Tech Support Forum banner

Possible Trojan in my PC

4.9K views 8 replies 2 participants last post by  Gary R  
#1 ·
Hello,
I wanted to play Sims 4 and my friend happened to have a "safe way" to unlock all DLCs that I installed the 09.04.23, I trusted him and today someone sold hundreads of $ worth of items on my steam account. I managed to stop the slaugther before it went any further. And now that I wanted to restore the PC save I made before installing the Trojan, I see that it had been modified to the next day (10.04.23). So Windows Defender told me about the trojan and deleted it but I don't know how reliable it is. I'm so stupid for believing him and lost a lot already so is it over ? Did I get rid of it ? The folder that I installed was just a link that made me download a "Sims 4 DLCs Unlocker" that I deleted later as I suspected something but it was too late already.
 

Attachments

#2 ·
Here is the FRST.txt:

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 13-04-2023 02
Exécuté par Adrián (administrateur) sur DESKTOP-MIFQ18R (ASUS System Product Name) (13-04-2023 18:49:29)
Exécuté depuis C:\Users\Adrián\Downloads\FRST64.exe
Profils chargés: Adrián
Plate-forme: Microsoft Windows 11 Professionnel Version 21H2 22000.1574 (X64) Langue: Français (France)
Navigateur par défaut: Chrome
Mode d'amorçage: Normal

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe ->) (ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe ->) (ASUSTEK COMPUTER INCORPORATION -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.UserSessionHelper.exe
(C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe
(C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe ->) (Electronic Arts, Inc. -> The Qt Company Ltd.) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\QtWebEngineProcess.exe <2>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe
(C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe
(C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_421.20070.425.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.37\msedgewebview2.exe <6>
(C:\Windows\ImmersiveControlPanel\SystemSettings.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SystemSettingsAdminFlows.exe <2>
(Discord Inc. -> Discord Inc.) C:\Users\Adrián\AppData\Local\Discord\app-1.0.9012\Discord.exe <6>
(explorer.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <52>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.202\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.202\GoogleCrashHandler64.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCopyAccelerator.exe
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\LightingService.exe
(services.exe ->) (ASUSTEK COMPUTER INCORPORATION -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\gamingservices.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2>
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(services.exe ->) (Virtual Desktop, Inc. -> Virtual Desktop, Inc.) C:\Program Files\Virtual Desktop\VirtualDesktop.Service.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ) C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x86.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\AacExtCard\extensionCardHal_x86.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS_Aac_DRAM\Aac3572DramHal_x86.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.SecHealthUI_1000.25305.1000.0_x64__8wekyb3d8bbwe\SecHealthUI.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.22000.1510_none_8275c43aff04bc32\TiWorker.exe
(svchost.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\System32\SecurityHealth\1.0.2302.21002-0\SecurityHealthHost.exe <2>
(SystemSettingsAdminFlows.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Users\ADRIN~1\AppData\Local\Temp\BF0B278D-67FB-40E8-AFB1-7BB8CD3A5B9F\DismHost.exe

==================== Registre (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [SteelSeriesGG] => C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe [12692160 2022-05-13] (SteelSeries ApS -> SteelSeries ApS)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4361576 2023-04-07] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [LGHUB] => C:\Program Files\LGHUB\lghub.exe [146944768 2022-07-29] (Logitech Inc -> Logitech, Inc.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [49958368 2022-02-01] (Google LLC -> )
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1784664 2023-03-14] (Overwolf Ltd -> Overwolf Ltd.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [Battle.net] => D:\Battle.net\Battle.net.exe [1087376 2021-12-21] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [EADM] => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart (Pas de fichier)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKLM\...\Windows x64\Print Processors\Canon MP630 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD9C.DLL [27648 2008-04-21] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MP630 series: C:\Windows\system32\CNMLM9C.DLL [279040 2008-04-21] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\111.0.5563.147\Installer\chrmstp.exe [2023-03-31] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
AppInit_DLLs: C:\PROGRA~1\VIRTUA~1\VIRTUA~4.DLL => C:\Program Files\Virtual Desktop Streamer\VirtualDesktop.Injector64.dll [132520 2021-03-04] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)

==================== Tâches planifiées (Avec liste blanche) ============

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

Task: {0735A24B-E894-4180-9329-1C972A0B6173} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {11EE1835-15A4-4E09-8633-866179ED55C4} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2FD37739-F52E-4C52-9EB1-9A13D83C9BBB} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-01-27] (Nvidia Corporation -> NVIDIA Corporation)
Task: {372A8A8C-BAEA-4A63-9804-163F1D52A2DD} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4518E052-3509-4846-9B65-645D1B0B0A18} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {45B15C20-259C-4353-9BFB-90E80E00D7F5} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-15] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {5373AAA2-7895-4B12-8A1F-F102F8C42EDA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-06-14] (Google LLC -> Google LLC)
Task: {55DAA2DD-C09C-4C7B-B54A-E604132B4AE7} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [115464 2021-12-17] (ASUSTeK Computer Inc. -> ASUS)
Task: {595C82F3-D65E-46DE-B133-1F68B59759FA} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2638856 2023-03-14] (Overwolf Ltd -> Overwolf LTD)
Task: {6EF54466-3128-4CA4-BC10-420D39A368B3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {70D890C4-3797-48B2-BE62-B4E9E19298CD} - System32\Tasks\Microsoft\Windows\WaaSMedic\DeferredWork => {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32}
Task: {77231B27-B153-4DAB-AE82-E83D1F52DF67} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {79B3C747-41F6-4A1F-AADA-8FDB2BCABFB1} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe [49048864 2020-03-16] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {80148F75-235B-415B-BFFA-7D40D050FDBB} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (Pas de fichier)
Task: {8CAA5EAB-7360-4CEA-8A29-C82763C3ADD3} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {968AA82D-0B95-4416-9CCC-7B182367D2D7} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A8518B53-C1D3-4A60-804A-24818151E8C9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B3AA668D-E85E-425C-A2CB-F11664F8B974} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B6E87EF6-AC5B-43DD-84BD-4A3AB20D9A63} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {BD824950-39DD-44EF-9B26-A86A06DECF66} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C4BD17DB-E7AB-4294-AE78-B32B53D88CC2} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe [2248120 2021-12-17] (ASUSTeK Computer Inc. -> ASUS)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (Pas de fichier)
Task: {F12561EC-C9C9-444E-B2EE-EFE2F06E9B9F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-06-14] (Google LLC -> Google LLC)
Task: {F6512D8F-108E-4A26-BC87-5599BEBC2C23} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d641f088e22505 => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)

(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{722b5480-08ce-4eea-9418-78ce2e0dfce5}: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{bd361947-815d-443a-8784-71534a032b8a}: [DhcpNameServer] 192.168.1.1

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Adrián\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-13]

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.311.2 -> C:\Program Files\Java\jre1.8.0_311\bin\dtplugin\npDeployJava1.dll [2021-12-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.311.2 -> C:\Program Files\Java\jre1.8.0_311\bin\plugin2\npjp2.dll [2021-12-03] (Oracle America, Inc. -> Oracle Corporation)

Chrome:
=======
CHR Profile: C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default [2023-04-13]
CHR Notifications: Default -> hxxps://www.facebook.com
CHR Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2023-03-09]
CHR Extension: (Google Docs hors connexion) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-04-06]
CHR Extension: (Lanceur d'applications pour Drive (par Google)) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-01-26]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30]
CHR HKLM\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKLM\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]

==================== Services (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 ArmouryCrateService; C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe [349408 2022-01-22] (ASUSTEK COMPUTER INCORPORATION -> ASUSTeK COMPUTER INC.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe [457544 2021-10-21] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [179488 2021-09-16] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.)
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 AsusUpdateCheck; C:\WINDOWS\System32\AsusUpdateCheck.exe [1191552 2023-04-11] (ASUSTeK Computer Inc. -> )
S3 EAAntiCheatService; C:\Program Files\EA\AC\eaanticheat.gameservice.exe [57017864 2022-12-06] (Electronic Arts, Inc. -> )
R3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [10456168 2023-03-28] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811496 2022-12-05] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [584680 2022-08-15] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029456 2022-07-04] (Epic Games Inc. -> Epic Games, Inc.)
R2 GamingServices; C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\GamingServices.exe [75216 2023-03-19] (Microsoft Corporation -> )
R2 GamingServicesNet; C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe [75216 2023-03-19] (Microsoft Corporation -> )
R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [10876672 2022-07-29] (Logitech Inc -> Logitech, Inc.)
R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [3683496 2021-11-24] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
S3 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2638856 2023-03-14] (Overwolf Ltd -> Overwolf LTD)
S3 OVRLibraryService; C:\Program Files\Oculus\Support\oculus-librarian\OVRLibraryService.exe [148024 2023-02-23] (Oculus VR, LLC -> Facebook Technologies, LLC)
R2 OVRService; C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe [514616 2023-02-23] (Oculus VR, LLC -> Facebook Technologies, LLC)
S3 Rockstar Service; D:\Program Files\Rockstar Games\Launcher\RockstarService.exe [2584528 2022-04-05] (Rockstar Games, Inc. -> Rockstar Games)
R2 ROG Live Service; C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe [6101680 2021-12-17] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [245216 2023-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 SteelSeriesUpdateService; C:\Program Files\SteelSeries\GG\SteelSeriesUpdateService.exe [32960 2022-05-13] (SteelSeries ApS -> )
S3 Updater; C:\Program Files\Virtual Desktop Streamer\Updater.exe [1122216 2021-03-04] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)
R2 VirtualDesktop.Service.exe; C:\Program Files\Virtual Desktop\VirtualDesktop.Service.exe [1962920 2020-12-01] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\NisSrv.exe [3170576 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MsMpEng.exe [133584 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Pilotes (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [34384 2021-10-21] (ASUSTeK Computer Inc. -> )
R1 Asusgio3; C:\Windows\system32\drivers\AsIO3.sys [43192 2021-09-16] (ASUSTeK Computer Inc. -> )
S3 atvi-brynhildr; C:\ProgramData\Battle.net_components\brynhildr_odin\brynhildr.sys [2355952 2021-12-21] (Activision Publishing Inc -> Activision Blizzard, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [507904 2022-01-22] (Microsoft Corporation) [Fichier non signé]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [180224 2022-01-22] (Microsoft Corporation) [Fichier non signé]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [98304 2021-06-05] (Microsoft Corporation) [Fichier non signé]
R1 CTIIO; C:\WINDOWS\system32\drivers\CtiIo64.sys [30728 2022-01-22] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
R1 GLCKIO2; C:\Windows\system32\drivers\GLCKIO2.sys [29368 2019-04-24] (ASUSTeK Computer Inc. -> )
R1 googledrivefs31092; C:\WINDOWS\System32\DRIVERS\googledrivefs31092.sys [384600 2023-02-08] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [46728 2021-06-28] (ASUSTEK COMPUTER INC. -> ASUSTeK Computer Inc.)
R3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [33528 2022-03-24] (WDKTestCert builder,132743893872553407 -> Logitech)
S3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [21704 2022-03-24] (WDKTestCert builder,132743893872553407 -> Logitech)
R3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [62904 2022-03-24] (WDKTestCert builder,132743893872553407 -> Logitech)
R3 MpKsl899a4487; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{12815B20-1960-4D08-8880-F5E60B7479C6}\MpKslDrv.sys [211208 2023-04-11] (Microsoft Windows -> Microsoft Corporation)
S3 MpKsle1fe2cd0; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{12815B20-1960-4D08-8880-F5E60B7479C6}\MpKslDrv.sys [211208 2023-04-11] (Microsoft Windows -> Microsoft Corporation)
R1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation)
R3 oculusvad_oculusvad; C:\WINDOWS\System32\drivers\oculusvad.sys [75280 2021-11-08] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 Oculus_ViGEmBus; C:\WINDOWS\System32\drivers\Oculus_ViGEmBus.sys [32856 2020-09-19] (Oculus VR, LLC -> Facebook Inc.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R3 rtwlane_13; C:\WINDOWS\System32\drivers\rtwlane_13.sys [3717120 2021-06-01] (Microsoft Windows -> Realtek Semiconductor Corporation)
R3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [48848 2020-12-21] (SteelSeries ApS -> SteelSeries ApS)
R3 SteelSeries_Sonar_VAD; C:\WINDOWS\System32\DriverStore\FileRepository\steelseries-sonar-vad.inf_amd64_6f6e907eca1efa31\SteelSeries-Sonar-VAD.sys [89568 2022-03-23] (SteelSeries ApS -> Windows (R) Win 7 DDK provider)
S3 TPS65994; C:\WINDOWS\System32\drivers\TPS65994.sys [49232 2019-12-24] (FPT USA Corp. -> )
R3 vdvad_WaveExtensible; C:\WINDOWS\System32\drivers\vdvad.sys [41072 2019-03-14] (Virtual Desktop, Inc. -> Virtual Desktop)
R3 vdvge; C:\WINDOWS\System32\drivers\vdvge.sys [77864 2018-11-13] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49616 2022-10-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [455968 2022-10-19] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [95520 2022-10-19] (Microsoft Windows -> Microsoft Corporation)
U3 EAAntiCheat; system32\drivers\eaanticheat.sys [X]

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois (créés) (Avec liste blanche) =========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2023-04-13 18:49 - 2023-04-13 18:50 - 000029055 _ C:\Users\Adrián\Downloads\FRST.txt
2023-04-13 18:49 - 2023-04-13 18:50 - 000000000 ____D C:\FRST
2023-04-13 18:46 - 2023-04-13 18:47 - 002380288 _ (Farbar) C:\Users\Adrián\Downloads\FRST64.exe
2023-04-11 20:46 - 2023-04-11 20:46 - 000000000 ___HD C:\$WinREAgent
2023-04-11 15:28 - 2023-04-11 15:28 - 000000000 ____D C:\Users\Adrián\AppData\Roaming\EA
2023-04-11 15:28 - 2023-04-11 15:28 - 000000000 ____D C:\Program Files\EA
2023-04-11 15:21 - 2023-04-11 15:21 - 000000839 _ C:\Users\Public\Desktop\FIFA 23.lnk
2023-04-11 14:47 - 2023-04-11 15:11 - 000000000 ____D C:\ProgramData\EA Desktop
2023-04-11 14:47 - 2023-04-11 14:47 - 002048920 _ (Electronic Arts) C:\Users\Adrián\Downloads\EAappInstaller.exe
2023-04-11 14:47 - 2023-04-11 14:47 - 000000000 ____D C:\Users\Adrián\AppData\Local\Origin
2023-04-11 14:20 - 2023-04-11 14:20 - 000004040 _ C:\WINDOWS\system32\Tasks\PostponeDeviceSetupToast_S-1-5-21-3254008329-1205757616-3926439971-1001_2
2023-04-10 01:00 - 2023-04-10 01:00 - 000001040 _ C:\Users\Public\Desktop\Les Sims 4.lnk
2023-04-10 01:00 - 2023-04-10 00:53 - 000447752 _ (On2.com) C:\WINDOWS\SysWOW64\vp6vfw.dll
2023-04-09 22:12 - 2023-04-09 22:12 - 000000000 ____D C:\Users\Adrián\AppData\Local\Yandex
2023-04-03 21:25 - 2023-04-03 21:25 - 000000000 ____D C:\Users\Adrián\AppData\LocalLow\Cyanide
2023-04-03 21:24 - 2023-04-03 21:24 - 000000223 _ C:\Users\Adrián\Desktop\Chef Life A Restaurant Simulator.url
2023-03-21 19:37 - 2023-03-21 19:37 - 000000222 _ C:\Users\Adrián\Desktop\Rocket League.url
2023-03-19 20:50 - 2023-03-19 20:50 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2023-03-19 20:50 - 2023-03-19 20:50 - 000000000 ____D C:\Program Files (x86)\Microsoft GameInput
2023-03-15 03:23 - 2023-03-09 09:57 - 002172512 _ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 002172512 _ C:\WINDOWS\system32\vulkaninfo.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 001607776 _ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 001607776 _ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 001487336 _ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001479264 _ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001479264 _ C:\WINDOWS\system32\vulkan-1.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001226736 _ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001211488 _ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001211488 _ C:\WINDOWS\SysWOW64\vulkan-1.dll
2023-03-15 03:23 - 2023-03-09 09:54 - 000671744 _ C:\WINDOWS\system32\nvofapi64.dll
2023-03-15 03:23 - 2023-03-09 09:54 - 000506344 _ C:\WINDOWS\SysWOW64\nvofapi.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 001534448 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 001192960 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 000851432 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 000741360 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2023-03-15 03:23 - 2023-03-09 09:52 - 002163736 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2023-03-15 03:23 - 2023-03-09 09:52 - 001620016 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2023-03-15 03:23 - 2023-03-09 09:52 - 000977944 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2023-03-15 03:23 - 2023-03-09 09:52 - 000758272 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 013765632 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 011645952 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 003430400 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 000457752 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2023-03-15 03:23 - 2023-03-09 09:50 - 006084136 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2023-03-15 03:23 - 2023-03-09 09:50 - 005911600 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2023-03-15 03:23 - 2023-03-09 09:50 - 005835312 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2023-03-15 03:23 - 2023-03-09 09:50 - 000852976 _ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2023-03-15 03:23 - 2023-03-08 13:17 - 000104256 _ C:\WINDOWS\system32\nvinfo.pb
2023-03-15 03:12 - 2022-07-14 01:32 - 000060112 _ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys

==================== Un mois (modifiés) ==================

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2023-04-13 18:48 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-04-13 18:33 - 2020-06-14 04:12 - 000000000 ____D C:\Program Files (x86)\Steam
2023-04-13 18:23 - 2020-06-14 03:57 - 000000000 ____D C:\Users\Adrián\AppData\Local\D3DSCache
2023-04-13 18:10 - 2020-10-25 11:40 - 000000000 ____D C:\Users\Adrián\AppData\Local\Discord
2023-04-13 18:09 - 2020-10-25 11:40 - 000000000 ____D C:\Users\Adrián\AppData\Roaming\discord
2023-04-13 18:02 - 2022-01-22 18:17 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-04-12 19:29 - 2021-06-05 14:10 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-04-12 18:25 - 2020-06-14 04:07 - 000000000 ____D C:\Program Files (x86)\Google
2023-04-11 20:50 - 2021-06-05 14:01 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-04-11 15:21 - 2022-06-20 18:12 - 000000000 ___HD C:\Program Files\Common Files\EAInstaller
2023-04-11 15:12 - 2022-01-22 18:32 - 002702328 _ C:\WINDOWS\system32\PerfStringBackup.INI
2023-04-11 15:12 - 2022-01-22 17:58 - 000745774 _ C:\WINDOWS\system32\perfh007.dat
2023-04-11 15:12 - 2022-01-22 17:58 - 000155996 _ C:\WINDOWS\system32\perfc007.dat
2023-04-11 15:12 - 2021-06-05 20:15 - 000806506 _ C:\WINDOWS\system32\perfh00C.dat
2023-04-11 15:12 - 2021-06-05 20:15 - 000156164 _ C:\WINDOWS\system32\perfc00C.dat
2023-04-11 15:12 - 2021-06-05 14:09 - 000000000 ____D C:\WINDOWS\INF
2023-04-11 15:07 - 2021-02-24 17:05 - 000000000 ____D C:\Users\Adrián\AppData\Local\CrashDumps
2023-04-11 15:06 - 2022-01-22 18:29 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-04-11 15:06 - 2020-06-18 22:33 - 000000000 ____D C:\ProgramData\NVIDIA
2023-04-11 15:06 - 2020-06-14 05:33 - 000000000 ____D C:\Users\Adrián\AppData\Local\Oculus
2023-04-11 15:05 - 2021-06-05 14:01 - 000524288 _ C:\WINDOWS\system32\config\BBI
2023-04-11 15:05 - 2020-06-14 02:34 - 001230088 _ C:\WINDOWS\system32\wpbbin.exe
2023-04-11 15:05 - 2020-06-14 02:34 - 001191552 _ C:\WINDOWS\system32\AsusUpdateCheck.exe
2023-04-11 15:05 - 2020-06-14 02:34 - 000012288 ___SH C:\DumpStack.log.tmp
2023-04-11 14:47 - 2023-02-06 20:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2023-04-11 14:47 - 2023-02-06 20:32 - 000000000 ____D C:\Program Files\Electronic Arts
2023-04-11 14:47 - 2020-06-14 04:14 - 000000000 ____D C:\ProgramData\Origin
2023-04-11 14:47 - 2020-06-14 04:07 - 000000000 ____D C:\ProgramData\Package Cache
2023-04-11 14:46 - 2020-06-14 04:59 - 000000000 ____D C:\Program Files (x86)\Origin Games
2023-04-11 14:29 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-04-11 13:16 - 2022-01-22 18:29 - 000003592 _ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3254008329-1205757616-3926439971-1001
2023-04-11 13:16 - 2022-01-22 18:29 - 000003382 _ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3254008329-1205757616-3926439971-1001
2023-04-11 13:16 - 2021-08-25 12:44 - 000002424 _ C:\Users\Adrián\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-04-11 01:20 - 2022-01-22 18:29 - 000003884 _ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-04-11 01:20 - 2022-01-22 18:29 - 000003760 _ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2023-04-11 00:38 - 2020-09-23 21:05 - 000000000 ____D C:\Users\Adrián\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2023-04-10 14:39 - 2021-08-31 16:55 - 000002057 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2023-04-10 14:39 - 2021-08-31 16:55 - 000001899 _ C:\Users\Default\Desktop\Google Slides.lnk
2023-04-10 14:39 - 2021-08-31 16:55 - 000001899 _ C:\Users\Default\Desktop\Google Sheets.lnk
2023-04-10 14:39 - 2021-08-31 16:55 - 000001887 _ C:\Users\Default\Desktop\Google Docs.lnk
2023-04-07 17:49 - 2022-01-22 18:29 - 000003690 _ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-04-07 17:49 - 2022-01-22 18:29 - 000003566 _ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-04-07 17:49 - 2020-10-25 11:37 - 000002236 _ C:\Users\Adrián\Desktop\Discord.lnk
2023-04-05 18:39 - 2020-06-14 01:45 - 000000000 ____D C:\Users\Adrián\AppData\Local\NVIDIA
2023-03-27 18:19 - 2021-11-29 14:19 - 000000000 ____D C:\Program Files (x86)\Overwolf
2023-03-23 19:39 - 2021-06-05 14:10 - 000000000 ___HD C:\Program Files\WindowsApps
2023-03-19 20:50 - 2022-11-26 21:15 - 000079352 _ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2023-03-19 20:50 - 2022-11-26 21:15 - 000062928 _ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2023-03-19 20:50 - 2021-12-03 18:02 - 002786768 _ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000476624 _ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000243200 _ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000202192 _ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000165328 _ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000131072 _ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2023-03-15 03:12 - 2022-01-22 18:29 - 000004308 C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003976 C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003940 C:\WINDOWS\system32\Tasks\NvNodeLauncher{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003894 C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003654 C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2023-03-15 03:12 - 2020-06-14 13:50 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2023-03-15 03:12 - 2020-06-14 04:12 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2023-03-15 03:12 - 2020-06-14 04:12 - 000000000 ____D C:\Program Files\NVIDIA Corporation

==================== Fichiers Ă  la racine de certains dossiers ========

2020-07-05 18:40 - 2020-07-05 18:43 - 006576161 _ () C:\Program Files (x86)\Common Files\forge-1.16.1-32.0.20-installer.jar
2020-07-01 19:15 - 2020-07-05 18:46 - 005322161 _ () C:\Program Files (x86)\Common Files\OptiFine_1.16_HD_U_H1.jar
2021-04-02 14:33 - 2021-04-02 14:37 - 000012288 _ () C:\Users\Adrián\AppData\Roaming\emp.bin
2022-02-07 14:36 - 2023-02-13 20:17 - 000000128 _ () C:\Users\Adrián\AppData\Local\PUTTY.RND
2020-06-14 04:20 - 2021-08-06 19:08 - 000007604 _ () C:\Users\Adrián\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

==================== Fin de FRST.txt ========================
 
#4 ·
Oh sorry didn't expect that ! Here it should be fine now, thank you for the fast answer !! And maybe I forgot to mention that I cannot access the BiOS on my computer anymore because they ask me for a password that I don't have and never had to put in order to access the BiOS it's weird

FRST in english:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-04-2023 02
Ran by Adrián (administrator) on DESKTOP-MIFQ18R (ASUS System Product Name) (13-04-2023 19:30:46)
Running from C:\Users\Adrián\Downloads\FRSTEnglish.exe
Loaded Profiles: Adrián
Platform: Microsoft Windows 11 Professionnel Version 21H2 22000.1574 (X64) Language: Français (France)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.202\GoogleCrashHandler.exe
(C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.202\GoogleCrashHandler64.exe
(C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe ->) (Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <5>
(C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe ->) (ASUSTEK COMPUTER INCORPORATION -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.UserSessionHelper.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe
(C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <49>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\LightingService.exe
(services.exe ->) (ASUSTEK COMPUTER INCORPORATION -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\gamingservices.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2>
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(services.exe ->) (Virtual Desktop, Inc. -> Virtual Desktop, Inc.) C:\Program Files\Virtual Desktop\VirtualDesktop.Service.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ) C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x86.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\AacExtCard\extensionCardHal_x86.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS_Aac_DRAM\Aac3572DramHal_x86.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(svchost.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SteelSeriesGG] => C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe [12692160 2022-05-13] (SteelSeries ApS -> SteelSeries ApS)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4361576 2023-04-07] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [LGHUB] => C:\Program Files\LGHUB\lghub.exe [146944768 2022-07-29] (Logitech Inc -> Logitech, Inc.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [49958368 2022-02-01] (Google LLC -> )
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1784664 2023-03-14] (Overwolf Ltd -> Overwolf Ltd.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [Battle.net] => D:\Battle.net\Battle.net.exe [1087376 2021-12-21] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [EADM] => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart (No File)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKLM\...\Windows x64\Print Processors\Canon MP630 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD9C.DLL [27648 2008-04-21] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MP630 series: C:\Windows\system32\CNMLM9C.DLL [279040 2008-04-21] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\111.0.5563.147\Installer\chrmstp.exe [2023-03-31] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
AppInit_DLLs: C:\PROGRA~1\VIRTUA~1\VIRTUA~4.DLL => C:\Program Files\Virtual Desktop Streamer\VirtualDesktop.Injector64.dll [132520 2021-03-04] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0735A24B-E894-4180-9329-1C972A0B6173} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {11EE1835-15A4-4E09-8633-866179ED55C4} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2FD37739-F52E-4C52-9EB1-9A13D83C9BBB} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-01-27] (Nvidia Corporation -> NVIDIA Corporation)
Task: {372A8A8C-BAEA-4A63-9804-163F1D52A2DD} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4518E052-3509-4846-9B65-645D1B0B0A18} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {45B15C20-259C-4353-9BFB-90E80E00D7F5} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-15] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {5373AAA2-7895-4B12-8A1F-F102F8C42EDA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-06-14] (Google LLC -> Google LLC)
Task: {55DAA2DD-C09C-4C7B-B54A-E604132B4AE7} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [115464 2021-12-17] (ASUSTeK Computer Inc. -> ASUS)
Task: {595C82F3-D65E-46DE-B133-1F68B59759FA} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2638856 2023-03-14] (Overwolf Ltd -> Overwolf LTD)
Task: {6EF54466-3128-4CA4-BC10-420D39A368B3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {70D890C4-3797-48B2-BE62-B4E9E19298CD} - System32\Tasks\Microsoft\Windows\WaaSMedic\DeferredWork => {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32}
Task: {77231B27-B153-4DAB-AE82-E83D1F52DF67} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {79B3C747-41F6-4A1F-AADA-8FDB2BCABFB1} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe [49048864 2020-03-16] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {80148F75-235B-415B-BFFA-7D40D050FDBB} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {8CAA5EAB-7360-4CEA-8A29-C82763C3ADD3} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {968AA82D-0B95-4416-9CCC-7B182367D2D7} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A8518B53-C1D3-4A60-804A-24818151E8C9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B3AA668D-E85E-425C-A2CB-F11664F8B974} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B6E87EF6-AC5B-43DD-84BD-4A3AB20D9A63} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {BD824950-39DD-44EF-9B26-A86A06DECF66} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C4BD17DB-E7AB-4294-AE78-B32B53D88CC2} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe [2248120 2021-12-17] (ASUSTeK Computer Inc. -> ASUS)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (No File)
Task: {F12561EC-C9C9-444E-B2EE-EFE2F06E9B9F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-06-14] (Google LLC -> Google LLC)
Task: {F6512D8F-108E-4A26-BC87-5599BEBC2C23} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d641f088e22505 => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{722b5480-08ce-4eea-9418-78ce2e0dfce5}: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{bd361947-815d-443a-8784-71534a032b8a}: [DhcpNameServer] 192.168.1.1

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Adrián\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-13]

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.311.2 -> C:\Program Files\Java\jre1.8.0_311\bin\dtplugin\npDeployJava1.dll [2021-12-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.311.2 -> C:\Program Files\Java\jre1.8.0_311\bin\plugin2\npjp2.dll [2021-12-03] (Oracle America, Inc. -> Oracle Corporation)

Chrome:
=======
CHR Profile: C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default [2023-04-13]
CHR Notifications: Default -> hxxps://www.facebook.com
CHR Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2023-03-09]
CHR Extension: (Google Docs hors connexion) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-04-06]
CHR Extension: (Lanceur d'applications pour Drive (par Google)) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-01-26]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30]
CHR HKLM\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKLM\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ArmouryCrateService; C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe [349408 2022-01-22] (ASUSTEK COMPUTER INCORPORATION -> ASUSTeK COMPUTER INC.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe [457544 2021-10-21] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [179488 2021-09-16] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.)
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 AsusUpdateCheck; C:\WINDOWS\System32\AsusUpdateCheck.exe [1191552 2023-04-13] (ASUSTeK Computer Inc. -> )
S3 EAAntiCheatService; C:\Program Files\EA\AC\eaanticheat.gameservice.exe [57017864 2022-12-06] (Electronic Arts, Inc. -> )
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [11027048 2023-04-13] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811496 2022-12-05] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [584680 2022-08-15] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029456 2022-07-04] (Epic Games Inc. -> Epic Games, Inc.)
R2 GamingServices; C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\GamingServices.exe [75216 2023-03-19] (Microsoft Corporation -> )
R2 GamingServicesNet; C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe [75216 2023-03-19] (Microsoft Corporation -> )
R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [10876672 2022-07-29] (Logitech Inc -> Logitech, Inc.)
R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [3683496 2021-11-24] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
S3 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2638856 2023-03-14] (Overwolf Ltd -> Overwolf LTD)
S3 OVRLibraryService; C:\Program Files\Oculus\Support\oculus-librarian\OVRLibraryService.exe [148024 2023-02-23] (Oculus VR, LLC -> Facebook Technologies, LLC)
R2 OVRService; C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe [514616 2023-02-23] (Oculus VR, LLC -> Facebook Technologies, LLC)
S3 Rockstar Service; D:\Program Files\Rockstar Games\Launcher\RockstarService.exe [2584528 2022-04-05] (Rockstar Games, Inc. -> Rockstar Games)
R2 ROG Live Service; C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe [6101680 2021-12-17] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [245216 2023-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 SteelSeriesUpdateService; C:\Program Files\SteelSeries\GG\SteelSeriesUpdateService.exe [32960 2022-05-13] (SteelSeries ApS -> )
S3 Updater; C:\Program Files\Virtual Desktop Streamer\Updater.exe [1122216 2021-03-04] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)
R2 VirtualDesktop.Service.exe; C:\Program Files\Virtual Desktop\VirtualDesktop.Service.exe [1962920 2020-12-01] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\NisSrv.exe [3170576 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MsMpEng.exe [133584 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [34384 2021-10-21] (ASUSTeK Computer Inc. -> )
R1 Asusgio3; C:\Windows\system32\drivers\AsIO3.sys [43192 2021-09-16] (ASUSTeK Computer Inc. -> )
S3 atvi-brynhildr; C:\ProgramData\Battle.net_components\brynhildr_odin\brynhildr.sys [2355952 2021-12-21] (Activision Publishing Inc -> Activision Blizzard, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [507904 2022-01-22] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [180224 2022-01-22] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [98304 2021-06-05] (Microsoft Corporation) [File not signed]
R1 CTIIO; C:\WINDOWS\system32\drivers\CtiIo64.sys [30728 2022-01-22] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
R1 GLCKIO2; C:\Windows\system32\drivers\GLCKIO2.sys [29368 2019-04-24] (ASUSTeK Computer Inc. -> )
R1 googledrivefs31092; C:\WINDOWS\System32\DRIVERS\googledrivefs31092.sys [384600 2023-02-08] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [46728 2021-06-28] (ASUSTEK COMPUTER INC. -> ASUSTeK Computer Inc.)
R3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [33528 2022-03-24] (WDKTestCert builder,132743893872553407 -> Logitech)
S3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [21704 2022-03-24] (WDKTestCert builder,132743893872553407 -> Logitech)
R3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [62904 2022-03-24] (WDKTestCert builder,132743893872553407 -> Logitech)
R3 MpKsl80b62f97; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{12815B20-1960-4D08-8880-F5E60B7479C6}\MpKslDrv.sys [211208 2023-04-13] (Microsoft Windows -> Microsoft Corporation)
R1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation)
R3 oculusvad_oculusvad; C:\WINDOWS\System32\drivers\oculusvad.sys [75280 2021-11-08] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 Oculus_ViGEmBus; C:\WINDOWS\System32\drivers\Oculus_ViGEmBus.sys [32856 2020-09-19] (Oculus VR, LLC -> Facebook Inc.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R3 rtwlane_13; C:\WINDOWS\System32\drivers\rtwlane_13.sys [3717120 2021-06-01] (Microsoft Windows -> Realtek Semiconductor Corporation)
R3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [48848 2020-12-21] (SteelSeries ApS -> SteelSeries ApS)
R3 SteelSeries_Sonar_VAD; C:\WINDOWS\System32\DriverStore\FileRepository\steelseries-sonar-vad.inf_amd64_6f6e907eca1efa31\SteelSeries-Sonar-VAD.sys [89568 2022-03-23] (SteelSeries ApS -> Windows (R) Win 7 DDK provider)
S3 TPS65994; C:\WINDOWS\System32\drivers\TPS65994.sys [49232 2019-12-24] (FPT USA Corp. -> )
R3 vdvad_WaveExtensible; C:\WINDOWS\System32\drivers\vdvad.sys [41072 2019-03-14] (Virtual Desktop, Inc. -> Virtual Desktop)
R3 vdvge; C:\WINDOWS\System32\drivers\vdvge.sys [77864 2018-11-13] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49616 2022-10-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [455968 2022-10-19] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [95520 2022-10-19] (Microsoft Windows -> Microsoft Corporation)
S3 EAAntiCheat; system32\drivers\eaanticheat.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-04-13 18:49 - 2023-04-13 19:31 - 000026768 _ C:\Users\Adrián\Downloads\FRST.txt
2023-04-13 18:49 - 2023-04-13 19:31 - 000000000 ____D C:\FRST
2023-04-13 18:46 - 2023-04-13 18:47 - 002380288 _ (Farbar) C:\Users\Adrián\Downloads\FRSTEnglish.exe
2023-04-11 20:46 - 2023-04-11 20:46 - 000000000 ___HD C:\$WinREAgent
2023-04-11 15:28 - 2023-04-11 15:28 - 000000000 ____D C:\Users\Adrián\AppData\Roaming\EA
2023-04-11 15:28 - 2023-04-11 15:28 - 000000000 ____D C:\Program Files\EA
2023-04-11 15:21 - 2023-04-11 15:21 - 000000839 _ C:\Users\Public\Desktop\FIFA 23.lnk
2023-04-11 14:47 - 2023-04-11 15:11 - 000000000 ____D C:\ProgramData\EA Desktop
2023-04-11 14:47 - 2023-04-11 14:47 - 002048920 _ (Electronic Arts) C:\Users\Adrián\Downloads\EAappInstaller.exe
2023-04-11 14:47 - 2023-04-11 14:47 - 000000000 ____D C:\Users\Adrián\AppData\Local\Origin
2023-04-11 14:20 - 2023-04-11 14:20 - 000004040 _ C:\WINDOWS\system32\Tasks\PostponeDeviceSetupToast_S-1-5-21-3254008329-1205757616-3926439971-1001_2
2023-04-10 01:00 - 2023-04-10 01:00 - 000001040 _ C:\Users\Public\Desktop\Les Sims 4.lnk
2023-04-10 01:00 - 2023-04-10 00:53 - 000447752 _ (On2.com) C:\WINDOWS\SysWOW64\vp6vfw.dll
2023-04-09 22:12 - 2023-04-09 22:12 - 000000000 ____D C:\Users\Adrián\AppData\Local\Yandex
2023-04-03 21:25 - 2023-04-03 21:25 - 000000000 ____D C:\Users\Adrián\AppData\LocalLow\Cyanide
2023-04-03 21:24 - 2023-04-03 21:24 - 000000223 _ C:\Users\Adrián\Desktop\Chef Life A Restaurant Simulator.url
2023-03-21 19:37 - 2023-03-21 19:37 - 000000222 _ C:\Users\Adrián\Desktop\Rocket League.url
2023-03-19 20:50 - 2023-03-19 20:50 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2023-03-19 20:50 - 2023-03-19 20:50 - 000000000 ____D C:\Program Files (x86)\Microsoft GameInput
2023-03-15 03:23 - 2023-03-09 09:57 - 002172512 _ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 002172512 _ C:\WINDOWS\system32\vulkaninfo.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 001607776 _ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 001607776 _ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 001487336 _ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001479264 _ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001479264 _ C:\WINDOWS\system32\vulkan-1.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001226736 _ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001211488 _ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001211488 _ C:\WINDOWS\SysWOW64\vulkan-1.dll
2023-03-15 03:23 - 2023-03-09 09:54 - 000671744 _ C:\WINDOWS\system32\nvofapi64.dll
2023-03-15 03:23 - 2023-03-09 09:54 - 000506344 _ C:\WINDOWS\SysWOW64\nvofapi.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 001534448 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 001192960 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 000851432 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 000741360 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2023-03-15 03:23 - 2023-03-09 09:52 - 002163736 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2023-03-15 03:23 - 2023-03-09 09:52 - 001620016 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2023-03-15 03:23 - 2023-03-09 09:52 - 000977944 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2023-03-15 03:23 - 2023-03-09 09:52 - 000758272 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 013765632 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 011645952 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 003430400 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 000457752 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2023-03-15 03:23 - 2023-03-09 09:50 - 006084136 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2023-03-15 03:23 - 2023-03-09 09:50 - 005911600 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2023-03-15 03:23 - 2023-03-09 09:50 - 005835312 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2023-03-15 03:23 - 2023-03-09 09:50 - 000852976 _ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2023-03-15 03:23 - 2023-03-08 13:17 - 000104256 _ C:\WINDOWS\system32\nvinfo.pb
2023-03-15 03:12 - 2022-07-14 01:32 - 000060112 _ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-04-13 19:31 - 2021-02-24 17:05 - 000000000 ____D C:\Users\Adrián\AppData\Local\CrashDumps
2023-04-13 19:31 - 2020-06-14 04:12 - 000000000 ____D C:\Program Files (x86)\Steam
2023-04-13 19:30 - 2022-01-22 18:19 - 000000000 ____D C:\Users\Adrián
2023-04-13 19:30 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-04-13 19:30 - 2021-06-05 14:10 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-04-13 19:30 - 2020-06-18 22:33 - 000000000 ____D C:\ProgramData\NVIDIA
2023-04-13 19:30 - 2020-06-14 05:33 - 000000000 ____D C:\Users\Adrián\AppData\Local\Oculus
2023-04-13 19:30 - 2020-06-14 04:07 - 000000000 ____D C:\Program Files (x86)\Google
2023-04-13 19:29 - 2022-01-22 18:29 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-04-13 19:29 - 2022-01-22 18:17 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-04-13 19:29 - 2020-06-14 02:34 - 001230088 _ C:\WINDOWS\system32\wpbbin.exe
2023-04-13 19:29 - 2020-06-14 02:34 - 001191552 _ C:\WINDOWS\system32\AsusUpdateCheck.exe
2023-04-13 19:29 - 2020-06-14 02:34 - 000012288 ___SH C:\DumpStack.log.tmp
2023-04-13 19:13 - 2020-10-25 11:40 - 000000000 ____D C:\Users\Adrián\AppData\Roaming\discord
2023-04-13 19:10 - 2020-10-25 11:40 - 000000000 ____D C:\Users\Adrián\AppData\Local\Discord
2023-04-13 18:52 - 2021-06-05 14:09 - 000000000 ____D C:\WINDOWS\INF
2023-04-13 18:23 - 2020-06-14 03:57 - 000000000 ____D C:\Users\Adrián\AppData\Local\D3DSCache
2023-04-11 20:50 - 2021-06-05 14:01 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-04-11 15:21 - 2022-06-20 18:12 - 000000000 ___HD C:\Program Files\Common Files\EAInstaller
2023-04-11 15:12 - 2022-01-22 18:32 - 002702328 _ C:\WINDOWS\system32\PerfStringBackup.INI
2023-04-11 15:12 - 2022-01-22 17:58 - 000745774 _ C:\WINDOWS\system32\perfh007.dat
2023-04-11 15:12 - 2022-01-22 17:58 - 000155996 _ C:\WINDOWS\system32\perfc007.dat
2023-04-11 15:12 - 2021-06-05 20:15 - 000806506 _ C:\WINDOWS\system32\perfh00C.dat
2023-04-11 15:12 - 2021-06-05 20:15 - 000156164 _ C:\WINDOWS\system32\perfc00C.dat
2023-04-11 15:05 - 2021-06-05 14:01 - 000524288 _ C:\WINDOWS\system32\config\BBI
2023-04-11 14:47 - 2023-02-06 20:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2023-04-11 14:47 - 2023-02-06 20:32 - 000000000 ____D C:\Program Files\Electronic Arts
2023-04-11 14:47 - 2020-06-14 04:14 - 000000000 ____D C:\ProgramData\Origin
2023-04-11 14:47 - 2020-06-14 04:07 - 000000000 ____D C:\ProgramData\Package Cache
2023-04-11 14:46 - 2020-06-14 04:59 - 000000000 ____D C:\Program Files (x86)\Origin Games
2023-04-11 14:29 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-04-11 13:16 - 2022-01-22 18:29 - 000003592 _ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3254008329-1205757616-3926439971-1001
2023-04-11 13:16 - 2022-01-22 18:29 - 000003382 _ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3254008329-1205757616-3926439971-1001
2023-04-11 13:16 - 2021-08-25 12:44 - 000002424 _ C:\Users\Adrián\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-04-11 01:20 - 2022-01-22 18:29 - 000003884 _ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-04-11 01:20 - 2022-01-22 18:29 - 000003760 _ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2023-04-11 00:38 - 2020-09-23 21:05 - 000000000 ____D C:\Users\Adrián\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2023-04-10 14:39 - 2021-08-31 16:55 - 000002057 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2023-04-10 14:39 - 2021-08-31 16:55 - 000001899 _ C:\Users\Default\Desktop\Google Slides.lnk
2023-04-10 14:39 - 2021-08-31 16:55 - 000001899 _ C:\Users\Default\Desktop\Google Sheets.lnk
2023-04-10 14:39 - 2021-08-31 16:55 - 000001887 _ C:\Users\Default\Desktop\Google Docs.lnk
2023-04-07 17:49 - 2022-01-22 18:29 - 000003690 _ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-04-07 17:49 - 2022-01-22 18:29 - 000003566 _ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-04-07 17:49 - 2020-10-25 11:37 - 000002236 _ C:\Users\Adrián\Desktop\Discord.lnk
2023-04-05 18:39 - 2020-06-14 01:45 - 000000000 ____D C:\Users\Adrián\AppData\Local\NVIDIA
2023-03-27 18:19 - 2021-11-29 14:19 - 000000000 ____D C:\Program Files (x86)\Overwolf
2023-03-23 19:39 - 2021-06-05 14:10 - 000000000 ___HD C:\Program Files\WindowsApps
2023-03-19 20:50 - 2022-11-26 21:15 - 000079352 _ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2023-03-19 20:50 - 2022-11-26 21:15 - 000062928 _ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2023-03-19 20:50 - 2021-12-03 18:02 - 002786768 _ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000476624 _ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000243200 _ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000202192 _ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000165328 _ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000131072 _ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2023-03-15 03:12 - 2022-01-22 18:29 - 000004308 C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003976 C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003940 C:\WINDOWS\system32\Tasks\NvNodeLauncher{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003894 C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003654 C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2023-03-15 03:12 - 2020-06-14 13:50 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2023-03-15 03:12 - 2020-06-14 04:12 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2023-03-15 03:12 - 2020-06-14 04:12 - 000000000 ____D C:\Program Files\NVIDIA Corporation

==================== Files in the root of some directories ========

2020-07-05 18:40 - 2020-07-05 18:43 - 006576161 _ () C:\Program Files (x86)\Common Files\forge-1.16.1-32.0.20-installer.jar
2020-07-01 19:15 - 2020-07-05 18:46 - 005322161 _ () C:\Program Files (x86)\Common Files\OptiFine_1.16_HD_U_H1.jar
2021-04-02 14:33 - 2021-04-02 14:37 - 000012288 _ () C:\Users\Adrián\AppData\Roaming\emp.bin
2022-02-07 14:36 - 2023-02-13 20:17 - 000000128 _ () C:\Users\Adrián\AppData\Local\PUTTY.RND
2020-06-14 04:20 - 2021-08-06 19:08 - 000007604 _ () C:\Users\Adrián\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
 

Attachments

#5 ·
No real signs of an active infection in your logs. However a few things that could do with attention ...

First ...

Please uninstall the following Chrome Extensions ...

CHR HKLM\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKLM\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]


Next ...

  • Start FRST.
  • Hit your Windows Key + R to open a Run window
  • Type Notepad then click OK
  • This will open an empty Notepad document
  • Copy/Paste the following into it (Don't include Code: ) .....
Code:
FirewallRules: [{E3C20326-E80D-431E-BFB2-69F31CC658F6}] => (Allow) D:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe => No File
FirewallRules: [{42FA6174-0B14-42C9-AF84-21E9CF867FB6}] => (Allow) D:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe => No File
FirewallRules: [{63244C77-6974-4EBF-840E-2812AE046DD3}] => (Allow) D:\SteamLibrary\steamapps\common\Kukui 2 Demo\Kukui2.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{D5135B26-DFA3-4165-96B5-D4AF29EBE4AD}] => (Allow) D:\SteamLibrary\steamapps\common\Kukui 2 Demo\Kukui2.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{83105D6F-1D5B-469A-93B8-A1E44FA7882F}] => (Allow) D:\SteamLibrary\steamapps\common\Ikai Demo\Ikai.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{4D590132-4EBF-4337-9F31-2545B03F1D9A}] => (Allow) D:\SteamLibrary\steamapps\common\Ikai Demo\Ikai.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{5CAD990C-4768-4CBF-A2CB-6C68F52E4926}] => (Allow) D:\SteamLibrary\steamapps\common\What Never Was\WhatNeverWas.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{16088590-9FDF-4AAC-8584-8844E8484DFD}] => (Allow) D:\SteamLibrary\steamapps\common\What Never Was\WhatNeverWas.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{BDB7D2ED-659D-4AD2-8186-E0FFE67C1621}] => (Allow) D:\SteamLibrary\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [{AC511FDF-8F88-4DD8-A446-07E659671EEC}] => (Allow) D:\SteamLibrary\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [{9ED778E0-9668-4FA8-B01C-788371BEAD2A}] => (Allow) D:\SteamLibrary\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [{06DFA6D5-AF15-4262-B23E-77C5E81A18CA}] => (Allow) D:\SteamLibrary\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [UDP Query User{029FC0C6-0B8E-4023-B9A6-FECCDC4F68BD}D:\programmes (x86)\call of duty modern warfare\modernwarfare.exe] => (Allow) D:\programmes (x86)\call of duty modern warfare\modernwarfare.exe => No File
FirewallRules: [TCP Query User{52F0E687-63CC-4547-83FC-C5A27FE1A0F2}D:\programmes (x86)\call of duty modern warfare\modernwarfare.exe] => (Allow) D:\programmes (x86)\call of duty modern warfare\modernwarfare.exe => No File
FirewallRules: [{4F8D1434-51F5-48F1-BB4B-27B49EA6E673}] => (Allow) D:\SteamLibrary\steamapps\common\Valheim\valheim.exe () [File not signed]
FirewallRules: [{B3F9D4A9-68D9-43E6-8C32-DC8EC2EDA1B8}] => (Allow) D:\SteamLibrary\steamapps\common\Valheim\valheim.exe () [File not signed]
FirewallRules: [{B1B98AD9-E29D-4DF6-8D1A-483AB70C0D03}] => (Allow) D:\SteamLibrary\steamapps\common\Phasmophobia\Phasmophobia.exe () [File not signed]
FirewallRules: [{6375D95F-4399-4DEA-A091-1BA74B070137}] => (Allow) D:\SteamLibrary\steamapps\common\Phasmophobia\Phasmophobia.exe () [File not signed]
FirewallRules: [{AB93D9CC-1AA8-41D2-A5C9-1DC35D2E7781}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VRChat\VRChat.exe () [File not signed]
FirewallRules: [{46030151-0B9E-4A75-AC6D-5DAB1078C46C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VRChat\VRChat.exe () [File not signed]
FirewallRules: [{BF76020C-D5AE-4719-A2AC-27F3E6AEED84}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crab Game\Crab Game.exe () [File not signed]
FirewallRules: [{8679A5C0-CC1D-4FA0-B82B-D9C0C5E6BBF2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crab Game\Crab Game.exe () [File not signed]
FirewallRules: [{80611E62-7C70-4905-9F01-C65173B6FFB9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SCP Labrat\SCP Labrat.exe () [File not signed]
FirewallRules: [{EF29D8A4-1A77-4AED-A9E4-E67168600AD9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SCP Labrat\SCP Labrat.exe () [File not signed]
FirewallRules: [{80676016-69F2-40F7-BEC5-DCFB3850DDA3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe => No File
FirewallRules: [{573B3116-7067-404E-BA3E-21155418E552}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe => No File
FirewallRules: [UDP Query User{2E798C16-4D61-42EA-B152-7F631E89ED67}C:\program files (x86)\steam\steamapps\common\knockout city\knockoutcity.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\knockout city\knockoutcity.exe => No File
FirewallRules: [TCP Query User{89A933B2-15A3-4EF5-8502-058D08D6F624}C:\program files (x86)\steam\steamapps\common\knockout city\knockoutcity.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\knockout city\knockoutcity.exe => No File
FirewallRules: [UDP Query User{627F1DF3-B582-4AF9-8F08-D37124ADFA8B}C:\program files (x86)\steam\steamapps\common\knockoutcity\knockoutcity.exe] => (Block) C:\program files (x86)\steam\steamapps\common\knockoutcity\knockoutcity.exe => No File
FirewallRules: [TCP Query User{E78CFB1A-7D8A-4936-AFB5-E4F4808D9679}C:\program files (x86)\steam\steamapps\common\knockoutcity\knockoutcity.exe] => (Block) C:\program files (x86)\steam\steamapps\common\knockoutcity\knockoutcity.exe => No File
FirewallRules: [UDP Query User{093F2391-2F14-46EB-8815-33D5D3A431D4}C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe] => (Allow) C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe => No File
FirewallRules: [TCP Query User{FAC8EB69-80B2-4B7E-8DF2-BE9399E27B48}C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe] => (Allow) C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe => No File
FirewallRules: [{3C43AF91-6F38-45BA-ABF0-AD3672F46BB3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life is Strange 2\LIS2\Binaries\Win64\LIS2-Win64-Shipping.exe (Square Enix) [File not signed]
FirewallRules: [{9882FEBD-41C1-429A-B915-528D59F176C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life is Strange 2\LIS2\Binaries\Win64\LIS2-Win64-Shipping.exe (Square Enix) [File not signed]
FirewallRules: [UDP Query User{875C3088-1D22-4D79-946F-93438A6F67B9}C:\users\adrián\appdata\local\temp\pmstart.exe] => (Block) C:\users\adrián\appdata\local\temp\pmstart.exe => No File
FirewallRules: [TCP Query User{6D7EB602-24CD-4CD4-AB51-8C9CED1AA6EE}C:\users\adrián\appdata\local\temp\pmstart.exe] => (Block) C:\users\adrián\appdata\local\temp\pmstart.exe => No File
FirewallRules: [UDP Query User{CA72BE29-5AD3-43D9-A719-13776EC11EDC}C:\users\adrián\downloads\agfy-welcome.to.the.game.ii\welcome to the game ii\wttg2.exe] => (Allow) C:\users\adrián\downloads\agfy-welcome.to.the.game.ii\welcome to the game ii\wttg2.exe => No File
FirewallRules: [TCP Query User{0EB29676-E2FA-4610-ACC0-AE278443B4F5}C:\users\adrián\downloads\agfy-welcome.to.the.game.ii\welcome to the game ii\wttg2.exe] => (Allow) C:\users\adrián\downloads\agfy-welcome.to.the.game.ii\welcome to the game ii\wttg2.exe => No File
FirewallRules: [UDP Query User{03390C60-6A9F-4E83-8A8B-6252108EF031}C:\users\adrián\downloads\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\downloads\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [TCP Query User{5CC6038B-3834-4701-BC26-DA113C849AD7}C:\users\adrián\downloads\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\downloads\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [UDP Query User{4374A818-7D01-42F4-BC96-13EC90067797}C:\users\adrián\appdata\local\temp\rar$exa404.1216\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\appdata\local\temp\rar$exa404.1216\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [TCP Query User{26F76958-B62B-4F01-8D46-0908F6D42F4D}C:\users\adrián\appdata\local\temp\rar$exa404.1216\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\appdata\local\temp\rar$exa404.1216\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [UDP Query User{2DF95CFE-EB8C-400A-A9B2-597B1817E099}C:\users\adrián\downloads\agfy-planet.zoo\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\downloads\agfy-planet.zoo\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [TCP Query User{B75B35B2-56C9-4AF4-907B-3B01C79CC11D}C:\users\adrián\downloads\agfy-planet.zoo\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\downloads\agfy-planet.zoo\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [{E4695B73-FF4C-4E74-BA76-7F8569A4F5B4}] => (Allow) C:\Games\Steam Library\steamapps\common\VRChat\VRChat.exe => No File
FirewallRules: [{201932D7-160B-4393-9215-33AB5DDB1865}] => (Allow) C:\Games\Steam Library\steamapps\common\VRChat\VRChat.exe => No File
FirewallRules: [UDP Query User{E3B91AFB-B5AB-452F-95AA-DF6E479A863F}C:\users\adrián\downloads\agfy-beat.saber.v1.9.0.all.dlc\agfy-beat.saber.v1.9.0.all.dlc\beat saber\beat saber.exe] => (Allow) C:\users\adrián\downloads\agfy-beat.saber.v1.9.0.all.dlc\agfy-beat.saber.v1.9.0.all.dlc\beat saber\beat saber.exe => No File
FirewallRules: [TCP Query User{76B1AD56-8875-48BA-A788-8AD8E2632009}C:\users\adrián\downloads\agfy-beat.saber.v1.9.0.all.dlc\agfy-beat.saber.v1.9.0.all.dlc\beat saber\beat saber.exe] => (Allow) C:\users\adrián\downloads\agfy-beat.saber.v1.9.0.all.dlc\agfy-beat.saber.v1.9.0.all.dlc\beat saber\beat saber.exe => No File
FirewallRules: [{0629661C-DBFF-4DE2-B5A3-F4C983EC7F8B}] => (Allow) C:\Games\Steam Library\steamapps\common\Gorilla Tag\Gorilla Tag.exe => No File
FirewallRules: [{D1908F0B-E282-4901-914C-AB5CCBBA866C}] => (Allow) C:\Games\Steam Library\steamapps\common\Gorilla Tag\Gorilla Tag.exe => No File
FirewallRules: [UDP Query User{9A778B8A-D91F-42D2-A367-366D9AB0591D}C:\games\steam library\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Allow) C:\games\steam library\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe => No File
FirewallRules: [TCP Query User{FC3C8AD6-48DE-454A-8482-9F8D981FD9D4}C:\games\steam library\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Allow) C:\games\steam library\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe => No File
FirewallRules: [{A33B01F1-F281-4E06-9D34-435BE2A0C7D6}] => (Allow) C:\Games\Steam Library\steamapps\common\PavlovVR\Pavlov.exe => No File
FirewallRules: [{F203D012-0A2B-4F0D-8F86-850FFB316C14}] => (Allow) C:\Games\Steam Library\steamapps\common\PavlovVR\Pavlov.exe => No File
FirewallRules: [{FF53EE2B-5D30-4EF2-BB40-22BCD831DBB7}] => (Allow) C:\Games\Steam Library\steamapps\common\Hunt Showdown\hunt.exe => No File
FirewallRules: [{C6FE9283-44AD-4C53-9AA0-5F98CAC15BF3}] => (Allow) C:\Games\Steam Library\steamapps\common\Hunt Showdown\hunt.exe => No File
FirewallRules: [{3F19E968-06AD-4F55-B5C4-6FF493C6F106}] => (Allow) C:\Games\Steam Library\steamapps\common\Valheim\valheim.exe => No File
FirewallRules: [{90B409FC-5AE1-46D4-AC96-4296CF5C6CF4}] => (Allow) C:\Games\Steam Library\steamapps\common\Valheim\valheim.exe => No File
FirewallRules: [{1231889A-C2F2-4A85-AF69-AE688B02402A}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe => No File
FirewallRules: [{EB260F1D-DF23-490E-B450-9F5048B1A3CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OVR_AdvancedSettings\AdvancedSettings.exe () [File not signed]
FirewallRules: [{B8073A49-3835-4415-B7AF-DBBE572E65B9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OVR_AdvancedSettings\AdvancedSettings.exe () [File not signed]
FirewallRules: [UDP Query User{4095A84A-0302-49AD-B841-6619F0CA99AA}C:\program files\epic games\gtav\gta5.exe] => (Allow) C:\program files\epic games\gtav\gta5.exe => No File
FirewallRules: [TCP Query User{72B7F466-6E5E-415B-9642-0BB055E4F1CE}C:\program files\epic games\gtav\gta5.exe] => (Allow) C:\program files\epic games\gtav\gta5.exe => No File
FirewallRules: [{C1C0E8CB-9326-4B83-AB66-FE39B0BE4DFE}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe (Oculus VR, LLC) [File not signed]
FirewallRules: [{C04A1C6B-E842-4F4E-8004-5A06D0A88B2C}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe (Oculus VR, LLC) [File not signed]
FirewallRules: [{5D571AA1-A950-4545-BA4B-8C61CB78341C}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Engine\Binaries\Win64\UnrealCEFSubProcess.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{86D8797B-7C08-40A0-9B8D-62853E0B720A}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Engine\Binaries\Win64\UnrealCEFSubProcess.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{696763C1-0CD0-4523-974E-43E39870F4A0}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{EB54494D-AFFA-4680-B63A-D76040A57E97}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{9836AD10-DE92-44F7-A866-CB10CA3D73C1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\RocketLeague.exe => No File
FirewallRules: [{4AD190F0-8B34-4B26-AC4E-CA605CF0697E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\RocketLeague.exe => No File
FirewallRules: [UDP Query User{CDCB6C2D-C562-451C-8D97-19B3D0A0C0C2}C:\program files (x86)\steam\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe => No File
FirewallRules: [TCP Query User{89CA186A-B0EA-481C-AE32-46DA2D81798B}C:\program files (x86)\steam\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe => No File
FirewallRules: [UDP Query User{B9639CE4-B3A1-4916-8912-BC35977C8CBB}C:\program files (x86)\steam\steamapps\common\for honor\forhonor.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\for honor\forhonor.exe => No File
FirewallRules: [TCP Query User{C4CDF850-0768-4B78-BC86-7E96C569D0D6}C:\program files (x86)\steam\steamapps\common\for honor\forhonor.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\for honor\forhonor.exe => No File
FirewallRules: [{CF88C3E4-DB59-4F56-861A-517555D25A5C}] => (Allow) C:\Users\Adrián\AppData\Local\Chromium\Application\chrome.exe => No File
FirewallRules: [{780E077E-D758-4E71-A9F2-6A357A4B1DFE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\RocketLeague.exe => No File
FirewallRules: [{000F22B5-6FFD-4827-8129-E5226FE3BCA6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\RocketLeague.exe => No File
FirewallRules: [UDP Query User{CBD5794E-3F16-4ED2-ABFA-007BDEDD44E3}C:\users\adrián\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\adrián\appdata\roaming\spotify\spotify.exe => No File
FirewallRules: [TCP Query User{CC642D35-ABA2-4B39-9A61-BE4D3BEFC344}C:\users\adrián\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\adrián\appdata\roaming\spotify\spotify.exe => No File
FirewallRules: [{47B0CD22-DFFC-4D6E-A7E6-17F140316632}] => (Allow) D:\SteamLibrary\steamapps\common\Dear Esther Landmark Edition\DearEsther.exe () [File not signed]
FirewallRules: [{BF23AB38-8C33-4AE0-9E0C-8DBC7DB16707}] => (Allow) D:\SteamLibrary\steamapps\common\Dear Esther Landmark Edition\DearEsther.exe () [File not signed]
FirewallRules: [{87FB9911-922C-4A50-A740-13FE4471E90F}] => (Allow) C:\Users\Adrián\AppData\Local\Chromium\Application\chrome.exe => No File
FirewallRules: [TCP Query User{E8E64319-D8DA-42DF-AE72-BBA3CDA03F6E}D:\steamlibrary\steamapps\common\kukui\kukui_pc\binaries\win64\kukui_pc-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\kukui\kukui_pc\binaries\win64\kukui_pc-win64-shipping.exe => No File
FirewallRules: [UDP Query User{D56C4393-C759-4D4A-8583-9BB83690C059}D:\steamlibrary\steamapps\common\kukui\kukui_pc\binaries\win64\kukui_pc-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\kukui\kukui_pc\binaries\win64\kukui_pc-win64-shipping.exe => No File
FirewallRules: [{AA527351-4CDA-438F-9C61-AD9374EC18D7}] => (Allow) D:\SteamLibrary\steamapps\common\ELDEN RING\Game\start_protected_game.exe => No File
FirewallRules: [{2AC2D687-8F4A-49A1-B598-1AC76FEA78A8}] => (Allow) D:\SteamLibrary\steamapps\common\ELDEN RING\Game\start_protected_game.exe => No File
FirewallRules: [{8B202764-EBB1-48BC-803F-2C3D86835C3C}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client.exe () [File not signed]
FirewallRules: [{F0B15C85-6327-46D3-AFD1-CEA5625189D5}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client.exe () [File not signed]
FirewallRules: [TCP Query User{9764BDC0-FEA9-41EE-BBBE-CA8BD6AB8476}D:\steamlibrary\steamapps\common\pandemic express\bin\win_x64\pandemicexpress.exe] => (Allow) D:\steamlibrary\steamapps\common\pandemic express\bin\win_x64\pandemicexpress.exe (tinyBuild LLC) [File not signed]
FirewallRules: [UDP Query User{D796E78F-FBFC-4D8A-A286-661FB4469CC9}D:\steamlibrary\steamapps\common\pandemic express\bin\win_x64\pandemicexpr
FirewallRules: [{8948EAA4-B7D4-49CA-9963-08125401A39A}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client_game.exe () [File not signed]
FirewallRules: [{C97CBFAA-0429-4999-A62B-09388BC06740}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client_game.exe () [File not signed]
FirewallRules: [TCP Query User{3669E2E5-4DC2-4BC3-8220-A5901DE86125}D:\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe (Vankrupt Games, Inc.) [File not signed]
FirewallRules: [UDP Query User{3810553E-F5DD-484A-9F7E-7F58AD7624E5}D:\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe (Vankrupt Games, Inc.) [File not signed]
FirewallRules: [TCP Query User{A637B39D-E5FD-4B06-8C3F-C4EA21FF0193}D:\a township tale\a township tale.exe] => (Allow) D:\a township tale\a township tale.exe () [File not signed]
FirewallRules: [UDP Query User{C0DE5151-1E97-4149-8F09-044D712E97CC}D:\a township tale\a township tale.exe] => (Allow) D:\a township tale\a township tale.exe () [File not signed]
FirewallRules: [TCP Query User{E84BD1AA-CA25-4380-A774-C32DFEFC7187}C:\users\adrián\appdata\local\temp\rar$exa5564.5375\fallendoll(extendeddemo1.26)(vr)\windowsnoeditor\fallendoll\binaries\win64\fallendoll.exe] => (Block) C:\users\adrián\appdata\local\temp\rar$exa5564.5375\fallendoll(extendeddemo1.26)(vr)\windowsnoeditor\fallendoll\binaries\win64\fallendoll.exe => No File
FirewallRules: [UDP Query User{D88CCDA9-97FC-4417-A727-8C8A6D5BC921}C:\users\adrián\appdata\local\temp\rar$exa5564.5375\fallendoll(extendeddemo1.26)(vr)\windowsnoeditor\fallendoll\binaries\win64\fallendoll.exe] => (Block) C:\users\adrián\appdata\local\temp\rar$exa5564.5375\fallendoll(extendeddemo1.26)(vr)\windowsnoeditor\fallendoll\binaries\win64\fallendoll.exe => No File
FirewallRules: [{98797C73-E238-4DD3-9BE0-F6F88B4D64BA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VRChat\launch.exe () [File not signed]
FirewallRules: [{E8F8569D-C989-41DA-8CB1-6C06A042F217}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VRChat\launch.exe () [File not signed]
FirewallRules: [{FD0B41E4-AA4C-4FA8-AFF5-387E3EE3CCD4}] => (Allow) D:\SteamLibrary\steamapps\common\RecRoom\Recroom_Release.exe (Epic Games, Inc) [File not signed]
FirewallRules: [{C2F1CBE8-EF2F-4357-B428-3B88035D3E81}] => (Allow) D:\SteamLibrary\steamapps\common\RecRoom\Recroom_Release.exe (Epic Games, Inc) [File not signed]
FirewallRules: [TCP Query User{BE959D89-E670-4C91-B5C6-7CFF75A86E36}D:\program files\secondlifeviewer\slvoice.exe] => (Allow) D:\program files\secondlifeviewer\slvoice.exe () [File not signed]
FirewallRules: [UDP Query User{297904DD-3BF3-4A98-A9ED-6EB1CC7D98E8}D:\program files\secondlifeviewer\slvoice.exe] => (Allow) D:\program files\secondlifeviewer\slvoice.exe () [File not signed]
FirewallRules: [{8E88243D-F84A-4ACF-958C-AFC9FDDB5B51}] => (Allow) D:\Program Files (x86)\Origin games\Battlefield V\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [{F3DC8B6C-2495-4116-B622-59609D73999B}] => (Allow) D:\Program Files (x86)\Origin games\Battlefield V\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [TCP Query User{772EA311-C4F0-4BD8-8D34-1D5973FA3F32}D:\program files (x86)\origin games\battlefield v\bfv.exe] => (Block) D:\program files (x86)\origin games\battlefield v\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [UDP Query User{7807736A-DF26-4AA6-B01D-041D2275B776}D:\program files (x86)\origin games\battlefield v\bfv.exe] => (Block) D:\program files (x86)\origin games\battlefield v\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [{22BA7263-312B-4A42-A46A-7689F43E6118}] => (Allow) D:\SteamLibrary\steamapps\common\No Man's Sky\Binaries\NMS.exe (Hello Games) [File not signed]
FirewallRules: [{7C809C9F-A87D-46D1-8B4B-6EFC7FCDFDA9}] => (Allow) D:\SteamLibrary\steamapps\common\No Man's Sky\Binaries\NMS.exe (Hello Games) [File not signed]
FirewallRules: [TCP Query User{305D85F9-4884-4CD4-97D9-1B340E55A939}D:\steamlibrary\steamapps\common\fifa 22\fifa22.exe] => (Block) D:\steamlibrary\steamapps\common\fifa 22\fifa22.exe => No File
FirewallRules: [UDP Query User{4038F98A-4485-4EE8-AD52-17D5A058D5AF}D:\steamlibrary\steamapps\common\fifa 22\fifa22.exe] => (Block) D:\steamlibrary\steamapps\common\fifa 22\fifa22.exe => No File
FirewallRules: [{53766F46-5B28-4EA6-8E68-1DD2B24C3A1B}] => (Allow) D:\SteamLibrary\steamapps\common\assettocorsa\AssettoCorsa.exe (Kunos Simulazioni) [File not signed]
FirewallRules: [{10E6DFB4-B6E8-4476-A804-240470AB71DA}] => (Allow) D:\SteamLibrary\steamapps\common\assettocorsa\AssettoCorsa.exe (Kunos Simulazioni) [File not signed]
FirewallRules: [TCP Query User{A875CED1-E76B-40CB-8808-A4B553709372}D:\steamlibrary\steamapps\common\assettocorsa\acs.exe] => (Allow) D:\steamlibrary\steamapps\common\assettocorsa\acs.exe () [File not signed]
FirewallRules: [UDP Query User{D26FB6F8-758F-4DD9-858D-B443D8BB5921}D:\steamlibrary\steamapps\common\assettocorsa\acs.exe] => (Allow) D:\steamlibrary\steamapps\common\assettocorsa\acs.exe () [File not signed]
FirewallRules: [TCP Query User{4D6CB43B-5623-4202-A0CF-A1B5CC485E2E}D:\steamlibrary\steamapps\common\star wars battlefront ii\starwarsbattlefrontii.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars battlefront ii\starwarsbattlefrontii.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [UDP Query User{6775F48C-3EF8-4AC2-964D-5AF9B2D43B19}D:\steamlibrary\steamapps\common\star wars battlefront ii\starwarsbattlefrontii.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars battlefront ii\starwarsbattlefrontii.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [{B08DEB2F-B9DC-4CD0-BBAB-536F195A7AEF}] => (Allow) D:\SteamLibrary\steamapps\common\Sons Of The Forest\SonsOfTheForest.exe () [File not signed]
FirewallRules: [{8EB2C9DC-E670-4E80-80BB-6472315A4798}] => (Allow) D:\SteamLibrary\steamapps\common\Sons Of The Forest\SonsOfTheForest.exe () [File not signed]
FirewallRules: [{0D06F2BE-26DA-4C8D-994D-1E3215F46F52}] => (Allow) D:\SteamLibrary\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe (Psyonix, LLC) [File not signed]
FirewallRules: [{A08EE456-6494-40B5-A8B4-70032B6EC19D}] => (Allow) D:\SteamLibrary\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe (Psyonix, LLC) [File not signed]
FirewallRules: [{2640AB01-D51C-427F-9ED1-9B15CCE806BD}] => (Allow) C:\Program Files (x86)\Overwolf\0.220.0.1\OverwolfBrowser.exe => No File
FirewallRules: [{0A0DF3A0-9A66-433D-BB11-10FE42D618ED}] => (Allow) C:\Program Files (x86)\Overwolf\0.220.0.1\OverwolfBrowser.exe => No File
FirewallRules: [{6665A718-4236-4DCB-BAEA-9B9A0E2E4673}] => (Block) C:\Program Files (x86)\Overwolf\0.220.0.1\OverwolfBrowser.exe => No File
FirewallRules: [{9F897F72-AEA3-4731-A52A-FF4EE5DB876A}] => (Block) C:\Program Files (x86)\Overwolf\0.220.0.1\OverwolfBrowser.exe => No File
FirewallRules: [{2FC5BF06-988C-478A-871A-8DD914D6B9F5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Chef LIFE  A Restaurant Simulator\Chef Life  A Restaurant Simulator.exe () [File not signed]
FirewallRules: [{51CDCBF3-94C8-46A4-8D2C-939D354DA4AA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Chef LIFE  A Restaurant Simulator\Chef Life  A Restaurant Simulator.exe () [File not signed]

EmptyTemp:
CMD: ipconfig /flushdns
  • Save it as fixlist.txt to the same location as FRST (must be in this location)
  • NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log

Next ...

Download ESET Online Scanner and save it to your desktop.
  • Right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET.
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply.
 
#6 ·
Thank you this is good news !

STEP 1
I tried uninstalling the 3 chrome extensions but I only managed to find the last one and didn't find these two:
CHR HKLM\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKLM\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]

I even tried uninstalling the chrome extensions manually, as explained on the website you linked, but only the last one and others with others names were on it.

STEP 2 (Fixlog.txt)
Fix result of Farbar Recovery Scan Tool (x64) Version: 13-04-2023 02
Ran by Adrián (14-04-2023 00:29:14) Run:1
Running from C:\Users\Adrián\Downloads
Loaded Profiles: Adrián
Boot Mode: Normal
==============================================

fixlist content:
*
FirewallRules: [{E3C20326-E80D-431E-BFB2-69F31CC658F6}] => (Allow) D:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe => No File
FirewallRules: [{42FA6174-0B14-42C9-AF84-21E9CF867FB6}] => (Allow) D:\Program Files\Rockstar Games\Red Dead Redemption 2\RDR2.exe => No File
FirewallRules: [{63244C77-6974-4EBF-840E-2812AE046DD3}] => (Allow) D:\SteamLibrary\steamapps\common\Kukui 2 Demo\Kukui2.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{D5135B26-DFA3-4165-96B5-D4AF29EBE4AD}] => (Allow) D:\SteamLibrary\steamapps\common\Kukui 2 Demo\Kukui2.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{83105D6F-1D5B-469A-93B8-A1E44FA7882F}] => (Allow) D:\SteamLibrary\steamapps\common\Ikai Demo\Ikai.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{4D590132-4EBF-4337-9F31-2545B03F1D9A}] => (Allow) D:\SteamLibrary\steamapps\common\Ikai Demo\Ikai.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{5CAD990C-4768-4CBF-A2CB-6C68F52E4926}] => (Allow) D:\SteamLibrary\steamapps\common\What Never Was\WhatNeverWas.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{16088590-9FDF-4AAC-8584-8844E8484DFD}] => (Allow) D:\SteamLibrary\steamapps\common\What Never Was\WhatNeverWas.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{BDB7D2ED-659D-4AD2-8186-E0FFE67C1621}] => (Allow) D:\SteamLibrary\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [{AC511FDF-8F88-4DD8-A446-07E659671EEC}] => (Allow) D:\SteamLibrary\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [{9ED778E0-9668-4FA8-B01C-788371BEAD2A}] => (Allow) D:\SteamLibrary\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [{06DFA6D5-AF15-4262-B23E-77C5E81A18CA}] => (Allow) D:\SteamLibrary\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [UDP Query User{029FC0C6-0B8E-4023-B9A6-FECCDC4F68BD}D:\programmes (x86)\call of duty modern warfare\modernwarfare.exe] => (Allow) D:\programmes (x86)\call of duty modern warfare\modernwarfare.exe => No File
FirewallRules: [TCP Query User{52F0E687-63CC-4547-83FC-C5A27FE1A0F2}D:\programmes (x86)\call of duty modern warfare\modernwarfare.exe] => (Allow) D:\programmes (x86)\call of duty modern warfare\modernwarfare.exe => No File
FirewallRules: [{4F8D1434-51F5-48F1-BB4B-27B49EA6E673}] => (Allow) D:\SteamLibrary\steamapps\common\Valheim\valheim.exe () [File not signed]
FirewallRules: [{B3F9D4A9-68D9-43E6-8C32-DC8EC2EDA1B8}] => (Allow) D:\SteamLibrary\steamapps\common\Valheim\valheim.exe () [File not signed]
FirewallRules: [{B1B98AD9-E29D-4DF6-8D1A-483AB70C0D03}] => (Allow) D:\SteamLibrary\steamapps\common\Phasmophobia\Phasmophobia.exe () [File not signed]
FirewallRules: [{6375D95F-4399-4DEA-A091-1BA74B070137}] => (Allow) D:\SteamLibrary\steamapps\common\Phasmophobia\Phasmophobia.exe () [File not signed]
FirewallRules: [{AB93D9CC-1AA8-41D2-A5C9-1DC35D2E7781}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VRChat\VRChat.exe () [File not signed]
FirewallRules: [{46030151-0B9E-4A75-AC6D-5DAB1078C46C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VRChat\VRChat.exe () [File not signed]
FirewallRules: [{BF76020C-D5AE-4719-A2AC-27F3E6AEED84}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crab Game\Crab Game.exe () [File not signed]
FirewallRules: [{8679A5C0-CC1D-4FA0-B82B-D9C0C5E6BBF2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crab Game\Crab Game.exe () [File not signed]
FirewallRules: [{80611E62-7C70-4905-9F01-C65173B6FFB9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SCP Labrat\SCP Labrat.exe () [File not signed]
FirewallRules: [{EF29D8A4-1A77-4AED-A9E4-E67168600AD9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SCP Labrat\SCP Labrat.exe () [File not signed]
FirewallRules: [{80676016-69F2-40F7-BEC5-DCFB3850DDA3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe => No File
FirewallRules: [{573B3116-7067-404E-BA3E-21155418E552}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe => No File
FirewallRules: [UDP Query User{2E798C16-4D61-42EA-B152-7F631E89ED67}C:\program files (x86)\steam\steamapps\common\knockout city\knockoutcity.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\knockout city\knockoutcity.exe => No File
FirewallRules: [TCP Query User{89A933B2-15A3-4EF5-8502-058D08D6F624}C:\program files (x86)\steam\steamapps\common\knockout city\knockoutcity.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\knockout city\knockoutcity.exe => No File
FirewallRules: [UDP Query User{627F1DF3-B582-4AF9-8F08-D37124ADFA8B}C:\program files (x86)\steam\steamapps\common\knockoutcity\knockoutcity.exe] => (Block) C:\program files (x86)\steam\steamapps\common\knockoutcity\knockoutcity.exe => No File
FirewallRules: [TCP Query User{E78CFB1A-7D8A-4936-AFB5-E4F4808D9679}C:\program files (x86)\steam\steamapps\common\knockoutcity\knockoutcity.exe] => (Block) C:\program files (x86)\steam\steamapps\common\knockoutcity\knockoutcity.exe => No File
FirewallRules: [UDP Query User{093F2391-2F14-46EB-8815-33D5D3A431D4}C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe] => (Allow) C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe => No File
FirewallRules: [TCP Query User{FAC8EB69-80B2-4B7E-8DF2-BE9399E27B48}C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe] => (Allow) C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe => No File
FirewallRules: [{3C43AF91-6F38-45BA-ABF0-AD3672F46BB3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life is Strange 2\LIS2\Binaries\Win64\LIS2-Win64-Shipping.exe (Square Enix) [File not signed]
FirewallRules: [{9882FEBD-41C1-429A-B915-528D59F176C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Life is Strange 2\LIS2\Binaries\Win64\LIS2-Win64-Shipping.exe (Square Enix) [File not signed]
FirewallRules: [UDP Query User{875C3088-1D22-4D79-946F-93438A6F67B9}C:\users\adrián\appdata\local\temp\pmstart.exe] => (Block) C:\users\adrián\appdata\local\temp\pmstart.exe => No File
FirewallRules: [TCP Query User{6D7EB602-24CD-4CD4-AB51-8C9CED1AA6EE}C:\users\adrián\appdata\local\temp\pmstart.exe] => (Block) C:\users\adrián\appdata\local\temp\pmstart.exe => No File
FirewallRules: [UDP Query User{CA72BE29-5AD3-43D9-A719-13776EC11EDC}C:\users\adrián\downloads\agfy-welcome.to.the.game.ii\welcome to the game ii\wttg2.exe] => (Allow) C:\users\adrián\downloads\agfy-welcome.to.the.game.ii\welcome to the game ii\wttg2.exe => No File
FirewallRules: [TCP Query User{0EB29676-E2FA-4610-ACC0-AE278443B4F5}C:\users\adrián\downloads\agfy-welcome.to.the.game.ii\welcome to the game ii\wttg2.exe] => (Allow) C:\users\adrián\downloads\agfy-welcome.to.the.game.ii\welcome to the game ii\wttg2.exe => No File
FirewallRules: [UDP Query User{03390C60-6A9F-4E83-8A8B-6252108EF031}C:\users\adrián\downloads\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\downloads\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [TCP Query User{5CC6038B-3834-4701-BC26-DA113C849AD7}C:\users\adrián\downloads\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\downloads\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [UDP Query User{4374A818-7D01-42F4-BC96-13EC90067797}C:\users\adrián\appdata\local\temp\rar$exa404.1216\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\appdata\local\temp\rar$exa404.1216\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [TCP Query User{26F76958-B62B-4F01-8D46-0908F6D42F4D}C:\users\adrián\appdata\local\temp\rar$exa404.1216\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\appdata\local\temp\rar$exa404.1216\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [UDP Query User{2DF95CFE-EB8C-400A-A9B2-597B1817E099}C:\users\adrián\downloads\agfy-planet.zoo\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\downloads\agfy-planet.zoo\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [TCP Query User{B75B35B2-56C9-4AF4-907B-3B01C79CC11D}C:\users\adrián\downloads\agfy-planet.zoo\agfy-planet.zoo\planet.zoo\planetzoo.exe] => (Allow) C:\users\adrián\downloads\agfy-planet.zoo\agfy-planet.zoo\planet.zoo\planetzoo.exe => No File
FirewallRules: [{E4695B73-FF4C-4E74-BA76-7F8569A4F5B4}] => (Allow) C:\Games\Steam Library\steamapps\common\VRChat\VRChat.exe => No File
FirewallRules: [{201932D7-160B-4393-9215-33AB5DDB1865}] => (Allow) C:\Games\Steam Library\steamapps\common\VRChat\VRChat.exe => No File
FirewallRules: [UDP Query User{E3B91AFB-B5AB-452F-95AA-DF6E479A863F}C:\users\adrián\downloads\agfy-beat.saber.v1.9.0.all.dlc\agfy-beat.saber.v1.9.0.all.dlc\beat saber\beat saber.exe] => (Allow) C:\users\adrián\downloads\agfy-beat.saber.v1.9.0.all.dlc\agfy-beat.saber.v1.9.0.all.dlc\beat saber\beat saber.exe => No File
FirewallRules: [TCP Query User{76B1AD56-8875-48BA-A788-8AD8E2632009}C:\users\adrián\downloads\agfy-beat.saber.v1.9.0.all.dlc\agfy-beat.saber.v1.9.0.all.dlc\beat saber\beat saber.exe] => (Allow) C:\users\adrián\downloads\agfy-beat.saber.v1.9.0.all.dlc\agfy-beat.saber.v1.9.0.all.dlc\beat saber\beat saber.exe => No File
FirewallRules: [{0629661C-DBFF-4DE2-B5A3-F4C983EC7F8B}] => (Allow) C:\Games\Steam Library\steamapps\common\Gorilla Tag\Gorilla Tag.exe => No File
FirewallRules: [{D1908F0B-E282-4901-914C-AB5CCBBA866C}] => (Allow) C:\Games\Steam Library\steamapps\common\Gorilla Tag\Gorilla Tag.exe => No File
FirewallRules: [UDP Query User{9A778B8A-D91F-42D2-A367-366D9AB0591D}C:\games\steam library\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Allow) C:\games\steam library\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe => No File
FirewallRules: [TCP Query User{FC3C8AD6-48DE-454A-8482-9F8D981FD9D4}C:\games\steam library\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Allow) C:\games\steam library\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe => No File
FirewallRules: [{A33B01F1-F281-4E06-9D34-435BE2A0C7D6}] => (Allow) C:\Games\Steam Library\steamapps\common\PavlovVR\Pavlov.exe => No File
FirewallRules: [{F203D012-0A2B-4F0D-8F86-850FFB316C14}] => (Allow) C:\Games\Steam Library\steamapps\common\PavlovVR\Pavlov.exe => No File
FirewallRules: [{FF53EE2B-5D30-4EF2-BB40-22BCD831DBB7}] => (Allow) C:\Games\Steam Library\steamapps\common\Hunt Showdown\hunt.exe => No File
FirewallRules: [{C6FE9283-44AD-4C53-9AA0-5F98CAC15BF3}] => (Allow) C:\Games\Steam Library\steamapps\common\Hunt Showdown\hunt.exe => No File
FirewallRules: [{3F19E968-06AD-4F55-B5C4-6FF493C6F106}] => (Allow) C:\Games\Steam Library\steamapps\common\Valheim\valheim.exe => No File
FirewallRules: [{90B409FC-5AE1-46D4-AC96-4296CF5C6CF4}] => (Allow) C:\Games\Steam Library\steamapps\common\Valheim\valheim.exe => No File
FirewallRules: [{1231889A-C2F2-4A85-AF69-AE688B02402A}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe => No File
FirewallRules: [{EB260F1D-DF23-490E-B450-9F5048B1A3CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OVR_AdvancedSettings\AdvancedSettings.exe () [File not signed]
FirewallRules: [{B8073A49-3835-4415-B7AF-DBBE572E65B9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\OVR_AdvancedSettings\AdvancedSettings.exe () [File not signed]
FirewallRules: [UDP Query User{4095A84A-0302-49AD-B841-6619F0CA99AA}C:\program files\epic games\gtav\gta5.exe] => (Allow) C:\program files\epic games\gtav\gta5.exe => No File
FirewallRules: [TCP Query User{72B7F466-6E5E-415B-9642-0BB055E4F1CE}C:\program files\epic games\gtav\gta5.exe] => (Allow) C:\program files\epic games\gtav\gta5.exe => No File
FirewallRules: [{C1C0E8CB-9326-4B83-AB66-FE39B0BE4DFE}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe (Oculus VR, LLC) [File not signed]
FirewallRules: [{C04A1C6B-E842-4F4E-8004-5A06D0A88B2C}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe (Oculus VR, LLC) [File not signed]
FirewallRules: [{5D571AA1-A950-4545-BA4B-8C61CB78341C}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Engine\Binaries\Win64\UnrealCEFSubProcess.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{86D8797B-7C08-40A0-9B8D-62853E0B720A}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Engine\Binaries\Win64\UnrealCEFSubProcess.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{696763C1-0CD0-4523-974E-43E39870F4A0}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{EB54494D-AFFA-4680-B63A-D76040A57E97}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{9836AD10-DE92-44F7-A866-CB10CA3D73C1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\RocketLeague.exe => No File
FirewallRules: [{4AD190F0-8B34-4B26-AC4E-CA605CF0697E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\RocketLeague.exe => No File
FirewallRules: [UDP Query User{CDCB6C2D-C562-451C-8D97-19B3D0A0C0C2}C:\program files (x86)\steam\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe => No File
FirewallRules: [TCP Query User{89CA186A-B0EA-481C-AE32-46DA2D81798B}C:\program files (x86)\steam\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe => No File
FirewallRules: [UDP Query User{B9639CE4-B3A1-4916-8912-BC35977C8CBB}C:\program files (x86)\steam\steamapps\common\for honor\forhonor.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\for honor\forhonor.exe => No File
FirewallRules: [TCP Query User{C4CDF850-0768-4B78-BC86-7E96C569D0D6}C:\program files (x86)\steam\steamapps\common\for honor\forhonor.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\for honor\forhonor.exe => No File
FirewallRules: [{CF88C3E4-DB59-4F56-861A-517555D25A5C}] => (Allow) C:\Users\Adrián\AppData\Local\Chromium\Application\chrome.exe => No File
FirewallRules: [{780E077E-D758-4E71-A9F2-6A357A4B1DFE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\RocketLeague.exe => No File
FirewallRules: [{000F22B5-6FFD-4827-8129-E5226FE3BCA6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\RocketLeague.exe => No File
FirewallRules: [UDP Query User{CBD5794E-3F16-4ED2-ABFA-007BDEDD44E3}C:\users\adrián\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\adrián\appdata\roaming\spotify\spotify.exe => No File
FirewallRules: [TCP Query User{CC642D35-ABA2-4B39-9A61-BE4D3BEFC344}C:\users\adrián\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\adrián\appdata\roaming\spotify\spotify.exe => No File
FirewallRules: [{47B0CD22-DFFC-4D6E-A7E6-17F140316632}] => (Allow) D:\SteamLibrary\steamapps\common\Dear Esther Landmark Edition\DearEsther.exe () [File not signed]
FirewallRules: [{BF23AB38-8C33-4AE0-9E0C-8DBC7DB16707}] => (Allow) D:\SteamLibrary\steamapps\common\Dear Esther Landmark Edition\DearEsther.exe () [File not signed]
FirewallRules: [{87FB9911-922C-4A50-A740-13FE4471E90F}] => (Allow) C:\Users\Adrián\AppData\Local\Chromium\Application\chrome.exe => No File
FirewallRules: [TCP Query User{E8E64319-D8DA-42DF-AE72-BBA3CDA03F6E}D:\steamlibrary\steamapps\common\kukui\kukui_pc\binaries\win64\kukui_pc-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\kukui\kukui_pc\binaries\win64\kukui_pc-win64-shipping.exe => No File
FirewallRules: [UDP Query User{D56C4393-C759-4D4A-8583-9BB83690C059}D:\steamlibrary\steamapps\common\kukui\kukui_pc\binaries\win64\kukui_pc-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\kukui\kukui_pc\binaries\win64\kukui_pc-win64-shipping.exe => No File
FirewallRules: [{AA527351-4CDA-438F-9C61-AD9374EC18D7}] => (Allow) D:\SteamLibrary\steamapps\common\ELDEN RING\Game\start_protected_game.exe => No File
FirewallRules: [{2AC2D687-8F4A-49A1-B598-1AC76FEA78A8}] => (Allow) D:\SteamLibrary\steamapps\common\ELDEN RING\Game\start_protected_game.exe => No File
FirewallRules: [{8B202764-EBB1-48BC-803F-2C3D86835C3C}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client.exe () [File not signed]
FirewallRules: [{F0B15C85-6327-46D3-AFD1-CEA5625189D5}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client.exe () [File not signed]
FirewallRules: [TCP Query User{9764BDC0-FEA9-41EE-BBBE-CA8BD6AB8476}D:\steamlibrary\steamapps\common\pandemic express\bin\win_x64\pandemicexpress.exe] => (Allow) D:\steamlibrary\steamapps\common\pandemic express\bin\win_x64\pandemicexpress.exe (tinyBuild LLC) [File not signed]
FirewallRules: [UDP Query User{D796E78F-FBFC-4D8A-A286-661FB4469CC9}D:\steamlibrary\steamapps\common\pandemic express\bin\win_x64\pandemicexpr
FirewallRules: [{8948EAA4-B7D4-49CA-9963-08125401A39A}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client_game.exe () [File not signed]
FirewallRules: [{C97CBFAA-0429-4999-A62B-09388BC06740}] => (Allow) D:\SteamLibrary\steamapps\common\Fall Guys\FallGuys_client_game.exe () [File not signed]
FirewallRules: [TCP Query User{3669E2E5-4DC2-4BC3-8220-A5901DE86125}D:\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe (Vankrupt Games, Inc.) [File not signed]
FirewallRules: [UDP Query User{3810553E-F5DD-484A-9F7E-7F58AD7624E5}D:\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe (Vankrupt Games, Inc.) [File not signed]
FirewallRules: [TCP Query User{A637B39D-E5FD-4B06-8C3F-C4EA21FF0193}D:\a township tale\a township tale.exe] => (Allow) D:\a township tale\a township tale.exe () [File not signed]
FirewallRules: [UDP Query User{C0DE5151-1E97-4149-8F09-044D712E97CC}D:\a township tale\a township tale.exe] => (Allow) D:\a township tale\a township tale.exe () [File not signed]
FirewallRules: [TCP Query User{E84BD1AA-CA25-4380-A774-C32DFEFC7187}C:\users\adrián\appdata\local\temp\rar$exa5564.5375\fallendoll(extendeddemo1.26)(vr)\windowsnoeditor\fallendoll\binaries\win64\fallendoll.exe] => (Block) C:\users\adrián\appdata\local\temp\rar$exa5564.5375\fallendoll(extendeddemo1.26)(vr)\windowsnoeditor\fallendoll\binaries\win64\fallendoll.exe => No File
FirewallRules: [UDP Query User{D88CCDA9-97FC-4417-A727-8C8A6D5BC921}C:\users\adrián\appdata\local\temp\rar$exa5564.5375\fallendoll(extendeddemo1.26)(vr)\windowsnoeditor\fallendoll\binaries\win64\fallendoll.exe] => (Block) C:\users\adrián\appdata\local\temp\rar$exa5564.5375\fallendoll(extendeddemo1.26)(vr)\windowsnoeditor\fallendoll\binaries\win64\fallendoll.exe => No File
FirewallRules: [{98797C73-E238-4DD3-9BE0-F6F88B4D64BA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VRChat\launch.exe () [File not signed]
FirewallRules: [{E8F8569D-C989-41DA-8CB1-6C06A042F217}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VRChat\launch.exe () [File not signed]
FirewallRules: [{FD0B41E4-AA4C-4FA8-AFF5-387E3EE3CCD4}] => (Allow) D:\SteamLibrary\steamapps\common\RecRoom\Recroom_Release.exe (Epic Games, Inc) [File not signed]
FirewallRules: [{C2F1CBE8-EF2F-4357-B428-3B88035D3E81}] => (Allow) D:\SteamLibrary\steamapps\common\RecRoom\Recroom_Release.exe (Epic Games, Inc) [File not signed]
FirewallRules: [TCP Query User{BE959D89-E670-4C91-B5C6-7CFF75A86E36}D:\program files\secondlifeviewer\slvoice.exe] => (Allow) D:\program files\secondlifeviewer\slvoice.exe () [File not signed]
FirewallRules: [UDP Query User{297904DD-3BF3-4A98-A9ED-6EB1CC7D98E8}D:\program files\secondlifeviewer\slvoice.exe] => (Allow) D:\program files\secondlifeviewer\slvoice.exe () [File not signed]
FirewallRules: [{8E88243D-F84A-4ACF-958C-AFC9FDDB5B51}] => (Allow) D:\Program Files (x86)\Origin games\Battlefield V\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [{F3DC8B6C-2495-4116-B622-59609D73999B}] => (Allow) D:\Program Files (x86)\Origin games\Battlefield V\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [TCP Query User{772EA311-C4F0-4BD8-8D34-1D5973FA3F32}D:\program files (x86)\origin games\battlefield v\bfv.exe] => (Block) D:\program files (x86)\origin games\battlefield v\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [UDP Query User{7807736A-DF26-4AA6-B01D-041D2275B776}D:\program files (x86)\origin games\battlefield v\bfv.exe] => (Block) D:\program files (x86)\origin games\battlefield v\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [{22BA7263-312B-4A42-A46A-7689F43E6118}] => (Allow) D:\SteamLibrary\steamapps\common\No Man's Sky\Binaries\NMS.exe (Hello Games) [File not signed]
FirewallRules: [{7C809C9F-A87D-46D1-8B4B-6EFC7FCDFDA9}] => (Allow) D:\SteamLibrary\steamapps\common\No Man's Sky\Binaries\NMS.exe (Hello Games) [File not signed]
FirewallRules: [TCP Query User{305D85F9-4884-4CD4-97D9-1B340E55A939}D:\steamlibrary\steamapps\common\fifa 22\fifa22.exe] => (Block) D:\steamlibrary\steamapps\common\fifa 22\fifa22.exe => No File
FirewallRules: [UDP Query User{4038F98A-4485-4EE8-AD52-17D5A058D5AF}D:\steamlibrary\steamapps\common\fifa 22\fifa22.exe] => (Block) D:\steamlibrary\steamapps\common\fifa 22\fifa22.exe => No File
FirewallRules: [{53766F46-5B28-4EA6-8E68-1DD2B24C3A1B}] => (Allow) D:\SteamLibrary\steamapps\common\assettocorsa\AssettoCorsa.exe (Kunos Simulazioni) [File not signed]
FirewallRules: [{10E6DFB4-B6E8-4476-A804-240470AB71DA}] => (Allow) D:\SteamLibrary\steamapps\common\assettocorsa\AssettoCorsa.exe (Kunos Simulazioni) [File not signed]
FirewallRules: [TCP Query User{A875CED1-E76B-40CB-8808-A4B553709372}D:\steamlibrary\steamapps\common\assettocorsa\acs.exe] => (Allow) D:\steamlibrary\steamapps\common\assettocorsa\acs.exe () [File not signed]
FirewallRules: [UDP Query User{D26FB6F8-758F-4DD9-858D-B443D8BB5921}D:\steamlibrary\steamapps\common\assettocorsa\acs.exe] => (Allow) D:\steamlibrary\steamapps\common\assettocorsa\acs.exe () [File not signed]
FirewallRules: [TCP Query User{4D6CB43B-5623-4202-A0CF-A1B5CC485E2E}D:\steamlibrary\steamapps\common\star wars battlefront ii\starwarsbattlefrontii.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars battlefront ii\starwarsbattlefrontii.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [UDP Query User{6775F48C-3EF8-4AC2-964D-5AF9B2D43B19}D:\steamlibrary\steamapps\common\star wars battlefront ii\starwarsbattlefrontii.exe] => (Allow) D:\steamlibrary\steamapps\common\star wars battlefront ii\starwarsbattlefrontii.exe (Electronic Arts Inc.) [File not signed]
FirewallRules: [{B08DEB2F-B9DC-4CD0-BBAB-536F195A7AEF}] => (Allow) D:\SteamLibrary\steamapps\common\Sons Of The Forest\SonsOfTheForest.exe () [File not signed]
FirewallRules: [{8EB2C9DC-E670-4E80-80BB-6472315A4798}] => (Allow) D:\SteamLibrary\steamapps\common\Sons Of The Forest\SonsOfTheForest.exe () [File not signed]
FirewallRules: [{0D06F2BE-26DA-4C8D-994D-1E3215F46F52}] => (Allow) D:\SteamLibrary\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe (Psyonix, LLC) [File not signed]
FirewallRules: [{A08EE456-6494-40B5-A8B4-70032B6EC19D}] => (Allow) D:\SteamLibrary\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe (Psyonix, LLC) [File not signed]
FirewallRules: [{2640AB01-D51C-427F-9ED1-9B15CCE806BD}] => (Allow) C:\Program Files (x86)\Overwolf\0.220.0.1\OverwolfBrowser.exe => No File
FirewallRules: [{0A0DF3A0-9A66-433D-BB11-10FE42D618ED}] => (Allow) C:\Program Files (x86)\Overwolf\0.220.0.1\OverwolfBrowser.exe => No File
FirewallRules: [{6665A718-4236-4DCB-BAEA-9B9A0E2E4673}] => (Block) C:\Program Files (x86)\Overwolf\0.220.0.1\OverwolfBrowser.exe => No File
FirewallRules: [{9F897F72-AEA3-4731-A52A-FF4EE5DB876A}] => (Block) C:\Program Files (x86)\Overwolf\0.220.0.1\OverwolfBrowser.exe => No File
FirewallRules: [{2FC5BF06-988C-478A-871A-8DD914D6B9F5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Chef LIFE A Restaurant Simulator\Chef Life A Restaurant Simulator.exe () [File not signed]
FirewallRules: [{51CDCBF3-94C8-46A4-8D2C-939D354DA4AA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Chef LIFE A Restaurant Simulator\Chef Life A Restaurant Simulator.exe () [File not signed]

EmptyTemp:
CMD: ipconfig /flushdns
*

"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E3C20326-E80D-431E-BFB2-69F31CC658F6}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{42FA6174-0B14-42C9-AF84-21E9CF867FB6}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{63244C77-6974-4EBF-840E-2812AE046DD3}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D5135B26-DFA3-4165-96B5-D4AF29EBE4AD}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{83105D6F-1D5B-469A-93B8-A1E44FA7882F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4D590132-4EBF-4337-9F31-2545B03F1D9A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5CAD990C-4768-4CBF-A2CB-6C68F52E4926}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{16088590-9FDF-4AAC-8584-8844E8484DFD}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BDB7D2ED-659D-4AD2-8186-E0FFE67C1621}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AC511FDF-8F88-4DD8-A446-07E659671EEC}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9ED778E0-9668-4FA8-B01C-788371BEAD2A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{06DFA6D5-AF15-4262-B23E-77C5E81A18CA}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{029FC0C6-0B8E-4023-B9A6-FECCDC4F68BD}D:\programmes (x86)\call of duty modern warfare\modernwarfare.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{52F0E687-63CC-4547-83FC-C5A27FE1A0F2}D:\programmes (x86)\call of duty modern warfare\modernwarfare.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4F8D1434-51F5-48F1-BB4B-27B49EA6E673}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B3F9D4A9-68D9-43E6-8C32-DC8EC2EDA1B8}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B1B98AD9-E29D-4DF6-8D1A-483AB70C0D03}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6375D95F-4399-4DEA-A091-1BA74B070137}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AB93D9CC-1AA8-41D2-A5C9-1DC35D2E7781}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{46030151-0B9E-4A75-AC6D-5DAB1078C46C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BF76020C-D5AE-4719-A2AC-27F3E6AEED84}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8679A5C0-CC1D-4FA0-B82B-D9C0C5E6BBF2}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{80611E62-7C70-4905-9F01-C65173B6FFB9}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EF29D8A4-1A77-4AED-A9E4-E67168600AD9}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{80676016-69F2-40F7-BEC5-DCFB3850DDA3}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{573B3116-7067-404E-BA3E-21155418E552}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2E798C16-4D61-42EA-B152-7F631E89ED67}C:\program files (x86)\steam\steamapps\common\knockout city\knockoutcity.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{89A933B2-15A3-4EF5-8502-058D08D6F624}C:\program files (x86)\steam\steamapps\common\knockout city\knockoutcity.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{627F1DF3-B582-4AF9-8F08-D37124ADFA8B}C:\program files (x86)\steam\steamapps\common\knockoutcity\knockoutcity.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E78CFB1A-7D8A-4936-AFB5-E4F4808D9679}C:\program files (x86)\steam\steamapps\common\knockoutcity\knockoutcity.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{093F2391-2F14-46EB-8815-33D5D3A431D4}C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FAC8EB69-80B2-4B7E-8DF2-BE9399E27B48}C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3C43AF91-6F38-45BA-ABF0-AD3672F46BB3}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9882FEBD-41C1-429A-B915-528D59F176C6}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{875C3088-1D22-4D79-946F-93438A6F67B9}C:\users\adrián\appdata\local\temp\pmstart.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6D7EB602-24CD-4CD4-AB51-8C9CED1AA6EE}C:\users\adrián\appdata\local\temp\pmstart.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{CA72BE29-5AD3-43D9-A719-13776EC11EDC}C:\users\adrián\downloads\agfy-welcome.to.the.game.ii\welcome to the game ii\wttg2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0EB29676-E2FA-4610-ACC0-AE278443B4F5}C:\users\adrián\downloads\agfy-welcome.to.the.game.ii\welcome to the game ii\wttg2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{03390C60-6A9F-4E83-8A8B-6252108EF031}C:\users\adrián\downloads\agfy-planet.zoo\planet.zoo\planetzoo.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5CC6038B-3834-4701-BC26-DA113C849AD7}C:\users\adrián\downloads\agfy-planet.zoo\planet.zoo\planetzoo.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{4374A818-7D01-42F4-BC96-13EC90067797}C:\users\adrián\appdata\local\temp\rar$exa404.1216\agfy-planet.zoo\planet.zoo\planetzoo.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{26F76958-B62B-4F01-8D46-0908F6D42F4D}C:\users\adrián\appdata\local\temp\rar$exa404.1216\agfy-planet.zoo\planet.zoo\planetzoo.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2DF95CFE-EB8C-400A-A9B2-597B1817E099}C:\users\adrián\downloads\agfy-planet.zoo\agfy-planet.zoo\planet.zoo\planetzoo.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{B75B35B2-56C9-4AF4-907B-3B01C79CC11D}C:\users\adrián\downloads\agfy-planet.zoo\agfy-planet.zoo\planet.zoo\planetzoo.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E4695B73-FF4C-4E74-BA76-7F8569A4F5B4}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{201932D7-160B-4393-9215-33AB5DDB1865}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{E3B91AFB-B5AB-452F-95AA-DF6E479A863F}C:\users\adrián\downloads\agfy-beat.saber.v1.9.0.all.dlc\agfy-beat.saber.v1.9.0.all.dlc\beat saber\beat saber.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{76B1AD56-8875-48BA-A788-8AD8E2632009}C:\users\adrián\downloads\agfy-beat.saber.v1.9.0.all.dlc\agfy-beat.saber.v1.9.0.all.dlc\beat saber\beat saber.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0629661C-DBFF-4DE2-B5A3-F4C983EC7F8B}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D1908F0B-E282-4901-914C-AB5CCBBA866C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9A778B8A-D91F-42D2-A367-366D9AB0591D}C:\games\steam library\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FC3C8AD6-48DE-454A-8482-9F8D981FD9D4}C:\games\steam library\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A33B01F1-F281-4E06-9D34-435BE2A0C7D6}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F203D012-0A2B-4F0D-8F86-850FFB316C14}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FF53EE2B-5D30-4EF2-BB40-22BCD831DBB7}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C6FE9283-44AD-4C53-9AA0-5F98CAC15BF3}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3F19E968-06AD-4F55-B5C4-6FF493C6F106}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{90B409FC-5AE1-46D4-AC96-4296CF5C6CF4}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1231889A-C2F2-4A85-AF69-AE688B02402A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EB260F1D-DF23-490E-B450-9F5048B1A3CC}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B8073A49-3835-4415-B7AF-DBBE572E65B9}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{4095A84A-0302-49AD-B841-6619F0CA99AA}C:\program files\epic games\gtav\gta5.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{72B7F466-6E5E-415B-9642-0BB055E4F1CE}C:\program files\epic games\gtav\gta5.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C1C0E8CB-9326-4B83-AB66-FE39B0BE4DFE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C04A1C6B-E842-4F4E-8004-5A06D0A88B2C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5D571AA1-A950-4545-BA4B-8C61CB78341C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{86D8797B-7C08-40A0-9B8D-62853E0B720A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{696763C1-0CD0-4523-974E-43E39870F4A0}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EB54494D-AFFA-4680-B63A-D76040A57E97}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9836AD10-DE92-44F7-A866-CB10CA3D73C1}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4AD190F0-8B34-4B26-AC4E-CA605CF0697E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{CDCB6C2D-C562-451C-8D97-19B3D0A0C0C2}C:\program files (x86)\steam\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{89CA186A-B0EA-481C-AE32-46DA2D81798B}C:\program files (x86)\steam\steamapps\common\hunt showdown\bin\win_x64\huntgame.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{B9639CE4-B3A1-4916-8912-BC35977C8CBB}C:\program files (x86)\steam\steamapps\common\for honor\forhonor.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C4CDF850-0768-4B78-BC86-7E96C569D0D6}C:\program files (x86)\steam\steamapps\common\for honor\forhonor.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CF88C3E4-DB59-4F56-861A-517555D25A5C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{780E077E-D758-4E71-A9F2-6A357A4B1DFE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{000F22B5-6FFD-4827-8129-E5226FE3BCA6}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{CBD5794E-3F16-4ED2-ABFA-007BDEDD44E3}C:\users\adrián\appdata\roaming\spotify\spotify.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{CC642D35-ABA2-4B39-9A61-BE4D3BEFC344}C:\users\adrián\appdata\roaming\spotify\spotify.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{47B0CD22-DFFC-4D6E-A7E6-17F140316632}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BF23AB38-8C33-4AE0-9E0C-8DBC7DB16707}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{87FB9911-922C-4A50-A740-13FE4471E90F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E8E64319-D8DA-42DF-AE72-BBA3CDA03F6E}D:\steamlibrary\steamapps\common\kukui\kukui_pc\binaries\win64\kukui_pc-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D56C4393-C759-4D4A-8583-9BB83690C059}D:\steamlibrary\steamapps\common\kukui\kukui_pc\binaries\win64\kukui_pc-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AA527351-4CDA-438F-9C61-AD9374EC18D7}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2AC2D687-8F4A-49A1-B598-1AC76FEA78A8}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8B202764-EBB1-48BC-803F-2C3D86835C3C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F0B15C85-6327-46D3-AFD1-CEA5625189D5}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{9764BDC0-FEA9-41EE-BBBE-CA8BD6AB8476}D:\steamlibrary\steamapps\common\pandemic express\bin\win_x64\pandemicexpress.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\FirewallRules: [UDP Query User{D796E78F-FBFC-4D8A-A286-661FB4469CC9}D:\steamlibrary\steamapps\common\pandemic express\bin\win_x64\pandemicexpr" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8948EAA4-B7D4-49CA-9963-08125401A39A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C97CBFAA-0429-4999-A62B-09388BC06740}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{3669E2E5-4DC2-4BC3-8220-A5901DE86125}D:\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{3810553E-F5DD-484A-9F7E-7F58AD7624E5}D:\steamlibrary\steamapps\common\pavlovvr\pavlov\binaries\win64\pavlov-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{A637B39D-E5FD-4B06-8C3F-C4EA21FF0193}D:\a township tale\a township tale.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C0DE5151-1E97-4149-8F09-044D712E97CC}D:\a township tale\a township tale.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E84BD1AA-CA25-4380-A774-C32DFEFC7187}C:\users\adrián\appdata\local\temp\rar$exa5564.5375\fallendoll(extendeddemo1.26)(vr)\windowsnoeditor\fallendoll\binaries\win64\fallendoll.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D88CCDA9-97FC-4417-A727-8C8A6D5BC921}C:\users\adrián\appdata\local\temp\rar$exa5564.5375\fallendoll(extendeddemo1.26)(vr)\windowsnoeditor\fallendoll\binaries\win64\fallendoll.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{98797C73-E238-4DD3-9BE0-F6F88B4D64BA}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E8F8569D-C989-41DA-8CB1-6C06A042F217}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FD0B41E4-AA4C-4FA8-AFF5-387E3EE3CCD4}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C2F1CBE8-EF2F-4357-B428-3B88035D3E81}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{BE959D89-E670-4C91-B5C6-7CFF75A86E36}D:\program files\secondlifeviewer\slvoice.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{297904DD-3BF3-4A98-A9ED-6EB1CC7D98E8}D:\program files\secondlifeviewer\slvoice.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8E88243D-F84A-4ACF-958C-AFC9FDDB5B51}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F3DC8B6C-2495-4116-B622-59609D73999B}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{772EA311-C4F0-4BD8-8D34-1D5973FA3F32}D:\program files (x86)\origin games\battlefield v\bfv.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{7807736A-DF26-4AA6-B01D-041D2275B776}D:\program files (x86)\origin games\battlefield v\bfv.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{22BA7263-312B-4A42-A46A-7689F43E6118}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7C809C9F-A87D-46D1-8B4B-6EFC7FCDFDA9}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{305D85F9-4884-4CD4-97D9-1B340E55A939}D:\steamlibrary\steamapps\common\fifa 22\fifa22.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{4038F98A-4485-4EE8-AD52-17D5A058D5AF}D:\steamlibrary\steamapps\common\fifa 22\fifa22.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{53766F46-5B28-4EA6-8E68-1DD2B24C3A1B}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{10E6DFB4-B6E8-4476-A804-240470AB71DA}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{A875CED1-E76B-40CB-8808-A4B553709372}D:\steamlibrary\steamapps\common\assettocorsa\acs.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D26FB6F8-758F-4DD9-858D-B443D8BB5921}D:\steamlibrary\steamapps\common\assettocorsa\acs.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{4D6CB43B-5623-4202-A0CF-A1B5CC485E2E}D:\steamlibrary\steamapps\common\star wars battlefront ii\starwarsbattlefrontii.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{6775F48C-3EF8-4AC2-964D-5AF9B2D43B19}D:\steamlibrary\steamapps\common\star wars battlefront ii\starwarsbattlefrontii.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B08DEB2F-B9DC-4CD0-BBAB-536F195A7AEF}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8EB2C9DC-E670-4E80-80BB-6472315A4798}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0D06F2BE-26DA-4C8D-994D-1E3215F46F52}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A08EE456-6494-40B5-A8B4-70032B6EC19D}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2640AB01-D51C-427F-9ED1-9B15CCE806BD}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0A0DF3A0-9A66-433D-BB11-10FE42D618ED}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6665A718-4236-4DCB-BAEA-9B9A0E2E4673}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9F897F72-AEA3-4731-A52A-FF4EE5DB876A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2FC5BF06-988C-478A-871A-8DD914D6B9F5}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{51CDCBF3-94C8-46A4-8D2C-939D354DA4AA}" => removed successfully

========= ipconfig /flushdns =========


Configuration IP de Windows

Cache de r‚solution DNS vid‚.

========= End of CMD: =========


=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 36166409 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 716953353 B
Windows/system/drivers => 7544695860 B
Edge => 0 B
Chrome => 360540567 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 21 B
LocalService => 21 B
NetworkService => 781119 B
Adrián => 462776466 B
OVRLibraryService => 462776466 B

RecycleBin => 327784 B
EmptyTemp: => 8.9 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 00:29:39 ====

STEP 3
As I started the full scan with ESET, 6 windows pop-ups appeared all saying that it is "impossible to charge this driver in this computer. Driver: ehdrv.sys ehdrv.sys. A security setting is blocking the loading of this driver. You must change your settings in order to charge this driver." and either close the pop-up or press on more info which led me in microsoft support "A driver can't load on this device" website. Even if I did nothing the scan seems to be working like nothing happened. Here is the eset.txt:

14.04.2023 03:23:25
Files scanned: 748375
Detected files: 0
Cleaned files: 0
Total scan time: 01:42:21
Scan status: Finished
 
#7 ·
Don't worry about the notice for ehdrv.sys that's just the driver for the E-Set scanner, and it couldn't load because of the security settings on Windows 11.

Can you please run another scan with FRST, and post your new FRST.txt and Addition.txt, I need to see whether the two extensions you couldn't find are still present or not.
 
#8 ·
I tried looking those extensions on google and some other people seem to have problems deleting them as well. No solutiond found tho, here is the FRST.txt:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-04-2023
Ran by Adrián (administrator) on DESKTOP-MIFQ18R (ASUS System Product Name) (14-04-2023 14:30:14)
Running from C:\Users\Adrián\Downloads\FRSTEnglish.exe
Loaded Profiles: Adrián
Platform: Microsoft Windows 11 Professionnel Version 21H2 22000.1574 (X64) Language: Français (France)
Default browser: Chrome
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe ->) (ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe ->) (ASUSTEK COMPUTER INCORPORATION -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.UserSessionHelper.exe
(C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe
(C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe
(C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_421.20070.425.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.37\msedgewebview2.exe <6>
(Discord Inc. -> Discord Inc.) C:\Users\Adrián\AppData\Local\Discord\app-1.0.9012\Discord.exe <6>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <38>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.202\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.202\GoogleCrashHandler64.exe
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\LightingService.exe
(services.exe ->) (ASUSTEK COMPUTER INCORPORATION -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\gamingservices.exe
(services.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2>
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(services.exe ->) (Virtual Desktop, Inc. -> Virtual Desktop, Inc.) C:\Program Files\Virtual Desktop\VirtualDesktop.Service.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ) C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x86.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\AacExtCard\extensionCardHal_x86.exe
(svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS_Aac_DRAM\Aac3572DramHal_x86.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SteelSeriesGG] => C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe [12692160 2022-05-13] (SteelSeries ApS -> SteelSeries ApS)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4361576 2023-04-07] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [LGHUB] => C:\Program Files\LGHUB\lghub.exe [146944768 2022-07-29] (Logitech Inc -> Logitech, Inc.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [49958368 2022-02-01] (Google LLC -> )
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1784664 2023-03-14] (Overwolf Ltd -> Overwolf Ltd.)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [Battle.net] => D:\Battle.net\Battle.net.exe [1087376 2021-12-21] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\...\Run: [EADM] => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart (No File)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\73.0.4.0\GoogleDriveFS.exe [53181720 2023-04-10] (Google LLC -> Google, Inc.)
HKLM\...\Windows x64\Print Processors\Canon MP630 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD9C.DLL [27648 2008-04-21] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MP630 series: C:\Windows\system32\CNMLM9C.DLL [279040 2008-04-21] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\112.0.5615.86\Installer\chrmstp.exe [2023-04-13] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
AppInit_DLLs: C:\PROGRA~1\VIRTUA~1\VIRTUA~4.DLL => C:\Program Files\Virtual Desktop Streamer\VirtualDesktop.Injector64.dll [132520 2021-03-04] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0735A24B-E894-4180-9329-1C972A0B6173} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {11EE1835-15A4-4E09-8633-866179ED55C4} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2FD37739-F52E-4C52-9EB1-9A13D83C9BBB} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-01-27] (Nvidia Corporation -> NVIDIA Corporation)
Task: {372A8A8C-BAEA-4A63-9804-163F1D52A2DD} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4518E052-3509-4846-9B65-645D1B0B0A18} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {45B15C20-259C-4353-9BFB-90E80E00D7F5} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-15] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {5373AAA2-7895-4B12-8A1F-F102F8C42EDA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-06-14] (Google LLC -> Google LLC)
Task: {55DAA2DD-C09C-4C7B-B54A-E604132B4AE7} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [115464 2021-12-17] (ASUSTeK Computer Inc. -> ASUS)
Task: {595C82F3-D65E-46DE-B133-1F68B59759FA} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2638856 2023-03-14] (Overwolf Ltd -> Overwolf LTD)
Task: {6EF54466-3128-4CA4-BC10-420D39A368B3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {70D890C4-3797-48B2-BE62-B4E9E19298CD} - System32\Tasks\Microsoft\Windows\WaaSMedic\DeferredWork => {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32}
Task: {77231B27-B153-4DAB-AE82-E83D1F52DF67} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {79B3C747-41F6-4A1F-AADA-8FDB2BCABFB1} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe [49048864 2020-03-16] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {80148F75-235B-415B-BFFA-7D40D050FDBB} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {8CAA5EAB-7360-4CEA-8A29-C82763C3ADD3} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {968AA82D-0B95-4416-9CCC-7B182367D2D7} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A1A5F5E5-CEC7-4F8D-9466-F8B531BABA0F} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Adrián\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [21737944 2023-04-14] (ESET, spol. s r.o. -> ESET)
Task: {A8518B53-C1D3-4A60-804A-24818151E8C9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpCmdRun.exe [1348368 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B3AA668D-E85E-425C-A2CB-F11664F8B974} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B6E87EF6-AC5B-43DD-84BD-4A3AB20D9A63} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {BD824950-39DD-44EF-9B26-A86A06DECF66} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C4BD17DB-E7AB-4294-AE78-B32B53D88CC2} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe [2248120 2021-12-17] (ASUSTeK Computer Inc. -> ASUS)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (No File)
Task: {EF668038-5C88-4DC1-8C4A-599024B1EC4E} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Adrián\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [21737944 2023-04-14] (ESET, spol. s r.o. -> ESET)
Task: {F12561EC-C9C9-444E-B2EE-EFE2F06E9B9F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-06-14] (Google LLC -> Google LLC)
Task: {F6512D8F-108E-4A26-BC87-5599BEBC2C23} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d641f088e22505 => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{722b5480-08ce-4eea-9418-78ce2e0dfce5}: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{bd361947-815d-443a-8784-71534a032b8a}: [DhcpNameServer] 192.168.1.1

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Adrián\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-13]

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.311.2 -> C:\Program Files\Java\jre1.8.0_311\bin\dtplugin\npDeployJava1.dll [2021-12-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.311.2 -> C:\Program Files\Java\jre1.8.0_311\bin\plugin2\npjp2.dll [2021-12-03] (Oracle America, Inc. -> Oracle Corporation)

Chrome:
=======
CHR Profile: C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default [2023-04-14]
CHR Notifications: Default -> hxxps://www.facebook.com
CHR Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2023-03-09]
CHR Extension: (Google Docs hors connexion) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-04-06]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Adrián\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30]
CHR HKLM\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKLM\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKU\S-1-5-21-3254008329-1205757616-3926439971-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ArmouryCrateService; C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe [349408 2022-01-22] (ASUSTEK COMPUTER INCORPORATION -> ASUSTeK COMPUTER INC.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe [457544 2021-10-21] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [179488 2021-09-16] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.)
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [163176 2020-06-14] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 AsusUpdateCheck; C:\WINDOWS\System32\AsusUpdateCheck.exe [1191552 2023-04-14] (ASUSTeK Computer Inc. -> )
S3 EAAntiCheatService; C:\Program Files\EA\AC\eaanticheat.gameservice.exe [57017864 2022-12-06] (Electronic Arts, Inc. -> )
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [11027048 2023-04-13] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811496 2022-12-05] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [584680 2022-08-15] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029456 2022-07-04] (Epic Games Inc. -> Epic Games, Inc.)
R2 GamingServices; C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\GamingServices.exe [75216 2023-03-19] (Microsoft Corporation -> )
R2 GamingServicesNet; C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe [75216 2023-03-19] (Microsoft Corporation -> )
R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [10876672 2022-07-29] (Logitech Inc -> Logitech, Inc.)
R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [3683496 2021-11-24] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
S3 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2638856 2023-03-14] (Overwolf Ltd -> Overwolf LTD)
S3 OVRLibraryService; C:\Program Files\Oculus\Support\oculus-librarian\OVRLibraryService.exe [148024 2023-02-23] (Oculus VR, LLC -> Facebook Technologies, LLC)
R2 OVRService; C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe [514616 2023-02-23] (Oculus VR, LLC -> Facebook Technologies, LLC)
S3 Rockstar Service; D:\Program Files\Rockstar Games\Launcher\RockstarService.exe [2584528 2022-04-05] (Rockstar Games, Inc. -> Rockstar Games)
R2 ROG Live Service; C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe [6101680 2021-12-17] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [245216 2023-03-06] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 SteelSeriesUpdateService; C:\Program Files\SteelSeries\GG\SteelSeriesUpdateService.exe [32960 2022-05-13] (SteelSeries ApS -> )
S3 Updater; C:\Program Files\Virtual Desktop Streamer\Updater.exe [1122216 2021-03-04] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)
R2 VirtualDesktop.Service.exe; C:\Program Files\Virtual Desktop\VirtualDesktop.Service.exe [1962920 2020-12-01] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\NisSrv.exe [3170576 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MsMpEng.exe [133584 2022-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [34384 2021-10-21] (ASUSTeK Computer Inc. -> )
R1 Asusgio3; C:\Windows\system32\drivers\AsIO3.sys [43192 2021-09-16] (ASUSTeK Computer Inc. -> )
S3 atvi-brynhildr; C:\ProgramData\Battle.net_components\brynhildr_odin\brynhildr.sys [2355952 2021-12-21] (Activision Publishing Inc -> Activision Blizzard, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [507904 2022-01-22] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [180224 2022-01-22] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [98304 2021-06-05] (Microsoft Corporation) [File not signed]
R1 CTIIO; C:\WINDOWS\system32\drivers\CtiIo64.sys [30728 2022-01-22] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
R1 GLCKIO2; C:\Windows\system32\drivers\GLCKIO2.sys [29368 2019-04-24] (ASUSTeK Computer Inc. -> )
R1 googledrivefs31092; C:\WINDOWS\System32\DRIVERS\googledrivefs31092.sys [384600 2023-02-08] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [46728 2021-06-28] (ASUSTEK COMPUTER INC. -> ASUSTeK Computer Inc.)
R3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [33528 2022-03-24] (WDKTestCert builder,132743893872553407 -> Logitech)
S3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [21704 2022-03-24] (WDKTestCert builder,132743893872553407 -> Logitech)
R3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [62904 2022-03-24] (WDKTestCert builder,132743893872553407 -> Logitech)
R3 MpKsl473235f5; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{12815B20-1960-4D08-8880-F5E60B7479C6}\MpKslDrv.sys [211208 2023-04-14] (Microsoft Windows -> Microsoft Corporation)
R1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation)
R3 oculusvad_oculusvad; C:\WINDOWS\System32\drivers\oculusvad.sys [75280 2021-11-08] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 Oculus_ViGEmBus; C:\WINDOWS\System32\drivers\Oculus_ViGEmBus.sys [32856 2020-09-19] (Oculus VR, LLC -> Facebook Inc.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R3 rtwlane_13; C:\WINDOWS\System32\drivers\rtwlane_13.sys [3717120 2021-06-01] (Microsoft Windows -> Realtek Semiconductor Corporation)
R3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [48848 2020-12-21] (SteelSeries ApS -> SteelSeries ApS)
R3 SteelSeries_Sonar_VAD; C:\WINDOWS\System32\DriverStore\FileRepository\steelseries-sonar-vad.inf_amd64_6f6e907eca1efa31\SteelSeries-Sonar-VAD.sys [89568 2022-03-23] (SteelSeries ApS -> Windows (R) Win 7 DDK provider)
S3 TPS65994; C:\WINDOWS\System32\drivers\TPS65994.sys [49232 2019-12-24] (FPT USA Corp. -> )
R3 vdvad_WaveExtensible; C:\WINDOWS\System32\drivers\vdvad.sys [41072 2019-03-14] (Virtual Desktop, Inc. -> Virtual Desktop)
R3 vdvge; C:\WINDOWS\System32\drivers\vdvge.sys [77864 2018-11-13] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49616 2022-10-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [455968 2022-10-19] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [95520 2022-10-19] (Microsoft Windows -> Microsoft Corporation)
S3 EAAntiCheat; system32\drivers\eaanticheat.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-04-14 14:30 - 2023-04-14 14:30 - 000027091 _ C:\Users\Adrián\Downloads\FRST.txt
2023-04-14 14:30 - 2023-04-14 14:30 - 000000000 ____D C:\Users\Adrián\Downloads\FRST-OlderVersion
2023-04-14 03:23 - 2023-04-14 03:23 - 000003862 _ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2023-04-14 03:23 - 2023-04-14 03:23 - 000003420 _ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2023-04-14 03:23 - 2023-04-14 03:23 - 000000262 _ C:\Users\Adrián\Downloads\eset.txt
2023-04-14 00:32 - 2023-04-14 00:32 - 000001383 _ C:\Users\Adrián\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2023-04-14 00:32 - 2023-04-14 00:32 - 000001277 _ C:\Users\Adrián\Desktop\ESET Online Scanner.lnk
2023-04-14 00:32 - 2023-04-14 00:32 - 000000000 ____D C:\Users\Adrián\AppData\Local\ESET
2023-04-14 00:31 - 2023-04-14 00:31 - 015274968 _ (ESET) C:\Users\Adrián\Downloads\esetonlinescanner.exe
2023-04-14 00:29 - 2023-04-14 00:29 - 000051068 _ C:\Users\Adrián\Downloads\Fixlog.txt
2023-04-14 00:20 - 2023-04-14 00:20 - 002380288 _ (Farbar) C:\Users\Adrián\Downloads\Non confirmé 120565.crdownload
2023-04-13 19:32 - 2023-04-13 19:34 - 000086722 _ C:\Users\Adrián\Downloads\Addition.txt
2023-04-13 18:49 - 2023-04-14 14:30 - 000000000 ____D C:\FRST
2023-04-13 18:46 - 2023-04-14 14:30 - 002380288 _ (Farbar) C:\Users\Adrián\Downloads\FRSTEnglish.exe
2023-04-11 20:46 - 2023-04-11 20:46 - 000000000 ___HD C:\$WinREAgent
2023-04-11 15:28 - 2023-04-11 15:28 - 000000000 ____D C:\Users\Adrián\AppData\Roaming\EA
2023-04-11 15:28 - 2023-04-11 15:28 - 000000000 ____D C:\Program Files\EA
2023-04-11 15:21 - 2023-04-11 15:21 - 000000839 _ C:\Users\Public\Desktop\FIFA 23.lnk
2023-04-11 14:47 - 2023-04-11 15:11 - 000000000 ____D C:\ProgramData\EA Desktop
2023-04-11 14:47 - 2023-04-11 14:47 - 002048920 _ (Electronic Arts) C:\Users\Adrián\Downloads\EAappInstaller.exe
2023-04-11 14:47 - 2023-04-11 14:47 - 000000000 ____D C:\Users\Adrián\AppData\Local\Origin
2023-04-11 14:20 - 2023-04-11 14:20 - 000004040 _ C:\WINDOWS\system32\Tasks\PostponeDeviceSetupToast_S-1-5-21-3254008329-1205757616-3926439971-1001_2
2023-04-10 01:00 - 2023-04-10 01:00 - 000001040 _ C:\Users\Public\Desktop\Les Sims 4.lnk
2023-04-10 01:00 - 2023-04-10 00:53 - 000447752 _ (On2.com) C:\WINDOWS\SysWOW64\vp6vfw.dll
2023-04-09 22:12 - 2023-04-09 22:12 - 000000000 ____D C:\Users\Adrián\AppData\Local\Yandex
2023-04-03 21:25 - 2023-04-03 21:25 - 000000000 ____D C:\Users\Adrián\AppData\LocalLow\Cyanide
2023-04-03 21:24 - 2023-04-03 21:24 - 000000223 _ C:\Users\Adrián\Desktop\Chef Life A Restaurant Simulator.url
2023-03-21 19:37 - 2023-03-21 19:37 - 000000222 _ C:\Users\Adrián\Desktop\Rocket League.url
2023-03-19 20:50 - 2023-03-19 20:50 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2023-03-19 20:50 - 2023-03-19 20:50 - 000000000 ____D C:\Program Files (x86)\Microsoft GameInput
2023-03-15 03:23 - 2023-03-09 09:57 - 002172512 _ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 002172512 _ C:\WINDOWS\system32\vulkaninfo.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 001607776 _ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 001607776 _ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2023-03-15 03:23 - 2023-03-09 09:57 - 001487336 _ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001479264 _ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001479264 _ C:\WINDOWS\system32\vulkan-1.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001226736 _ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001211488 _ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2023-03-15 03:23 - 2023-03-09 09:57 - 001211488 _ C:\WINDOWS\SysWOW64\vulkan-1.dll
2023-03-15 03:23 - 2023-03-09 09:54 - 000671744 _ C:\WINDOWS\system32\nvofapi64.dll
2023-03-15 03:23 - 2023-03-09 09:54 - 000506344 _ C:\WINDOWS\SysWOW64\nvofapi.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 001534448 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 001192960 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 000851432 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2023-03-15 03:23 - 2023-03-09 09:53 - 000741360 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2023-03-15 03:23 - 2023-03-09 09:52 - 002163736 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2023-03-15 03:23 - 2023-03-09 09:52 - 001620016 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2023-03-15 03:23 - 2023-03-09 09:52 - 000977944 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2023-03-15 03:23 - 2023-03-09 09:52 - 000758272 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 013765632 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 011645952 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 003430400 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2023-03-15 03:23 - 2023-03-09 09:51 - 000457752 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2023-03-15 03:23 - 2023-03-09 09:50 - 006084136 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2023-03-15 03:23 - 2023-03-09 09:50 - 005911600 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2023-03-15 03:23 - 2023-03-09 09:50 - 005835312 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2023-03-15 03:23 - 2023-03-09 09:50 - 000852976 _ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2023-03-15 03:23 - 2023-03-08 13:17 - 000104256 _ C:\WINDOWS\system32\nvinfo.pb
2023-03-15 03:12 - 2022-07-14 01:32 - 000060112 _ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2023-04-14 14:29 - 2020-10-25 11:40 - 000000000 ____D C:\Users\Adrián\AppData\Roaming\discord
2023-04-14 14:29 - 2020-10-25 11:40 - 000000000 ____D C:\Users\Adrián\AppData\Local\Discord
2023-04-14 14:29 - 2020-06-14 04:12 - 000000000 ____D C:\Program Files (x86)\Steam
2023-04-14 14:28 - 2022-01-22 18:17 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-04-14 14:28 - 2020-06-14 04:07 - 000000000 ____D C:\Program Files (x86)\Google
2023-04-14 13:48 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-04-14 13:48 - 2020-06-18 22:33 - 000000000 ____D C:\ProgramData\NVIDIA
2023-04-14 13:48 - 2020-06-14 05:33 - 000000000 ____D C:\Users\Adrián\AppData\Local\Oculus
2023-04-14 03:30 - 2021-06-05 14:10 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-04-14 01:35 - 2020-06-14 03:57 - 000000000 ____D C:\Users\Adrián\AppData\Local\D3DSCache
2023-04-14 00:37 - 2022-01-22 18:32 - 002702328 _ C:\WINDOWS\system32\PerfStringBackup.INI
2023-04-14 00:37 - 2022-01-22 17:58 - 000745774 _ C:\WINDOWS\system32\perfh007.dat
2023-04-14 00:37 - 2022-01-22 17:58 - 000155996 _ C:\WINDOWS\system32\perfc007.dat
2023-04-14 00:37 - 2021-06-05 20:15 - 000806506 _ C:\WINDOWS\system32\perfh00C.dat
2023-04-14 00:37 - 2021-06-05 20:15 - 000156164 _ C:\WINDOWS\system32\perfc00C.dat
2023-04-14 00:37 - 2021-06-05 14:09 - 000000000 ____D C:\WINDOWS\INF
2023-04-14 00:31 - 2021-02-24 17:05 - 000000000 ____D C:\Users\Adrián\AppData\Local\CrashDumps
2023-04-14 00:30 - 2022-01-22 18:29 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-04-14 00:30 - 2020-06-14 02:34 - 001230088 _ C:\WINDOWS\system32\wpbbin.exe
2023-04-14 00:30 - 2020-06-14 02:34 - 001191552 _ C:\WINDOWS\system32\AsusUpdateCheck.exe
2023-04-14 00:30 - 2020-06-14 02:34 - 000012288 ___SH C:\DumpStack.log.tmp
2023-04-14 00:29 - 2021-06-05 14:01 - 000524288 _ C:\WINDOWS\system32\config\BBI
2023-04-13 21:33 - 2022-01-22 18:19 - 000000000 ____D C:\Users\Adrián
2023-04-13 19:32 - 2021-06-05 14:10 - 000000000 ___HD C:\Program Files\WindowsApps
2023-04-13 19:32 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-04-11 20:50 - 2021-06-05 14:01 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-04-11 15:21 - 2022-06-20 18:12 - 000000000 ___HD C:\Program Files\Common Files\EAInstaller
2023-04-11 14:47 - 2023-02-06 20:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2023-04-11 14:47 - 2023-02-06 20:32 - 000000000 ____D C:\Program Files\Electronic Arts
2023-04-11 14:47 - 2020-06-14 04:14 - 000000000 ____D C:\ProgramData\Origin
2023-04-11 14:47 - 2020-06-14 04:07 - 000000000 ____D C:\ProgramData\Package Cache
2023-04-11 14:46 - 2020-06-14 04:59 - 000000000 ____D C:\Program Files (x86)\Origin Games
2023-04-11 13:16 - 2022-01-22 18:29 - 000003592 _ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3254008329-1205757616-3926439971-1001
2023-04-11 13:16 - 2022-01-22 18:29 - 000003382 _ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3254008329-1205757616-3926439971-1001
2023-04-11 13:16 - 2021-08-25 12:44 - 000002424 _ C:\Users\Adrián\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-04-11 01:20 - 2022-01-22 18:29 - 000003884 _ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-04-11 01:20 - 2022-01-22 18:29 - 000003760 _ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2023-04-11 00:38 - 2020-09-23 21:05 - 000000000 ____D C:\Users\Adrián\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2023-04-10 14:39 - 2021-08-31 16:55 - 000002057 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2023-04-10 14:39 - 2021-08-31 16:55 - 000001899 _ C:\Users\Default\Desktop\Google Slides.lnk
2023-04-10 14:39 - 2021-08-31 16:55 - 000001899 _ C:\Users\Default\Desktop\Google Sheets.lnk
2023-04-10 14:39 - 2021-08-31 16:55 - 000001887 _ C:\Users\Default\Desktop\Google Docs.lnk
2023-04-07 17:49 - 2022-01-22 18:29 - 000003690 _ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-04-07 17:49 - 2022-01-22 18:29 - 000003566 _ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-04-07 17:49 - 2020-10-25 11:37 - 000002236 _ C:\Users\Adrián\Desktop\Discord.lnk
2023-04-05 18:39 - 2020-06-14 01:45 - 000000000 ____D C:\Users\Adrián\AppData\Local\NVIDIA
2023-03-27 18:19 - 2021-11-29 14:19 - 000000000 ____D C:\Program Files (x86)\Overwolf
2023-03-19 20:50 - 2022-11-26 21:15 - 000079352 _ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2023-03-19 20:50 - 2022-11-26 21:15 - 000062928 _ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2023-03-19 20:50 - 2021-12-03 18:02 - 002786768 _ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000476624 _ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000243200 _ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000202192 _ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000165328 _ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2023-03-19 20:50 - 2021-12-03 18:02 - 000131072 _ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2023-03-15 03:12 - 2022-01-22 18:29 - 000004308 C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003976 C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003940 C:\WINDOWS\system32\Tasks\NvNodeLauncher{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003894 C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003858 C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2022-01-22 18:29 - 000003654 C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2023-03-15 03:12 - 2021-06-05 14:10 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2023-03-15 03:12 - 2020-06-14 13:50 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2023-03-15 03:12 - 2020-06-14 04:12 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2023-03-15 03:12 - 2020-06-14 04:12 - 000000000 ____D C:\Program Files\NVIDIA Corporation

==================== Files in the root of some directories ========

2020-07-05 18:40 - 2020-07-05 18:43 - 006576161 _ () C:\Program Files (x86)\Common Files\forge-1.16.1-32.0.20-installer.jar
2020-07-01 19:15 - 2020-07-05 18:46 - 005322161 _ () C:\Program Files (x86)\Common Files\OptiFine_1.16_HD_U_H1.jar
2021-04-02 14:33 - 2021-04-02 14:37 - 000012288 _ () C:\Users\Adrián\AppData\Roaming\emp.bin
2022-02-07 14:36 - 2023-02-13 20:17 - 000000128 _ () C:\Users\Adrián\AppData\Local\PUTTY.RND
2020-06-14 04:20 - 2021-08-06 19:08 - 000007604 _ () C:\Users\Adrián\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
 

Attachments

#9 ·
They're still there, so I recommend you do the following ....

Uninstall Chrome ... Uninstall Google Chrome - Computer - Google Chrome Help

If you sync your Chrome data, clear your browsing data first ... Clear browsing data - Android - Google Chrome Help

Delete your Chrome profile folder ... How to Find Your Chrome Profile Folder on Windows, Mac, and Linux

Reboot your Computer .... to complete the removal.

Now re-install a new clean copy of Chrome .... Google Chrome – Download the fast, secure browser from Google