Re-run
Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.
- Double click to run it.
- Press Scan button.
- Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-07-2022
Ran by Unknown (administrator) on RAZ (Gigabyte Technology Co., Ltd. Z370P D3) (23-07-2022 18:49:51)
Running from C:\Users\Unknown\Downloads
Loaded Profiles: Unknown
Platform: Microsoft Windows 10 Pro Version 21H2 19044.1826 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Discord Inc. -> Discord Inc.) C:\Users\Unknown\AppData\Local\Discord\app-1.0.9005\Discord.exe <6>
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(explorer.exe ->) (F.lux Software LLC -> f.lux Software LLC) C:\Users\Unknown\AppData\Local\FluxSoftware\Flux\flux.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(explorer.exe ->) (VS Revo Group Ltd. -> VS Revo Group) C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe
(GIGA-BYTE TECHNOLOGY CO., LTD. -> ) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe
(GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\GraphicsCardEngine.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler64.exe
(IObit CO., LTD -> IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe
(services.exe ->) (Adobe Systems Incorporated -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe
(services.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft) C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_ba273d0ffb93e225\RstMwService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService_IObitDel_IObitDel.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (nordvpn s.a. -> TEFINCOM S.A.) C:\Program Files\NordUpdater\NordUpdateService.exe
(services.exe ->) (nordvpn s.a. -> TEFINCOM S.A.) C:\Program Files\NordVPN\nordvpn-service.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_246e95e4066041ad\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_85cff5320735903d\RtkAudUService64.exe <2>
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(svchost.exe ->) (CoderBag, LLC -> Coderbag) C:\Program Files\QuickCPU\QuickCPU.exe
(svchost.exe ->) (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGABYTE Technology Co.,Ltd.) C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\AORUS.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_85cff5320735903d\RtkAudUService64.exe [3378592 2021-10-27] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Discord] => C:\ProgramData\SquirrelMachineInstalls\Discord.exe [82992808 2022-03-09] (Discord Inc. -> Discord Inc.)
HKLM-x32\...\RunOnce: [PreRun] => C:\Program Files (x86)\Gigabyte\AppCenter\PreRun.exe [14632 2016-02-26] (GIGA-BYTE TECHNOLOGY CO., LTD. -> )
HKU\S-1-5-21-3635629567-1418942999-3944559301-1002\...\Run: [Discord] => C:\Users\Unknown\AppData\Local\Discord\Update.exe [1522176 2022-06-08] (Discord Inc. -> GitHub)
HKU\S-1-5-21-3635629567-1418942999-3944559301-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4282328 2022-06-07] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3635629567-1418942999-3944559301-1002\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [941416 2022-06-16] (Nota, Inc. -> Nota Inc.)
HKU\S-1-5-21-3635629567-1418942999-3944559301-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [479632 2022-01-15] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-3635629567-1418942999-3944559301-1002\...\Run: [NGenuity] => C:\Program Files (x86)\HyperX\NGenuity\NGenuity.exe [1834184 2020-10-08] (Kingston Technology Company, Inc. -> HyperX NGenuity Software)
HKU\S-1-5-21-3635629567-1418942999-3944559301-1002\...\Run: [f.lux] => C:\Users\Unknown\AppData\Local\FluxSoftware\Flux\flux.exe [1515848 2021-06-18] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-3635629567-1418942999-3944559301-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [37054552 2022-07-18] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-3635629567-1418942999-3944559301-1002\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKLM\Software\Microsoft\Active Setup\Installed Components: [OpenVPN_UserSetup] -> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\103.0.5060.134\Installer\chrmstp.exe [2022-07-20] (Google LLC -> Google LLC)
IFEO\osppsvc.exe: [VerifierDlls] SppExtComObjHook.dll
IFEO\SppExtComObj.exe: [VerifierDlls] SppExtComObjHook.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AdsPower.lnk [2022-01-10]
ShortcutTarget: AdsPower.lnk -> C:\Program Files\AdsPower\AdsPower.exe (广州散步去信息科技有限公司 -> AdsPower)
Startup: C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AORUS ENGINE.lnk [2022-07-23]
ShortcutTarget: AORUS ENGINE.lnk -> C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\autorun.exe () [File not signed]
Startup: C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tamriel Trade Centre Client.lnk [2022-05-30]
ShortcutTarget: Tamriel Trade Centre Client.lnk -> C:\Users\Unknown\Documents\Elder Scrolls Online\live\AddOns\TamrielTradeCentre\Client\Client.exe () [File not signed]
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {06854399-2EB6-45A8-A62D-BDF1B97C5EDF} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23378864 2022-07-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {0E3ED632-63F3-46C8-8F0E-63ECFF4330FA} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-9QCU0QU-Unknown => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {102440D0-C204-4D26-9322-8E92EB96E24A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8414664 2022-07-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {1BAB1805-401C-4E07-86F8-08C2BB232C88} - System32\Tasks\EasyTune 1 => C:\Program Files (x86)\GIGABYTE\EasyTune\etocfile.exe [20352 2021-10-11] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
Task: {20F5B379-EFB3-41EF-898E-7AC997BE0099} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {218746FD-71C5-4F57-A7ED-DB91632422CE} - System32\Tasks\Git for Windows Updater => C:\Program Files\Git\git-bash.exe [137776 2022-07-11] (Johannes Schindelin -> The Git Development Community)
Task: {239456F7-BDD2-426D-8A32-D0026F7D4576} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342080 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {27A43513-F119-465F-A7B5-0FF3AA939D4A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23378864 2022-07-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {2E22DAC4-DE18-4662-A660-D4797A483B9A} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe /NoUACCheck
Task: {308CDF02-D68E-44D7-B309-C4D6D7760348} - System32\Tasks\QuickCPUx64 => C:\Program Files\QuickCPU\QuickCPU.exe [3735744 2022-04-20] (CoderBag, LLC -> Coderbag)
Task: {45C6024A-EAB3-47B1-B8F4-37921E2784E3} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {4FE850B3-01D9-4C0C-9CD7-A27D785B8C91} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {56EF8172-439D-47D2-A329-577F88A631B7} - System32\Tasks\GraphicsCardEngine => C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\GraphicsCardEngineStarter.exe [234880 2021-04-13] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
Task: {57ECC321-A632-4AE7-8A21-DDB7FB4CC36A} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646344 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {5DD956BD-AB41-4773-9A7F-9E63ACAA4BE9} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\9.4.0\AutoUpdate.exe [2476640 2022-06-06] (IObit CO., LTD -> IObit)
Task: {80330F3C-3B98-4A54-8D5C-E0602CA591AB} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {8E8E8EB9-B100-435D-BB34-CE9CBB15226A} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-01] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {8F2A7974-0441-4293-A725-9D769E3D7A8B} - System32\Tasks\Driver Booster SkipUAC (Unknown) => C:\Program Files (x86)\IObit\Driver Booster\9.4.0\DriverBooster.exe [8662112 2022-06-06] (IObit CO., LTD -> IObit)
Task: {92FB0824-0003-4886-BB06-E68E010196AD} - System32\Tasks\CCleanerSkipUAC - Unknown => C:\Program Files\CCleaner\CCleaner.exe [31101528 2022-07-18] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {985DE295-F27F-4272-A296-A84228AE4D88} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [145312 2022-07-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {9EE6EC85-85E9-45C9-A1A2-36BA70C84C5B} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [11254592 2022-06-16] (Nota, Inc. -> Nota Inc.)
Task: {A371B860-E8DA-43B6-8841-A5835A34DC87} - System32\Tasks\EasyTune => C:\Program Files (x86)\GIGABYTE\EasyTune\etinit.exe [17280 2021-04-08] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
Task: {A6E02026-95D2-4858-A8A1-815C60A9AD9C} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [11254592 2022-06-16] (Nota, Inc. -> Nota Inc.)
Task: {A7A67363-3ABA-4A71-8200-0E5E8B2486DF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8414664 2022-07-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {B95929D2-CEA9-40B2-B580-87D6F7A0DC07} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2022-01-10] (Google LLC -> Google LLC)
Task: {BD31C126-6598-4223-BD42-771BA068CD2D} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {BD5E7D8C-391C-498C-AA24-8092ECA54CFC} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [145312 2022-07-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {BF4AC18D-A14D-4D93-A73D-4DD7FEB14E4A} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {C140FF70-2B78-4654-AB7E-71F2DC57A15D} - System32\Tasks\Uninstaller_SkipUac_Unknown => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [7562760 2022-07-07] (IObit CO., LTD -> IObit)
Task: {CEB57680-63E8-4614-9F99-094BAECCD12D} - System32\Tasks\Launcher GIGABYTE AORUS GRAPHICS ENGINE => C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\AORUS.exe [34684784 2022-06-27] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGABYTE Technology Co.,Ltd.)
Task: {D0A417F8-6D53-454E-B9F9-BDF57D37EE81} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {E23BB998-AAAA-47B0-A636-EEC8911D47D9} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [64416 2022-07-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {EA6D2AB8-6C0F-4422-A9C0-16A07F4D7C3D} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-3635629567-1418942999-3944559301-1002 => C:\ProgramData\MEGAsync\MEGAupdater.exe [2531504 2022-07-01] (Mega Limited -> )
Task: {F6A7550C-ABE8-43D7-BFE1-FFB591DF2CDA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2022-01-10] (Google LLC -> Google LLC)
Task: {F996A570-241B-4E8F-980A-EE4396AD71A2} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-07-18] (Piriform Software Ltd -> Piriform)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: Hosts file not detected in the default directory
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Unknown\AppData\Local\Microsoft\Edge\User Data\Default [2022-07-23]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\Unknown\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2022-06-23]
FireFox:
========
FF DefaultProfile: yfzic9f0.default
FF ProfilePath: C:\Users\Unknown\AppData\Roaming\Mozilla\Firefox\Profiles\yfzic9f0.default [2022-05-03]
FF ProfilePath: C:\Users\Unknown\AppData\Roaming\Mozilla\Firefox\Profiles\9tmybvze.default-release [2022-07-23]
FF NetworkProxy: Mozilla\Firefox\Profiles\9tmybvze.default-release -> type", 0
FF Session Restore: Mozilla\Firefox\Profiles\9tmybvze.default-release -> is enabled.
FF Extension: (EPUBReader) - C:\Users\Unknown\AppData\Roaming\Mozilla\Firefox\Profiles\9tmybvze.default-release\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}.xpi [2022-07-22]
FF Extension: (Popup Blocker Ultimate) - C:\Users\Unknown\AppData\Roaming\Mozilla\Firefox\Profiles\9tmybvze.default-release\Extensions\{60B7679C-BED9-11E5-998D-8526BB8E7F8B}.xpi [2022-05-12]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Unknown\AppData\Roaming\Mozilla\Firefox\Profiles\9tmybvze.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2022-07-05]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-07-08] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-07-08] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2022-03-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2022-03-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems Incorporated -> Adobe Systems)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default [2022-07-23]
CHR Session Restore: Default -> is enabled.
CHR Extension: (Popup Blocker (strict)) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\aefkmifgmaafnojlojpnekbpbmjiiogg [2022-05-03]
CHR Extension: (Pop up blocker for Chrome™ - Poper Blocker) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2022-07-05]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2022-07-05]
CHR Extension: (Google Docs Offline) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-07-21]
CHR Extension: (Similar Sites - Discover Related Websites) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\necpbmbhhdiplmfhmjicabdeighkndkn [2022-05-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-05-03]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [1843392 2015-08-20] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8885112 2022-05-03] (BattlEye Innovations e.K. -> )
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1081432 2022-07-18] (Piriform Software Ltd -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12111288 2022-07-20] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4958096 2022-01-15] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2022-04-20] (EasyAntiCheat Oy -> Epic Games, Inc)
R2 EasyTuneEngineService; C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\EasyTuneEngineService.exe [147840 2022-01-25] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R2 Gservice; C:\Program Files (x86)\GIGABYTE\GService\GCloud.exe [19888 2016-12-02] (GIGA-BYTE TECHNOLOGY CO., LTD. -> Microsoft)
S2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [158744 2022-02-10] (IObit CO., LTD -> IObit)
R2 MyService1; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [18944 2021-04-08] () [File not signed]
S3 nordsec-threatprotection-service; C:\Program Files\NordVPN\NordSec ThreatProtection\nordsec-threatprotection-service.exe [310136 2021-06-11] (nordvpn s.a. -> TEFINCOM S.A.)
R2 NordUpdaterService; C:\Program Files\NordUpdater\NordUpdateService.exe [297848 2021-06-07] (nordvpn s.a. -> TEFINCOM S.A.)
R2 nordvpn-service; C:\Program Files\NordVPN\nordvpn-service.exe [281464 2022-02-18] (nordvpn s.a. -> TEFINCOM S.A.)
S2 OCButtonService; C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\OcButtonService.exe [127360 2021-04-13] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [14592472 2022-06-13] (ADLICE -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6232176 2022-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\UNCHEATER\ucldr_battlegrounds_gl.exe [7152880 2022-01-31] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S4 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\NisSrv.exe [3120992 2022-06-23] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MsMpEng.exe [133544 2022-06-23] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WMIRegistrationService; C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe [538736 2021-07-25] (Intel Corporation -> Intel Corporation)
S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [8737992 2022-01-31] (PUBG CORPORATION -> PUBG Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_246e95e4066041ad\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_246e95e4066041ad\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AmdTools64; C:\Windows\System32\drivers\AmdTools64.sys [63392 2020-06-16] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 cbhardwarelink2; C:\Program Files\QuickCPU\hwdlink.sys [26320 2022-07-23] (CoderBag, LLC -> Coderbag)
S3 CsrBtPort; C:\Windows\system32\DRIVERS\CsrBtPort.sys [2784968 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrpan; C:\Windows\System32\drivers\csrpan.sys [39616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrserial; C:\Windows\system32\DRIVERS\csrserial.sys [61128 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrusb; C:\Windows\System32\Drivers\csrusb.sys [47296 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrusbfilter; C:\Windows\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [42256 2022-01-15] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [63696 2022-01-15] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 gdrv; C:\Windows\gdrv.sys [26192 2022-07-01] (Giga-Byte Technology -> Windows (R) Server 2003 DDK provider)
R3 gdrv3; C:\Windows\System32\drivers\gdrv3.sys [41480 2022-02-24] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R3 int0800; C:\Windows\System32\drivers\flashud.sys [62984 2019-08-28] (Intel Corporation -> Intel Corporation)
R3 IUFileFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys [43896 2020-07-31] (IObit Information Technology -> IObit)
R3 IUProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys [37112 2020-07-31] (IObit Information Technology -> IObit)
R3 IURegistryFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys [51128 2020-07-31] (IObit Information Technology -> IObit)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [223176 2022-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [21480 2022-07-23] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239544 2022-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R2 NDivert; C:\Program Files\NordVPN\6.47.22.0\Drivers\NDivert.sys [131456 2022-04-20] (nordvpn s.a. -> Nordvpn S.A.)
R1 nordlwf; C:\Windows\system32\DRIVERS\nordlwf.sys [44928 2022-02-22] (nordvpn s.a. -> TEFINCOM S.A.)
R1 npcap; C:\Windows\system32\DRIVERS\npcap.sys [72792 2021-12-01] (Insecure.Com LLC -> Insecure.Com LLC.)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [48552 2021-12-15] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
S3 Revoflt; C:\Windows\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S3 RzCommon; C:\Windows\System32\drivers\RzCommon.sys [54632 2021-03-30] (Razer USA Ltd. -> Razer Inc)
S3 RzDev_025e; C:\Windows\System32\drivers\RzDev_025e.sys [54160 2020-08-24] (Razer USA Ltd. -> Razer Inc)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [167544 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 tap0901; C:\Windows\System32\drivers\tap0901.sys [37360 2019-04-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
R3 tapnordvpn; C:\Windows\System32\drivers\tapnordvpn.sys [44896 2020-06-09] (TEFINCOM S.A. -> The OpenVPN Project)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [49576 2022-06-23] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S4 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [452856 2022-06-23] (Microsoft Windows -> Microsoft Corporation)
S4 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [91384 2022-06-23] (Microsoft Windows -> Microsoft Corporation)
S3 xhunter1; C:\Windows\xhunter1.sys [2522256 2022-01-31] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
U4 napagent; no ImagePath
U4 npcap_wifi; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-07-23 18:49 - 2022-07-23 18:50 - 000030228 _____ C:\Users\Unknown\Downloads\FRST.txt
2022-07-23 16:53 - 2022-07-23 16:53 - 000223176 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2022-07-23 16:51 - 2022-07-23 16:51 - 000001136 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2022-07-23 16:51 - 2022-07-23 16:51 - 000000000 ____D C:\Users\Unknown\AppData\Local\VS Revo Group
2022-07-23 16:51 - 2022-07-23 16:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2022-07-23 16:51 - 2021-11-17 14:50 - 000038400 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2022-07-23 15:41 - 2022-07-23 15:41 - 000000008 __RSH C:\ProgramData\ntuser.pol
2022-07-23 15:27 - 2022-07-23 15:27 - 000000837 _____ C:\Users\Public\Desktop\UCheck.lnk
2022-07-23 15:27 - 2022-07-23 15:27 - 000000000 ____D C:\ProgramData\UCheck
2022-07-23 15:27 - 2022-07-23 15:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UCheck
2022-07-23 15:27 - 2022-07-23 15:27 - 000000000 ____D C:\Program Files\UCheck
2022-07-23 15:26 - 2022-07-23 15:26 - 028808536 _____ (Adlice Software ) C:\Users\Unknown\Downloads\UCheck_setup.exe
2022-07-23 15:26 - 2022-07-23 15:26 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update
2022-07-23 15:19 - 2022-07-23 18:10 - 000000000 ____D C:\Users\Unknown\AppData\Local\Discord
2022-07-23 15:19 - 2022-07-23 15:19 - 000002243 _____ C:\Users\Unknown\Desktop\Discord.lnk
2022-07-23 15:18 - 2022-07-23 15:18 - 083112448 _____ (Discord Inc.) C:\Users\Unknown\Downloads\DiscordSetup.exe
2022-07-23 15:02 - 2022-07-23 15:02 - 000000000 ____D C:\AdwCleaner
2022-07-23 15:01 - 2022-07-23 15:23 - 000000000 ____D C:\ProgramData\RogueKiller
2022-07-23 15:00 - 2022-07-23 15:00 - 000005252 _____ C:\Users\Public\Desktop\mbst-fix-results.txt
2022-07-23 14:59 - 2022-07-23 14:59 - 008551608 _____ (Malwarebytes) C:\Users\Unknown\Downloads\adwcleaner.exe
2022-07-23 14:59 - 2022-07-23 14:59 - 000000905 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2022-07-23 14:59 - 2022-07-23 14:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2022-07-23 14:59 - 2022-07-23 14:59 - 000000000 ____D C:\Program Files\RogueKiller
2022-07-23 14:57 - 2022-07-23 14:57 - 043599792 _____ (Adlice Software ) C:\Users\Unknown\Downloads\RogueKiller_setup.exe
2022-07-23 14:50 - 2022-07-23 14:50 - 002369536 _____ (Farbar) C:\Users\Unknown\Downloads\FRST64.exe
2022-07-23 14:49 - 2022-07-23 14:49 - 000294912 _____ C:\Users\Unknown\Desktop\123.wfw
2022-07-23 14:47 - 2022-07-23 14:48 - 298190568 _____ (Malwarebytes) C:\Users\Unknown\Downloads\mb4-setup-consumer-4.5.11.202-1.0.1716-1.0.57206.exe
2022-07-23 14:46 - 2022-07-23 18:50 - 000000000 ____D C:\FRST
2022-07-23 14:39 - 2022-07-23 14:39 - 000239544 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2022-07-23 14:36 - 2022-07-23 14:36 - 000034293 _____ C:\Users\Public\Desktop\mbst-clean-results.txt
2022-07-23 14:35 - 2022-07-23 14:44 - 000002041 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2022-07-23 14:35 - 2022-07-23 14:35 - 000158640 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2022-07-23 14:35 - 2022-07-23 14:34 - 000021480 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2022-07-23 14:34 - 2022-07-23 14:43 - 000000000 ____D C:\ProgramData\Malwarebytes
2022-07-23 14:34 - 2022-07-23 14:43 - 000000000 ____D C:\Program Files\Malwarebytes
2022-07-23 14:32 - 2022-07-23 14:32 - 013471344 _____ C:\Users\Unknown\Downloads\mb-support-1.8.7.918.exe
2022-07-23 14:29 - 2022-07-23 14:29 - 002556344 _____ (Malwarebytes) C:\Users\Unknown\Downloads\MBSetup-AD870978-37335.37335.exe
2022-07-23 14:28 - 2022-07-23 14:28 - 000003424 _____ C:\Windows\system32\Tasks\Launcher GIGABYTE AORUS GRAPHICS ENGINE
2022-07-23 14:23 - 2022-07-23 14:23 - 000003156 _____ C:\Windows\system32\Tasks\Uninstaller_SkipUac_Unknown
2022-07-23 14:23 - 2022-07-23 14:23 - 000001434 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk
2022-07-23 14:23 - 2022-07-23 14:23 - 000001422 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2022-07-23 14:19 - 2022-07-23 14:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
2022-07-23 13:59 - 2022-07-23 13:59 - 000000232 _____ C:\Users\Unknown\Desktop\discord_backup_codes.txt
2022-07-23 13:41 - 2022-07-23 13:41 - 000000000 ____D C:\ProgramData\boost_interprocess
2022-07-23 13:40 - 2022-07-23 13:40 - 000006881 _____ C:\Users\Unknown\-1.14-windows.xml
2022-07-23 13:39 - 2022-07-23 13:39 - 000000000 ____D C:\Users\Public\BlueStacks
2022-07-23 13:38 - 2022-07-23 13:49 - 000000000 ____D C:\Users\Unknown\AppData\Local\BlueStacks
2022-07-22 15:48 - 2022-07-22 15:48 - 000000711 _____ C:\Users\Unknown\Desktop\Stray.lnk
2022-07-22 15:48 - 2022-07-22 15:48 - 000000000 ____D C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Stray
2022-07-22 15:47 - 2022-07-22 15:47 - 000000000 ____D C:\Games
2022-07-21 12:58 - 2022-07-21 12:58 - 000000000 ____D C:\ProgramData\Steam
2022-07-21 11:44 - 2022-07-21 11:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Games
2022-07-19 21:10 - 2022-07-21 20:20 - 000000000 ____D C:\Users\Unknown\AppData\Roaming\DarknessII
2022-07-15 09:42 - 2022-07-15 09:42 - 002260480 _____ C:\Windows\system32\TextInputMethodFormatter.dll
2022-07-15 09:42 - 2022-07-15 09:42 - 000693248 _____ C:\Windows\system32\FsNVSDeviceSource.dll
2022-07-15 09:42 - 2022-07-15 09:42 - 000640512 _____ C:\Windows\system32\SettingSyncDownloadHelper.dll
2022-07-15 09:42 - 2022-07-15 09:42 - 000530944 _____ (curl, hxxps://curl.se/) C:\Windows\system32\curl.exe
2022-07-15 09:42 - 2022-07-15 09:42 - 000470528 _____ (curl, hxxps://curl.se/) C:\Windows\SysWOW64\curl.exe
2022-07-15 09:42 - 2022-07-15 09:42 - 000288768 _____ C:\Windows\system32\Windows.Management.InprocObjects.dll
2022-07-15 09:42 - 2022-07-15 09:42 - 000270848 _____ C:\Windows\system32\EsclScan.dll
2022-07-15 09:42 - 2022-07-15 09:42 - 000152064 _____ C:\Windows\system32\EsclProtocol.dll
2022-07-15 09:42 - 2022-07-15 09:42 - 000061952 _____ C:\Windows\system32\printticketvalidation.dll
2022-07-15 09:42 - 2022-07-15 09:42 - 000057344 _____ C:\Windows\system32\APMonUI.dll
2022-07-15 09:42 - 2022-07-15 09:42 - 000033280 _____ (Microsoft Corporation) C:\Windows\system32\mode.com
2022-07-15 09:42 - 2022-07-15 09:42 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mode.com
2022-07-15 09:42 - 2022-07-15 09:42 - 000024576 _____ C:\Windows\system32\WsdProviderUtil.dll
2022-07-15 09:42 - 2022-07-15 09:42 - 000020992 _____ (Microsoft Corporation) C:\Windows\system32\tree.com
2022-07-15 09:42 - 2022-07-15 09:42 - 000018944 _____ C:\Windows\SysWOW64\WsdProviderUtil.dll
2022-07-15 09:42 - 2022-07-15 09:42 - 000017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tree.com
2022-07-15 09:42 - 2022-07-15 09:42 - 000014848 _____ (Microsoft Corporation) C:\Windows\system32\chcp.com
2022-07-15 09:42 - 2022-07-15 09:42 - 000012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chcp.com
2022-07-15 09:42 - 2022-07-15 09:42 - 000011811 _____ C:\Windows\system32\DrtmAuthTxt.wim
2022-07-15 09:37 - 2022-07-15 09:37 - 000000000 ___HD C:\$WinREAgent
2022-07-14 11:52 - 2022-07-14 11:52 - 000000000 ____D C:\Users\Unknown\Documents\AutomaticSolution Software
2022-07-14 00:43 - 2022-07-14 00:43 - 000000053 _____ C:\Users\Unknown\.git-for-windows-updater
2022-07-13 12:38 - 2022-07-13 12:38 - 000000000 ____D C:\Users\Unknown\AppData\Local\ARKBreedingStats
2022-07-13 12:37 - 2022-07-19 15:21 - 000000000 ____D C:\Users\Unknown\AppData\Local\ARK Smart Breeding
2022-07-13 12:37 - 2022-07-13 12:37 - 000001220 _____ C:\Users\Public\Desktop\ARK Smart Breeding.lnk
2022-07-13 12:37 - 2022-07-13 12:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ARK Smart Breeding
2022-07-13 12:37 - 2022-07-13 12:37 - 000000000 ____D C:\Program Files (x86)\ARK Smart Breeding
2022-07-13 00:43 - 2022-07-13 00:43 - 000002594 _____ C:\Windows\system32\Tasks\Git for Windows Updater
2022-07-13 00:43 - 2022-07-13 00:43 - 000001764 _____ C:\Users\Public\Desktop\Git Bash.lnk
2022-07-13 00:43 - 2022-07-13 00:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Git
2022-07-13 00:24 - 2022-07-13 00:24 - 000001362 _____ C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Git for Windows.lnk
2022-07-11 00:37 - 2022-07-11 00:37 - 000000000 ____D C:\Users\Unknown\AppData\Local\pip
2022-07-11 00:35 - 2022-07-11 00:35 - 000000000 ____D C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.10
2022-07-11 00:35 - 2022-07-11 00:35 - 000000000 ____D C:\Users\Unknown\AppData\Local\Package Cache
2022-07-11 00:28 - 2022-07-11 00:28 - 000000047 _____ C:\Users\Unknown\.bash_history
2022-07-11 00:24 - 2022-07-13 00:43 - 000000000 ____D C:\Program Files\Git
2022-07-11 00:15 - 2022-07-11 00:38 - 000000000 ____D C:\Users\Unknown\Desktop\MHDDoS
2022-07-11 00:13 - 2022-07-23 13:31 - 000000000 ____D C:\Users\Unknown\AppData\Local\PlaceholderTileLogoFolder
2022-07-10 23:54 - 2022-07-11 00:17 - 000007614 _____ C:\Users\Unknown\AppData\Local\Resmon.ResmonCfg
2022-07-10 22:24 - 2022-07-10 22:25 - 000000000 ____D C:\Users\Unknown\AppData\Roaming\Wireshark
2022-07-10 22:17 - 2022-07-10 22:17 - 000001827 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark.lnk
2022-07-10 22:17 - 2022-07-10 22:17 - 000001815 _____ C:\Users\Public\Desktop\Wireshark.lnk
2022-07-10 22:17 - 2022-07-10 22:17 - 000000000 ____D C:\Windows\SysWOW64\Npcap
2022-07-10 22:17 - 2022-07-10 22:17 - 000000000 ____D C:\Windows\system32\Npcap
2022-07-10 22:16 - 2022-07-10 22:17 - 000000000 ____D C:\Program Files\Wireshark
2022-07-10 22:01 - 2022-07-10 22:01 - 000000000 ____D C:\TFTP-Root
2022-07-10 22:00 - 2022-07-10 22:12 - 000000031 _____ C:\ProgramData\swi500b08e4-f553-418c-941d-d523edc3e2a0.txt
2022-07-10 22:00 - 2022-07-10 22:01 - 000000000 ____D C:\Users\Unknown\AppData\Local\SolarWinds
2022-07-10 22:00 - 2022-07-10 22:00 - 000000000 ____D C:\Users\Unknown\AppData\Local\Solarwinds Toolset Installs
2022-07-10 21:59 - 2022-07-10 22:15 - 000000000 ____D C:\ProgramData\SolarWinds
2022-07-10 21:59 - 2022-07-10 21:59 - 000000000 ____D C:\Users\Unknown\AppData\Local\f9027c8f-f115-4617-b716-19de7ec5e9d6
2022-07-10 21:59 - 2022-07-10 21:59 - 000000000 ____D C:\Users\Unknown\AppData\Local\Applications
2022-07-10 21:59 - 2022-07-10 21:59 - 000000000 ____D C:\ProgramData\Applications
2022-07-10 21:59 - 2022-07-10 21:59 - 000000000 ____D C:\Program Files (x86)\Microsoft Corporation
2022-07-10 21:54 - 2022-07-10 21:54 - 000000218 _____ C:\Users\Unknown\AppData\Local\recently-used.xbel
2022-07-10 21:17 - 2022-07-10 21:54 - 000000000 ____D C:\Users\Unknown\.zenmap
2022-07-10 21:15 - 2022-07-10 21:15 - 000001036 _____ C:\Users\Unknown\Desktop\Nmap - Zenmap GUI.lnk
2022-07-10 21:15 - 2022-07-10 21:15 - 000000000 ____D C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nmap
2022-07-10 21:14 - 2022-07-10 22:17 - 000000000 ____D C:\Program Files\Npcap
2022-07-10 21:14 - 2022-07-10 21:15 - 000000000 ____D C:\Program Files (x86)\Nmap
2022-07-07 21:04 - 2022-07-07 21:04 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2022-07-07 14:47 - 2022-07-09 10:02 - 000000000 ____D C:\Users\Unknown\Desktop\dControl
2022-07-07 11:01 - 2022-07-07 11:01 - 000007131 _____ C:\Windows\Simple Static IP Setup Log.txt
2022-07-07 11:01 - 2022-07-07 11:01 - 000002078 _____ C:\Users\Unknown\Desktop\Simple Static IP.lnk
2022-07-07 11:01 - 2022-07-07 11:01 - 000000000 ____D C:\Windows\Simple Static IP
2022-07-07 11:01 - 2022-07-07 11:01 - 000000000 ____D C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Simple Static IP
2022-07-07 11:01 - 2022-07-07 11:01 - 000000000 ____D C:\Program Files (x86)\Simple Static IP
2022-07-06 00:31 - 2022-07-06 00:31 - 000000000 ____D C:\Users\Unknown\AppData\Local\ZIsland
2022-07-06 00:31 - 2022-07-06 00:31 - 000000000 ____D C:\Users\Unknown\AppData\Local\UnrealEngine
2022-07-03 09:47 - 2022-07-03 09:47 - 000003344 _____ C:\Windows\system32\Tasks\QuickCPUx64
2022-07-02 13:10 - 2022-07-02 13:10 - 000000000 ____D C:\Users\Unknown\AppData\LocalLow\MogWomp Games
2022-07-01 21:34 - 2022-07-23 15:41 - 000008192 ___SH C:\DumpStack.log.tmp
2022-07-01 21:34 - 2022-07-01 21:34 - 000000000 ____D C:\Windows\Minidump
2022-07-01 17:55 - 2022-07-01 17:55 - 000000000 ____D C:\Users\Unknown\AppData\LocalLow\RiezOn
2022-07-01 17:42 - 2022-07-01 17:42 - 000000000 ____D C:\Users\Unknown\AppData\LocalLow\Team Nimbus
2022-07-01 14:45 - 2022-07-01 14:45 - 000001243 _____ C:\Users\Public\Desktop\AORUS ENGINE.lnk
2022-07-01 14:32 - 2022-07-01 14:32 - 000001199 _____ C:\Users\Public\Desktop\HyperX NGenuity.lnk
2022-07-01 14:31 - 2022-07-01 14:31 - 001215199 _____ C:\Windows\unins000.exe
2022-07-01 14:12 - 2022-07-23 15:02 - 000000000 ____D C:\Program Files\QuickCPU
2022-07-01 14:12 - 2022-07-01 14:22 - 000000000 ____D C:\Users\Unknown\AppData\Local\Coderbag
2022-07-01 14:12 - 2022-07-01 14:12 - 000000990 _____ C:\Users\Public\Desktop\QuickCPU.lnk
2022-07-01 14:12 - 2022-07-01 14:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickCPU64
2022-07-01 14:12 - 2019-10-19 00:12 - 000897728 _____ (CoderBag) C:\Users\Unknown\Desktop\UnparkCpu.exe
2022-07-01 14:07 - 2019-09-03 10:35 - 000000020 _____ C:\Users\Unknown\Desktop\autoexec.bat
2022-07-01 14:07 - 2019-08-13 11:09 - 016777216 _____ C:\Users\Unknown\Desktop\Z370PD3.F14