Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-01-2023 Ran by [removed] (administrator) on DESKTOP-JO1MHFN (Gigabyte Technology Co., Ltd. B560 HD3) (22-01-2023 14:42:42) Running from C:\Users\[removed]\Desktop [removed] Platform: Microsoft Windows 10 Home Version 22H2 19045.2486 (X64) Language: Polish (Poland) -> English (United Kingdom) Default browser: Opera Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (C:\Program Files (x86)\Steam\steam.exe ->) () [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\GeometryDash.exe (C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <9> (C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\GameOverlayUI.exe (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3> (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (C:\Users\danie\AppData\Local\Programs\Opera GX\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\danie\AppData\Local\Programs\Opera GX\94.0.4606.69\opera_crashreporter.exe (Discord Inc. -> Discord Inc.) C:\ProgramData\danie\Discord\app-1.0.9010\Discord.exe <6> (explorer.exe ->) (Malwarebytes Inc. -> Malwarebytes) D:\malwarebytes\mbam.exe (explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe (explorer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe <3> (explorer.exe ->) (Spotify AB -> Spotify Ltd) C:\Users\danie\AppData\Roaming\Spotify\Spotify.exe <6> (explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe (Kilonova LLC -> Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe (Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Opera Norway AS -> Opera Software) C:\Users\danie\AppData\Local\Programs\Opera GX\opera.exe <25> (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_ec6acb81b9300f24\RstMwService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe (services.exe ->) (Malwarebytes Inc. -> Malwarebytes) D:\malwarebytes\MBAMService.exe (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3> (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_ee20464bb4ac57f4\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe <2> (services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\GameBarPresenceWriter.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe [1231864 2021-02-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2022-11-01] (Adobe Inc. -> ) HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226728 2019-07-21] (Kilonova LLC -> ) HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\Run: [Spotify] => C:\Users\danie\AppData\Roaming\Spotify\Spotify.exe [20511096 2023-01-18] (Spotify AB -> Spotify Ltd) HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4246376 2022-12-15] (Valve Corp. -> Valve Corporation) HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\Run: [EpicGamesLauncher] => D:\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32754128 2022-12-12] (Epic Games Inc. -> Epic Games, Inc.) HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\Run: [Opera GX Stable] => C:\Users\danie\AppData\Local\Programs\Opera GX\launcher.exe [2542536 2023-01-14] (Opera Norway AS -> Opera Software) HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\Run: [MicrosoftEdgeAutoLaunch_E0359248083FDB44B7852C7D3585D0D2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4188616 2023-01-19] (Microsoft Corporation -> Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {07D7B982-1514-4991-8ADB-5B1BFEFEBB89} - System32\Tasks\Microsoft\Windows\DirectX\EnableFirewall => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile /v EnableFirewall /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {128D3331-A026-4BD0-9AF7-CE4B1F162AE3} - \Agent Activation Runtime\S-1-5-21-2007841477-1455595398-3338308244-1001 -> No File <==== ATTENTION Task: {16AE8BC8-DD67-4331-BC9B-4270EC59EB42} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1655336 2022-12-07] (Nvidia Corporation -> NVIDIA Corporation) Task: {19EE2924-6066-4951-AC4A-359738DBCA12} - System32\Tasks\Microsoft\Windows\DirectX\AccountProtection_MicrosoftAccount_Disconnected => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add ""HKLM\NTUSER\SOFTWARE\Microsoft\Windows Security Health\State"" /v AccountProtection_MicrosoftAccount_Disconnected /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {35C0C45E-6101-4F64-B4E9-6D736BF091CD} - System32\Tasks\Microsoft\Windows\DirectX\SecurityHealth2 => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v SecurityHealth /t REG_BINARY /d 030000000000000000000000 /f",0)(Window.Close) Task: {44F61F61-9B88-4B54-98C0-DEE6ADAA9045} - System32\Tasks\Microsoft\Windows\DirectX\EnableFirewall2 => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile /v EnableFirewall /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {49E52568-4E80-4541-9B05-74CA3D70F0D2} - System32\Tasks\Microsoft\Windows\DirectX\AppAndBrowser_StoreAppsSmartScreenOff => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add ""HKLM\SOFTWARE\Microsoft\Windows Security Health\State"" /v AppAndBrowser_StoreAppsSmartScreenOff /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {50462035-DF06-4C54-96B6-D65C1C90BDF1} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe [818008 2021-09-15] (Intel Corporation -> Intel(R) Corporation) Task: {5803E56E-7FEC-418C-9E1A-6B8702FEB714} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1655336 2022-12-07] (Nvidia Corporation -> NVIDIA Corporation) Task: {5B365335-6C4C-402E-A8CC-60C0034A9F2C} - System32\Tasks\Microsoft\Windows\DirectX\Sense => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SYSTEM\ControlSet001\Services\Sense /v Start /t REG_DWORD /d 4 /f",0)(Window.Close) Task: {5F819697-3EA0-4712-AF71-1E2DCD97D259} - System32\Tasks\Microsoft\Windows\DirectX\EnabledV9 => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\PhishingFilter /v EnabledV9 /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {6507CE44-F904-43BA-861C-6B98D4FD11A6} - System32\Tasks\Microsoft\Windows\DirectX\PreventOverride1 => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\NTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost /v PreventOverride /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {6AFABAD3-36E4-42AE-8E23-4183F5CA95AC} - System32\Tasks\Microsoft\Windows\DirectX\EnableWebContentEvaluation => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost /v EnableWebContentEvaluation /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {70A1C2CB-55E0-4780-9681-B8EE0348054B} - System32\Tasks\Microsoft\Windows\DirectX\PreventOverride3 => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SOFTWARE\Policies\Microsoft\MicrosoftEdge\PhishingFilter /v PreventOverride /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {71078021-FB30-45FC-8ADA-BAA06915F5FC} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1655336 2022-12-07] (Nvidia Corporation -> NVIDIA Corporation) Task: {7814DDFC-6557-4818-9EB1-AFDF1B7E99A8} - System32\Tasks\Opera GX scheduled Autoupdate 1667585905 => C:\Users\danie\AppData\Local\Programs\Opera GX\launcher.exe [2542536 2023-01-14] (Opera Norway AS -> Opera Software) Task: {85F4CF55-ED03-4962-AAF0-A68B794D8FB0} - System32\Tasks\Microsoft\Windows\DirectX\EnableSmartScreen => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\System /v EnableSmartScreen /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {986D1774-AAA5-49BA-94BF-0A852B73EC02} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-17] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log Task: {98BB674A-54B9-4B16-A50F-A689612AD34D} - System32\Tasks\Microsoft\Windows\DirectX\EnabledV92 => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SOFTWARE\Policies\Microsoft\MicrosoftEdge\PhishingFilter /v EnabledV9 /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {A276D535-0F26-4CBB-8EE2-26D60B344FC9} - System32\Tasks\Microsoft\Windows\DirectX\EnableFirewall3 => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile /v EnableFirewall /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {B250586E-0D3A-4EE7-887C-7AE3CD828681} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2022-12-07] (Nvidia Corporation -> NVIDIA Corporation) Task: {C7F2431E-AF30-46F3-A3BF-B2FBB88908FF} - System32\Tasks\Microsoft\Windows\DirectX\PreventOverride2 => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\PhishingFilter /v PreventOverride /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {C8EA00F3-586B-42CB-8413-78411C6A85B9} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2022-12-07] (Nvidia Corporation -> NVIDIA Corporation) Task: {CC4EA4AF-6CF0-47B0-8549-EDED6350E894} - System32\Tasks\Microsoft\Windows\DirectX\Antimalware => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SYSTEM\ControlSet001\Services\EventLog\System\Microsoft-Antimalware-ShieldProvider /v Start /t REG_DWORD /d 4 /f",0)(Window.Close) Task: {D6D382CF-942D-4F14-8BBF-C5EE769CD4B8} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1655336 2022-12-07] (Nvidia Corporation -> NVIDIA Corporation) Task: {DD4632A4-24D4-4038-847B-C4652EC7E050} - System32\Tasks\Microsoft\Windows\DirectX\EnableWebContentEvaluation2 => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\NTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost /v EnableWebContentEvaluation /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {E3C09834-3DFF-4BEE-84C3-2BDFEC331F05} - System32\Tasks\Microsoft\Windows\DirectX\WinDefend3 => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SYSTEM\ControlSet001\Services\EventLog\System\WinDefend /v Start /t REG_DWORD /d 4 /f",0)(Window.Close) Task: {EBDCB2EF-D695-4443-A06A-2E944A04A088} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2022-12-07] (Nvidia Corporation -> NVIDIA Corporation) Task: {EF0A44B6-EE94-432C-BD57-5A16FC1EAF4C} - System32\Tasks\Microsoft\Windows\DirectX\PreventOverride => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost /v PreventOverride /t REG_DWORD /d 0 /f",0)(Window.Close) Task: {F3E36714-BFBE-4021-9A37-5B3F3F99CEEE} - System32\Tasks\Microsoft\Windows\DirectX\MsSecFlt => mshta.exe vbscript:CreateObject("WScript.Shell").Run("cmd /c reg add HKLM\SYSTEM\ControlSet001\Services\MsSecFlt /v Start /t REG_DWORD /d 4 /f",0)(Window.Close) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\update-S-1-5-21-2007841477-1455595398-3338308244-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe Task: C:\WINDOWS\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.31.1 Tcpip\..\Interfaces\{1034a11e-9015-430a-a95d-4ae4ff5f0ecc}: [DhcpNameServer] 192.168.31.1 Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\danie\AppData\Local\Microsoft\Edge\User Data\Default [2023-01-17] Edge Extension: (AdBlock — best ad blocker) - C:\Users\danie\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2022-12-20] FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll [2013-09-13] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll [2013-09-13] (Microsoft Corporation -> Microsoft Corporation) Opera: ======= StartMenuInternet: (HKU\S-1-5-21-2007841477-1455595398-3338308244-1001) Opera GXStable - "C:\Users\danie\AppData\Local\Programs\Opera GX\Launcher.exe" ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [9712432 2022-12-04] (BattlEye Innovations e.K. -> ) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [813032 2022-12-04] (EasyAntiCheat Oy -> Epic Games, Inc) S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2022-07-11] (Epic Games Inc. -> Epic Games, Inc.) R2 MBAMService; D:\malwarebytes\MBAMService.exe [8891160 2023-01-20] (Malwarebytes Inc. -> Malwarebytes) S3 Rockstar Service; D:\Launcher\RockstarService.exe [2703192 2022-12-23] (Rockstar Games, Inc. -> Rockstar Games) S4 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.4-0\NisSrv.exe [3191224 2022-11-01] (Microsoft Windows Publisher -> Microsoft Corporation) S4 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.4-0\MsMpEng.exe [133536 2022-11-01] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_ee20464bb4ac57f4\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_ee20464bb4ac57f4\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 CorsairGamingAudioService; C:\Windows\System32\drivers\CorsairGamingAudio64.sys [63008 2022-11-11] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) R3 iaLPSS2_GPIO2_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_2546dafe2183e972\iaLPSS2_GPIO2_TGL.sys [131224 2022-10-31] (Intel Corporation -> Intel Corporation) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223176 2022-12-13] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2022-12-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R0 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2022-12-11] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation) R3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [48800 2022-02-23] (SteelSeries ApS -> SteelSeries ApS) S3 usbscan; C:\WINDOWS\System32\drivers\usbscan.sys [49152 2019-12-07] (Microsoft Corporation) [File not signed] S4 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49616 2022-11-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S4 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [469280 2022-11-01] (Microsoft Windows -> Microsoft Corporation) S4 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [95520 2022-11-01] (Microsoft Windows -> Microsoft Corporation) U4 MsSecFlt; no ImagePath S4 Sense; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2023-01-22 01:33 - 2023-01-22 01:33 - 006532470 _____ C:\Users\danie\Downloads\8mb.video-qKS-FAArJ4id.mp4 2023-01-20 22:41 - 2023-01-20 22:41 - 000000000 ____D C:\Users\danie\AppData\LocalLow\Straight Back Games 2023-01-20 20:28 - 2023-01-20 20:28 - 000000223 _____ C:\Users\danie\Desktop\DEVOUR.url 2023-01-17 21:33 - 2023-01-17 21:33 - 006475110 _____ C:\Users\danie\Downloads\zawodowe.pptx 2023-01-11 15:50 - 2023-01-11 15:50 - 000000000 __HDC C:\$WinREAgent 2023-01-10 22:39 - 2023-01-10 22:45 - 000000552 _____ C:\Users\danie\Desktop\albumy.txt 2023-01-06 20:47 - 2023-01-06 20:47 - 000000000 __SHD C:\Users\danie\AppData\Roaming\jun-takahashi 2023-01-06 20:47 - 2023-01-06 20:47 - 000000000 __SHD C:\Users\danie\AppData\Roaming\blue-helmets 2023-01-06 20:47 - 2023-01-06 20:47 - 000000000 ___HD C:\Users\danie\AppData\Roaming\ts-modmail 2023-01-06 20:47 - 2023-01-06 20:47 - 000000000 ___HD C:\Users\danie\AppData\Roaming\mongo-db 2023-01-06 20:47 - 2023-01-06 20:47 - 000000000 ____D C:\Users\danie\AppData\LocalLow\Northwood 2023-01-06 20:27 - 2023-01-06 20:27 - 000000000 ____D C:\Users\danie\AppData\Local\FPSChess 2023-01-05 22:45 - 2023-01-18 16:16 - 000004260 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1667585905 2023-01-04 23:08 - 2023-01-04 23:08 - 000007966 _____ C:\Users\danie\Downloads\Windows_Defender_Advanced_Threat_Protection_Service (1).reg 2023-01-04 22:36 - 2023-01-04 23:10 - 000000333 _____ C:\Users\danie\Desktop\Fixlog.txt 2023-01-04 21:53 - 2023-01-04 22:40 - 000037839 _____ C:\Users\danie\Desktop\Addition.txt 2023-01-04 21:52 - 2023-01-22 14:43 - 000020378 _____ C:\Users\danie\Desktop\FRST.txt 2023-01-04 20:50 - 2023-01-22 14:42 - 000000000 ____D C:\Users\danie\Desktop\FRST-OlderVersion 2023-01-03 21:48 - 2023-01-03 21:53 - 000000000 ____D C:\Users\danie\AppData\Local\Sysinternals 2023-01-03 21:46 - 2023-01-03 21:46 - 002226419 _____ C:\Users\danie\Downloads\TCPView.zip 2023-01-01 01:30 - 2023-01-01 01:30 - 000000000 ____D C:\Users\danie\Documents\FeedbackHub 2022-12-26 20:19 - 2022-12-26 20:19 - 019097259 _____ C:\Users\danie\Downloads\v71installer.zip 2022-12-26 20:02 - 2022-12-26 20:02 - 000000222 _____ C:\Users\danie\Desktop\Geometry Dash.url 2022-12-25 17:42 - 2022-12-25 17:42 - 044283624 _____ C:\Users\danie\Downloads\vlc-3.0.18-win64.exe 2022-12-23 23:22 - 2022-12-23 23:26 - 000000000 ____D C:\Users\danie\AppData\Local\Rockstar Games 2022-12-23 23:22 - 2022-12-23 23:22 - 000000000 ____D C:\Users\danie\Documents\Rockstar Games 2022-12-23 23:05 - 2022-12-23 23:05 - 000000481 _____ C:\Users\danie\Desktop\Rockstar Games Launcher.lnk 2022-12-23 23:05 - 2022-12-23 23:05 - 000000000 ____D C:\Users\danie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rockstar Games 2022-12-23 23:04 - 2022-12-23 23:22 - 000000000 ____D C:\Program Files\Rockstar Games 2022-12-23 23:04 - 2022-12-23 23:22 - 000000000 ____D C:\Program Files (x86)\Rockstar Games 2022-12-23 23:04 - 2022-12-23 23:05 - 000000000 ____D C:\ProgramData\Rockstar Games 2022-12-23 21:23 - 2022-12-23 21:23 - 000000332 _____ C:\Users\danie\Desktop\Grand Theft Auto V.url ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2023-01-22 14:43 - 2022-10-28 19:48 - 000000000 ____D C:\Program Files (x86)\Steam 2023-01-22 14:42 - 2022-11-03 20:03 - 000000000 ___DC C:\FRST 2023-01-22 14:42 - 2022-11-03 20:02 - 002376704 ____C (Farbar) C:\Users\danie\Desktop\FRST64.exe 2023-01-22 14:25 - 2022-10-28 17:41 - 000000000 ____D C:\Users\danie\AppData\Roaming\discord 2023-01-22 13:58 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-01-22 13:53 - 2022-10-28 20:10 - 000000000 ____D C:\Users\danie\AppData\Local\GeometryDash 2023-01-22 13:53 - 2022-10-28 14:32 - 000000000 ____D C:\ProgramData\NVIDIA 2023-01-22 13:15 - 2022-10-28 17:38 - 000000000 ____D C:\Users\danie\AppData\Local\Spotify 2023-01-22 13:14 - 2022-10-28 17:38 - 000000000 ____D C:\Users\danie\AppData\Roaming\Spotify 2023-01-22 13:14 - 2022-10-28 16:57 - 000000000 ___RD C:\Users\danie\OneDrive 2023-01-22 01:59 - 2022-10-28 14:59 - 000000000 ____D C:\Users\danie 2023-01-21 21:46 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps 2023-01-21 21:46 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-01-21 21:22 - 2022-11-05 11:53 - 000000000 ____D C:\Users\danie\AppData\Local\CrashDumps 2023-01-21 21:22 - 2022-10-31 19:11 - 000000000 ____D C:\Users\danie\AppData\Local\Septima 2023-01-21 18:50 - 2022-10-28 17:38 - 000000000 ____D C:\ProgramData\Riot Games 2023-01-21 13:45 - 2022-10-28 14:31 - 000002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-01-21 13:45 - 2022-10-28 14:31 - 000002286 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2023-01-21 00:44 - 2022-10-28 16:58 - 000000000 ____D C:\Users\danie\AppData\Local\D3DSCache 2023-01-21 00:44 - 2022-10-28 14:31 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-01-20 22:57 - 2022-11-01 21:59 - 000000000 ____D C:\Users\danie\AppData\Roaming\obs-studio 2023-01-20 21:10 - 2022-11-01 16:45 - 000000000 ___DC C:\rip awatary xd ;( 2023-01-20 20:28 - 2022-10-28 19:52 - 000000000 ____D C:\Users\danie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2023-01-20 11:24 - 2022-10-28 17:41 - 000001995 _____ C:\Users\danie\Desktop\Discord.lnk 2023-01-18 16:16 - 2022-11-04 19:18 - 000001438 _____ C:\Users\danie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Przeglądarka Opera GX.lnk 2023-01-17 16:33 - 2022-10-28 16:58 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2007841477-1455595398-3338308244-1001 2023-01-17 16:33 - 2022-10-28 16:57 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2007841477-1455595398-3338308244-1001 2023-01-17 16:33 - 2022-10-28 14:59 - 000002383 _____ C:\Users\danie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2023-01-14 11:58 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF 2023-01-13 16:55 - 2022-10-28 14:37 - 001795714 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2023-01-13 16:55 - 2019-12-07 16:08 - 000793696 _____ C:\WINDOWS\system32\perfh015.dat 2023-01-13 16:55 - 2019-12-07 16:08 - 000157522 _____ C:\WINDOWS\system32\perfc015.dat 2023-01-13 15:38 - 2022-10-28 14:31 - 000008192 ___SH C:\DumpStack.log.tmp 2023-01-13 15:38 - 2022-10-28 14:31 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2023-01-12 23:55 - 2022-10-28 14:31 - 000258584 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2023-01-12 23:55 - 2019-12-07 10:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2023-01-12 23:54 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources 2023-01-12 23:54 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2023-01-12 23:54 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\migwiz 2023-01-12 23:54 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2023-01-12 17:18 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2023-01-12 17:17 - 2022-10-28 14:34 - 003014656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2023-01-11 15:52 - 2022-10-31 13:07 - 000000000 ____D C:\WINDOWS\system32\MRT 2023-01-11 15:51 - 2022-10-31 13:07 - 150199536 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2023-01-06 21:00 - 2022-12-22 00:40 - 000000000 ____D C:\Users\danie\AppData\Roaming\SCP Secret Laboratory 2023-01-06 20:27 - 2022-12-03 19:34 - 000000000 ____D C:\Users\danie\AppData\Local\UnrealEngine 2023-01-06 20:27 - 2022-12-03 19:33 - 000000000 ____D C:\ProgramData\Epic 2023-01-04 20:38 - 2022-12-11 10:35 - 002376192 ____C (Farbar) C:\Users\danie\Downloads\FRST64 (1).exe 2023-01-01 18:16 - 2022-10-28 15:27 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2007841477-1455595398-3338308244-1002 2023-01-01 18:16 - 2022-10-28 15:27 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2007841477-1455595398-3338308244-1002 2022-12-29 17:53 - 2022-11-02 18:49 - 000000000 ____D C:\Users\danie\AppData\Roaming\DnsCache 2022-12-27 22:47 - 2022-12-10 10:55 - 000003642 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{7BAB599F-A2B7-4714-A06F-9D0865F0D792} 2022-12-27 22:47 - 2022-12-10 10:55 - 000003518 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{58995FA2-73E3-4194-A2EE-79B98E3AF415} 2022-12-26 20:27 - 2022-10-28 19:55 - 000000000 ____D C:\Users\danie\Downloads\v71installer 2022-12-26 19:59 - 2022-11-10 01:04 - 000000000 ____D C:\Users\danie\AppData\Local\ElevatedDiagnostics ==================== Files in the root of some directories ======== 2022-10-31 17:24 - 2022-10-31 17:24 - 000000017 _____ () C:\Users\danie\AppData\Local\resmon.resmoncfg 2022-11-01 17:51 - 2022-11-01 17:51 - 000000003 _____ () C:\Users\danie\AppData\Local\updater.log 2022-11-01 17:51 - 2022-11-01 17:51 - 000000424 _____ () C:\Users\danie\AppData\Local\UserProducts.xml ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================