I don't know if this is an infection of anything, just weird activity I've noticed recently in processexplorer. It isn't happening constantly, and I'm just noticing it for the second time over the course of the last month after constant monitoring. The parent iexplorer.exe can be killed and doesn't seem to return on any schedule. I never use internet explorer for anything, relying almost exclusively on chrome with some firefox use. I've also noticed some windows explorer lag, but unsure if that's anything either. MSE nor malwarebytes have thrown a fit over anything, but maybe they're missing something that you guys will catch.
FRST.txt :
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-10-2022
Ran by Austin (administrator) on SORA (MSI MS-7673) (25-10-2022 21:33:28)
Running from C:\Users\Austin\Desktop
Loaded Profiles: Austin
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Elaborate Bytes AG -> Elaborate Bytes AG) C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe
(explorer.exe ->) () [File not signed] C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
(explorer.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(explorer.exe ->) (F.lux Software LLC -> f.lux Software LLC) C:\Users\Austin\AppData\Local\FluxSoftware\Flux\flux.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <41>
(explorer.exe ->) (Logitech -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(explorer.exe ->) (Open Source Developer, Stefan KUENG -> hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(explorer.exe ->) (Vincent Burel -> VB-AUDIO Software) C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Renesas Electronics Corporation -> Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(services.exe ->) (Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(services.exe ->) (Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(services.exe ->) (Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6612072 2011-03-07] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [13318424 2015-03-12] (Logitech -> Logitech Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4234088 2022-10-18] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Run: [f.lux] => C:\Users\Austin\AppData\Local\FluxSoftware\Flux\flux.exe [1511824 2021-02-04] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Run: [uTorrent] => "C:\Users\Austin\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED (No File)
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Run: [DAEMON Tools Lite Automount] => "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun (No File)
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\Software\Policies\...\system: [disablecmd] 0
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\106.0.5249.119\Installer\chrmstp.exe [2022-10-13] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{50968FF7-10C1-4fb3-98B0-CD654D6CB97E}] -> C:\Program Files\WIDCOMM\Bluetooth Software\\BtwCP.dll [2014-07-17] (Broadcom Corporation -> Broadcom Corporation.)
HKLM\Software\...\Authentication\Credential Providers: [{D28973E5-8630-41af-8831-50A15FEB396B}] -> C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll [2014-07-17] (Broadcom Corporation -> Broadcom Corporation.)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2021-07-20]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation -> Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2014-09-18]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe () [File not signed]
Startup: C:\Users\Austin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Core Temp.exe - Shortcut.lnk [2016-01-24]
ShortcutTarget: Core Temp.exe - Shortcut.lnk -> C:\Program Files\Core Temp\Core Temp.exe (Artur Liberman -> )
Startup: C:\Users\Austin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Voicemeeter (VB-Audio).LNK [2021-02-01]
ShortcutTarget: Voicemeeter (VB-Audio).LNK -> C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe (Vincent Burel -> VB-AUDIO Software)
GroupPolicy\User: Restriction ? <==== ATTENTION
GroupPolicyUsers\S-1-5-21-2558064723-1881834265-789328380-1003\User: Restriction <==== ATTENTION
Policies: C:\Users\Austin\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {316FB720-E624-4A95-B4BD-67E4E0E91172} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [862 2020-06-09] () [File not signed]
Task: {42C63EDD-883C-473F-81F7-707A592639E8} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.)
Task: {621063E6-D9FE-41AC-BD62-2D1EE3DDBE90} - System32\Tasks\{4870BB68-040C-4044-BCE0-E7F92EFFE874} => C:\Windows\system32\pcalua.exe -a C:\Users\Austin\Downloads\vbrun60sp6.exe -d C:\Users\Austin\Downloads
Task: {66F85F06-41A6-46E0-A3CE-542E3B0E4C2D} - System32\Tasks\elbyExecuteWithUAC => C:\Program Files (x86)\VirtualCloneDrive\ExecuteWithUAC.exe [77824 2013-03-21] () [File not signed]
Task: {69A85458-7E83-4F53-B991-76004A25CEF4} - System32\Tasks\sd => shutdown /s /f /t 0
Task: {85CD66E4-A4DA-4859-8EE0-030734A8B3AE} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_170_pepper.exe [1319424 2017-10-19] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {92489B32-DCDD-4F2B-AC75-83DE8ACD7FC9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-11-18] (Google Inc -> Google Inc.)
Task: {949BEB55-E2CF-42DC-B441-3A1BB2AFCEE7} - System32\Tasks\MATLAB R2014a Startup Accelerator => C:\Program Files\MATLAB\R2014a\bin\win64\MATLABStartupAccelerator.exe [42496 2014-01-29] () [File not signed]
Task: {A297B83D-4160-47C0-810D-0C46433FEA1A} - System32\Tasks\{C8FD5FFE-3812-4F3D-8CD9-9AC1183B065F} => C:\Windows\system32\pcalua.exe -a C:\Users\Austin\AppData\Roaming\uTorrent\uTorrent.exe -c /UNINSTALL
Task: {B6A28BD1-62FE-463A-87A4-16F261139F98} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-11-18] (Google Inc -> Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\MATLAB R2014a Startup Accelerator.job => C:\Program Files\MATLAB\R2014a\bin\win64\MATLABStartupAccelerator.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Hosts: 77.72.3.39 nmm.nexusmods.com # legacy-api.nexusmods.com
Tcpip\Parameters: [DhcpNameServer] 24.48.160.2 24.48.160.3
Tcpip\..\Interfaces\{55223230-04B3-47C4-A87D-32DF136473BD}: [DhcpNameServer] 24.48.160.2 24.48.160.3
Tcpip\..\Interfaces\{E1793131-E5E1-44CB-B3AA-14E257781EEB}: [DhcpNameServer] 208.180.42.68 208.180.42.100
FireFox:
========
FF DefaultProfile: 0yquk31o.default
FF ProfilePath: C:\Users\Austin\AppData\Roaming\Mozilla\Firefox\Profiles\0yquk31o.default [2022-10-22]
FF Session Restore: Mozilla\Firefox\Profiles\0yquk31o.default -> is enabled.
FF HKLM-x32\...\Firefox\Extensions: [WSVCU@Wondershare.com] - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com => not found
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-04-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-04-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll [2015-12-07] (Adobe Systems Incorporated -> )
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2022-10-16] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default [2022-10-25]
CHR DownloadDir: C:\Users\Austin\Desktop\kpopng
CHR Notifications: Default -> hxxps://deathsnacks.com; hxxps://www.predictit.org; hxxps://www1.darenjarvis.pro; hxxps://www45.darenjarvis.pro; hxxps://www54.darenjarvis.pro; hxxps://www55.josueshah.pro; hxxps://www7.darenjarvis.pro; hxxps://www82.darenjarvis.pro; hxxps://www84.darenjarvis.pro; hxxps://www87.darenjarvis.pro
CHR Session Restore: Default -> is enabled.
CHR Extension: (h264ify) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aleakchihdccplidncghkekgioiakgal [2021-10-20]
CHR Extension: (WOT Website Security & Privacy Protection) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2022-08-23]
CHR Extension: (Alternate Player for Twitch.tv) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhplkbgoehhhddaoolmakpocnenplmhf [2022-02-11]
CHR Extension: (MEGA) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2022-10-25]
CHR Extension: (uBlock Origin) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2022-09-22]
CHR Extension: (Powerful Pixiv Downloader) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkndmhgdcmjdmkdonmbgjpijejdcilfh [2022-10-25]
CHR Extension: (Old Reddit Redirect) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dneaehbmnbhcippjikoajpoabadpodje [2022-02-16]
CHR Extension: (AHA Music - Song Finder for Browser) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpacanjfikmhoddligfbehkpomnbgblf [2022-09-12]
CHR Extension: (Dark Reader) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2022-10-15]
CHR Extension: (Volume Booster) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejkiikneibegknkgimmihdpcbcedgmpo [2022-10-02]
CHR Extension: (Google Docs Offline) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-08-30]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2022-10-15]
CHR Extension: (Magic Enhancer For YouTube™) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2020-02-10]
CHR Extension: (Wallhaven Direct Downloader) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mggclgefcmlpigdbcpfheklbhflnknkf [2019-07-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-31]
CHR Extension: (The Marvellous Suspender) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\noogafoofpebimajpfpamcfhoaifemoa [2021-07-01]
CHR Extension: (History Trends Unlimited) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnmchffiealhkdloeffcdnbgdnedheme [2022-05-17]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. -> Adobe Inc.)
S4 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2020-07-30] (BitRaider LLC -> BitRaider, LLC)
S4 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [216576 2016-08-18] () [File not signed]
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [1959776 2022-02-15] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6484832 2022-02-15] (GOG Sp. z o.o. -> GOG.com)
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [22872 2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8838880 2022-10-14] (Malwarebytes Inc. -> Malwarebytes)
S4 MsMpiLaunchSvc; C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe [27760 2015-11-06] (AzureEngBuildCodeSign -> ) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4490376 2020-09-18] (Logitech Inc -> Logitech)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3758336 2015-11-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
S4 WPSService20; C:\Program Files (x86)\ASUS USB-N13 Wireless LAN Driver\WPSService20.exe [96768 2014-05-06] () [File not signed]
S2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [X]
S2 NMSAccess; "C:\Program Files (x86)\Blaze Media Pro\NMSAccess32.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2020-07-30] (BitRaider -> BitRaider)
S3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [59904 2015-01-26] (Microsoft Windows Hardware Compatibility Publisher -> www.winchiphead.com)
S3 CM_VENDER_CMD; C:\Program Files\Common Files\Logitech\G430Install\CMVC64.sys [17104 2014-07-30] (C-MEDIA ELECTRONICS INC. -> Windows (R) Win 7 DDK provider)
S3 DABlackFltr; C:\Windows\System32\drivers\DABlack.sys [23040 2010-11-29] (Razer (Asia-Pacific) Pte Ltd) [File not signed]
S3 droidpad; C:\Windows\System32\DRIVERS\droidpad.sys [21320 2013-04-18] (ReactOS Foundation -> Windows (R) Win 7 DDK provider)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-08-06] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-08-06] (Disc Soft Ltd -> Disc Soft Ltd)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239544 2022-09-23] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R3 MpKsla3e734b6; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EF3CF7D9-E62C-4B9B-B122-0D696587AB9A}\MpKslDrv.sys [50456 2022-10-25] (Microsoft Windows -> Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R1 npcap; C:\Windows\System32\DRIVERS\npcap.sys [71440 2020-06-12] (Insecure.Com LLC -> Insecure.Com LLC.)
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [82432 2011-02-10] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [181760 2011-02-10] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
R3 NVHDA; C:\Windows\System32\drivers\nvhda64v.sys [136848 2022-07-11] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
R3 nvlddmkm; C:\Windows\System32\DRIVERS\nvlddmkm.sys [37058984 2022-07-14] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3810520 2015-10-08] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation)
S3 RzCommon; C:\Windows\System32\DRIVERS\RzCommon.sys [52040 2021-03-30] (Razer USA Ltd. -> Razer Inc)
S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [43720 2015-08-13] (Razer Inc. -> Razer Inc)
S3 RzDev_0084; C:\Windows\System32\DRIVERS\RzDev_0084.sys [50584 2020-08-24] (Razer USA Ltd. -> Razer Inc)
S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [51736 2016-06-22] (Razer USA Ltd. -> Razer Inc)
S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [44232 2015-08-13] (Razer Inc. -> Razer Inc)
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [38032 2022-10-25] (Adlice -> )
R3 VBAudioVACMME; C:\Windows\System32\DRIVERS\vbaudio_cable64_win7.sys [41192 2014-09-02] (Vincent Burel -> Windows (R) Win 7 DDK provider)
R3 VBAudioVMVAIOMME; C:\Windows\System32\DRIVERS\vbaudio_vmvaio64_win7.sys [41192 2016-03-17] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S3 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [240704 2022-03-22] (Oracle Corporation -> Oracle Corporation)
S3 VKbms; C:\Windows\System32\DRIVERS\VKbms.sys [13312 2010-10-01] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 ALSysIO; \??\C:\Users\Austin\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 BCMH43XX; system32\DRIVERS\bcmwlhigh664.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
U4 npcap_wifi; no ImagePath
S3 NPF; system32\DRIVERS\npf.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
S4 nvvhci; system32\DRIVERS\nvvhci.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-10-25 21:33 - 2022-10-25 21:34 - 000023113 _____ C:\Users\Austin\Desktop\FRST.txt
2022-10-25 21:05 - 2022-10-25 21:05 - 000000000 ____D C:\Windows\erdnt
2022-10-25 21:05 - 2022-10-25 21:05 - 000000000 ____D C:\Qoobox
2022-10-25 20:19 - 2022-10-25 20:43 - 000038032 _____ C:\Windows\system32\Drivers\truesight.sys
2022-10-25 20:19 - 2022-10-25 20:19 - 000000000 ____D C:\ProgramData\RogueKiller
2022-10-25 19:58 - 2022-10-25 21:33 - 000000000 ____D C:\FRST
2022-10-25 19:58 - 2022-10-25 19:58 - 002373632 _____ (Farbar) C:\Users\Austin\Desktop\FRST64.exe
2022-10-25 18:48 - 2022-10-25 18:48 - 000000804 _____ C:\Users\Public\Desktop\Children of Morta.lnk
2022-10-25 18:38 - 2022-10-25 18:38 - 000000999 _____ C:\Users\Public\Desktop\The Dungeon Of Naheulbeuk - The Amulet Of Chaos.lnk
2022-10-25 08:55 - 2022-10-25 08:55 - 002843475 _____ C:\Users\Austin\Desktop\1666702234628302.webm
2022-10-25 08:54 - 2022-10-25 08:54 - 000000735 _____ C:\Users\Public\Desktop\Fatal Twelve.lnk
2022-10-24 22:41 - 2022-10-24 22:41 - 003052293 _____ C:\Users\Austin\Desktop\1666667465597307.webm
2022-10-24 21:50 - 2022-10-24 21:50 - 003018073 _____ C:\Users\Austin\Desktop\brent mod.webm
2022-10-13 17:02 - 2022-10-22 20:53 - 000002059 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2022-10-13 17:02 - 2022-10-22 20:53 - 000002047 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
2022-10-13 04:25 - 2022-10-13 04:25 - 001298555 _____ C:\Users\Austin\Desktop\1665651881593107.webm
2022-10-07 07:07 - 2022-10-07 07:07 - 000000000 ____D C:\Users\Austin\AppData\Roaming\JetBrains
2022-10-07 07:07 - 2022-10-07 07:07 - 000000000 ____D C:\Users\Austin\AppData\Local\SymbolSourceSymbols
2022-10-07 07:07 - 2022-10-07 07:07 - 000000000 ____D C:\Users\Austin\AppData\Local\RefSrcSymbols
2022-10-07 07:06 - 2022-10-07 07:07 - 000000000 ____D C:\Users\Austin\AppData\Local\JetBrains
2022-10-07 06:29 - 2022-10-07 06:29 - 000000000 ____D C:\Users\Austin\AppData\Local\imhex
2022-09-25 17:53 - 2022-09-25 17:53 - 000000000 ____D C:\Users\Austin\AppData\Local\Microsoft_Corporation
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-10-25 21:32 - 2022-03-05 00:13 - 000000000 ____D C:\Users\Austin\Desktop\kpopng
2022-10-25 21:30 - 2014-09-18 23:04 - 000000000 ____D C:\Program Files (x86)\Steam
2022-10-25 21:23 - 2009-07-13 23:45 - 000031680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2022-10-25 21:23 - 2009-07-13 23:45 - 000031680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2022-10-25 21:19 - 2009-07-14 00:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
2022-10-25 21:19 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2022-10-25 21:15 - 2014-09-18 21:18 - 000000000 ____D C:\Program Files (x86)\Google
2022-10-25 21:14 - 2016-03-17 10:06 - 000003339 _____ C:\Users\Austin\AppData\Roaming\VoiceMeeterDefault.xml
2022-10-25 21:14 - 2014-10-05 18:04 - 000000548 _____ C:\Windows\Tasks\MATLAB R2014a Startup Accelerator.job
2022-10-25 21:13 - 2016-06-15 21:54 - 000000000 ____D C:\Users\Austin\AppData\Local\TSVNCache
2022-10-25 21:13 - 2014-09-18 22:21 - 000000000 ____D C:\ProgramData\NVIDIA
2022-10-25 21:13 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-10-25 19:30 - 2014-09-19 00:48 - 000000000 ____D C:\Users\Austin\AppData\Local\Battle.net
2022-10-25 18:48 - 2015-12-28 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2022-10-25 18:38 - 2014-10-17 21:03 - 000000000 ____D C:\ProgramData\Package Cache
2022-10-25 13:05 - 2021-05-14 16:26 - 000000000 ____D C:\Users\Austin\AppData\Local\User Data
2022-10-25 09:01 - 2016-03-25 00:45 - 000000000 ____D C:\Users\Austin\AppData\Roaming\qBittorrent
2022-10-24 22:59 - 2021-03-04 07:01 - 000000000 ____D C:\Program Files\Cheat Engine 7.2
2022-10-23 22:52 - 2021-12-22 05:02 - 000000000 ____D C:\Program Files\Genshin Impact
2022-10-22 18:54 - 2014-09-19 00:48 - 000000000 ____D C:\Program Files (x86)\Battle.net
2022-10-22 15:34 - 2017-06-06 22:00 - 000000000 ____D C:\Users\Austin\AppData\LocalLow\Mozilla
2022-10-21 20:57 - 2022-09-14 17:39 - 000000000 ____D C:\Program Files (x86)\SteamCMD
2022-10-19 03:01 - 2021-10-29 19:46 - 000000000 ____D C:\Users\Austin\Desktop\Locale.Emulator.2.5.0.1
2022-10-16 20:32 - 2016-09-18 04:24 - 000000000 ____D C:\Users\Austin\AppData\Local\CrashDumps
2022-10-14 07:47 - 2014-09-18 22:15 - 000000000 ____D C:\Windows\pss
2022-10-13 17:02 - 2016-12-04 21:20 - 000004476 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2022-10-13 16:40 - 2016-11-18 03:42 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-10-08 23:46 - 2020-12-07 07:54 - 000000000 ____D C:\Users\Austin\Desktop\twitch prof
2022-09-26 07:12 - 2022-05-27 02:13 - 000000000 ____D C:\Users\Austin\AppData\Local\HoYoverse
==================== Files in the root of some directories ========
2016-09-03 19:31 - 2016-09-03 19:31 - 000000445 _____ () C:\Users\Austin\AppData\Roaming\CSharpAnalytics-MeasurementSession
2016-01-20 09:58 - 2016-01-20 10:03 - 000003209 _____ () C:\Users\Austin\AppData\Roaming\droid4xinstaller.log
2021-11-17 07:18 - 2021-11-17 07:23 - 000003216 _____ () C:\Users\Austin\AppData\Roaming\ETCAvenueScores
2021-11-17 07:21 - 2021-11-17 07:23 - 000000048 _____ () C:\Users\Austin\AppData\Roaming\ETCAvenueStats
2021-11-17 07:25 - 2021-11-17 07:27 - 000000568 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonicScoring
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench0
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench1
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench2
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench3
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench4
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench5
2021-11-17 07:17 - 2021-11-17 07:17 - 000000017 _____ () C:\Users\Austin\AppData\Roaming\ETCPlayers
2021-11-17 07:17 - 2021-11-17 07:27 - 000000396 _____ () C:\Users\Austin\AppData\Roaming\ETCPrefs6
2019-02-04 00:26 - 2019-02-04 00:26 - 000000624 _____ () C:\Users\Austin\AppData\Roaming\jd-gui.cfg
2014-09-20 10:24 - 2015-09-27 12:23 - 000000907 _____ () C:\Users\Austin\AppData\Roaming\MPQEditor.ini
2016-06-15 20:34 - 2016-06-29 16:34 - 000000134 _____ () C:\Users\Austin\AppData\Roaming\RbNorthAmerica-MeasurementQueue
2016-06-15 20:34 - 2016-07-05 07:30 - 000000444 _____ () C:\Users\Austin\AppData\Roaming\RbNorthAmerica-MeasurementSession
2016-06-15 20:34 - 2016-06-29 16:34 - 000000134 _____ () C:\Users\Austin\AppData\Roaming\RebornBuddy-MeasurementQueue
2016-06-15 20:34 - 2016-07-05 07:30 - 000000444 _____ () C:\Users\Austin\AppData\Roaming\RebornBuddy-MeasurementSession
2016-03-17 10:06 - 2022-10-25 21:14 - 000003339 _____ () C:\Users\Austin\AppData\Roaming\VoiceMeeterDefault.xml
2016-03-19 06:35 - 2016-03-19 06:35 - 000225280 ____T (MultiMedia Soft) C:\Users\Austin\AppData\Roaming\Microsoft\AdjMmsVista.dll
2021-02-14 11:53 - 2021-02-14 11:53 - 000001799 _____ () C:\Users\Austin\AppData\Local\2bf55744-b047-477d-849c-446f99a5bef2HDGraph.log
2017-09-20 20:18 - 2017-09-20 20:18 - 000001807 _____ () C:\Users\Austin\AppData\Local\2e5e69fb-0ebb-4720-89f9-fe161564a96bHDGraph.log
2017-09-20 20:17 - 2017-09-20 20:17 - 000001807 _____ () C:\Users\Austin\AppData\Local\5e17b0e1-63c5-406d-a622-f0fa6e358076HDGraph.log
2017-09-20 20:18 - 2017-09-20 20:18 - 000001807 _____ () C:\Users\Austin\AppData\Local\79ec6bad-635c-4763-a148-ac04a699fb44HDGraph.log
2021-10-10 14:53 - 2021-10-10 14:58 - 000009423 _____ () C:\Users\Austin\AppData\Local\986efbfb-9c37-45ab-821d-aceaab6ea404HDGraph.log
2017-09-20 20:17 - 2017-09-20 20:17 - 000001807 _____ () C:\Users\Austin\AppData\Local\b045eaf9-8f98-4a1d-b05b-519309c89d47HDGraph.log
2022-03-28 04:23 - 2022-03-28 04:23 - 000000000 _____ () C:\Users\Austin\AppData\Local\D216C4.tmp
2022-03-25 06:23 - 2022-03-25 06:23 - 000000000 _____ () C:\Users\Austin\AppData\Local\D21AF9.tmp
2022-03-25 15:46 - 2022-03-25 15:46 - 000000000 _____ () C:\Users\Austin\AppData\Local\D21B23.tmp
2022-03-27 19:10 - 2022-03-27 19:10 - 000000000 _____ () C:\Users\Austin\AppData\Local\D22145.tmp
2022-03-28 04:26 - 2022-03-28 04:26 - 000000000 _____ () C:\Users\Austin\AppData\Local\D22AF0.tmp
2022-03-26 20:02 - 2022-03-26 20:02 - 000000000 _____ () C:\Users\Austin\AppData\Local\D23038.tmp
2022-03-30 19:11 - 2022-03-30 19:11 - 000000000 _____ () C:\Users\Austin\AppData\Local\D236D3.tmp
2022-03-25 21:09 - 2022-03-25 21:09 - 000000000 _____ () C:\Users\Austin\AppData\Local\D24709.tmp
2022-04-08 10:03 - 2022-04-08 10:03 - 000000000 _____ () C:\Users\Austin\AppData\Local\D24A1F.tmp
2022-04-08 03:39 - 2022-04-08 03:39 - 000000000 _____ () C:\Users\Austin\AppData\Local\D27186.tmp
2022-03-31 03:21 - 2022-03-31 03:21 - 000000000 _____ () C:\Users\Austin\AppData\Local\D27F60.tmp
2022-03-29 19:02 - 2022-03-29 19:02 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2996.tmp
2022-03-26 23:49 - 2022-03-26 23:49 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2C386.tmp
2022-03-25 01:33 - 2022-03-25 01:33 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2C3D0.tmp
2022-03-31 00:17 - 2022-03-31 00:17 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2C957.tmp
2022-04-03 08:54 - 2022-04-03 08:54 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2CB84.tmp
2022-03-30 03:21 - 2022-03-30 03:21 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2CDC8.tmp
2022-04-01 06:54 - 2022-04-01 06:54 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2D0D.tmp
2022-04-02 02:04 - 2022-04-02 02:04 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2DC91.tmp
2022-04-06 13:41 - 2022-04-06 13:41 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2EA14.tmp
2022-03-28 17:35 - 2022-03-28 17:35 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2EEBA.tmp
2022-03-25 06:28 - 2022-03-25 06:28 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2F0BF.tmp
2021-03-17 22:55 - 2021-03-17 23:28 - 000014734 _____ () C:\Users\Austin\AppData\Local\d509f535-47d1-45a2-a7a6-36acd258c149HDGraph.log
2021-05-03 21:49 - 2021-05-03 21:49 - 000001799 _____ () C:\Users\Austin\AppData\Local\d62d7d44-dc5a-4ff7-8938-abef12031d75HDGraph.log
2021-06-26 07:18 - 2021-06-26 07:18 - 000001799 _____ () C:\Users\Austin\AppData\Local\de0c69db-b9fa-4a48-b2a5-f78d5555b459HDGraph.log
2017-02-16 12:22 - 2022-09-26 17:39 - 006199167 _____ () C:\Users\Austin\AppData\Local\HDGraph.log
2022-08-10 16:07 - 2022-08-10 16:07 - 000001450 _____ () C:\Users\Austin\AppData\Local\recently-used.xbel
2015-01-25 21:09 - 2022-08-12 19:14 - 000007605 _____ () C:\Users\Austin\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2022-10-24 00:36
==================== End of FRST.txt ========================
FRST.txt :
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-10-2022
Ran by Austin (administrator) on SORA (MSI MS-7673) (25-10-2022 21:33:28)
Running from C:\Users\Austin\Desktop
Loaded Profiles: Austin
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Elaborate Bytes AG -> Elaborate Bytes AG) C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe
(explorer.exe ->) () [File not signed] C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
(explorer.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(explorer.exe ->) (F.lux Software LLC -> f.lux Software LLC) C:\Users\Austin\AppData\Local\FluxSoftware\Flux\flux.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <41>
(explorer.exe ->) (Logitech -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(explorer.exe ->) (Open Source Developer, Stefan KUENG -> hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(explorer.exe ->) (Vincent Burel -> VB-AUDIO Software) C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Renesas Electronics Corporation -> Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(services.exe ->) (Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(services.exe ->) (Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(services.exe ->) (Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6612072 2011-03-07] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [13318424 2015-03-12] (Logitech -> Logitech Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4234088 2022-10-18] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Run: [f.lux] => C:\Users\Austin\AppData\Local\FluxSoftware\Flux\flux.exe [1511824 2021-02-04] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Run: [uTorrent] => "C:\Users\Austin\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED (No File)
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Run: [DAEMON Tools Lite Automount] => "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun (No File)
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2558064723-1881834265-789328380-1000\Software\Policies\...\system: [disablecmd] 0
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\106.0.5249.119\Installer\chrmstp.exe [2022-10-13] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{50968FF7-10C1-4fb3-98B0-CD654D6CB97E}] -> C:\Program Files\WIDCOMM\Bluetooth Software\\BtwCP.dll [2014-07-17] (Broadcom Corporation -> Broadcom Corporation.)
HKLM\Software\...\Authentication\Credential Providers: [{D28973E5-8630-41af-8831-50A15FEB396B}] -> C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll [2014-07-17] (Broadcom Corporation -> Broadcom Corporation.)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2021-07-20]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation -> Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2014-09-18]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe () [File not signed]
Startup: C:\Users\Austin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Core Temp.exe - Shortcut.lnk [2016-01-24]
ShortcutTarget: Core Temp.exe - Shortcut.lnk -> C:\Program Files\Core Temp\Core Temp.exe (Artur Liberman -> )
Startup: C:\Users\Austin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Voicemeeter (VB-Audio).LNK [2021-02-01]
ShortcutTarget: Voicemeeter (VB-Audio).LNK -> C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe (Vincent Burel -> VB-AUDIO Software)
GroupPolicy\User: Restriction ? <==== ATTENTION
GroupPolicyUsers\S-1-5-21-2558064723-1881834265-789328380-1003\User: Restriction <==== ATTENTION
Policies: C:\Users\Austin\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {316FB720-E624-4A95-B4BD-67E4E0E91172} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [862 2020-06-09] () [File not signed]
Task: {42C63EDD-883C-473F-81F7-707A592639E8} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.)
Task: {621063E6-D9FE-41AC-BD62-2D1EE3DDBE90} - System32\Tasks\{4870BB68-040C-4044-BCE0-E7F92EFFE874} => C:\Windows\system32\pcalua.exe -a C:\Users\Austin\Downloads\vbrun60sp6.exe -d C:\Users\Austin\Downloads
Task: {66F85F06-41A6-46E0-A3CE-542E3B0E4C2D} - System32\Tasks\elbyExecuteWithUAC => C:\Program Files (x86)\VirtualCloneDrive\ExecuteWithUAC.exe [77824 2013-03-21] () [File not signed]
Task: {69A85458-7E83-4F53-B991-76004A25CEF4} - System32\Tasks\sd => shutdown /s /f /t 0
Task: {85CD66E4-A4DA-4859-8EE0-030734A8B3AE} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_170_pepper.exe [1319424 2017-10-19] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {92489B32-DCDD-4F2B-AC75-83DE8ACD7FC9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-11-18] (Google Inc -> Google Inc.)
Task: {949BEB55-E2CF-42DC-B441-3A1BB2AFCEE7} - System32\Tasks\MATLAB R2014a Startup Accelerator => C:\Program Files\MATLAB\R2014a\bin\win64\MATLABStartupAccelerator.exe [42496 2014-01-29] () [File not signed]
Task: {A297B83D-4160-47C0-810D-0C46433FEA1A} - System32\Tasks\{C8FD5FFE-3812-4F3D-8CD9-9AC1183B065F} => C:\Windows\system32\pcalua.exe -a C:\Users\Austin\AppData\Roaming\uTorrent\uTorrent.exe -c /UNINSTALL
Task: {B6A28BD1-62FE-463A-87A4-16F261139F98} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-11-18] (Google Inc -> Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\MATLAB R2014a Startup Accelerator.job => C:\Program Files\MATLAB\R2014a\bin\win64\MATLABStartupAccelerator.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Hosts: 77.72.3.39 nmm.nexusmods.com # legacy-api.nexusmods.com
Tcpip\Parameters: [DhcpNameServer] 24.48.160.2 24.48.160.3
Tcpip\..\Interfaces\{55223230-04B3-47C4-A87D-32DF136473BD}: [DhcpNameServer] 24.48.160.2 24.48.160.3
Tcpip\..\Interfaces\{E1793131-E5E1-44CB-B3AA-14E257781EEB}: [DhcpNameServer] 208.180.42.68 208.180.42.100
FireFox:
========
FF DefaultProfile: 0yquk31o.default
FF ProfilePath: C:\Users\Austin\AppData\Roaming\Mozilla\Firefox\Profiles\0yquk31o.default [2022-10-22]
FF Session Restore: Mozilla\Firefox\Profiles\0yquk31o.default -> is enabled.
FF HKLM-x32\...\Firefox\Extensions: [WSVCU@Wondershare.com] - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com => not found
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-04-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-04-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll [2015-12-07] (Adobe Systems Incorporated -> )
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2022-10-16] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default [2022-10-25]
CHR DownloadDir: C:\Users\Austin\Desktop\kpopng
CHR Notifications: Default -> hxxps://deathsnacks.com; hxxps://www.predictit.org; hxxps://www1.darenjarvis.pro; hxxps://www45.darenjarvis.pro; hxxps://www54.darenjarvis.pro; hxxps://www55.josueshah.pro; hxxps://www7.darenjarvis.pro; hxxps://www82.darenjarvis.pro; hxxps://www84.darenjarvis.pro; hxxps://www87.darenjarvis.pro
CHR Session Restore: Default -> is enabled.
CHR Extension: (h264ify) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aleakchihdccplidncghkekgioiakgal [2021-10-20]
CHR Extension: (WOT Website Security & Privacy Protection) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2022-08-23]
CHR Extension: (Alternate Player for Twitch.tv) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhplkbgoehhhddaoolmakpocnenplmhf [2022-02-11]
CHR Extension: (MEGA) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2022-10-25]
CHR Extension: (uBlock Origin) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2022-09-22]
CHR Extension: (Powerful Pixiv Downloader) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkndmhgdcmjdmkdonmbgjpijejdcilfh [2022-10-25]
CHR Extension: (Old Reddit Redirect) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dneaehbmnbhcippjikoajpoabadpodje [2022-02-16]
CHR Extension: (AHA Music - Song Finder for Browser) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpacanjfikmhoddligfbehkpomnbgblf [2022-09-12]
CHR Extension: (Dark Reader) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2022-10-15]
CHR Extension: (Volume Booster) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejkiikneibegknkgimmihdpcbcedgmpo [2022-10-02]
CHR Extension: (Google Docs Offline) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-08-30]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2022-10-15]
CHR Extension: (Magic Enhancer For YouTube™) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2020-02-10]
CHR Extension: (Wallhaven Direct Downloader) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mggclgefcmlpigdbcpfheklbhflnknkf [2019-07-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-31]
CHR Extension: (The Marvellous Suspender) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\noogafoofpebimajpfpamcfhoaifemoa [2021-07-01]
CHR Extension: (History Trends Unlimited) - C:\Users\Austin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnmchffiealhkdloeffcdnbgdnedheme [2022-05-17]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. -> Adobe Inc.)
S4 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2020-07-30] (BitRaider LLC -> BitRaider, LLC)
S4 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [216576 2016-08-18] () [File not signed]
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [1959776 2022-02-15] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6484832 2022-02-15] (GOG Sp. z o.o. -> GOG.com)
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [22872 2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8838880 2022-10-14] (Malwarebytes Inc. -> Malwarebytes)
S4 MsMpiLaunchSvc; C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe [27760 2015-11-06] (AzureEngBuildCodeSign -> ) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4490376 2020-09-18] (Logitech Inc -> Logitech)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3758336 2015-11-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
S4 WPSService20; C:\Program Files (x86)\ASUS USB-N13 Wireless LAN Driver\WPSService20.exe [96768 2014-05-06] () [File not signed]
S2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [X]
S2 NMSAccess; "C:\Program Files (x86)\Blaze Media Pro\NMSAccess32.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2020-07-30] (BitRaider -> BitRaider)
S3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [59904 2015-01-26] (Microsoft Windows Hardware Compatibility Publisher -> www.winchiphead.com)
S3 CM_VENDER_CMD; C:\Program Files\Common Files\Logitech\G430Install\CMVC64.sys [17104 2014-07-30] (C-MEDIA ELECTRONICS INC. -> Windows (R) Win 7 DDK provider)
S3 DABlackFltr; C:\Windows\System32\drivers\DABlack.sys [23040 2010-11-29] (Razer (Asia-Pacific) Pte Ltd) [File not signed]
S3 droidpad; C:\Windows\System32\DRIVERS\droidpad.sys [21320 2013-04-18] (ReactOS Foundation -> Windows (R) Win 7 DDK provider)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-08-06] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-08-06] (Disc Soft Ltd -> Disc Soft Ltd)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239544 2022-09-23] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R3 MpKsla3e734b6; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EF3CF7D9-E62C-4B9B-B122-0D696587AB9A}\MpKslDrv.sys [50456 2022-10-25] (Microsoft Windows -> Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R1 npcap; C:\Windows\System32\DRIVERS\npcap.sys [71440 2020-06-12] (Insecure.Com LLC -> Insecure.Com LLC.)
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [82432 2011-02-10] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [181760 2011-02-10] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
R3 NVHDA; C:\Windows\System32\drivers\nvhda64v.sys [136848 2022-07-11] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
R3 nvlddmkm; C:\Windows\System32\DRIVERS\nvlddmkm.sys [37058984 2022-07-14] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3810520 2015-10-08] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation)
S3 RzCommon; C:\Windows\System32\DRIVERS\RzCommon.sys [52040 2021-03-30] (Razer USA Ltd. -> Razer Inc)
S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [43720 2015-08-13] (Razer Inc. -> Razer Inc)
S3 RzDev_0084; C:\Windows\System32\DRIVERS\RzDev_0084.sys [50584 2020-08-24] (Razer USA Ltd. -> Razer Inc)
S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [51736 2016-06-22] (Razer USA Ltd. -> Razer Inc)
S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [44232 2015-08-13] (Razer Inc. -> Razer Inc)
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [38032 2022-10-25] (Adlice -> )
R3 VBAudioVACMME; C:\Windows\System32\DRIVERS\vbaudio_cable64_win7.sys [41192 2014-09-02] (Vincent Burel -> Windows (R) Win 7 DDK provider)
R3 VBAudioVMVAIOMME; C:\Windows\System32\DRIVERS\vbaudio_vmvaio64_win7.sys [41192 2016-03-17] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S3 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [240704 2022-03-22] (Oracle Corporation -> Oracle Corporation)
S3 VKbms; C:\Windows\System32\DRIVERS\VKbms.sys [13312 2010-10-01] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 ALSysIO; \??\C:\Users\Austin\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 BCMH43XX; system32\DRIVERS\bcmwlhigh664.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
U4 npcap_wifi; no ImagePath
S3 NPF; system32\DRIVERS\npf.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
S4 nvvhci; system32\DRIVERS\nvvhci.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-10-25 21:33 - 2022-10-25 21:34 - 000023113 _____ C:\Users\Austin\Desktop\FRST.txt
2022-10-25 21:05 - 2022-10-25 21:05 - 000000000 ____D C:\Windows\erdnt
2022-10-25 21:05 - 2022-10-25 21:05 - 000000000 ____D C:\Qoobox
2022-10-25 20:19 - 2022-10-25 20:43 - 000038032 _____ C:\Windows\system32\Drivers\truesight.sys
2022-10-25 20:19 - 2022-10-25 20:19 - 000000000 ____D C:\ProgramData\RogueKiller
2022-10-25 19:58 - 2022-10-25 21:33 - 000000000 ____D C:\FRST
2022-10-25 19:58 - 2022-10-25 19:58 - 002373632 _____ (Farbar) C:\Users\Austin\Desktop\FRST64.exe
2022-10-25 18:48 - 2022-10-25 18:48 - 000000804 _____ C:\Users\Public\Desktop\Children of Morta.lnk
2022-10-25 18:38 - 2022-10-25 18:38 - 000000999 _____ C:\Users\Public\Desktop\The Dungeon Of Naheulbeuk - The Amulet Of Chaos.lnk
2022-10-25 08:55 - 2022-10-25 08:55 - 002843475 _____ C:\Users\Austin\Desktop\1666702234628302.webm
2022-10-25 08:54 - 2022-10-25 08:54 - 000000735 _____ C:\Users\Public\Desktop\Fatal Twelve.lnk
2022-10-24 22:41 - 2022-10-24 22:41 - 003052293 _____ C:\Users\Austin\Desktop\1666667465597307.webm
2022-10-24 21:50 - 2022-10-24 21:50 - 003018073 _____ C:\Users\Austin\Desktop\brent mod.webm
2022-10-13 17:02 - 2022-10-22 20:53 - 000002059 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2022-10-13 17:02 - 2022-10-22 20:53 - 000002047 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
2022-10-13 04:25 - 2022-10-13 04:25 - 001298555 _____ C:\Users\Austin\Desktop\1665651881593107.webm
2022-10-07 07:07 - 2022-10-07 07:07 - 000000000 ____D C:\Users\Austin\AppData\Roaming\JetBrains
2022-10-07 07:07 - 2022-10-07 07:07 - 000000000 ____D C:\Users\Austin\AppData\Local\SymbolSourceSymbols
2022-10-07 07:07 - 2022-10-07 07:07 - 000000000 ____D C:\Users\Austin\AppData\Local\RefSrcSymbols
2022-10-07 07:06 - 2022-10-07 07:07 - 000000000 ____D C:\Users\Austin\AppData\Local\JetBrains
2022-10-07 06:29 - 2022-10-07 06:29 - 000000000 ____D C:\Users\Austin\AppData\Local\imhex
2022-09-25 17:53 - 2022-09-25 17:53 - 000000000 ____D C:\Users\Austin\AppData\Local\Microsoft_Corporation
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-10-25 21:32 - 2022-03-05 00:13 - 000000000 ____D C:\Users\Austin\Desktop\kpopng
2022-10-25 21:30 - 2014-09-18 23:04 - 000000000 ____D C:\Program Files (x86)\Steam
2022-10-25 21:23 - 2009-07-13 23:45 - 000031680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2022-10-25 21:23 - 2009-07-13 23:45 - 000031680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2022-10-25 21:19 - 2009-07-14 00:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
2022-10-25 21:19 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2022-10-25 21:15 - 2014-09-18 21:18 - 000000000 ____D C:\Program Files (x86)\Google
2022-10-25 21:14 - 2016-03-17 10:06 - 000003339 _____ C:\Users\Austin\AppData\Roaming\VoiceMeeterDefault.xml
2022-10-25 21:14 - 2014-10-05 18:04 - 000000548 _____ C:\Windows\Tasks\MATLAB R2014a Startup Accelerator.job
2022-10-25 21:13 - 2016-06-15 21:54 - 000000000 ____D C:\Users\Austin\AppData\Local\TSVNCache
2022-10-25 21:13 - 2014-09-18 22:21 - 000000000 ____D C:\ProgramData\NVIDIA
2022-10-25 21:13 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-10-25 19:30 - 2014-09-19 00:48 - 000000000 ____D C:\Users\Austin\AppData\Local\Battle.net
2022-10-25 18:48 - 2015-12-28 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2022-10-25 18:38 - 2014-10-17 21:03 - 000000000 ____D C:\ProgramData\Package Cache
2022-10-25 13:05 - 2021-05-14 16:26 - 000000000 ____D C:\Users\Austin\AppData\Local\User Data
2022-10-25 09:01 - 2016-03-25 00:45 - 000000000 ____D C:\Users\Austin\AppData\Roaming\qBittorrent
2022-10-24 22:59 - 2021-03-04 07:01 - 000000000 ____D C:\Program Files\Cheat Engine 7.2
2022-10-23 22:52 - 2021-12-22 05:02 - 000000000 ____D C:\Program Files\Genshin Impact
2022-10-22 18:54 - 2014-09-19 00:48 - 000000000 ____D C:\Program Files (x86)\Battle.net
2022-10-22 15:34 - 2017-06-06 22:00 - 000000000 ____D C:\Users\Austin\AppData\LocalLow\Mozilla
2022-10-21 20:57 - 2022-09-14 17:39 - 000000000 ____D C:\Program Files (x86)\SteamCMD
2022-10-19 03:01 - 2021-10-29 19:46 - 000000000 ____D C:\Users\Austin\Desktop\Locale.Emulator.2.5.0.1
2022-10-16 20:32 - 2016-09-18 04:24 - 000000000 ____D C:\Users\Austin\AppData\Local\CrashDumps
2022-10-14 07:47 - 2014-09-18 22:15 - 000000000 ____D C:\Windows\pss
2022-10-13 17:02 - 2016-12-04 21:20 - 000004476 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2022-10-13 16:40 - 2016-11-18 03:42 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-10-08 23:46 - 2020-12-07 07:54 - 000000000 ____D C:\Users\Austin\Desktop\twitch prof
2022-09-26 07:12 - 2022-05-27 02:13 - 000000000 ____D C:\Users\Austin\AppData\Local\HoYoverse
==================== Files in the root of some directories ========
2016-09-03 19:31 - 2016-09-03 19:31 - 000000445 _____ () C:\Users\Austin\AppData\Roaming\CSharpAnalytics-MeasurementSession
2016-01-20 09:58 - 2016-01-20 10:03 - 000003209 _____ () C:\Users\Austin\AppData\Roaming\droid4xinstaller.log
2021-11-17 07:18 - 2021-11-17 07:23 - 000003216 _____ () C:\Users\Austin\AppData\Roaming\ETCAvenueScores
2021-11-17 07:21 - 2021-11-17 07:23 - 000000048 _____ () C:\Users\Austin\AppData\Roaming\ETCAvenueStats
2021-11-17 07:25 - 2021-11-17 07:27 - 000000568 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonicScoring
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench0
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench1
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench2
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench3
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench4
2021-11-17 07:17 - 2021-11-17 07:17 - 000000015 _____ () C:\Users\Austin\AppData\Roaming\ETCHarmonyBench5
2021-11-17 07:17 - 2021-11-17 07:17 - 000000017 _____ () C:\Users\Austin\AppData\Roaming\ETCPlayers
2021-11-17 07:17 - 2021-11-17 07:27 - 000000396 _____ () C:\Users\Austin\AppData\Roaming\ETCPrefs6
2019-02-04 00:26 - 2019-02-04 00:26 - 000000624 _____ () C:\Users\Austin\AppData\Roaming\jd-gui.cfg
2014-09-20 10:24 - 2015-09-27 12:23 - 000000907 _____ () C:\Users\Austin\AppData\Roaming\MPQEditor.ini
2016-06-15 20:34 - 2016-06-29 16:34 - 000000134 _____ () C:\Users\Austin\AppData\Roaming\RbNorthAmerica-MeasurementQueue
2016-06-15 20:34 - 2016-07-05 07:30 - 000000444 _____ () C:\Users\Austin\AppData\Roaming\RbNorthAmerica-MeasurementSession
2016-06-15 20:34 - 2016-06-29 16:34 - 000000134 _____ () C:\Users\Austin\AppData\Roaming\RebornBuddy-MeasurementQueue
2016-06-15 20:34 - 2016-07-05 07:30 - 000000444 _____ () C:\Users\Austin\AppData\Roaming\RebornBuddy-MeasurementSession
2016-03-17 10:06 - 2022-10-25 21:14 - 000003339 _____ () C:\Users\Austin\AppData\Roaming\VoiceMeeterDefault.xml
2016-03-19 06:35 - 2016-03-19 06:35 - 000225280 ____T (MultiMedia Soft) C:\Users\Austin\AppData\Roaming\Microsoft\AdjMmsVista.dll
2021-02-14 11:53 - 2021-02-14 11:53 - 000001799 _____ () C:\Users\Austin\AppData\Local\2bf55744-b047-477d-849c-446f99a5bef2HDGraph.log
2017-09-20 20:18 - 2017-09-20 20:18 - 000001807 _____ () C:\Users\Austin\AppData\Local\2e5e69fb-0ebb-4720-89f9-fe161564a96bHDGraph.log
2017-09-20 20:17 - 2017-09-20 20:17 - 000001807 _____ () C:\Users\Austin\AppData\Local\5e17b0e1-63c5-406d-a622-f0fa6e358076HDGraph.log
2017-09-20 20:18 - 2017-09-20 20:18 - 000001807 _____ () C:\Users\Austin\AppData\Local\79ec6bad-635c-4763-a148-ac04a699fb44HDGraph.log
2021-10-10 14:53 - 2021-10-10 14:58 - 000009423 _____ () C:\Users\Austin\AppData\Local\986efbfb-9c37-45ab-821d-aceaab6ea404HDGraph.log
2017-09-20 20:17 - 2017-09-20 20:17 - 000001807 _____ () C:\Users\Austin\AppData\Local\b045eaf9-8f98-4a1d-b05b-519309c89d47HDGraph.log
2022-03-28 04:23 - 2022-03-28 04:23 - 000000000 _____ () C:\Users\Austin\AppData\Local\D216C4.tmp
2022-03-25 06:23 - 2022-03-25 06:23 - 000000000 _____ () C:\Users\Austin\AppData\Local\D21AF9.tmp
2022-03-25 15:46 - 2022-03-25 15:46 - 000000000 _____ () C:\Users\Austin\AppData\Local\D21B23.tmp
2022-03-27 19:10 - 2022-03-27 19:10 - 000000000 _____ () C:\Users\Austin\AppData\Local\D22145.tmp
2022-03-28 04:26 - 2022-03-28 04:26 - 000000000 _____ () C:\Users\Austin\AppData\Local\D22AF0.tmp
2022-03-26 20:02 - 2022-03-26 20:02 - 000000000 _____ () C:\Users\Austin\AppData\Local\D23038.tmp
2022-03-30 19:11 - 2022-03-30 19:11 - 000000000 _____ () C:\Users\Austin\AppData\Local\D236D3.tmp
2022-03-25 21:09 - 2022-03-25 21:09 - 000000000 _____ () C:\Users\Austin\AppData\Local\D24709.tmp
2022-04-08 10:03 - 2022-04-08 10:03 - 000000000 _____ () C:\Users\Austin\AppData\Local\D24A1F.tmp
2022-04-08 03:39 - 2022-04-08 03:39 - 000000000 _____ () C:\Users\Austin\AppData\Local\D27186.tmp
2022-03-31 03:21 - 2022-03-31 03:21 - 000000000 _____ () C:\Users\Austin\AppData\Local\D27F60.tmp
2022-03-29 19:02 - 2022-03-29 19:02 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2996.tmp
2022-03-26 23:49 - 2022-03-26 23:49 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2C386.tmp
2022-03-25 01:33 - 2022-03-25 01:33 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2C3D0.tmp
2022-03-31 00:17 - 2022-03-31 00:17 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2C957.tmp
2022-04-03 08:54 - 2022-04-03 08:54 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2CB84.tmp
2022-03-30 03:21 - 2022-03-30 03:21 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2CDC8.tmp
2022-04-01 06:54 - 2022-04-01 06:54 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2D0D.tmp
2022-04-02 02:04 - 2022-04-02 02:04 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2DC91.tmp
2022-04-06 13:41 - 2022-04-06 13:41 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2EA14.tmp
2022-03-28 17:35 - 2022-03-28 17:35 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2EEBA.tmp
2022-03-25 06:28 - 2022-03-25 06:28 - 000000000 _____ () C:\Users\Austin\AppData\Local\D2F0BF.tmp
2021-03-17 22:55 - 2021-03-17 23:28 - 000014734 _____ () C:\Users\Austin\AppData\Local\d509f535-47d1-45a2-a7a6-36acd258c149HDGraph.log
2021-05-03 21:49 - 2021-05-03 21:49 - 000001799 _____ () C:\Users\Austin\AppData\Local\d62d7d44-dc5a-4ff7-8938-abef12031d75HDGraph.log
2021-06-26 07:18 - 2021-06-26 07:18 - 000001799 _____ () C:\Users\Austin\AppData\Local\de0c69db-b9fa-4a48-b2a5-f78d5555b459HDGraph.log
2017-02-16 12:22 - 2022-09-26 17:39 - 006199167 _____ () C:\Users\Austin\AppData\Local\HDGraph.log
2022-08-10 16:07 - 2022-08-10 16:07 - 000001450 _____ () C:\Users\Austin\AppData\Local\recently-used.xbel
2015-01-25 21:09 - 2022-08-12 19:14 - 000007605 _____ () C:\Users\Austin\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2022-10-24 00:36
==================== End of FRST.txt ========================