NonTechyDad
Posts: 26 +0
Greetings,
I am trying to remove virus/malware off of my son's computer and this is my first time using farbar scan. I have generated the FRST and Addition.txt files but I am not sure what to do next. The system has restricted his admin priv's.
Thank you for any help in advance.
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-07-2022
Ran by TheVerbalArteest (administrator) on DESKTOP-RIMVDU7 (Hewlett-Packard HP Compaq dc7900 Small Form Factor) (17-07-2022 06:15:26)
Running from C:\Users\TheVe\Desktop
Loaded Profiles: TheVerbalArteest & temp.fix
Platform: Microsoft Windows 10 Home Version 1803 17134.706 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(C:\Users\TheVe\AppData\Local\wdkmbcg\wdkmbcg.exe ->) () [Access Denied] C:\Users\TheVe\AppData\Local\wdkmbcg\raakpmi.exe <2>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <24>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler64.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <12>
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\Kinoni\EpocCam_and_Barcode_drivers\KinoniSvc.exe
(services.exe ->) (Andrea Electronics Corporation) [File not signed] C:\Windows\System32\AEADISRV.EXE
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\AMT\LMS.exe
(services.exe ->) (Intel(R) Driver & Support Assistant -> Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <5>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (PACE Anti-Piracy, Inc. -> PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Synchro Arts Ltd -> Synchro Arts Ltd) [File not signed] C:\Program Files (x86)\Common Files\Synchro Arts Shared\License.exe
(services.exe ->) (TOSHIBA CORPORATION) [File not signed] [File is in use] C:\Windows\System32\spsnzersvc.exe
(spsnzersvc.exe ->) () [Access Denied] C:\Users\TheVe\AppData\Local\wdkmbcg\wdkmbcg.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_3.1.55.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.580_none_ead976921d8220dc\TiWorker.exe
(svchost.exe ->) (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.42.60.0_x64__kzf8qxf38zg5c\SkypeApp.exe <2>
(svchost.exe ->) (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.42.60.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe <2>
(winlogon.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LogonUI.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [picon] => C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [796696 2009-07-24] (Intel Corporation -> Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-03-24] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.) [File not signed]
HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [131360 2018-01-17] (Intel(R) Driver & Support Assistant -> Intel)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [76600 2019-03-09] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) [File not signed]
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-10-25] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2010-10-25] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [821144 2010-10-25] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\Run: [com.squirrel.splice.Splice] => C:\Users\TheVe\AppData\Local\splice\app-3.3.109793\Splice.exe (No File)
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\Run: [Browser Manager] => C:\Users\TheVe\AppData\Local\Yandex\BrowserManager\MBLauncher.exe (No File)
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\Run: [MP3 Skype recorder] => C:\Users\TheVe\AppData\Local\MP3 Skype recorder\MP3SkypeRecorder.exe [3880584 2018-11-11] (DOMIT LIMITED -> Domit UK LTD)
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\Run: [GoogleChromeAutoLaunch_C4EF761CAF8184320C85D0131A064097] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [2673480 2022-07-01] (Google LLC -> Google LLC)
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\MountPoints2: {6cae8016-6a0c-11e9-8827-0050b6294e10} - "F:\MfeEERM.exe"
HKU\S-1-5-21-3999933350-674082219-2972644759-1002\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\temp.fix\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-3999933350-674082219-2972644759-1002\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\temp.fix\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [53656 2010-10-25] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\...\Print\Monitors\IppMon: C:\WINDOWS\system32\IPPMon.dll [251392 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\103.0.5060.114\Installer\chrmstp.exe [2022-07-07] (Google LLC -> Google LLC)
Startup: C:\Users\TheVe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EOS Utility.lnk [2018-01-28]
ShortcutTarget: EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon Inc. -> Canon INC.)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {00ADCC9D-F367-488C-ACFF-7AD89E3C1236} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0C02645C-34C1-4AFF-894F-0EB347BDF67B} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [887152 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0EAE4EF2-C8D0-4E1C-BA7C-324099D4BCAD} - System32\Tasks\Red Giant Link => C:\Program Files\Red Giant Link\Red Giant Link.exe --silent (No File)
Task: {1BAD968B-ADC1-4484-A863-B2A06EAFE2F3} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23378880 2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {231268DA-C332-4852-9926-BAFDEBAAB7FC} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3560304 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {289FAC5C-A456-425D-9877-8A3A4EF2B0B4} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [786800 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {3C3B1D1A-7930-45F4-AF52-29CB173E0C97} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {405D6045-7143-4BE5-97EE-F7D0352A2C87} - System32\Tasks\categorizations exasperated relishing => C:\Users\TheVe\AppData\Local\Antigens.exe oklavwoklavwoklavwoklav.oklavkoklavnoklavmoklav.oklavpoklavwoklav/oklavg2rm0rm1rmoklav9rm0zn4zn2oklavg3grmhtmlroklavuT6gmnRGUFoklavyXjvAeYnK (No File)
Task: {572F0843-E2DF-4F65-8616-0278EA00AFE0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-01-26] (Google Inc -> Google Inc.)
Task: {5CB93FB4-EF3B-4B2C-BD29-1E81715BFE69} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [275136 2022-01-31] (Bluestack Systems, Inc -> BlueStack Systems, Inc.)
Task: {60DA993F-7DA0-4198-84B6-59987281D6AC} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [786800 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {6321E5BE-09B8-4234-996E-A28BBAE5AF56} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {67162561-8F50-4C28-9AA0-2327EF46EA96} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [887152 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6FFB5A39-DF90-4F51-821C-773F98FF1AE9} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {77E46CF6-4F8F-4D7E-A3AF-C93242C36133} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {793B7B22-EA3A-4010-8789-DB8E9801C23D} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [1003888 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {799EDE7A-1487-41C3-A300-B3D44D41A7EC} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [887152 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8012F695-FA52-47B6-95D5-3FB8261052E6} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [562544 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {85B15520-C670-407E-8397-57FAB64CFE94} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23378880 2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {9BC64336-A8E1-4B80-9704-560E560103E1} - System32\Tasks\categorizations exasperated relishingcategorizations exasperated relishing => C:\Users\TheVe\AppData\Local\Antigens.exe oklavwoklavwoklavwoklav.oklavkoklavnoklavmoklav.oklavpoklavwoklav/oklavg2rm0rm1rmoklav9rm0zn4zn2oklavg3grmhtmlroklavuT6gmnRGUFoklavyXjvAeYnK (No File)
Task: {A1A3D805-19B0-453D-983B-BCE709E9EF50} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [855408 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A30A24E9-B197-467B-A1FD-7E3262117A46} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116656 2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {A6F81679-D86A-4D96-9E47-C5E6FFF20F6D} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {AA017D50-057E-4683-940B-F79DBF9A27BB} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {AA797A31-5155-491F-A119-4A294BC4B676} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [855408 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AE888DB4-C560-4D6A-ABC9-ED569DB35432} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B60F94EF-967B-4F92-89F7-DFA38E4268F7} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [887152 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D88B52CD-F1A8-4413-B610-EE2D2B5548B8} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2250576 2022-05-24] (Avast Software s.r.o. -> Avast Software)
Task: {E0243755-C9B2-4D4E-9D7E-FE9CFA0B86C9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-01-26] (Google Inc -> Google Inc.)
Task: {E2158A77-C3D3-4EB4-8BDC-390BEA3340FE} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {E5CCEF5F-F876-475E-9271-80701F601FCA} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {F2D357E0-2829-4406-BA91-95667E031E16} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116656 2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 208.59.247.45 208.59.247.46
Tcpip\..\Interfaces\{665f913f-0411-4e38-b250-529f0438f3e7}: [DhcpNameServer] 208.59.247.45 208.59.247.46
Tcpip\..\Interfaces\{d99ff61f-598e-4809-921f-9121ab7cc41e}: [DhcpNameServer] 208.59.247.45 208.59.247.46
Edge:
=======
Edge HomeButtonPage: HKU\S-1-5-21-3999933350-674082219-2972644759-1001 -> hxxps://www.yandex.ru/?win=362&clid=2255618
FireFox:
========
FF DefaultProfile: nahd6ha2.default
FF ProfilePath: C:\Users\TheVe\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default [2022-07-17]
FF NewTabOverride: Mozilla\Firefox\Profiles\nahd6ha2.default -> Disabled: vb@yandex.ru
FF Extension: (Visual Bookmarks) - C:\Users\TheVe\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\vb@yandex.ru.xpi [2022-06-21]
FF SearchPlugin: C:\Users\TheVe\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\yandex.ru-20182703.xml [2018-12-03]
FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
FF Extension: (Adobe Contribute Toolbar) - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2019-05-19] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2019-06-06] [Legacy] [not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-03-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-03-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default [2022-07-17]
CHR Notifications: Default -> hxxps://go.proctoru.com; hxxps://slimsk.pro; hxxps://www.facebook.com; hxxps://www.tiktok.com
CHR Extension: (Privacy Pass) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhmfdgkijocedmfjonnpjfojldioehi [2022-06-21]
CHR Extension: (Chrome IG Story) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\bojgejgifofondahckoaahkilneffhmf [2019-02-13]
CHR Extension: (DownAlbum) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgjnhhjpfcdhbhlcmmjppicjmgfkppok [2022-07-04]
CHR Extension: (Video Downloader professional) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2022-06-22]
CHR Extension: (Google Docs Offline) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-06-18]
CHR Extension: (Google Play Books) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2018-02-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-03-03]
CHR Extension: (Vimeo Downloader Professional) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocaallccmjamifmbnammngacjphelonn [2020-03-07]
CHR Extension: (vidIQ Vision for YouTube) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pachckjkecffpdphbpmfolblodfkgbhl [2022-07-17]
CHR Profile: C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\System Profile [2018-01-28]
CHR HKLM-x32\...\Chrome\Extension: [gndelhfhcfbdhndfpcinebijfcjpmpec]
Yandex:
=======
YAN Profile: C:\Users\TheVe\AppData\Local\Yandex\YandexBrowser\User Data\Default [2018-12-03]
YAN Extension: (Rating Program Extension - Cloud) - C:\Users\TheVe\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\aeblbnaefoaakjgpedmjbogemoegfdfm [2018-12-03]
YAN Extension: (Chrome IG Story) - C:\Users\TheVe\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\bojgejgifofondahckoaahkilneffhmf [2018-12-03]
YAN Extension: (vidIQ Vision for YouTube) - C:\Users\TheVe\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\pachckjkecffpdphbpmfolblodfkgbhl [2018-12-03]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"ixdog" => service could not be unlocked. <==== ATTENTION
HKLM\SYSTEM\ControlSet001\Services\ixdog => C:\WINDOWS\System32\drivers\ianruybe.sys [145744 2022-06-24] (Access Denied) [File not signed] <==== ATTENTION (Rootkit!/Locked Service)
"MBAMInstallerService" => service could not be unlocked. <==== ATTENTION
HKLM\SYSTEM\ControlSet001\Services\MBAMInstallerService => C:\Users\TheVe\AppData\Local\Temp\MBAMInstallerService.exe [8693208 2022-07-17] (Malwarebytes Inc. -> Malwarebytes) <==== ATTENTION (Rootkit!/Locked Service)
"MBAMWebProtection" => service could not be unlocked. <==== ATTENTION
HKLM\SYSTEM\ControlSet001\Services\MBAMWebProtection => \SystemRoot\system32\DRIVERS\mwac.sys <==== ATTENTION (Rootkit!/Locked Service)
R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12111264 2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [22304 2018-01-17] (Intel(R) Driver & Support Assistant -> Intel)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [775296 2018-04-26] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 KinoniSvc; C:\Program Files (x86)\Kinoni\EpocCam_and_Barcode_drivers\KinoniSvc.exe [525312 2013-02-26] () [File not signed]
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-05-22] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
R2 Synchro Arts License Manager; C:\Program Files (x86)\Common Files\Synchro Arts Shared\License.exe [175488 2008-02-22] (Synchro Arts Ltd -> Synchro Arts Ltd) [File not signed]
R2 UNS; C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2066968 2009-07-24] (Intel Corporation -> Intel Corporation)
S2 gramblrclient; C:\Program Files\Gramblr\gramblr.exe [X]
R2 PaceLicenseDServices; "C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe" -u hxxps://activation.paceap.com/InitiateActivation
S3 WdNisSvc; "%ProgramData%\Microsoft\Windows Defender\platform\4.18.1909.6-0\NisSrv.exe" [X]
S2 WinDefend; "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MsMpEng.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [357768 2018-08-22] (Bitdefender SRL -> Bitdefender)
S3 edrsensor; C:\WINDOWS\System32\DRIVERS\edrsensor.sys [294000 2018-10-09] (Bitdefender SRL -> BitDefender S.R.L. Bucharest, ROMANIA)
R3 KINONI_Wave; C:\WINDOWS\system32\drivers\kinonivad.sys [32360 2016-04-17] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 LoopBeMidi1; C:\WINDOWS\system32\drivers\loopbe1.sys [13824 2011-04-09] (nerds.de) [File not signed]
S4 lzrutis; C:\WINDOWS\System32\drivers\vdrcuspz.sys [148816 2019-04-23] () [File not signed]
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-22] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 VBAudioVMVAIOMME; C:\WINDOWS\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [41192 2017-06-30] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46472 2019-10-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [351968 2019-10-30] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2019-10-30] (Microsoft Windows -> Microsoft Corporation)
S3 BstkDrv; \??\C:\Program Files (x86)\BlueStacks\BstkDrv.sys [X]
S3 cpuz148; \??\C:\WINDOWS\temp\cpuz148\cpuz148_x64.sys [X]
R3 mpswzc; system32\drivers\svzcfj.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-07-17 06:05 - 2022-07-17 06:11 - 000054253 _____ C:\Users\TheVe\Desktop\Addition.txt
2022-07-17 06:02 - 2022-07-17 06:16 - 000028807 _____ C:\Users\TheVe\Desktop\FRST.txt
2022-07-17 05:54 - 2022-07-17 06:16 - 000000000 ____D C:\FRST
2022-07-17 05:52 - 2022-07-17 05:52 - 002369536 _____ (Farbar) C:\Users\TheVe\Desktop\FRST64.exe
2022-07-17 05:41 - 2022-07-17 05:43 - 000004974 _____ C:\Users\TheVe\Downloads\.6efeab48d0425dd4637604354adea9c6476d2ade.parts
2022-07-17 05:37 - 2022-07-17 05:37 - 000011379 _____ C:\Users\TheVe\Downloads\[audionews.org].t334847.torrent
2022-07-17 05:37 - 2022-07-17 05:37 - 000000000 ____D C:\Users\TheVe\Downloads\Adobe.Animate.2022.v22.0.6.202.x64.WIN
2022-07-17 05:13 - 2022-07-17 05:13 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3999933350-674082219-2972644759-1002
2022-07-17 05:13 - 2022-07-17 05:13 - 000003384 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3999933350-674082219-2972644759-1002
2022-07-17 05:12 - 2022-07-17 05:13 - 000002770 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task v2
2022-07-17 05:10 - 2022-07-17 05:10 - 000000000 ____D C:\Users\temp.fix\ansel
2022-07-17 05:07 - 2022-07-17 05:07 - 000001417 _____ C:\Users\temp.fix\Desktop\Microsoft Edge.lnk
2022-07-17 05:07 - 2022-07-17 05:07 - 000000000 ___HD C:\Users\temp.fix\MicrosoftEdgeBackups
2022-07-17 05:07 - 2022-07-17 05:07 - 000000000 ____D C:\Users\temp.fix\AppData\Local\MicrosoftEdge
2022-07-17 05:07 - 2022-07-17 05:07 - 000000000 ____D C:\Users\temp.fix\AppData\Local\CEF
2022-07-17 05:06 - 2022-07-17 05:08 - 000000000 ____D C:\Users\temp.fix\AppData\Local\NVIDIA Corporation
2022-07-17 05:06 - 2022-07-17 05:06 - 000000000 ___RD C:\Users\temp.fix\3D Objects
2022-07-17 05:06 - 2022-07-17 05:06 - 000000000 ____D C:\Users\temp.fix\AppData\Local\VirtualStore
2022-07-17 05:06 - 2022-07-17 05:06 - 000000000 ____D C:\Users\temp.fix\AppData\Local\NVIDIA
2022-07-17 05:06 - 2022-07-17 05:06 - 000000000 ____D C:\Users\temp.fix\AppData\Local\Google
2022-07-17 05:05 - 2022-07-17 05:36 - 000000000 ____D C:\Users\temp.fix\AppData\Local\Packages
2022-07-17 05:05 - 2022-07-17 05:13 - 000002379 _____ C:\Users\temp.fix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-07-17 05:05 - 2022-07-17 05:12 - 000000000 ___RD C:\Users\temp.fix\OneDrive
2022-07-17 05:05 - 2022-07-17 05:10 - 000000000 ____D C:\Users\temp.fix
2022-07-17 05:05 - 2022-07-17 05:08 - 000000000 ____D C:\Users\temp.fix\AppData\Local\ConnectedDevicesPlatform
2022-07-17 05:05 - 2022-07-17 05:05 - 000000020 ___SH C:\Users\temp.fix\ntuser.ini
2022-07-17 05:05 - 2018-01-26 12:01 - 000000000 ____D C:\Users\temp.fix\AppData\Roaming\Adobe
2022-07-17 05:05 - 2018-01-26 12:01 - 000000000 ____D C:\Users\temp.fix\AppData\Local\TileDataLayer
2022-07-17 05:05 - 2018-01-26 12:01 - 000000000 ____D C:\Users\temp.fix\AppData\Local\Publishers
2022-07-17 05:05 - 2018-01-26 12:01 - 000000000 ____D C:\Users\temp.fix\AppData\Local\Comms
2022-07-17 05:05 - 2016-09-02 11:32 - 000000319 _____ C:\Users\temp.fix\Desktop\Get Office 365 Personal.url
2022-07-17 05:05 - 2016-09-02 11:31 - 000000194 _____ C:\Users\temp.fix\Desktop\Get Office 365 Home.url
2022-07-17 05:05 - 2016-08-31 16:58 - 000000154 _____ C:\Users\temp.fix\Desktop\Microsoft Store.url
2022-07-17 03:53 - 2022-07-17 04:11 - 000000000 ____D C:\Users\TheVe\Downloads\Adobe.Animate.2022.v22.0.7.214.x64.WIN
2022-07-17 03:52 - 2022-07-17 03:52 - 000011379 _____ C:\Users\TheVe\Downloads\[audionews.org].t339695.torrent
2022-07-10 23:19 - 2022-07-10 23:19 - 001232282 _____ C:\Users\TheVe\Downloads\Blank.zip
2022-07-05 11:59 - 2022-07-05 11:59 - 000000000 ____D C:\Users\TheVe\AppData\Local\aundsgb
2022-07-02 00:29 - 2022-07-02 00:29 - 000000000 _____ C:\Users\TheVe\Downloads\download
2022-06-30 08:34 - 2022-07-17 03:25 - 000000170 _____ C:\WINDOWS\wininit.ini
2022-06-30 04:43 - 2022-06-30 04:43 - 000800839 _____ C:\Users\TheVe\Downloads\Bluster.zip
2022-06-28 04:56 - 2022-06-28 04:58 - 1367096420 _____ C:\Users\TheVe\Downloads\Adobe Flash Pro CS6.exe
2022-06-28 04:46 - 2022-06-28 04:47 - 130656256 _____ C:\Users\TheVe\Downloads\Searching for_ adobe animate in_.iso
2022-06-28 04:45 - 2022-06-28 04:45 - 130656256 _____ C:\Users\TheVe\Downloads\Adobe Animate CC 2017 v16.0.1 (x64) + Crack [Sa....iso
2022-06-24 05:22 - 2022-06-24 05:22 - 000000000 ____D C:\Users\TheVe\AppData\Local\pwhvnux
2022-06-24 05:18 - 2022-06-24 05:18 - 000145744 ____N C:\WINDOWS\system32\Drivers\ianruybe.sys
2022-06-21 09:36 - 2022-06-21 09:36 - 000005473 _____ C:\Users\TheVe\Downloads\index(1).m3u8
2022-06-21 09:36 - 2022-06-21 09:36 - 000005445 _____ C:\Users\TheVe\Downloads\index.m3u8
2022-06-21 09:26 - 2022-06-21 09:26 - 000104140 _____ C:\Users\TheVe\Downloads\NEWDAYLYTvideoplayback.mp4
2022-06-21 09:19 - 2022-06-21 09:20 - 000211848 _____ C:\Users\TheVe\Downloads\DAYLYT “ Battlr rap talk ! Matches I want to seeee.mp4
2022-06-21 09:18 - 2022-06-21 09:19 - 001291014 _____ C:\Users\TheVe\Downloads\DAYLYTvideoplayback.mp4
2022-06-21 08:48 - 2022-07-17 05:52 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-06-21 08:48 - 2022-07-17 03:25 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-06-21 07:33 - 2022-06-24 05:15 - 000000000 ____D C:\Users\TheVe\Desktop\battle life
2022-06-19 07:17 - 2022-06-19 07:17 - 000000000 ____D C:\ProgramData\obs-studio-hook
2022-06-19 05:13 - 2022-06-19 05:13 - 000000798 _____ C:\Users\TheVe\Downloads\init-stream_0.m4s.mp4.mp4
2022-06-18 00:42 - 2022-06-18 00:42 - 000000000 ____D C:\Users\TheVe\AppData\Local\snbdpxc
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-07-17 06:11 - 2018-04-11 19:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-07-17 06:08 - 2018-04-11 19:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-07-17 06:05 - 2018-02-08 18:55 - 000000000 ____D C:\Users\TheVe\AppData\Roaming\qBittorrent
2022-07-17 05:54 - 2018-01-26 12:09 - 000000000 ____D C:\Program Files (x86)\Google
2022-07-17 05:51 - 2019-04-27 20:20 - 000000000 ____D C:\Users\TheVe\AppData\LocalLow\Mozilla
2022-07-17 05:39 - 2019-04-23 22:47 - 000000000 ____D C:\Users\TheVe\AppData\Local\wdkmbcg
2022-07-17 05:36 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-07-17 05:35 - 2018-06-22 18:29 - 000000000 ____D C:\ProgramData\Packages
2022-07-17 05:34 - 2018-04-11 19:38 - 000000000 ___HD C:\Program Files\WindowsApps
2022-07-17 05:11 - 2018-04-12 16:09 - 000000000 ____D C:\ProgramData\NVIDIA
2022-07-17 05:06 - 2016-11-20 14:51 - 000000000 __RHD C:\Users\Public\AccountPictures
2022-07-17 04:30 - 2018-04-16 12:59 - 000000000 ____D C:\Users\TheVe\AppData\Local\CrashDumps
2022-07-17 04:18 - 2018-08-14 12:56 - 000000000 ____D C:\Users\TheVe\AppData\Local\D3DSCache
2022-07-17 04:16 - 2018-02-17 21:04 - 000000000 ____D C:\ProgramData\Package Cache
2022-07-17 04:12 - 2018-01-28 18:41 - 000000000 ____D C:\Users\TheVe\AppData\Local\Adobe
2022-07-17 04:12 - 2018-01-28 18:41 - 000000000 ____D C:\ProgramData\Adobe
2022-07-17 03:25 - 2019-04-27 20:20 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-07-17 03:25 - 2019-04-27 20:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-07-17 02:32 - 2018-05-22 18:54 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-07-15 22:19 - 2018-05-22 19:13 - 000838560 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-07-15 22:19 - 2018-04-11 19:36 - 000000000 ____D C:\WINDOWS\INF
2022-07-14 07:41 - 2022-02-14 11:30 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3999933350-674082219-2972644759-1001
2022-07-14 07:41 - 2018-05-22 19:15 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3999933350-674082219-2972644759-1001
2022-07-14 07:41 - 2018-05-22 19:00 - 000002386 _____ C:\Users\TheVe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-07-13 07:38 - 2019-06-11 00:17 - 000000132 _____ C:\Users\TheVe\AppData\Roaming\Adobe PNG Format CS5 Prefs
2022-07-09 03:11 - 2017-01-11 15:52 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2022-07-07 10:55 - 2018-01-26 12:10 - 000002338 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-07-07 10:55 - 2018-01-26 12:10 - 000002297 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-07-06 05:35 - 2018-01-26 23:45 - 000000000 ____D C:\Users\TheVe\AppData\Roaming\vlc
2022-07-05 11:55 - 2018-05-22 19:15 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-07-05 11:54 - 2019-04-23 21:56 - 002930176 _____ (TOSHIBA CORPORATION) C:\WINDOWS\system32\spsnzersvc.exe
2022-06-30 08:54 - 2018-05-22 19:00 - 000000000 ____D C:\Users\TheVe\AppData\Local\Packages
2022-06-29 08:15 - 2022-02-14 03:49 - 000000000 ____D C:\Users\TheVe\AppData\Local\ElevatedDiagnostics
2022-06-24 05:19 - 2018-04-11 17:04 - 018612224 _____ C:\WINDOWS\system32\config\HARDWARE
2022-06-24 05:19 - 2018-04-11 17:04 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2022-06-21 09:35 - 2018-01-26 13:59 - 000001146 _____ C:\Users\Public\Desktop\VLC media player.lnk
2022-06-21 08:48 - 2019-04-27 20:20 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-06-19 10:59 - 2018-01-26 14:30 - 000000000 ____D C:\Users\TheVe\AppData\Roaming\obs-studio
==================== Files in the root of some directories ========
2018-12-03 16:23 - 2018-12-03 16:24 - 000137168 _____ (Mozilla Foundation) C:\ProgramData\mozglue.dll
2018-12-03 16:23 - 2018-12-03 16:24 - 001246160 _____ (Mozilla Foundation) C:\ProgramData\nss3.dll
2018-08-09 16:03 - 2018-09-17 18:03 - 002722286 _____ () C:\Program Files (x86)\Auto-Tune 8 Manual.pdf
2018-08-09 16:03 - 2018-09-17 18:03 - 000056051 _____ () C:\Program Files (x86)\VST PC Read Me.pdf
2019-06-11 00:16 - 2019-06-12 10:41 - 000000132 _____ () C:\Users\TheVe\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
2019-06-11 00:17 - 2022-07-13 07:38 - 000000132 _____ () C:\Users\TheVe\AppData\Roaming\Adobe PNG Format CS5 Prefs
2018-03-10 17:10 - 2020-11-21 19:35 - 000000032 _____ () C:\Users\TheVe\AppData\Roaming\msregsvv.dll
2018-02-18 15:51 - 2022-02-19 11:25 - 000002824 _____ () C:\Users\TheVe\AppData\Roaming\VoiceMeeterDefault.xml
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_essentials.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_mixbus3.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000109 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_mixbus32c-4.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000107 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_mixbus32c.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_mixbus4.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_bc3.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_ds.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_eg.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_eq.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000107 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_lc.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_mc.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_me.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000107 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_sc.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_tg.txt
2020-10-16 15:27 - 2020-10-16 15:27 - 000000787 _____ () C:\Users\TheVe\AppData\Local\recently-used.xbel
==================== FLock ==============================
2019-04-23 21:56 C:\WINDOWS\system32\zacldsw
2022-07-05 11:54 C:\WINDOWS\system32\config\SYSTEM
2022-06-24 05:18 C:\WINDOWS\system32\Drivers\ianruybe.sys
2018-12-03 23:25 C:\Users\TheVe\AppData\Roaming\wow64_microsoft-windows-I..lprovider.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_4025bb8924a11670
2022-07-17 05:39 C:\Users\TheVe\AppData\Local\wdkmbcg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
I am trying to remove virus/malware off of my son's computer and this is my first time using farbar scan. I have generated the FRST and Addition.txt files but I am not sure what to do next. The system has restricted his admin priv's.
Thank you for any help in advance.
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-07-2022
Ran by TheVerbalArteest (administrator) on DESKTOP-RIMVDU7 (Hewlett-Packard HP Compaq dc7900 Small Form Factor) (17-07-2022 06:15:26)
Running from C:\Users\TheVe\Desktop
Loaded Profiles: TheVerbalArteest & temp.fix
Platform: Microsoft Windows 10 Home Version 1803 17134.706 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(C:\Users\TheVe\AppData\Local\wdkmbcg\wdkmbcg.exe ->) () [Access Denied] C:\Users\TheVe\AppData\Local\wdkmbcg\raakpmi.exe <2>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <24>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler64.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <12>
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\Kinoni\EpocCam_and_Barcode_drivers\KinoniSvc.exe
(services.exe ->) (Andrea Electronics Corporation) [File not signed] C:\Windows\System32\AEADISRV.EXE
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\AMT\LMS.exe
(services.exe ->) (Intel(R) Driver & Support Assistant -> Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <5>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (PACE Anti-Piracy, Inc. -> PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Synchro Arts Ltd -> Synchro Arts Ltd) [File not signed] C:\Program Files (x86)\Common Files\Synchro Arts Shared\License.exe
(services.exe ->) (TOSHIBA CORPORATION) [File not signed] [File is in use] C:\Windows\System32\spsnzersvc.exe
(spsnzersvc.exe ->) () [Access Denied] C:\Users\TheVe\AppData\Local\wdkmbcg\wdkmbcg.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_3.1.55.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.580_none_ead976921d8220dc\TiWorker.exe
(svchost.exe ->) (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.42.60.0_x64__kzf8qxf38zg5c\SkypeApp.exe <2>
(svchost.exe ->) (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.42.60.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe <2>
(winlogon.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LogonUI.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [picon] => C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [796696 2009-07-24] (Intel Corporation -> Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-03-24] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.) [File not signed]
HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [131360 2018-01-17] (Intel(R) Driver & Support Assistant -> Intel)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [76600 2019-03-09] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) [File not signed]
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-10-25] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2010-10-25] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [821144 2010-10-25] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\Run: [com.squirrel.splice.Splice] => C:\Users\TheVe\AppData\Local\splice\app-3.3.109793\Splice.exe (No File)
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\Run: [Browser Manager] => C:\Users\TheVe\AppData\Local\Yandex\BrowserManager\MBLauncher.exe (No File)
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\Run: [MP3 Skype recorder] => C:\Users\TheVe\AppData\Local\MP3 Skype recorder\MP3SkypeRecorder.exe [3880584 2018-11-11] (DOMIT LIMITED -> Domit UK LTD)
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\Run: [GoogleChromeAutoLaunch_C4EF761CAF8184320C85D0131A064097] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [2673480 2022-07-01] (Google LLC -> Google LLC)
HKU\S-1-5-21-3999933350-674082219-2972644759-1001\...\MountPoints2: {6cae8016-6a0c-11e9-8827-0050b6294e10} - "F:\MfeEERM.exe"
HKU\S-1-5-21-3999933350-674082219-2972644759-1002\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\temp.fix\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-3999933350-674082219-2972644759-1002\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\temp.fix\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [53656 2010-10-25] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\...\Print\Monitors\IppMon: C:\WINDOWS\system32\IPPMon.dll [251392 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\103.0.5060.114\Installer\chrmstp.exe [2022-07-07] (Google LLC -> Google LLC)
Startup: C:\Users\TheVe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EOS Utility.lnk [2018-01-28]
ShortcutTarget: EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon Inc. -> Canon INC.)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {00ADCC9D-F367-488C-ACFF-7AD89E3C1236} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0C02645C-34C1-4AFF-894F-0EB347BDF67B} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [887152 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0EAE4EF2-C8D0-4E1C-BA7C-324099D4BCAD} - System32\Tasks\Red Giant Link => C:\Program Files\Red Giant Link\Red Giant Link.exe --silent (No File)
Task: {1BAD968B-ADC1-4484-A863-B2A06EAFE2F3} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23378880 2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {231268DA-C332-4852-9926-BAFDEBAAB7FC} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3560304 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {289FAC5C-A456-425D-9877-8A3A4EF2B0B4} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [786800 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {3C3B1D1A-7930-45F4-AF52-29CB173E0C97} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {405D6045-7143-4BE5-97EE-F7D0352A2C87} - System32\Tasks\categorizations exasperated relishing => C:\Users\TheVe\AppData\Local\Antigens.exe oklavwoklavwoklavwoklav.oklavkoklavnoklavmoklav.oklavpoklavwoklav/oklavg2rm0rm1rmoklav9rm0zn4zn2oklavg3grmhtmlroklavuT6gmnRGUFoklavyXjvAeYnK (No File)
Task: {572F0843-E2DF-4F65-8616-0278EA00AFE0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-01-26] (Google Inc -> Google Inc.)
Task: {5CB93FB4-EF3B-4B2C-BD29-1E81715BFE69} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [275136 2022-01-31] (Bluestack Systems, Inc -> BlueStack Systems, Inc.)
Task: {60DA993F-7DA0-4198-84B6-59987281D6AC} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [786800 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {6321E5BE-09B8-4234-996E-A28BBAE5AF56} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {67162561-8F50-4C28-9AA0-2327EF46EA96} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [887152 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6FFB5A39-DF90-4F51-821C-773F98FF1AE9} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {77E46CF6-4F8F-4D7E-A3AF-C93242C36133} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {793B7B22-EA3A-4010-8789-DB8E9801C23D} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [1003888 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {799EDE7A-1487-41C3-A300-B3D44D41A7EC} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [887152 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8012F695-FA52-47B6-95D5-3FB8261052E6} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [562544 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {85B15520-C670-407E-8397-57FAB64CFE94} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23378880 2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {9BC64336-A8E1-4B80-9704-560E560103E1} - System32\Tasks\categorizations exasperated relishingcategorizations exasperated relishing => C:\Users\TheVe\AppData\Local\Antigens.exe oklavwoklavwoklavwoklav.oklavkoklavnoklavmoklav.oklavpoklavwoklav/oklavg2rm0rm1rmoklav9rm0zn4zn2oklavg3grmhtmlroklavuT6gmnRGUFoklavyXjvAeYnK (No File)
Task: {A1A3D805-19B0-453D-983B-BCE709E9EF50} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [855408 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A30A24E9-B197-467B-A1FD-7E3262117A46} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116656 2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {A6F81679-D86A-4D96-9E47-C5E6FFF20F6D} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {AA017D50-057E-4683-940B-F79DBF9A27BB} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {AA797A31-5155-491F-A119-4A294BC4B676} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [855408 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AE888DB4-C560-4D6A-ABC9-ED569DB35432} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B60F94EF-967B-4F92-89F7-DFA38E4268F7} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [887152 2018-11-16] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D88B52CD-F1A8-4413-B610-EE2D2B5548B8} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2250576 2022-05-24] (Avast Software s.r.o. -> Avast Software)
Task: {E0243755-C9B2-4D4E-9D7E-FE9CFA0B86C9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-01-26] (Google Inc -> Google Inc.)
Task: {E2158A77-C3D3-4EB4-8BDC-390BEA3340FE} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {E5CCEF5F-F876-475E-9271-80701F601FCA} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {F2D357E0-2829-4406-BA91-95667E031E16} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116656 2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 208.59.247.45 208.59.247.46
Tcpip\..\Interfaces\{665f913f-0411-4e38-b250-529f0438f3e7}: [DhcpNameServer] 208.59.247.45 208.59.247.46
Tcpip\..\Interfaces\{d99ff61f-598e-4809-921f-9121ab7cc41e}: [DhcpNameServer] 208.59.247.45 208.59.247.46
Edge:
=======
Edge HomeButtonPage: HKU\S-1-5-21-3999933350-674082219-2972644759-1001 -> hxxps://www.yandex.ru/?win=362&clid=2255618
FireFox:
========
FF DefaultProfile: nahd6ha2.default
FF ProfilePath: C:\Users\TheVe\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default [2022-07-17]
FF NewTabOverride: Mozilla\Firefox\Profiles\nahd6ha2.default -> Disabled: vb@yandex.ru
FF Extension: (Visual Bookmarks) - C:\Users\TheVe\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\vb@yandex.ru.xpi [2022-06-21]
FF SearchPlugin: C:\Users\TheVe\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\yandex.ru-20182703.xml [2018-12-03]
FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
FF Extension: (Adobe Contribute Toolbar) - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2019-05-19] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2019-06-06] [Legacy] [not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-03-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-03-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default [2022-07-17]
CHR Notifications: Default -> hxxps://go.proctoru.com; hxxps://slimsk.pro; hxxps://www.facebook.com; hxxps://www.tiktok.com
CHR Extension: (Privacy Pass) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhmfdgkijocedmfjonnpjfojldioehi [2022-06-21]
CHR Extension: (Chrome IG Story) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\bojgejgifofondahckoaahkilneffhmf [2019-02-13]
CHR Extension: (DownAlbum) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgjnhhjpfcdhbhlcmmjppicjmgfkppok [2022-07-04]
CHR Extension: (Video Downloader professional) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2022-06-22]
CHR Extension: (Google Docs Offline) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-06-18]
CHR Extension: (Google Play Books) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2018-02-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-03-03]
CHR Extension: (Vimeo Downloader Professional) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocaallccmjamifmbnammngacjphelonn [2020-03-07]
CHR Extension: (vidIQ Vision for YouTube) - C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pachckjkecffpdphbpmfolblodfkgbhl [2022-07-17]
CHR Profile: C:\Users\TheVe\AppData\Local\Google\Chrome\User Data\System Profile [2018-01-28]
CHR HKLM-x32\...\Chrome\Extension: [gndelhfhcfbdhndfpcinebijfcjpmpec]
Yandex:
=======
YAN Profile: C:\Users\TheVe\AppData\Local\Yandex\YandexBrowser\User Data\Default [2018-12-03]
YAN Extension: (Rating Program Extension - Cloud) - C:\Users\TheVe\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\aeblbnaefoaakjgpedmjbogemoegfdfm [2018-12-03]
YAN Extension: (Chrome IG Story) - C:\Users\TheVe\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\bojgejgifofondahckoaahkilneffhmf [2018-12-03]
YAN Extension: (vidIQ Vision for YouTube) - C:\Users\TheVe\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\pachckjkecffpdphbpmfolblodfkgbhl [2018-12-03]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"ixdog" => service could not be unlocked. <==== ATTENTION
HKLM\SYSTEM\ControlSet001\Services\ixdog => C:\WINDOWS\System32\drivers\ianruybe.sys [145744 2022-06-24] (Access Denied) [File not signed] <==== ATTENTION (Rootkit!/Locked Service)
"MBAMInstallerService" => service could not be unlocked. <==== ATTENTION
HKLM\SYSTEM\ControlSet001\Services\MBAMInstallerService => C:\Users\TheVe\AppData\Local\Temp\MBAMInstallerService.exe [8693208 2022-07-17] (Malwarebytes Inc. -> Malwarebytes) <==== ATTENTION (Rootkit!/Locked Service)
"MBAMWebProtection" => service could not be unlocked. <==== ATTENTION
HKLM\SYSTEM\ControlSet001\Services\MBAMWebProtection => \SystemRoot\system32\DRIVERS\mwac.sys <==== ATTENTION (Rootkit!/Locked Service)
R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12111264 2022-07-09] (Microsoft Corporation -> Microsoft Corporation)
R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [22304 2018-01-17] (Intel(R) Driver & Support Assistant -> Intel)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [775296 2018-04-26] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 KinoniSvc; C:\Program Files (x86)\Kinoni\EpocCam_and_Barcode_drivers\KinoniSvc.exe [525312 2013-02-26] () [File not signed]
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-05-22] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
R2 Synchro Arts License Manager; C:\Program Files (x86)\Common Files\Synchro Arts Shared\License.exe [175488 2008-02-22] (Synchro Arts Ltd -> Synchro Arts Ltd) [File not signed]
R2 UNS; C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2066968 2009-07-24] (Intel Corporation -> Intel Corporation)
S2 gramblrclient; C:\Program Files\Gramblr\gramblr.exe [X]
R2 PaceLicenseDServices; "C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe" -u hxxps://activation.paceap.com/InitiateActivation
S3 WdNisSvc; "%ProgramData%\Microsoft\Windows Defender\platform\4.18.1909.6-0\NisSrv.exe" [X]
S2 WinDefend; "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MsMpEng.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [357768 2018-08-22] (Bitdefender SRL -> Bitdefender)
S3 edrsensor; C:\WINDOWS\System32\DRIVERS\edrsensor.sys [294000 2018-10-09] (Bitdefender SRL -> BitDefender S.R.L. Bucharest, ROMANIA)
R3 KINONI_Wave; C:\WINDOWS\system32\drivers\kinonivad.sys [32360 2016-04-17] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 LoopBeMidi1; C:\WINDOWS\system32\drivers\loopbe1.sys [13824 2011-04-09] (nerds.de) [File not signed]
S4 lzrutis; C:\WINDOWS\System32\drivers\vdrcuspz.sys [148816 2019-04-23] () [File not signed]
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-22] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 VBAudioVMVAIOMME; C:\WINDOWS\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [41192 2017-06-30] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46472 2019-10-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [351968 2019-10-30] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2019-10-30] (Microsoft Windows -> Microsoft Corporation)
S3 BstkDrv; \??\C:\Program Files (x86)\BlueStacks\BstkDrv.sys [X]
S3 cpuz148; \??\C:\WINDOWS\temp\cpuz148\cpuz148_x64.sys [X]
R3 mpswzc; system32\drivers\svzcfj.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-07-17 06:05 - 2022-07-17 06:11 - 000054253 _____ C:\Users\TheVe\Desktop\Addition.txt
2022-07-17 06:02 - 2022-07-17 06:16 - 000028807 _____ C:\Users\TheVe\Desktop\FRST.txt
2022-07-17 05:54 - 2022-07-17 06:16 - 000000000 ____D C:\FRST
2022-07-17 05:52 - 2022-07-17 05:52 - 002369536 _____ (Farbar) C:\Users\TheVe\Desktop\FRST64.exe
2022-07-17 05:41 - 2022-07-17 05:43 - 000004974 _____ C:\Users\TheVe\Downloads\.6efeab48d0425dd4637604354adea9c6476d2ade.parts
2022-07-17 05:37 - 2022-07-17 05:37 - 000011379 _____ C:\Users\TheVe\Downloads\[audionews.org].t334847.torrent
2022-07-17 05:37 - 2022-07-17 05:37 - 000000000 ____D C:\Users\TheVe\Downloads\Adobe.Animate.2022.v22.0.6.202.x64.WIN
2022-07-17 05:13 - 2022-07-17 05:13 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3999933350-674082219-2972644759-1002
2022-07-17 05:13 - 2022-07-17 05:13 - 000003384 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3999933350-674082219-2972644759-1002
2022-07-17 05:12 - 2022-07-17 05:13 - 000002770 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task v2
2022-07-17 05:10 - 2022-07-17 05:10 - 000000000 ____D C:\Users\temp.fix\ansel
2022-07-17 05:07 - 2022-07-17 05:07 - 000001417 _____ C:\Users\temp.fix\Desktop\Microsoft Edge.lnk
2022-07-17 05:07 - 2022-07-17 05:07 - 000000000 ___HD C:\Users\temp.fix\MicrosoftEdgeBackups
2022-07-17 05:07 - 2022-07-17 05:07 - 000000000 ____D C:\Users\temp.fix\AppData\Local\MicrosoftEdge
2022-07-17 05:07 - 2022-07-17 05:07 - 000000000 ____D C:\Users\temp.fix\AppData\Local\CEF
2022-07-17 05:06 - 2022-07-17 05:08 - 000000000 ____D C:\Users\temp.fix\AppData\Local\NVIDIA Corporation
2022-07-17 05:06 - 2022-07-17 05:06 - 000000000 ___RD C:\Users\temp.fix\3D Objects
2022-07-17 05:06 - 2022-07-17 05:06 - 000000000 ____D C:\Users\temp.fix\AppData\Local\VirtualStore
2022-07-17 05:06 - 2022-07-17 05:06 - 000000000 ____D C:\Users\temp.fix\AppData\Local\NVIDIA
2022-07-17 05:06 - 2022-07-17 05:06 - 000000000 ____D C:\Users\temp.fix\AppData\Local\Google
2022-07-17 05:05 - 2022-07-17 05:36 - 000000000 ____D C:\Users\temp.fix\AppData\Local\Packages
2022-07-17 05:05 - 2022-07-17 05:13 - 000002379 _____ C:\Users\temp.fix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-07-17 05:05 - 2022-07-17 05:12 - 000000000 ___RD C:\Users\temp.fix\OneDrive
2022-07-17 05:05 - 2022-07-17 05:10 - 000000000 ____D C:\Users\temp.fix
2022-07-17 05:05 - 2022-07-17 05:08 - 000000000 ____D C:\Users\temp.fix\AppData\Local\ConnectedDevicesPlatform
2022-07-17 05:05 - 2022-07-17 05:05 - 000000020 ___SH C:\Users\temp.fix\ntuser.ini
2022-07-17 05:05 - 2018-01-26 12:01 - 000000000 ____D C:\Users\temp.fix\AppData\Roaming\Adobe
2022-07-17 05:05 - 2018-01-26 12:01 - 000000000 ____D C:\Users\temp.fix\AppData\Local\TileDataLayer
2022-07-17 05:05 - 2018-01-26 12:01 - 000000000 ____D C:\Users\temp.fix\AppData\Local\Publishers
2022-07-17 05:05 - 2018-01-26 12:01 - 000000000 ____D C:\Users\temp.fix\AppData\Local\Comms
2022-07-17 05:05 - 2016-09-02 11:32 - 000000319 _____ C:\Users\temp.fix\Desktop\Get Office 365 Personal.url
2022-07-17 05:05 - 2016-09-02 11:31 - 000000194 _____ C:\Users\temp.fix\Desktop\Get Office 365 Home.url
2022-07-17 05:05 - 2016-08-31 16:58 - 000000154 _____ C:\Users\temp.fix\Desktop\Microsoft Store.url
2022-07-17 03:53 - 2022-07-17 04:11 - 000000000 ____D C:\Users\TheVe\Downloads\Adobe.Animate.2022.v22.0.7.214.x64.WIN
2022-07-17 03:52 - 2022-07-17 03:52 - 000011379 _____ C:\Users\TheVe\Downloads\[audionews.org].t339695.torrent
2022-07-10 23:19 - 2022-07-10 23:19 - 001232282 _____ C:\Users\TheVe\Downloads\Blank.zip
2022-07-05 11:59 - 2022-07-05 11:59 - 000000000 ____D C:\Users\TheVe\AppData\Local\aundsgb
2022-07-02 00:29 - 2022-07-02 00:29 - 000000000 _____ C:\Users\TheVe\Downloads\download
2022-06-30 08:34 - 2022-07-17 03:25 - 000000170 _____ C:\WINDOWS\wininit.ini
2022-06-30 04:43 - 2022-06-30 04:43 - 000800839 _____ C:\Users\TheVe\Downloads\Bluster.zip
2022-06-28 04:56 - 2022-06-28 04:58 - 1367096420 _____ C:\Users\TheVe\Downloads\Adobe Flash Pro CS6.exe
2022-06-28 04:46 - 2022-06-28 04:47 - 130656256 _____ C:\Users\TheVe\Downloads\Searching for_ adobe animate in_.iso
2022-06-28 04:45 - 2022-06-28 04:45 - 130656256 _____ C:\Users\TheVe\Downloads\Adobe Animate CC 2017 v16.0.1 (x64) + Crack [Sa....iso
2022-06-24 05:22 - 2022-06-24 05:22 - 000000000 ____D C:\Users\TheVe\AppData\Local\pwhvnux
2022-06-24 05:18 - 2022-06-24 05:18 - 000145744 ____N C:\WINDOWS\system32\Drivers\ianruybe.sys
2022-06-21 09:36 - 2022-06-21 09:36 - 000005473 _____ C:\Users\TheVe\Downloads\index(1).m3u8
2022-06-21 09:36 - 2022-06-21 09:36 - 000005445 _____ C:\Users\TheVe\Downloads\index.m3u8
2022-06-21 09:26 - 2022-06-21 09:26 - 000104140 _____ C:\Users\TheVe\Downloads\NEWDAYLYTvideoplayback.mp4
2022-06-21 09:19 - 2022-06-21 09:20 - 000211848 _____ C:\Users\TheVe\Downloads\DAYLYT “ Battlr rap talk ! Matches I want to seeee.mp4
2022-06-21 09:18 - 2022-06-21 09:19 - 001291014 _____ C:\Users\TheVe\Downloads\DAYLYTvideoplayback.mp4
2022-06-21 08:48 - 2022-07-17 05:52 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-06-21 08:48 - 2022-07-17 03:25 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-06-21 07:33 - 2022-06-24 05:15 - 000000000 ____D C:\Users\TheVe\Desktop\battle life
2022-06-19 07:17 - 2022-06-19 07:17 - 000000000 ____D C:\ProgramData\obs-studio-hook
2022-06-19 05:13 - 2022-06-19 05:13 - 000000798 _____ C:\Users\TheVe\Downloads\init-stream_0.m4s.mp4.mp4
2022-06-18 00:42 - 2022-06-18 00:42 - 000000000 ____D C:\Users\TheVe\AppData\Local\snbdpxc
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-07-17 06:11 - 2018-04-11 19:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-07-17 06:08 - 2018-04-11 19:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-07-17 06:05 - 2018-02-08 18:55 - 000000000 ____D C:\Users\TheVe\AppData\Roaming\qBittorrent
2022-07-17 05:54 - 2018-01-26 12:09 - 000000000 ____D C:\Program Files (x86)\Google
2022-07-17 05:51 - 2019-04-27 20:20 - 000000000 ____D C:\Users\TheVe\AppData\LocalLow\Mozilla
2022-07-17 05:39 - 2019-04-23 22:47 - 000000000 ____D C:\Users\TheVe\AppData\Local\wdkmbcg
2022-07-17 05:36 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-07-17 05:35 - 2018-06-22 18:29 - 000000000 ____D C:\ProgramData\Packages
2022-07-17 05:34 - 2018-04-11 19:38 - 000000000 ___HD C:\Program Files\WindowsApps
2022-07-17 05:11 - 2018-04-12 16:09 - 000000000 ____D C:\ProgramData\NVIDIA
2022-07-17 05:06 - 2016-11-20 14:51 - 000000000 __RHD C:\Users\Public\AccountPictures
2022-07-17 04:30 - 2018-04-16 12:59 - 000000000 ____D C:\Users\TheVe\AppData\Local\CrashDumps
2022-07-17 04:18 - 2018-08-14 12:56 - 000000000 ____D C:\Users\TheVe\AppData\Local\D3DSCache
2022-07-17 04:16 - 2018-02-17 21:04 - 000000000 ____D C:\ProgramData\Package Cache
2022-07-17 04:12 - 2018-01-28 18:41 - 000000000 ____D C:\Users\TheVe\AppData\Local\Adobe
2022-07-17 04:12 - 2018-01-28 18:41 - 000000000 ____D C:\ProgramData\Adobe
2022-07-17 03:25 - 2019-04-27 20:20 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-07-17 03:25 - 2019-04-27 20:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-07-17 02:32 - 2018-05-22 18:54 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-07-15 22:19 - 2018-05-22 19:13 - 000838560 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-07-15 22:19 - 2018-04-11 19:36 - 000000000 ____D C:\WINDOWS\INF
2022-07-14 07:41 - 2022-02-14 11:30 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3999933350-674082219-2972644759-1001
2022-07-14 07:41 - 2018-05-22 19:15 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3999933350-674082219-2972644759-1001
2022-07-14 07:41 - 2018-05-22 19:00 - 000002386 _____ C:\Users\TheVe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-07-13 07:38 - 2019-06-11 00:17 - 000000132 _____ C:\Users\TheVe\AppData\Roaming\Adobe PNG Format CS5 Prefs
2022-07-09 03:11 - 2017-01-11 15:52 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2022-07-07 10:55 - 2018-01-26 12:10 - 000002338 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-07-07 10:55 - 2018-01-26 12:10 - 000002297 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-07-06 05:35 - 2018-01-26 23:45 - 000000000 ____D C:\Users\TheVe\AppData\Roaming\vlc
2022-07-05 11:55 - 2018-05-22 19:15 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-07-05 11:54 - 2019-04-23 21:56 - 002930176 _____ (TOSHIBA CORPORATION) C:\WINDOWS\system32\spsnzersvc.exe
2022-06-30 08:54 - 2018-05-22 19:00 - 000000000 ____D C:\Users\TheVe\AppData\Local\Packages
2022-06-29 08:15 - 2022-02-14 03:49 - 000000000 ____D C:\Users\TheVe\AppData\Local\ElevatedDiagnostics
2022-06-24 05:19 - 2018-04-11 17:04 - 018612224 _____ C:\WINDOWS\system32\config\HARDWARE
2022-06-24 05:19 - 2018-04-11 17:04 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2022-06-21 09:35 - 2018-01-26 13:59 - 000001146 _____ C:\Users\Public\Desktop\VLC media player.lnk
2022-06-21 08:48 - 2019-04-27 20:20 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-06-19 10:59 - 2018-01-26 14:30 - 000000000 ____D C:\Users\TheVe\AppData\Roaming\obs-studio
==================== Files in the root of some directories ========
2018-12-03 16:23 - 2018-12-03 16:24 - 000137168 _____ (Mozilla Foundation) C:\ProgramData\mozglue.dll
2018-12-03 16:23 - 2018-12-03 16:24 - 001246160 _____ (Mozilla Foundation) C:\ProgramData\nss3.dll
2018-08-09 16:03 - 2018-09-17 18:03 - 002722286 _____ () C:\Program Files (x86)\Auto-Tune 8 Manual.pdf
2018-08-09 16:03 - 2018-09-17 18:03 - 000056051 _____ () C:\Program Files (x86)\VST PC Read Me.pdf
2019-06-11 00:16 - 2019-06-12 10:41 - 000000132 _____ () C:\Users\TheVe\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
2019-06-11 00:17 - 2022-07-13 07:38 - 000000132 _____ () C:\Users\TheVe\AppData\Roaming\Adobe PNG Format CS5 Prefs
2018-03-10 17:10 - 2020-11-21 19:35 - 000000032 _____ () C:\Users\TheVe\AppData\Roaming\msregsvv.dll
2018-02-18 15:51 - 2022-02-19 11:25 - 000002824 _____ () C:\Users\TheVe\AppData\Roaming\VoiceMeeterDefault.xml
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_essentials.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_mixbus3.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000109 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_mixbus32c-4.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000107 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_mixbus32c.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_mixbus4.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_bc3.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_ds.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_eg.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_eq.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000107 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_lc.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_mc.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_me.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000107 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_sc.txt
2018-01-26 14:23 - 2018-01-26 14:23 - 000000106 _____ () C:\Users\TheVe\AppData\Local\license_key_harrison_xt_tg.txt
2020-10-16 15:27 - 2020-10-16 15:27 - 000000787 _____ () C:\Users\TheVe\AppData\Local\recently-used.xbel
==================== FLock ==============================
2019-04-23 21:56 C:\WINDOWS\system32\zacldsw
2022-07-05 11:54 C:\WINDOWS\system32\config\SYSTEM
2022-06-24 05:18 C:\WINDOWS\system32\Drivers\ianruybe.sys
2018-12-03 23:25 C:\Users\TheVe\AppData\Roaming\wow64_microsoft-windows-I..lprovider.resources_31bf3856ad364e35_6.1.7600.16385_ru-ru_4025bb8924a11670
2022-07-17 05:39 C:\Users\TheVe\AppData\Local\wdkmbcg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================