My computer takes much longer to finish booting windows after logging in and I noticed three black command line windows appearing and disappearing very quickly. Please see FRST logs below.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-05-2021 01
Ran by Matthew Balent (administrator) on MATTHEW-4790K-B (ASUS All Series) (31-05-2021 15:42:10)
Running from C:\Users\Matthew Balent\Desktop\Installers
Loaded Profiles: Matthew Balent
Platform: Windows 10 Home Version 21H1 19043.985 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(A. & M. Neuber Software -> Neuber Software) C:\Program Files (x86)\Security Task Manager\TaskMan.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.CpuIdRemote64.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.DisplayAdapter.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CueLLAccessService.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <18>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.17003.0_x64__8wekyb3d8bbwe\GamingServices.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.17003.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CastSrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MsMpEng.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmdi.inf_amd64_b5c7e9f1cc7d29c6\Display.NvContainer\NVDisplay.Container.exe <2>
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\...\Run: [ScanSnap WIA Service Checker] => C:\Program Files (x86)\PFU\ScanSnap\Driver\SSDriver\fi5110\SsWiaChecker.exe [86016 2016-02-18] (PFU LIMITED) [File not signed]
HKLM-x32\...\Run: [ScanSnap OnlineUpdate Watcher] => C:\Program Files (x86)\PFU\ScanSnap\Update\SsUWatcher.exe [454144 2016-09-06] (PFU Limited) [File not signed]
HKLM-x32\...\Run: [CORSAIR iCUE Software] => C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\iCUE Launcher.exe [410152 2020-12-29] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
HKU\S-1-5-21-2520759900-3737204395-3222954602-1001\...\Run: [Discord] => C:\Users\Matthew Balent\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.212\Installer\chrmstp.exe [2021-05-12] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnk [2019-11-19]
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU Limited) [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0601A0EE-3716-4125-9037-E0955DB02C9A} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {08BBC0A4-44A3-48FA-8203-E2FD2CC48EE8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {17702CE9-C78A-48A6-BCA4-9F49F1AEC786} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1CFE7997-0E02-4764-A22F-A573EF632952} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3A79F16C-176D-42D1-B510-92F555F2D986} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [127176 2020-05-17] (Mozilla Corporation -> Mozilla Foundation)
Task: {3F615222-DE8F-49DA-B14D-848C00F027E7} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {45EDEC4F-26BE-4FCF-87B9-140A2D0C9E85} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905584 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {63586D95-26CE-40E4-A8A1-0525CDD80ADD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {66F1D148-1B53-45E4-96FA-BE12FD1A34FC} - System32\Tasks\Core Temp Autostart Matthew Balent => C:\Program Files\Core Temp\Core Temp.exe
Task: {781E8D33-67EB-4B60-897B-8D1EFCBE102C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-27] (Google Inc -> Google LLC)
Task: {8598F86E-D765-4C36-AADF-D127C5E7C013} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AA2B3154-7F59-4BB0-A47B-D07B87E8BC29} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-09-28] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {AAAAC37B-3523-4C4D-B19E-E5D61B3187A7} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C2AA7653-CB60-4AC7-9811-FB382547AF85} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C4EE57C7-CE59-4834-AA50-D9221BA045E5} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905584 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C8697969-600B-4CA8-B9B1-CB7F4AC7BC9D} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3336560 2021-04-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D5427032-72ED-450D-BF10-695F3B0E4DBC} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [880 2020-09-24] () [File not signed]
Task: {DC712529-C239-4EA1-B4D5-6D47EEE02652} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-27] (Google Inc -> Google LLC)
Task: {F2489D9B-B2EB-4B2C-981B-E235C9CA17B2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {F73C1545-0D94-4B26-B019-65D2278D5507} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-09-28] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{42f495a5-b90e-4c59-bd85-a6da00ebf8f5}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{b5868b49-a737-4288-abe6-1d62c616eb22}: [DhcpNameServer] 192.168.1.1
Edge:
=======
DownloadDir: C:\Users\Matthew Balent\Downloads
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\Matthew Balent\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-31]
FireFox:
========
FF DefaultProfile: sgg8645v.default-1568009218829
FF ProfilePath: C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829 [2021-05-31]
FF Homepage: Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829 -> hxxps://mail.google.com/mail/u/0/#inbox
FF Extension: (Default Bookmark Folder) - C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829\Extensions\default-bookmark-folder@gustiaux.com.xpi [2020-03-12]
FF Extension: (Enhancer for YouTube™) - C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829\Extensions\enhancerforyoutube@maximerf.addons.mozilla.org.xpi [2020-04-02]
FF Extension: (HTTPS Everywhere) - C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829\Extensions\https-everywhere@eff.org.xpi [2020-04-02]
FF Extension: (To Google Translate) - C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2019-11-24]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-04-02]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-04-27] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2520759900-3737204395-3222954602-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Matthew Balent\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-12] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
Chrome:
=======
CHR Profile: C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default [2021-05-31]
CHR Notifications: Default -> hxxps://app.houseparty.com; hxxps://calendar.google.com; hxxps://voice.google.com
CHR HomePage: Default -> hxxp://gmail.com/
CHR StartupUrls: Default -> "hxxp://gmail.com/"
CHR Extension: (Slides) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-27]
CHR Extension: (Docs) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-27]
CHR Extension: (Google Drive) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-28]
CHR Extension: (YouTube) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-27]
CHR Extension: (Slinky Elegant) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln [2020-03-31]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-05-19]
CHR Extension: (uBlock Origin) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2021-05-09]
CHR Extension: (Adblock for Youtube™) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2021-05-18]
CHR Extension: (Sheets) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-27]
CHR Extension: (Google Docs Offline) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-05-14]
CHR Extension: (Microsoft Editor: Spelling & Grammar Checker) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpaiobkfhnonedkhhfjpmhdalgeoebfa [2021-05-19]
CHR Extension: (Zoom) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmbjbjdpkobdjplfobhljndfdfdipjhg [2021-05-27]
CHR Extension: (No Name) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\nenlahapcbofgnanklpelkaejcehkggg [2019-10-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-01]
CHR Extension: (Netflix Party is now Teleparty) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\oocalimimngaihdkbihfgmpkcpnmlaoa [2021-05-03]
CHR Extension: (Hulu Ad Skipper | Ad Blocker) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgpdfnkeeppfohmophlpcfmciioeenig [2021-01-04]
CHR Extension: (Gmail) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
CHR Extension: (Chrome Media Router) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-04-26]
CHR Profile: C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\System Profile [2021-05-14]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-07-03] (ASUSTeK Computer Inc. -> )
R2 CorsairGamingAudioConfig; C:\WINDOWS\system32\CorsairGamingAudioCfgService64.exe [616344 2020-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R2 CorsairLLAService; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CueLLAccessService.exe [421928 2020-12-29] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
R2 CorsairService; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.exe [80936 2020-12-29] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [818288 2020-11-24] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [926176 2021-03-16] (Epic Games Inc. -> Epic Games, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7391408 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2547288 2021-05-10] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3487320 2021-05-10] (Electronic Arts, Inc. -> Electronic Arts)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1679240 2021-02-16] (Rockstar Games, Inc. -> Rockstar Games)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13109776 2020-07-02] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\NisSrv.exe [2599328 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MsMpEng.exe [128376 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_b5c7e9f1cc7d29c6\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_b5c7e9f1cc7d29c6\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-03] (ASUSTeK Computer Inc. -> )
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
R3 CorsairGamingAudioService; C:\WINDOWS\system32\DRIVERS\CorsairGamingAudio64.sys [60312 2020-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R2 CorsairLLAccess3B84E98236B28D4E075D5737DF9F567A1FB76E8A; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CorsairLLAccess64.sys [21752 2020-11-19] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [45984 2020-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21920 2020-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 cpuz150; C:\WINDOWS\temp\cpuz150\cpuz150_x64.sys [44832 2021-05-30] (CPUID S.A.R.L.U. -> CPUID)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [199128 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
S3 kmloop; C:\WINDOWS\System32\drivers\loop.sys [17408 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220752 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-05-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [198888 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [77496 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [157944 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
R1 npcap; C:\WINDOWS\system32\DRIVERS\npcap.sys [74616 2020-09-25] (Insecure.Com LLC -> Insecure.Com LLC.)
S4 npcap_wifi; C:\WINDOWS\system32\DRIVERS\npcap.sys [74616 2020-09-25] (Insecure.Com LLC -> Insecure.Com LLC.)
S3 REDRAGON_MOUSE; C:\WINDOWS\system32\drivers\REDRAGON_MOUSE.sys [26112 2017-09-21] () [File not signed]
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [24000 2019-09-25] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
S3 ViGEmBus; C:\WINDOWS\System32\drivers\ViGEmBus.sys [53128 2018-01-19] (Microsoft Windows Hardware Compatibility Publisher -> Benjamin Höglinger-Stelzer)
S3 VKbms; C:\WINDOWS\System32\drivers\VKbms.sys [13824 2014-07-12] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2021-05-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [421112 2021-05-13] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [73960 2021-05-13] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-31 15:41 - 2021-05-31 15:42 - 000000000 ____D C:\FRST
2021-05-31 14:57 - 2021-05-31 14:57 - 000001231 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spy Protector.lnk
2021-05-31 14:57 - 2021-05-31 14:57 - 000001220 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager.lnk
2021-05-31 14:57 - 2021-05-31 14:57 - 000000000 ____D C:\ProgramData\SecTaskMan
2021-05-31 14:57 - 2021-05-31 14:57 - 000000000 ____D C:\Program Files (x86)\Security Task Manager
2021-05-30 20:25 - 2021-05-30 20:25 - 000198888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2021-05-30 20:25 - 2021-05-30 20:25 - 000157944 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2021-05-30 20:25 - 2021-05-30 20:25 - 000077496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2021-05-30 20:24 - 2021-05-30 20:24 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-05-30 20:24 - 2021-05-30 20:24 - 000220752 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-05-30 20:24 - 2021-05-30 20:24 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-05-30 20:24 - 2021-05-30 20:24 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2021-05-30 20:24 - 2021-05-30 20:24 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2021-05-30 20:23 - 2021-05-30 20:23 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-05-30 20:23 - 2021-05-30 20:23 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-05-30 20:23 - 2021-05-30 20:23 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-05-30 20:23 - 2021-05-30 20:23 - 000000000 ____D C:\Program Files\Malwarebytes
2021-05-20 17:39 - 2021-05-20 17:39 - 000197638 _____ C:\Users\Matthew Balent\Desktop\PSN Backup.mp4
2021-05-20 16:39 - 2021-05-13 03:38 - 000037656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhdap64.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2021-05-20 16:27 - 2021-05-13 11:22 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo.exe
2021-05-20 16:27 - 2021-05-13 11:22 - 001453360 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 001435880 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-05-20 16:27 - 2021-05-13 11:22 - 001435880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2021-05-20 16:27 - 2021-05-13 11:22 - 001192752 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 001094864 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 001094864 _____ C:\WINDOWS\system32\vulkan-1.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 000948968 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 000948968 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 001514800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 001166112 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 000715544 _____ C:\WINDOWS\system32\nvofapi64.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 000675104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 000626968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 000575768 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 000564000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2021-05-20 16:27 - 2021-05-13 11:18 - 002106144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2021-05-20 16:27 - 2021-05-13 11:18 - 001590576 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2021-05-20 16:27 - 2021-05-13 11:18 - 000811824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2021-05-20 16:27 - 2021-05-13 11:18 - 000689952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2021-05-20 16:27 - 2021-05-13 11:18 - 000445744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2021-05-20 16:27 - 2021-05-13 11:17 - 008317232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2021-05-20 16:27 - 2021-05-13 11:17 - 007434032 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2021-05-20 16:27 - 2021-05-13 11:17 - 004795184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2021-05-20 16:27 - 2021-05-13 11:17 - 002823472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2021-05-20 16:27 - 2021-05-13 11:16 - 000848688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2021-05-20 16:27 - 2021-05-13 11:15 - 006159152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2021-05-20 16:27 - 2021-05-13 03:38 - 000087164 _____ C:\WINDOWS\system32\nvinfo.pb
2021-05-15 15:48 - 2021-05-15 15:48 - 000000000 ____D C:\Program Files (x86)\Intel
2021-05-14 00:51 - 2021-05-14 00:51 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\GetsuFumaDen
2021-05-11 10:51 - 2021-05-11 10:51 - 000011351 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-31 15:42 - 2020-04-01 13:40 - 000000000 ____D C:\Users\Matthew Balent\Desktop\Installers
2021-05-31 14:46 - 2020-06-19 22:12 - 000004186 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{54E83F89-2951-42A7-B12A-1B696A9BC3FA}
2021-05-31 14:46 - 2019-06-27 18:36 - 000000000 ____D C:\ProgramData\NVIDIA
2021-05-30 22:36 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-05-30 22:36 - 2019-07-28 20:03 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\Battle.net
2021-05-30 22:02 - 2020-06-19 22:09 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-05-30 22:02 - 2019-07-28 20:03 - 000000000 ____D C:\Program Files (x86)\Battle.net
2021-05-30 21:20 - 2019-12-07 02:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-05-30 21:20 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-05-30 20:32 - 2020-06-19 22:12 - 000840598 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-05-30 20:32 - 2019-12-07 02:13 - 000000000 ____D C:\WINDOWS\INF
2021-05-30 20:28 - 2020-06-19 22:12 - 000003398 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2520759900-3737204395-3222954602-1001
2021-05-30 20:28 - 2020-06-19 21:57 - 000002394 _____ C:\Users\Matthew Balent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-05-30 20:28 - 2019-04-26 23:49 - 000000000 ___RD C:\Users\Matthew Balent\OneDrive
2021-05-30 20:27 - 2019-12-07 02:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2021-05-30 20:25 - 2020-06-19 22:12 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-05-30 20:25 - 2020-06-19 22:09 - 000008192 ___SH C:\DumpStack.log.tmp
2021-05-30 20:25 - 2019-12-07 02:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-05-30 20:25 - 2019-07-17 00:03 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-05-30 20:23 - 2019-12-07 02:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-05-30 20:23 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-05-30 00:21 - 2019-06-23 14:43 - 000000000 ____D C:\Users\Matthew Balent\AppData\Roaming\Discord
2021-05-29 23:28 - 2019-06-23 14:43 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\Discord
2021-05-29 15:27 - 2020-07-10 14:45 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-05-29 14:35 - 2019-05-16 17:06 - 000000000 ____D C:\Program Files (x86)\Overwatch
2021-05-23 14:32 - 2019-06-16 11:25 - 000001267 _____ C:\Users\Matthew Balent\Desktop\Downloads - Shortcut.lnk
2021-05-21 22:42 - 2021-03-14 16:21 - 000000000 ____D C:\Users\Matthew Balent\.zenmap
2021-05-21 15:25 - 2019-04-27 11:09 - 000000000 ____D C:\Users\Matthew Balent\AppData\LocalLow\Mozilla
2021-05-21 14:38 - 2020-05-17 10:48 - 001694672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2021-05-21 14:38 - 2020-05-17 10:48 - 000250304 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2021-05-21 14:38 - 2020-05-17 10:48 - 000192952 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2021-05-21 14:38 - 2020-05-17 10:48 - 000159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2021-05-21 14:38 - 2020-05-17 10:48 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2021-05-21 14:38 - 2020-05-17 10:48 - 000038328 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamemodcontrol.exe
2021-05-20 16:40 - 2019-06-27 18:45 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\NVIDIA
2021-05-19 17:52 - 2020-11-26 21:19 - 000000000 ____D C:\Program Files (x86)\Origin
2021-05-19 17:33 - 2019-04-27 11:09 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-05-18 19:21 - 2019-07-15 17:30 - 000000000 ____D C:\Users\Matthew Balent\GNS3
2021-05-18 19:21 - 2019-07-15 17:30 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\CrashDumps
2021-05-17 21:58 - 2021-03-16 19:34 - 000000000 ____D C:\Users\Matthew Balent\Desktop\IT Education
2021-05-15 16:38 - 2019-05-12 17:54 - 000000000 ____D C:\ProgramData\Package Cache
2021-05-15 15:37 - 2019-04-26 23:44 - 000000000 ____D C:\Program Files\Intel
2021-05-14 00:51 - 2019-06-17 19:41 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\UnrealEngine
2021-05-14 00:51 - 2019-06-17 19:41 - 000000000 ____D C:\ProgramData\Epic
2021-05-13 23:50 - 2019-04-26 23:39 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-05-13 11:18 - 2021-04-30 15:15 - 000656176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2021-05-13 11:15 - 2020-05-27 11:27 - 007212224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2021-05-13 03:38 - 2020-05-27 11:28 - 000136472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2021-05-12 17:03 - 2021-04-28 14:09 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-05-11 10:52 - 2020-06-19 22:09 - 000257904 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-05-11 10:52 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-05-11 10:52 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-05-11 10:47 - 2019-04-27 11:08 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-05-11 10:46 - 2019-04-27 11:08 - 132732536 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories ========
2019-07-16 23:56 - 2019-07-16 23:56 - 000002226 _____ () C:\Users\Matthew Balent\MarkYO.bat
2019-08-23 17:17 - 2019-09-03 15:45 - 000007606 _____ () C:\Users\Matthew Balent\AppData\Local\Resmon.ResmonCfg
2021-03-14 16:21 - 2021-03-14 16:21 - 000000000 _____ () C:\Users\Matthew Balent\AppData\Local\zenmap.exe.log
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-05-2021 01
Ran by Matthew Balent (administrator) on MATTHEW-4790K-B (ASUS All Series) (31-05-2021 15:42:10)
Running from C:\Users\Matthew Balent\Desktop\Installers
Loaded Profiles: Matthew Balent
Platform: Windows 10 Home Version 21H1 19043.985 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(A. & M. Neuber Software -> Neuber Software) C:\Program Files (x86)\Security Task Manager\TaskMan.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.CpuIdRemote64.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.DisplayAdapter.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CueLLAccessService.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <18>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.17003.0_x64__8wekyb3d8bbwe\GamingServices.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.53.17003.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CastSrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MsMpEng.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmdi.inf_amd64_b5c7e9f1cc7d29c6\Display.NvContainer\NVDisplay.Container.exe <2>
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\...\Run: [ScanSnap WIA Service Checker] => C:\Program Files (x86)\PFU\ScanSnap\Driver\SSDriver\fi5110\SsWiaChecker.exe [86016 2016-02-18] (PFU LIMITED) [File not signed]
HKLM-x32\...\Run: [ScanSnap OnlineUpdate Watcher] => C:\Program Files (x86)\PFU\ScanSnap\Update\SsUWatcher.exe [454144 2016-09-06] (PFU Limited) [File not signed]
HKLM-x32\...\Run: [CORSAIR iCUE Software] => C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\iCUE Launcher.exe [410152 2020-12-29] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
HKU\S-1-5-21-2520759900-3737204395-3222954602-1001\...\Run: [Discord] => C:\Users\Matthew Balent\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.212\Installer\chrmstp.exe [2021-05-12] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnk [2019-11-19]
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU Limited) [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0601A0EE-3716-4125-9037-E0955DB02C9A} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {08BBC0A4-44A3-48FA-8203-E2FD2CC48EE8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {17702CE9-C78A-48A6-BCA4-9F49F1AEC786} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1CFE7997-0E02-4764-A22F-A573EF632952} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3A79F16C-176D-42D1-B510-92F555F2D986} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [127176 2020-05-17] (Mozilla Corporation -> Mozilla Foundation)
Task: {3F615222-DE8F-49DA-B14D-848C00F027E7} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {45EDEC4F-26BE-4FCF-87B9-140A2D0C9E85} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905584 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {63586D95-26CE-40E4-A8A1-0525CDD80ADD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {66F1D148-1B53-45E4-96FA-BE12FD1A34FC} - System32\Tasks\Core Temp Autostart Matthew Balent => C:\Program Files\Core Temp\Core Temp.exe
Task: {781E8D33-67EB-4B60-897B-8D1EFCBE102C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-27] (Google Inc -> Google LLC)
Task: {8598F86E-D765-4C36-AADF-D127C5E7C013} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AA2B3154-7F59-4BB0-A47B-D07B87E8BC29} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-09-28] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {AAAAC37B-3523-4C4D-B19E-E5D61B3187A7} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C2AA7653-CB60-4AC7-9811-FB382547AF85} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C4EE57C7-CE59-4834-AA50-D9221BA045E5} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905584 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C8697969-600B-4CA8-B9B1-CB7F4AC7BC9D} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3336560 2021-04-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D5427032-72ED-450D-BF10-695F3B0E4DBC} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [880 2020-09-24] () [File not signed]
Task: {DC712529-C239-4EA1-B4D5-6D47EEE02652} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-27] (Google Inc -> Google LLC)
Task: {F2489D9B-B2EB-4B2C-981B-E235C9CA17B2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {F73C1545-0D94-4B26-B019-65D2278D5507} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-09-28] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{42f495a5-b90e-4c59-bd85-a6da00ebf8f5}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{b5868b49-a737-4288-abe6-1d62c616eb22}: [DhcpNameServer] 192.168.1.1
Edge:
=======
DownloadDir: C:\Users\Matthew Balent\Downloads
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\Matthew Balent\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-31]
FireFox:
========
FF DefaultProfile: sgg8645v.default-1568009218829
FF ProfilePath: C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829 [2021-05-31]
FF Homepage: Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829 -> hxxps://mail.google.com/mail/u/0/#inbox
FF Extension: (Default Bookmark Folder) - C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829\Extensions\default-bookmark-folder@gustiaux.com.xpi [2020-03-12]
FF Extension: (Enhancer for YouTube™) - C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829\Extensions\enhancerforyoutube@maximerf.addons.mozilla.org.xpi [2020-04-02]
FF Extension: (HTTPS Everywhere) - C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829\Extensions\https-everywhere@eff.org.xpi [2020-04-02]
FF Extension: (To Google Translate) - C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2019-11-24]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Matthew Balent\AppData\Roaming\Mozilla\Firefox\Profiles\sgg8645v.default-1568009218829\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-04-02]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-04-27] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2520759900-3737204395-3222954602-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Matthew Balent\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-12] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
Chrome:
=======
CHR Profile: C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default [2021-05-31]
CHR Notifications: Default -> hxxps://app.houseparty.com; hxxps://calendar.google.com; hxxps://voice.google.com
CHR HomePage: Default -> hxxp://gmail.com/
CHR StartupUrls: Default -> "hxxp://gmail.com/"
CHR Extension: (Slides) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-27]
CHR Extension: (Docs) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-27]
CHR Extension: (Google Drive) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-28]
CHR Extension: (YouTube) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-27]
CHR Extension: (Slinky Elegant) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln [2020-03-31]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-05-19]
CHR Extension: (uBlock Origin) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2021-05-09]
CHR Extension: (Adblock for Youtube™) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2021-05-18]
CHR Extension: (Sheets) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-27]
CHR Extension: (Google Docs Offline) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-05-14]
CHR Extension: (Microsoft Editor: Spelling & Grammar Checker) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpaiobkfhnonedkhhfjpmhdalgeoebfa [2021-05-19]
CHR Extension: (Zoom) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmbjbjdpkobdjplfobhljndfdfdipjhg [2021-05-27]
CHR Extension: (No Name) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\nenlahapcbofgnanklpelkaejcehkggg [2019-10-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-01]
CHR Extension: (Netflix Party is now Teleparty) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\oocalimimngaihdkbihfgmpkcpnmlaoa [2021-05-03]
CHR Extension: (Hulu Ad Skipper | Ad Blocker) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgpdfnkeeppfohmophlpcfmciioeenig [2021-01-04]
CHR Extension: (Gmail) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
CHR Extension: (Chrome Media Router) - C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-04-26]
CHR Profile: C:\Users\Matthew Balent\AppData\Local\Google\Chrome\User Data\System Profile [2021-05-14]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-07-03] (ASUSTeK Computer Inc. -> )
R2 CorsairGamingAudioConfig; C:\WINDOWS\system32\CorsairGamingAudioCfgService64.exe [616344 2020-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R2 CorsairLLAService; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CueLLAccessService.exe [421928 2020-12-29] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
R2 CorsairService; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.exe [80936 2020-12-29] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [818288 2020-11-24] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [926176 2021-03-16] (Epic Games Inc. -> Epic Games, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7391408 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2547288 2021-05-10] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3487320 2021-05-10] (Electronic Arts, Inc. -> Electronic Arts)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1679240 2021-02-16] (Rockstar Games, Inc. -> Rockstar Games)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13109776 2020-07-02] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\NisSrv.exe [2599328 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MsMpEng.exe [128376 2021-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_b5c7e9f1cc7d29c6\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_b5c7e9f1cc7d29c6\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-03] (ASUSTeK Computer Inc. -> )
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
R3 CorsairGamingAudioService; C:\WINDOWS\system32\DRIVERS\CorsairGamingAudio64.sys [60312 2020-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R2 CorsairLLAccess3B84E98236B28D4E075D5737DF9F567A1FB76E8A; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CorsairLLAccess64.sys [21752 2020-11-19] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [45984 2020-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21920 2020-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 cpuz150; C:\WINDOWS\temp\cpuz150\cpuz150_x64.sys [44832 2021-05-30] (CPUID S.A.R.L.U. -> CPUID)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [199128 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
S3 kmloop; C:\WINDOWS\System32\drivers\loop.sys [17408 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220752 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-05-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [198888 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [77496 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [157944 2021-05-30] (Malwarebytes Inc -> Malwarebytes)
R1 npcap; C:\WINDOWS\system32\DRIVERS\npcap.sys [74616 2020-09-25] (Insecure.Com LLC -> Insecure.Com LLC.)
S4 npcap_wifi; C:\WINDOWS\system32\DRIVERS\npcap.sys [74616 2020-09-25] (Insecure.Com LLC -> Insecure.Com LLC.)
S3 REDRAGON_MOUSE; C:\WINDOWS\system32\drivers\REDRAGON_MOUSE.sys [26112 2017-09-21] () [File not signed]
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [24000 2019-09-25] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
S3 ViGEmBus; C:\WINDOWS\System32\drivers\ViGEmBus.sys [53128 2018-01-19] (Microsoft Windows Hardware Compatibility Publisher -> Benjamin Höglinger-Stelzer)
S3 VKbms; C:\WINDOWS\System32\drivers\VKbms.sys [13824 2014-07-12] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2021-05-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [421112 2021-05-13] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [73960 2021-05-13] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-31 15:41 - 2021-05-31 15:42 - 000000000 ____D C:\FRST
2021-05-31 14:57 - 2021-05-31 14:57 - 000001231 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spy Protector.lnk
2021-05-31 14:57 - 2021-05-31 14:57 - 000001220 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager.lnk
2021-05-31 14:57 - 2021-05-31 14:57 - 000000000 ____D C:\ProgramData\SecTaskMan
2021-05-31 14:57 - 2021-05-31 14:57 - 000000000 ____D C:\Program Files (x86)\Security Task Manager
2021-05-30 20:25 - 2021-05-30 20:25 - 000198888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2021-05-30 20:25 - 2021-05-30 20:25 - 000157944 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2021-05-30 20:25 - 2021-05-30 20:25 - 000077496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2021-05-30 20:24 - 2021-05-30 20:24 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-05-30 20:24 - 2021-05-30 20:24 - 000220752 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-05-30 20:24 - 2021-05-30 20:24 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-05-30 20:24 - 2021-05-30 20:24 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2021-05-30 20:24 - 2021-05-30 20:24 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2021-05-30 20:23 - 2021-05-30 20:23 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-05-30 20:23 - 2021-05-30 20:23 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-05-30 20:23 - 2021-05-30 20:23 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-05-30 20:23 - 2021-05-30 20:23 - 000000000 ____D C:\Program Files\Malwarebytes
2021-05-20 17:39 - 2021-05-20 17:39 - 000197638 _____ C:\Users\Matthew Balent\Desktop\PSN Backup.mp4
2021-05-20 16:39 - 2021-05-13 03:38 - 000037656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhdap64.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2021-05-20 16:27 - 2021-05-13 11:22 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo.exe
2021-05-20 16:27 - 2021-05-13 11:22 - 001453360 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 001435880 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-05-20 16:27 - 2021-05-13 11:22 - 001435880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2021-05-20 16:27 - 2021-05-13 11:22 - 001192752 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 001094864 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 001094864 _____ C:\WINDOWS\system32\vulkan-1.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 000948968 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2021-05-20 16:27 - 2021-05-13 11:22 - 000948968 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 001514800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 001166112 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 000715544 _____ C:\WINDOWS\system32\nvofapi64.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 000675104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 000626968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 000575768 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2021-05-20 16:27 - 2021-05-13 11:19 - 000564000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2021-05-20 16:27 - 2021-05-13 11:18 - 002106144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2021-05-20 16:27 - 2021-05-13 11:18 - 001590576 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2021-05-20 16:27 - 2021-05-13 11:18 - 000811824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2021-05-20 16:27 - 2021-05-13 11:18 - 000689952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2021-05-20 16:27 - 2021-05-13 11:18 - 000445744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2021-05-20 16:27 - 2021-05-13 11:17 - 008317232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2021-05-20 16:27 - 2021-05-13 11:17 - 007434032 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2021-05-20 16:27 - 2021-05-13 11:17 - 004795184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2021-05-20 16:27 - 2021-05-13 11:17 - 002823472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2021-05-20 16:27 - 2021-05-13 11:16 - 000848688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2021-05-20 16:27 - 2021-05-13 11:15 - 006159152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2021-05-20 16:27 - 2021-05-13 03:38 - 000087164 _____ C:\WINDOWS\system32\nvinfo.pb
2021-05-15 15:48 - 2021-05-15 15:48 - 000000000 ____D C:\Program Files (x86)\Intel
2021-05-14 00:51 - 2021-05-14 00:51 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\GetsuFumaDen
2021-05-11 10:51 - 2021-05-11 10:51 - 000011351 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-31 15:42 - 2020-04-01 13:40 - 000000000 ____D C:\Users\Matthew Balent\Desktop\Installers
2021-05-31 14:46 - 2020-06-19 22:12 - 000004186 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{54E83F89-2951-42A7-B12A-1B696A9BC3FA}
2021-05-31 14:46 - 2019-06-27 18:36 - 000000000 ____D C:\ProgramData\NVIDIA
2021-05-30 22:36 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-05-30 22:36 - 2019-07-28 20:03 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\Battle.net
2021-05-30 22:02 - 2020-06-19 22:09 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-05-30 22:02 - 2019-07-28 20:03 - 000000000 ____D C:\Program Files (x86)\Battle.net
2021-05-30 21:20 - 2019-12-07 02:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-05-30 21:20 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-05-30 20:32 - 2020-06-19 22:12 - 000840598 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-05-30 20:32 - 2019-12-07 02:13 - 000000000 ____D C:\WINDOWS\INF
2021-05-30 20:28 - 2020-06-19 22:12 - 000003398 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2520759900-3737204395-3222954602-1001
2021-05-30 20:28 - 2020-06-19 21:57 - 000002394 _____ C:\Users\Matthew Balent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-05-30 20:28 - 2019-04-26 23:49 - 000000000 ___RD C:\Users\Matthew Balent\OneDrive
2021-05-30 20:27 - 2019-12-07 02:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2021-05-30 20:25 - 2020-06-19 22:12 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-05-30 20:25 - 2020-06-19 22:09 - 000008192 ___SH C:\DumpStack.log.tmp
2021-05-30 20:25 - 2019-12-07 02:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-05-30 20:25 - 2019-07-17 00:03 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-05-30 20:23 - 2019-12-07 02:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-05-30 20:23 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-05-30 00:21 - 2019-06-23 14:43 - 000000000 ____D C:\Users\Matthew Balent\AppData\Roaming\Discord
2021-05-29 23:28 - 2019-06-23 14:43 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\Discord
2021-05-29 15:27 - 2020-07-10 14:45 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-05-29 14:35 - 2019-05-16 17:06 - 000000000 ____D C:\Program Files (x86)\Overwatch
2021-05-23 14:32 - 2019-06-16 11:25 - 000001267 _____ C:\Users\Matthew Balent\Desktop\Downloads - Shortcut.lnk
2021-05-21 22:42 - 2021-03-14 16:21 - 000000000 ____D C:\Users\Matthew Balent\.zenmap
2021-05-21 15:25 - 2019-04-27 11:09 - 000000000 ____D C:\Users\Matthew Balent\AppData\LocalLow\Mozilla
2021-05-21 14:38 - 2020-05-17 10:48 - 001694672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2021-05-21 14:38 - 2020-05-17 10:48 - 000250304 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2021-05-21 14:38 - 2020-05-17 10:48 - 000192952 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2021-05-21 14:38 - 2020-05-17 10:48 - 000159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2021-05-21 14:38 - 2020-05-17 10:48 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2021-05-21 14:38 - 2020-05-17 10:48 - 000038328 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamemodcontrol.exe
2021-05-20 16:40 - 2019-06-27 18:45 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\NVIDIA
2021-05-19 17:52 - 2020-11-26 21:19 - 000000000 ____D C:\Program Files (x86)\Origin
2021-05-19 17:33 - 2019-04-27 11:09 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-05-18 19:21 - 2019-07-15 17:30 - 000000000 ____D C:\Users\Matthew Balent\GNS3
2021-05-18 19:21 - 2019-07-15 17:30 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\CrashDumps
2021-05-17 21:58 - 2021-03-16 19:34 - 000000000 ____D C:\Users\Matthew Balent\Desktop\IT Education
2021-05-15 16:38 - 2019-05-12 17:54 - 000000000 ____D C:\ProgramData\Package Cache
2021-05-15 15:37 - 2019-04-26 23:44 - 000000000 ____D C:\Program Files\Intel
2021-05-14 00:51 - 2019-06-17 19:41 - 000000000 ____D C:\Users\Matthew Balent\AppData\Local\UnrealEngine
2021-05-14 00:51 - 2019-06-17 19:41 - 000000000 ____D C:\ProgramData\Epic
2021-05-13 23:50 - 2019-04-26 23:39 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-05-13 11:18 - 2021-04-30 15:15 - 000656176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2021-05-13 11:15 - 2020-05-27 11:27 - 007212224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2021-05-13 03:38 - 2020-05-27 11:28 - 000136472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2021-05-12 17:03 - 2021-04-28 14:09 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-05-11 10:52 - 2020-06-19 22:09 - 000257904 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-05-11 10:52 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-05-11 10:52 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-05-11 10:47 - 2019-04-27 11:08 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-05-11 10:46 - 2019-04-27 11:08 - 132732536 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories ========
2019-07-16 23:56 - 2019-07-16 23:56 - 000002226 _____ () C:\Users\Matthew Balent\MarkYO.bat
2019-08-23 17:17 - 2019-09-03 15:45 - 000007606 _____ () C:\Users\Matthew Balent\AppData\Local\Resmon.ResmonCfg
2021-03-14 16:21 - 2021-03-14 16:21 - 000000000 _____ () C:\Users\Matthew Balent\AppData\Local\zenmap.exe.log
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================