000 ____D C:\ProgramData\boost_interprocess
2020-12-05 13:28 - 2020-12-05 13:28 - 000000000 ____D C:\Users\Caro\AppData\Local\MicrosoftEdge
2020-12-05 12:34 - 2020-12-05 12:34 - 000000000 ___DC C:\Users\Caro\AppData\LocalLow\IObit
2020-12-05 12:33 - 2020-12-05 12:33 - 000000000 ____D C:\Program Files (x86)\IObit
2020-12-05 12:32 - 2020-12-06 11:31 - 000000000 ____D C:\Users\Caro\AppData\Roaming\IObit
2020-12-05 12:32 - 2020-12-05 12:34 - 000000000 ____D C:\ProgramData\IObit
2020-12-05 12:32 - 2020-12-05 12:32 - 025230736 _____ (IObit ) C:\Users\Caro\Downloads\iobituninstaller.exe
2020-12-05 11:25 - 2020-12-05 11:25 - 000000000 ____D C:\Users\Caro\AppData\Local\ESET
2020-12-05 11:25 - 2020-12-05 11:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2020-12-05 11:25 - 2020-12-05 11:25 - 000000000 ____D C:\ProgramData\ESET
2020-12-05 11:25 - 2020-12-05 11:25 - 000000000 ____D C:\Program Files\ESET
2020-12-05 11:22 - 2020-12-05 12:35 - 000000000 ____D C:\AdwCleaner
2020-12-05 11:22 - 2020-12-05 11:22 - 008447152 _____ (Malwarebytes) C:\Users\Caro\Desktop\adwcleaner_8.0.8.exe
2020-12-05 11:22 - 2020-12-05 11:22 - 006341552 _____ (ESET) C:\Users\Caro\Downloads\eset_internet_security_live_installer.exe
2020-12-05 11:15 - 2020-12-05 11:15 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-12-05 11:15 - 2020-12-05 11:14 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-11-28 20:01 - 2020-11-28 20:01 - 000001130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro 2020.lnk
2020-11-28 19:53 - 2020-11-28 19:53 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2021.lnk
2020-11-28 19:49 - 2020-11-28 19:49 - 000001085 ____C C:\Users\Caro\Desktop\Adobe Lightroom Classic.lnk
2020-11-28 19:49 - 2020-11-28 19:49 - 000001085 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom Classic.lnk
2020-11-23 10:46 - 2020-12-03 18:32 - 000001456 _____ C:\Users\Caro\AppData\Local\Adobe Save for Web 13.0 Prefs
2020-11-17 11:53 - 2020-11-17 11:53 - 001919470 _____ C:\Users\Caro\Downloads\Wedding Photography Contract - Sam & Mark 1.pdf
2020-11-15 12:29 - 2020-11-15 12:29 - 000000000 ___DC C:\Users\Caro\Documents\Zoom
2020-11-15 12:28 - 2020-12-05 12:44 - 000000000 ____D C:\Users\Caro\AppData\Roaming\Zoom
2020-11-10 23:51 - 2020-11-10 23:51 - 001841152 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2020-11-10 23:51 - 2020-11-10 23:51 - 001101312 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-11-10 23:50 - 2020-11-10 23:50 - 000200704 _____ C:\WINDOWS\system32\IHDS.dll
2020-11-10 23:50 - 2020-11-10 23:50 - 000164864 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2020-11-10 14:36 - 2020-11-10 14:36 - 000112759 _____ C:\Users\Caro\Downloads\Wedding Photography Contract (1).pdf
2020-11-10 14:35 - 2020-11-10 14:35 - 000112759 _____ C:\Users\Caro\Downloads\Wedding Photography Contract.pdf
2020-11-09 15:38 - 2020-11-09 15:38 - 000000000 ____D C:\Users\Caro\Downloads\Wedding-titles-v3-30607
2020-11-09 15:36 - 2020-11-09 15:36 - 022486391 _____ C:\Users\Caro\Downloads\Wedding-titles-v3-30607.zip
2020-11-08 12:27 - 2020-11-08 12:27 - 000353190 _____ C:\Users\Caro\Downloads\Carolyn_CRA_2019_summary.pdf
2020-11-06 12:06 - 2020-11-06 12:06 - 002222316 _____ C:\Users\Caro\Downloads\ImprovePhotographyContracts.zip
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-12-06 12:53 - 2020-05-09 17:54 - 000000000 ____D C:\ProgramData\NVIDIA
2020-12-06 12:52 - 2018-05-09 09:01 - 000000000 ___RD C:\Users\Caro\Creative Cloud Files
2020-12-06 12:51 - 2020-05-09 17:56 - 000003092 _____ C:\WINDOWS\system32\Tasks\GPU Tweak II
2020-12-06 12:51 - 2020-04-06 14:17 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-12-06 12:50 - 2020-04-30 19:09 - 000012510 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1
2020-12-06 12:50 - 2020-04-30 19:09 - 000012312 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1
2020-12-06 12:50 - 2020-04-30 19:09 - 000006472 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1
2020-12-06 12:50 - 2020-04-06 17:46 - 000761886 _____ C:\WINDOWS\system32\prfh0416.dat
2020-12-06 12:50 - 2020-04-06 17:46 - 000148752 _____ C:\WINDOWS\system32\prfc0416.dat
2020-12-06 12:50 - 2020-04-06 14:14 - 001742324 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-12-06 12:50 - 2019-03-18 23:50 - 000000000 ____D C:\WINDOWS\INF
2020-12-06 12:50 - 2019-03-18 23:37 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2020-12-06 12:46 - 2019-03-18 23:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-12-06 12:09 - 2018-07-01 10:42 - 000000000 ___DC C:\Users\Caro\AppData\Local\D3DSCache
2020-12-06 11:40 - 2018-05-09 11:08 - 000000000 ___RD C:\Users\Caro\OneDrive
2020-12-06 10:33 - 2020-04-06 14:17 - 000004164 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{1140566A-E7E9-45BC-8379-45654BCF9F6C}
2020-12-06 10:30 - 2020-04-06 14:04 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-12-05 23:06 - 2019-03-18 23:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-12-05 23:06 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-12-05 15:32 - 2020-04-30 19:08 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2020-12-05 14:24 - 2020-05-10 11:27 - 000000000 ____D C:\Users\Caro\AppData\Local\NVIDIA Corporation
2020-12-05 13:31 - 2018-05-09 11:07 - 000000000 ___DC C:\Users\Caro\AppData\Local\Packages
2020-12-05 11:42 - 2020-04-06 14:17 - 000003766 _____ C:\WINDOWS\system32\Tasks\Power_a17007
2020-12-05 11:25 - 2019-03-18 23:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-12-05 11:15 - 2020-08-26 09:49 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-12-05 11:15 - 2019-08-18 13:32 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-12-05 11:15 - 2019-08-18 13:32 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-12-05 11:15 - 2018-05-25 17:38 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2020-12-05 11:14 - 2019-08-18 13:32 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-12-04 22:49 - 2019-10-03 13:56 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-12-04 22:49 - 2019-10-03 13:56 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData
2020-12-04 16:45 - 2018-05-08 20:35 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-12-03 18:47 - 2020-04-06 14:17 - 000003418 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-12-03 18:47 - 2020-04-06 14:17 - 000003294 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-12-02 17:35 - 2018-05-08 20:17 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-12-02 17:35 - 2018-05-08 20:17 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-12-02 17:35 - 2018-05-08 20:17 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-11-29 12:43 - 2018-05-09 08:30 - 000000000 ___DC C:\Users\Caro\AppData\Local\Adobe
2020-11-28 23:40 - 2018-05-09 09:12 - 000000000 ___DC C:\Users\Caro\Documents\Adobe
2020-11-28 20:01 - 2018-05-09 09:22 - 000000000 ____D C:\Users\Public\Documents\Adobe
2020-11-28 20:01 - 2018-05-09 09:22 - 000000000 ____D C:\ProgramData\Documents\Adobe
2020-11-28 20:01 - 2018-05-09 09:01 - 000000000 ____D C:\Program Files\Adobe
2020-11-28 19:54 - 2018-05-09 11:07 - 000000000 ___DC C:\Users\Caro\AppData\Roaming\Adobe
2020-11-28 16:44 - 2020-05-12 15:32 - 000000000 ____D C:\Users\Caro\AppData\Local\CrashDumps
2020-11-25 13:16 - 2018-05-09 09:02 - 000000000 ____D C:\Program Files\Common Files\Adobe
2020-11-25 13:16 - 2018-05-09 08:32 - 000000000 ____D C:\ProgramData\Adobe
2020-11-25 12:56 - 2020-04-06 14:17 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-11-25 12:56 - 2018-12-09 17:54 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-11-25 07:16 - 2020-08-21 09:10 - 000002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2020-11-25 07:16 - 2020-08-21 09:10 - 000002103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2020-11-24 00:20 - 2019-04-27 08:54 - 000000000 ____D C:\Users\Caro\AppData\Roaming\vlc
2020-11-24 00:11 - 2019-04-27 08:53 - 000001139 _____ C:\Users\Public\Desktop\VLC media player.lnk
2020-11-24 00:11 - 2019-04-27 08:53 - 000001139 _____ C:\ProgramData\Desktop\VLC media player.lnk
2020-11-23 23:29 - 2020-04-06 14:17 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-881217815-4272472998-2328836942-1001
2020-11-23 23:29 - 2020-04-06 14:08 - 000002360 ____C C:\Users\Caro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-11-22 11:48 - 2018-11-25 15:08 - 000000000 ____D C:\Program Files\Microsoft Office 15
2020-11-20 13:01 - 2018-06-17 22:31 - 000002338 ____C C:\Users\Caro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive (1).lnk
2020-11-19 21:17 - 2020-09-30 16:09 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2020-11-12 11:00 - 2020-03-22 20:35 - 000907064 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2020-11-12 10:59 - 2020-09-30 16:09 - 000436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
2020-11-11 01:28 - 2018-06-18 18:02 - 000000000 ___RD C:\Users\Caro\3D Objects
2020-11-11 01:28 - 2018-05-09 11:07 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-11-11 01:27 - 2020-04-06 14:04 - 000322760 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-11-11 01:26 - 2019-03-19 01:23 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\TextInput
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\system32\setup
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-11-10 23:57 - 2019-03-18 23:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-11-10 23:50 - 2020-04-06 14:07 - 002876928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-11-10 23:10 - 2018-05-08 20:34 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-11-10 23:06 - 2018-05-08 20:34 - 133736600 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories ========
2018-06-17 13:50 - 2018-06-17 13:50 - 000000033 ____C () C:\Users\Caro\AppData\Roaming\AdobeWLCMCache.dat
2020-11-23 10:46 - 2020-12-03 18:32 - 000001456 _____ () C:\Users\Caro\AppData\Local\Adobe Save for Web 13.0 Prefs
2018-09-28 07:13 - 2018-09-28 07:13 - 000000000 ____C () C:\Users\Caro\AppData\Local\oobelibMkey.log
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
I was video editing on my PC last night and my program was running slow so I restarted. Got notification that a program called escalated privileges file operation daemon was preventing restart. Looked it up and results seemed like this was not a good thing. From here started trying to clean up files and found C:\ProgramData\ProductData that will not uninstall. Noticed the same on my laptop (they were connected through network and chrome browser, other computers on the home network don't have this, chrome sync disabled now). Been reading similar issues on some forums attempting to fix but nothing is working. PC also has new file C:\ProgramData\boost_interprocess (8kb) which I am unsure what it is. Ran FRST and think I may need fix file.
I ran a few programs based on other forums and will post txt log files
1. Junkware removal took - JRT which removed ProductData but it just reappears after a few minutes.
2. Rogue Killer - rk - found only Honey PuP, removed
3. Malwarebytes (updated), nothing detected, restarted pc
4. Adw cleaner - nothing found, ran basic repair, restarted.
5. FRST 64
Similar results on laptop but this is only for my PC right now to keep things simple
Thank you,
Caro
--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Enterprise x64
Ran by Caro (Administrator) on 2020-12-06 at 10:36:33.33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 1
Successfully deleted: C:\ProgramData\productdata (Folder)
Registry: 1
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2020-12-06 at 10:41:08.25
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
RogueKiller Anti-Malware V14.8.0.0 (x64) [Nov 17 2020] (Premium) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.18363) 64 bits
Started in : Normal mode
User : Caro [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20200213_081045, Driver : Loaded
Mode : Standard Scan, Delete -- Date : 2020/12/06 12:33:46 (Duration : 00:14:24)
Switches : -minimize
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Gen0 (Potentially Malicious)] Honey -- bmnlcjabgnpnenekpadlanbbkooimhnj -> Deleted
Malwarebytes
www.malwarebytes.com
-Log Details-
Scan Date: 12/6/20
Scan Time: 12:38 PM
Log File: d1b08580-37e9-11eb-938b-e0d55e6ea072.json
-Software Information-
Version: 4.2.3.96
Components Version: 1.0.1122
Update Package Version: 1.0.33973
License: Trial
-System Information-
OS: Windows 10 (Build 18362.1198)
CPU: x64
File System: NTFS
User: DESKTOP-PSDRESQ\Caro
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 323869
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 3 min, 15 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 0
(No malicious items detected)
Registry Value: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 0
(No malicious items detected)
File: 0
(No malicious items detected)
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)
# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build: 10-08-2020
# Database: 2020-09-29.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 12-06-2020
# Duration: 00:00:54
# OS: Windows 10 Pro
# Scanned: 31837
# Detected: 0
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
***** [ Files ] *****
No malicious files found.
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
No malicious registry entries found.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Hosts File Entries ] *****
No malicious hosts file entries found.
***** [ Preinstalled Software ] *****
No Preinstalled Software found.
AdwCleaner[S00].txt - [1609 octets] - [05/12/2020 11:23:46]
AdwCleaner[C00].txt - [1803 octets] - [05/12/2020 12:35:17]
AdwCleaner[S01].txt - [1615 octets] - [06/12/2020 11:25:31]
AdwCleaner[C01].txt - [1765 octets] - [06/12/2020 11:31:03]
AdwCleaner_Debug.log - [68 octets] - [06/12/2020 12:47:30]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S02].txt ##########
# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build: 10-08-2020
# Database: 2020-09-29.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 12-06-2020
# Duration: 00:00:01
# OS: Windows 10 Pro
# Cleaned: 0
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
No malicious folders cleaned.
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
No malicious registry entries cleaned.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [1609 octets] - [05/12/2020 11:23:46]
AdwCleaner[C00].txt - [1803 octets] - [05/12/2020 12:35:17]
AdwCleaner[S01].txt - [1615 octets] - [06/12/2020 11:25:31]
AdwCleaner[C01].txt - [1765 octets] - [06/12/2020 11:31:03]
AdwCleaner_Debug.log - [68 octets] - [06/12/2020 12:47:30]
AdwCleaner[S02].txt - [1709 octets] - [06/12/2020 12:48:33]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C02].txt ##########
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-12-2020
Ran by Caro (administrator) on DESKTOP-PSDRESQ (Gigabyte Technology Co., Ltd. AB350N-Gaming WIFI) (06-12-2020 12:55:13)
Running from C:\Users\Caro\Desktop\FRST
Loaded Profiles: Caro
Platform: Windows 10 Pro Version 1909 18363.1198 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\Adobe Installer.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud Helper.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe <4>
(Adobe Inc. -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\CCLibrary.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AdobeNotificationClient_2.0.1.8_x86__enpm4xejd91yc\AdobeNotificationClient.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0326224.inf_amd64_54f142d34a8acc18\B323593\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0326224.inf_amd64_54f142d34a8acc18\B323593\atiesrxx.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(ASUSTEK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel(R) Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Caro\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2009.4.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\commsapps.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\HxAccounts.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\AuthHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\PickerHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1190_none_1716e3ef2a15f08c\TiWorker.exe
(Node.js Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(Node.js Foundation -> Node.js) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\libs\node.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5ad622f7ea43f50a\Display.NvContainer\NVDisplay.Container.exe <2>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9235936 2017-11-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [331064 2020-10-16] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [175504 2020-10-26] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2095672 2020-10-06] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [114824 2020-10-07] (Adobe Inc. -> )
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5866032 2020-11-18] (Adobe Inc. -> Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [11219376 2020-12-05] (Support.com Inc -> SUPERAntiSpyware)
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\Run: [CCXProcess] => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [677512 2020-11-05] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe [5491248 2020-11-18] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [5491248 2020-11-18] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-881217815-4272472998-2328836942-1001\...\MountPoints2: {1f0fef9e-5a4b-11e8-b960-8ca982ff9587} - "D:\UI.exe"
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [65496 2020-10-22] (Adobe Inc. -> Adobe Systems Inc)
HKLM\...\Print\Monitors\HP CC11 Status Monitor: C:\WINDOWS\system32\hpinkstsCC11LM.dll [391992 2019-03-15] (HP Inc -> HP Inc.)
HKLM\...\Print\Monitors\HP CE11 Status Monitor: C:\WINDOWS\system32\hpinkstsCE11LM.dll [393352 2017-03-20] (Hewlett Packard -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.88\Installer\chrmstp.exe [2020-12-02] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {053BCB64-EFFD-4B0C-A6E3-9D1C548AC083} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-05-08] (Google Inc -> Google Inc.)
Task: {07F19A41-BE43-4770-B475-E38F8829A46C} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0C83218A-5CD6-43A8-B91F-0814E107F087} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3787304 2019-05-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1568A3F6-6BE0-442A-97AE-2593521EF59F} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [972176 2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {1D7656BB-B74B-4696-89AC-4C0584167F3F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [972176 2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {3DE0D252-113B-41F0-980D-EA87D56FCCF7} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-02-27] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {3F054FBB-58BA-4CE3-8FD6-7D05A2D181AE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
Task: {4BAFFEE6-1486-4602-9918-0A8A21AB118F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [899056 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4F5550B4-38B3-4333-8590-CF77EB07B263} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe
Task: {72C85641-E1E2-47E5-9DA4-AD3D3C6A26B3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-05-08] (Google Inc -> Google Inc.)
Task: {776AE28A-F40F-4187-8BD7-FE2D70CA14F4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {8E968E6C-4203-493C-B5CB-FB1322EC7234} - System32\Tasks\GPU Tweak II => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [12793856 2019-07-05] (ASUSTEK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
Task: {9BCE3AC9-79F7-4DA4-8674-4F728E086F93} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A3BE0BBE-AE80-4A91-AAC2-13A2D1423744} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {B7796DE6-1063-4B5E-AF53-3214A12C8E01} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C66E2AFB-AC70-41A5-B9D5-FA6611E9387C} - System32\Tasks\Adobe Uninstaller => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [431160 2020-10-06] (Adobe Inc. -> Adobe Inc.)
Task: {CCDE8FB7-C13F-4DD0-8EE3-7E88A6067F05} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D4CCE032-2C87-40C1-AA19-4C2A52E4C9B4} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-02-27] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {DE759EB7-9336-411E-8861-09A2E83819D6} - System32\Tasks\Power_a17007 => C:\Program Files\Cold Turkey\CTServiceInstaller.exe
Task: {E21283F0-32D4-4199-8BDF-CB77AAF073AE} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-PSDRESQ-Caro => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {F8115776-354B-447F-B009-B2DE90048CA5} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648504 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FAAE8DA3-E857-4521-8C0C-43A56FC953AE} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [899056 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 64.71.255.204 64.71.255.198
Tcpip\..\Interfaces\{fa7b2c5c-fd19-4705-aba8-17553d47644d}: [DhcpNameServer] 64.71.255.204 64.71.255.198
FireFox:
========
FF DefaultProfile: rc7p17am.default
FF ProfilePath: C:\Users\Caro\AppData\Roaming\Zotero\Zotero\Profiles\rc7p17am.default [2019-04-22]
FF Extension: (No Name) - C:\Program Files (x86)\Zotero\extensions\zoteroOpenOfficeIntegration@zotero.org [not found]
FF Extension: (No Name) - C:\Program Files (x86)\Zotero\extensions\zoteroWinWordIntegration@zotero.org [not found]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2020-07-30]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2020-10-06] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2018-11-25] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-11-18] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-11-18] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2020-10-06] (Adobe Inc. -> Adobe Systems)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default [2020-12-06]
CHR DefaultSearchKeyword: Default -> mcafee
CHR DefaultSuggestURL: Default -> hxxps://ca.search.yahoo.com/sugg/gossip/gossip-ca-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms}
CHR Extension: (Slides) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-08]
CHR Extension: (Docs) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-08]
CHR Extension: (Google Drive) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24]
CHR Extension: (YouTube) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-08]
CHR Extension: (Adobe Acrobat) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-08-21]
CHR Extension: (Zotero Connector) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekhagklcjbdpajgpjgmbionohlpdbjgc [2020-10-28]
CHR Extension: (Sheets) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-08]
CHR Extension: (Google Docs Offline) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-23]
CHR Extension: (Google Calendar) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich [2020-06-11]
CHR Extension: (Keywords Everywhere - Keyword Tool) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbapdpeemoojbophdfndmlgdhppljgmp [2020-12-05]
CHR Extension: (Norton Safe Search as default for Chrome) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbmobhkkblcgdifigjglcjneplefbkmh [2020-08-26]
CHR Extension: (Grammarly for Chrome) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2020-11-23]
CHR Extension: (Google Keep Chrome Extension) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2020-12-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-24]
CHR Extension: (Chrome Media Router) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-11-23]
CHR Profile: C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-12-05]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-30] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [170056 2020-11-03] (Adobe Inc. -> Adobe Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [852024 2020-10-06] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3739728 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3511376 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2020-09-24] (Apple Inc. -> Apple Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe [384000 2019-03-22] (ASUSTEK COMPUTER INC. -> ASUSTeK Computer Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3052944 2020-07-14] (Microsoft Corporation -> Microsoft Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-26] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2595360 2020-10-26] (ESET, spol. s r.o. -> ESET)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7269976 2020-12-05] (Malwarebytes Inc -> Malwarebytes)
S2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [13666872 2020-11-17] (Adlice -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6153048 2020-11-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2020-12-04] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2020-12-04] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 BEService; "C:\Program Files (x86)\Common Files\BattlEye\BEService.exe" [X]
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [X]
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5ad622f7ea43f50a\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5ad622f7ea43f50a\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2017-04-14] (ASUSTeK Computer Inc. -> )
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [160992 2020-10-26] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [109360 2020-10-26] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15288 2020-10-22] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [190464 2020-10-26] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [43720 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [70048 2020-10-26] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [107784 2020-10-26] (ESET, spol. s r.o. -> ESET)
S3 gdrv; C:\Windows\gdrv.sys [26192 2018-05-17] (Giga-Byte Technology -> Windows (R) Server 2003 DDK provider)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [34064 2019-01-22] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-12-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-12-05] (Malwarebytes Inc -> Malwarebytes)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2018-02-01] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2020-12-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [429296 2020-12-04] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [70896 2020-12-04] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-12-06 12:42 - 2020-12-06 12:52 - 000000000 ___DC C:\Users\Caro\Desktop\PC Scan Reports
2020-12-06 12:11 - 2020-12-06 12:22 - 000000000 ____D C:\ProgramData\RogueKiller
2020-12-06 12:11 - 2020-12-06 12:11 - 000000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2020-12-06 12:11 - 2020-12-06 12:11 - 000000899 _____ C:\ProgramData\Desktop\RogueKiller.lnk
2020-12-06 12:11 - 2020-12-06 12:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2020-12-06 12:11 - 2020-12-06 12:11 - 000000000 ____D C:\Program Files\RogueKiller
2020-12-06 12:08 - 2020-12-06 12:08 - 040473968 _____ (Adlice Software ) C:\Users\Caro\Downloads\setup.exe
2020-12-06 11:31 - 2020-12-06 11:31 - 000000000 ____D C:\WINDOWS\Panther
2020-12-06 11:08 - 2020-12-06 12:55 - 000000000 ____D C:\FRST
2020-12-06 11:07 - 2020-12-06 11:13 - 000000000 ___DC C:\Users\Caro\Desktop\FRST
2020-12-06 11:03 - 2020-12-06 11:06 - 002288640 _____ (Farbar) C:\Users\Caro\Downloads\FRST64.exe
2020-12-06 10:41 - 2020-12-06 10:41 - 000000744 ____C C:\Users\Caro\Desktop\JRT.txt
2020-12-06 10:36 - 2020-12-06 10:36 - 001790024 _____ (Malwarebytes) C:\Users\Caro\Downloads\JRT.exe
2020-12-05 14:24 - 2020-12-05 15:59 - 000000000 ____D C:\ProgramData\boost_interprocess
2020-12-05 13:28 - 2020-12-05 13:28 - 000000000 ____D C:\Users\Caro\AppData\Local\MicrosoftEdge
2020-12-05 12:34 - 2020-12-05 12:34 - 000000000 ___DC C:\Users\Caro\AppData\LocalLow\IObit
2020-12-05 12:33 - 2020-12-05 12:33 - 000000000 ____D C:\Program Files (x86)\IObit
2020-12-05 12:32 - 2020-12-06 11:31 - 000000000 ____D C:\Users\Caro\AppData\Roaming\IObit
2020-12-05 12:32 - 2020-12-05 12:34 - 000000000 ____D C:\ProgramData\IObit
2020-12-05 12:32 - 2020-12-05 12:32 - 025230736 _____ (IObit ) C:\Users\Caro\Downloads\iobituninstaller.exe
2020-12-05 11:25 - 2020-12-05 11:25 - 000000000 ____D C:\Users\Caro\AppData\Local\ESET
2020-12-05 11:25 - 2020-12-05 11:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2020-12-05 11:25 - 2020-12-05 11:25 - 000000000 ____D C:\ProgramData\ESET
2020-12-05 11:25 - 2020-12-05 11:25 - 000000000 ____D C:\Program Files\ESET
2020-12-05 11:22 - 2020-12-05 12:35 - 000000000 ____D C:\AdwCleaner
2020-12-05 11:22 - 2020-12-05 11:22 - 008447152 _____ (Malwarebytes) C:\Users\Caro\Desktop\adwcleaner_8.0.8.exe
2020-12-05 11:22 - 2020-12-05 11:22 - 006341552 _____ (ESET) C:\Users\Caro\Downloads\eset_internet_security_live_installer.exe
2020-12-05 11:15 - 2020-12-05 11:15 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-12-05 11:15 - 2020-12-05 11:14 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-11-28 20:01 - 2020-11-28 20:01 - 000001130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro 2020.lnk
2020-11-28 19:53 - 2020-11-28 19:53 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2021.lnk
2020-11-28 19:49 - 2020-11-28 19:49 - 000001085 ____C C:\Users\Caro\Desktop\Adobe Lightroom Classic.lnk
2020-11-28 19:49 - 2020-11-28 19:49 - 000001085 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom Classic.lnk
2020-11-23 10:46 - 2020-12-03 18:32 - 000001456 _____ C:\Users\Caro\AppData\Local\Adobe Save for Web 13.0 Prefs
2020-11-17 11:53 - 2020-11-17 11:53 - 001919470 _____ C:\Users\Caro\Downloads\Wedding Photography Contract - Sam & Mark 1.pdf
2020-11-15 12:29 - 2020-11-15 12:29 - 000000000 ___DC C:\Users\Caro\Documents\Zoom
2020-11-15 12:28 - 2020-12-05 12:44 - 000000000 ____D C:\Users\Caro\AppData\Roaming\Zoom
2020-11-10 23:51 - 2020-11-10 23:51 - 001841152 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2020-11-10 23:51 - 2020-11-10 23:51 - 001101312 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-11-10 23:51 - 2020-11-10 23:51 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-11-10 23:50 - 2020-11-10 23:50 - 000200704 _____ C:\WINDOWS\system32\IHDS.dll
2020-11-10 23:50 - 2020-11-10 23:50 - 000164864 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2020-11-10 14:36 - 2020-11-10 14:36 - 000112759 _____ C:\Users\Caro\Downloads\Wedding Photography Contract (1).pdf
2020-11-10 14:35 - 2020-11-10 14:35 - 000112759 _____ C:\Users\Caro\Downloads\Wedding Photography Contract.pdf
2020-11-09 15:38 - 2020-11-09 15:38 - 000000000 ____D C:\Users\Caro\Downloads\Wedding-titles-v3-30607
2020-11-09 15:36 - 2020-11-09 15:36 - 022486391 _____ C:\Users\Caro\Downloads\Wedding-titles-v3-30607.zip
2020-11-08 12:27 - 2020-11-08 12:27 - 000353190 _____ C:\Users\Caro\Downloads\Carolyn_CRA_2019_summary.pdf
2020-11-06 12:06 - 2020-11-06 12:06 - 002222316 _____ C:\Users\Caro\Downloads\ImprovePhotographyContracts.zip
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-12-06 12:53 - 2020-05-09 17:54 - 000000000 ____D C:\ProgramData\NVIDIA
2020-12-06 12:52 - 2018-05-09 09:01 - 000000000 ___RD C:\Users\Caro\Creative Cloud Files
2020-12-06 12:51 - 2020-05-09 17:56 - 000003092 _____ C:\WINDOWS\system32\Tasks\GPU Tweak II
2020-12-06 12:51 - 2020-04-06 14:17 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-12-06 12:50 - 2020-04-30 19:09 - 000012510 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1
2020-12-06 12:50 - 2020-04-30 19:09 - 000012312 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1
2020-12-06 12:50 - 2020-04-30 19:09 - 000006472 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1
2020-12-06 12:50 - 2020-04-06 17:46 - 000761886 _____ C:\WINDOWS\system32\prfh0416.dat
2020-12-06 12:50 - 2020-04-06 17:46 - 000148752 _____ C:\WINDOWS\system32\prfc0416.dat
2020-12-06 12:50 - 2020-04-06 14:14 - 001742324 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-12-06 12:50 - 2019-03-18 23:50 - 000000000 ____D C:\WINDOWS\INF
2020-12-06 12:50 - 2019-03-18 23:37 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2020-12-06 12:46 - 2019-03-18 23:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-12-06 12:09 - 2018-07-01 10:42 - 000000000 ___DC C:\Users\Caro\AppData\Local\D3DSCache
2020-12-06 11:40 - 2018-05-09 11:08 - 000000000 ___RD C:\Users\Caro\OneDrive
2020-12-06 10:33 - 2020-04-06 14:17 - 000004164 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{1140566A-E7E9-45BC-8379-45654BCF9F6C}
2020-12-06 10:30 - 2020-04-06 14:04 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-12-05 23:06 - 2019-03-18 23:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-12-05 23:06 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-12-05 15:32 - 2020-04-30 19:08 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2020-12-05 14:24 - 2020-05-10 11:27 - 000000000 ____D C:\Users\Caro\AppData\Local\NVIDIA Corporation
2020-12-05 13:31 - 2018-05-09 11:07 - 000000000 ___DC C:\Users\Caro\AppData\Local\Packages
2020-12-05 11:42 - 2020-04-06 14:17 - 000003766 _____ C:\WINDOWS\system32\Tasks\Power_a17007
2020-12-05 11:25 - 2019-03-18 23:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-12-05 11:15 - 2020-08-26 09:49 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-12-05 11:15 - 2019-08-18 13:32 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-12-05 11:15 - 2019-08-18 13:32 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-12-05 11:15 - 2018-05-25 17:38 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2020-12-05 11:14 - 2019-08-18 13:32 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-12-04 22:49 - 2019-10-03 13:56 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-12-04 22:49 - 2019-10-03 13:56 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData
2020-12-04 16:45 - 2018-05-08 20:35 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-12-03 18:47 - 2020-04-06 14:17 - 000003418 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-12-03 18:47 - 2020-04-06 14:17 - 000003294 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-12-02 17:35 - 2018-05-08 20:17 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-12-02 17:35 - 2018-05-08 20:17 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-12-02 17:35 - 2018-05-08 20:17 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-11-29 12:43 - 2018-05-09 08:30 - 000000000 ___DC C:\Users\Caro\AppData\Local\Adobe
2020-11-28 23:40 - 2018-05-09 09:12 - 000000000 ___DC C:\Users\Caro\Documents\Adobe
2020-11-28 20:01 - 2018-05-09 09:22 - 000000000 ____D C:\Users\Public\Documents\Adobe
2020-11-28 20:01 - 2018-05-09 09:22 - 000000000 ____D C:\ProgramData\Documents\Adobe
2020-11-28 20:01 - 2018-05-09 09:01 - 000000000 ____D C:\Program Files\Adobe
2020-11-28 19:54 - 2018-05-09 11:07 - 000000000 ___DC C:\Users\Caro\AppData\Roaming\Adobe
2020-11-28 16:44 - 2020-05-12 15:32 - 000000000 ____D C:\Users\Caro\AppData\Local\CrashDumps
2020-11-25 13:16 - 2018-05-09 09:02 - 000000000 ____D C:\Program Files\Common Files\Adobe
2020-11-25 13:16 - 2018-05-09 08:32 - 000000000 ____D C:\ProgramData\Adobe
2020-11-25 12:56 - 2020-04-06 14:17 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-11-25 12:56 - 2018-12-09 17:54 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-11-25 07:16 - 2020-08-21 09:10 - 000002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2020-11-25 07:16 - 2020-08-21 09:10 - 000002103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2020-11-24 00:20 - 2019-04-27 08:54 - 000000000 ____D C:\Users\Caro\AppData\Roaming\vlc
2020-11-24 00:11 - 2019-04-27 08:53 - 000001139 _____ C:\Users\Public\Desktop\VLC media player.lnk
2020-11-24 00:11 - 2019-04-27 08:53 - 000001139 _____ C:\ProgramData\Desktop\VLC media player.lnk
2020-11-23 23:29 - 2020-04-06 14:17 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-881217815-4272472998-2328836942-1001
2020-11-23 23:29 - 2020-04-06 14:08 - 000002360 ____C C:\Users\Caro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-11-22 11:48 - 2018-11-25 15:08 - 000000000 ____D C:\Program Files\Microsoft Office 15
2020-11-20 13:01 - 2018-06-17 22:31 - 000002338 ____C C:\Users\Caro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive (1).lnk
2020-11-19 21:17 - 2020-09-30 16:09 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2020-11-12 11:00 - 2020-03-22 20:35 - 000907064 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2020-11-12 10:59 - 2020-09-30 16:09 - 000436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
2020-11-11 01:28 - 2018-06-18 18:02 - 000000000 ___RD C:\Users\Caro\3D Objects
2020-11-11 01:28 - 2018-05-09 11:07 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-11-11 01:27 - 2020-04-06 14:04 - 000322760 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-11-11 01:26 - 2019-03-19 01:23 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\TextInput
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\system32\setup
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2020-11-11 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-11-10 23:57 - 2019-03-18 23:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-11-10 23:50 - 2020-04-06 14:07 - 002876928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-11-10 23:10 - 2018-05-08 20:34 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-11-10 23:06 - 2018-05-08 20:34 - 133736600 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories ========
2018-06-17 13:50 - 2018-06-17 13:50 - 000000033 ____C () C:\Users\Caro\AppData\Roaming\AdobeWLCMCache.dat
2020-11-23 10:46 - 2020-12-03 18:32 - 000001456 _____ () C:\Users\Caro\AppData\Local\Adobe Save for Web 13.0 Prefs
2018-09-28 07:13 - 2018-09-28 07:13 - 000000000 ____C () C:\Users\Caro\AppData\Local\oobelibMkey.log
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================