Here is the FRST log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28.04.2019
Ran by anduc (administrator) on DESKTOP-NC4FND6 (Gigabyte Technology Co., Ltd. H67A-USB3-B3) (01-05-2019 11:13:37)
Running from C:\Users\anduc\Desktop
Loaded Profiles: anduc (Available Profiles: anduc)
Platform: Windows 10 Home Version 1809 17763.107 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.42.60.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19032.731.0_x64__8wekyb3d8bbwe\YourPhone.exe
(Discord Inc. -> Discord Inc.) C:\Users\anduc\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\anduc\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\anduc\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\anduc\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\anduc\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\anduc\AppData\Local\Discord\app-0.0.305\Discord.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleCrashHandler64.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\anduc\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.42.60.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.42.60.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Ubisoft Entertainment Sweden AB -> Ubisoft) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe
(Ubisoft Entertainment Sweden AB -> Ubisoft) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
(Ubisoft Entertainment Sweden AB -> Ubisoft) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
(Ubisoft Entertainment Sweden AB -> Ubisoft) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
(Ubisoft Entertainment Sweden AB -> Ubisoft) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-21-3286981972-3961765893-2546697801-1001\...\Run: [Discord] => C:\Users\anduc\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-3286981972-3961765893-2546697801-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3152160 2019-04-17] (Valve -> Valve Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\74.0.3729.108\Installer\chrmstp.exe [2019-05-01] (Google LLC -> Google Inc.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {DB624EA0-7C57-45A6-BBB0-385E4388F862} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-05-01] (Google Inc -> Google LLC)
Task: {E53EFF6F-9596-4AA3-B218-6004BC3B132E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-05-01] (Google Inc -> Google LLC)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 95.77.94.88 78.96.7.88
Tcpip\..\Interfaces\{3f37376d-0ceb-44a7-b889-2b94b2b1b416}: [DhcpNameServer] 95.77.94.88 78.96.7.88
Internet Explorer:
==================
FireFox:
========
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-05-01] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-05-01] (Google Inc -> Google LLC)
Chrome:
=======
CHR Profile: C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default [2019-05-01]
CHR Extension: (Prezentări) - C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-05-01]
CHR Extension: (Documente) - C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-05-01]
CHR Extension: (Disc Google) - C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-05-01]
CHR Extension: (YouTube) - C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-05-01]
CHR Extension: (Foi de calcul) - C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-05-01]
CHR Extension: (Documente Google Offline) - C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-05-01]
CHR Extension: (AdBlock) - C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2019-05-01]
CHR Extension: (PlățI prin Magazinul web Chrome) - C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-05-01]
CHR Extension: (Gmail) - C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-01]
CHR Extension: (Chrome Media Router) - C:\Users\anduc\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-05-01]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3830488 2018-09-15] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [110944 2018-09-15] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [198512 2019-05-01] (Malwarebytes Corporation -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2019-02-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [127136 2019-04-30] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73912 2019-04-30] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [274416 2019-04-30] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [114040 2019-04-30] (Malwarebytes Corporation -> Malwarebytes)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys [16936048 2017-11-09] (NVIDIA Corporation -> NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [605696 2018-09-15] (Microsoft Windows -> Realtek )
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46584 2018-09-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [340008 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [61992 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-05-01 11:13 - 2019-05-01 11:14 - 000012474 _____ C:\Users\anduc\Desktop\FRST.txt
2019-05-01 11:13 - 2019-05-01 11:13 - 000000000 ____D C:\Users\anduc\Desktop\FRST-OlderVersion
2019-05-01 11:13 - 2019-05-01 11:13 - 000000000 ____D C:\FRST
2019-05-01 11:12 - 2019-05-01 11:13 - 002429952 _____ (Farbar) C:\Users\anduc\Desktop\FRST64.exe
2019-05-01 11:02 - 2019-05-01 11:02 - 000000000 ___HD C:\OneDriveTemp
2019-05-01 06:40 - 2019-05-01 06:40 - 000000000 ____D C:\AdwCleaner
2019-05-01 06:25 - 2019-05-01 06:25 - 000008192 __RSH C:\BOOTSECT.BAK
2019-05-01 06:25 - 2019-05-01 05:28 - 000000000 ____D C:\Windows\Panther
2019-05-01 06:25 - 2018-10-30 01:39 - 000408074 __RSH C:\bootmgr
2019-05-01 06:25 - 2018-09-15 10:28 - 000000001 ___SH C:\BOOTNXT
2019-05-01 06:04 - 2019-05-01 11:05 - 000000000 ____D C:\Users\anduc\AppData\Local\Ubisoft Game Launcher
2019-05-01 06:04 - 2019-05-01 06:04 - 000001278 _____ C:\Users\anduc\Desktop\Uplay.lnk
2019-05-01 06:04 - 2019-05-01 06:04 - 000000000 ____D C:\Users\anduc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2019-05-01 06:03 - 2019-05-01 06:03 - 000000000 ____D C:\Program Files (x86)\Ubisoft
2019-05-01 06:00 - 2019-05-01 06:00 - 000000000 ____D C:\Users\anduc\AppData\Local\Steam
2019-05-01 06:00 - 2019-05-01 06:00 - 000000000 ____D C:\Users\anduc\AppData\Local\CEF
2019-05-01 05:58 - 2019-05-01 11:02 - 000000000 ____D C:\Program Files (x86)\Steam
2019-05-01 05:58 - 2019-05-01 05:58 - 000001036 _____ C:\Users\Public\Desktop\Steam.lnk
2019-05-01 05:58 - 2019-05-01 05:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2019-05-01 05:53 - 2019-05-01 06:01 - 000000000 ____D C:\ProgramData\Packages
2019-05-01 05:52 - 2019-05-01 05:52 - 000000000 ____D C:\Users\anduc\AppData\Roaming\Google
2019-05-01 05:51 - 2019-05-01 06:04 - 000000000 ____D C:\Users\anduc\AppData\Local\Google
2019-05-01 05:51 - 2019-05-01 05:51 - 000003626 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2019-05-01 05:51 - 2019-05-01 05:51 - 000003502 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2019-05-01 05:51 - 2019-05-01 05:51 - 000002379 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-05-01 05:51 - 2019-05-01 05:51 - 000002338 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-05-01 05:51 - 2019-05-01 05:51 - 000000000 ____D C:\Program Files (x86)\Google
2019-05-01 05:48 - 2019-04-30 21:41 - 000000000 ____D C:\Users\anduc\AppData\Local\D3DSCache
2019-05-01 05:43 - 2019-05-01 05:43 - 000198512 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2019-05-01 05:43 - 2019-05-01 05:43 - 000000000 ____D C:\Users\anduc\AppData\Local\mbam
2019-05-01 05:42 - 2019-05-01 05:42 - 000001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-05-01 05:42 - 2019-05-01 05:42 - 000000000 ____D C:\Users\anduc\AppData\Local\mbamtray
2019-05-01 05:42 - 2019-05-01 05:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-05-01 05:42 - 2019-05-01 05:42 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-05-01 05:42 - 2019-05-01 05:42 - 000000000 ____D C:\Program Files\Malwarebytes
2019-05-01 05:42 - 2019-02-01 12:20 - 000020936 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2019-05-01 05:42 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-05-01 05:40 - 2019-05-01 05:40 - 000000000 ____D C:\Users\anduc\AppData\Local\OneDrive
2019-05-01 05:39 - 2019-04-30 21:34 - 000000000 ____D C:\Users\anduc\AppData\Local\PlaceholderTileLogoFolder
2019-05-01 05:38 - 2019-05-01 05:38 - 000002237 _____ C:\Users\anduc\Desktop\Discord.lnk
2019-05-01 05:38 - 2019-05-01 05:38 - 000002134 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2019-05-01 05:38 - 2019-05-01 05:38 - 000000000 ____D C:\Users\anduc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2019-05-01 05:38 - 2019-05-01 05:38 - 000000000 ____D C:\Users\anduc\AppData\Local\SquirrelTemp
2019-05-01 05:38 - 2019-05-01 05:38 - 000000000 ____D C:\Users\anduc\AppData\Local\Discord
2019-05-01 05:38 - 2019-05-01 05:38 - 000000000 ____D C:\Users\anduc\AppData\Local\Comms
2019-05-01 05:38 - 2019-05-01 05:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2019-05-01 05:38 - 2019-04-30 22:29 - 000000000 ____D C:\Users\anduc\AppData\Roaming\Discord
2019-05-01 05:37 - 2019-05-01 11:02 - 000000000 ___RD C:\Users\anduc\OneDrive
2019-05-01 05:37 - 2019-05-01 05:38 - 000003380 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3286981972-3961765893-2546697801-1001
2019-05-01 05:37 - 2019-05-01 05:37 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2019-05-01 05:37 - 2019-05-01 05:37 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2019-05-01 05:37 - 2019-04-30 23:46 - 000000000 ____D C:\ProgramData\NVIDIA
2019-05-01 05:37 - 2019-04-30 22:34 - 000795988 _____ C:\Windows\system32\PerfStringBackup.INI
2019-05-01 05:37 - 2017-11-09 04:43 - 000540784 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2019-05-01 05:37 - 2017-11-09 04:43 - 000446392 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2019-05-01 05:37 - 2017-10-27 19:36 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2019-05-01 05:37 - 2017-10-27 19:12 - 005960824 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2019-05-01 05:37 - 2017-10-27 19:12 - 002587768 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2019-05-01 05:37 - 2017-10-27 19:12 - 001766520 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2019-05-01 05:37 - 2017-10-27 19:12 - 000607168 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2019-05-01 05:37 - 2017-10-27 19:12 - 000449656 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2019-05-01 05:37 - 2017-10-27 19:12 - 000123000 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2019-05-01 05:37 - 2017-10-27 19:12 - 000081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2019-05-01 05:37 - 2017-10-27 19:06 - 000136312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2019-05-01 05:37 - 2017-10-25 13:33 - 007802921 _____ C:\Windows\system32\nvcoproc.bin
2019-05-01 05:37 - 2017-09-14 02:20 - 000798008 _____ C:\Windows\SysWOW64\vulkan-1.dll
2019-05-01 05:37 - 2017-09-14 02:20 - 000490296 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2019-05-01 05:37 - 2017-09-14 02:19 - 000927544 _____ C:\Windows\system32\vulkan-1.dll
2019-05-01 05:37 - 2017-09-14 02:19 - 000591160 _____ C:\Windows\system32\vulkaninfo.exe
2019-05-01 05:36 - 2019-05-01 05:38 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2019-05-01 05:36 - 2019-05-01 05:38 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-05-01 05:36 - 2019-05-01 05:37 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-05-01 05:36 - 2019-05-01 05:36 - 000001446 _____ C:\Users\anduc\Desktop\Microsoft Edge.lnk
2019-05-01 05:36 - 2019-05-01 05:36 - 000000000 ___HD C:\Users\anduc\MicrosoftEdgeBackups
2019-05-01 05:35 - 2019-05-01 06:41 - 000000000 ____D C:\Users\anduc\AppData\Local\ConnectedDevicesPlatform
2019-05-01 05:35 - 2019-05-01 06:11 - 000000000 ____D C:\Users\anduc\AppData\Local\Publishers
2019-05-01 05:35 - 2019-05-01 05:35 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-05-01 05:35 - 2019-05-01 05:35 - 000000000 ___RD C:\Users\anduc\3D Objects
2019-05-01 05:35 - 2019-05-01 05:35 - 000000000 ____D C:\Users\anduc\AppData\Roaming\Adobe
2019-05-01 05:35 - 2019-05-01 05:35 - 000000000 ____D C:\Users\anduc\AppData\Local\VirtualStore
2019-05-01 05:35 - 2019-05-01 05:35 - 000000000 ____D C:\Users\anduc\AppData\Local\MicrosoftEdge
2019-05-01 05:35 - 2019-04-30 22:35 - 000000000 ____D C:\Users\anduc\AppData\Local\Packages
2019-05-01 05:34 - 2019-05-01 05:38 - 000002367 _____ C:\Users\anduc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-05-01 05:34 - 2019-05-01 05:34 - 000000020 ___SH C:\Users\anduc\ntuser.ini
2019-05-01 05:34 - 2019-04-30 22:21 - 000000000 ____D C:\Users\anduc
2019-05-01 05:33 - 2019-05-01 05:33 - 000000000 ____D C:\ProgramData\USOShared
2019-05-01 05:33 - 2018-09-15 10:28 - 002864640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2019-05-01 05:31 - 2019-05-01 05:31 - 000000000 _SHDL C:\Documents and Settings
2019-05-01 05:27 - 2019-05-01 05:27 - 000257824 _____ C:\Windows\system32\FNTCACHE.DAT
2019-05-01 05:27 - 2019-05-01 05:27 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2019-05-01 05:27 - 2019-05-01 05:27 - 000000000 ____D C:\Windows\system32\Drivers\wd
2019-05-01 05:27 - 2019-05-01 05:27 - 000000000 ____D C:\Windows\ServiceProfiles
2019-05-01 05:27 - 2019-04-30 22:28 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-05-01 05:27 - 2019-04-30 21:27 - 000000000 ____D C:\Windows\system32\SleepStudy
2019-04-30 22:29 - 2019-04-30 22:29 - 000073912 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-04-30 22:28 - 2019-04-30 22:28 - 000274416 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-04-30 22:28 - 2019-04-30 22:28 - 000127136 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-04-30 22:28 - 2019-04-30 22:28 - 000114040 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-05-01 11:05 - 2018-09-15 10:33 - 000000000 ____D C:\Windows\appcompat
2019-05-01 11:05 - 2018-09-15 10:31 - 000000000 ____D C:\Windows\INF
2019-05-01 11:02 - 2018-09-15 10:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-05-01 06:25 - 2018-09-15 10:31 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2019-05-01 06:09 - 2018-09-15 10:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-05-01 05:53 - 2018-09-15 10:33 - 000000000 ____D C:\Windows\ServiceState
2019-05-01 05:42 - 2018-09-15 10:33 - 000000000 ___HD C:\Windows\ELAMBKUP
2019-05-01 05:37 - 2018-09-15 10:33 - 000000000 ____D C:\Windows\Help
2019-05-01 05:34 - 2018-09-15 10:33 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2019-05-01 05:34 - 2018-09-15 10:23 - 000000000 ____D C:\Windows\CbsTemp
2019-05-01 05:33 - 2018-09-15 10:33 - 000000000 ____D C:\Windows\system32\spool
2019-05-01 05:33 - 2018-09-15 10:33 - 000000000 ____D C:\Windows\system32\FxsTmp
2019-05-01 05:33 - 2018-09-15 10:33 - 000000000 ____D C:\ProgramData\USOPrivate
2019-05-01 05:27 - 2018-09-15 10:33 - 000000000 ___RD C:\Windows\PrintDialog
2019-05-01 05:27 - 2018-09-15 10:33 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2019-05-01 05:27 - 2018-09-15 09:09 - 000032768 _____ C:\Windows\system32\config\ELAM
2019-04-30 22:40 - 2018-09-15 10:33 - 000000000 ____D C:\Windows\AppReadiness
2019-04-30 22:28 - 2018-09-15 09:09 - 000524288 _____ C:\Windows\system32\config\BBI
2019-04-30 21:26 - 2018-09-15 10:33 - 000000000 ____D C:\Windows\LiveKernelReports
==================== SigCheck ===============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ============================