Thanks Broni Avast found nothing
Log fileway too long and I didn't post addition.txt yet ?
PART1 Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-06-2019 01
Ran by planetsolid (administrator) on DESKTOP-HPQBIB7 (06-06-2019 21:52:46)
Running from C:\Users\planetsolid\Desktop
Loaded Profiles: planetsolid (Available Profiles: planetsolid)
Platform: Windows 10 Home Version 1803 17134.799 (X64) Language: English (United Kingdom)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.46.60.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19031.17720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Adlice -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe
(EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe
(EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\SpyHunter5.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_767e7683f9ad126c\igfxCUIService.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch_base.inf_amd64_b95c9a044993331b\IntelCpHDCPSvc.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch_base.inf_amd64_b95c9a044993331b\IntelCpHeciSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.46.60.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd) C:\Windows\SysWOW64\Creative.UWPRPCService.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1905.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1905.4-0\NisSrv.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Desktop.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files\TeamViewer\tv_w32.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files\TeamViewer\tv_x64.exe
(WinZip Computing, S.L.) [File not signed] C:\Program Files\WinZip\WzPreloader.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2047744 2017-11-01] (Corel Corporation -> WinZip) [File not signed]
HKLM\...\Run: [WinZip PreLoader] => C:\Program Files\WinZip\WzPreloader.exe [117760 2017-11-01] (WinZip Computing, S.L.) [File not signed]
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [839968 2019-06-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [319520 2018-07-30] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18390912 2019-06-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKU\S-1-5-21-2124791510-613836525-3741084517-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22515488 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\74.0.3729.169\Installer\chrmstp.exe [2019-06-01] (Google LLC -> Google Inc.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {21E4C119-7D78-4611-A67B-7C4E294D8F57} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-06-01] (Google Inc -> Google Inc.)
Task: {224BED63-CD3A-46A6-B042-B6637B425D35} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_192_Plugin.exe [1457208 2019-06-01] (Adobe Inc. -> Adobe)
Task: {34EBB160-7758-46CC-B458-1521122402C2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {37C52427-E63D-410A-B1EA-DD3340FD560F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {63481BEF-F012-472C-A005-6F5126EBBFE9} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [570240 2017-02-14] (Apple Inc. -> Apple Inc.)
Task: {6563A7C1-E2F8-4B64-9657-3A788C5335B2} - System32\Tasks\Microsoft\Windows\RetailDemo\CleanupOfflineContent => {61f77d5e-afe9-400b-a5e6-e9e80fc8e601} C:\Windows\System32\RDXTaskFactory.dll [393728 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
Task: {7B6D6943-C068-48F1-9A02-0DC4E6F543D2} - System32\Tasks\RogueKiller Anti-Malware => C:\Program Files\RogueKiller\RogueKiller64.exe [33971256 2019-05-22] (Adlice -> )
Task: {809D8AE3-55B1-4DFC-A23D-49628B256500} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {AED8C0BF-CE91-4FA5-A18E-E7066524659A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-06-01] (Adobe Inc. -> Adobe)
Task: {BC6FC195-84A1-45E6-A28B-4309C86B23F4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C4143BD1-BDD8-4AA6-83E1-57F4C83800BA} - System32\Tasks\Microsoft\Windows\Setup\SetupCleanupTask => {7C83C056-1D0D-4C8E-A6B0-89E79C213559} C:\WINDOWS\system32\oobe\SetupCleanupTask.dll [181248 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
Task: {CDD726CC-C9AE-4DE0-B4CF-9AE9A368E460} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E9F51089-CD8A-47A2-8124-8673EEEEB36B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [16509040 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {EF229018-15EC-4F65-A30E-7962FCC44D5C} - System32\Tasks\AMHelper => C:\Program Files\Zemana\AntiMalware\AntiMalware.exe [644672 2019-05-23] (Zemana D.O.O. Sarajevo -> Zemana Ltd.)
Task: {F35BB162-8787-49DA-8974-BAFF1226A2CE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-06-01] (Google Inc -> Google Inc.)
Task: {FB6A34A1-A4F1-4AA2-8785-0BDC98ECBC06} - System32\Tasks\AMSkipUAC => C:\Program Files\Zemana\AntiMalware\AntiMalware.exe [644672 2019-05-23] (Zemana D.O.O. Sarajevo -> Zemana Ltd.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{a2ae9d32-59d8-4372-9c60-79b8fcf6afd2}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
FireFox:
========
FF DefaultProfile: a9iv5fd6.default
FF ProfilePath: C:\Users\planetsolid\AppData\Roaming\Mozilla\Firefox\Profiles\a9iv5fd6.default [2019-06-06]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_192.dll [2019-06-01] (Adobe Inc. -> )
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-01-10] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_192.dll [2019-06-01] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2018-06-06] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-08-01] (Google Inc -> Google, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-06-01] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-06-01] (Google Inc -> Google LLC)
Chrome:
=======
CHR Profile: C:\Users\planetsolid\AppData\Local\Google\Chrome\User Data\Default [2019-06-06]
CHR Extension: (Slides) - C:\Users\planetsolid\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-06-01]
CHR Extension: (Docs) - C:\Users\planetsolid\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-06-01]
CHR Extension: (Google Drive) - C:\Users\planetsolid\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-06-01]
CHR Extension: (YouTube) - C:\Users\planetsolid\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-06-01]
CHR Extension: (Sheets) - C:\Users\planetsolid\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-06-01]
CHR Extension: (Google Docs Offline) - C:\Users\planetsolid\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-06-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\planetsolid\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-06-01]
CHR Extension: (Gmail) - C:\Users\planetsolid\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-06-01]
CHR Extension: (Chrome Media Router) - C:\Users\planetsolid\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-01]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
R2 EsgShKernel; C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe [11457840 2019-06-01] (EnigmaSoft Limited -> EnigmaSoft Limited)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [17440 2018-07-30] (Intel® Rapid Storage Technology -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [265824 2018-06-25] (Intel Corporation -> )
R2 RtkAudioUniversalService; C:\WINDOWS\System32\RtkAudUService64.exe [839968 2019-06-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
R2 ShMonitor; C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe [512816 2019-06-01] (EnigmaSoft Limited -> EnigmaSoft Limited)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [11795800 2019-04-15] (TeamViewer GmbH -> TeamViewer GmbH)
R2 UWPService; C:\WINDOWS\SysWOW64\Creative.UWPRPCService.exe [351320 2018-11-13] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\NisSrv.exe [2433136 2019-06-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MsMpEng.exe [109896 2019-06-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3848800 2018-06-25] (Intel Corporation -> Intel® Corporation)
S2 WinZip Compression Smart Monitor Service; "C:\Program Files\WinZip\WinZip Smart Monitor\WinZip Compression Smart Monitor Service.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 amsdk; C:\Windows\system32\drivers\amsdk.sys [232792 2019-06-01] (Zemana D.O.O. Sarajevo -> Copyright 2018.)
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_9b64147bed2d44a1\e1d68x64.sys [567872 2019-06-06] (Intel® INTELND1820 -> Intel Corporation)
R3 EnigmaFileMonDriver; C:\WINDOWS\System32\drivers\EnigmaFileMonDriver.sys [68424 2019-06-04] (EnigmaSoft Limited -> EnigmaSoft Limited)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
R0 iaStorAC; C:\WINDOWS\System32\drivers\iaStorAC.sys [1017200 2019-06-06] (Intel® Rapid Storage Technology -> Intel Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [199768 2019-06-04] (Malwarebytes Corporation -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-02-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [127136 2019-06-04] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73912 2019-06-04] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [275232 2019-06-04] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [117344 2019-06-04] (Malwarebytes Corporation -> Malwarebytes)
R3 MBfilt; C:\WINDOWS\system32\drivers\MBfilt64.sys [34896 2018-12-10] (WDKTestCert ctl_avpbuild,131450919658074287 -> Creative Technology Ltd.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1141752 2019-06-06] (Realtek Semiconductor Corp. -> Realtek )
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [28272 2019-06-04] (Adlice -> )
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [47496 2019-06-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [337632 2019-06-01] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2019-06-01] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49896 2019-06-06] (Microsoft Corporation -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-06-06 21:52 - 2019-06-06 21:53 - 000022275 _____ C:\Users\planetsolid\Desktop\FRST.txt
2019-06-06 21:52 - 2019-06-06 21:52 - 000000000 ____D C:\FRST
2019-06-06 21:51 - 2019-06-06 21:52 - 002417664 _____ (Farbar) C:\Users\planetsolid\Desktop\FRST64.exe
2019-06-06 21:13 - 2019-06-06 21:13 - 000049896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WirelessKeyboardFilter.sys
2019-06-06 21:13 - 2019-06-06 21:13 - 000000000 ____H C:\ProgramData\DP45977C.lfl
2019-06-06 21:13 - 2019-06-06 21:13 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2019-06-06 21:13 - 2019-06-06 21:13 - 000000000 ____D C:\WINDOWS\system32\DAX3
2019-06-06 21:13 - 2019-06-06 21:13 - 000000000 ____D C:\WINDOWS\system32\DAX2
2019-06-06 21:13 - 2019-06-06 21:13 - 000000000 ____D C:\WINDOWS\LastGood
2019-06-06 21:13 - 2019-06-06 21:13 - 000000000 ____D C:\Program Files\Realtek
2019-06-06 21:13 - 2019-06-06 21:13 - 000000000 _____ C:\WINDOWS\system32\fpfftResultsFile.txt
2019-06-06 21:12 - 2019-06-06 21:13 - 000487360 _____ (Harman International Industries, Incorporated.) C:\WINDOWS\system32\HarmanAPOUI64.dll
2019-06-06 21:12 - 2019-06-06 21:12 - 001610848 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOv251gm.dll
2019-06-06 21:12 - 2019-06-06 21:12 - 001596296 _____ (Harman International Industries, Incorporated.) C:\WINDOWS\system32\HarmanAPO64.dll
2019-06-06 21:12 - 2019-06-06 21:12 - 001287496 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOvlldpgm.dll
2019-06-06 21:09 - 2019-06-06 21:09 - 001544144 _____ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOProp.dll
2019-06-06 21:09 - 2019-06-06 21:09 - 001372280 _____ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOv251.dll
2019-06-06 21:09 - 2019-06-06 21:09 - 001259832 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOvlldp.dll
2019-06-06 21:09 - 2019-06-06 21:09 - 000406560 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2APIPCLL.dll
2019-06-06 21:08 - 2019-06-06 21:09 - 000154256 _____ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll
2019-06-06 21:08 - 2019-06-06 21:08 - 000416400 _____ (Harman) C:\WINDOWS\system32\HMUI.dll
2019-06-06 21:08 - 2019-06-06 21:08 - 000366224 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll
2019-06-06 21:08 - 2019-06-06 21:08 - 000360448 _____ (Harman) C:\WINDOWS\system32\HMClariFi.dll
2019-06-06 21:08 - 2019-06-06 21:08 - 000203944 _____ (Harman) C:\WINDOWS\system32\HMHVS.dll
2019-06-06 21:08 - 2019-06-06 21:08 - 000191040 _____ (Harman) C:\WINDOWS\system32\HMEQ.dll
2019-06-06 21:08 - 2019-06-06 21:08 - 000191032 _____ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll
2019-06-06 21:08 - 2019-06-06 21:08 - 000179728 _____ (Harman) C:\WINDOWS\system32\HMLimiter.dll
2019-06-06 21:05 - 2019-06-06 21:05 - 001159080 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2019-06-06 21:05 - 2019-06-06 21:05 - 000378280 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2019-06-06 21:04 - 2019-06-06 21:05 - 005347096 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
2019-06-06 21:03 - 2019-06-06 21:04 - 002444576 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
2019-06-06 21:03 - 2019-06-06 21:03 - 001180416 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
2019-06-06 21:03 - 2019-06-06 21:03 - 001073560 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll
2019-06-06 21:03 - 2019-06-06 21:03 - 001027720 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll
2019-06-06 21:02 - 2019-06-06 21:03 - 001318744 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll
2019-06-06 21:02 - 2019-06-06 21:02 - 001396056 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
2019-06-06 21:02 - 2019-06-06 21:02 - 001282448 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
2019-06-06 21:02 - 2019-06-06 21:02 - 000604688 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll
2019-06-06 21:00 - 2019-06-06 21:02 - 006270088 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
2019-06-06 21:00 - 2019-06-06 21:00 - 001965048 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
2019-06-06 21:00 - 2019-06-06 21:00 - 000367504 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
2019-06-06 21:00 - 2019-06-06 21:00 - 000315872 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
2019-06-06 20:59 - 2019-06-06 21:00 - 003336384 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2019-06-06 20:59 - 2019-06-06 20:59 - 001435248 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
2019-06-06 20:59 - 2019-06-06 20:59 - 000467264 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
2019-06-06 20:59 - 2019-06-06 20:59 - 000381512 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
2019-06-06 20:59 - 2019-06-06 20:59 - 000341256 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
2019-06-06 20:59 - 2019-06-06 20:59 - 000341256 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
2019-06-06 20:58 - 2019-06-06 20:58 - 003306920 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
2019-06-06 20:57 - 2019-06-06 20:58 - 002198080 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
2019-06-06 20:56 - 2019-06-06 20:57 - 007101640 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2019-06-06 20:56 - 2019-06-06 20:56 - 000332904 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2019-06-06 20:55 - 2019-06-06 20:56 - 001971264 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2019-06-06 20:55 - 2019-06-06 20:55 - 001337536 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll
2019-06-06 20:55 - 2019-06-06 20:55 - 000692264 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2019-06-06 20:55 - 2019-06-06 20:55 - 000447072 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll
2019-06-06 20:55 - 2019-06-06 20:55 - 000278168 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2019-06-06 20:55 - 2019-06-06 20:55 - 000118488 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2019-06-06 20:55 - 2019-06-06 20:55 - 000105200 _____ C:\WINDOWS\system32\audioLibVc.dll
2019-06-06 20:54 - 2019-06-06 20:55 - 000852032 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll
2019-06-06 20:54 - 2019-06-06 20:54 - 000122216 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2019-06-06 20:52 - 2019-06-06 20:53 - 003168488 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
2019-06-06 20:51 - 2019-06-06 20:52 - 003445640 _____ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll
2019-06-06 20:51 - 2019-06-06 20:51 - 001110072 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
2019-06-06 20:51 - 2019-06-06 20:51 - 000266448 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
2019-06-06 20:45 - 2019-06-06 20:51 - 029186050 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2019-06-06 20:45 - 2019-06-06 20:45 - 001382128 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
2019-06-06 20:45 - 2019-06-06 20:45 - 000873568 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
2019-06-06 20:45 - 2019-06-06 20:45 - 000158800 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
2019-06-06 20:45 - 2019-06-06 20:45 - 000075432 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
2019-06-06 20:39 - 2019-06-06 20:39 - 000139856 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2019-06-06 20:38 - 2019-06-06 20:39 - 007178360 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2019-06-06 20:38 - 2019-06-06 20:38 - 000453376 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2019-06-06 20:38 - 2019-06-06 20:38 - 000157448 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2019-06-06 20:38 - 2019-06-06 20:38 - 000090272 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2019-06-06 20:37 - 2019-06-06 20:38 - 000964920 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2019-06-06 20:37 - 2019-06-06 20:37 - 001516368 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2019-06-06 20:37 - 2019-06-06 20:37 - 000751408 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2019-06-06 20:37 - 2019-06-06 20:37 - 000734880 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2019-06-06 20:37 - 2019-06-06 20:37 - 000452840 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2019-06-06 20:37 - 2019-06-06 20:37 - 000448712 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2019-06-06 20:36 - 2019-06-06 20:37 - 001598504 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2019-06-06 20:36 - 2019-06-06 20:36 - 001788064 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2019-06-06 20:36 - 2019-06-06 20:36 - 000715752 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2019-06-06 20:36 - 2019-06-06 20:36 - 000511744 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2019-06-06 20:36 - 2019-06-06 20:36 - 000261304 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2019-06-06 20:36 - 2019-06-06 20:36 - 000260320 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2019-06-06 20:35 - 2019-06-06 20:36 - 000261344 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000392976 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000343808 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000327376 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000327376 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000231808 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000220488 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000116648 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000094032 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000090808 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000088216 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2019-06-06 20:35 - 2019-06-06 20:35 - 000083520 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2019-06-06 20:34 - 2019-06-06 20:34 - 003340512 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2019-06-06 20:34 - 2019-06-06 20:34 - 001353424 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2019-06-06 20:34 - 2019-06-06 20:34 - 000218376 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2019-06-06 20:33 - 2019-06-06 20:34 - 000230808 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll