Jump to content


Photo

I keep getting disconnected from the internet


  • Please log in to reply
13 replies to this topic

#1 psychicguy

psychicguy

    Advanced Member

  • Helper Trainee
  • PipPipPip
  • 126 posts

Posted 06 February 2018 - 10:15 PM

I'm noticing that I disconnect from the internet no matter what im doing on it and it happends frequently.  It goes off then starts back on again.  I've checked with my ISP and they have told me my modem and router are doing fine and the signal strength is really good.  I think I might be infected with something or a setting isn't correct.
 
All help is appreciated, Thank you.
 
Below are my logs for malwarebytes, Farbar Recovery Scan Tool, and Security Analysis: 
 
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 2/6/18
Scan Time: 8:04 PM
Log File: f06dbed2-0bbb-11e8-8629-10c37b6f461d.json
Administrator: Yes
 
-Software Information-
Version: 3.2.2.2018
Components Version: 1.0.212
Update Package Version: 1.0.3886
License: Free
 
-System Information-
OS: Windows 10 (Build 16299.214)
CPU: x64
File System: NTFS
User: MARTY-PC\Marty
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 289950
Threats Detected: 3
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 2 min, 23 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 2
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support, No Action By User, [2287], [484512],1.0.3886
PUP.Optional.DriverSupport, C:\PROGRAMDATA\DRIVER SUPPORT, No Action By User, [2287], [484512],1.0.3886
 
File: 1
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\dd.lic, No Action By User, [2287], [484512],1.0.3886
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27.01.2018
Ran by Marty (administrator) on MARTY-PC (06-02-2018 20:11:51)
Running from C:\Users\Marty\Desktop
Loaded Profiles: Marty (Available Profiles: Marty)
Platform: Windows 10 Pro Version 1709 16299.214 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\avp.exe
(Camshare Inc.) C:\Program Files (x86)\Camfrog\Camfrog Video Chat\update\cf_update_service.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
(Visicom Media Inc.) C:\ProgramData\ManyCam\Service\ManyCamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\avpui.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
(Visicom Media Inc.) C:\Program Files (x86)\ManyCam\ManyCam.exe
(Samsung Electronics Co. Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
() C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CTxfispi.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11801.1001.4.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1712.3351.0_x64__8wekyb3d8bbwe\Calculator.exe
() C:\Program Files (x86)\ManyCam\QtWebEngineProcess.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_3.37.23004.0_x64__8wekyb3d8bbwe\MessagingApplication.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [123800 2016-11-18] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-12] (Logitech Inc.)
HKLM-x32\...\Run: [OGMgmmouseRun] => C:\Program Files (x86)\UtechSmart 16400DPI VENUS Gaming Mouse\ogmmon.exe [3386880 2014-05-19] ()
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE*
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-521291403-2743771419-2724471075-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3111712 2017-12-15] (Valve Corporation)
HKU\S-1-5-21-521291403-2743771419-2724471075-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10257872 2018-01-09] (Piriform Ltd)
HKU\S-1-5-21-521291403-2743771419-2724471075-1000\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\ManyCam.exe [12864528 2017-10-30] (Visicom Media Inc.)
HKU\S-1-5-21-521291403-2743771419-2724471075-1000\...\Run: [Xvid] => powershell.exe -nologo -WindowStyle hidden -Noninteractive -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files (x86)\Xvid\CheckUpdate.ps1"
HKU\S-1-5-21-521291403-2743771419-2724471075-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [799880 2017-10-30] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-521291403-2743771419-2724471075-1000\...\MountPoints2: {d0b2002c-0182-11e7-8190-806e6f6e6963} - "E:\.\Bin\ASSETUP.exe" 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{bb0595c3-9747-4377-8f5f-0db25c4f751b}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
BHO: Kaspersky Protection -> {0E2877D3-2641-4970-B794-A553E295428D} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\x64\IEExt\ie_plugin.dll [2017-08-03] (AO Kaspersky Lab)
BHO-x32: Kaspersky Protection -> {0E2877D3-2641-4970-B794-A553E295428D} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\IEExt\ie_plugin.dll [2017-08-03] (AO Kaspersky Lab)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\ssv.dll [2018-01-19] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-01-19] (Oracle Corporation)
Toolbar: HKLM - Kaspersky Protection Toolbar - {4853DF44-7D6B-48E9-9258-D800EEE54AF6} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\x64\IEExt\ie_plugin.dll [2017-08-03] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {4853DF44-7D6B-48E9-9258-D800EEE54AF6} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\IEExt\ie_plugin.dll [2017-08-03] (AO Kaspersky Lab)
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab
 
FireFox:
========
FF ProfilePath: C:\Users\Marty\AppData\Roaming\Mozilla\Firefox\Profiles\xc5qs7du.default [2018-02-05]
FF HKLM\...\Firefox\Extensions: [light_plugin_448EC0843447455C9DA355B3C2811D6A@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\FFExt\light_plugin_firefox\addon.xpi [2017-12-12]
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_448EC0843447455C9DA355B3C2811D6A@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin-x32: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-01-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-01-19] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default [2018-02-06]
CHR Extension: (Slides) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-03]
CHR Extension: (YouTube) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-03]
CHR Extension: (Adblock Plus) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-01-26]
CHR Extension: (Sheets) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2017-11-02]
CHR Extension: (Google Docs Offline) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-08-03]
CHR Extension: (GAuth Authenticator) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilgcnhelpchnceeipipijaljkblbcobl [2017-08-03]
CHR Extension: (Grammarly for Chrome) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-02-02]
CHR Extension: (Kaspersky Protection) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mchjnmdbdlkdbfliogedbnpnanfjnolk [2017-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-03]
CHR Extension: (Chrome Media Router) - C:\Users\Marty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-26]
CHR HKLM\...\Chrome\Extension: [mchjnmdbdlkdbfliogedbnpnanfjnolk] - hxxps://chrome.google.com/webstore/detail/mchjnmdbdlkdbfliogedbnpnanfjnolk
CHR HKLM-x32\...\Chrome\Extension: [mchjnmdbdlkdbfliogedbnpnanfjnolk] - hxxps://chrome.google.com/webstore/detail/mchjnmdbdlkdbfliogedbnpnanfjnolk
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AVP18.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\avp.exe [354672 2017-01-24] (AO Kaspersky Lab)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2018-01-23] ()
R2 camfrog_update_service; C:\Program Files (x86)\Camfrog\Camfrog Video Chat\update\cf_update_service.exe [1063968 2016-12-18] (Camshare Inc.)
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2017-08-03] (Creative Labs) [File not signed]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2017-08-03] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [File not signed]
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [382504 2017-12-02] (EasyAntiCheat Ltd)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [135488 2017-08-30] (SurfRight B.V.)
S3 klvssbridge64_18.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 18.0.0\x64\vssbridge64.exe [426416 2017-08-03] (AO Kaspersky Lab)
R2 ManyCam Service; C:\ProgramData\ManyCam\Service\ManyCamService.exe [544984 2016-03-31] (Visicom Media Inc.)
R3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)
R2 SamsungRapidSvc; C:\WINDOWS\System32\RAPID\SamsungRapidSvc.exe [29080 2016-11-18] (Samsung Electronics Co., Ltd.)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [198792 2017-10-30] (Sandboxie Holdings, LLC)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4329952 2017-11-26] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [247008 2016-12-26] (AO Kaspersky Lab)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R0 kl1; C:\WINDOWS\System32\DRIVERS\kl1.sys [554408 2016-10-01] (AO Kaspersky Lab)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [70880 2017-12-12] (AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [117984 2017-12-12] (AO Kaspersky Lab)
R2 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [78216 2016-05-31] (AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [29816 2016-10-14] (AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [207576 2017-10-13] (AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [594144 2017-10-13] (AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP18.0.0\Bases\klids.sys [190832 2018-01-28] (AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1055424 2017-12-14] (AO Kaspersky Lab)
R1 KLIM6; C:\WINDOWS\system32\DRIVERS\klim6.sys [57424 2016-10-12] (AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [57056 2016-12-23] (AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [58592 2016-12-07] (AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [50672 2017-06-22] (AO Kaspersky Lab)
R3 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [44768 2017-01-20] (AO Kaspersky Lab)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [230280 2018-01-31] (AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [87584 2017-08-03] (AO Kaspersky Lab)
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [253192 2017-11-23] (AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [107680 2017-11-23] (AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [173664 2017-11-25] (AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [93920 2016-12-20] (AO Kaspersky Lab)
R1 Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [135904 2017-12-12] (AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [199392 2017-12-12] (AO Kaspersky Lab)
R3 ManyCam; C:\WINDOWS\system32\DRIVERS\mcvidrv.sys [58792 2017-03-05] (Visicom Media Inc.)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [252232 2018-02-06] (Malwarebytes)
R3 mcaudrv_simple; C:\WINDOWS\system32\drivers\mcaudrv_x64.sys [35960 2014-12-28] (Visicom Media Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d37ca5c2cde53609\nvlddmkm.sys [17028552 2017-12-18] (NVIDIA Corporation)
U5 rzudd; C:\Windows\System32\Drivers\rzudd.sys [202952 2015-08-13] (Razer Inc)
R0 SamsungRapidDiskFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidDiskFltr.sys [272792 2016-11-18] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidFSFltr.sys [111512 2016-11-18] (Samsung Electronics Co., Ltd.)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [209544 2017-10-30] (Sandboxie Holdings, LLC)
S3 smbdirect; C:\WINDOWS\System32\DRIVERS\smbdirect.sys [151552 2017-11-25] (Microsoft Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2017-09-25] (The OpenVPN Project) [File not signed]
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [38368 2017-08-19] (Wellbia.com Co., Ltd.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-02-06 20:11 - 2018-02-06 20:12 - 000019609 _____ C:\Users\Marty\Desktop\FRST.txt
2018-02-06 20:11 - 2018-02-06 20:11 - 002393088 _____ (Farbar) C:\Users\Marty\Desktop\FRST64.exe
2018-02-06 20:07 - 2018-02-06 20:07 - 000001494 _____ C:\Users\Marty\Desktop\malwarebytes scan 2-6-2018.txt
2018-02-06 20:03 - 2018-02-06 20:03 - 000252232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-02-06 16:32 - 2018-02-06 16:32 - 000000000 ____D C:\Users\Marty\AppData\Local\D2AE23.tmpd
2018-02-06 16:32 - 2018-02-06 16:32 - 000000000 ____D C:\Users\Marty\AppData\Local\D28A7D.tmpd
2018-02-06 16:32 - 2018-02-06 16:32 - 000000000 _____ C:\Users\Marty\AppData\Local\D2AE23.tmp
2018-02-06 16:32 - 2018-02-06 16:32 - 000000000 _____ C:\Users\Marty\AppData\Local\D28A7D.tmp
2018-02-06 15:56 - 2018-02-06 15:56 - 000000000 ____D C:\Users\Marty\AppData\Local\D221CC.tmpd
2018-02-06 15:56 - 2018-02-06 15:56 - 000000000 _____ C:\Users\Marty\AppData\Local\D221CC.tmp
2018-02-06 07:08 - 2018-02-06 07:08 - 000000000 ____D C:\Users\Marty\AppData\Local\D2ABEE.tmpd
2018-02-06 07:08 - 2018-02-06 07:08 - 000000000 _____ C:\Users\Marty\AppData\Local\D2ABEE.tmp
2018-02-06 06:18 - 2018-02-06 06:18 - 000000000 ____D C:\Users\Marty\AppData\Local\D2C65C.tmpd
2018-02-06 06:18 - 2018-02-06 06:18 - 000000000 _____ C:\Users\Marty\AppData\Local\D2C65C.tmp
2018-02-06 06:17 - 2018-02-06 06:17 - 000000000 ____D C:\Users\Marty\AppData\Local\D2D97A.tmpd
2018-02-06 06:17 - 2018-02-06 06:17 - 000000000 _____ C:\Users\Marty\AppData\Local\D2D97A.tmp
2018-02-06 01:43 - 2018-02-06 01:43 - 000000000 ____D C:\Users\Marty\AppData\Local\D2811E.tmpd
2018-02-06 01:43 - 2018-02-06 01:43 - 000000000 _____ C:\Users\Marty\AppData\Local\D2811E.tmp
2018-02-05 18:56 - 2018-02-05 18:56 - 000000000 ____D C:\Users\Marty\AppData\Local\CrashRpt
2018-02-05 15:14 - 2018-02-05 15:14 - 000000000 ____D C:\Users\Marty\AppData\Local\D28A58.tmpd
2018-02-05 15:14 - 2018-02-05 15:14 - 000000000 _____ C:\Users\Marty\AppData\Local\D28A58.tmp
2018-02-05 14:15 - 2018-02-05 14:15 - 000000000 ____D C:\Users\Marty\AppData\Local\D2C7B5.tmpd
2018-02-05 14:15 - 2018-02-05 14:15 - 000000000 _____ C:\Users\Marty\AppData\Local\D2C7B5.tmp
2018-02-05 09:48 - 2018-02-05 09:48 - 000000000 ____D C:\Users\Marty\AppData\Local\D2BF6A.tmpd
2018-02-05 09:48 - 2018-02-05 09:48 - 000000000 _____ C:\Users\Marty\AppData\Local\D2BF6A.tmp
2018-02-05 09:27 - 2018-02-05 09:27 - 000000000 ____D C:\Users\Marty\AppData\Local\D29FE8.tmpd
2018-02-05 09:27 - 2018-02-05 09:27 - 000000000 _____ C:\Users\Marty\AppData\Local\D29FE8.tmp
2018-02-05 08:57 - 2018-01-17 14:19 - 001206688 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-02-05 08:57 - 2018-01-17 14:19 - 001055640 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-02-05 08:57 - 2018-01-17 14:19 - 000599456 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-02-05 08:57 - 2018-01-17 14:18 - 001193192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2018-02-05 08:57 - 2018-01-17 14:18 - 001092016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-02-05 08:57 - 2018-01-17 14:18 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-02-05 08:57 - 2018-01-17 14:18 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-02-05 08:57 - 2018-01-17 14:18 - 000319864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-02-05 08:57 - 2018-01-17 14:18 - 000279456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2018-02-05 08:57 - 2018-01-17 14:18 - 000077216 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-02-05 08:57 - 2018-01-17 14:15 - 008605080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-02-05 08:57 - 2018-01-17 14:15 - 002406456 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2018-02-05 08:57 - 2018-01-17 14:15 - 001954560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-02-05 08:57 - 2018-01-17 14:15 - 001415296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-02-05 08:57 - 2018-01-17 14:15 - 001209248 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-02-05 08:57 - 2018-01-17 14:15 - 001002600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-02-05 08:57 - 2018-01-17 14:12 - 004537040 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
2018-02-05 08:57 - 2018-01-17 14:12 - 001313024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2018-02-05 08:57 - 2018-01-17 14:12 - 001277848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2018-02-05 08:57 - 2018-01-17 14:12 - 000711432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-02-05 08:57 - 2018-01-17 14:11 - 001044384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-02-05 08:57 - 2018-01-17 14:10 - 003904296 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-02-05 08:57 - 2018-01-17 14:10 - 003010248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2018-02-05 08:57 - 2018-01-17 14:10 - 002574232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-02-05 08:57 - 2018-01-17 14:10 - 001416392 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2018-02-05 08:57 - 2018-01-17 14:10 - 000749984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-02-05 08:57 - 2018-01-17 14:10 - 000408992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-02-05 08:57 - 2018-01-17 14:09 - 007675792 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-02-05 08:57 - 2018-01-17 14:09 - 002709200 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-02-05 08:57 - 2018-01-17 14:09 - 000712096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-02-05 08:57 - 2018-01-17 14:09 - 000436632 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2018-02-05 08:57 - 2018-01-17 14:09 - 000246176 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-02-05 08:57 - 2018-01-17 14:09 - 000154528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2018-02-05 08:57 - 2018-01-17 14:09 - 000097176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2018-02-05 08:57 - 2018-01-17 14:08 - 021351632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-02-05 08:57 - 2018-01-17 14:08 - 004486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2018-02-05 08:57 - 2018-01-17 14:08 - 002447768 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2018-02-05 08:57 - 2018-01-17 14:08 - 000824896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2018-02-05 08:57 - 2018-01-17 14:08 - 000677792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-02-05 08:57 - 2018-01-17 14:08 - 000614168 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2018-02-05 08:57 - 2018-01-17 14:08 - 000519152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-02-05 08:57 - 2018-01-17 14:08 - 000494496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2018-02-05 08:57 - 2018-01-17 14:08 - 000374032 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
2018-02-05 08:57 - 2018-01-17 14:08 - 000189344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2018-02-05 08:57 - 2018-01-17 14:08 - 000100248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 007385080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 006791984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 004506584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 001430760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2018-02-05 08:57 - 2018-01-17 14:07 - 001426672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 001254152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 001170008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 000688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 000603928 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-02-05 08:57 - 2018-01-17 14:07 - 000404888 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 000096200 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbrand.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 000093600 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-02-05 08:57 - 2018-01-17 14:07 - 000075168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-02-05 08:57 - 2018-01-17 14:06 - 000413888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-02-05 08:57 - 2018-01-17 14:06 - 000339872 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2018-02-05 08:57 - 2018-01-17 14:06 - 000087392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2018-02-05 08:57 - 2018-01-17 14:04 - 001103776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-02-05 08:57 - 2018-01-17 14:04 - 000628632 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2018-02-05 08:57 - 2018-01-17 13:20 - 000022432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hvsicontainerservice.dll
2018-02-05 08:57 - 2018-01-17 13:19 - 001615712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-02-05 08:57 - 2018-01-17 13:19 - 000542856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2018-02-05 08:57 - 2018-01-17 13:16 - 002255120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2018-02-05 08:57 - 2018-01-17 13:15 - 001145624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-02-05 08:57 - 2018-01-17 13:13 - 004382040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
2018-02-05 08:57 - 2018-01-17 13:13 - 001250528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2018-02-05 08:57 - 2018-01-17 13:10 - 025250304 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-02-05 08:57 - 2018-01-17 13:10 - 006092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-02-05 08:57 - 2018-01-17 13:10 - 003485392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-02-05 08:57 - 2018-01-17 13:10 - 002338784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2018-02-05 08:57 - 2018-01-17 13:10 - 002192112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-02-05 08:57 - 2018-01-17 13:10 - 001123464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2018-02-05 08:57 - 2018-01-17 13:10 - 000354200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2018-02-05 08:57 - 2018-01-17 13:09 - 003980720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2018-02-05 08:57 - 2018-01-17 13:09 - 000527864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2018-02-05 08:57 - 2018-01-17 13:09 - 000123800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2018-02-05 08:57 - 2018-01-17 13:09 - 000089504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2018-02-05 08:57 - 2018-01-17 13:08 - 020286120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-02-05 08:57 - 2018-01-17 13:08 - 000543920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2018-02-05 08:57 - 2018-01-17 13:08 - 000083224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbrand.dll
2018-02-05 08:57 - 2018-01-17 13:07 - 006479560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-02-05 08:57 - 2018-01-17 13:07 - 006014688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2018-02-05 08:57 - 2018-01-17 13:07 - 004670728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-02-05 08:57 - 2018-01-17 13:07 - 001246432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-02-05 08:57 - 2018-01-17 13:07 - 000982536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-02-05 08:57 - 2018-01-17 13:07 - 000662216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2018-02-05 08:57 - 2018-01-17 13:06 - 001149280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2018-02-05 08:57 - 2018-01-17 13:06 - 000386432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2018-02-05 08:57 - 2018-01-17 13:06 - 000129192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-02-05 08:57 - 2018-01-17 13:06 - 000077552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudNotifications.exe
2018-02-05 08:57 - 2018-01-17 13:06 - 000074992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2018-02-05 08:57 - 2018-01-17 13:04 - 000505160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp_win.dll
2018-02-05 08:57 - 2018-01-17 12:52 - 017160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2018-02-05 08:57 - 2018-01-17 12:52 - 003668480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-02-05 08:57 - 2018-01-17 12:51 - 001664512 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2018-02-05 08:57 - 2018-01-17 12:51 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-02-05 08:57 - 2018-01-17 12:51 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2018-02-05 08:57 - 2018-01-17 12:51 - 000536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-02-05 08:57 - 2018-01-17 12:50 - 002890240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2018-02-05 08:57 - 2018-01-17 12:49 - 023657984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-02-05 08:57 - 2018-01-17 12:49 - 000201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2018-02-05 08:57 - 2018-01-17 12:49 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-02-05 08:57 - 2018-01-17 12:49 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2018-02-05 08:57 - 2018-01-17 12:48 - 013703680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2018-02-05 08:57 - 2018-01-17 12:48 - 007545344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2018-02-05 08:57 - 2018-01-17 12:48 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-02-05 08:57 - 2018-01-17 12:48 - 000199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2018-02-05 08:57 - 2018-01-17 12:48 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2018-02-05 08:57 - 2018-01-17 12:48 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCShellCommonProxyStub.dll
2018-02-05 08:57 - 2018-01-17 12:47 - 008020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-02-05 08:57 - 2018-01-17 12:47 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll
2018-02-05 08:57 - 2018-01-17 12:47 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsku.dll
2018-02-05 08:57 - 2018-01-17 12:47 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2018-02-05 08:57 - 2018-01-17 12:47 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2018-02-05 08:57 - 2018-01-17 12:46 - 018921984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-02-05 08:57 - 2018-01-17 12:46 - 001498112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-02-05 08:57 - 2018-01-17 12:46 - 000800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Magnify.exe
2018-02-05 08:57 - 2018-01-17 12:46 - 000579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Payments.dll
2018-02-05 08:57 - 2018-01-17 12:46 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_User.dll
2018-02-05 08:57 - 2018-01-17 12:46 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2018-02-05 08:57 - 2018-01-17 12:46 - 000388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2018-02-05 08:57 - 2018-01-17 12:46 - 000276992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2018-02-05 08:57 - 2018-01-17 12:46 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2018-02-05 08:57 - 2018-01-17 12:46 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2018-02-05 08:57 - 2018-01-17 12:46 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2018-02-05 08:57 - 2018-01-17 12:45 - 012831744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-02-05 08:57 - 2018-01-17 12:45 - 003756032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
2018-02-05 08:57 - 2018-01-17 12:45 - 001216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2018-02-05 08:57 - 2018-01-17 12:45 - 000859648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2018-02-05 08:57 - 2018-01-17 12:45 - 000580608 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2018-02-05 08:57 - 2018-01-17 12:45 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-02-05 08:57 - 2018-01-17 12:45 - 000566272 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2018-02-05 08:57 - 2018-01-17 12:45 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2018-02-05 08:57 - 2018-01-17 12:45 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreCommonProxyStub.dll
2018-02-05 08:57 - 2018-01-17 12:45 - 000311808 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2018-02-05 08:57 - 2018-01-17 12:45 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\twext.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 004113408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 003367936 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 002905600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-02-05 08:57 - 2018-01-17 12:44 - 002873344 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 001470976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 001425408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 001113600 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2018-02-05 08:57 - 2018-01-17 12:44 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000975872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000792064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContent.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rshx32.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2018-02-05 08:57 - 2018-01-17 12:44 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2018-02-05 08:57 - 2018-01-17 12:44 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2018-02-05 08:57 - 2018-01-17 12:43 - 006466560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 003169280 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 002976256 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 001495552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 001234432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SEMgrSvc.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 001002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000930816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000820224 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000815616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000680960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000377856 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2018-02-05 08:57 - 2018-01-17 12:43 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
2018-02-05 08:57 - 2018-01-17 12:43 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2018-02-05 08:57 - 2018-01-17 12:42 - 019338240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 006722560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2018-02-05 08:57 - 2018-01-17 12:42 - 005500928 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 004748288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 003578368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 003405824 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 002209280 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 001547776 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 001167360 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 000621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 000526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\timedate.cpl
2018-02-05 08:57 - 2018-01-17 12:42 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-02-05 08:57 - 2018-01-17 12:42 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 005833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 004815360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 002857984 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 002741248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 002490880 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 002086400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-02-05 08:57 - 2018-01-17 12:41 - 001669120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 001353728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 001231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 001166336 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2018-02-05 08:57 - 2018-01-17 12:41 - 000939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000885248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000863744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000648704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000509440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\system32\srchadmin.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000247296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsku.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2018-02-05 08:57 - 2018-01-17 12:41 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCShellCommonProxyStub.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 004772352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 002523648 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 002035712 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 001822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 001759744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 001597952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 001487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 000965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 000731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Magnify.exe
2018-02-05 08:57 - 2018-01-17 12:40 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 000397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 000308224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingMonitor.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll
2018-02-05 08:57 - 2018-01-17 12:40 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 006567936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 002677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 001739264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 000504832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 000405504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Payments.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2018-02-05 08:57 - 2018-01-17 12:39 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000943104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000940544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000918528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000886784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2018-02-05 08:57 - 2018-01-17 12:38 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2018-02-05 08:57 - 2018-01-17 12:38 - 000721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVXENCD.DLL
2018-02-05 08:57 - 2018-01-17 12:38 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\timedate.cpl
2018-02-05 08:57 - 2018-01-17 12:38 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVSENCD.DLL
2018-02-05 08:57 - 2018-01-17 12:38 - 000346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreCommonProxyStub.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twext.dll
2018-02-05 08:57 - 2018-01-17 12:38 - 000111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.ProxyStub.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 011925504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 003676672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 002983936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 001936384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
2018-02-05 08:57 - 2018-01-17 12:37 - 001661440 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 001557504 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2018-02-05 08:57 - 2018-01-17 12:37 - 000653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 000447488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcbase.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sysdm.cpl
2018-02-05 08:57 - 2018-01-17 12:37 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2018-02-05 08:57 - 2018-01-17 12:37 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2018-02-05 08:57 - 2018-01-17 12:36 - 002184192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2018-02-05 08:57 - 2018-01-17 12:36 - 001342464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2018-02-05 08:57 - 2018-01-17 12:36 - 000862208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2018-02-05 08:57 - 2018-01-17 12:36 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2018-02-05 08:57 - 2018-01-17 12:36 - 000482816 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2018-02-05 08:57 - 2018-01-17 12:36 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\L

Attached Files



#2 Android 8888

Android 8888

    SWI Malware Tracker

  • Trusted Advisor*
  • PipPipPipPipPip
  • 1,102 posts

Posted 07 February 2018 - 05:12 PM

Hello psychicguy and welcome back to SpywareInfo Forum.

I'm Android 8888 and I'll be helping you with your computer issues. Please ask questions if anything is unclear.

 

I see you using CCleaner. There's nothing wrong with CCleaner as long as you don't use the Registry cleaner function. The small gain you might get from a Registry cleaner is far outweighed by the system damage that they have the potential to cause. Please read the link Do I Need a Windows Registry Cleaner? for further information.

 

I noticed that you have Torrent installed. I would recommend that you uninstall Torrent, however that choice is up to you. If you choose to remove it, you can do so via Start > Control Panel > Programs and Features.
If you wish to keep it, please do not use it until your computer is cleaned.

 

Do you know this file and its content?
C:\Users\Marty\Desktop\run.bat

 

 

Next,

  • Re-run Malwarebytes;
  • When the scan completes if potential threats are detected, ensure to checkmark all the listed items, and click the Quarantine Selected button.
  • While still on the Scan tab, click the View Report button, and in the window that opens click the Export button, select Text file (*.txt), give it a name and save it to your Desktop.
  • The log can also be viewed by clicking the log to select it, then clicking the View Report button.
  • Please copy and paste the content of the log in your next reply.

 

Next,

  • Download AdwCleaner and move it to your computer Desktop;
  • Right-click on AdwCleaner.exe and select Run as Administrator;
  • Accept the EULA (I accept), then click on Scan button;
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button;
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, please do it;
  • After the restart, a log will open when logging in. Please copy and paste the content of that log in your next reply;

 

 

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system.

Press the Windows key + R on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and click the OK button.
Please copy the entire contents of the code box below. To do this highlight the contents of the box and right click on it and select Copy.
Paste this into the open Notepad.

Start::
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
AlternateDataStreams: C:\Users\Public\AppData:CSM [476]
VirusTotal: C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
CMD: ipconfig /flushDNS
EmptyTemp:
End::

Save the file as fixlist.txt in to the same location as FRST.
Right-click the FRST icon and select Run as administrator to run the tool.
Click the Fix button only once and wait.
When finished FRST will generate a log (Fixlog.txt) on the same folder where FRST is located. Please post its content to your next reply.

NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.


How is the computer running? Are you still having Internet connection issues?

Android 8888


Android 8888
 
Website: http://android8888.comlu.com
 
Tavira - Here's where I live!
 
Please read the Instructions for posting requested logs and the article "So how did I get infected in the first place?"
 
Our help is free, but if you wish to help keep these forums running please consider a donation; Please see This Topic for details.

#3 psychicguy

psychicguy

    Advanced Member

  • Helper Trainee
  • PipPipPip
  • 126 posts

Posted 07 February 2018 - 07:46 PM

The run.bat contains my settings for my bitcoin asic miner.
 
Malwarebytes log is below: 
 
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 2/7/18
Scan Time: 5:28 PM
Log File: 6c390a5e-0c6f-11e8-82e5-10c37b6f461d.json
Administrator: Yes
 
-Software Information-
Version: 3.2.2.2018
Components Version: 1.0.212
Update Package Version: 1.0.3893
License: Free
 
-System Information-
OS: Windows 10 (Build 16299.214)
CPU: x64
File System: NTFS
User: MARTY-PC\Marty
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 289693
Threats Detected: 3
Threats Quarantined: 3
Time Elapsed: 2 min, 33 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 2
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support, Delete-on-Reboot, [2288], [484512],1.0.3893
PUP.Optional.DriverSupport, C:\PROGRAMDATA\DRIVER SUPPORT, Delete-on-Reboot, [2288], [484512],1.0.3893
 
File: 1
PUP.Optional.DriverSupport, C:\ProgramData\Driver Support\Driver Support\dd.lic, Delete-on-Reboot, [2288], [484512],1.0.3893
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)
 
 
Below is my adwcleaner log after cleaning: 
 
# AdwCleaner 7.0.7.0 - Logfile created on Thu Feb 08 01:36:20 2018
# Updated on 2018/18/01 by Malwarebytes 
# Running on Windows 10 Pro (X64)
# Mode: clean
 
***** [ Services ] *****
 
No malicious services deleted.
 
***** [ Folders ] *****
 
No malicious folders deleted.
 
***** [ Files ] *****
 
Deleted: C:\END
Deleted: C:\Users\Marty\AppData\Roaming\Mozilla\Firefox\Profiles\xc5qs7du.default\invalidprefs.js
 
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks deleted.
 
***** [ Registry ] *****
 
No malicious registry entries deleted.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries deleted.
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries deleted.
 
*************************
 
::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0
 
 
 
*************************
 
C:/AdwCleaner/AdwCleaner[C0].txt - [1152 B] - [2017/6/20 19:48:9]
C:/AdwCleaner/AdwCleaner[S0].txt - [1270 B] - [2017/6/18 23:8:41]
C:/AdwCleaner/AdwCleaner[S1].txt - [1286 B] - [2017/6/20 19:47:47]
C:/AdwCleaner/AdwCleaner[S2].txt - [1261 B] - [2018/2/8 1:35:49]
 
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt ##########
 
Below is my  Fixit log: 
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 07.02.2018 01
Ran by Marty (07-02-2018 17:40:34) Run:2
Running from C:\Users\Marty\Desktop
Loaded Profiles: Marty (Available Profiles: Marty)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
AlternateDataStreams: C:\Users\Public\AppData:CSM [476]
VirusTotal: C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
CMD: ipconfig /flushDNS
EmptyTemp:
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" => removed successfully
C:\Users\Public\AppData => ":CSM" ADS removed successfully
VirusTotal: C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe => https://www.virustot...sis/1517898840/
 
========= ipconfig /flushDNS =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 7888896 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 165556371 B
Java, Flash, Steam htmlcache => 200166301 B
Windows/system/drivers => 1980797 B
Edge => 26112 B
Chrome => 31187337 B
Firefox => 2997323 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 2 B
LocalService => 4102 B
NetworkService => 0 B
Marty => 209170623 B
 
RecycleBin => 37394 B
EmptyTemp: => 590.3 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 17:40:53 ====
 
 
I will keep an eye out to see if my internet disconnects.


#4 Android 8888

Android 8888

    SWI Malware Tracker

  • Trusted Advisor*
  • PipPipPipPipPip
  • 1,102 posts

Posted 08 February 2018 - 03:53 AM

Hello, thank you for the information concerning the batch file and the logs.

 

I will keep an eye out to see if my internet disconnects.

Alright. Please keep me updated.

 

Thank you.

 

Android 8888


Android 8888
 
Website: http://android8888.comlu.com
 
Tavira - Here's where I live!
 
Please read the Instructions for posting requested logs and the article "So how did I get infected in the first place?"
 
Our help is free, but if you wish to help keep these forums running please consider a donation; Please see This Topic for details.

#5 psychicguy

psychicguy

    Advanced Member

  • Helper Trainee
  • PipPipPip
  • 126 posts

Posted 10 February 2018 - 11:01 PM

It seems that the problem is fixed.  Thank you.

 

If you don't mind me asking...What exactly did you do to fix it?



#6 Android 8888

Android 8888

    SWI Malware Tracker

  • Trusted Advisor*
  • PipPipPipPipPip
  • 1,102 posts

Posted 11 February 2018 - 09:45 AM

Hello. I'm glad the issue is solved. You're welcome! :good:

Well, the Internet connection issues can be due to several reasons that we can try to resolve by process of elimination. If your Internet Service Provider (ISP) and yourself stated the connection and the Router were working well, then the problem was most likely in your computer.

Sometimes ‘Domain Name Service (DNS) tables’ need to be flushed for updating DNS records and name servers of websites, otherwise the connection could fail. In this case, cleaning temporary data (History, cookies, cache, temp files) and flush the DNS tables was most likely the solution for this problem.
 

 

Now it's time to check for leftovers on you system by running an online scan with ESET. This is a very thorough scan and can take some time to complete but it's worth it.

 

Please scan your computer with ESET Online Scanner.

  • Click on this link to open ESET Online Scanner in a new window.
    • Click on the Scan Now button to download the esetonlinescanner_enu.exe file and save it to your computer Desktop.
    • Close all your programs and browsers and disconnect any USB flash drives from the computer.
    • Please disable your antivirus program to avoid potential conflicts, improve the performance and speed up the scan.
    • Right-click on esetonlinescanner_enu.exe and select Run as administrator.
    • Click Yes to accept the User Account Control security warning that may appear. It will open a window with the Terms of Use.
  • Click the Accept button.
  • Under Computer scan settings, check mark Enable detection of potentially unwanted applications.
  • Then click Advanced settings and check mark the following options:
    • Enable detection of potentially unsafe applications
    • Clean threats automatically
  • Click the Scan button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats.
  • Click Export, and save the file to your Desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.

Note: If nothing is found, it will not produce a log.

 
Please re-enable your antivirus program and post the ESET log (if it produced one) in your next reply.

Thank you.
 
Android 8888


Android 8888
 
Website: http://android8888.comlu.com
 
Tavira - Here's where I live!
 
Please read the Instructions for posting requested logs and the article "So how did I get infected in the first place?"
 
Our help is free, but if you wish to help keep these forums running please consider a donation; Please see This Topic for details.

#7 psychicguy

psychicguy

    Advanced Member

  • Helper Trainee
  • PipPipPip
  • 126 posts

Posted 11 February 2018 - 11:50 AM

C:\Users\Marty\AppData\Local\MultiMiner\Miners\BFGMiner\bfgminer-rpc.exe a variant of Win32/CoinMiner.AN potentially unwanted application cleaned by deleting
C:\Users\Marty\Documents\bitcoin mining\cgminer-4-3-5-zeus-windows.zip a variant of Win32/CoinMiner.BF potentially unwanted application deleted
C:\Users\Marty\Documents\bitcoin mining\sgminer-5.6.1-nicehash-51-windows-i386.zip a variant of Win32/CoinMiner.BY potentially unwanted application deleted
C:\Users\Marty\Documents\bitcoin mining\[Scrypt ONLY] cpuminer-2.3.2-GC3355-win32.zip a variant of Win32/CoinMiner.W potentially unwanted application deleted
C:\Users\Marty\Documents\bitcoin mining\cgminer-4-3-5-zeus-windows\cgminer-4-3-5-zeus-windows\cgminer.exe a variant of Win32/CoinMiner.BF potentially unwanted application cleaned by deleting
C:\Users\Marty\Documents\bitcoin mining\sgminer-5.6.1-nicehash-51-windows-i386\sgminer.exe a variant of Win32/CoinMiner.BY potentially unwanted application cleaned by deleting
C:\Users\Marty\Documents\bitcoin mining\[Scrypt ONLY] cpuminer-2.3.2-GC3355-win32\[Scrypt ONLY] cpuminer-2.3.2-GC3355-win32\minerd.exe a variant of Win32/CoinMiner.W potentially unwanted application cleaned by deleting
C:\Users\Marty\Documents\Diablo 2\ccsetup539.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application cleaned by deleting
C:\Users\Marty\Documents\UO Online\ccsetup538 (1).exe Win32/Bundled.Toolbar.Google.D potentially unsafe application cleaned by deleting
C:\Users\Marty\Documents\UO Online\Launcher_v21_RC4.zip a variant of MSIL/Packed.DotBundle.A suspicious application deleted


#8 Android 8888

Android 8888

    SWI Malware Tracker

  • Trusted Advisor*
  • PipPipPipPipPip
  • 1,102 posts

Posted 11 February 2018 - 12:33 PM

Excellent! Now your computer appears to be clean and malware free. :thumbup:
 
Now it's time to check for updates. Outdated programs contains security vulnerabilities that are exploited by malware in order to infect the computer without the user's knowledge. Usually this is one of the ways that more contributes to infect computers.


Please update Mozilla Firefox browser:
Update Firefox to the latest version

Open Malwarebytes and search for updates. The latest version is 3.3.1.2183 and you are running an older version (3.2.2.2018)
You can download the new version from this link

You can also run a program like Personal Software Inspector (PSI) or FileHippo Update Checker or UCheck to see what programs need to be updated.


If all updates went well, you can delete the tools used in the malware cleaning process by running DelFix.

Follow the instructions below to download and execute DelFix.

  • Download DelFix and move the executable to your Desktop;
  • Right-click on DelFix.exe and select Run as Administrator;
  • Check the following options :
    • Activate UAC (this option will activate the User Account Control feature).
    • Remove disinfection tools (this option will remove the tools used in the cleaning process).
    • Create registry backup (this option will create a backup from the Windows Registry).
    • Purge system restore (this option will remove all previous and possibly infected restore points, and will create a new and clean restore point of your system).
    • Reset system settings (this option will reset any system settings back to default that were changed either by us during cleansing or by malware infection).
  • Once the options mentioned above are checked, click on Run;
  • After DelFix is done running, a log will open. I do not need to see the log, just close and delete it.

 

Are there any questions or concerns?
 
Android 8888


Android 8888
 
Website: http://android8888.comlu.com
 
Tavira - Here's where I live!
 
Please read the Instructions for posting requested logs and the article "So how did I get infected in the first place?"
 
Our help is free, but if you wish to help keep these forums running please consider a donation; Please see This Topic for details.

#9 psychicguy

psychicguy

    Advanced Member

  • Helper Trainee
  • PipPipPip
  • 126 posts

Posted 11 February 2018 - 01:09 PM

You said my DNS had to be flushed.  I had removed all my temporary files using ccleaner with all browsers closed and typed in an admin CMD ipconfig /flushdns  and ipconfig /release and ipconfig /renew and it didn't fix my problem.  What was the difference that you did I am wondering.



#10 Android 8888

Android 8888

    SWI Malware Tracker

  • Trusted Advisor*
  • PipPipPipPipPip
  • 1,102 posts

Posted 11 February 2018 - 01:40 PM

 

I had removed all my temporary files using ccleaner with all browsers closed

There are differences in the criteria and cleaning routines for each tools (CCleaner and FRST). They don't use the same criteria and routines to clean the same data. And that could make the difference.

 

Also, did you restart the computer after running the commands you listed? That is very important and FRST did that after running the fix.


Android 8888
 
Website: http://android8888.comlu.com
 
Tavira - Here's where I live!
 
Please read the Instructions for posting requested logs and the article "So how did I get infected in the first place?"
 
Our help is free, but if you wish to help keep these forums running please consider a donation; Please see This Topic for details.

#11 psychicguy

psychicguy

    Advanced Member

  • Helper Trainee
  • PipPipPip
  • 126 posts

Posted 14 February 2018 - 03:01 AM

I am now experiencing the same problem.  Any suggestions would be appreciated it :)



#12 Android 8888

Android 8888

    SWI Malware Tracker

  • Trusted Advisor*
  • PipPipPipPipPip
  • 1,102 posts

Posted 14 February 2018 - 08:02 AM

Hello psychicguy.

Please read the instructions on the links below and do the following steps:

 

 

Clear the history, cache and cookies of all browsers.

Microsoft Edge
https://www.howtogee...microsoft-edge/

Internet Explorer
https://kb.wisc.edu/page.php?id=15141

Mozilla Firefox
https://kb.wisc.edu/...ge.php?id=17504

Google Chrome
https://support.goog...wer/32050?hl=en
 

 

Reset all browsers settings to default.

Microsoft Edge
How to Reset Microsoft Edge in Windows 10

Internet Explorer
https://support.micr...en-us/kb/923737

Mozilla Firefox
https://support.mozi...es-fix-problems

Google Chrome
https://support.goog...r/3296214?hl=en

 

 

Next,

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to the operating system.

Press the Windows key + R on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and click the OK button.
Please copy the entire contents of the code box below. To do this highlight the contents of the box and right click on it and select Copy.
Paste this into the open Notepad.
 

Start::
CreateRestorePoint:
CloseProcesses:
CMD: ipconfig /flushdns
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
CMD: bitsadmin /reset /allusers
Hosts:
EmptyTemp:
End::

Save the file as fixlist.txt in to the same folder as FRST.
Right-click the FRST icon and select Run as administrator to run the tool.
Click the Fix button only once and wait.
When finished FRST will generate a log (Fixlog.txt) on the same folder where FRST is located. Please post its content to your next reply.

NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.

 

 

Please post the content of Fixlog.txt, test all Internet browsers and let me know if the connection issue persists.


Android 8888


Android 8888
 
Website: http://android8888.comlu.com
 
Tavira - Here's where I live!
 
Please read the Instructions for posting requested logs and the article "So how did I get infected in the first place?"
 
Our help is free, but if you wish to help keep these forums running please consider a donation; Please see This Topic for details.

#13 psychicguy

psychicguy

    Advanced Member

  • Helper Trainee
  • PipPipPip
  • 126 posts

Posted 14 February 2018 - 10:17 PM

Before doing all of that I noticed when I called my ISP that there was an outage in the neighborhood. after about 20 mins it worked just fine.  It hasn't been turning off and on like before...this time it just disconnected once then the modem lights stopped being stable colors.

 

perhaps they've fixed the issue. I don't know.  I would like to wait and see if it is fixed or not.  I'll try it for a few days.



#14 Android 8888

Android 8888

    SWI Malware Tracker

  • Trusted Advisor*
  • PipPipPipPipPip
  • 1,102 posts

Posted 15 February 2018 - 05:58 AM

Thank you for the information.

 

I agree, it will be better to test it for a few days before running the fix.

 

I will wait for your feedback.

 

Android 8888


Android 8888
 
Website: http://android8888.comlu.com
 
Tavira - Here's where I live!
 
Please read the Instructions for posting requested logs and the article "So how did I get infected in the first place?"
 
Our help is free, but if you wish to help keep these forums running please consider a donation; Please see This Topic for details.




Member of ASAP and UNITE
Support SpywareInfo Forum - click the button