Hello. So, i entered a website and it redirected me to this other side called. v4.s.arclk.net. Thankfully NoScript blocked it from working, but i still don't know if i'm 100% safe.I've read that it was adware website and i just wanted to check. Norton doesn't detect anything.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-04-2021
Ran by kubsons07 (administrator) on DESKTOP-7J71UVT (05-05-2021 15:24:44)
Running from C:\Users\kubsons07\Desktop\FRST
Loaded Profiles: kubsons07
Platform: Windows 10 Home Version 2004 19041.928 (X64) Language: Polski (Polska)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Electronic Arts, Inc. -> ) C:\Program Files (x86)\Origin\QtWebEngineProcess.exe <2>
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe
(Malwarebytes Inc -> Malwarebytes) D:\Program Files\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) D:\Program Files\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\kubsons07\AppData\Local\Microsoft\Teams\current\Teams.exe <10>
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.20122.11121.0_x64__8wekyb3d8bbwe\Music.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mspaint.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.) C:\Windows\V0790Mon.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe <6>
(NortonLifeLock Inc. -> NortonLifeLock Inc.) C:\Program Files\Norton Security\Norton Security\Engine\22.21.2.50\nsWscSvc.exe
(NortonLifeLock Inc. -> Symantec Corporation) C:\Program Files\Norton Security\Norton Security\Engine\22.21.2.50\NortonSecurity.exe <2>
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Skutta, Kristjan -> ) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8495320 2015-06-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [V0790Mon.exe] => C:\WINDOWS\V0790Mon.exe [43120 2015-08-24] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706288 2021-04-09] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-2944253907-4126696763-4153681683-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4087528 2021-04-12] (Valve -> Valve Corporation)
HKU\S-1-5-21-2944253907-4126696763-4153681683-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3144760 2021-04-27] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-2944253907-4126696763-4153681683-1001\...\Run: [Discord] => C:\ProgramData\kubsons07\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2944253907-4126696763-4153681683-1001\...\Run: [WallpaperEngine] => C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe [2769000 2021-03-02] (Skutta, Kristjan -> )
HKU\S-1-5-21-2944253907-4126696763-4153681683-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\kubsons07\AppData\Local\Microsoft\Teams\Update.exe [2453728 2021-04-14] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe /StartMinimized
HKLM\...\Print\Monitors\HP E611 Status Monitor: C:\Windows\system32\hpinkstsE611LM.dll [401920 2019-07-01] (Hewlett Packard -> HP Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.93\Installer\chrmstp.exe [2021-04-27] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {026C09C6-6379-4323-88DD-5B91FE8EFA09} - System32\Tasks\CorelUpdateHelperTaskCore => C:\Program Files (x86)\Corel\CUH\v2\CUH.exe [3583264 2020-06-03] (Corel Corporation -> Corel Corporation)
Task: {06CAA493-F24B-4597-906E-9D6F4CD8C2B1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-06-13] (Google Inc -> Google Inc.)
Task: {28006914-A4CC-4E70-B028-2B6C815D2A3D} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3336560 2021-04-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {395517F0-9BE9-4E98-A87D-B0BA1F80D6CF} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-09-29] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {3B60934E-99A0-4107-BCEA-7285F4784077} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Security\Norton Security\Engine\22.21.2.50\WSCStub.exe [643584 2021-03-27] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
Task: {4B468D47-3B67-4E33-B9DA-C5B3D8D920C7} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security\Upgrade.exe [2344608 2021-03-27] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
Task: {60FB07F5-F819-45A1-A422-41909F26296E} - System32\Tasks\Norton Security\Norton Security Error Analyzer => C:\Program Files\Norton Security\Norton Security\Engine\22.21.2.50\SymErr.exe [115640 2021-03-27] (NortonLifeLock Inc. -> NortonLifeLock Inc)
Task: {809E3FFB-F34C-400B-ABA3-3523B418E036} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-09-29] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {883B83A5-A696-4E67-A76E-963271C55684} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {887773E8-7BC3-44CB-A468-DAE3DFF906D3} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {8CC62A65-6305-4FED-91E6-573D4752BFF7} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B91B47A4-FAF5-4509-BFE9-2BD2268C3BC5} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905584 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CE35495F-E536-4372-88FA-C03C5C92CD42} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {DF26F89F-54B9-49E1-8760-798A296A3D1C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-06-13] (Google Inc -> Google Inc.)
Task: {E0ACAFA3-7A5B-4C8D-8EF1-8FE1BD7110B7} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E6C7861C-3D4D-47C5-B6B2-6DB4A8F28E55} - System32\Tasks\Norton Security\Norton Security Error Processor => C:\Program Files\Norton Security\Norton Security\Engine\22.21.2.50\SymErr.exe [115640 2021-03-27] (NortonLifeLock Inc. -> NortonLifeLock Inc)
Task: {E9665764-65EC-40D5-BFF9-A8AC60069104} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [696304 2021-04-21] (Mozilla Corporation -> Mozilla Foundation)
Task: {EF6E906B-AD98-45AE-AC74-566CFD909780} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {EFAD52E7-0C09-4469-B04C-903CA730E7C6} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905584 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F8F565DB-EBFE-4860-8404-F64291EA178F} - System32\Tasks\Norton Security\Norton Security Autofix => C:\Program Files\Norton Security\Norton Security\Engine\22.21.2.50\SymErr.exe [115640 2021-03-27] (NortonLifeLock Inc. -> NortonLifeLock Inc)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.31.1
Tcpip\..\Interfaces\{5727f1df-f5f5-41d1-8aac-4618ca034e36}: [DhcpNameServer] 192.168.31.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\kubsons07\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-05]
FireFox:
========
FF DefaultProfile: aq3w9l33.default-1523276245035
FF ProfilePath: C:\Users\kubsons07\AppData\Roaming\Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035 [2021-05-05]
FF Homepage: Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035 -> www.google.com
FF Extension: (Dark Reader) - C:\Users\kubsons07\AppData\Roaming\Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035\Extensions\addon@darkreader.org.xpi [2021-04-22]
FF Extension: (Norton Password Manager) - C:\Users\kubsons07\AppData\Roaming\Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035\Extensions\idsafe@norton.com.xpi [2021-04-20]
FF Extension: (Norton Home Page) - C:\Users\kubsons07\AppData\Roaming\Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035\Extensions\nortonhomepage@symantec.com.xpi [2021-05-04] [UpdateUrl:hxxps://static.nortoncdn.com/idscp/firefox/nsss/hp/updates.json]
FF Extension: (Norton Safe Search) - C:\Users\kubsons07\AppData\Roaming\Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035\Extensions\nortonsafesearch_ul_2@symantec.com.xpi [2021-05-04] [UpdateUrl:hxxps://static.nortoncdn.com/idscp/firefox/nsss/ds_modified/updates.json]
FF Extension: (Norton Safe Web) - C:\Users\kubsons07\AppData\Roaming\Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035\Extensions\nortonsafeweb@symantec.com.xpi [2021-05-03]
FF Extension: (Light Sea) - C:\Users\kubsons07\AppData\Roaming\Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035\Extensions\{124ac638-9949-4296-83e5-0a30089482fa}.xpi [2019-08-16]
FF Extension: (NoScript) - C:\Users\kubsons07\AppData\Roaming\Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2021-05-04]
FF Extension: (rainbow blur) - C:\Users\kubsons07\AppData\Roaming\Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035\Extensions\{7477cece-5973-41fe-a60e-2d2ffae6d21e}.xpi [2019-08-16]
FF Extension: (Adblock Plus - darmowy adblocker) - C:\Users\kubsons07\AppData\Roaming\Mozilla\Firefox\Profiles\aq3w9l33.default-1523276245035\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2021-01-29]
FF Plugin: @java.com/DTPlugin,version=11.291.2 -> C:\Program Files\Java\jre1.8.0_291\bin\dtplugin\npDeployJava1.dll [2021-04-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.291.2 -> C:\Program Files\Java\jre1.8.0_291\bin\plugin2\npjp2.dll [2021-04-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.291.2 -> C:\Program Files (x86)\Java\jre1.8.0_291\bin\dtplugin\npDeployJava1.dll [2021-04-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.291.2 -> C:\Program Files (x86)\Java\jre1.8.0_291\bin\plugin2\npjp2.dll [2021-04-24] (Oracle America, Inc. -> Oracle Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\kubsons07\AppData\Local\Google\Chrome\User Data\Default [2021-02-18]
CHR Notifications: Default -> hxxps://www.youtube.com
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\kubsons07\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-06-23]
CHR Extension: (Chrome Media Router) - C:\Users\kubsons07\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-12-01]
CHR Profile: C:\Users\kubsons07\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-06-03]
CHR Profile: C:\Users\kubsons07\AppData\Local\Google\Chrome\User Data\System Profile [2020-06-03]
CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security\Norton Security\Engine\22.21.2.50\Exts\Chrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security\Norton Security\Engine\22.21.2.50\Exts\Chrome.crx <not found>
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3780296 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3548360 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8736880 2020-11-07] (BattlEye Innovations e.K. -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [802432 2019-08-14] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 FvSvc; C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [409456 2021-03-30] (NVIDIA Corporation -> NVIDIA)
R3 Intel® Security Assist; C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 MBAMService; D:\Program Files\MBAMService.exe [7456464 2021-04-09] (Malwarebytes Inc -> Malwarebytes)
R2 NortonSecurity; C:\Program Files\Norton Security\Norton Security\Engine\22.21.2.50\NortonSecurity.exe [343336 2021-03-27] (NortonLifeLock Inc. -> Symantec Corporation)
R2 nsWscSvc; C:\Program Files\Norton Security\Norton Security\Engine\22.21.2.50\nsWscSvc.exe [1054536 2021-03-27] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2545752 2021-04-27] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3485784 2021-04-27] (Electronic Arts, Inc. -> Electronic Arts)
R2 PSI_SVC_2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
R2 PSI_SVC_2_x64; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 BHDrvx64; C:\Program Files\Norton Security\Norton Security\NortonData\22.20.2.57\Definitions\BASHDefs\20210427.011\BHDrvx64.sys [1995864 2021-03-16] (Symantec Corporation -> Broadcom)
R1 ccSet_NGC; C:\WINDOWS\System32\drivers\NGCx64\1615020.032\ccSetx64.sys [192248 2021-03-27] (Symantec Corporation -> Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [516168 2021-02-03] (Symantec Corporation -> Broadcom)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [153672 2021-02-13] (Symantec Corporation -> Broadcom)
R1 IDSVia64; C:\Program Files\Norton Security\Norton Security\NortonData\22.20.2.57\Definitions\IPSDefs\20210504.061\IDSvia64.sys [1488976 2021-04-06] (Symantec Corporation -> Broadcom)
S3 Larmkanal; C:\WINDOWS\System32\drivers\Larmkanal.sys [33112 2015-09-02] (ADORIASOFT LLC -> Adoriasoft LLC)
S3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [38136 2020-02-18] (Logitech Inc -> Logitech)
S3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [26672 2020-08-10] (Logitech Inc -> Logitech)
S3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [66808 2020-02-18] (Logitech Inc -> Logitech)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220752 2021-05-01] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-04-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-05-01] (Malwarebytes Inc -> Malwarebytes)
S3 nsvst_NGC; C:\WINDOWS\System32\drivers\NGCx64\1615020.032\nsvst.sys [56912 2021-03-27] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
S3 Phosgene; C:\WINDOWS\system32\DRIVERS\Phosgene.sys [34136 2015-09-02] (ADORIASOFT LLC -> Adoriasoft LLC)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2013-09-30] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] (MiniTool Solution Ltd -> )
S3 RzCommon; C:\WINDOWS\System32\drivers\RzCommon.sys [51776 2020-02-17] (Razer USA Ltd. -> Razer Inc)
S3 RzDev_021e; C:\WINDOWS\System32\drivers\RzDev_021e.sys [52288 2020-02-17] (Razer USA Ltd. -> Razer Inc)
S3 RzDev_0306; C:\WINDOWS\System32\drivers\RzDev_0306.sys [52504 2020-02-17] (Razer USA Ltd. -> Razer Inc)
R3 SRTSP; C:\WINDOWS\System32\drivers\NGCx64\1615020.032\SRTSP64.SYS [890464 2021-03-27] (Symantec Corporation -> Broadcom)
R1 SRTSPX; C:\WINDOWS\System32\drivers\NGCx64\1615020.032\SRTSPX64.SYS [50272 2021-03-27] (Symantec Corporation -> Broadcom)
S3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [48040 2018-09-25] (SteelSeries ApS -> SteelSeries ApS)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166760 2019-09-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 SteamStreamingMicrophone; C:\WINDOWS\system32\drivers\SteamStreamingMicrophone.sys [40736 2017-07-28] (Valve Corp. -> )
R3 SteamStreamingSpeakers; C:\WINDOWS\system32\drivers\SteamStreamingSpeakers.sys [40736 2017-07-21] (Valve Corp. -> )
R0 SymEFASI; C:\WINDOWS\System32\drivers\NGCx64\1615020.032\SYMEFASI64.SYS [2060656 2021-03-27] (Symantec Corporation -> Broadcom)
S0 SymELAM; C:\WINDOWS\System32\drivers\NGCx64\1615020.032\SymELAM.sys [25080 2021-03-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Broadcom Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [100064 2019-07-28] (Symantec Corporation -> Symantec Corporation)
R3 SymEvnt; C:\Program Files\Norton Security\Norton Security\NortonData\22.20.2.57\SymPlatform\SymEvnt.sys [712368 2020-03-20] (Symantec Corporation -> Symantec Corporation)
R1 SymIRON; C:\WINDOWS\System32\drivers\NGCx64\1615020.032\Ironx64.SYS [316488 2021-03-27] (Symantec Corporation -> Symantec Corporation)
R1 SymNetS; C:\WINDOWS\System32\drivers\NGCx64\1615020.032\symnets.sys [575328 2021-03-27] (Symantec Corporation -> Symantec Corporation)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
S3 V0790Vid; C:\WINDOWS\system32\DRIVERS\V0790Vid.sys [389128 2015-08-24] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.)
S2 vcs; C:\Program Files (x86)\Common Files\Avnex\vcs64.sys [4096 2017-07-15] () [File not signed]
R3 VCSVADHWSer; C:\WINDOWS\System32\drivers\vcsvad.sys [29320 2015-10-01] (AVSOFT CORP. -> AVSOFT Corp.)
S3 VOICEMOD_Driver; C:\WINDOWS\system32\drivers\vmdrv.sys [45408 2018-03-15] (Voicemod Sociedad Limitada -> Windows ® Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 wpCtrlDrv_NGC; C:\WINDOWS\System32\drivers\NGCx64\1615020.032\wpCtrlDrv.sys [1013792 2021-03-27] (NortonLifeLock Inc. -> NortonLifeLock Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-05 15:23 - 2021-05-05 15:24 - 000000000 ____D C:\Users\kubsons07\Desktop\FRST
2021-05-05 13:06 - 2021-05-05 13:06 - 000015158 _____ C:\Users\kubsons07\AppData\Local\recently-used.xbel
2021-05-05 10:44 - 2021-05-05 10:44 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation
2021-05-04 21:29 - 2021-05-04 21:30 - 000000000 ____D C:\Users\kubsons07\Desktop\hitsound pack1
2021-05-03 15:41 - 2021-05-03 15:42 - 001299185 _____ C:\Users\kubsons07\Desktop\sfm.dem
2021-05-03 15:21 - 2021-05-03 15:21 - 000000000 _____ C:\Users\kubsons07\Desktop\Nowy dokument tekstowy.txt
2021-05-03 15:18 - 2021-05-03 15:18 - 000083342 _____ C:\Users\kubsons07\Desktop\bbb.jpeg
2021-05-03 15:16 - 2021-05-03 15:16 - 000001041 _____ C:\Users\kubsons07\Desktop\hammer — skrót.lnk
2021-05-02 14:21 - 2021-05-04 21:21 - 000000000 ____D C:\Users\kubsons07\Desktop\toonhud
2021-05-01 13:06 - 2021-05-01 13:06 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-05-01 13:06 - 2021-05-01 13:06 - 000220752 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-04-29 21:57 - 2021-04-29 21:58 - 000000000 ____D C:\WINDOWS\LastGood
2021-04-29 21:53 - 2021-04-28 15:54 - 001855192 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2021-04-29 21:53 - 2021-04-28 15:54 - 001855192 _____ C:\WINDOWS\system32\vulkaninfo.exe
2021-04-29 21:53 - 2021-04-28 15:54 - 001453344 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2021-04-29 21:53 - 2021-04-28 15:54 - 001435864 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-04-29 21:53 - 2021-04-28 15:54 - 001435864 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2021-04-29 21:53 - 2021-04-28 15:54 - 001192728 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2021-04-29 21:53 - 2021-04-28 15:54 - 001094880 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2021-04-29 21:53 - 2021-04-28 15:54 - 001094880 _____ C:\WINDOWS\system32\vulkan-1.dll
2021-04-29 21:53 - 2021-04-28 15:54 - 000948952 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2021-04-29 21:53 - 2021-04-28 15:54 - 000948952 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2021-04-29 21:53 - 2021-04-28 15:52 - 000715552 _____ C:\WINDOWS\system32\nvofapi64.dll
2021-04-29 21:53 - 2021-04-28 15:52 - 000575776 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2021-04-29 21:53 - 2021-04-28 15:51 - 002106144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2021-04-29 21:53 - 2021-04-28 15:51 - 001590560 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2021-04-29 21:53 - 2021-04-28 15:51 - 001514776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2021-04-29 21:53 - 2021-04-28 15:51 - 001166104 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2021-04-29 21:53 - 2021-04-28 15:51 - 000675120 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2021-04-29 21:53 - 2021-04-28 15:51 - 000564016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2021-04-29 21:53 - 2021-04-28 15:50 - 008317216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2021-04-29 21:53 - 2021-04-28 15:50 - 007434032 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2021-04-29 21:53 - 2021-04-28 15:50 - 004795160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2021-04-29 21:53 - 2021-04-28 15:50 - 002823448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2021-04-29 21:53 - 2021-04-28 15:50 - 001730864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6446627.dll
2021-04-29 21:53 - 2021-04-28 15:50 - 001490224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6446627.dll
2021-04-29 21:53 - 2021-04-28 15:50 - 000811800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2021-04-29 21:52 - 2021-04-28 15:42 - 006159152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2021-04-27 20:41 - 2021-04-27 20:41 - 000012246 _____ C:\Users\kubsons07\Desktop\killsound1.wav
2021-04-24 17:27 - 2021-04-24 17:26 - 000191776 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll
2021-04-24 16:39 - 2021-04-24 21:05 - 000000000 ____D C:\Users\kubsons07\Desktop\1.8.9
2021-04-23 21:37 - 2021-04-23 21:37 - 049061420 _____ C:\Users\kubsons07\Desktop\after dark.wav
2021-04-23 16:46 - 2021-05-02 14:28 - 000000000 ____D C:\Users\kubsons07\Desktop\nocritsounds
2021-04-22 10:47 - 2021-04-22 10:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2021-04-21 20:34 - 2021-04-24 17:06 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2021-04-16 11:37 - 2021-04-16 11:37 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-04-16 11:35 - 2021-04-16 11:35 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-04-16 11:35 - 2021-04-16 11:35 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-04-15 14:23 - 2021-04-15 14:24 - 000000000 ____D C:\Users\kubsons07\Desktop\AdvHUD files
2021-04-14 18:13 - 2020-08-14 09:59 - 000043416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\NvModuleTracker.sys
2021-04-13 16:29 - 2021-05-05 11:36 - 000000000 ____D C:\WINDOWS\system32\Tasks\Norton Security
2021-04-13 16:28 - 2021-04-13 16:49 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security
2021-04-13 16:28 - 2021-04-13 16:28 - 000003408 _____ C:\WINDOWS\system32\Tasks\Norton WSC Integration
2021-04-09 16:28 - 2021-04-09 16:28 - 000000650 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-04-09 16:28 - 2021-04-09 16:27 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-04-09 16:28 - 2021-04-09 16:27 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-04-08 18:16 - 2021-04-08 18:16 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-05 15:29 - 2020-11-15 03:37 - 000000000 ____D C:\FRST
2021-05-05 15:23 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-05-05 14:18 - 2017-06-13 11:22 - 000000000 ____D C:\ProgramData\NVIDIA
2021-05-05 14:17 - 2017-06-14 19:39 - 000000000 ____D C:\Program Files (x86)\Steam
2021-05-05 13:08 - 2020-10-30 13:51 - 000000000 ____D C:\Users\kubsons07\AppData\Local\babl-0.1
2021-05-05 13:06 - 2017-07-28 23:24 - 000000000 ____D C:\Users\kubsons07\AppData\Local\gtk-2.0
2021-05-05 07:40 - 2019-02-06 13:38 - 000000000 ____D C:\ProgramData\Mozilla
2021-05-05 07:39 - 2017-08-19 21:16 - 000000000 ____D C:\Users\kubsons07\AppData\Roaming\Origin
2021-05-05 07:39 - 2017-08-19 20:26 - 000000000 ____D C:\ProgramData\Origin
2021-05-05 07:39 - 2017-06-14 17:11 - 000000000 ____D C:\Users\kubsons07\AppData\LocalLow\Mozilla
2021-05-05 07:36 - 2017-08-19 21:16 - 000000000 ____D C:\Users\kubsons07\AppData\Local\Origin
2021-05-04 23:54 - 2017-09-13 17:36 - 000000000 ____D C:\Users\kubsons07\AppData\Roaming\discord
2021-05-04 20:48 - 2020-10-12 18:09 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-05-04 20:26 - 2017-08-19 20:26 - 000000000 ____D C:\Program Files (x86)\Origin
2021-05-04 17:44 - 2019-10-12 12:47 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2021-05-04 13:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-05-03 16:12 - 2018-05-15 20:19 - 000000000 ____D C:\Users\kubsons07\AppData\Local\PlaceholderTileLogoFolder
2021-05-03 15:37 - 2017-06-15 10:43 - 000000000 ____D C:\Users\kubsons07\AppData\Local\CrashDumps
2021-05-03 15:19 - 2018-01-20 23:55 - 000000000 ____D C:\Users\kubsons07\AppData\Local\Packages
2021-05-03 15:18 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-04-30 22:51 - 2020-12-21 00:44 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-04-30 19:11 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2021-04-30 14:33 - 2019-10-29 20:07 - 000000000 ____D C:\Users\kubsons07\AppData\Local\NVIDIA
2021-04-29 20:37 - 2018-05-16 17:33 - 000000000 ____D C:\Users\kubsons07\AppData\Local\D3DSCache
2021-04-29 16:34 - 2020-10-12 18:24 - 000003388 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2944253907-4126696763-4153681683-1001
2021-04-29 16:33 - 2020-10-12 18:15 - 000002430 _____ C:\Users\kubsons07\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-04-29 16:33 - 2017-06-14 17:11 - 000000000 ___RD C:\Users\kubsons07\OneDrive
2021-04-29 14:37 - 2019-06-02 11:55 - 000000000 ____D C:\Users\kubsons07\AppData\Roaming\.minecraft
2021-04-29 12:36 - 2017-06-22 20:45 - 000000000 ____D C:\Users\kubsons07\AppData\Roaming\obs-studio
2021-04-29 12:02 - 2018-01-10 20:03 - 000000000 ____D C:\Users\kubsons07\AppData\Roaming\audacity
2021-04-28 15:50 - 2021-02-26 14:35 - 000656152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2021-04-28 15:42 - 2020-10-09 21:49 - 007212248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2021-04-27 20:42 - 2019-03-13 15:03 - 000000000 ____D C:\Users\kubsons07\Desktop\My TF2 stuff
2021-04-27 12:44 - 2017-06-13 11:28 - 000002314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-04-26 07:49 - 2020-12-21 00:44 - 000003510 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-04-26 07:49 - 2020-12-21 00:44 - 000003386 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-04-24 17:27 - 2017-12-29 23:42 - 000000000 ____D C:\Program Files (x86)\Java
2021-04-24 17:27 - 2017-09-16 16:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2021-04-24 17:27 - 2017-06-25 10:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2021-04-24 17:26 - 2017-09-16 16:09 - 000191776 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2021-04-24 17:25 - 2020-05-25 02:50 - 000164640 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2021-04-24 17:25 - 2017-09-16 16:08 - 000000000 ____D C:\Program Files\Java
2021-04-24 17:14 - 2020-10-12 18:28 - 001758684 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-04-24 17:14 - 2019-12-07 17:08 - 000780534 _____ C:\WINDOWS\system32\perfh015.dat
2021-04-24 17:14 - 2019-12-07 17:08 - 000151102 _____ C:\WINDOWS\system32\perfc015.dat
2021-04-24 17:11 - 2019-12-07 11:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2021-04-24 17:07 - 2020-10-12 18:24 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-04-24 17:07 - 2020-10-12 18:09 - 000008192 ___SH C:\DumpStack.log.tmp
2021-04-24 17:06 - 2017-06-13 11:27 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-04-24 17:05 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-04-24 13:44 - 2020-11-27 20:37 - 000000000 ____D C:\Users\kubsons07\AppData\Local\Battle.net
2021-04-24 03:10 - 2020-10-09 21:49 - 000063943 _____ C:\WINDOWS\system32\nvinfo.pb
2021-04-23 23:13 - 2019-10-29 20:06 - 005667696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2021-04-23 23:13 - 2019-10-29 20:06 - 002637680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2021-04-23 23:13 - 2019-10-29 20:06 - 001758064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2021-04-23 23:13 - 2019-10-29 20:06 - 000990064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2021-04-23 23:13 - 2019-10-29 20:06 - 000120176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2021-04-23 23:13 - 2019-10-29 20:06 - 000082288 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2021-04-23 22:18 - 2021-01-03 16:56 - 000000000 ____D C:\Users\kubsons07\AppData\Local\GeometryDash
2021-04-22 10:47 - 2017-06-13 11:27 - 000001235 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-04-21 08:39 - 2020-10-15 16:26 - 000003568 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-04-21 08:39 - 2020-10-15 16:26 - 000003444 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-04-16 22:14 - 2020-10-12 18:09 - 000320520 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-04-16 22:10 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2021-04-16 22:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-04-16 22:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-04-16 22:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-04-16 22:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-04-16 22:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-04-16 22:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-04-16 22:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-04-16 22:09 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-04-16 22:09 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-04-16 22:09 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-04-16 22:09 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-04-16 13:36 - 2019-03-30 23:04 - 000000000 ____D C:\Users\kubsons07\Desktop\Launchers
2021-04-16 13:26 - 2018-04-21 11:26 - 000000000 ____D C:\Users\kubsons07\AppData\Local\Ubisoft Game Launcher
2021-04-16 11:45 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-04-16 11:34 - 2020-10-12 18:12 - 002877440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2021-04-16 09:02 - 2019-10-29 20:06 - 009536587 _____ C:\WINDOWS\system32\nvcoproc.bin
2021-04-15 23:35 - 2017-06-15 18:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-04-15 23:32 - 2017-06-15 18:39 - 131963968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-04-15 14:25 - 2019-03-30 23:03 - 000000000 ____D C:\Users\kubsons07\Desktop\Games Stuff
2021-04-15 14:24 - 2018-06-15 19:42 - 000000000 ___RD C:\Users\kubsons07\Desktop\Everything
2021-04-15 14:23 - 2020-10-18 20:43 - 000000000 ____D C:\Users\kubsons07\Desktop\passes
2021-04-15 14:23 - 2019-03-30 23:04 - 000000000 ___RD C:\Users\kubsons07\Desktop\Tools
2021-04-15 14:23 - 2019-03-30 23:04 - 000000000 ____D C:\Users\kubsons07\Desktop\Calls
2021-04-14 18:15 - 2017-06-13 11:21 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2021-04-14 18:14 - 2020-10-12 18:24 - 000004308 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-14 18:14 - 2020-10-12 18:24 - 000004106 _____ C:\WINDOWS\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-14 18:14 - 2020-10-12 18:24 - 000003976 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-14 18:14 - 2020-10-12 18:24 - 000003940 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-14 18:14 - 2020-10-12 18:24 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-14 18:14 - 2020-10-12 18:24 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-14 18:14 - 2020-10-12 18:24 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-14 18:14 - 2020-10-12 18:24 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-14 18:14 - 2017-06-13 11:21 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2021-04-14 18:14 - 2017-06-13 11:19 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2021-04-14 18:13 - 2020-10-12 18:24 - 000003894 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-14 18:13 - 2020-10-12 18:24 - 000003654 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-14 14:09 - 2020-10-19 07:38 - 000002395 _____ C:\Users\kubsons07\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2021-04-13 16:54 - 2017-06-26 20:29 - 000000000 ____D C:\Program Files\Common Files\AV
2021-04-13 16:28 - 2019-07-21 18:17 - 000000000 ____D C:\WINDOWS\system32\Drivers\NGCx64
2021-04-13 11:21 - 2021-02-26 14:35 - 000656152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\SETE230.tmp
2021-04-13 11:17 - 2020-10-09 21:49 - 007212248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\SETC207.tmp
2021-04-12 15:04 - 2017-08-06 15:01 - 000000251 _____ C:\Users\kubsons07\AppData\LocalLow\rbxcsettings.rbx
2021-04-09 16:28 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-04-08 18:02 - 2018-04-07 12:52 - 000000000 ____D C:\Users\kubsons07\AppData\Roaming\Adobe
2021-04-08 17:20 - 2017-07-23 23:28 - 000000000 ____D C:\Users\kubsons07\AppData\Local\NPE
2021-04-07 13:38 - 2019-10-29 20:07 - 002817904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2021-04-07 13:38 - 2019-10-29 20:07 - 002171760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2021-04-07 13:38 - 2019-10-29 20:07 - 001293680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvRtmpStreamer64.dll
2021-04-07 00:01 - 2020-10-12 18:15 - 000000000 ____D C:\Users\kubsons07
2021-04-06 15:02 - 2020-10-12 18:15 - 000000000 ____D C:\Users\defaultuser0
==================== Files in the root of some directories ========
2020-11-04 23:18 - 2021-01-29 16:23 - 000000015 _____ () C:\Users\kubsons07\AppData\Roaming\obs-virtualcam.txt
2020-06-05 13:14 - 2020-06-05 13:14 - 000000000 _____ () C:\Users\kubsons07\AppData\Local\oobelibMkey.log
2021-05-05 13:06 - 2021-05-05 13:06 - 000015158 _____ () C:\Users\kubsons07\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================



This topic is locked
Back to top









