FRST LOG
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-01-2022
Ran by Alex (administrator) on ALEXPC (Micro-Star International Co., Ltd. MS-7A38) (04-02-2022 12:42:52)
Running from C:\Users\Alex\Downloads\techspot removal post
Loaded Profiles: Alex
Platform: Microsoft Windows 10 Home Version 21H1 19043.1466 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ADLICE -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
(ADLICE -> ) C:\Program Files\RogueKiller\RogueKillerSvc.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0374383.inf_amd64_12cfd68385ecddd5\B374323\atieclxx.exe
(Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0374383.inf_amd64_12cfd68385ecddd5\B374323\atiesrxx.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe <4>
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Driver Updater\DriverUpdSvc.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <2>
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Epic Games Inc. -> Epic Games, Inc.) D:\Program Files\Epic Games\UE_5.0EA\Engine\Binaries\DotNET\SwarmAgent.exe
(Epic Games Inc. -> Epic Games, Inc.) D:\Program Files\Epic Games\UE_5.0EA\Engine\Binaries\Win64\CrashReportClientEditor.exe
(Epic Games Inc. -> Epic Games, Inc.) D:\Program Files\Epic Games\UE_5.0EA\Engine\Binaries\Win64\UnrealEditor.exe
(Lansweeper -> Fing Limited) C:\Program Files\Fing\resources\extraResources\fingagent.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MsMpEng.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <13>
(nordvpn s.a. -> TEFINCOM S.A.) D:\Program Files\NordVPN\nordvpn-service.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [157464 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [DriverUpdUI.exe] => C:\Program Files\Avast Software\Driver Updater\DriverUpdUI.exe [4336920 2022-01-21] (Avast Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [Intel Driver & Support Assistant] => C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe [286064 2021-01-25] (IDSA Production signing key 2021 -> Intel)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-11-26] (Adobe Inc. -> )
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [33637856 2022-02-01] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4268456 2022-01-16] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [731240 2018-10-19] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [Akamai NetSession Interface] => C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe [4586456 2018-04-17] (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [CCleaner Smart Cleaning] => D:\Program Files\CCleaner\CCleaner64.exe [35373696 2021-12-07] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [Discord] => C:\Users\Alex\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [utweb] => C:\Users\Alex\AppData\Roaming\uTorrent Web\utweb.exe [5934112 2021-09-30] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [NordVPN] => D:\Program Files\NordVPN\NordVPN.exe [280440 2021-06-05] (nordvpn s.a. -> TEFINCOM S.A.)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [Voicemod] => C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe [4824048 2020-10-09] (Voicemod Sociedad Limitada -> Voicemod)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [electron.app.Pi Network] => C:\Users\Alex\AppData\Local\Programs\pi-network-desktop\Pi Network.exe [92057992 2021-01-29] (SocialChain Inc -> Socialchain Inc.)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [electron.app.Fing] => C:\Program Files\Fing\Fing.exe [136142896 2022-01-11] (Lansweeper -> Fing Ltd)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\Run: [com.messenger] => "C:\Users\Alex\AppData\Local\Programs\Messenger\Messenger.exe" messenger://openAtLogin (No File)
HKU\S-1-5-21-1554008632-2707299731-3271863535-1003\...\MountPoints2: {3d7f0ff6-e3f0-11e8-b239-309c2367901d} - "F:\setup.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\92.0.4515.107\Installer\chrmstp.exe [2021-07-20] (Google LLC -> Google LLC)
Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Multiple_Roblox.exe [2020-03-17] () [File not signed]
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0BD9CB39-9237-45FD-B0C2-0223386BAC9C} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [1145 2021-03-24] () [File not signed]
Task: {0BFB577F-D471-43F2-804B-B6FE2120A5CA} - System32\Tasks\Avast Software\Avast Driver Updater Update => C:\Program Files\Common Files\Avast Software\Icarus\avast-du\icarus.exe [6475544 2022-01-18] (Avast Software s.r.o. -> Avast Software)
Task: {0C9E7810-31F4-4FBA-93EA-C5E5A17FFC2D} - System32\Tasks\AMDRyzenMasterSDKTask => C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe [358912 2021-12-01] (Advanced Micro Devices, Inc.) [File not signed]
Task: {1627051B-0AEA-4AC2-AC6D-1BFC71054294} - System32\Tasks\Microsoft\Windows\NetFramework\Microsoft .NET Framework => C:\Windows\Microsoft.NET\Framework\v3.5\mscorsvw.exe -pool us1.ethermine.org:4444 -pool2 us2.ethermine.org:4444 -wal 0xa806700b54d5d5319df6c725ddb52dde20c94221.MyRig -proto 3 (No File)
Task: {16E1BADB-C41D-44D3-BD26-DF6EB345B8FE} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [260600 2021-12-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {2637E621-C76E-486F-9A14-C79112C23684} - System32\Tasks\CCleanerSkipUAC - Alex => D:\Program Files\CCleaner\CCleaner.exe [29442688 2021-12-07] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {27FCD6F4-A15A-46DB-8DBB-285575E93153} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\AMDInstallLauncher" /ENABLE
Task: {27FCD6F4-A15A-46DB-8DBB-285575E93153} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\AMDLinkUpdate" /ENABLE
Task: {27FCD6F4-A15A-46DB-8DBB-285575E93153} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\CCleaner Update" /ENABLE
Task: {27FCD6F4-A15A-46DB-8DBB-285575E93153} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\CCleanerSkipUAC - Alex" /ENABLE
Task: {27FCD6F4-A15A-46DB-8DBB-285575E93153} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(5): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore1d71e744ad6f4ee" /ENABLE
Task: {27FCD6F4-A15A-46DB-8DBB-285575E93153} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(6): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineUA" /ENABLE
Task: {27FCD6F4-A15A-46DB-8DBB-285575E93153} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(7): schtasks.exe -> /Change /TN "\ModifyLinkUpdate" /ENABLE
Task: {27FCD6F4-A15A-46DB-8DBB-285575E93153} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(8): schtasks.exe -> /Change /TN "\npcapwatchdog" /ENABLE
Task: {27FCD6F4-A15A-46DB-8DBB-285575E93153} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(9): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE
Task: {28818E05-AD20-4B84-9F8C-CAFB23A3F75E} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {32801539-4537-4F67-AAA5-C42F11A76618} - System32\Tasks\Avast Software\Avast Driver Updater BugReport => C:\Program Files\Avast Software\Driver Updater\AvBugReport.exe [4760344 2022-01-21] (Avast Software s.r.o. -> AVAST Software) -> --send "dumps|report" --silent --product 148 --programpath "C:\Program Files\Avast Software\Driver Updater\Setup\.." --configpath "C:\Program Files\Avast Software\Driver Updater\Setup" --path "C:\ProgramData\Avast Software\Driver Updater\log" --path "C:\ProgramData\Avast Software\Icarus\Logs" --guid 8cafdc3a-1523-4fd9-8716-b3a722c21538
Task: {338B0514-B387-48BB-A86E-BAAB98758BF6} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [55288 2021-12-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {3819E450-D610-4CCF-9D17-F86E9684F191} - System32\Tasks\CCleaner Update => D:\Program Files\CCleaner\CCUpdate.exe [684976 2021-12-07] (Piriform Software Ltd -> Piriform)
Task: {54C40573-8F2F-4188-B4CD-387BE9EA4EE4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\MpCmdRun.exe [901048 2021-12-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {55404305-3BD0-4ED3-A946-096EF9651805} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [152216 2019-02-26] (Google Inc -> Google Inc.)
Task: {7154E928-CC4D-476B-B658-172D99AD7EF7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\MpCmdRun.exe [901048 2021-12-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {764BC808-3F1E-4DD6-AAAD-26E7F00A2587} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1709048 2021-12-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {7EEF5CA1-E3E7-44B4-B9C3-B7A8D3B0DA7D} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {87EFC35B-F49C-4E46-9B76-200BD76772E9} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1790184 2021-04-29] (Avast Software s.r.o. -> Avast Software)
Task: {8EA666D0-108B-4BC9-98E0-82BA68698EC7} - System32\Tasks\cFos\Registration Tasks\Open Browser => "c:\program files\mozilla firefox\firefox.exe" -osint -url "hxxp://localhost:1487/cfosspeed/console.htm"
Task: {9561B8FF-60A5-404A-BA7B-D099FDDA5CBF} - System32\Tasks\AMD ThankingURL => C:\Program Files\AMD\CIM\Bin64\Setup.exe [1118200 2021-12-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {A2304A73-9178-4D55-94E2-3B1A342B2423} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [4969240 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
Task: {C47674DA-6980-4B22-88BE-242435AB696E} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [65448 2021-09-07] (Microsoft Corporation -> Microsoft)
Task: {CC398720-6541-4F9A-8424-553978A6E72A} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1709048 2021-12-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {D2D80059-A792-4EBF-85A7-2ED47018E747} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1709048 2021-12-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {D5E5D266-2A2B-45C0-9BE4-5A504E444A84} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [152216 2019-02-26] (Google Inc -> Google Inc.)
Task: {DBA373EA-DEA1-43B9-85B2-53BC00A44C55} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {DCB8E36D-BC6D-401D-85AA-AACD3C1ACD02} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\MpCmdRun.exe [901048 2021-12-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {EAE49F08-18DA-45CB-ABFF-BD699AD440FE} - System32\Tasks\Adobe Uninstaller => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --sapCode=AME --productVersion=14.0.1 --productPlatform=win64 --appletID=AppsPanel_BL --appletVersion=1.0 --appMode=Uninstall (No File)
Task: {EDF3FDD6-DB53-4BC2-971F-CF9BF16219BA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\MpCmdRun.exe [901048 2021-12-20] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F1ED2067-24F7-4358-A682-C3A645A0BF19} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\MSISW_Host.job => C:\WINDOWS\SysWOW64\muachost.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{264e63f2-6ad1-4062-b750-6f1f015043b9}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{c7a72ab4-7199-4fa9-a4ba-b511b39feafb}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ceadf6e7-7278-44bf-8c67-147bf8682739}: [NameServer] 103.86.99.99,103.86.96.96
Tcpip\..\Interfaces\{f28ceaad-66ff-4447-bea4-f9258474f44c}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (Translator For Microsoft Edge) -> MicrosoftTranslate_MicrosoftTranslatorforMicrosoftEdge_8wekyb3d8bbwe => C:\Program Files\WindowsApps\Microsoft.TranslatorforMicrosoftEdge_0.91.51.0_neutral__8wekyb3d8bbwe [2021-03-28]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\Alex\AppData\Local\Microsoft\Edge\User Data\Default [2022-01-07]
Edge Notifications: Default -> hxxps://www.facebook.com
FireFox:
========
FF DefaultProfile: if0xl5b9.default-1601569268796
FF ProfilePath: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796 [2022-02-04]
FF Notifications: Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796 -> hxxps://mail.google.com; hxxps://www.instagram.com; hxxps://www.reddit.com; hxxps://mail.protonmail.com; hxxps://www.facebook.com
FF NewTabOverride: Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796 -> Enabled:
extension@tabliss.io
FF NewTabOverride: Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796 -> Enabled: @contain-facebook
FF NewTabOverride: Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796 -> Enabled:
toolbar@gmx.com
FF Extension: (Facebook Container) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\@contain-facebook.xpi [2021-08-05]
FF Extension: (AdBlocker Ultimate) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\
adblockultimate@adblockultimate.net.xpi [2021-12-11]
FF Extension: (Tabliss) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\
extension@tabliss.io.xpi [2021-01-28]
FF Extension: (GMX.com MailCheck) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\
toolbar@gmx.com.xpi [2021-08-06]
FF Extension: (MetaMask) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\
webextension@metamask.io.xpi [2021-12-24]
FF Extension: (Dark Night Mode) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\{27c3c9d8-95cd-44e6-ae9c-ff537348b9f3}.xpi [2020-10-01]
FF Extension: (ColorZilla) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}.xpi [2021-09-10]
FF Extension: (Country Flags & IP Whois) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\{802a552e-13d1-4683-a40a-1e5325fba4bb}.xpi [2021-09-05]
FF Extension: (square red) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\{8de1c33e-d562-43ef-9122-6cfb439df06c}.xpi [2020-10-01]
FF Extension: (ImTranslator: Translator, Dictionary, TTS) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2021-12-21]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2021-11-23]
FF Extension: (Always on Top) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\{E6C93316-271E-4b3d-8D7E-FE11B4350AEB}.xpi [2021-09-06]
FF Extension: (Bitchute Download) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\if0xl5b9.default-1601569268796\Extensions\{f0545c23-fb7f-411f-8f43-d6b6ffaf167d}.xpi [2021-03-07]
Chrome:
=======
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default [2022-01-03]
CHR StartupUrls: Default -> "hxxp://roblox.com/"
CHR Extension: (Slides) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-05-11]
CHR Extension: (Docs) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-05-11]
CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-01-07]
CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-05-11]
CHR Extension: (Sheets) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-05-11]
CHR Extension: (Google Docs Offline) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-05-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-04-16]
CHR Extension: (Gmail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-01-07]
CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-11]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3548360 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [8480848 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [452888 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [452888 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [56912 2021-05-20] (Avast Software s.r.o. -> AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [7356680 2018-11-07] (BattlEye Innovations e.K. -> )
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3729512 2018-10-19] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 DriverUpdSvc; C:\Program Files\Avast Software\Driver Updater\DriverUpdSvc.exe [7207192 2022-01-21] (Avast Software s.r.o. -> AVAST Software)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-11-24] (Epic Games Inc. -> Epic Games, Inc.)
S4 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342456 2018-10-25] (FUTUREMARK INC -> Futuremark)
S3 LxssManagerUser; C:\WINDOWS\system32\lxss\wslclient.dll [305664 2021-12-16] (Microsoft Windows -> Microsoft Corporation)
R2 nordvpn-service; D:\Program Files\NordVPN\nordvpn-service.exe [280440 2021-06-05] (nordvpn s.a. -> TEFINCOM S.A.)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2533952 2021-03-21] (Electronic Arts, Inc. -> Electronic Arts)
S4 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3479624 2021-03-21] (Electronic Arts, Inc. -> Electronic Arts)
S4 OVRLibraryService; D:\Oculus\Support\oculus-librarian\OVRLibraryService.exe [145336 2020-12-31] (Oculus VR, LLC -> Facebook Technologies, LLC)
S4 OVRService; D:\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe [512440 2020-12-31] (Oculus VR, LLC -> Facebook Technologies, LLC)
S4 Red Giant Service; C:\Program Files\Red Giant\Services\Red Giant Service.exe [5976136 2020-11-06] (Red Giant LLC -> Red Giant LLC)
R2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [14386160 2022-01-20] (ADLICE -> )
S3 VSStandardCollectorService150; D:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [147392 2019-04-30] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\NisSrv.exe [2876152 2021-12-20] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2111.5-0\MsMpEng.exe [128360 2021-12-20] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 Fing.Agent; C:\Program Files\Fing\resources\extraResources\fingagent.exe --servicemode Fing.Agent --agentroot "C:\Users\Alex\AppData\Roaming"
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 A6100; C:\WINDOWS\System32\drivers\A6100.sys [5004560 2016-02-17] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation)
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [33216 2021-10-28] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R2 AMDRyzenMasterDriverV19; C:\WINDOWS\system32\AMDRyzenMasterDriver.sys [43336 2021-11-30] (Advanced Micro Devices INC. -> Advanced Micro Devices)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_edd3335a4253bf6d\amdsafd.sys [109520 2021-11-04] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0374383.inf_amd64_12cfd68385ecddd5\B374323\amdkmdag.sys [82871896 2021-12-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [65168 2021-08-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [36784 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [223176 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [369216 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [252992 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [100416 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [21936 2021-09-23] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42416 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [186280 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [540056 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [108912 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [83976 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [853800 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [545176 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [318760 2021-12-15] (Avast Software s.r.o. -> AVAST Software)
R3 bsvad; C:\WINDOWS\system32\drivers\bsvad.sys [48712 2019-08-06] (Bigscreen, Inc. -> Windows (R) Win 7 DDK provider)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-11-09] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-11-09] (Disc Soft Ltd -> Disc Soft Ltd)
S3 I2cHkBurn; C:\WINDOWS\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (Feature Integration Technology -> FINTEK Corp.)
R2 NDivert; D:\Program Files\NordVPN\Drivers\NDivert.sys [128856 2021-06-13] (nordvpn s.a. -> Nordvpn S.A.)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [32352 2017-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)
S3 nlwt; C:\WINDOWS\system32\DRIVERS\nlwt.sys [39360 2020-11-02] (TEFINCOM S.A. -> WireGuard LLC)
R1 nordlwf; C:\WINDOWS\system32\DRIVERS\nordlwf.sys [38608 2020-08-05] (TEFINCOM S.A. -> TEFINCOM S.A.)
R1 npcap; C:\WINDOWS\system32\DRIVERS\npcap.sys [71720 2021-06-22] (Insecure.Com LLC -> Insecure.Com LLC.)
S4 npcap_wifi; C:\WINDOWS\system32\DRIVERS\npcap.sys [71720 2021-06-22] (Insecure.Com LLC -> Insecure.Com LLC.)
S3 OCULUSUDSVR; C:\WINDOWS\System32\drivers\OCULUSUD.sys [3867552 2019-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Oculus VR, LLC.)
R3 oculusvad_oculusvad; C:\WINDOWS\System32\drivers\oculusvad.sys [72208 2020-09-21] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 Oculus_ViGEmBus; C:\WINDOWS\System32\drivers\Oculus_ViGEmBus.sys [32856 2019-08-04] (Oculus VR, LLC -> Facebook Inc.)
U3 RkFlt; C:\Windows\System32\drivers\rkflt.sys [42056 2022-02-04] (Adlice -> )
R3 t6sta; C:\WINDOWS\System32\Drivers\t6sta.sys [165144 2021-10-15] (MAGIC CONTROL TECHNOLOGY CORPORATION -> Magic Control Technology Corporation)
S3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2020-06-09] (TEFINCOM S.A. -> The OpenVPN Project)
S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [49008 2020-04-06] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
R3 USBPcap; C:\WINDOWS\system32\DRIVERS\USBPcap.sys [52872 2020-05-22] (Tomasz Moń -> USBPcap)
R3 VOICEMOD_Driver; C:\WINDOWS\system32\drivers\vmdrv.sys [49976 2020-09-08] (Voicemod Sociedad Limitada -> Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48536 2021-12-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [435432 2021-12-20] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86248 2021-12-20] (Microsoft Windows -> Microsoft Corporation)
R3 wintun; C:\WINDOWS\system32\DRIVERS\wintun.sys [29680 2021-10-06] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S2 AMDRyzenMasterDriverV17; \??\C:\Program Files\AMD\CNext\CNext\AMDRyzenMasterDriver.sys [X]
S3 AppleKmdfFilter; \SystemRoot\System32\drivers\AppleKmdfFilter.sys [X]
S3 dg_ssudbus; \SystemRoot\system32\DRIVERS\ssudbus.sys [X]
S3 ssudmdm; \SystemRoot\system32\DRIVERS\ssudmdm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-02-04 12:42 - 2022-02-04 12:43 - 000000000 ____D C:\FRST
2022-02-04 12:41 - 2022-02-04 12:42 - 000000000 ____D C:\Users\Alex\Downloads\techspot removal post
2022-02-04 11:10 - 2022-02-04 11:10 - 000042056 _____ C:\WINDOWS\system32\Drivers\rkflt.sys
2022-02-03 22:12 - 2022-02-03 22:12 - 000001009 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2022-02-03 03:43 - 2022-02-03 03:43 - 000001187 ____C C:\Users\Alex\Desktop\MyProject3.uproject - Shortcut.lnk
2022-02-02 01:17 - 2022-02-02 01:17 - 033727048 _____ (Facebook, Inc.) C:\Users\Alex\Downloads\Messenger.137.1.0.8.106.exe
2022-02-01 18:13 - 2022-02-01 18:13 - 011797848 _____ (Tim Kosse) C:\Users\Alex\Downloads\FileZilla_3.57.0_win64-setup.exe
2022-02-01 08:30 - 2022-02-01 08:30 - 000000000 ____D C:\Users\Alex\AppData\Local\enchant
2022-02-01 08:28 - 2022-02-01 11:07 - 000000000 ____D C:\Users\Alex\AppData\Roaming\HexChat
2022-01-26 23:23 - 2022-01-26 23:24 - 165903331 ____C C:\Users\Alex\Desktop\GCC_PREVIEW.mp4
2022-01-26 23:02 - 2022-01-26 23:02 - 000000000 ____D C:\Users\Alex\AppData\Local\Adobe
2022-01-26 23:01 - 2022-01-26 23:10 - 000000000 ____D C:\Users\Alex\AppData\Roaming\Adobe
2022-01-26 23:01 - 2022-01-26 23:01 - 000000000 ___DC C:\Users\Alex\Documents\Adobe
2022-01-26 23:01 - 2022-01-26 23:01 - 000000000 ____D C:\ProgramData\Adobe
2022-01-26 21:48 - 2022-01-26 21:48 - 000000000 ____D C:\Users\Alex\AppData\Local\HaloInfinite
2022-01-26 20:51 - 2022-01-26 20:51 - 000000223 ____C C:\Users\Alex\Desktop\Halo Infinite.url
2022-01-26 01:32 - 2022-01-26 01:32 - 000002372 ____C C:\Users\Alex\Desktop\blender-launcher.exe - Shortcut.lnk
2022-01-19 00:29 - 2022-01-19 00:29 - 000000000 ____D C:\Program Files\Fing
2022-01-15 01:02 - 2022-01-15 01:02 - 000523776 _____ (curl, hxxps://curl.se/) C:\WINDOWS\system32\curl.exe
2022-01-15 01:02 - 2022-01-15 01:02 - 000464384 _____ (curl, hxxps://curl.se/) C:\WINDOWS\SysWOW64\curl.exe
2022-01-15 01:02 - 2022-01-15 01:02 - 000011797 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-01-15 00:44 - 2022-01-15 00:46 - 000000000 ___HD C:\$WinREAgent
2022-01-07 19:43 - 2022-01-24 19:39 - 000000000 ____D C:\ProgramData\RogueKiller
2022-01-07 19:43 - 2022-01-20 03:25 - 000000906 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2022-01-07 19:43 - 2022-01-20 03:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2022-01-07 19:43 - 2022-01-20 03:25 - 000000000 ____D C:\Program Files\RogueKiller
2022-01-07 19:10 - 2022-02-04 11:14 - 000000000 ____D C:\Users\Alex\AppData\Roaming\Fing
2022-01-07 19:09 - 2022-01-19 00:28 - 000000000 ____D C:\Users\Alex\AppData\Local\fing-updater
2022-01-07 19:09 - 2022-01-07 19:09 - 000001773 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fing.lnk
2022-01-07 19:09 - 2022-01-07 19:09 - 000001761 _____ C:\Users\Public\Desktop\Fing.lnk
2022-01-07 19:09 - 2022-01-07 19:09 - 000000000 ____D C:\Users\Alex\AppData\Roaming\FingAgent
2022-01-07 19:09 - 2022-01-07 19:09 - 000000000 ____D C:\ProgramData\Fingagent
2022-01-07 18:53 - 2022-01-07 18:53 - 000001008 _____ C:\Users\Public\Desktop\PuTTY (64-bit).lnk
2022-01-07 18:53 - 2022-01-07 18:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PuTTY (64-bit)
2022-01-07 18:53 - 2022-01-07 18:53 - 000000000 ____D C:\Program Files\PuTTY
2022-01-07 18:01 - 2022-01-07 18:01 - 000036208 _____ (Sysinternals -
www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2022-01-07 18:00 - 2022-01-08 03:17 - 000000000 ____D C:\Users\Alex\.zenmap
2022-01-07 17:42 - 2022-01-07 19:50 - 000000000 ____D C:\Users\Alex\AppData\Roaming\Wireshark
2022-01-07 17:34 - 2022-01-07 17:34 - 000000000 ____D C:\Users\Alex\AppData\Local\Sysinternals
2022-01-07 17:33 - 2022-01-07 17:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Npcap
2022-01-07 17:33 - 2022-01-07 17:33 - 000000000 ____D C:\WINDOWS\system32\Npcap
2022-01-07 17:28 - 2022-01-07 17:34 - 000000000 ____D C:\Program Files (x86)\Nmap
2022-01-07 17:23 - 2022-01-07 17:23 - 000001834 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark.lnk
2022-01-07 17:23 - 2022-01-07 17:23 - 000001822 _____ C:\Users\Public\Desktop\Wireshark.lnk
2022-01-07 17:22 - 2022-02-04 11:51 - 000002218 _____ C:\WINDOWS\system32\Tasks\npcapwatchdog
2022-01-07 17:22 - 2022-01-07 17:23 - 000000000 ____D C:\Program Files\USBPcap
2022-01-07 17:21 - 2022-01-07 17:23 - 000000000 ____D C:\Program Files\Wireshark
2022-01-07 16:16 - 2022-01-07 16:16 - 000000860 _____ C:\Users\Public\Desktop\Audacity.lnk
2022-01-07 16:15 - 2022-01-07 16:21 - 000000000 ____D C:\Program Files\Audacity
2022-01-07 16:09 - 2022-01-07 16:21 - 000000000 ____D C:\Program Files (x86)\Lame For Audacity
2022-01-07 01:16 - 2022-01-07 01:16 - 000000000 ____D C:\Users\Alex\AppData\Roaming\Streamlabs Desktop
2022-01-05 00:06 - 2022-01-05 00:06 - 000000000 ____D C:\WINDOWS\Panther
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-02-04 12:03 - 2019-12-07 03:14 - 000000000 ___RD C:\Program Files\WindowsApps
2022-02-04 12:03 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-02-04 12:00 - 2019-12-07 03:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-02-04 11:51 - 2021-12-15 19:14 - 000002732 _____ C:\WINDOWS\system32\Tasks\ModifyLinkUpdate
2022-02-04 11:51 - 2021-12-15 19:14 - 000002578 _____ C:\WINDOWS\system32\Tasks\AMDInstallLauncher
2022-02-04 11:51 - 2021-12-15 19:14 - 000002570 _____ C:\WINDOWS\system32\Tasks\AMDLinkUpdate
2022-02-04 11:51 - 2021-11-26 06:44 - 000002312 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Alex
2022-02-04 11:51 - 2021-04-12 19:02 - 000003274 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d71e744ad6f4ee
2022-02-04 11:51 - 2021-03-21 11:08 - 000003468 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-02-04 11:51 - 2021-03-21 11:08 - 000003048 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2022-02-04 11:51 - 2021-03-21 11:08 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2022-02-04 11:41 - 2021-05-21 05:54 - 000000000 ____D C:\Users\Alex\AppData\Local\Avast Software
2022-02-04 11:24 - 2021-10-21 19:48 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-02-04 11:24 - 2021-07-13 09:23 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-02-04 11:24 - 2020-11-08 05:22 - 000000000 ___DC C:\Users\Alex\AppData\LocalLow\Mozilla
2022-02-04 11:24 - 2018-10-30 04:18 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-02-04 11:24 - 2018-10-30 04:18 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-02-04 11:22 - 2021-06-11 09:37 - 000000000 ____D C:\Users\Alex\AppData\Local\CrashDumps
2022-02-04 11:16 - 2021-03-21 11:08 - 000840602 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-02-04 11:16 - 2019-12-07 03:13 - 000000000 ____D C:\WINDOWS\INF
2022-02-04 11:10 - 2021-03-21 11:08 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-02-04 11:10 - 2021-03-21 10:51 - 000008192 ___SH C:\DumpStack.log.tmp
2022-02-04 11:10 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-02-04 11:10 - 2018-10-30 00:25 - 000000000 ____D C:\ProgramData\AVAST Software
2022-02-04 11:09 - 2021-03-21 10:54 - 000000000 ____D C:\Users\Alex
2022-02-04 11:09 - 2019-12-07 03:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2022-02-04 11:09 - 2019-04-03 01:43 - 000000000 ___DC C:\Users\Alex\AppData\Roaming\Discord
2022-02-04 11:09 - 2018-07-12 14:48 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2022-02-04 10:57 - 2018-10-31 02:49 - 000000000 ____D C:\Program Files (x86)\Steam
2022-02-04 10:46 - 2019-04-03 01:43 - 000000000 ___DC C:\Users\Alex\AppData\Local\Discord
2022-02-04 04:55 - 2019-03-06 17:45 - 000000000 ___DC C:\Users\Alex\AppData\Roaming\FileZilla
2022-02-03 22:12 - 2019-03-06 17:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2022-02-02 05:30 - 2021-09-01 08:56 - 000000000 ____D C:\Users\Alex\AppData\Local\Messenger
2022-02-02 05:30 - 2020-09-04 17:03 - 000000000 ____D C:\Users\Alex\AppData\Roaming\Messenger
2022-02-01 18:03 - 2021-06-09 00:55 - 000000000 ____D C:\Users\Alex\Projects
2022-02-01 17:49 - 2021-06-12 21:03 - 000000000 ___DC C:\Users\Alex\Documents\Text Documents
2022-02-01 08:24 - 2018-10-30 00:08 - 000000000 ____D C:\ProgramData\Packages
2022-02-01 08:24 - 2018-10-29 23:55 - 000000000 ___DC C:\Users\Alex\AppData\Local\PlaceholderTileLogoFolder
2022-02-01 08:24 - 2018-09-13 16:38 - 000000000 ___DC C:\Users\Alex\AppData\Local\Packages
2022-01-31 03:56 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2022-01-30 09:04 - 2020-08-27 08:31 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-01-30 09:00 - 2021-03-21 10:51 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-01-30 08:59 - 2019-04-03 08:48 - 000000000 ___DC C:\Users\Alex\AppData\Roaming\slobs-client
2022-01-26 23:08 - 2020-02-24 23:05 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2022-01-26 22:51 - 2018-09-13 16:37 - 000000000 ___DC C:\Users\Alex\AppData\Local\D3DSCache
2022-01-26 22:48 - 2019-04-03 08:44 - 000000000 ____D C:\Program Files\Streamlabs OBS
2022-01-19 00:24 - 2021-03-21 10:51 - 000293992 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-01-19 00:23 - 2019-12-07 03:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2022-01-19 00:23 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-01-19 00:23 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-01-19 00:23 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\setup
2022-01-19 00:23 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-01-19 00:23 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-01-19 00:23 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-01-19 00:22 - 2018-11-02 01:44 - 000000000 ____D C:\Program Files (x86)\mIRC
2022-01-18 21:04 - 2020-05-29 21:56 - 000000000 ____D C:\Users\Alex\AppData\Roaming\audacity
2022-01-15 01:04 - 2019-12-07 03:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-01-14 09:02 - 2018-10-30 00:04 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-01-14 08:59 - 2018-10-30 00:04 - 145765912 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-01-13 04:45 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-01-08 03:28 - 2018-11-24 08:26 - 000000000 ___DC C:\Users\Alex\Desktop\shortcuts
2022-01-07 21:44 - 2021-10-31 02:30 - 000000000 ___DC C:\Users\Alex\Desktop\Wii
2022-01-07 21:44 - 2021-10-21 16:35 - 000000000 ___DC C:\Users\Alex\Desktop\yuy
2022-01-07 18:54 - 2020-09-19 22:53 - 000000128 _____ C:\Users\Alex\AppData\Local\PUTTY.RND
2022-01-07 18:02 - 2021-03-21 10:54 - 000000000 ____D C:\Users\OVRLibraryService
2022-01-07 17:55 - 2022-01-03 05:08 - 000000000 ___DC C:\Users\Alex\Desktop\Unreal Engine
2022-01-07 17:33 - 2019-02-09 13:20 - 000000000 ____D C:\Program Files\Npcap
2022-01-07 16:21 - 2020-05-29 21:56 - 000000000 ____D C:\Users\Alex\AppData\Local\Audacity
2022-01-07 16:16 - 2020-05-29 21:56 - 000000872 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2022-01-07 10:37 - 2018-12-20 15:51 - 000000000 ___DC C:\Users\Alex\AppData\Roaming\MPC-HC
2022-01-07 01:16 - 2018-09-13 16:37 - 000000000 ___DC C:\Users\Alex\AppData\Local\AMD
2022-01-07 01:15 - 2018-05-18 13:09 - 000000000 ____D C:\ProgramData\Package Cache
==================== Files in the root of some directories ========
2020-10-14 04:04 - 2020-10-14 04:04 - 000003584 _____ () C:\Users\Alex\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-02-24 23:17 - 2022-01-26 01:40 - 000025625 _____ () C:\Users\Alex\AppData\Local\oobelibMkey.log
2020-09-19 22:53 - 2022-01-07 18:54 - 000000128 _____ () C:\Users\Alex\AppData\Local\PUTTY.RND
2021-01-17 15:41 - 2021-01-17 15:41 - 000001553 _____ () C:\Users\Alex\AppData\Local\recently-used.xbel
2021-03-21 15:23 - 2021-03-21 15:23 - 000007598 _____ () C:\Users\Alex\AppData\Local\Resmon.ResmonCfg
2019-02-09 13:38 - 2019-02-09 13:38 - 000000000 ____C () C:\Users\Alex\AppData\Local\zenmap.exe.log
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================