mykiger.com
Page 1 of 2 12 LastLast
Results 1 to 15 of 16

Thread: mykiger.com

  1. #1
    Join Date
    Aug 2019
    Posts
    11

    mykiger.com

    well i screwed up and loaded this crap on my pc windows 10.

    pop ups that seem to be based around mykiger.com

    any help for removal appreciated.

  2. #2
    Join Date
    Jul 1998
    Location
    Toronto
    Posts
    25,456
    Welcome to VirtualDr. Pls read this sticky at the top of the forum and then copy the results below.

    https://discussions.virtualdr.com/sh...ted-3-21-2015)

    VirtualDr email notices are not working.
    Check back regularly for responses.

    _____________________
    cat lovers click here

  3. #3
    Join Date
    Aug 2019
    Posts
    11
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-12-2021
    Ran by wparr (administrator) on MEDIA-CENTER (14-12-2021 08:53:58)
    Running from C:\Users\wparr\Downloads
    Loaded Profiles: wparr
    Platform: Microsoft Windows 10 Pro Version 20H2 19042.1387 (X64) Language: English (United States)
    Default browser: Edge
    Boot Mode: Normal

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe
    (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed] C:\Program Files (x86)\WinTV\TVServer\CaptureGenPCI.exe <4>
    (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed] C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe
    (MEDIATEK INC. -> Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe
    (MEDIATEK INC. -> Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <19>
    (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
    (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCopyAccelerator.exe
    (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe
    (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe
    (Mudhook Marketing, Inc. -> Mudhook Marketing, Inc) C:\Program Files\IPVanish VPN\IPVanish.exe
    (NETGEAR TAIWAN CO., LTD -> ) C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
    (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
    (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
    (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe

    ==================== Registry (Whitelisted) ===================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [339000 2021-10-26] (Apple Inc. -> Apple Inc.)
    HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5388128 2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [11224432 2021-12-13] (Support.com Inc -> SUPERAntiSpyware)
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\Run: [Discord] => C:\Users\wparr\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\Policies\Explorer: [NoPreviewPane] 0
    HKLM\...\Print\Monitors\HP DC11 Status Monitor: C:\WINDOWS\system32\hpinkstsDC11LM.dll [391984 2019-03-15] (HP Inc -> HP Inc.)
    HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\96.0.4664.93\Installer\chrmstp.exe [2021-12-09] (Google LLC -> Google LLC)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoStart IR.lnk [2019-02-27]
    ShortcutTarget: AutoStart IR.lnk -> C:\Program Files (x86)\WinTV\Ir.exe (Hauppauge Computer Works Inc. -> Hauppauge Computer Works) [File not signed]
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Mediatek Wireless Utility.lnk [2019-06-07]
    ShortcutTarget: Mediatek Wireless Utility.lnk -> C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe (MEDIATEK INC. -> Mediatek Inc.) [File not signed]
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinTV Recording Status.lnk [2019-02-27]
    ShortcutTarget: WinTV Recording Status.lnk -> C:\Program Files (x86)\WinTV\WinTV8\WinTVTray.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

    ==================== Scheduled Tasks (Whitelisted) ============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {01420282-1D7D-46DC-A5BE-4A8AAF397A3E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18227896 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
    Task: {0C6D2CBE-0927-4900-B371-69BFE5820F6A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1562376 2021-08-16] (Adobe Inc. -> Adobe Inc.)
    Task: {0D74D4B4-1E35-4D2B-8C74-FD4B9A3DCDF3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8386448 2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Task: {131F040D-0055-4B8D-AA7A-9B2221D1D51D} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\wparr\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [19989464 2021-12-12] (ESET, spol. s r.o. -> ESET)
    Task: {252B13E4-C8FD-4B55-A895-B60932A83EA8} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [139656 2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Task: {4625F88E-5879-4529-8211-959BB8392F55} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\wparr\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [19989464 2021-12-12] (ESET, spol. s r.o. -> ESET)
    Task: {5F6B92C3-3E79-4DB4-8FFC-EFA08B1D7ABA} - System32\Tasks\Western Digital\SmartWare\____Volume_7096e00b_0000_0000_0000_602200000000__uuid_73656761_7465_7375_636b_0090a942a598_SmartWare_ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [59232 2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    Task: {65287B98-BBAD-4051-B316-3F52D5AA31E4} - System32\Tasks\IPVanish => C:\Program Files\IPVanish VPN\IPVanish.exe [2530896 2021-07-06] (Mudhook Marketing, Inc. -> Mudhook Marketing, Inc)
    Task: {92D61871-AC58-4F2D-A003-8F0C58EFDAE7} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1706496 2020-05-15] () [File not signed]
    Task: {97081292-368E-46BF-BC7A-00FDAC936220} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8386448 2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Task: {9AA5AA82-F0F6-435C-8036-AABFB1A50122} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {AACAD0A0-FDB7-430F-8C4B-4B5A0321AED2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-26] (Google Inc -> Google Inc.)
    Task: {ABF782D3-FE83-4386-8F2E-F988F148F47C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
    Task: {B2CF477D-F178-4434-BF7B-010873E12AF2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {BAA6FF00-72A3-45B5-B33C-F22BBBA81FB1} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [139656 2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Task: {BC936AC3-FBFA-4D23-B87C-324A5E6D95B6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22799320 2021-12-02] (Microsoft Corporation -> Microsoft Corporation)
    Task: {BE9A53FE-1BF4-4D80-951D-9DD8CDED2406} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {D16540FA-DB2B-48D5-B92D-4CC3B47F4CF8} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
    Task: {EF63D73F-80E2-498E-BDCA-110BF8E354E7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {EFBFE77A-1FCA-49B4-813E-F8945639A777} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-26] (Google Inc -> Google Inc.)
    Task: {F3462AB0-B30C-4E21-8187-0E32A082315B} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22799320 2021-12-02] (Microsoft Corporation -> Microsoft Corporation)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\..\Interfaces\{1152BD5F-9A35-4F04-A2A4-07241DA62761}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{1152BD5F-9A35-4F04-A2A4-07241DA62761}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{15a374f3-56f9-4681-8bad-935ac6461374}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{15a374f3-56f9-4681-8bad-935ac6461374}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{2044b21d-77b2-406b-b2b9-9e1eb5c24313}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{2C92F934-C975-4458-B8B2-9A971FE5DF96}: [NameServer] 10.222.0.1
    Tcpip\..\Interfaces\{3A0E2406-5D9F-4FF6-9D51-683D09A5AE8B}: [DhcpNameServer] 10.0.1.1
    Tcpip\..\Interfaces\{49461da5-c956-4c85-88d1-e43824c15ee1}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{49BB631A-0F6B-4336-867B-2119EEF1EC46}: [DhcpNameServer] 10.0.1.1
    Tcpip\..\Interfaces\{6f84f292-ee91-46b4-b728-c4c7107c89cc}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{6f84f292-ee91-46b4-b728-c4c7107c89cc}: [DhcpNameServer] 192.168.254.254
    Tcpip\..\Interfaces\{a02414b0-bda5-4b1b-a208-b6d407c8c575}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{a02414b0-bda5-4b1b-a208-b6d407c8c575}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{a2b6ad52-3a16-11e9-b8b6-806e6f6e6963}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{b5ab89d6-dd66-408f-902e-08d8704c4aa1}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{C2A40734-BB65-4CD1-8F6D-11109F97EE90}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{C2A40734-BB65-4CD1-8F6D-11109F97EE90}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{d55f0245-7af0-4ee1-9c88-c0bcce1619bd}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{D905D5CD-3FC2-4DF5-A7F7-3F6011FD28F9}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{D905D5CD-3FC2-4DF5-A7F7-3F6011FD28F9}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{da70202c-a9ca-40b2-a1b6-0c837fd005da}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{DE056950-DE94-475C-94D8-DECFDD855DC6}: [NameServer] 198.18.0.1 198.18.0.2
    Tcpip\..\Interfaces\{F4BD3271-021F-4471-B209-CE94E1792D2D}: [DhcpNameServer] 10.0.1.1
    Tcpip\..\Interfaces\{f563c0ee-d36f-4ba3-a36c-a18f13d54162}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{f563c0ee-d36f-4ba3-a36c-a18f13d54162}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{FE76A9A7-5E92-4B8F-AA5A-AA4EFD8ACE8F}: [DhcpNameServer] 10.0.1.1

    Edge:
    =======
    DownloadDir: C:\Users\wparr\Downloads
    Edge HomeButtonPage: HKU\S-1-5-21-3399867593-3550638609-2408602673-1001 -> hxxp://www.google.com/
    Edge Notifications: HKU\S-1-5-21-3399867593-3550638609-2408602673-1001 -> hxxps://notification-list.com; hxxps://topflownews.com; hxxps://www2.thefastpush.com
    Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
    Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
    Edge Extension: (No Name) -> hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.48.0.0_neutral__qq0fmhteeht3j [not found]
    Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
    Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
    Edge DefaultProfile: Default
    Edge Profile: C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default [2021-12-14]
    Edge DownloadDir: Default -> C:\Users\wparr\Downloads
    Edge Notifications: Default -> hxxps://apsolutamente.com
    Edge HomePage: Default -> hxxp://www.google.com/
    Edge StartupUrls: Default -> "hxxp://www.google.com/","hxxps://google.com/"
    Edge DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
    Edge DefaultSearchKeyword: Default -> duckduckgo.com
    Edge DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
    Edge Extension: (LastPass: Free Password Manager) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bbcinlkgjjkejfdpemiealijmmooekmp [2021-12-13]
    Edge Extension: (DuckDuckGo) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caoacbimdbbljakfhgikoodekdnlcgpk [2021-12-11]
    Edge Extension: (ExpressVPN: VPN proxy for a better internet) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fgddmllnllkalaagkghckoinaemmogpe [2021-12-11]
    Edge Extension: (Capital One Shopping: Add to Edge for Free) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kiiaghlmeikbpmeabhilfphikfcefljn [2021-12-13]
    Edge Extension: (TubeBuddy) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mhkhmbddkmdggbhaaaodilponhnccicb [2021-12-14]
    Edge Extension: (Show Apps in new tab) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nohbdifokmdgjcbbeobglcbaifinhfip [2021-12-11]

    FireFox:
    ========
    FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google Inc -> Google, Inc.)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-10-05] (Adobe Inc. -> Adobe Systems Inc.)

    Chrome:
    =======
    CHR DefaultProfile: Default
    CHR Profile: C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default [2021-12-11]
    CHR Notifications: Default -> hxxps://paymentsweb.org
    CHR HomePage: Default -> hxxp://www.google.com/ig
    CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxp://www.google.com","hxxp://www.google.com/"
    CHR NewTab: Default -> Not-active:"chrome-extension://nohbdifokmdgjcbbeobglcbaifinhfip/go.html"
    CHR Extension: (Google Drive) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-12-11]
    CHR Extension: (Ledger Manager) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\beimhnaefocolcplfimocfiaiefpkgbf [2019-02-26]
    CHR Extension: (TV) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2019-03-07]
    CHR Extension: (YouTube) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-02-26]
    CHR Extension: (Adobe Acrobat) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2021-12-11]
    CHR Extension: (ExpressVPN: VPN proxy for a better internet) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgddmllnllkalaagkghckoinaemmogpe [2021-12-11]
    CHR Extension: (Chrome Remote Desktop) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-26]
    CHR Extension: (The Economist) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebjgjhbjedcomcajgpodjgfjgkepgpl [2019-02-26]
    CHR Extension: (LastPass: Free Password Manager) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2021-12-11]
    CHR Extension: (Ledger Wallet Ethereum) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmlhkialjkaldndjnlcdfdphcgeadkkm [2019-07-26]
    CHR Extension: (The Weather Channel for Chrome) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\iflpcokdamgefbghpdipcibmhlkdopop [2019-03-07]
    CHR Extension: (Chrome Remote Desktop) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2019-11-20]
    CHR Extension: (Roomstyler 3D planner) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfnniehafojoidolddmhfnpnbiolbppi [2019-02-26]
    CHR Extension: (Ledger Wallet Bitcoin) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkdpmhnladdopljabkgpacgpliggeeaf [2019-02-26]
    CHR Extension: (Google Maps) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2019-02-26]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-12-11]
    CHR Extension: (Ultimate Mp3 Music Search) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pddlnfginfgejmncfhgljdddjlhhedmp [2019-02-26]
    CHR Extension: (Gmail) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-12-11]
    CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

    ==================== Services (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-30] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
    R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.)
    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [99104 2021-08-20] (Apple Inc. -> Apple Inc.)
    S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (Shanghai Comet Network Technology -> www.BitComet.com)
    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12129160 2021-12-02] (Microsoft Corporation -> Microsoft Corporation)
    R2 HauppaugeTVServer; C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [594216 2019-02-14] (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [7901368 2021-12-11] (Malwarebytes Inc -> Malwarebytes)
    R2 MediatekRegistryWriter; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe [405136 2014-12-04] (MEDIATEK INC. -> Mediatek Inc.)
    R2 MediatekRegistryWriter64; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe [454288 2014-12-04] (MEDIATEK INC. -> Mediatek Inc.)
    S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6136520 2021-12-10] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [668808 2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [363888 2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe [2872024 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe [128376 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WSWNDA3100v2; C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [316128 2014-12-23] (NETGEAR TAIWAN CO., LTD -> )

    ===================== Drivers (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 HCW85BDA; C:\WINDOWS\system32\drivers\HCW85BDA.sys [2268008 2018-10-05] (Hauppauge Computer Works Inc. -> Hauppauge Computer Works)
    R3 hcw85cir; C:\WINDOWS\system32\drivers\hcw85cir4.sys [79720 2018-10-05] (Hauppauge Computer Works Inc. -> Hauppauge Computer Works, Inc.)
    S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-06-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
    S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-12-11] (Malwarebytes Inc -> Malwarebytes)
    R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] (ASUSTeK Computer Inc. -> )
    S3 NPF; C:\WINDOWS\system32\DRIVERS\npf.sys [47632 2010-02-03] (CACE Technologies, Inc. -> CACE Technologies, Inc.)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R0 SCMNdisP; C:\WINDOWS\System32\DRIVERS\scmndisp.sys [25312 2007-01-19] (NETGEAR -> Windows (R) Codename Longhorn DDK provider)
    S3 TKCtrl; C:\WINDOWS\system32\TKCtrl2k64.sys [147240 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKFsAvM; C:\WINDOWS\system32\TKFsAv64.sys [198808 2018-03-07] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKFsFtM; C:\WINDOWS\system32\TKFsFt64.sys [28824 2018-03-07] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKPcFt; C:\WINDOWS\system32\TKPcFtCb64.sys [54504 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKRgAc; C:\WINDOWS\system32\TKRgAc2k64.sys [115760 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKRgFt; C:\WINDOWS\system32\TKRgFtXp64.sys [68848 2018-02-04] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKSP; C:\WINDOWS\system32\TKSPxp64.sys [80824 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48520 2021-12-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
    S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2018-05-23] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
    R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [435424 2021-12-09] (Microsoft Windows -> Microsoft Corporation)
    R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-12-09] (Microsoft Windows -> Microsoft Corporation)
    R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2019-03-12] (Zemana Ltd. -> Zemana Ltd.)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One month (created) (Whitelisted) =========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2021-12-14 08:53 - 2021-12-14 08:55 - 000026761 _____ C:\Users\wparr\Downloads\FRST.txt
    2021-12-14 08:53 - 2021-12-14 08:54 - 000000000 ____D C:\FRST
    2021-12-14 08:53 - 2021-12-14 08:53 - 002311168 _____ (Farbar) C:\Users\wparr\Downloads\FRST64 (1).exe
    2021-12-14 08:52 - 2021-12-14 08:52 - 002311168 _____ (Farbar) C:\Users\wparr\Downloads\Unconfirmed 108652.crdownload
    2021-12-14 08:09 - 2021-12-14 08:09 - 003594016 _____ (RCS LT) C:\Users\wparr\Downloads\CCSetup.exe
    2021-12-13 20:49 - 2021-12-14 07:51 - 000000000 ____D C:\Program Files\Trojan Killer
    2021-12-13 20:49 - 2021-12-13 20:49 - 000001774 _____ C:\Users\Public\Desktop\Reset Browser Settings.lnk
    2021-12-13 20:49 - 2021-12-13 20:49 - 000000900 _____ C:\Users\Public\Desktop\Trojan Killer.lnk
    2021-12-13 20:48 - 2021-12-13 20:48 - 001207208 _____ (Gridinsoft LLC) C:\Users\wparr\Downloads\TKSetup.exe
    2021-12-13 20:48 - 2021-12-13 20:48 - 001207208 _____ (Gridinsoft LLC) C:\Users\wparr\Downloads\TKSetup (1).exe
    2021-12-13 18:02 - 2021-12-13 18:02 - 000003852 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
    2021-12-13 18:02 - 2021-12-13 18:02 - 000003410 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
    2021-12-12 21:38 - 2021-12-12 21:38 - 013311448 _____ (ESET) C:\Users\wparr\Downloads\esetonlinescanner.exe
    2021-12-12 21:38 - 2021-12-12 21:38 - 000001424 _____ C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
    2021-12-12 21:38 - 2021-12-12 21:38 - 000001318 _____ C:\Users\wparr\Desktop\ESET Online Scanner.lnk
    2021-12-12 21:38 - 2021-12-12 21:38 - 000000000 ____D C:\Users\wparr\AppData\Local\ESET
    2021-12-12 15:48 - 2021-12-12 15:48 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3399867593-3550638609-2408602673-1001
    2021-12-11 20:58 - 2021-12-11 20:58 - 008540344 _____ (Malwarebytes) C:\Users\wparr\Desktop\adwcleaner_8.3.1.exe
    2021-12-11 16:30 - 2021-12-11 16:30 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
    2021-12-10 10:37 - 2021-12-10 10:37 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
    2021-12-10 10:37 - 2021-12-10 10:37 - 000011785 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
    2021-12-10 10:25 - 2021-12-10 10:25 - 000000000 ___HD C:\$WinREAgent
    2021-12-09 17:46 - 2021-12-09 17:46 - 000203264 _____ C:\WINDOWS\system32\uwfcfgmgmt.dll
    2021-12-09 17:46 - 2021-12-09 17:46 - 000170496 _____ C:\WINDOWS\system32\DeviceUpdateCenterCsp.dll
    2021-12-09 17:46 - 2021-12-09 17:46 - 000158208 _____ C:\WINDOWS\system32\uwfcsp.dll
    2021-12-09 17:46 - 2021-12-09 17:46 - 000040960 _____ C:\WINDOWS\system32\uwfservicingapi.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 002295296 _____ (Digimarc) C:\WINDOWS\system32\DMRCDecoder.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 002111488 _____ (Digimarc) C:\WINDOWS\SysWOW64\DMRCDecoder.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 001164288 _____ C:\WINDOWS\system32\MBR2GPT.EXE
    2021-12-09 17:45 - 2021-12-09 17:45 - 000672768 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 000611960 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
    2021-12-09 17:45 - 2021-12-09 17:45 - 000098304 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
    2021-12-09 17:45 - 2021-12-09 17:45 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
    2021-12-09 17:44 - 2021-12-09 17:44 - 000706536 _____ C:\WINDOWS\system32\TextShaping.dll
    2021-12-09 17:44 - 2021-12-09 17:44 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
    2021-12-09 17:44 - 2021-12-09 17:44 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
    2021-12-09 15:13 - 2021-12-09 15:13 - 000001816 _____ C:\Users\Public\Desktop\iTunes.lnk
    2021-12-09 15:13 - 2021-12-09 15:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2021-12-09 15:13 - 2021-12-09 15:13 - 000000000 ____D C:\Program Files\iTunes
    2021-12-09 15:01 - 2021-12-09 15:01 - 000001146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
    2021-12-09 15:01 - 2021-12-09 15:01 - 000000000 ____D C:\Program Files\PCHealthCheck

    ==================== One month (modified) ==================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2021-12-14 08:55 - 2019-03-12 12:38 - 000056437 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
    2021-12-14 08:52 - 2019-02-26 15:25 - 000000000 ____D C:\Program Files (x86)\Google
    2021-12-14 08:50 - 2020-07-15 17:31 - 000008192 _____ C:\WINDOWS\SysWOW64\WDPABKP.dat
    2021-12-14 08:50 - 2020-07-11 06:56 - 000000000 ____D C:\Users\wparr\AppData\Local\IPVanish
    2021-12-14 08:50 - 2019-02-27 07:03 - 000000000 ____D C:\ProgramData\Hauppauge
    2021-12-14 08:49 - 2020-06-04 16:20 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2021-12-14 08:49 - 2020-06-04 16:11 - 000008192 ___SH C:\DumpStack.log.tmp
    2021-12-14 08:49 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2021-12-14 08:49 - 2019-12-07 04:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
    2021-12-14 08:49 - 2019-02-26 14:53 - 000000000 ____D C:\ProgramData\NVIDIA
    2021-12-14 08:48 - 2019-03-13 13:48 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2021-12-14 07:56 - 2020-06-04 16:14 - 001390218 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2021-12-14 07:56 - 2020-06-04 12:24 - 000426112 _____ C:\WINDOWS\system32\prfh0804.dat
    2021-12-14 07:56 - 2020-06-04 12:24 - 000132670 _____ C:\WINDOWS\system32\prfc0804.dat
    2021-12-14 07:56 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF
    2021-12-14 07:49 - 2020-06-04 16:11 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2021-12-14 07:49 - 2019-02-26 17:16 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
    2021-12-14 05:13 - 2020-06-04 16:20 - 000004168 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{E40FD7B8-2283-43B4-8DF9-946CEF68E72E}
    2021-12-13 22:40 - 2020-06-03 16:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet (64-bit)
    2021-12-13 22:40 - 2019-02-26 16:36 - 000000000 ____D C:\Program Files\BitComet
    2021-12-13 20:41 - 2020-07-01 11:28 - 000000000 ____D C:\Program Files (x86)\MuldeR
    2021-12-13 20:39 - 2019-02-26 15:49 - 000001079 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
    2021-12-13 20:39 - 2019-02-26 15:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
    2021-12-13 18:58 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
    2021-12-13 18:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness
    2021-12-13 18:03 - 2019-02-26 16:36 - 000000000 ____D C:\Users\wparr\AppData\Roaming\BitComet
    2021-12-12 21:38 - 2019-11-24 14:39 - 000000000 ____D C:\Users\wparr\AppData\Local\CrashDumps
    2021-12-12 15:48 - 2021-03-04 16:28 - 000002425 _____ C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2021-12-12 15:48 - 2020-06-04 16:20 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3399867593-3550638609-2408602673-1001
    2021-12-11 23:22 - 2019-03-01 17:27 - 000000000 ____D C:\Users\wparr\AppData\Roaming\vlc
    2021-12-11 16:30 - 2020-06-27 11:39 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
    2021-12-11 16:30 - 2019-08-02 09:15 - 000160176 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
    2021-12-11 16:30 - 2019-08-02 09:15 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2021-12-11 16:29 - 2019-02-26 16:00 - 000000000 ____D C:\ProgramData\Malwarebytes
    2021-12-11 16:29 - 2019-02-26 16:00 - 000000000 ____D C:\Program Files\Malwarebytes
    2021-12-11 16:07 - 2019-02-26 17:03 - 000000000 ____D C:\Users\wparr\AppData\Local\D3DSCache
    2021-12-11 14:57 - 2020-06-04 20:53 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
    2021-12-11 14:57 - 2020-06-04 20:53 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
    2021-12-10 21:05 - 2020-06-04 20:53 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
    2021-12-10 21:05 - 2020-06-04 20:53 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
    2021-12-10 16:36 - 2019-02-26 15:19 - 000000000 ____D C:\Users\wparr\AppData\Roaming\MusicBee
    2021-12-10 16:28 - 2019-04-01 07:46 - 000000000 ____D C:\Users\wparr\Downloads\incomplete
    2021-12-10 16:27 - 2018-08-24 14:02 - 000000000 ____D C:\Users\wparr\Documents\Bill
    2021-12-10 16:24 - 2018-08-24 14:02 - 000000000 ____D C:\Users\wparr\Documents\Ryan
    2021-12-10 10:52 - 2020-06-04 16:11 - 000486384 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2021-12-10 10:51 - 2019-12-07 04:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SystemResources
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\oobe
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\Provisioning
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\bcastdvr
    2021-12-10 10:41 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp
    2021-12-10 00:09 - 2019-02-26 17:15 - 000000000 ____D C:\Program Files\CCleaner
    2021-12-10 00:08 - 2019-12-07 04:54 - 000000000 ___SD C:\WINDOWS\system32\AppV
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\setup
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Dism
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellComponents
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\DiagTrack
    2021-12-10 00:08 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\servicing
    2021-12-09 17:32 - 2021-01-22 11:16 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
    2021-12-09 16:40 - 2019-02-26 15:02 - 000000000 ____D C:\ProgramData\Packages
    2021-12-09 16:31 - 2019-02-26 17:34 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
    2021-12-09 15:24 - 2019-02-26 14:45 - 000000000 ____D C:\Users\wparr\AppData\Local\Packages
    2021-12-09 15:15 - 2020-06-04 16:20 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
    2021-12-09 15:15 - 2019-02-26 17:21 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
    2021-12-09 15:13 - 2019-06-11 09:22 - 000000000 ____D C:\Program Files\Microsoft Office
    2021-12-09 15:07 - 2019-02-26 15:26 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2021-12-09 15:07 - 2019-02-26 15:26 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2021-12-09 15:06 - 2019-02-26 15:09 - 000000000 ____D C:\WINDOWS\system32\MRT
    2021-12-09 15:01 - 2019-02-26 15:09 - 141529560 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2021-12-09 15:00 - 2020-06-04 16:20 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
    2021-12-09 15:00 - 2020-06-04 16:20 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
    2021-12-09 15:00 - 2019-02-26 14:49 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe

    ==================== Files in the root of some directories ========

    2019-11-24 11:10 - 2020-10-09 11:31 - 000000128 _____ () C:\Users\wparr\AppData\Local\PUTTY.RND

    ==================== SigCheck ============================

    (There is no automatic fix for files that do not pass verification.)

    ==================== End of FRST.txt ========================

  4. #4
    Join Date
    Aug 2019
    Posts
    11
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-12-2021
    Ran by wparr (14-12-2021 08:56:48)
    Running from C:\Users\wparr\Downloads
    Microsoft Windows 10 Pro Version 20H2 19042.1387 (X64) (2020-06-04 21:20:21)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================


    (If an entry is included in the fixlist, it will be removed.)

    Administrator (S-1-5-21-3399867593-3550638609-2408602673-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-3399867593-3550638609-2408602673-503 - Limited - Disabled)
    Guest (S-1-5-21-3399867593-3550638609-2408602673-501 - Limited - Disabled)
    WDAGUtilityAccount (S-1-5-21-3399867593-3550638609-2408602673-504 - Limited - Disabled)
    wparr (S-1-5-21-3399867593-3550638609-2408602673-1001 - Administrator - Enabled) => C:\Users\wparr

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: TACHYON Internet Security 5.0 (Enabled - Up to date) {7FF5C59B-27F8-CF97-96BE-6B3FAA495547}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    7-Zip 18.05 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1805-000001000000}) (Version: 18.05.00.0 - Igor Pavlov)
    Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 21.007.20099 - Adobe Systems Incorporated)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 32.0.0.125 - Adobe)
    ApowerMirror V1.4.3.5 (HKLM-x32\...\{a9482532-9c34-478c-80c3-85bdccbb981f}_is1) (Version: 1.4.3.5 - APOWERSOFT LIMITED)
    Apowersoft Online Launcher version 1.7.7 (HKLM-x32\...\{20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1) (Version: 1.7.7 - APOWERSOFT LIMITED)
    Apple Application Support (32-bit) (HKLM-x32\...\{9738288C-21BC-4F54-AB4F-72F059339376}) (Version: 8.6 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\...\{DEB339C1-2687-43AB-816A-8714F3E26846}) (Version: 8.6 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{527DD209-8A66-482F-8779-C7B3BACCA8F1}) (Version: 15.0.0.16 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{A3985C05-7386-411F-A4BF-32A73F37EB44}) (Version: 2.6.3.1 - Apple Inc.)
    BitComet 1.67 (HKLM-x32\...\BitComet_x64) (Version: 1.67 - CometNetwork)
    Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
    calibre (HKLM-x32\...\{09CF108A-927D-492C-9D42-54D5F7678096}) (Version: 4.22.0 - Kovid Goyal)
    CCleaner (HKLM\...\CCleaner) (Version: 5.65 - Piriform)
    EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version: - EaseUS)
    EdgeManage (HKLM-x32\...\{535F8180-FCD4-4593-8E21-BF228B216BE3}) (Version: 2.2.8 - Emmet Gray)
    EPUB to MOBI (HKLM-x32\...\{C65AA5AE-8B80-46B6-ADFC-BBF1EFF2AD98}_is1) (Version: - epubtomobi.com)
    FileZilla Client 3.51.0 (HKLM-x32\...\FileZilla Client) (Version: 3.51.0 - Tim Kosse)
    FlacSquisher 1.3.8 (HKLM-x32\...\FlacSquisher) (Version: 1.3.8 - FlacSquisher)
    Free APE to MP3 Converter 1.0 (HKLM-x32\...\{23CAF97E-FC9A-4043-A8B2-3C8605305D35}_is1) (Version: 1.0 - Jacek Pazera)
    Free FLAC to MP3 Converter 1.4 (HKLM-x32\...\{A54C01BD-1277-4722-B42B-EC9800A90B1E}_is1) (Version: 1.4 - PolySoft Solutions)
    Free M4a to MP3 Converter X (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com)
    FreeFileSync 11.4 (HKLM-x32\...\FreeFileSync_is1) (Version: 11.4 - FreeFileSync.org)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 96.0.4664.93 - Google LLC)
    Hauppauge WinTV 8.5 (HKLM-x32\...\Hauppauge WinTV 8.5) (Version: v8.5.37045 - Hauppauge Computer Works)
    IPVanish (HKLM\...\{E293F597-AF63-4D16-B313-EF4054532953}) (Version: 3.6.6.0 - Mudhook Marketing, Inc) Hidden
    IPVanish (HKLM-x32\...\{90e9256e-5d6a-4ca4-834b-a9d1f9014024}) (Version: 3.6.6.0 - Mudhook Marketing, Inc)
    iTunes (HKLM\...\{0B3CC856-3A62-443A-B6CE-DED2D4495D56}) (Version: 12.12.2.2 - Apple Inc.)
    K-Lite Codec Pack 15.4.8 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 15.4.8 - KLCP)
    Malwarebytes version 4.4.11.149 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.4.11.149 - Malwarebytes)
    MediaHuman Audio Converter version 1.9.7 (HKLM-x32\...\MHAudioConverter_is1) (Version: 1.9.7 - MediaHuman)
    Mediatek RT2870 Wireless LAN Card (HKLM-x32\...\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}) (Version: 5.1.28.0 - MediatekWiFi)
    Medieval CUE Splitter (HKLM-x32\...\{B96D2269-568B-4CBF-9332-12FAE8B158F7}) (Version: 1.2.0 - Medieval Software)
    Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 96.0.1054.53 - Microsoft Corporation)
    Microsoft Office Professional Plus 2019 - en-us (HKLM\...\ProPlus2019Retail - en-us) (Version: 16.0.14701.20226 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\OneDriveSetup.exe) (Version: 21.230.1107.0004 - Microsoft Corporation)
    Microsoft Project - en-us (HKLM\...\ProjectPro2019Retail - en-us) (Version: 16.0.14701.20226 - Microsoft Corporation)
    Microsoft Update Health Tools (HKLM\...\{29B15818-E79F-4AB0-8938-9410C807AD76}) (Version: 2.84.0.0 - Microsoft Corporation)
    Microsoft Visio - en-us (HKLM\...\VisioPro2019Retail - en-us) (Version: 16.0.14701.20226 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{4cadd82e-f9f2-4f69-bcfd-a0b929d8e6e2}) (Version: 14.0.23918.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{8a225685-3b19-4387-b61b-830061421071}) (Version: 14.0.23918.0 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
    MusicBee 3.3.7491 (HKLM-x32\...\MusicBee) (Version: 3.3.7491 - Steven Mayall)
    MusicBrainz Picard (HKLM-x32\...\MusicBrainz Picard) (Version: 2.5.6 - MusicBrainz)
    MyHarmony (HKLM-x32\...\{2AD8F8A1-ECE5-4890-BCC2-B4396370A0D4}) (Version: 1.0.308 - Logitech)
    NativeDesktopMediaService (HKLM-x32\...\{4A91D8B3-712F-4815-B29B-E610008C4704}) (Version: 3.6.1 - Jetmedia) <==== ATTENTION
    NETGEAR WNDA3100v2 wireless USB 2.0 driver (HKLM-x32\...\{3C7839E7-21F4-49E0-B4D5-AC8ED818CCB0}) (Version: 2.2.0.6 - NETGEAR)
    NVIDIA Graphics Driver 456.71 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 456.71 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.3.38.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.35 - NVIDIA Corporation)
    Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14701.20226 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14701.20226 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
    paint.net (HKLM\...\{2025DAA7-0653-4F18-B66F-900E6F2320EC}) (Version: 4.2.13 - dotPDN LLC)
    Photo Transfer App (HKLM-x32\...\com.erclab.air.phototransferapp) (Version: 2.8.3 - UNKNOWN)
    Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
    PowerISO (HKLM-x32\...\PowerISO) (Version: 7.5 - Power Software Ltd)
    Revo Uninstaller 2.3.5 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.3.5 - VS Revo Group, Ltd.)
    SABnzbd 3.1.1 (HKLM-x32\...\SABnzbd) (Version: 3.1.1 - The SABnzbd Team)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 8.0.1030 - SUPERAntiSpyware.com)
    Switch Sound File Converter (HKLM-x32\...\Switch) (Version: 5.06 - NCH Software)
    Trojan Killer Portable (HKLM\...\GridinSoft Trojan Killer) (Version: 2.1.98 - Gridinsoft LLC)
    VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.11 - VideoLAN)
    WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 9.16 - NCH Software)
    WD Quick View (HKLM-x32\...\{4EA8640B-DEB6-478F-BDAC-F4BCBEEFAFAB}) (Version: 2.4.21.1 - Western Digital Technologies, Inc.)
    WD SmartWare (HKLM\...\{798354C0-D5F2-4A43-ADEE-3DA9B1725ECC}) (Version: 2.4.21.1 - Western Digital Technologies, Inc.)
    WD SmartWare Installer (HKLM-x32\...\{5be946d0-7ba1-41b6-808a-0e7f2b7cb4a8}) (Version: 2.4.21.1 - Western Digital Technologies, Inc.)
    Windows PC Health Check (HKLM\...\{B1E7D0FD-7CFE-4E0C-A5DA-0F676499DB91}) (Version: 3.2.2110.14001 - Microsoft Corporation)
    WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
    Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.3) (Version: 1.3.7 - Xvid Team)

    Packages:
    =========
    Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.70.2.0_x86__kgqvnymyfvs32 [2021-12-09] (king.com)
    Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.2170.3.0_x86__kgqvnymyfvs32 [2021-12-13] (king.com)
    Cooking Fever -> C:\Program Files\WindowsApps\NORDCURRENT.COOKINGFEVER_13.0.10.0_x86__m9bz608c1b9ra [2021-08-06] (Nordcurrent)
    CUE Splitter -> C:\Program Files\WindowsApps\38812MedievalSoftware.CUESplitter_2.0.8.0_x64__qfb5004rcjhse [2019-06-06] (Medieval Software)
    EZ TV Listings -> C:\Program Files\WindowsApps\32063Envisra.EZTVListings_2.2.0.0_neutral__jyw6djrsfaffg [2019-03-08] (Envisra)
    HEVC Video Extensions -> C:\Program Files\WindowsApps\Microsoft.HEVCVideoExtensions_1.0.42702.0_x64__8wekyb3d8bbwe [2021-12-09] (Microsoft Corporation)
    HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_133.1.340.0_x64__v10z8vjag6ke6 [2021-12-13] (HP Inc.)
    iHeartRadio -> C:\Program Files\WindowsApps\ClearChannelRadioDigital.iHeartRadio_7.2.1.0_x64__a76a11dkgb644 [2021-12-09] (iHeartMedia.)
    LastPass: Free Password Manager -> C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.69.0.0_neutral__qq0fmhteeht3j [2021-08-05] (LastPass)
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-26] (Microsoft Corporation) [MS Ad]
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-26] (Microsoft Corporation) [MS Ad]
    Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.11.12030.0_x64__8wekyb3d8bbwe [2021-12-09] (Microsoft Studios) [MS Ad]
    MusicBee -> C:\Program Files\WindowsApps\50072StevenMayall.MusicBee_3.4.1.0_x86__kcr266et74avj [2021-08-05] (Steven Mayall)
    My MP4 to MP3 Converter -> C:\Program Files\WindowsApps\32573MMSoftware.MyMP4toMP3Converter_1.5.7.0_x64__xky5rpyx4kdm4 [2021-12-09] (M&amp;MSoftware) [MS Ad]
    Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-10-25] (Microsoft Corporation)
    Phototastic Collage -> C:\Program Files\WindowsApps\ThumbmunkeysLtd.PhototasticCollage_3.27.4.0_x64__nfy108tqq3p12 [2021-12-09] (Thumbmunkeys Ltd)

    ==================== Custom CLSID (Whitelisted): ==============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
    ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2019-09-14] (Power Software Limited -> Power Software Ltd)
    ContextMenuHandlers1: [WDBackupMenuHandler] -> {C752BC82-C19A-4827-9C15-0996BA85C180} => C:\Program Files\Western Digital\WD SmartWare\\WDContextMenuHandler.dll [2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers2: [CWDDriveMenuHandler] -> {CCEFA845-DCDB-4A2F-8BED-DBE87CD198EC} => C:\Program Files\Western Digital\WD SmartWare\\WDContextMenuHandler.dll [2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
    ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2019-09-14] (Power Software Limited -> Power Software Ltd)
    ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-10-01] (NVIDIA Corporation -> NVIDIA Corporation)
    ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2019-09-14] (Power Software Limited -> Power Software Ltd)
    ContextMenuHandlers6: [WDBackupMenuHandler] -> {C752BC82-C19A-4827-9C15-0996BA85C180} => C:\Program Files\Western Digital\WD SmartWare\\WDContextMenuHandler.dll [2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)

    ==================== Codecs (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Drivers32: [vidc.XVID] => C:\WINDOWS\system32\xvidvfw.dll [251392 2019-12-28] () [File not signed]
    HKLM\...\Drivers32: [msacm.l3acm] => C:\Windows\SysWOW64\l3codecp.acm [189440 2019-12-07] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
    HKLM\...\Drivers32: [vidc.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [235520 2019-12-28] () [File not signed]

    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)

    Shortcut: C:\Users\wparr\Favorites\NCH Software Download Site.lnk -> hxxp://www.nch.com.au/index.htm
    ShortcutWithArgument: C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
    ShortcutWithArgument: C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ledger Manager.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=beimhnaefocolcplfimocfiaiefpkgbf
    ShortcutWithArgument: C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ledger Wallet Bitcoin.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=kkdpmhnladdopljabkgpacgpliggeeaf
    ShortcutWithArgument: C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ledger Wallet Ethereum.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=hmlhkialjkaldndjnlcdfdphcgeadkkm
    ShortcutWithArgument: C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\The Economist.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=gebjgjhbjedcomcajgpodjgfjgkepgpl

    ==================== Loaded Modules (Whitelisted) =============

    2019-03-13 13:48 - 2015-03-05 17:22 - 000380928 _____ () [File not signed] C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiLib.dll
    2019-02-27 07:13 - 2011-08-23 12:04 - 000057344 _____ () [File not signed] C:\Program Files (x86)\WinTV\TVServer\libhdhomerun.dll
    2019-08-15 17:13 - 2019-08-15 17:13 - 000989184 _____ () [File not signed] C:\Program Files\IPVanish VPN\runtimes\win-x86\native\e_sqlite3.dll
    2019-03-13 13:48 - 2011-06-21 15:04 - 000229376 _____ (Broadcom Corporation) [File not signed] C:\Program Files (x86)\NETGEAR\WNDA3100v2\wps_api.dll
    2019-02-27 07:13 - 2015-11-24 19:59 - 000134656 _____ (Hauppauge Computer Works) [File not signed] C:\Program Files (x86)\WinTV\WinTV8\hcwtsfilter.ax
    2019-02-27 07:13 - 2018-06-12 15:20 - 000113152 _____ (Hauppauge Computer Works) [File not signed] C:\Program Files (x86)\WinTV\WinTV8\HCWTSWriter.ax
    2019-02-27 07:13 - 2018-12-21 11:50 - 000334848 _____ (Hauppauge Computer Works, Inc.) [File not signed] C:\Program Files (x86)\WinTV\WinTV8\PsiParser.ax
    2018-05-23 11:02 - 2018-05-23 11:02 - 001006080 ____R (Robert Simpson, et al.) [File not signed] [File is in use] C:\Program Files (x86)\Western Digital\WD SmartWare\System.Data.SQLite.dll

    ==================== Alternate Data Streams (Whitelisted) ========

    ==================== Safe Mode (Whitelisted) ==================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

    ==================== Association (Whitelisted) =================

    ==================== Internet Explorer (Whitelisted) ==========

    BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)

    ==================== Hosts content: =========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2018-09-15 02:31 - 2018-09-15 02:31 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

    ==================== Other Areas ===========================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
    DNS Servers: 198.18.0.1 - 198.18.0.2
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
    Windows Firewall is enabled.

    Network Binding:
    =============
    Bluetooth Network Connection: General NDIS Protocol Driver -> SCM_NDISPROT (enabled)
    Ethernet: General NDIS Protocol Driver -> SCM_NDISPROT (enabled)

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (If an entry is included in the fixlist, it will be removed.)

    HKLM\...\StartupApproved\StartupFolder: => "Mediatek Wireless Utility.lnk"
    HKLM\...\StartupApproved\StartupFolder: => "AutoStart IR.lnk"
    HKLM\...\StartupApproved\StartupFolder: => "WinTV Recording Status.lnk"
    HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
    HKLM\...\StartupApproved\Run: => "iTunesHelper"
    HKLM\...\StartupApproved\Run32: => "BCSSync"
    HKLM\...\StartupApproved\Run32: => "PWRISOVM.EXE"
    HKLM\...\StartupApproved\Run32: => "T5"
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\StartupApproved\Run: => "Discord"

    ==================== FirewallRules (Whitelisted) ================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{076F5BDD-AE62-464D-860B-52014AC35B23}] => (Block) C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe (ERCLab -> ) [File not signed]
    FirewallRules: [{A36228CD-0987-49FB-8160-FE9D688DCCF1}] => (Block) C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe (ERCLab -> ) [File not signed]
    FirewallRules: [{D63A26F2-DFEE-4BBC-BD4A-92C480A84048}] => (Block) C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe () [File not signed]
    FirewallRules: [{523BFA55-4408-48FB-8B41-77331EEDD121}] => (Block) C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe () [File not signed]
    FirewallRules: [UDP Query User{12822254-0783-40AF-8484-012EB9FDE37F}C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe] => (Allow) C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe () [File not signed]
    FirewallRules: [TCP Query User{F82F0342-4B5E-40E5-A6A5-E5AE5F788E33}C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe] => (Allow) C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe () [File not signed]
    FirewallRules: [UDP Query User{E63B10F8-65A1-4B36-8C31-30B9A8B2A0BC}C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe] => (Allow) C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe (ERCLab -> ) [File not signed]
    FirewallRules: [TCP Query User{F69661A7-A6BF-4C28-89D5-AD6C8135BFC7}C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe] => (Allow) C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe (ERCLab -> ) [File not signed]
    FirewallRules: [{FF5E6163-0CBD-4573-B9CD-851FDD3C746F}] => (Allow) C:\Users\wparr\AppData\Local\Apowersoft\Online Audio Recorder\Online Audio Recorder.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [{B9CF1440-3AFB-4E6F-8ABC-B05F4DE48264}] => (Allow) C:\Users\wparr\AppData\Local\Apowersoft\Online Audio Recorder\Online Audio Recorder.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [{CE07184C-8EC7-4346-B6B1-EA5F9D0FB4D2}] => (Allow) C:\Users\wparr\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [{6CA9AAC4-FC3A-4E55-BBC3-54A4CBE2C9C8}] => (Allow) C:\Users\wparr\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [{9EE516F8-5269-48B8-A39C-E251E44059DB}] => (Allow) C:\WINDOWS\SysWOW64\TCPSVCS.EXE (Microsoft Windows -> Microsoft Corporation)
    FirewallRules: [{10CA01A3-7F5F-4AD2-BE14-D2027FA9F12B}] => (Allow) C:\Program Files\BitComet\BitComet.exe => No File
    FirewallRules: [{181FA518-16AA-40D3-A6AB-418BE927FC17}] => (Allow) C:\Program Files\BitComet\BitComet.exe => No File
    FirewallRules: [{D705DA25-1E31-4483-9629-D21592729026}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe (The SABnzbd-Team) [File not signed]
    FirewallRules: [TCP Query User{2FD54D65-17C8-4E8E-856E-AD9C7970E7EC}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe => No File
    FirewallRules: [UDP Query User{5298B4F5-CF99-4334-AA3B-DCF612401F25}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe => No File
    FirewallRules: [{922A863D-008A-4BB3-AC1C-29C73ED7CA13}] => (Allow) C:\Program Files (x86)\WinTV\WinTV8\WinTV8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [{FD50C90B-8443-436B-8E6D-EDE9C91A0A43}] => (Allow) C:\Program Files (x86)\WinTV\WinTV8\WinTV8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [{13CA2D9F-B1D9-43D6-B9B0-A1848D5B2071}] => (Allow) C:\Program Files (x86)\WinTV\WinTV8\WinTV8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [{14357ADE-2E17-46EA-961C-1530A843A0DF}] => (Allow) C:\Program Files (x86)\WinTV\WinTV8\WinTV8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [{5773ACBE-AD64-4EA7-899B-EA19FBC0B478}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\CaptureDCR.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{26DDCF11-1D0C-417E-A1F4-52228430962D}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\CaptureDCR.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{E419C9C5-1FB6-4228-AD81-A2329E0B235B}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\CaptureDCR.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{CB741285-1CC1-42B8-BB22-83FFAA6F26A8}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\CaptureDCR.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{64F6F302-C37D-4658-89F0-D09367616236}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{D4A4D5B8-6C6A-4F2C-9FC9-C87B4F1DA420}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{73A0E39D-BC48-451C-87ED-DC6E4FDBEC8E}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{E9D78991-5279-4A55-A046-FA376CD65376}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [TCP Query User{8A54691C-F183-42E3-9051-BBC6AC1C6263}C:\program files\bitcomet\bitcomet.exe] => (Allow) C:\program files\bitcomet\bitcomet.exe => No File
    FirewallRules: [UDP Query User{561B9F98-2906-46EA-AD22-B95113428304}C:\program files\bitcomet\bitcomet.exe] => (Allow) C:\program files\bitcomet\bitcomet.exe => No File
    FirewallRules: [{51E3B656-8403-46A4-BCCE-5B4CDC09FDF4}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{B5189686-99C1-43A9-9E7C-E06CDDCA8523}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{3A85F4D0-F17E-4CF2-A34B-88E487C326EB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{5E15087F-14F0-4646-A495-95824B7ACC7C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{F709B005-4BCB-44A1-9332-82F20EB871A8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{35B14249-E655-4703-BAA7-4E4A45D6B20D}] => (Allow) C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe (MEDIATEK INC. -> Mediatek Inc.) [File not signed]
    FirewallRules: [TCP Query User{CF3E6E2F-D011-4D58-A9CC-1AE27E9FE652}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe => No File
    FirewallRules: [UDP Query User{52635DBA-64FD-4E65-9B89-E0B1E7084F71}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe => No File
    FirewallRules: [{64671D0F-9588-4E4D-A966-8DFAC1441401}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe (The SABnzbd-Team) [File not signed]
    FirewallRules: [{D270B93F-1D2D-4823-A0E3-DEA4C6BB748A}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerMirror\ApowerMirror.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [{F532B012-7F0F-4AA9-B077-F903833BB6C9}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerMirror\ApowerMirror.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [TCP Query User{DABB14A4-85AA-4448-BB21-A4F076AC8EA5}C:\program files (x86)\wintv\wintv8\wintv8.exe] => (Allow) C:\program files (x86)\wintv\wintv8\wintv8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [UDP Query User{6948D116-6706-412C-8C81-0FCDD2C7F6C7}C:\program files (x86)\wintv\wintv8\wintv8.exe] => (Allow) C:\program files (x86)\wintv\wintv8\wintv8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [{FAB314C4-F5C9-451C-A0AE-1A523E8B0DEE}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe (The SABnzbd-Team) [File not signed]
    FirewallRules: [{3948A791-6391-4D5F-917D-5E765AC8AB06}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe (The SABnzbd-Team) [File not signed]
    FirewallRules: [{A75A9CA1-6956-4526-8445-4C9BA948DE71}] => (Allow) C:\Program Files\SABnzbd\SABnzbd-console.exe (The SABnzbd-Team) [File not signed]
    FirewallRules: [{61FC4AA5-0F63-454E-A05D-0B33A538EAB6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
    FirewallRules: [{87098815-1973-491C-9592-4A5AFA996B7B}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{E5529D02-8D41-4405-974C-AE69FD238C7D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
    FirewallRules: [{FEB761E8-7B83-4CE7-9D94-328943CD87F2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{7AF64732-F2C8-49A9-8AD6-CFBEEA42962D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{B1B6D1C5-3716-4A49-B336-7D65999299AD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{E1708892-EC2D-42A0-AD54-FE5202AADCCC}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)

    ==================== Restore Points =========================

    09-12-2021 15:45:30 Scheduled Checkpoint
    09-12-2021 16:19:00 Windows Modules Installer
    09-12-2021 17:32:20 Windows Modules Installer
    09-12-2021 17:34:47 Windows Modules Installer
    10-12-2021 10:24:32 Windows Modules Installer
    10-12-2021 10:27:04 Windows Modules Installer

    ==================== Faulty Device Manager Devices ============


    ==================== Event log errors: ========================

    Application errors:
    ==================
    Error: (12/14/2021 08:50:53 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0

    Error: (12/14/2021 08:50:53 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=25, authorId=9, vendorId=0, vendorType=0

    Error: (12/14/2021 08:50:53 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=17, authorId=9, vendorId=0, vendorType=0

    Error: (12/14/2021 08:50:53 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=55, authorId=311, vendorId=0, vendorType=0

    Error: (12/14/2021 08:50:53 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=254, authorId=311, vendorId=14122, vendorType=1

    Error: (12/14/2021 08:50:53 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=21, authorId=1814, vendorId=0, vendorType=0

    Error: (12/14/2021 08:50:53 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=18, authorId=1814, vendorId=0, vendorType=0

    Error: (12/14/2021 08:50:52 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0


    System errors:
    =============
    Error: (12/14/2021 08:47:26 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The ComboCleaner.Guard service terminated unexpectedly. It has done this 1 time(s).

    Error: (12/14/2021 08:47:26 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The ComboCleaner.WinService service terminated unexpectedly. It has done this 1 time(s).

    Error: (12/14/2021 07:49:01 AM) (Source: DCOM) (EventID: 10010) (User: MEDIA-CENTER)
    Description: The server microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout.

    Error: (12/14/2021 07:49:01 AM) (Source: DCOM) (EventID: 10010) (User: MEDIA-CENTER)
    Description: The server Microsoft.Windows.Search_1.14.2.19041_neutral_neutral_cw5n1h2txyewy!ShellFeedsUI.AppXfbff151h5bmghg166fvn34ccayg70vts.mca did not register with DCOM within the required timeout.

    Error: (12/14/2021 07:49:01 AM) (Source: DCOM) (EventID: 10010) (User: MEDIA-CENTER)
    Description: The server NcsiUwpApp_1000.19041.1023.0_neutral_neutral_8wekyb3d8bbwe!App.AppXw175g9nmx2zykh9fyt6xjc0xf8vmj1w6.mca did not register with DCOM within the required timeout.

    Error: (12/14/2021 07:49:01 AM) (Source: DCOM) (EventID: 10010) (User: MEDIA-CENTER)
    Description: The server Microsoft.MicrosoftOfficeHub_18.2110.13110.0_x64__8wekyb3d8bbwe!Microsoft.MicrosoftOfficeHub.AppXt4mh7c9swwc5cmd5jgmtmwcfmvkddpn1.mca did not register with DCOM within the required timeout.

    Error: (12/12/2021 09:40:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The eapihdrv service failed to start due to the following error:
    This driver has been blocked from loading

    Error: (12/12/2021 09:40:55 PM) (Source: Application Popup) (EventID: 1060) (User: )
    Description: \??\C:\Users\wparr\AppData\Local\Temp\ehdrv.sys


    Windows Defender:
    ================
    Date: 2021-12-13 17:05:25
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2021-12-13 07:40:00
    Description:
    Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...1&enterprise=0
    Name: HackTool:BAT/AutoKMS!MSR
    Severity: High
    Category: Tool
    Path: file:_E:\Software\Microsoft Office\Office 2019\ACTIVATOR.CMD
    Detection Origin: Local machine
    Detection Type: Concrete
    Detection Source: Real-Time Protection
    Process Name: C:\Users\wparr\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
    Security intelligence Version: AV: 1.355.148.0, AS: 1.355.148.0, NIS: 1.355.148.0
    Engine Version: AM: 1.1.18800.4, NIS: 1.1.18800.4

    Date: 2021-12-13 07:40:00
    Description:
    Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...7&enterprise=0
    Name: HackTool:MSIL/AutoKms
    Severity: High
    Category: Tool
    Path: file:_E:\Software\Microsoft Office\Office 2013\Microsoft.Office.+.Visio.+.Project.Professional.2013 32 bit version\Crack\KMSpico Only Service\TriggerKMS.exe
    Detection Origin: Local machine
    Detection Type: Concrete
    Detection Source: Real-Time Protection
    Process Name: C:\Users\wparr\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
    Security intelligence Version: AV: 1.355.148.0, AS: 1.355.148.0, NIS: 1.355.148.0
    Engine Version: AM: 1.1.18800.4, NIS: 1.1.18800.4

    Date: 2021-12-13 07:39:59
    Description:
    Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...0&enterprise=0
    Name: HackTool:Win32/AutoKMS
    Severity: High
    Category: Tool
    Path: containerfile:_E:\Software\Microsoft Office\Office 2013\Microsoft.Office.+.Visio.+.Project.Professional.2013 32 bit version\Crack\KMSpico Only Service\Service_KMS.exe; file:_E:\Software\Microsoft Office\Office 2013\Microsoft.Office.+.Visio.+.Project.Professional.2013 32 bit version\Crack\KMSpico Only Service\Service_KMS.exe; file:_E:\Software\Microsoft Office\Office 2013\Microsoft.Office.+.Visio.+.Project.Professional.2013 32 bit version\Crack\KMSpico Only Service\Service_KMS.exe->[b64mz]->(Base64); file:_E:\Software\Microsoft Office\Office 2013\Microsoft.Office.+.Visio.+.Project.Professional.2013 32 bit version\Crack\KMSpico Only Service\Service_KMS.exe->[Base64]->(Base64)
    Detection Origin: Local machine
    Detection Type: FastPath
    Detection Source: Real-Time Protection
    Process Name: C:\Users\wparr\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
    Security intelligence Version: AV: 1.355.148.0, AS: 1.355.148.0, NIS: 1.355.148.0
    Engine Version: AM: 1.1.18800.4, NIS: 1.1.18800.4

    Date: 2021-12-13 07:39:42
    Description:
    Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...2&enterprise=0
    Name: HackTool:Win32/AutoKMS.E!MSR
    Severity: High
    Category: Tool
    Path: file:_E:\Software\Microsoft Office\Office 2010\Office 2010 Toolkit and EZ-Activator v 2.1.4 Final by ADNAN\Office 2010 Toolkit\Office 2010 Toolkit.exe
    Detection Origin: Local machine
    Detection Type: Concrete
    Detection Source: Real-Time Protection
    Process Name: C:\Users\wparr\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
    Security intelligence Version: AV: 1.355.148.0, AS: 1.355.148.0, NIS: 1.355.148.0
    Engine Version: AM: 1.1.18800.4, NIS: 1.1.18800.4
    
    CodeIntegrity:
    ===============
    Date: 2020-10-22 14:14:24
    Description:
    Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\WindowManagementAPI.dll because the set of per-page image hashes could not be found on the system.

    Date: 2020-10-22 14:14:24
    Description:
    Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    BIOS: American Megatrends Inc. 2403 12/23/2010
    Motherboard: ASUSTeK Computer INC. M4A88T-M
    Processor: AMD Athlon(tm) II X3 450 Processor
    Percentage of memory in use: 24%
    Total physical RAM: 16382.05 MB
    Available physical RAM: 12396.01 MB
    Total Virtual: 17406.05 MB
    Available Virtual: 12482.25 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:930.5 GB) (Free:338.28 GB) NTFS
    Drive d: (New Volume) (Fixed) (Total:931.51 GB) (Free:135.06 GB) NTFS
    Drive e: (New Volume) (Fixed) (Total:1863.01 GB) (Free:1399.2 GB) NTFS

    \\?\Volume{7096e00b-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.54 GB) (Free:0.13 GB) NTFS
    \\?\Volume{7096e00b-0000-0000-0000-20c2e8000000}\ () (Fixed) (Total:0.48 GB) (Free:0.05 GB) NTFS

    ==================== MBR & Partition Table ====================

    ==========================================================
    Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 7096E00B)
    Partition 1: (Active) - (Size=549 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=930.5 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=489 MB) - (Type=27)

    ==========================================================
    Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: F9C085CB)
    Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)

    ==========================================================
    Disk: 2 (MBR Code: Windows 7/8/10) (Size: 1863 GB) (Disk ID: AA669DB1)
    Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt =======================

  5. #5
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Please, observe following rules:

    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.



    Uninstall following unwanted program:

    NativeDesktopMediaService

    Download RogueKiller from one of the following links and save it to your Desktop:

    Link 1
    Link 2
    • Close all the running programs
    • Double click on downloaded setup.exe file to install the program.
    • Click on Start Scan button.
    • Click on another Start Scan button.
    • Wait until the Status box shows Scan Finished
    • Click on Remove Selected.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.

    Please download Malwarebytes to your desktop.
    • Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
    • Then click Finish.
    • Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
    • If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
    • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
    • Restart your computer when prompted to do so.
    • The Scan log is available throughout History ->Application logs. Please post it contents in your next reply.

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8/10 users right-click and select Run As Administrator
    • The tool will start to update the database if one is required.
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Logfile button.
    • A window will open which lists the logs of your scans.
    • Click on the Scan tab.
    • Double-click the most recent scan which will be at the top of the list....the log will appear.
    • Review the results...see note below
    • After reviewing the log, click on the Clean button.
    • Press OK when asked to close all programs and follow the onscreen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[CX].txt) will open automatically (where the largest value of X represents the most recent report).
    • To open a Cleaning log, launch AdwareClearer, click on the Logfile button, click on the Cleaning tab and double-click the log at the top of the list.
    • Copy and paste the contents of AdwCleaner[CX].txt in your next reply.
    • A copy of all logfiles are saved to C:\AdwCleaner.

    -- Note: The contents of the AdwCleaner log file may be confusing. Unless you see a program name or entry that you recognize and know should not be removed, don't worry about it. If you see an entry you want to keep, return to AdwCleaner before cleaning...all detected items will be listed (and checked) in each tab. Click on and uncheck any items you want to keep.

  6. #6
    Join Date
    Aug 2019
    Posts
    11
    Program : RogueKiller Anti-Malware
    Version : 15.1.5.0
    x64 : Yes
    Program Date : Dec 15 2021
    Location : C:\Program Files\RogueKiller\RogueKiller64.exe
    Premium : No
    Company : Adlice Software
    Website : https://www.adlice.com/
    Contact : https://adlice.com/contact/
    Website : https://adlice.com/download/roguekiller/
    Operating System : Windows 10 (10.0.19042) 64-bit
    64-bit OS : Yes
    Startup : 0
    WindowsPE : No
    User : wparr
    User is Admin : Yes
    Date : 2021/12/15 14:41:16
    Type : Removal
    Aborted : No
    Scan Mode : Standard
    Duration : 1342
    Found items : 11
    Total scanned : 121173
    Signatures Version : 20211210_135159
    Truesight Driver : Yes
    Updates Count : 10
    Arguments : -minimize

    ************************* Warnings *************************

    ************************* Removal *************************
    [PUP.Auslogics (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Auslogics -- -> Deleted
    [+] scan_what : 2
    [+] vendors : PUP.Auslogics
    [+] Name : HKEY_LOCAL_MACHINE\Software\Auslogics
    [+] Type : Registry
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 0
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

    [PUP.Popcorn (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{2FD54D65-17C8-4E8E-856E-AD9C7970E7EC}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe -- [%localappdata%\popcorn-time\popcorn-time.exe] -> Deleted
    [+] scan_what : 1
    [+] vendors : PUP.Popcorn
    [+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{2FD54D65-17C8-4E8E-856E-AD9C7970E7EC}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe
    [+] value : [%localappdata%\popcorn-time\popcorn-time.exe]
    [+] Type : Registry
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 1
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

    [PUP.Popcorn (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{5298B4F5-CF99-4334-AA3B-DCF612401F25}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe -- [%localappdata%\popcorn-time\popcorn-time.exe] -> Deleted
    [+] scan_what : 1
    [+] vendors : PUP.Popcorn
    [+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{5298B4F5-CF99-4334-AA3B-DCF612401F25}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe
    [+] value : [%localappdata%\popcorn-time\popcorn-time.exe]
    [+] Type : Registry
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 2
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

    [PUP.Popcorn (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{CF3E6E2F-D011-4D58-A9CC-1AE27E9FE652}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe -- [%localappdata%\popcorn-time\popcorn-time.exe] -> Deleted
    [+] scan_what : 1
    [+] vendors : PUP.Popcorn
    [+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{CF3E6E2F-D011-4D58-A9CC-1AE27E9FE652}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe
    [+] value : [%localappdata%\popcorn-time\popcorn-time.exe]
    [+] Type : Registry
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 3
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

    [PUP.Popcorn (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{52635DBA-64FD-4E65-9B89-E0B1E7084F71}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe -- [%localappdata%\popcorn-time\popcorn-time.exe] -> Deleted
    [+] scan_what : 1
    [+] vendors : PUP.Popcorn
    [+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{52635DBA-64FD-4E65-9B89-E0B1E7084F71}C:\users\wparr\appdata\local\popcorn-time\popcorn-time.exe
    [+] value : [%localappdata%\popcorn-time\popcorn-time.exe]
    [+] Type : Registry
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 4
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

    [PUP.HackTool (Potentially Malicious)] AutoKMS -- %SystemRoot%\AutoKMS -> Deleted
    [+] scan_what : 1
    [+] vendors : PUP.HackTool
    [+] Name : AutoKMS
    [+] value : %SystemRoot%\AutoKMS
    [+] Type : File/Folder
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 5
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

    [PUP.OnlineIO (Potentially Malicious)] AdvinstAnalytics -- %localappdata%\AdvinstAnalytics -> Deleted
    [+] scan_what : 1
    [+] vendors : PUP.OnlineIO
    [+] Name : AdvinstAnalytics
    [+] value : %localappdata%\AdvinstAnalytics
    [+] Type : File/Folder
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 6
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

    [PUP.Auslogics (Potentially Malicious)] Auslogics -- %programdata%\Auslogics -> Deleted
    [+] scan_what : 1
    [+] vendors : PUP.Auslogics
    [+] Name : Auslogics
    [+] value : %programdata%\Auslogics
    [+] Type : File/Folder
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 7
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

    [PUP.HackTool (Potentially Malicious)] KMSAutoS -- %programdata%\KMSAutoS -> Deleted
    [+] scan_what : 1
    [+] vendors : PUP.HackTool
    [+] Name : KMSAutoS
    [+] value : %programdata%\KMSAutoS
    [+] Type : File/Folder
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 8
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

    [PUP.Auslogics (Potentially Malicious)] Auslogics -- %programdata%\Microsoft\Windows\Start Menu\Programs\Auslogics -> Deleted
    [+] scan_what : 1
    [+] vendors : PUP.Auslogics
    [+] Name : Auslogics
    [+] value : %programdata%\Microsoft\Windows\Start Menu\Programs\Auslogics
    [+] Type : File/Folder
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 9
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

    [PUP.Auslogics (Potentially Malicious)] Auslogics -- %programfiles(x86)%\Auslogics -> Deleted
    [+] scan_what : 1
    [+] vendors : PUP.Auslogics
    [+] Name : Auslogics
    [+] value : %programfiles(x86)%\Auslogics
    [+] Type : File/Folder
    [+] file_vtscore : -1
    [+] file_vttotal : 0
    [+] is_malicious : Yes
    [+] detection_level : 3
    [+] id : 10
    [+] status : 3
    [+] status_str : Deleted
    [+] removed : Yes
    [+] status_choice : 2
    [+] malpe_score : -1

  7. #7
    Join Date
    Aug 2019
    Posts
    11
    Malwarebytes
    www.malwarebytes.com

    -Log Details-
    Scan Date: 12/15/21
    Scan Time: 9:43 AM
    Log File: 65f9e3ac-5db5-11ec-aa99-001a7dda7113.json

    -Software Information-
    Version: 4.4.11.149
    Components Version: 1.0.1513
    Update Package Version: 1.0.48640
    License: Free

    -System Information-
    OS: Windows 10 (Build 19042.1387)
    CPU: x64
    File System: NTFS
    User: Media-Center\wparr

    -Scan Summary-
    Scan Type: Threat Scan
    Scan Initiated By: Manual
    Result: Completed
    Objects Scanned: 325360
    Threats Detected: 0
    Threats Quarantined: 0
    Time Elapsed: 7 min, 36 sec

    -Scan Options-
    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Detect
    PUM: Detect

    -Scan Details-
    Process: 0
    (No malicious items detected)

    Module: 0
    (No malicious items detected)

    Registry Key: 0
    (No malicious items detected)

    Registry Value: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Data Stream: 0
    (No malicious items detected)

    Folder: 0
    (No malicious items detected)

    File: 0
    (No malicious items detected)

    Physical Sector: 0
    (No malicious items detected)

    WMI: 0
    (No malicious items detected)


    (end)

  8. #8
    Join Date
    Aug 2019
    Posts
    11
    # -------------------------------
    # Malwarebytes AdwCleaner 8.3.1.0
    # -------------------------------
    # Build: 11-18-2021
    # Database: 2021-12-02.1 (Cloud)
    # Support: https://www.malwarebytes.com/support
    #
    # -------------------------------
    # Mode: Scan
    # -------------------------------
    # Start: 12-15-2021
    # Duration: 00:00:10
    # OS: Windows 10 Pro
    # Scanned: 32027
    # Detected: 0


    ***** [ Services ] *****

    No malicious services found.

    ***** [ Folders ] *****

    No malicious folders found.

    ***** [ Files ] *****

    No malicious files found.

    ***** [ DLL ] *****

    No malicious DLLs found.

    ***** [ WMI ] *****

    No malicious WMI found.

    ***** [ Shortcuts ] *****

    No malicious shortcuts found.

    ***** [ Tasks ] *****

    No malicious tasks found.

    ***** [ Registry ] *****

    No malicious registry entries found.

    ***** [ Chromium (and derivatives) ] *****

    No malicious Chromium entries found.

    ***** [ Chromium URLs ] *****

    No malicious Chromium URLs found.

    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries found.

    ***** [ Firefox URLs ] *****

    No malicious Firefox URLs found.

    ***** [ Hosts File Entries ] *****

    No malicious hosts file entries found.

    ***** [ Preinstalled Software ] *****

    No Preinstalled Software found.


    AdwCleaner[S00].txt - [1773 octets] - [10/02/2019 13:01:36]
    AdwCleaner[C00].txt - [1903 octets] - [10/02/2019 13:02:12]
    AdwCleaner[S01].txt - [3662 octets] - [12/02/2019 07:55:29]
    AdwCleaner[C01].txt - [3536 octets] - [12/02/2019 07:55:45]
    AdwCleaner[S02].txt - [1493 octets] - [12/02/2019 07:58:06]
    AdwCleaner[S03].txt - [1554 octets] - [13/02/2019 15:35:44]
    AdwCleaner[C03].txt - [1740 octets] - [13/02/2019 15:35:54]
    AdwCleaner[S04].txt - [4878 octets] - [18/03/2019 17:25:02]
    AdwCleaner[C04].txt - [4810 octets] - [18/03/2019 17:25:19]
    AdwCleaner[S05].txt - [2678 octets] - [29/04/2019 07:20:31]
    AdwCleaner[C05].txt - [2790 octets] - [29/04/2019 07:20:46]
    AdwCleaner[S06].txt - [1920 octets] - [29/04/2019 07:25:07]
    AdwCleaner[S07].txt - [4241 octets] - [08/05/2019 16:56:57]
    AdwCleaner[C07].txt - [4245 octets] - [08/05/2019 16:57:37]
    AdwCleaner[S08].txt - [2780 octets] - [11/06/2019 10:06:17]
    AdwCleaner[C08].txt - [2836 octets] - [11/06/2019 10:06:34]
    AdwCleaner[S09].txt - [5954 octets] - [01/08/2019 16:27:40]
    AdwCleaner[C09].txt - [5852 octets] - [01/08/2019 16:28:11]
    AdwCleaner[S10].txt - [2423 octets] - [03/08/2019 09:50:41]
    AdwCleaner_Debug.log - [67694 octets] - [24/09/2019 11:24:36]
    AdwCleaner[S11].txt - [4806 octets] - [24/09/2019 11:25:03]
    AdwCleaner[C11].txt - [4813 octets] - [24/09/2019 11:25:22]
    AdwCleaner[S12].txt - [5409 octets] - [01/10/2019 11:34:46]
    AdwCleaner[C12].txt - [5249 octets] - [01/10/2019 11:35:03]
    AdwCleaner[S13].txt - [2846 octets] - [01/10/2019 12:24:22]
    AdwCleaner[C13].txt - [3014 octets] - [01/10/2019 12:24:31]
    AdwCleaner[S14].txt - [5227 octets] - [03/12/2019 17:59:22]
    AdwCleaner[C14].txt - [5213 octets] - [03/12/2019 17:59:37]
    AdwCleaner[S15].txt - [3981 octets] - [11/12/2019 09:34:29]
    AdwCleaner[C15].txt - [4075 octets] - [11/12/2019 09:34:59]
    AdwCleaner[S16].txt - [4035 octets] - [15/12/2019 09:51:24]
    AdwCleaner[C16].txt - [4149 octets] - [15/12/2019 09:51:47]
    AdwCleaner[S17].txt - [3746 octets] - [27/12/2019 05:45:07]
    AdwCleaner[C17].txt - [3876 octets] - [27/12/2019 05:45:22]
    AdwCleaner[S18].txt - [4413 octets] - [23/03/2020 08:14:18]
    AdwCleaner[C18].txt - [4509 octets] - [23/03/2020 08:14:32]
    AdwCleaner[S19].txt - [4932 octets] - [12/06/2020 16:23:05]
    AdwCleaner[C19].txt - [5012 octets] - [12/06/2020 16:23:28]
    AdwCleaner[S20].txt - [3725 octets] - [16/06/2020 12:26:37]
    AdwCleaner[S21].txt - [3786 octets] - [26/07/2020 19:57:35]
    AdwCleaner[S22].txt - [3847 octets] - [29/09/2020 10:10:35]
    AdwCleaner[S23].txt - [3908 octets] - [11/12/2021 21:01:05]
    AdwCleaner[C23].txt - [4098 octets] - [11/12/2021 21:01:15]
    AdwCleaner[S24].txt - [4030 octets] - [12/12/2021 21:37:14]
    AdwCleaner[S25].txt - [4091 octets] - [15/12/2021 09:52:38]

    ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S26].txt ##########

  9. #9
    Join Date
    Aug 2019
    Posts
    11
    issue still there

    Capture.JPG

  10. #10
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Can you give me some more details about your issue?

    Then...

    Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.


    • Double click to run it.
    • Press Scan button.
    • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.

  11. #11
    Join Date
    Aug 2019
    Posts
    11
    I clicked on a "I am a human" link and go these pop ups that continue to show up in the lower right corner of the screen.

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-12-2021
    Ran by wparr (administrator) on MEDIA-CENTER (15-12-2021 13:30:00)
    Running from C:\Users\wparr\Downloads
    Loaded Profiles: wparr
    Platform: Microsoft Windows 10 Pro Version 20H2 19042.1387 (X64) Language: English (United States)
    Default browser: Edge
    Boot Mode: Normal

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe
    (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed] [File is in use] C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe
    (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed] C:\Program Files (x86)\WinTV\TVServer\CaptureGenPCI.exe <4>
    (MEDIATEK INC. -> Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe
    (MEDIATEK INC. -> Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <37>
    (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.1371_none_7e1bd7147c8285b0\TiWorker.exe
    (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe
    (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe
    (Mudhook Marketing, Inc. -> Mudhook Marketing, Inc) C:\Program Files\IPVanish VPN\IPVanish.exe
    (NETGEAR TAIWAN CO., LTD -> ) C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
    (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
    (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
    (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe

    ==================== Registry (Whitelisted) ===================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [339000 2021-10-26] (Apple Inc. -> Apple Inc.)
    HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5388128 2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [11224432 2021-12-13] (Support.com Inc -> SUPERAntiSpyware)
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\Run: [Discord] => C:\Users\wparr\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\Policies\Explorer: [NoPreviewPane] 0
    HKLM\...\Print\Monitors\HP DC11 Status Monitor: C:\WINDOWS\system32\hpinkstsDC11LM.dll [391984 2019-03-15] (HP Inc -> HP Inc.)
    HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\96.0.4664.110\Installer\chrmstp.exe [2021-12-14] (Google LLC -> Google LLC)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoStart IR.lnk [2019-02-27]
    ShortcutTarget: AutoStart IR.lnk -> C:\Program Files (x86)\WinTV\Ir.exe (Hauppauge Computer Works Inc. -> Hauppauge Computer Works) [File not signed]
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Mediatek Wireless Utility.lnk [2019-06-07]
    ShortcutTarget: Mediatek Wireless Utility.lnk -> C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe (MEDIATEK INC. -> Mediatek Inc.) [File not signed]
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinTV Recording Status.lnk [2019-02-27]
    ShortcutTarget: WinTV Recording Status.lnk -> C:\Program Files (x86)\WinTV\WinTV8\WinTVTray.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

    ==================== Scheduled Tasks (Whitelisted) ============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {01420282-1D7D-46DC-A5BE-4A8AAF397A3E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18227896 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
    Task: {0C6D2CBE-0927-4900-B371-69BFE5820F6A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1562376 2021-08-16] (Adobe Inc. -> Adobe Inc.)
    Task: {0D74D4B4-1E35-4D2B-8C74-FD4B9A3DCDF3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8386448 2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Task: {131F040D-0055-4B8D-AA7A-9B2221D1D51D} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\wparr\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [19989464 2021-12-12] (ESET, spol. s r.o. -> ESET)
    Task: {252B13E4-C8FD-4B55-A895-B60932A83EA8} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [139656 2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Task: {4625F88E-5879-4529-8211-959BB8392F55} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\wparr\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [19989464 2021-12-12] (ESET, spol. s r.o. -> ESET)
    Task: {5F6B92C3-3E79-4DB4-8FFC-EFA08B1D7ABA} - System32\Tasks\Western Digital\SmartWare\____Volume_7096e00b_0000_0000_0000_602200000000__uuid_73656761_7465_7375_636b_0090a942a598_SmartWare_ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [59232 2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    Task: {65287B98-BBAD-4051-B316-3F52D5AA31E4} - System32\Tasks\IPVanish => C:\Program Files\IPVanish VPN\IPVanish.exe [2530896 2021-07-06] (Mudhook Marketing, Inc. -> Mudhook Marketing, Inc)
    Task: {92D61871-AC58-4F2D-A003-8F0C58EFDAE7} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1706496 2020-05-15] () [File not signed]
    Task: {97081292-368E-46BF-BC7A-00FDAC936220} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8386448 2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Task: {9AA5AA82-F0F6-435C-8036-AABFB1A50122} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {AACAD0A0-FDB7-430F-8C4B-4B5A0321AED2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-26] (Google Inc -> Google Inc.)
    Task: {ABF782D3-FE83-4386-8F2E-F988F148F47C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
    Task: {B2CF477D-F178-4434-BF7B-010873E12AF2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {BAA6FF00-72A3-45B5-B33C-F22BBBA81FB1} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [139656 2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Task: {BC936AC3-FBFA-4D23-B87C-324A5E6D95B6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22799320 2021-12-02] (Microsoft Corporation -> Microsoft Corporation)
    Task: {BE9A53FE-1BF4-4D80-951D-9DD8CDED2406} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {D16540FA-DB2B-48D5-B92D-4CC3B47F4CF8} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
    Task: {EF63D73F-80E2-498E-BDCA-110BF8E354E7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {EFBFE77A-1FCA-49B4-813E-F8945639A777} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-26] (Google Inc -> Google Inc.)
    Task: {F3462AB0-B30C-4E21-8187-0E32A082315B} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22799320 2021-12-02] (Microsoft Corporation -> Microsoft Corporation)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\..\Interfaces\{1152BD5F-9A35-4F04-A2A4-07241DA62761}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{1152BD5F-9A35-4F04-A2A4-07241DA62761}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{15a374f3-56f9-4681-8bad-935ac6461374}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{15a374f3-56f9-4681-8bad-935ac6461374}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{2044b21d-77b2-406b-b2b9-9e1eb5c24313}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{2C92F934-C975-4458-B8B2-9A971FE5DF96}: [NameServer] 10.222.0.1
    Tcpip\..\Interfaces\{3A0E2406-5D9F-4FF6-9D51-683D09A5AE8B}: [DhcpNameServer] 10.0.1.1
    Tcpip\..\Interfaces\{49461da5-c956-4c85-88d1-e43824c15ee1}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{49BB631A-0F6B-4336-867B-2119EEF1EC46}: [DhcpNameServer] 10.0.1.1
    Tcpip\..\Interfaces\{6f84f292-ee91-46b4-b728-c4c7107c89cc}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{6f84f292-ee91-46b4-b728-c4c7107c89cc}: [DhcpNameServer] 192.168.254.254
    Tcpip\..\Interfaces\{a02414b0-bda5-4b1b-a208-b6d407c8c575}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{a02414b0-bda5-4b1b-a208-b6d407c8c575}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{a2b6ad52-3a16-11e9-b8b6-806e6f6e6963}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{b5ab89d6-dd66-408f-902e-08d8704c4aa1}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{C2A40734-BB65-4CD1-8F6D-11109F97EE90}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{C2A40734-BB65-4CD1-8F6D-11109F97EE90}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{d55f0245-7af0-4ee1-9c88-c0bcce1619bd}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{D905D5CD-3FC2-4DF5-A7F7-3F6011FD28F9}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{D905D5CD-3FC2-4DF5-A7F7-3F6011FD28F9}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{da70202c-a9ca-40b2-a1b6-0c837fd005da}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{DE056950-DE94-475C-94D8-DECFDD855DC6}: [NameServer] 198.18.0.1 198.18.0.2
    Tcpip\..\Interfaces\{F4BD3271-021F-4471-B209-CE94E1792D2D}: [DhcpNameServer] 10.0.1.1
    Tcpip\..\Interfaces\{f563c0ee-d36f-4ba3-a36c-a18f13d54162}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{f563c0ee-d36f-4ba3-a36c-a18f13d54162}: [DhcpNameServer] 8.8.8.8
    Tcpip\..\Interfaces\{FE76A9A7-5E92-4B8F-AA5A-AA4EFD8ACE8F}: [DhcpNameServer] 10.0.1.1

    Edge:
    =======
    DownloadDir: C:\Users\wparr\Downloads
    Edge HomeButtonPage: HKU\S-1-5-21-3399867593-3550638609-2408602673-1001 -> hxxp://www.google.com/
    Edge Notifications: HKU\S-1-5-21-3399867593-3550638609-2408602673-1001 -> hxxps://notification-list.com; hxxps://topflownews.com; hxxps://www2.thefastpush.com
    Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
    Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
    Edge Extension: (No Name) -> hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.48.0.0_neutral__qq0fmhteeht3j [not found]
    Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
    Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
    Edge DefaultProfile: Default
    Edge Profile: C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default [2021-12-15]
    Edge DownloadDir: Default -> C:\Users\wparr\Downloads
    Edge Notifications: Default -> hxxps://apsolutamente.com
    Edge HomePage: Default -> hxxp://www.google.com/
    Edge StartupUrls: Default -> "hxxp://www.google.com/","hxxps://google.com/"
    Edge DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
    Edge DefaultSearchKeyword: Default -> duckduckgo.com
    Edge DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
    Edge Extension: (LastPass: Free Password Manager) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bbcinlkgjjkejfdpemiealijmmooekmp [2021-12-13]
    Edge Extension: (DuckDuckGo) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caoacbimdbbljakfhgikoodekdnlcgpk [2021-12-11]
    Edge Extension: (ExpressVPN: VPN proxy for a better internet) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fgddmllnllkalaagkghckoinaemmogpe [2021-12-11]
    Edge Extension: (Capital One Shopping: Add to Edge for Free) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kiiaghlmeikbpmeabhilfphikfcefljn [2021-12-13]
    Edge Extension: (TubeBuddy) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mhkhmbddkmdggbhaaaodilponhnccicb [2021-12-14]
    Edge Extension: (Show Apps in new tab) - C:\Users\wparr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nohbdifokmdgjcbbeobglcbaifinhfip [2021-12-11]

    FireFox:
    ========
    FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google Inc -> Google, Inc.)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-10-05] (Adobe Inc. -> Adobe Systems Inc.)

    Chrome:
    =======
    CHR DefaultProfile: Default
    CHR Profile: C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default [2021-12-11]
    CHR Notifications: Default -> hxxps://paymentsweb.org
    CHR HomePage: Default -> hxxp://www.google.com/ig
    CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxp://www.google.com","hxxp://www.google.com/"
    CHR NewTab: Default -> Not-active:"chrome-extension://nohbdifokmdgjcbbeobglcbaifinhfip/go.html"
    CHR Extension: (Google Drive) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-12-11]
    CHR Extension: (Ledger Manager) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\beimhnaefocolcplfimocfiaiefpkgbf [2019-02-26]
    CHR Extension: (TV) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2019-03-07]
    CHR Extension: (YouTube) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-02-26]
    CHR Extension: (Adobe Acrobat) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2021-12-11]
    CHR Extension: (ExpressVPN: VPN proxy for a better internet) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgddmllnllkalaagkghckoinaemmogpe [2021-12-11]
    CHR Extension: (Chrome Remote Desktop) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-26]
    CHR Extension: (The Economist) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebjgjhbjedcomcajgpodjgfjgkepgpl [2019-02-26]
    CHR Extension: (LastPass: Free Password Manager) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2021-12-11]
    CHR Extension: (Ledger Wallet Ethereum) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmlhkialjkaldndjnlcdfdphcgeadkkm [2019-07-26]
    CHR Extension: (The Weather Channel for Chrome) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\iflpcokdamgefbghpdipcibmhlkdopop [2019-03-07]
    CHR Extension: (Chrome Remote Desktop) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2019-11-20]
    CHR Extension: (Roomstyler 3D planner) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfnniehafojoidolddmhfnpnbiolbppi [2019-02-26]
    CHR Extension: (Ledger Wallet Bitcoin) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkdpmhnladdopljabkgpacgpliggeeaf [2019-02-26]
    CHR Extension: (Google Maps) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2019-02-26]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-12-11]
    CHR Extension: (Ultimate Mp3 Music Search) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pddlnfginfgejmncfhgljdddjlhhedmp [2019-02-26]
    CHR Extension: (Gmail) - C:\Users\wparr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-12-11]
    CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

    ==================== Services (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-30] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
    R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.)
    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [99104 2021-08-20] (Apple Inc. -> Apple Inc.)
    S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [2682920 2021-11-16] (Xing Wang -> www.BitComet.com)
    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12129160 2021-12-02] (Microsoft Corporation -> Microsoft Corporation)
    R2 HauppaugeTVServer; C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [594216 2019-02-14] (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed] [File is in use]
    S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [7901368 2021-12-11] (Malwarebytes Inc -> Malwarebytes)
    R2 MediatekRegistryWriter; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe [405136 2014-12-04] (MEDIATEK INC. -> Mediatek Inc.)
    R2 MediatekRegistryWriter64; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe [454288 2014-12-04] (MEDIATEK INC. -> Mediatek Inc.)
    S2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [14204760 2021-12-15] (ADLICE (ASCOET JULIEN) -> )
    S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6136520 2021-12-10] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [668808 2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [363888 2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe [2872024 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe [128376 2021-12-09] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WSWNDA3100v2; C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [316128 2014-12-23] (NETGEAR TAIWAN CO., LTD -> )

    ===================== Drivers (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 HCW85BDA; C:\WINDOWS\system32\drivers\HCW85BDA.sys [2268008 2018-10-05] (Hauppauge Computer Works Inc. -> Hauppauge Computer Works)
    R3 hcw85cir; C:\WINDOWS\system32\drivers\hcw85cir4.sys [79720 2018-10-05] (Hauppauge Computer Works Inc. -> Hauppauge Computer Works, Inc.)
    S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-06-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
    S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-12-11] (Malwarebytes Inc -> Malwarebytes)
    R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] (ASUSTeK Computer Inc. -> )
    S3 NPF; C:\WINDOWS\system32\DRIVERS\npf.sys [47632 2010-02-03] (CACE Technologies, Inc. -> CACE Technologies, Inc.)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R0 SCMNdisP; C:\WINDOWS\System32\DRIVERS\scmndisp.sys [25312 2007-01-19] (NETGEAR -> Windows (R) Codename Longhorn DDK provider)
    S3 TKCtrl; C:\WINDOWS\system32\TKCtrl2k64.sys [147240 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKFsAvM; C:\WINDOWS\system32\TKFsAv64.sys [198808 2018-03-07] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKFsFtM; C:\WINDOWS\system32\TKFsFt64.sys [28824 2018-03-07] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKPcFt; C:\WINDOWS\system32\TKPcFtCb64.sys [54504 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKRgAc; C:\WINDOWS\system32\TKRgAc2k64.sys [115760 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKRgFt; C:\WINDOWS\system32\TKRgFtXp64.sys [68848 2018-02-04] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKSP; C:\WINDOWS\system32\TKSPxp64.sys [80824 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48520 2021-12-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
    S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2018-05-23] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
    R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [435424 2021-12-09] (Microsoft Windows -> Microsoft Corporation)
    R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-12-09] (Microsoft Windows -> Microsoft Corporation)
    R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2019-03-12] (Zemana Ltd. -> Zemana Ltd.)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One month (created) (Whitelisted) =========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2021-12-15 13:30 - 2021-12-15 13:31 - 000027094 _____ C:\Users\wparr\Downloads\FRST.txt
    2021-12-15 13:29 - 2021-12-15 13:29 - 002311168 _____ (Farbar) C:\Users\wparr\Downloads\FRST64.exe
    2021-12-15 11:44 - 2021-12-15 11:44 - 000000000 ___HD C:\$WinREAgent
    2021-12-15 09:56 - 2021-12-15 09:56 - 000038032 _____ C:\WINDOWS\system32\Drivers\truesight.sys
    2021-12-15 09:44 - 2021-12-15 09:44 - 008540344 _____ (Malwarebytes) C:\Users\wparr\Downloads\AdwCleaner.exe
    2021-12-15 09:15 - 2021-12-15 09:39 - 000000000 ____D C:\ProgramData\RogueKiller
    2021-12-15 09:15 - 2021-12-15 09:15 - 000000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
    2021-12-15 09:15 - 2021-12-15 09:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
    2021-12-15 09:15 - 2021-12-15 09:15 - 000000000 ____D C:\Program Files\RogueKiller
    2021-12-15 09:14 - 2021-12-15 09:14 - 041646128 _____ (Adlice Software ) C:\Users\wparr\Downloads\RogueKiller_setup.exe
    2021-12-14 15:31 - 2021-12-14 15:31 - 000001391 _____ C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
    2021-12-14 15:31 - 2021-12-14 15:31 - 000000000 ____D C:\Users\wparr\AppData\Local\PCHealthCheck
    2021-12-14 15:25 - 2021-12-14 15:25 - 000000853 _____ C:\Users\Public\Desktop\BitComet.lnk
    2021-12-14 15:25 - 2021-12-14 15:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet (64-bit)
    2021-12-14 08:53 - 2021-12-15 13:30 - 000000000 ____D C:\FRST
    2021-12-13 20:49 - 2021-12-14 07:51 - 000000000 ____D C:\Program Files\Trojan Killer
    2021-12-13 20:49 - 2021-12-13 20:49 - 000001774 _____ C:\Users\Public\Desktop\Reset Browser Settings.lnk
    2021-12-13 20:49 - 2021-12-13 20:49 - 000000900 _____ C:\Users\Public\Desktop\Trojan Killer.lnk
    2021-12-13 18:02 - 2021-12-13 18:02 - 000003852 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
    2021-12-13 18:02 - 2021-12-13 18:02 - 000003410 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
    2021-12-12 21:38 - 2021-12-12 21:38 - 000001424 _____ C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
    2021-12-12 21:38 - 2021-12-12 21:38 - 000001318 _____ C:\Users\wparr\Desktop\ESET Online Scanner.lnk
    2021-12-12 21:38 - 2021-12-12 21:38 - 000000000 ____D C:\Users\wparr\AppData\Local\ESET
    2021-12-12 15:48 - 2021-12-12 15:48 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3399867593-3550638609-2408602673-1001
    2021-12-11 20:58 - 2021-12-11 20:58 - 008540344 _____ (Malwarebytes) C:\Users\wparr\Desktop\adwcleaner_8.3.1.exe
    2021-12-11 16:30 - 2021-12-11 16:30 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
    2021-12-10 10:37 - 2021-12-10 10:37 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
    2021-12-10 10:37 - 2021-12-10 10:37 - 000011785 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
    2021-12-09 17:46 - 2021-12-09 17:46 - 000203264 _____ C:\WINDOWS\system32\uwfcfgmgmt.dll
    2021-12-09 17:46 - 2021-12-09 17:46 - 000170496 _____ C:\WINDOWS\system32\DeviceUpdateCenterCsp.dll
    2021-12-09 17:46 - 2021-12-09 17:46 - 000158208 _____ C:\WINDOWS\system32\uwfcsp.dll
    2021-12-09 17:46 - 2021-12-09 17:46 - 000040960 _____ C:\WINDOWS\system32\uwfservicingapi.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 002295296 _____ (Digimarc) C:\WINDOWS\system32\DMRCDecoder.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 002111488 _____ (Digimarc) C:\WINDOWS\SysWOW64\DMRCDecoder.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 001164288 _____ C:\WINDOWS\system32\MBR2GPT.EXE
    2021-12-09 17:45 - 2021-12-09 17:45 - 000672768 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 000611960 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
    2021-12-09 17:45 - 2021-12-09 17:45 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
    2021-12-09 17:45 - 2021-12-09 17:45 - 000098304 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
    2021-12-09 17:45 - 2021-12-09 17:45 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
    2021-12-09 17:44 - 2021-12-09 17:44 - 000706536 _____ C:\WINDOWS\system32\TextShaping.dll
    2021-12-09 17:44 - 2021-12-09 17:44 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
    2021-12-09 17:44 - 2021-12-09 17:44 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
    2021-12-09 15:13 - 2021-12-09 15:13 - 000001816 _____ C:\Users\Public\Desktop\iTunes.lnk
    2021-12-09 15:13 - 2021-12-09 15:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2021-12-09 15:13 - 2021-12-09 15:13 - 000000000 ____D C:\Program Files\iTunes
    2021-12-09 15:01 - 2021-12-09 15:01 - 000001146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
    2021-12-09 15:01 - 2021-12-09 15:01 - 000000000 ____D C:\Program Files\PCHealthCheck

    ==================== One month (modified) ==================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2021-12-15 13:32 - 2020-07-11 06:56 - 000000000 ____D C:\Users\wparr\AppData\Local\IPVanish
    2021-12-15 13:32 - 2019-03-12 12:38 - 000266574 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
    2021-12-15 13:27 - 2020-06-04 16:11 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2021-12-15 13:27 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2021-12-15 13:27 - 2019-02-26 15:25 - 000000000 ____D C:\Program Files (x86)\Google
    2021-12-15 11:56 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp
    2021-12-15 11:44 - 2019-02-26 15:09 - 000000000 ____D C:\WINDOWS\system32\MRT
    2021-12-15 11:40 - 2019-02-26 15:09 - 137938848 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2021-12-15 10:01 - 2020-06-04 16:14 - 001390218 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2021-12-15 10:01 - 2020-06-04 12:24 - 000426112 _____ C:\WINDOWS\system32\prfh0804.dat
    2021-12-15 10:01 - 2020-06-04 12:24 - 000132670 _____ C:\WINDOWS\system32\prfc0804.dat
    2021-12-15 10:01 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF
    2021-12-15 09:57 - 2020-07-15 17:31 - 000008192 _____ C:\WINDOWS\SysWOW64\WDPABKP.dat
    2021-12-15 09:57 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness
    2021-12-15 09:56 - 2020-06-04 16:20 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2021-12-15 09:56 - 2020-06-04 16:11 - 000008192 ___SH C:\DumpStack.log.tmp
    2021-12-15 09:56 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
    2021-12-15 09:56 - 2019-02-27 07:03 - 000000000 ____D C:\ProgramData\Hauppauge
    2021-12-15 09:56 - 2019-02-26 14:53 - 000000000 ____D C:\ProgramData\NVIDIA
    2021-12-15 09:55 - 2019-12-07 04:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
    2021-12-15 09:12 - 2020-06-04 20:53 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
    2021-12-15 09:12 - 2020-06-04 20:53 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
    2021-12-15 09:09 - 2020-06-04 16:20 - 000004168 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{E40FD7B8-2283-43B4-8DF9-946CEF68E72E}
    2021-12-14 23:04 - 2019-03-01 17:27 - 000000000 ____D C:\Users\wparr\AppData\Roaming\vlc
    2021-12-14 20:29 - 2019-02-26 16:36 - 000000000 ____D C:\Users\wparr\AppData\Roaming\BitComet
    2021-12-14 18:06 - 2019-02-26 15:26 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2021-12-14 18:06 - 2019-02-26 15:26 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2021-12-14 15:25 - 2019-02-26 16:36 - 000000000 ____D C:\Program Files\BitComet
    2021-12-14 08:48 - 2019-03-13 13:48 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2021-12-14 07:49 - 2019-02-26 17:16 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
    2021-12-13 20:41 - 2020-07-01 11:28 - 000000000 ____D C:\Program Files (x86)\MuldeR
    2021-12-13 20:39 - 2019-02-26 15:49 - 000001079 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
    2021-12-13 20:39 - 2019-02-26 15:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
    2021-12-12 21:38 - 2019-11-24 14:39 - 000000000 ____D C:\Users\wparr\AppData\Local\CrashDumps
    2021-12-12 15:48 - 2021-03-04 16:28 - 000002425 _____ C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2021-12-12 15:48 - 2020-06-04 16:20 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3399867593-3550638609-2408602673-1001
    2021-12-11 16:30 - 2020-06-27 11:39 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
    2021-12-11 16:30 - 2019-08-02 09:15 - 000160176 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
    2021-12-11 16:30 - 2019-08-02 09:15 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2021-12-11 16:29 - 2019-02-26 16:00 - 000000000 ____D C:\ProgramData\Malwarebytes
    2021-12-11 16:29 - 2019-02-26 16:00 - 000000000 ____D C:\Program Files\Malwarebytes
    2021-12-11 16:07 - 2019-02-26 17:03 - 000000000 ____D C:\Users\wparr\AppData\Local\D3DSCache
    2021-12-10 21:05 - 2020-06-04 20:53 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
    2021-12-10 21:05 - 2020-06-04 20:53 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
    2021-12-10 16:36 - 2019-02-26 15:19 - 000000000 ____D C:\Users\wparr\AppData\Roaming\MusicBee
    2021-12-10 16:28 - 2019-04-01 07:46 - 000000000 ____D C:\Users\wparr\Downloads\incomplete
    2021-12-10 16:27 - 2018-08-24 14:02 - 000000000 ____D C:\Users\wparr\Documents\Bill
    2021-12-10 16:24 - 2018-08-24 14:02 - 000000000 ____D C:\Users\wparr\Documents\Ryan
    2021-12-10 10:52 - 2020-06-04 16:11 - 000486384 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2021-12-10 10:51 - 2019-12-07 04:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SystemResources
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\oobe
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\Provisioning
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
    2021-12-10 10:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\bcastdvr
    2021-12-10 00:09 - 2019-02-26 17:15 - 000000000 ____D C:\Program Files\CCleaner
    2021-12-10 00:08 - 2019-12-07 04:54 - 000000000 ___SD C:\WINDOWS\system32\AppV
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\setup
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Dism
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellComponents
    2021-12-10 00:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\DiagTrack
    2021-12-10 00:08 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\servicing
    2021-12-09 17:32 - 2021-01-22 11:16 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
    2021-12-09 16:40 - 2019-02-26 15:02 - 000000000 ____D C:\ProgramData\Packages
    2021-12-09 16:31 - 2019-02-26 17:34 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
    2021-12-09 15:24 - 2019-02-26 14:45 - 000000000 ____D C:\Users\wparr\AppData\Local\Packages
    2021-12-09 15:15 - 2020-06-04 16:20 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
    2021-12-09 15:15 - 2019-02-26 17:21 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
    2021-12-09 15:13 - 2019-06-11 09:22 - 000000000 ____D C:\Program Files\Microsoft Office
    2021-12-09 15:00 - 2020-06-04 16:20 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
    2021-12-09 15:00 - 2020-06-04 16:20 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
    2021-12-09 15:00 - 2019-02-26 14:49 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe

    ==================== Files in the root of some directories ========

    2019-11-24 11:10 - 2020-10-09 11:31 - 000000128 _____ () C:\Users\wparr\AppData\Local\PUTTY.RND

    ==================== SigCheck ============================

    (There is no automatic fix for files that do not pass verification.)

    ==================== End of FRST.txt ========================

  12. #12
    Join Date
    Aug 2019
    Posts
    11
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-12-2021
    Ran by wparr (15-12-2021 13:34:06)
    Running from C:\Users\wparr\Downloads
    Microsoft Windows 10 Pro Version 20H2 19042.1387 (X64) (2020-06-04 21:20:21)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================


    (If an entry is included in the fixlist, it will be removed.)

    Administrator (S-1-5-21-3399867593-3550638609-2408602673-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-3399867593-3550638609-2408602673-503 - Limited - Disabled)
    Guest (S-1-5-21-3399867593-3550638609-2408602673-501 - Limited - Disabled)
    WDAGUtilityAccount (S-1-5-21-3399867593-3550638609-2408602673-504 - Limited - Disabled)
    wparr (S-1-5-21-3399867593-3550638609-2408602673-1001 - Administrator - Enabled) => C:\Users\wparr

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: TACHYON Internet Security 5.0 (Enabled - Up to date) {7FF5C59B-27F8-CF97-96BE-6B3FAA495547}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    7-Zip 18.05 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1805-000001000000}) (Version: 18.05.00.0 - Igor Pavlov)
    Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 21.007.20099 - Adobe Systems Incorporated)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 32.0.0.125 - Adobe)
    ApowerMirror V1.4.3.5 (HKLM-x32\...\{a9482532-9c34-478c-80c3-85bdccbb981f}_is1) (Version: 1.4.3.5 - APOWERSOFT LIMITED)
    Apowersoft Online Launcher version 1.7.7 (HKLM-x32\...\{20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1) (Version: 1.7.7 - APOWERSOFT LIMITED)
    Apple Application Support (32-bit) (HKLM-x32\...\{9738288C-21BC-4F54-AB4F-72F059339376}) (Version: 8.6 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\...\{DEB339C1-2687-43AB-816A-8714F3E26846}) (Version: 8.6 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{527DD209-8A66-482F-8779-C7B3BACCA8F1}) (Version: 15.0.0.16 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{A3985C05-7386-411F-A4BF-32A73F37EB44}) (Version: 2.6.3.1 - Apple Inc.)
    BitComet 1.84 (HKLM-x32\...\BitComet_x64) (Version: 1.84 - CometNetwork)
    Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
    calibre (HKLM-x32\...\{09CF108A-927D-492C-9D42-54D5F7678096}) (Version: 4.22.0 - Kovid Goyal)
    CCleaner (HKLM\...\CCleaner) (Version: 5.65 - Piriform)
    EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version: - EaseUS)
    EdgeManage (HKLM-x32\...\{535F8180-FCD4-4593-8E21-BF228B216BE3}) (Version: 2.2.8 - Emmet Gray)
    EPUB to MOBI (HKLM-x32\...\{C65AA5AE-8B80-46B6-ADFC-BBF1EFF2AD98}_is1) (Version: - epubtomobi.com)
    FileZilla Client 3.51.0 (HKLM-x32\...\FileZilla Client) (Version: 3.51.0 - Tim Kosse)
    FlacSquisher 1.3.8 (HKLM-x32\...\FlacSquisher) (Version: 1.3.8 - FlacSquisher)
    Free APE to MP3 Converter 1.0 (HKLM-x32\...\{23CAF97E-FC9A-4043-A8B2-3C8605305D35}_is1) (Version: 1.0 - Jacek Pazera)
    Free FLAC to MP3 Converter 1.4 (HKLM-x32\...\{A54C01BD-1277-4722-B42B-EC9800A90B1E}_is1) (Version: 1.4 - PolySoft Solutions)
    Free M4a to MP3 Converter X (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com)
    FreeFileSync 11.4 (HKLM-x32\...\FreeFileSync_is1) (Version: 11.4 - FreeFileSync.org)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 96.0.4664.110 - Google LLC)
    Hauppauge WinTV 8.5 (HKLM-x32\...\Hauppauge WinTV 8.5) (Version: v8.5.37045 - Hauppauge Computer Works)
    IPVanish (HKLM\...\{E293F597-AF63-4D16-B313-EF4054532953}) (Version: 3.6.6.0 - Mudhook Marketing, Inc) Hidden
    IPVanish (HKLM-x32\...\{90e9256e-5d6a-4ca4-834b-a9d1f9014024}) (Version: 3.6.6.0 - Mudhook Marketing, Inc)
    iTunes (HKLM\...\{0B3CC856-3A62-443A-B6CE-DED2D4495D56}) (Version: 12.12.2.2 - Apple Inc.)
    K-Lite Codec Pack 15.4.8 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 15.4.8 - KLCP)
    Malwarebytes version 4.4.11.149 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.4.11.149 - Malwarebytes)
    MediaHuman Audio Converter version 1.9.7 (HKLM-x32\...\MHAudioConverter_is1) (Version: 1.9.7 - MediaHuman)
    Mediatek RT2870 Wireless LAN Card (HKLM-x32\...\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}) (Version: 5.1.28.0 - MediatekWiFi)
    Medieval CUE Splitter (HKLM-x32\...\{B96D2269-568B-4CBF-9332-12FAE8B158F7}) (Version: 1.2.0 - Medieval Software)
    Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 96.0.1054.57 - Microsoft Corporation)
    Microsoft Office Professional Plus 2019 - en-us (HKLM\...\ProPlus2019Retail - en-us) (Version: 16.0.14701.20226 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\OneDriveSetup.exe) (Version: 21.230.1107.0004 - Microsoft Corporation)
    Microsoft Project - en-us (HKLM\...\ProjectPro2019Retail - en-us) (Version: 16.0.14701.20226 - Microsoft Corporation)
    Microsoft Update Health Tools (HKLM\...\{29B15818-E79F-4AB0-8938-9410C807AD76}) (Version: 2.84.0.0 - Microsoft Corporation)
    Microsoft Visio - en-us (HKLM\...\VisioPro2019Retail - en-us) (Version: 16.0.14701.20226 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{4cadd82e-f9f2-4f69-bcfd-a0b929d8e6e2}) (Version: 14.0.23918.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{8a225685-3b19-4387-b61b-830061421071}) (Version: 14.0.23918.0 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
    MusicBee 3.3.7491 (HKLM-x32\...\MusicBee) (Version: 3.3.7491 - Steven Mayall)
    MusicBrainz Picard (HKLM-x32\...\MusicBrainz Picard) (Version: 2.5.6 - MusicBrainz)
    MyHarmony (HKLM-x32\...\{2AD8F8A1-ECE5-4890-BCC2-B4396370A0D4}) (Version: 1.0.308 - Logitech)
    NativeDesktopMediaService (HKLM-x32\...\{4A91D8B3-712F-4815-B29B-E610008C4704}) (Version: 3.6.1 - Jetmedia) <==== ATTENTION
    NETGEAR WNDA3100v2 wireless USB 2.0 driver (HKLM-x32\...\{3C7839E7-21F4-49E0-B4D5-AC8ED818CCB0}) (Version: 2.2.0.6 - NETGEAR)
    NVIDIA Graphics Driver 456.71 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 456.71 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.3.38.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.35 - NVIDIA Corporation)
    Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14701.20226 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14701.20226 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
    paint.net (HKLM\...\{2025DAA7-0653-4F18-B66F-900E6F2320EC}) (Version: 4.2.13 - dotPDN LLC)
    Photo Transfer App (HKLM-x32\...\com.erclab.air.phototransferapp) (Version: 2.8.3 - UNKNOWN)
    Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
    PowerISO (HKLM-x32\...\PowerISO) (Version: 7.5 - Power Software Ltd)
    Revo Uninstaller 2.3.5 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.3.5 - VS Revo Group, Ltd.)
    RogueKiller version 15.1.5.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 15.1.5.0 - Adlice Software)
    SABnzbd 3.1.1 (HKLM-x32\...\SABnzbd) (Version: 3.1.1 - The SABnzbd Team)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 8.0.1030 - SUPERAntiSpyware.com)
    Switch Sound File Converter (HKLM-x32\...\Switch) (Version: 5.06 - NCH Software)
    Trojan Killer Portable (HKLM\...\GridinSoft Trojan Killer) (Version: 2.1.98 - Gridinsoft LLC)
    VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.11 - VideoLAN)
    WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 9.16 - NCH Software)
    WD Quick View (HKLM-x32\...\{4EA8640B-DEB6-478F-BDAC-F4BCBEEFAFAB}) (Version: 2.4.21.1 - Western Digital Technologies, Inc.)
    WD SmartWare (HKLM\...\{798354C0-D5F2-4A43-ADEE-3DA9B1725ECC}) (Version: 2.4.21.1 - Western Digital Technologies, Inc.)
    WD SmartWare Installer (HKLM-x32\...\{5be946d0-7ba1-41b6-808a-0e7f2b7cb4a8}) (Version: 2.4.21.1 - Western Digital Technologies, Inc.)
    Windows PC Health Check (HKLM\...\{014B7442-C784-45D3-A152-F7D2C651F28A}) (Version: 3.3.2110.22002 - Microsoft Corporation)
    Windows PC Health Check (HKLM\...\{B1E7D0FD-7CFE-4E0C-A5DA-0F676499DB91}) (Version: 3.2.2110.14001 - Microsoft Corporation)
    WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
    Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.3) (Version: 1.3.7 - Xvid Team)

    Packages:
    =========
    Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.71.3.0_x86__kgqvnymyfvs32 [2021-12-15] (king.com)
    Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.2170.3.0_x86__kgqvnymyfvs32 [2021-12-13] (king.com)
    Cooking Fever -> C:\Program Files\WindowsApps\NORDCURRENT.COOKINGFEVER_13.0.10.0_x86__m9bz608c1b9ra [2021-08-06] (Nordcurrent)
    CUE Splitter -> C:\Program Files\WindowsApps\38812MedievalSoftware.CUESplitter_2.0.8.0_x64__qfb5004rcjhse [2019-06-06] (Medieval Software)
    EZ TV Listings -> C:\Program Files\WindowsApps\32063Envisra.EZTVListings_2.2.0.0_neutral__jyw6djrsfaffg [2019-03-08] (Envisra)
    HEVC Video Extensions -> C:\Program Files\WindowsApps\Microsoft.HEVCVideoExtensions_1.0.42702.0_x64__8wekyb3d8bbwe [2021-12-09] (Microsoft Corporation)
    HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_133.1.340.0_x64__v10z8vjag6ke6 [2021-12-13] (HP Inc.)
    iHeartRadio -> C:\Program Files\WindowsApps\ClearChannelRadioDigital.iHeartRadio_7.2.1.0_x64__a76a11dkgb644 [2021-12-09] (iHeartMedia.)
    LastPass: Free Password Manager -> C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.69.0.0_neutral__qq0fmhteeht3j [2021-08-05] (LastPass)
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-26] (Microsoft Corporation) [MS Ad]
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-26] (Microsoft Corporation) [MS Ad]
    Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.11.12030.0_x64__8wekyb3d8bbwe [2021-12-09] (Microsoft Studios) [MS Ad]
    MusicBee -> C:\Program Files\WindowsApps\50072StevenMayall.MusicBee_3.4.1.0_x86__kcr266et74avj [2021-08-05] (Steven Mayall)
    My MP4 to MP3 Converter -> C:\Program Files\WindowsApps\32573MMSoftware.MyMP4toMP3Converter_1.5.7.0_x64__xky5rpyx4kdm4 [2021-12-09] (M&amp;MSoftware) [MS Ad]
    Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-10-25] (Microsoft Corporation)
    Phototastic Collage -> C:\Program Files\WindowsApps\ThumbmunkeysLtd.PhototasticCollage_3.27.5.0_x64__nfy108tqq3p12 [2021-12-15] (Thumbmunkeys Ltd)

    ==================== Custom CLSID (Whitelisted): ==============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
    ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2019-09-14] (Power Software Limited -> Power Software Ltd)
    ContextMenuHandlers1: [WDBackupMenuHandler] -> {C752BC82-C19A-4827-9C15-0996BA85C180} => C:\Program Files\Western Digital\WD SmartWare\\WDContextMenuHandler.dll [2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers2: [CWDDriveMenuHandler] -> {CCEFA845-DCDB-4A2F-8BED-DBE87CD198EC} => C:\Program Files\Western Digital\WD SmartWare\\WDContextMenuHandler.dll [2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
    ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2019-09-14] (Power Software Limited -> Power Software Ltd)
    ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-10-01] (NVIDIA Corporation -> NVIDIA Corporation)
    ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2019-09-14] (Power Software Limited -> Power Software Ltd)
    ContextMenuHandlers6: [WDBackupMenuHandler] -> {C752BC82-C19A-4827-9C15-0996BA85C180} => C:\Program Files\Western Digital\WD SmartWare\\WDContextMenuHandler.dll [2018-05-23] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
    ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)

    ==================== Codecs (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Drivers32: [vidc.XVID] => C:\WINDOWS\system32\xvidvfw.dll [251392 2019-12-28] () [File not signed]
    HKLM\...\Drivers32: [msacm.l3acm] => C:\Windows\SysWOW64\l3codecp.acm [189440 2019-12-07] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
    HKLM\...\Drivers32: [vidc.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [235520 2019-12-28] () [File not signed]

    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)

    Shortcut: C:\Users\wparr\Favorites\NCH Software Download Site.lnk -> hxxp://www.nch.com.au/index.htm
    ShortcutWithArgument: C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
    ShortcutWithArgument: C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ledger Manager.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=beimhnaefocolcplfimocfiaiefpkgbf
    ShortcutWithArgument: C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ledger Wallet Bitcoin.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=kkdpmhnladdopljabkgpacgpliggeeaf
    ShortcutWithArgument: C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ledger Wallet Ethereum.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=hmlhkialjkaldndjnlcdfdphcgeadkkm
    ShortcutWithArgument: C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\The Economist.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=gebjgjhbjedcomcajgpodjgfjgkepgpl

    ==================== Loaded Modules (Whitelisted) =============

    2019-03-13 13:48 - 2015-03-05 17:22 - 000380928 _____ () [File not signed] C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiLib.dll
    2019-02-27 07:13 - 2017-08-23 22:40 - 000025600 _____ () [File not signed] C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServerps.dll
    2019-02-27 07:13 - 2011-08-23 12:04 - 000057344 _____ () [File not signed] C:\Program Files (x86)\WinTV\TVServer\libhdhomerun.dll
    2019-08-15 17:13 - 2019-08-15 17:13 - 000989184 _____ () [File not signed] C:\Program Files\IPVanish VPN\runtimes\win-x86\native\e_sqlite3.dll
    2019-03-13 13:48 - 2011-06-21 15:04 - 000229376 _____ (Broadcom Corporation) [File not signed] C:\Program Files (x86)\NETGEAR\WNDA3100v2\wps_api.dll
    2019-02-27 07:13 - 2015-11-24 19:59 - 000134656 _____ (Hauppauge Computer Works) [File not signed] C:\Program Files (x86)\WinTV\WinTV8\hcwtsfilter.ax
    2019-02-27 07:13 - 2018-06-12 15:20 - 000113152 _____ (Hauppauge Computer Works) [File not signed] C:\Program Files (x86)\WinTV\WinTV8\HCWTSWriter.ax
    2019-02-27 07:13 - 2018-12-21 11:50 - 000334848 _____ (Hauppauge Computer Works, Inc.) [File not signed] C:\Program Files (x86)\WinTV\WinTV8\PsiParser.ax
    2018-04-30 16:00 - 2018-04-30 16:00 - 000075776 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
    2018-05-23 11:02 - 2018-05-23 11:02 - 001006080 ____R (Robert Simpson, et al.) [File not signed] [File is in use] C:\Program Files (x86)\Western Digital\WD SmartWare\System.Data.SQLite.dll

    ==================== Alternate Data Streams (Whitelisted) ========

    ==================== Safe Mode (Whitelisted) ==================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

    ==================== Association (Whitelisted) =================

    ==================== Internet Explorer (Whitelisted) ==========

    BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)
    Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-12-09] (Microsoft Corporation -> Microsoft Corporation)

    ==================== Hosts content: =========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2018-09-15 02:31 - 2018-09-15 02:31 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

    ==================== Other Areas ===========================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\wparr\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
    DNS Servers: 198.18.0.1 - 198.18.0.2
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
    Windows Firewall is enabled.

    Network Binding:
    =============
    Bluetooth Network Connection: General NDIS Protocol Driver -> SCM_NDISPROT (enabled)
    Ethernet: General NDIS Protocol Driver -> SCM_NDISPROT (enabled)

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (If an entry is included in the fixlist, it will be removed.)

    HKLM\...\StartupApproved\StartupFolder: => "Mediatek Wireless Utility.lnk"
    HKLM\...\StartupApproved\StartupFolder: => "AutoStart IR.lnk"
    HKLM\...\StartupApproved\StartupFolder: => "WinTV Recording Status.lnk"
    HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
    HKLM\...\StartupApproved\Run: => "iTunesHelper"
    HKLM\...\StartupApproved\Run32: => "BCSSync"
    HKLM\...\StartupApproved\Run32: => "PWRISOVM.EXE"
    HKLM\...\StartupApproved\Run32: => "T5"
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\...\StartupApproved\Run: => "Discord"

    ==================== FirewallRules (Whitelisted) ================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{076F5BDD-AE62-464D-860B-52014AC35B23}] => (Block) C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe (ERCLab -> ) [File not signed]
    FirewallRules: [{A36228CD-0987-49FB-8160-FE9D688DCCF1}] => (Block) C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe (ERCLab -> ) [File not signed]
    FirewallRules: [{D63A26F2-DFEE-4BBC-BD4A-92C480A84048}] => (Block) C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe () [File not signed]
    FirewallRules: [{523BFA55-4408-48FB-8B41-77331EEDD121}] => (Block) C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe () [File not signed]
    FirewallRules: [UDP Query User{12822254-0783-40AF-8484-012EB9FDE37F}C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe] => (Allow) C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe () [File not signed]
    FirewallRules: [TCP Query User{F82F0342-4B5E-40E5-A6A5-E5AE5F788E33}C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe] => (Allow) C:\program files (x86)\erclab\phototransferapp\phototransferapp\assets\utils\tunnel\phototransferusbtunnel.core.exe () [File not signed]
    FirewallRules: [UDP Query User{E63B10F8-65A1-4B36-8C31-30B9A8B2A0BC}C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe] => (Allow) C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe (ERCLab -> ) [File not signed]
    FirewallRules: [TCP Query User{F69661A7-A6BF-4C28-89D5-AD6C8135BFC7}C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe] => (Allow) C:\program files (x86)\erclab\phototransferapp\phototransferapp\phototransferapp.exe (ERCLab -> ) [File not signed]
    FirewallRules: [{FF5E6163-0CBD-4573-B9CD-851FDD3C746F}] => (Allow) C:\Users\wparr\AppData\Local\Apowersoft\Online Audio Recorder\Online Audio Recorder.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [{B9CF1440-3AFB-4E6F-8ABC-B05F4DE48264}] => (Allow) C:\Users\wparr\AppData\Local\Apowersoft\Online Audio Recorder\Online Audio Recorder.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [{CE07184C-8EC7-4346-B6B1-EA5F9D0FB4D2}] => (Allow) C:\Users\wparr\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [{6CA9AAC4-FC3A-4E55-BBC3-54A4CBE2C9C8}] => (Allow) C:\Users\wparr\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [{9EE516F8-5269-48B8-A39C-E251E44059DB}] => (Allow) C:\WINDOWS\SysWOW64\TCPSVCS.EXE (Microsoft Windows -> Microsoft Corporation)
    FirewallRules: [{10CA01A3-7F5F-4AD2-BE14-D2027FA9F12B}] => (Allow) C:\Program Files\BitComet\BitComet.exe (Xing Wang -> www.BitComet.com)
    FirewallRules: [{181FA518-16AA-40D3-A6AB-418BE927FC17}] => (Allow) C:\Program Files\BitComet\BitComet.exe (Xing Wang -> www.BitComet.com)
    FirewallRules: [{D705DA25-1E31-4483-9629-D21592729026}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe (The SABnzbd-Team) [File not signed]
    FirewallRules: [{922A863D-008A-4BB3-AC1C-29C73ED7CA13}] => (Allow) C:\Program Files (x86)\WinTV\WinTV8\WinTV8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [{FD50C90B-8443-436B-8E6D-EDE9C91A0A43}] => (Allow) C:\Program Files (x86)\WinTV\WinTV8\WinTV8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [{13CA2D9F-B1D9-43D6-B9B0-A1848D5B2071}] => (Allow) C:\Program Files (x86)\WinTV\WinTV8\WinTV8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [{14357ADE-2E17-46EA-961C-1530A843A0DF}] => (Allow) C:\Program Files (x86)\WinTV\WinTV8\WinTV8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [{5773ACBE-AD64-4EA7-899B-EA19FBC0B478}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\CaptureDCR.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{26DDCF11-1D0C-417E-A1F4-52228430962D}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\CaptureDCR.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{E419C9C5-1FB6-4228-AD81-A2329E0B235B}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\CaptureDCR.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{CB741285-1CC1-42B8-BB22-83FFAA6F26A8}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\CaptureDCR.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed]
    FirewallRules: [{64F6F302-C37D-4658-89F0-D09367616236}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed] [File is in use]
    FirewallRules: [{D4A4D5B8-6C6A-4F2C-9FC9-C87B4F1DA420}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed] [File is in use]
    FirewallRules: [{73A0E39D-BC48-451C-87ED-DC6E4FDBEC8E}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed] [File is in use]
    FirewallRules: [{E9D78991-5279-4A55-A046-FA376CD65376}] => (Allow) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc) [File not signed] [File is in use]
    FirewallRules: [TCP Query User{8A54691C-F183-42E3-9051-BBC6AC1C6263}C:\program files\bitcomet\bitcomet.exe] => (Allow) C:\program files\bitcomet\bitcomet.exe (Xing Wang -> www.BitComet.com)
    FirewallRules: [UDP Query User{561B9F98-2906-46EA-AD22-B95113428304}C:\program files\bitcomet\bitcomet.exe] => (Allow) C:\program files\bitcomet\bitcomet.exe (Xing Wang -> www.BitComet.com)
    FirewallRules: [{51E3B656-8403-46A4-BCCE-5B4CDC09FDF4}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{B5189686-99C1-43A9-9E7C-E06CDDCA8523}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{3A85F4D0-F17E-4CF2-A34B-88E487C326EB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{5E15087F-14F0-4646-A495-95824B7ACC7C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{F709B005-4BCB-44A1-9332-82F20EB871A8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{35B14249-E655-4703-BAA7-4E4A45D6B20D}] => (Allow) C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe (MEDIATEK INC. -> Mediatek Inc.) [File not signed]
    FirewallRules: [{64671D0F-9588-4E4D-A966-8DFAC1441401}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe (The SABnzbd-Team) [File not signed]
    FirewallRules: [{D270B93F-1D2D-4823-A0E3-DEA4C6BB748A}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerMirror\ApowerMirror.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [{F532B012-7F0F-4AA9-B077-F903833BB6C9}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerMirror\ApowerMirror.exe (Apowersoft Ltd -> Apowersoft)
    FirewallRules: [TCP Query User{DABB14A4-85AA-4448-BB21-A4F076AC8EA5}C:\program files (x86)\wintv\wintv8\wintv8.exe] => (Allow) C:\program files (x86)\wintv\wintv8\wintv8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [UDP Query User{6948D116-6706-412C-8C81-0FCDD2C7F6C7}C:\program files (x86)\wintv\wintv8\wintv8.exe] => (Allow) C:\program files (x86)\wintv\wintv8\wintv8.exe (HAUPPAUGE COMPUTER WORKS, INC. -> Hauppauge Computer Works, Inc.) [File not signed]
    FirewallRules: [{FAB314C4-F5C9-451C-A0AE-1A523E8B0DEE}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe (The SABnzbd-Team) [File not signed]
    FirewallRules: [{3948A791-6391-4D5F-917D-5E765AC8AB06}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe (The SABnzbd-Team) [File not signed]
    FirewallRules: [{A75A9CA1-6956-4526-8445-4C9BA948DE71}] => (Allow) C:\Program Files\SABnzbd\SABnzbd-console.exe (The SABnzbd-Team) [File not signed]
    FirewallRules: [{87098815-1973-491C-9592-4A5AFA996B7B}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{E5529D02-8D41-4405-974C-AE69FD238C7D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
    FirewallRules: [{FEB761E8-7B83-4CE7-9D94-328943CD87F2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{7AF64732-F2C8-49A9-8AD6-CFBEEA42962D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{B1B6D1C5-3716-4A49-B336-7D65999299AD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{E1708892-EC2D-42A0-AD54-FE5202AADCCC}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{97CAFAB5-D182-4667-8DA7-3449F961B493}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

    ==================== Restore Points =========================

    09-12-2021 15:45:30 Scheduled Checkpoint
    09-12-2021 16:19:00 Windows Modules Installer
    09-12-2021 17:32:20 Windows Modules Installer
    09-12-2021 17:34:47 Windows Modules Installer
    10-12-2021 10:24:32 Windows Modules Installer
    10-12-2021 10:27:04 Windows Modules Installer
    14-12-2021 15:30:59 Installed Windows PC Health Check
    15-12-2021 11:44:48 Windows Modules Installer

    ==================== Faulty Device Manager Devices ============


    ==================== Event log errors: ========================

    Application errors:
    ==================
    Error: (12/15/2021 01:27:35 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0

    Error: (12/15/2021 01:27:35 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=25, authorId=9, vendorId=0, vendorType=0

    Error: (12/15/2021 01:27:35 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=17, authorId=9, vendorId=0, vendorType=0

    Error: (12/15/2021 01:27:35 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=55, authorId=311, vendorId=0, vendorType=0

    Error: (12/15/2021 01:27:35 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=254, authorId=311, vendorId=14122, vendorType=1

    Error: (12/15/2021 01:27:35 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=21, authorId=1814, vendorId=0, vendorType=0

    Error: (12/15/2021 01:27:35 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=18, authorId=1814, vendorId=0, vendorType=0

    Error: (12/15/2021 01:27:34 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: MEDIA-CENTER)
    Description: Skipping: Eap method DLL path validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0


    System errors:
    =============
    Error: (12/15/2021 09:55:13 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The WD Backup service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.

    Error: (12/15/2021 09:55:12 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The WD Drive Manager service terminated unexpectedly. It has done this 1 time(s).

    Error: (12/15/2021 09:55:12 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The MediatekRegistryWriter64 service terminated unexpectedly. It has done this 1 time(s).

    Error: (12/15/2021 09:55:12 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The SAS Core Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.

    Error: (12/15/2021 09:55:12 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The MediatekRegistryWriter service terminated unexpectedly. It has done this 1 time(s).

    Error: (12/15/2021 09:55:12 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The RogueKiller RTP service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.

    Error: (12/15/2021 09:55:12 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The HauppaugeTVServer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.

    Error: (12/15/2021 09:55:12 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).


    Windows Defender:
    ================
    Date: 2021-12-14 15:15:02
    Description:
    Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...6&enterprise=0
    Name: PUABundler:Win32/BitComet_BundleInstaller
    Severity: Low
    Category: Potentially Unwanted Software
    Path: file:_C:\Users\wparr\Downloads\bitcomet_setup (1).exe; file:_C:\Users\wparr\Downloads\bitcomet_setup.exe; webfile:_C:\Users\wparr\Downloads\bitcomet_setup (1).exe|https://dkh85d4edd1z8.cloudfront.net...9864966286593; webfile:_C:\Users\wparr\Downloads\bitcomet_setup.exe|https://dkh85d4edd1z8.cloudfront.net...39864466598886
    Detection Origin: Internet
    Detection Type: Concrete
    Detection Source: Downloads and attachments
    Process Name: C:\Windows\explorer.exe
    Security intelligence Version: AV: 1.355.247.0, AS: 1.355.247.0, NIS: 1.355.247.0
    Engine Version: AM: 1.1.18800.4, NIS: 1.1.18800.4

    Date: 2021-12-14 15:14:58
    Description:
    Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...6&enterprise=0
    Name: PUABundler:Win32/BitComet_BundleInstaller
    Severity: Low
    Category: Potentially Unwanted Software
    Path: file:_C:\Users\wparr\Downloads\bitcomet_setup (1).exe; file:_C:\Users\wparr\Downloads\bitcomet_setup.exe; webfile:_C:\Users\wparr\Downloads\bitcomet_setup (1).exe|https://dkh85d4edd1z8.cloudfront.net...9864966286593; webfile:_C:\Users\wparr\Downloads\bitcomet_setup.exe|https://dkh85d4edd1z8.cloudfront.net...39864466598886
    Detection Origin: Internet
    Detection Type: Concrete
    Detection Source: Downloads and attachments
    Process Name: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
    Security intelligence Version: AV: 1.355.247.0, AS: 1.355.247.0, NIS: 1.355.247.0
    Engine Version: AM: 1.1.18800.4, NIS: 1.1.18800.4

    Date: 2021-12-14 15:14:29
    Description:
    Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...6&enterprise=0
    Name: PUABundler:Win32/BitComet_BundleInstaller
    Severity: Low
    Category: Potentially Unwanted Software
    Path: file:_C:\Users\wparr\Downloads\bitcomet_setup.exe; webfile:_C:\Users\wparr\Downloads\bitcomet_setup.exe|https://dkh85d4edd1z8.cloudfront.net...39864466598886
    Detection Origin: Internet
    Detection Type: Concrete
    Detection Source: Downloads and attachments
    Process Name: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
    Security intelligence Version: AV: 1.355.247.0, AS: 1.355.247.0, NIS: 1.355.247.0
    Engine Version: AM: 1.1.18800.4, NIS: 1.1.18800.4

    Date: 2021-12-14 15:14:09
    Description:
    Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...6&enterprise=0
    Name: PUABundler:Win32/BitComet_BundleInstaller
    Severity: Low
    Category: Potentially Unwanted Software
    Path: file:_C:\Users\wparr\Downloads\bitcomet_setup.exe; webfile:_C:\Users\wparr\Downloads\bitcomet_setup.exe|https://dkh85d4edd1z8.cloudfront.net...39864466598886
    Detection Origin: Internet
    Detection Type: Concrete
    Detection Source: Downloads and attachments
    Process Name: Unknown
    Security intelligence Version: AV: 1.355.247.0, AS: 1.355.247.0, NIS: 1.355.247.0
    Engine Version: AM: 1.1.18800.4, NIS: 1.1.18800.4

    Date: 2021-12-13 17:05:25
    Description:
    Microsoft Defender Antivirus scan has been stopped before completion.
    Scan Type: Antimalware
    Scan Parameters: Quick Scan
    
    CodeIntegrity:
    ===============
    Date: 2020-10-22 14:14:24
    Description:
    Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\WindowManagementAPI.dll because the set of per-page image hashes could not be found on the system.

    Date: 2020-10-22 14:14:24
    Description:
    Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    BIOS: American Megatrends Inc. 2403 12/23/2010
    Motherboard: ASUSTeK Computer INC. M4A88T-M
    Processor: AMD Athlon(tm) II X3 450 Processor
    Percentage of memory in use: 35%
    Total physical RAM: 16382.05 MB
    Available physical RAM: 10604.21 MB
    Total Virtual: 17406.05 MB
    Available Virtual: 10632.14 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:930.5 GB) (Free:332.49 GB) NTFS
    Drive d: (New Volume) (Fixed) (Total:931.51 GB) (Free:135.06 GB) NTFS
    Drive e: (New Volume) (Fixed) (Total:1863.01 GB) (Free:1399.2 GB) NTFS

    \\?\Volume{7096e00b-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.54 GB) (Free:0.13 GB) NTFS
    \\?\Volume{7096e00b-0000-0000-0000-20c2e8000000}\ () (Fixed) (Total:0.48 GB) (Free:0.05 GB) NTFS

    ==================== MBR & Partition Table ====================

    ==========================================================
    Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 7096E00B)
    Partition 1: (Active) - (Size=549 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=930.5 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=489 MB) - (Type=27)

    ==========================================================
    Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: F9C085CB)
    Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)

    ==========================================================
    Disk: 2 (MBR Code: Windows 7/8/10) (Size: 1863 GB) (Disk ID: AA669DB1)
    Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt =======================

  13. #13
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    1. In my first reply, I asked you to uninstall following unwanted program: NativeDesktopMediaService
    You didn't do it. Why?

    2. Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
    Attached Files Attached Files

  14. #14
    Join Date
    Aug 2019
    Posts
    11
    sorry about that, i totally missed that. I just tried and this is what i got,Capture.JPG

  15. #15
    Join Date
    Aug 2019
    Posts
    11
    Fix result of Farbar Recovery Scan Tool (x64) Version: 11-12-2021
    Ran by wparr (15-12-2021 15:18:45) Run:1
    Running from C:\Users\wparr\Desktop
    Loaded Profiles: wparr
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
    Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
    Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
    Edge Extension: (No Name) -> hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.48.0.0_neutral__qq0fmhteeht3j [not found]
    Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
    Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
    S3 TKCtrl; C:\WINDOWS\system32\TKCtrl2k64.sys [147240 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKFsAvM; C:\WINDOWS\system32\TKFsAv64.sys [198808 2018-03-07] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKFsFtM; C:\WINDOWS\system32\TKFsFt64.sys [28824 2018-03-07] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKPcFt; C:\WINDOWS\system32\TKPcFtCb64.sys [54504 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKRgAc; C:\WINDOWS\system32\TKRgAc2k64.sys [115760 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKRgFt; C:\WINDOWS\system32\TKRgFtXp64.sys [68848 2018-02-04] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    S3 TKSP; C:\WINDOWS\system32\TKSPxp64.sys [80824 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== ATTENTION
    C:\WINDOWS\system32\TKCtrl2k64.sys
    C:\WINDOWS\system32\TKFsAv64.sys
    C:\WINDOWS\system32\TKFsFt64.sys
    C:\WINDOWS\system32\TKPcFtCb64.sys
    C:\WINDOWS\system32\TKRgAc2k64.sys
    C:\WINDOWS\system32\TKRgFtXp64.sys
    C:\WINDOWS\system32\TKSPxp64.sys
    2019-11-24 11:10 - 2020-10-09 11:31 - 000000128 _____ () C:\Users\wparr\AppData\Local\PUTTY.RND

    *****************

    HKLM\SOFTWARE\Policies\Google => removed successfully
    HKU\S-1-5-21-3399867593-3550638609-2408602673-1001\SOFTWARE\Policies\Google => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully
    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully
    HKLM\System\CurrentControlSet\Services\TKCtrl => removed successfully
    TKCtrl => service removed successfully
    HKLM\System\CurrentControlSet\Services\TKFsAvM => removed successfully
    TKFsAvM => service removed successfully
    HKLM\System\CurrentControlSet\Services\TKFsFtM => removed successfully
    TKFsFtM => service removed successfully
    HKLM\System\CurrentControlSet\Services\TKPcFt => removed successfully
    TKPcFt => service removed successfully
    HKLM\System\CurrentControlSet\Services\TKRgAc => removed successfully
    TKRgAc => service removed successfully
    HKLM\System\CurrentControlSet\Services\TKRgFt => removed successfully
    TKRgFt => service removed successfully
    HKLM\System\CurrentControlSet\Services\TKSP => removed successfully
    TKSP => service removed successfully
    C:\WINDOWS\system32\TKCtrl2k64.sys => moved successfully
    C:\WINDOWS\system32\TKFsAv64.sys => moved successfully
    C:\WINDOWS\system32\TKFsFt64.sys => moved successfully
    C:\WINDOWS\system32\TKPcFtCb64.sys => moved successfully
    C:\WINDOWS\system32\TKRgAc2k64.sys => moved successfully
    C:\WINDOWS\system32\TKRgFtXp64.sys => moved successfully
    C:\WINDOWS\system32\TKSPxp64.sys => moved successfully
    C:\Users\wparr\AppData\Local\PUTTY.RND => moved successfully

    ==== End of Fixlog 15:18:45 ====

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •