Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-08-2019 Ran by 12qun (administrator) on DESKTOP-7THS4O7 (Gigabyte Technology Co., Ltd. H55M-S2V) (19-08-2019 18:59:48) Running from C:\Users\12qun\OneDrive\Pulpit Loaded Profiles: 12qun (Available Profiles: 12qun) Platform: Windows 10 Pro Version 1903 18362.30 (X64) Language: English (United States) Default browser: Opera Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation -> Microsoft Corporation) C:\Users\12qun\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\usocoreworker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.30_none_788560eb0ef1f3b0\TiWorker.exe (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.) C:\Windows\V0790Mon.exe (Opera Software AS -> Opera Software) C:\Users\12qun\AppData\Local\Programs\Opera\62.0.3331.88\opera.exe (Opera Software AS -> Opera Software) C:\Users\12qun\AppData\Local\Programs\Opera\62.0.3331.88\opera.exe (Opera Software AS -> Opera Software) C:\Users\12qun\AppData\Local\Programs\Opera\62.0.3331.88\opera.exe (Opera Software AS -> Opera Software) C:\Users\12qun\AppData\Local\Programs\Opera\62.0.3331.88\opera.exe (Opera Software AS -> Opera Software) C:\Users\12qun\AppData\Local\Programs\Opera\62.0.3331.88\opera.exe (Opera Software AS -> Opera Software) C:\Users\12qun\AppData\Local\Programs\Opera\62.0.3331.88\opera.exe (Opera Software AS -> Opera Software) C:\Users\12qun\AppData\Local\Programs\Opera\62.0.3331.88\opera.exe (Opera Software AS -> Opera Software) C:\Users\12qun\AppData\Local\Programs\Opera\62.0.3331.88\opera.exe (Opera Software AS -> Opera Software) C:\Users\12qun\AppData\Local\Programs\Opera\62.0.3331.88\opera.exe (Opera Software AS -> Opera Software) C:\Users\12qun\AppData\Local\Programs\Opera\62.0.3331.88\opera_crashreporter.exe (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.35.152.0_x64__kzf8qxf38zg5c\SkypeApp.exe (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.35.152.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe (SoundMixer) [File not signed] C:\Users\12qun\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [V0790Mon.exe] => C:\Windows\V0790Mon.exe [41600 2015-09-17] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) HKU\S-1-5-21-156907257-2484602571-1260501974-1001\...\Winlogon: [Shell] %comspec% <==== ATTENTION HKU\S-1-5-21-156907257-2484602571-1260501974-1001\...\Command Processor: @mode 20,5 & tasklist /FI "IMAGENAME eq SoundMixer.exe" 2>NUL | find /I /N "SoundMixer.exe">NUL && exit & if exist "C:\Users\12qun\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" ( start /MIN "" "C:\Users\12qun\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" & tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) else ( tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) <==== ATTENTION Lsa: [Authentication Packages] msv1_0 SshdPinAuthLsa ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {12BEB902-C9EF-46DD-8F55-79900C30FBD0} - System32\Tasks\Microsoft\Windows\RetailDemo\CleanupOfflineContent => {61f77d5e-afe9-400b-a5e6-e9e80fc8e601} C:\Windows\System32\RDXTaskFactory.dll [415744 2019-03-19] (Microsoft Windows -> Microsoft Corporation) Task: {F10290D1-AC1E-4A88-8A35-3D8E29E94979} - System32\Tasks\Opera scheduled Autoupdate 1566199999 => C:\Users\12qun\AppData\Local\Programs\Opera\launcher.exe [1519640 2019-07-23] (Opera Software AS -> Opera Software) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1 Tcpip\..\Interfaces\{48a29ab1-b421-48f9-bd73-27c535747053}: [DhcpNameServer] 192.168.8.1 192.168.8.1 Internet Explorer: ================== ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [255472 2015-12-16] (Microsoft Windows Hardware Compatibility Publisher -> AMD) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5773592 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) S3 sshd; C:\Windows\System32\OpenSSH\sshd.exe [974848 2019-03-01] (Microsoft Windows -> ) S3 SshdBroker; C:\Windows\System32\SshdBroker.dll [290816 2019-03-18] (Microsoft Windows -> Microsoft Corporation) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-19] (Microsoft Corporation -> Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-19] (Microsoft Corporation -> Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [21648880 2015-12-16] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) R3 amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [674288 2015-12-16] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [662528 2019-03-19] (Microsoft Windows -> Realtek ) R3 V0790Vid; C:\Windows\system32\DRIVERS\V0790Vid.sys [390648 2015-09-17] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46472 2019-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [333784 2019-03-19] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [62432 2019-03-19] (Microsoft Windows -> Microsoft Corporation) R3 WinDivert1.1; C:\Users\12qun\OneDrive\Pulpit\Activation\Activation\wdvdriver\x64WDV\WinDivert.sys [35376 2019-08-19] (Nemea Mjukvaruutveckling AB -> Basil Projects) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-08-19 18:59 - 2019-08-19 18:59 - 000000000 ____D C:\FRST 2019-08-19 18:52 - 2019-08-19 18:52 - 000000000 ___HD C:\OneDriveTemp 2019-08-19 18:51 - 2019-08-19 18:51 - 000008192 __RSH C:\BOOTSECT.BAK 2019-08-19 18:51 - 2019-08-19 18:51 - 000000000 ____D C:\Users\12qun\AppData\Roaming\ATI 2019-08-19 18:51 - 2019-08-19 18:51 - 000000000 ____D C:\Users\12qun\AppData\Local\ATI 2019-08-19 18:51 - 2019-08-19 18:51 - 000000000 ____D C:\ProgramData\ATI 2019-08-19 18:51 - 2019-08-19 08:56 - 000000000 ____D C:\Windows\Panther 2019-08-19 18:51 - 2019-04-02 01:06 - 000409654 __RSH C:\bootmgr 2019-08-19 18:51 - 2019-03-19 06:44 - 000000001 ___SH C:\BOOTNXT 2019-08-19 18:47 - 2019-08-19 18:47 - 000001105 _____ C:\Users\12qun\AppData\Roaming\Microsoft\Windows\Start Menu\Forza.Horizon.4.Ultimate.Edition-LOOTBOX.lnk 2019-08-19 17:38 - 2019-08-19 17:38 - 000000000 __RSD C:\Windows\SysWOW64\WindowsDevicePortal 2019-08-19 17:38 - 2019-08-19 17:38 - 000000000 __RSD C:\Windows\system32\WindowsDevicePortal 2019-08-19 17:38 - 2019-08-19 17:38 - 000000000 ___RD C:\Windows\WebManagement 2019-08-19 17:38 - 2019-03-18 19:32 - 000516648 _____ (Microsoft Corporation) C:\Windows\system32\MicrosoftWebDriver.exe 2019-08-19 17:38 - 2019-03-18 18:27 - 000393768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MicrosoftWebDriver.exe 2019-08-19 17:38 - 2019-03-18 15:19 - 000111616 _____ (Microsoft Corporation) C:\Windows\system32\SshdPinAuthLsa.dll 2019-08-19 17:38 - 2019-03-18 15:19 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\DeployUtil.exe 2019-08-19 17:38 - 2019-03-18 15:19 - 000020480 _____ (Microsoft Corporation) C:\Windows\system32\DeveloperTools.ProxyStub.dll 2019-08-19 17:38 - 2019-03-18 15:18 - 000032768 _____ (Microsoft Corporation) C:\Windows\system32\debugregsvcapi.dll 2019-08-19 17:38 - 2019-03-18 15:17 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\DevToolsLauncher.exe 2019-08-19 17:38 - 2019-03-18 15:16 - 000296448 _____ (Microsoft Corporation) C:\Windows\system32\PerceptionSimulationREST.dll 2019-08-19 17:38 - 2019-03-18 15:16 - 000290816 _____ (Microsoft Corporation) C:\Windows\system32\SshdBroker.dll 2019-08-19 17:38 - 2019-03-18 15:16 - 000174080 _____ (Microsoft Corporation) C:\Windows\system32\DeveloperToolsSvc.exe 2019-08-19 17:38 - 2019-03-18 15:15 - 000101888 _____ (Microsoft Corporation) C:\Windows\system32\DeveloperSetupCSP.dll 2019-08-19 17:38 - 2019-03-18 15:13 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\debugregsvc.dll 2019-08-19 17:38 - 2019-03-18 15:12 - 000960512 _____ (Microsoft Corporation) C:\Windows\system32\wdp.dll 2019-08-19 17:38 - 2019-03-18 15:09 - 001359872 _____ (Microsoft Corporation) C:\Windows\system32\WebManagement.exe 2019-08-19 17:38 - 2019-03-18 15:02 - 000637952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdp.dll 2019-08-19 15:52 - 2019-08-19 15:52 - 000000000 ____D C:\Users\12qun\AppData\Roaming\WinRAR 2019-08-19 15:51 - 2019-08-19 15:52 - 000000000 ____D C:\Program Files\WinRAR 2019-08-19 15:51 - 2019-08-19 15:51 - 000000000 ____D C:\Users\12qun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2019-08-19 15:51 - 2019-08-19 15:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2019-08-19 15:48 - 2019-08-19 15:48 - 000000000 ____D C:\Users\12qun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView 2019-08-19 15:48 - 2019-08-19 15:48 - 000000000 ____D C:\Users\12qun\AppData\Roaming\IrfanView 2019-08-19 15:48 - 2019-08-19 15:48 - 000000000 ____D C:\Program Files\IrfanView 2019-08-19 15:42 - 2019-08-19 15:43 - 000000000 ____D C:\Program Files (x86)\WinRAR 2019-08-19 15:35 - 2019-08-19 15:37 - 000000000 ____D C:\Users\12qun\AppData\Roaming\AIMP 2019-08-19 15:35 - 2019-08-19 15:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP 2019-08-19 15:34 - 2019-08-19 15:34 - 000000000 ____D C:\Program Files (x86)\AIMP 2019-08-19 15:30 - 2019-08-19 15:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2019-08-19 15:29 - 2019-08-19 15:29 - 000000000 ____D C:\Program Files\VideoLAN 2019-08-19 14:26 - 2019-08-19 11:17 - 000741432 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2019-08-19 09:33 - 2019-08-19 09:33 - 000004206 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1566199999 2019-08-19 09:33 - 2019-08-19 09:33 - 000001393 _____ C:\Users\12qun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk 2019-08-19 09:33 - 2019-08-19 09:33 - 000000000 ____D C:\Users\12qun\AppData\Local\Opera Software 2019-08-19 09:31 - 2019-08-19 09:31 - 000000000 ____D C:\Users\12qun\AppData\Roaming\Opera Software 2019-08-19 09:31 - 2019-08-19 09:31 - 000000000 ____D C:\Users\12qun\AppData\Local\D3DSCache 2019-08-19 09:30 - 2019-08-19 09:30 - 000000000 ____D C:\Users\12qun\AppData\Local\PlaceholderTileLogoFolder 2019-08-19 09:27 - 2019-08-19 09:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2019-08-19 09:27 - 2019-08-19 09:27 - 000000000 ____D C:\Program Files\ATI Technologies 2019-08-19 09:26 - 2019-08-19 09:27 - 000000000 ____D C:\Program Files (x86)\ATI Technologies 2019-08-19 09:26 - 2019-08-19 09:26 - 000000000 ____D C:\ProgramData\Package Cache 2019-08-19 09:26 - 2015-09-17 02:57 - 001983736 _____ (Creative Technology Ltd.) C:\Windows\system32\V0790Afx64.dll 2019-08-19 09:26 - 2015-09-17 02:56 - 000400904 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\V0790Afx.sys 2019-08-19 09:26 - 2015-09-17 02:56 - 000390648 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\V0790Vid.sys 2019-08-19 09:26 - 2015-09-17 02:56 - 000130552 _____ (Creative Technology Ltd.) C:\Windows\system32\V0790Ext.ax 2019-08-19 09:26 - 2015-09-17 02:56 - 000123400 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\V0790Ext.ax 2019-08-19 09:26 - 2015-09-17 02:56 - 000120824 _____ (Creative Technology Ltd.) C:\Windows\CtDrvIns.exe 2019-08-19 09:26 - 2015-09-17 02:56 - 000111112 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\V0790Ext.crl 2019-08-19 09:26 - 2015-09-17 02:56 - 000103416 _____ (Creative Technology Ltd.) C:\Windows\system32\V0790Ext.crl 2019-08-19 09:26 - 2015-09-17 02:56 - 000075888 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\V0790Pin.dll 2019-08-19 09:26 - 2015-09-17 02:56 - 000075256 _____ (Creative Technology Ltd.) C:\Windows\system32\V0790Pin.dll 2019-08-19 09:26 - 2015-09-17 02:56 - 000034808 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\CtCamPin.crl 2019-08-19 09:26 - 2015-09-17 02:56 - 000027128 _____ (Creative Technology Ltd.) C:\Windows\system32\CtCamPin.crl 2019-08-19 09:26 - 2015-09-17 02:53 - 000041600 _____ (Creative Technology Ltd.) C:\Windows\V0790Mon.exe 2019-08-19 09:26 - 2015-09-17 02:43 - 000057656 _____ C:\Windows\system32\Drivers\V0790PC.bmp 2019-08-19 09:26 - 2015-09-17 02:43 - 000004402 _____ C:\Windows\VF0790.uns 2019-08-19 09:25 - 2019-08-19 09:25 - 000000000 ____D C:\Program Files\Common Files\ATI Technologies 2019-08-19 09:25 - 2019-08-19 09:25 - 000000000 ____D C:\Program Files\AMD 2019-08-19 09:25 - 2019-08-19 09:25 - 000000000 ____D C:\AMD 2019-08-19 09:25 - 2019-08-19 09:25 - 000000000 _____ C:\Windows\ativpsrm.bin 2019-08-19 09:19 - 2019-08-19 18:47 - 000000000 ____D C:\Program Files (x86)\Forza.Horizon.4.Ultimate.Edition-LOOTBOX 2019-08-19 09:18 - 2019-08-19 09:18 - 000000000 ____D C:\Users\12qun\AppData\Local\OneDrive 2019-08-19 09:17 - 2019-08-19 18:56 - 000000000 ____D C:\Users\12qun\AppData\Local\Comms 2019-08-19 09:16 - 2019-08-19 09:17 - 000000000 ____D C:\ProgramData\Packages 2019-08-19 09:13 - 2019-08-19 18:52 - 000000000 ___RD C:\Users\12qun\OneDrive 2019-08-19 09:13 - 2019-08-19 09:18 - 000003378 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-156907257-2484602571-1260501974-1001 2019-08-19 09:12 - 2019-08-19 09:12 - 000000000 ____D C:\ProgramData\Microsoft OneDrive 2019-08-19 09:11 - 2019-08-19 09:11 - 000000000 ___HD C:\Users\12qun\MicrosoftEdgeBackups 2019-08-19 09:11 - 2019-08-19 09:11 - 000000000 ____D C:\Users\12qun\AppData\Local\Publishers 2019-08-19 09:11 - 2019-08-19 09:11 - 000000000 ____D C:\Users\12qun\AppData\Local\MicrosoftEdge 2019-08-19 09:10 - 2019-08-19 18:54 - 000000000 ____D C:\Users\12qun\AppData\Local\Packages 2019-08-19 09:10 - 2019-08-19 09:15 - 000000000 ____D C:\Users\12qun\AppData\Local\ConnectedDevicesPlatform 2019-08-19 09:10 - 2019-08-19 09:10 - 000000000 __RHD C:\Users\Public\AccountPictures 2019-08-19 09:10 - 2019-08-19 09:10 - 000000000 ___RD C:\Users\12qun\3D Objects 2019-08-19 09:10 - 2019-08-19 09:10 - 000000000 ____D C:\Users\12qun\AppData\Roaming\Adobe 2019-08-19 09:10 - 2019-08-19 09:10 - 000000000 ____D C:\Users\12qun\AppData\Local\VirtualStore 2019-08-19 09:08 - 2019-08-19 09:30 - 000795988 _____ C:\Windows\system32\PerfStringBackup.INI 2019-08-19 09:06 - 2019-08-19 09:18 - 000002363 _____ C:\Users\12qun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2019-08-19 09:06 - 2019-08-19 09:18 - 000000000 ____D C:\Users\12qun 2019-08-19 09:06 - 2019-08-19 09:06 - 000000020 ___SH C:\Users\12qun\ntuser.ini 2019-08-19 09:01 - 2019-08-19 09:01 - 000000000 ____D C:\Windows\minidump 2019-08-19 09:01 - 2019-08-19 09:01 - 000000000 ____D C:\Windows\CSC 2019-08-19 08:58 - 2019-08-19 08:58 - 000000000 _SHDL C:\Documents and Settings 2019-08-19 08:56 - 2019-08-19 08:56 - 000000000 ____D C:\ProgramData\USOShared 2019-08-19 08:55 - 2019-03-19 06:43 - 002873856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll 2019-08-19 08:53 - 2019-08-19 08:53 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2019-08-19 08:52 - 2019-08-19 17:33 - 000000000 ____D C:\Windows\system32\SleepStudy 2019-08-19 08:52 - 2019-08-19 09:04 - 000257824 _____ C:\Windows\system32\FNTCACHE.DAT 2019-08-19 08:52 - 2019-08-19 09:04 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-08-19 08:52 - 2019-08-19 08:52 - 000000000 ____D C:\Windows\system32\Drivers\wd 2019-08-19 08:52 - 2019-08-19 08:52 - 000000000 ____D C:\Windows\ServiceProfiles ==================== One month (modified) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-08-19 18:51 - 2019-03-19 06:49 - 000028672 _____ C:\Windows\system32\config\BCD-Template 2019-08-19 18:47 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-08-19 17:57 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\AppReadiness 2019-08-19 17:39 - 2019-03-19 06:37 - 000000000 ____D C:\Windows\CbsTemp 2019-08-19 17:38 - 2019-03-19 08:21 - 000000000 ____D C:\Windows\system32\OpenSSH 2019-08-19 17:38 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\SystemApps 2019-08-19 16:45 - 2019-03-19 06:37 - 000000000 ____D C:\Windows\servicing 2019-08-19 09:30 - 2019-03-19 06:50 - 000000000 ____D C:\Windows\INF 2019-08-19 09:17 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps 2019-08-19 09:17 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\ServiceState 2019-08-19 09:06 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\WinBioDatabase 2019-08-19 09:06 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\USOPrivate 2019-08-19 09:02 - 2019-03-19 06:37 - 000524288 _____ C:\Windows\system32\config\BBI 2019-08-19 09:01 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\spool 2019-08-19 09:01 - 2019-03-19 06:52 - 000000000 ____D C:\Windows\system32\FxsTmp 2019-08-19 08:54 - 2019-03-19 06:52 - 000000000 ___RD C:\Windows\PrintDialog 2019-08-19 08:54 - 2019-03-19 06:52 - 000000000 ___RD C:\Windows\ImmersiveControlPanel 2019-08-19 08:53 - 2019-03-19 06:37 - 000032768 _____ C:\Windows\system32\config\ELAM ==================== SigCheck =============================== (There is no automatic fix for files that do not pass verification.) ATTENTION: ==> Could not access BCD. -> 0 ==================== End of FRST.txt ============================