Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-04-2022
Ran by Ganja (administrator) on DESKTOP-V4BFEG5 (ASUSTeK COMPUTER INC. X456URK) (15-04-2022 22:52:17)
Running from C:\Users\Ganja\Desktop
Loaded Profiles: Ganja
Platform: Microsoft Windows 10 Pro Version 20H2 19042.1586 (X64) Language: English (United Kingdom)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Conexant Systems LLC → Conexant Systems, Inc) C:\Program Files\CONEXANT\SAII\SmartAudio.exe
(Conexant Systems LLC → Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent 64.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_b8e0 1d9e8716d2a7\igfxCUIService.exe ->) (Intel(R) pGFX 2020 → Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui _dch.inf_amd64_b8e01d9e8716d2a7\igfxEM.exe
(explorer.exe ->) (Google LLC → Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <9>
(explorer.exe ->) (INTEL CORP) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1. 100.3407.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSys Tray\IGCCTray.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation → Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(services.exe ->) (Conexant Systems, Inc. → Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(services.exe ->) (Conexant Systems, Inc. → Conexant Systems, Inc.) C:\Windows\System32\SASrv.exe
(services.exe ->) (Dropbox, Inc → Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(services.exe ->) (ICEpower a/s → ICEpower A/S) C:\Windows\System32\DriverStore\FileRepository\x40 plmwa.inf_amd64_0fe274d0aafd5420\ICEsoundService64 .exe
(services.exe ->) (Intel Corporation → Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel(R) pGFX 2020 → Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui _dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe
(services.exe ->) (Intel(R) pGFX 2020 → Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igc c_dch.inf_amd64_54b736e5be5b50b2\OneApp.IGCC.WinSe rvice.exe
(services.exe ->) (Intel(R) pGFX 2020 → Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iig d_dch.inf_amd64_a086f01cc7be643a\IntelCpHDCPSvc.ex e
(services.exe ->) (Intel(R) pGFX 2020 → Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iig d_dch.inf_amd64_a086f01cc7be643a\IntelCpHeciSvc.ex e
(services.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\Pres entationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher → Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher → Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation → NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nva mi.inf_amd64_036f20146ac187ce\Display.NvContainer\ NVDisplay.Container.exe <2>
(svchost.exe ->) (INTEL CORP) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1. 100.3407.0_x64__8j3eq9eme6ctt\IGCC.exe
(svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.e xe [509936 2018-04-11] (Adobe Systems Incorporated → Adobe Systems Incorporated)
HKLM...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-10-09] (Adobe Inc. → Adobe Systems, Incorporated)
HKLM...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation → Microsoft Corporation)
HKLM-x32...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [10586448 2022-04-12] (Dropbox, Inc → Dropbox, Inc.)
HKLM...\Policies\Explorer: [HideSCAMeetNow] 1
HKLM...\Policies\Explorer: [NoWindowsUpdate] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3947486154-1424391867-2577238500-1001...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [36705520 2022-04-07] (Piriform Software Ltd → Piriform Software Ltd)
HKU\S-1-5-21-3947486154-1424391867-2577238500-1001...\Policies\Explorer: [HideSCAMeetNow] 1
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] → C:\Program Files (x86)\Google\Chrome\Application\100.0.4896.88\Inst aller\chrmstp.exe [2022-04-14] (Google LLC → Google LLC)
IFEO\EOSnotify.exe: [Debugger] /
IFEO\InstallAgent.exe: [Debugger] /
IFEO\MusNotification.exe: [Debugger] /
IFEO\MusNotificationUx.exe: [Debugger] /
IFEO\remsh.exe: [Debugger] /
IFEO\SihClient.exe: [Debugger] /
IFEO\UpdateAssistant.exe: [Debugger] /
IFEO\upfc.exe: [Debugger] /
IFEO\UsoClient.exe: [Debugger] /
IFEO\WaaSMedic.exe: [Debugger] /
IFEO\WaasMedicAgent.exe: [Debugger] /
IFEO\Windows10Upgrade.exe: [Debugger] /
IFEO\Windows10UpgraderApp.exe: [Debugger] /
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
HKU\S-1-5-21-3947486154-1424391867-2577238500-1001\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {21F74A47-3424-418E-A53B-4E2562C05ABA} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-29] (Dropbox, Inc → Dropbox, Inc.)
Task: {35C3CE0C-6E9C-4368-8970-5A1EC2984974} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Ganja\AppData\Local\ESET\ESETOnlineScanne r\ESETOnlineScanner.exe SCHED (No File)
Task: {38B1D35F-5B27-469E-9023-B883D23E4840} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
Task: {6D49D09F-9853-422D-A970-E82C99B5D8DF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
Task: {7F3569B1-34AE-46F6-B4D7-9D41822A766E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
Task: {8B831FA3-91A3-4CA8-8115-CED07AB87029} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-04-07] (Piriform Software Ltd → Piriform)
Task: {A35BAD01-9115-4CE5-8E83-CE0363167108} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-10-09] (Adobe Inc. → Adobe Systems, Incorporated)
Task: {A9461498-6A3F-4F98-B10D-680CD902F8BB} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Ganja\AppData\Local\ESET\ESETOnlineScanne r\ESETOnlineScanner.exe LOGON (No File)
Task: {B40A30F0-F3F8-4F31-B890-EEC38512349B} - System32\Tasks\Microsoft\Windows\Conexant\SA2 => C:\Program Files\CONEXANT\SAII\SACpl.exe [1832280 2017-06-07] (Conexant Systems, Inc. → Conexant Systems, Inc.)
Task: {B9D60D3E-8E0C-48C1-B4EF-1EF747D27549} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
Task: {C630BFDF-4B2F-4271-9B1F-2DB64E5A7F09} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [275136 2022-03-30] (Bluestack Systems, Inc → BlueStack Systems, Inc.)
Task: {DC0F9DAF-1B83-45D9-AA91-B9C6BD78042B} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-29] (Dropbox, Inc → Dropbox, Inc.)
Task: {E8D71E94-B741-496F-BAFF-AFADFF2255A0} - System32\Tasks\Microsoft\Windows\Conexant\AFA => C:\Program Files\CONEXANT\cAudioFilterAgent\SACpl.exe [1823232 2016-07-05] (Conexant Systems, Inc.) [File not signed]
Task: {EF5C000F-603E-4C0E-B31C-A6C10E91FE43} - System32\Tasks\CCleanerSkipUAC - Ganja => C:\Program Files\CCleaner\CCleaner.exe [30836464 2022-04-07] (Piriform Software Ltd → Piriform Software Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.43.193
Tcpip..\Interfaces{bff8e11e-7cb0-43cd-8ed2-84f8481e005d}: [DhcpNameServer] 192.168.43.193
Tcpip..\Interfaces{fc72d37d-562e-4e97-a7cf-ea1989188cd8}: [DhcpNameServer] 192.168.1.1
[HEADING=1]FireFox:[/HEADING]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 → C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation → Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.12 → C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-19] (VideoLAN → VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 → C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-19] (VideoLAN → VideoLAN)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 → C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation → Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 → C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation → Microsoft Corporation)
[HEADING=1]Chrome:[/HEADING]
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Default [2022-04-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda [2021-02-16]
CHR Profile: C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Guest Profile [2022-04-14]
CHR Profile: C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1 [2022-04-15]
CHR Extension: (Slides) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2022-03-19]
CHR Extension: (Docs) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2022-03-19]
CHR Extension: (Google Drive) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2022-03-19]
CHR Extension: (YouTube) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2022-03-19]
CHR Extension: (Sheets) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2022-03-19]
CHR Extension: (Google Docs Offline) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-03-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-03-19]
CHR Extension: (Gmail) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2022-03-19]
CHR Profile: C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\System Profile [2022-04-14]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3147344 2019-10-09] (Adobe Inc. → Adobe Systems, Incorporated)
S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2914896 2019-10-09] (Adobe Inc. → Adobe Systems, Incorporated)
S4 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-29] (Dropbox, Inc → Dropbox, Inc.)
S4 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-29] (Dropbox, Inc → Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [45408 2022-04-12] (Dropbox, Inc → Dropbox, Inc.)
S4 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [805488 2019-10-16] (EasyAntiCheat Oy → EasyAntiCheat Ltd)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [7965288 2020-03-05] (INCA Internet Co.,Ltd. → INCA Internet Co., Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6228008 2022-04-10] (Microsoft Windows Publisher → Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\NisSrv.exe [3116848 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MsMpEng.exe [133544 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nva mi.inf_amd64_036f20146ac187ce\Display.NvContainer\ NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nva mi.inf_amd64_036f20146ac187ce\Display.NvContainer\ plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AsusPTPDrv; C:\WINDOWS\System32\drivers\AsusPTPFilter.sys [108504 2019-04-24] (ASUSTek Computer Inc. → ASUSTek COMPUTER INC.)
R2 BlueStacksDrv_nxt; C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [320728 2022-03-30] (Bluestack Systems, Inc → Bluestack System Inc.)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32696 2020-11-19] (ASUSTek Computer Inc. → ASUS)
S3 MpKslbaf14ff9; C:\ProgramData\Microsoft\Windows Defender\Definition Updates{7F45780D-EC7B-4BC8-8BAA-D56A3AB21734}\MpKslDrv.sys [139536 2022-04-15] (Microsoft Windows → Microsoft Corporation)
R3 Neo_VPN; C:\WINDOWS\System32\drivers\Neo6_x64_VPN.sys [37824 2020-04-18] (SoftEther Corporation → SoftEther Corporation)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [23040 2020-01-10] (Apple Inc.) [File not signed]
R1 SeLow; C:\WINDOWS\system32\DRIVERS\SeLow_x64.sys [50624 2020-04-18] (SoftEther Corporation → SoftEther Corporation)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [31232 2019-12-02] (OpenVPN Technologies, Inc. → The OpenVPN Project)
S3 tesrsdt; C:\Windows\system32\drivers\tesrsdt.sys [812208 2020-06-29] (Tencent Technology(Shenzhen) Company Limited → TENCENT)
S3 UniSafe; C:\Windows\system32\drivers\UniSafe.sys [581912 2020-06-29] (Tencent Technology(Shenzhen) Company Limited → TENCENT)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49600 2022-04-14] (Microsoft Windows Early Launch Anti-malware Publisher → Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [443664 2022-04-14] (Microsoft Windows → Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [90384 2022-04-14] (Microsoft Windows → Microsoft Corporation)
S3 MpKsl5fba685f; ??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates{2B02F115-5134-4409-8760-F9955DF0D9D3}\MpKslDrv.sys
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-04-15 22:52 - 2022-04-15 22:54 - 000016808 _____ C:\Users\Ganja\Desktop\FRST.txt
2022-04-15 22:49 - 2022-01-29 00:20 - 000000000 ____D C:\Users\Ganja\Desktop\Wub
2022-04-15 22:40 - 2022-04-15 22:41 - 000011406 _____ C:\ProgramData\DisplaySessionContainer1.log_backup 1
2022-04-15 21:43 - 2022-04-15 21:43 - 000000000 ____D C:\Users\Ganja\AppData\Local\OO Software
2022-04-15 21:25 - 2022-04-15 21:25 - 001604008 _____ (O&O Software GmbH) C:\Users\Ganja\Desktop\OOSU10.exe
2022-04-15 21:16 - 2022-04-15 22:41 - 000022706 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_back up1
2022-04-15 21:16 - 2022-04-15 22:41 - 000018632 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_ backup1
2022-04-15 21:16 - 2022-04-15 21:16 - 000001206 _____ C:\ProgramData\NvcDispCorePlugin.log_backup1
2022-04-15 19:42 - 2022-04-15 21:06 - 000107535 _____ C:\Users\Ganja\Desktop\Fixlog.txt
2022-04-15 19:42 - 2022-04-15 19:42 - 002366464 _____ (Farbar) C:\Users\Ganja\Desktop\FRST64.exe
2022-04-15 19:40 - 2022-04-15 19:40 - 000000000 ____D C:\Users\Ganja\AppData\Local\BlueStacks
2022-04-15 19:21 - 2022-04-15 19:21 - 000000000 ____D C:\Users\Ganja\AppData\Local\Conexant
2022-04-14 22:51 - 2022-04-14 22:51 - 000000000 ____D C:\Users\Ganja\Downloads\Lang
2022-04-14 22:51 - 2019-10-18 02:19 - 000918718 ____N C:\Users\Ganja\Downloads\readme.txt
2022-04-14 22:51 - 2019-10-18 02:19 - 000038514 ____N C:\Users\Ganja\Downloads\Setup.if2
2022-04-14 22:51 - 2019-10-18 02:19 - 000014060 ____N C:\Users\Ganja\Downloads\Installation_Readme.txt
2022-04-14 22:51 - 2019-10-18 02:19 - 000007567 ____N C:\Users\Ganja\Downloads\mup.xml
2022-04-14 22:50 - 2022-04-15 19:09 - 000000000 ____D C:\Users\Ganja\Downloads\Graphics
2022-04-14 22:46 - 2022-04-15 08:11 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2022-04-14 22:39 - 2022-04-14 22:39 - 000000000 ____D C:\Program Files\Common Files\QCA_Bluetooth
2022-04-14 22:38 - 2022-04-14 22:39 - 000000000 ____D C:\Program Files (x86)\Qualcomm
2022-04-14 22:35 - 2022-04-15 19:09 - 000000000 ____D C:\ProgramData\AmUStor
2022-04-14 22:35 - 2022-04-15 19:09 - 000000000 ____D C:\Program Files (x86)\AmUStor
2022-04-14 22:01 - 2022-04-15 00:04 - 000000000 ____D C:\ProgramData\ASUS
2022-04-14 21:50 - 2022-04-14 21:50 - 000000000 ____D C:\Users\Ganja\Intel
2022-04-14 21:47 - 2022-04-15 00:04 - 000000000 ____D C:\Program Files (x86)\ASUS
2022-04-14 21:40 - 2022-04-14 21:44 - 379569687 _____ C:\Users\Ganja\Downloads\VGA_Intel_Win10_64_VER262 01007325_DriverOnly.zip.zip
2022-04-14 21:40 - 2022-04-14 21:42 - 135721680 _____ (ASUSTeK COMPUTER INC.) C:\Users\Ganja\Downloads\Audio_Conexant_Z_V8.66.95 .70Sub3_21875.exe
2022-04-14 21:40 - 2022-04-14 21:42 - 066241082 _____ C:\Users\Ganja\Downloads\MEI_Intel_15M_Win10_64_VE R11001177.zip
2022-04-14 20:20 - 2022-04-14 20:20 - 000001985 _____ C:\Users\Ganja\Desktop\RöX.lnk
2022-04-14 19:46 - 2022-04-14 19:46 - 000003938 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper_nxt
2022-04-14 19:46 - 2022-04-14 19:46 - 000002115 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5 Multi-Instance Manager.lnk
2022-04-14 19:46 - 2022-04-14 19:46 - 000002103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk
2022-04-14 19:44 - 2022-04-15 19:21 - 000000000 ____D C:\ProgramData\BlueStacks_nxt
2022-04-14 19:44 - 2022-04-15 19:10 - 000000000 ____D C:\Program Files\BlueStacks_nxt
2022-04-14 19:40 - 2022-04-15 19:10 - 000000000 ____D C:\Users\Ganja\AppData\Local\BlueStacksSetup
2022-04-14 19:12 - 2022-04-14 19:12 - 000000000 ____D C:\LDPlayer
2022-04-14 19:06 - 2022-04-14 19:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2022-04-14 19:06 - 2022-04-14 19:06 - 000000000 ____D C:\Program Files\Google
2022-04-14 18:58 - 2022-04-14 21:19 - 000001050 _____ C:\Users\Public\Desktop\CCleaner.lnk
2022-04-14 18:58 - 2022-04-14 18:58 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2022-04-14 18:58 - 2022-04-14 18:58 - 000002904 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Ganja
2022-04-14 18:57 - 2022-04-14 19:07 - 000000000 ____D C:\PatchMyPCUpdates
2022-04-13 23:40 - 2022-04-13 23:40 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Tencent
2022-04-13 23:40 - 2022-04-13 23:40 - 000000000 ____D C:\ProgramData\Tencent
2022-04-13 18:15 - 2022-04-13 18:17 - 000000865 _____ C:\Users\Ganja\Desktop\ZHPDiag.lnk
2022-04-13 17:23 - 2022-04-13 17:29 - 000290304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\subinacl.exe
2022-04-13 17:23 - 2022-04-13 17:23 - 000000000 ____D C:\Program Files (x86)\Adware Removal Tool by TSA
2022-04-13 17:21 - 2022-04-13 17:21 - 000752296 _____ C:\Users\Ganja\Desktop\adware-removal-tool-by-tsa.exe
2022-04-13 17:19 - 2022-04-13 17:19 - 003295944 _____ (Nicolas Coolman) C:\Users\Ganja\Desktop\ZHPCleaner.exe
2022-04-13 17:19 - 2022-04-13 17:19 - 003287240 _____ (Nicolas Coolman) C:\Users\Ganja\Desktop\ZHPDiag3.exe
2022-04-13 06:52 - 2022-04-13 06:52 - 000003858 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2022-04-13 06:52 - 2022-04-13 06:52 - 000003416 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2022-04-12 21:52 - 2022-04-12 21:52 - 000001398 _____ C:\Users\Ganja\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\ESET Online Scanner.lnk
2022-04-12 21:52 - 2022-04-12 21:52 - 000001292 _____ C:\Users\Ganja\Desktop\ESET Online Scanner.lnk
2022-04-12 21:52 - 2022-04-12 21:52 - 000000000 ____D C:\Users\Ganja\AppData\Local\ESET
2022-04-12 21:49 - 2022-04-12 21:49 - 015274968 _____ (ESET) C:\Users\Ganja\Desktop\esetonlinescanner.exe
2022-04-12 21:33 - 2022-04-12 21:33 - 000000008 __RSH C:\ProgramData\ntuser.pol
2022-04-12 21:28 - 2022-04-12 21:28 - 000010416 _____ C:\ProgramData\DisplaySessionContainer2.log_backup 1
2022-04-12 21:20 - 2022-04-12 21:25 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Geek Uninstaller
2022-04-12 21:19 - 2022-03-23 06:16 - 006392680 _____ (Geek UnС–nstaller) C:\Users\Ganja\Desktop\geek.exe
2022-04-12 21:15 - 2022-04-12 21:16 - 008540344 _____ (Malwarebytes) C:\Users\Ganja\Desktop\adwcleaner_8.3.1.exe
2022-04-12 08:52 - 2022-04-12 08:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2022-04-12 08:52 - 2022-04-12 08:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2022-04-12 08:52 - 2022-04-12 08:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2022-04-12 08:52 - 2022-04-12 08:52 - 000045408 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2022-04-10 04:33 - 2022-04-09 20:11 - 000000000 ____D C:\Windows.old
2022-04-10 04:20 - 2022-04-10 04:33 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2022-04-10 04:14 - 2022-04-10 04:20 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2022-04-10 04:14 - 2022-04-10 04:14 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2022-04-10 04:03 - 2022-04-10 04:03 - 000000000 ____D C:\WINDOWS\SystemTemp
2022-04-10 04:03 - 2022-04-10 04:03 - 000000000 ____D C:\ProgramData\ssh
2022-04-10 03:48 - 2022-04-10 03:48 - 001687040 _____ C:\WINDOWS\system32\libcrypto.dll
2022-04-10 03:47 - 2022-04-10 03:47 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2022-04-10 03:47 - 2022-04-10 03:47 - 000101704 _____ C:\WINDOWS\SysWOW64\HvsiManagementApi.dll
2022-04-10 03:47 - 2022-04-10 03:47 - 000095744 _____ C:\WINDOWS\system32\VirtualMonitorManager.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2022-04-10 03:46 - 2022-04-10 03:46 - 000480256 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000195584 _____ C:\WINDOWS\system32\uwfcfgmgmt.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000170496 _____ C:\WINDOWS\system32\DeviceUpdateCenterCsp.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000158208 _____ C:\WINDOWS\system32\uwfcsp.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000138056 _____ C:\WINDOWS\system32\HvsiManagementApi.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000040960 _____ C:\WINDOWS\system32\uwfservicingapi.dll
2022-04-10 03:45 - 2022-04-10 03:45 - 000672768 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2022-04-10 03:45 - 2022-04-10 03:45 - 000464384 _____ (curl, hxxps://curl.se/) C:\WINDOWS\SysWOW64\curl.exe
2022-04-10 03:45 - 2022-04-10 03:45 - 000053760 _____ C:\WINDOWS\SysWOW64\BWContextHandler.dll
2022-04-10 03:45 - 2022-04-10 03:45 - 000045880 _____ C:\WINDOWS\system32\HvSocket.dll
2022-04-10 03:44 - 2022-04-10 03:44 - 002371072 _____ C:\WINDOWS\system32\rdpnano.dll
2022-04-10 03:44 - 2022-04-10 03:44 - 000523776 _____ (curl, hxxps://curl.se/) C:\WINDOWS\system32\curl.exe
2022-04-10 03:44 - 2022-04-10 03:44 - 000067072 _____ C:\WINDOWS\system32\BWContextHandler.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000011911 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-04-10 03:42 - 2022-04-10 03:42 - 002111488 _____ (Digimarc) C:\WINDOWS\SysWOW64\DMRCDecoder.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 001864192 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 000611960 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 000468440 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 000235520 _____ C:\WINDOWS\SysWOW64\HeatCore.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 000047472 _____ C:\WINDOWS\SysWOW64\umpdc.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 001164288 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2022-04-10 03:41 - 2022-04-10 03:41 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 000330752 _____ C:\WINDOWS\SysWOW64\ssdm.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 000266240 _____ C:\WINDOWS\SysWOW64\Windows.Internal.UI.Shell.Wind owTabManager.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 000240640 _____ C:\WINDOWS\SysWOW64\CoreMas.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2022-04-10 03:41 - 2022-04-10 03:41 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 000010752 _____ C:\WINDOWS\SysWOW64\agentactivationruntimestarter. exe
2022-04-10 03:39 - 2022-04-10 03:39 - 002254336 _____ C:\WINDOWS\system32\dwmscene.dll
2022-04-10 03:39 - 2022-04-10 03:39 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2022-04-10 03:39 - 2022-04-10 03:39 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2022-04-10 03:39 - 2022-04-10 03:39 - 000001370 _____ C:\WINDOWS\system32\ThirdPartyNoticesBySHS.txt
2022-04-10 03:38 - 2022-04-10 03:38 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2022-04-10 03:38 - 2022-04-10 03:38 - 000190976 _____ C:\WINDOWS\system32\BthpanContextHandler.dll
2022-04-10 03:38 - 2022-04-10 03:38 - 000152064 _____ C:\WINDOWS\system32\EoAExperiences.exe
2022-04-10 03:38 - 2022-04-10 03:38 - 000098304 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2022-04-10 03:37 - 2022-04-10 03:37 - 002295296 _____ (Digimarc) C:\WINDOWS\system32\DMRCDecoder.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 000706536 _____ C:\WINDOWS\system32\TextShaping.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 000657464 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 000306688 _____ C:\WINDOWS\system32\HeatCore.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 000029696 _____ (The ICU Project) C:\WINDOWS\system32\icuuc.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 000025088 _____ (The ICU Project) C:\WINDOWS\system32\icuin.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 004227116 _____ C:\WINDOWS\system32\DefaultHrtfs.bin
2022-04-10 03:35 - 2022-04-10 03:35 - 000455168 _____ C:\WINDOWS\system32\ssdm.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000363520 _____ C:\WINDOWS\system32\Windows.Internal.UI.Shell.Wind owTabManager.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjec ts.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000272896 _____ C:\WINDOWS\system32\TpmTool.exe
2022-04-10 03:35 - 2022-04-10 03:35 - 000197632 _____ C:\WINDOWS\system32\IHDS.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2022-04-10 03:35 - 2022-04-10 03:35 - 000089088 _____ C:\WINDOWS\system32\windows.applicationmodel.conve rsationalagent.proxystub.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000074240 _____ C:\WINDOWS\system32\rdsxvmaudio.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000073216 _____ C:\WINDOWS\system32\windows.applicationmodel.conve rsationalagent.internal.proxystub.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000064552 _____ C:\WINDOWS\system32\umpdc.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter. exe
2022-04-10 03:04 - 2022-04-10 03:04 - 000417792 _____ C:\WINDOWS\system32\d3dconfig.exe
2022-04-10 03:04 - 2022-04-10 03:04 - 000374784 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe
2022-04-10 03:04 - 2022-04-10 03:04 - 000365056 _____ C:\WINDOWS\SysWOW64\d3dconfig.exe
2022-04-10 03:04 - 2022-04-10 03:04 - 000347136 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DXCpl.exe
2022-04-10 03:01 - 2022-04-10 03:01 - 000002060 _____ C:\WINDOWS\system32\noise.jpn
2022-04-10 02:55 - 2022-04-12 21:31 - 000465578 _____ C:\WINDOWS\system32\perfh011.dat
2022-04-10 02:55 - 2022-04-12 21:31 - 000130494 _____ C:\WINDOWS\system32\perfc011.dat
2022-04-10 02:55 - 2022-04-10 02:55 - 000144624 _____ C:\WINDOWS\system32\perfi011.dat
2022-04-10 02:55 - 2022-04-10 02:55 - 000033402 _____ C:\WINDOWS\system32\perfd011.dat
2022-04-10 02:55 - 2022-04-10 02:55 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2022-04-10 02:55 - 2022-04-10 02:55 - 000000000 ____D C:\WINDOWS\SysWOW64\ja
2022-04-10 02:55 - 2022-04-10 02:55 - 000000000 ____D C:\WINDOWS\system32\ja
2022-04-10 02:39 - 2022-04-14 18:43 - 000000000 ____D C:\Program Files (x86)\MSBuild
2022-04-10 02:39 - 2022-04-10 02:39 - 000000000 ____D C:\Program Files\Reference Assemblies
2022-04-10 02:39 - 2022-04-10 02:39 - 000000000 ____D C:\Program Files\MSBuild
2022-04-10 02:39 - 2022-04-10 02:39 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2022-04-09 21:15 - 2022-04-09 21:15 - 000000000 ____D C:\WINDOWS\pss
2022-04-09 20:37 - 2022-04-09 20:37 - 000001154 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2022-04-09 20:37 - 2022-04-09 20:37 - 000000000 ____D C:\Program Files\PCHealthCheck
2022-04-09 20:14 - 2022-04-09 20:14 - 000000020 ___SH C:\Users\Ganja\ntuser.ini
2022-04-09 20:09 - 2022-04-15 22:42 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-04-09 20:09 - 2022-04-09 20:10 - 000003410 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachine UA
2022-04-09 20:09 - 2022-04-09 20:10 - 000002668 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0
2022-04-09 20:09 - 2022-04-09 20:09 - 000003186 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachine Core
2022-04-09 20:09 - 2022-04-09 20:09 - 000000000 ____D C:\WINDOWS\system32\Tasks\OfficeSoftwareProtection Platform
2022-04-09 20:08 - 2022-04-09 20:09 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2022-04-09 20:08 - 2022-04-09 20:09 - 000007623 _____ C:\WINDOWS\diagerr.xml
2022-04-09 20:00 - 2022-04-09 20:00 - 001451302 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-04-09 19:47 - 2022-04-15 19:16 - 000000000 ____D C:\Users\Ganja
2022-04-09 19:43 - 2016-10-27 16:14 - 000416576 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SASrv.exe
2022-04-09 19:43 - 2016-10-27 16:14 - 000416576 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\SASrv.exe
2022-04-09 19:43 - 2015-07-31 17:29 - 000004664 _____ C:\WINDOWS\system32\Drivers\CxSfPt.DAT
2022-04-09 19:43 - 2014-10-20 14:54 - 000207576 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
2022-04-09 19:35 - 2022-04-15 21:14 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-04-09 19:34 - 2022-04-15 22:42 - 000008192 ___SH C:\DumpStack.log.tmp
2022-04-09 19:34 - 2022-04-09 19:35 - 000319144 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-04-09 15:53 - 2022-04-09 20:36 - 000000000 ____D C:\Program Files\ruxim
2022-04-09 09:33 - 2022-04-14 21:22 - 000000000 ___DC C:\WINDOWS\Panther
2022-04-09 09:26 - 2022-04-09 09:26 - 000000000 ___HD C:$WinREAgent
2022-04-09 02:32 - 2022-04-09 02:32 - 000000000 ____D C:\Users\Ganja\AppData\Local\NemuPlayer
2022-04-09 02:32 - 2022-04-09 02:32 - 000000000 ____D C:\Users\Ganja\AppData\Local\cache
2022-04-09 02:02 - 2022-04-13 18:41 - 000000000 ____D C:\Users\Ganja\Documents\MuMuSharedFolder
2022-04-09 02:01 - 2022-04-09 02:01 - 000000000 ____D C:\Users\Ganja\AppData\Local\CrashRpt
2022-04-09 01:54 - 2022-04-14 18:03 - 000000000 ____D C:\Users\Public\Documents\MuMu Files
2022-04-09 01:54 - 2022-04-14 18:03 - 000000000 ____D C:\Program Files\NemuVbox
2022-04-09 01:50 - 2022-04-09 01:50 - 000000000 ____D C:\Program Files\MuMu
2022-04-09 01:49 - 2022-04-09 01:49 - 009731600 _____ (NetEase, Inc.) C:\Users\Ganja\Downloads\MuMuInstaller_1.4.0.0_gw-overseas_all_1644473805.exe
2022-04-09 01:21 - 2022-04-09 10:39 - 000000000 ____D C:\Users\Ganja.TianTianVM
2022-04-09 01:15 - 2022-04-09 01:15 - 000000299 _____ C:\Users\Ganja\d4ac4633ebd6440fa397b84f1bc94a3c.7z
2022-04-09 00:30 - 2022-04-09 01:23 - 000000000 ____D C:\Users\Ganja.android
2022-04-09 00:29 - 2022-04-09 00:29 - 000000066 _____ C:\Users\Ganja\inittk.ini
2022-04-09 00:27 - 2022-04-09 00:43 - 000000000 ____D C:\Users\Ganja\AppData\Local\NoxSrv
2022-04-09 00:27 - 2022-04-09 00:27 - 000000053 _____ C:\Users\Ganja\useruid.ini
2022-04-09 00:27 - 2022-04-09 00:27 - 000000045 _____ C:\Users\Ganja\nuuid.ini
2022-04-09 00:27 - 2022-04-09 00:27 - 000000041 _____ C:\Users\Ganja\inst.ini
2022-04-09 00:27 - 2022-04-09 00:27 - 000000000 ____D C:\Users\Ganja\Nox_share
2022-04-09 00:26 - 2022-04-09 00:43 - 000000000 ____D C:\Users\Ganja\vmlogs
2022-04-09 00:21 - 2022-04-14 18:04 - 000000000 ____D C:\Users\Ganja\AppData\Local\Nox
2022-04-09 00:16 - 2022-04-09 00:21 - 527327744 _____ (Duodian Technology Co. Ltd.) C:\Users\Ganja\Downloads\nox_setup_v7.0.2.5_full_i ntl.exe
2022-04-08 23:50 - 2022-04-08 23:50 - 000000000 ____D C:\Users\Ganja\AppData\Local\CrashDumps
2022-03-26 14:25 - 2022-03-27 20:00 - 000076461 _____ C:\Users\Ganja\Desktop\Ragnarok (Autosaved).xlsx
2022-03-26 10:43 - 2022-03-26 10:43 - 000000000 __RHD C:\MSOCache
2022-03-26 10:38 - 2022-03-26 10:38 - 000000165 ____H C:\Users\Ganja\Desktop~$Ragnarok.xlsx
2022-03-20 09:41 - 2022-03-20 09:45 - 000000000 ____D C:\Users\Ganja\Documents\CTK
2022-03-20 09:39 - 2022-03-20 09:39 - 000001124 _____ C:\Users\Ganja\Desktop\BloonsTK.exe - Shortcut.lnk
2022-03-19 16:32 - 2022-03-20 09:12 - 000014198 _____ C:\ProgramData\DisplaySessionContainer3.log_backup 1
2022-03-17 23:14 - 2022-03-17 23:14 - 000000112 ___SH C:\bootTel.dat
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-04-15 22:53 - 2022-03-14 17:42 - 000000000 ____D C:\FRST
2022-04-15 22:51 - 2019-03-19 13:52 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2022-04-15 22:47 - 2020-03-06 12:09 - 000000000 ____D C:\Program Files\CCleaner
2022-04-15 22:46 - 2019-12-07 18:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-04-15 22:45 - 2020-02-29 23:02 - 000000000 __SHD C:\Users\Ganja\IntelGraphicsProfiles
2022-04-15 22:42 - 2022-03-15 11:27 - 000000000 ____D C:\Intel
2022-04-15 22:42 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-04-15 22:41 - 2019-12-07 18:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2022-04-15 21:06 - 2019-12-07 18:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-04-15 19:10 - 2019-12-07 18:13 - 000000000 ____D C:\WINDOWS\INF
2022-04-15 19:09 - 2020-02-29 21:10 - 000000000 ____D C:\Program Files\CONEXANT
2022-04-15 19:09 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\security
2022-04-15 18:59 - 2019-12-07 18:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-04-15 18:48 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\registration
2022-04-15 18:47 - 2021-04-07 09:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
2022-04-15 08:13 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2022-04-15 07:28 - 2020-03-01 14:56 - 000000000 ____D C:\Users\Ganja\AppData\Local\ElevatedDiagnostics
2022-04-14 23:23 - 2020-02-29 21:19 - 000000000 ____D C:\Users\Ganja\AppData\Local\D3DSCache
2022-04-14 23:01 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-04-14 21:58 - 2020-02-29 21:10 - 000000000 ____D C:\ProgramData\UIU
2022-04-14 19:38 - 2021-12-15 22:03 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\XuanZhi64
2022-04-14 19:22 - 2021-12-15 22:17 - 000000000 ____D C:\Users\Ganja.Ld2VirtualBox
2022-04-14 19:09 - 2020-03-08 23:49 - 000000000 ____D C:\Users\Ganja\AppData\Local\Dropbox
2022-04-14 19:08 - 2020-03-08 23:49 - 000000000 ____D C:\Program Files (x86)\Dropbox
2022-04-14 18:58 - 2020-02-29 21:12 - 000002377 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-04-14 18:58 - 2020-02-29 21:08 - 000000000 ____D C:\Program Files (x86)\Google
2022-04-14 18:43 - 2020-04-29 14:24 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Visual Studio Setup
2022-04-14 18:43 - 2020-04-29 14:23 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
2022-04-14 18:42 - 2020-04-29 14:36 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2022-04-14 18:42 - 2020-04-29 14:36 - 000000000 ____D C:\Program Files (x86)\Microsoft SDKs
2022-04-14 18:38 - 2020-02-29 22:55 - 000000000 ____D C:\ProgramData\Package Cache
2022-04-14 18:12 - 2020-04-29 14:22 - 000000000 ____D C:\ProgramData\Microsoft Visual Studio
2022-04-14 18:06 - 2020-02-29 21:37 - 000000000 ____D C:\Games
2022-04-14 18:02 - 2020-02-29 21:09 - 000000000 ___RD C:\Users\Ganja\OneDrive
2022-04-14 18:01 - 2020-03-01 04:04 - 000000000 ____D C:\Users\Ganja\AppData\Local\Packages
2022-04-14 17:59 - 2020-03-04 00:17 - 000000000 ____D C:\Program Files\Cheat Engine 7.0
2022-04-14 17:34 - 2020-03-06 15:40 - 000000000 ____D C:\Program Files (x86)\Adobe
2022-04-14 17:34 - 2020-03-06 15:39 - 000000000 ____D C:\ProgramData\Adobe
2022-04-14 17:34 - 2020-03-01 04:04 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Adobe
2022-04-14 04:27 - 2020-03-01 03:49 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-04-13 23:41 - 2020-06-29 19:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tencent Software
2022-04-13 18:24 - 2020-03-11 19:31 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\ZHP
2022-04-13 17:57 - 2022-03-14 17:15 - 000000877 _____ C:\Users\Ganja\Desktop\ZHPCleaner.lnk
2022-04-12 21:31 - 2020-04-30 19:39 - 000000000 ____D C:\Users\Ganja\AppData\LocalLow\Temp
2022-04-12 21:19 - 2020-03-11 11:39 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\360DesktopLite
2022-04-12 21:18 - 2019-12-07 18:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2022-04-10 04:33 - 2021-11-29 19:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoHotkey
2022-04-10 04:33 - 2021-02-16 08:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2022-04-10 04:33 - 2020-05-29 19:42 - 000000000 ____D C:\Program Files\UNP
2022-04-10 04:33 - 2020-03-28 20:33 - 000000000 ____D C:\WINDOWS\system32\CleanLog
2022-04-10 04:33 - 2020-03-21 09:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2022-04-10 04:33 - 2020-03-06 12:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2022-04-10 04:33 - 2020-03-04 19:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2022-04-10 04:33 - 2020-03-04 00:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 7.0
2022-04-10 04:33 - 2020-03-03 14:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2022-04-10 04:33 - 2020-03-01 04:42 - 000000000 ____D C:\WINDOWS\ShellNew
2022-04-10 04:33 - 2020-02-29 23:03 - 000000000 ____D C:\Program Files\Intel
2022-04-10 04:33 - 2019-12-07 18:18 - 000000000 ____D C:\WINDOWS\Setup
2022-04-10 04:33 - 2019-12-07 18:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2022-04-10 04:33 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2022-04-10 04:33 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\spool
2022-04-10 04:33 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-04-10 04:33 - 2019-12-07 18:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2022-04-10 04:33 - 2019-03-19 13:52 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2022-04-10 04:33 - 2019-03-19 13:52 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2022-04-10 04:22 - 2020-02-29 21:09 - 000000000 ____D C:\WINDOWS\system32\Intel
2022-04-10 04:20 - 2020-04-29 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2019
2022-04-10 04:04 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2022-04-10 04:03 - 2019-12-07 23:49 - 000000000 ___SD C:\WINDOWS\system32\AppV
2022-04-10 04:03 - 2019-12-07 23:49 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2022-04-10 04:03 - 2019-12-07 23:49 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-04-10 04:03 - 2019-12-07 23:49 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2022-04-10 04:03 - 2019-12-07 23:46 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2022-04-10 04:03 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2022-04-10 04:03 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\en-GB
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\setup
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\Keywords
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\Com
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\Provisioning
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\IME
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\Program Files\Common Files\System
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2022-04-10 04:03 - 2019-12-07 18:03 - 000000000 ____D C:\WINDOWS\servicing
2022-04-10 03:58 - 2019-12-07 23:49 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2022-04-10 03:58 - 2019-12-07 23:49 - 000020908 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2022-04-10 03:03 - 2019-12-07 23:47 - 000000000 ____D C:\WINDOWS\OCR
2022-04-10 03:01 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2022-04-10 03:01 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\system32\WCN
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\system32\winrm
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\system32\slmgr
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2022-04-10 02:55 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\system32\dsc
2022-04-10 02:55 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2022-04-10 02:55 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\MUI
2022-04-09 21:39 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\appcompat
2022-04-09 20:42 - 2020-10-07 17:08 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2022-04-09 20:36 - 2019-12-07 18:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2022-04-09 20:35 - 2020-02-29 21:54 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2022-04-09 20:19 - 2020-02-29 21:22 - 000000000 ____D C:\ProgramData\Packages
2022-04-09 20:19 - 2019-12-07 18:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-04-09 20:17 - 2020-03-01 04:04 - 000000000 __RHD C:\Users\Public\AccountPictures
2022-04-09 20:17 - 2020-03-01 04:04 - 000000000 ___RD C:\Users\Ganja\3D Objects
2022-04-09 20:11 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-04-09 20:10 - 2019-12-07 18:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2022-04-09 20:09 - 2019-12-07 18:14 - 000000000 ____D C:\ProgramData\USOPrivate
2022-04-09 20:09 - 2019-12-07 18:14 - 000000000 ____D C:\Program Files\Windows Defender
2022-04-09 19:58 - 2019-12-07 18:14 - 000000000 __RHD C:\Users\Public\Libraries
2022-04-09 19:48 - 2022-03-12 16:42 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Redfinger
2022-04-09 19:48 - 2020-03-04 19:25 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\WinRAR
2022-04-09 19:45 - 2020-05-19 00:00 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2022-04-09 19:44 - 2021-04-07 09:07 - 000001963 _____ C:\ProgramData\Microsoft\Windows\Start Menu\SmartAudio.lnk
2022-04-09 19:43 - 2020-02-29 21:10 - 001705080 _____ (TODO: ) C:\WINDOWS\SysWOW64\RebootPrompt.exe
2022-04-09 15:54 - 2020-04-29 14:32 - 000000000 ____D C:\Program Files\dotnet
2022-04-09 15:43 - 2020-02-29 22:19 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-04-09 15:42 - 2020-02-29 22:19 - 145666720 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-04-09 15:41 - 2020-04-29 14:32 - 000000000 ____D C:\Program Files (x86)\dotnet
2022-04-09 15:38 - 2020-04-29 14:35 - 000000000 ____D C:\Users\Ganja.dotnet
2022-04-09 09:23 - 2020-02-29 23:02 - 000000000 ____D C:\Users\Ganja\AppData\Local\Intel
2022-03-18 08:34 - 2022-03-15 13:00 - 000000000 ____D C:\Program Files (x86)\TurboVPN
2022-03-18 08:34 - 2022-03-12 16:42 - 000000000 ____D C:\Program Files (x86)\RedFingerPlayerGlobal
2022-03-18 08:18 - 2020-02-29 22:54 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2022-03-17 23:35 - 2020-03-08 23:50 - 000000938 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2022-03-17 23:35 - 2020-03-08 23:49 - 000000934 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
==================== Files in the root of some directories ========
2020-04-10 11:34 - 2020-04-10 11:34 - 003295616 _____ (Nicolas Coolman) C:\Users\Ganja\ZHPCleaner.exe
2021-12-15 22:17 - 2021-12-15 22:17 - 000000068 _____ () C:\Users\Ganja\AppData\Roaming\changzhi_leidian.da ta
2021-12-15 22:17 - 2021-12-15 22:17 - 000000154 _____ () C:\Users\Ganja\AppData\Roaming\changzhi_leidianmac .data
2020-05-02 22:47 - 2021-01-04 14:51 - 000001190 _____ () C:\Users\Ganja\AppData\Roaming_encryptiondb.grf
2020-03-08 11:10 - 2020-03-08 11:10 - 000000000 _____ () C:\Users\Ganja\AppData\Local\oobelibMkey.log
2020-03-15 19:56 - 2020-03-15 19:56 - 000007625 _____ () C:\Users\Ganja\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Ran by Ganja (administrator) on DESKTOP-V4BFEG5 (ASUSTeK COMPUTER INC. X456URK) (15-04-2022 22:52:17)
Running from C:\Users\Ganja\Desktop
Loaded Profiles: Ganja
Platform: Microsoft Windows 10 Pro Version 20H2 19042.1586 (X64) Language: English (United Kingdom)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Conexant Systems LLC → Conexant Systems, Inc) C:\Program Files\CONEXANT\SAII\SmartAudio.exe
(Conexant Systems LLC → Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent 64.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_b8e0 1d9e8716d2a7\igfxCUIService.exe ->) (Intel(R) pGFX 2020 → Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui _dch.inf_amd64_b8e01d9e8716d2a7\igfxEM.exe
(explorer.exe ->) (Google LLC → Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <9>
(explorer.exe ->) (INTEL CORP) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1. 100.3407.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSys Tray\IGCCTray.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation → Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(services.exe ->) (Conexant Systems, Inc. → Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(services.exe ->) (Conexant Systems, Inc. → Conexant Systems, Inc.) C:\Windows\System32\SASrv.exe
(services.exe ->) (Dropbox, Inc → Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(services.exe ->) (ICEpower a/s → ICEpower A/S) C:\Windows\System32\DriverStore\FileRepository\x40 plmwa.inf_amd64_0fe274d0aafd5420\ICEsoundService64 .exe
(services.exe ->) (Intel Corporation → Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel(R) pGFX 2020 → Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui _dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe
(services.exe ->) (Intel(R) pGFX 2020 → Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igc c_dch.inf_amd64_54b736e5be5b50b2\OneApp.IGCC.WinSe rvice.exe
(services.exe ->) (Intel(R) pGFX 2020 → Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iig d_dch.inf_amd64_a086f01cc7be643a\IntelCpHDCPSvc.ex e
(services.exe ->) (Intel(R) pGFX 2020 → Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iig d_dch.inf_amd64_a086f01cc7be643a\IntelCpHeciSvc.ex e
(services.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\Pres entationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher → Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher → Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation → NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nva mi.inf_amd64_036f20146ac187ce\Display.NvContainer\ NVDisplay.Container.exe <2>
(svchost.exe ->) (INTEL CORP) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1. 100.3407.0_x64__8j3eq9eme6ctt\IGCC.exe
(svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.e xe [509936 2018-04-11] (Adobe Systems Incorporated → Adobe Systems Incorporated)
HKLM...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-10-09] (Adobe Inc. → Adobe Systems, Incorporated)
HKLM...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation → Microsoft Corporation)
HKLM-x32...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [10586448 2022-04-12] (Dropbox, Inc → Dropbox, Inc.)
HKLM...\Policies\Explorer: [HideSCAMeetNow] 1
HKLM...\Policies\Explorer: [NoWindowsUpdate] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3947486154-1424391867-2577238500-1001...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [36705520 2022-04-07] (Piriform Software Ltd → Piriform Software Ltd)
HKU\S-1-5-21-3947486154-1424391867-2577238500-1001...\Policies\Explorer: [HideSCAMeetNow] 1
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] → C:\Program Files (x86)\Google\Chrome\Application\100.0.4896.88\Inst aller\chrmstp.exe [2022-04-14] (Google LLC → Google LLC)
IFEO\EOSnotify.exe: [Debugger] /
IFEO\InstallAgent.exe: [Debugger] /
IFEO\MusNotification.exe: [Debugger] /
IFEO\MusNotificationUx.exe: [Debugger] /
IFEO\remsh.exe: [Debugger] /
IFEO\SihClient.exe: [Debugger] /
IFEO\UpdateAssistant.exe: [Debugger] /
IFEO\upfc.exe: [Debugger] /
IFEO\UsoClient.exe: [Debugger] /
IFEO\WaaSMedic.exe: [Debugger] /
IFEO\WaasMedicAgent.exe: [Debugger] /
IFEO\Windows10Upgrade.exe: [Debugger] /
IFEO\Windows10UpgraderApp.exe: [Debugger] /
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
HKU\S-1-5-21-3947486154-1424391867-2577238500-1001\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {21F74A47-3424-418E-A53B-4E2562C05ABA} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-29] (Dropbox, Inc → Dropbox, Inc.)
Task: {35C3CE0C-6E9C-4368-8970-5A1EC2984974} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Ganja\AppData\Local\ESET\ESETOnlineScanne r\ESETOnlineScanner.exe SCHED (No File)
Task: {38B1D35F-5B27-469E-9023-B883D23E4840} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
Task: {6D49D09F-9853-422D-A970-E82C99B5D8DF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
Task: {7F3569B1-34AE-46F6-B4D7-9D41822A766E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
Task: {8B831FA3-91A3-4CA8-8115-CED07AB87029} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-04-07] (Piriform Software Ltd → Piriform)
Task: {A35BAD01-9115-4CE5-8E83-CE0363167108} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-10-09] (Adobe Inc. → Adobe Systems, Incorporated)
Task: {A9461498-6A3F-4F98-B10D-680CD902F8BB} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Ganja\AppData\Local\ESET\ESETOnlineScanne r\ESETOnlineScanner.exe LOGON (No File)
Task: {B40A30F0-F3F8-4F31-B890-EEC38512349B} - System32\Tasks\Microsoft\Windows\Conexant\SA2 => C:\Program Files\CONEXANT\SAII\SACpl.exe [1832280 2017-06-07] (Conexant Systems, Inc. → Conexant Systems, Inc.)
Task: {B9D60D3E-8E0C-48C1-B4EF-1EF747D27549} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
Task: {C630BFDF-4B2F-4271-9B1F-2DB64E5A7F09} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [275136 2022-03-30] (Bluestack Systems, Inc → BlueStack Systems, Inc.)
Task: {DC0F9DAF-1B83-45D9-AA91-B9C6BD78042B} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-29] (Dropbox, Inc → Dropbox, Inc.)
Task: {E8D71E94-B741-496F-BAFF-AFADFF2255A0} - System32\Tasks\Microsoft\Windows\Conexant\AFA => C:\Program Files\CONEXANT\cAudioFilterAgent\SACpl.exe [1823232 2016-07-05] (Conexant Systems, Inc.) [File not signed]
Task: {EF5C000F-603E-4C0E-B31C-A6C10E91FE43} - System32\Tasks\CCleanerSkipUAC - Ganja => C:\Program Files\CCleaner\CCleaner.exe [30836464 2022-04-07] (Piriform Software Ltd → Piriform Software Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.43.193
Tcpip..\Interfaces{bff8e11e-7cb0-43cd-8ed2-84f8481e005d}: [DhcpNameServer] 192.168.43.193
Tcpip..\Interfaces{fc72d37d-562e-4e97-a7cf-ea1989188cd8}: [DhcpNameServer] 192.168.1.1
[HEADING=1]FireFox:[/HEADING]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 → C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation → Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.12 → C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-19] (VideoLAN → VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.16 → C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-19] (VideoLAN → VideoLAN)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 → C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation → Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 → C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation → Microsoft Corporation)
[HEADING=1]Chrome:[/HEADING]
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Default [2022-04-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda [2021-02-16]
CHR Profile: C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Guest Profile [2022-04-14]
CHR Profile: C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1 [2022-04-15]
CHR Extension: (Slides) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2022-03-19]
CHR Extension: (Docs) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2022-03-19]
CHR Extension: (Google Drive) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2022-03-19]
CHR Extension: (YouTube) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2022-03-19]
CHR Extension: (Sheets) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2022-03-19]
CHR Extension: (Google Docs Offline) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-03-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-03-19]
CHR Extension: (Gmail) - C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2022-03-19]
CHR Profile: C:\Users\Ganja\AppData\Local\Google\Chrome\User Data\System Profile [2022-04-14]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3147344 2019-10-09] (Adobe Inc. → Adobe Systems, Incorporated)
S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2914896 2019-10-09] (Adobe Inc. → Adobe Systems, Incorporated)
S4 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-29] (Dropbox, Inc → Dropbox, Inc.)
S4 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-29] (Dropbox, Inc → Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [45408 2022-04-12] (Dropbox, Inc → Dropbox, Inc.)
S4 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [805488 2019-10-16] (EasyAntiCheat Oy → EasyAntiCheat Ltd)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [7965288 2020-03-05] (INCA Internet Co.,Ltd. → INCA Internet Co., Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6228008 2022-04-10] (Microsoft Windows Publisher → Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\NisSrv.exe [3116848 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MsMpEng.exe [133544 2022-04-14] (Microsoft Windows Publisher → Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nva mi.inf_amd64_036f20146ac187ce\Display.NvContainer\ NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nva mi.inf_amd64_036f20146ac187ce\Display.NvContainer\ plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AsusPTPDrv; C:\WINDOWS\System32\drivers\AsusPTPFilter.sys [108504 2019-04-24] (ASUSTek Computer Inc. → ASUSTek COMPUTER INC.)
R2 BlueStacksDrv_nxt; C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [320728 2022-03-30] (Bluestack Systems, Inc → Bluestack System Inc.)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32696 2020-11-19] (ASUSTek Computer Inc. → ASUS)
S3 MpKslbaf14ff9; C:\ProgramData\Microsoft\Windows Defender\Definition Updates{7F45780D-EC7B-4BC8-8BAA-D56A3AB21734}\MpKslDrv.sys [139536 2022-04-15] (Microsoft Windows → Microsoft Corporation)
R3 Neo_VPN; C:\WINDOWS\System32\drivers\Neo6_x64_VPN.sys [37824 2020-04-18] (SoftEther Corporation → SoftEther Corporation)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [23040 2020-01-10] (Apple Inc.) [File not signed]
R1 SeLow; C:\WINDOWS\system32\DRIVERS\SeLow_x64.sys [50624 2020-04-18] (SoftEther Corporation → SoftEther Corporation)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [31232 2019-12-02] (OpenVPN Technologies, Inc. → The OpenVPN Project)
S3 tesrsdt; C:\Windows\system32\drivers\tesrsdt.sys [812208 2020-06-29] (Tencent Technology(Shenzhen) Company Limited → TENCENT)
S3 UniSafe; C:\Windows\system32\drivers\UniSafe.sys [581912 2020-06-29] (Tencent Technology(Shenzhen) Company Limited → TENCENT)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49600 2022-04-14] (Microsoft Windows Early Launch Anti-malware Publisher → Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [443664 2022-04-14] (Microsoft Windows → Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [90384 2022-04-14] (Microsoft Windows → Microsoft Corporation)
S3 MpKsl5fba685f; ??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates{2B02F115-5134-4409-8760-F9955DF0D9D3}\MpKslDrv.sys
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-04-15 22:52 - 2022-04-15 22:54 - 000016808 _____ C:\Users\Ganja\Desktop\FRST.txt
2022-04-15 22:49 - 2022-01-29 00:20 - 000000000 ____D C:\Users\Ganja\Desktop\Wub
2022-04-15 22:40 - 2022-04-15 22:41 - 000011406 _____ C:\ProgramData\DisplaySessionContainer1.log_backup 1
2022-04-15 21:43 - 2022-04-15 21:43 - 000000000 ____D C:\Users\Ganja\AppData\Local\OO Software
2022-04-15 21:25 - 2022-04-15 21:25 - 001604008 _____ (O&O Software GmbH) C:\Users\Ganja\Desktop\OOSU10.exe
2022-04-15 21:16 - 2022-04-15 22:41 - 000022706 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_back up1
2022-04-15 21:16 - 2022-04-15 22:41 - 000018632 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_ backup1
2022-04-15 21:16 - 2022-04-15 21:16 - 000001206 _____ C:\ProgramData\NvcDispCorePlugin.log_backup1
2022-04-15 19:42 - 2022-04-15 21:06 - 000107535 _____ C:\Users\Ganja\Desktop\Fixlog.txt
2022-04-15 19:42 - 2022-04-15 19:42 - 002366464 _____ (Farbar) C:\Users\Ganja\Desktop\FRST64.exe
2022-04-15 19:40 - 2022-04-15 19:40 - 000000000 ____D C:\Users\Ganja\AppData\Local\BlueStacks
2022-04-15 19:21 - 2022-04-15 19:21 - 000000000 ____D C:\Users\Ganja\AppData\Local\Conexant
2022-04-14 22:51 - 2022-04-14 22:51 - 000000000 ____D C:\Users\Ganja\Downloads\Lang
2022-04-14 22:51 - 2019-10-18 02:19 - 000918718 ____N C:\Users\Ganja\Downloads\readme.txt
2022-04-14 22:51 - 2019-10-18 02:19 - 000038514 ____N C:\Users\Ganja\Downloads\Setup.if2
2022-04-14 22:51 - 2019-10-18 02:19 - 000014060 ____N C:\Users\Ganja\Downloads\Installation_Readme.txt
2022-04-14 22:51 - 2019-10-18 02:19 - 000007567 ____N C:\Users\Ganja\Downloads\mup.xml
2022-04-14 22:50 - 2022-04-15 19:09 - 000000000 ____D C:\Users\Ganja\Downloads\Graphics
2022-04-14 22:46 - 2022-04-15 08:11 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2022-04-14 22:39 - 2022-04-14 22:39 - 000000000 ____D C:\Program Files\Common Files\QCA_Bluetooth
2022-04-14 22:38 - 2022-04-14 22:39 - 000000000 ____D C:\Program Files (x86)\Qualcomm
2022-04-14 22:35 - 2022-04-15 19:09 - 000000000 ____D C:\ProgramData\AmUStor
2022-04-14 22:35 - 2022-04-15 19:09 - 000000000 ____D C:\Program Files (x86)\AmUStor
2022-04-14 22:01 - 2022-04-15 00:04 - 000000000 ____D C:\ProgramData\ASUS
2022-04-14 21:50 - 2022-04-14 21:50 - 000000000 ____D C:\Users\Ganja\Intel
2022-04-14 21:47 - 2022-04-15 00:04 - 000000000 ____D C:\Program Files (x86)\ASUS
2022-04-14 21:40 - 2022-04-14 21:44 - 379569687 _____ C:\Users\Ganja\Downloads\VGA_Intel_Win10_64_VER262 01007325_DriverOnly.zip.zip
2022-04-14 21:40 - 2022-04-14 21:42 - 135721680 _____ (ASUSTeK COMPUTER INC.) C:\Users\Ganja\Downloads\Audio_Conexant_Z_V8.66.95 .70Sub3_21875.exe
2022-04-14 21:40 - 2022-04-14 21:42 - 066241082 _____ C:\Users\Ganja\Downloads\MEI_Intel_15M_Win10_64_VE R11001177.zip
2022-04-14 20:20 - 2022-04-14 20:20 - 000001985 _____ C:\Users\Ganja\Desktop\RöX.lnk
2022-04-14 19:46 - 2022-04-14 19:46 - 000003938 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper_nxt
2022-04-14 19:46 - 2022-04-14 19:46 - 000002115 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5 Multi-Instance Manager.lnk
2022-04-14 19:46 - 2022-04-14 19:46 - 000002103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk
2022-04-14 19:44 - 2022-04-15 19:21 - 000000000 ____D C:\ProgramData\BlueStacks_nxt
2022-04-14 19:44 - 2022-04-15 19:10 - 000000000 ____D C:\Program Files\BlueStacks_nxt
2022-04-14 19:40 - 2022-04-15 19:10 - 000000000 ____D C:\Users\Ganja\AppData\Local\BlueStacksSetup
2022-04-14 19:12 - 2022-04-14 19:12 - 000000000 ____D C:\LDPlayer
2022-04-14 19:06 - 2022-04-14 19:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2022-04-14 19:06 - 2022-04-14 19:06 - 000000000 ____D C:\Program Files\Google
2022-04-14 18:58 - 2022-04-14 21:19 - 000001050 _____ C:\Users\Public\Desktop\CCleaner.lnk
2022-04-14 18:58 - 2022-04-14 18:58 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2022-04-14 18:58 - 2022-04-14 18:58 - 000002904 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Ganja
2022-04-14 18:57 - 2022-04-14 19:07 - 000000000 ____D C:\PatchMyPCUpdates
2022-04-13 23:40 - 2022-04-13 23:40 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Tencent
2022-04-13 23:40 - 2022-04-13 23:40 - 000000000 ____D C:\ProgramData\Tencent
2022-04-13 18:15 - 2022-04-13 18:17 - 000000865 _____ C:\Users\Ganja\Desktop\ZHPDiag.lnk
2022-04-13 17:23 - 2022-04-13 17:29 - 000290304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\subinacl.exe
2022-04-13 17:23 - 2022-04-13 17:23 - 000000000 ____D C:\Program Files (x86)\Adware Removal Tool by TSA
2022-04-13 17:21 - 2022-04-13 17:21 - 000752296 _____ C:\Users\Ganja\Desktop\adware-removal-tool-by-tsa.exe
2022-04-13 17:19 - 2022-04-13 17:19 - 003295944 _____ (Nicolas Coolman) C:\Users\Ganja\Desktop\ZHPCleaner.exe
2022-04-13 17:19 - 2022-04-13 17:19 - 003287240 _____ (Nicolas Coolman) C:\Users\Ganja\Desktop\ZHPDiag3.exe
2022-04-13 06:52 - 2022-04-13 06:52 - 000003858 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2022-04-13 06:52 - 2022-04-13 06:52 - 000003416 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2022-04-12 21:52 - 2022-04-12 21:52 - 000001398 _____ C:\Users\Ganja\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\ESET Online Scanner.lnk
2022-04-12 21:52 - 2022-04-12 21:52 - 000001292 _____ C:\Users\Ganja\Desktop\ESET Online Scanner.lnk
2022-04-12 21:52 - 2022-04-12 21:52 - 000000000 ____D C:\Users\Ganja\AppData\Local\ESET
2022-04-12 21:49 - 2022-04-12 21:49 - 015274968 _____ (ESET) C:\Users\Ganja\Desktop\esetonlinescanner.exe
2022-04-12 21:33 - 2022-04-12 21:33 - 000000008 __RSH C:\ProgramData\ntuser.pol
2022-04-12 21:28 - 2022-04-12 21:28 - 000010416 _____ C:\ProgramData\DisplaySessionContainer2.log_backup 1
2022-04-12 21:20 - 2022-04-12 21:25 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Geek Uninstaller
2022-04-12 21:19 - 2022-03-23 06:16 - 006392680 _____ (Geek UnС–nstaller) C:\Users\Ganja\Desktop\geek.exe
2022-04-12 21:15 - 2022-04-12 21:16 - 008540344 _____ (Malwarebytes) C:\Users\Ganja\Desktop\adwcleaner_8.3.1.exe
2022-04-12 08:52 - 2022-04-12 08:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2022-04-12 08:52 - 2022-04-12 08:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2022-04-12 08:52 - 2022-04-12 08:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2022-04-12 08:52 - 2022-04-12 08:52 - 000045408 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2022-04-10 04:33 - 2022-04-09 20:11 - 000000000 ____D C:\Windows.old
2022-04-10 04:20 - 2022-04-10 04:33 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2022-04-10 04:14 - 2022-04-10 04:20 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2022-04-10 04:14 - 2022-04-10 04:14 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2022-04-10 04:03 - 2022-04-10 04:03 - 000000000 ____D C:\WINDOWS\SystemTemp
2022-04-10 04:03 - 2022-04-10 04:03 - 000000000 ____D C:\ProgramData\ssh
2022-04-10 03:48 - 2022-04-10 03:48 - 001687040 _____ C:\WINDOWS\system32\libcrypto.dll
2022-04-10 03:47 - 2022-04-10 03:47 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2022-04-10 03:47 - 2022-04-10 03:47 - 000101704 _____ C:\WINDOWS\SysWOW64\HvsiManagementApi.dll
2022-04-10 03:47 - 2022-04-10 03:47 - 000095744 _____ C:\WINDOWS\system32\VirtualMonitorManager.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2022-04-10 03:46 - 2022-04-10 03:46 - 000480256 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000195584 _____ C:\WINDOWS\system32\uwfcfgmgmt.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000170496 _____ C:\WINDOWS\system32\DeviceUpdateCenterCsp.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000158208 _____ C:\WINDOWS\system32\uwfcsp.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000138056 _____ C:\WINDOWS\system32\HvsiManagementApi.dll
2022-04-10 03:46 - 2022-04-10 03:46 - 000040960 _____ C:\WINDOWS\system32\uwfservicingapi.dll
2022-04-10 03:45 - 2022-04-10 03:45 - 000672768 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2022-04-10 03:45 - 2022-04-10 03:45 - 000464384 _____ (curl, hxxps://curl.se/) C:\WINDOWS\SysWOW64\curl.exe
2022-04-10 03:45 - 2022-04-10 03:45 - 000053760 _____ C:\WINDOWS\SysWOW64\BWContextHandler.dll
2022-04-10 03:45 - 2022-04-10 03:45 - 000045880 _____ C:\WINDOWS\system32\HvSocket.dll
2022-04-10 03:44 - 2022-04-10 03:44 - 002371072 _____ C:\WINDOWS\system32\rdpnano.dll
2022-04-10 03:44 - 2022-04-10 03:44 - 000523776 _____ (curl, hxxps://curl.se/) C:\WINDOWS\system32\curl.exe
2022-04-10 03:44 - 2022-04-10 03:44 - 000067072 _____ C:\WINDOWS\system32\BWContextHandler.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2022-04-10 03:43 - 2022-04-10 03:43 - 000011911 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-04-10 03:42 - 2022-04-10 03:42 - 002111488 _____ (Digimarc) C:\WINDOWS\SysWOW64\DMRCDecoder.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 001864192 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 000611960 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 000468440 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 000235520 _____ C:\WINDOWS\SysWOW64\HeatCore.dll
2022-04-10 03:42 - 2022-04-10 03:42 - 000047472 _____ C:\WINDOWS\SysWOW64\umpdc.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 001164288 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2022-04-10 03:41 - 2022-04-10 03:41 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 000330752 _____ C:\WINDOWS\SysWOW64\ssdm.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 000266240 _____ C:\WINDOWS\SysWOW64\Windows.Internal.UI.Shell.Wind owTabManager.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 000240640 _____ C:\WINDOWS\SysWOW64\CoreMas.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2022-04-10 03:41 - 2022-04-10 03:41 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll
2022-04-10 03:41 - 2022-04-10 03:41 - 000010752 _____ C:\WINDOWS\SysWOW64\agentactivationruntimestarter. exe
2022-04-10 03:39 - 2022-04-10 03:39 - 002254336 _____ C:\WINDOWS\system32\dwmscene.dll
2022-04-10 03:39 - 2022-04-10 03:39 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2022-04-10 03:39 - 2022-04-10 03:39 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2022-04-10 03:39 - 2022-04-10 03:39 - 000001370 _____ C:\WINDOWS\system32\ThirdPartyNoticesBySHS.txt
2022-04-10 03:38 - 2022-04-10 03:38 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2022-04-10 03:38 - 2022-04-10 03:38 - 000190976 _____ C:\WINDOWS\system32\BthpanContextHandler.dll
2022-04-10 03:38 - 2022-04-10 03:38 - 000152064 _____ C:\WINDOWS\system32\EoAExperiences.exe
2022-04-10 03:38 - 2022-04-10 03:38 - 000098304 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2022-04-10 03:37 - 2022-04-10 03:37 - 002295296 _____ (Digimarc) C:\WINDOWS\system32\DMRCDecoder.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 000706536 _____ C:\WINDOWS\system32\TextShaping.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 000657464 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 000306688 _____ C:\WINDOWS\system32\HeatCore.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 000029696 _____ (The ICU Project) C:\WINDOWS\system32\icuuc.dll
2022-04-10 03:37 - 2022-04-10 03:37 - 000025088 _____ (The ICU Project) C:\WINDOWS\system32\icuin.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 004227116 _____ C:\WINDOWS\system32\DefaultHrtfs.bin
2022-04-10 03:35 - 2022-04-10 03:35 - 000455168 _____ C:\WINDOWS\system32\ssdm.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000363520 _____ C:\WINDOWS\system32\Windows.Internal.UI.Shell.Wind owTabManager.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjec ts.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000272896 _____ C:\WINDOWS\system32\TpmTool.exe
2022-04-10 03:35 - 2022-04-10 03:35 - 000197632 _____ C:\WINDOWS\system32\IHDS.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2022-04-10 03:35 - 2022-04-10 03:35 - 000089088 _____ C:\WINDOWS\system32\windows.applicationmodel.conve rsationalagent.proxystub.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000074240 _____ C:\WINDOWS\system32\rdsxvmaudio.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000073216 _____ C:\WINDOWS\system32\windows.applicationmodel.conve rsationalagent.internal.proxystub.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000064552 _____ C:\WINDOWS\system32\umpdc.dll
2022-04-10 03:35 - 2022-04-10 03:35 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter. exe
2022-04-10 03:04 - 2022-04-10 03:04 - 000417792 _____ C:\WINDOWS\system32\d3dconfig.exe
2022-04-10 03:04 - 2022-04-10 03:04 - 000374784 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe
2022-04-10 03:04 - 2022-04-10 03:04 - 000365056 _____ C:\WINDOWS\SysWOW64\d3dconfig.exe
2022-04-10 03:04 - 2022-04-10 03:04 - 000347136 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DXCpl.exe
2022-04-10 03:01 - 2022-04-10 03:01 - 000002060 _____ C:\WINDOWS\system32\noise.jpn
2022-04-10 02:55 - 2022-04-12 21:31 - 000465578 _____ C:\WINDOWS\system32\perfh011.dat
2022-04-10 02:55 - 2022-04-12 21:31 - 000130494 _____ C:\WINDOWS\system32\perfc011.dat
2022-04-10 02:55 - 2022-04-10 02:55 - 000144624 _____ C:\WINDOWS\system32\perfi011.dat
2022-04-10 02:55 - 2022-04-10 02:55 - 000033402 _____ C:\WINDOWS\system32\perfd011.dat
2022-04-10 02:55 - 2022-04-10 02:55 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2022-04-10 02:55 - 2022-04-10 02:55 - 000000000 ____D C:\WINDOWS\SysWOW64\ja
2022-04-10 02:55 - 2022-04-10 02:55 - 000000000 ____D C:\WINDOWS\system32\ja
2022-04-10 02:39 - 2022-04-14 18:43 - 000000000 ____D C:\Program Files (x86)\MSBuild
2022-04-10 02:39 - 2022-04-10 02:39 - 000000000 ____D C:\Program Files\Reference Assemblies
2022-04-10 02:39 - 2022-04-10 02:39 - 000000000 ____D C:\Program Files\MSBuild
2022-04-10 02:39 - 2022-04-10 02:39 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2022-04-09 21:15 - 2022-04-09 21:15 - 000000000 ____D C:\WINDOWS\pss
2022-04-09 20:37 - 2022-04-09 20:37 - 000001154 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2022-04-09 20:37 - 2022-04-09 20:37 - 000000000 ____D C:\Program Files\PCHealthCheck
2022-04-09 20:14 - 2022-04-09 20:14 - 000000020 ___SH C:\Users\Ganja\ntuser.ini
2022-04-09 20:09 - 2022-04-15 22:42 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-04-09 20:09 - 2022-04-09 20:10 - 000003410 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachine UA
2022-04-09 20:09 - 2022-04-09 20:10 - 000002668 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0
2022-04-09 20:09 - 2022-04-09 20:09 - 000003186 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachine Core
2022-04-09 20:09 - 2022-04-09 20:09 - 000000000 ____D C:\WINDOWS\system32\Tasks\OfficeSoftwareProtection Platform
2022-04-09 20:08 - 2022-04-09 20:09 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2022-04-09 20:08 - 2022-04-09 20:09 - 000007623 _____ C:\WINDOWS\diagerr.xml
2022-04-09 20:00 - 2022-04-09 20:00 - 001451302 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-04-09 19:47 - 2022-04-15 19:16 - 000000000 ____D C:\Users\Ganja
2022-04-09 19:43 - 2016-10-27 16:14 - 000416576 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SASrv.exe
2022-04-09 19:43 - 2016-10-27 16:14 - 000416576 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\SASrv.exe
2022-04-09 19:43 - 2015-07-31 17:29 - 000004664 _____ C:\WINDOWS\system32\Drivers\CxSfPt.DAT
2022-04-09 19:43 - 2014-10-20 14:54 - 000207576 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
2022-04-09 19:35 - 2022-04-15 21:14 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-04-09 19:34 - 2022-04-15 22:42 - 000008192 ___SH C:\DumpStack.log.tmp
2022-04-09 19:34 - 2022-04-09 19:35 - 000319144 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-04-09 15:53 - 2022-04-09 20:36 - 000000000 ____D C:\Program Files\ruxim
2022-04-09 09:33 - 2022-04-14 21:22 - 000000000 ___DC C:\WINDOWS\Panther
2022-04-09 09:26 - 2022-04-09 09:26 - 000000000 ___HD C:$WinREAgent
2022-04-09 02:32 - 2022-04-09 02:32 - 000000000 ____D C:\Users\Ganja\AppData\Local\NemuPlayer
2022-04-09 02:32 - 2022-04-09 02:32 - 000000000 ____D C:\Users\Ganja\AppData\Local\cache
2022-04-09 02:02 - 2022-04-13 18:41 - 000000000 ____D C:\Users\Ganja\Documents\MuMuSharedFolder
2022-04-09 02:01 - 2022-04-09 02:01 - 000000000 ____D C:\Users\Ganja\AppData\Local\CrashRpt
2022-04-09 01:54 - 2022-04-14 18:03 - 000000000 ____D C:\Users\Public\Documents\MuMu Files
2022-04-09 01:54 - 2022-04-14 18:03 - 000000000 ____D C:\Program Files\NemuVbox
2022-04-09 01:50 - 2022-04-09 01:50 - 000000000 ____D C:\Program Files\MuMu
2022-04-09 01:49 - 2022-04-09 01:49 - 009731600 _____ (NetEase, Inc.) C:\Users\Ganja\Downloads\MuMuInstaller_1.4.0.0_gw-overseas_all_1644473805.exe
2022-04-09 01:21 - 2022-04-09 10:39 - 000000000 ____D C:\Users\Ganja.TianTianVM
2022-04-09 01:15 - 2022-04-09 01:15 - 000000299 _____ C:\Users\Ganja\d4ac4633ebd6440fa397b84f1bc94a3c.7z
2022-04-09 00:30 - 2022-04-09 01:23 - 000000000 ____D C:\Users\Ganja.android
2022-04-09 00:29 - 2022-04-09 00:29 - 000000066 _____ C:\Users\Ganja\inittk.ini
2022-04-09 00:27 - 2022-04-09 00:43 - 000000000 ____D C:\Users\Ganja\AppData\Local\NoxSrv
2022-04-09 00:27 - 2022-04-09 00:27 - 000000053 _____ C:\Users\Ganja\useruid.ini
2022-04-09 00:27 - 2022-04-09 00:27 - 000000045 _____ C:\Users\Ganja\nuuid.ini
2022-04-09 00:27 - 2022-04-09 00:27 - 000000041 _____ C:\Users\Ganja\inst.ini
2022-04-09 00:27 - 2022-04-09 00:27 - 000000000 ____D C:\Users\Ganja\Nox_share
2022-04-09 00:26 - 2022-04-09 00:43 - 000000000 ____D C:\Users\Ganja\vmlogs
2022-04-09 00:21 - 2022-04-14 18:04 - 000000000 ____D C:\Users\Ganja\AppData\Local\Nox
2022-04-09 00:16 - 2022-04-09 00:21 - 527327744 _____ (Duodian Technology Co. Ltd.) C:\Users\Ganja\Downloads\nox_setup_v7.0.2.5_full_i ntl.exe
2022-04-08 23:50 - 2022-04-08 23:50 - 000000000 ____D C:\Users\Ganja\AppData\Local\CrashDumps
2022-03-26 14:25 - 2022-03-27 20:00 - 000076461 _____ C:\Users\Ganja\Desktop\Ragnarok (Autosaved).xlsx
2022-03-26 10:43 - 2022-03-26 10:43 - 000000000 __RHD C:\MSOCache
2022-03-26 10:38 - 2022-03-26 10:38 - 000000165 ____H C:\Users\Ganja\Desktop~$Ragnarok.xlsx
2022-03-20 09:41 - 2022-03-20 09:45 - 000000000 ____D C:\Users\Ganja\Documents\CTK
2022-03-20 09:39 - 2022-03-20 09:39 - 000001124 _____ C:\Users\Ganja\Desktop\BloonsTK.exe - Shortcut.lnk
2022-03-19 16:32 - 2022-03-20 09:12 - 000014198 _____ C:\ProgramData\DisplaySessionContainer3.log_backup 1
2022-03-17 23:14 - 2022-03-17 23:14 - 000000112 ___SH C:\bootTel.dat
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-04-15 22:53 - 2022-03-14 17:42 - 000000000 ____D C:\FRST
2022-04-15 22:51 - 2019-03-19 13:52 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2022-04-15 22:47 - 2020-03-06 12:09 - 000000000 ____D C:\Program Files\CCleaner
2022-04-15 22:46 - 2019-12-07 18:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-04-15 22:45 - 2020-02-29 23:02 - 000000000 __SHD C:\Users\Ganja\IntelGraphicsProfiles
2022-04-15 22:42 - 2022-03-15 11:27 - 000000000 ____D C:\Intel
2022-04-15 22:42 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-04-15 22:41 - 2019-12-07 18:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2022-04-15 21:06 - 2019-12-07 18:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-04-15 19:10 - 2019-12-07 18:13 - 000000000 ____D C:\WINDOWS\INF
2022-04-15 19:09 - 2020-02-29 21:10 - 000000000 ____D C:\Program Files\CONEXANT
2022-04-15 19:09 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\security
2022-04-15 18:59 - 2019-12-07 18:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-04-15 18:48 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\registration
2022-04-15 18:47 - 2021-04-07 09:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
2022-04-15 08:13 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2022-04-15 07:28 - 2020-03-01 14:56 - 000000000 ____D C:\Users\Ganja\AppData\Local\ElevatedDiagnostics
2022-04-14 23:23 - 2020-02-29 21:19 - 000000000 ____D C:\Users\Ganja\AppData\Local\D3DSCache
2022-04-14 23:01 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-04-14 21:58 - 2020-02-29 21:10 - 000000000 ____D C:\ProgramData\UIU
2022-04-14 19:38 - 2021-12-15 22:03 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\XuanZhi64
2022-04-14 19:22 - 2021-12-15 22:17 - 000000000 ____D C:\Users\Ganja.Ld2VirtualBox
2022-04-14 19:09 - 2020-03-08 23:49 - 000000000 ____D C:\Users\Ganja\AppData\Local\Dropbox
2022-04-14 19:08 - 2020-03-08 23:49 - 000000000 ____D C:\Program Files (x86)\Dropbox
2022-04-14 18:58 - 2020-02-29 21:12 - 000002377 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-04-14 18:58 - 2020-02-29 21:08 - 000000000 ____D C:\Program Files (x86)\Google
2022-04-14 18:43 - 2020-04-29 14:24 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Visual Studio Setup
2022-04-14 18:43 - 2020-04-29 14:23 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
2022-04-14 18:42 - 2020-04-29 14:36 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2022-04-14 18:42 - 2020-04-29 14:36 - 000000000 ____D C:\Program Files (x86)\Microsoft SDKs
2022-04-14 18:38 - 2020-02-29 22:55 - 000000000 ____D C:\ProgramData\Package Cache
2022-04-14 18:12 - 2020-04-29 14:22 - 000000000 ____D C:\ProgramData\Microsoft Visual Studio
2022-04-14 18:06 - 2020-02-29 21:37 - 000000000 ____D C:\Games
2022-04-14 18:02 - 2020-02-29 21:09 - 000000000 ___RD C:\Users\Ganja\OneDrive
2022-04-14 18:01 - 2020-03-01 04:04 - 000000000 ____D C:\Users\Ganja\AppData\Local\Packages
2022-04-14 17:59 - 2020-03-04 00:17 - 000000000 ____D C:\Program Files\Cheat Engine 7.0
2022-04-14 17:34 - 2020-03-06 15:40 - 000000000 ____D C:\Program Files (x86)\Adobe
2022-04-14 17:34 - 2020-03-06 15:39 - 000000000 ____D C:\ProgramData\Adobe
2022-04-14 17:34 - 2020-03-01 04:04 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Adobe
2022-04-14 04:27 - 2020-03-01 03:49 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-04-13 23:41 - 2020-06-29 19:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tencent Software
2022-04-13 18:24 - 2020-03-11 19:31 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\ZHP
2022-04-13 17:57 - 2022-03-14 17:15 - 000000877 _____ C:\Users\Ganja\Desktop\ZHPCleaner.lnk
2022-04-12 21:31 - 2020-04-30 19:39 - 000000000 ____D C:\Users\Ganja\AppData\LocalLow\Temp
2022-04-12 21:19 - 2020-03-11 11:39 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\360DesktopLite
2022-04-12 21:18 - 2019-12-07 18:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2022-04-10 04:33 - 2021-11-29 19:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoHotkey
2022-04-10 04:33 - 2021-02-16 08:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2022-04-10 04:33 - 2020-05-29 19:42 - 000000000 ____D C:\Program Files\UNP
2022-04-10 04:33 - 2020-03-28 20:33 - 000000000 ____D C:\WINDOWS\system32\CleanLog
2022-04-10 04:33 - 2020-03-21 09:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2022-04-10 04:33 - 2020-03-06 12:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2022-04-10 04:33 - 2020-03-04 19:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2022-04-10 04:33 - 2020-03-04 00:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 7.0
2022-04-10 04:33 - 2020-03-03 14:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2022-04-10 04:33 - 2020-03-01 04:42 - 000000000 ____D C:\WINDOWS\ShellNew
2022-04-10 04:33 - 2020-02-29 23:03 - 000000000 ____D C:\Program Files\Intel
2022-04-10 04:33 - 2019-12-07 18:18 - 000000000 ____D C:\WINDOWS\Setup
2022-04-10 04:33 - 2019-12-07 18:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2022-04-10 04:33 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2022-04-10 04:33 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\spool
2022-04-10 04:33 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-04-10 04:33 - 2019-12-07 18:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2022-04-10 04:33 - 2019-03-19 13:52 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2022-04-10 04:33 - 2019-03-19 13:52 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2022-04-10 04:22 - 2020-02-29 21:09 - 000000000 ____D C:\WINDOWS\system32\Intel
2022-04-10 04:20 - 2020-04-29 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2019
2022-04-10 04:04 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2022-04-10 04:03 - 2019-12-07 23:49 - 000000000 ___SD C:\WINDOWS\system32\AppV
2022-04-10 04:03 - 2019-12-07 23:49 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2022-04-10 04:03 - 2019-12-07 23:49 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-04-10 04:03 - 2019-12-07 23:49 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2022-04-10 04:03 - 2019-12-07 23:46 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2022-04-10 04:03 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2022-04-10 04:03 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\en-GB
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\setup
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\Keywords
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\Com
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\Provisioning
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\IME
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\Program Files\Common Files\System
2022-04-10 04:03 - 2019-12-07 18:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2022-04-10 04:03 - 2019-12-07 18:03 - 000000000 ____D C:\WINDOWS\servicing
2022-04-10 03:58 - 2019-12-07 23:49 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2022-04-10 03:58 - 2019-12-07 23:49 - 000020908 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2022-04-10 03:03 - 2019-12-07 23:47 - 000000000 ____D C:\WINDOWS\OCR
2022-04-10 03:01 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2022-04-10 03:01 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\system32\WCN
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\system32\winrm
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\system32\slmgr
2022-04-10 02:55 - 2019-12-07 23:45 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2022-04-10 02:55 - 2019-12-07 18:14 - 000000000 ___SD C:\WINDOWS\system32\dsc
2022-04-10 02:55 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2022-04-10 02:55 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\MUI
2022-04-09 21:39 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\appcompat
2022-04-09 20:42 - 2020-10-07 17:08 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2022-04-09 20:36 - 2019-12-07 18:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2022-04-09 20:35 - 2020-02-29 21:54 - 000803176 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2022-04-09 20:19 - 2020-02-29 21:22 - 000000000 ____D C:\ProgramData\Packages
2022-04-09 20:19 - 2019-12-07 18:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-04-09 20:17 - 2020-03-01 04:04 - 000000000 __RHD C:\Users\Public\AccountPictures
2022-04-09 20:17 - 2020-03-01 04:04 - 000000000 ___RD C:\Users\Ganja\3D Objects
2022-04-09 20:11 - 2019-12-07 18:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-04-09 20:10 - 2019-12-07 18:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2022-04-09 20:09 - 2019-12-07 18:14 - 000000000 ____D C:\ProgramData\USOPrivate
2022-04-09 20:09 - 2019-12-07 18:14 - 000000000 ____D C:\Program Files\Windows Defender
2022-04-09 19:58 - 2019-12-07 18:14 - 000000000 __RHD C:\Users\Public\Libraries
2022-04-09 19:48 - 2022-03-12 16:42 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Redfinger
2022-04-09 19:48 - 2020-03-04 19:25 - 000000000 ____D C:\Users\Ganja\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\WinRAR
2022-04-09 19:45 - 2020-05-19 00:00 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2022-04-09 19:44 - 2021-04-07 09:07 - 000001963 _____ C:\ProgramData\Microsoft\Windows\Start Menu\SmartAudio.lnk
2022-04-09 19:43 - 2020-02-29 21:10 - 001705080 _____ (TODO: ) C:\WINDOWS\SysWOW64\RebootPrompt.exe
2022-04-09 15:54 - 2020-04-29 14:32 - 000000000 ____D C:\Program Files\dotnet
2022-04-09 15:43 - 2020-02-29 22:19 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-04-09 15:42 - 2020-02-29 22:19 - 145666720 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-04-09 15:41 - 2020-04-29 14:32 - 000000000 ____D C:\Program Files (x86)\dotnet
2022-04-09 15:38 - 2020-04-29 14:35 - 000000000 ____D C:\Users\Ganja.dotnet
2022-04-09 09:23 - 2020-02-29 23:02 - 000000000 ____D C:\Users\Ganja\AppData\Local\Intel
2022-03-18 08:34 - 2022-03-15 13:00 - 000000000 ____D C:\Program Files (x86)\TurboVPN
2022-03-18 08:34 - 2022-03-12 16:42 - 000000000 ____D C:\Program Files (x86)\RedFingerPlayerGlobal
2022-03-18 08:18 - 2020-02-29 22:54 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2022-03-17 23:35 - 2020-03-08 23:50 - 000000938 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2022-03-17 23:35 - 2020-03-08 23:49 - 000000934 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
==================== Files in the root of some directories ========
2020-04-10 11:34 - 2020-04-10 11:34 - 003295616 _____ (Nicolas Coolman) C:\Users\Ganja\ZHPCleaner.exe
2021-12-15 22:17 - 2021-12-15 22:17 - 000000068 _____ () C:\Users\Ganja\AppData\Roaming\changzhi_leidian.da ta
2021-12-15 22:17 - 2021-12-15 22:17 - 000000154 _____ () C:\Users\Ganja\AppData\Roaming\changzhi_leidianmac .data
2020-05-02 22:47 - 2021-01-04 14:51 - 000001190 _____ () C:\Users\Ganja\AppData\Roaming_encryptiondb.grf
2020-03-08 11:10 - 2020-03-08 11:10 - 000000000 _____ () C:\Users\Ganja\AppData\Local\oobelibMkey.log
2020-03-15 19:56 - 2020-03-15 19:56 - 000007625 _____ () C:\Users\Ganja\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Comment