Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-10-2020
Ran by nibbz (administrator) on NIBBZ-PC (31-10-2020 11:29:15)
Running from C:\Users\nibbz\Desktop
Loaded Profiles: nibbz
Platform: Windows 10 Pro Version 2009 19042.572 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2009.7-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2009.7-0\NisSrv.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe <2>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <6>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_edab19158bdd0d0a\Display.NvContainer\NVDisplay.Container.exe <2>
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [54176 2019-12-02] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645648 2019-10-05] (Oracle America, Inc. -> Oracle Corporation)
HKLM\...\Policies\Explorer: [RestrictRun] 0
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1243112257-1756932303-4238688702-1001\...\Policies\Explorer: [RestrictRun] 0
HKLM\...\Windows x64\Print Processors\hpfpp70v: C:\Windows\System32\spool\prtprocs\x64\hpfpp70v.dll [248320 2009-04-16] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\hpf3l70v.dll: C:\WINDOWS\system32\hpf3l70v.dll [136704 2009-04-16] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Company)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2020-06-21]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett Packard -> Hewlett-Packard Co.)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01E3ECC8-CEE2-4596-88AF-CC278929F117} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1243112257-1756932303-4238688702-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {02B1FC84-4058-4A65-884C-68AFBB0A1482} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {050682AF-F6C3-45F3-87B1-F0E978BD0E9D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MpCmdRun.exe [533312 2020-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0AADC2B9-9BDE-4B6B-9032-C6BE06E4AA85} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [782320 2019-10-26] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
Task: {10F60B49-4D1B-4796-844D-27B30A71D8EE} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [667856 2020-10-28] (Mozilla Corporation -> Mozilla Foundation)
Task: {11146950-1D02-44A0-850E-58290B201146} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MpCmdRun.exe [533312 2020-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {12CE4CD2-D469-4EC8-A21E-70BC54DBB006} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {18F05D4B-C1F8-47F0-A5EF-A9EE93A13C9D} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {1AD05F1E-C1ED-4A23-A219-4CC2BB7474CA} - System32\Tasks\{90D778C6-62A9-4618-BA48-BDA4538F7EEF} => C:\Windows\system32\pcalua.exe -a "C:\Users\nibbz\Desktop\DVR Client_V3.3.2.exe" -d C:\Users\nibbz\Desktop
Task: {1FD1DD61-9D5F-4CA2-828D-D105E6DEEBC8} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43da-BFD7-FBEEA2180A1E}
Task: {2593C2B3-C7B6-48C8-83BC-D19F626AA965} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {2BF0D047-05F2-4F61-8A5F-367E2F0D1B6D} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1243112257-1756932303-4238688702-1004 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {2E7DBAE9-BE56-4D33-851D-AC7C4512FA64} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {31DA857A-D150-4348-A380-D24A8D416A48} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1243112257-1756932303-4238688702-1003 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {361970D8-0327-4F9D-A6EA-6D2AF62DF366} - System32\Tasks\{CA6760AA-AB8F-415B-AC6D-28667E31222F} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Torntv V9.0\Uninstall.exe" -c /fcp=1
Task: {39DAE6B6-3A8A-4767-BBB0-C0B5C9FA6A7B} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {3D258B33-10DF-4620-8F8E-CA5DCF8D8F52} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {4524FA5C-E696-4025-9145-14A75F342912} - System32\Tasks\{A7C374DD-7621-47F8-B2CD-40DF4A5901F1} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\setup.exe" -c -runfromtemp -l0x0009 -removeonly
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47C2-B62A-B7C4CED925CB}
Task: {49831755-AE46-4A32-BB61-835DC950E56E} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {63BEDAC9-B83F-46AE-9D67-FFCBA1F2CE33} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {675925EB-99DC-4AEB-A1E2-C7AB6A51EFA7} - System32\Tasks\{4393EFA4-55A4-492A-91BB-5DD78D4B5610} => E:\Setup.exe
Task: {67FD7BEB-E6A7-4226-8FF7-D2587C9737EC} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDfE067B1}
Task: {699BF0D2-029E-4206-AEA1-BB9E52D730EC} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6AD54841-B75C-4A0B-8829-F3C6783B9272} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {6E1C9C44-A7E4-4F70-A3C1-7CE9BE97E7ED} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {765513FB-28D0-479C-815A-C27DEC91E075} - System32\Tasks\{3821735C-16E0-4833-8747-FCEF541B79FE} => C:\Windows\system32\pcalua.exe -a C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe -c /M{B98A34C0-A6A2-4087-B272-557C1C6D0A07}
Task: {7736BB95-83C0-481B-944D-F7C1A9297F34} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MpCmdRun.exe [533312 2020-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {776FA914-7650-45EB-A1CB-7F11D3505C6B} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1243112257-1756932303-4238688702-1004 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {7A252441-18D0-4992-B60A-B660C5CD3E88} - System32\Tasks\EVGAPrecisionX => C:\Program Files (x86)\EVGA\PrecisionX 16\PrecisionX_x64.exe
Task: {84396829-DB5D-4F61-8743-58417694A409} - System32\Tasks\{6C068100-BB24-4ABD-8A71-4B7E8C4F25EF} => C:\Windows\system32\pcalua.exe -a "C:\Users\nibbz\Virtual Machines\DVR Client_CIF_D1_V3.3.2\DVR Client_V3.3.2.exe" -d "C:\Users\nibbz\Virtual Machines\DVR Client_CIF_D1_V3.3.2"
Task: {84639797-E13C-4069-9E83-79B4702D52AC} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {84C5AAD2-D944-48BA-B6EB-876B87753141} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {8BDDFB40-C91C-49DB-A402-42C069F7D295} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8D997A60-6ED5-481F-84D4-98489AF64F29} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {8F914994-0F9E-4E55-BEC6-D3AAF162AE84} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {94F837F5-0123-4528-A911-25513A27141A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {98C4D312-BC2F-4982-B9E0-90DE2AA176A2} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {9FAEC481-F059-4FDC-9296-A004C8D44349} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A3F3E078-E6B9-49DB-9E81-C322C25F389A} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A5386531-8161-4D05-AE14-05BA386E3989} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {ABF721EF-24FE-4981-B60E-4048CEF551E5} - System32\Tasks\{5046E3C8-D2D6-41A8-AE13-57AA06147E79} => C:\Windows\system32\pcalua.exe -a C:\Users\nibbz\Desktop\pdSetup.exe -d C:\Users\nibbz\Desktop
Task: {AFC3543E-8FB4-42D5-A419-E4AD24A3519A} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40b4-8963-D3C761B18371}
Task: {B2A1BFB9-A9F5-4A29-806D-7E307EAD1351} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {B36D8CE8-7FA4-446B-B878-AFE95BACA63B} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B6419424-6D97-4ED5-A49C-5A0F10B947AD} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4f47-879B-29A80C355D61}
Task: {B6C919DE-03E5-4B25-978D-274432ECC2D5} - System32\Tasks\{1137E975-1973-4F72-B9A9-E4C71AF6205F} => C:\Windows\system32\pcalua.exe -a "C:\Users\nibbz\Documents\BitLord\RealFlight G4 + 3 Addons + Dongle v3.3 + Update 4.00.051 + 5 Expansion Packs+RealFlight G4.5\RealFlight4_00_035.exe" -d "C:\Users\nibbz\Documents\BitLord\RealFlight G4 + 3 Addons + Dongle v3.3 + Update 4.00.051 + 5 Expansion Packs+RealFlight G4.5"
Task: {BA6D07A8-F8E6-43D6-9A06-2027BEE74B97} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MpCmdRun.exe [533312 2020-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C6FAEF05-889E-44F2-B774-77ACE8D48DC0} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [3047944 2020-08-31] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
Task: {CC6D56D0-ADED-465C-AE89-51692FD13BA7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-03-15] (Google Inc -> Google Inc.)
Task: {D1750D58-E8DD-47FA-8271-EFF55435DFCB} - System32\Tasks\{E0201C48-4C1D-4DB2-A733-A48E5FE2113A} => E:\Setup.exe
Task: {D23D3737-CCD6-4DC7-A470-8519841E7018} - System32\Tasks\{ACCD3500-F3B3-4F07-B307-FF4AA92040C1} => E:\Setup.exe
Task: {D30233A8-6403-443E-AF12-8E24A84F246F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-03-15] (Google Inc -> Google Inc.)
Task: {DA742604-28E2-403B-B129-ADC5B4FC1766} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {DACBF11C-C042-4218-AE30-ACA169DBF62E} - System32\Tasks\{69247383-4062-40E7-8ED3-CAB9D28C1F9F} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Common Files\DongJob\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\DongJob\uninstall.dat" -a uninstallme AEE7AF37-2C16-4CB7-9856-72FC5F7901F7 DeviceId=401724b6-9f7d-869c-33a5-6e1ad23ac7b5 BarcodeId=51126003 ChannelId=3 DistributerName=APSFAM
Task: {E6FD53C6-1F52-4581-8207-DE4B50513B20} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1243112257-1756932303-4238688702-1003 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {F5551C9D-2AAF-4C3E-8EDD-DC72A9F4B335} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1243112257-1756932303-4238688702-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{02fa9f72-b917-4322-a8df-fbe013ca5c16}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{81783699-432d-4850-8686-e6c3cf669644}: [DhcpNameServer] 192.168.1.1
Edge:
======
DownloadDir: C:\Users\nibbz\Downloads
Edge Profile: C:\Users\nibbz\AppData\Local\Microsoft\Edge\User Data\Default [2020-10-28]
Edge DownloadDir: C:\Users\nibbz\Downloads
FireFox:
========
FF DefaultProfile: 2x993i6h.default-1470504307528-1603843932508
FF ProfilePath: C:\Users\nibbz\AppData\Roaming\Mozilla\Firefox\Profiles\2x993i6h.default-1470504307528-1603843932508 [2020-10-31]
FF HKU\S-1-5-21-1243112257-1756932303-4238688702-1001\...\SeaMonkey\Extensions: [
mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll [2014-03-11] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-04-02] (Foxit Corporation -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-04-02] (Foxit Corporation -> Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2019-11-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2019-11-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-12-21] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - <no Path/update_url>
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65432 2013-12-21] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7185288 2020-10-26] (Malwarebytes Inc -> Malwarebytes)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [13617208 2020-10-22] (Adlice -> )
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1676416 2020-07-25] (Rockstar Games, Inc. -> Rockstar Games)
R2 SamsungRapidSvc; C:\WINDOWS\System32\RAPID\SamsungRapidSvc.exe [30504 2019-12-02] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5102504 2020-10-28] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\NisSrv.exe [2372048 2020-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MsMpEng.exe [128376 2020-10-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_edab19158bdd0d0a\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_edab19158bdd0d0a\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Apowersoft_AudioDevice; C:\WINDOWS\System32\drivers\Apowersoft_AudioDevice.sys [31920 2014-04-09] (APOWERSOFT LIMITED -> Wondershare)
R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [314016 2014-05-10] (Tages SA -> )
R1 HWiNFO; C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [55960 2018-07-25] (Martin Malik - REALiX -> REALiX(tm))
R1 HWiNFO_150; C:\WINDOWS\system32\drivers\HWiNFO64A_150.SYS [62240 2020-07-19] (Martin Malik - REALiX -> REALiX(tm))
S3 I2cHkBurn; C:\WINDOWS\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (Feature Integration Technology -> FINTEK Corp.)
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115448 2013-11-21] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
S3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2016-12-08] (Logitech Inc -> Logitech Inc.)
S3 LGSHidFilt; C:\WINDOWS\system32\DRIVERS\LGSHidFilt.Sys [64280 2016-12-08] (Logitech -> Logitech Inc.)
R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [43680 2014-05-10] (Tages SA -> )
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-10-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-10-26] (Malwarebytes Inc -> Malwarebytes)
R2 mi2c; C:\Windows\system32\drivers\mi2c.sys [20784 2014-01-18] (AOC International (Europe) GmbH -> Nicomsoft Ltd.)
R3 MpKsl681707d3; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E27D06E-A0C0-49A4-B0F9-B94A0F562F9F}\MpKslDrv.sys [47336 2020-10-31] (Microsoft Windows -> Microsoft Corporation)
R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] (ASUSTeK Computer Inc. -> )
R3 mv91cons; C:\WINDOWS\System32\drivers\mv91cons.sys [32184 2015-06-25] (Marvell Semiconductor, Inc. -> Marvell Semiconductor Inc.)
R2 NPF; C:\WINDOWS\system32\drivers\npf.sys [35344 2017-03-13] (CACE Technologies, Inc. -> CACE Technologies, Inc.)
S3 PPJoyBus; C:\WINDOWS\System32\DRIVERS\PPJoyBus64.sys [20024 2010-02-20] (Deon van der Westhuysen Test Certificate -> Deon van der Westhuysen) [File not signed]
S3 PPortJoystick; C:\WINDOWS\System32\DRIVERS\PPortJoy64.sys [39488 2009-11-03] (Deon van der Westhuysen Test Certificate -> Deon van der Westhuysen) [File not signed]
R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [24000 2019-09-25] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R0 SamsungRapidDiskFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidDiskFltr.sys [309752 2019-06-13] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidFSFltr.sys [120280 2019-06-13] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48536 2020-10-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [428264 2020-10-07] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [69864 2020-10-07] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-10-31 11:29 - 2020-10-31 11:29 - 000024456 _____ C:\Users\nibbz\Desktop\FRST.txt
2020-10-29 23:02 - 2020-10-29 23:02 - 000000000 ___HD C:\$SysReset
2020-10-28 22:22 - 2020-10-31 11:27 - 000003386 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d6ad9967b70c85
2020-10-28 22:20 - 2020-10-31 01:18 - 000971870 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-10-28 22:20 - 2020-10-28 22:20 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-10-28 22:20 - 2020-10-28 22:20 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2020-10-28 22:18 - 2020-10-28 22:18 - 000000020 ___SH C:\Users\nibbz\ntuser.ini
2020-10-28 22:17 - 2020-10-31 11:27 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-10-28 22:17 - 2020-10-31 09:44 - 000003128 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner
2020-10-28 22:17 - 2020-10-31 09:42 - 000004154 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{F6F60183-C372-49C9-937E-703DCEE2983D}
2020-10-28 22:17 - 2020-10-31 01:13 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-10-28 22:17 - 2020-10-28 22:17 - 000019053 _____ C:\WINDOWS\diagwrn.xml
2020-10-28 22:17 - 2020-10-28 22:17 - 000019053 _____ C:\WINDOWS\diagerr.xml
2020-10-28 22:17 - 2020-10-28 22:17 - 000003346 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-10-28 22:17 - 2020-10-28 22:17 - 000003300 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{782DCC4D-C225-4B8D-B09E-DB638395DB58}
2020-10-28 22:17 - 2020-10-28 22:17 - 000003184 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-10-28 22:17 - 2020-10-28 22:17 - 000003122 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-10-28 22:17 - 2020-10-28 22:17 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1243112257-1756932303-4238688702-1001
2020-10-28 22:17 - 2020-10-28 22:17 - 000002646 _____ C:\WINDOWS\system32\Tasks\EVGAPrecisionX
2020-10-28 22:17 - 2020-10-28 22:17 - 000002590 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2020-10-28 22:17 - 2020-10-28 22:17 - 000002534 _____ C:\WINDOWS\system32\Tasks\SamsungMagician
2020-10-28 22:17 - 2020-10-28 22:17 - 000000000 ____D C:\WINDOWS\system32\Tasks\WPD
2020-10-28 22:17 - 2020-10-28 22:17 - 000000000 ____D C:\WINDOWS\system32\Tasks\S-1-5-21-1243112257-1756932303-4238688702-1001
2020-10-28 22:17 - 2020-10-28 22:17 - 000000000 ____D C:\WINDOWS\system32\Tasks\OfficeSoftwareProtectionPlatform
2020-10-28 22:17 - 2016-05-08 12:14 - 000003710 _____ C:\WINDOWS\system32\Tasks\{69247383-4062-40E7-8ED3-CAB9D28C1F9F}
2020-10-28 22:17 - 2016-05-08 12:14 - 000003708 _____ C:\WINDOWS\system32\Tasks\{1137E975-1973-4F72-B9A9-E4C71AF6205F}
2020-10-28 22:17 - 2016-05-08 12:14 - 000003492 _____ C:\WINDOWS\system32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1243112257-1756932303-4238688702-1001
2020-10-28 22:17 - 2016-05-08 12:14 - 000003266 _____ C:\WINDOWS\system32\Tasks\{5046E3C8-D2D6-41A8-AE13-57AA06147E79}
2020-10-28 22:17 - 2016-05-08 12:14 - 000003042 _____ C:\WINDOWS\system32\Tasks\{E0201C48-4C1D-4DB2-A733-A48E5FE2113A}
2020-10-28 22:17 - 2016-05-08 12:14 - 000003042 _____ C:\WINDOWS\system32\Tasks\{ACCD3500-F3B3-4F07-B307-FF4AA92040C1}
2020-10-28 22:17 - 2016-05-08 12:13 - 000003444 _____ C:\WINDOWS\system32\Tasks\{A7C374DD-7621-47F8-B2CD-40DF4A5901F1}
2020-10-28 22:17 - 2016-05-08 12:13 - 000003430 _____ C:\WINDOWS\system32\Tasks\{6C068100-BB24-4ABD-8A71-4B7E8C4F25EF}
2020-10-28 22:17 - 2016-05-08 12:13 - 000003358 _____ C:\WINDOWS\system32\Tasks\RealUpgradeLogonTaskS-1-5-21-1243112257-1756932303-4238688702-1001
2020-10-28 22:17 - 2016-05-08 12:13 - 000003354 _____ C:\WINDOWS\system32\Tasks\{3821735C-16E0-4833-8747-FCEF541B79FE}
2020-10-28 22:17 - 2016-05-08 12:13 - 000003290 _____ C:\WINDOWS\system32\Tasks\{90D778C6-62A9-4618-BA48-BDA4538F7EEF}
2020-10-28 22:17 - 2016-05-08 12:13 - 000003266 _____ C:\WINDOWS\system32\Tasks\{CA6760AA-AB8F-415B-AC6D-28667E31222F}
2020-10-28 22:17 - 2016-05-08 12:13 - 000003042 _____ C:\WINDOWS\system32\Tasks\{4393EFA4-55A4-492A-91BB-5DD78D4B5610}
2020-10-28 22:17 - 2012-08-25 11:32 - 000003342 _____ C:\WINDOWS\system32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1243112257-1756932303-4238688702-1004
2020-10-28 22:17 - 2012-08-25 11:32 - 000003210 _____ C:\WINDOWS\system32\Tasks\RealUpgradeLogonTaskS-1-5-21-1243112257-1756932303-4238688702-1004
2020-10-28 22:17 - 2012-06-03 18:30 - 000003342 _____ C:\WINDOWS\system32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1243112257-1756932303-4238688702-1003
2020-10-28 22:17 - 2012-06-03 18:30 - 000003210 _____ C:\WINDOWS\system32\Tasks\RealUpgradeLogonTaskS-1-5-21-1243112257-1756932303-4238688702-1003
2020-10-28 22:09 - 2020-10-28 21:32 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-10-28 22:08 - 2020-10-31 01:46 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-10-28 22:08 - 2020-10-31 01:13 - 000008192 ___SH C:\DumpStack.log.tmp
2020-10-28 22:08 - 2020-10-31 01:13 - 000001134 _____ C:\WINDOWS\system32\config\VSMIDK
2020-10-28 22:08 - 2020-10-28 22:18 - 000000000 ____D C:\Windows.old
2020-10-28 22:08 - 2020-10-28 22:08 - 000654416 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-10-28 22:07 - 2020-10-28 22:07 - 000073016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WinSetupBoot.sys
2020-10-28 21:42 - 2020-10-28 22:08 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2020-10-28 21:42 - 2020-10-28 21:42 - 000000000 ____D C:\Program Files\Common Files\SpeechEngines
2020-10-28 21:40 - 2020-10-28 22:18 - 000000000 ____D C:\Users\nibbz
2020-10-28 21:40 - 2020-10-28 22:14 - 000000000 ____D C:\Users\DefaultAppPool
2020-10-28 21:40 - 2020-10-28 22:14 - 000000000 ____D C:\Users\.NET v4.5 Classic
2020-10-28 21:40 - 2020-10-28 22:14 - 000000000 ____D C:\Users\.NET v4.5
2020-10-28 21:40 - 2019-12-07 05:10 - 000001105 _____ C:\Users\nibbz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-10-28 21:40 - 2019-12-07 05:10 - 000001105 _____ C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start