Format du document : text/plain
Prévisualisation
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-03-2022
Ran by Leo (administrator) on DESKTOP-CHFB72S (Micro-Star International Co., Ltd. GL63 8RD) (16-03-2022 22:21:05)
Running from E:\Downloads
Loaded Profiles: Leo
Platform: Microsoft Windows 10 Home Version 21H2 19044.1288 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCopyAccelerator.exe
(C:\Users\Leo\AppData\Local\Programs\Messenger\Messenger.exe ->) (Facebook, Inc. -> ) C:\Users\Leo\AppData\Local\Programs\Messenger\CrashpadHandlerWindows.exe
(C:\Users\Leo\AppData\Local\Programs\Opera\opera.exe ->) (Opera Software AS -> Opera Software) C:\Users\Leo\AppData\Local\Programs\Opera\84.0.4316.31\opera_crashreporter.exe
(Discord Inc. -> Discord Inc.) C:\Users\Leo\AppData\Local\Discord\app-1.0.9004\Discord.exe <6>
(DriverStore\FileRepository\cui_dch.inf_amd64_8a301c120b987c01\igfxCUIService.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_8a301c120b987c01\igfxEM.exe
(explorer.exe ->) (Facebook, Inc. -> Facebook Inc.) C:\Users\Leo\AppData\Local\Programs\Messenger\Messenger.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler64.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <26>
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Opera Software AS -> Opera Software) C:\Users\Leo\AppData\Local\Programs\Opera\opera.exe <13>
(Piriform Software Ltd -> Piriform Software) C:\Program Files (x86)\CCleaner Browser\Update\1.8.1208.2\CCleanerBrowserCrashHandler.exe
(Piriform Software Ltd -> Piriform Software) C:\Program Files (x86)\CCleaner Browser\Update\1.8.1208.2\CCleanerBrowserCrashHandler64.exe
(services.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\System32\NahimicService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_8a301c120b987c01\igfxCUIService.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_523d41b353d185cf\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_233e086e960c2400\IntelCpHDCPSvc.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_233e086e960c2400\IntelCpHeciSvc.exe
(services.exe ->) (Locktime Software s.r.o. -> Locktime Software) E:\Program Files\NLSvc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmii.inf_amd64_1cacf25fc4e8a006\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_aeb956cefa859cb1\RtkAudUService64.exe <2>
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
(svchost.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\System32\NahimicSvc64.exe
(svchost.exe ->) (A-Volute SAS -> Nahimic) C:\Windows\SysWOW64\NahimicSvc32.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2202.10603.0_x64__8wekyb3d8bbwe\Cortana.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPHelper.exe
(SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_aeb956cefa859cb1\RtkAudUService64.exe [3423632 2022-01-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKU\S-1-5-21-3832259144-3547445895-3466673875-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [35646080 2022-02-14] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-3832259144-3547445895-3466673875-1001\...\Run: [Lync] => C:\Program Files\Microsoft Office\root\Office16\lync.exe [26456976 2022-03-16] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3832259144-3547445895-3466673875-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Leo\AppData\Local\Microsoft\Teams\Update.exe [2455264 2021-09-10] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3832259144-3547445895-3466673875-1001\...\Run: [Opera Browser Assistant] => C:\Users\Leo\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [4105424 2021-10-14] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-3832259144-3547445895-3466673875-1001\...\Run: [com.messenger] => "C:\Users\Leo\AppData\Local\Programs\Messenger\Messenger.exe" messenger://openAtLogin (No File)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{052EB454-9F19-CB42-7875-807F79F311C4}] -> C:\Program Files (x86)\CCleaner Browser\Application\98.1.14514.105\Installer\chrmstp.exe [2022-03-10] (Piriform Software Ltd -> Piriform Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\99.0.4844.51\Installer\chrmstp.exe [2022-03-08] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {066DC0E4-2983-4BAD-BD04-FBE250C543E9} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe [818008 2021-09-15] (Intel Corporation -> Intel(R) Corporation)
Task: {0901BEB1-AE31-44BB-8615-47A5DBE56237} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2020-03-23] (Google Inc -> Google LLC)
Task: {14FF7143-DAC7-46C8-B87F-0AD2E02ECDE6} - System32\Tasks\CCleaner Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [2760608 2022-02-23] (Piriform Software Ltd -> Piriform Software)
Task: {1833E29D-DBFE-41D9-A540-E553ADDAED36} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCmdRun.exe [979568 2022-03-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1B8665D8-1408-4FA0-B61B-AEDDA3185DDC} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1009872 2021-11-02] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {1C8A967F-8AD6-4EBC-8DBB-F7619AE6C160} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [647376 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {234807B7-455E-445C-A778-173A57803DD7} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [137072 2022-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {26C4D6C7-E065-4677-8900-4F2F257E72AD} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1656320 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {29FAACF2-A73C-4881-A36C-01C96D6B43FC} - System32\Tasks\CCleanerUpdateTaskMachineCore => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [196976 2022-03-08] (Piriform Software Ltd -> Piriform Software)
Task: {303F71F5-64F4-4B74-A534-19426AA76256} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCmdRun.exe [979568 2022-03-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {384F61D0-2918-4AAD-93C9-19F5B6B02FFA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8307120 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {4906404A-A4E2-4CC7-8AB0-7AED3926C30F} - System32\Tasks\CCleanerSkipUAC - Leo => C:\Program Files\CCleaner\CCleaner.exe [29764224 2022-02-14] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {54F15E2A-6556-4E7C-BFCC-24E99FC34BCF} - System32\Tasks\Microsoft\Windows\AppListBackup\Backup => {E0DCC2CC-3354-45F2-8914-519E07809082}
Task: {575F7612-AB9A-4F28-90B6-1B52A6946993} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1656320 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {59A6A390-82AA-4D56-9428-86BE87A4587C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339472 2022-02-03] (Nvidia Corporation -> NVIDIA Corporation)
Task: {5D8BA977-81C8-40B7-AE46-D3011B613492} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {6311DDA4-5063-47CB-A2D0-7B5626FAB41C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8307120 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {67C183B2-0FE6-4718-8FD8-94CE3ED04666} - System32\Tasks\NahimicTask32 => C:\WINDOWS\system32\..\SysWOW64\NahimicSvc32.exe [833704 2021-10-08] (A-Volute SAS -> Nahimic)
Task: {6C297225-D68C-4DBF-8EE4-9A192705A7C6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22580696 2022-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {6FB22B22-2D24-4A75-A28C-38DFE21EF29D} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {792ACD58-887B-4F0B-A469-DFBE3C257A48} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {8CF59A40-6D1D-48DA-A162-CFA253915233} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [137072 2022-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {91CE967F-37DF-4D54-94FA-D713A8E1A0FC} - System32\Tasks\CCleanerUpdateTaskMachineUA => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [196976 2022-03-08] (Piriform Software Ltd -> Piriform Software)
Task: {9969848B-686F-4A72-B4AA-3AEE08E434D2} - System32\Tasks\MATLAB R2014a Startup Accelerator => E:\Program Files\Matlab\bin\win64\MATLABStartupAccelerator.exe [42496 2014-01-29] () [File not signed]
Task: {9C1BD744-11C3-4CD0-B3E3-418A06C65180} - System32\Tasks\NahimicSvc64Run => C:\Windows\System32\NahimicSvc64.exe [1094824 2021-10-08] (A-Volute SAS -> Nahimic)
Task: {9C6C6266-D591-48C8-B686-63F6138A884D} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [59232 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {A56387EC-7E79-4A10-A51C-2CDF442E911D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCmdRun.exe [979568 2022-03-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BAE56D52-43C4-440E-A7AC-3568DF32C992} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2020-03-23] (Google Inc -> Google LLC)
Task: {C15672A5-A6AF-499E-BE20-0108102F8A64} - System32\Tasks\Opera scheduled assistant Autoupdate 1582752165 => C:\Users\Leo\AppData\Local\Programs\Opera\launcher.exe [2470608 2022-03-03] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Leo\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {C81E68ED-3FB2-4193-87A2-E6AB5138305A} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22580696 2022-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {D0C48CE4-AF5B-482A-8BE6-994D82C91CFA} - System32\Tasks\Opera scheduled Autoupdate 1555961028 => C:\Users\Leo\AppData\Local\Programs\Opera\launcher.exe [2470608 2022-03-03] (Opera Software AS -> Opera Software)
Task: {D92C3D99-5718-457A-950E-7BB9932885DD} - System32\Tasks\NahimicTask64 => C:\WINDOWS\system32\.\NahimicSvc64.exe [1094824 2021-10-08] (A-Volute SAS -> Nahimic)
Task: {E027062C-C8B7-4E25-89F7-58C184A90E66} - System32\Tasks\NahimicSvc32Run => C:\Windows\SysWOW64\NahimicSvc32.exe [833704 2021-10-08] (A-Volute SAS -> Nahimic)
Task: {E3CFF243-9510-43AF-BDF1-80224DB00E8B} - System32\Tasks\CCleaner Browser Heartbeat Task (Logon) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [2760608 2022-02-23] (Piriform Software Ltd -> Piriform Software)
Task: {EBEF3D17-55E9-48E7-836C-C27FDF77A293} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-02-14] (Piriform Software Ltd -> Piriform)
Task: {EF05C10F-682D-497D-8020-CD11B72BD881} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCmdRun.exe [979568 2022-03-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F5B112AB-AE08-45B6-90E7-AD05FD1D5910} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1656320 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
Task: {FDCB8812-5865-4BF9-9937-47750BA8351F} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1656320 2022-01-28] (Nvidia Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\Intel PTT EK Recertification.job => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe
Task: C:\WINDOWS\Tasks\MATLAB R2014a Startup Accelerator.job => E:\Program Files\Matlab\bin\win64\MATLABStartupAccelerator.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1c25c914-f648-4968-9f34-6e41723ce3d7}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{741c9884-e549-45d5-92ef-cbee8bb00d98}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\Leo\AppData\Local\Microsoft\Edge\User Data\Default [2022-03-15]
FireFox:
========
FF DefaultProfile: zc2ikfxt.default
FF DefaultProfile: tzenwuvx.default-1611743209618
FF ProfilePath: C:\Users\Leo\AppData\Roaming\Zotero\Zotero\Profiles\zc2ikfxt.default [2022-01-11]
FF ProfilePath: C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\tzenwuvx.default-1611743209618 [2022-03-16]
FF Session Restore: Mozilla\Firefox\Profiles\tzenwuvx.default-1611743209618 -> is enabled.
FF Notifications: Mozilla\Firefox\Profiles\tzenwuvx.default-1611743209618 -> hxxps://app.element.io
FF Extension: (English (US) Language Pack) - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\tzenwuvx.default-1611743209618\Extensions\langpack-en-US@firefox.mozilla.org.xpi [2022-03-13]
FF Extension: (uBlock Origin) - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\tzenwuvx.default-1611743209618\Extensions\uBlock0@raymondhill.net.xpi [2022-02-25]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=3 -> C:\Program Files (x86)\CCleaner Browser\Update\1.8.1208.2\npCCleanerBrowserUpdate3.dll [2022-03-08] (Piriform Software Ltd -> Piriform Software)
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=9 -> C:\Program Files (x86)\CCleaner Browser\Update\1.8.1208.2\npCCleanerBrowserUpdate3.dll [2022-03-08] (Piriform Software Ltd -> Piriform Software)
FF Plugin HKU\S-1-5-21-3832259144-3547445895-3466673875-1001: SkypeForBusinessPlugin-16.2 -> C:\Users\Leo\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi.dll [2019-08-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-3832259144-3547445895-3466673875-1001: SkypeForBusinessPlugin64-16.2 -> C:\Users\Leo\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi-x64.dll [2019-08-03] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR Profile: C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default [2022-03-15]
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Extension: (Slides) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-03-23]
CHR Extension: (Docs) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-03-23]
CHR Extension: (Google Drive) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-11-21]
CHR Extension: (YouTube) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-03-23]
CHR Extension: (Sheets) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-03-23]
CHR Extension: (Google Docs Offline) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-12-03]
CHR Extension: (Transpose ▲▼ pitch ▹ speed ▹ loop for videos) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioimlbgefgadofblnajllknopjboejda [2021-12-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-28]
CHR Extension: (Gmail) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-11-21]
Opera:
=======
OPR Profile: C:\Users\Leo\AppData\Roaming\Opera Software\Opera Stable [2022-03-16]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\Leo\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2022-02-24]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\Leo\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2021-09-14]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 ccleaner; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [196976 2022-03-08] (Piriform Software Ltd -> Piriform Software)
S3 CCleanerBrowserElevationService; C:\Program Files (x86)\CCleaner Browser\Application\98.1.14514.105\elevation_service.exe [1893872 2022-02-23] (Piriform Software Ltd -> Piriform Software)
S3 ccleanerm; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [196976 2022-03-08] (Piriform Software Ltd -> Piriform Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11649952 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [810928 2021-07-02] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [1874272 2021-03-29] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6840672 2021-03-29] (GOG Sp. z o.o. -> GOG.com)
R2 NahimicService; C:\WINDOWS\system32\NahimicService.exe [1888424 2021-10-08] (A-Volute SAS -> Nahimic)
R2 nlsvc; E:\Program Files\NLSvc.exe [309112 2019-10-05] (Locktime Software s.r.o. -> Locktime Software)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2202.4-0\NisSrv.exe [3046608 2022-03-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2202.4-0\MsMpEng.exe [132504 2022-03-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_1cacf25fc4e8a006\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_1cacf25fc4e8a006\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R3 MpKsl054e7845; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DF33DDBA-6AD1-4344-BCF8-368DFD46D64B}\MpKslDrv.sys [137464 2022-03-16] (Microsoft Windows -> Microsoft Corporation)
R3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [85616 2021-08-13] (A-Volute -> Windows (R) Win 7 DDK provider)
R0 nldrv; C:\WINDOWS\System32\drivers\nldrv.sys [181464 2019-10-05] (Locktime Software s.r.o. -> Locktime Software)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48552 2021-11-01] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166752 2019-07-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49600 2022-03-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [439544 2022-03-15] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [90360 2022-03-15] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-03-17 04:29 - 2022-03-16 19:35 - 000000000 ____D C:\Windows.old
2022-03-16 22:20 - 2022-03-16 22:21 - 000000000 ____D C:\FRST
2022-03-16 20:36 - 2022-03-16 20:36 - 000000000 ____D C:\Users\Leo\Intel
2022-03-16 20:36 - 2022-03-16 20:36 - 000000000 ____D C:\ProgramData\Intel Package Cache {1CEAC85D-2590-4760-800F-8DE5E91F3700}
2022-03-16 19:39 - 2022-03-16 20:22 - 000840598 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-03-16 19:37 - 2022-03-16 19:37 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2022-03-16 19:35 - 2022-03-16 19:36 - 000003112 _____ C:\WINDOWS\system32\Tasks\NahimicTask32
2022-03-16 19:35 - 2022-03-16 19:36 - 000003092 _____ C:\WINDOWS\system32\Tasks\NahimicTask64
2022-03-16 19:35 - 2022-03-16 19:35 - 000003752 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1582752165
2022-03-16 19:35 - 2022-03-16 19:35 - 000003502 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1555961028
2022-03-16 19:35 - 2022-03-16 19:35 - 000003408 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-03-16 19:35 - 2022-03-16 19:35 - 000003402 _____ C:\WINDOWS\system32\Tasks\CCleanerUpdateTaskMachineUA
2022-03-16 19:35 - 2022-03-16 19:35 - 000003398 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-03-16 19:35 - 2022-03-16 19:35 - 000003348 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2022-03-16 19:35 - 2022-03-16 19:35 - 000003220 _____ C:\WINDOWS\system32\Tasks\Intel PTT EK Recertification
2022-03-16 19:35 - 2022-03-16 19:35 - 000003216 _____ C:\WINDOWS\system32\Tasks\MATLAB R2014a Startup Accelerator
2022-03-16 19:35 - 2022-03-16 19:35 - 000003214 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d6a266f76c987f
2022-03-16 19:35 - 2022-03-16 19:35 - 000003194 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2022-03-16 19:35 - 2022-03-16 19:35 - 000003184 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2022-03-16 19:35 - 2022-03-16 19:35 - 000003178 _____ C:\WINDOWS\system32\Tasks\CCleanerUpdateTaskMachineCore
2022-03-16 19:35 - 2022-03-16 19:35 - 000003152 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-03-16 19:35 - 2022-03-16 19:35 - 000003124 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2022-03-16 19:35 - 2022-03-16 19:35 - 000003104 _____ C:\WINDOWS\system32\Tasks\CCleaner Browser Heartbeat Task (Hourly)
2022-03-16 19:35 - 2022-03-16 19:35 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3832259144-3547445895-3466673875-1001
2022-03-16 19:35 - 2022-03-16 19:35 - 000002984 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-03-16 19:35 - 2022-03-16 19:35 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-03-16 19:35 - 2022-03-16 19:35 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-03-16 19:35 - 2022-03-16 19:35 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-03-16 19:35 - 2022-03-16 19:35 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-03-16 19:35 - 2022-03-16 19:35 - 000002914 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-03-16 19:35 - 2022-03-16 19:35 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3832259144-3547445895-3466673875-1001
2022-03-16 19:35 - 2022-03-16 19:35 - 000002744 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-03-16 19:35 - 2022-03-16 19:35 - 000002622 _____ C:\WINDOWS\system32\Tasks\CCleaner Browser Heartbeat Task (Logon)
2022-03-16 19:35 - 2022-03-16 19:35 - 000002342 _____ C:\WINDOWS\system32\Tasks\NahimicSvc64Run
2022-03-16 19:35 - 2022-03-16 19:35 - 000002342 _____ C:\WINDOWS\system32\Tasks\NahimicSvc32Run
2022-03-16 19:35 - 2022-03-16 19:35 - 000002250 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Leo
2022-03-16 19:35 - 2022-03-16 19:35 - 000000020 ___SH C:\Users\Leo\ntuser.ini
2022-03-16 19:35 - 2022-03-16 19:35 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-03-16 19:35 - 2022-03-16 19:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-03-16 19:35 - 2022-03-16 19:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
2022-03-16 19:34 - 2022-03-16 19:35 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2022-03-16 19:34 - 2022-03-16 19:35 - 000007623 _____ C:\WINDOWS\diagerr.xml
2022-03-16 19:32 - 2022-03-16 19:32 - 000000368 ____H C:\WINDOWS\Tasks\Intel PTT EK Recertification.job
2022-03-16 19:30 - 2022-03-16 20:09 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-03-16 19:30 - 2022-03-16 19:30 - 000452392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-03-16 19:30 - 2022-03-16 19:30 - 000000000 ____D C:\WINDOWS\system32\lxss
2022-03-16 19:10 - 2022-03-17 04:29 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2022-03-16 19:09 - 2022-03-16 20:36 - 000000000 ____D C:\Users\Leo
2022-03-16 19:09 - 2019-12-07 10:10 - 000001105 _____ C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-03-16 19:08 - 2022-03-16 19:09 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2022-03-16 19:03 - 2022-03-16 19:03 - 000000000 ____D C:\Program Files\Reference Assemblies
2022-03-16 19:03 - 2022-03-16 19:03 - 000000000 ____D C:\Program Files\MSBuild
2022-03-16 19:03 - 2022-03-16 19:03 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2022-03-16 19:03 - 2022-03-16 19:03 - 000000000 ____D C:\Program Files (x86)\MSBuild
2022-03-16 18:58 - 2022-03-16 18:58 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2022-03-16 18:53 - 2022-03-16 19:35 - 000000258 __RSH C:\ProgramData\ntuser.pol
2022-03-16 17:53 - 2022-03-16 19:35 - 000000000 ___DC C:\WINDOWS\Panther
2022-03-16 17:49 - 2022-03-16 17:53 - 000000036 _____ C:\WINDOWS\progress.ini
2022-03-16 16:26 - 2022-03-16 19:35 - 000000000 ___HD C:\$GetCurrent
2022-03-16 16:26 - 2022-03-16 17:49 - 000000000 ____D C:\Program Files (x86)\WindowsInstallationAssistant
2022-03-15 10:31 - 2022-03-15 16:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-03-10 16:24 - 2022-03-10 16:24 - 000000000 ___HD C:\$WinREAgent
2022-03-08 16:04 - 2022-03-16 19:34 - 000002390 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner Browser.lnk
2022-03-08 16:04 - 2022-03-08 16:04 - 000000000 ____D C:\Users\Leo\AppData\Local\CCleaner Browser
2022-03-08 16:04 - 2022-03-08 16:04 - 000000000 ____D C:\ProgramData\CCleaner Browser
2022-03-08 16:02 - 2022-03-10 15:58 - 000000000 ____D C:\Program Files (x86)\CCleaner Browser
2022-03-08 15:59 - 2022-02-10 19:42 - 001905936 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2022-03-08 15:59 - 2022-02-10 19:42 - 001905936 _____ C:\WINDOWS\system32\vulkaninfo.exe
2022-03-08 15:59 - 2022-02-10 19:42 - 001478416 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2022-03-08 15:59 - 2022-02-10 19:42 - 001478416 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2022-03-08 15:59 - 2022-02-10 19:42 - 001467840 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2022-03-08 15:59 - 2022-02-10 19:42 - 001432336 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2022-03-08 15:59 - 2022-02-10 19:42 - 001432336 _____ C:\WINDOWS\system32\vulkan-1.dll
2022-03-08 15:59 - 2022-02-10 19:42 - 001209280 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2022-03-08 15:59 - 2022-02-10 19:42 - 001145616 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2022-03-08 15:59 - 2022-02-10 19:42 - 001145616 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2022-03-08 15:59 - 2022-02-10 19:39 - 000797112 _____ C:\WINDOWS\system32\nvofapi64.dll
2022-03-08 15:59 - 2022-02-10 19:39 - 000717760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2022-03-08 15:59 - 2022-02-10 19:39 - 000636032 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2022-03-08 15:59 - 2022-02-10 19:37 - 005727376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2022-03-08 15:58 - 2022-02-10 19:39 - 001531872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2022-03-08 15:58 - 2022-02-10 19:39 - 001176704 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2022-03-08 15:58 - 2022-02-10 19:38 - 002120320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2022-03-08 15:58 - 2022-02-10 19:38 - 001602728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2022-03-08 15:58 - 2022-02-10 19:38 - 000983992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2022-03-08 15:58 - 2022-02-10 19:38 - 000795584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2022-03-08 15:58 - 2022-02-10 19:38 - 000711608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2022-03-08 15:58 - 2022-02-10 19:37 - 008612496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2022-03-08 15:58 - 2022-02-10 19:37 - 007714960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2022-03-08 15:58 - 2022-02-10 19:37 - 005099152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2022-03-08 15:58 - 2022-02-10 19:37 - 002935744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2022-03-08 15:58 - 2022-02-10 19:37 - 000456848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2022-03-08 15:58 - 2022-02-10 19:35 - 000849024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2022-03-08 15:58 - 2022-02-10 19:34 - 007613344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2022-03-08 15:58 - 2022-02-10 19:34 - 006461040 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2022-03-08 15:58 - 2022-02-10 07:18 - 000089251 _____ C:\WINDOWS\system32\nvinfo.pb
2022-03-08 15:46 - 2022-03-08 15:46 - 000000000 ____D C:\Users\Leo\AppData\Roaming\sonic-visualiser
2022-03-08 15:42 - 2021-06-02 15:03 - 000067464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2022-03-08 15:29 - 2022-03-08 15:29 - 000000000 ____D C:\Users\Leo\AppData\Local\pip
2022-02-18 15:56 - 2022-02-18 15:56 - 000000805 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.10.30.lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-03-17 04:29 - 2021-08-27 10:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free PDF Compressor
2022-03-17 04:29 - 2021-05-23 16:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office
2022-03-17 04:29 - 2021-04-01 16:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Divinity - Original Sin 2 [GOG.com]
2022-03-17 04:29 - 2021-03-19 18:45 - 000000000 ____D C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2022-03-17 04:29 - 2020-12-28 22:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Divinity - Original Sin Enhanced Edition [GOG.com]
2022-03-17 04:29 - 2020-06-18 21:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MTG Arena
2022-03-17 04:29 - 2020-04-23 20:00 - 000000000 ____D C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wizards of the Coast, LLC
2022-03-17 04:29 - 2020-04-22 23:35 - 000000000 ____D C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn-Time
2022-03-17 04:29 - 2019-12-07 10:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2022-03-17 04:29 - 2019-12-07 10:14 - 000000000 __RHD C:\Users\Public\Libraries
2022-03-17 04:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2022-03-17 04:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2022-03-17 04:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\spool
2022-03-17 04:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2022-03-17 04:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-03-17 04:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-03-17 04:29 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2022-03-17 04:29 - 2019-10-09 21:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
2022-03-17 04:29 - 2019-06-30 18:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2022-03-17 04:29 - 2019-06-19 19:45 - 000000000 ____D C:\Program Files\UNP
2022-03-17 04:29 - 2019-05-27 22:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2022-03-17 04:29 - 2019-05-26 13:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2
2022-03-17 04:29 - 2018-12-15 17:34 - 000000000 ____D C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2022-03-17 04:29 - 2018-12-14 09:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Git
2022-03-17 04:29 - 2018-12-13 11:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2022-03-17 04:29 - 2018-12-13 09:23 - 000000000 ____D C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Anaconda3 (64-bit)
2022-03-17 04:29 - 2018-12-10 22:49 - 000000000 ____D C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc
2022-03-17 04:29 - 2018-12-10 22:45 - 000000000 ____D C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MiKTeX 2.9
2022-03-17 04:29 - 2018-11-19 19:03 - 000000000 ____D C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2022-03-17 04:29 - 2018-11-03 00:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ori and The Blind Forest - Definitive Edition [GOG.com]
2022-03-17 04:29 - 2018-10-20 07:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spelunky [GOG.com]
2022-03-17 04:29 - 2018-10-14 19:06 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
2022-03-17 04:29 - 2018-10-14 19:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2022-03-17 04:29 - 2018-10-14 06:21 - 000000000 ____D C:\WINDOWS\system32\A-Volute
2022-03-17 04:29 - 2018-10-14 06:20 - 000000000 ____D C:\Program Files\Intel
2022-03-17 04:29 - 2018-10-14 03:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2022-03-17 04:29 - 2018-10-14 01:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2022-03-17 04:29 - 2018-04-12 00:38 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2022-03-17 04:29 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2022-03-17 04:29 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\catroot2.old
2022-03-16 22:23 - 2018-11-19 19:03 - 000000000 ____D C:\Users\Leo\AppData\Roaming\discord
2022-03-16 22:22 - 2021-10-25 16:57 - 000000000 ____D C:\Users\Leo\AppData\Roaming\Messenger
2022-03-16 22:22 - 2021-10-25 16:57 - 000000000 ____D C:\Users\Leo\AppData\Local\Messenger
2022-03-16 22:21 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2022-03-16 22:19 - 2020-03-23 23:07 - 000000000 ____D C:\Program Files (x86)\Google
2022-03-16 22:09 - 2018-11-19 19:03 - 000000000 ____D C:\Users\Leo\AppData\Local\Discord
2022-03-16 21:59 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-03-16 19:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-03-16 19:52 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2022-03-16 19:39 - 2022-02-09 10:53 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-03-16 19:37 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-03-16 19:37 - 2019-05-27 22:21 - 000000000 ____D C:\Program Files\CCleaner
2022-03-16 19:37 - 2018-10-14 02:00 - 000000000 ____D C:\Users\Leo\AppData\LocalLow\Mozilla
2022-03-16 19:36 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-03-16 19:36 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-03-16 19:36 - 2018-10-15 10:14 - 000000000 __RHD C:\Users\Public\AccountPictures
2022-03-16 19:36 - 2018-10-15 10:14 - 000000000 ___RD C:\Users\Leo\3D Objects
2022-03-16 19:36 - 2018-10-14 03:01 - 000000000 ____D C:\ProgramData\NVIDIA
2022-03-16 19:35 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-03-16 19:35 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2022-03-16 19:35 - 2019-12-07 10:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2022-03-16 19:35 - 2018-10-14 06:20 - 000000000 __SHD C:\Users\Leo\IntelGraphicsProfiles
2022-03-16 19:32 - 2019-12-07 10:14 - 000000000 __RSD C:\WINDOWS\Media
2022-03-16 19:32 - 2018-10-14 06:19 - 000000000 ____D C:\Intel
2022-03-16 19:31 - 2020-10-14 21:12 - 000008192 ___SH C:\DumpStack.log.tmp
2022-03-16 19:31 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2022-03-16 19:30 - 2021-02-01 12:27 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2022-03-16 19:30 - 2020-06-29 18:18 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-03-16 19:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\appcompat
2022-03-16 19:17 - 2019-12-07 10:18 - 000000000 ____D C:\WINDOWS\Setup
2022-03-16 19:14 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\USOPrivate
2022-03-16 19:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Resources
2022-03-16 19:10 - 2018-12-10 22:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Texmaker
2022-03-16 19:10 - 2018-10-14 18:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2022-03-16 19:09 - 2018-10-14 00:38 - 000000000 ____D C:\Users\Leo\AppData\Local\Packages
2022-03-16 18:57 - 2018-10-14 02:04 - 000000000 ____D C:\ProgramData\Riot Games
2022-03-16 18:44 - 2018-10-14 02:23 - 000000000 ____D C:\ProgramData\Package Cache
2022-03-16 18:24 - 2018-10-14 02:06 - 000000000 ____D C:\Users\Leo\AppData\Local\D3DSCache
2022-03-16 14:15 - 2018-12-14 19:18 - 000000000 ____D C:\Program Files\Microsoft Office
2022-03-15 17:20 - 2017-08-19 21:00 - 000162024 _____ (Qualcomm Atheros, Inc.) C:\WINDOWS\system32\Drivers\L1C63x64.sys
2022-03-15 16:51 - 2018-10-14 06:22 - 000000000 ____D C:\ProgramData\A-Volute
2022-03-15 16:51 - 2018-10-14 00:42 - 000000000 ____D C:\Users\Leo\AppData\Local\PlaceholderTileLogoFolder
2022-03-15 16:51 - 2018-10-14 00:38 - 000000000 ____D C:\Users\Leo\AppData\Local\Publishers
2022-03-15 16:20 - 2018-10-14 01:38 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-03-15 12:52 - 2019-10-09 21:09 - 000000000 ____D C:\Users\Leo\AppData\Local\Riot Games
2022-03-15 12:52 - 2019-10-09 21:09 - 000000000 ____D C:\Program Files\Riot Games
2022-03-15 12:48 - 2018-10-14 01:38 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-03-15 10:27 - 2018-10-14 00:31 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-03-10 17:54 - 2018-12-13 11:12 - 000000000 ____D C:\Users\Leo\AppData\Local\cache
2022-03-10 17:54 - 2018-10-14 03:01 - 000000000 ____D C:\Users\Leo\AppData\Local\NVIDIA
2022-03-10 17:49 - 2018-10-14 00:54 - 000000000 ____D C:\ProgramData\Packages
2022-03-09 14:45 - 2020-08-22 23:22 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2022-03-09 14:43 - 2018-10-14 13:30 - 145666720 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-03-09 14:43 - 2018-10-14 13:30 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-03-08 22:49 - 2019-04-22 20:23 - 000001406 _____ C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2022-03-08 16:03 - 2018-10-16 21:26 - 000000000 ____D C:\Users\Leo\AppData\Local\CrashDumps
2022-03-08 16:01 - 2021-08-18 16:00 - 000000000 ____D C:\Users\Leo\AppData\Roaming\audacity
2022-03-08 15:42 - 2018-10-14 03:01 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2022-03-08 15:42 - 2018-10-14 02:59 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2022-03-08 15:42 - 2018-10-14 02:59 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2022-03-08 15:41 - 2019-12-14 21:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetLimiter 4
2022-03-08 15:35 - 2018-12-13 09:14 - 000000000 ____D C:\Users\Leo\Anaconda3
2022-03-08 15:12 - 2018-12-13 11:11 - 000000018 _____ C:\Users\Leo\.condarc
2022-03-08 15:12 - 2018-12-13 11:11 - 000000000 ____D C:\Users\Leo\.conda
2022-03-08 15:02 - 2018-12-13 11:12 - 000000000 ____D C:\Users\Leo\.spyder-py3
2022-02-18 15:53 - 2020-12-15 22:52 - 000000000 ____D C:\Users\Leo\AppData\Local\babl-0.1
2022-02-14 21:06 - 2020-08-22 23:22 - 000600944 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2022-02-14 21:06 - 2020-08-22 23:22 - 000482120 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
==================== Files in the root of some directories ========
2018-12-14 11:42 - 2018-12-14 11:42 - 000000337 _____ () C:\Users\Leo\AppData\Local\Perfmon.PerfmonCfg
2021-04-25 20:41 - 2021-04-25 20:41 - 000000849 _____ () C:\Users\Leo\AppData\Local\recently-used.xbel
2021-04-27 17:58 - 2021-04-27 17:58 - 000007597 _____ () C:\Users\Leo\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================