User Tag List

Malware help, please!!

This is a discussion on Malware help, please!! within the Inactive Malware Help Topics forums, part of the Tech Support Forum category. I am getting popup pages and popup dialog boxes whenever I click on anything in my browser. A photo of


 
 
Thread Tools Search this Thread
Old 06-27-2019, 03:34 PM   #1
Registered Member
 
Join Date: Feb 2009
Posts: 48
OS: windows 10



I am getting popup pages and popup dialog boxes whenever I click on anything in my browser. A photo of my comupter info and the attachement file is attached. Below is the FRST info. Thank you for your help in advance.

Sabrina


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-06-2019
Ran by sabri (administrator) on DESKTOP-9HDFBNQ (LENOVO 90GU0007US) (27-06-2019 15:15:27)
Running from C:\Users\sabri\OneDrive\Desktop
Loaded Profiles: sabri & postgres (Available Profiles: sabri & postgres)
Platform: Windows 10 Home Version 1803 17134.829 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.46.60.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19041.16510.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1905.28.0_x64__8wekyb3d8bbwe\Calculator.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19031.11411.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atiesrxx.exe
(Intuit Inc.) [File not signed] C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
(Intuit, Inc. -> Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(Intuit, Inc. -> Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(LITE-ON TECHNOLOGY CORP. -> Lenovo) C:\Program Files\Lenovo\Lenovo Calliope USB Keyboard\SklFundKb.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.46.60.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.46.60.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20174.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20174.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\rempl\sedlauncher.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1905.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1905.4-0\NisSrv.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.5\bin\pg_ctl.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.5\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.5\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.5\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.5\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.5\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.5\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.5\bin\postgres.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(SweetLabs Inc. -> SweetLabs, Inc) C:\Users\sabri\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [Lenovo Fundamental USB Keyboard] => C:\Program Files\Lenovo\Lenovo Calliope USB Keyboard\SklFundKb.exe [2644472 2017-04-10] (LITE-ON TECHNOLOGY CORP. -> Lenovo)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [672192 2018-04-19] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2622520 2019-05-19] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1088911561-2027019468-1293300719-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1088911561-2027019468-1293300719-1003\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-18] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk [2018-11-26]
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit, Inc. -> Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk [2018-11-26]
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc. -> Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk [2018-11-26]
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files (x86)\Intuit\QuickBooks 2018\QBW32.EXE (Intuit, Inc. -> Intuit Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {041B2F41-4C7A-499A-872F-6E5FCA9F96ED} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\46fe8ed6-113c-4f2f-9fac-e319f824443a => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {0A695222-1BE7-4D39-A044-49052E7F979D} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\4b82dcd8-4908-45da-bc19-eea8da734faf => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {2F0FC04E-51D4-482B-AFF3-ECB29F46CA9B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-21] (Google Inc -> Google Inc.)
Task: {3E7C5D11-4A95-4629-A782-5AD9241924DE} - System32\Tasks\App Explorer => C:\Users\sabri\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [7399080 2019-06-03] (SweetLabs Inc. -> SweetLabs, Inc) <==== ATTENTION
Task: {3E7E215E-099F-403F-8020-9BA33DDB2622} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {40D8D06D-7F0C-4D3F-81C7-DC3F3959EF78} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-[Removed] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {4E877D1A-E41A-42F6-9C5E-4B375FCFAC4C} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {6A21EAAE-B9BC-4619-8E89-FE3290522BD9} - System32\Tasks\QBScheduledReport => C:\Program Files (x86)\Common Files\Intuit\QuickBooks\ScheduledReports\ScheduledReports.Scheduler.exe [389168 2019-05-29] (Intuit, Inc. -> Intuit Inc.)
Task: {75D68251-2ADF-43FD-9821-79E165ACAEAC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {8E7A867E-D32A-4377-9B75-3712E6B45C30} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\f0533b25-52a2-40fb-831a-106a31fac01a => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {AE66B2A4-0257-4F02-8390-D255DAE17974} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [54440 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {C05F14A4-8FD4-44E5-B960-A71731F33D68} - System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-[Removed] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {E1F86CB8-BC67-41F1-BD6A-6605907EE6BA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-21] (Google Inc -> Google Inc.)
Task: {E68C4BB8-634C-44D4-B16F-19AA78C4AA08} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [52104 2017-09-18] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {ECBE7A1D-5054-482A-BFC0-7C9A96AB9B7B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {FA067EA4-10A5-4CAA-8978-6F469D3FF7BF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {FFE9978A-FD90-4998-B102-252DC2C0483E} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => %windir%\system32\sc.exe START ImControllerService

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{a10b3ac1-45c5-49d2-a1b9-5659334b59ba}: [DhcpNameServer] 192.168.1.10 8.8.8.8

Internet Explorer:
==================
HKU\S-1-5-21-1088911561-2027019468-1293300719-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-1088911561-2027019468-1293300719-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-1088911561-2027019468-1293300719-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
SearchScopes: HKU\S-1-5-21-1088911561-2027019468-1293300719-1001 -> DefaultScope {1D5642BE-1C34-4AAF-A98F-78358DF8304F} URL =
SearchScopes: HKU\S-1-5-21-1088911561-2027019468-1293300719-1001 -> {1D5642BE-1C34-4AAF-A98F-78358DF8304F} URL =
Handler-x32: intu-help-qb11 - {5AFDE6E8-AD0F-450B-818F-21D1CDC2E3EE} - C:\Program Files (x86)\Intuit\QuickBooks 2018\HelpAsyncPluggableProtocol.dll [2019-05-29] (Intuit, Inc. -> Intuit, Inc.)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\WINDOWS\SysWOW64\mscoree.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)

FireFox:
========
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2019-05-19] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @ glance.net/GlanceClient -> C:\Program Files (x86)\GlanceGuest\npglance.dll [2018-06-23] (Glance Networks Inc -> Glance Networks, Inc.)
FF Plugin-x32: @ tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @ tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2019-05-19] (Adobe Inc. -> Adobe Systems)

Chrome:
=======
CHR DefaultProfile: Default
CHR StartupUrls: Default -> "hxxps://www.bing.com/?PC=FT04"
CHR DefaultSearchURL: Default -> hxxps://www.bing.com/search?q={searchTerms}&PC=FT03&FORM=FTSBRD
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSuggestURL: Default -> hxxps://www.bing.com/osjson.aspx?query={searchTerms}
CHR Profile: C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default [2019-06-27]
CHR Extension: (Slides) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-11-21]
CHR Extension: (Docs) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-11-21]
CHR Extension: (Google Drive) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-11-21]
CHR Extension: (YouTube) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-11-21]
CHR Extension: (Free Time Card Calculator | Timesheet...) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\fakjceoaanbipaajkfoaoflafpjkgbjh [2018-11-27]
CHR Extension: (Sheets) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-11-21]
CHR Extension: (Google Docs Offline) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-11-26]
CHR Extension: (Popup Blocker Pro) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiodaajmphnkcajieajajinghpejdjai [2019-06-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-11-21]
CHR Extension: (PackageTrak Promos) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\oanbpfkcehelcjjipodkaafialmfejmi [2019-06-26]
CHR Extension: (Gmail) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-15]
CHR Extension: (Chrome Media Router) - C:\Users\sabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-04]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [816184 2019-05-19] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3117648 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2888272 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [560544 2017-10-01] (Advanced Micro Devices, Inc. -> AMD)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [65536 2018-11-07] (Intuit Inc.) [File not signed]
R2 QBVSS; C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [1537536 2018-11-07] (Intuit Inc.) [File not signed]
R2 RtkAudioUniversalService; C:\WINDOWS\System32\RtkAudUService64.exe [672192 2018-04-19] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
R2 RtkBtManServ; C:\WINDOWS\RtkBtManServ.exe [694896 2019-04-08] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\NisSrv.exe [2433136 2019-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MsMpEng.exe [109896 2019-06-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 postgresql-x64-9.5; "C:\Program Files\PostgreSQL\9.5\bin\pg_ctl.exe" runservice -N "postgresql-x64-9.5" -D "C:\Program Files\PostgreSQL\9.5\data" -w

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 amdkmcsp; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [101232 2017-06-15] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc. )
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0318578.inf_amd64_96ab7c1927e50449\atikmdag.sys [38773664 2017-10-01] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0318578.inf_amd64_96ab7c1927e50449\atikmpag.sys [549792 2017-10-01] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R0 amdpsp; C:\WINDOWS\System32\DRIVERS\amdpsp.sys [243048 2017-06-15] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc. )
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [110088 2017-04-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [954368 2017-04-11] (Realtek Semiconductor Corp. -> Realtek )
R3 RtkBtFilter; C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys [811176 2019-04-08] (WDKTestCert VSAuto,131800073559665678 -> Realtek Semiconductor Corporation)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [420832 2017-04-06] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
R3 RTWlanE; C:\WINDOWS\System32\drivers\rtwlane.sys [6991216 2017-08-15] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation )
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [47496 2019-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [337632 2019-06-05] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2019-06-05] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-06-27 15:08 - 2019-06-27 15:15 - 000000000 ____D C:\FRST
2019-06-27 13:44 - 2019-06-27 13:44 - 002418688 _____ (Farbar) C:\Users\sabri\Downloads\FRST64.exe
2019-06-24 13:53 - 2019-06-24 13:53 - 000141023 _____ C:\Users\sabri\Downloads\TranDtl_V395395.pdf
2019-06-24 12:32 - 2019-06-24 12:32 - 000005262 _____ C:\Users\sabri\Downloads\0007891006.pdf
2019-06-24 12:32 - 2019-06-24 12:32 - 000005262 _____ C:\Users\sabri\Downloads\0007891006 (1).pdf
2019-06-24 12:31 - 2019-06-24 12:31 - 000000813 _____ C:\Users\sabri\Downloads\OrderTrackingDownload 5-24-2019 12_31.csv
2019-06-24 12:31 - 2019-06-24 12:31 - 000000813 _____ C:\Users\sabri\Downloads\OrderTrackingDownload 5-24-2019 12_31 (1).csv
2019-06-24 08:36 - 2019-06-24 08:37 - 000000000 ___HD C:\adobeTemp
2019-06-19 09:32 - 2019-06-19 09:32 - 000048861 _____ C:\Users\sabri\Downloads\RBS Invoice _ 08.11.19 _ Images & Video.pdf
2019-06-18 12:10 - 2019-06-18 12:10 - 000001054 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge 2019.lnk
2019-06-18 12:07 - 2019-06-18 12:07 - 000001278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects 2019.lnk
2019-06-18 11:57 - 2019-06-18 11:57 - 000001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2019.lnk
2019-06-18 11:57 - 2019-06-18 11:57 - 000000000 ____D C:\Program Files\UNP
2019-06-17 11:42 - 2019-06-17 13:38 - 000000000 ____D C:\Users\sabri\Downloads\StudioStrawberry-Classic-Giveaway-Post
2019-06-17 11:29 - 2019-06-17 11:29 - 002843453 _____ C:\Users\sabri\Downloads\Template-Tutorial-How-To.pdf
2019-06-17 11:29 - 2019-06-17 11:29 - 000289798 _____ C:\Users\sabri\Downloads\StudioStrawberry-Classic-Giveaway-Post.zip
2019-06-12 11:09 - 2019-06-07 04:04 - 021388752 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-06-12 11:09 - 2019-06-07 03:45 - 012756480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-06-12 11:09 - 2019-06-07 03:42 - 003613696 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-06-12 11:09 - 2019-06-07 03:07 - 011942400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-06-12 11:09 - 2019-06-07 03:04 - 002881536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-06-12 11:09 - 2019-06-06 22:57 - 007519896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-06-12 11:09 - 2019-06-06 22:57 - 007436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-06-12 11:09 - 2019-06-06 22:56 - 009084216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-06-12 11:09 - 2019-06-06 22:46 - 006569344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-06-12 11:09 - 2019-06-06 22:46 - 006043496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-06-12 11:09 - 2019-06-06 22:38 - 025857536 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-06-12 11:09 - 2019-06-06 22:37 - 022019584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-06-12 11:09 - 2019-06-06 22:31 - 019372544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-06-12 11:09 - 2019-06-06 22:27 - 022718976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-06-12 11:09 - 2019-06-06 22:24 - 005784064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-06-12 11:09 - 2019-06-06 22:21 - 007588864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-06-12 11:09 - 2019-06-06 22:21 - 004866048 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-06-12 11:09 - 2019-05-17 05:27 - 006586880 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-06-12 11:09 - 2019-05-17 05:25 - 004718080 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-06-12 11:09 - 2019-05-16 23:42 - 005625160 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-06-12 11:09 - 2019-05-16 23:19 - 004515840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-06-12 11:09 - 2019-05-16 22:44 - 016597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-06-12 11:09 - 2019-05-16 22:38 - 004709376 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2019-06-12 11:09 - 2019-05-16 22:37 - 004385280 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-06-12 11:09 - 2019-05-16 22:31 - 004937216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-06-12 11:08 - 2019-06-07 04:04 - 001633136 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-06-12 11:08 - 2019-06-07 03:47 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2019-06-12 11:08 - 2019-06-07 03:41 - 004055552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2019-06-12 11:08 - 2019-06-07 03:40 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-06-12 11:08 - 2019-06-07 03:40 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2019-06-12 11:08 - 2019-06-07 03:23 - 001453920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-06-12 11:08 - 2019-06-07 03:19 - 020383832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-06-12 11:08 - 2019-06-07 03:10 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2019-06-12 11:08 - 2019-06-07 03:04 - 004056064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2019-06-12 11:08 - 2019-06-07 03:04 - 001471488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-06-12 11:08 - 2019-06-06 23:07 - 000707384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2019-06-12 11:08 - 2019-06-06 23:01 - 001035040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-06-12 11:08 - 2019-06-06 22:58 - 001220112 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-06-12 11:08 - 2019-06-06 22:58 - 001027384 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-06-12 11:08 - 2019-06-06 22:58 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-06-12 11:08 - 2019-06-06 22:58 - 000422416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmicmiplugin.dll
2019-06-12 11:08 - 2019-06-06 22:58 - 000135176 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-06-12 11:08 - 2019-06-06 22:58 - 000076304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-06-12 11:08 - 2019-06-06 22:57 - 002811192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-06-12 11:08 - 2019-06-06 22:57 - 002719032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-06-12 11:08 - 2019-06-06 22:57 - 001934808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-06-12 11:08 - 2019-06-06 22:57 - 001209696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-06-12 11:08 - 2019-06-06 22:57 - 000792888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-06-12 11:08 - 2019-06-06 22:57 - 000709728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-06-12 11:08 - 2019-06-06 22:57 - 000594024 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-06-12 11:08 - 2019-06-06 22:57 - 000494304 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-06-12 11:08 - 2019-06-06 22:57 - 000435000 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-06-12 11:08 - 2019-06-06 22:57 - 000413720 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2019-06-12 11:08 - 2019-06-06 22:57 - 000412984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2019-06-12 11:08 - 2019-06-06 22:57 - 000383504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2019-06-12 11:08 - 2019-06-06 22:57 - 000170296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-06-12 11:08 - 2019-06-06 22:57 - 000148280 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2019-06-12 11:08 - 2019-06-06 22:57 - 000137448 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2019-06-12 11:08 - 2019-06-06 22:56 - 000713272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2019-06-12 11:08 - 2019-06-06 22:47 - 000380432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-06-12 11:08 - 2019-06-06 22:47 - 000097272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2019-06-12 11:08 - 2019-06-06 22:46 - 001805656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2019-06-12 11:08 - 2019-06-06 22:46 - 001011872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2019-06-12 11:08 - 2019-06-06 22:46 - 000581048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2019-06-12 11:08 - 2019-06-06 22:46 - 000357072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-06-12 11:08 - 2019-06-06 22:46 - 000128792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2019-06-12 11:08 - 2019-06-06 22:24 - 003400704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-06-12 11:08 - 2019-06-06 22:23 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-06-12 11:08 - 2019-06-06 22:23 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2019-06-12 11:08 - 2019-06-06 22:22 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2019-06-12 11:08 - 2019-06-06 22:22 - 003710976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-06-12 11:08 - 2019-06-06 22:22 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-06-12 11:08 - 2019-06-06 22:21 - 001778688 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-06-12 11:08 - 2019-06-06 22:21 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-06-12 11:08 - 2019-06-06 22:21 - 000473600 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2019-06-12 11:08 - 2019-06-06 22:20 - 002610688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-06-12 11:08 - 2019-06-06 22:20 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2019-06-12 11:08 - 2019-06-06 22:20 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-06-12 11:08 - 2019-06-06 22:19 - 003212288 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-06-12 11:08 - 2019-06-06 22:19 - 002175488 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-06-12 11:08 - 2019-06-06 22:19 - 001560576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-06-12 11:08 - 2019-06-06 22:19 - 001549824 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-06-12 11:08 - 2019-06-06 22:19 - 000778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-06-12 11:08 - 2019-06-06 22:19 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskcomp.dll
2019-06-12 11:08 - 2019-06-06 22:18 - 002166784 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-06-12 11:08 - 2019-06-06 22:18 - 000686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-06-12 11:08 - 2019-06-06 22:18 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-06-12 11:08 - 2019-06-06 22:17 - 001920000 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-06-12 11:08 - 2019-06-06 22:17 - 000961024 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2019-06-12 11:08 - 2019-06-06 22:17 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2019-06-12 11:08 - 2019-06-06 22:16 - 001102336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2019-06-12 11:08 - 2019-06-06 22:16 - 000900096 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-06-12 11:08 - 2019-06-06 22:16 - 000544768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-06-12 11:08 - 2019-06-06 22:16 - 000478720 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2019-06-12 11:08 - 2019-05-18 15:12 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2019-06-12 11:08 - 2019-05-18 15:12 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-06-12 11:08 - 2019-05-18 15:12 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2019-06-12 11:08 - 2019-05-18 15:12 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2019-06-12 11:08 - 2019-05-17 05:44 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2019-06-12 11:08 - 2019-05-17 05:40 - 002394960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2019-06-12 11:08 - 2019-05-17 05:40 - 000280888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2019-06-12 11:08 - 2019-05-17 05:26 - 004393984 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-06-12 11:08 - 2019-05-17 05:25 - 004491264 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2019-06-12 11:08 - 2019-05-17 05:25 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsUpdateElevatedInstaller.exe
2019-06-12 11:08 - 2019-05-17 05:24 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2019-06-12 11:08 - 2019-05-17 05:22 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2019-06-12 11:08 - 2019-05-17 05:22 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll
2019-06-12 11:08 - 2019-05-17 05:21 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2019-06-12 11:08 - 2019-05-17 05:21 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2019-06-12 11:08 - 2019-05-17 05:21 - 000878592 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2019-06-12 11:08 - 2019-05-17 05:21 - 000274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3gpui.dll
2019-06-12 11:08 - 2019-05-17 05:21 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2019-06-12 11:08 - 2019-05-17 05:20 - 002084864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2019-06-12 11:08 - 2019-05-17 05:19 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2019-06-12 11:08 - 2019-05-17 05:07 - 002206424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2019-06-12 11:08 - 2019-05-17 05:00 - 005658112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-06-12 11:08 - 2019-05-17 04:58 - 003397632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2019-06-12 11:08 - 2019-05-17 04:56 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2019-06-12 11:08 - 2019-05-17 04:56 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3gpui.dll
2019-06-12 11:08 - 2019-05-17 04:55 - 000704000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-06-12 11:08 - 2019-05-17 04:55 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2019-06-12 11:08 - 2019-05-17 04:55 - 000470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2019-06-12 11:08 - 2019-05-17 04:54 - 002016768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2019-06-12 11:08 - 2019-05-17 02:33 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2019-06-12 11:08 - 2019-05-17 01:52 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2019-06-12 11:08 - 2019-05-17 00:07 - 000105272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2019-06-12 11:08 - 2019-05-16 23:44 - 000829960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2019-06-12 11:08 - 2019-05-16 23:44 - 000550520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2019-06-12 11:08 - 2019-05-16 23:43 - 000297688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2019-06-12 11:08 - 2019-05-16 23:42 - 004789944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-06-12 11:08 - 2019-05-16 23:42 - 002256560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-06-12 11:08 - 2019-05-16 23:42 - 001989552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-06-12 11:08 - 2019-05-16 23:42 - 001980256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-06-12 11:08 - 2019-05-16 23:42 - 001620264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2019-06-12 11:08 - 2019-05-16 23:42 - 001380096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2019-06-12 11:08 - 2019-05-16 23:42 - 001130568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-06-12 11:08 - 2019-05-16 23:42 - 000129088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2019-06-12 11:08 - 2019-05-16 23:42 - 000125504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2019-06-12 11:08 - 2019-05-16 23:30 - 013878784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-06-12 11:08 - 2019-05-16 23:26 - 002969600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2019-06-12 11:08 - 2019-05-16 23:23 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2019-06-12 11:08 - 2019-05-16 23:22 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2019-06-12 11:08 - 2019-05-16 23:21 - 000333824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-06-12 11:08 - 2019-05-16 23:21 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esentutl.exe
2019-06-12 11:08 - 2019-05-16 23:21 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2019-06-12 11:08 - 2019-05-16 23:20 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2019-06-12 11:08 - 2019-05-16 23:20 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2019-06-12 11:08 - 2019-05-16 23:19 - 001630720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-06-12 11:08 - 2019-05-16 23:19 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2019-06-12 11:08 - 2019-05-16 23:19 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2019-06-12 11:08 - 2019-05-16 23:19 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2019-06-12 11:08 - 2019-05-16 23:18 - 002796032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2019-06-12 11:08 - 2019-05-16 23:18 - 001006592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2019-06-12 11:08 - 2019-05-16 23:18 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2019-06-12 11:08 - 2019-05-16 23:08 - 001063224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-06-12 11:08 - 2019-05-16 23:08 - 000723432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-06-12 11:08 - 2019-05-16 23:08 - 000491200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-06-12 11:08 - 2019-05-16 23:08 - 000401328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2019-06-12 11:08 - 2019-05-16 23:07 - 004404720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-06-12 11:08 - 2019-05-16 23:07 - 002768960 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-06-12 11:08 - 2019-05-16 23:07 - 002571640 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-06-12 11:08 - 2019-05-16 23:07 - 002467320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-06-12 11:08 - 2019-05-16 23:07 - 001459120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-06-12 11:08 - 2019-05-16 23:07 - 001288712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-06-12 11:08 - 2019-05-16 23:07 - 001260272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-06-12 11:08 - 2019-05-16 23:07 - 000930616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2019-06-12 11:08 - 2019-05-16 23:07 - 000275768 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2019-06-12 11:08 - 2019-05-16 23:07 - 000260800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2019-06-12 11:08 - 2019-05-16 23:06 - 001943136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-06-12 11:08 - 2019-05-16 23:06 - 001784696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2019-06-12 11:08 - 2019-05-16 23:06 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2019-06-12 11:08 - 2019-05-16 23:06 - 001140992 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-06-12 11:08 - 2019-05-16 23:06 - 001098056 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-06-12 11:08 - 2019-05-16 23:06 - 000983424 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-06-12 11:08 - 2019-05-16 23:06 - 000151888 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2019-06-12 11:08 - 2019-05-16 23:04 - 001826816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2019-06-12 11:08 - 2019-05-16 23:00 - 001295360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2019-06-12 11:08 - 2019-05-16 22:37 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2019-06-12 11:08 - 2019-05-16 22:37 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DuCsps.dll
2019-06-12 11:08 - 2019-05-16 22:36 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2019-06-12 11:08 - 2019-05-16 22:36 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2019-06-12 11:08 - 2019-05-16 22:36 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2019-06-12 11:08 - 2019-05-16 22:35 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-06-12 11:08 - 2019-05-16 22:35 - 000362496 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentutl.exe
2019-06-12 11:08 - 2019-05-16 22:35 - 000322560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-06-12 11:08 - 2019-05-16 22:34 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2019-06-12 11:08 - 2019-05-16 22:34 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-06-12 11:08 - 2019-05-16 22:34 - 000671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2019-06-12 11:08 - 2019-05-16 22:34 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2019-06-12 11:08 - 2019-05-16 22:34 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2019-06-12 11:08 - 2019-05-16 22:34 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2019-06-12 11:08 - 2019-05-16 22:33 - 003091456 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-06-12 11:08 - 2019-05-16 22:33 - 002912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-06-12 11:08 - 2019-05-16 22:33 - 002370560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-06-12 11:08 - 2019-05-16 22:33 - 001487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2019-06-12 11:08 - 2019-05-16 22:33 - 001214464 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2019-06-12 11:08 - 2019-05-16 22:33 - 000787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2019-06-12 11:08 - 2019-05-16 22:32 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2019-06-12 11:08 - 2019-05-16 22:32 - 000815104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2019-06-12 11:08 - 2019-05-16 22:31 - 003376640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2019-06-12 11:08 - 2019-05-16 22:31 - 003293184 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2019-06-12 11:08 - 2019-05-16 22:31 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-06-12 11:08 - 2019-05-16 22:31 - 001805312 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-06-12 11:08 - 2019-05-16 22:31 - 001383424 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2019-06-12 11:08 - 2019-05-16 22:31 - 001215488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-06-12 11:08 - 2019-05-16 22:31 - 001211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2019-06-12 11:08 - 2019-05-16 22:31 - 001027584 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2019-06-12 11:08 - 2019-05-16 22:31 - 000620032 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2019-06-12 11:08 - 2019-05-16 22:31 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2019-06-12 11:08 - 2019-05-16 22:30 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2019-06-12 11:08 - 2019-05-16 22:30 - 000507392 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-06-12 11:08 - 2019-05-16 22:30 - 000276992 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2019-06-12 11:07 - 2019-06-07 03:48 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2019-06-12 11:07 - 2019-06-06 22:24 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2019-06-12 11:07 - 2019-06-06 22:23 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-06-12 11:07 - 2019-06-06 22:22 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2019-06-12 11:07 - 2019-06-06 22:22 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll
2019-06-12 11:07 - 2019-06-06 22:21 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-06-12 11:07 - 2019-06-06 22:20 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-06-12 11:07 - 2019-06-06 21:00 - 000001308 _____ C:\WINDOWS\system32\tcbres.wim
2019-06-12 11:07 - 2019-05-17 05:23 - 000110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2019-06-12 11:07 - 2019-05-17 04:54 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2019-06-12 11:07 - 2019-05-16 23:23 - 000074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2019-06-12 11:07 - 2019-05-16 23:23 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-06-12 11:07 - 2019-05-16 23:22 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2019-06-12 11:07 - 2019-05-16 23:19 - 001073664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2019-06-12 11:07 - 2019-05-16 22:36 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2019-06-12 11:07 - 2019-05-16 22:36 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2019-06-12 11:07 - 2019-05-16 22:36 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2019-06-12 11:07 - 2019-05-16 22:36 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-06-12 11:07 - 2019-05-16 22:34 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2019-06-12 11:07 - 2019-05-16 22:34 - 000047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscore.dll
2019-06-12 11:07 - 2019-05-16 22:33 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2019-06-12 10:49 - 2019-06-12 10:49 - 003652986 _____ C:\Users\sabri\Downloads\Images&Video promo with wed vid.mp4
2019-06-12 09:39 - 2019-06-12 09:39 - 000000000 ____D C:\Users\sabri\Downloads\videoblocks-universal-photo-slideshow_H5NHjpts4
2019-06-12 09:24 - 2019-06-12 09:25 - 086053650 _____ C:\Users\sabri\Downloads\videoblocks-universal-photo-slideshow_H5NHjpts4.zip
2019-06-12 09:23 - 2019-06-12 09:23 - 000001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom Classic.lnk
2019-06-10 11:53 - 2019-06-10 11:53 - 000321640 _____ C:\Users\sabri\Downloads\PTL00004.pdf
2019-06-07 10:41 - 2019-06-07 10:41 - 006446391 _____ C:\Users\sabri\Downloads\530.921.5086 www.facebook.com_imagesandvideos.pdf
2019-06-06 11:49 - 2019-04-08 17:28 - 000070644 _____ C:\WINDOWS\rtl8761a_mp_chip_bt40_fw_asic_rom_patch_8192ee_new.dll
2019-06-06 11:49 - 2019-04-08 17:28 - 000051068 _____ C:\WINDOWS\rtl8723b_mp_chip_bt40_fw_asic_rom_patch_new.dll
2019-06-06 11:49 - 2019-04-08 17:28 - 000051016 _____ C:\WINDOWS\rtl8723b_mp_chip_bt40_fw_asic_rom_patch_new_s1.dll
2019-06-06 11:49 - 2019-04-08 17:28 - 000050892 _____ C:\WINDOWS\rtl8822c_mp_chip_bt40_fw_asic_rom_patch_new.dll
2019-06-06 11:49 - 2019-04-08 17:28 - 000049332 _____ C:\WINDOWS\rtl8822b_mp_chip_bt40_fw_asic_rom_patch_new.dll
2019-06-06 11:49 - 2019-04-08 17:28 - 000048016 _____ C:\WINDOWS\rtl8821c_mp_chip_bt40_fw_asic_rom_patch_new.dll
2019-06-06 11:49 - 2019-04-08 17:28 - 000038012 _____ C:\WINDOWS\rtl8821a_mp_chip_bt40_fw_asic_rom_patch_new.dll
2019-06-06 11:49 - 2019-04-08 17:28 - 000004080 _____ C:\WINDOWS\PidVid_List.dll
2019-06-06 10:33 - 2019-06-06 10:33 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2019-06-05 09:08 - 2019-06-05 09:08 - 000000000 ____D C:\Users\sabri\Downloads\Oroville, CA
2019-06-04 10:48 - 2019-06-04 10:49 - 072394968 _____ C:\Users\sabri\Downloads\Oroville, CA.zip
2019-06-04 10:40 - 2019-06-04 10:40 - 000020155 _____ C:\Users\sabri\Downloads\e85d7c60-554c-466c-af0f-89d377d2338e.pdf
2019-06-03 09:16 - 2019-06-03 09:16 - 000054788 _____ C:\Users\sabri\Downloads\The-House-on-Churn-Creek-Bottom-5-31-19-1.pdf
2019-05-30 10:41 - 2019-05-30 10:42 - 021915992 _____ C:\Users\sabri\Downloads\Jay & Olivia low res 720.mp4
2019-05-29 11:09 - 2019-05-29 11:09 - 000142206 _____ C:\Users\sabri\Downloads\TranDtl_V125335.pdf
2019-05-29 11:08 - 2019-05-29 11:08 - 000143833 _____ C:\Users\sabri\Downloads\TranDtl_V119700.pdf
2019-05-28 10:17 - 2019-05-28 10:17 - 000000000 ____D C:\Users\sabri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bryxen Software
2019-05-28 10:17 - 2019-05-28 10:17 - 000000000 ____D C:\Users\sabri\AppData\Roaming\Doodly
2019-05-28 10:16 - 2019-05-28 10:17 - 000000000 ____D C:\Users\sabri\AppData\Local\SquirrelTemp
2019-05-28 10:16 - 2019-05-28 10:17 - 000000000 ____D C:\Users\sabri\AppData\Local\Doodly
2019-05-28 10:07 - 2019-05-28 10:09 - 083477072 _____ (Bryxen Software) C:\Users\sabri\Downloads\Doodly Setup 1.19.11.exe

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-06-27 15:05 - 2018-11-21 14:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-06-27 14:25 - 2018-04-11 16:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-06-27 10:28 - 2018-04-11 16:38 - 000000000 ___HD C:\Program Files\WindowsApps
2019-06-27 10:28 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-06-27 10:26 - 2018-11-21 10:52 - 000000000 ____D C:\Users\sabri\AppData\Local\Host App Service
2019-06-24 14:00 - 2018-11-21 14:05 - 000000000 ____D C:\Users\sabri
2019-06-24 10:10 - 2018-11-21 14:14 - 000793700 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-06-24 10:10 - 2018-04-11 16:36 - 000000000 ____D C:\WINDOWS\INF
2019-06-24 10:05 - 2019-01-08 11:35 - 000000000 ____D C:\Users\postgres
2019-06-24 10:05 - 2018-11-21 14:17 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-06-24 08:37 - 2018-11-29 10:45 - 000000000 ___RD C:\Users\sabri\Creative Cloud Files
2019-06-24 08:35 - 2018-11-28 13:07 - 000000000 ____D C:\Users\sabri\AppData\Local\Adobe
2019-06-21 13:50 - 2018-04-11 14:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2019-06-21 13:50 - 2018-01-28 13:55 - 000065536 _____ C:\WINDOWS\psp_storage.bin
2019-06-21 10:39 - 2018-11-21 12:01 - 000000000 ____D C:\Program Files\rempl
2019-06-19 09:15 - 2018-11-26 09:38 - 000000090 _____ C:\WINDOWS\QBChanUtil_Trigger.ini
2019-06-18 12:10 - 2018-11-28 13:52 - 000000000 ____D C:\Program Files\Common Files\Adobe
2019-06-18 12:07 - 2018-11-28 13:51 - 000000000 ____D C:\Program Files\Adobe
2019-06-18 11:57 - 2018-11-28 13:26 - 000000000 ____D C:\Users\sabri\OneDrive\Documents\Adobe
2019-06-18 11:57 - 2018-11-21 10:54 - 000000000 ____D C:\Users\sabri\AppData\Roaming\Adobe
2019-06-18 08:53 - 2018-11-21 11:54 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-06-18 08:53 - 2018-11-21 11:54 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-06-17 08:45 - 2018-11-21 14:17 - 000003380 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1088911561-2027019468-1293300719-1001
2019-06-17 08:45 - 2018-11-21 14:05 - 000002374 _____ C:\Users\sabri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-06-17 08:45 - 2018-11-21 10:57 - 000000000 ___RD C:\Users\sabri\OneDrive
2019-06-14 11:22 - 2019-01-11 12:47 - 000000000 ____D C:\Users\sabri\AppData\Local\CrashDumps
2019-06-13 08:54 - 2018-11-21 10:54 - 000000000 ___RD C:\Users\sabri\3D Objects
2019-06-13 08:54 - 2017-10-03 09:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-06-13 08:53 - 2018-11-21 14:02 - 000252000 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-06-12 14:03 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\TextInput
2019-06-12 14:03 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-06-12 14:03 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\Provisioning
2019-06-12 14:03 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-06-12 11:38 - 2018-04-11 16:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-06-12 11:06 - 2018-11-21 11:57 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-06-12 11:00 - 2018-11-21 11:57 - 135349160 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-06-12 09:14 - 2018-11-28 13:10 - 000000000 ____D C:\ProgramData\Adobe
2019-06-12 09:08 - 2018-11-28 13:58 - 000001417 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2019-06-12 09:08 - 2018-11-28 13:58 - 000001405 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2019-06-12 09:08 - 2018-11-28 13:10 - 000000000 ____D C:\Program Files (x86)\Adobe
2019-06-05 08:41 - 2018-11-21 12:44 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-05-30 18:57 - 2018-04-11 16:41 - 000835688 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-05-30 18:57 - 2018-04-11 16:41 - 000179816 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories ================

2018-11-28 13:10 - 2018-11-28 13:10 - 000000410 _____ () C:\Users\sabri\AppData\Local\oobelibMkey.log

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ============================
Attached Thumbnails
Click image for larger version

Name:	PC info.PNG
Views:	26
Size:	34.4 KB
ID:	323870  
Attached Files
File Type: txt Addition.txt (37.0 KB, 11 views)
jus me is offline  
Sponsored Links
Advertisement
 
Old 06-28-2019, 08:21 AM   #2
Security Team
Moderator
 
Join Date: Jan 2011
Location: Bulgaria
Posts: 152
OS: win 10 Pro 1903



Hi,Sabrina..! Welcome to the TSF Malware Removal forum...!


Uninstall a Program
  • Press the Windows Key + R.
  • Type appwiz.cpl in the Run box and click OK.
  • The Add/Remove Programs list will open. Locate the following programs on the list:
Quote:
Lenovo App Explorer (HKU\S-1-5-21-1088911561-2027019468-1293300719-1001\...\Host App Service) (Version: 0.273.3.522 - SweetLabs for Lenovo) <==== ATTENTION

Lenovo App Explorer (HKU\S-1-5-21-1088911561-2027019468-1293300719-1003\...\Host App Service) (Version: 0.273.2.343 - SweetLabs for Lenovo) <==== ATTENTION
  • Select each program and click Uninstall.
  • Restart the computer if prompted


====================================================================================



Farbar Recovery Scan Tool - Fix

  • Open Notepad (Start > All Programs > Accessories > Notepad).
  • Please copy all the text in the codebox below. (To do this highlight the contents of the box, right-click on it and select Copy. Right-click in the open Notepad and select Paste).
  • Save it as fixlist.txt next to FRST/FRST64.exe

    NOTE: Both FRST/FRST64.exe and the fixlist.txt must be in the same location or the fix will not work.
Code:
Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

(SweetLabs Inc. -> SweetLabs, Inc) C:\Users\sabri\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
Task: {3E7C5D11-4A95-4629-A782-5AD9241924DE} - System32\Tasks\App Explorer => C:\Users\sabri\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [7399080 2019-06-03] (SweetLabs Inc. -> SweetLabs, Inc) <==== ATTENTION

AlternateDataStreams: C:\Users\sabri\OneDrive\Documents\Adobe:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]

C:\Users\sabri\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
 
End
  • Double-click FRST/FRST64 to run the tool. If the tool warns you the version is outdated, please download and run the updated version.
  • Click the Fix button just once, and wait.
  • If you receive a message that a reboot is required, please make sure you allow it to restart normally.
  • The tool will complete its run after the restart.
  • When finished, the tool will make a log (Fixlog.txt) in the same location from where it was run. Please post the Fixlog.txt log in your reply.
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


=============================================================


AdwCleaner

Download AdwCleaner and save it to your desktop.
  • Right-click on AdwCleaner.exe and select Run as Administrator
  • Accept the EULA (I accept), then click on Scan.
  • Let the scan complete. If no objects are detected, close the AdwCleaner window.
  • If any objects are detected, uncheck any items you want to keep.
  • Click on the Clean and Repair button.
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer. Allow it to do so.
  • After the restart, an AdwCleaner window will open. Click on View Log File, and the log will open in notepad. Copy and paste the contents of the log into your next reply.

Note: the AdwCleaner log is also saved to C:\AdwCleaner\Logs\AdwCleaner[CXX].txt (where XX is two numbers).


=========================================================


Scanning with SecurityCheck by glax24

  • Download SecurityCheck by glax24 from here and remember the tool on the desktop.
  • Run the program right-click the administrator name
  • Wait for the scan to finish. It will open in a text file named SecurityType.txt. Copy the contents of this file to your next post
  • You can find this file in the root of the system disk in a folder called SecurityCheck, C: \\ SecurityCheck \\ SecurityCheck.txt
icotonev is offline  
Old 06-28-2019, 10:31 AM   #3
Registered Member
 
Join Date: Feb 2009
Posts: 48
OS: windows 10



Thank you so much for your help!
I have attached the fixlog file. I noticed at the end of your reply to me it said to download and use ADW cleaner. I"m sure that was just an ad right? I didn't do that.

It is still redirecting anytime I open a browser or click on anything. Also, even though the internet options is set to google.com it comes up as bing.
Attached Files
File Type: txt Fixlog.txt (2.4 KB, 10 views)
jus me is offline  
Sponsored Links
Advertisement
 
Old 06-28-2019, 11:05 AM   #4
Security Team
Moderator
 
Join Date: Jan 2011
Location: Bulgaria
Posts: 152
OS: win 10 Pro 1903



Quote:
Originally Posted by jus me View Post
Thank you so much for your help!
I have attached the fixlog file. I noticed at the end of your reply to me it said to download and use ADW cleaner. I"m sure that was just an ad right? I didn't do that.

It is still redirecting anytime I open a browser or click on anything. Also, even though the internet options is set to google.com it comes up as bing.



No, this is a program with which I expect to scan your system ..! Please read my instructions carefully ..!
icotonev is offline  
Old 06-28-2019, 11:23 AM   #5
Registered Member
 
Join Date: Feb 2009
Posts: 48
OS: windows 10



# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build: 04-04-2019
# Database: 2019-06-28.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 06-28-2019
# Duration: 00:00:01
# OS: Windows 10 Home
# Cleaned: 5
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Users\postgres\AppData\Local\Host App Service
Deleted C:\Users\sabri\AppData\Roaming\download Manager

***** [ Files ] *****

Deleted C:\Windows\System32\Tasks_Migrated\App Explorer

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKU\S-1-5-21-1088911561-2027019468-1293300719-1003\Software\Host App Service
Deleted HKU\S-1-5-21-1088911561-2027019468-1293300719-1003\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1663 octets] - [28/06/2019 11:16:37]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
jus me is offline  
Old 06-28-2019, 11:31 AM   #6
Registered Member
 
Join Date: Feb 2009
Posts: 48
OS: windows 10



Defender isn't allowing me to do the security check by glax. I have attached the dialog box photo.
Attached Thumbnails
Click image for larger version

Name:	defender report.PNG
Views:	31
Size:	101.1 KB
ID:	323878  
jus me is offline  
Old 06-28-2019, 11:42 AM   #7
Security Team
Moderator
 
Join Date: Jan 2011
Location: Bulgaria
Posts: 152
OS: win 10 Pro 1903



Scanning with SecurityCheck by glax24

  • Download SecurityCheck by glax24 from here and remember the tool on the desktop.
  • Run the program right-click the administrator name
  • Wait for the scan to finish. It will open in a text file named SecurityType.txt. Copy the contents of this file to your next post
  • You can find this file in the root of the system disk in a folder called SecurityCheck, C: \\ SecurityCheck \\ SecurityCheck.txt
icotonev is offline  
Old 06-28-2019, 02:53 PM   #8
Registered Member
 
Join Date: Feb 2009
Posts: 48
OS: windows 10



It says the SecurityCheck by glax24 is a trojan virus and it won't download. Am i supposed to turn off my windows defender?
jus me is offline  
Old 06-29-2019, 12:17 AM   #9
Security Team
Moderator
 
Join Date: Jan 2011
Location: Bulgaria
Posts: 152
OS: win 10 Pro 1903


Hello again!

Please prepare fresh diaries:


Download FRST and save it to your desktop from here

Note: You need to run the version compatible with your system.
If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system; that will be the right version.


Double-click FRST then click the 'Scan' button to run the tool.
When done, FRST will save 2 logs to your desktop.
  1. FRST.txt
  2. Addition.txt

Quote:
Originally Posted by jus me View Post
It says the SecurityCheck by glax24 is a trojan virus and it won't download. Am i supposed to turn off my windows defender?


Attach the program Please download it here:
Attached Files
File Type: rar SecurityCheck.rar (456.6 KB, 7 views)
icotonev is offline  
Old 07-05-2019, 08:05 AM   #10
Security Team
Moderator
 
Join Date: Jan 2011
Location: Bulgaria
Posts: 152
OS: win 10 Pro 1903



Due to lack of response, this topic will now be closed. If you need support, please begin a new thread, and provide a link to this topic. Have a nice evening...!
icotonev is offline  
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is on
Smilies are on
[IMG] code is on
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Post a Question


» Site Navigation
 > FAQ
  > 10.0.0.2
Powered by vBadvanced CMPS v3.2.3


All times are GMT -7. The time now is 07:13 AM.


Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2020, vBulletin Solutions, Inc.
vBulletin Security provided by vBSecurity v2.2.2 (Pro) - vBulletin Mods & Addons Copyright © 2020 DragonByte Technologies Ltd.
User Alert System provided by Advanced User Tagging v3.1.0 (Pro) - vBulletin Mods & Addons Copyright © 2020 DragonByte Technologies Ltd.
Copyright 2001 - 2018, Tech Support Forum

Windows 10 - Windows 7 - Windows XP - Windows Vista - Trojan Removal - Spyware Removal - Virus Removal - Networking - Security - Top Web Hosts