start:: closeprocesses: createrestorepoint: AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AlternateDataStreams: C:\Users\pcpc\Application Data:fbd50e2f7662a5c33287ddc6e65ab5a1 [394] AlternateDataStreams: C:\Users\pcpc\AppData\Roaming:fbd50e2f7662a5c33287ddc6e65ab5a1 [394] IE trusted site: HKU\S-1-5-21-1685461111-408504773-3306633349-1001\...\webcompanion.com -> hxxp://webcompanion.com HKU\S-1-5-21-1685461111-408504773-3306633349-1001\...\StartupApproved\Run: => "Web Companion" HKU\S-1-5-21-1685461111-408504773-3306633349-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize C:\Program Files (x86)\Lavasoft HKU\S-1-5-21-1685461111-408504773-3306633349-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [34612864 2021-06-07] (Piriform Software Ltd -> Piriform Software Ltd) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION S0 FACEIT; \SystemRoot\System32\Drivers\FACEIT.sys [X] S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X] S3 VBAudioVMVAIOMME; \SystemRoot\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] cmd: DISM /Online /Cleanup-image /Restorehealth cmd: sfc /scannow cmd: netsh advfirewall reset emptytemp: end::