Results 1 to 9 of 9

Thread: My Computer is infected, please help

  1. #1
    Junior Member
    Join Date
    Jan 2020
    Posts
    4

    Default My Computer is infected, please help

    Half a year ago (start of august) both of my emails and my paypal got hacked, and i just barely got them back through my phone and my Laptop.

    Because i only use my PC for those things i expected a virus on there, and after i informed myself for a good anti-malware, i installed spybot and it found around 3 Trojans on there and successfully removed them.

    Since then my Computer acted strangely from time to time and malwarebytes showed me that my browser tried to open malicious websites on its own, particular when i opened games.

    December i finally decided to get rid of everything on my PC to be safe. So i prepared a USB with Windows Creation Tool, changed the boot order to open up the USB first, formatted my main drive and ended the setup.
    Should have been the end of it, but my PC acted strangely again and after i ran Spybot a couple of times it found 2 Trojans again.

    I then remembered that there was an option to delete everything in the windows setup and i did everything again, a few days ago. Did not help a bit and Malwarebytes still showed me that Firefox tried to open malicious websites.

    Please help me.

    P.S. I do have a Home License for Spybot but it didn't show me anything, also i ran adwarecleaner and RogueKiller with no success.

    P.S.S. i tried running aswMBR, but i always get a blue screen with the error something about Drivers not equal less, so I'm just going to post the FRST log.

    P.S.S.S. I'm from Germany so the FRST log is automaticity in German and i tried everything to make it completely into English, but some parts are still German. I'm very sorry about that.

    Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 08-01-2020
    durchgeführt von Leonard (Administrator) auf DESKTOP-A41L3FV (Gigabyte Technology Co., Ltd. Z370 AORUS ULTRA GAMING WIFI) (11-01-2020 22:35:19)
    Gestartet von C:\Users\Leonard\Desktop
    Geladene Profile: Leonard (Verfügbare Profile: Leonard)
    Platform: Windows 10 Home Version 1909 18363.535 (X64) Sprache: German (Germany)
    Standard-Browser: FF
    Start-Modus: Normal
    Anleitung für Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Prozesse (Nicht auf der Ausnahmeliste) =================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

    (Adlice -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
    (Adlice -> ) C:\Program Files\RogueKiller\RogueKillerSvc.exe
    (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
    (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
    (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Users\Leonard\AppData\Local\Microsoft\OneDrive\OneDrive.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11912.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.471_none_5f12f35059003107\TiWorker.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\Display.NvContainer\NVDisplay.Container.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\Display.NvContainer\NVDisplay.Container.exe
    (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    (Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    (Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    (Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
    (Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    (Spotify AB -> Spotify Ltd) C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe
    (Spotify AB -> Spotify Ltd) C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe
    (Spotify AB -> Spotify Ltd) C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe
    (Spotify AB -> Spotify Ltd) C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe
    (Spotify AB -> Spotify Ltd) C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe
    (Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe

    ==================== Registry (Nicht auf der Ausnahmeliste) ===================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9235936 2017-11-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
    HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [6788032 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
    HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-12-16] (Valve -> Valve Corporation)
    HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\Run: [Spotify] => C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe [22151072 2020-01-09] (Spotify AB -> Spotify Ltd)
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-12-16] (Valve -> Valve Corporation)
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\Run: [Spotify] => C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe [22151072 2020-01-09] (Spotify AB -> Spotify Ltd)
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\RunOnce: [Application Restart #0] => C:\Program Files\Mozilla Firefox\firefox.exe -os-restarted
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-12-16] (Valve -> Valve Corporation)
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\Run: [Spotify] => C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe [22151072 2020-01-09] (Spotify AB -> Spotify Ltd)
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\RunOnce: [Application Restart #0] => C:\Program Files\Mozilla Firefox\firefox.exe -os-restarted
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-12-16] (Valve -> Valve Corporation)
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\Run: [Spotify] => C:\Users\Leonard\AppData\Roaming\Spotify\Spotify.exe [22151072 2020-01-09] (Spotify AB -> Spotify Ltd)
    BootExecute: autocheck autochk * sdnclean64.exe

    ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

    Task: {7B797784-141A-45C7-84AA-27104DDDABB8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [7192192 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
    Task: {E3FFD7DE-EB75-4A43-9D27-18E0D1E20619} - System32\Tasks\Microsoft\Windows\RetailDemo\CleanupOfflineContent => {61f77d5e-afe9-400b-a5e6-e9e80fc8e601} C:\Windows\System32\RDXTaskFactory.dll [415744 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
    Task: {F6387FE8-CCF3-41C0-B7C9-C09C027F71E4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [7651984 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
    Task: {F72A9D58-D115-4C5C-AA7C-9377E51013A7} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [6944304 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)


    ==================== Internet (Nicht auf der Ausnahmeliste) ====================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

    Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.101.1
    Tcpip\..\Interfaces\{fc0a4e6f-4f37-4e9c-90c6-a6aa9a923641}: [DhcpNameServer] 192.168.101.1

    Internet Explorer:
    ==================

    FireFox:
    ========
    FF DefaultProfile: 2w5lohba.default
    FF ProfilePath: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\2w5lohba.default [2020-01-09]
    FF ProfilePath: C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\j4jjxgiw.default-release [2020-01-11]
    FF Session Restore: Mozilla\Firefox\Profiles\j4jjxgiw.default-release -> ist aktiviert.
    FF Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\j4jjxgiw.default-release\Extensions\firefox@ghostery.com.xpi [2020-01-09]
    FF Extension: (English (GB) Language Pack) - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\j4jjxgiw.default-release\Extensions\langpack-en-GB@firefox.mozilla.org.xpi [2020-01-10]
    FF Extension: (British English Dictionary (Marco Pinto)) - C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\j4jjxgiw.default-release\Extensions\marcoagpinto@mail.telepac.pt.xpi [2020-01-10]

    ==================== Dienste (Nicht auf der Ausnahmeliste) ===================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

    S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [805488 2020-01-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
    R2 ibtsiva; C:\Windows\system32\ibtsiva.exe [530208 2019-09-12] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6960640 2020-01-09] (Malwarebytes Inc -> Malwarebytes)
    R2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [16576568 2020-01-06] (Adlice -> )
    R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3892256 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
    R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [3943664 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
    R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233712 2018-02-06] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
    R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

    ===================== Treiber (Nicht auf der Ausnahmeliste) ===================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

    R3 e1dexpress; C:\Windows\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_b44028fc7fdf4fca\e1d68x64.sys [599920 2019-09-13] (Intel(R) INTELND1820 -> Intel Corporation)
    R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153312 2020-01-09] (Malwarebytes Corporation -> Malwarebytes)
    R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [731424 2019-09-12] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
    R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [218288 2020-01-09] (Malwarebytes Inc -> Malwarebytes)
    S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2020-01-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
    R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [226448 2020-01-11] (Malwarebytes Inc -> Malwarebytes)
    R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2020-01-11] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-01-11] (Malwarebytes Inc -> Malwarebytes)
    R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [105112 2020-01-11] (Malwarebytes Inc -> Malwarebytes)
    R3 MEIx64; C:\Windows\System32\DriverStore\FileRepository\heci.inf_amd64_85021432489d6a1c\x64\TeeDriverW8x64.sys [266128 2019-04-17] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
    R3 Netwtw06; C:\Windows\System32\drivers\Netwtw06.sys [8723968 2019-03-19] (Microsoft Windows -> Intel Corporation)
    R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\nvlddmkm.sys [22094936 2019-10-04] (NVIDIA Corporation -> NVIDIA Corporation)
    R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [8206848 2019-03-19] (Microsoft Windows -> Realtek Semiconductor Corporation )
    U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [28272 2020-01-11] (Adlice -> )
    S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46472 2019-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
    S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [333784 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
    S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [62432 2019-03-19] (Microsoft Windows -> Microsoft Corporation)

    ==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


    ==================== Ein Monat (erstellte) ===================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

    2020-01-11 22:35 - 2020-01-11 22:35 - 000015506 _____ C:\Users\Leonard\Desktop\FRST.txt
    2020-01-11 22:34 - 2020-01-11 22:34 - 002573312 _____ (Farbar) C:\Users\Leonard\Desktop\FRST64.exe
    2020-01-11 21:55 - 2020-01-11 21:55 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
    2020-01-11 21:55 - 2020-01-11 21:55 - 000226448 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
    2020-01-11 21:55 - 2020-01-11 21:55 - 000105112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
    2020-01-11 21:55 - 2020-01-11 21:55 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
    2020-01-11 21:32 - 2020-01-11 21:32 - 000772596 _____ C:\Windows\Minidump\011120-6953-01.dmp
    2020-01-11 21:30 - 2020-01-11 21:32 - 936522033 _____ C:\Windows\MEMORY.DMP
    2020-01-11 21:30 - 2020-01-11 21:30 - 000772724 _____ C:\Windows\Minidump\011120-6968-01.dmp
    2020-01-11 21:29 - 2020-01-11 21:29 - 005198336 _____ (AVAST Software) C:\Users\Leonard\Desktop\aswMBR.exe
    2020-01-11 17:51 - 2020-01-11 17:52 - 088060112 _____ (TeamSpeak Systems GmbH) C:\Users\Leonard\Downloads\TeamSpeak3-Client-win64-3.3.2.exe
    2020-01-10 21:17 - 2019-03-18 14:20 - 005739008 _____ (Microsoft Corporation) C:\Windows\system32\prm0009.dll
    2020-01-10 21:17 - 2019-03-18 14:19 - 002629120 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0009.dll
    2020-01-10 21:17 - 2019-03-18 14:07 - 006359552 _____ (Microsoft Corporation) C:\Windows\system32\NlsData0009.dll
    2020-01-10 21:17 - 2019-03-18 14:01 - 005496832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NlsData0009.dll
    2020-01-10 20:57 - 2020-01-10 20:57 - 000017999 _____ C:\Windows\Tweaking.com - Registry Backup Setup Log.txt
    2020-01-10 20:57 - 2020-01-10 20:57 - 000002304 _____ C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
    2020-01-10 20:57 - 2020-01-10 20:57 - 000002304 _____ C:\ProgramData\Desktop\Tweaking.com - Registry Backup.lnk
    2020-01-10 20:57 - 2020-01-10 20:57 - 000000207 _____ C:\Windows\tweaking.com-regbackup-DESKTOP-A41L3FV-Windows-10-Home-(64-bit).dat
    2020-01-10 20:57 - 2020-01-10 20:57 - 000000000 ____D C:\RegBackup
    2020-01-10 20:57 - 2020-01-10 20:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
    2020-01-10 20:57 - 2020-01-10 20:57 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
    2020-01-10 20:55 - 2020-01-10 20:56 - 005766144 _____ (Tweaking.com) C:\Users\Leonard\Downloads\tweaking.com_registry_backup_setup.exe
    2020-01-10 20:06 - 2020-01-11 22:35 - 000000000 ____D C:\FRST
    2020-01-10 19:32 - 2020-01-10 19:33 - 000000000 ____D C:\Windows\system32\MRT
    2020-01-10 19:32 - 2020-01-10 19:32 - 129221664 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 025901056 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 025443840 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 022627840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 019849216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 018020352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 017787904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 014816256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 009927992 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 009711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 008011264 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 007905000 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 007849424 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 007754240 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 007600448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 007278592 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 007263992 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 007195648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 007015936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 006516648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 006435840 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 006232576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 006227104 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 006166016 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 006083832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 005943296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 005914112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 005890048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AI.MachineLearning.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 005764664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 005501952 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 005112320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 004615616 _____ (Microsoft Corporation) C:\Windows\explorer.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 004578816 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 004307968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 004150272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AI.MachineLearning.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 004140544 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 004129416 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 004047360 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 004005888 _____ (Microsoft Corporation) C:\Windows\system32\EdgeContent.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 003967920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 003791360 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 003752960 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 003742544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 003729408 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 003703296 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 003591208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 003487232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 003387392 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 003371928 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 003263488 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 003105792 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 003084800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002988344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 002956472 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002871848 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 002870784 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002800640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 002772272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002762296 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002716672 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 002703872 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002698768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 002586816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002562048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002494432 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002399232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcGenral.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002305536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002284544 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002258848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002147328 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002126112 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002120704 _____ (Microsoft Corporation) C:\Windows\system32\WpcDesktopMonSvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002114048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 002082208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001974824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refs.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 001942528 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001920512 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001916984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001866272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001856512 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001757304 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
    2020-01-10 19:29 - 2020-01-10 19:29 - 001748480 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001743888 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001726480 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001697280 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001691648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001687040 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001664904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001656600 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001647072 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001610752 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001539584 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001512528 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 001458688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001451520 _____ (Microsoft Corporation) C:\Windows\system32\usocoreworker.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 001428992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 001413912 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001413840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001399312 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 001394168 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001366128 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
    2020-01-10 19:29 - 2020-01-10 19:29 - 001348096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001327064 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001283072 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001261464 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001259416 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 001257472 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001189376 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001182448 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 001171704 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001154656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001149712 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 001098928 _____ (Microsoft Corporation) C:\Windows\system32\DolbyDecMFT.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001094656 _____ (Microsoft Corporation) C:\Windows\system32\WpcRefreshTask.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001072952 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 001070080 _____ (Microsoft Corporation) C:\Windows\system32\BTAGService.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001069064 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001066496 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001062912 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001059840 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 001054864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001027000 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001017680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001007616 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 001006904 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostCommon.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000986936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refsv1.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000982840 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000975872 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000921600 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000913920 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000911824 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000892696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Service.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000874936 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000874536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000864256 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000849920 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000844800 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000842752 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000842552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000832000 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000826368 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelinesvc.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000822416 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000822072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000811536 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000797112 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000774456 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000768528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000768488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000765440 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000750080 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000747320 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000735744 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000708096 _____ (Microsoft Corporation) C:\Windows\system32\agentactivationruntimewindows.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000704000 _____ (Microsoft Corporation) C:\Windows\system32\agentactivationruntime.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000700416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BTAGService.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000689664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000679152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000674280 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000673456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000669696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000669352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000657424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000649728 _____ (Microsoft Corporation) C:\Windows\system32\DevicesFlowBroker.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\cdpsvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000642560 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000638264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000632320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000618496 _____ (Microsoft Corporation) C:\Windows\system32\CredProvDataModel.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000606720 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000604984 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000599552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000598528 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000598016 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000595968 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000593128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000589592 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000586768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000578560 _____ (Microsoft Corporation) C:\Windows\system32\SppExtComObj.Exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000563712 _____ (Microsoft Corporation) C:\Windows\system32\wpnprv.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000552448 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000551736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Vid.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000550400 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000534528 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Bluetooth.UserService.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000532480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000530944 _____ (Microsoft Corporation) C:\Windows\system32\usosvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000524800 _____ (Microsoft Corporation) C:\Windows\system32\cdpusersvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000524264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Enumeration.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000522176 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000517432 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000516544 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000514576 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000513536 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000513336 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000511000 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000496640 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000492032 _____ (Microsoft Corporation) C:\Windows\system32\Narrator.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000487424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.FileExplorer.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000477712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
    2020-01-10 19:29 - 2020-01-10 19:29 - 000477184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000469504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000466928 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000465208 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000461320 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000457216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cldflt.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000456192 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.ConversationalAgent.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000455168 _____ (Microsoft Corporation) C:\Windows\system32\upnphost.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000453632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000452920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000446464 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000443904 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000441144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000435200 _____ (Microsoft Corporation) C:\Windows\system32\wincorlib.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000431616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BioFeedback.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000430080 _____ (Microsoft Corporation) C:\Windows\system32\fhcfg.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000429568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000422712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000416016 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000415544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aepic.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000406480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Enumeration.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000404904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000404480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000401920 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000401408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000392192 _____ (Microsoft Corporation) C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000382976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000381952 _____ (Microsoft Corporation) C:\Windows\system32\AppLockerCSP.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000380944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000380928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcLayers.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000375720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000372752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000368128 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000359424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\MbbCx.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000358400 _____ (Microsoft Corporation) C:\Windows\system32\AcGenral.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Magnify.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000350720 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_SpeechPrivacy.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000342528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000327680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnphost.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000327680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000324624 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000322504 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\AcLayers.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000308736 _____ (Microsoft Corporation) C:\Windows\system32\msIso.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000307712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincorlib.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000299520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000292664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000291256 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000283648 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000283136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000280064 _____ (Microsoft Corporation) C:\Windows\system32\cmd.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000278016 _____ (Microsoft Corporation) C:\Windows\system32\WpcTok.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000277504 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_CapabilityAccess.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000265216 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\UpdateDeploymentProvider.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000251904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000251512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winnat.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000249856 _____ (Gracenote, Inc.) C:\Windows\SysWOW64\gnsdk_fp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000247856 _____ (Microsoft Corporation) C:\Windows\system32\weretw.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000241152 _____ (Microsoft Corporation) C:\Windows\system32\policymanagerprecheck.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000239104 _____ (Microsoft Corporation) C:\Windows\system32\vdsbas.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000236032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000236032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000235008 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000227840 _____ (Microsoft Corporation) C:\Windows\system32\IndexedDbLegacy.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000225280 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE
    2020-01-10 19:29 - 2020-01-10 19:29 - 000220472 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000219136 _____ (Microsoft Corporation) C:\Windows\system32\wscinterop.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000214528 _____ (Microsoft Corporation) C:\Windows\system32\DiagSvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000211968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000210744 _____ (Microsoft Corporation) C:\Windows\system32\tcbloader.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000206336 _____ (Microsoft Corporation) C:\Windows\system32\wincredui.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000204816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spacedump.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000204800 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000202552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000201728 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\accessibilitycpl.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000199480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000197632 _____ (Microsoft Corporation) C:\Windows\system32\Win32CompatibilityAppraiserCSP.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000193800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\weretw.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000189440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
    2020-01-10 19:29 - 2020-01-10 19:29 - 000184832 _____ (Microsoft Corporation) C:\Windows\system32\AarSvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000179712 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IndexedDbLegacy.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000175616 _____ (Microsoft Corporation) C:\Windows\system32\dmvdsitf.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000169472 _____ (Microsoft Corporation) C:\Windows\system32\SpatialAudioLicenseSrv.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscinterop.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000164776 _____ (Microsoft Corporation) C:\Windows\system32\omadmapi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000164368 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000162816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredui.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000162304 _____ (Microsoft Corporation) C:\Windows\system32\fwbase.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000159232 _____ (Microsoft Corporation) C:\Windows\system32\srpapi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000157184 _____ (Microsoft Corporation) C:\Windows\system32\RMapi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000155136 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000154112 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000147456 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SpatialAudioLicenseSrv.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000139776 _____ (Microsoft Corporation) C:\Windows\system32\Chakrathunk.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000136536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\omadmapi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000132608 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwbase.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000129024 _____ (Microsoft Corporation) C:\Windows\system32\UtcDecoderHost.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000127272 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000126464 _____ (Microsoft Corporation) C:\Windows\system32\WinHvPlatform.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\ApplicationControlCSP.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000122880 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\Utilman.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000118272 _____ (Microsoft Corporation) C:\Windows\system32\EaseOfAccessDialog.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthenum.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000113160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000111104 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000108032 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000105488 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000105472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakrathunk.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000100352 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000100352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdfs.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
    2020-01-10 19:29 - 2020-01-10 19:29 - 000097080 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000094720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Utilman.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EaseOfAccessDialog.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000093496 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000090624 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000089536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000088568 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\ApiSetHost.AppExecutionAlias.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcXtrnal.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000086016 _____ (Microsoft Corporation) C:\Windows\system32\AtBroker.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000084488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winhvr.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000084488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvservice.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000083456 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl
    2020-01-10 19:29 - 2020-01-10 19:29 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dtdump.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sethc.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000079360 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000077824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\CustomInstallExec.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\autopilot.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000074240 _____ (Microsoft Corporation) C:\Windows\system32\reg.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000073024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\remoteaudioendpoint.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000071480 _____ (Microsoft Corporation) C:\Windows\system32\win32appinventorycsp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\udhisapi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\fdProxy.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscui.cpl
    2020-01-10 19:29 - 2020-01-10 19:29 - 000067112 _____ (Microsoft Corporation) C:\Windows\system32\WindowsManagementServiceWinRt.ProxyStub.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AtBroker.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ApiSetHost.AppExecutionAlias.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iemigplugin.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\vss_ps.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000061240 _____ (Microsoft Corporation) C:\Windows\system32\hvhostsvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\AxInstUI.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\reg.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\udhisapi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000057856 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000057344 _____ (Microsoft Corporation) C:\Windows\system32\audioresourceregistrar.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000051200 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000048128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000047616 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000047208 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000046592 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelineprxy.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\upnpcont.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000039936 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthMini.SYS
    2020-01-10 19:29 - 2020-01-10 19:29 - 000036368 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnpcont.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\DevQueryBroker.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LaunchWinApp.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000033280 _____ (Microsoft Corporation) C:\Windows\system32\posetup.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000032056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000028344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000027648 _____ (Microsoft Corporation) C:\Windows\system32\wscisvif.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\autopilotdiag.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\appidtel.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000024792 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000021304 _____ (Microsoft Corporation) C:\Windows\system32\kdhvcom.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000020352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\wscproxystub.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\applockerfltr.sys
    2020-01-10 19:29 - 2020-01-10 19:29 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\iscsilog.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000015360 _____ (Microsoft Corporation) C:\Windows\system32\AcXtrnal.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDJPN.DLL
    2020-01-10 19:29 - 2020-01-10 19:29 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\dstokenclean.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\pacjsworker.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\DMAlertListener.ProxyStub.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000009216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\wscadminui.exe
    2020-01-10 19:29 - 2020-01-10 19:29 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbd106.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DMAlertListener.ProxyStub.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000005632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
    2020-01-10 19:29 - 2020-01-10 19:29 - 000005632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
    2020-01-10 19:29 - 2020-01-10 19:29 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
    2020-01-10 19:29 - 2020-01-10 19:29 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tier2punctuations.dll
    2020-01-10 19:26 - 2020-01-11 21:48 - 000001483 _____ C:\Users\Leonard\Desktop\4.txt
    2020-01-10 19:25 - 2019-10-17 06:17 - 000492544 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
    2020-01-10 19:25 - 2019-10-17 06:01 - 000390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
    2020-01-10 18:06 - 2020-01-11 21:55 - 000000000 ____D C:\Users\Leonard\AppData\Local\CrashDumps
    2020-01-10 16:24 - 2019-03-19 04:49 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts.20200110-172418.backup
    2020-01-10 16:19 - 2020-01-11 21:55 - 000028272 _____ C:\Windows\system32\Drivers\truesight.sys
    2020-01-10 16:19 - 2020-01-10 16:19 - 000000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
    2020-01-10 16:19 - 2020-01-10 16:19 - 000000899 _____ C:\ProgramData\Desktop\RogueKiller.lnk
    2020-01-10 16:19 - 2020-01-10 16:19 - 000000000 ____D C:\ProgramData\RogueKiller
    2020-01-10 16:19 - 2020-01-10 16:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
    2020-01-10 16:19 - 2020-01-10 16:19 - 000000000 ____D C:\Program Files\RogueKiller
    2020-01-09 17:18 - 2020-01-09 17:18 - 000000000 ____D C:\AdwCleaner
    2020-01-09 17:17 - 2020-01-09 17:18 - 008237744 _____ (Malwarebytes) C:\Users\Leonard\Desktop\adwcleaner_8.0.1.exe
    2020-01-09 15:28 - 2020-01-09 15:28 - 000000000 ____D C:\Users\Leonard\AppData\Roaming\EasyAntiCheat
    2020-01-09 15:27 - 2020-01-09 15:28 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
    2020-01-09 15:27 - 2010-06-02 03:55 - 000527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
    2020-01-09 15:27 - 2010-06-02 03:55 - 000518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
    2020-01-09 15:27 - 2010-06-02 03:55 - 000239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
    2020-01-09 15:27 - 2010-06-02 03:55 - 000176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
    2020-01-09 15:27 - 2010-06-02 03:55 - 000077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
    2020-01-09 15:27 - 2010-06-02 03:55 - 000074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
    2020-01-09 15:27 - 2010-05-26 10:41 - 002526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
    2020-01-09 15:27 - 2010-05-26 10:41 - 002401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
    2020-01-09 15:27 - 2010-05-26 10:41 - 002106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
    2020-01-09 15:27 - 2010-05-26 10:41 - 001998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
    2020-01-09 15:27 - 2010-05-26 10:41 - 001907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
    2020-01-09 15:27 - 2010-05-26 10:41 - 001868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
    2020-01-09 15:27 - 2010-05-26 10:41 - 000511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
    2020-01-09 15:27 - 2010-05-26 10:41 - 000470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
    2020-01-09 15:27 - 2010-05-26 10:41 - 000276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
    2020-01-09 15:27 - 2010-05-26 10:41 - 000248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
    2020-01-09 15:27 - 2010-02-04 09:01 - 000530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
    2020-01-09 15:27 - 2010-02-04 09:01 - 000528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
    2020-01-09 15:27 - 2010-02-04 09:01 - 000238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
    2020-01-09 15:27 - 2010-02-04 09:01 - 000176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
    2020-01-09 15:27 - 2010-02-04 09:01 - 000078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
    2020-01-09 15:27 - 2010-02-04 09:01 - 000074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
    2020-01-09 15:27 - 2010-02-04 09:01 - 000024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
    2020-01-09 15:27 - 2010-02-04 09:01 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
    2020-01-09 15:27 - 2009-09-04 16:44 - 000517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
    2020-01-09 15:27 - 2009-09-04 16:44 - 000515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
    2020-01-09 15:27 - 2009-09-04 16:44 - 000238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
    2020-01-09 15:27 - 2009-09-04 16:44 - 000176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
    2020-01-09 15:27 - 2009-09-04 16:44 - 000073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
    2020-01-09 15:27 - 2009-09-04 16:44 - 000069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
    2020-01-09 15:27 - 2009-09-04 16:29 - 005554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
    2020-01-09 15:27 - 2009-09-04 16:29 - 005501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
    2020-01-09 15:27 - 2009-09-04 16:29 - 002582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
    2020-01-09 15:27 - 2009-09-04 16:29 - 002475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
    2020-01-09 15:27 - 2009-09-04 16:29 - 001974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
    2020-01-09 15:27 - 2009-09-04 16:29 - 001892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
    2020-01-09 15:27 - 2009-09-04 16:29 - 000523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
    2020-01-09 15:27 - 2009-09-04 16:29 - 000453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
    2020-01-09 15:27 - 2009-09-04 16:29 - 000285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
    2020-01-09 15:27 - 2009-09-04 16:29 - 000235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
    2020-01-09 15:27 - 2009-03-16 13:18 - 000521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
    2020-01-09 15:27 - 2009-03-16 13:18 - 000517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
    2020-01-09 15:27 - 2009-03-16 13:18 - 000235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
    2020-01-09 15:27 - 2009-03-16 13:18 - 000174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
    2020-01-09 15:27 - 2009-03-16 13:18 - 000024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
    2020-01-09 15:27 - 2009-03-16 13:18 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
    2020-01-09 15:27 - 2009-03-09 14:27 - 005425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
    2020-01-09 15:27 - 2009-03-09 14:27 - 004178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
    2020-01-09 15:27 - 2009-03-09 14:27 - 002430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
    2020-01-09 15:27 - 2009-03-09 14:27 - 001846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
    2020-01-09 15:27 - 2009-03-09 14:27 - 000520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
    2020-01-09 15:27 - 2009-03-09 14:27 - 000453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
    2020-01-09 15:27 - 2008-10-27 09:04 - 000518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
    2020-01-09 15:27 - 2008-10-27 09:04 - 000514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
    2020-01-09 15:27 - 2008-10-27 09:04 - 000235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
    2020-01-09 15:27 - 2008-10-27 09:04 - 000175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
    2020-01-09 15:27 - 2008-10-27 09:04 - 000074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
    2020-01-09 15:27 - 2008-10-27 09:04 - 000070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
    2020-01-09 15:27 - 2008-10-27 09:04 - 000025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
    2020-01-09 15:27 - 2008-10-27 09:04 - 000023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
    2020-01-09 15:27 - 2008-10-15 05:22 - 005631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
    2020-01-09 15:27 - 2008-10-15 05:22 - 004379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
    2020-01-09 15:27 - 2008-10-15 05:22 - 002605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
    2020-01-09 15:27 - 2008-10-15 05:22 - 002036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
    2020-01-09 15:27 - 2008-10-15 05:22 - 000519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
    2020-01-09 15:27 - 2008-10-15 05:22 - 000452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
    2020-01-09 15:27 - 2008-07-31 09:41 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
    2020-01-09 15:27 - 2008-07-31 09:41 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
    2020-01-09 15:27 - 2008-07-31 09:41 - 000072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
    2020-01-09 15:27 - 2008-07-31 09:41 - 000068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
    2020-01-09 15:27 - 2008-07-31 09:40 - 000513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
    2020-01-09 15:27 - 2008-07-31 09:40 - 000509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
    2020-01-09 15:27 - 2008-07-10 10:01 - 000467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
    2020-01-09 15:27 - 2008-07-10 10:00 - 004992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
    2020-01-09 15:27 - 2008-07-10 10:00 - 003851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
    2020-01-09 15:27 - 2008-07-10 10:00 - 001942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
    2020-01-09 15:27 - 2008-07-10 10:00 - 001493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
    2020-01-09 15:27 - 2008-07-10 10:00 - 000540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
    2020-01-09 15:27 - 2008-05-30 13:19 - 000511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
    2020-01-09 15:27 - 2008-05-30 13:19 - 000507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
    2020-01-09 15:27 - 2008-05-30 13:18 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
    2020-01-09 15:27 - 2008-05-30 13:18 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
    2020-01-09 15:27 - 2008-05-30 13:17 - 000068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
    2020-01-09 15:27 - 2008-05-30 13:17 - 000065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
    2020-01-09 15:27 - 2008-05-30 13:17 - 000025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
    2020-01-09 15:27 - 2008-05-30 13:16 - 000028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
    2020-01-09 15:27 - 2008-05-30 13:11 - 004991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
    2020-01-09 15:27 - 2008-05-30 13:11 - 003850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
    2020-01-09 15:27 - 2008-05-30 13:11 - 001941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
    2020-01-09 15:27 - 2008-05-30 13:11 - 001491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
    2020-01-09 15:27 - 2008-05-30 13:11 - 000540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
    2020-01-09 15:27 - 2008-05-30 13:11 - 000467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
    2020-01-09 15:27 - 2008-03-05 15:04 - 000489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
    2020-01-09 15:27 - 2008-03-05 15:03 - 000479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
    2020-01-09 15:27 - 2008-03-05 15:03 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
    2020-01-09 15:27 - 2008-03-05 15:03 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
    2020-01-09 15:27 - 2008-03-05 15:00 - 000028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
    2020-01-09 15:27 - 2008-03-05 15:00 - 000025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
    2020-01-09 15:27 - 2008-03-05 14:56 - 004910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
    2020-01-09 15:27 - 2008-03-05 14:56 - 003786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
    2020-01-09 15:27 - 2008-03-05 14:56 - 001860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
    2020-01-09 15:27 - 2008-03-05 14:56 - 001420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
    2020-01-09 15:27 - 2008-02-05 22:07 - 000529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
    2020-01-09 15:27 - 2008-02-05 22:07 - 000462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
    2020-01-09 15:27 - 2007-10-22 02:40 - 000411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
    2020-01-09 15:27 - 2007-10-22 02:39 - 000267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
    2020-01-09 15:27 - 2007-10-22 02:37 - 000021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
    2020-01-09 15:27 - 2007-10-22 02:37 - 000017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
    2020-01-09 15:27 - 2007-10-12 14:14 - 005081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
    2020-01-09 15:27 - 2007-10-12 14:14 - 003734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
    2020-01-09 15:27 - 2007-10-12 14:14 - 002006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
    2020-01-09 15:27 - 2007-10-12 14:14 - 001374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
    2020-01-09 15:27 - 2007-10-02 08:56 - 000508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
    2020-01-09 15:27 - 2007-10-02 08:56 - 000444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
    2020-01-09 15:27 - 2007-07-19 23:57 - 000411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
    2020-01-09 15:27 - 2007-07-19 23:57 - 000267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
    2020-01-09 15:27 - 2007-07-19 17:14 - 005073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
    2020-01-09 15:27 - 2007-07-19 17:14 - 003727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
    2020-01-09 15:27 - 2007-07-19 17:14 - 001985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
    2020-01-09 15:27 - 2007-07-19 17:14 - 001358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
    2020-01-09 15:27 - 2007-07-19 17:14 - 000508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
    2020-01-09 15:27 - 2007-07-19 17:14 - 000444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
    2020-01-09 15:27 - 2007-06-20 19:49 - 000409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
    2020-01-09 15:27 - 2007-06-20 19:46 - 000266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
    2020-01-09 15:27 - 2007-05-16 15:45 - 004496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
    2020-01-09 15:27 - 2007-05-16 15:45 - 003497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
    2020-01-09 15:27 - 2007-05-16 15:45 - 001401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
    2020-01-09 15:27 - 2007-05-16 15:45 - 001124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
    2020-01-09 15:27 - 2007-05-16 15:45 - 000506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
    2020-01-09 15:27 - 2007-05-16 15:45 - 000443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
    2020-01-09 15:27 - 2007-04-04 17:55 - 000403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
    2020-01-09 15:27 - 2007-04-04 17:55 - 000261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
    2020-01-09 15:27 - 2007-04-04 17:54 - 000107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
    2020-01-09 15:27 - 2007-04-04 17:53 - 000081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
    2020-01-09 15:27 - 2007-03-15 15:57 - 000506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
    2020-01-09 15:27 - 2007-03-15 15:57 - 000443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
    2020-01-09 15:27 - 2007-03-12 15:42 - 004494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
    2020-01-09 15:27 - 2007-03-12 15:42 - 003495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
    2020-01-09 15:27 - 2007-03-12 15:42 - 001400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
    2020-01-09 15:27 - 2007-03-12 15:42 - 001123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
    2020-01-09 15:27 - 2007-03-05 11:42 - 000017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
    2020-01-09 15:27 - 2007-03-05 11:42 - 000015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
    2020-01-09 15:27 - 2007-01-24 14:27 - 000393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
    2020-01-09 15:27 - 2007-01-24 14:27 - 000255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
    2020-01-09 15:27 - 2006-12-08 11:02 - 000251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
    2020-01-09 15:27 - 2006-12-08 11:00 - 000390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
    2020-01-09 15:27 - 2006-11-29 12:06 - 004398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
    2020-01-09 15:27 - 2006-11-29 12:06 - 003426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
    2020-01-09 15:27 - 2006-11-29 12:06 - 000469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
    2020-01-09 15:27 - 2006-11-29 12:06 - 000440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
    2020-01-09 15:27 - 2006-09-28 15:05 - 003977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
    2020-01-09 15:27 - 2006-09-28 15:05 - 002414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
    2020-01-09 15:27 - 2006-09-28 15:05 - 000237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
    2020-01-09 15:27 - 2006-09-28 15:04 - 000364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
    2020-01-09 15:27 - 2006-07-28 08:31 - 000083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
    2020-01-09 15:27 - 2006-07-28 08:30 - 000363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
    2020-01-09 15:27 - 2006-07-28 08:30 - 000236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
    2020-01-09 15:27 - 2006-07-28 08:30 - 000062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
    2020-01-09 15:27 - 2006-05-31 06:24 - 000230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
    2020-01-09 15:27 - 2006-05-31 06:22 - 000354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
    2020-01-09 15:27 - 2006-03-31 11:41 - 003927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
    2020-01-09 15:27 - 2006-03-31 11:40 - 002388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
    2020-01-09 15:27 - 2006-03-31 11:40 - 000352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
    2020-01-09 15:27 - 2006-03-31 11:39 - 000229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
    2020-01-09 15:27 - 2006-03-31 11:39 - 000083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
    2020-01-09 15:27 - 2006-03-31 11:39 - 000062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
    2020-01-09 15:27 - 2006-02-03 07:43 - 003830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
    2020-01-09 15:27 - 2006-02-03 07:43 - 002332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
    2020-01-09 15:27 - 2006-02-03 07:42 - 000355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
    2020-01-09 15:27 - 2006-02-03 07:42 - 000230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
    2020-01-09 15:27 - 2006-02-03 07:41 - 000016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
    2020-01-09 15:27 - 2006-02-03 07:41 - 000014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
    2020-01-09 15:27 - 2005-12-05 17:09 - 003815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
    2020-01-09 15:27 - 2005-12-05 17:09 - 002323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
    2020-01-09 15:27 - 2005-07-22 18:59 - 003807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
    2020-01-09 15:27 - 2005-07-22 18:59 - 002319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
    2020-01-09 15:27 - 2005-05-26 14:34 - 003767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
    2020-01-09 15:27 - 2005-05-26 14:34 - 002297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
    2020-01-09 15:27 - 2005-03-18 16:19 - 003823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
    2020-01-09 15:27 - 2005-03-18 16:19 - 002337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
    2020-01-09 15:27 - 2005-02-05 18:45 - 003544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
    2020-01-09 15:27 - 2005-02-05 18:45 - 002222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
    2020-01-09 15:03 - 2020-01-09 14:59 - 000748816 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
    2020-01-09 13:59 - 2020-01-09 15:27 - 000000000 ____D C:\ProgramData\Package Cache
    2020-01-09 13:59 - 2020-01-09 13:59 - 000000000 ____D C:\Users\Leonard\AppData\LocalLow\Hopoo Games, LLC
    2020-01-09 13:38 - 2020-01-11 21:55 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2020-01-09 13:38 - 2020-01-10 16:18 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2020-01-09 13:38 - 2020-01-09 13:38 - 000001456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    2020-01-09 13:38 - 2020-01-09 13:38 - 000001444 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    2020-01-09 13:38 - 2020-01-09 13:38 - 000001444 _____ C:\ProgramData\Desktop\Spybot-S&D Start Center.lnk
    2020-01-09 13:38 - 2020-01-09 13:38 - 000000000 ____D C:\Windows\system32\Tasks\Safer-Networking
    2020-01-09 13:38 - 2020-01-09 13:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    2020-01-09 13:38 - 2018-02-06 18:04 - 000032168 _____ (Safer-Networking Ltd.) C:\Windows\system32\sdnclean64.exe
    2020-01-09 13:37 - 2020-01-09 13:37 - 069910960 _____ (Safer-Networking Ltd. ) C:\Users\Leonard\Downloads\spybotsd-2.7.64.0.exe
    2020-01-09 13:36 - 2020-01-09 13:36 - 002473688 _____ (Opera Software) C:\Users\Leonard\Downloads\OperaSetup.exe
    2020-01-09 13:31 - 2020-01-11 21:54 - 000006604 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1
    2020-01-09 13:27 - 2020-01-09 13:27 - 000000000 ____D C:\Users\Leonard\AppData\Local\D3DSCache
    2020-01-09 13:27 - 2020-01-09 13:27 - 000000000 ____D C:\ProgramData\NVIDIA
    2020-01-09 13:25 - 2020-01-11 21:54 - 000020896 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1
    2020-01-09 13:25 - 2020-01-11 21:54 - 000012964 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1
    2020-01-09 13:25 - 2020-01-10 21:29 - 000006608 _____ C:\ProgramData\DisplaySessionContainer2.log_backup1
    2020-01-09 13:24 - 2020-01-09 15:31 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
    2020-01-09 13:24 - 2020-01-09 13:25 - 000000000 ____D C:\Program Files\NVIDIA Corporation
    2020-01-09 13:24 - 2020-01-09 13:24 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
    2020-01-09 13:23 - 2020-01-09 13:23 - 000000000 ____D C:\Users\Leonard\AppData\Local\Steam
    2020-01-09 13:23 - 2020-01-09 13:23 - 000000000 ____D C:\Users\Leonard\AppData\Local\CEF
    2020-01-09 13:23 - 2019-10-04 15:15 - 001006800 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
    2020-01-09 13:23 - 2019-10-04 15:15 - 001006800 _____ C:\Windows\system32\vulkan-1.dll
    2020-01-09 13:23 - 2019-10-04 15:15 - 000870096 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
    2020-01-09 13:23 - 2019-10-04 15:15 - 000870096 _____ C:\Windows\SysWOW64\vulkan-1.dll
    2020-01-09 13:23 - 2019-10-04 15:15 - 000552328 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
    2020-01-09 13:23 - 2019-10-04 15:15 - 000456640 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
    2020-01-09 13:23 - 2019-10-04 15:15 - 000286416 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
    2020-01-09 13:23 - 2019-10-04 15:15 - 000286416 _____ C:\Windows\system32\vulkaninfo.exe
    2020-01-09 13:23 - 2019-10-04 15:15 - 000260304 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
    2020-01-09 13:23 - 2019-10-04 15:15 - 000260304 _____ C:\Windows\SysWOW64\vulkaninfo.exe
    2020-01-09 13:23 - 2019-10-04 15:14 - 011059400 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
    2020-01-09 13:23 - 2019-10-04 15:14 - 009492680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
    2020-01-09 13:23 - 2019-10-04 15:14 - 000676608 _____ C:\Windows\system32\nvofapi64.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 020194504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 017471368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 005443976 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 005425600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 004767952 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 002041784 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 001543424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 001472408 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 001164168 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 001136024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 001004936 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 000914120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 000822016 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcumd.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 000810240 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 000656128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 000633936 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 000572376 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
    2020-01-09 13:23 - 2019-10-04 15:13 - 000543952 _____ C:\Windows\SysWOW64\nvofapi.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 000523728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
    2020-01-09 13:23 - 2019-10-04 15:13 - 000449736 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
    2020-01-09 13:23 - 2019-10-04 15:13 - 000237424 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
    2020-01-09 13:23 - 2019-10-04 15:13 - 000055664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhdap64.dll
    2020-01-09 13:23 - 2019-10-04 15:12 - 040412552 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
    2020-01-09 13:23 - 2019-10-04 15:12 - 035269840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2020-01-09 13:23 - 2019-10-04 15:12 - 005087232 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
    2020-01-09 13:23 - 2019-10-04 15:12 - 004342736 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2020-01-09 13:23 - 2019-10-04 15:12 - 000858504 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
    2020-01-09 13:23 - 2019-10-04 14:53 - 000104564 _____ C:\Windows\system32\nvidia-smi.1.pdf
    2020-01-09 13:23 - 2019-10-04 14:53 - 000057400 _____ C:\Windows\system32\nvinfo.pb
    2020-01-09 13:19 - 2020-01-10 21:30 - 000000000 ____D C:\Users\Leonard\AppData\Local\Spotify
    2020-01-09 13:19 - 2020-01-09 13:19 - 000001860 _____ C:\Users\Leonard\Desktop\Spotify.lnk
    2020-01-09 13:19 - 2020-01-09 13:19 - 000001846 _____ C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
    2020-01-09 13:18 - 2020-01-09 13:18 - 000000000 ____H C:\ProgramData\DP45977C.lfl
    2020-01-09 13:18 - 2020-01-09 13:18 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
    2020-01-09 13:18 - 2020-01-09 13:18 - 000000000 ____D C:\Program Files\Realtek
    2020-01-09 13:17 - 2017-11-16 00:45 - 072520704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
    2020-01-09 13:17 - 2017-11-16 00:45 - 006038440 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
    2020-01-09 13:17 - 2017-11-16 00:45 - 003677152 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
    2020-01-09 13:17 - 2017-11-16 00:45 - 003205600 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
    2020-01-09 13:17 - 2017-11-16 00:45 - 002922976 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
    2020-01-09 13:17 - 2017-11-16 00:45 - 000023688 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
    2020-01-09 13:17 - 2017-11-16 00:44 - 007172904 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
    2020-01-09 13:17 - 2017-11-16 00:44 - 007096184 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
    2020-01-09 13:17 - 2017-11-16 00:43 - 000118584 _____ C:\Windows\system32\AcpiServiceVnA64.dll
    2020-01-09 13:17 - 2017-11-16 00:43 - 000105304 _____ C:\Windows\system32\audioLibVc.dll
    2020-01-09 13:17 - 2017-11-16 00:41 - 003509192 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
    2020-01-09 13:17 - 2017-11-16 00:41 - 000343704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
    2020-01-09 13:17 - 2017-11-16 00:41 - 000192976 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
    2020-01-09 13:17 - 2017-11-16 00:40 - 003562432 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
    2020-01-09 13:17 - 2017-11-16 00:40 - 001351232 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
    2020-01-09 13:17 - 2017-11-16 00:40 - 000691672 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
    2020-01-09 13:17 - 2017-11-16 00:40 - 000151784 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
    2020-01-09 13:17 - 2017-11-16 00:40 - 000084608 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
    2020-01-09 13:17 - 2017-11-16 00:39 - 001780608 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
    2020-01-09 13:17 - 2017-11-16 00:39 - 001591056 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
    2020-01-09 13:17 - 2017-11-16 00:39 - 000727432 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
    2020-01-09 13:17 - 2017-11-16 00:39 - 000708304 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
    2020-01-09 13:17 - 2017-11-16 00:39 - 000447712 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
    2020-01-09 13:17 - 2017-11-16 00:39 - 000134192 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 001965808 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 001508928 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 000743960 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 000504296 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 000445392 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 000441264 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 000327448 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 000272712 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 000253896 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 000253856 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
    2020-01-09 13:17 - 2017-11-16 00:38 - 000252872 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
    2020-01-09 13:17 - 2017-11-16 00:09 - 014964257 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
    2020-01-09 13:14 - 2020-01-11 22:01 - 000000000 ____D C:\Users\Leonard\AppData\Roaming\Spotify
    2020-01-09 13:13 - 2020-01-11 21:55 - 000000000 ____D C:\Program Files (x86)\Steam
    2020-01-09 13:13 - 2020-01-10 21:42 - 000000000 ____D C:\ProgramData\Packages
    2020-01-09 13:13 - 2020-01-09 13:14 - 000896512 _____ (Spotify Ltd) C:\Users\Leonard\Downloads\SpotifySetup.exe
    2020-01-09 13:13 - 2020-01-09 13:13 - 001573568 _____ C:\Users\Leonard\Downloads\SteamSetup.exe
    2020-01-09 13:13 - 2020-01-09 13:13 - 000001028 _____ C:\Users\Public\Desktop\Steam.lnk
    2020-01-09 13:13 - 2020-01-09 13:13 - 000001028 _____ C:\ProgramData\Desktop\Steam.lnk
    2020-01-09 13:13 - 2020-01-09 13:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
    2020-01-09 13:12 - 2020-01-09 13:12 - 000000000 ____D C:\Users\Leonard\AppData\Local\Comms
    2020-01-09 13:09 - 2020-01-11 21:55 - 000000000 ____D C:\Users\Leonard\AppData\LocalLow\Mozilla
    2020-01-09 13:09 - 2020-01-09 13:09 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
    2020-01-09 13:09 - 2020-01-09 13:09 - 000000993 _____ C:\Users\Public\Desktop\Firefox.lnk
    2020-01-09 13:09 - 2020-01-09 13:09 - 000000993 _____ C:\ProgramData\Desktop\Firefox.lnk
    2020-01-09 13:09 - 2020-01-09 13:09 - 000000000 ____D C:\Users\Leonard\AppData\Roaming\Mozilla
    2020-01-09 13:09 - 2020-01-09 13:09 - 000000000 ____D C:\Users\Leonard\AppData\Local\Mozilla
    2020-01-09 13:09 - 2020-01-09 13:09 - 000000000 ____D C:\ProgramData\Mozilla
    2020-01-09 13:09 - 2020-01-09 13:09 - 000000000 ____D C:\Program Files\Mozilla Firefox
    2020-01-09 13:09 - 2020-01-09 13:09 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2020-01-09 13:07 - 2020-01-09 13:07 - 000218288 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
    2020-01-09 13:07 - 2020-01-09 13:07 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
    2020-01-09 13:07 - 2020-01-09 13:07 - 000020936 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
    2020-01-09 13:07 - 2020-01-09 13:07 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2020-01-09 13:07 - 2020-01-09 13:07 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
    2020-01-09 13:07 - 2020-01-09 13:07 - 000000000 ____D C:\Users\Leonard\AppData\Local\mbamtray
    2020-01-09 13:07 - 2020-01-09 13:07 - 000000000 ____D C:\Users\Leonard\AppData\Local\mbam
    2020-01-09 13:07 - 2020-01-09 13:07 - 000000000 ____D C:\Users\Leonard\AppData\Local\cache
    2020-01-09 13:07 - 2020-01-09 13:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
    2020-01-09 13:07 - 2020-01-09 13:07 - 000000000 ____D C:\ProgramData\Malwarebytes
    2020-01-09 13:06 - 2020-01-09 13:06 - 000000000 ___HD C:\Users\Leonard\MicrosoftEdgeBackups
    2020-01-09 13:06 - 2020-01-09 13:06 - 000000000 ____D C:\Program Files\Malwarebytes
    2020-01-09 13:05 - 2020-01-10 21:18 - 000000000 ____D C:\Users\Leonard\AppData\Local\PlaceholderTileLogoFolder
    2020-01-09 13:01 - 2020-01-09 13:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-Link
    2020-01-09 12:59 - 2020-01-09 12:59 - 000000000 ____D C:\Program Files (x86)\TP-Link
    2020-01-09 12:58 - 2020-01-09 12:59 - 000000000 ____D C:\Users\Leonard\AppData\Local\TP-Link
    2020-01-09 12:58 - 2020-01-09 12:58 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2020-01-09 12:58 - 2020-01-09 12:58 - 000000000 ____D C:\ProgramData\TP-Link
    2020-01-09 12:58 - 2017-12-20 03:25 - 004776168 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\rtwlanu.sys
    2020-01-09 12:58 - 2017-12-20 03:25 - 000018548 _____ C:\Windows\system32\netrtwlanu.cat
    2020-01-09 12:58 - 2017-12-20 03:18 - 000004453 _____ C:\Windows\system32\LIM_TLWN821N_5_UN.txt
    2020-01-09 12:58 - 2017-12-20 03:18 - 000004453 _____ C:\Windows\system32\Drivers\LIM_TLWN821N_5_UN.txt
    2020-01-09 12:58 - 2017-12-20 03:18 - 000002703 _____ C:\Windows\system32\PBR_TLWN821N_5_UN.txt
    2020-01-09 12:58 - 2017-12-20 03:18 - 000002703 _____ C:\Windows\system32\Drivers\PBR_TLWN821N_5_UN.txt
    2020-01-09 12:57 - 2020-01-09 13:32 - 000003378 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-68706545-277898625-3769142786-1001
    2020-01-09 12:57 - 2020-01-09 13:32 - 000000000 ___RD C:\Users\Leonard\OneDrive
    2020-01-09 12:57 - 2020-01-09 13:05 - 000000000 ____D C:\Users\Leonard\AppData\Local\MicrosoftEdge
    2020-01-09 12:57 - 2020-01-09 12:57 - 000001450 _____ C:\Users\Leonard\Desktop\Microsoft Edge.lnk
    2020-01-09 12:57 - 2020-01-09 12:57 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
    2020-01-09 12:56 - 2020-01-09 13:27 - 000000000 ____D C:\Users\Leonard\AppData\Local\Publishers
    2020-01-09 12:55 - 2020-01-11 21:54 - 000000000 ____D C:\Users\Leonard
    2020-01-09 12:55 - 2020-01-10 21:26 - 000000000 ____D C:\Users\Leonard\AppData\Local\Packages
    2020-01-09 12:55 - 2020-01-10 19:36 - 000000000 __RHD C:\Users\Public\AccountPictures
    2020-01-09 12:55 - 2020-01-10 19:36 - 000000000 ___RD C:\Users\Leonard\3D Objects
    2020-01-09 12:55 - 2020-01-09 13:32 - 000002381 _____ C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2020-01-09 12:55 - 2020-01-09 12:56 - 000000000 ____D C:\Users\Leonard\AppData\Local\ConnectedDevicesPlatform
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000020 ___SH C:\Users\Leonard\ntuser.ini
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Vorlagen
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Startmenü
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Netzwerkumgebung
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Lokale Einstellungen
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Eigene Dateien
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Druckumgebung
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Documents\Eigene Videos
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Documents\Eigene Musik
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Documents\Eigene Bilder
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\AppData\Local\Verlauf
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\AppData\Local\Anwendungsdaten
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 _SHDL C:\Users\Leonard\Anwendungsdaten
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 ____D C:\Users\Leonard\AppData\Roaming\Adobe
    2020-01-09 12:55 - 2020-01-09 12:55 - 000000000 ____D C:\Users\Leonard\AppData\Local\VirtualStore
    2020-01-09 12:54 - 2020-01-11 22:01 - 001632524 _____ C:\Windows\system32\PerfStringBackup.INI
    2020-01-09 12:52 - 2019-10-07 02:55 - 002874368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
    2020-01-09 12:50 - 2020-01-11 21:32 - 000000000 ____D C:\Windows\minidump
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Videos
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Musik
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Vorlagen
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Startmenü
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Netzwerkumgebung
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Lokale Einstellungen
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Eigene Dateien
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Druckumgebung
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Videos
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Musik
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default\Anwendungsdaten
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Vorlagen
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Startmenü
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Netzwerkumgebung
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Lokale Einstellungen
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Eigene Dateien
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Druckumgebung
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Documents\Eigene Videos
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Users\Default User\Anwendungsdaten
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Programme
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\ProgramData\Vorlagen
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\ProgramData\Startmenü
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\ProgramData\Dokumente
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\ProgramData\Anwendungsdaten
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Program Files\Gemeinsame Dateien
    2020-01-09 12:50 - 2020-01-09 12:50 - 000000000 _SHDL C:\Dokumente und Einstellungen
    2020-01-09 12:48 - 2020-01-11 21:55 - 000000006 ____H C:\Windows\Tasks\SA.DAT
    2020-01-09 12:48 - 2020-01-11 21:32 - 000000000 ____D C:\Windows\system32\SleepStudy
    2020-01-09 12:48 - 2020-01-11 17:37 - 000000000 ____D C:\Windows\Panther
    2020-01-09 12:48 - 2020-01-10 19:34 - 000257920 _____ C:\Windows\system32\FNTCACHE.DAT
    2020-01-09 12:48 - 2020-01-09 12:48 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
    2020-01-09 12:48 - 2020-01-09 12:48 - 000000000 ____D C:\Windows\system32\Drivers\wd
    2020-01-09 12:48 - 2020-01-09 12:48 - 000000000 ____D C:\Windows\ServiceProfiles

    ==================== Ein Monat (geänderte) ==================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

    2020-01-11 22:25 - 2019-03-19 04:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2020-01-11 22:15 - 2019-03-19 04:37 - 000000000 ____D C:\Windows\CbsTemp
    2020-01-11 22:10 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\AppReadiness
    2020-01-11 22:01 - 2019-03-19 12:16 - 000704076 _____ C:\Windows\system32\perfh007.dat
    2020-01-11 22:01 - 2019-03-19 12:16 - 000142100 _____ C:\Windows\system32\perfc007.dat
    2020-01-11 22:01 - 2019-03-19 04:50 - 000000000 ____D C:\Windows\INF
    2020-01-11 21:54 - 2019-03-19 04:37 - 000524288 _____ C:\Windows\system32\config\BBI
    2020-01-10 23:39 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\NDF
    2020-01-10 21:42 - 2019-03-19 04:52 - 000000000 ___HD C:\Program Files\WindowsApps
    2020-01-10 21:20 - 2019-03-19 12:18 - 000000000 ____D C:\Program Files\Windows Photo Viewer
    2020-01-10 21:20 - 2019-03-19 12:18 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\SysWOW64\winrm
    2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\SysWOW64\WCN
    2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\SysWOW64\slmgr
    2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
    2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\system32\winrm
    2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\system32\WCN
    2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\system32\slmgr
    2020-01-10 21:20 - 2019-03-19 12:16 - 000000000 ____D C:\Windows\system32\Printing_Admin_Scripts
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___SD C:\Windows\SysWOW64\F12
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___SD C:\Windows\system32\F12
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___SD C:\Windows\system32\dsc
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___SD C:\Windows\system32\DiagSvcs
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\SysWOW64\oobe
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\oobe
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\migwiz
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\PolicyDefinitions
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\IME
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Windows Defender
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Common Files\System
    2020-01-10 21:20 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files (x86)\Windows Defender
    2020-01-10 21:20 - 2019-03-19 04:37 - 000000000 ____D C:\Windows\servicing
    2020-01-10 21:17 - 2019-03-19 12:17 - 000000000 ____D C:\Windows\OCR
    2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ___RD C:\Windows\PrintDialog
    2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\SystemResources
    2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\appraiser
    2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\ShellExperiences
    2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\ShellComponents
    2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\DiagTrack
    2020-01-10 19:34 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\bcastdvr
    2020-01-10 18:54 - 2019-03-19 04:37 - 000032768 _____ C:\Windows\system32\config\ELAM
    2020-01-10 11:31 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\appcompat
    2020-01-09 15:27 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
    2020-01-09 13:14 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\ServiceState
    2020-01-09 13:07 - 2019-03-19 04:52 - 000000000 ___HD C:\Windows\ELAMBKUP
    2020-01-09 12:57 - 2019-03-19 04:52 - 000000000 ____D C:\ProgramData\USOPrivate
    2020-01-09 12:52 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\spool
    2020-01-09 12:52 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\FxsTmp
    2020-01-09 12:51 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\system32\WinBioDatabase
    2020-01-09 12:51 - 2019-03-19 04:52 - 000000000 ____D C:\Windows\LiveKernelReports
    2020-01-09 12:50 - 2019-03-19 04:52 - 000000000 ____D C:\Program Files\Windows NT
    2020-01-09 12:48 - 2019-03-19 04:49 - 000028672 _____ C:\Windows\system32\config\BCD-Template

    ==================== SigCheck ============================

    (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

    ==================== Ende von FRST.txt ========================

    Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 08-01-2020
    durchgeführt von Leonard (11-01-2020 22:35:59)
    Gestartet von C:\Users\Leonard\Desktop
    Windows 10 Home Version 1909 18363.535 (X64) (2020-01-09 12:50:52)
    Start-Modus: Normal
    ==========================================================


    ==================== Konten: =============================

    Administrator (S-1-5-21-68706545-277898625-3769142786-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-68706545-277898625-3769142786-503 - Limited - Disabled)
    Gast (S-1-5-21-68706545-277898625-3769142786-501 - Limited - Disabled)
    Leonard (S-1-5-21-68706545-277898625-3769142786-1001 - Administrator - Enabled) => C:\Users\Leonard
    WDAGUtilityAccount (S-1-5-21-68706545-277898625-3769142786-504 - Limited - Disabled)

    ==================== Sicherheits-Center ========================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}

    ==================== Installierte Programme ======================

    (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

    Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes)
    Microsoft OneDrive (HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
    Mozilla Firefox 72.0.1 (x64 de) (HKLM\...\Mozilla Firefox 72.0.1 (x64 de)) (Version: 72.0.1 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 72.0.1 - Mozilla)
    NVIDIA Grafiktreiber 432.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 432.00 - NVIDIA Corporation)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8302 - Realtek Semiconductor Corp.)
    RogueKiller Version 14.0.4.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 14.0.4.0 - Adlice Software)
    Spotify (HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\Spotify) (Version: 1.1.22.633.g1bab253a - Spotify AB)
    Spotify (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\Spotify) (Version: 1.1.22.633.g1bab253a - Spotify AB)
    Spotify (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\Spotify) (Version: 1.1.22.633.g1bab253a - Spotify AB)
    Spotify (HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\Spotify) (Version: 1.1.22.633.g1bab253a - Spotify AB)
    Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.7.64.0 - Safer-Networking Ltd.)
    Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
    TP-Link TL-WN821N (HKLM-x32\...\{03468BE2-4451-416D-B045-60F2101122D4}) (Version: 2.1.0 - TP-Link)
    Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 3.5.3 - Tweaking.com)

    Packages:
    =========
    Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.28.8.0_x86__kgqvnymyfvs32 [2020-01-09] (king.com)
    Farm Heroes Saga -> C:\Program Files\WindowsApps\king.com.FarmHeroesSaga_5.30.9.0_x86__kgqvnymyfvs32 [2020-01-10] (king.com)
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-01-10] (Microsoft Corporation) [MS Ad]
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-01-10] (Microsoft Corporation) [MS Ad]
    Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2020-01-10] (Microsoft Studios) [MS Ad]
    MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.34.13393.0_x64__8wekyb3d8bbwe [2020-01-10] (Microsoft Corporation) [MS Ad]
    NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.956.0_x64__56jybvy8sckqj [2020-01-09] (NVIDIA Corp.)
    XING -> C:\Program Files\WindowsApps\XINGAG.XING_3.145.2.0_x86__xpfg3f7e9an52 [2020-01-09] (New Work SE)

    ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==============

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

    ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
    ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-09] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\nvshext.dll [2019-10-04] (NVIDIA Corporation -> NVIDIA Corporation)
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-09] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
    ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)

    ==================== Codecs (Nicht auf der Ausnahmeliste) ====================

    ==================== Verknüpfungen & WMI ========================

    ==================== Geladene Module (Nicht auf der Ausnahmeliste) =============


    ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========

    ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ==================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

    ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =================

    ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ==========

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

    IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
    IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
    IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
    IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

    Da befinden sich 7942 mehr Seiten.

    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\008i.com -> 008i.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\008k.com -> www.008k.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\010402.com -> 010402.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001\...\123simsen.com -> www.123simsen.com

    Da befinden sich 7942 mehr Seiten.

    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\008i.com -> 008i.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\008k.com -> www.008k.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\010402.com -> 010402.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\...\123simsen.com -> www.123simsen.com

    Da befinden sich 7942 mehr Seiten.

    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\008i.com -> 008i.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\008k.com -> www.008k.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\010402.com -> 010402.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\...\123simsen.com -> www.123simsen.com

    Da befinden sich 7942 mehr Seiten.

    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\008i.com -> 008i.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\008k.com -> www.008k.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\010402.com -> 010402.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\...\123simsen.com -> www.123simsen.com

    Da befinden sich 7942 mehr Seiten.


    ==================== Hosts Inhalt: =========================

    (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

    2019-03-19 04:49 - 2020-01-10 16:24 - 000454708 ____R C:\Windows\system32\drivers\etc\hosts
    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com
    127.0.0.1 www.0scan.com
    127.0.0.1 0scan.com
    127.0.0.1 1000gratisproben.com
    127.0.0.1 www.1000gratisproben.com
    127.0.0.1 1001namen.com
    127.0.0.1 www.1001namen.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100888290cs.com
    127.0.0.1 www.100sexlinks.com
    127.0.0.1 100sexlinks.com
    127.0.0.1 10sek.com
    127.0.0.1 www.10sek.com
    127.0.0.1 www.1-2005-search.com
    127.0.0.1 1-2005-search.com
    127.0.0.1 123fporn.info
    127.0.0.1 www.123fporn.info
    127.0.0.1 www.123haustiereundmehr.com
    127.0.0.1 123haustiereundmehr.com
    127.0.0.1 123moviedownload.com
    127.0.0.1 www.123moviedownload.com

    Da befinden sich 15607 zusätzliche Einträge.


    ==================== Andere Bereiche ===========================

    (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

    HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513148\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
    HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514148\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
    HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944339\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
    HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513257\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
    HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514273\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
    HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944395\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
    HKU\S-1-5-21-68706545-277898625-3769142786-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225513351\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225514366\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
    HKU\S-1-5-21-68706545-277898625-3769142786-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01112020225944458\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
    DNS Servers: 192.168.101.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
    ist aktiviert.

    ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

    ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ================

    (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

    FirewallRules: [{C23099A0-9BAD-4206-8840-EC1C604E2A32}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
    FirewallRules: [{8E199E48-1B9E-4E42-BFF9-D1ED9FAC4E1E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
    FirewallRules: [{74C3C881-3292-4459-A09D-1E6F5CE9A5C8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
    FirewallRules: [{8B15969A-97D3-4D47-B8BD-EA8FB88A9F83}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
    FirewallRules: [TCP Query User{9FD1E7DC-5779-46D3-9CB1-3CEC99C18D4F}C:\users\leonard\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\leonard\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [UDP Query User{DC157001-0CBB-47BE-8E2E-41A60745C83D}C:\users\leonard\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\leonard\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [{C5E30BD3-0E5B-4E44-B99F-3BEA775E2C86}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
    FirewallRules: [{AC87B4B7-B15C-4F80-BB71-F5227DFC35CF}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
    FirewallRules: [{11166E47-97D9-4C5E-9E74-C6993320BAFD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Risk of Rain 2\Risk of Rain 2.exe () [Datei ist nicht signiert]
    FirewallRules: [{2323BF67-6459-48B3-A6CD-6371570E3B2F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Risk of Rain 2\Risk of Rain 2.exe () [Datei ist nicht signiert]
    FirewallRules: [{4C546CB5-5FDE-4803-8B7E-D2D644D8321F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom Under Fire 2\KUF2SteamLauncher.exe (Gameforge 4D GmbH -> )
    FirewallRules: [{F6E7B600-0373-469F-AE2F-9A5F34922EFE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom Under Fire 2\KUF2SteamLauncher.exe (Gameforge 4D GmbH -> )
    FirewallRules: [{A8A32258-88A0-4617-BF31-CF8E5F8E5590}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AoE2DE\AoE2DE_s.exe (Microsoft Corporation -> Microsoft Corporation)
    FirewallRules: [{2815C75A-6FE5-4897-8C0B-991FE84DC792}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AoE2DE\AoE2DE_s.exe (Microsoft Corporation -> Microsoft Corporation)
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

    ==================== Wiederherstellungspunkte =========================

    ACHTUNG: Systemwiederherstellung ist deaktiviert (Total:111.22 GB) (Free:35.03 GB) (31%)

    ==================== Fehlerhafte Geräte im Gerätemanager ============


    ==================== Fehlereinträge in der Ereignisanzeige: ========================

    Applikationsfehler:
    ==================
    Error: (01/11/2020 09:55:55 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
    Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
    Exception code: 0xe06d7363
    Fault offset: 0x000000000003a839
    Faulting process ID: 0x26c
    Faulting application start time: 0x01d5c8c9e6709ec6
    Faulting application path: C:\Windows\system32\ctfmon.exe
    Faulting module path: C:\Windows\System32\KERNELBASE.dll
    Report ID: be451b2b-a212-439d-8a16-89642ac820b7
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (01/11/2020 09:55:50 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
    Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
    Exception code: 0xe06d7363
    Fault offset: 0x000000000003a839
    Faulting process ID: 0x1ffc
    Faulting application start time: 0x01d5c8c9e3718069
    Faulting application path: C:\Windows\system32\ctfmon.exe
    Faulting module path: C:\Windows\System32\KERNELBASE.dll
    Report ID: a6564c4d-95e2-4ca7-829d-9ef10a254baf
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (01/11/2020 09:55:46 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
    Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
    Exception code: 0xe06d7363
    Fault offset: 0x000000000003a839
    Faulting process ID: 0x2a30
    Faulting application start time: 0x01d5c8c9e072a0f1
    Faulting application path: C:\Windows\system32\ctfmon.exe
    Faulting module path: C:\Windows\System32\KERNELBASE.dll
    Report ID: 2e6ef05e-a0aa-45e8-9bbe-1b76b9f666e5
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (01/11/2020 09:55:40 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
    Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
    Exception code: 0xe06d7363
    Fault offset: 0x000000000003a839
    Faulting process ID: 0x2b60
    Faulting application start time: 0x01d5c8c9dd75078a
    Faulting application path: C:\Windows\system32\ctfmon.exe
    Faulting module path: C:\Windows\System32\KERNELBASE.dll
    Report ID: dc328812-db4e-429c-afa6-af639dce0139
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (01/11/2020 09:55:35 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
    Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
    Exception code: 0xe06d7363
    Fault offset: 0x000000000003a839
    Faulting process ID: 0x293c
    Faulting application start time: 0x01d5c8c9da76c0e8
    Faulting application path: C:\Windows\system32\ctfmon.exe
    Faulting module path: C:\Windows\System32\KERNELBASE.dll
    Report ID: b15dc70f-ca3d-4991-920e-a1e76aa57d37
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (01/11/2020 09:55:30 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
    Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
    Exception code: 0xe06d7363
    Fault offset: 0x000000000003a839
    Faulting process ID: 0x1fa8
    Faulting application start time: 0x01d5c8c9d7791fb3
    Faulting application path: C:\Windows\system32\ctfmon.exe
    Faulting module path: C:\Windows\System32\KERNELBASE.dll
    Report ID: 363b22b9-e56d-459c-91a0-08d336e09c32
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (01/11/2020 09:55:25 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
    Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
    Exception code: 0xe06d7363
    Fault offset: 0x000000000003a839
    Faulting process ID: 0x21fc
    Faulting application start time: 0x01d5c8c9d479b3d9
    Faulting application path: C:\Windows\system32\ctfmon.exe
    Faulting module path: C:\Windows\System32\KERNELBASE.dll
    Report ID: 6a5dbc23-8a88-41bd-b526-347b9174b307
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (01/11/2020 09:55:20 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ctfmon.exe, version: 10.0.18362.1, time stamp: 0x50d94f4d
    Faulting module name: KERNELBASE.dll, version: 10.0.18362.535, time stamp: 0x50cc8d5a
    Exception code: 0xe06d7363
    Fault offset: 0x000000000003a839
    Faulting process ID: 0x2178
    Faulting application start time: 0x01d5c8c9d09e9b2a
    Faulting application path: C:\Windows\system32\ctfmon.exe
    Faulting module path: C:\Windows\System32\KERNELBASE.dll
    Report ID: 222da474-4953-4c77-80ea-e32bd90da535
    Faulting package full name:
    Faulting package-relative application ID:


    Systemfehler:
    =============
    Error: (01/11/2020 09:55:09 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\Windows\system32\Rtlihvs.dll
    Error Code: 126

    Error: (01/11/2020 09:32:59 PM) (Source: BugCheck) (EventID: 1001) (User: )
    Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0xfffff8051cc5b010, 0x00000000000000ff, 0x0000000000000000, 0xfffff8051ddd95ae). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 8f06bf1e-541f-4817-bbec-03352736ad88.

    Error: (01/11/2020 09:32:56 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\Windows\system32\Rtlihvs.dll
    Error Code: 126

    Error: (01/11/2020 09:32:55 PM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 22:30:25 on ‎11.‎01.‎2020 was unexpected.

    Error: (01/11/2020 09:30:30 PM) (Source: BugCheck) (EventID: 1001) (User: )
    Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff6fb7dbedde0, 0x0000000000000000, 0xfffff8056a0e78be, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: bea19e77-5c5b-4d98-97ec-fe8b94df829e.

    Error: (01/11/2020 09:30:26 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\Windows\system32\Rtlihvs.dll
    Error Code: 126

    Error: (01/11/2020 09:30:25 PM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 22:23:09 on ‎11.‎01.‎2020 was unexpected.

    Error: (01/10/2020 09:29:51 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\Windows\system32\Rtlihvs.dll
    Error Code: 126


    Windows Defender:
    ===================================
    Date: 2020-01-10 18:54:11.855
    Description:
    Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
    Feature: Behavior Monitoring
    Error Code: 0x80508023
    Error description: Auf dem Gerät wurde keine Schadsoftware oder andere potenziell unerwünschte Software gefunden.
    Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

    Date: 2020-01-10 16:22:24.686
    Description:
    Windows Defender Antivirus has encountered an error trying to update security intelligence.
    New security intelligence Version:
    Previous security intelligence Version: 1.307.2007.0
    Update Source: Microsoft Update Server
    Security intelligence Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.16600.7
    Error code: 0x8024402f
    Error description: Unerwartetes Problem bei der Überprüfung auf Updates. Informationen zum Installieren von Updates oder zur Problembehandlung finden Sie unter "Hilfe und Support".

    Date: 2020-01-09 20:10:39.614
    Description:
    Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
    Feature: Behavior Monitoring
    Error Code: 0x80508023
    Error description: Auf dem Gerät wurde keine Schadsoftware oder andere potenziell unerwünschte Software gefunden.
    Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

    CodeIntegrity:
    ===================================

    Date: 2020-01-11 21:55:10.691
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-01-11 21:55:10.651
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-01-11 21:34:36.616
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

    Date: 2020-01-11 21:32:58.184
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-01-11 21:32:58.155
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-01-11 21:30:28.345
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-01-11 21:30:28.323
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-01-11 13:03:39.789
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

    ==================== Speicherinformationen ===========================

    BIOS: American Megatrends Inc. F10 09/18/2018
    Hauptplatine: Gigabyte Technology Co., Ltd. Z370 AORUS ULTRA GAMING WIFI-CF
    Prozessor: Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
    Prozentuale Nutzung des RAM: 37%
    Installierter physikalischer RAM: 16326.27 MB
    Verfügbarer physikalischer RAM: 10134.73 MB
    Summe virtueller Speicher: 19270.27 MB
    Verfügbarer virtueller Speicher: 10656.82 MB

    ==================== Laufwerke ================================

    Drive c: () (Fixed) (Total:111.22 GB) (Free:35.03 GB) NTFS
    Drive d: () (Fixed) (Total:931.39 GB) (Free:931.18 GB) NTFS

    \\?\Volume{a16fb195-0000-0000-0000-100000000000}\ (System-reserviert) (Fixed) (Total:0.57 GB) (Free:0.11 GB) NTFS

    ==================== MBR & Partitionstabelle ====================

    ==========================================================
    Disk: 0 (MBR Code: Windows 7/8/10) (Size: 111.8 GB) (Disk ID: A16FB195)
    Partition 1: (Active) - (Size=579 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=111.2 GB) - (Type=07 NTFS)

    ==========================================================
    Disk: 1 (Size: 931.5 GB) (Disk ID: 2AAA9BAC)

    Partition: GPT.

    ==================== Ende von Addition.txt =======================

  2. #2
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,855

    Default

    malwarebytes showed me that my browser tried to open malicious websites on its own, particular when i opened games.
    This is probably coming from the site, we might be able to download an addon to block those.

    uBlock-Origin can be installed from here: https://addons.mozilla.org/en-GB/fir...ublock-origin/ <<--- Recommended.

    I would like to see the logs from the scans you ran to see what was identified.
    If you cannot find these please run fresh scans.

    AdwCleaner C:\AdwCleaner\Logs\AdwCleaner, see if you can find the last scan run so I can see the logs. If not
    We can run new scans.



    Malwarebytes Anti-Malware 4.0
    Open, click on Quarantined Items, then on history, open the last scan, copy and paste that log here so I can see it.


    Please post the last scan log from here as well.

    If, those logs cannot be found, run a fresh scan so I can see the results.
    C:\ProgramData\RogueKiller\Logs\RKreport_DEL_mmddyyyy_hhmmss.log

    ~~

    It would be a good idea to refresh Firefox

    Possibly using the "Refresh" option will be enough to remove whatever is lurking within Firefox... Have a read at the following link:

    https://support.mozilla.org/en-US/kb...s-and-settings

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`
    If you prefer we could make a clean install of Firefox and start from scratch..
    try a fresh install see if that helps..
    Make a "Clean" install Firefox:

    Use the following link for instructions how to back up your bookmarks, same link can be used to import saved Bookmarks:

    https://support.mozilla.org/en-US/kb...up-or-transfer

    Next,

    Remove all synced data from Firefox to stop possible re-infection or exploitation.

    https://support.mozilla.org/en-US/questions/1037353

    Next,

    Go here: http://www.mozilla.org/en-US/ download save the latest version of Firefox.. We will install this later...


    Next,

    Lets totally remove Firefox and start over.

    Go here: https://support.mozilla.org/en-US/kb...-your-computer and follow those instructions...

    Ensure when the uninstall completes to navigate to and delete the firefox installation folder (if present):

    (32-bit Windows) C:\Program Files\Mozilla Firefox
    (64-bit Windows) C:\Program Files (x86)\Mozilla Firefox

    It is essential the installation folder is removed. Re-boot your system when that is completed....


    Next,

    To remove all remaining data and profile information...

    Press "Windows key + R" to open the Run box
    In the Run box, type in or copy and paste %APPDATA%
    Click OK. A Windows Explorer window will appear.
    In this window, choose/open in succession Mozilla > Firefox > Profiles.
    Select Delete on each entry in reverse, eg Profiles > Delete. Firefox > Delete. Mozilla > Delete.

    Re-boot your system when complete!

    Next,

    Use the Mozilla Firefox installer to reinstall your Browser....

    When Firefox is installed and open select these keys together :- Ctrl - Shift - A that will access Addons manger, this gives access to find addons/extensions, use, start, stop or disable those features etc....

    uBlock-Origin can be installed from here: https://addons.mozilla.org/en-GB/fir...ublock-origin/ <<--- Recommended.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  3. #3
    Junior Member
    Join Date
    Jan 2020
    Posts
    4

    Default

    The six items found by AdwCleaner are supposed to be a problem if you run Immunize with Spybot and AdwCleaner together, i was told.

    As i refreshed Firefox it came up with the Warning, i posted below, about firefox trying to open the website. It was the same website it tried to open a couple of days ago.

    After i posted this i will follow the instructions and reinstall firefox.

    Sorry for the german in the Logs again.

    [AdwCleaner Scanresults]

    # Malwarebytes AdwCleaner 8.0.1.0
    # -------------------------------
    # Build: 12-17-2019
    # Database: 2019-12-17.1 (Local)
    # Support: https://www.malwarebytes.com/support
    #
    # -------------------------------
    # Mode: Scan
    # -------------------------------
    # Start: 01-11-2020
    # Duration: 00:00:15
    # OS: Windows 10 Home
    # Scanned: 35232
    # Detected: 6


    ***** [ Services ] *****

    No malicious services found.

    ***** [ Folders ] *****

    No malicious folders found.

    ***** [ Files ] *****

    No malicious files found.

    ***** [ DLL ] *****

    No malicious DLLs found.

    ***** [ WMI ] *****

    No malicious WMI found.

    ***** [ Shortcuts ] *****

    No malicious shortcuts found.

    ***** [ Tasks ] *****

    No malicious tasks found.

    ***** [ Registry ] *****

    PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
    PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
    PUP.Optional.Legacy HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
    PUP.Optional.Legacy HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
    PUP.Optional.Legacy HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
    PUP.Optional.Legacy HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com

    ***** [ Chromium (and derivatives) ] *****

    No malicious Chromium entries found.

    ***** [ Chromium URLs ] *****

    No malicious Chromium URLs found.

    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries found.

    ***** [ Firefox URLs ] *****

    No malicious Firefox URLs found.

    ***** [ Preinstalled Software ] *****

    No Preinstalled Software found.


    AdwCleaner[S00].txt - [1326 octets] - [09/01/2020 18:18:43]
    AdwCleaner[S01].txt - [1387 octets] - [10/01/2020 17:17:49]
    AdwCleaner[S02].txt - [2204 octets] - [10/01/2020 19:39:04]
    AdwCleaner[S03].txt - [2265 octets] - [10/01/2020 19:40:39]
    AdwCleaner[S04].txt - [2326 octets] - [11/01/2020 22:12:27]

    ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S05].txt ##########

    [Last Malwarebytes Warning]

    Malwarebytes
    www.malwarebytes.com

    -Protokolldetails-
    Datum des Schutzereignisses: 12.01.20
    Uhrzeit des Schutzereignisses: 14:41
    Protokolldatei: 3b331592-3541-11ea-af27-e0d55eb53d63.json

    -Softwaredaten-
    Version: 4.0.4.49
    Komponentenversion: 1.0.793
    Version des Aktualisierungspakets: 1.0.17625
    Lizenz: Testversion

    -Systemdaten-
    Betriebssystem: Windows 10 (Build 18362.535)
    CPU: x64
    Dateisystem: NTFS
    Benutzer: System

    -Einzelheiten zu blockierten Websites-
    Bösartige Website: 1
    , C:\Program Files\Mozilla Firefox\firefox.exe, Blockiert, -1, -1, 0.0.0

    -Website-Daten-
    Kategorie: „Malvertising“
    Domäne: find-my-great-life.com
    IP-Adresse: 213.174.153.231
    Port: 80
    Typ: Ausgehend
    Datei: C:\Program Files\Mozilla Firefox\firefox.exe



    (end)

    [Last Malwarebytes Scan]

    Malwarebytes
    www.malwarebytes.com

    -Protokolldetails-
    Scan-Datum: 12.01.20
    Scan-Zeit: 12:27
    Protokolldatei: 7609b2f6-352e-11ea-8008-e0d55eb53d63.json

    -Softwaredaten-
    Version: 4.0.4.49
    Komponentenversion: 1.0.793
    Version des Aktualisierungspakets: 1.0.17621
    Lizenz: Testversion

    -Systemdaten-
    Betriebssystem: Windows 10 (Build 18362.535)
    CPU: x64
    Dateisystem: NTFS
    Benutzer: System

    -Scan-Übersicht-
    Scan-Typ: Bedrohungs-Scan
    Scan gestartet von: Zeitplaner
    Ergebnis: Abgeschlossen
    Gescannte Objekte: 268695
    Erkannte Bedrohungen: 0
    In die Quarantäne verschobene Bedrohungen: 0
    Abgelaufene Zeit: 2 Min., 1 Sek.

    -Scan-Optionen-
    Speicher: Aktiviert
    Start: Aktiviert
    Dateisystem: Aktiviert
    Archive: Aktiviert
    Rootkits: Deaktiviert
    Heuristik: Aktiviert
    PUP: Erkennung
    PUM: Erkennung

    -Scan-Details-
    Prozess: 0
    (keine bösartigen Elemente erkannt)

    Modul: 0
    (keine bösartigen Elemente erkannt)

    Registrierungsschlüssel: 0
    (keine bösartigen Elemente erkannt)

    Registrierungswert: 0
    (keine bösartigen Elemente erkannt)

    Registrierungsdaten: 0
    (keine bösartigen Elemente erkannt)

    Daten-Stream: 0
    (keine bösartigen Elemente erkannt)

    Ordner: 0
    (keine bösartigen Elemente erkannt)

    Datei: 0
    (keine bösartigen Elemente erkannt)

    Physischer Sektor: 0
    (keine bösartigen Elemente erkannt)

    WMI: 0
    (keine bösartigen Elemente erkannt)


    (end)

    [RogueKiller Scan Results]

    {
    "header": {
    "program": {
    "project": "RogueKiller Anti-Malware",
    "version": "14.0.4.0",
    "x64": true,
    "date": "Jan 6 2020",
    "contact": "https://adlice.com/contact/",
    "website": "https://adlice.com/download/roguekiller/"
    },
    "environment": {
    "operating_system": "Windows 10 (10.0.18363) 64 bits",
    "boot": 0,
    "winpe": false,
    "user": "Leonard",
    "user_admin": true,
    "program_location": "C:\\Program Files\\RogueKiller\\RogueKiller64.exe",
    "x64": true,
    "licensing": "free"
    },
    "report": {
    "type": 1,
    "aborted": false,
    "date": "2020/01/12 13:55:40",
    "duration": 207,
    "count": 0,
    "scanned_count": 45565,
    "scan_mode": "standard",
    "signatures_version": "20200110_140015",
    "log_legit": false,
    "expert_mode": false,
    "truesight_loaded": true,
    "switches": [
    "-minimize"
    ],
    "id": "3FCE98621FA96FBB"
    }
    },
    "results": {
    "processes": [
    {
    "name": "[System Process]",
    "pid": 0,
    "children": []
    },
    {
    "name": "System",
    "pid": 4,
    "children": [
    {
    "name": "smss.exe",
    "pid": 416,
    "children": []
    },
    {
    "name": "Memory Compression",
    "pid": 2056,
    "children": []
    }
    ]
    },
    {
    "name": "Registry",
    "pid": 144,
    "children": []
    },
    {
    "name": "csrss.exe",
    "pid": 608,
    "children": []
    },
    {
    "name": "wininit.exe",
    "pid": 696,
    "children": [
    {
    "name": "services.exe",
    "pid": 768,
    "children": [
    {
    "name": "svchost.exe",
    "pid": 600,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 688,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 904,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 968,
    "children": [
    {
    "name": "Microsoft.Photos.exe",
    "pid": 152,
    "children": []
    },
    {
    "name": "RuntimeBroker.exe",
    "pid": 828,
    "children": []
    },
    {
    "name": "CompPkgSrv.exe",
    "pid": 1088,
    "children": []
    },
    {
    "name": "ShellExperienceHost.exe",
    "pid": 3360,
    "children": []
    },
    {
    "name": "ApplicationFrameHost.exe",
    "pid": 5548,
    "children": []
    },
    {
    "name": "SearchUI.exe",
    "pid": 5932,
    "children": []
    },
    {
    "name": "WinStore.App.exe",
    "pid": 6368,
    "children": []
    },
    {
    "name": "RuntimeBroker.exe",
    "pid": 6920,
    "children": []
    },
    {
    "name": "smartscreen.exe",
    "pid": 7336,
    "children": []
    },
    {
    "name": "dllhost.exe",
    "pid": 7548,
    "children": []
    },
    {
    "name": "RuntimeBroker.exe",
    "pid": 7880,
    "children": []
    },
    {
    "name": "RuntimeBroker.exe",
    "pid": 7936,
    "children": []
    },
    {
    "name": "backgroundTaskHost.exe",
    "pid": 9716,
    "children": []
    },
    {
    "name": "StartMenuExperienceHost.exe",
    "pid": 10088,
    "children": []
    },
    {
    "name": "dllhost.exe",
    "pid": 10128,
    "children": []
    },
    {
    "name": "WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe",
    "pid": 10780,
    "children": []
    },
    {
    "name": "RuntimeBroker.exe",
    "pid": 11464,
    "children": []
    },
    {
    "name": "RuntimeBroker.exe",
    "pid": 11596,
    "children": []
    },
    {
    "name": "RuntimeBroker.exe",
    "pid": 12332,
    "children": []
    }
    ]
    },
    {
    "name": "svchost.exe",
    "pid": 1248,
    "children": [
    {
    "name": "taskhostw.exe",
    "pid": 1240,
    "children": []
    }
    ]
    },
    {
    "name": "svchost.exe",
    "pid": 1268,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1276,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1324,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1332,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1352,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1500,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1580,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1588,
    "children": [
    {
    "name": "sihost.exe",
    "pid": 10524,
    "children": []
    }
    ]
    },
    {
    "name": "svchost.exe",
    "pid": 1704,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1760,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1828,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1836,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 1860,
    "children": []
    },
    {
    "name": "NVDisplay.Container.exe",
    "pid": 1892,
    "children": [
    {
    "name": "NVDisplay.Container.exe",
    "pid": 12204,
    "children": []
    }
    ]
    },
    {
    "name": "svchost.exe",
    "pid": 1928,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2000,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2008,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2012,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2024,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2100,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2184,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2192,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2200,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2272,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2352,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2524,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2692,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2744,
    "children": [
    {
    "name": "audiodg.exe",
    "pid": 2784,
    "children": []
    }
    ]
    },
    {
    "name": "svchost.exe",
    "pid": 2836,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2844,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2864,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 2888,
    "children": [
    {
    "name": "ctfmon.exe",
    "pid": 3236,
    "children": []
    }
    ]
    },
    {
    "name": "svchost.exe",
    "pid": 3016,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3044,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3076,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3200,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3208,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3336,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3412,
    "children": [
    {
    "name": "wlanext.exe",
    "pid": 3636,
    "children": [
    {
    "name": "conhost.exe",
    "pid": 3688,
    "children": []
    }
    ]
    }
    ]
    },
    {
    "name": "svchost.exe",
    "pid": 3460,
    "children": []
    },
    {
    "name": "spoolsv.exe",
    "pid": 3680,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3800,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3808,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3880,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3900,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3904,
    "children": []
    },
    {
    "name": "ibtsiva.exe",
    "pid": 3944,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 3952,
    "children": []
    },
    {
    "name": "SDUpdSvc.exe",
    "pid": 4104,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 4112,
    "children": []
    },
    {
    "name": "SDFSSvc.exe",
    "pid": 4124,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 4152,
    "children": []
    },
    {
    "name": "RogueKillerSvc.exe",
    "pid": 4164,
    "children": [
    {
    "name": "RogueKiller64.exe",
    "pid": 11392,
    "children": []
    }
    ]
    },
    {
    "name": "svchost.exe",
    "pid": 4344,
    "children": []
    },
    {
    "name": "SDWSCSvc.exe",
    "pid": 4408,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 4416,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 4424,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 4488,
    "children": []
    },
    {
    "name": "MBAMService.exe",
    "pid": 4520,
    "children": [
    {
    "name": "mbamtray.exe",
    "pid": 10156,
    "children": []
    }
    ]
    },
    {
    "name": "svchost.exe",
    "pid": 5332,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 5720,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 6532,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 6556,
    "children": []
    },
    {
    "name": "SearchIndexer.exe",
    "pid": 6704,
    "children": [
    {
    "name": "SearchProtocolHost.exe",
    "pid": 856,
    "children": []
    },
    {
    "name": "SearchFilterHost.exe",
    "pid": 1532,
    "children": []
    },
    {
    "name": "SearchProtocolHost.exe",
    "pid": 5812,
    "children": []
    }
    ]
    },
    {
    "name": "svchost.exe",
    "pid": 6944,
    "children": []
    },
    {
    "name": "SgrmBroker.exe",
    "pid": 7208,
    "children": []
    },
    {
    "name": "SteamService.exe",
    "pid": 7324,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 7492,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 7580,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 7612,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 7744,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 8088,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 8240,
    "children": []
    },
    {
    "name": "SecurityHealthService.exe",
    "pid": 8836,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 9388,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 9872,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 10360,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 10696,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 12424,
    "children": []
    },
    {
    "name": "svchost.exe",
    "pid": 12904,
    "children": []
    }
    ]
    },
    {
    "name": "lsass.exe",
    "pid": 776,
    "children": []
    },
    {
    "name": "fontdrvhost.exe",
    "pid": 1008,
    "children": []
    }
    ]
    },
    {
    "name": "firefox.exe",
    "pid": 996,
    "children": [
    {
    "name": "firefox.exe",
    "pid": 8,
    "children": []
    },
    {
    "name": "firefox.exe",
    "pid": 3180,
    "children": []
    },
    {
    "name": "firefox.exe",
    "pid": 6716,
    "children": []
    },
    {
    "name": "firefox.exe",
    "pid": 7408,
    "children": []
    },
    {
    "name": "firefox.exe",
    "pid": 8404,
    "children": []
    },
    {
    "name": "firefox.exe",
    "pid": 9276,
    "children": []
    },
    {
    "name": "firefox.exe",
    "pid": 9392,
    "children": []
    },
    {
    "name": "firefox.exe",
    "pid": 10080,
    "children": []
    },
    {
    "name": "firefox.exe",
    "pid": 10868,
    "children": []
    }
    ]
    },
    {
    "name": "winlogon.exe",
    "pid": 2896,
    "children": [
    {
    "name": "dwm.exe",
    "pid": 6188,
    "children": []
    },
    {
    "name": "fontdrvhost.exe",
    "pid": 9076,
    "children": []
    }
    ]
    },
    {
    "name": "csrss.exe",
    "pid": 4092,
    "children": []
    },
    {
    "name": "SDTray.exe",
    "pid": 4928,
    "children": [
    {
    "name": "SDWelcome.exe",
    "pid": 8476,
    "children": [
    {
    "name": "SDScan.exe",
    "pid": 1468,
    "children": []
    }
    ]
    }
    ]
    },
    {
    "name": "explorer.exe",
    "pid": 9564,
    "children": [
    {
    "name": "rundll32.exe",
    "pid": 508,
    "children": []
    },
    {
    "name": "Spotify.exe",
    "pid": 2880,
    "children": [
    {
    "name": "Spotify.exe",
    "pid": 532,
    "children": []
    },
    {
    "name": "Spotify.exe",
    "pid": 2096,
    "children": []
    },
    {
    "name": "Spotify.exe",
    "pid": 6816,
    "children": []
    },
    {
    "name": "Spotify.exe",
    "pid": 11168,
    "children": []
    }
    ]
    },
    {
    "name": "notepad.exe",
    "pid": 5552,
    "children": []
    },
    {
    "name": "SecurityHealthSystray.exe",
    "pid": 10380,
    "children": []
    },
    {
    "name": "OneDrive.exe",
    "pid": 11404,
    "children": []
    },
    {
    "name": "Steam.exe",
    "pid": 11492,
    "children": [
    {
    "name": "steamwebhelper.exe",
    "pid": 11244,
    "children": [
    {
    "name": "steamwebhelper.exe",
    "pid": 6312,
    "children": []
    },
    {
    "name": "steamwebhelper.exe",
    "pid": 7996,
    "children": []
    },
    {
    "name": "steamwebhelper.exe",
    "pid": 9120,
    "children": []
    },
    {
    "name": "steamwebhelper.exe",
    "pid": 11208,
    "children": []
    },
    {
    "name": "steamwebhelper.exe",
    "pid": 11660,
    "children": []
    },
    {
    "name": "steamwebhelper.exe",
    "pid": 13168,
    "children": []
    }
    ]
    }
    ]
    },
    {
    "name": "RtkNGUI64.exe",
    "pid": 11740,
    "children": []
    }
    ]
    },
    {
    "name": "mbam.exe",
    "pid": 12676,
    "children": []
    }
    ],
    "modules": [],
    "services": [],
    "tasks": [],
    "registry": [],
    "wmi": [],
    "hosts": {
    "is_too_big": true,
    "hosts_file_path": "C:\\Windows\\System32\\drivers\\etc\\hosts",
    "lines": []
    },
    "filesystem": [],
    "web_browsers": []
    }
    }

  4. #4
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,855

    Default

    There is a web site your visiting that trying to inject malicious code. Thats why the alert for Firefox.
    https://blog.malwarebytes.com/detect...reat-life-com/


    Disable Spybot long enough to run AdwCleaner, ensure all items found have a check mark by them to delete.


    The below addon is good to use with Firefox
    https://addons.mozilla.org/en-US/fir.../adblock-plus/

    ~~

    Zemana AntiMalware - Fix
    • Download and install Zemana AntiMalware
    • Open Zemana AntiMalware, and click on the Scan button
    • Wait for the scan to complete
    • Once done, click on any threats it detected, then select Apply to all and Quarantine to quarantine all threats, and click on the Next button
    • If it asks you to reboot your computer to finish the clean-up, do so
    • After that, click on the most upper right button to go to the Reports tab, select the latest System Scan entry and click on the Open Report button
    • A log will open in Notepad
    • Copy/paste the content of that log in your next reply


    ~~

    ESET Online Scanner
    • Download and execute ESET Online Scanner
    • Check the following settings (two of them are under Advanced Settings, click on it to display them):
      • Enable detection of potentially unwanted applications
      • Enable detection of potentially unsafe applications
      • Scan archives
      • Scan for potentially unsafe applications
      • Optional : If you want to scan more drives, click on Change... and select the drives you want to include in the scan
    • After you're done checking these options, click on the Scan button and ESET Online Scanner will download its virus signature database before starting the scan
    • Once done, the scan will start automatically. ESET Online Scanner can have an extremely long scan time that can last between 2 or 3 hours. So if you start the scan, do not interrupt it, let it complete
    • On completion, a summary window will appear to give you the information about the scan. Then you'll have to the option to see what threads were found and to manage the threats that were quarantined
    • Click on List of found threats, it'll display every threat identified during that scan, their type and what action was taken against them. Click on Copy to clipboard to copy these results on our clipboard and post them in your next reply
    • Once you're done, click on the Back button, then click on the Finish button
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #5
    Junior Member
    Join Date
    Jan 2020
    Posts
    4

    Default

    I followed your instructions and reinstalled Firefox, but i still got the warning from Malwarebytes. So i installed a second browser to see if it still occurs on there and it did(Result below).

    Zemana found something, but one Object always comes back up when i scan again.

    [AdwCleaner Scan without Spybot]

    # -------------------------------
    # Malwarebytes AdwCleaner 8.0.1.0
    # -------------------------------
    # Build: 12-17-2019
    # Database: 2020-01-06.1 (Cloud)
    # Support: https://www.malwarebytes.com/support
    #
    # -------------------------------
    # Mode: Scan
    # -------------------------------
    # Start: 01-12-2020
    # Duration: 00:00:08
    # OS: Windows 10 Home
    # Scanned: 34757
    # Detected: 0


    ***** [ Services ] *****

    No malicious services found.

    ***** [ Folders ] *****

    No malicious folders found.

    ***** [ Files ] *****

    No malicious files found.

    ***** [ DLL ] *****

    No malicious DLLs found.

    ***** [ WMI ] *****

    No malicious WMI found.

    ***** [ Shortcuts ] *****

    No malicious shortcuts found.

    ***** [ Tasks ] *****

    No malicious tasks found.

    ***** [ Registry ] *****

    No malicious registry entries found.

    ***** [ Chromium (and derivatives) ] *****

    No malicious Chromium entries found.

    ***** [ Chromium URLs ] *****

    No malicious Chromium URLs found.

    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries found.

    ***** [ Firefox URLs ] *****

    No malicious Firefox URLs found.

    ***** [ Preinstalled Software ] *****

    No Preinstalled Software found.


    AdwCleaner[S00].txt - [1326 octets] - [09/01/2020 18:18:43]
    AdwCleaner[S01].txt - [1387 octets] - [10/01/2020 17:17:49]
    AdwCleaner[S02].txt - [2204 octets] - [10/01/2020 19:39:04]
    AdwCleaner[S03].txt - [2265 octets] - [10/01/2020 19:40:39]
    AdwCleaner[S04].txt - [2326 octets] - [11/01/2020 22:12:27]
    AdwCleaner[S05].txt - [2387 octets] - [11/01/2020 22:34:49]
    AdwCleaner[S06].txt - [2448 octets] - [12/01/2020 14:43:59]
    AdwCleaner[S07].txt - [2509 octets] - [12/01/2020 18:36:48]

    ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S08].txt ##########

    [Malwarebytes Warnings with Opera Browser]

    Malwarebytes
    www.malwarebytes.com

    -Log Details-
    Protection Event Date: 12/01/2020
    Protection Event Time: 20:08
    Log File: f35737ca-356e-11ea-8b29-e0d55eb53d63.json

    -Software Information-
    Version: 4.0.4.49
    Components Version: 1.0.793
    Update Package Version: 1.0.17633
    Licence: Trial

    -System Information-
    OS: Windows 10 (Build 18362.535)
    CPU: x64
    File System: NTFS
    User: System

    -Blocked Website Details-
    Malicious Website: 1
    , C:\Users\Leonard\AppData\Local\Programs\Opera\66.0.3515.27\opera.exe, Blocked, -1, -1, 0.0.0

    -Website Data-
    Category: Malvertising
    Domain: allmygoodlife.com
    IP Address: 213.174.153.231
    Port: 80
    Type: Outbound
    File: C:\Users\Leonard\AppData\Local\Programs\Opera\66.0.3515.27\opera.exe



    (end)

    Malwarebytes
    www.malwarebytes.com

    -Log Details-
    Protection Event Date: 12/01/2020
    Protection Event Time: 18:57
    Log File: fd4f55f0-3564-11ea-b486-e0d55eb53d63.json

    -Software Information-
    Version: 4.0.4.49
    Components Version: 1.0.793
    Update Package Version: 1.0.17633
    Licence: Trial

    -System Information-
    OS: Windows 10 (Build 18362.535)
    CPU: x64
    File System: NTFS
    User: System

    -Blocked Website Details-
    Malicious Website: 1
    , C:\Users\Leonard\AppData\Local\Programs\Opera\66.0.3515.27\opera.exe, Blocked, -1, -1, 0.0.0

    -Website Data-
    Category: PUP
    Domain: mygoodlives.com
    IP Address: 213.174.153.229
    Port: 80
    Type: Outbound
    File: C:\Users\Leonard\AppData\Local\Programs\Opera\66.0.3515.27\opera.exe



    (end)

    [Zemana Scan]

    Scan Information
    Product Name    :  Zemana AntiMalware
    Scan Status    :  Completed
    Scan Date    :  1/12/2020 9:28:36 PM
    Scan Type    :  Smart Scan
    Scan Duration    :  00:00:11
    Scanned Objects    :  1836
    Detected Objects    :  4
    Excluded Objects    :  0
    Auto Upload    :  True
    OS    :  Windows 10 x64
    Processor    :  12X Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
    BIOS Mode    :  Legacy
    Domain Info    :  WORKGROUP,False,NetSetupWorkgroupName
    CUID    :  1249A2899D2519B3DD6FA5


    Detections
    MD5    :  3904416F6068643D528BF132EB5EAB09
    Status    :  Scanned
    Object    :  c:\program files (x86)\steam\steamapps\common\kingdom under fire 2\fmod_distance_filter64.dll
    Publisher    :  
    Size    :  11776
    Detection    :  Suspicious:SRC!P
    Action    :  Quarantine
    -----------------------------------------------------------------------
    MD5    :  9C7A9018289E565DFA4F73D9E8BDF7B8
    Status    :  Scanned
    Object    :  c:\windows\system32\driverstore\filerepository\e1d68x64.inf_amd64_b44028fc7fdf4fca\e1d68x64.sys
    Publisher    :  Intel(R) INTELND1820
    Size    :  599920
    Detection    :  Suspicious:SRC!D
    Action    :  Quarantine
    -----------------------------------------------------------------------
    MD5    :  E7E39383B93BFF2047D87A9C6C9BBFB2
    Status    :  Scanned
    Object    :  c:\program files (x86)\steam\steamapps\common\kingdom under fire 2\fmod_noise64.dll
    Publisher    :  
    Size    :  9728
    Detection    :  Suspicious:SRC!P
    Action    :  Quarantine
    -----------------------------------------------------------------------
    MD5    :  FFAA0A1EB1EBFE276118DFC9B869F1E8
    Status    :  Scanned
    Object    :  c:\program files (x86)\steam\steamapps\common\kingdom under fire 2\fmod_gain64.dll
    Publisher    :  
    Size    :  9728
    Detection    :  Suspicious:SRC!P
    Action    :  Quarantine
    -----------------------------------------------------------------------

    [All Further Zemana Scans found this]

    Product Name    :  Zemana AntiMalware
    Scan Status    :  Completed
    Scan Date    :  1/12/2020 10:26:53 PM
    Scan Type    :  Smart Scan
    Scan Duration    :  00:00:12
    Scanned Objects    :  1857
    Detected Objects    :  1
    Excluded Objects    :  0
    Auto Upload    :  True
    OS    :  Windows 10 x64
    Processor    :  12X Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
    BIOS Mode    :  Legacy
    Domain Info    :  WORKGROUP,False,NetSetupWorkgroupName
    CUID    :  1249A2899D2519B3DD6FA5


    Detections
    MD5    :  9C7A9018289E565DFA4F73D9E8BDF7B8
    Status    :  Scanned
    Object    :  c:\windows\system32\driverstore\filerepository\e1d68x64.inf_amd64_b44028fc7fdf4fca\e1d68x64.sys
    Publisher    :  Intel(R) INTELND1820
    Size    :  599920
    Detection    :  Suspicious:SRC!D
    Action    :  Quarantine
    -----------------------------------------------------------------------

    [ESET Online Scanner]

    Log
    Scan Log
    Version of detection engine: 20661 (20200112)
    Date: 12/01/2020 Time: 23:17:02
    Scanned disks, folders and files: Operating memory;Boot sectors/UEFI;C:\Boot sectors/UEFI;C:\;D:\Boot sectors/UEFI;D:\;E:\Boot sectors/UEFI;E:\
    C:\Program Files (x86)\Steam\steamapps\common\Kingdom Under Fire 2\KUF2.exe.local - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_1084a0ad1177bae5_0_0__0.bin - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_1084a0ad1177bae5_0_0__0.toc - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_1084a0ad1177bae5_0_0__1.bin - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_1084a0ad1177bae5_0_0__1.toc - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_0__0.bin - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_0__0.toc - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_0__1.bin - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_0__1.toc - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_1__0.bin - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_1__0.toc - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_1__1.bin - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_1__1.toc - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_2__0.bin - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_2__1.bin - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_2__1.toc - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_4__1.bin - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\fb11f25cba07662fc4562751909995bd_fce8395c8fd8a999_15f74c7777689be5_0_0__0.bin - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\fb11f25cba07662fc4562751909995bd_fce8395c8fd8a999_15f74c7777689be5_0_0__0.toc - unable to open [4]
    C:\ProgramData\NVIDIA Corporation\NV_Cache\fb11f25cba07662fc4562751909995bd_fce8395c8fd8a999_15f74c7777689be5_0_1__0.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_1084a0ad1177bae5_0_0__0.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_1084a0ad1177bae5_0_0__0.toc - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_1084a0ad1177bae5_0_0__1.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_1084a0ad1177bae5_0_0__1.toc - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_0__0.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_0__0.toc - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_0__1.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_0__1.toc - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_1__0.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_1__0.toc - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_1__1.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_1__1.toc - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_2__0.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_2__1.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_2__1.toc - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\7368a2659809edfb37a4df1ab892065d_fce8395c8fd8a999_bcd58f9816366a0d_0_4__1.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\fb11f25cba07662fc4562751909995bd_fce8395c8fd8a999_15f74c7777689be5_0_0__0.bin - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\fb11f25cba07662fc4562751909995bd_fce8395c8fd8a999_15f74c7777689be5_0_0__0.toc - unable to open [4]
    C:\Users\All Users\NVIDIA Corporation\NV_Cache\fb11f25cba07662fc4562751909995bd_fce8395c8fd8a999_15f74c7777689be5_0_1__0.bin - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\Internet Explorer\CacheStorage\edb.log - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\Windows\UsrClass.dat - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\Windows\WebCache\V01.log - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\Windows\WebCacheLock.dat - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\WindowsApps\GameBarElevatedFT_Alias.exe - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\WindowsApps\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\python.exe - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\WindowsApps\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\python3.exe - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\WindowsApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\WindowsApps\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\GameBarElevatedFT_Alias.exe - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\WindowsApps\MicrosoftEdge.exe - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\WindowsApps\python.exe - unable to open [4]
    C:\Users\Leonard\AppData\Local\Microsoft\WindowsApps\python3.exe - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\InputApp_cw5n1h2txyewy\Settings\settings.dat - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\InputApp_cw5n1h2txyewy\Settings\settings.dat.LOG1 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\InputApp_cw5n1h2txyewy\Settings\settings.dat.LOG2 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\CacheStorage\CacheStorage.edb - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\CacheStorage\CacheStorage.jfm - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat.LOG1 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat.LOG2 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG1 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\settings.dat - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG1 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat.LOG1 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat.LOG2 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings\settings.dat - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings\settings.dat.LOG1 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\Settings\settings.dat.LOG2 - unable to open [4]
    C:\Users\Leonard\AppData\Local\Spotify\Data\89\89ac39247a314a96811b0b35616999e1be640868.file - unable to open [4]
    C:\Users\Leonard\AppData\Local\Spotify\Storage\index.dat - unable to open [4]
    C:\Users\Leonard\AppData\Local\Spotify\Users\11131571923-user\primary.ldb\000043.log - unable to open [4]
    C:\Users\Leonard\AppData\Local\Spotify\Users\11131571923-user\primary.ldb\MANIFEST-000041 - unable to open [4]
    C:\Users\Leonard\AppData\Roaming\Mozilla\Firefox\Profiles\tknvxj2r.default-release-1578850267090\parent.lock - unable to open [4]
    C:\Users\Leonard\AppData\Roaming\Opera Software\Opera Stable\Current Session - unable to open [4]
    C:\Users\Leonard\AppData\Roaming\Opera Software\Opera Stable\Current Tabs - unable to open [4]
    C:\Users\Leonard\NTUSER.DAT - unable to open [4]
    C:\Users\Leonard\ntuser.dat.LOG1 - unable to open [4]
    C:\Users\Leonard\ntuser.dat.LOG2 - unable to open [4]
    C:\Windows\System32\catroot2\edb.log - unable to open [4]
    C:\Windows\System32\catroot2\edbtmp.log - unable to open [4]
    C:\Windows\System32\catroot2\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\catdb - unable to open [4]
    C:\Windows\System32\catroot2\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\catdb.jfm - unable to open [4]
    C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - unable to open [4]
    C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb.jfm - unable to open [4]
    C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - unable to open [4]
    C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb.jfm - unable to open [4]
    C:\hiberfil.sys - unable to open [4]
    C:\pagefile.sys - unable to open [4]
    C:\swapfile.sys - unable to open [4]
    Boot sector of disk E: - unable to open [4]
    Number of scanned objects: 193188
    Number of detections: 0
    Time of completion: 23:17:29 Total scanning time: 27 sec (00:00:27)

    Notes:
    [4] Object cannot be opened. It may be in use by another application or operating system.

  6. #6
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,855

    Default

    still got the warning from Malwarebytes
    You will, it means the computer is being protected.

    https://forums.malwarebytes.com/topi...omment-1350368


    The block events by the web protection is keeping your pc safe. That is important to keep in mind.

    These are the blocked sites & IP's

    "mygoodlives.com" "213.174.153.231"

    "allmygoodlife.com" "213.174.153.229",

    "find-my-great-life.com" "213.174.153.229",

    "find-my-great-life.com" "213.174.153.231"
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    The real-time web protection of the Malwarebytes Premium is keeping your pc safe. The notice is a courtesy message & does not mean the presence of a infection on the machine itself.

    For Your Information:

    The website Block message indicates that a potential risk was blocked by the malicious website protection.

    The Malwarebytes web protection, by default, will always show each IP block occurrence.

    The Malwarebytes website protection feature will advise customers when a known or suspected malicious IP is attempted to be reached (outgoing) or is trying access your PC.
    info page https://www.malwarebytes.com/lp/ip-b.../?ipblock=true

    Incoming block notice can be ignored, our software is blocking the threat and there is nothing more that can be done.

    On Outbound blocks, any attempted connection was stopped.

    Kingdom Under Fire
    The file is password protected (for example, there are multiple user profiles on the computer)
    They could be in use, windows protected files, password protect or damaged. This article may explain it a little more https://support.eset.com/kb2155/?locale=en_US

    Some files and services are locked by the operating system or running programs during use for protection, so security scanners may encounter problems attempting to access them. Other legitimate files, especially those used by security programs, may be obfuscated, encrypted or password protected in order to conceal itself so they do not allow access as a protective measure. When the scanner finds such an object, it makes a note and then just skips to the next one. That explains why it may show with such notations but no action taken in certain anti-virus or anti-malware log scan reports. These are normal when using security scanning programs so there is seldom a need for concern.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~

    Other then receiving the alert, whats happening to the computer?
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  7. #7
    Junior Member
    Join Date
    Jan 2020
    Posts
    4

    Default

    There are other symptoms that i find strange, but it might not be associated with a virus. Sometimes when i start my Computer and it asks for the password it just spams "00000" infinitely until i press another key. Some keys on my keyboard don't work when i use them with the caps key, like f, it just doesn't do anything when i try to make F and i need to use Capslock (could be just my keyboard tho, its not new).

    You can disable Cookies for each browser profile with Spybot, normally it tells me i have 2 profiles(IE and Firefox), but sometimes it shows me up to 12 different ones and they go something like HKUS... also whenever i try to disable cookies for FF it just enables them again.

    When i try running the windows defender antivirus, it sometimes comes up with the message "Your IT administrator has limited access to some areas of this app, and the item you tried to access is not available. Contact the IT helpdesk for more information."

    The main thing i associated my infection with were the malwarebytes warnings, but you are suggesting that there might be nothing wrong with that, right?

  8. #8
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,855

    Default

    Quote Originally Posted by LeonardM View Post
    There are other symptoms that i find strange, but it might not be associated with a virus. Sometimes when i start my Computer and it asks for the password it just spams "00000" infinitely until i press another key. Some keys on my keyboard don't work when i use them with the caps key, like f, it just doesn't do anything when i try to make F and i need to use Capslock (could be just my keyboard tho, its not new).

    You can disable Cookies for each browser profile with Spybot, normally it tells me i have 2 profiles(IE and Firefox), but sometimes it shows me up to 12 different ones and they go something like HKUS... also whenever i try to disable cookies for FF it just enables them again.

    When i try running the windows defender antivirus, it sometimes comes up with the message "Your IT administrator has limited access to some areas of this app, and the item you tried to access is not available. Contact the IT helpdesk for more information."

    The main thing i associated my infection with were the malwarebytes warnings, but you are suggesting that there might be nothing wrong with that, right?
    I'll have to guess at some of these it's really not my forte but, I can send you to a tech forum that might can straighten some of this out.
    https://forums.whatthetech.com/index.php?showforum=126 I am a member here too.
    In my mind your dealing with some hardware issues with your keyboard _ maybe?, somethings not working right there.


    For the errors with cookies -re-enabling I think you should post a new topic in this forum
    https://forums.spybot.info/forumdisplay.php?4-Spybot
    Allow a member there that is more familar then me see if they can figure out why it's doing that.

    From the error trying to use Windows Defender, it might be required you disable SpyBot and MalwareBytes (possibly has blocked these settings) long enough to attempt and run a new scan.

    malwarebytes warnings <==, the program is doing what it is designed to do, doesn't matter if it's inbound or outbound, What I did to resolve my personal issue with a same message warning for a pop up (I scanned my Laptop with everything on the planet to learn my machine was clean), I posted a topic at the MalwareBytes forum. The best answer was, when the pop up warning appears, check the little box "Do do not show me this message again"
    Now I have peace. I never found what, where, or when it all originated from but my machine was and still is clean.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  9. #9
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,855

    Default

    Glad we could help.
    Since this issue appears resolved ... this Topic is closed.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •