Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-08-2019
Ran by Ana (administrator) on ANA-PC (SAMSUNG ELECTRONICS CO., LTD. 305V4A/305V5A/3415VA) (22-08-2019 21:01:05)
Running from C:\Users\Ana\Desktop
Loaded Profiles: Ana (Available Profiles: Ana)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Español (España, internacional)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(AppEx Networks Corporation -> AppEx Networks Corporation) C:\Program Files\AMD Quick Stream\AMDQuickStream.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc. -> Apple, Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe
(Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Atheros Communications Inc. -> Atheros Communications) [File not signed] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Communications Inc. -> Atheros) [File not signed] C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(CyberLink -> ) [File not signed] C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(CyberLink -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(CyberLink -> CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink -> CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Company -> ArcSoft, Inc.) C:\Users\Ana\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\avpui.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Nota Inc. -> Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(pdfforge GmbH -> © pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) [File not signed] C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\EasySpeedUpManager.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics) [File not signed] C:\Program Files (x86)\Samsung\Eco Mode\SmartEco.exe
(Samsung Electronics CO., LTD. -> SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
(Samsung Electronics CO., LTD. -> SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11895400 2011-06-25] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [790688 2011-06-15] (Atheros Communications Inc. -> Atheros Communications) [File not signed]
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [657568 2011-06-15] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-13] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-05-07] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [912776 2019-08-01] (Nota Inc. -> Nota Inc.)
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [46993264 2019-06-27] (Google LLC -> )
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2019-05-08] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2019-05-08] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2019-05-08] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\Run: [Spotify] => C:\Users\Ana\AppData\Roaming\Spotify\Spotify.exe [25828256 2019-08-02] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [488640 2015-04-06] (AppEx Networks Corporation -> AppEx Networks Corporation)
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19589208 2018-12-10] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2019-05-08] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\MountPoints2: {2cee3b63-0b22-11e2-a7e8-e8039a8082d3} - F:\HPLauncher.exe
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\MountPoints2: {b4c82a67-cdcd-11e7-87a3-e8039a8082d3} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\...\MountPoints2: {cb384ac6-56fb-11e5-902d-e8039a8082d3} - F:\setup.exe
HKU\S-1-5-21-1231317149-393754485-1902646098-1000\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKLM\...\Drivers32: [VIDC.FPS1] => C:\windows\system32\frapsv64.dll [71680 2013-02-26] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [vidc.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [155648 2004-12-20] () [File not signed]
HKLM\...\Drivers32: [vidc.dvsd] => C:\Windows\SysWOW64\pdvcodec.dll [265797 2010-03-12] (Matsushita Electric Industrial Co., Ltd.) [File not signed]
HKLM\...\Drivers32: [vidc.VP60] => C:\windows\SysWOW64\vp6vfw.dll [442368 2005-02-26] (On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP61] => C:\windows\SysWOW64\vp6vfw.dll [442368 2005-02-26] (On2.com) [File not signed]
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [65536 2013-02-26] (Beepa P/L) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\windows\system32\cmd.exe /D /C start C:\windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.100\Installer\chrmstp.exe [2019-08-08] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\windows\system32\cmd.exe /D /C start C:\windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2011-03-28] (Microsoft Corporation -> Microsoft Corp.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {05142308-AEA3-426C-B276-11CD57252671} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\Overseer.exe [2045832 2019-08-20] (AVAST Software s.r.o. -> AVAST Software)
Task: {39A7EB5C-59F5-4003-AEC8-062395A9003A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [14636224 2018-12-10] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {3EC8477E-4C56-4ABF-8A2E-876ECE06FB7F} - \EPUpdater -> No File <==== ATTENTION
Task: {6B13C1FB-CCDD-4606-94D6-BC194C921057} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-09-14] (Google Inc -> Google Inc.)
Task: {75E6C989-5165-4EDD-82EB-5A9CC54005C5} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [4399696 2011-03-29] (Samsung Electronics CO., LTD. -> SEC)
Task: {8E8A1F14-E616-4977-940A-37DAAF20EBC5} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe [775848 2011-02-16] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) [File not signed]
Task: {970B8590-D99F-4DA0-AB85-81BDFD991EC4} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6785448 2019-08-01] (Nota Inc. -> Nota Inc.)
Task: {A2A55F13-8230-4004-B906-35D9F5EEFA65} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe [2213968 2011-06-04] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {AF3A331E-BAD3-4631-BA9E-9930CE472450} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-09-14] (Google Inc -> Google Inc.)
Task: {B25AA6A2-1878-466F-96BD-4EC102FE1193} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2782064 2011-01-12] (Samsung Electronics CO., LTD. -> Samsung Electronics)
Task: {B635957A-938C-4D8B-B497-CB5D8DA020A1} - \BrowserDefendert -> No File <==== ATTENTION
Task: {BD09A8C9-4AE0-42EF-8E74-6F376DE46510} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {C2421444-0EB6-489E-AB89-4540DDDD85E9} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6785448 2019-08-01] (Nota Inc. -> Nota Inc.)
Task: {C2C1471B-3C53-4CFA-8968-975C81A9F121} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe [2158160 2011-06-15] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {C8D338A7-0AF5-4DC9-AEBC-7FE2109FC582} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [3398736 2011-09-04] (Samsung Electronics CO., LTD. -> SAMSUNG Electronics)
Task: {C9A48647-3938-4242-A922-87655C713DA6} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-08-17] (CyberLink -> CyberLink)
Task: {D00F3BB1-CA74-41AD-988D-BCF14026DD0B} - System32\Tasks\EcoMode => C:\Program Files (x86)\Samsung\Eco Mode\SmartEco.exe [3870112 2011-06-06] (Samsung Electronics CO., LTD. -> Samsung Electronics) [File not signed]
Task: {D0D33214-2833-486F-BA95-A57F735FC105} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-08-20] (Adobe Inc. -> Adobe)
Task: {D206D0B7-2490-4C84-8D11-5030C0A5DD30} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {DEF2127F-45A2-45D6-8315-E6BB24D637A9} - System32\Tasks\SvcDelay => C:\windows\temp\SvcDelay.exe <==== ATTENTION
Task: {E55CF88C-0EBF-4169-A47A-16494F3123C1} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {F5A982A4-C3B0-4078-BB46-32DBE7672422} - System32\Tasks\SCCSpeedBoot => Command(1): "%programfiles(x86)%\Samsung\Samsung Control Center\SCCSpeedBoot.exe" -> /s
Task: {F5A982A4-C3B0-4078-BB46-32DBE7672422} - System32\Tasks\SCCSpeedBoot => Command(2): C:\Program Files (x86)\Samsung\Samsung Control Center\EasySpeedUpManager.exe [727120 [727120 2011-04-14]] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
Task: {F68F1B8D-3CBA-4389-80EE-E9686121F17E} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Samsung Control Center\EBM\EasyBatteryMgr4.exe [1701456 2011-05-09] (Samsung Electronics CO., LTD. -> SAMSUNG Electronics co., LTD.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 80.58.61.250 80.58.61.254
Tcpip\..\Interfaces\{6F42BB7F-991B-4DA8-8216-75A04656AD0F}: [DhcpNameServer] 80.58.61.250 80.58.61.254
Tcpip\..\Interfaces\{F2147347-DDF4-4D9D-A09E-B48D48DBA9E2}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
BHO: Kaspersky Protection -> {0E2877D3-2641-4970-B794-A553E295428D} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\IEExt\ie_plugin.dll [2019-05-24] (Kaspersky Lab -> AO Kaspersky Lab)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: Kaspersky Protection -> {0E2877D3-2641-4970-B794-A553E295428D} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\IEExt\ie_plugin.dll [2019-05-24] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-06-15] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: Samsung BHO Class -> {AA609D72-8482-4076-8991-8CDAE5B93BCB} -> C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll [2010-10-25] () [File not signed]
Toolbar: HKLM - Kaspersky Protection Toolbar - {4853DF44-7D6B-48E9-9258-D800EEE54AF6} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\IEExt\ie_plugin.dll [2019-05-24] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {4853DF44-7D6B-48E9-9258-D800EEE54AF6} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\IEExt\ie_plugin.dll [2019-05-24] (Kaspersky Lab -> AO Kaspersky Lab)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
FireFox:
========
FF ProfilePath: C:\Users\Ana\AppData\Roaming\Mozilla\Firefox\Profiles\5s6tjayi.default-1442222326095 [2019-08-22]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\FFExt\light_plugin_firefox\addon.xpi [2019-05-24]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-17] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-17] (Google Inc -> Google LLC)
FF Plugin HKU\S-1-5-21-1231317149-393754485-1902646098-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\Ana\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-10-10] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default [2019-08-22]
CHR Extension: (Google Drive) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-19]
CHR Extension: (YouTube) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Búsqueda de Google) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-30]
CHR Extension: (Botón Guardar de Pinterest) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2019-08-22]
CHR Extension: (Player para ver Movistar+) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\kenfcfndncbbggmafjjeihkdclggbojn [2019-03-13]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-11-18]
CHR Extension: (Kaspersky Protection) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\mchjnmdbdlkdbfliogedbnpnanfjnolk [2018-02-21]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-05]
CHR Extension: (Gmail) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-07]
CHR Extension: (Chrome Media Router) - C:\Users\Ana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-08]
CHR HKLM\...\Chrome\Extension: [mchjnmdbdlkdbfliogedbnpnanfjnolk] - hxxps://chrome.google.com/webstore/detail/mchjnmdbdlkdbfliogedbnpnanfjnolk
CHR HKU\S-1-5-21-1231317149-393754485-1902646098-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Ana\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2015-11-18]
CHR HKU\S-1-5-21-1231317149-393754485-1902646098-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mchjnmdbdlkdbfliogedbnpnanfjnolk] - hxxps://chrome.google.com/webstore/detail/mchjnmdbdlkdbfliogedbnpnanfjnolk
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD External Events Utility; C:\windows\system32\atiesrxx.exe [246784 2015-08-04] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-06-15] (Atheros Communications Inc. -> Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [91296 2011-06-15] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
R2 AVP18.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\avp.exe [354672 2017-01-24] (Kaspersky Lab -> AO Kaspersky Lab)
R2 BackupService; C:\Users\Ana\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe [83512 2010-07-01] (Hewlett-Packard Company -> ArcSoft, Inc.)
S3 klvssbridge64_18.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\vssbridge64.exe [424080 2019-05-24] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119176 2017-01-14] (Electronic Arts, Inc. -> Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2181648 2017-01-14] (Electronic Arts, Inc. -> Electronic Arts)
R2 PDF Architect 5 Manager; C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe [985904 2017-02-01] (pdfforge GmbH -> © pdfforge GmbH.)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] (CyberLink -> ) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdkmdag; C:\windows\System32\DRIVERS\atikmdag.sys [21622784 2015-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\windows\System32\DRIVERS\atikmpag.sys [665088 2015-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R0 amd_sata; C:\windows\System32\DRIVERS\amd_sata.sys [79488 2011-06-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R0 amd_xata; C:\windows\System32\DRIVERS\amd_xata.sys [40064 2011-06-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
S3 Apowersoft_AudioDevice; C:\windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2014-04-09] (APOWERSOFT LIMITED -> Wondershare)
R2 APXACC; C:\windows\System32\DRIVERS\appexDrv.sys [229056 2015-04-03] (AppEx Networks Corporation -> AppEx Networks Corporation)
R3 athr; C:\windows\System32\DRIVERS\athrx.sys [2797056 2011-12-13] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\windows\System32\drivers\AtihdW76.sys [104976 2016-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R3 clwvd; C:\windows\System32\DRIVERS\clwvd.sys [31216 2011-08-17] (CyberLink -> CyberLink Corporation)
R0 cm_km; C:\windows\System32\DRIVERS\cm_km.sys [247008 2016-12-26] (Kaspersky Lab -> AO Kaspersky Lab)
S3 dtlitescsibus; C:\windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-09-09] (Disc Soft Ltd -> Disc Soft Ltd)
R0 kl1; C:\windows\System32\DRIVERS\kl1.sys [554408 2016-10-01] (Kaspersky Lab -> AO Kaspersky Lab)
R0 klbackupdisk; C:\windows\System32\DRIVERS\klbackupdisk.sys [70880 2017-12-24] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\windows\System32\DRIVERS\klbackupflt.sys [119608 2019-05-24] (Kaspersky Lab -> AO Kaspersky Lab)
R2 kldisk; C:\windows\System32\DRIVERS\kldisk.sys [85704 2018-07-25] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klflt; C:\windows\System32\DRIVERS\klflt.sys [206024 2018-05-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klhk; C:\windows\System32\DRIVERS\klhk.sys [1093248 2019-05-24] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLIF; C:\windows\System32\DRIVERS\klif.sys [1075024 2019-05-24] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLIM6; C:\windows\System32\DRIVERS\klim6.sys [56520 2018-05-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\windows\System32\DRIVERS\klkbdflt.sys [57568 2016-12-23] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\windows\System32\DRIVERS\klmouflt.sys [58592 2016-12-07] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\windows\System32\DRIVERS\klpd.sys [50672 2017-12-24] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kltdi; C:\windows\System32\DRIVERS\kltdi.sys [81904 2017-12-24] (Kaspersky Lab -> AO Kaspersky Lab)
R1 Klwtp; C:\windows\System32\DRIVERS\klwtp.sys [141952 2019-05-24] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\windows\System32\DRIVERS\kneps.sys [199392 2017-12-24] (Kaspersky Lab -> AO Kaspersky Lab)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-02-14] (Realtek Semiconductor Corp -> Windows (R) 2003 DDK 3790 provider)
R1 SABI; C:\windows\system32\Drivers\SABI.sys [13824 2009-05-28] (Microsoft Windows Hardware Compatibility Publisher -> SAMSUNG ELECTRONICS)
S3 USBAAPL64; C:\windows\System32\Drivers\usbaapl64.sys [54784 2015-06-17] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 mbamchameleon; \??\C:\windows\system32\drivers\mbamchameleon.sys [X]
S3 MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 SBIOSIO; \??\C:\Users\Ana\AppData\Local\Temp\__Samsung_Update\SBIOSIO64.sys [X] <==== ATTENTION
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-08-22 21:01 - 2019-08-22 21:04 - 000033281 _____ C:\Users\Ana\Desktop\FRST.txt
2019-08-22 21:00 - 2019-08-22 21:01 - 000000000 ____D C:\FRST
2019-08-22 20:57 - 2019-08-22 20:57 - 001612800 _____ (Farbar) C:\Users\Ana\Desktop\FRST64.exe
2019-08-22 16:38 - 2019-08-22 16:38 - 000000000 ___RD C:\Users\Ana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2019-08-22 12:09 - 2019-08-06 00:58 - 000397432 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2019-08-22 12:09 - 2019-08-05 23:55 - 000348800 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2019-08-22 12:09 - 2019-08-04 04:02 - 000048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2019-08-22 12:09 - 2019-08-04 03:51 - 000144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2019-08-22 12:09 - 2019-08-04 03:51 - 000116224 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2019-08-22 12:09 - 2019-08-04 03:43 - 000969216 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2019-08-22 12:09 - 2019-08-04 03:34 - 000077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2019-08-22 12:09 - 2019-08-04 03:21 - 020291584 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2019-08-22 12:09 - 2019-08-04 03:14 - 000728064 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2019-08-22 12:09 - 2019-08-04 03:04 - 000496128 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2019-08-22 12:09 - 2019-08-04 03:03 - 000062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2019-08-22 12:09 - 2019-08-04 03:00 - 002301952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2019-08-22 12:09 - 2019-08-04 02:57 - 000030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2019-08-22 12:09 - 2019-08-04 02:54 - 000115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2019-08-22 12:09 - 2019-08-04 02:50 - 001566208 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2019-08-22 12:09 - 2019-08-04 02:41 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2019-08-22 12:09 - 2019-08-04 02:40 - 000091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2019-08-22 12:09 - 2019-08-04 02:37 - 000076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2019-08-22 12:09 - 2019-08-04 02:36 - 000279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2019-08-22 12:09 - 2019-08-04 02:28 - 002058752 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2019-08-22 12:09 - 2019-08-04 02:28 - 000696320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2019-08-22 12:09 - 2019-08-04 02:06 - 001331200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2019-08-22 12:08 - 2019-08-04 05:37 - 025754624 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2019-08-22 12:08 - 2019-08-04 04:16 - 002724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2019-08-22 12:08 - 2019-08-04 04:16 - 000004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2019-08-22 12:08 - 2019-08-04 04:04 - 002909184 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2019-08-22 12:08 - 2019-08-04 04:03 - 000066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2019-08-22 12:08 - 2019-08-04 04:02 - 000578560 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2019-08-22 12:08 - 2019-08-04 04:02 - 000417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2019-08-22 12:08 - 2019-08-04 04:01 - 000088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2019-08-22 12:08 - 2019-08-04 03:55 - 000054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2019-08-22 12:08 - 2019-08-04 03:54 - 005775872 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2019-08-22 12:08 - 2019-08-04 03:54 - 000034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2019-08-22 12:08 - 2019-08-04 03:52 - 000615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2019-08-22 12:08 - 2019-08-04 03:51 - 000790528 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2019-08-22 12:08 - 2019-08-04 03:50 - 000814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2019-08-22 12:08 - 2019-08-04 03:40 - 000489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2019-08-22 12:08 - 2019-08-04 03:33 - 000107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2019-08-22 12:08 - 2019-08-04 03:33 - 000087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2019-08-22 12:08 - 2019-08-04 03:30 - 000199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2019-08-22 12:08 - 2019-08-04 03:29 - 000092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2019-08-22 12:08 - 2019-08-04 03:27 - 000315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2019-08-22 12:08 - 2019-08-04 03:25 - 000152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2019-08-22 12:08 - 2019-08-04 03:16 - 000262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2019-08-22 12:08 - 2019-08-04 03:15 - 002724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2019-08-22 12:08 - 2019-08-04 03:14 - 000809472 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2019-08-22 12:08 - 2019-08-04 03:12 - 002132480 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2019-08-22 12:08 - 2019-08-04 03:12 - 001359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2019-08-22 12:08 - 2019-08-04 03:11 - 015390720 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2019-08-22 12:08 - 2019-08-04 03:03 - 000341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2019-08-22 12:08 - 2019-08-04 03:03 - 000047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2019-08-22 12:08 - 2019-08-04 03:02 - 000064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2019-08-22 12:08 - 2019-08-04 03:01 - 004859392 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2019-08-22 12:08 - 2019-08-04 02:57 - 000047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2019-08-22 12:08 - 2019-08-04 02:55 - 000476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2019-08-22 12:08 - 2019-08-04 02:54 - 000663040 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2019-08-22 12:08 - 2019-08-04 02:53 - 000620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2019-08-22 12:08 - 2019-08-04 02:45 - 000416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2019-08-22 12:08 - 2019-08-04 02:41 - 000073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2019-08-22 12:08 - 2019-08-04 02:40 - 000800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2019-08-22 12:08 - 2019-08-04 02:38 - 000168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2019-08-22 12:08 - 2019-08-04 02:35 - 000130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2019-08-22 12:08 - 2019-08-04 02:32 - 004494848 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2019-08-22 12:08 - 2019-08-04 02:29 - 000230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2019-08-22 12:08 - 2019-08-04 02:27 - 001155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2019-08-22 12:08 - 2019-08-04 02:23 - 013791744 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2019-08-22 12:08 - 2019-08-04 02:09 - 004387840 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2019-08-22 12:08 - 2019-08-04 02:04 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2019-08-22 12:08 - 2019-07-30 04:25 - 000627424 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2019-08-22 12:08 - 2019-07-30 04:23 - 005552568 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2019-08-22 12:08 - 2019-07-30 04:23 - 000710072 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2019-08-22 12:08 - 2019-07-30 04:23 - 000264120 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
2019-08-22 12:08 - 2019-07-30 04:23 - 000155576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2019-08-22 12:08 - 2019-07-30 04:23 - 000097208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2019-08-22 12:08 - 2019-07-30 04:22 - 001671000 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 002072576 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 001472512 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 001211392 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 001162752 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000878080 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000733184 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000517632 _____ (Microsoft Corporation) C:\windows\system32\rpcss.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000408576 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000361984 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000317440 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000236032 _____ (Microsoft Corporation) C:\windows\system32\srvsvc.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000094208 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000026112 _____ (Microsoft Corporation) C:\windows\system32\oleres.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2019-08-22 12:08 - 2019-07-30 04:20 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\sscore.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 004058848 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2019-08-22 12:08 - 2019-07-30 04:19 - 003965664 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2019-08-22 12:08 - 2019-07-30 04:19 - 000880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000008704 _____ (Microsoft Corporation) C:\windows\system32\comcat.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000007168 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2019-08-22 12:08 - 2019-07-30 04:19 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll