@Broni
please check Scan result of Farbar Recovery Scan Tool
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by #root (administrator) on ROOT (22-06-2018 15:56:36)
Running from C:\Users\RIYAS\Desktop\New folder (2)\FRST-OlderVersion\FRST-OlderVersion
Loaded Profiles: #root (Available Profiles: #root & Administrator & Guest)
Platform: Windows 7 Professional (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(ESET) C:\Program Files\ESET\ESET Security\egui.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\nvapiw.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\RIYAS\Desktop\New folder (2)\FRST-OlderVersion\FRST-OlderVersion\FRSTEnglish.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\RIYAS\Desktop\New folder (2)\FRST-OlderVersion\FRST-OlderVersion\FRSTEnglish.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [178496 2018-04-19] (ESET)
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\Policies\Explorer: [RestrictRun] 0
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {01f74df5-7d8b-11e7-85bd-645a04bf7d48} - H:\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {01f74e02-7d8b-11e7-85bd-645a04bf7d48} - G:\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {02d7fbc2-28e9-11e8-a325-645a04bf7d48} - G:\Windows\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {02d7fbce-28e9-11e8-a325-645a04bf7d48} - G:\Windows\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {1aa30557-4317-11e8-9c6b-645a04bf7d48} - G:\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {1aa30562-4317-11e8-9c6b-645a04bf7d48} - G:\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {21dd083d-9ad3-11e7-b1ea-645a04bf7d48} - I:\Setup.exe /s
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {34a4ae6a-1543-11e8-b89c-b82a72cbe732} - G:\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {3dbc1f60-07d4-11e8-b377-645a04bf7d48} - G:\.\3G-Connect.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {42d70992-865b-11e7-b7c6-645a04bf7d48} - G:\.\Airtel_4G.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {5df88ca2-e54a-11e7-b29d-645a04bf7d48} - G:\Setup.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {5df88d2f-e54a-11e7-b29d-645a04bf7d48} - G:\Setup.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {8bf175d5-ec9c-11e7-9c03-645a04bf7d48} - I:\HiSuiteDownLoader.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {9296536d-7db4-11e7-864a-645a04bf7d48} - G:\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {9d2a2790-7f31-11e7-9cba-645a04bf7d48} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {b7f4b303-133d-11e8-9350-645a04bf7d48} - G:\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {d94178e9-7dc7-11e7-b485-645a04bf7d48} - G:\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {e14b1898-479e-11e8-bc42-645a04bf7d48} - G:\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {e14b18a3-479e-11e8-bc42-645a04bf7d48} - G:\AutoRun.exe
HKU\S-1-5-21-570170127-3439773959-704584474-1000\...\MountPoints2: {f596b884-d03c-11e7-8c5c-645a04bf7d48} - G:\.\Airtel_4G.exe
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [177952 2016-07-11] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [155768 2016-07-11] (NVIDIA Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\Parameters: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{03C537D5-A4D5-4555-9394-7EC1604B8EBB}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{0DDD04AC-7857-45E9-B8F7-4D85631F0411}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{238FEAC3-AEB6-4D96-B1FE-E91050F7DAC4}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{238FEAC3-AEB6-4D96-B1FE-E91050F7DAC4}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{245C93DB-554F-4F27-8273-577C237EDEE7}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{245C93DB-554F-4F27-8273-577C237EDEE7}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{3C18D9E3-1C04-418E-9263-6EACA557253C}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{3C18D9E3-1C04-418E-9263-6EACA557253C}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{68FE99FC-C7EE-4B6F-8E7B-1DCCB7593CD4}: [NameServer] 8.8.8.8
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-570170127-3439773959-704584474-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://
www.msn.com/en-in/?ocid=iehp
HKU\S-1-5-21-570170127-3439773959-704584474-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://
www.google.com/ie
HKU\S-1-5-21-570170127-3439773959-704584474-1000\Software\Microsoft\Internet Explorer\Main,Start Page =
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-570170127-3439773959-704584474-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-570170127-3439773959-704584474-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-570170127-3439773959-704584474-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://
www.google.com/search?q={sear
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_161\bin\ssv.dll [2018-03-15] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-03-15] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM-x32 - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: 23ofghs6.default
FF ProfilePath: C:\Users\RIYAS\AppData\Roaming\Mozilla\Firefox\Profiles\23ofghs6.default [2018-06-21]
FF Homepage: Mozilla\Firefox\Profiles\23ofghs6.default -> hxxps://in.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10454__180604__yaff
FF NewTab: Mozilla\Firefox\Profiles\23ofghs6.default -> hxxps://in.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10454__180604__yaff
FF SearchPlugin: C:\Users\RIYAS\AppData\Roaming\Mozilla\Firefox\Profiles\23ofghs6.default\searchplugins\yahoo-lavasoft-ff59.xml [2018-06-05]
FF HKLM-x32\...\Firefox\Extensions: [daplinkchecker@speedbit.com] - C:\Program Files (x86)\DAP\daplinkchecker => not found
FF Plugin: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-03-15] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-03-15] (Oracle Corporation)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-08-01] (Google, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-12-21] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
CHR Profile: C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default [2018-06-22]
CHR Extension: (Slides) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14]
CHR Extension: (Docs) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Google Drive) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-17]
CHR Extension: (Touch VPN) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\bihmplhobchoageeokmgbdihknkjbknd [2018-06-19]
CHR Extension: (YouTube) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-17]
CHR Extension: (Sheets) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14]
CHR Extension: (Google Docs Offline) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-08-17]
CHR Extension: (160by2) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieodemnbjjlohmojcimkdpmdfjcihehg [2018-06-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (Speedtest by Ookla) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjjikdiikihdfpoppgaidccahalehjh [2018-06-03]
CHR Extension: (Gmail) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-17]
CHR Extension: (Chrome Media Router) - C:\Users\RIYAS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-19]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKLM\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-570170127-3439773959-704584474-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ffdcfjdljhbehggjdkdioajnknjcpbjb] - C:\Program Files (x86)\DAP\DAPChrome\DAPChrome6.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] - hxxps://clients2.google.com/service/update2/crx
Opera:
=======
OPR Extension: (Download with Download Accelerator Plus (DAP)) - C:\Users\RIYAS\AppData\Roaming\Opera Software\Opera Stable\Extensions\ekeecmblpnobdaijmfkcfcnofopooipg [2018-03-15]
StartMenuInternet: (HKLM) OperaStable - C:\Users\RIYAS\AppData\Local\Programs\Opera\Launcher.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [1810120 2018-02-15] ()
S4 CG6Service; C:\Program Files\CyberGhost 6\CyberGhost.Service.exe [239184 2018-05-14] (CyberGhost S.A.)
S3 Change Modem Device Service; C:\Windows\SysWOW64\ChgService.exe [135168 2015-10-09] () [File not signed]
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [208792 2017-12-14] (Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3294608 2017-12-14] (Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217488 2017-12-14] (Dell Inc.)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2240264 2018-04-19] (ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2240264 2018-04-19] (ESET)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344184 2016-04-05] (Intel Corporation)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [382456 2016-04-01] (McAfee, Inc.)
S3 mfevtp; C:\Windows\system32\mfevtps.exe [277744 2016-03-07] (McAfee, Inc.)
R2 PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) [File not signed]
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [41432 2018-02-14] (Dell Inc.)
S3 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10945264 2017-11-24] (TeamViewer GmbH)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 DDDriver; C:\Windows\System32\drivers\DDDriver64Dcsa.sys [41608 2017-12-14] (Dell Inc.)
R3 DellProf; C:\Windows\System32\drivers\DellProf.sys [41208 2017-12-14] (Dell Computer Corporation)
S3 Diag_driver_dev; C:\Windows\System32\DRIVERS\ztetsplog.sys [152848 2017-05-03] ( )
S3 ew_hwusbdev; C:\Windows\System32\DRIVERS\ew_hwusbdev.sys [109568 2013-01-25] (Huawei Technologies Co., Ltd.) [File not signed]
S3 ew_usbenumfilter; C:\Windows\System32\DRIVERS\ew_usbenumfilter.sys [18560 2015-01-07] (Huawei Technologies Co., Ltd.) [File not signed]
S3 hwusb_cdcacm; C:\Windows\System32\DRIVERS\ew_cdcacm.sys [125952 2014-07-25] (Huawei Technologies Co., Ltd.) [File not signed]
S3 hwusb_wwanecm; C:\Windows\System32\DRIVERS\ew_wwanecm.sys [380800 2015-01-07] (Huawei Technologies Co., Ltd.) [File not signed]
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
S3 MEMSWEEP2; C:\Windows\system32\7F1F.tmp [6144 2011-08-25] (Sophos Plc) [File not signed]
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [419624 2016-03-11] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [349480 2016-03-11] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [842536 2016-03-11] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [243496 2016-03-11] (McAfee, Inc.)
S3 Modem_driver_d; C:\Windows\System32\DRIVERS\Modem_driver_d.sys [387416 2016-12-06] ( )
S3 Nmea_driver_dev; C:\Windows\System32\DRIVERS\ztetspnmea.sys [396176 2017-05-03] ( )
R3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [416472 2016-05-17] (Realsil Semiconductor Corporation)
S1 SAVRKBootTasks; C:\Windows\SysWOW64\SAVRKBootTasks.sys [18816 2011-08-25] (Sophos Group) [File not signed]
S3 Updt_driver_dev; C:\Windows\System32\DRIVERS\Updt_driver_dev.sys [396176 2017-05-03] ( )
S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [159936 2016-08-16] (MBB)
S3 zteusbfilter1021; C:\Windows\System32\DRIVERS\zteusbfilter1021.sys [57048 2017-03-06] (ZTE Incorporated)
S3 zteusbnetqn4025; C:\Windows\System32\DRIVERS\zteusbnetqn4025.sys [397528 2017-03-06] (ZTE Incorporated)
S3 cmnuusbser14; system32\DRIVERS\cmnuusbser14.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 mmx_cmnxnet; system32\DRIVERS\mmx_cmnxnet.sys [X]
S3 mmx_cmnxusbser; system32\DRIVERS\mmx_cmnxusbser.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
S3 WCDMA_Datacard_Usb_Ser; system32\DRIVERS\WCDMA_Datacard_Usb_Ser.sys [X]
S3 WinRing0_1_2_0; \??\Z:\bin\tools\openhardwaremonitor\OpenHardwareMonitor.sys [X]
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-22 15:54 - 2018-06-22 15:55 - 000041999 _____ C:\Users\RIYAS\Downloads\Addition (1).txt
2018-06-22 15:54 - 2018-06-22 15:54 - 000040387 _____ C:\Users\RIYAS\Downloads\FRST.txt
2018-06-21 22:28 - 2018-06-21 22:28 - 000000043 _____ C:\Users\RIYAS\Downloads\fixlist.txt
2018-06-21 20:55 - 2018-06-21 20:55 - 000000000 ____D C:\Users\RIYAS\AppData\Local\CrashDumps
2018-06-21 20:36 - 2018-06-21 20:37 - 000003164 _____ C:\Users\RIYAS\Desktop\Rkill.txt
2018-06-21 20:31 - 2018-06-21 20:31 - 000441280 _____ C:\Users\RIYAS\Desktop\SysInspector-ROOT-180621-202538.zip
2018-06-21 20:29 - 2018-06-21 20:29 - 002109580 _____ C:\Users\RIYAS\Desktop\SysInspector-ROOT-180621-202538.txt
2018-06-21 20:08 - 2018-06-21 20:10 - 000125399 _____ C:\Users\RIYAS\Downloads\hosts.zip
2018-06-21 18:14 - 2018-06-21 20:33 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2018-06-21 17:16 - 2018-06-21 17:16 - 000000000 ____D C:\Users\RIYAS\AppData\Local\ESET
2018-06-21 15:51 - 2018-06-21 15:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2018-06-21 15:51 - 2018-06-21 15:51 - 000000000 ____D C:\ProgramData\ESET
2018-06-21 15:51 - 2018-06-21 15:51 - 000000000 ____D C:\Program Files\ESET
2018-06-21 15:03 - 2018-06-21 15:09 - 004279416 _____ (ESET) C:\Users\RIYAS\Downloads\eset_nod32_antivirus_live_installer.exe
2018-06-21 14:52 - 2018-06-21 14:52 - 000000000 ____D C:\Windows\System32\Tasks\AVG
2018-06-21 12:45 - 2018-06-21 12:45 - 000255928 _____ (Malwarebytes) C:\Windows\system32\Drivers\5769B3F3.sys
2018-06-21 01:31 - 2018-06-21 01:31 - 000000000 ____D C:\Program Files\Common Files\AVG
2018-06-21 01:29 - 2018-06-21 01:29 - 000000000 ____D C:\ProgramData\RogueKiller
2018-06-21 01:29 - 2018-06-21 01:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-06-21 01:29 - 2018-06-21 01:29 - 000000000 ____D C:\Program Files\RogueKiller
2018-06-21 01:24 - 2018-06-21 01:24 - 000000000 ____D C:\Windows\Trend Micro
2018-06-21 01:24 - 2018-06-21 01:24 - 000000000 ____D C:\ProgramData\Trend Micro
2018-06-21 01:16 - 2018-06-21 20:22 - 000000000 ____D C:\ProgramData\AVG
2018-06-21 01:10 - 2018-06-21 01:10 - 000522825 _____ C:\Users\RIYAS\AppData\Local\census.cache
2018-06-21 01:09 - 2018-06-21 01:09 - 000340588 _____ C:\Users\RIYAS\AppData\Local\ars.cache
2018-06-21 00:19 - 2018-06-21 00:19 - 000000036 _____ C:\Users\RIYAS\AppData\Local\housecall.guid.cache
2018-06-20 23:35 - 2018-06-20 23:35 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-06-20 20:46 - 2011-08-25 09:37 - 000018816 ____N (Sophos Group) C:\Windows\SysWOW64\SAVRKBootTasks.sys
2018-06-20 20:18 - 2011-08-25 09:33 - 000006144 ____N (Sophos Plc) C:\Windows\system32\7F1F.tmp
2018-06-20 20:17 - 2011-08-25 09:33 - 000006144 ____N (Sophos Plc) C:\Windows\system32\D43F.tmp
2018-06-20 20:16 - 2018-06-20 20:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2018-06-20 20:16 - 2018-06-20 20:16 - 000000000 ____D C:\Program Files (x86)\Sophos
2018-06-19 23:43 - 2018-06-19 23:43 - 000000000 ____H C:\Users\RIYAS\AppData\Local\BIT7423.tmp
2018-06-19 23:43 - 2018-06-19 23:43 - 000000000 _____ C:\Users\RIYAS\AppData\Local\{72368EF5-ACDD-465C-A3B8-0A2C6CA10BFD}
2018-06-19 16:49 - 2018-06-20 19:37 - 000000000 ____D C:\ProgramData\MB3Install
2018-06-19 16:37 - 2018-06-19 16:49 - 078101496 _____ (Malwarebytes ) C:\Windows\SysWOW64\mb-setup.exe
2018-06-19 16:30 - 2018-06-21 22:32 - 002413568 _____ (Farbar) C:\Users\RIYAS\Downloads\FRSTEnglish.exe
2018-06-19 14:50 - 2018-06-19 14:57 - 017583333 _____ C:\Users\RIYAS\Downloads\mbar-1.10.3.1001.zip
2018-06-19 14:32 - 2018-06-19 14:32 - 000025566 _____ C:\ProgramData\agent.uninstall.1529398959.bdinstall.bin
2018-06-19 14:26 - 2018-06-19 14:39 - 035086936 _____ (Malwarebytes ) C:\Users\RIYAS\Downloads\Unconfirmed 724565.crdownload
2018-06-19 14:24 - 2018-06-19 14:24 - 000001644 _____ C:\Users\RIYAS\Downloads\mb-clean-results.txt
2018-06-19 13:41 - 2018-06-19 13:41 - 000085600 ____N (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\02111698.sys
2018-06-19 03:47 - 2018-06-19 03:47 - 000042582 _____ C:\ProgramData\agent.1529360227.bdinstall.bin
2018-06-19 03:29 - 2018-06-19 03:29 - 000000926 _____ C:\Users\RIYAS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-06-19 03:29 - 2018-06-19 03:29 - 000000926 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-06-19 03:29 - 2018-06-19 03:29 - 000000896 _____ C:\Users\RIYAS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2018-06-19 03:29 - 2018-06-19 03:29 - 000000896 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2018-06-19 03:02 - 2018-06-19 03:04 - 000211570 _____ C:\TDSSKiller.3.1.0.17_19.06.2018_03.02.50_log.txt
2018-06-19 02:33 - 2018-06-19 02:35 - 000210908 _____ C:\TDSSKiller.3.1.0.17_19.06.2018_02.33.54_log.txt
2018-06-19 02:26 - 2018-06-21 22:32 - 000000000 ____D C:\Users\RIYAS\Desktop\New folder (2)
2018-06-19 01:49 - 2018-06-19 01:49 - 000052320 ____N (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\35199727.sys
2018-06-19 01:09 - 2018-06-19 01:10 - 000000000 ____D C:\KVRT_Data
2018-06-19 00:06 - 2018-06-19 03:26 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-06-19 00:05 - 2018-06-19 03:26 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-06-18 23:05 - 2018-06-18 23:05 - 000000000 ____D C:\Users\RIYAS\Downloads\E3372h-607_Update_22.200.05.00.00_universal
2018-06-18 22:33 - 2018-06-18 22:33 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2018-06-18 22:11 - 2018-06-18 22:11 - 000000000 ____D C:\ProgramData\MB2Migration
2018-06-18 21:55 - 2018-06-22 15:56 - 000000000 ____D C:\FRST
2018-06-18 21:50 - 2018-06-18 21:51 - 000000000 ____D C:\AdwCleaner
2018-06-18 17:24 - 2018-06-18 17:24 - 000000000 ____D C:\Users\RIYAS\Downloads\mbam-chameleon-3.1.33.0
2018-06-14 20:27 - 2018-06-14 20:27 - 000093816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-06-14 20:27 - 2018-06-14 20:27 - 000044768 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-06-14 20:15 - 2018-06-14 20:15 - 000923537 _____ C:\Users\RIYAS\Downloads\Turn Off IDM Auto-Update Notification - My PC Tips.pdf
2018-06-14 19:39 - 2018-06-21 01:11 - 000477682 _____ C:\Users\RIYAS\Desktop\n hosts.txt
2018-06-14 05:29 - 2018-06-14 05:29 - 000000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-06-14 05:29 - 2018-06-14 05:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-06-08 17:44 - 2018-06-09 14:49 - 000003506 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-570170127-3439773959-704584474-1000UA
2018-06-08 17:44 - 2018-06-09 14:49 - 000003234 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-570170127-3439773959-704584474-1000Core
2018-06-08 17:42 - 2018-06-21 22:10 - 000000000 ____D C:\Users\RIYAS\Desktop\New folder
2018-06-07 16:48 - 2018-06-10 09:46 - 008441460 _____ C:\Users\RIYAS\Documents\FIELD WORK PRESENTATION.pptx
2018-06-05 11:56 - 2018-06-05 11:56 - 000016640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-06-05 01:13 - 2018-06-05 01:13 - 000000000 ____D C:\Windows\System32\Tasks\Avast Software
2018-06-05 01:11 - 2018-06-05 01:11 - 000000000 ____D C:\Program Files\Common Files\AVAST Software
2018-06-05 01:04 - 2018-06-21 20:42 - 000000000 ____D C:\Users\RIYAS\AppData\Roaming\uTorrent
2018-06-05 01:04 - 2018-06-05 01:04 - 000000847 _____ C:\Users\RIYAS\Desktop\µTorrent.lnk
2018-06-05 01:01 - 2018-06-21 21:26 - 000000000 ____D C:\Users\RIYAS\Downloads\uTorrent Pro 3.5.3 Build 44396 Full Crack CracksNow_
2018-06-05 01:01 - 2018-06-05 00:51 - 029739790 _____ C:\Users\RIYAS\Downloads\uTorrent Pro 3.5.3 Build 44396 Full Crack CracksNow .zip
2018-06-05 00:56 - 2018-06-21 22:56 - 000004128 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-06-05 00:56 - 2018-06-05 00:56 - 000002782 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2018-06-05 00:56 - 2018-06-05 00:56 - 000000000 ____D C:\Program Files\CCleaner
2018-06-05 00:49 - 2018-06-21 21:26 - 000000000 ____D C:\Users\RIYAS\Downloads\CCleaner (All Editions) 5.41.6446 Crack CracksNow_
2018-06-05 00:48 - 2018-06-05 00:48 - 000002071 _____ C:\Users\RIYAS\Downloads\read me.txt
2018-06-05 00:33 - 2018-06-21 21:26 - 000000000 ____D C:\Users\RIYAS\Downloads\Malwarebytes Premium 3.4.5.2467 Crack CracksNow_
2018-06-05 00:25 - 2018-06-21 21:26 - 000000000 ____D C:\Users\RIYAS\Downloads\Total Uninstall Professional 6.23.0.510 _28x86%29 Crack CracksMind_
2018-06-04 23:49 - 2018-06-04 23:49 - 000000000 ____D C:\Users\RIYAS\AppData\Roaming\Obsidium
2018-06-04 22:23 - 2018-06-04 22:28 - 000000000 ____D C:\Users\RIYAS\AppData\Roaming\Telegram Desktop
2018-06-04 22:23 - 2018-06-04 22:28 - 000000000 ____D C:\Users\RIYAS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop
2018-06-04 13:37 - 2018-06-04 13:37 - 000000000 ____D C:\Users\RIYAS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2018-06-04 13:37 - 2018-06-04 13:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2018-06-04 13:26 - 2018-06-04 13:59 - 000000000 ____D C:\Users\RIYAS\AppData\Local\CyberGhost
2018-06-04 13:25 - 2018-06-04 22:24 - 000000000 ____D C:\Program Files\CyberGhost 6
2018-06-04 13:25 - 2018-06-04 13:25 - 000001728 _____ C:\Users\RIYAS\Desktop\CyberGhost 6.lnk
2018-06-04 13:25 - 2018-06-04 13:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 6
2018-05-27 15:40 - 2015-01-07 17:21 - 000018560 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys
2018-05-27 15:40 - 2015-01-07 17:16 - 000380800 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_wwanecm.sys
2018-05-27 15:40 - 2014-09-11 15:36 - 000457728 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbwwan.sys
2018-05-27 15:40 - 2014-08-21 13:40 - 000248320 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juwwanecm.sys
2018-05-27 15:40 - 2014-07-25 17:08 - 000125952 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_cdcacm.sys
2018-05-27 15:40 - 2013-11-30 17:10 - 000077312 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys
2018-05-27 15:40 - 2013-11-30 17:10 - 000030720 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys
2018-05-27 15:40 - 2013-11-30 16:55 - 000226176 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys
2018-05-27 15:40 - 2013-01-25 09:16 - 000109568 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys
2018-05-27 15:40 - 2010-10-08 16:59 - 000032768 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys
2018-05-27 15:40 - 2010-09-26 18:09 - 000022016 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys
2018-05-25 18:01 - 2018-06-10 14:37 - 000000000 ____D C:\Users\RIYAS\Downloads\New folder (2)
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-22 15:52 - 2018-01-25 03:50 - 000004278 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{63818375-8335-4A5C-8361-85FD73B5C50E}
2018-06-22 15:38 - 2009-07-14 10:15 - 000020512 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-06-22 15:38 - 2009-07-14 10:15 - 000020512 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-06-22 15:35 - 2009-07-14 10:43 - 000863612 _____ C:\Windows\system32\PerfStringBackup.INI
2018-06-22 15:35 - 2009-07-14 08:50 - 000000000 ____D C:\Windows\inf
2018-06-22 15:29 - 2009-07-14 10:38 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-06-22 01:29 - 2017-09-19 14:17 - 000000252 _____ C:\Windows\Tasks\{5E612DA9-698B-41D1-BE36-24F3B190E1A9}.job
2018-06-21 22:15 - 2017-08-09 23:59 - 000000000 ____D C:\Users\RIYAS\AppData\Roaming\Adobe
2018-06-21 22:11 - 2018-04-09 00:01 - 000000000 ____D C:\Users\RIYAS\Downloads\topdf (1)
2018-06-21 22:10 - 2018-05-08 19:15 - 000000000 ____D C:\Users\RIYAS\Downloads\AIRTEL-E3372-ORIGINAL-DASHBOARD
2018-06-21 22:10 - 2018-04-08 16:31 - 000000000 ____D C:\Users\RIYAS\Downloads\Muhammed Riyas V.K-Payslip
2018-06-21 22:10 - 2018-01-16 22:42 - 000000000 ___RD C:\Users\RIYAS\Documents\Scanned Documents
2018-06-21 22:10 - 2017-11-28 00:35 - 000000000 ____D C:\Users\RIYAS\Documents\Youcam
2018-06-21 22:10 - 2017-10-25 15:50 - 000000000 ____D C:\Users\RIYAS\Documents\OneNote Notebooks
2018-06-21 21:26 - 2018-02-09 01:33 - 000000000 ____D C:\Users\RIYAS\Downloads\New folder
2018-06-21 21:26 - 2017-08-10 12:34 - 000000000 ____D C:\Users\RIYAS\Downloads\torrents
2018-06-21 20:47 - 2017-08-09 22:28 - 000000000 ____D C:\ProgramData\DatacardService
2018-06-21 17:00 - 2017-08-09 23:26 - 000000000 ____D C:\KMPlayer
2018-06-21 14:49 - 2018-03-15 00:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Download Accelerator Plus (DAP)
2018-06-21 14:49 - 2018-01-25 12:44 - 000000000 ____D C:\Disk
2018-06-20 19:33 - 2017-08-09 22:18 - 000000000 ____D C:\Users\RIYAS
2018-06-19 15:03 - 2018-03-25 02:29 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-06-19 14:55 - 2017-08-09 22:36 - 000000000 ____D C:\Users\RIYAS\AppData\Local\Google
2018-06-19 03:29 - 2018-01-09 09:54 - 000000896 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2018-06-19 03:29 - 2018-01-09 09:53 - 000000926 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-06-18 22:44 - 2017-08-09 23:51 - 000000000 ____D C:\Users\RIYAS\Downloads\Compressed
2018-06-18 22:24 - 2017-08-10 12:53 - 000000000 ____D C:\ProgramData\AVAST Software
2018-06-18 19:30 - 2017-12-16 18:42 - 000000000 ____D C:\Users\RIYAS\AppData\Local\ElevatedDiagnostics
2018-06-18 19:07 - 2018-01-25 12:14 - 000000000 ____D C:\found.000
2018-06-18 18:45 - 2009-07-14 10:15 - 000012288 _____ C:\Windows\system32\umstartup.etl
2018-06-18 18:08 - 2009-07-14 08:50 - 000000000 ____D C:\Windows\LiveKernelReports
2018-06-18 16:17 - 2018-02-04 14:35 - 000003484 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask
2018-06-14 19:43 - 2017-08-09 22:40 - 000002214 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-14 19:43 - 2017-08-09 22:40 - 000002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-06-14 18:58 - 2018-03-13 10:28 - 000003868 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1508862486
2018-06-14 06:07 - 2018-02-03 22:02 - 000000000 ____D C:\Program Files\Recuva
2018-06-08 12:27 - 2018-02-04 14:35 - 000000000 ____D C:\ProgramData\PCDr
2018-06-05 12:10 - 2017-10-21 11:47 - 000000000 ____D C:\Program Files\WinRAR
2018-06-05 01:13 - 2017-08-10 11:56 - 000000000 ___SD C:\Users\RIYAS\AppData\LocalLow\Temp
2018-06-05 00:38 - 2017-08-10 11:41 - 000000000 ____D C:\Windows\Panther
2018-06-04 23:58 - 2017-11-28 00:31 - 000000000 ____D C:\ProgramData\Temp
==================== Files in the root of some directories =======
2018-03-24 20:42 - 2018-03-24 20:42 - 000356864 _____ () C:\ProgramData\wmimgmt.exe
2017-10-21 10:34 - 2017-10-21 10:53 - 000000048 _____ () C:\Users\RIYAS\AppData\Roaming\MCVi2UserDetail.ini
2017-08-14 16:14 - 2017-10-17 15:31 - 000000024 _____ () C:\Users\RIYAS\AppData\Roaming\MyPhrases.dta
2017-09-20 00:17 - 2017-10-15 21:22 - 000000286 _____ () C:\Users\RIYAS\AppData\Roaming\WB.CFG
2018-06-21 01:09 - 2018-06-21 01:09 - 000340588 _____ () C:\Users\RIYAS\AppData\Local\ars.cache
2018-06-19 23:43 - 2018-06-19 23:43 - 000000000 ____H () C:\Users\RIYAS\AppData\Local\BIT7423.tmp
2018-06-21 01:10 - 2018-06-21 01:10 - 000522825 _____ () C:\Users\RIYAS\AppData\Local\census.cache
2017-12-14 17:47 - 2017-12-14 17:47 - 000000068 _____ () C:\Users\RIYAS\AppData\Local\evMXizQbsJ
2018-06-21 00:19 - 2018-06-21 00:19 - 000000036 _____ () C:\Users\RIYAS\AppData\Local\housecall.guid.cache
2018-01-25 12:45 - 2018-01-25 12:45 - 000140800 _____ () C:\Users\RIYAS\AppData\Local\installer.dat
2017-08-24 11:59 - 2017-09-13 11:22 - 000000600 _____ () C:\Users\RIYAS\AppData\Local\PUTTY.RND
2017-08-10 00:07 - 2018-03-15 20:02 - 000007597 _____ () C:\Users\RIYAS\AppData\Local\resmon.resmoncfg
2018-06-19 23:43 - 2018-06-19 23:43 - 000000000 _____ () C:\Users\RIYAS\AppData\Local\{72368EF5-ACDD-465C-A3B8-0A2C6CA10BFD}
Files to move or delete:
====================
C:\Windows\Tasks\{5E612DA9-698B-41D1-BE36-24F3B190E1A9}.job
Some files in TEMP:
====================
2018-06-21 22:41 - 2018-05-03 09:34 - 000858912 _____ (Malwarebytes) C:\Users\RIYAS\AppData\Local\Temp\mb-clean.exe
2018-06-21 22:41 - 2018-06-19 02:36 - 074288784 _____ (Malwarebytes ) C:\Users\RIYAS\AppData\Local\Temp\mb3-setup-1878.1878-3.5.1.2522.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-06-19 17:32
==================== End of FRST.txt ============================