Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-11-2022
Ran by Chuck (administrator) on CHUCK-PC (22-11-2022 15:30:48)
Running from D:\Sysnative Tools
Loaded Profiles: Chuck
Platform: Microsoft Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(cmd.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <20>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(services.exe ->) (Novawave Inc. -> Novawave Inc.) D:\System Tools\Novabench\NovabenchService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [9922800 2022-10-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-4060470119-733395135-3709892937-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [38650192 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-4060470119-733395135-3709892937-1001\...\Run: [cdloader] => C:\Users\Chuck\AppData\Roaming\mjusbsp\cdloader2.exe [58816 2018-04-05] (magicJack, L.P. -> magicJack L.P.)
HKU\S-1-5-21-4060470119-733395135-3709892937-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-4060470119-733395135-3709892937-1001\...\MountPoints2: E - E:\Autorun.exe
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\107.0.5304.107\Installer\chrmstp.exe [2022-11-10] (Google LLC -> Google LLC)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2014-02-19]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2016-01-08]
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass (Marvasol Inc) -> LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2016-01-08]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass (Marvasol Inc) -> LastPass)
GroupPolicyScripts: Restriction <==== ATTENTION
GroupPolicyScripts\User: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0429E07B-5A04-4599-AE23-8D75BE68FA72} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3728752 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0BFBD582-A478-4155-8DAA-71369737467D} - System32\Tasks\{B12163EC-2A0F-4DB6-B448-3F1E1C447C92} => msiexec.exe /package "D:\DownLoads\DebugDiagx64.msi"
Task: {0C91D2F3-72FB-4433-A17C-7B3E6EC5D0E2} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [1174016 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Task: {0DFECF84-7CFC-445D-8AE9-246936167FC1} - System32\Tasks\{69549C03-FFF0-4BFC-8B8D-B37887F8ECAE} => C:\Windows\system32\pcalua.exe -a E:\disk1\setup.exe -d E:\
Task: {13A94C32-AE2A-4DD1-8BD0-EDCB06CF227B} - System32\Tasks\{9BBC9E44-985F-4751-9E09-A1136DB25F47} => C:\Windows\system32\pcalua.exe -a D:\DownLoads\AdobeAIRInstaller_3.2.0.2070.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {1DA860CF-5DFE-4C1B-9C56-7C13DDF0F773} - \{08797947-0A0E-0C0C-7A11-040F0B78117F} -> No File <==== ATTENTION
Task: {24646530-7148-414B-A522-7667DBDD8F25} - System32\Tasks\{D79C03CB-3094-45B4-8EE1-04C9F9F008C0} => C:\Windows\system32\pcalua.exe -a D:\DownLoads\dotnetfx35setup(1).exe -d D:\DownLoads
Task: {32385522-1924-47A1-B4FF-D9CFE91CFDE4} - System32\Tasks\{41971C23-3C99-42C5-BCBB-92728124F03D} => C:\Windows\system32\pcalua.exe -a D:\DownLoads\winsdk_web.exe -d D:\DownLoads
Task: {38685812-E4BC-4DC9-BE86-6A659B4044E4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-11] (Google Inc -> Google Inc.)
Task: {4B06C3CF-BF80-464E-8E56-82713B5C4359} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-11-09] (Piriform Software Ltd -> Piriform)
Task: {51D784C5-4B12-48B3-B395-B49CAA5658E2} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {52E06A5E-382C-43C9-802C-4C46121B6131} - System32\Tasks\{C0CFCFB0-8193-46C5-A156-7F247046C33B} => C:\Windows\system32\pcalua.exe -a D:\DownLoads\SH-S223L_SB04.exe
Task: {5B43C5C0-0162-47A1-B3BF-B3D844877FF0} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5EB47497-0696-41FB-9FCC-5E7B6DBF383B} - System32\Tasks\{BD34E7F5-E78E-4B4D-BF34-27AFFD7428F0} => C:\Windows\system32\pcalua.exe -a "D:\System Tools\ProcessQuickLink 2\unins000.exe"
Task: {61F158BE-13BC-4C36-9D77-75474D232B20} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {6A232CB0-B3FF-46F0-9A87-1B7EAC41D8FE} - System32\Tasks\{E2B7E4FE-2714-4984-B7DC-98AF5995DB26} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe"
Task: {73BBBC78-6381-476A-8111-CEBFAD111923} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {78CA1312-8C29-47B5-8B55-44A0680BDEA7} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [849264 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7E7783EA-CC00-4D3D-852E-20DA977EAFF9} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [849264 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8DF32B52-D280-4121-BA6B-613A7B78B238} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9F7D2AB7-57F6-424F-8698-94CDDE9A7A12} - System32\Tasks\{A8A659B3-0401-4CB6-B708-C17A88F05072} => C:\Windows\system32\pcalua.exe -a C:\Windows\system32\pcwrun.exe -c D:\Quicken\qw.exe
Task: {A20C5916-EA64-4DDD-A348-7A967B30D390} - System32\Tasks\Extend Health
Task: {AA35CA84-0159-480D-8323-45D76ECD2215} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [781680 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {AFD3D950-259A-4034-B1D3-36845A707AA7} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.)
Task: {B39BF604-F2EB-4A86-943E-65BD677F1B6C} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [590704 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C3E55553-2031-421D-A0E2-C96955E833A3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-11] (Google Inc -> Google Inc.)
Task: {C5891914-10A3-4098-B16E-AF25CD02FA67} - System32\Tasks\{9CDADED3-9866-456D-ADC7-8C3E92D1AF87} => C:\Windows\system32\pcalua.exe -a D:\DownLoads\MicroFrameworkSDK3_0.exe -d D:\DownLoads
Task: {DEAA4E96-0111-4470-9BD0-4DCE1A359495} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4669264 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "07b8aa54-ba8d-4f5e-a3e2-6288a9738815" --version "6.06.10144" --silent
Task: {EE3C39B2-4D9C-4BEC-9967-E03FADBA7BAA} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [781680 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {F3B06D00-3B07-457F-8AA4-3BFDF4254041} - System32\Tasks\CCleanerSkipUAC - Chuck => C:\Program Files\CCleaner\CCleaner.exe [32325456 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {F4CC5EEF-081F-4B57-832F-82BD681C0F87} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648048 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{ACC1B417-2078-4C2B-9C53-80C2DD2F3295}: [DhcpNameServer] 192.168.1.1
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
FireFox:
========
FF DefaultProfile: u7cjq9be.default-1630423938134
FF ProfilePath: C:\Users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134 [2022-11-22]
FF Homepage: Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134 -> hxxps://my.yahoo.com/
FF Session Restore: Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134 -> is enabled.
FF Extension: (LastPass: Free Password Manager) - C:\Users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134\Extensions\support@lastpass.com.xpi [2022-11-19]
FF Extension: (uBlock Origin) - C:\Users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134\Extensions\uBlock0@raymondhill.net.xpi [2022-09-21]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2022-08-16]
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-01-08] (LastPass (Marvasol Inc) -> LastPass)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-01-08] (LastPass (Marvasol Inc) -> LastPass)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2022-11-14] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default [2022-11-22]
CHR Notifications: Default -> hxxps://askbobrankin.com; hxxps://mg.mail.yahoo.com; hxxps://news.yahoo.com; hxxps://www.askwoody.com; hxxps://www.facebook.com; hxxps://www.phone.instantcheckmate.com; hxxps://www.sendspace.com; hxxps://www.yahoo.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxp://my.yahoo.com/
CHR StartupUrls: Default -> "hxxps://my.yahoo.com/#"
CHR NewTab: Default -> Active:"chrome-extension://jonikckfpolfcdcgdficelkfffkloemh/n.html"
CHR Extension: (uBlock Origin) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2022-11-20]
CHR Extension: (Google Docs Offline) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-11-01]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2022-11-22]
CHR Extension: (Tabs to the Front) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiembaoomcehoiehhdldabfgnmphappc [2017-06-18]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2022-11-17]
CHR Extension: (Blank New Tab Page) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\jonikckfpolfcdcgdficelkfffkloemh [2017-04-27]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-01-23]
CHR Extension: (Plugins) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcblfncjaclajmegihojiekebofjcen [2021-11-24]
CHR Extension: (Popup my Bookmarks) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppflflkbbafeopeoeigkbbdjdbeifni [2020-11-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Profile: C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\System Profile [2022-11-21]
CHR HKU\S-1-5-21-4060470119-733395135-3709892937-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd]
CHR HKU\S-1-5-21-4060470119-733395135-3709892937-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. -> Adobe Inc.)
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1003344 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [11072008 2022-10-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8842536 2022-10-21] (Malwarebytes Inc. -> Malwarebytes)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
R2 NovabenchService; D:\System Tools\Novabench\NovabenchService.exe [1229808 2020-08-30] (Novawave Inc. -> Novawave Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] (ASUSTeK Computer Inc. -> )
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [158640 2022-06-22] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2014-12-07] (Martin Malik - REALiX -> REALiX(tm))
S3 JLTECH0227; C:\Windows\System32\Drivers\jl2005c.sys [80240 2010-05-18] (JEILIN TECHNOLOGIES CORPORATION -> Windows (R) Codename Longhorn DDK provider)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [223176 2022-11-19] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [193992 2022-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [75216 2022-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239544 2022-07-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [149432 2022-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] (ASUSTeK Computer Inc. -> )
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R3 NovabenchDriver; D:\System Tools\Novabench\NovabenchDriver.sys [27488 2018-05-27] (Novawave Inc. -> )
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [77824 2010-01-22] (Microsoft Windows Hardware Compatibility Publisher -> NEC Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [180224 2010-01-22] (Microsoft Windows Hardware Compatibility Publisher -> NEC Electronics Corporation)
R3 NVHDA; C:\Windows\System32\drivers\nvhda64v.sys [129960 2021-05-15] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
R3 nvlddmkm; C:\Windows\System32\DRIVERS\nvlddmkm.sys [38196648 2021-05-13] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [398112 2012-01-25] (Marvell Semiconductor -> Marvell)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-11-22 15:30 - 2022-11-22 15:31 - 000000000 ____D C:\FRST
2022-11-22 06:14 - 2022-11-22 06:14 - 000193992 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2022-11-22 06:14 - 2022-11-22 06:14 - 000149432 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2022-11-22 06:14 - 2022-11-22 06:14 - 000075216 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2022-11-19 20:10 - 2022-11-19 20:10 - 000223176 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2022-11-19 17:12 - 2022-11-19 17:12 - 000002157 _____ C:\Users\Chuck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk
2022-10-26 07:07 - 2022-10-26 07:07 - 000000930 _____ C:\Users\Public\Desktop\Firefox.lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-11-22 15:29 - 2022-07-15 19:32 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-11-22 15:29 - 2016-11-16 09:15 - 000000000 ____D C:\Users\Chuck\AppData\LocalLow\Mozilla
2022-11-22 15:29 - 2012-04-12 15:28 - 000000000 ____D C:\Program Files (x86)\Google
2022-11-22 12:25 - 2016-10-14 14:00 - 000000000 ____D C:\ProgramData\NVIDIA
2022-11-22 08:11 - 2020-09-17 13:54 - 000000000 ____D C:\Program Files\CCleaner
2022-11-22 06:32 - 2009-07-13 20:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2022-11-22 06:32 - 2009-07-13 20:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2022-11-22 06:16 - 2009-07-13 21:13 - 000832608 _____ C:\Windows\system32\PerfStringBackup.INI
2022-11-22 06:16 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\inf
2022-11-22 06:14 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\system32\inetsrv
2022-11-22 06:12 - 2009-07-13 21:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-11-21 20:24 - 2022-09-21 19:24 - 000000760 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2022-11-20 06:30 - 2016-10-22 08:47 - 000000000 ____D C:\Users\Chuck\AppData\Local\CrashDumps
2022-11-20 06:23 - 2012-04-24 08:00 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-11-19 17:13 - 2022-05-24 07:32 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-11-19 17:12 - 2022-05-24 07:32 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2022-11-19 17:12 - 2015-12-16 09:00 - 000006610 _____ C:\Windows\wininit.ini
2022-11-19 08:10 - 2022-09-11 19:18 - 000000000 ____D C:\Users\Chuck\AppData\Roaming\com.adobe.dunamis
2022-11-19 07:58 - 2009-07-13 21:08 - 000032548 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2022-11-18 12:04 - 2022-10-13 14:33 - 000002113 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2022-11-18 08:11 - 2022-09-21 19:24 - 000003352 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2022-11-18 08:11 - 2020-09-17 13:54 - 000003870 _____ C:\Windows\system32\Tasks\CCleaner Update
2022-11-10 20:07 - 2017-04-11 08:51 - 000002278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-11-09 08:14 - 2013-07-23 06:48 - 000000000 ____D C:\Windows\system32\MRT
2022-11-09 08:11 - 2012-01-03 16:51 - 146960040 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2022-10-28 19:10 - 2012-04-22 12:32 - 000000000 ____D C:\Users\Chuck\AppData\Roaming\mjusbsp
2022-10-28 15:42 - 2012-12-28 18:01 - 000000991 _____ C:\Users\Chuck\Desktop\magicJack.lnk
2022-10-28 15:42 - 2012-12-28 18:01 - 000000977 _____ C:\Users\Chuck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\magicJack.lnk
2022-10-28 15:25 - 2009-07-13 19:20 - 000000000 __RHD C:\Users\Public\Libraries
2022-10-28 07:51 - 2015-11-14 17:41 - 000000782 _____ C:\Users\Chuck\Desktop\Router Settings.txt
2022-10-27 14:15 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\system32\NDF
2022-10-26 07:07 - 2011-12-31 13:50 - 000000942 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-10-23 19:08 - 2022-10-13 14:33 - 000002101 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
==================== Files in the root of some directories ========
2013-06-28 05:37 - 2016-01-08 06:59 - 021382680 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2017-09-06 08:01 - 2017-09-06 08:01 - 000033193 _____ () C:\Users\Chuck\AppData\Roaming\UserTile.png
2014-03-18 15:30 - 2014-03-18 15:30 - 000000046 _____ () C:\Users\Chuck\AppData\Roaming\WB.CFG
2012-01-08 18:27 - 2022-08-12 20:26 - 000000173 _____ () C:\Users\Chuck\AppData\Local\msmathematics.qat.Chuck
2012-04-29 16:19 - 2022-09-01 09:18 - 000007655 _____ () C:\Users\Chuck\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2022-11-20 16:10
==================== End of FRST.txt ========================
Ran by Chuck (administrator) on CHUCK-PC (22-11-2022 15:30:48)
Running from D:\Sysnative Tools
Loaded Profiles: Chuck
Platform: Microsoft Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(cmd.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <20>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(services.exe ->) (Novawave Inc. -> Novawave Inc.) D:\System Tools\Novabench\NovabenchService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [9922800 2022-10-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-4060470119-733395135-3709892937-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [38650192 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-4060470119-733395135-3709892937-1001\...\Run: [cdloader] => C:\Users\Chuck\AppData\Roaming\mjusbsp\cdloader2.exe [58816 2018-04-05] (magicJack, L.P. -> magicJack L.P.)
HKU\S-1-5-21-4060470119-733395135-3709892937-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-4060470119-733395135-3709892937-1001\...\MountPoints2: E - E:\Autorun.exe
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\107.0.5304.107\Installer\chrmstp.exe [2022-11-10] (Google LLC -> Google LLC)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2014-02-19]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2016-01-08]
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass (Marvasol Inc) -> LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2016-01-08]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass (Marvasol Inc) -> LastPass)
GroupPolicyScripts: Restriction <==== ATTENTION
GroupPolicyScripts\User: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0429E07B-5A04-4599-AE23-8D75BE68FA72} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3728752 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0BFBD582-A478-4155-8DAA-71369737467D} - System32\Tasks\{B12163EC-2A0F-4DB6-B448-3F1E1C447C92} => msiexec.exe /package "D:\DownLoads\DebugDiagx64.msi"
Task: {0C91D2F3-72FB-4433-A17C-7B3E6EC5D0E2} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [1174016 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Task: {0DFECF84-7CFC-445D-8AE9-246936167FC1} - System32\Tasks\{69549C03-FFF0-4BFC-8B8D-B37887F8ECAE} => C:\Windows\system32\pcalua.exe -a E:\disk1\setup.exe -d E:\
Task: {13A94C32-AE2A-4DD1-8BD0-EDCB06CF227B} - System32\Tasks\{9BBC9E44-985F-4751-9E09-A1136DB25F47} => C:\Windows\system32\pcalua.exe -a D:\DownLoads\AdobeAIRInstaller_3.2.0.2070.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {1DA860CF-5DFE-4C1B-9C56-7C13DDF0F773} - \{08797947-0A0E-0C0C-7A11-040F0B78117F} -> No File <==== ATTENTION
Task: {24646530-7148-414B-A522-7667DBDD8F25} - System32\Tasks\{D79C03CB-3094-45B4-8EE1-04C9F9F008C0} => C:\Windows\system32\pcalua.exe -a D:\DownLoads\dotnetfx35setup(1).exe -d D:\DownLoads
Task: {32385522-1924-47A1-B4FF-D9CFE91CFDE4} - System32\Tasks\{41971C23-3C99-42C5-BCBB-92728124F03D} => C:\Windows\system32\pcalua.exe -a D:\DownLoads\winsdk_web.exe -d D:\DownLoads
Task: {38685812-E4BC-4DC9-BE86-6A659B4044E4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-11] (Google Inc -> Google Inc.)
Task: {4B06C3CF-BF80-464E-8E56-82713B5C4359} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-11-09] (Piriform Software Ltd -> Piriform)
Task: {51D784C5-4B12-48B3-B395-B49CAA5658E2} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {52E06A5E-382C-43C9-802C-4C46121B6131} - System32\Tasks\{C0CFCFB0-8193-46C5-A156-7F247046C33B} => C:\Windows\system32\pcalua.exe -a D:\DownLoads\SH-S223L_SB04.exe
Task: {5B43C5C0-0162-47A1-B3BF-B3D844877FF0} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5EB47497-0696-41FB-9FCC-5E7B6DBF383B} - System32\Tasks\{BD34E7F5-E78E-4B4D-BF34-27AFFD7428F0} => C:\Windows\system32\pcalua.exe -a "D:\System Tools\ProcessQuickLink 2\unins000.exe"
Task: {61F158BE-13BC-4C36-9D77-75474D232B20} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {6A232CB0-B3FF-46F0-9A87-1B7EAC41D8FE} - System32\Tasks\{E2B7E4FE-2714-4984-B7DC-98AF5995DB26} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe"
Task: {73BBBC78-6381-476A-8111-CEBFAD111923} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {78CA1312-8C29-47B5-8B55-44A0680BDEA7} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [849264 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7E7783EA-CC00-4D3D-852E-20DA977EAFF9} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [849264 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8DF32B52-D280-4121-BA6B-613A7B78B238} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [876912 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9F7D2AB7-57F6-424F-8698-94CDDE9A7A12} - System32\Tasks\{A8A659B3-0401-4CB6-B708-C17A88F05072} => C:\Windows\system32\pcalua.exe -a C:\Windows\system32\pcwrun.exe -c D:\Quicken\qw.exe
Task: {A20C5916-EA64-4DDD-A348-7A967B30D390} - System32\Tasks\Extend Health
Task: {AA35CA84-0159-480D-8323-45D76ECD2215} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [781680 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {AFD3D950-259A-4034-B1D3-36845A707AA7} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.)
Task: {B39BF604-F2EB-4A86-943E-65BD677F1B6C} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [590704 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C3E55553-2031-421D-A0E2-C96955E833A3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-11] (Google Inc -> Google Inc.)
Task: {C5891914-10A3-4098-B16E-AF25CD02FA67} - System32\Tasks\{9CDADED3-9866-456D-ADC7-8C3E92D1AF87} => C:\Windows\system32\pcalua.exe -a D:\DownLoads\MicroFrameworkSDK3_0.exe -d D:\DownLoads
Task: {DEAA4E96-0111-4470-9BD0-4DCE1A359495} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4669264 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "07b8aa54-ba8d-4f5e-a3e2-6288a9738815" --version "6.06.10144" --silent
Task: {EE3C39B2-4D9C-4BEC-9967-E03FADBA7BAA} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [781680 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {F3B06D00-3B07-457F-8AA4-3BFDF4254041} - System32\Tasks\CCleanerSkipUAC - Chuck => C:\Program Files\CCleaner\CCleaner.exe [32325456 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {F4CC5EEF-081F-4B57-832F-82BD681C0F87} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648048 2019-04-02] (NVIDIA Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{ACC1B417-2078-4C2B-9C53-80C2DD2F3295}: [DhcpNameServer] 192.168.1.1
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
FireFox:
========
FF DefaultProfile: u7cjq9be.default-1630423938134
FF ProfilePath: C:\Users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134 [2022-11-22]
FF Homepage: Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134 -> hxxps://my.yahoo.com/
FF Session Restore: Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134 -> is enabled.
FF Extension: (LastPass: Free Password Manager) - C:\Users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134\Extensions\support@lastpass.com.xpi [2022-11-19]
FF Extension: (uBlock Origin) - C:\Users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134\Extensions\uBlock0@raymondhill.net.xpi [2022-09-21]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\u7cjq9be.default-1630423938134\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2022-08-16]
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-01-08] (LastPass (Marvasol Inc) -> LastPass)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-01-08] (LastPass (Marvasol Inc) -> LastPass)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2022-11-14] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default [2022-11-22]
CHR Notifications: Default -> hxxps://askbobrankin.com; hxxps://mg.mail.yahoo.com; hxxps://news.yahoo.com; hxxps://www.askwoody.com; hxxps://www.facebook.com; hxxps://www.phone.instantcheckmate.com; hxxps://www.sendspace.com; hxxps://www.yahoo.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxp://my.yahoo.com/
CHR StartupUrls: Default -> "hxxps://my.yahoo.com/#"
CHR NewTab: Default -> Active:"chrome-extension://jonikckfpolfcdcgdficelkfffkloemh/n.html"
CHR Extension: (uBlock Origin) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2022-11-20]
CHR Extension: (Google Docs Offline) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-11-01]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2022-11-22]
CHR Extension: (Tabs to the Front) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiembaoomcehoiehhdldabfgnmphappc [2017-06-18]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2022-11-17]
CHR Extension: (Blank New Tab Page) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\jonikckfpolfcdcgdficelkfffkloemh [2017-04-27]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-01-23]
CHR Extension: (Plugins) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcblfncjaclajmegihojiekebofjcen [2021-11-24]
CHR Extension: (Popup my Bookmarks) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppflflkbbafeopeoeigkbbdjdbeifni [2020-11-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Profile: C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\System Profile [2022-11-21]
CHR HKU\S-1-5-21-4060470119-733395135-3709892937-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd]
CHR HKU\S-1-5-21-4060470119-733395135-3709892937-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. -> Adobe Inc.)
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1003344 2022-11-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
R2 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [11072008 2022-10-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8842536 2022-10-21] (Malwarebytes Inc. -> Malwarebytes)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
R2 NovabenchService; D:\System Tools\Novabench\NovabenchService.exe [1229808 2020-08-30] (Novawave Inc. -> Novawave Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] (ASUSTeK Computer Inc. -> )
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [158640 2022-06-22] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2014-12-07] (Martin Malik - REALiX -> REALiX(tm))
S3 JLTECH0227; C:\Windows\System32\Drivers\jl2005c.sys [80240 2010-05-18] (JEILIN TECHNOLOGIES CORPORATION -> Windows (R) Codename Longhorn DDK provider)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [223176 2022-11-19] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [193992 2022-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [75216 2022-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239544 2022-07-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [149432 2022-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] (ASUSTeK Computer Inc. -> )
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R3 NovabenchDriver; D:\System Tools\Novabench\NovabenchDriver.sys [27488 2018-05-27] (Novawave Inc. -> )
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [77824 2010-01-22] (Microsoft Windows Hardware Compatibility Publisher -> NEC Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [180224 2010-01-22] (Microsoft Windows Hardware Compatibility Publisher -> NEC Electronics Corporation)
R3 NVHDA; C:\Windows\System32\drivers\nvhda64v.sys [129960 2021-05-15] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
R3 nvlddmkm; C:\Windows\System32\DRIVERS\nvlddmkm.sys [38196648 2021-05-13] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [398112 2012-01-25] (Marvell Semiconductor -> Marvell)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-11-22 15:30 - 2022-11-22 15:31 - 000000000 ____D C:\FRST
2022-11-22 06:14 - 2022-11-22 06:14 - 000193992 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2022-11-22 06:14 - 2022-11-22 06:14 - 000149432 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2022-11-22 06:14 - 2022-11-22 06:14 - 000075216 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2022-11-19 20:10 - 2022-11-19 20:10 - 000223176 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2022-11-19 17:12 - 2022-11-19 17:12 - 000002157 _____ C:\Users\Chuck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk
2022-10-26 07:07 - 2022-10-26 07:07 - 000000930 _____ C:\Users\Public\Desktop\Firefox.lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-11-22 15:29 - 2022-07-15 19:32 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-11-22 15:29 - 2016-11-16 09:15 - 000000000 ____D C:\Users\Chuck\AppData\LocalLow\Mozilla
2022-11-22 15:29 - 2012-04-12 15:28 - 000000000 ____D C:\Program Files (x86)\Google
2022-11-22 12:25 - 2016-10-14 14:00 - 000000000 ____D C:\ProgramData\NVIDIA
2022-11-22 08:11 - 2020-09-17 13:54 - 000000000 ____D C:\Program Files\CCleaner
2022-11-22 06:32 - 2009-07-13 20:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2022-11-22 06:32 - 2009-07-13 20:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2022-11-22 06:16 - 2009-07-13 21:13 - 000832608 _____ C:\Windows\system32\PerfStringBackup.INI
2022-11-22 06:16 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\inf
2022-11-22 06:14 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\system32\inetsrv
2022-11-22 06:12 - 2009-07-13 21:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-11-21 20:24 - 2022-09-21 19:24 - 000000760 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2022-11-20 06:30 - 2016-10-22 08:47 - 000000000 ____D C:\Users\Chuck\AppData\Local\CrashDumps
2022-11-20 06:23 - 2012-04-24 08:00 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-11-19 17:13 - 2022-05-24 07:32 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-11-19 17:12 - 2022-05-24 07:32 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2022-11-19 17:12 - 2015-12-16 09:00 - 000006610 _____ C:\Windows\wininit.ini
2022-11-19 08:10 - 2022-09-11 19:18 - 000000000 ____D C:\Users\Chuck\AppData\Roaming\com.adobe.dunamis
2022-11-19 07:58 - 2009-07-13 21:08 - 000032548 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2022-11-18 12:04 - 2022-10-13 14:33 - 000002113 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2022-11-18 08:11 - 2022-09-21 19:24 - 000003352 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting
2022-11-18 08:11 - 2020-09-17 13:54 - 000003870 _____ C:\Windows\system32\Tasks\CCleaner Update
2022-11-10 20:07 - 2017-04-11 08:51 - 000002278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-11-09 08:14 - 2013-07-23 06:48 - 000000000 ____D C:\Windows\system32\MRT
2022-11-09 08:11 - 2012-01-03 16:51 - 146960040 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2022-10-28 19:10 - 2012-04-22 12:32 - 000000000 ____D C:\Users\Chuck\AppData\Roaming\mjusbsp
2022-10-28 15:42 - 2012-12-28 18:01 - 000000991 _____ C:\Users\Chuck\Desktop\magicJack.lnk
2022-10-28 15:42 - 2012-12-28 18:01 - 000000977 _____ C:\Users\Chuck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\magicJack.lnk
2022-10-28 15:25 - 2009-07-13 19:20 - 000000000 __RHD C:\Users\Public\Libraries
2022-10-28 07:51 - 2015-11-14 17:41 - 000000782 _____ C:\Users\Chuck\Desktop\Router Settings.txt
2022-10-27 14:15 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\system32\NDF
2022-10-26 07:07 - 2011-12-31 13:50 - 000000942 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-10-23 19:08 - 2022-10-13 14:33 - 000002101 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
==================== Files in the root of some directories ========
2013-06-28 05:37 - 2016-01-08 06:59 - 021382680 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2017-09-06 08:01 - 2017-09-06 08:01 - 000033193 _____ () C:\Users\Chuck\AppData\Roaming\UserTile.png
2014-03-18 15:30 - 2014-03-18 15:30 - 000000046 _____ () C:\Users\Chuck\AppData\Roaming\WB.CFG
2012-01-08 18:27 - 2022-08-12 20:26 - 000000173 _____ () C:\Users\Chuck\AppData\Local\msmathematics.qat.Chuck
2012-04-29 16:19 - 2022-09-01 09:18 - 000007655 _____ () C:\Users\Chuck\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2022-11-20 16:10
==================== End of FRST.txt ========================