Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-11-2020
Ran by xyz (administrator) on DESKTOP-0H1FL2Q (Micro-Star International Co., Ltd. MS-7B18) (27-11-2020 08:51:08)
Running from E:\DL 2020
Loaded Profiles: xyz & JetBrainsYouTrack
Platform: Windows 10 Pro Version 2004 19041.630 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Amazon.com Inc.) [File not signed] E:\YouTrack\internal\java\windows-amd64\bin\java.exe
(Amazon.com Inc.) [File not signed] E:\YouTrack\internal\java\windows-amd64\bin\javaw.exe
(Amazon.com Services LLC -> Amazon.com Inc.) C:\Users\xyz\AppData\Local\Amazon Drive\AmazonPhotos.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\DiscoverySrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdagent.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdredline.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsserv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpnd\expressvpn-browser-helper.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPN.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationService.exe
(Express Vpn LLC -> The OpenVPN Project) C:\Program Files (x86)\ExpressVPN\expressvpnd\windows\openvpn.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <96>
(GP Software -> GP Software) C:\Program Files\GPSoftware\Directory Opus\dopus.exe
(GP Software -> GP Software) C:\Program Files\GPSoftware\Directory Opus\dopusrt.exe
(ICEpower a/s -> ICEpower) C:\Windows\System32\ICEsoundService64.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(JetBrains s.r.o. -> JetBrains GmbH) E:\YouTrack\launcher\bin\JetService.exe
(JRiver, Inc. -> JRiver, Inc.) C:\Program Files\J River\Media Center 26\JRService.exe
(JRiver, Inc. -> JRiver, Inc.) C:\Program Files\J River\Media Center 26\Media Center 26.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Mediafour Corporation -> Mediafour Corporation) C:\Program Files\Mediafour\MacDrive 10\MacDrive10Service.exe
(Mediafour Corporation -> Mediafour Corporation) C:\Program Files\Mediafour\MacDrive 10\MDHelper.exe
(Mediafour Corporation -> Mediafour) C:\Program Files\Mediafour\MacDrive 10\MacDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2009.4.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\vds.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <12>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\NVDisplay.Container.exe <2>
(Opera Software AS -> Opera Software) C:\Users\xyz\AppData\Local\Programs\Opera\assistant\browser_assistant.exe <2>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(ShareX Team) [File not signed] C:\Program Files\ShareX\ShareX.exe
(The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\scalc.exe
(The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.bin
(The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.exe
(voidtools -> voidtools) C:\Program Files\Everything\Everything.exe <2>
(Wiziple software -> 1Clipboard) C:\Users\xyz\AppData\Local\1Clipboard\app-0.1.8\1Clipboard.exe <4>
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9279432 2018-09-21] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2240288 2019-02-03] (voidtools -> voidtools)
HKLM\...\Run: [MacDrive 10 helper] => C:\Program Files\Mediafour\MacDrive 10\MDHelper.exe [299872 2017-09-28] (Mediafour Corporation -> Mediafour Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [331064 2020-07-24] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646776 2020-03-12] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [ExpressVPNNotificationService] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationServiceStarter.exe [465120 2020-08-20] (Express Vpn LLC -> ExpressVPN)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2048631613-2831981643-1474844327-1003\...\Run: [GoogleChromeAutoLaunch_99D1FF639E3638B290DAE6A24A50957B] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
HKU\S-1-5-21-2048631613-2831981643-1474844327-1003\...\Run: [1Clipboard] => C:\Users\xyz\AppData\Local\1Clipboard\app-0.1.8\1Clipboard.exe [51310576 2016-08-17] (Wiziple software -> 1Clipboard)
HKU\S-1-5-21-2048631613-2831981643-1474844327-1003\...\Run: [Directory Opus Desktop Dblclk] => C:\Program Files\GPSoftware\Directory Opus\dopusrt.exe [714944 2020-06-22] (GP Software -> GP Software)
HKU\S-1-5-21-2048631613-2831981643-1474844327-1003\...\Run: [Amazon Photos] => C:\Users\xyz\AppData\Local\Amazon Drive\AmazonPhotos.exe [10028720 2020-11-25] (Amazon.com Services LLC -> Amazon.com Inc.)
HKU\S-1-5-21-2048631613-2831981643-1474844327-1003\...\Run: [ExpressVPN4] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPN.exe [1161440 2020-08-20] (Express Vpn LLC -> ExpressVPN)
HKU\S-1-5-21-2048631613-2831981643-1474844327-1003\...\Run: [Opera Browser Assistant] => C:\Users\xyz\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3154456 2020-11-24] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2048631613-2831981643-1474844327-1004\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.198\Installer\chrmstp.exe [2020-11-16] (Google LLC -> Google LLC)
Startup: C:\Users\xyz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Directory Opus (Startup).lnk [2020-05-23]
ShortcutTarget: Directory Opus (Startup).lnk -> C:\Program Files\GPSoftware\Directory Opus\dopus.exe (GP Software -> GP Software)
Startup: C:\Users\xyz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShareX.lnk [2020-06-19]
ShortcutTarget: ShareX.lnk -> C:\Program Files\ShareX\ShareX.exe (ShareX Team) [File not signed]
BootExecute: autocheck autochk * bddel.exe
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0F7D3612-374C-4BC5-B24C-2E863F9333C4} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144744 2020-11-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {0F9D98F5-C277-472F-85EF-BE0C03E97017} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {2949E04B-A71B-4CCB-8E61-720C67C083A5} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939528 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {3CE88125-D5F1-422D-856F-C5AF03417DEE} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3F7ED1AD-D2AD-4E84-BF85-607E57AAB993} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939528 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {3FA1A6F5-ADA1-44BE-ABE8-44CD0EE251B6} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [895080 2020-10-28] (Bitdefender SRL -> Bitdefender)
Task: {4DF67F2C-C557-4244-8C67-99EC39235E40} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\IntelPTTEKRecertification.exe [918288 2020-04-22] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {545ACD33-9D1F-40E2-A3BA-E8E444E0FD22} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6955E9ED-B2E6-4C62-B331-9D3A229C4A46} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-12-05] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {6B9345A2-DDB3-4914-9D07-6A8220C49258} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [670928 2020-11-18] (Mozilla Corporation -> Mozilla Foundation)
Task: {941E3EDC-ADD9-467A-AE15-90290661E0AB} - System32\Tasks\G2MUpdateTask-S-1-5-21-2048631613-2831981643-1474844327-1003 => C:\Users\xyz\AppData\Local\GoToMeeting\18962\g2mupdate.exe [31320 2020-10-22] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {972821C9-8DA9-4BEC-9FE5-9863D720D3E5} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [914456 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9E04343B-B177-43D7-8A80-68E8EA6291C5} - System32\Tasks\BraveSoftwareUpdateTaskUserS-1-5-21-2048631613-2831981643-1474844327-1003Core => C:\Users\xyz\AppData\Local\BraveSoftware\Update\BraveUpdate.exe [157320 2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {AA34A7EA-B9B4-4961-ACD0-87B28DD98F22} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [914456 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AC5CE38E-BDD5-4449-BCF6-CA4987ED3145} - System32\Tasks\Opera scheduled assistant Autoupdate 1583002139 => C:\Users\xyz\AppData\Local\Programs\Opera\launcher.exe [1721368 2020-11-09] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\xyz\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {B849ED77-6EBC-41C9-BA6C-AEA77FE1805B} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [653848 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {BB6DA6BF-FA65-4BD0-A2C6-EDA057F04C62} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-12-05] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {C4ED33F8-257D-43E2-A53C-DD331E64E3F9} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C6A3D794-218F-4173-830B-99A032BD6DEA} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3302880 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D0C4DEA1-2157-41A6-937F-481FCAF6CFD4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-02-06] (Google LLC -> Google LLC)
Task: {D140CD2D-5DB1-4656-8B82-D66B8A10CE9E} - System32\Tasks\BraveSoftwareUpdateTaskUserS-1-5-21-2048631613-2831981643-1474844327-1003UA => C:\Users\xyz\AppData\Local\BraveSoftware\Update\BraveUpdate.exe [157320 2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {E3FD55AF-480F-4E0C-B132-3DA4B13CCBEE} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E7F7B079-D1ED-4DD4-9212-0CB808714A31} - System32\Tasks\G2MUploadTask-S-1-5-21-2048631613-2831981643-1474844327-1003 => C:\Users\xyz\AppData\Local\GoToMeeting\18962\g2mupload.exe [31320 2020-10-22] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {F0438804-3AD3-4C78-9369-A508ACEC4EAA} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144744 2020-11-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {F90DF26B-E601-4BE4-A8FB-D4D0844678C3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-02-06] (Google LLC -> Google LLC)
Task: {FE8F51F6-5460-49A7-8BEC-5F63144891FE} - System32\Tasks\Opera scheduled Autoupdate 1581188361 => c:\users\xyz\appdata\local\programs\opera\launcher.exe [1721368 2020-11-09] (Opera Software AS -> Opera Software)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2048631613-2831981643-1474844327-1003.job => C:\Users\xyz\AppData\Local\GoToMeeting\18962\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2048631613-2831981643-1474844327-1003.job => C:\Users\xyz\AppData\Local\GoToMeeting\18962\g2mupload.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{1ebc415e-fce3-42f6-a54a-68b8ec60b35b}: [DhcpNameServer] 10.0.1.1 10.0.1.3
Tcpip\..\Interfaces\{6926abb0-6bfd-4e6d-9d7c-bf81eaf5897e}: [DhcpNameServer] 10.157.0.1
Tcpip\..\Interfaces\{84bd8d22-5c22-4c0d-b155-506b7440e219}: [DhcpNameServer] 192.168.0.1
Edge:
======
Edge Extension: (uBlock Origin) -> EdgeExtension_37833NikRollsuBlockOrigin_f8jsg5mm64m62 => C:\Program Files\WindowsApps\37833NikRolls.uBlockOrigin_1.15.24.0_neutral__f8jsg5mm64m62 [2020-02-06]
Edge DefaultProfile: Default
Edge Profile: C:\Users\xyz\AppData\Local\Microsoft\Edge\User Data\Default [2020-11-25]
Edge Notifications: Default -> hxxps://twitter.com
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF DefaultProfile: 9xl9sqvh.default
FF DefaultProfile: y4ty9tmy.default
FF ProfilePath: C:\Users\xyz\AppData\Roaming\Mozilla\SeaMonkey\Profiles\9xl9sqvh.default [2020-11-02]
FF Extension: (DOM Inspector) - C:\Users\xyz\AppData\Roaming\Mozilla\SeaMonkey\Profiles\9xl9sqvh.default\Extensions\
inspector@mozilla.org.xpi [2020-02-06] [Legacy] [not signed]
FF Extension: (ChatZilla) - C:\Users\xyz\AppData\Roaming\Mozilla\SeaMonkey\Profiles\9xl9sqvh.default\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}.xpi [2020-02-06] [Legacy] [not signed]
FF Extension: (Lightning) - C:\Users\xyz\AppData\Roaming\Mozilla\SeaMonkey\Profiles\9xl9sqvh.default\Extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103} [2020-02-06] [Legacy] [not signed]
FF ProfilePath: C:\Users\xyz\AppData\Roaming\Mozilla\Firefox\Profiles\y4ty9tmy.default [2020-09-19]
FF Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\xyz\AppData\Roaming\Mozilla\Firefox\Profiles\y4ty9tmy.default\Extensions\
sp@avast.com.xpi [2020-02-06]
FF Extension: (Avast Online Security) - C:\Users\xyz\AppData\Roaming\Mozilla\Firefox\Profiles\y4ty9tmy.default\Extensions\
wrc@avast.com.xpi [2020-02-06]
FF ProfilePath: C:\Users\xyz\AppData\Roaming\Mozilla\Firefox\Profiles\7lqtzs3i.default-release-1605384285072 [2020-11-27]
FF Extension: (Facebook Container) - C:\Users\xyz\AppData\Roaming\Mozilla\Firefox\Profiles\7lqtzs3i.default-release-1605384285072\Extensions\@contain-facebook.xpi [2020-11-20]
FF Extension: (LastPass: Free Password Manager) - C:\Users\xyz\AppData\Roaming\Mozilla\Firefox\Profiles\7lqtzs3i.default-release-1605384285072\Extensions\
support@lastpass.com.xpi [2020-11-18]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\xyz\AppData\Roaming\Mozilla\Firefox\Profiles\7lqtzs3i.default-release-1605384285072\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2020-11-25]
FF Extension: (Save to Notion) - C:\Users\xyz\AppData\Roaming\Mozilla\Firefox\Profiles\7lqtzs3i.default-release-1605384285072\Extensions\{4b547b2c-e114-4344-9b70-09b2fe0785f3}.xpi [2020-11-18]
FF Extension: (Old Layout for Facebook) - C:\Users\xyz\AppData\Roaming\Mozilla\Firefox\Profiles\7lqtzs3i.default-release-1605384285072\Extensions\{8792af17-0df8-40ab-81d3-6cc777171564}.xpi [2020-11-25]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-16] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll [2020-04-22] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\plugin2\npjp2.dll [2020-04-22] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-09-16] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-11-18] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2048631613-2831981643-1474844327-1003: @tools.brave.com/BraveSoftware Update;version=3 -> C:\Users\xyz\AppData\Local\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin HKU\S-1-5-21-2048631613-2831981643-1474844327-1003: @tools.brave.com/BraveSoftware Update;version=9 -> C:\Users\xyz\AppData\Local\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2020-02-08] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin HKU\S-1-5-21-2048631613-2831981643-1474844327-1003: @zoom.us/ZoomVideoPlugin -> C:\Users\xyz\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-14] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\bd_js_config.js [2020-09-20] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\bd_config.cfg [2020-09-20] <==== ATTENTION
Chrome:
=======
CHR Profile: C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default [2020-11-27]
CHR DownloadDir: E:\DL 2020
CHR Notifications: Default -> hxxps://app.slack.com; hxxps://calendar.google.com; hxxps://drive.google.com; hxxps://neilpatel.com; hxxps://twitter.com; hxxps://voice.google.com; hxxps://www.instagram.com
CHR Extension: (Google Translate) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2020-03-18]
CHR Extension: (Slides) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-02-06]
CHR Extension: (Simple mass downloader) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\abdkkegmcbiomijcbdaodaflgehfffed [2020-07-12]
CHR Extension: (lock) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeblfdkhhhdcdjpifhhbdiojplfjncoa [2020-11-17]
CHR Extension: (Flash Video Downloader) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiimdkdngfcipjohbjenkahhlhccpdbc [2020-05-02]
CHR Extension: (Adblocker for Chrome - NoAds) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\alplpnakfeabeiebipdmaenpmbgknjce [2020-02-29]
CHR Extension: (Docs) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-02-06]
CHR Extension: (1Password extension (desktop app required)) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aomjjhallfgjeglblehebfpbcfeobpgk [2020-02-08]
CHR Extension: (Google Drive) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24]
CHR Extension: (Image Downloader for IW) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcieicfnbnmlffkgbiemoofinidpgloa [2020-07-08]
CHR Extension: (Turn Off the Lights) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2020-07-23]
CHR Extension: (DuckDuckGo) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2020-10-24]
CHR Extension: (Double-click Image Downloader) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkijmpolkanhdehnlnabfooghjdokakc [2020-05-26]
CHR Extension: (YouTube) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-02-06]
CHR Extension: (Vimeo™ Video Downloader) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgpbghdbejagejmciefmekcklikpoeel [2020-11-21]
CHR Extension: (uBlock Origin) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2020-10-20]
CHR Extension: (Superhuman) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcgcnpooblobhncpnddnhoendgbnglpn [2020-06-13]
CHR Extension: (Session Buddy) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\edacconmaakjimmfgnblocblbcdcpbko [2020-05-13]
CHR Extension: (Proper Menubar for Google Chrome) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\egclcjdpndeoioimlbbbmdhcaopnedkp [2020-03-12]
CHR Extension: (GoFullPage - Full Page Screen Capture) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2020-09-14]
CHR Extension: (Sheets) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-02-06]
CHR Extension: (ExpressVPN: VPN proxy to unblock everything) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgddmllnllkalaagkghckoinaemmogpe [2020-11-17]
CHR Extension: (Google Docs Offline) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-11]
CHR Extension: (Avast Online Security) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2020-06-04]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2020-11-25]
CHR Extension: (feedly) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipbfijinpcgfogaopmgehiegacbhmob [2020-02-08]
CHR Extension: (Ledger Wallet Ethereum) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmlhkialjkaldndjnlcdfdphcgeadkkm [2020-02-08]
CHR Extension: (VIEW LATER - save links in a stack) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnolaplfoobcmgfmjphkmbjolinelpkb [2020-02-08]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2020-11-25]
CHR Extension: (Stream Video Downloader) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\imkngaibigegepnlckfcbecjoilcjbhf [2020-02-08]
CHR Extension: (TREZOR Chrome Extension) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcjjhjgimijdkoamemaghajlhegmoclj [2020-02-08]
CHR Extension: (Chrome Audio Capture) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfokdmfpdnokpmpbjhjbcabgligoelgp [2020-02-08]
CHR Extension: (Ledger Wallet Bitcoin) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkdpmhnladdopljabkgpacgpliggeeaf [2020-07-29]
CHR Extension: (Notion Web Clipper) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\knheggckgoiihginacbkhaalnibhilkk [2020-10-06]
CHR Extension: (Linkclump) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfpjkncokllnfokkgpkobnkbkmelfefj [2020-07-29]
CHR Extension: (TabCopy) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\micdllihgoppmejpecmkilggmaagfdmb [2020-08-26]
CHR Extension: (RSS Subscription Extension (by Google)) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd [2020-07-23]
CHR Extension: (MEW CX) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbmnnijcnlegkjjpcfjclmcfggfefdm [2020-11-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-02-06]
CHR Extension: (ColorPick Eyedropper) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohcpnigalekghcmgcdcenkpelffpdolg [2020-10-04]
CHR Extension: (Downloader for Instagram) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkpikmlhoaojbbmmpejnimiglejmboe [2020-11-25]
CHR Extension: (Send from Gmail (by Google)) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc [2020-02-08]
CHR Extension: (Gmail) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-24]
CHR Extension: (Chrome Media Router) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-20]
CHR Extension: (Privacy Badger) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkehgijcmpdhfbdbbnkijodmdjhbjlgp [2020-10-11]
CHR Extension: (RSS Feed Reader) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp [2020-09-03]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
Opera:
=======
OPR Extension: (Privacy Badger) - C:\Users\xyz\AppData\Roaming\Opera Software\Opera Stable\Extensions\ldfkcgjipgfchpnojicdgpgiocoeelik [2020-04-29]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [170056 2020-11-03] (Adobe Inc. -> Adobe Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2020-05-20] (Apple Inc. -> Apple Inc.)
R2 bdredline; C:\Program Files\Bitdefender Antivirus Free\bdredline.exe [2500144 2019-03-27] (Bitdefender SRL -> Bitdefender)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9057136 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
R2 Everything; C:\Program Files\Everything\Everything.exe [2240288 2019-02-03] (voidtools -> voidtools)
R2 ExpressVPNService; C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe [437472 2020-08-20] (Express Vpn LLC -> ExpressVPN)
R2 MacDrive10Service; C:\Program Files\Mediafour\MacDrive 10\MacDrive10Service.exe [223088 2018-03-21] (Mediafour Corporation -> Mediafour Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7269976 2020-11-25] (Malwarebytes Inc -> Malwarebytes)
R3 Media Center 26 Service; C:\Program Files\J River\Media Center 26\JRService.exe [435088 2020-09-04] (JRiver, Inc. -> JRiver, Inc.)
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1355768 2020-10-28] (Bitdefender SRL -> Bitdefender)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5101992 2020-11-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 updatesrv; C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe [242024 2020-03-17] (Bitdefender SRL -> Bitdefender)
R2 vsserv; C:\Program Files\Bitdefender Antivirus Free\vsserv.exe [582304 2020-10-02] (Bitdefender SRL -> Bitdefender)
R2 vsservppl; C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe [242024 2020-03-17] (Bitdefender SRL -> Bitdefender)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 YouTrack; E:\YouTrack\launcher\bin\JetService.exe [392808 2020-06-23] (JetBrains s.r.o. -> JetBrains GmbH)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R1 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [2151624 2020-10-02] (Bitdefender SRL -> Bitdefender S.R.L. Bucharest, ROMANIA)
R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [796200 2020-05-26] (Bitdefender SRL -> Bitdefender)
S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [22960 2019-03-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Bitdefender)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
R1 CBDisk; C:\Windows\system32\drivers\CBDisk.sys [70344 2015-06-09] (EldoS Corporation -> EldoS Corporation)
S3 edrsensor; C:\WINDOWS\System32\DRIVERS\edrsensor.sys [309120 2020-02-03] (Bitdefender SRL -> BitDefender S.R.L. Bucharest, ROMANIA)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-11-25] (Malwarebytes Corporation -> Malwarebytes)
S3 EvoMouseDriverFilterHidUsb; C:\WINDOWS\System32\drivers\EvoMouseDriverFilterHidUsb.sys [29936 2016-01-29] (WDKTestCert v.kurilovich,130838452094803308 -> Evoluent)
S3 expressvpnsplittunnel; C:\Program Files (x86)\ExpressVPN\splittunnel\expressvpnsplittunnel.sys [37024 2020-08-20] (ExprsVPN LLC -> ExpressVPN)
R1 Gemma; C:\WINDOWS\System32\DRIVERS\gemma.sys [473608 2020-10-02] (Bitdefender SRL -> BitDefender S.R.L. Bucharest, ROMANIA)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220160 2020-11-25] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-11-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [197792 2020-11-25] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [77496 2020-11-25] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-11-25] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [138904 2020-11-25] (Malwarebytes Inc -> Malwarebytes)
R0 MDAPFS; C:\Windows\System32\Drivers\MDAPFS.sys [458800 2017-12-04] (Mediafour Corporation -> Other World Computing)
R0 MDAPFSCT; C:\Windows\System32\Drivers\MDAPFSCT.sys [47944 2017-12-04] (Mediafour Corporation -> Other World Computing)
R0 MDDISK; C:\Windows\System32\Drivers\MDDISK.sys [37808 2017-12-04] (Mediafour Corporation -> Other World Computing)
R0 MDFSYSNT; C:\Windows\System32\Drivers\MDFSYSNT.sys [321856 2017-12-04] (Mediafour Corporation -> Other World Computing)
R0 MDMOUNT; C:\Windows\System32\Drivers\MDMOUNT.sys [29064 2017-12-04] (Mediafour Corporation -> Other World Computing)
R3 tapexpressvpn; C:\WINDOWS\System32\drivers\tapexpressvpn.sys [44304 2019-12-06] (ExprsVPN LLC -> The OpenVPN Project)
R2 trufos; C:\WINDOWS\System32\drivers\trufos.sys [640760 2020-10-02] (Bitdefender SRL -> Bitdefender)
R0 vlflt; C:\WINDOWS\System32\DRIVERS\vlflt.sys [385776 2020-10-02] (Bitdefender SRL -> Bitdefender)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-27 08:50 - 2020-11-27 08:51 - 000000000 ____D C:\FRST
2020-11-26 16:34 - 2020-11-26 16:34 - 000000000 ____D C:\Users\xyz\AppData\Local\Amazon Drive
2020-11-26 08:19 - 2020-11-26 08:19 - 000000000 ___DC C:\Users\xyz\Documents\BCU Backup 2020-11-26_08-19-58
2020-11-25 20:17 - 2020-11-25 20:20 - 106442969 _____ C:\Users\xyz\Downloads\2020-12-01_France.pdf
2020-11-25 19:44 - 2020-11-26 08:30 - 000000000 ____D C:\Program Files\BCUninstaller
2020-11-25 19:44 - 2020-11-25 19:44 - 000000913 _____ C:\Users\Public\Desktop\BCUninstaller.lnk
2020-11-25 19:44 - 2020-11-25 19:44 - 000000913 _____ C:\ProgramData\Desktop\BCUninstaller.lnk
2020-11-25 19:44 - 2020-11-25 19:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BCUninstaller
2020-11-25 19:39 - 2020-11-25 19:39 - 000044008 _____ C:\WINDOWS\system32\bddel.exe
2020-11-25 19:39 - 2020-11-25 19:39 - 000000594 _____ C:\WINDOWS\system32\bddel.dat
2020-11-25 18:33 - 2020-11-25 18:33 - 000197792 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-11-25 18:33 - 2020-11-25 18:33 - 000138904 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-11-25 18:33 - 2020-11-25 18:33 - 000077496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2020-11-25 13:27 - 2020-11-25 13:27 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-11-25 13:27 - 2020-11-25 13:27 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-11-25 13:27 - 2020-11-25 13:27 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-11-25 13:26 - 2020-11-25 13:26 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-11-25 13:26 - 2020-11-25 13:26 - 000220160 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-11-25 13:26 - 2020-11-25 13:26 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-11-25 13:26 - 2020-11-25 13:26 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-11-25 13:26 - 2020-11-25 13:26 - 000000000 ____D C:\Program Files\Malwarebytes
2020-11-24 23:40 - 2020-11-24 23:40 - 000000039 _____ C:\Users\xyz\AppData\Local\kritadisplayrc
2020-11-21 19:02 - 2020-11-21 19:26 - 921549587 _____ C:\Users\xyz\Downloads\Ricoh_BounceFM Interview.mov
2020-11-21 17:19 - 2020-11-21 17:19 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-11-19 18:54 - 2020-11-19 19:00 - 1426386834 _____ C:\Users\xyz\Downloads\Candido - Anthology (2-CD) (2005) (WAV).zip
2020-11-19 18:52 - 2020-11-19 19:07 - 2843426079 _____ C:\Users\xyz\Downloads\David Mancuso - 2005 Shibuya FM (Japan) (5-CD) (WAV)(2).zip
2020-11-19 18:48 - 2020-11-19 18:50 - 374046944 _____ C:\Users\xyz\Downloads\Candido - Thousand Finger Man (1970) (WAV)(1).zip
2020-11-19 18:47 - 2020-11-19 18:50 - 630946015 _____ C:\Users\xyz\Downloads\Eddie Hazel - Game, Dames & Guitar Thangs (Expanded) (1977) (WAV) (CD Rip).zip
2020-11-19 18:46 - 2020-11-19 18:47 - 332793414 _____ C:\Users\xyz\Downloads\Candido Camero - Candido (1956) (WAV).zip
2020-11-19 18:46 - 2020-11-19 18:47 - 076796638 _____ C:\Users\xyz\Downloads\Whitney Houston - Love Will Save the Day (Jellybean & Morales 12'' Remix) (WAV)(1).zip
2020-11-19 18:44 - 2020-11-19 18:45 - 118967302 _____ C:\Users\xyz\Downloads\Herbie Hancock - Stars In Your Eyes (Special Disco Remix) (1980) (WAV)(1).wav
2020-11-18 22:35 - 2020-11-18 22:35 - 076796638 _____ C:\Users\xyz\Downloads\Whitney Houston - Love Will Save the Day (Jellybean & Morales 12'' Remix) (WAV).zip
2020-11-18 22:32 - 2020-11-18 22:33 - 118967302 _____ C:\Users\xyz\Downloads\Herbie Hancock - Stars In Your Eyes (Special Disco Remix) (1980) (WAV).wav
2020-11-18 20:02 - 2020-11-18 20:08 - 1720214697 _____ C:\Users\xyz\Downloads\Frenzy in The Club for Face The Bass 11-17-2020.mp4
2020-11-18 19:51 - 2020-11-18 19:51 - 005063883 _____ C:\Users\xyz\Downloads\fe1302_b3b74b626a544a26a0bd6f209a909683.pdf
2020-11-18 18:53 - 2020-11-18 19:02 - 2843426079 _____ C:\Users\xyz\Downloads\David Mancuso - 2005 Shibuya FM (Japan) (5-CD) (WAV)(1).zip
2020-11-18 18:46 - 2020-11-25 18:32 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-11-18 12:57 - 2020-11-18 12:58 - 374046944 _____ C:\Users\xyz\Downloads\Candido - Thousand Finger Man (1970) (WAV).zip
2020-11-18 10:41 - 2020-11-18 10:47 - 2843426079 _____ C:\Users\xyz\Downloads\David Mancuso - 2005 Shibuya FM (Japan) (5-CD) (WAV).zip
2020-11-16 09:28 - 2020-11-25 19:19 - 000000000 ____D C:\Users\xyz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2020-11-14 12:04 - 2020-11-14 12:04 - 000000000 ____D C:\Users\xyz\Desktop\Old Firefox Data
2020-11-11 00:14 - 2020-11-11 00:14 - 000086620 _____ C:\ProgramData\agent.update.1605082466.bdinstall.v2.bin
2020-11-10 22:26 - 2020-11-10 22:26 - 000363520 _____ C:\WINDOWS\system32\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-11-10 22:26 - 2020-11-10 22:26 - 000266240 _____ C:\WINDOWS\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-11-10 22:26 - 2020-11-10 22:26 - 000152576 _____ C:\WINDOWS\system32\EoAExperiences.exe
2020-11-10 22:26 - 2020-11-10 22:26 - 000009265 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2020-11-10 22:25 - 2020-11-10 22:25 - 000197632 _____ C:\WINDOWS\system32\IHDS.dll
2020-11-09 00:09 - 2020-11-09 00:09 - 000000078 _____ C:\Users\xyz\AppData\Roaming\VCFX.dat
2020-11-09 00:05 - 2020-11-09 00:05 - 000001128 _____ C:\Users\Public\Desktop\VCartoonizer.lnk
2020-11-09 00:05 - 2020-11-09 00:05 - 000001128 _____ C:\ProgramData\Desktop\VCartoonizer.lnk
2020-11-09 00:05 - 2020-11-09 00:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VCartoonizer
2020-11-09 00:05 - 2020-11-09 00:05 - 000000000 ____D C:\Program Files (x86)\VCartoonizer
2020-11-08 23:59 - 2020-11-09 00:10 - 000000078 _____ C:\Users\xyz\AppData\Roaming\IP.dat
2020-11-08 23:59 - 2020-11-08 23:59 - 000001075 _____ C:\Users\Public\Desktop\iToon.lnk
2020-11-08 23:59 - 2020-11-08 23:59 - 000001075 _____ C:\ProgramData\Desktop\iToon.lnk
2020-11-08 23:59 - 2020-11-08 23:59 - 000000000 ____D C:\Users\xyz\AppData\Roaming\iToon
2020-11-08 23:59 - 2020-11-08 23:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iToon
2020-11-08 23:59 - 2020-11-08 23:59 - 000000000 ____D C:\Program Files (x86)\iToon
2020-11-08 23:51 - 2020-11-08 23:51 - 000000000 ____D C:\Users\xyz\AppData\Roaming\gmic
2020-11-08 23:51 - 2020-11-08 23:51 - 000000000 ____D C:\Users\xyz\AppData\Local\ImageMagick
2020-11-08 23:50 - 2020-11-08 23:50 - 000000000 ____D C:\Users\xyz\AppData\Roaming\PrimaCartoonizer
2020-11-08 23:49 - 2020-11-09 00:16 - 000000078 _____ C:\Users\xyz\AppData\Roaming\PC.dat
2020-11-08 23:49 - 2020-11-08 23:49 - 000001183 _____ C:\Users\Public\Desktop\Prima Cartoonizer.lnk
2020-11-08 23:49 - 2020-11-08 23:49 - 000001183 _____ C:\ProgramData\Desktop\Prima Cartoonizer.lnk
2020-11-08 23:49 - 2020-11-08 23:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prima Cartoonizer
2020-11-08 23:49 - 2020-11-08 23:49 - 000000000 ____D C:\Program Files (x86)\Prima Cartoonizer
2020-11-06 14:25 - 2020-11-06 14:26 - 028577997 _____ C:\Users\xyz\Downloads\2020-11-01_FHM_Australia.pdf
2020-11-05 19:37 - 2020-11-05 19:38 - 204230656 _____ C:\Users\xyz\Downloads\PM6SetupR5260.msi
2020-11-04 13:08 - 2020-11-04 13:08 - 000001263 _____ C:\Users\xyz\AppData\Local\recently-used.xbel
2020-11-01 13:26 - 2020-11-24 23:40 - 000021459 _____ C:\Users\xyz\AppData\Local\kritarc
2020-11-01 13:26 - 2020-11-01 13:26 - 000000000 ____D C:\Users\xyz\AppData\Roaming\krita
2020-11-01 13:26 - 2020-11-01 13:26 - 000000000 ____D C:\Users\xyz\AppData\Local\krita
2020-11-01 13:25 - 2020-11-01 13:25 - 000001823 _____ C:\Users\Public\Desktop\Krita.lnk
2020-11-01 13:25 - 2020-11-01 13:25 - 000001823 _____ C:\ProgramData\Desktop\Krita.lnk
2020-11-01 13:25 - 2020-11-01 13:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Krita
2020-11-01 13:25 - 2020-11-01 13:25 - 000000000 ____D C:\Program Files\Krita (x64)
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-27 08:52 - 2020-09-19 14:12 - 000000000 ____D C:\Program Files\Bitdefender Antivirus Free
2020-11-27 08:48 - 2020-10-04 06:52 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-11-27 08:48 - 2019-12-07 01:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-27 02:37 - 2019-12-07 01:03 - 000008192 _____ C:\WINDOWS\system32\config\ELAM
2020-11-27 00:11 - 2020-04-08 09:34 - 000000000 ____D C:\Users\xyz\AppData\Roaming\1Clipboard
2020-11-27 00:03 - 2020-02-08 11:54 - 000000000 ____D C:\Users\xyz\AppData\Roaming\vlc
2020-11-26 16:35 - 2020-10-12 20:41 - 000001233 _____ C:\Users\xyz\Desktop\Amazon Backup.lnk
2020-11-26 16:35 - 2020-10-12 20:38 - 000000000 ____D C:\Users\xyz\AppData\Roaming\Amazon Cloud Drive
2020-11-26 16:34 - 2020-10-12 20:39 - 000001217 _____ C:\Users\xyz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon Photos.lnk
2020-11-26 13:37 - 2020-10-04 06:56 - 000004444 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1583002139
2020-11-26 12:25 - 2020-02-02 13:25 - 000000000 ____D C:\ProgramData\NVIDIA
2020-11-26 08:18 - 2020-02-06 23:53 - 000000000 ____D C:\Users\xyz\AppData\LocalLow\Mozilla
2020-11-26 01:46 - 2020-10-04 06:56 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-11-26 01:46 - 2020-05-05 15:24 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-11-25 20:08 - 2020-02-08 10:59 - 000000000 ____D C:\ProgramData\Mozilla
2020-11-25 19:24 - 2020-03-24 11:16 - 000000000 ____D C:\Users\xyz\AppData\Local\SquirrelTemp
2020-11-25 18:36 - 2020-10-04 07:01 - 000795738 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-11-25 18:36 - 2019-12-07 01:13 - 000000000 ____D C:\WINDOWS\INF
2020-11-25 18:32 - 2020-10-04 06:56 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-11-25 18:32 - 2020-10-04 06:52 - 000008192 ___SH C:\DumpStack.log.tmp
2020-11-25 18:32 - 2020-06-19 17:43 - 000000000 ____D C:\Users\xyz\Documents\ShareX
2020-11-25 18:32 - 2020-02-08 11:45 - 000000000 ____D C:\Users\xyz\AppData\Local\Everything
2020-11-25 18:32 - 2020-02-08 11:10 - 000000000 ____D C:\Users\xyz\AppData\Roaming\Everything
2020-11-25 18:32 - 2020-02-08 10:59 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-11-25 18:32 - 2020-02-02 13:25 - 000054443 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1
2020-11-25 18:32 - 2020-02-02 13:25 - 000020121 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1
2020-11-25 18:32 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\ServiceState
2020-11-25 18:32 - 2019-12-07 01:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-11-25 13:26 - 2019-12-07 01:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-11-25 11:25 - 2020-02-02 13:25 - 000011853 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1
2020-11-25 08:29 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-11-25 07:18 - 2020-06-16 16:55 - 000002421 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-11-25 07:18 - 2020-06-16 16:55 - 000002259 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-11-25 07:18 - 2020-06-16 16:55 - 000002259 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2020-11-25 07:18 - 2019-12-07 01:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-21 17:19 - 2020-02-08 10:59 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-21 17:17 - 2020-02-02 13:25 - 000001209 _____ C:\ProgramData\NvcDispCorePlugin.log_backup1
2020-11-21 17:16 - 2020-02-06 23:18 - 000011787 _____ C:\ProgramData\DisplaySessionContainer2.log_backup1
2020-11-21 17:15 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-11-20 16:05 - 2020-02-08 10:59 - 000002613 _____ C:\Users\xyz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2020-11-20 16:05 - 2020-02-08 10:59 - 000002576 _____ C:\Users\xyz\Desktop\Brave.lnk
2020-11-16 12:31 - 2020-02-06 23:48 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-16 12:31 - 2020-02-06 23:48 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-11-16 12:31 - 2020-02-06 23:48 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-11-15 00:03 - 2019-05-24 09:23 - 000000000 ____D C:\Program Files\Microsoft Office
2020-11-13 13:43 - 2020-10-04 06:56 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-11-13 13:43 - 2020-10-04 06:56 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-11-12 17:03 - 2020-02-06 23:32 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-11-12 17:01 - 2020-02-06 23:32 - 133736600 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-11-12 08:16 - 2020-10-04 06:56 - 000004194 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1581188361
2020-11-12 08:16 - 2020-02-08 10:59 - 000001403 _____ C:\Users\xyz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2020-11-11 00:14 - 2020-06-13 14:27 - 000000000 ____D C:\Program Files\Bitdefender Agent
2020-11-11 00:13 - 2020-10-04 06:52 - 000699888 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-11-11 00:12 - 2020-10-05 22:07 - 000000000 ____D C:\Users\xyz\AppData\Roaming\Notion
2020-11-11 00:12 - 2020-03-24 11:17 - 000000000 ____D C:\Users\xyz\AppData\Roaming\Slack
2020-11-11 00:12 - 2019-12-07 01:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2020-11-11 00:12 - 2019-12-07 01:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-11-11 00:12 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-11-11 00:12 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\SystemResources
2020-11-11 00:12 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-11-11 00:12 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\system32\setup
2020-11-11 00:12 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-11-11 00:12 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-11-11 00:12 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-11-11 00:12 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2020-11-11 00:12 - 2019-12-07 01:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-11-10 22:27 - 2019-12-07 01:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-11-10 22:25 - 2020-10-04 06:53 - 002876928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-11-06 17:01 - 2020-06-19 17:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShareX
2020-11-06 17:01 - 2020-06-19 17:43 - 000000000 ____D C:\Program Files\ShareX
2020-11-05 07:31 - 2020-10-04 02:38 - 000000000 ___DC C:\WINDOWS\Panther
2020-11-04 17:14 - 2020-03-24 11:17 - 000002193 _____ C:\Users\xyz\Desktop\Slack.lnk
2020-11-04 17:14 - 2020-03-24 11:17 - 000000000 ____D C:\Users\xyz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies Inc
2020-11-04 17:14 - 2020-03-24 11:16 - 000000000 ____D C:\Users\xyz\AppData\Local\slack
2020-11-02 16:52 - 2020-08-20 17:00 - 000000000 ____D C:\Users\xyz\.dbus-keyrings
2020-11-01 13:54 - 2020-03-30 15:17 - 000000000 ____D C:\Users\xyz\AppData\Roaming\XnViewMP
2020-11-01 08:38 - 2020-05-05 07:51 - 000000000 ____D C:\Users\xyz\AppData\Local\GoToMeeting
2020-10-29 06:11 - 2020-10-04 06:56 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2048631613-2831981643-1474844327-1003
2020-10-29 06:11 - 2020-10-04 03:20 - 000002361 _____ C:\Users\xyz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-10-29 06:11 - 2020-02-06 23:19 - 000000000 ___RD C:\Users\xyz\OneDrive
==================== Files in the root of some directories ========
2003-12-04 08:05 - 2003-12-04 08:05 - 000000000 ____H () C:\ProgramData\sdpsenv.dat
2020-11-08 23:59 - 2020-11-09 00:10 - 000000078 _____ () C:\Users\xyz\AppData\Roaming\IP.dat
2020-11-08 23:49 - 2020-11-09 00:16 - 000000078 _____ () C:\Users\xyz\AppData\Roaming\PC.dat
2020-11-09 00:09 - 2020-11-09 00:09 - 000000078 _____ () C:\Users\xyz\AppData\Roaming\VCFX.dat
2020-11-01 13:26 - 2020-11-24 23:39 - 000002974 _____ () C:\Users\xyz\AppData\Local\krita-sysinfo.log
2020-11-01 13:26 - 2020-11-24 23:40 - 000042057 _____ () C:\Users\xyz\AppData\Local\krita.log
2020-11-24 23:40 - 2020-11-24 23:40 - 000000039 _____ () C:\Users\xyz\AppData\Local\kritadisplayrc
2020-11-01 13:26 - 2020-11-24 23:40 - 000021459 _____ () C:\Users\xyz\AppData\Local\kritarc
2020-11-04 13:08 - 2020-11-04 13:08 - 000001263 _____ () C:\Users\xyz\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================