Hi sorry I didn't know about that I will attach them in a post now
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-08-2021
Ran by Waqar (administrator) on DESKTOP-AIMSR73 (06-08-2021 19:28:10)
Running from C:\Users\Waqar\Downloads
Loaded Profiles: Waqar
Platform: Windows 10 Education Version 20H2 19042.746 (X64) Language: English (United Kingdom)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(ASUSTeK Computer Inc. -> ) [File not signed] C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.25\AsSysCtrlService.exe
(ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe
(ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
(ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe
(ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe
(ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
(ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe
(ASUSTeK Computer Inc. -> ASUSTek Compputer Inc.) C:\Program Files\ASUS\AacMB\Aac3572MbHal_x86.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe <2>
(ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\2.01.07\AsusFanControlService.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.02.06\atkexComSvc.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\LightingService.exe
(ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe
(ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.UserSessionHelper.exe
(ASUSTEK COMPUTER INCORPORATION -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe
(Autodesk, Inc. -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\10.1.0.3194\AdskLicensingService\AdskLicensingService.exe
(A-Volute -> Nahimic) C:\Windows\System32\NahimicService.exe
(A-Volute -> Nahimic) C:\Windows\System32\NahimicSvc64.exe <2>
(A-Volute -> Nahimic) C:\Windows\SysWOW64\NahimicSvc32.exe <2>
(A-Volute SAS -> A-Volute) C:\Users\Waqar\AppData\Local\NhNotifSys\sonicstudio\asusns.exe
(Chaos Software Ltd. -> ) C:\Program Files\Chaos Group\VRLService\OLS\vrol.exe
(DTS, Inc. -> DTS Inc.) C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(EVGA Corp. -> EVGA Co., Ltd.) C:\Program Files\EVGA\Precision X1\PrecisionX_x64.exe
(Flexera Software LLC -> Flexera) C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <21>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.28001.0_x64__8wekyb3d8bbwe\GamingServices.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.28001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2012.21.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20566.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20566.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.521.2012.0_x64__8wekyb3d8bbwe\GameBar.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.521.2012.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(Microsoft Windows -> ) C:\Windows\System32\OpenSSH\sshd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Spectrum.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WebManagement.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\NisSrv.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5d5c294bb8d17217\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\nvrla.exe
(NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\PresentMon_x64.exe <2>
(NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Tobii AB -> ) C:\Program Files (x86)\Tobii\Tobii VRU02 Runtime\platform_runtime_VR4U2P2_service.exe
(TODO: <Company name>) [File not signed] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AIOFanSDK\ArmouryAIOFanServer.exe
(Travis Nickles -> DS4Windows) C:\Users\Waqar\Downloads\DS4Windows\DS4Windows.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <4>
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [961824 2019-07-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412736 2021-07-14] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [RamCache III ] => C:\Program Files (x86)\RamCache III\RamCache.exe [5416728 2020-11-24] (FNet Co., Ltd. -> FNet Co., Ltd)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2017-09-12] (Wondershare Technology Co.,Ltd -> Wondershare)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1871344 2017-11-28] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Autodesk Genuine Service ] => C:\Users\Waqar\AppData\Local\Programs\Autodesk\Genuine Service\GenuineService.exe [1077864 2020-01-02] (Autodesk, Inc. -> Autodesk)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [668376 2021-03-04] (Autodesk, Inc. -> Autodesk, Inc.)
HKU\S-1-5-21-2327868397-2116308143-3992419034-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4110568 2021-07-21] (Valve -> Valve Corporation)
HKU\S-1-5-21-2327868397-2116308143-3992419034-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [33264096 2021-08-04] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-2327868397-2116308143-3992419034-1001\...\Run: [Spotify] => C:\Users\Waqar\AppData\Roaming\Spotify\Spotify.exe [24276096 2021-08-04] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-2327868397-2116308143-3992419034-1001\...\Run: [Magnet.bootstrap_Vive] => "C:\Program Files (x86)\VIVE\PCClient\Vive.exe" --silent
HKU\S-1-5-21-2327868397-2116308143-3992419034-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [886768 2017-11-28] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKU\S-1-5-21-2327868397-2116308143-3992419034-1001\...\Policies\Explorer: [DisallowRun] 1
HKU\S-1-5-21-2327868397-2116308143-3992419034-1001\...\Policies\Explorer\DisallowRun: [1] irsetup.exe
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [65096 2017-11-28] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\...\Print\Monitors\PDFill Writer Monitor: C:\Program Files (x86)\PlotSoft\PDFill\PDFWriter\Driver\PDFillWriterMon.dll [38824 2021-03-21] (PlotSoft LLC -> Windows (R) Codename Longhorn DDK provider)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{43F137B0-8F4D-463B-AB83-ADEAD4F15096}] -> C:\Program Files (x86)\Microsoft\Edge Beta\Application\93.0.961.11\Installer\setup.exe [2021-08-04] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\92.0.4515.131\Installer\chrmstp.exe [2021-08-05] (Google LLC -> Google LLC)
Startup: C:\Users\Waqar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DS4Windows.lnk [2021-06-12]
ShortcutTarget: DS4Windows.lnk -> C:\Users\Waqar\Downloads\DS4Windows\DS4Windows.exe (Travis Nickles -> DS4Windows)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01BC88CB-D19F-466C-8224-FD6CEE1068D9} - System32\Tasks\NahimicTask64 => C:\Windows\system32\.\NahimicSvc64.exe [1066416 2020-11-04] (A-Volute -> Nahimic)
Task: {03816C2A-5847-4083-8AF4-38E8A473917D} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [168520 2020-11-15] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {05C9F490-0191-431F-8129-A064CD396BEB} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412736 2021-07-14] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {1386F695-B164-426E-A645-CB2AA6700042} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [64936 2021-04-17] (Microsoft Corporation -> Microsoft)
Task: {19CD352D-8E71-420F-946D-2419EF644835} - System32\Tasks\EVGAPrecisionX => C:\Program Files\EVGA\Precision X1\PrecisionX_x64.exe [27703944 2021-06-02] (EVGA Corp. -> EVGA Co., Ltd.)
Task: {1B7B3DDC-5672-4EC4-929C-E292350D13DC} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-05-04] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {212DC347-DAAB-43D8-8A4F-11B22F4E4A9D} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe [56784 2020-08-27] (ASUSTeK Computer Inc. -> )
Task: {25ADC58E-2FE5-4C4D-92F7-E598D67E2A86} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {2A289D52-71F1-4840-9BCD-175E9A486088} - System32\Tasks\ASUS\ASUS DIPAwayMode => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe [1469800 2020-10-30] (ASUSTeK Computer Inc. -> )
Task: {3119EBB3-2EDA-4AC1-A015-FC21D4B04B84} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {344B5074-6CEA-4E36-B55A-075BC98F0358} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpCmdRun.exe [673816 2021-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {408AA742-CF6C-46C2-95D9-C37D9704EECD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpCmdRun.exe [673816 2021-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4386054B-210E-4044-8781-438B65C9B732} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-06-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4726EC48-3F5D-4442-B474-8431D3ABE786} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [113992 2021-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {4BEC0D5A-FEA4-433F-B2EA-F96C5378B323} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-06-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {590768F0-628A-41AB-9ABD-532DB0391984} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [113992 2021-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {5D62815A-083F-40ED-9E9C-2E3AFD472D22} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23253376 2021-07-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {714C57A5-D32C-4690-9704-0C5CED0A0F94} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpCmdRun.exe [673816 2021-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {72D9D692-9901-41C8-B5DB-8CE31E89CDC8} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339120 2021-06-15] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {85E20104-AC2F-4D1F-A9E1-B4AD65CCC165} - System32\Tasks\NahimicTask32 => C:\Windows\system32\..\SysWOW64\NahimicSvc32.exe [822704 2020-11-04] (A-Volute -> Nahimic)
Task: {8DC4E236-9B97-4146-B630-EBFBE8C6F552} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4282288 2021-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {8E46AD15-DAD7-4647-922A-6DFFC120D409} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpCmdRun.exe [673816 2021-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {923DB172-11B1-4339-8A0B-886CAE4112A9} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9A4E50EC-7DF0-47BE-885A-8FE525F81C16} - System32\Tasks\NahimicSvc32Run => C:\Windows\SysWOW64\NahimicSvc32.exe [822704 2020-11-04] (A-Volute -> Nahimic)
Task: {A4D5C04B-68B7-4ECE-ACBD-4C2172AF2928} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4282288 2021-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {A6031097-AC1E-4FC6-9456-E11B96291C7B} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe [1899656 2020-11-25] (ASUSTeK Computer Inc. -> ASUS)
Task: {AC4CE1FE-75E3-4B4E-90E0-DB0224225BE8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2020-11-15] (Google LLC -> Google LLC)
Task: {BC1C11FA-A811-4F5C-A04D-47420066D662} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23253376 2021-07-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {C0608248-468D-4F9A-AA49-79B832433D4D} - System32\Tasks\NahimicSvc64Run => C:\Windows\system32\NahimicSvc64.exe [1066416 2020-11-04] (A-Volute -> Nahimic)
Task: {C12B1701-2311-4893-B856-2C4825E07643} - System32\Tasks\ASUS\GpuFanHelper => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\GpuFanHelper.exe [4329008 2020-10-13] (ASUSTeK Computer Inc. -> TODO: <Company name>)
Task: {C203BD24-5587-418B-AE8F-C3FD022E0F2A} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C5922DF6-F130-4BAE-A374-7E6F9625EF85} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-06-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C8D9EE3F-748F-4C4B-97FE-473D2ACAD1BD} - System32\Tasks\ASUS\NoiseCancelingEngine.exe => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe [1238328 2021-01-21] (ASUSTeK Computer Inc. -> ASUS)
Task: {CC9CF38D-2720-4D05-BF3B-F6C16E61D705} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe [45540760 2021-01-13] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {CCD3B5BF-E945-4428-8FBD-AE391FA7E634} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d6bb3effa23db6 => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [168520 2020-11-15] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {D42EB68C-88BC-4BE1-A02E-CC906393D9D0} - System32\Tasks\AMDAutoUpdate => C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe [677624 2019-11-21] (Advanced Micro Devices INC. -> )
Task: {D51289C2-0B1B-4984-B9FB-1AF48B9573EF} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2115632 2020-10-23] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {E5C4D18C-5648-4182-929E-A371D0F35FBD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2020-11-15] (Google LLC -> Google LLC)
Task: {E7A52DFE-F600-4068-8401-77BCC82148E3} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905072 2021-06-10] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F2555AA5-BEB0-4036-84E0-5FC3EBFD4B89} - System32\Tasks\ASUS\ArmouryAIOFanServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AIOFanSDK\ArmouryAIOFanServer.exe [1039360 2020-11-10] (TODO: <Company name>) [File not signed]
Task: {FCDD3B7E-A12C-4CD7-87A6-26030A7E6ADA} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-05-04] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{61fd3046-d5fe-4358-ba97-92942e7dc4aa}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Waqar\AppData\Local\Microsoft\Edge\User Data\Default [2021-08-01]
Edge Extension: (360 Viewer) - C:\Users\Waqar\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmglcbnpblebkmcllnfcgamdelbbekge [2021-06-10]
StartMenuInternet: Microsoft Edge Beta - C:\Program Files (x86)\Microsoft\Edge Beta\Application\msedge.exe
FireFox:
========
FF HKLM\...\Firefox\Extensions: [
web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2017-11-27]
FF HKLM-x32\...\Firefox\Extensions: [
web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-05] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-05] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-05-28] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-28] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.0-git -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-11-22] (VideoLAN) [File not signed]
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2017-11-28] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default [2021-08-06]
CHR Notifications: Default -> hxxps://www.reddit.com
CHR HomePage: Default -> hxxp://www.oursurfing.com/?type=hp&ts=1435771788&z=96d34dc6754b672d6bda019g8z3c5wdmcm2gam4qbg&from=amt&uid=WDCXWD3200AAJS-00L7A0_WD-WMAV2211074210742
CHR StartupUrls: Default -> "hxxp://www.oursurfing.com/?type=hp&ts=1435771788&z=96d34dc6754b672d6bda019g8z3c5wdmcm2gam4qbg&from=amt&uid=WDCXWD3200AAJS-00L7A0_WD-WMAV2211074210742","hxxp://www.oursurfing.com/?type=hppp&ts=1435771870&z=e9934bf8adf1b566aa546d4g5z8c9w5mamegabfz5c&from=amt&uid=WDCXWD3200AAJS-00L7A0_WD-WMAV2211074210742","hxxp://d2ucfwpxlh3zh3.cloudfront.net/?ts=AHEqBHQkBH4sBk..&v=20160611&uid=539C6BEC8EE41381B880630540D96475&ptid=epf1&mode=loadm","hxxp://go.css.herts.ac.uk/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Slides) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-11-16]
CHR Extension: (Docs) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-11-16]
CHR Extension: (Google Drive) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-11-16]
CHR Extension: (YouTube) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-11-16]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-07-28]
CHR Extension: (TwoSeven Extension) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjdnfmjmdligcpfcekfmenlhiopehjkd [2021-08-04]
CHR Extension: (SlitherPlus - Zoom, Skin Creator, Mod, Bots) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpbghpalffgmgocmnigfhalghmaemffo [2020-11-16]
CHR Extension: (WGT Golf Challenge) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcilimldmomiaihcfkmaldanopfejefg [2020-11-16]
CHR Extension: (Slither.io Skins, Mods, Hack & Guide) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\dggomkijbihggjgcgdbnleolpleddaid [2020-11-16]
CHR Extension: (Adobe Acrobat) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2021-04-17]
CHR Extension: (Pixlr-o-matic) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2020-11-16]
CHR Extension: (Sheets) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-11-16]
CHR Extension: (Alloy) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\fljipcgeenffdcglannkpppedokbpgjl [2020-11-16]
CHR Extension: (Google Docs Offline) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-06-27]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-06-24]
CHR Extension: (TU-95 - Pilot the Plane!) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbjohfoloehbkffdihkengbkjgalmabj [2020-11-16]
CHR Extension: (AllCast Receiver) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjbljnpdahefgnopeohlaeohgkiidnoe [2020-11-16]
CHR Extension: (Color Piano!) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihmigmmflfcbhdpdgbkkeojchjhhphnh [2020-11-16]
CHR Extension: (Pacman) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcecjlbneginpknnnfkfijdfhaedihll [2020-11-16]
CHR Extension: (Google Forms) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhknlonaankphkkbnmjdlpehkinifeeg [2020-11-16]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2021-06-03]
CHR Extension: (Little Alchemy) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd [2020-11-16]
CHR Extension: (Until AM Web App) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kodigjkcpaoeodlnmcnekemakpnmegnk [2020-11-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Gmail) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-11-16]
CHR Extension: (Chrome Media Router) - C:\Users\Waqar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-07-25]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1050920 2021-03-04] (Autodesk, Inc. -> Autodesk Inc.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 AdskLicensingService; C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe [16930616 2019-12-18] (Autodesk, Inc. -> Autodesk)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3779840 2021-07-14] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3547904 2021-07-14] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 ArmouryCrateService; C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe [348280 2021-03-25] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.06\atkexComSvc.exe [456008 2021-06-28] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.25\AsSysCtrlService.exe [1360016 2020-10-12] (ASUSTeK Computer Inc. -> ) [File not signed]
S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [168520 2020-11-15] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [313008 2021-02-17] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.)
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\2.01.07\AsusFanControlService.exe [2092872 2021-06-28] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [168520 2020-11-15] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 AsusUpdateCheck; C:\Windows\System32\AsusUpdateCheck.exe [842128 2021-08-06] (ASUSTeK Computer Inc. -> )
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8912272 2021-06-15] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9141648 2021-07-21] (Microsoft Corporation -> Microsoft Corporation)
R2 DtsApo4Service; C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.exe [145128 2019-06-26] (DTS, Inc. -> DTS Inc.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [810928 2021-06-12] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [926176 2021-03-16] (Epic Games Inc. -> Epic Games, Inc.)
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [14288 2020-12-02] (Microsoft Corporation -> Microsoft Corporation)
R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [3210232 2021-03-03] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
S3 MicrosoftEdgeBetaElevationService; C:\Program Files (x86)\Microsoft\Edge Beta\Application\93.0.961.11\elevation_service.exe [1639824 2021-08-03] (Microsoft Corporation -> Microsoft Corporation)
R2 NahimicService; C:\Windows\system32\NahimicService.exe [2719664 2020-11-04] (A-Volute -> Nahimic)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2556048 2021-07-15] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3474584 2021-07-15] (Electronic Arts, Inc. -> Electronic Arts)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1848624 2021-07-30] (Rockstar Games, Inc. -> Rockstar Games)
R2 ROG Live Service; C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe [5632232 2021-06-18] (ASUSTEK COMPUTER INCORPORATION -> ASUSTek COMPUTER INC.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5198064 2021-01-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12871464 2021-04-30] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 Tobii VRU02 Runtime; C:\Program Files (x86)\Tobii\Tobii VRU02 Runtime\platform_runtime_VR4U2P2_service.exe [4010344 2020-01-29] (Tobii AB -> )
R2 VRLService; C:\Program Files\Chaos Group\VRLService\OLS\vrol.exe [20309016 2021-05-09] (Chaos Software Ltd. -> )
S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [147392 2019-04-30] (Microsoft Corporation -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\NisSrv.exe [2727416 2021-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MsMpEng.exe [136656 2021-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5d5c294bb8d17217\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5d5c294bb8d17217\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [35136 2020-05-25] (ASUSTeK Computer Inc. -> )
R1 Asusgio3; C:\Windows\system32\drivers\AsIO3.sys [43920 2021-02-17] (ASUSTeK Computer Inc. -> )
R3 AVoluteSS3Vad; C:\Windows\System32\drivers\AVoluteSS3Vad.sys [85080 2019-08-14] (A-Volute -> Windows (R) Win 7 DDK provider)
S3 BTWUSB; C:\Windows\System32\Drivers\btwusb.sys [75560 2020-12-26] (Broadcom Corporation -> Broadcom Corporation.)
S3 cpuz150; C:\Windows\temp\cpuz150\cpuz150_x64.sys [44832 2021-08-04] (CPUID S.A.R.L.U. -> CPUID)
R3 Driver; C:\Program Files\EVGA\Precision X1\driver-x64.sys [39856 2020-07-23] (EVGA Corp. -> )
R1 EneTechIo; C:\Windows\system32\drivers\ene.sys [20992 2020-05-12] (Microsoft Windows Hardware Compatibility Publisher -> )
R0 FNETHYRAMAS; C:\Windows\System32\drivers\FNETHYRAMAS.SYS [56496 2020-11-24] (FNet Co., Ltd. -> FNet Co., Ltd.)
R1 GLCKIO2; C:\Windows\system32\drivers\GLCKIO2.sys [29368 2019-04-24] (ASUSTeK Computer Inc. -> )
S3 GPUZ-v2; C:\Users\Waqar\AppData\Local\Temp\GPUZ-v2.sys [50216 2021-01-10] (TechPowerUp LLC -> ) <==== ATTENTION
S3 HWiNFO_161; C:\Users\Waqar\AppData\Local\Temp\HWiNFO64A_161.SYS [64528 2021-06-28] (Martin Malik - REALiX -> REALiX(tm)) <==== ATTENTION
R2 inpoutx64; C:\Windows\System32\Drivers\inpoutx64.sys [15008 2021-02-26] (Red Fox UK Limited -> Highresolution Enterprises [
www.highrez.co.uk])
R4 IOMap; C:\Windows\system32\drivers\IOMap64.sys [35344 2020-11-03] (ASUSTEK COMPUTER INC. -> ASUSTeK Computer Inc.)
S3 LSaiMini; C:\Windows\System32\drivers\LSaiMini.sys [30840 2018-09-04] (WDKTestCert SYSTEM,131245371151827277 -> Logitech)
S3 LSaiNtBus; C:\Windows\system32\drivers\LSaiBus.sys [70456 2018-09-04] (WDKTestCert SYSTEM,131245371151827277 -> Logitech)
R1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [17424 2020-01-20] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
S3 SaiK2221; C:\Windows\system32\DRIVERS\SaiK2221.sys [227128 2018-09-04] (WDKTestCert SYSTEM,131245371151827277 -> Logitech)
S3 SaiKa221; C:\Windows\system32\DRIVERS\SaiKa221.sys [227128 2018-09-04] (WDKTestCert SYSTEM,131245371151827277 -> Logitech)
S3 SaiU2221; C:\Windows\system32\DRIVERS\SaiU2221.sys [33512 2018-09-04] (WDKTestCert SYSTEM,131245371151827277 -> Logitech)
S3 SaiUa221; C:\Windows\system32\DRIVERS\SaiUa221.sys [33512 2018-09-04] (WDKTestCert SYSTEM,131245371151827277 -> Logitech)
R2 SSGDIO; C:\Windows\SysWOW64\DRIVERS\ssgdio64.sys [14608 2020-11-22] (ATI Technologies, Inc -> ATI Technologies Inc.)
R1 ViGEmBus; C:\Windows\System32\drivers\ViGEmBus.sys [165744 2020-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Nefarius Software Solutions e.U.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [49568 2021-08-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [434424 2021-08-04] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [78072 2021-08-04] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-08-06 19:28 - 2021-08-06 19:28 - 000038975 _____ C:\Users\Waqar\Downloads\FRST.txt
2021-08-06 19:28 - 2021-08-06 19:28 - 000000000 ____D C:\FRST
2021-08-06 19:27 - 2021-08-06 19:27 - 002300416 _____ (Farbar) C:\Users\Waqar\Downloads\FRST64.exe
2021-08-06 19:17 - 2021-08-06 19:17 - 000000000 ____D C:\Users\Waqar\Downloads\AIDA64Portable_5.90.4200-Extreme
2021-08-06 19:08 - 2021-08-06 19:08 - 050926505 _____ C:\Users\Waqar\Downloads\AIDA64Portable_5.90.4200-Extreme.rar
2021-08-05 18:07 - 2021-08-05 18:07 - 000011592 _____ C:\Users\Waqar\Downloads\WhatsApp Image 2019-12-06 at 8.40.21 AM.jpeg
2021-08-05 18:02 - 2021-08-05 18:08 - 000771925 _____ C:\Users\Waqar\Downloads\GST REGISTRATION FORM.pdf
2021-08-04 22:10 - 2021-08-04 22:10 - 000000222 _____ C:\Users\Waqar\Desktop\Green Hell.url
2021-08-04 19:51 - 2021-08-04 19:51 - 000000000 ____D C:\Users\Waqar\Downloads\ZenTimings_v1.2.5
2021-08-04 19:36 - 2021-08-04 19:36 - 000184409 _____ C:\Users\Waqar\Desktop\DESKTOP.html
2021-08-02 20:46 - 2021-08-02 20:46 - 000000000 ____D C:\Users\Waqar\Desktop\Zeeshan
2021-08-01 22:42 - 2021-08-01 22:42 - 000369374 _____ C:\Users\Waqar\Desktop\DESKTOP-AIMSR73.html
2021-08-01 15:37 - 2021-07-14 03:07 - 001858664 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2021-08-01 15:37 - 2021-07-14 03:07 - 001858664 _____ C:\Windows\system32\vulkaninfo.exe
2021-08-01 15:37 - 2021-07-14 03:07 - 001438824 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-08-01 15:37 - 2021-07-14 03:07 - 001438824 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2021-08-01 15:37 - 2021-07-14 03:07 - 001097856 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2021-08-01 15:37 - 2021-07-14 03:07 - 001097856 _____ C:\Windows\system32\vulkan-1.dll
2021-08-01 15:37 - 2021-07-14 03:07 - 000951936 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2021-08-01 15:37 - 2021-07-14 03:07 - 000951936 _____ C:\Windows\SysWOW64\vulkan-1.dll
2021-08-01 15:37 - 2021-07-14 03:06 - 001474704 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2021-08-01 15:37 - 2021-07-14 03:06 - 001212560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2021-08-01 15:37 - 2021-07-14 03:02 - 001520776 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2021-08-01 15:37 - 2021-07-14 03:02 - 000716912 _____ C:\Windows\system32\nvofapi64.dll
2021-08-01 15:37 - 2021-07-14 03:02 - 000676480 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2021-08-01 15:37 - 2021-07-14 03:02 - 000645232 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2021-08-01 15:37 - 2021-07-14 03:02 - 000577152 _____ C:\Windows\SysWOW64\nvofapi.dll
2021-08-01 15:37 - 2021-07-14 03:02 - 000564352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2021-08-01 15:37 - 2021-07-14 03:01 - 002112128 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2021-08-01 15:37 - 2021-07-14 03:01 - 001595520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2021-08-01 15:37 - 2021-07-14 03:01 - 001171072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2021-08-01 15:37 - 2021-07-14 03:01 - 000919168 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2021-08-01 15:37 - 2021-07-14 03:01 - 000750208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2021-08-01 15:37 - 2021-07-14 03:01 - 000706176 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2021-08-01 15:37 - 2021-07-14 03:00 - 008854144 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2021-08-01 15:37 - 2021-07-14 03:00 - 007920768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2021-08-01 15:37 - 2021-07-14 03:00 - 005680760 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2021-08-01 15:37 - 2021-07-14 03:00 - 004987520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2021-08-01 15:37 - 2021-07-14 03:00 - 002925696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2021-08-01 15:37 - 2021-07-14 03:00 - 000447104 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2021-08-01 15:37 - 2021-07-14 02:59 - 000849008 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2021-08-01 15:37 - 2021-07-12 21:32 - 000083062 _____ C:\Windows\system32\nvinfo.pb
2021-08-01 05:50 - 2021-08-01 05:50 - 000000363 _____ C:\Users\Waqar\Desktop\Train Sim World 2.url
2021-07-31 16:12 - 2021-07-31 16:13 - 000000000 ____D C:\Users\Waqar\AppData\Roaming\Liveries Mega Pack Manager
2021-07-31 16:12 - 2021-07-31 16:12 - 097104384 _____ (David Wheatley) C:\Users\Waqar\Downloads\Liveries_Mega_Pack_Manager-0.4.5-setup.exe
2021-07-31 16:12 - 2021-07-31 16:12 - 000002663 _____ C:\Users\Waqar\Desktop\Liveries Mega Pack Manager.lnk
2021-07-31 16:12 - 2021-07-31 16:12 - 000000000 ____D C:\Users\Waqar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\David Wheatley
2021-07-31 16:12 - 2021-07-31 16:12 - 000000000 ____D C:\Users\Waqar\AppData\Local\Liveries_Mega_Pack_Manager
2021-07-22 16:18 - 2021-07-22 16:19 - 006331220 _____ C:\Windows\Minidump\072221-13546-01.dmp
2021-07-12 17:45 - 2021-07-12 17:45 - 006196188 _____ C:\Windows\Minidump\071221-21093-01.dmp
2021-07-11 14:35 - 2021-07-11 14:35 - 000000000 ____D C:\Users\Waqar\AppData\Local\Pavlov
2021-07-10 21:18 - 2021-07-10 21:18 - 000000223 _____ C:\Users\Waqar\Desktop\Transport Fever 2.url
2021-07-10 21:18 - 2021-07-10 21:18 - 000000222 _____ C:\Users\Waqar\Desktop\Pavlov VR.url
2021-07-07 17:42 - 2021-07-07 17:42 - 000000000 ____D C:\Users\Waqar\AppData\Roaming\paradox-launcher-v2