Hi so I was on my PC and downloaded a patch for my ps2 emulator. I extracted the file (didn't run it) and MSE came up with a detection and deleted it.
here are the logs
if youre wondering why I have testsigning on, its because a windows service for my dualshock 3 controller wont work without it
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28.09.2018
Ran by Eric (administrator) on MAIN (05-11-2018 13:22:18)
Running from C:\Users\Eric\Desktop
Loaded Profiles: Eric (Available Profiles: Eric)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Scarlet.Crush Productions) C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe
(Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(ALCPU) C:\Program Files\Core Temp\Core Temp.exe
(VIA Technologies, Inc.) C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Spotify Ltd) C:\Users\Eric\AppData\Roaming\Spotify\SpotifyWebHelper.exe
() C:\Windows\SysWOW64\Codecs\TrayMenu.exe
(Scarlet.Crush Productions) C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8497368 2015-07-07] (Realtek Semiconductor)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596664 2018-01-15] (Razer Inc.)
HKLM-x32\...\Run: [Codec Settings UAC Manager] => C:\Windows\SysWOW64\Codecs\CodecUACManager.exe [66216 2018-07-24] ()
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\MountPoints2: G - G:\setup.exe
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\MountPoints2: {4727379c-182c-11e8-881c-806e6f6e6963} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\setup.exe
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk [2018-10-04]
ShortcutTarget: CodecPackTrayMenu.lnk -> C:\Windows\SysWOW64\Codecs\TrayMenu.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScpToolkit Tray Notifications.lnk [2018-10-25]
ShortcutTarget: ScpToolkit Tray Notifications.lnk -> C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe (Scarlet.Crush Productions)
GroupPolicy: Restriction ? <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-32538046-3854998793-3802812278-1000] => 127.0.0.1:80
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{15F81B08-A815-4CC8-B50E-2B8F15DCB9D5}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{227B6D41-7D5D-48A9-9D03-CE3A6CC3F216}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{6D7B8BFD-1463-4A80-800B-2D63C7A581AA}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
FireFox:
========
FF DefaultProfile: 62izzuiv.default
FF ProfilePath: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\62izzuiv.default [2018-11-05]
FF Extension: (Telemetry coverage) - C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\62izzuiv.default\features\{b2d5c4b0-417f-43d5-9062-7193a44e8926}\telemetry-coverage-bug1487578@mozilla.org.xpi [2018-10-10] [Legacy]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6877224 2018-09-26] ()
S3 Bonjour Service; C:\Program Files (x86)\Blizzard\Bonjour Service\mDNSResponder.exe [390504 2018-05-27] (Apple Inc.)
R2 Ds3Service; C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe [394944 2016-04-12] (Scarlet.Crush Productions)
S3 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [73200 2018-09-24] (Freemake)
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2018-09-24] (Ellora Assets Corp.) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S4 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2017-07-19] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S4 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 csrusbfilter; C:\Windows\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Limited)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [50392 2015-08-13] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [43256 2017-07-18] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [137208 2017-08-19] (Razer, Inc.)
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [42856 2016-03-27] (Nefarius Software Solutions)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [225792 2013-08-12] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [295424 2013-08-12] (VIA Technologies, Inc.)
R3 ALSysIO; \??\C:\Users\Eric\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 csravrcp; system32\DRIVERS\csravrcp.sys [X]
S3 CsrBtPort; system32\DRIVERS\CsrBtPort.sys [X]
S3 csrduncmdm; system32\DRIVERS\csrdunc.sys [X]
S3 csrpan; system32\DRIVERS\csrpan.sys [X]
S3 csrserial; system32\DRIVERS\csrserial.sys [X]
S3 csrusb; System32\Drivers\csrusb.sys [X]
S3 csr_bthav; system32\drivers\csrbthav.sys [X]
S1 MpKsl1530086a; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2E64D21B-39A0-492F-BEB4-45A9375A3D7E}\MpKsl1530086a.sys [X]
S3 NPF; system32\drivers\NPF.sys [X]
S2 WinRing0_1_2_0; \??\C:\Program Files (x86)\Steam\steamapps\common\EVGA PrecisionX\WinRing0\WinRing0x64.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
S1 YSDrv; \??\C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-11-05 13:22 - 2018-11-05 13:22 - 000010015 _____ C:\Users\Eric\Desktop\FRST.txt
2018-11-05 13:22 - 2018-11-05 13:22 - 000000000 ____D C:\FRST
2018-11-05 13:21 - 2018-11-05 13:20 - 002414080 _____ (Farbar) C:\Users\Eric\Desktop\FRST64.exe
2018-11-05 12:57 - 2018-11-05 12:57 - 000000000 ____D C:\Users\Eric\AppData\LocalLow\Temp
2018-11-05 12:51 - 2018-11-05 12:51 - 000009333 _____ C:\Users\Eric\AppData\Local\recently-used.xbel
2018-11-05 12:48 - 2018-11-05 12:49 - 000000000 ____D C:\Users\Eric\Desktop\snes9x
2018-11-05 12:24 - 2018-11-05 12:24 - 000003368 ____N C:\bootsqm.dat
2018-11-05 11:47 - 2018-11-05 11:47 - 000000000 ____D C:\Users\Eric\AppData\Local\mbam
2018-11-05 11:44 - 2018-11-05 11:44 - 000001881 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-11-05 11:44 - 2018-11-05 11:44 - 000000000 ____D C:\Users\Eric\AppData\Local\mbamtray
2018-11-05 11:44 - 2018-11-05 11:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-11-05 11:44 - 2018-11-05 11:44 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-11-05 11:44 - 2018-11-05 11:44 - 000000000 ____D C:\Program Files\Malwarebytes
2018-11-05 11:44 - 2018-10-18 08:44 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2018-11-04 16:59 - 2018-11-04 17:10 - 190222918 _____ C:\Users\Eric\Desktop\Front_Mission_2_[T+Eng_PatchF].zip
2018-11-04 16:59 - 2018-11-04 16:59 - 002288693 _____ C:\Users\Eric\Desktop\Front_Mission_[T+Eng1.00].zip
2018-11-04 16:41 - 2018-11-04 16:41 - 000000000 ____D C:\Users\Eric\Desktop\2076.63mb used 11-4-18-1641
2018-11-03 12:51 - 2018-11-04 09:21 - 000220413 _____ C:\Users\Eric\Desktop\fm3.txt
2018-11-02 15:22 - 2018-11-05 12:50 - 000000000 ____D C:\Users\Eric\Desktop\EPSXE
2018-10-31 14:11 - 2018-10-31 14:11 - 000000000 ____D C:\Users\Eric\jagexcache
2018-10-31 14:10 - 2018-10-31 14:11 - 000000000 ____D C:\Users\Eric\.runelite
2018-10-29 14:44 - 2018-10-29 14:44 - 000008720 _____ C:\Users\Eric\Desktop\New Text Document.txt
2018-10-29 07:06 - 2018-11-05 12:29 - 000000000 ____D C:\Users\Eric\AppData\LocalLow\uTorrent
2018-10-25 12:25 - 2018-10-25 15:34 - 000000000 ____D C:\Users\Eric\AppData\Local\visualboyadvance-m
2018-10-25 12:24 - 2018-03-14 11:50 - 017184052 _____ (hxxp://vba-m.com/) C:\Users\Eric\Desktop\visualboyadvance-m.exe
2018-10-25 12:24 - 2018-03-14 11:50 - 000008406 _____ C:\Users\Eric\Desktop\vba-over.ini
2018-10-25 12:21 - 2018-11-05 11:00 - 000000428 _____ C:\Windows\Tasks\ScpUpdater.job
2018-10-25 12:21 - 2018-10-25 12:21 - 000002988 _____ C:\Windows\System32\Tasks\ScpUpdater
2018-10-25 12:21 - 2018-10-25 12:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScpToolkit
2018-10-25 06:05 - 2018-10-25 06:05 - 000001067 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1964.lnk
2018-10-25 06:05 - 2018-10-25 06:05 - 000000000 ____D C:\Program Files (x86)\1964
2018-10-20 22:47 - 2018-10-29 14:33 - 000000000 ____D C:\Users\Eric\AppData\Local\gtk-2.0
2018-10-20 22:27 - 2018-11-05 12:52 - 000000000 ____D C:\Users\Eric\AppData\Local\babl-0.1
2018-10-20 22:27 - 2018-10-29 14:36 - 000000945 _____ C:\Users\Public\Desktop\GIMP 2.10.6.lnk
2018-10-20 22:27 - 2018-10-20 22:27 - 000000913 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.10.6.lnk
2018-10-20 22:27 - 2018-10-20 22:27 - 000000000 ____D C:\Users\Eric\AppData\Roaming\GIMP
2018-10-20 22:27 - 2018-10-20 22:27 - 000000000 ____D C:\Users\Eric\AppData\Local\GIMP
2018-10-20 22:27 - 2018-10-20 22:27 - 000000000 ____D C:\Users\Eric\AppData\Local\gegl-0.4
2018-10-20 22:26 - 2018-10-20 22:28 - 000000000 ____D C:\Program Files\GIMP 2
2018-10-20 17:40 - 2018-10-25 12:15 - 000000000 ____D C:\ProgramData\RedFox
2018-10-20 17:40 - 2018-10-20 17:40 - 000000000 ____D C:\Program Files (x86)\RedFox
2018-10-13 12:57 - 2018-10-13 13:01 - 000000000 ____D C:\StarCraft
2018-10-12 23:27 - 2018-10-12 23:38 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2018-10-07 15:07 - 2018-10-25 12:16 - 000000000 ____D C:\Windows\system32\appmgmt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-11-05 13:02 - 2018-09-07 14:08 - 000000000 ____D C:\Users\Eric\AppData\LocalLow\Mozilla
2018-11-05 12:34 - 2018-04-16 20:32 - 000004128 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-11-05 12:33 - 2009-07-13 23:45 - 000022768 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-11-05 12:33 - 2009-07-13 23:45 - 000022768 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-11-05 12:30 - 2018-10-04 12:18 - 000000000 ____D C:\Users\Eric\AppData\Roaming\MPC-HC
2018-11-05 12:30 - 2018-03-04 18:44 - 000000000 ____D C:\Users\Eric\AppData\Roaming\uTorrent
2018-11-05 12:30 - 2018-02-24 02:07 - 000000000 ____D C:\Users\Eric\AppData\Local\CrashDumps
2018-11-05 12:30 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2018-11-05 12:29 - 2009-07-14 00:13 - 000781782 _____ C:\Windows\system32\PerfStringBackup.INI
2018-11-05 12:25 - 2018-07-20 21:28 - 000000434 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2018-11-05 12:25 - 2018-04-12 15:14 - 000000000 ____D C:\Program Files\Core Temp
2018-11-05 12:25 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-11-05 12:24 - 2018-02-22 16:37 - 000000000 ____D C:\ProgramData\NVIDIA
2018-11-05 11:11 - 2018-09-07 14:08 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-11-04 21:13 - 2018-04-19 12:58 - 000000000 ____D C:\Program Files (x86)\Steam
2018-11-04 17:45 - 2018-06-10 01:27 - 000000000 ____D C:\Users\Eric\Documents\The Witcher 3
2018-11-01 08:22 - 2018-02-25 14:47 - 000000043 _____ C:\Users\Eric\jagex_cl_oldschool_LIVE.dat
2018-10-31 14:11 - 2018-02-22 16:08 - 000000000 ____D C:\Users\Eric
2018-10-29 14:38 - 2018-05-21 08:47 - 000000000 ____D C:\Program Files (x86)\Google
2018-10-29 14:37 - 2018-02-22 16:45 - 000000000 ____D C:\Users\Eric\AppData\Local\Google
2018-10-23 21:56 - 2018-05-27 06:08 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-10-23 18:52 - 2018-05-27 06:09 - 000000000 ____D C:\Users\Eric\AppData\Local\Battle.net
2018-10-20 06:27 - 2018-05-29 02:07 - 000001078 _____ C:\Users\Public\Desktop\Medivia Online - DirectX.lnk
2018-10-20 06:27 - 2018-04-13 11:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medivia Online
2018-10-20 06:27 - 2018-04-13 11:35 - 000000000 ____D C:\Program Files (x86)\Medivia Online
2018-10-18 07:15 - 2018-02-22 17:13 - 000000000 ____D C:\Users\Eric\AppData\Local\Spotify
2018-10-18 07:15 - 2018-02-22 17:12 - 000000000 ____D C:\Users\Eric\AppData\Roaming\Spotify
2018-10-07 15:06 - 2018-04-19 18:07 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
==================== Files in the root of some directories =======
2018-11-05 12:51 - 2018-11-05 12:51 - 000009333 _____ () C:\Users\Eric\AppData\Local\recently-used.xbel
2018-06-15 09:54 - 2018-09-10 09:35 - 000007609 _____ () C:\Users\Eric\AppData\Local\Resmon.ResmonCfg
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
testsigning: ==> 'testsigning' is set. Check for possible unsigned driver <==== ATTENTION
LastRegBack: 2018-11-04 07:16
==================== End of FRST.txt ============================
here are the logs
if youre wondering why I have testsigning on, its because a windows service for my dualshock 3 controller wont work without it
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28.09.2018
Ran by Eric (administrator) on MAIN (05-11-2018 13:22:18)
Running from C:\Users\Eric\Desktop
Loaded Profiles: Eric (Available Profiles: Eric)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Scarlet.Crush Productions) C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe
(Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(ALCPU) C:\Program Files\Core Temp\Core Temp.exe
(VIA Technologies, Inc.) C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Spotify Ltd) C:\Users\Eric\AppData\Roaming\Spotify\SpotifyWebHelper.exe
() C:\Windows\SysWOW64\Codecs\TrayMenu.exe
(Scarlet.Crush Productions) C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8497368 2015-07-07] (Realtek Semiconductor)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596664 2018-01-15] (Razer Inc.)
HKLM-x32\...\Run: [Codec Settings UAC Manager] => C:\Windows\SysWOW64\Codecs\CodecUACManager.exe [66216 2018-07-24] ()
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\MountPoints2: G - G:\setup.exe
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\...\MountPoints2: {4727379c-182c-11e8-881c-806e6f6e6963} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\setup.exe
HKU\S-1-5-21-32538046-3854998793-3802812278-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk [2018-10-04]
ShortcutTarget: CodecPackTrayMenu.lnk -> C:\Windows\SysWOW64\Codecs\TrayMenu.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScpToolkit Tray Notifications.lnk [2018-10-25]
ShortcutTarget: ScpToolkit Tray Notifications.lnk -> C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpTrayApp.exe (Scarlet.Crush Productions)
GroupPolicy: Restriction ? <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-32538046-3854998793-3802812278-1000] => 127.0.0.1:80
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{15F81B08-A815-4CC8-B50E-2B8F15DCB9D5}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{227B6D41-7D5D-48A9-9D03-CE3A6CC3F216}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{6D7B8BFD-1463-4A80-800B-2D63C7A581AA}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
FireFox:
========
FF DefaultProfile: 62izzuiv.default
FF ProfilePath: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\62izzuiv.default [2018-11-05]
FF Extension: (Telemetry coverage) - C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\62izzuiv.default\features\{b2d5c4b0-417f-43d5-9062-7193a44e8926}\telemetry-coverage-bug1487578@mozilla.org.xpi [2018-10-10] [Legacy]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6877224 2018-09-26] ()
S3 Bonjour Service; C:\Program Files (x86)\Blizzard\Bonjour Service\mDNSResponder.exe [390504 2018-05-27] (Apple Inc.)
R2 Ds3Service; C:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe [394944 2016-04-12] (Scarlet.Crush Productions)
S3 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [73200 2018-09-24] (Freemake)
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2018-09-24] (Ellora Assets Corp.) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S4 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2017-07-19] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S4 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 csrusbfilter; C:\Windows\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Limited)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [50392 2015-08-13] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [43256 2017-07-18] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [137208 2017-08-19] (Razer, Inc.)
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [42856 2016-03-27] (Nefarius Software Solutions)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [225792 2013-08-12] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [295424 2013-08-12] (VIA Technologies, Inc.)
R3 ALSysIO; \??\C:\Users\Eric\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 csravrcp; system32\DRIVERS\csravrcp.sys [X]
S3 CsrBtPort; system32\DRIVERS\CsrBtPort.sys [X]
S3 csrduncmdm; system32\DRIVERS\csrdunc.sys [X]
S3 csrpan; system32\DRIVERS\csrpan.sys [X]
S3 csrserial; system32\DRIVERS\csrserial.sys [X]
S3 csrusb; System32\Drivers\csrusb.sys [X]
S3 csr_bthav; system32\drivers\csrbthav.sys [X]
S1 MpKsl1530086a; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2E64D21B-39A0-492F-BEB4-45A9375A3D7E}\MpKsl1530086a.sys [X]
S3 NPF; system32\drivers\NPF.sys [X]
S2 WinRing0_1_2_0; \??\C:\Program Files (x86)\Steam\steamapps\common\EVGA PrecisionX\WinRing0\WinRing0x64.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
S1 YSDrv; \??\C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-11-05 13:22 - 2018-11-05 13:22 - 000010015 _____ C:\Users\Eric\Desktop\FRST.txt
2018-11-05 13:22 - 2018-11-05 13:22 - 000000000 ____D C:\FRST
2018-11-05 13:21 - 2018-11-05 13:20 - 002414080 _____ (Farbar) C:\Users\Eric\Desktop\FRST64.exe
2018-11-05 12:57 - 2018-11-05 12:57 - 000000000 ____D C:\Users\Eric\AppData\LocalLow\Temp
2018-11-05 12:51 - 2018-11-05 12:51 - 000009333 _____ C:\Users\Eric\AppData\Local\recently-used.xbel
2018-11-05 12:48 - 2018-11-05 12:49 - 000000000 ____D C:\Users\Eric\Desktop\snes9x
2018-11-05 12:24 - 2018-11-05 12:24 - 000003368 ____N C:\bootsqm.dat
2018-11-05 11:47 - 2018-11-05 11:47 - 000000000 ____D C:\Users\Eric\AppData\Local\mbam
2018-11-05 11:44 - 2018-11-05 11:44 - 000001881 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-11-05 11:44 - 2018-11-05 11:44 - 000000000 ____D C:\Users\Eric\AppData\Local\mbamtray
2018-11-05 11:44 - 2018-11-05 11:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-11-05 11:44 - 2018-11-05 11:44 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-11-05 11:44 - 2018-11-05 11:44 - 000000000 ____D C:\Program Files\Malwarebytes
2018-11-05 11:44 - 2018-10-18 08:44 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2018-11-04 16:59 - 2018-11-04 17:10 - 190222918 _____ C:\Users\Eric\Desktop\Front_Mission_2_[T+Eng_PatchF].zip
2018-11-04 16:59 - 2018-11-04 16:59 - 002288693 _____ C:\Users\Eric\Desktop\Front_Mission_[T+Eng1.00].zip
2018-11-04 16:41 - 2018-11-04 16:41 - 000000000 ____D C:\Users\Eric\Desktop\2076.63mb used 11-4-18-1641
2018-11-03 12:51 - 2018-11-04 09:21 - 000220413 _____ C:\Users\Eric\Desktop\fm3.txt
2018-11-02 15:22 - 2018-11-05 12:50 - 000000000 ____D C:\Users\Eric\Desktop\EPSXE
2018-10-31 14:11 - 2018-10-31 14:11 - 000000000 ____D C:\Users\Eric\jagexcache
2018-10-31 14:10 - 2018-10-31 14:11 - 000000000 ____D C:\Users\Eric\.runelite
2018-10-29 14:44 - 2018-10-29 14:44 - 000008720 _____ C:\Users\Eric\Desktop\New Text Document.txt
2018-10-29 07:06 - 2018-11-05 12:29 - 000000000 ____D C:\Users\Eric\AppData\LocalLow\uTorrent
2018-10-25 12:25 - 2018-10-25 15:34 - 000000000 ____D C:\Users\Eric\AppData\Local\visualboyadvance-m
2018-10-25 12:24 - 2018-03-14 11:50 - 017184052 _____ (hxxp://vba-m.com/) C:\Users\Eric\Desktop\visualboyadvance-m.exe
2018-10-25 12:24 - 2018-03-14 11:50 - 000008406 _____ C:\Users\Eric\Desktop\vba-over.ini
2018-10-25 12:21 - 2018-11-05 11:00 - 000000428 _____ C:\Windows\Tasks\ScpUpdater.job
2018-10-25 12:21 - 2018-10-25 12:21 - 000002988 _____ C:\Windows\System32\Tasks\ScpUpdater
2018-10-25 12:21 - 2018-10-25 12:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScpToolkit
2018-10-25 06:05 - 2018-10-25 06:05 - 000001067 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1964.lnk
2018-10-25 06:05 - 2018-10-25 06:05 - 000000000 ____D C:\Program Files (x86)\1964
2018-10-20 22:47 - 2018-10-29 14:33 - 000000000 ____D C:\Users\Eric\AppData\Local\gtk-2.0
2018-10-20 22:27 - 2018-11-05 12:52 - 000000000 ____D C:\Users\Eric\AppData\Local\babl-0.1
2018-10-20 22:27 - 2018-10-29 14:36 - 000000945 _____ C:\Users\Public\Desktop\GIMP 2.10.6.lnk
2018-10-20 22:27 - 2018-10-20 22:27 - 000000913 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.10.6.lnk
2018-10-20 22:27 - 2018-10-20 22:27 - 000000000 ____D C:\Users\Eric\AppData\Roaming\GIMP
2018-10-20 22:27 - 2018-10-20 22:27 - 000000000 ____D C:\Users\Eric\AppData\Local\GIMP
2018-10-20 22:27 - 2018-10-20 22:27 - 000000000 ____D C:\Users\Eric\AppData\Local\gegl-0.4
2018-10-20 22:26 - 2018-10-20 22:28 - 000000000 ____D C:\Program Files\GIMP 2
2018-10-20 17:40 - 2018-10-25 12:15 - 000000000 ____D C:\ProgramData\RedFox
2018-10-20 17:40 - 2018-10-20 17:40 - 000000000 ____D C:\Program Files (x86)\RedFox
2018-10-13 12:57 - 2018-10-13 13:01 - 000000000 ____D C:\StarCraft
2018-10-12 23:27 - 2018-10-12 23:38 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2018-10-07 15:07 - 2018-10-25 12:16 - 000000000 ____D C:\Windows\system32\appmgmt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-11-05 13:02 - 2018-09-07 14:08 - 000000000 ____D C:\Users\Eric\AppData\LocalLow\Mozilla
2018-11-05 12:34 - 2018-04-16 20:32 - 000004128 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-11-05 12:33 - 2009-07-13 23:45 - 000022768 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-11-05 12:33 - 2009-07-13 23:45 - 000022768 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-11-05 12:30 - 2018-10-04 12:18 - 000000000 ____D C:\Users\Eric\AppData\Roaming\MPC-HC
2018-11-05 12:30 - 2018-03-04 18:44 - 000000000 ____D C:\Users\Eric\AppData\Roaming\uTorrent
2018-11-05 12:30 - 2018-02-24 02:07 - 000000000 ____D C:\Users\Eric\AppData\Local\CrashDumps
2018-11-05 12:30 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2018-11-05 12:29 - 2009-07-14 00:13 - 000781782 _____ C:\Windows\system32\PerfStringBackup.INI
2018-11-05 12:25 - 2018-07-20 21:28 - 000000434 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2018-11-05 12:25 - 2018-04-12 15:14 - 000000000 ____D C:\Program Files\Core Temp
2018-11-05 12:25 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-11-05 12:24 - 2018-02-22 16:37 - 000000000 ____D C:\ProgramData\NVIDIA
2018-11-05 11:11 - 2018-09-07 14:08 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-11-04 21:13 - 2018-04-19 12:58 - 000000000 ____D C:\Program Files (x86)\Steam
2018-11-04 17:45 - 2018-06-10 01:27 - 000000000 ____D C:\Users\Eric\Documents\The Witcher 3
2018-11-01 08:22 - 2018-02-25 14:47 - 000000043 _____ C:\Users\Eric\jagex_cl_oldschool_LIVE.dat
2018-10-31 14:11 - 2018-02-22 16:08 - 000000000 ____D C:\Users\Eric
2018-10-29 14:38 - 2018-05-21 08:47 - 000000000 ____D C:\Program Files (x86)\Google
2018-10-29 14:37 - 2018-02-22 16:45 - 000000000 ____D C:\Users\Eric\AppData\Local\Google
2018-10-23 21:56 - 2018-05-27 06:08 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-10-23 18:52 - 2018-05-27 06:09 - 000000000 ____D C:\Users\Eric\AppData\Local\Battle.net
2018-10-20 06:27 - 2018-05-29 02:07 - 000001078 _____ C:\Users\Public\Desktop\Medivia Online - DirectX.lnk
2018-10-20 06:27 - 2018-04-13 11:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medivia Online
2018-10-20 06:27 - 2018-04-13 11:35 - 000000000 ____D C:\Program Files (x86)\Medivia Online
2018-10-18 07:15 - 2018-02-22 17:13 - 000000000 ____D C:\Users\Eric\AppData\Local\Spotify
2018-10-18 07:15 - 2018-02-22 17:12 - 000000000 ____D C:\Users\Eric\AppData\Roaming\Spotify
2018-10-07 15:06 - 2018-04-19 18:07 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
==================== Files in the root of some directories =======
2018-11-05 12:51 - 2018-11-05 12:51 - 000009333 _____ () C:\Users\Eric\AppData\Local\recently-used.xbel
2018-06-15 09:54 - 2018-09-10 09:35 - 000007609 _____ () C:\Users\Eric\AppData\Local\Resmon.ResmonCfg
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
testsigning: ==> 'testsigning' is set. Check for possible unsigned driver <==== ATTENTION
LastRegBack: 2018-11-04 07:16
==================== End of FRST.txt ============================