Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-11-2021 Ran by kenzi (administrator) on DESKTOP-NRR6AVG (LENOVO 10SUS64X00) (07-11-2021 19:06:13) Running from C:\Users\kenzi\Desktop Loaded Profiles: kenzi : Microsoft Windows 10 Pro Version 21H1 19043.1288 (X64) Language: English (United Kingdom) Default browser: Opera Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (8bit Solutions LLC -> Bitwarden Inc.) C:\Program Files\Bitwarden\Bitwarden.exe <4> (Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe (Discord Inc. -> Discord Inc.) C:\Users\kenzi\AppData\Local\Discord\app-1.0.9003\Discord.exe <6> (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_ca344d3091c489b2\igfxCUIService.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_ca344d3091c489b2\igfxEM.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_f83b924791f3a52a\OneApp.IGCC.WinService.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_bb614eb89871cffc\IntelCpHDCPSvc.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_bb614eb89871cffc\IntelCpHeciSvc.exe (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_3e38e338bd327f33\LMS.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_614656429f721e16\RstMwService.exe (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub.exe <3> (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\21.205.1003.0005\FileCoAuth.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.microsoftstickynotes_4.1.6.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe <4> (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe <3> (ND_Apps -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Node.js Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe (OP.GG -> OP.GG) C:\Users\kenzi\AppData\Local\Programs\opgg-electron-app\OP.GG.exe <6> (Opera Software AS -> Opera Software) C:\Users\kenzi\AppData\Local\Programs\Opera GX\80.0.4170.61\opera_crashreporter.exe (Opera Software AS -> Opera Software) C:\Users\kenzi\AppData\Local\Programs\Opera GX\opera.exe <16> (Private Internet Access, Inc. -> ) C:\Program Files\Private Internet Access\pia-service.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2> (Spotify AB -> Spotify Ltd) C:\Users\kenzi\AppData\Roaming\Spotify\Spotify.exe <6> (Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7> (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe (Vincent Burel -> VB-AUDIO Software) C:\Program Files (x86)\VB\Voicemeeter\voicemeeterpro.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [1164080 2020-09-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-10-21] (Adobe Inc. -> ) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5267168 2021-10-05] (Adobe Inc. -> Adobe Systems Inc.) HKLM-x32\...\Run: [Intel Driver & Support Assistant] => C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe [288184 2021-11-02] (Intel Corporation -> Intel) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2340216 2021-11-07] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [LGHUB] => C:\Program Files\LGHUB\lghub.exe [136443968 2021-11-03] (Logitech Inc -> Logitech, Inc.) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [Discord] => C:\Users\kenzi\AppData\Local\Discord\Update.exe [1512608 2021-09-21] (Discord Inc. -> GitHub) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [electron.app.OP.GG] => C:\Users\kenzi\AppData\Local\Programs\opgg-electron-app\OP.GG.exe [126316160 2021-11-03] (OP.GG -> OP.GG) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3145912 2021-10-19] (Electronic Arts, Inc. -> Electronic Arts) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [electron.app.Bitwarden] => C:\Program Files\Bitwarden\Bitwarden.exe [136871096 2021-10-30] (8bit Solutions LLC -> Bitwarden Inc.) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4267928 2021-10-13] (Valve -> Valve Corporation) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [Speech Recognition] => C:\WINDOWS\Speech\Common\sapisvr.exe [44544 2019-12-07] (Microsoft Windows -> Microsoft Corporation) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [33526752 2021-11-05] (Epic Games Inc. -> Epic Games, Inc.) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [Spotify] => C:\Users\kenzi\AppData\Roaming\Spotify\Spotify.exe [18682808 2021-10-29] (Spotify AB -> Spotify Ltd) HKU\S-1-5-21-1266628079-2253192551-1405753121-1001\...\Run: [GoogleChromeAutoLaunch_51468CC7A89CF6F2E72B3A5E67F0C488] => C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe [2345416 2021-10-29] (Brave Software, Inc. -> Brave Software, Inc.) HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [65160 2021-10-05] (Adobe Inc. -> Adobe Systems Inc) HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files\BraveSoftware\Brave-Browser\Application\95.1.31.88\Installer\chrmstp.exe [2021-10-30] (Brave Software, Inc. -> Brave Software, Inc.) Startup: C:\Users\kenzi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Voicemeeter (VB-Audio).LNK [2021-10-16] ShortcutTarget: Voicemeeter (VB-Audio).LNK -> C:\Program Files (x86)\VB\Voicemeeter\voicemeeterpro.exe (Vincent Burel -> VB-AUDIO Software) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0B7794D1-E10A-43BA-9DB2-BFF9C697A4F8} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3075936 2021-07-21] (Intel Corporation -> Intel Corporation) Task: {0D842771-F7C0-4F50-9C66-0DC9F6C2E390} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-03] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {20AB8E4A-18F5-4FDE-8DD1-728B990AABAA} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21856112 2021-08-12] (Microsoft Corporation -> Microsoft Corporation) Task: {245FE6F4-2397-45FB-86B7-E917EB1A09BB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [7053752 2021-10-21] (Microsoft Corporation -> Microsoft Corporation) Task: {2E3C31CA-B7CE-4284-8FAD-EB39986C3012} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [139120 2021-10-21] (Microsoft Corporation -> Microsoft Corporation) Task: {4FAE4F4A-7B3F-49EC-B688-A8D764BCE1FA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-03] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {6775D868-A71F-48DB-8108-83DFD2486762} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [139120 2021-10-21] (Microsoft Corporation -> Microsoft Corporation) Task: {6912A71F-7A22-4133-B942-FA07D42767EE} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3075936 2021-07-21] (Intel Corporation -> Intel Corporation) Task: {85B3FBEB-0FC0-482A-9766-669C1E3C080B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File) Task: {91DEFA4B-91D9-4C1A-86EF-7C9A4654C4D5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21856112 2021-08-12] (Microsoft Corporation -> Microsoft Corporation) Task: {A343AA6C-9F77-484A-BB8B-FEE020E1A1CB} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162456 2021-10-16] (Brave Software, Inc. -> BraveSoftware Inc.) Task: {C5833B79-2B51-4B91-83A8-DE948994144E} - System32\Tasks\Opera GX scheduled Autoupdate 1634841160 => C:\Users\kenzi\AppData\Local\Programs\Opera GX\launcher.exe [3963600 2021-10-19] (Opera Software AS -> Opera Software) Task: {C82E49B9-AE4C-4855-9EDC-51651A6EF3D7} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [275136 2021-11-01] (Bluestack Systems, Inc -> BlueStack Systems, Inc.) Task: {CB66DD95-1049-4F39-88B0-FAD2710C2E5B} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162456 2021-10-16] (Brave Software, Inc. -> BraveSoftware Inc.) Task: {D1AEC93A-7A0C-4BEE-B7CF-F0E3EC4CA9A7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [7053752 2021-10-21] (Microsoft Corporation -> Microsoft Corporation) Task: {E72E820B-3B7F-49D7-97AE-58D23DBF2C1E} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\WINDOWS\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs" Task: {ECAEAF05-2271-473A-ADF2-6D984DFBA0FE} - System32\Tasks\Microsoft\Windows\Flighting\microsoft.windowsmediBrokerCookies => C:\WINDOWS\SysWOW64\RUNDLL32 C:\ProgramData\NotifyTrace\YtyyesHack\ayrseft_Brared.dll XM3_0ame_ocl Task: {EE7C6727-6420-4038-8F44-1F5D6FC50363} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [3978624 2021-11-07] (Microsoft Corporation -> Microsoft Corporation) Task: {F4904E6F-7DB0-4088-9C8D-A0AEA4BE47D0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-03] (Microsoft Windows Publisher -> Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4 Tcpip\..\Interfaces\{a2f9bccb-52a0-4cc1-bf2f-8fa5d118ba8a}: [DhcpNameServer] 8.8.8.8 8.8.4.4 Edge: ======= Edge Profile: C:\Users\kenzi\AppData\Local\Microsoft\Edge\User Data\Default [2021-11-07] Edge Extension: (uDocPrint) - C:\ProgramData\Klzz\Wnfwnv\5AF80890 [2021-11-01] FireFox: ======== FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2021-10-05] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-10-21] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-10-21] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2021-10-05] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] Opera: ======= StartMenuInternet: (HKU\S-1-5-21-1266628079-2253192551-1405753121-1001) Opera GXStable - "C:\Users\kenzi\AppData\Local\Programs\Opera GX\Launcher.exe" Brave: ======= BRA Profile: C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2021-11-07] BRA DefaultSearchKeyword: Default -> :g BRA Extension: (Google Translate) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2021-10-16] BRA Extension: (Safe Torrent Scanner) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2021-11-06] BRA Extension: (uBlock Origin) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2021-10-16] BRA Extension: (Easy Video Downloader) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\eaicplkoeceoelookkiaeekhodehdhde [2021-10-16] BRA Extension: (Adobe Acrobat) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2021-10-22] BRA Extension: (FrankerFaceZ) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\fadndhdgpmmaapbmfcknlfgcflmmmieb [2021-10-16] BRA Extension: (Picture-in-Picture Extension (by Google)) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\hkgfoiooedgoejojocmhlaklaeopbecg [2021-10-16] BRA Extension: (Thesaurus for Google Chrome™) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\idkamlaejpamdckefmbhknakamfgkaih [2021-10-16] BRA Extension: (Netflix Party is now Teleparty) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\oocalimimngaihdkbihfgmpkcpnmlaoa [2021-11-06] BRA Extension: (Speedtest by Ookla) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\pgjjikdiikihdfpoppgaidccahalehjh [2021-10-16] BRA Extension: (uDocPrint) - C:\ProgramData\Klzz\Wnfwnv [2021-11-01] BRA Extension: (Brave Local Data Files Updater) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2021-10-16] BRA Extension: (Brave Ad Block Updater (Default)) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2021-11-06] BRA Extension: (Brave Ads Resources) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\cmdlemldhabgmejfognbhdejendfeikd [2021-10-21] BRA Extension: (Brave SpeedReader Updater) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\jicbkmdloagakknpihibphagfckhjdih [2021-10-16] BRA Extension: (Brave NTP sponsored images) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\mjpbonbjgpinifgnneajcbigekbpfige [2021-11-06] BRA Extension: (Brave Ads Resources) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\ocilmpijebaopmdifcomolmpigakocmo [2021-10-21] BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\kenzi\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2021-11-06] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.) S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2128872 2018-05-11] (Adobe Systems Incorporated -> Adobe Systems, Incorporated) S2 AppServicea; C:\WINDOWS\system32\YU48JP100K.tmp [6144 2021-11-07] (Microsoft Corporation) [File not signed] <==== ATTENTION S2 AppServicec; C:\WINDOWS\system32\YU48JP100K.tmp [6144 2021-11-07] (Microsoft Corporation) [File not signed] <==== ATTENTION S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8901968 2021-10-29] (BattlEye Innovations e.K. -> ) S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162456 2021-10-16] (Brave Software, Inc. -> BraveSoftware Inc.) S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162456 2021-10-16] (Brave Software, Inc. -> BraveSoftware Inc.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9162144 2021-08-12] (Microsoft Corporation -> Microsoft Corporation) R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [39352 2021-11-02] (Intel Corporation -> Intel) R3 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [177080 2021-11-02] (Intel Corporation -> Intel) R2 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [9877912 2021-11-04] (Electronic Arts, Inc. -> Electronic Arts) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [818304 2021-10-29] (EasyAntiCheat Oy -> Epic Games, Inc) S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-10-29] (Epic Games Inc. -> Epic Games, Inc.) S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\21.205.1003.0005\FileSyncHelper.exe [3253120 2021-11-07] (Microsoft Corporation -> Microsoft Corporation) R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [11148864 2021-11-03] (Logitech Inc -> Logitech, Inc.) S3 LxssManagerUser; C:\WINDOWS\system32\lxss\wslclient.dll [300544 2021-10-16] (Microsoft Windows -> Microsoft Corporation) S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\21.205.1003.0005\OneDriveUpdaterService.exe [3721600 2021-11-07] (Microsoft Corporation -> Microsoft Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2557656 2021-10-19] (Electronic Arts, Inc. -> Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3476184 2021-10-19] (Electronic Arts, Inc. -> Electronic Arts) R2 PrivateInternetAccessService; C:\Program Files\Private Internet Access\pia-service.exe [1225752 2021-10-06] (Private Internet Access, Inc. -> ) S3 PrivateInternetAccessWireguard; C:\Program Files\Private Internet Access\pia-wgservice.exe [4447632 2021-10-06] (Private Internet Access, Inc. -> ) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5414976 2021-10-16] (Microsoft Windows Publisher -> Microsoft Corporation) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe [2872024 2021-11-03] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe [128376 2021-11-03] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 BlueStacksDrv_nxt; C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [320728 2021-11-01] (Bluestack Systems, Inc -> Bluestack System Inc.) S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2021-04-29] (AVB Disc Soft, SIA -> Disc Soft Ltd) R3 LBAI; C:\WINDOWS\System32\Drivers\LBAI.sys [31000 2020-08-03] (Microsoft Windows Hardware Compatibility Publisher -> Lenovo) R3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [37200 2021-10-13] (Logitech Inc -> Logitech) R3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [25928 2021-10-13] (Logitech Inc -> Logitech) R3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [66896 2021-10-13] (Logitech Inc -> Logitech) R3 MpKsle54b788d; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6977D832-10BB-47B3-8F76-54F9B013920F}\MpKslDrv.sys [130296 2021-11-07] (Microsoft Windows -> Microsoft Corporation) R3 tap-pia-0901; C:\WINDOWS\System32\drivers\tap-pia-0901.sys [39944 2021-10-06] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project) R3 VBAudioVMAUXVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmauxvaio64_win10.sys [71920 2021-10-13] (Vincent Burel -> Windows (R) Win 7 DDK provider) R3 VBAudioVMVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmvaio64_win10.sys [71712 2021-10-13] (Vincent Burel -> Windows (R) Win 7 DDK provider) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48520 2021-11-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [435424 2021-11-03] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-11-03] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2021-11-07 18:53 - 2021-11-07 18:53 - 017039360 ____N C:\WINDOWS\system32\config\SYSTEM 2021-11-07 18:53 - 2021-11-07 18:53 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\YU48JP100K.tmp 2021-11-07 18:52 - 2021-11-07 18:53 - 000003898 _____ C:\Users\kenzi\Desktop\Fixlog.txt 2021-11-07 18:11 - 2021-11-07 18:13 - 000050420 _____ C:\Users\kenzi\Desktop\Addition.txt 2021-11-07 18:08 - 2021-11-07 19:06 - 000025347 _____ C:\Users\kenzi\Desktop\FRST.txt 2021-11-07 17:24 - 2021-11-07 19:06 - 000000000 ___DC C:\FRST 2021-11-07 17:23 - 2021-11-07 17:23 - 002312192 _____ (Farbar) C:\Users\kenzi\Desktop\FRST64.exe 2021-11-07 11:44 - 2021-11-07 11:44 - 004800948 _____ C:\Users\kenzi\Downloads\ANG.T.Act2.10.joan-clarke-decoupe (2).mp4 2021-11-07 11:43 - 2021-11-07 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2021-11-07 11:43 - 2021-11-07 11:41 - 000449056 _____ (Intel Corporation) C:\WINDOWS\system32\PROUnstl.exe 2021-11-07 11:43 - 2021-11-07 11:41 - 000002291 ____N C:\WINDOWS\system32\SetupBD.din 2021-11-07 11:41 - 2021-11-07 11:42 - 004800948 _____ C:\Users\kenzi\Downloads\ANG.T.Act2.10.joan-clarke-decoupe (1).mp4 2021-11-07 11:41 - 2021-11-07 11:41 - 002269456 _____ (Intel Corporation) C:\WINDOWS\system32\PRONtObj.dll 2021-11-07 11:41 - 2021-11-07 11:41 - 000164416 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\iANSW60e.sys 2021-11-07 11:41 - 2021-11-07 11:41 - 000058304 _____ (Intel Corporation ) C:\WINDOWS\system32\Drivers\iqvw64e.sys 2021-11-07 11:40 - 2021-11-07 11:42 - 000000000 ____D C:\Users\kenzi\Downloads\intel_lan_msft_24_3 2021-11-07 11:39 - 2021-11-07 11:40 - 214585708 _____ C:\Users\kenzi\Downloads\intel_lan_msft_24_3.zip 2021-11-07 11:25 - 2021-11-07 11:25 - 000187675 _____ C:\Users\kenzi\Downloads\wake-on-lan_wake_on_lan_v1_anglais_194272.zip 2021-11-06 12:40 - 2021-11-06 12:40 - 000001435 _____ C:\WINDOWS\system32\default_error_stack-000005-000000.txt 2021-11-05 22:56 - 2021-11-07 16:43 - 000000000 ____D C:\Users\kenzi\AppData\Local\Plex 2021-11-05 22:55 - 2021-11-05 22:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex 2021-11-05 22:54 - 2021-11-05 22:55 - 122533312 _____ C:\Users\kenzi\Downloads\Plex-1.35.1.2632-c6783c78-x86_64.exe 2021-11-05 22:50 - 2021-11-05 23:24 - 000000000 ____D C:\Program Files\Plex 2021-11-05 22:50 - 2021-11-05 22:54 - 000000000 ____D C:\Users\kenzi\AppData\Local\PlexMediaPlayer 2021-11-05 22:50 - 2021-11-05 22:50 - 107182696 _____ (Plex) C:\Users\kenzi\Downloads\PlexMediaPlayer-2.58.0.1076-38e019da-windows-x64.exe 2021-11-05 19:08 - 2021-11-05 19:08 - 000000000 ____D C:\Users\kenzi\AppData\Local\DBG 2021-11-04 22:00 - 2021-11-04 22:00 - 000001517 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver & Support Assistant.lnk 2021-11-04 19:14 - 2021-11-05 15:21 - 000000000 ____D C:\ProgramData\BlueStacks_nxt 2021-11-04 19:14 - 2021-11-04 19:14 - 000006875 _____ C:\Users\kenzi\-1.14-windows.xml 2021-11-04 19:14 - 2021-11-04 19:14 - 000003936 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper_nxt 2021-11-04 19:14 - 2021-11-04 19:14 - 000002102 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5 Multi-Instance Manager.lnk 2021-11-04 19:14 - 2021-11-04 19:14 - 000001998 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk 2021-11-04 19:14 - 2021-11-04 19:14 - 000000000 ____D C:\Program Files\BlueStacks_nxt 2021-11-04 19:13 - 2021-11-04 19:13 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2021-11-04 19:13 - 2021-11-04 19:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks X 2021-11-04 19:12 - 2021-11-04 19:15 - 000000000 ____D C:\Users\kenzi\AppData\Local\BlueStacksSetup 2021-11-04 19:12 - 2021-11-04 19:14 - 000000000 ____D C:\Users\kenzi\AppData\Local\Bluestacks 2021-11-04 19:12 - 2021-11-04 19:13 - 000000000 ____D C:\Program Files (x86)\BlueStacks X 2021-11-04 19:12 - 2021-11-04 19:12 - 001070960 _____ (BlueStack Systems Inc.) C:\Users\kenzi\Downloads\BlueStacksMicroInstaller_5.3.145.1003_native_2ad276af2543421e1cf9d3ec5cef499a_0.exe 2021-11-04 19:12 - 2021-11-04 19:12 - 000000000 ____D C:\Users\Public\BlueStacks 2021-11-04 18:52 - 2021-11-04 18:52 - 000859387 _____ C:\Users\kenzi\Downloads\La.Flamme.S01.FRENCH.1080i.HDTV.H264-COLL3CTiF.torrent 2021-11-04 15:16 - 2021-11-04 15:16 - 000068020 _____ C:\Users\kenzi\Downloads\Feuille de calcul sans titre.pdf 2021-11-04 15:11 - 2021-11-04 15:14 - 000014527 _____ C:\Users\kenzi\Documents\Feuille de calcul sans titre.xlsx 2021-11-04 14:58 - 2021-11-04 15:30 - 000013806 _____ C:\Users\kenzi\Downloads\Feuille de calcul sans titre.xlsx 2021-11-03 21:53 - 2021-11-03 21:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi 2021-11-03 21:34 - 2021-11-03 21:34 - 000038727 _____ C:\Users\kenzi\Downloads\Titans.2018.S01.MULTi.1080p.NF.WEB-DL.DD5.1.x264-ARK01.torrent 2021-11-03 21:33 - 2021-11-03 21:33 - 000037348 _____ C:\Users\kenzi\Downloads\On My Block - S04.torrent 2021-11-03 21:10 - 2021-11-03 21:10 - 000001426 _____ C:\WINDOWS\system32\default_error_stack-000004-000000.txt 2021-11-03 20:43 - 2021-11-03 20:43 - 000001153 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk 2021-11-03 20:43 - 2021-11-03 20:43 - 000000000 ____D C:\Program Files\PCHealthCheck 2021-11-03 20:42 - 2021-11-07 11:24 - 000000000 ____D C:\Program Files\Microsoft OneDrive 2021-11-01 20:49 - 2021-11-01 20:49 - 001624440 _____ (Tous Les Drivers) C:\Users\kenzi\Downloads\Mes_Drivers_3.0.4.exe 2021-11-01 20:44 - 2021-11-01 20:44 - 000000000 ___HD C:\ProgramData\Klzz 2021-11-01 14:26 - 2021-11-01 14:26 - 000000000 ____D C:\Users\kenzi\Documents\VMware.Workstation.Pro.v16.2.0.Pro.X64.Incl.Keys 2021-11-01 14:23 - 2021-11-01 14:23 - 000049614 _____ C:\Users\kenzi\Downloads\VMware.Workstation.Pro.v16.2.0.Pro.X64.Incl.Keys.torrent 2021-11-01 13:27 - 2021-11-01 13:27 - 000026469 _____ C:\Users\kenzi\Downloads\Harry.Potter.A.L.Ecole.Des.Sorciers.2001.MULTI.1080p.BluRay.HDLight.AC3.x264.mkv.torrent 2021-11-01 13:26 - 2021-11-01 13:26 - 000026491 _____ C:\Users\kenzi\Downloads\Harry Potter 1 A L'Ecole Des Sorciers [1080p] MULTI 2001 Bluray X264 lorraines.mkv.torrent 2021-10-31 20:52 - 2021-11-07 18:55 - 000000000 ____D C:\Users\kenzi\AppData\Local\Discord 2021-10-31 20:52 - 2021-10-31 20:52 - 082973864 _____ (Discord Inc.) C:\Users\kenzi\Downloads\DiscordSetup.exe 2021-10-31 20:52 - 2021-10-31 20:52 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc 2021-10-31 20:40 - 2021-10-31 20:40 - 000000000 ___SH C:\Users\Public\Shared Files 2021-10-31 20:25 - 2021-10-31 21:16 - 000819799 _____ C:\Users\kenzi\Downloads\feuille heures pdf.pdf 2021-10-31 20:17 - 2021-10-31 20:17 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\EasyAntiCheat 2021-10-31 20:15 - 2021-10-31 20:18 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat 2021-10-31 20:15 - 2021-10-31 20:15 - 000000000 ____D C:\Users\kenzi\AppData\Local\FortniteGame 2021-10-31 20:15 - 2021-10-31 20:15 - 000000000 ____D C:\Users\kenzi\AppData\Local\CrashReportClient 2021-10-30 15:53 - 2021-10-30 15:53 - 000000000 ____D C:\Users\kenzi\AppData\Local\EACrashReporter 2021-10-30 15:26 - 2021-10-30 15:26 - 000000000 ____D C:\Program Files\Bitwarden 2021-10-30 15:11 - 2021-10-30 15:24 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\ZHP 2021-10-30 15:11 - 2021-10-30 15:11 - 003290264 _____ (Nicolas Coolman) C:\Users\kenzi\Downloads\ZHPCleaner.exe 2021-10-30 15:11 - 2021-10-30 15:11 - 000000000 ____D C:\Users\kenzi\AppData\Local\ZHP 2021-10-30 14:35 - 2021-10-30 14:35 - 000001425 _____ C:\WINDOWS\system32\default_error_stack-000003-000000.txt 2021-10-30 14:32 - 2021-10-30 14:32 - 000008052 _____ C:\Users\kenzi\Documents\cc_20211030_153201.reg 2021-10-30 14:32 - 2021-10-30 14:32 - 000000684 _____ C:\Users\kenzi\Documents\cc_20211030_153218.reg 2021-10-30 14:27 - 2021-10-30 14:27 - 000065624 _____ C:\Users\kenzi\Documents\cc_20211030_152733.reg 2021-10-30 14:19 - 2021-10-30 14:21 - 000000000 ____D C:\Users\kenzi\AppData\LocalLow\BitTorrent 2021-10-30 14:19 - 2021-10-30 14:20 - 000000000 ____D C:\Users\kenzi\Downloads\CCleaner Pro Portable 5.86.9258 (Windows) 2021-10-30 14:19 - 2021-10-30 14:19 - 000018278 _____ C:\Users\kenzi\Downloads\CCleaner Pro Portable 5.86.9258 (Windows).torrent 2021-10-30 14:18 - 2021-10-30 14:18 - 021498912 _____ C:\Users\kenzi\Downloads\pia-windows-x64-3.1-06756.exe 2021-10-30 14:18 - 2021-10-30 14:18 - 000001090 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Private Internet Access.lnk 2021-10-29 19:17 - 2021-10-29 19:17 - 000000663 _____ C:\Users\kenzi\Downloads\FileBot_License_P30109464.psm 2021-10-29 19:05 - 2021-10-29 19:05 - 048727747 _____ C:\Users\kenzi\Downloads\FileBot_4.9.4_x64 (2).msi 2021-10-29 19:05 - 2021-10-29 19:05 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileBot 2021-10-29 19:05 - 2021-10-29 19:05 - 000000000 ____D C:\Program Files\FileBot 2021-10-29 18:57 - 2021-10-29 18:57 - 120012957 _____ C:\Users\kenzi\Downloads\TVRename-4.4.0.exe 2021-10-29 18:54 - 2021-10-29 18:54 - 013690712 _____ (Hulubulu Software ) C:\Users\kenzi\Downloads\advanced_renamer_setup_3_88_1.exe 2021-10-29 18:54 - 2021-10-29 18:54 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Hulubulu 2021-10-29 18:52 - 2021-10-29 19:46 - 012142936 _____ C:\ProgramData\zohplghndapsm.tmp 2021-10-29 18:52 - 2021-10-29 18:52 - 000000000 ____D C:\Users\kenzi\AppData\Local\ASP.NET 2021-10-29 18:52 - 2021-10-29 18:52 - 000000000 ____D C:\ProgramData\ShokoServer 2021-10-29 18:51 - 2021-10-29 18:51 - 068929704 _____ C:\Users\kenzi\Downloads\Shoko_Server_Setup_4.1.1.zip 2021-10-29 18:51 - 2021-10-29 18:51 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\uneath 2021-10-29 18:51 - 2021-10-29 18:51 - 000000000 ____D C:\Users\kenzi\AppData\LocalLow\qU3rQ4cX4z 2021-10-29 18:51 - 2021-10-29 18:51 - 000000000 ____D C:\Users\kenzi\AppData\LocalLow\discord_files 2021-10-29 18:51 - 2021-10-29 18:51 - 000000000 ____D C:\Users\kenzi\AppData\LocalLow\bitwarden 2021-10-29 18:51 - 2021-10-29 18:51 - 000000000 ____D C:\ProgramData\Posse 2021-10-29 18:51 - 2021-10-29 18:51 - 000000000 ____D C:\Program Files (x86)\foler 2021-10-29 18:50 - 2021-10-29 19:25 - 006826592 ____N C:\WINDOWS\system32\Drivers\MYsK1Pz.sys 2021-10-29 18:50 - 2021-10-29 18:50 - 001246160 _____ (Mozilla Foundation) C:\ProgramData\nss3.dll 2021-10-29 18:50 - 2021-10-29 18:50 - 000334288 _____ (Mozilla Foundation) C:\ProgramData\freebl3.dll 2021-10-29 18:50 - 2021-10-29 18:50 - 000248832 _____ C:\ProgramData\258218.exe 2021-10-29 18:50 - 2021-10-29 18:50 - 000248832 _____ () C:\ProgramData\5159339.exe 2021-10-29 18:50 - 2021-10-29 18:50 - 000147456 _____ (sdfsdfsadea) C:\ProgramData\1839858.exe 2021-10-29 18:50 - 2021-10-29 18:50 - 000144848 _____ (Mozilla Foundation) C:\ProgramData\softokn3.dll 2021-10-29 18:50 - 2021-10-29 18:50 - 000137168 _____ (Mozilla Foundation) C:\ProgramData\mozglue.dll 2021-10-29 18:50 - 2021-10-29 18:50 - 000000000 ____D C:\Users\kenzi\AppData\Local\Yandex 2021-10-29 18:50 - 2021-10-29 18:50 - 000000000 ____D C:\Users\kenzi\AppData\Local\Calculator 2021-10-29 18:50 - 2021-10-29 18:50 - 000000000 ____D C:\ProgramData\H318VOJXNJ9XHVC4I7AGRR597 2021-10-29 18:49 - 2021-10-29 18:49 - 006115282 _____ C:\Users\kenzi\Downloads\Password_is_36266352731___Filebot-494-Cra.zip 2021-10-29 18:47 - 2021-10-29 18:47 - 048727747 _____ C:\Users\kenzi\Downloads\FileBot_4.9.4_x64 (1).msi 2021-10-29 18:43 - 2021-10-29 18:43 - 000001426 _____ C:\WINDOWS\system32\default_error_stack-000002-000000.txt 2021-10-29 18:36 - 2021-10-29 18:37 - 000000000 ____D C:\Users\kenzi\Downloads\FileBot-4.8.2-WIN[1312] 2021-10-29 18:36 - 2021-10-29 18:36 - 000014834 _____ C:\Users\kenzi\Downloads\FileBot-4.8.2-WIN[1312].torrent 2021-10-29 18:30 - 2021-10-29 18:31 - 085109732 _____ C:\Users\kenzi\Downloads\FileBot_4.8.5_x64.msi 2021-10-29 18:29 - 2021-10-29 18:29 - 000000000 ____D C:\ProgramData\Oracle 2021-10-29 18:22 - 2021-10-30 14:21 - 000000000 ____D C:\Users\kenzi\AppData\Local\BitTorrentHelper 2021-10-29 18:22 - 2021-10-29 18:22 - 000000000 ____D C:\Users\kenzi\Downloads\FileBot_4.8.0_x86-64 2021-10-29 18:21 - 2021-10-30 14:24 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\BitTorrent 2021-10-29 18:21 - 2021-10-29 18:21 - 000000903 _____ C:\Users\kenzi\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk 2021-10-29 18:21 - 2021-10-29 18:21 - 000000000 ____D C:\WINDOWS\system32\appmgmt 2021-10-29 18:21 - 2021-10-29 18:21 - 000000000 ____D C:\Users\kenzi\AppData\Local\Adaware 2021-10-29 18:20 - 2021-10-29 18:20 - 005079720 _____ (BitTorrent Inc.) C:\Users\kenzi\Downloads\BitTorrent.exe 2021-10-29 18:19 - 2021-10-29 18:19 - 000055915 _____ C:\Users\kenzi\Downloads\FileBot_4.8.0_x86-64.torrent 2021-10-29 18:13 - 2021-10-29 19:19 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\FileBot 2021-10-29 17:50 - 2021-10-29 17:51 - 048727747 _____ C:\Users\kenzi\Downloads\FileBot_4.9.4_x64.msi 2021-10-29 14:27 - 2021-11-04 18:30 - 000000000 ____D C:\Program Files\Epic Games 2021-10-29 14:25 - 2021-10-29 14:25 - 000000000 ____D C:\Users\kenzi\AppData\Local\EOSUserHelper 2021-10-29 14:23 - 2021-10-31 20:16 - 000000000 ____D C:\Users\kenzi\AppData\Local\NVIDIA Corporation 2021-10-29 14:19 - 2021-10-31 20:15 - 000000000 ____D C:\Users\kenzi\AppData\Local\UnrealEngine 2021-10-29 14:19 - 2021-10-29 14:23 - 000000000 ____D C:\ProgramData\Epic 2021-10-29 14:19 - 2021-10-29 14:19 - 000001270 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk 2021-10-29 14:19 - 2021-10-29 14:19 - 000000000 ____D C:\Users\kenzi\AppData\Local\UnrealEngineLauncher 2021-10-29 14:19 - 2021-10-29 14:19 - 000000000 ____D C:\Users\kenzi\AppData\Local\EpicGamesLauncher 2021-10-29 14:19 - 2021-10-29 14:19 - 000000000 ____D C:\Users\kenzi\AppData\Local\Epic Games 2021-10-29 14:19 - 2021-10-29 14:19 - 000000000 ____D C:\Program Files (x86)\Epic Games 2021-10-29 14:16 - 2021-10-29 14:16 - 000000000 ____D C:\Users\kenzi\Downloads\Hama.bundle-master 2021-10-29 14:15 - 2021-10-29 14:15 - 000319642 _____ C:\Users\kenzi\Downloads\Hama.bundle-master.zip 2021-10-29 13:46 - 2021-10-29 13:46 - 157548544 _____ C:\Users\kenzi\Downloads\EpicInstaller-13.0.0.msi 2021-10-25 21:07 - 2021-10-25 21:07 - 000132060 _____ C:\Users\kenzi\Documents\Apple – Assistance – Confirmation.pdf 2021-10-23 13:37 - 2021-10-23 13:37 - 000001434 _____ C:\WINDOWS\system32\default_error_stack-000001-000000.txt 2021-10-23 11:51 - 2021-10-23 11:51 - 000001356 _____ C:\Users\kenzi\Documents\caca.reg 2021-10-23 11:47 - 2021-10-23 11:47 - 000826712 _____ C:\Users\kenzi\Downloads\AD5.odt 2021-10-22 17:17 - 2021-10-22 17:17 - 000000000 ____D C:\Users\kenzi\Documents\Modèles Office personnalisés 2021-10-22 12:38 - 2021-10-22 12:38 - 000041985 _____ C:\Users\kenzi\Downloads\Methodologie - Krimi-Serie.pdf 2021-10-22 12:22 - 2021-10-22 12:22 - 000125978 _____ C:\Users\kenzi\Downloads\Hidden Figures.pdf 2021-10-22 12:21 - 2021-10-22 12:21 - 004800948 _____ C:\Users\kenzi\Downloads\ANG.T.Act2.10.joan-clarke-decoupe.mp4 2021-10-22 12:20 - 2021-10-22 12:20 - 008991648 _____ C:\Users\kenzi\Downloads\TheEnigmaMachine.mp4 2021-10-22 12:19 - 2021-10-22 12:19 - 000093197 _____ C:\Users\kenzi\Downloads\Showroomprive.com.html 2021-10-22 12:19 - 2021-10-22 12:19 - 000000000 ____D C:\Users\kenzi\Downloads\Showroomprive.com_files 2021-10-22 07:28 - 2021-10-22 07:28 - 001204589 _____ C:\Users\kenzi\Downloads\archive.zip 2021-10-21 20:33 - 2021-10-21 20:33 - 000000000 ____D C:\Users\kenzi\AppData\Local\Steam 2021-10-21 20:32 - 2021-11-07 18:55 - 000000000 ____D C:\Program Files (x86)\Steam 2021-10-21 20:32 - 2021-10-21 20:32 - 001770744 _____ C:\Users\kenzi\Downloads\SteamSetup.exe 2021-10-21 20:32 - 2021-10-21 20:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2021-10-21 20:15 - 2021-10-21 20:15 - 000000000 ____D C:\Users\kenzi\Documents\1427158512 2021-10-21 20:14 - 2021-10-21 20:14 - 000000000 ____D C:\Users\kenzi\Documents\843403819 2021-10-21 20:11 - 2021-10-21 20:11 - 000000000 ____D C:\Users\kenzi\Documents\843424166 2021-10-21 20:08 - 2021-10-21 20:10 - 000000000 ____D C:\Users\kenzi\Documents\1190785367 2021-10-21 20:03 - 2021-10-21 20:10 - 000000000 ____D C:\Users\kenzi\Documents\965807428 2021-10-21 19:49 - 2021-11-07 18:56 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Bitwarden 2021-10-21 19:48 - 2021-10-30 15:26 - 000001963 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitwarden.lnk 2021-10-21 19:48 - 2021-10-27 21:33 - 000000000 ____D C:\Users\kenzi\AppData\Local\bitwarden-updater 2021-10-21 19:48 - 2021-10-21 19:48 - 000711008 _____ (Bitwarden Inc.) C:\Users\kenzi\Downloads\Bitwarden-Installer-1.28.3.exe 2021-10-21 19:43 - 2021-10-21 19:48 - 000000000 ___HD C:\WINDOWS\msdownld.tmp 2021-10-21 19:41 - 2021-10-21 19:41 - 000036717 _____ C:\Users\kenzi\Documents\Brave Passwords.csv 2021-10-21 19:37 - 2021-10-21 19:49 - 000000000 ____D C:\WINDOWS\SysWOW64\directx 2021-10-21 19:35 - 2021-10-21 19:35 - 000000000 ____D C:\Users\kenzi\Documents\Wallpaper_Engine_v1.5.2_RePack_by_xetrin 2021-10-21 19:34 - 2021-10-21 19:34 - 000016270 _____ C:\Users\kenzi\Downloads\Wallpaper_Engine_v1.5.2_RePack_by_xetrin.torrent 2021-10-21 19:32 - 2021-10-21 19:32 - 003233016 _____ (Opera Software) C:\Users\kenzi\Downloads\OperaGXSetup.exe 2021-10-21 19:32 - 2021-10-21 19:32 - 000004218 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1634841160 2021-10-21 19:32 - 2021-10-21 19:32 - 000001439 _____ C:\Users\kenzi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera GX Browser .lnk 2021-10-21 19:32 - 2021-10-21 19:32 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Opera Software 2021-10-21 19:32 - 2021-10-21 19:32 - 000000000 ____D C:\Users\kenzi\AppData\Local\Opera Software 2021-10-21 18:06 - 2021-10-21 18:06 - 000598961 _____ C:\Users\kenzi\Downloads\ancien DS suite - correction.pdf 2021-10-21 18:02 - 2021-10-21 18:02 - 000084313 _____ C:\Users\kenzi\Downloads\ancien DS suite.pdf 2021-10-21 17:59 - 2021-10-31 20:26 - 000000000 ____D C:\Users\kenzi\AppData\LocalLow\Adobe 2021-10-21 17:58 - 2021-10-21 17:58 - 000000040 ___HC C:\1EC5268B6D49 2021-10-21 17:58 - 2021-10-21 17:58 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2021-10-21 17:57 - 2021-10-21 17:57 - 000002121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk 2021-10-21 17:57 - 2021-10-21 17:57 - 000002110 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk 2021-10-21 17:50 - 2021-10-21 17:50 - 000001071 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2021.lnk 2021-10-21 17:47 - 2021-10-21 17:56 - 000000000 ____D C:\Program Files (x86)\Adobe 2021-10-21 17:47 - 2021-10-21 17:50 - 000000000 ____D C:\Program Files\Common Files\Adobe 2021-10-21 17:47 - 2021-10-21 17:50 - 000000000 ____D C:\Program Files\Adobe 2021-10-21 17:46 - 2021-10-22 07:10 - 000000000 ____D C:\Users\kenzi\AppData\Local\Adobe 2021-10-21 17:46 - 2021-10-21 17:57 - 000000000 ____D C:\ProgramData\Adobe 2021-10-21 17:34 - 2021-10-21 17:34 - 000001426 _____ C:\WINDOWS\system32\default_error_stack-000000-000000.txt 2021-10-21 16:29 - 2021-10-21 16:29 - 000018432 _____ C:\WINDOWS\system32\SppExtComObjHook.dll 2021-10-21 16:28 - 2021-11-07 11:24 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task 2021-10-21 16:28 - 2021-11-07 11:24 - 000002139 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-10-21 16:28 - 2021-10-21 16:28 - 000000000 ___RD C:\Users\Default\OneDrive 2021-10-21 16:27 - 2021-10-21 16:27 - 000000000 ____D C:\Program Files\Common Files\DESIGNER 2021-10-21 16:26 - 2021-10-21 16:27 - 000000000 ____D C:\Program Files\Microsoft Office 2021-10-21 16:26 - 2021-10-21 16:26 - 000002479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk 2021-10-21 16:26 - 2021-10-21 16:26 - 000002462 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk 2021-10-21 16:26 - 2021-10-21 16:26 - 000002452 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk 2021-10-21 16:26 - 2021-10-21 16:26 - 000002452 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk 2021-10-21 16:26 - 2021-10-21 16:26 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk 2021-10-21 16:26 - 2021-10-21 16:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office 2021-10-21 16:25 - 2021-10-21 16:25 - 000000000 ____D C:\Program Files\Microsoft Office 15 2021-10-21 15:49 - 2021-11-01 14:30 - 000000128 _____ C:\Users\kenzi\AppData\Roaming\winscp.rnd 2021-10-21 15:49 - 2021-10-21 15:49 - 000001153 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk 2021-10-21 15:49 - 2021-10-21 15:49 - 000000000 ____D C:\Program Files (x86)\WinSCP 2021-10-21 13:56 - 2021-10-21 13:56 - 000000000 ____D C:\Users\kenzi\AppData\Local\EALaunchHelper 2021-10-21 11:14 - 2021-10-21 11:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskMark8 2021-10-21 11:14 - 2021-10-21 11:14 - 000000000 ____D C:\Program Files\CrystalDiskMark8 2021-10-21 11:13 - 2021-10-21 11:14 - 000000000 ____D C:\Program Files\CrystalDiskInfo 2021-10-21 11:13 - 2021-10-21 11:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo 2021-10-21 11:10 - 2021-10-21 11:10 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2021-10-20 14:58 - 2021-10-20 14:58 - 000000000 ____D C:\Program Files (x86)\Origin Games 2021-10-20 14:57 - 2021-10-21 11:11 - 000000000 ____D C:\Program Files (x86)\Origin 2021-10-20 14:57 - 2021-10-20 14:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin 2021-10-20 14:56 - 2021-10-21 11:11 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Origin 2021-10-20 14:56 - 2021-10-20 14:56 - 000000000 ____D C:\Users\kenzi\.QtWebEngineProcess 2021-10-20 14:56 - 2021-10-20 14:56 - 000000000 ____D C:\Users\kenzi\.Origin 2021-10-19 13:30 - 2021-10-30 14:18 - 000000000 ____D C:\Program Files\Private Internet Access 2021-10-19 13:30 - 2021-10-19 13:30 - 000000000 ____D C:\Users\kenzi\AppData\Local\Private Internet Access 2021-10-19 13:30 - 2021-10-06 16:39 - 000039944 _____ (The OpenVPN Project) C:\WINDOWS\system32\Drivers\tap-pia-0901.sys 2021-10-19 07:22 - 2021-11-07 19:06 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Spotify 2021-10-19 07:22 - 2021-11-07 18:58 - 000000000 ____D C:\Users\kenzi\AppData\Local\Spotify 2021-10-19 07:22 - 2021-10-19 07:22 - 000001843 _____ C:\Users\kenzi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk 2021-10-18 09:36 - 2021-10-18 09:36 - 000253643 _____ C:\Users\kenzi\Documents\NextDocument.pdf 2021-10-17 20:53 - 2021-10-17 20:53 - 000000000 ____D C:\Users\kenzi\AppData\Local\PeerDistRepub 2021-10-17 13:56 - 2021-10-17 13:56 - 000000000 ____D C:\Users\kenzi\AppData\Local\log 2021-10-17 13:54 - 2021-11-07 18:56 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\opgg-electron-app 2021-10-17 13:54 - 2021-11-07 11:44 - 000000000 ____D C:\Users\kenzi\AppData\Local\CrashDumps 2021-10-17 13:54 - 2021-10-17 13:54 - 000002318 _____ C:\Users\kenzi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OP.GG.lnk 2021-10-17 13:54 - 2021-10-17 13:54 - 000000000 ____D C:\Users\kenzi\AppData\Local\opgg-electron-app-updater 2021-10-17 08:52 - 2021-10-17 08:52 - 000000000 ____D C:\Users\kenzi\Intel 2021-10-17 08:52 - 2021-10-17 08:52 - 000000000 ____D C:\ProgramData\Intel Package Cache {1CEAC85D-2590-4760-800F-8DE5E91F3700} 2021-10-17 08:49 - 2021-10-17 08:49 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Cybelsoft 2021-10-17 08:49 - 2021-10-17 08:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriversCloud.com 2021-10-17 08:49 - 2021-10-17 08:49 - 000000000 ____D C:\ProgramData\driverscloud.com 2021-10-17 08:49 - 2021-10-17 08:49 - 000000000 ____D C:\Program Files\Cybelsoft 2021-10-17 08:46 - 2021-10-17 08:46 - 000003834 _____ C:\WINDOWS\system32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2021-10-17 08:42 - 2021-10-17 08:42 - 000000000 __HDC C:\$WinREAgent 2021-10-17 08:42 - 2021-10-17 08:42 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2021-10-17 08:40 - 2021-10-17 08:40 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-10-17 08:39 - 2021-10-17 08:39 - 000003762 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 2021-10-17 08:39 - 2021-10-17 08:39 - 000003528 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon 2021-10-17 08:39 - 2021-07-23 10:36 - 000041816 _____ C:\WINDOWS\system32\Drivers\semav6msr64.sys 2021-10-17 08:38 - 2021-11-07 11:43 - 000000000 ____D C:\Program Files\Intel 2021-10-17 08:38 - 2021-11-04 22:00 - 000000000 ____D C:\Program Files (x86)\Intel 2021-10-17 08:38 - 2021-10-17 08:38 - 000003670 _____ C:\WINDOWS\system32\Tasks\USER_ESRV_SVC_QUEENCREEK 2021-10-17 08:21 - 2021-10-17 08:21 - 000000000 ____D C:\ProgramData\HP 2021-10-16 22:58 - 2021-11-07 17:53 - 000037927 _____ C:\Users\kenzi\AppData\Roaming\VoiceMeeterBananaDefault.xml 2021-10-16 22:39 - 2021-10-16 22:39 - 000000000 ____D C:\Users\kenzi\Documents\League of Legends 2021-10-16 22:32 - 2021-11-07 16:06 - 000000000 ____D C:\ProgramData\Riot Games 2021-10-16 22:32 - 2021-10-17 13:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games 2021-10-16 22:32 - 2021-10-16 22:39 - 000000000 ____D C:\Users\kenzi\AppData\Local\Riot Games 2021-10-16 22:32 - 2021-10-16 22:32 - 000000000 ___DC C:\Riot Games 2021-10-16 22:32 - 2021-10-16 22:32 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Riot Games 2021-10-16 22:32 - 2021-10-16 22:32 - 000000000 ____D C:\Users\kenzi\AppData\Local\CEF 2021-10-16 22:10 - 2021-10-16 22:10 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Brave Apps 2021-10-16 21:45 - 2021-10-16 21:45 - 000000000 ___SD C:\WINDOWS\SysWOW64\lxss 2021-10-16 21:45 - 2021-10-16 21:45 - 000000000 ___SD C:\WINDOWS\system32\lxss 2021-10-16 21:35 - 2021-10-16 21:35 - 000000000 ____D C:\Users\kenzi\Documents\FIFA 21 2021-10-16 21:34 - 2021-10-16 21:34 - 000000000 ___HD C:\Program Files\Common Files\EAInstaller 2021-10-16 21:34 - 2021-10-16 21:34 - 000000000 ____D C:\ProgramData\Electronic Arts 2021-10-16 21:22 - 2021-10-16 21:22 - 000000000 ____D C:\Users\kenzi\AppData\Local\OneDrive 2021-10-16 21:18 - 2021-10-16 21:18 - 000000000 ____D C:\ProgramData\Apple Computer 2021-10-16 21:18 - 2021-10-16 21:18 - 000000000 ____D C:\ProgramData\Apple 2021-10-16 20:45 - 2021-11-03 21:50 - 000000000 ____D C:\WINDOWS\Panther 2021-10-16 20:45 - 2021-10-16 20:48 - 000000000 ___DC C:\Windows.old 2021-10-16 20:44 - 2021-10-16 20:44 - 000000000 ____D C:\ProgramData\ssh 2021-10-16 20:41 - 2021-10-16 20:41 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 002371072 _____ C:\WINDOWS\system32\rdpnano.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 002111488 _____ (Digimarc) C:\WINDOWS\SysWOW64\DMRCDecoder.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 001864192 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 001687040 _____ C:\WINDOWS\system32\libcrypto.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 001164288 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2021-10-16 20:41 - 2021-10-16 20:41 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000672768 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000611960 _____ C:\WINDOWS\SysWOW64\TextShaping.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr 2021-10-16 20:41 - 2021-10-16 20:41 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr 2021-10-16 20:41 - 2021-10-16 20:41 - 000480256 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000468440 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000330752 _____ C:\WINDOWS\SysWOW64\ssdm.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000266240 _____ C:\WINDOWS\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000240640 _____ C:\WINDOWS\SysWOW64\CoreMas.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000235520 _____ C:\WINDOWS\SysWOW64\HeatCore.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe 2021-10-16 20:41 - 2021-10-16 20:41 - 000203264 _____ C:\WINDOWS\system32\uwfcfgmgmt.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000170496 _____ C:\WINDOWS\system32\DeviceUpdateCenterCsp.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000158208 _____ C:\WINDOWS\system32\uwfcsp.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000138056 _____ C:\WINDOWS\system32\HvsiManagementApi.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000101704 _____ C:\WINDOWS\SysWOW64\HvsiManagementApi.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000095744 _____ C:\WINDOWS\system32\VirtualMonitorManager.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000067072 _____ C:\WINDOWS\system32\BWContextHandler.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe 2021-10-16 20:41 - 2021-10-16 20:41 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000053760 _____ C:\WINDOWS\SysWOW64\BWContextHandler.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000047472 _____ C:\WINDOWS\SysWOW64\umpdc.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000045880 _____ C:\WINDOWS\system32\HvSocket.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000040960 _____ C:\WINDOWS\system32\uwfservicingapi.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2021-10-16 20:41 - 2021-10-16 20:41 - 000011495 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2021-10-16 20:41 - 2021-10-16 20:41 - 000010752 _____ C:\WINDOWS\SysWOW64\agentactivationruntimestarter.exe 2021-10-16 20:41 - 2021-10-16 20:41 - 000001370 _____ C:\WINDOWS\system32\ThirdPartyNoticesBySHS.txt 2021-10-16 20:40 - 2021-10-16 20:40 - 004227116 _____ C:\WINDOWS\system32\DefaultHrtfs.bin 2021-10-16 20:40 - 2021-10-16 20:40 - 002295296 _____ (Digimarc) C:\WINDOWS\system32\DMRCDecoder.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 002254336 _____ C:\WINDOWS\system32\dwmscene.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000706536 _____ C:\WINDOWS\system32\TextShaping.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000657464 _____ C:\WINDOWS\system32\WindowManagementAPI.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000455168 _____ C:\WINDOWS\system32\ssdm.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000363520 _____ C:\WINDOWS\system32\Windows.Internal.UI.Shell.WindowTabManager.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000306688 _____ C:\WINDOWS\system32\HeatCore.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe 2021-10-16 20:40 - 2021-10-16 20:40 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000197632 _____ C:\WINDOWS\system32\IHDS.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000190976 _____ C:\WINDOWS\system32\BthpanContextHandler.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe 2021-10-16 20:40 - 2021-10-16 20:40 - 000152064 _____ C:\WINDOWS\system32\EoAExperiences.exe 2021-10-16 20:40 - 2021-10-16 20:40 - 000098304 _____ C:\WINDOWS\system32\Drivers\cimfs.sys 2021-10-16 20:40 - 2021-10-16 20:40 - 000089088 _____ C:\WINDOWS\system32\windows.applicationmodel.conversationalagent.proxystub.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000074240 _____ C:\WINDOWS\system32\rdsxvmaudio.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000073216 _____ C:\WINDOWS\system32\windows.applicationmodel.conversationalagent.internal.proxystub.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000064552 _____ C:\WINDOWS\system32\umpdc.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000029696 _____ (The ICU Project) C:\WINDOWS\system32\icuuc.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000025088 _____ (The ICU Project) C:\WINDOWS\system32\icuin.dll 2021-10-16 20:40 - 2021-10-16 20:40 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe 2021-10-16 20:36 - 2021-10-16 20:36 - 000000000 __RSD C:\WINDOWS\SysWOW64\WindowsDevicePortal 2021-10-16 20:36 - 2021-10-16 20:36 - 000000000 __RSD C:\WINDOWS\system32\WindowsDevicePortal 2021-10-16 20:36 - 2021-10-16 20:36 - 000000000 ___RD C:\WINDOWS\WebManagement 2021-10-16 20:34 - 2021-10-16 20:34 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2021-10-16 20:34 - 2021-10-16 20:34 - 000000000 ____D C:\Program Files\Reference Assemblies 2021-10-16 20:34 - 2021-10-16 20:34 - 000000000 ____D C:\Program Files\MSBuild 2021-10-16 20:34 - 2021-10-16 20:34 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies 2021-10-16 20:34 - 2021-10-16 20:34 - 000000000 ____D C:\Program Files (x86)\MSBuild 2021-10-16 20:32 - 2021-10-16 20:32 - 000000000 ____D C:\WINDOWS\Firmware 2021-10-16 20:31 - 2021-10-16 20:31 - 000008192 _____ C:\WINDOWS\system32\config\userdiff 2021-10-16 20:25 - 2021-10-16 20:25 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VB Audio 2021-10-16 20:25 - 2021-10-16 20:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VB Audio 2021-10-16 20:25 - 2021-10-16 20:25 - 000000000 ____D C:\Program Files\VB 2021-10-16 20:25 - 2021-10-16 20:25 - 000000000 ____D C:\Program Files (x86)\VB 2021-10-16 20:22 - 2021-11-07 19:09 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\discord 2021-10-16 20:22 - 2021-10-31 20:52 - 000000000 ____D C:\Users\kenzi\AppData\Local\SquirrelTemp 2021-10-16 20:21 - 2021-10-22 07:27 - 000000000 ____D C:\ProgramData\Origin 2021-10-16 20:19 - 2021-11-07 18:55 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\LGHUB 2021-10-16 20:19 - 2021-11-07 18:55 - 000000000 ____D C:\Users\kenzi\AppData\Local\LGHUB 2021-10-16 20:19 - 2021-11-05 22:50 - 000000000 ____D C:\Users\kenzi\AppData\Local\cache 2021-10-16 20:19 - 2021-11-05 18:44 - 000000000 ____D C:\Program Files\EA Games 2021-10-16 20:19 - 2021-11-03 21:53 - 000000000 ____D C:\Program Files\LGHUB 2021-10-16 20:19 - 2021-10-30 14:15 - 000002371 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk 2021-10-16 20:19 - 2021-10-22 07:10 - 000000000 ____D C:\Users\kenzi\AppData\Local\Origin 2021-10-16 20:19 - 2021-10-16 20:21 - 000000000 ____D C:\ProgramData\EA Desktop 2021-10-16 20:19 - 2021-10-16 20:19 - 000000000 ____D C:\Users\kenzi\AppData\Local\Electronic Arts 2021-10-16 20:19 - 2021-10-16 20:19 - 000000000 ____D C:\Users\kenzi\AppData\Local\EADesktop 2021-10-16 20:19 - 2021-10-16 20:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA 2021-10-16 20:19 - 2021-10-16 20:19 - 000000000 ____D C:\ProgramData\Logishrd 2021-10-16 20:19 - 2021-10-16 20:19 - 000000000 ____D C:\Program Files\Electronic Arts 2021-10-16 20:19 - 2021-10-16 20:19 - 000000000 ____D C:\Program Files\BraveSoftware 2021-10-16 20:18 - 2021-11-05 23:24 - 000000000 ____D C:\ProgramData\Package Cache 2021-10-16 20:18 - 2021-10-16 20:19 - 000000000 ____D C:\Users\kenzi\AppData\Local\BraveSoftware 2021-10-16 20:18 - 2021-10-16 20:19 - 000000000 ____D C:\ProgramData\LGHUB 2021-10-16 20:18 - 2021-10-16 20:18 - 000003438 _____ C:\WINDOWS\system32\Tasks\BraveSoftwareUpdateTaskMachineUA 2021-10-16 20:18 - 2021-10-16 20:18 - 000003314 _____ C:\WINDOWS\system32\Tasks\BraveSoftwareUpdateTaskMachineCore 2021-10-16 20:18 - 2021-10-16 20:18 - 000000000 ____D C:\Program Files (x86)\BraveSoftware 2021-10-16 20:13 - 2021-10-16 20:41 - 000000000 ____D C:\Users\kenzi\AppData\Local\Comms 2021-10-16 19:58 - 2021-11-03 22:15 - 000000000 ____D C:\Users\kenzi\AppData\Local\PlaceholderTileLogoFolder 2021-10-16 19:58 - 2021-10-16 19:58 - 000000000 __HDC C:\OneDriveTemp 2021-10-16 19:57 - 2021-10-22 07:10 - 000000000 ___RD C:\Users\kenzi\OneDrive 2021-10-16 19:57 - 2021-10-16 19:57 - 000000000 ____D C:\ProgramData\Microsoft OneDrive 2021-10-16 19:56 - 2021-11-07 18:58 - 001770974 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-10-16 19:56 - 2021-11-07 18:55 - 000000000 __SHD C:\Users\kenzi\IntelGraphicsProfiles 2021-10-16 19:56 - 2021-11-07 17:41 - 000000000 ____D C:\Users\kenzi\AppData\Local\Packages 2021-10-16 19:56 - 2021-10-30 14:13 - 000000000 ____D C:\Users\kenzi\AppData\Local\VirtualStore 2021-10-16 19:56 - 2021-10-29 18:46 - 000000000 ____D C:\Users\kenzi\AppData\Local\D3DSCache 2021-10-16 19:56 - 2021-10-28 22:51 - 000000000 ____D C:\ProgramData\Packages 2021-10-16 19:56 - 2021-10-21 17:59 - 000000000 ____D C:\Users\kenzi\AppData\Roaming\Adobe 2021-10-16 19:56 - 2021-10-17 08:39 - 000000000 ____D C:\Users\kenzi\AppData\Local\Intel 2021-10-16 19:56 - 2021-10-16 21:46 - 000000000 ____D C:\Users\kenzi\AppData\Local\ConnectedDevicesPlatform 2021-10-16 19:56 - 2021-10-16 21:18 - 000000000 ____D C:\Users\kenzi\AppData\Local\Publishers 2021-10-16 19:56 - 2021-10-16 19:57 - 000000000 __RHD C:\Users\Public\AccountPictures 2021-10-16 19:56 - 2021-10-16 19:56 - 000000000 ___RD C:\Users\kenzi\3D Objects 2021-10-16 19:56 - 2021-10-16 19:56 - 000000000 ____D C:\Users\kenzi\AppData\LocalLow\Intel 2021-10-16 19:53 - 2021-11-04 19:15 - 000000000 ____D C:\Users\kenzi 2021-10-16 19:53 - 2021-10-16 19:53 - 000000020 ___SH C:\Users\kenzi\ntuser.ini 2021-10-16 19:50 - 2021-10-30 14:35 - 000000000 ____D C:\ProgramData\Intel 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 SHDCL C:\Documents and Settings 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Public\Documents\Mes vidéos 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Public\Documents\Mes images 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Public\Documents\Ma musique 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Default\Voisinage réseau 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Default\Voisinage d'impression 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Default\Modèles 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Default\Mes documents 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Default\Menu Démarrer 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Default\Documents\Mes vidéos 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Default\Documents\Mes images 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Default\Documents\Ma musique 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Users\Default\AppData\Local\Historique 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\ProgramData\Modèles 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programmes 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\ProgramData\Menu Démarrer 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\ProgramData\Bureau 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 _SHDL C:\Program Files\Fichiers communs 2021-10-16 19:50 - 2021-10-16 19:50 - 000000000 ____D C:\WINDOWS\CSC 2021-10-16 19:48 - 2021-11-07 18:54 - 000008192 ___SH C:\DumpStack.log.tmp 2021-10-16 19:48 - 2021-11-07 18:54 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-10-16 19:48 - 2021-11-07 18:54 - 000000000 ___DC C:\Intel 2021-10-16 19:48 - 2021-11-07 11:22 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-10-16 19:48 - 2021-11-03 20:44 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2021-10-16 19:48 - 2021-10-28 14:53 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-10-16 19:48 - 2021-10-23 13:37 - 000324584 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-10-16 19:48 - 2021-10-23 11:53 - 000003634 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-10-16 19:48 - 2021-10-23 11:53 - 000003510 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2021-10-16 19:48 - 2021-10-16 19:48 - 000000000 ____D C:\WINDOWS\ServiceProfiles 2021-10-16 19:48 - 2021-10-16 19:48 - 000000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin 2021-10-16 19:20 - 2021-10-16 20:46 - 000000000 __HDC C:\$SysReset 2021-10-14 11:26 - 2020-09-16 23:44 - 001164080 _____ (Realtek Semiconductor) C:\WINDOWS\system32\RtkAudUService64.exe 2021-10-14 11:26 - 2020-09-16 23:44 - 001145472 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtCOM64.dll 2021-10-14 11:26 - 2020-09-16 23:44 - 000855136 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64U.dll 2021-10-14 11:26 - 2020-09-16 23:44 - 000468784 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll 2021-10-14 11:26 - 2020-09-16 23:44 - 000224280 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll 2021-10-14 11:25 - 2020-09-16 23:42 - 006150224 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys 2021-10-14 11:25 - 2020-09-16 23:30 - 042142619 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT 2021-10-13 14:53 - 2021-10-13 14:53 - 000066896 _____ (Logitech) C:\WINDOWS\system32\Drivers\logi_joy_xlcore.sys 2021-10-13 14:53 - 2021-10-13 14:53 - 000037200 _____ (Logitech) C:\WINDOWS\system32\Drivers\logi_joy_bus_enum.sys 2021-10-13 14:53 - 2021-10-13 14:53 - 000025928 _____ (Logitech) C:\WINDOWS\system32\Drivers\logi_joy_vir_hid.sys 2021-10-13 14:50 - 2021-10-13 14:50 - 000071920 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\vbaudio_vmauxvaio64_win10.sys 2021-10-13 14:50 - 2021-10-13 14:50 - 000071712 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\vbaudio_vmvaio64_win10.sys 2021-10-11 13:38 - 2021-10-11 13:38 - 000481952 _____ C:\WINDOWS\system32\libvpl.dll 2021-10-11 13:38 - 2021-10-11 13:38 - 000417312 _____ C:\WINDOWS\SysWOW64\libvpl.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 001878280 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2021-10-11 13:37 - 2021-10-11 13:37 - 001878280 _____ C:\WINDOWS\system32\vulkaninfo.exe 2021-10-11 13:37 - 2021-10-11 13:37 - 001454216 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2021-10-11 13:37 - 2021-10-11 13:37 - 001454216 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2021-10-11 13:37 - 2021-10-11 13:37 - 001107056 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 001107056 _____ C:\WINDOWS\system32\vulkan-1.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 000960616 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 000960616 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 000942416 _____ (Intel Corporation) C:\WINDOWS\system32\libmfxhw64.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 000703232 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\libmfxhw32.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 000450448 _____ C:\WINDOWS\system32\ze_tracing_layer.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 000369560 _____ C:\WINDOWS\system32\ze_loader.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 000140176 _____ C:\WINDOWS\system32\ze_validation_layer.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 000039032 _____ (Intel Corporation) C:\WINDOWS\system32\intel_gfx_api-x64.dll 2021-10-11 13:37 - 2021-10-11 13:37 - 000036400 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\intel_gfx_api-x86.dll 2021-10-11 13:36 - 2021-10-11 13:36 - 027888016 _____ (Intel Corporation) C:\WINDOWS\system32\mfxplugin64_hw.dll 2021-10-11 13:36 - 2021-10-11 13:36 - 020630416 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\mfxplugin32_hw.dll 2021-10-11 13:36 - 2021-10-11 13:36 - 000499088 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2021-10-11 13:36 - 2021-10-11 13:36 - 000361896 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2021-10-11 13:35 - 2021-10-11 13:35 - 000424040 _____ C:\WINDOWS\system32\ControlLib.dll ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2021-11-07 18:58 - 2019-12-07 15:50 - 000794232 _____ C:\WINDOWS\system32\perfh00C.dat 2021-11-07 18:58 - 2019-12-07 15:50 - 000153556 _____ C:\WINDOWS\system32\perfc00C.dat 2021-11-07 18:58 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF 2021-11-07 18:56 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-11-07 18:54 - 2019-12-07 10:03 - 017039360 _____ C:\WINDOWS\system32\config\BCD000000 2021-11-07 18:53 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2021-11-07 17:37 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-11-07 13:12 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps 2021-11-04 23:54 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-11-01 12:03 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\NDF 2021-10-31 20:40 - 2019-12-07 10:14 - 000000000 __SHD C:\Users\Public\Libraries 2021-10-30 14:35 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy 2021-10-21 16:27 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2021-10-17 08:45 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing 2021-10-17 08:40 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender 2021-10-17 08:23 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\appcompat 2021-10-16 21:39 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2021-10-16 20:45 - 2019-12-07 10:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template 2021-10-16 20:44 - 2019-12-07 15:53 - 000000000 ___SD C:\WINDOWS\system32\AppV 2021-10-16 20:44 - 2019-12-07 15:53 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2021-10-16 20:44 - 2019-12-07 15:53 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2021-10-16 20:44 - 2019-12-07 15:53 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2021-10-16 20:44 - 2019-12-07 15:51 - 000000000 ____D C:\WINDOWS\system32\OpenSSH 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\F12 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\migwiz 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Keywords 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\DDFs 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Com 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\appraiser 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellComponents 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\IME 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\DiagTrack 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System 2021-10-16 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender 2021-10-16 20:43 - 2019-12-07 15:53 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll 2021-10-16 20:43 - 2019-12-07 15:53 - 000020908 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2021-10-16 20:36 - 2019-12-07 15:52 - 000000000 ____D C:\WINDOWS\OCR 2021-10-16 20:36 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemApps 2021-10-16 20:34 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN 2021-10-16 20:34 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\system32\WCN 2021-10-16 20:34 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI 2021-10-16 20:34 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\MUI 2021-10-16 20:33 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm 2021-10-16 20:33 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr 2021-10-16 20:33 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2021-10-16 20:33 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\system32\winrm 2021-10-16 20:33 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\system32\slmgr 2021-10-16 20:33 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2021-10-16 20:33 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\dsc 2021-10-16 20:12 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog 2021-10-16 20:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState 2021-10-16 19:56 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2021-10-16 19:53 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase 2021-10-16 19:52 - 2019-12-07 15:51 - 000000000 ____D C:\WINDOWS\system32\FxsTmp 2021-10-16 19:52 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\spool 2021-10-16 19:50 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows NT 2021-10-16 19:48 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\USOPrivate 2021-10-16 19:48 - 2019-12-07 10:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM ==================== Files in the root of some directories ======== 2021-10-29 18:50 - 2021-10-29 18:50 - 000147456 _____ (sdfsdfsadea) C:\ProgramData\1839858.exe 2021-10-29 18:50 - 2021-10-29 18:50 - 000248832 _____ () C:\ProgramData\258218.exe 2021-10-29 18:50 - 2021-10-29 18:50 - 000248832 _____ () C:\ProgramData\5159339.exe 2021-10-29 18:50 - 2021-10-29 18:50 - 000334288 _____ (Mozilla Foundation) C:\ProgramData\freebl3.dll 2021-10-29 18:50 - 2021-10-29 18:50 - 000137168 _____ (Mozilla Foundation) C:\ProgramData\mozglue.dll 2021-10-29 18:50 - 2021-10-29 18:50 - 000440120 _____ (Microsoft Corporation) C:\ProgramData\msvcp140.dll 2021-10-29 18:50 - 2021-10-29 18:50 - 001246160 _____ (Mozilla Foundation) C:\ProgramData\nss3.dll 2021-10-29 18:50 - 2021-10-29 18:50 - 000144848 _____ (Mozilla Foundation) C:\ProgramData\softokn3.dll 2021-10-29 18:50 - 2021-10-29 18:50 - 000083784 _____ (Microsoft Corporation) C:\ProgramData\vcruntime140.dll 2021-10-16 22:58 - 2021-11-07 17:53 - 000037927 _____ () C:\Users\kenzi\AppData\Roaming\VoiceMeeterBananaDefault.xml 2021-10-21 15:49 - 2021-11-01 14:30 - 000000128 _____ () C:\Users\kenzi\AppData\Roaming\winscp.rnd 2021-10-21 17:57 - 2021-10-21 17:57 - 000000410 _____ () C:\Users\kenzi\AppData\Local\oobelibMkey.log ==================== FLock ============================== 2021-11-07 18:53 C:\WINDOWS\system32\config\SYSTEM 2021-10-29 19:25 C:\WINDOWS\system32\Drivers\MYsK1Pz.sys ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================