Joined
·
6 Posts
It shows the general dialogue when the site needs login and password. This says roughly
"On proxy-server hxxps://koiq-37c8e4.cream-regards.net you need to enter login and password"
Also if you could write what that typically says on english it would help a lot since I would know what exactly to google
And I same pop up appear absolutely randomly with different URLS
this url looks particularly suspicious.
"On proxy-server hxxps://koiq-37c8e4.cream-regards.net you need to enter login and password"
Also if you could write what that typically says on english it would help a lot since I would know what exactly to google
And I same pop up appear absolutely randomly with different URLS
this url looks particularly suspicious.
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-01-2021
Ran by nkshv (administrator) on MSI (Micro-Star International Co., Ltd. GL65 Leopard 10SCXR) (15-01-2021 20:59:34)
Running from D:\Apps\Farbar Recovery Scan Tool
Loaded Profiles: nkshv
Platform: Windows 10 Home Single Language Version 20H2 19042.685 (X64) Language: Русский (Россия)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Autodesk, Inc. -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\10.1.0.3194\AdskLicensingService\AdskLicensingService.exe
(Autodesk, Inc. -> Autodesk) C:\Users\nkshv\AppData\Local\Programs\Autodesk\Genuine Service\GenuineService.exe
(Autodesk, Inc. -> Autodesk, Inc.) D:\Apps\Autodesk\Inventor 2021\Moldflow\bin\mitsijm.exe
(A-Volute -> Nahimic) C:\Windows\System32\NahimicService.exe
(A-Volute SAS -> A-Volute) C:\Users\nkshv\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrB.exe
(Flexera Software LLC -> Flexera) C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) pGFX 2020 -> ) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_26b207b939eae50e\OneApp.IGCC.WinService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_e67d3946e6cd0335\igfxCUIService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_e67d3946e6cd0335\igfxEM.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_67ebcbaf734be2a4\IntelCpHDCPSvc.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_67ebcbaf734be2a4\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_48973fc6c96c696a\RstMwService.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <22>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mspaint.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2011.6-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2011.6-0\NisSrv.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmii.inf_amd64_bd367893e1ff9b5c\Display.NvContainer\NVDisplay.Container.exe <2>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_85a48ee0cac1d3dd\RtkAudUService64.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) D:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(Valve -> Valve Corporation) D:\Games\Steam\steam.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [321112 2019-12-10] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706680 2020-09-17] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [664872 2020-03-04] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [Autodesk Genuine Service ] => C:\Users\nkshv\AppData\Local\Programs\Autodesk\Genuine Service\GenuineService.exe [1077864 2020-01-02] (Autodesk, Inc. -> Autodesk)
HKU\S-1-5-21-1482872955-3569544570-3760393657-1001\...\Run: [Steam] => D:\Games\Steam\steam.exe [3411232 2020-12-21] (Valve -> Valve Corporation)
HKU\S-1-5-21-1482872955-3569544570-3760393657-1001\...\Run: [XDM] => "C:\Program Files (x86)\XDM\java-runtime\bin\javaw.exe" -jar "C:\Program Files (x86)\XDM\xdman.jar" -m
HKU\S-1-5-21-1482872955-3569544570-3760393657-1001\...\Run: [GalaxyClient] => [X]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{28B89EEF-4107-0000-7102-CF3F3A09B77D}] -> msiexec /fus {28B89EEF-4107-0000-7102-CF3F3A09B77D}
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Policies: C:\Users\Все пользователи\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01290C41-32F4-4ECA-99EB-4C6784D4BD2B} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {186623A4-952E-4DC5-8C00-A5E3185DF8CF} - System32\Tasks\NahimicSvc64Run => C:\Windows\system32\NahimicSvc64.exe [1066416 2020-11-04] (A-Volute -> Nahimic)
Task: {5D0EC8EC-DC63-4964-B98A-0BCFA2F93FCA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {614A56AA-456B-4A27-92E1-8376726B4D6A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {77FEC3F8-BEC1-4650-A072-BB7B47E2E1D6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {844F5B76-AAD6-4A42-80D0-7C61031E82B5} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\IntelPTTEKRecertification.exe [918288 2020-04-22] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {A3852E11-1401-4E3F-8203-8401DC1D7B59} - System32\Tasks\Agent Activation Runtime\S-1-5-21-1482872955-3569544570-3760393657-1001 => C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe [13312 2020-12-09] (Microsoft Windows -> )
Task: {B7919E87-0BE7-4961-B047-387DC2D8898D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MpCmdRun.exe [545704 2020-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E644F3DE-DB0D-4268-8AB5-0017452B4533} - System32\Tasks\NahimicSvc32Run => C:\Windows\SysWOW64\NahimicSvc32.exe [822704 2020-11-04] (A-Volute -> Nahimic)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{8b8a78fc-ea66-41a9-809a-32dec8e1eb7d}: [NameServer] 195.34.31.50,62.112.106.130
Tcpip\..\Interfaces\{8b8a78fc-ea66-41a9-809a-32dec8e1eb7d}: [DhcpNameServer] 192.168.1.254
Edge:
======
DownloadDir: C:\Users\nkshv\Downloads
Edge HomeButtonPage: HKU\S-1-5-21-1482872955-3569544570-3760393657-1001 -> hxxp://google.com/
Edge DefaultProfile: Default
Edge Profile: C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Default [2021-01-15]
Edge DownloadDir: D:\Загрузки\Edge
Edge HomePage: Default -> hxxps://www.youtube.com/
Edge StartupUrls: Default -> "hxxp://google.com/"
Edge Extension: (Universal Bypass) - C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ckiidekccfgninkobmmofopbbdgdclgg [2020-12-07]
Edge Extension: (Xtreme Download Manager) - C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dkckaoghoiffdbomfbbodbbgmhjblecj [2020-12-09]
Edge Extension: (GoFullPage - Full Page Screen Capture) - C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2020-12-17]
Edge Extension: (Google Документы офлайн) - C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-01-13]
Edge Extension: (uBlock Origin) - C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2020-12-31]
Edge Extension: (SetupVPN - Lifetime Free VPN) - C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\oofgbpoabipfcfjapgnbbjjaenockbdp [2020-12-08]
Edge Profile: C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2021-01-15]
Edge Extension: (Xtreme Download Manager) - C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\dkckaoghoiffdbomfbbodbbgmhjblecj [2020-12-16]
Edge Extension: (MetaMask) - C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn [2021-01-08]
Edge Extension: (uBlock Origin) - C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2020-12-31]
Edge Profile: C:\Users\nkshv\AppData\Local\Microsoft\Edge\User Data\Profile 2 [2021-01-15]
FireFox:
========
FF Plugin-x32: @java.com/DTPlugin,version=11.271.2 -> C:\Program Files (x86)\Java\jre1.8.0_271\bin\dtplugin\npDeployJava1.dll [2020-12-07] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.271.2 -> C:\Program Files (x86)\Java\jre1.8.0_271\bin\plugin2\npjp2.dll [2020-12-07] (Oracle America, Inc. -> Oracle Corporation)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1046904 2020-03-04] (Autodesk, Inc. -> Autodesk Inc.)
R2 AdskLicensingService; C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe [16930616 2019-12-18] (Autodesk, Inc. -> Autodesk)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [818288 2020-12-07] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 GalaxyClientService; C:\Games\GOG Galaxy\GalaxyClientService.exe [1741384 2020-12-08] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6821960 2020-12-08] (GOG Sp. z o.o. -> GOG.com)
R2 mitsijm2021; D:\Apps\Autodesk\Inventor 2021\Moldflow\bin\mitsijm.exe [844088 2019-12-04] (Autodesk, Inc. -> Autodesk, Inc.)
R2 NahimicService; C:\WINDOWS\system32\NahimicService.exe [2719664 2020-11-04] (A-Volute -> Nahimic)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2020-12-11] (Even Balance, Inc. -> )
R2 PnkBstrB; C:\WINDOWS\SysWOW64\PnkBstrB.exe [107832 2020-12-11] (Even Balance, Inc. -> )
R2 RtkAudioUniversalService; C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_85a48ee0cac1d3dd\RtkAudUService64.exe [1183968 2020-10-15] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2020-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2020-12-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_bd367893e1ff9b5c\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_bd367893e1ff9b5c\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
R1 MSIO; C:\WINDOWS\system32\drivers\MsIo64.sys [18448 2019-10-17] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [85592 2020-06-16] (A-Volute -> Windows (R) Win 7 DDK provider)
U5 PROCMON24; C:\Windows\System32\Drivers\PROCMON24.sys [89968 2020-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Sysinternals - www.sysinternals.com)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48536 2020-12-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [429296 2020-12-06] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [70896 2020-12-06] (Microsoft Windows -> Microsoft Corporation)
S1 EneTechIo; \??\C:\WINDOWS\system32\drivers\ene.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-01-15 20:58 - 2021-01-15 20:59 - 000000000 ____D C:\FRST
2021-01-14 22:03 - 2021-01-14 22:03 - 020077498 _ C:\Users\nkshv\Downloads\Unusual Music Creators Collab.zip
2021-01-12 16:51 - 2021-01-12 16:56 - 000000000 ____D C:\Users\nkshv\AppData\Roaming\gsmartcontrol
2021-01-10 13:07 - 2021-01-10 13:07 - 000000000 ____D C:\Users\nkshv\AppData\Local\IsolatedStorage
2021-01-10 12:26 - 2021-01-10 12:26 - 000000000 ____D C:\Users\nkshv\AppData\Local\Autodesk,_Inc
2021-01-10 12:24 - 2021-01-10 12:24 - 000000000 ____D C:\Users\nkshv\AppData\Local\CefSharp
2021-01-10 12:23 - 2021-01-10 12:23 - 000000000 ____D C:\Users\Все пользователи\FLEXnet
2021-01-10 12:23 - 2021-01-10 12:23 - 000000000 ____D C:\ProgramData\FLEXnet
2021-01-10 12:19 - 2021-01-10 12:19 - 000000000 ____D C:\Users\nkshv\AppData\Local\AdSSO
2021-01-10 12:15 - 2021-01-10 12:15 - 000002298 _ C:\Users\nkshv\Desktop\Install Now Autodesk Inventor 2021.lnk
2021-01-10 12:15 - 2021-01-10 12:15 - 000001460 _ C:\Users\Public\Desktop\Приложение Autodesk для ПК.lnk
2021-01-10 12:15 - 2021-01-10 12:15 - 000000000 ____D C:\Users\nkshv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk
2021-01-10 12:15 - 2021-01-10 12:15 - 000000000 ____D C:\Program Files (x86)\Autodesk
2021-01-10 12:13 - 2021-01-10 12:13 - 000001957 _ C:\Users\Public\Desktop\DWG TrueView 2021 - English.lnk
2021-01-10 12:13 - 2021-01-10 12:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DWG TrueView 2021 - English
2021-01-10 12:04 - 2021-01-10 12:04 - 000000000 ____D C:\Users\Public\Documents\.forever
2021-01-10 12:04 - 2021-01-10 12:04 - 000000000 ____D C:\Program Files\Microsoft SQL Server
2021-01-10 12:04 - 2021-01-10 12:04 - 000000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2021-01-10 12:03 - 2021-01-10 12:28 - 000000000 ____D C:\Users\nkshv\Documents\Inventor
2021-01-10 12:03 - 2021-01-10 12:23 - 000000000 ____D C:\Users\nkshv\AppData\Local\Autodesk
2021-01-10 12:02 - 2021-01-10 12:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk Inventor 2021
2021-01-10 12:02 - 2021-01-10 12:32 - 000000000 ____D C:\Program Files\Common Files\Autodesk Shared
2021-01-10 12:02 - 2021-01-10 12:24 - 000000000 ____D C:\Users\Public\Documents\Autodesk
2021-01-10 12:02 - 2021-01-10 12:02 - 000001913 _ C:\Users\Public\Desktop\Autodesk Inventor Professional 2021.lnk
2021-01-10 11:40 - 2021-01-10 12:32 - 000000000 ____D C:\Program Files\Autodesk
2021-01-10 11:37 - 2021-01-10 12:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2021-01-10 11:32 - 2021-01-10 20:40 - 000000000 ____D C:\Users\Все пользователи\Autodesk
2021-01-10 11:32 - 2021-01-10 20:40 - 000000000 ____D C:\ProgramData\Autodesk
2021-01-10 11:30 - 2021-01-10 12:15 - 000000000 ____D C:\Users\nkshv\AppData\Roaming\Autodesk
2021-01-10 11:30 - 2021-01-10 11:30 - 000000000 ____D C:\Autodesk
2021-01-09 22:31 - 2021-01-09 22:46 - 000000000 ____D C:\Users\nkshv\AppData\Roaming\shapez.io-standalone
2021-01-09 18:41 - 2021-01-09 18:41 - 000000000 ____D C:\Users\nkshv\AppData\LocalLow\Vonsnake
2021-01-07 13:13 - 2021-01-07 13:13 - 000000000 ____D C:\Users\nkshv\Documents\Uncrewed Game
2021-01-06 17:10 - 2021-01-06 17:10 - 000000016 _ C:\Users\nkshv\AppData\Roaming\obs-virtualcam.txt
2021-01-06 14:58 - 2021-01-06 14:59 - 119314642 _ C:\Users\nkshv\Downloads\Cement Tea - 抜歯.zip
2021-01-04 14:21 - 2021-01-04 14:21 - 000000052 _ C:\Users\nkshv\Desktop\httpswww.researchgate.netprofileAsdasd_Asdasd47.txt
2020-12-31 15:53 - 2020-12-31 15:53 - 000000000 ____D C:\Users\nkshv\Documents\ColdBeamGames
2020-12-29 16:48 - 2021-01-12 15:10 - 000000231 _ C:\Users\nkshv\Desktop\Progress.txt
2020-12-27 14:26 - 2020-12-27 14:26 - 000000000 ____D C:\Users\nkshv\AppData\Local\NBTExplorer
2020-12-27 10:34 - 2020-12-27 10:34 - 000000000 ____D C:\Users\nkshv\AppData\Local\Overwolf
2020-12-27 10:11 - 2020-12-27 10:11 - 000001813 _ C:\Users\nkshv\Desktop\Новый текстовый документ.txt
2020-12-26 17:49 - 2020-12-26 17:49 - 000000000 ____D C:\Users\nkshv\AppData\Local\Fallout4
2020-12-26 17:38 - 2021-01-09 17:03 - 000000000 ____D C:\Users\nkshv\AppData\Roaming\.minecraft
2020-12-26 17:37 - 2020-12-26 17:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft Launcher
2020-12-26 17:32 - 2020-12-26 17:32 - 000001225 _ C:\Users\nkshv\Desktop\SSD.lnk
2020-12-26 15:40 - 2020-12-28 19:29 - 000000073 _ C:\Users\nkshv\Desktop\SSD.txt
2020-12-25 11:35 - 2020-12-25 11:35 - 000000000 ____D C:\Users\nkshv\AppData\Local\Saber
2020-12-24 21:57 - 2020-12-24 21:57 - 000000065 _ C:\Users\nkshv\Desktop\mcwait.txt
2020-12-24 21:07 - 2020-12-26 16:28 - 000007605 _ C:\Users\nkshv\AppData\Local\Resmon.ResmonCfg
2020-12-24 19:44 - 2020-12-24 19:44 - 000000000 ____D C:\Users\nkshv\AppData\LocalLow\Temp
2020-12-24 13:39 - 2020-12-24 13:54 - 000000000 ____D C:\Users\nkshv\AppData\Roaming\vlc
2020-12-23 13:59 - 2020-12-23 13:59 - 000003632 _ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2020-12-22 17:56 - 2020-12-26 16:40 - 000000000 ____D C:\Program Files\AdoptOpenJDK
2020-12-22 16:10 - 2020-12-22 16:10 - 000000000 ____D C:\Users\nkshv\AppData\LocalLow\Unity
2020-12-21 23:19 - 2020-12-28 18:23 - 000000090 _ C:\Users\nkshv\Desktop\httpswww.youtube.comwatchv=ERq4Kb0aPfc.txt
2020-12-18 17:54 - 2020-12-18 17:54 - 000061872 _ C:\Users\nkshv\Downloads\a41a3fd0bf7460de0ddf6fd5.jpeg
2020-12-18 16:52 - 2021-01-14 14:34 - 000000000 ____D C:\Users\nkshv\Downloads\VK audio
2020-12-18 16:44 - 2020-12-18 16:44 - 000001164 _ C:\Users\nkshv\Desktop\Checked.lnk
2020-12-18 16:44 - 2020-12-18 16:44 - 000001164 _ C:\Users\nkshv\Desktop\Artists.lnk
2020-12-18 16:44 - 2020-12-18 16:44 - 000001144 _ C:\Users\nkshv\Desktop\Check.lnk
2020-12-18 16:44 - 2020-12-18 16:44 - 000001022 _ C:\Users\nkshv\Desktop\Notes.lnk
2020-12-18 16:43 - 2020-12-18 16:43 - 000000821 _ C:\Users\nkshv\Desktop\Info.lnk
2020-12-18 10:33 - 2020-12-19 20:39 - 000000258 __RSH C:\Users\Все пользователи\ntuser.pol
2020-12-18 10:33 - 2020-12-19 20:39 - 000000258 __RSH C:\ProgramData\ntuser.pol
2020-12-18 09:34 - 2020-12-18 09:34 - 000000000 ____D C:\Users\nkshv\AppData\Local\kenshi
2020-12-17 22:52 - 2020-12-21 11:29 - 000002507 _ C:\Users\nkshv\Desktop\Tr.lnk
2020-12-17 22:51 - 2020-12-17 22:51 - 000001245 _ C:\Users\nkshv\Desktop\PicoTorrent.lnk
2020-12-17 22:51 - 2020-12-17 22:51 - 000000932 _ C:\Users\nkshv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicoTorrent.lnk
2020-12-17 22:50 - 2020-12-17 22:50 - 000001290 _ C:\Users\nkshv\Desktop\OHM.lnk
2020-12-17 22:50 - 2020-12-17 22:50 - 000001170 _ C:\Users\nkshv\Desktop\Syncthing.lnk
2020-12-17 22:47 - 2020-12-17 22:47 - 000001236 _ C:\Users\nkshv\Desktop\YoutubeDL.lnk
2020-12-17 22:46 - 2020-12-17 22:46 - 000001329 _ C:\Users\nkshv\Desktop\OBS.lnk
2020-12-17 22:46 - 2020-12-17 22:46 - 000001136 _ C:\Users\nkshv\Desktop\Audacity.lnk
2020-12-17 22:46 - 2020-12-17 22:46 - 000001036 _ C:\Users\nkshv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\obs64.lnk
2020-12-17 22:46 - 2020-12-17 22:46 - 000000917 _ C:\Users\nkshv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\youtube-dl-gui.lnk
2020-12-17 22:45 - 2020-12-17 22:45 - 000000707 _ C:\Users\nkshv\Desktop\Приложения.lnk
2020-12-17 22:44 - 2020-12-17 22:44 - 000001094 _ C:\Users\nkshv\Desktop\5 Сем.lnk
2020-12-17 22:44 - 2020-12-17 22:44 - 000000870 _ C:\Users\nkshv\Desktop\Документы.lnk
2020-12-17 22:43 - 2020-12-17 22:43 - 000000791 _ C:\Users\nkshv\Desktop\Изображения.lnk
2020-12-17 22:42 - 2020-12-17 22:42 - 000000755 _ C:\Users\nkshv\Desktop\Загрузки.lnk
2020-12-17 22:41 - 2020-12-17 22:41 - 000000951 _ C:\Users\nkshv\Desktop\Tracks.lnk
2020-12-16 14:12 - 2020-12-16 14:12 - 000000000 ____D C:\Users\nkshv\.cache
2020-12-16 14:10 - 2020-12-16 14:11 - 000000000 ____D C:\Users\nkshv\AppData\Roaming\youtube-dlg
2020-12-16 14:04 - 2020-12-16 14:07 - 037725168 _ C:\Users\nkshv\Downloads\youtube-dl-gui-0.4-win-portable.zip
2020-12-16 12:44 - 2020-12-16 12:44 - 000000877 _ C:\Users\nkshv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\syncthing.lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-01-15 16:46 - 2019-12-07 12:14 - 000000000 ____D C:\Users\Все пользователи\regid.1991-06.com.microsoft
2021-01-15 16:46 - 2019-12-07 12:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-01-15 14:21 - 2020-12-10 10:21 - 000000000 ____D C:\Users\nkshv\AppData\Roaming\obs-studio
2021-01-15 10:45 - 2019-12-07 12:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-01-15 10:34 - 2020-12-07 09:23 - 000000000 ___HD C:\$WinREAgent
2021-01-15 10:32 - 2020-12-06 18:54 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-01-15 10:29 - 2020-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-01-15 10:29 - 2020-12-06 18:54 - 135062968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-01-13 20:10 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2021-01-13 15:03 - 2019-12-07 12:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-01-13 15:03 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-01-10 20:47 - 2020-12-07 11:22 - 001755704 _ C:\WINDOWS\system32\PerfStringBackup.INI
2021-01-10 20:47 - 2019-12-07 17:34 - 000772062 _ C:\WINDOWS\system32\perfh019.dat
2021-01-10 20:47 - 2019-12-07 17:34 - 000152272 _ C:\WINDOWS\system32\perfc019.dat
2021-01-10 20:47 - 2019-12-07 12:13 - 000000000 ____D C:\WINDOWS\INF
2021-01-10 20:40 - 2020-12-07 11:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-01-10 20:40 - 2020-12-07 11:14 - 000773152 _ C:\WINDOWS\system32\FNTCACHE.DAT
2021-01-10 20:40 - 2020-12-07 11:14 - 000008192 ___SH C:\DumpStack.log.tmp
2021-01-10 20:40 - 2020-12-06 17:42 - 000000000 ____D C:\Users\Все пользователи\NVIDIA
2021-01-10 20:40 - 2020-12-06 17:42 - 000000000 ____D C:\ProgramData\NVIDIA
2021-01-10 20:40 - 2020-12-06 17:24 - 000000000 __SHD C:\Users\nkshv\IntelGraphicsProfiles
2021-01-10 19:21 - 2019-12-07 12:03 - 000524288 _ C:\WINDOWS\system32\config\BBI
2021-01-10 12:12 - 2019-12-07 12:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2021-01-10 12:11 - 2019-11-14 02:47 - 000000000 ____D C:\Program Files\Microsoft Office
2021-01-09 21:11 - 2020-12-07 10:06 - 000002457 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-01-09 19:11 - 2020-12-07 12:21 - 000000000 ____D C:\Users\nkshv\Documents\BeamNG.drive
2021-01-07 17:29 - 2020-12-15 12:37 - 000000000 ____D C:\Users\nkshv\AppData\Roaming\audacity
2021-01-07 14:43 - 2020-12-07 09:27 - 000000000 ___DC C:\WINDOWS\Panther
2021-01-06 17:07 - 2020-12-09 18:47 - 000000496 _ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2021-01-03 14:53 - 2020-12-09 21:59 - 000000000 ____D C:\Users\nkshv\AppData\Local\Syncthing
2021-01-02 20:21 - 2020-12-07 12:19 - 000000000 ____D C:\Users\nkshv\AppData\Roaming\SpinTires MudRunner
2020-12-31 10:08 - 2020-12-14 10:11 - 000000000 ____D C:\Users\nkshv\Downloads\Compressed
2020-12-27 10:34 - 2020-12-06 17:30 - 000000000 ____D C:\Users\nkshv\AppData\Local\D3DSCache
2020-12-26 22:50 - 2020-12-06 17:25 - 000000000 ____D C:\Users\nkshv\AppData\Local\NVIDIA Corporation
2020-12-26 17:49 - 2020-12-07 11:33 - 000000000 ____D C:\Users\nkshv\Documents\My Games
2020-12-26 16:35 - 2020-12-07 20:56 - 000000000 _ C:\Users\nkshv\.xdm-global-lock
2020-12-26 16:26 - 2020-12-07 11:15 - 000000000 ____D C:\Users\nkshv
2020-12-26 16:03 - 2020-12-06 17:24 - 000000000 ____D C:\Users\nkshv\AppData\Local\ConnectedDevicesPlatform
2020-12-26 16:03 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-12-25 18:20 - 2020-12-06 17:24 - 000000000 ____D C:\Users\nkshv\AppData\Local\Packages
2020-12-25 13:25 - 2020-12-06 17:26 - 000000000 ____D C:\Users\nkshv\AppData\Local\PlaceholderTileLogoFolder
2020-12-25 13:25 - 2019-11-14 02:08 - 000000000 ____D C:\Users\Все пользователи\Packages
2020-12-25 13:25 - 2019-11-14 02:08 - 000000000 ____D C:\ProgramData\Packages
2020-12-22 17:06 - 2020-12-07 12:16 - 000000000 ____D C:\Users\nkshv\AppData\LocalLow\Nolla_Games_Noita
2020-12-21 11:29 - 2020-12-08 13:07 - 000002507 _ C:\Users\nkshv\Desktop\M.lnk
2020-12-19 20:29 - 2019-11-14 02:08 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-12-19 12:59 - 2020-12-09 18:42 - 000001162 _ C:\WINDOWS\system32\config\VSMIDK
2020-12-18 10:33 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2020-12-18 10:33 - 2019-03-19 07:52 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2020-12-17 19:25 - 2020-12-07 11:18 - 000003356 _ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1482872955-3569544570-3760393657-1001
2020-12-17 19:25 - 2020-12-07 11:15 - 000002422 _ C:\Users\nkshv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-12-17 19:25 - 2020-12-06 17:25 - 000000000 ___RD C:\Users\nkshv\OneDrive
2020-12-16 09:36 - 2020-12-06 21:38 - 000000000 ____D C:\Users\nkshv\AppData\Local\NVIDIA
==================== Files in the root of some directories ========
2021-01-06 17:10 - 2021-01-06 17:10 - 000000016 _ () C:\Users\nkshv\AppData\Roaming\obs-virtualcam.txt
2020-12-24 21:07 - 2020-12-26 16:28 - 000007605 _ () C:\Users\nkshv\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Attachments
-
240.9 KB Views: 74
-
109 KB Views: 13
-
105.9 KB Views: 16