Provjera

Provjera

offline
  • Anunnaki
  • Pridružio: 20 Apr 2012
  • Poruke: 1645

Zdravo forumasi,
Htio bih da provjerim da li ima virusa posto sistem nisam radio preko 4 godine.
Unaprijed hvala na trudu Ziveli

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-07-2022
Ran by Anunnaki (administrator) on DESKTOP-CD56IM0 (Micro-Star International Co., Ltd. MS-7B22) (05-07-2022 22:40:07)
Running from C:\Users\Anunnaki\Desktop
Loaded Profiles: Anunnaki
Platform: Microsoft Windows 10 Pro Version 21H2 19044.1766 (X64) Language: English (United States)
Default browser: Brave
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(1ncrivel Sistemas LTDA -> ) C:\Windows\System32\service.notification.center.exe
(cleanmgr.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Users\Anunnaki\AppData\Local\Temp\04E8E2DD-645B-471F-9C8D-A37724A4BCE8\DismHost.exe
(explorer.exe ->) (Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe <11>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cleanmgr.exe
(service.notification.center.exe ->) (Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\1.3.361.111\BraveCrashHandler.exe
(service.notification.center.exe ->) (Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\1.3.361.111\BraveCrashHandler64.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe
(services.exe ->) (DEVGURU Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_c52b34f1b30918c5\RstMwService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_647b4244e991951b\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_3dd75df32535321a\RtkAudUService64.exe <2>
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(svchost.exe ->) (Archiver) [File not signed] C:\Users\Anunnaki\AppData\Roaming\Archiver\Archiver.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
(svchost.exe ->) (ASUSTEK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AURA(GRAPHICS CARD)\ledcontrolservice.exe
(svchost.exe ->) (MICROLEAVES LTD -> ) C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.1737_none_7dec0d8c7ca729de\TiWorker.exe
(Zhorn Software) [File not signed] C:\Users\Anunnaki\Downloads\Tron v12.0.1 (2021-10-18)\tron\resources\stage_0_prep\caffeine\caffeine.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_3dd75df32535321a\RtkAudUService64.exe [1361000 2021-09-27] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706344 2021-09-27] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM\...\Policies\Explorer: [NoInstrumentation] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-222633774-1662573757-985405022-1001\...\Run: [ProductAuthenticationService] => C:\Users\Anunnaki\AppData\Roaming\ProductAuthenticationService\pas.exe [1004072 2019-09-20] (ResolveDevOps Limited -> ResolveDevOps Limited) <==== ATTENTION
HKU\S-1-5-21-222633774-1662573757-985405022-1001\...\Run: [Discord] => C:\Users\Anunnaki\AppData\Local\Discord\Update.exe [1522176 2022-06-08] (Discord Inc. -> GitHub)
HKU\S-1-5-21-222633774-1662573757-985405022-1001\...\RunOnce: [Application Restart #2] => C:\Windows\SysWOW64\muachost.exe [1692840 2015-08-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
HKU\S-1-5-21-222633774-1662573757-985405022-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-222633774-1662573757-985405022-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-222633774-1662573757-985405022-1001\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-222633774-1662573757-985405022-1001\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-222633774-1662573757-985405022-1001\...\Policies\Explorer: [NoInstrumentation] 1
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: c:\windows\system32\AdobePDF.dll [203936 2021-11-12] (Adobe Inc. -> Adobe Systems Inc)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files\BraveSoftware\Brave-Browser\Application\103.1.40.113\Installer\chrmstp.exe [2022-07-05] (Brave Software, Inc. -> Brave Software, Inc.)
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy-x32: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {3D043F30-9555-4687-8BFB-B7A762770B44} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-04-11] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {449A61E6-A341-40CB-A96E-63398C9E9592} - System32\Tasks\Online Application V2G6 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [199864 2017-11-02] (MICROLEAVES LTD -> ) <==== ATTENTION
Task: {55794411-1917-4FE3-8B3D-CE41779CD5F4} - System32\Tasks\AURA => C:\Program Files (x86)\ASUS\AURA(GRAPHICS CARD)\ledcontrolservice.exe [2425824 2019-12-10] (ASUSTEK COMPUTER INC. -> ASUSTek COMPUTER INC.)
Task: {5D6FD96E-3FDC-4A7B-9465-365E1537300D} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-09-09] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {5FCB89B6-A1E6-4CEE-B33C-A62E835B8D60} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpCmdRun.exe [993008 2022-06-23] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {68822F05-C699-4800-B429-78120128A012} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpCmdRun.exe [993008 2022-06-23] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7CB4C6B6-58D5-4F32-91CF-B760A557753F} - System32\Tasks\Safer-Networking\Spybot Anti-Beacon\Refresh Anti-Beacon immunization => C:\Program Files (x86)\Safer-Networking Ltd\Spybot Anti-Beacon\Spybot3AntiBeacon.exe /apply /silent /atlogon (No File)
Task: {7E7FF12A-526D-46B0-86CA-B4DE796FED65} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXvGPUDisableTask => C:\WINDOWS\System32\RemoteFXvGPUDisablement.exe Disable (No File)
Task: {80891107-50EE-47F9-A80B-7C5C723790E3} - System32\Tasks\ContentManagement => C:\Users\Anunnaki\AppData\Roaming\Archiver\Archiver.exe [275124054 2020-12-12] (Archiver) [File not signed] <==== ATTENTION
Task: {9599A741-E69F-493E-B740-C46A63E38F7D} - \NvNgxUpdateCheckDaily_{78821544-1544-1544-1544-788215441544} -> No File <==== ATTENTION
Task: {98F9F281-B841-4237-B58A-5D0FF4F5D81A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpCmdRun.exe [993008 2022-06-23] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AD0CE986-5AA9-4688-B51C-334489131329} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NoUACCheck
Task: {AE851CA5-6BDC-4763-87E3-BA676788A3C8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpCmdRun.exe [993008 2022-06-23] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B4A53F06-B1C8-4FFF-860E-24926652DB2B} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe [2178936 2021-08-19] (ASUSTeK Computer Inc. -> ASUS)
Task: {BF9BADE7-EF3B-4B9F-B5D6-68EEA37F1879} - System32\Tasks\PCIeBus => "wevtutil.exe" cl Application
Task: {C14440F0-4FF1-49A0-9EB7-A2B28011B726} - System32\Tasks\PCIeBusQueue => "wevtutil.exe" cl System
Task: {C500AEC9-54A1-428B-9F67-54A6601A7043} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {C7B9DA3F-9A91-44DF-BC30-0E30FFB18963} - System32\Tasks\PCIeBusPower => "vssadmin.exe" delete shadows /all /quiet
Task: {E0105837-0722-419D-BC6A-D7827BD1A431} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [104600 2021-08-19] (ASUSTeK Computer Inc. -> ASUS)
Task: {E550D9E3-8C9D-43FF-80F7-A1DBA6D716A9} - System32\Tasks\Notification Center => C:\ProgramData\Notification Center\service.notification.updater.exe [489992 2020-03-18] (1ncrivel Sistemas LTDA -> )
Task: {F249E847-8A22-49AA-99CC-C80CC1D921A2} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d7a501ef86945c => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-09-09] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {F2E1362D-F804-4A8C-8390-425596429AA1} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXWarningTask => C:\WINDOWS\System32\RemoteFXvGPUDisablement.exe Warning (No File)
Task: {F57C8EE7-C411-445E-B435-E65DD97674B3} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1562376 2021-08-16] (Adobe Inc. -> Adobe Inc.)
Task: {FD2434F7-2236-48D1-A258-B898F6853BF4} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-04-11] (Brave Software, Inc. -> BraveSoftware Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{0e888467-d548-4fda-a216-ef7d2bee943f}: [NameServer] 8.8.8.8,4.4.8.8
Tcpip\..\Interfaces\{0e888467-d548-4fda-a216-ef7d2bee943f}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{98681131-3e4e-4c74-83f4-16c99bede931}: [DhcpNameServer] 192.168.42.129
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION

Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]

FireFox:
========
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi => not found
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.311.2 -> C:\Program Files (x86)\Java\jre1.8.0_311\bin\dtplugin\npDeployJava1.dll [2021-10-31] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.311.2 -> C:\Program Files (x86)\Java\jre1.8.0_311\bin\plugin2\npjp2.dll [2021-10-31] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [No File]

Brave:
=======
BRA Profile: C:\Users\Anunnaki\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2022-07-05]
BRA StartupUrls: Default -> "hxxp://www.google.com/"
BRA Extension: (Return YouTube Dislike) - C:\Users\Anunnaki\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\gebbhagfogifgggkldgodflihgfeippi [2022-05-16]
BRA Extension: (FACEIT Enhancer) - C:\Users\Anunnaki\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\mokknliiomknodkdmpcellamkopbdmao [2022-07-01]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\Anunnaki\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2022-07-04]
BRA Extension: (Brave NTP background images) - C:\Users\Anunnaki\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2022-03-12]
BRA Extension: (Wallet Data Files Updater) - C:\Users\Anunnaki\AppData\Local\BraveSoftware\Brave-Browser\User Data\BraveWallet [2022-06-23]
BRA Extension: (Brave Ad Block Updater (Default)) - C:\Users\Anunnaki\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2022-07-05]
BRA Extension: (Brave NTP sponsored images) - C:\Users\Anunnaki\AppData\Local\BraveSoftware\Brave-Browser\User Data\gccbbckogglekeggclmmekihdgdpdgoe [2022-05-21]
BRA Extension: (Brave SpeedReader Updater) - C:\Users\Anunnaki\AppData\Local\BraveSoftware\Brave-Browser\User Data\jicbkmdloagakknpihibphagfckhjdih [2022-03-12]
BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\Anunnaki\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2022-07-05]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.)
S4 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.06\atkexComSvc.exe [456008 2021-08-12] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S4 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-09-09] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [181576 2021-09-30] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.)
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-09-09] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 AsusROGLSLService; C:\Program Files (x86)\ASUS\AsusROGLSLService\AsusROGLSLService.exe [591176 2021-09-09] (ASUSTeK Computer Inc. -> )
S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-04-11] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [162400 2021-04-11] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [812520 2022-03-20] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 FACEITService; C:\Program Files\FACEIT AC\faceitservice.exe [24705456 2022-07-05] (FACE IT LIMITED -> )
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2575624 2022-05-27] (Electronic Arts, Inc. -> Electronic Arts)
S4 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3494672 2022-05-27] (Electronic Arts, Inc. -> Electronic Arts)
S4 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6254368 2022-06-03] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182392 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2019-07-10] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [780328 2019-07-10] (DEVGURU Co., Ltd. -> DEVGURU Co., LTD.)
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [14585832 2022-05-11] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\NisSrv.exe [3120992 2022-06-23] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MsMpEng.exe [133544 2022-06-23] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 EpicOnlineServices; "C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe" [X]
S3 iPod Service; "C:\Program Files\iPod\bin\iPodService.exe" [X]
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_647b4244e991951b\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_647b4244e991951b\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AmdTools64; C:\WINDOWS\System32\drivers\AmdTools64.sys [63392 2020-06-16] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R1 Asusgio2; C:\WINDOWS\system32\drivers\AsIO2.sys [33832 2019-04-09] (ASUSTeK Computer Inc. -> )
R1 Asusgio3; C:\WINDOWS\system32\drivers\AsIO3.sys [43168 2021-09-30] (ASUSTeK Computer Inc. -> )
R1 CTIIO; C:\WINDOWS\system32\drivers\CtiIo64.sys [17944 2021-09-09] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_e64afe811c7e4662\e1d.sys [607400 2022-02-22] (Intel Corporation -> Intel Corporation)
S3 EasyAntiCheatSys; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys [11818584 2022-06-06] (EasyAntiCheat Oy -> EasyAntiCheat Oy)
R1 EneTechIo; C:\WINDOWS\system32\drivers\ene.sys [20992 2020-05-12] (Microsoft Windows Hardware Compatibility Publisher -> )
R1 FACEIT; C:\WINDOWS\System32\Drivers\FACEIT.sys [16146480 2022-07-05] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 gdrv2; C:\Windows\gdrv2.sys [32600 2019-07-30] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 hidusbf; C:\WINDOWS\system32\DRIVERS\hidusbf.sys [25288 2016-04-17] (Jeshua Starr Scully -> SweetLow)
S3 KMWDFILTER; C:\WINDOWS\System32\drivers\KMWDFILTER.sys [30208 2009-04-29] (MLK Technologies Limited -> Windows (R) Codename Longhorn DDK provider)
R3 MpKslbdd3a6a0; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{67B0EC7C-79A1-4AC3-B16E-253FA9FB93E5}\MpKslDrv.sys [141568 2022-07-05] (Microsoft Windows -> Microsoft Corporation)
R1 MSIO; C:\WINDOWS\system32\drivers\MsIo64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R2 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R3 phantomtap; C:\WINDOWS\System32\drivers\phantomtap.sys [50248 2020-07-06] (Avira Operations GmbH & Co. KG -> The OpenVPN Project)
S3 Revoflt; C:\WINDOWS\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
S3 SIVDriver; C:\WINDOWS\system32\Drivers\SIVX64.sys [205552 2021-02-12] (RH Software Ltd -> Ray Hinchliffe)
R3 sshid; C:\WINDOWS\system32\DRIVERS\sshid.sys [48800 2022-02-23] (SteelSeries ApS -> SteelSeries ApS)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167544 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43640 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 SteamStreamingMicrophone; C:\WINDOWS\system32\drivers\SteamStreamingMicrophone.sys [40736 2017-07-28] (Valve Corp. -> )
R3 SteamStreamingSpeakers; C:\WINDOWS\system32\drivers\SteamStreamingSpeakers.sys [40736 2017-07-21] (Valve Corp. -> )
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39920 2019-10-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [44976 2019-12-13] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 tapwindscribe0901; C:\WINDOWS\System32\drivers\tapwindscribe0901.sys [57768 2021-08-03] (Windscribe Limited -> The OpenVPN Project)
R1 ViGEmBus; C:\WINDOWS\System32\drivers\ViGEmBus.sys [165744 2020-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Nefarius Software Solutions e.U.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49576 2022-06-23] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [452856 2022-06-23] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-16] (NGO -> MBB)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [91384 2022-06-23] (Microsoft Windows -> Microsoft Corporation)
S3 windtun420; C:\WINDOWS\System32\drivers\windtun420.sys [47544 2021-08-03] (Windscribe Limited -> WireGuard LLC)
S3 WinRing0_1_2_0; \??\D:\Program Files (x86)\SimHub\OpenHardwareMonitorLib.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-07-05 22:40 - 2022-07-05 22:40 - 000025204 _____ C:\Users\Anunnaki\Desktop\FRST.txt
2022-07-05 22:39 - 2022-07-05 22:40 - 000000000 ____D C:\FRST
2022-07-05 22:39 - 2022-07-05 22:39 - 002369024 _____ (Farbar) C:\Users\Anunnaki\Desktop\FRST64.exe
2022-07-05 01:12 - 2021-02-12 19:24 - 000205552 _____ (Ray Hinchliffe) C:\WINDOWS\system32\Drivers\SIVX64.sys
2022-07-05 00:03 - 2022-07-05 00:03 - 016146480 _____ C:\WINDOWS\system32\Drivers\FACEIT.sys
2022-07-03 19:50 - 2022-07-03 19:50 - 000000000 ____D C:\Users\Anunnaki\Downloads\Tron v12.0.1 (2021-10-18)
2022-07-03 19:30 - 2022-07-03 19:49 - 476374211 _____ (Igor Pavlov) C:\Users\Anunnaki\Downloads\Tron v12.0.1 (2021-10-18).exe
2022-07-01 13:35 - 2022-07-01 13:35 - 000000073 _____ C:\Users\Anunnaki\AppData\Roaming\settings.conf
2022-07-01 13:32 - 2022-07-01 13:35 - 000001372 _____ C:\Users\Anunnaki\Desktop\SFVIP-Player-x64.lnk
2022-07-01 13:31 - 2022-07-01 13:37 - 000000000 ____D C:\Users\Anunnaki\AppData\Roaming\SFVIP-Player
2022-06-30 15:48 - 2022-06-30 16:04 - 000000000 ____D C:\Users\Anunnaki\AppData\Roaming\discord
2022-06-30 15:48 - 2022-06-30 15:50 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\Discord
2022-06-30 15:48 - 2022-06-30 15:48 - 000002242 _____ C:\Users\Anunnaki\Desktop\Discord.lnk
2022-06-21 23:52 - 2022-03-30 15:15 - 000000936 ____N C:\WINDOWS\system32\SetupBD.din
2022-06-21 21:55 - 2022-06-21 21:55 - 000000000 ____D C:\log
2022-06-21 21:53 - 2022-06-21 21:53 - 000011787 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-06-21 21:49 - 2022-06-21 21:49 - 000000000 ___HD C:\$WinREAgent
2022-06-18 16:42 - 2022-06-18 16:42 - 000000000 ____D C:\Users\Anunnaki\AppData\Roaming\NVIDIA
2022-06-18 16:41 - 2022-06-18 16:41 - 000000000 ____D C:\Users\Anunnaki\Documents\My Games
2022-06-18 16:41 - 2022-06-18 16:41 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\My Games
2022-06-18 13:55 - 2022-06-18 13:55 - 000000831 _____ C:\Users\Public\Desktop\Play Watch Dogs Legion.lnk
2022-06-17 20:24 - 2022-06-17 20:24 - 000000000 ____D C:\Users\Anunnaki\Documents\My Cheat Tables
2022-06-17 08:53 - 2022-06-17 08:53 - 000001016 _____ C:\Users\Public\Desktop\Launch BPB 22 Patch.lnk
2022-06-17 08:53 - 2022-06-17 08:53 - 000001016 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Launch BPB 22 Patch.lnk
2022-06-17 07:03 - 2022-06-23 17:31 - 000000000 ____D C:\Users\Anunnaki\Documents\KONAMI
2022-06-17 07:03 - 2022-06-23 17:31 - 000000000 ____D C:\ProgramData\KONAMI
2022-06-13 12:13 - 2022-06-13 12:13 - 000001885 _____ C:\Users\Anunnaki\Desktop\FirstBackup.spg
2022-06-13 11:30 - 2022-06-13 11:30 - 000684032 _____ (Speed Guide Inc.) C:\Users\Anunnaki\Desktop\TCPOptimizer.exe
2022-06-13 11:30 - 2022-06-13 11:30 - 000002734 _____ C:\Users\Anunnaki\Desktop\low ping.bat
2022-06-09 20:09 - 2022-06-09 20:09 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\NVIDIA Corporation
2022-06-09 12:48 - 2022-06-09 12:48 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\Steam
2022-06-09 12:41 - 2022-07-05 01:13 - 000000000 ____D C:\Program Files (x86)\Steam
2022-06-09 12:41 - 2022-06-30 01:19 - 000001032 _____ C:\Users\Public\Desktop\Steam.lnk
2022-06-09 12:41 - 2022-06-09 12:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2022-06-09 12:02 - 2022-06-09 12:09 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\NVIDIA
2022-06-09 04:34 - 2022-07-05 21:51 - 000000000 ____D C:\ProgramData\NVIDIA
2022-06-09 04:34 - 2022-06-09 04:34 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2022-06-09 04:33 - 2022-05-20 02:51 - 000047792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhdap64.dll
2022-06-09 04:32 - 2022-07-05 01:13 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2022-06-09 04:32 - 2022-06-09 21:23 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2022-06-09 04:32 - 2022-06-09 04:34 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2022-06-09 04:31 - 2022-05-21 05:18 - 007618584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2022-06-09 04:31 - 2022-05-20 02:51 - 000134832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2022-06-09 04:31 - 2020-10-07 13:34 - 000670616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2022-06-09 04:31 - 2020-10-07 13:34 - 000555248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2022-06-09 04:29 - 2022-05-21 05:26 - 001905912 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2022-06-09 04:29 - 2022-05-21 05:26 - 001905912 _____ C:\WINDOWS\system32\vulkaninfo.exe
2022-06-09 04:29 - 2022-05-21 05:26 - 001478384 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2022-06-09 04:29 - 2022-05-21 05:26 - 001478384 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2022-06-09 04:29 - 2022-05-21 05:26 - 001467080 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2022-06-09 04:29 - 2022-05-21 05:26 - 001432304 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2022-06-09 04:29 - 2022-05-21 05:26 - 001432304 _____ C:\WINDOWS\system32\vulkan-1.dll
2022-06-09 04:29 - 2022-05-21 05:26 - 001209408 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2022-06-09 04:29 - 2022-05-21 05:26 - 001145584 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2022-06-09 04:29 - 2022-05-21 05:26 - 001145584 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2022-06-09 04:29 - 2022-05-21 05:23 - 000587336 _____ C:\WINDOWS\system32\nvofapi64.dll
2022-06-09 04:29 - 2022-05-21 05:23 - 000460496 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2022-06-09 04:29 - 2022-05-21 05:22 - 002120896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2022-06-09 04:29 - 2022-05-21 05:22 - 001603144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2022-06-09 04:29 - 2022-05-21 05:22 - 001530456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2022-06-09 04:29 - 2022-05-21 05:22 - 001177312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2022-06-09 04:29 - 2022-05-21 05:22 - 000730320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2022-06-09 04:29 - 2022-05-21 05:22 - 000724688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2022-06-09 04:29 - 2022-05-21 05:22 - 000712416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2022-06-09 04:29 - 2022-05-21 05:21 - 006964824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2022-06-09 04:29 - 2022-05-21 05:21 - 006226640 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2022-06-09 04:29 - 2022-05-21 05:21 - 005100752 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2022-06-09 04:29 - 2022-05-21 05:21 - 002932952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2022-06-09 04:29 - 2022-05-21 05:21 - 000582712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2022-06-09 04:29 - 2022-05-21 05:21 - 000457944 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2022-06-09 04:29 - 2022-05-21 05:20 - 005730880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2022-06-09 04:29 - 2022-05-21 05:19 - 000851136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2022-06-09 04:29 - 2022-05-21 05:18 - 006465200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2022-06-09 04:29 - 2022-05-20 02:51 - 000089337 _____ C:\WINDOWS\system32\nvinfo.pb
2022-06-09 04:10 - 2022-06-21 23:46 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\D3DSCache
2022-06-09 03:37 - 2020-06-16 06:38 - 000063392 _____ C:\WINDOWS\system32\Drivers\AmdTools64.sys
2022-06-09 03:13 - 2022-07-05 01:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Software꞉ Adrenalin Edition
2022-06-09 03:13 - 2022-06-09 04:01 - 000003124 _____ C:\WINDOWS\system32\Tasks\AMDInstallLauncher
2022-06-09 03:13 - 2022-05-17 07:48 - 002949952 _____ (AMD Inc.) C:\WINDOWS\SysWOW64\AMDBugReportTool.exe
2022-06-09 03:12 - 2022-06-09 03:12 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\AMDSoftwareInstaller
2022-06-06 21:33 - 2022-06-06 21:33 - 000025632 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\eac_usermode_123019749162429.dll
2022-06-06 01:44 - 2022-06-06 01:44 - 000000000 ____D C:\WINDOWS\Panther
2022-06-05 20:07 - 2022-06-05 20:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2022-06-05 15:50 - 2022-06-05 15:50 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\MicrosoftEdge
2022-06-05 13:40 - 2022-06-05 13:40 - 000000000 ____D C:\Users\Anunnaki\Desktop\cfg

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-07-05 21:54 - 2021-05-26 13:20 - 000776046 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-07-05 21:54 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2022-07-05 21:51 - 2021-05-26 13:11 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-07-05 21:51 - 2021-04-11 21:41 - 000002364 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2022-07-05 21:49 - 2021-05-26 13:16 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-07-05 21:49 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-07-05 18:08 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2022-07-05 17:10 - 2021-10-11 16:18 - 000000000 ____D C:\Users\Anunnaki\AppData\Roaming\Origin
2022-07-05 17:10 - 2021-10-11 16:18 - 000000000 ____D C:\ProgramData\Origin
2022-07-05 17:02 - 2021-11-13 12:10 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\Origin
2022-07-05 14:32 - 2021-10-23 19:39 - 000000000 ____D C:\Program Files (x86)\Origin Games
2022-07-05 01:33 - 2021-05-26 12:33 - 000000000 ____D C:\Users\Anunnaki
2022-07-05 01:13 - 2020-04-08 23:02 - 000000000 ____D C:\Users\Anunnaki\AppData\Roaming\Notepad++
2022-07-05 01:13 - 2020-01-16 01:15 - 000000000 ____D C:\Program Files (x86)\WinPcap
2022-07-05 01:13 - 2019-11-15 15:15 - 000000000 ____D C:\Users\Anunnaki\AppData\Roaming\TeamViewer
2022-07-05 01:13 - 2019-11-15 15:15 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2022-07-05 01:13 - 2019-11-03 15:43 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\IsolatedStorage
2022-07-05 01:13 - 2019-10-23 12:50 - 000000000 ____D C:\Users\Anunnaki\AppData\Roaming\TS3Client
2022-07-05 00:55 - 2022-06-03 12:51 - 000000000 ____D C:\Program Files\FACEIT AC
2022-07-05 00:11 - 2022-05-13 09:59 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2022-07-05 00:11 - 2022-05-13 09:59 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2022-07-03 23:29 - 2021-05-22 20:27 - 000000000 ____D C:\Users\Anunnaki\AppData\Roaming\qBittorrent
2022-06-30 21:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-06-30 15:48 - 2020-02-08 18:51 - 000000000 ____D C:\Users\Anunnaki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2022-06-30 15:48 - 2020-02-05 01:20 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\SquirrelTemp
2022-06-23 06:02 - 2020-11-19 09:43 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-06-22 00:09 - 2020-05-09 21:49 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\Saber
2022-06-22 00:09 - 2019-11-06 09:25 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\CrashDumps
2022-06-21 23:58 - 2021-09-09 11:47 - 000000000 ____D C:\Program Files\Intel
2022-06-21 21:55 - 2021-05-26 13:11 - 000286112 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-06-21 21:54 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-06-21 21:54 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2022-06-21 21:54 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-06-21 21:54 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-06-21 21:15 - 2019-07-27 20:24 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-06-21 21:14 - 2019-07-27 20:24 - 145918784 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-06-21 21:12 - 2019-08-22 15:38 - 000002592 __RSH C:\ProgramData\ntuser.pol
2022-06-18 16:41 - 2022-05-06 19:51 - 000000000 ____D C:\Users\Anunnaki\AppData\Roaming\Goldberg UplayEmu Saves
2022-06-18 13:29 - 2019-07-27 05:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2022-06-09 20:59 - 2021-10-11 16:22 - 000000000 ____D C:\Program Files (x86)\Origin
2022-06-09 04:34 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-06-09 04:34 - 2019-07-27 13:27 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\Packages
2022-06-09 04:04 - 2022-05-16 10:04 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2022-06-09 04:01 - 2021-05-26 13:16 - 000003084 _____ C:\WINDOWS\system32\Tasks\AMDLinkUpdate
2022-06-09 03:58 - 2019-07-27 04:53 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2022-06-09 03:15 - 2019-07-27 05:18 - 000000000 ____D C:\Users\Anunnaki\AppData\Local\cache
2022-06-09 03:13 - 2021-05-26 13:16 - 000003488 _____ C:\WINDOWS\system32\Tasks\ModifyLinkUpdate
2022-06-09 03:13 - 2021-05-26 13:16 - 000003160 _____ C:\WINDOWS\system32\Tasks\StartCN
2022-06-09 03:13 - 2021-05-26 13:16 - 000003080 _____ C:\WINDOWS\system32\Tasks\StartDVR
2022-06-09 03:13 - 2020-11-19 09:48 - 000000000 ____D C:\ProgramData\Packages
2022-06-06 21:32 - 2021-03-24 13:01 - 000012288 _____ C:\Users\Anunnaki\AppData\Roaming\emp.bin

==================== Files in the root of some directories ========

2021-03-24 13:01 - 2022-06-06 21:32 - 000012288 _____ () C:\Users\Anunnaki\AppData\Roaming\emp.bin
2019-03-19 06:43 - 2019-03-19 06:43 - 000314570 ___SH () C:\Users\Anunnaki\AppData\Roaming\htedtge
2022-07-01 13:35 - 2022-07-01 13:35 - 000000073 _____ () C:\Users\Anunnaki\AppData\Roaming\settings.conf
2020-06-19 09:03 - 2022-05-09 17:45 - 000000205 _____ () C:\Users\Anunnaki\AppData\Local\oobelibMkey.log
2019-09-25 01:25 - 2021-03-25 18:44 - 000007591 _____ () C:\Users\Anunnaki\AppData\Local\Resmon.ResmonCfg
2019-09-09 19:41 - 2019-09-09 19:41 - 000000049 _____ () C:\Users\Anunnaki\AppData\Local\script.ps1

==================== FCheck ================================

(If an entry is included in the fixlist, the file/folder will be moved.)

FCheck: C:\WINDOWS\SysWOW64\version_IObitDel.dll [2021-03-13] <==== ATTENTION (zero byte File/Folder)

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

[Link mogu videti samo ulogovani korisnici]



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Izvini sto tek sad pisem, bio sam odsutan. Ako je potrebna neka pomoc, javi.



Ko je trenutno na forumu
 

Ukupno su 1092 korisnika na forumu :: 67 registrovanih, 3 sakrivenih i 1022 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, acatomic, acov34, antonije64, Apok, Asteker, Avalon015, B61, Ba4e, Ben Roj, bojan313, bojanM84, bolimejoli, boromir, branko7, Chainsaw, crnogorac, Dare, dekan.m, Djuro2000, dmarx1, Doc, dukajov, Futurama, Georgius, ginjica, GveX, jalos, jimi_agf, kihot, komsija1, Koča, LostInSpaceandTime, mango, Martin543, Maruti, Michellefromrezistance, mkukoleca, Najax, nenad81, nevjerna beba, Nobunaga, obsc, operniki, ozzy, padamacki, Pero, Pilence, Primus17, Ray1973, ruso, saki80, sevenino, sickmouse, Sir Budimir, Smajser, Srna, strelac07, tachinni, Trpe Grozni, vathra, Vlado82, vuksa72, x011, zlatkoa987, Zoran1959, Đurđevdan