Ladekabel612 | 25.04.2021 17:27 |
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-04-2021
Ran by Lem0th (administrator) on DESKTOP-J6EBHR7 (25-04-2021 18:22:09)
Running from C:\Users\Lem0th\Desktop
Loaded Profiles: Lem0th
Platform: Windows 10 Pro Version 20H2 19042.928 (X64) Language: German (Germany) -> English (United Kingdom)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe
(ASUSTeK Computer Inc. -> ) C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x86.exe
(ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
(ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
(ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe
(ASUSTeK Computer Inc. -> ASUSTek Compputer Inc.) C:\Program Files\ASUS\AacMB\Aac3572MbHal_x86.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe <2>
(ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.02.03\atkexComSvc.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\LightingService.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\AacExtCard\extensionCardHal_x86.exe
(ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe
(ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.UserSessionHelper.exe
(ASUSTEK COMPUTER INCORPORATION -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe
(A-Volute -> Nahimic) C:\Windows\System32\NahimicService.exe
(A-Volute SAS -> A-Volute) C:\Users\Lem0th\AppData\Local\NhNotifSys\sonicstudio\asusns.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.CpuIdRemote64.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.DisplayAdapter.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CueLLAccessService.exe
(Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\iCUE.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Even Balance, Inc. -> ) C:\Windows\System32\PnkBstrA.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(GuinpinSoft inc) [File not signed] C:\Program Files\Common Files\cdarbsvc\cdarbsvc_v1.0.0_x64.exe
(Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Leawo Software) [File not signed] C:\Program Files (x86)\Common Files\cdagtsvc\cdagtsvc_v1.0.0_x86.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Mega Limited -> Mega Limited) C:\Users\Lem0th\AppData\Local\MEGAsync\MEGAsync.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.52.13001.0_x64__8wekyb3d8bbwe\GamingServices.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_2.52.13001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\NisSrv.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <8>
(Nextcloud GmbH -> Nextcloud GmbH) C:\Program Files\Nextcloud\nextcloud.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(Skutta, Kristjan -> ) E:\SteamLibrary\steamapps\common\wallpaper_engine\bin\wallpaperservice32_c.exe
(Skutta, Kristjan -> ) E:\SteamLibrary\steamapps\common\wallpaper_engine\wallpaper32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TODO: <Company name>) [File not signed] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AIOFanSDK\ArmouryAIOFanServer.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [797216 2018-10-22] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706680 2020-09-16] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [CORSAIR iCUE Software] => C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\iCUE Launcher.exe [409760 2021-03-05] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
HKU\S-1-5-21-2331486850-4249055999-2076793073-1004\...\Run: [Discord] => C:\Users\Lem0th\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2331486850-4249055999-2076793073-1004\...\Run: [GogGalaxy] => C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [14916448 2021-03-29] (GOG Sp. z o.o. -> GOG.com)
HKU\S-1-5-21-2331486850-4249055999-2076793073-1004\...\Run: [pCloud] => C:\Program Files\pCloud Drive\pCloud.exe
HKU\S-1-5-21-2331486850-4249055999-2076793073-1004\...\Run: [Opera GX Browser Assistant] => C:\Users\Lem0th\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2331486850-4249055999-2076793073-1004\...\Run: [Nextcloud] => C:\Program Files\Nextcloud\nextcloud.exe [2683712 2021-04-09] (Nextcloud GmbH -> Nextcloud GmbH)
HKU\S-1-5-21-2331486850-4249055999-2076793073-1004\...\MountPoints2: {a1609cae-7353-11ea-b112-049226d53ae6} - "E:\HiSuiteDownLoader.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{43F137B0-8F4D-463B-AB83-ADEAD4F15096}] -> C:\Program Files (x86)\Microsoft\Edge Beta\Application\90.0.818.46\Installer\setup.exe [2021-04-23] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.85\Installer\chrmstp.exe [2021-04-20] (Google LLC -> Google LLC)
Startup: C:\Users\Lem0th\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2021-03-27]
ShortcutTarget: MEGAsync.lnk -> C:\Users\Lem0th\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01664F83-85F1-4DC0-90F2-DF330ABC0B0B} - System32\Tasks\Microsoft\Windows\PLA\CPU Usage => {FF679DA1-8FF2-4474-9C9E-52BBD409B557} C:\WINDOWS\system32\pla.dll [1493504 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {01EB0D2D-9242-4029-8BCA-471044BEB93B} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-09-29] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {093682DD-DEC7-4FDB-9AC9-A9707AD0A33F} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d729a046d57eec => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-04-05] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {0B047319-D529-4AC2-972B-F7F48C2BED95} - System32\Tasks\ASUS\NoiseCancelingEngine.exe => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe [1238328 2021-01-21] (ASUSTeK Computer Inc. -> ASUS)
Task: {1E34214F-8000-4F00-AC43-F06A53BA0439} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Lem0th\Downloads\ESETOnlineScanner_DEU.exe
Task: {28297989-FF1C-438C-BBEB-24797DBAF01D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\MpCmdRun.exe [566368 2021-04-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2A88A267-71FD-4683-B199-74D7DB593EDD} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [862 2019-04-30] () [File not signed]
Task: {2AFAE5D6-E448-4BD0-A2EB-E822F7266794} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2E05A762-241D-4789-A990-4A651EF0DB3E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\MpCmdRun.exe [566368 2021-04-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2EE2AD29-8E21-4B17-B828-6D8DA5832077} - System32\Tasks\Opera GX scheduled Autoupdate 1618421482 => C:\Users\Lem0th\AppData\Local\Programs\Opera GX\launcher.exe [1720472 2021-04-19] (Opera Software AS -> Opera Software)
Task: {33A040C4-FFBD-4F8C-8FDF-A87FBC882CE3} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {370059CC-13B8-4D86-8335-B97F10C8F389} - System32\Tasks\NahimicSvc32Run => C:\WINDOWS\SysWOW64\NahimicSvc32.exe [822704 2020-11-04] (A-Volute -> Nahimic)
Task: {38232CC6-BFE4-4886-9306-E71244898D51} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-10-27] (Google Inc -> Google LLC)
Task: {470D0E37-5950-432B-B344-3DDEF0D9D0FE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-10-27] (Google Inc -> Google LLC)
Task: {47ED6285-C387-4DE8-902D-A50F39C4B7F5} - System32\Tasks\ASUS\ArmouryAIOFanServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AIOFanSDK\ArmouryAIOFanServer.exe [756224 2021-02-18] (TODO: <Company name>) [File not signed]
Task: {48F98980-F45C-433A-8108-36E61B16A719} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe [45585520 2021-03-29] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {58B9B65A-A251-4F0F-AF8E-F1D34202B4D0} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-2331486850-4249055999-2076793073-1004 => C:\Users\Lem0th\AppData\Local\MEGAsync\MEGAupdater.exe [1818360 2021-01-28] (Mega Limited -> Mega Limited)
Task: {5963C6C5-4988-468A-8954-3E08943788C9} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5F162B60-2A00-4BC5-BABD-783F7FD10A95} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\MpCmdRun.exe [566368 2021-04-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5F1CAFE6-D9B8-4AF0-BEFA-4344F51077B4} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-09-29] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {8148F4B7-8A9C-4740-BA58-88B58F16C86B} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-04-05] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {84298132-B677-46E7-873D-5ADD2F5691F6} - System32\Tasks\Alle Fenster minmieren => C:\Users\Lem0th\Documents\screensaver.vbs
Task: {85271E1F-AA3B-4934-9EBD-01D8C3F8C37E} - System32\Tasks\NahimicSvc64Run => C:\WINDOWS\System32\NahimicSvc64.exe [1066416 2020-11-04] (A-Volute -> Nahimic)
Task: {88359139-948E-4E05-84E7-58BB653B8387} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Lem0th\Downloads\ESETOnlineScanner_DEU.exe
Task: {9E7637BD-4851-4DA7-B656-D8C079B9B728} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [113376 2021-03-08] (ASUSTeK Computer Inc. -> ASUS)
Task: {9F8718FC-0BC5-44DD-BA5F-7D94D269D1BA} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1260400 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AB8E148C-1196-423A-A059-6DC90934C514} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905584 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AFB46D49-C509-4C89-8BC6-991FDFE449B7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\MpCmdRun.exe [566368 2021-04-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B8CC6603-77F9-409A-BB32-130E22454001} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [645488 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B95C791B-B514-41D0-97C7-9DE49E035D7F} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3336560 2021-04-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C5460D46-B1A2-4718-A2C4-D7C661262264} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [696304 2021-04-19] (Mozilla Corporation -> Mozilla Foundation)
Task: {C960D680-97CC-4C39-B61A-BA08A0491EA3} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1618579602 => C:\Users\Lem0th\AppData\Local\Programs\Opera GX\launcher.exe [1720472 2021-04-19] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Lem0th\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {C9E56682-6E62-4FBC-A59A-8489CC3AAEF5} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe [2120032 2021-03-08] (ASUSTeK Computer Inc. -> ASUS)
Task: {CF513470-94D9-4003-9843-893AF510E726} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [1652536 2018-11-05] (Intel(R) Software -> Intel Corporation)
Task: {D4EC6155-3012-46D7-9586-1B8B760AB69C} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\IntelPTTEKRecertification.exe [918288 2020-04-22] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {E13BB522-48E3-4D96-89EF-3CD86877A71B} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [905584 2021-04-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {EE033EC3-45C4-4227-AA6D-5E7D46DE6273} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{035a39fa-271c-433c-b0d1-1424d18b82c7}: [NameServer] 1.1.1.1,1.0.0.1
Tcpip\..\Interfaces\{035a39fa-271c-433c-b0d1-1424d18b82c7}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{127dd634-8b90-4b9b-b0c4-7183103b83dc}: [NameServer] 192.168.178.34,1.0.0.1
Tcpip\..\Interfaces\{127dd634-8b90-4b9b-b0c4-7183103b83dc}: [DhcpNameServer] 192.168.178.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\Lem0th\AppData\Local\Microsoft\Edge\User Data\Default [2021-04-22]
Edge Notifications: Default -> hxxps://192.168.178.34
Edge Extension: (uBlock Origin) - C:\Users\Lem0th\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2021-03-24]
StartMenuInternet: Microsoft Edge Beta - C:\Program Files (x86)\Microsoft\Edge Beta\Application\msedge.exe
FireFox:
========
FF DefaultProfile: urpz1bnq.default
FF ProfilePath: C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\urpz1bnq.default [2021-04-25]
FF ProfilePath: C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release [2021-04-25]
FF Notifications: Mozilla\Firefox\Profiles\40a0sgm9.default-release -> hxxps://www2a.rudyvalencia.pro; hxxps://www2a.delmarmora.pro; hxxps://192.168.178.34
FF Extension: (English United States Dictionary) - C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\Extensions\@unitedstatesenglishdictionary.xpi [2020-10-12]
FF Extension: (Tampermonkey) - C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\Extensions\firefox@tampermonkey.net.xpi [2021-03-18]
FF Extension: (Deutsch (DE) Language Pack) - C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\Extensions\langpack-de@firefox.mozilla.org.xpi [2021-04-20]
FF Extension: (English (US) Language Pack) - C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\Extensions\langpack-en-US@firefox.mozilla.org.xpi [2021-04-20]
FF Extension: (uBlock Origin) - C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\Extensions\uBlock0@raymondhill.net.xpi [2021-04-23]
FF Extension: (Picture-In-Picture) - C:\Program Files\Mozilla Firefox\browser\features\pictureinpicture@mozilla.org.xpi [2021-04-19] [not signed]
FF Plugin: @java.com/DTPlugin,version=11.271.2 -> C:\Program Files\Java\jre1.8.0_271\bin\dtplugin\npDeployJava1.dll [2020-12-20] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.271.2 -> C:\Program Files\Java\jre1.8.0_271\bin\plugin2\npjp2.dll [2020-12-20] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) [File not signed]
Chrome:
=======
CHR Profile: C:\Users\Lem0th\AppData\Local\Google\Chrome\User Data\Default [2021-04-25]
CHR Extension: (Präsentationen) - C:\Users\Lem0th\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-10-27]
CHR Extension: (Docs) - C:\Users\Lem0th\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-10-27]
CHR Extension: (Google Drive) - C:\Users\Lem0th\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-11-07]
CHR Extension: (YouTube) - C:\Users\Lem0th\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-10-27]
CHR Extension: (Tabellen) - C:\Users\Lem0th\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-10-27]
CHR Extension: (Google Docs Offline) - C:\Users\Lem0th\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-04-22]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Lem0th\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-18]
CHR Extension: (Google Mail) - C:\Users\Lem0th\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-11-07]
CHR Extension: (Chrome Media Router) - C:\Users\Lem0th\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-04-22]
Opera:
=======
StartMenuInternet: (HKU\S-1-5-21-2331486850-4249055999-2076793073-1004) Opera GXStable - "C:\Users\Lem0th\AppData\Local\Programs\Opera GX\Launcher.exe"
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ArmouryCrateService; C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe [348280 2021-03-22] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.03\atkexComSvc.exe [449336 2021-02-17] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-04-05] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [313008 2020-11-19] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.)
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-04-05] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S2 AsusROGLSLService; C:\Program Files (x86)\ASUS\AsusROGLSLService\AsusROGLSLService.exe [591176 2021-04-25] (ASUSTeK Computer Inc. -> )
S2 AsusUpdateCheck; C:\WINDOWS\System32\AsusUpdateCheck.exe [1097976 2021-04-25] (ASUSTeK Computer Inc. -> )
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8736880 2021-03-11] (BattlEye Innovations e.K. -> )
R2 CdRomAccessAgentService; C:\Program Files (x86)\Common Files\cdagtsvc\cdagtsvc_v1.0.0_x86.exe [90112 2021-04-22] (Leawo Software) [File not signed]
R2 CdRomArbiterService; C:\Program Files\Common Files\cdarbsvc\cdarbsvc_v1.0.0_x64.exe [8704 2021-04-21] (GuinpinSoft inc) [File not signed]
R2 CorsairGamingAudioConfig; C:\WINDOWS\system32\CorsairGamingAudioCfgService64.exe [616344 2020-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R2 CorsairLLAService; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CueLLAccessService.exe [421536 2021-03-05] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
R2 CorsairService; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\Corsair.Service.exe [80544 2021-03-05] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342456 2021-01-18] (FUTUREMARK INC -> Futuremark)
S3 FvSvc; C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [409456 2021-03-30] (NVIDIA Corporation -> NVIDIA)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [1874272 2021-03-29] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6840672 2021-03-29] (GOG Sp. z o.o. -> GOG.com)
R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [3210232 2021-03-03] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7456464 2021-02-07] (Malwarebytes Inc -> Malwarebytes)
S3 MicrosoftEdgeBetaElevationService; C:\Program Files (x86)\Microsoft\Edge Beta\Application\90.0.818.46\elevation_service.exe [1567648 2021-04-22] (Microsoft Corporation -> Microsoft Corporation)
R2 NahimicService; C:\WINDOWS\system32\NahimicService.exe [2719664 2020-11-04] (A-Volute -> Nahimic)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2535000 2021-03-30] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3479640 2021-03-30] (Electronic Arts, Inc. -> Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2020-08-29] (Even Balance, Inc. -> )
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1676696 2021-03-27] (Rockstar Games, Inc. -> Rockstar Games)
R2 ROG Live Service; C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe [5557848 2021-03-24] (ASUSTEK COMPUTER INCORPORATION -> ASUSTek COMPUTER INC.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5361256 2021-04-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13103632 2020-09-17] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [746944 2021-01-07] (Oracle Corporation -> Oracle Corporation)
R2 Wallpaper Engine Service; E:\SteamLibrary\steamapps\common\wallpaper_engine\bin\wallpaperservice32_c.exe [520296 2021-02-21] (Skutta, Kristjan -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\NisSrv.exe [2624104 2021-04-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\MsMpEng.exe [128376 2021-04-11] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2017-04-14] (ASUSTeK Computer Inc. -> )
R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [33832 2019-04-09] (ASUSTeK Computer Inc. -> )
R1 Asusgio3; C:\WINDOWS\system32\drivers\AsIO3.sys [43920 2020-12-16] (ASUSTeK Computer Inc. -> )
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
R1 cbfsconnect2017; C:\WINDOWS\system32\drivers\cbfsconnect2017.sys [481296 2020-06-25] (Microsoft Windows Hardware Compatibility Publisher -> Callback Technologies, Inc.)
R3 CorsairGamingAudioService; C:\WINDOWS\system32\DRIVERS\CorsairGamingAudio64.sys [60312 2020-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R2 CorsairLLAccess3B84E98236B28D4E075D5737DF9F567A1FB76E8A; C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CorsairLLAccess64.sys [21752 2021-01-11] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [45984 2020-07-07] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21920 2020-07-07] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 cpuz150; C:\WINDOWS\temp\cpuz150\cpuz150_x64.sys [44832 2021-04-25] (CPUID S.A.R.L.U. -> CPUID)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 EneTechIo; C:\WINDOWS\system32\drivers\ene.sys [20992 2020-05-12] (Microsoft Windows Hardware Compatibility Publisher -> )
R1 GLCKIO2; C:\Windows\system32\drivers\GLCKIO2.sys [29368 2019-04-24] (ASUSTeK Computer Inc. -> )
S3 Hamachi; C:\WINDOWS\System32\drivers\Hamdrv.sys [45680 2019-04-02] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [35344 2021-03-24] (ASUSTEK COMPUTER INC. -> ASUSTeK Computer Inc.)
S3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2018-10-05] (Logitech Inc -> Logitech Inc.)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220752 2021-04-25] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-02-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-04-25] (Malwarebytes Inc -> Malwarebytes)
R1 MSIO; C:\WINDOWS\system32\drivers\MsIo64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
S3 npcap; C:\WINDOWS\system32\DRIVERS\npcap.sys [83776 2019-05-11] (Insecure.Com LLC -> Insecure.Com LLC.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14024 2017-08-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 tapwindscribe0901; C:\WINDOWS\System32\drivers\tapwindscribe0901.sys [54896 2018-07-06] (Windscribe Limited -> The OpenVPN Project)
R3 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [239872 2021-01-07] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [249776 2021-01-07] (Oracle Corporation -> Oracle Corporation)
R3 vpnpbus; C:\WINDOWS\System32\drivers\vpnpbus.sys [20496 2020-06-25] (Microsoft Windows Hardware Compatibility Publisher -> Callback Technologies, Inc.)
U5 vsock; C:\Windows\System32\Drivers\vsock.sys [103224 2019-08-14] (VMware, Inc. -> VMware, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2021-04-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [421088 2021-04-11] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [72928 2021-04-11] (Microsoft Windows -> Microsoft Corporation)
S3 cpuz149; \??\C:\WINDOWS\temp\cpuz149\cpuz149_x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-04-25 18:22 - 2021-04-25 18:22 - 000033784 _____ C:\Users\Lem0th\Desktop\FRST.txt
2021-04-25 18:20 - 2021-04-25 18:20 - 000220752 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-04-25 18:20 - 2021-04-25 18:20 - 000000008 __RSH C:\ProgramData\ntuser.pol
2021-04-25 18:11 - 2021-04-25 18:19 - 000043173 _____ C:\Users\Lem0th\Desktop\Fixlog.txt
2021-04-25 17:04 - 2021-04-25 17:04 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2021-04-25 17:04 - 2021-04-13 11:26 - 001435856 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-04-25 17:04 - 2021-04-13 11:26 - 001435856 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2021-04-25 17:04 - 2021-04-13 11:25 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2021-04-25 17:04 - 2021-04-13 11:25 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo.exe
2021-04-25 17:04 - 2021-04-13 11:25 - 001452312 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2021-04-25 17:04 - 2021-04-13 11:25 - 001191704 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2021-04-25 17:04 - 2021-04-13 11:25 - 001094864 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2021-04-25 17:04 - 2021-04-13 11:25 - 001094864 _____ C:\WINDOWS\system32\vulkan-1.dll
2021-04-25 17:04 - 2021-04-13 11:25 - 000948952 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2021-04-25 17:04 - 2021-04-13 11:25 - 000948952 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2021-04-25 17:04 - 2021-04-13 11:22 - 001514784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2021-04-25 17:04 - 2021-04-13 11:22 - 001166112 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2021-04-25 17:04 - 2021-04-13 11:22 - 000715552 _____ C:\WINDOWS\system32\nvofapi64.dll
2021-04-25 17:04 - 2021-04-13 11:22 - 000675096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2021-04-25 17:04 - 2021-04-13 11:22 - 000575776 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2021-04-25 17:04 - 2021-04-13 11:22 - 000564000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2021-04-25 17:04 - 2021-04-13 11:21 - 002106144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2021-04-25 17:04 - 2021-04-13 11:21 - 001590552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2021-04-25 17:04 - 2021-04-13 11:21 - 000811800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2021-04-25 17:04 - 2021-04-13 11:20 - 008317216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2021-04-25 17:04 - 2021-04-13 11:20 - 007434008 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2021-04-25 17:04 - 2021-04-13 11:20 - 004795184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2021-04-25 17:04 - 2021-04-13 11:20 - 002823456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2021-04-25 17:04 - 2021-04-13 11:20 - 001730848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6446611.dll
2021-04-25 17:04 - 2021-04-13 11:20 - 001490208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6446611.dll
2021-04-25 16:59 - 2020-08-14 09:59 - 000043416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\NvModuleTracker.sys
2021-04-25 16:13 - 2021-04-25 16:14 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Magic.TXD config
2021-04-25 16:02 - 2021-04-25 16:02 - 000000000 ____D C:\Program Files\Magic TXD
2021-04-25 16:00 - 2021-04-25 16:02 - 000000000 ____D C:\Users\Lem0th\Desktop\mods gta sa
2021-04-25 16:00 - 2021-04-25 16:00 - 022725711 _____ C:\Users\Lem0th\Downloads\setup_11_rc3.zip
2021-04-25 15:11 - 2021-04-25 15:11 - 001377907 _____ C:\Users\Lem0th\Downloads\ArmouryCrateInstallTool.zip
2021-04-25 14:32 - 2021-04-25 14:32 - 040488656 _____ (Adlice Software ) C:\Users\Lem0th\Downloads\RogueKiller_setup.exe
2021-04-25 14:30 - 2021-04-25 14:31 - 000000000 ____D C:\AdwCleaner
2021-04-25 11:48 - 2021-04-25 18:22 - 000000000 ____D C:\FRST
2021-04-25 11:48 - 2021-04-25 11:48 - 002298368 _____ (Farbar) C:\Users\Lem0th\Desktop\FRST64.exe
2021-04-25 11:43 - 2021-04-25 13:47 - 000000000 ____D C:\Users\Lem0th\AppData\LocalLow\IGDump
2021-04-24 22:59 - 2021-04-24 22:59 - 000001258 _____ C:\Users\Public\Desktop\Leawo Prof. Media.lnk
2021-04-24 22:59 - 2021-04-24 22:59 - 000001258 _____ C:\ProgramData\Desktop\Leawo Prof. Media.lnk
2021-04-24 22:59 - 2020-08-12 09:43 - 000606208 _____ (hxxp://www.xvid.org) C:\WINDOWS\SysWOW64\xvidcore.dll
2021-04-24 22:59 - 2020-08-12 09:43 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp71.dll
2021-04-24 22:59 - 2020-08-12 09:43 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr71.dll
2021-04-24 22:59 - 2020-08-12 09:43 - 000139264 _____ (hxxp://www.xvid.org) C:\WINDOWS\SysWOW64\xvid.ax
2021-04-24 21:57 - 2021-04-24 21:57 - 000278775 _____ C:\Users\Lem0th\Downloads\OldNewExplorer.rar
2021-04-24 21:57 - 2021-04-24 21:57 - 000000000 ____D C:\Users\Lem0th\Downloads\OldNewExplorer
2021-04-24 21:40 - 2021-04-24 21:40 - 004105063 _____ C:\Users\Lem0th\Downloads\nemo_by_kdr3w_dc8k7b7.zip
2021-04-24 21:17 - 2021-04-24 21:17 - 000162448 _____ (Manuel Hoefs (Zottel)) C:\Users\Lem0th\Downloads\UltraUXThemePatcher_4.1.2.exe
2021-04-24 15:25 - 2021-04-24 15:25 - 000000000 ____D C:\Users\Lem0th\AppData\Local\SmartTechnology
2021-04-24 15:23 - 2021-04-24 15:25 - 000000000 ____D C:\Users\Public\Documents\Mad Catz
2021-04-24 15:23 - 2021-04-24 15:23 - 000003065 _____ C:\Users\Lem0th\Desktop\MADCATZ R.A.T. 6+.lnk
2021-04-24 15:23 - 2021-04-24 15:23 - 000000000 ____D C:\Program Files\Mad Catz
2021-04-24 15:20 - 2021-04-24 15:22 - 015992319 _____ (Igor Pavlov) C:\Users\Lem0th\Downloads\RAT_6+_x64.exe
2021-04-23 18:07 - 2021-04-23 18:07 - 000000000 ____D C:\ProgramData\aacs
2021-04-23 18:01 - 2021-04-25 13:15 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\dvdcss
2021-04-23 17:45 - 2021-04-23 17:45 - 000046592 _____ C:\Users\Lem0th\Downloads\libdvdcss-2.dll
2021-04-23 17:45 - 2021-04-23 17:45 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\HandBrake
2021-04-23 17:41 - 2021-04-23 17:41 - 013534240 _____ C:\Users\Lem0th\Downloads\HandBrake-1.3.3-x86_64-Win_GUI.exe
2021-04-23 16:04 - 2021-04-23 16:04 - 001421296 _____ C:\Users\Lem0th\Downloads\drive-download-20210423T140444Z-001.zip
2021-04-22 16:56 - 2021-04-22 16:56 - 000050997 _____ C:\Users\Lem0th\Downloads\Unbenanntes Dokument.pdf
2021-04-22 16:45 - 2021-04-22 16:45 - 000088171 _____ C:\Users\Lem0th\Downloads\Aufgaben_Das Arbeitslosengeld_ea8def65b062ba3a4080908b29bb024c.pdf
2021-04-22 14:09 - 2021-04-22 14:10 - 000000000 ____D C:\Users\Lem0th\.dvdcss
2021-04-22 14:07 - 2021-04-22 14:07 - 000000000 ____D C:\Users\Lem0th\Downloads\Leawo Prof. Media 8.3.0.3
2021-04-22 13:53 - 2021-04-22 13:53 - 000094720 _____ C:\Users\Lem0th\Downloads\M65Elite_ISPv3.37.5.bin
2021-04-22 13:42 - 2021-04-22 13:42 - 000000000 ____D C:\Users\Lem0th\vm
2021-04-22 13:19 - 2021-04-22 13:28 - 140258448 _____ C:\Users\Lem0th\Downloads\Leawo Prof. Media 8.3.0.3.rar
2021-04-22 12:57 - 2021-04-22 13:03 - 132984680 _____ (Leawo Software Co., Ltd. ) C:\Users\Lem0th\Downloads\ltmcp_setup.exe
2021-04-22 12:42 - 2021-04-22 12:42 - 003374756 _____ C:\Users\Lem0th\Downloads\9 alte Prüfungsaufgaben allg(1).pdf
2021-04-22 12:28 - 2021-04-22 12:28 - 001614874 _____ C:\Users\Lem0th\Downloads\8 alte Prüfungsaufgabe(1).pdf
2021-04-22 12:14 - 2021-04-22 12:14 - 003335780 _____ C:\Users\Lem0th\Downloads\9 alte Prüfungsaufgaben allg.pdf
2021-04-22 12:10 - 2021-04-22 12:10 - 001591280 _____ C:\Users\Lem0th\Downloads\8 alte Prüfungsaufgabe.pdf
2021-04-22 09:05 - 2021-04-22 09:05 - 000001292 _____ C:\Users\Public\Desktop\Leawo Blu-ray Player.lnk
2021-04-22 09:05 - 2021-04-22 09:05 - 000001292 _____ C:\ProgramData\Desktop\Leawo Blu-ray Player.lnk
2021-04-22 09:05 - 2021-04-22 09:05 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Leawo
2021-04-22 09:04 - 2021-04-22 09:05 - 107116800 _____ (Leawo Software Co., Ltd. ) C:\Users\Lem0th\Downloads\blurayplayer2201_setup.exe
2021-04-22 08:56 - 2021-04-22 08:56 - 000000000 ___HD C:\$Windows.~WS
2021-04-22 08:56 - 2021-04-22 08:56 - 000000000 ____D C:\$WINDOWS.~BT
2021-04-22 08:52 - 2021-04-24 22:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Leawo
2021-04-22 08:52 - 2021-04-22 09:05 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\Leawo
2021-04-22 08:52 - 2021-04-22 09:05 - 000000000 ____D C:\ProgramData\Leawo
2021-04-22 08:52 - 2021-04-22 09:05 - 000000000 ____D C:\Program Files (x86)\Leawo
2021-04-22 08:52 - 2021-04-22 08:52 - 000000000 ____D C:\Users\Lem0th\Documents\Leawo
2021-04-22 08:52 - 2021-04-22 08:52 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\tiger-k
2021-04-22 08:52 - 2021-04-22 08:52 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Leawo Prof
2021-04-22 08:52 - 2020-08-12 09:43 - 000066944 _____ (TOSHIBA Corporation) C:\WINDOWS\SysWOW64\thdudf.sys
2021-04-22 08:52 - 2020-08-12 09:43 - 000066944 _____ (TOSHIBA Corporation) C:\WINDOWS\SysWOW64\Drivers\thdudf.sys
2021-04-22 08:47 - 2021-04-22 08:51 - 132984680 _____ (Leawo Software Co., Ltd. ) C:\Users\Lem0th\Downloads\ltmcp_setup_g108568.exe
2021-04-22 08:33 - 2021-04-22 08:33 - 007783723 _____ C:\Users\Lem0th\Downloads\twindexx_rrx_repaint_1.1.zip
2021-04-21 23:05 - 2021-04-22 08:45 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\aacs
2021-04-21 23:05 - 2021-04-21 23:05 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\bluray
2021-04-21 23:04 - 2021-04-21 23:05 - 001235968 _____ C:\Users\Lem0th\Downloads\libaacs.dll
2021-04-21 23:02 - 2021-04-25 16:09 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\vlc
2021-04-21 22:59 - 2021-04-21 22:59 - 000000916 _____ C:\Users\Public\Desktop\VLC media player.lnk
2021-04-21 22:59 - 2021-04-21 22:59 - 000000916 _____ C:\ProgramData\Desktop\VLC media player.lnk
2021-04-21 22:59 - 2021-04-21 22:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2021-04-21 22:56 - 2021-04-21 22:56 - 042585440 _____ C:\Users\Lem0th\Downloads\vlc-3.0.12-win64.exe
2021-04-21 22:55 - 2021-04-21 22:55 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\Macromedia
2021-04-21 19:15 - 2021-04-21 19:15 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\4316
2021-04-21 19:07 - 2021-04-22 16:28 - 000000000 ____D C:\Users\Lem0th\.MakeMKV
2021-04-21 19:07 - 2021-04-21 19:07 - 000001064 _____ C:\Users\Lem0th\Desktop\MakeMKV.lnk
2021-04-21 19:07 - 2021-04-21 19:07 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MakeMKV
2021-04-21 19:07 - 2021-04-21 19:07 - 000000000 ____D C:\Program Files\Common Files\cdarbsvc
2021-04-21 19:07 - 2021-04-21 19:07 - 000000000 ____D C:\Program Files (x86)\MakeMKV
2021-04-21 19:06 - 2021-04-21 19:06 - 014233787 _____ (GuinpinSoft inc) C:\Users\Lem0th\Downloads\Setup_MakeMKV_v1.16.3.exe
2021-04-21 19:00 - 2021-04-21 19:00 - 000000000 ____D C:\WINDOWS\system32\Tasks\AnyMP4 Studio
2021-04-21 19:00 - 2021-04-21 19:00 - 000000000 ____D C:\Users\Lem0th\AppData\Local\AnyMP4 Studio
2021-04-21 18:59 - 2021-04-21 18:59 - 001933496 _____ ( ) C:\Users\Lem0th\Downloads\screen-recorder.exe
2021-04-21 18:58 - 2021-04-22 11:28 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\DVDFab
2021-04-21 18:58 - 2021-04-21 18:58 - 000000000 ____D C:\Users\Lem0th\Downloads\DVDFab
2021-04-21 18:58 - 2021-04-21 18:58 - 000000000 ____D C:\Program Files\DVDFab
2021-04-21 18:57 - 2021-04-21 18:57 - 006131784 _____ (DVDFab 12) C:\Users\Lem0th\Downloads\dvdfab12_online_12026_64021c03.exe
2021-04-21 18:57 - 2021-04-21 18:57 - 000000000 ____D C:\Users\Lem0th\Documents\DVDFab
2021-04-20 16:00 - 2021-04-20 16:00 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2021-04-19 17:04 - 2021-04-21 16:01 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-04-18 21:09 - 2021-04-18 21:09 - 003038248 _____ (crosire) C:\Users\Lem0th\Downloads\ReShade_Setup_4.9.1.exe
2021-04-18 12:34 - 2021-04-18 19:36 - 000000000 ____D C:\Users\Lem0th\Downloads\takeout-20210417T205906Z-001
2021-04-18 12:08 - 2021-04-18 12:34 - 001520203 _____ C:\Users\Lem0th\Downloads\takeout-20210417T205906Z-002.zip
2021-04-18 12:08 - 2021-04-18 12:17 - 1132857394 _____ C:\Users\Lem0th\Downloads\takeout-20210417T205906Z-003.zip
2021-04-18 12:07 - 2021-04-18 12:33 - 4282062453 _____ C:\Users\Lem0th\Downloads\takeout-20210417T205906Z-001.zip
2021-04-17 23:17 - 2021-04-17 23:17 - 000000000 ____D C:\Users\Lem0th\AppData\LocalLow\SKS
2021-04-17 21:09 - 2021-04-18 18:53 - 000693180 _____ C:\Users\Lem0th\AppData\Roaming\GlobalStrDataWithoutExif.txt
2021-04-17 20:39 - 2021-04-17 20:39 - 000000113 _____ C:\Users\Lem0th\Desktop\remove files with 120x120 pixels.txt
2021-04-17 18:38 - 2021-04-18 18:53 - 000537074 _____ C:\Users\Lem0th\AppData\Roaming\GlobalStrDataWithExif.txt
2021-04-17 18:38 - 2021-04-18 18:53 - 000537074 _____ C:\Users\Lem0th\AppData\Roaming\GlobalStrData.txt
2021-04-17 16:47 - 2021-04-17 16:47 - 000000733 _____ C:\Users\Lem0th\Downloads\Downloads - Shortcut.lnk
2021-04-17 15:06 - 2021-04-17 15:06 - 000231542 _____ C:\Users\Lem0th\Downloads\überweisung.pdf
2021-04-17 10:01 - 2021-04-17 10:12 - 000000000 ____D C:\nextcloudnew
2021-04-16 19:35 - 2021-04-25 17:41 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-04-16 17:37 - 2021-04-16 17:37 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\by Mike Baker at Rediscovering Photography
2021-04-16 17:36 - 2021-04-18 18:53 - 000000574 _____ C:\Users\Lem0th\AppData\Roaming\ExtensionCount.csv
2021-04-16 17:34 - 2021-04-18 18:53 - 000000147 _____ C:\Users\Lem0th\AppData\Roaming\PhotoMoveOutput.txt
2021-04-16 17:32 - 2021-04-16 17:42 - 000000000 ____D C:\sort
2021-04-16 17:31 - 2021-04-16 17:31 - 000000000 ____D C:\Users\Lem0th\AppData\Local\by_Mike_Baker_at_Rediscov
2021-04-16 17:31 - 2021-04-16 17:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoMove 2
2021-04-16 17:31 - 2021-04-16 17:31 - 000000000 ____D C:\Program Files (x86)\PhotoMove 2
2021-04-16 17:29 - 2021-04-25 09:32 - 000000000 ___SD C:\Users\Lem0th\Nextcloud
2021-04-16 17:28 - 2021-04-25 02:44 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\Nextcloud
2021-04-16 17:28 - 2021-04-16 17:29 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Nextcloud
2021-04-16 17:28 - 2021-04-16 17:28 - 000001924 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nextcloud.lnk
2021-04-16 17:28 - 2021-04-16 17:28 - 000001912 _____ C:\Users\Public\Desktop\Nextcloud.lnk
2021-04-16 17:28 - 2021-04-16 17:28 - 000001912 _____ C:\ProgramData\Desktop\Nextcloud.lnk
2021-04-16 17:28 - 2021-04-16 17:28 - 000000000 ____D C:\Program Files\Nextcloud
2021-04-16 17:26 - 2021-04-16 17:26 - 007492830 _____ (Mike Baker @ Rediscovering Photography ) C:\Users\Lem0th\Downloads\PhotoMoveSetup.exe
2021-04-16 17:16 - 2021-04-16 17:16 - 088702976 _____ C:\Users\Lem0th\Downloads\Nextcloud-3.2.0-x64.msi
2021-04-16 17:00 - 2021-04-16 17:00 - 000000000 ____D C:\Users\Lem0th\Documents\mk_twindexx_445_1_04_09
2021-04-16 16:44 - 2021-04-16 16:44 - 000000000 ____D C:\Users\Lem0th\Downloads\Twindexx_Repaint_Vorlagen_Triebwagen_dabpbzfa+dabpzfa_21_04_03
2021-04-16 16:42 - 2021-04-16 16:42 - 000000000 ____D C:\Users\Lem0th\Downloads\Twindexx_Repaint_Vorlagen_Hocheinstieg_Mittelwagen_21_04_03(1)
2021-04-16 16:41 - 2021-04-16 16:41 - 081812262 _____ C:\Users\Lem0th\Downloads\Twindexx_Repaint_Vorlagen_Triebwagen_dabpbzfa+dabpzfa_21_04_03.zip
2021-04-16 16:41 - 2021-04-16 16:41 - 037942846 _____ C:\Users\Lem0th\Downloads\Twindexx_Repaint_Vorlagen_Hocheinstieg_Mittelwagen_21_04_03(1).zip
2021-04-16 16:39 - 2021-04-16 16:39 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-04-16 16:38 - 2021-04-16 16:38 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-04-16 16:38 - 2021-04-16 16:38 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-04-16 15:26 - 2021-04-16 15:26 - 000004488 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled assistant Autoupdate 1618579602
2021-04-15 20:56 - 2021-04-15 20:56 - 000162336 _____ C:\Users\Lem0th\Downloads\EPSON002.pdf
2021-04-15 20:29 - 2021-04-15 20:30 - 185762015 _____ C:\Users\Lem0th\Downloads\modwerkstatt_mwagen_1.zip
2021-04-15 15:59 - 2021-04-15 15:59 - 000000000 ____D C:\Users\Lem0th\AppData\LocalLow\DefaultCompany
2021-04-14 19:31 - 2021-04-20 16:04 - 000004226 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1618421482
2021-04-14 19:31 - 2021-04-20 16:04 - 000001441 _____ C:\Users\Lem0th\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera GX Browser .lnk
2021-04-14 19:31 - 2021-04-14 19:31 - 000001445 _____ C:\Users\Lem0th\Desktop\Opera GX Browser .lnk
2021-04-14 19:30 - 2021-04-14 19:30 - 003749584 _____ (Opera Software) C:\Users\Lem0th\Downloads\OperaGXSetup.exe
2021-04-11 21:41 - 2021-04-11 21:41 - 000000000 ____D C:\Users\Lem0th\Downloads\Twindexx_Repaint_Vorlagen_Hocheinstieg_Mittelwagen_21_04_03
2021-04-11 02:31 - 2021-04-11 02:31 - 037942846 _____ C:\Users\Lem0th\Downloads\Twindexx_Repaint_Vorlagen_Hocheinstieg_Mittelwagen_21_04_03.zip
2021-04-11 02:24 - 2021-04-11 02:24 - 000947379 _____ C:\Users\Lem0th\Downloads\compressjpeg(1).zip
2021-04-11 02:22 - 2021-04-11 02:22 - 001054111 _____ C:\Users\Lem0th\Downloads\compressjpeg.zip
2021-04-10 20:31 - 2020-11-11 03:54 - 000167280 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2021-04-10 20:30 - 2020-11-11 03:54 - 000159600 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudbus2.sys
2021-04-10 20:26 - 2021-04-10 20:26 - 000000000 ____D C:\Users\Lem0th\.cache
2021-04-10 20:26 - 2021-04-10 15:24 - 268842274 _____ C:\Users\Lem0th\Downloads\DAS DEUTSCHE SCHLAGER HIT ALBUM 2021..DJ.R.R.S.mp4
2021-04-10 20:22 - 2021-04-10 20:22 - 008166801 _____ C:\Users\Lem0th\Downloads\youtube-dl.exe
2021-04-10 02:12 - 2021-04-10 02:12 - 000011168 _____ C:\Users\Lem0th\Documents\stdout.txt
2021-04-09 20:32 - 2021-04-09 20:32 - 000000000 ____D C:\Users\Lem0th\Downloads\Aloy Explicit Outfits-53-1-6-1615533351
2021-04-09 14:09 - 2021-04-09 14:09 - 000457185 _____ C:\Users\Lem0th\Downloads\FLT_2_KGL3ES16128_0.pdf
2021-04-09 03:18 - 2021-04-09 20:48 - 000000000 ____D C:\Users\Lem0th\Documents\Horizon Zero Dawn
2021-04-09 03:18 - 2021-04-09 03:20 - 149226206 _____ C:\Users\Lem0th\Downloads\Aloy Explicit Outfits-53-1-6-1615533351.7z
2021-04-09 00:02 - 2021-04-09 00:02 - 000457287 _____ C:\Users\Lem0th\Downloads\FLT_4_M4Z81D5246_0.pdf
2021-04-08 00:15 - 2021-04-08 00:23 - 1350631094 _____ C:\Users\Lem0th\Downloads\sc3015-NFSU2M13ELA.rar
2021-04-07 22:04 - 2021-04-07 22:05 - 026724770 _____ (The qBittorrent project) C:\Users\Lem0th\Downloads\qbittorrent_4.3.4.1_x64_setup.exe
2021-04-07 21:45 - 2021-04-07 21:55 - 1595082050 _____ C:\Users\Lem0th\Downloads\ISO.zip
2021-04-05 18:45 - 2021-04-05 18:45 - 006118306 _____ C:\Users\Lem0th\Downloads\CryENB V3.7z
2021-04-05 18:45 - 2021-04-05 18:45 - 000000000 ____D C:\Users\Lem0th\Documents\MEGAsync Downloads
2021-04-05 14:41 - 2021-04-05 14:41 - 000000000 ____D C:\Users\Lem0th\AppData\Local\ASUS
2021-04-05 14:39 - 2021-04-25 15:14 - 000000000 ____D C:\Users\Lem0th\AppData\Local\AcSdkInsLog
2021-04-05 14:39 - 2021-04-05 14:39 - 000000000 ____D C:\Program Files\PHISON
2021-04-05 14:39 - 2021-04-05 14:39 - 000000000 ____D C:\Program Files\PD
2021-04-05 14:39 - 2021-04-05 14:39 - 000000000 ____D C:\Program Files\Patriot
2021-04-05 14:39 - 2021-02-02 15:56 - 000151608 _____ (©ASUSTeK Computer Inc.) C:\WINDOWS\system32\AsIO3.dll
2021-04-05 14:39 - 2021-02-02 15:56 - 000123744 _____ (©ASUSTeK Computer Inc.) C:\WINDOWS\SysWOW64\AsIO3.dll
2021-04-05 14:39 - 2020-12-16 14:46 - 000043920 _____ C:\WINDOWS\system32\Drivers\AsIO3.sys
2021-04-05 14:39 - 2020-01-19 19:49 - 000017424 _____ (MICSYS Technology Co., LTd) C:\WINDOWS\system32\Drivers\MsIo64.sys
2021-04-05 14:39 - 2020-01-19 19:49 - 000017424 _____ (MICSYS Technology Co., LTd) C:\WINDOWS\system32\Drivers\MsIo64.old
2021-04-05 00:20 - 2021-04-23 16:25 - 000002355 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge Beta.lnk
2021-04-05 00:17 - 2021-04-25 15:14 - 000000000 ____D C:\WINDOWS\system32\Tasks\ASUS
2021-04-05 00:13 - 2021-04-05 00:13 - 001348212 _____ C:\Users\Lem0th\Downloads\SetupROGLSLService.zip
2021-04-04 18:03 - 2021-04-04 18:03 - 081056014 _____ C:\Users\Lem0th\Downloads\volvofhcmi_20.12.20_Ty.zip
2021-04-04 17:00 - 2021-04-04 17:00 - 000000000 ____D C:\ProgramData\UNITE Team
2021-04-04 14:42 - 2021-04-04 14:43 - 064221968 _____ (Steganos Software GmbH) C:\Users\Lem0th\Downloads\sss21lmv2.exe
2021-04-03 13:59 - 2021-04-03 13:59 - 006891571 _____ C:\Users\Lem0th\Downloads\eis_os_commonapi2_1_20210310-dev(1).zip
2021-04-03 00:02 - 2021-04-03 18:13 - 000000000 ____D C:\Users\Lem0th\Documents\Need For Speed
2021-04-03 00:01 - 2021-04-03 00:01 - 000667460 _____ C:\Users\Lem0th\Downloads\R34 LED v2-16-1-0-1549247967.rar
2021-04-02 23:47 - 2021-04-02 23:51 - 1617651254 _____ (UNITE Team) C:\Users\Lem0th\Downloads\PROJECT UNITE 2015 Installer (1.2.3).exe
2021-04-02 23:43 - 2021-04-03 17:43 - 000000000 ____D C:\Users\Lem0th\Downloads\FrostyModManager_v1.0.5.9
2021-04-02 23:42 - 2021-04-02 23:42 - 032196225 _____ C:\Users\Lem0th\Downloads\FrostyModManager_v1.0.5.9.rar
2021-04-02 23:38 - 2021-04-02 23:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need for Speed™
2021-04-02 22:15 - 2021-04-02 22:16 - 000000000 ____D C:\Users\Lem0th\Downloads\promods-v252
2021-04-02 19:44 - 2021-03-26 11:14 - 001730864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6446589.dll
2021-04-02 19:44 - 2021-03-26 11:14 - 001490224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6446589.dll
2021-04-02 17:44 - 2021-04-02 18:01 - 520031423 _____ C:\Users\Lem0th\Downloads\Microsoft Windows 98 First Edition.7z
2021-04-02 17:18 - 2021-04-02 17:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2021-04-02 17:15 - 2021-04-02 17:16 - 128980992 _____ C:\Users\Lem0th\Downloads\archiveteam-warrior-v3.2-20210306.ova
2021-04-02 17:15 - 2021-04-02 17:16 - 108257728 _____ (Oracle Corporation) C:\Users\Lem0th\Downloads\VirtualBox-6.1.18-142142-Win.exe
2021-03-28 15:58 - 2021-03-28 15:58 - 000000000 ____D C:\Program Files (x86)\ENE
2021-03-28 15:57 - 2021-03-28 15:57 - 003657432 _____ C:\Users\Lem0th\Downloads\G.SKILL-Trident-Z-Lighting-Control-v1.00.22.zip
2021-03-28 15:51 - 2021-03-28 15:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Corsair
2021-03-27 10:34 - 2021-04-16 17:58 - 000000000 ___RD C:\Users\Lem0th\Documents\MEGAsync
2021-03-27 10:33 - 2021-03-27 10:34 - 000000022 _____ C:\Users\Lem0th\Downloads\MEGA-RECOVERYKEY.txt
2021-03-27 10:31 - 2021-03-27 10:31 - 034856824 _____ (MEGA Limited) C:\Users\Lem0th\Downloads\MEGAsyncSetup64.exe
2021-03-27 10:31 - 2021-03-27 10:31 - 000000000 ____D C:\WINDOWS\system32\Tasks\MEGA
2021-03-27 10:31 - 2021-03-27 10:31 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync
2021-03-27 10:31 - 2021-03-27 10:31 - 000000000 ____D C:\Users\Lem0th\AppData\Local\MEGAsync
2021-03-27 10:31 - 2021-03-27 10:31 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Mega Limited
2021-03-26 20:26 - 2021-03-26 20:27 - 015616404 _____ C:\Users\Lem0th\Downloads\promods-v252.7z.008
2021-03-26 20:11 - 2021-03-26 20:25 - 262144000 _____ C:\Users\Lem0th\Downloads\promods-v252.7z.006
2021-03-26 20:10 - 2021-03-26 20:24 - 262144000 _____ C:\Users\Lem0th\Downloads\promods-v252.7z.007
2021-03-26 19:48 - 2021-03-26 20:03 - 262144000 _____ C:\Users\Lem0th\Downloads\promods-v252.7z.005
2021-03-26 19:48 - 2021-03-26 20:03 - 262144000 _____ C:\Users\Lem0th\Downloads\promods-v252.7z.004
2021-03-26 19:11 - 2021-03-26 19:27 - 262144000 _____ C:\Users\Lem0th\Downloads\promods-v252.7z.003
2021-03-26 18:56 - 2021-03-26 19:12 - 262144000 _____ C:\Users\Lem0th\Downloads\promods-v252.7z.002
2021-03-26 18:56 - 2021-03-26 19:11 - 262144000 _____ C:\Users\Lem0th\Downloads\promods-v252.7z.001
2021-03-26 18:55 - 2021-03-26 18:55 - 003419427 _____ C:\Users\Lem0th\Downloads\promods-def-st-v252.scs
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-04-25 18:22 - 2019-08-03 13:37 - 000000000 ____D C:\Users\Lem0th\AppData\Local\CrashDumps
2021-04-25 18:22 - 2019-04-11 22:29 - 000000000 ____D C:\ProgramData\Mozilla
2021-04-25 18:21 - 2019-08-03 12:35 - 000000000 ____D C:\Users\Lem0th\AppData\LocalLow\Mozilla
2021-04-25 18:21 - 2019-05-04 15:34 - 000000000 ____D C:\ProgramData\NVIDIA
2021-04-25 18:20 - 2020-08-05 20:03 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-04-25 18:20 - 2020-06-08 07:59 - 000008192 ___SH C:\DumpStack.log.tmp
2021-04-25 18:20 - 2020-06-02 16:02 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-04-25 18:20 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-04-25 18:20 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-04-25 18:20 - 2019-04-12 04:10 - 001136008 _____ C:\WINDOWS\system32\wpbbin.exe
2021-04-25 18:20 - 2019-04-12 04:10 - 001097976 _____ C:\WINDOWS\system32\AsusUpdateCheck.exe
2021-04-25 18:15 - 2020-06-02 16:06 - 001722792 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-04-25 18:15 - 2019-12-07 16:51 - 000743714 _____ C:\WINDOWS\system32\perfh007.dat
2021-04-25 18:15 - 2019-12-07 16:51 - 000150136 _____ C:\WINDOWS\system32\perfc007.dat
2021-04-25 18:15 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2021-04-25 18:14 - 2019-09-03 16:27 - 000000000 ____D C:\Users\Lem0th\AppData\LocalLow\Temp
2021-04-25 18:11 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2021-04-25 18:11 - 2019-08-03 12:37 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\Discord
2021-04-25 18:11 - 2018-09-15 09:33 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2021-04-25 18:09 - 2019-08-03 12:37 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Discord
2021-04-25 18:08 - 2019-08-03 12:28 - 000000000 ____D C:\Users\Lem0th\AppData\Local\NVIDIA
2021-04-25 18:07 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-04-25 18:07 - 2019-04-11 22:33 - 000000000 ____D C:\Program Files (x86)\Steam
2021-04-25 18:06 - 2019-08-03 12:35 - 000000000 ____D C:\Users\Lem0th\Documents\Euro Truck Simulator 2
2021-04-25 16:59 - 2020-06-02 16:02 - 000004308 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-25 16:59 - 2020-06-02 16:02 - 000004106 _____ C:\WINDOWS\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-25 16:59 - 2020-06-02 16:02 - 000003976 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-25 16:59 - 2020-06-02 16:02 - 000003940 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-25 16:59 - 2020-06-02 16:02 - 000003894 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-25 16:59 - 2020-06-02 16:02 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-25 16:59 - 2020-06-02 16:02 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-25 16:59 - 2020-06-02 16:02 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-25 16:59 - 2020-06-02 16:02 - 000003858 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-25 16:59 - 2020-06-02 16:02 - 000003654 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2021-04-25 16:59 - 2019-04-11 22:30 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2021-04-25 16:59 - 2019-04-11 22:30 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2021-04-25 16:59 - 2019-04-11 22:30 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2021-04-25 16:45 - 2019-09-02 17:14 - 000000000 ____D C:\Users\Lem0th\Documents\GTA San Andreas User Files
2021-04-25 16:37 - 2019-08-03 13:37 - 000000000 ____D C:\Users\Lem0th\AppData\Local\modloader
2021-04-25 16:37 - 2019-06-02 03:24 - 000000000 ____D C:\ProgramData\modloader
2021-04-25 15:41 - 2019-08-14 22:33 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2021-04-25 15:15 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-04-25 15:15 - 2019-04-11 22:22 - 000000000 ____D C:\Program Files (x86)\ASUS
2021-04-25 15:14 - 2019-04-12 04:17 - 000000000 __RHD C:\Users\Public\AccountPictures
2021-04-25 15:14 - 2019-04-12 04:10 - 000000000 ____D C:\ProgramData\ASUS
2021-04-25 15:14 - 2019-04-12 02:37 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2021-04-25 15:14 - 2019-04-12 02:37 - 000000000 ____D C:\ProgramData\Package Cache
2021-04-25 15:14 - 2019-04-12 02:37 - 000000000 ____D C:\Program Files\ASUS
2021-04-25 01:22 - 2020-06-02 15:56 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-04-24 21:25 - 2020-06-02 17:04 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2021-04-24 21:25 - 2019-12-12 18:02 - 000236472 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2021-04-24 21:25 - 2019-11-13 20:51 - 000038328 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamemodcontrol.exe
2021-04-24 21:25 - 2019-08-08 18:05 - 001695184 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2021-04-24 21:25 - 2019-08-08 18:05 - 000176592 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2021-04-24 21:25 - 2019-08-08 18:05 - 000159672 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2021-04-24 21:18 - 2021-01-16 12:27 - 000399872 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2021-04-24 21:18 - 2019-12-07 11:09 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxinit.dll
2021-04-24 11:38 - 2019-04-15 19:10 - 000001104 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++.lnk
2021-04-24 11:37 - 2019-04-15 19:09 - 000000000 ____D C:\Program Files (x86)\Notepad++
2021-04-24 11:14 - 2020-01-29 18:17 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-04-23 17:13 - 2019-08-03 12:33 - 000000000 ____D C:\Users\Lem0th\Documents\my games
2021-04-23 16:27 - 2021-02-22 17:33 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-04-22 14:10 - 2019-12-24 01:29 - 000000000 ____D C:\Users\Lem0th\.VirtualBox
2021-04-22 14:09 - 2020-06-02 15:58 - 000000000 ____D C:\Users\Lem0th
2021-04-22 13:26 - 2019-05-11 10:56 - 000000000 ____D C:\ProgramData\VirtualBox
2021-04-22 09:16 - 2021-02-26 16:39 - 000000000 ____D C:\WINDOWS\Panther
2021-04-22 09:16 - 2019-11-17 13:10 - 000000000 ____D C:\ESD
2021-04-21 22:59 - 2019-10-20 14:51 - 000000000 ____D C:\Program Files\VideoLAN
2021-04-21 18:58 - 2019-05-04 14:57 - 000000000 ____D C:\ProgramData\boost_interprocess
2021-04-21 16:01 - 2019-04-11 22:30 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-04-20 21:20 - 2019-10-27 11:46 - 000002293 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-04-20 21:09 - 2020-06-02 16:02 - 000003418 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-04-20 21:09 - 2020-06-02 16:02 - 000003294 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-04-20 16:00 - 2019-04-11 22:30 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-04-19 17:20 - 2019-08-03 12:39 - 000000000 ____D C:\Users\Lem0th\AppData\Local\D3DSCache
2021-04-19 13:26 - 2021-01-23 17:40 - 000000000 ____D C:\Users\Lem0th\Documents\MAXON
2021-04-19 13:02 - 2020-02-16 00:42 - 000000000 ____D C:\Users\Lem0th\Documents\GTA Vice City User Files
2021-04-19 05:02 - 2020-06-02 15:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2021-04-19 05:02 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2021-04-19 05:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-04-19 05:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-04-17 21:16 - 2019-04-19 03:03 - 000000000 ____D C:\ProgramData\TruckersMP
2021-04-17 16:16 - 2019-08-24 11:55 - 000000000 ____D C:\Users\Lem0th\AppData\Local\ElevatedDiagnostics
2021-04-17 13:17 - 2019-08-03 12:29 - 000000000 ____D C:\Users\Lem0th\AppData\Local\PlaceholderTileLogoFolder
2021-04-17 13:17 - 2019-08-03 12:28 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Packages
2021-04-16 21:17 - 2021-03-01 23:10 - 000000000 ____D C:\Users\Lem0th\AppData\Local\RuneLite
2021-04-16 21:17 - 2019-11-14 18:03 - 000000045 _____ C:\Users\Lem0th\jagex_cl_oldschool_LIVE.dat
2021-04-16 16:40 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-04-16 16:34 - 2019-04-11 22:31 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-04-16 16:32 - 2019-04-11 22:31 - 131963968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-04-14 19:31 - 2020-04-26 17:27 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Opera Software
2021-04-14 19:30 - 2020-04-26 17:27 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\Opera Software
2021-04-13 16:20 - 2020-06-02 16:02 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-04-13 16:20 - 2020-06-02 16:02 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-04-13 11:21 - 2020-12-02 18:13 - 000656152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2021-04-13 11:17 - 2020-12-02 18:13 - 007212248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2021-04-13 11:17 - 2020-12-02 18:13 - 006159176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2021-04-13 01:48 - 2020-12-02 18:13 - 000063943 _____ C:\WINDOWS\system32\nvinfo.pb
2021-04-12 21:48 - 2020-12-02 18:15 - 005666672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2021-04-12 21:48 - 2020-12-02 18:15 - 002636656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2021-04-12 21:48 - 2020-12-02 18:15 - 001758064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2021-04-12 21:48 - 2020-12-02 18:15 - 000990064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2021-04-12 21:48 - 2020-12-02 18:15 - 000120176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2021-04-12 21:48 - 2020-12-02 18:15 - 000082288 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2021-04-12 21:20 - 2019-08-04 18:43 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Ubisoft Game Launcher
2021-04-11 16:50 - 2019-04-18 22:56 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2021-04-11 16:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-04-11 02:52 - 2019-04-12 04:10 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-04-11 00:46 - 2021-02-07 00:52 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-04-08 20:08 - 2020-03-02 22:17 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Battle.net
2021-04-08 03:54 - 2020-06-02 15:56 - 000640712 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-04-08 03:53 - 2019-12-07 16:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-04-08 03:53 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-04-08 03:53 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-04-08 03:53 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-04-08 03:53 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-04-08 03:53 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-04-08 03:53 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-04-08 03:53 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-04-08 03:53 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-04-08 03:53 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-04-07 23:24 - 2021-02-05 17:28 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\qBittorrent
2021-04-07 17:41 - 2020-12-02 18:15 - 009527077 _____ C:\WINDOWS\system32\nvcoproc.bin
2021-04-07 15:57 - 2020-06-02 15:56 - 002877440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2021-04-07 15:08 - 2019-04-12 02:37 - 000000000 ____D C:\Program Files\ENE
2021-04-07 13:38 - 2019-05-06 19:27 - 002817904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2021-04-07 13:38 - 2019-05-06 19:27 - 002171760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2021-04-07 13:38 - 2019-05-06 19:27 - 001293680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvRtmpStreamer64.dll
2021-04-05 15:27 - 2019-04-12 02:37 - 000000000 ____D C:\Program Files (x86)\LightingService
2021-04-05 15:21 - 2019-04-12 02:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2021-04-05 14:42 - 2019-04-11 22:33 - 000000000 ____D C:\ProgramData\Packages
2021-04-05 00:09 - 2019-11-28 17:28 - 000000000 ____D C:\Program Files (x86)\Corsair
2021-04-03 15:55 - 2020-12-06 13:23 - 000000000 ____D C:\Users\Lem0th\AppData\Roaming\Origin
2021-04-02 23:12 - 2021-01-25 21:03 - 000000000 ____D C:\Program Files (x86)\Origin Games
2021-04-02 23:12 - 2020-03-28 17:54 - 000000000 ____D C:\ProgramData\Origin
2021-04-02 23:09 - 2020-12-06 13:24 - 000000000 ____D C:\Program Files (x86)\Origin
2021-04-02 23:09 - 2020-12-06 13:23 - 000000000 ____D C:\Users\Lem0th\AppData\Local\Origin
2021-04-02 19:45 - 2020-06-02 15:36 - 000000000 ___SD C:\WINDOWS\system32\lxss
2021-03-30 15:42 - 2019-05-08 20:00 - 000000000 ____D C:\Program Files (x86)\GOG Galaxy
2021-03-30 12:57 - 2020-12-12 12:59 - 000074608 _____ C:\WINDOWS\system32\FvSDK_x64.dll
2021-03-30 12:57 - 2020-12-12 12:59 - 000064880 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
2021-03-28 15:58 - 2019-11-05 18:16 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2021-03-27 19:40 - 2019-04-14 21:58 - 000000000 ____D C:\Program Files\Rockstar Games
2021-03-27 19:40 - 2019-04-14 21:58 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
==================== Files in the root of some directories ========
2019-11-20 21:31 - 2021-01-29 23:28 - 645563019 _____ () C:\Users\Lem0th\AppData\Roaming\.minecraft.7z
2021-04-16 17:36 - 2021-04-18 18:53 - 000000574 _____ () C:\Users\Lem0th\AppData\Roaming\ExtensionCount.csv
2021-04-17 18:38 - 2021-04-18 18:53 - 000537074 _____ () C:\Users\Lem0th\AppData\Roaming\GlobalStrData.txt
2021-04-17 18:38 - 2021-04-18 18:53 - 000537074 _____ () C:\Users\Lem0th\AppData\Roaming\GlobalStrDataWithExif.txt
2021-04-17 21:09 - 2021-04-18 18:53 - 000693180 _____ () C:\Users\Lem0th\AppData\Roaming\GlobalStrDataWithoutExif.txt
2021-04-16 17:34 - 2021-04-18 18:53 - 000000147 _____ () C:\Users\Lem0th\AppData\Roaming\PhotoMoveOutput.txt
2020-04-04 13:35 - 2020-05-10 15:33 - 000000128 _____ () C:\Users\Lem0th\AppData\Roaming\PUTTY.RND
2020-10-22 17:32 - 2021-01-08 19:37 - 000000128 _____ () C:\Users\Lem0th\AppData\Roaming\winscp.rnd
2020-11-22 14:33 - 2020-11-22 14:50 - 001065984 _____ () C:\Users\Lem0th\AppData\Local\file__0.localstorage
2019-08-20 16:02 - 2021-03-13 18:09 - 000000205 _____ () C:\Users\Lem0th\AppData\Local\oobelibMkey.log
2020-04-16 20:24 - 2020-04-16 20:24 - 000000529 _____ () C:\Users\Lem0th\AppData\Local\Perfmon.PerfmonCfg
2020-02-07 17:40 - 2021-01-16 14:19 - 000000128 _____ () C:\Users\Lem0th\AppData\Local\PUTTY.RND
2021-02-07 15:48 - 2021-02-07 15:48 - 000000867 _____ () C:\Users\Lem0th\AppData\Local\recently-used.xbel
2019-10-12 15:03 - 2019-10-12 15:03 - 000007602 _____ () C:\Users\Lem0th\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ======================== --- --- --- Code:
Fix result of Farbar Recovery Scan Tool (x64) Version: 17-04-2021
Ran by Lem0th (25-04-2021 18:11:37) Run:1
Running from C:\Users\Lem0th\Desktop
Loaded Profiles: Lem0th
Boot Mode: Normal
==============================================
fixlist content:
*****************
CloseProcesses:
AppInit_DLLs: prio.dll => No File
Startup: C:\Users\Lem0th\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Folding@home.lnk [2020-03-15]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Task: {025189bb-e04b-4b4f-a102-009d1404148c} - no filepath
Task: {1007b121-f089-480e-90c7-57a8faa3c84f} - no filepath
Task: {23fbd644-894a-4474-a2b3-26241f331b82} - no filepath
Task: {245d09ce-4e9d-4fa2-8e67-cfb4f6511aac} - no filepath
Task: {301f8965-e4ae-4744-8a4b-33192acbb51d} - no filepath
Task: {363e780d-5be2-4194-875f-76ee4e5a6c79} - no filepath
Task: {3bb71775-0cb4-4539-b605-135d5ee03325} - no filepath
Task: {5730c70a-6ec2-44c0-b62c-ff188d990c6d} - no filepath
Task: {5ce387bf-dc0a-4cbb-b7f4-4dd795458def} - no filepath
Task: {6b898014-fd4a-4d4c-a5a3-b29773767e03} - no filepath
Task: {6ff8856b-af2c-4c24-9d7d-3031a3348ede} - no filepath
Task: {738695d2-4931-470f-b610-182cb72dd1c3} - no filepath
Task: {75902e42-c239-4c44-9134-8ae45933e238} - no filepath
Task: {8d4de376-48e2-4c9e-8fe3-14a0550de8c7} - no filepath
Task: {8fad8e1e-46b0-4443-8930-e631802435b8} - no filepath
Task: {aaaa1e8c-715b-4fcc-9159-e4608715675f} - no filepath
Task: {b3928b7b-3bb2-4fec-a52f-260c733e17b0} - no filepath
Task: {b3cec726-1abf-4308-b869-1d0a1e523858} - no filepath
Task: {d978b4b9-45d7-4183-9f25-00e0d2630123} - no filepath
Task: {e9c83afe-6b4d-4919-8a2a-cf14ee9e693c} - no filepath
Task: {ecac6b6e-a228-4f90-a467-260e334dc475} - no filepath
Task: {f0c223f9-6302-4d9f-a79a-4ed32ab5e219} - no filepath
Task: {fc7448f3-8afa-4b55-ba65-02e8cc565765} - no filepath
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
CMD: type "C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\prefs.js"
C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\prefs.js
FF Extension: (Honey) - C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\Extensions\jid1-93CWPmRbVPjRQA@jetpack.xpi [2020-10-28]
S3 ALSysIO; \??\C:\Users\Lem0th\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S1 SaferVPNNetfilter2; system32\drivers\SaferVPNNetfilter2.sys [X]
C:\Users\Lem0th\AppData\Roaming\prio.ini
C:\Users\Lem0th\AppData\Roaming\822f02e4-9e9a-4077-a765-71edfca16ad0
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
BHO: No Name -> {CA2FFF0C-1001-440D-9B9F-6ED7094288B7}' -> No File
BHO-x32: No Name -> {CA2FFF0C-1001-440D-9B9F-6ED7094288B7}' -> No File
CMD: ipconfig /flushdns
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: Bitsadmin /Reset /Allusers
powershell: Set-MpPreference -PUAProtection Enabled
powershell: Set-MpPreference -DisableScanningNetworkFiles 0
RemoveProxy:
SystemRestore: On
EmptyTemp:
*****************
Processes closed successfully.
"prio.dll" => Value data removed successfully
C:\Users\Lem0th\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Folding@home.lnk => moved successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
C:\ProgramData\NTUSER.pol => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{025189bb-e04b-4b4f-a102-009d1404148c}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1007b121-f089-480e-90c7-57a8faa3c84f}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{23fbd644-894a-4474-a2b3-26241f331b82}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{245d09ce-4e9d-4fa2-8e67-cfb4f6511aac}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{301f8965-e4ae-4744-8a4b-33192acbb51d}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{363e780d-5be2-4194-875f-76ee4e5a6c79}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3bb71775-0cb4-4539-b605-135d5ee03325}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5730c70a-6ec2-44c0-b62c-ff188d990c6d}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5ce387bf-dc0a-4cbb-b7f4-4dd795458def}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6b898014-fd4a-4d4c-a5a3-b29773767e03}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6ff8856b-af2c-4c24-9d7d-3031a3348ede}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{738695d2-4931-470f-b610-182cb72dd1c3}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75902e42-c239-4c44-9134-8ae45933e238}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8d4de376-48e2-4c9e-8fe3-14a0550de8c7}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8fad8e1e-46b0-4443-8930-e631802435b8}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{aaaa1e8c-715b-4fcc-9159-e4608715675f}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{b3928b7b-3bb2-4fec-a52f-260c733e17b0}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{b3cec726-1abf-4308-b869-1d0a1e523858}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d978b4b9-45d7-4183-9f25-00e0d2630123}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{e9c83afe-6b4d-4919-8a2a-cf14ee9e693c}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ecac6b6e-a228-4f90-a467-260e334dc475}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{f0c223f9-6302-4d9f-a79a-4ed32ab5e219}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{fc7448f3-8afa-4b55-ba65-02e8cc565765}" => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully
========= type "C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\prefs.js" =========
// Mozilla User Preferences
// DO NOT EDIT THIS FILE.
//
// If you make changes to this file while the application is running,
// the changes will be overwritten when the application exits.
//
// To change a preference value, you can either:
// - modify it via the UI (e.g. via about:config in the browser); or
// - set it within a user.js file in your profile.
user_pref("accessibility.typeaheadfind.flashBar", 0);
user_pref("app.normandy.first_run", false);
user_pref("app.normandy.migrationsApplied", 10);
user_pref("app.normandy.startupRolloutPrefs.app.normandy.onsync_skew_sec", 3300);
user_pref("app.normandy.startupRolloutPrefs.browser.migrate.showBookmarksToolbarAfterMigration", true);
user_pref("app.normandy.startupRolloutPrefs.browser.partnerlink.useAttributionURL", true);
user_pref("app.normandy.startupRolloutPrefs.browser.topsites.experiment.ebay-2020-1", true);
user_pref("app.normandy.startupRolloutPrefs.browser.topsites.useRemoteSetting", true);
user_pref("app.normandy.startupRolloutPrefs.extensions.formautofill.creditCards.available", true);
user_pref("app.normandy.startupRolloutPrefs.extensions.formautofill.creditCards.enabled", true);
user_pref("app.normandy.startupRolloutPrefs.extensions.formautofill.creditCards.hideui", false);
user_pref("app.normandy.startupRolloutPrefs.media.videocontrols.picture-in-picture.video-toggle.mode", 2);
user_pref("app.normandy.startupRolloutPrefs.pdfjs.renderInteractiveForms", true);
user_pref("app.normandy.startupRolloutPrefs.security.bad_cert_domain_error.url_fix_enabled", true);
user_pref("app.normandy.startupRolloutPrefs.security.remote_settings.intermediates.downloads_per_poll", 3000);
user_pref("app.normandy.user_id", "1c090834-6ba8-4d61-9435-8e559abec8aa");
user_pref("app.shield.optoutstudies.enabled", false);
user_pref("app.update.auto.migrated", true);
user_pref("app.update.download.attempts", 0);
user_pref("app.update.elevate.attempts", 0);
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 1619364439);
user_pref("app.update.lastUpdateTime.background-update-timer", 1619345604);
user_pref("app.update.lastUpdateTime.blocklist-background-update-timer", 1588690616);
user_pref("app.update.lastUpdateTime.browser-cleanup-thumbnails", 1619365012);
user_pref("app.update.lastUpdateTime.recipe-client-addon-run", 1619358052);
user_pref("app.update.lastUpdateTime.region-update-timer", 1619191488);
user_pref("app.update.lastUpdateTime.rs-experiment-loader-timer", 1608230489);
user_pref("app.update.lastUpdateTime.search-engine-update-timer", 1619357932);
user_pref("app.update.lastUpdateTime.services-settings-poll-changes", 1619359971);
user_pref("app.update.lastUpdateTime.telemetry_modules_ping", 1619208785);
user_pref("app.update.lastUpdateTime.telemetry_untrustedmodules_ping", 1619360092);
user_pref("app.update.lastUpdateTime.xpi-signature-verification", 1619364559);
user_pref("app.update.migrated.updateDir2.308046B0AF4A39CB", true);
user_pref("browser.bookmarks.defaultLocation", "unfiled");
user_pref("browser.bookmarks.editDialog.confirmationHintShowCount", 3);
user_pref("browser.bookmarks.restore_default_bookmarks", false);
user_pref("browser.cache.disk.amount_written", 1730818);
user_pref("browser.cache.disk.capacity", 1048576);
user_pref("browser.cache.disk.filesystem_reported", 1);
user_pref("browser.cache.disk.hashstats_reported", 1);
user_pref("browser.cache.disk.telemetry_report_ID", 525);
user_pref("browser.contentblocking.category", "custom");
user_pref("browser.contentblocking.cfr-milestone.milestone-achieved", 50000);
user_pref("browser.contentblocking.cfr-milestone.milestone-shown-time", "1614456572583");
user_pref("browser.contentblocking.introCount", 5);
user_pref("browser.download.lastDir", "C:\\Users\\Lem0th\\Desktop");
user_pref("browser.download.panel.shown", true);
user_pref("browser.download.save_converter_index", 0);
user_pref("browser.download.viewableInternally.typeWasRegistered.svg", true);
user_pref("browser.download.viewableInternally.typeWasRegistered.webp", true);
user_pref("browser.download.viewableInternally.typeWasRegistered.xml", true);
user_pref("browser.eme.ui.firstContentShown", true);
user_pref("browser.engagement.downloads-button.has-used", true);
user_pref("browser.engagement.fxa-toolbar-menu-button.has-used", true);
user_pref("browser.engagement.home-button.has-used", true);
user_pref("browser.engagement.library-button.has-used", true);
user_pref("browser.fixup.domainwhitelist.pi.hole", true);
user_pref("browser.laterrun.bookkeeping.profileCreationTime", 1564828533);
user_pref("browser.laterrun.bookkeeping.sessionCount", 42);
user_pref("browser.launcherProcess.enabled", true);
user_pref("browser.migration.version", 107);
user_pref("browser.newtab.url", "https://defaultsearch.co/homepage?hp=1&pId=AC191101&iDate=2020-05-09 10:03:19&bName=&bitmask=0600");
user_pref("browser.newtabpage.activity-stream.feeds.section.topstories.rec.impressions", "{\"50514\":1576509949641,\"50522\":1576509949641,\"50529\":1576526810929,\"50542\":1576509949641,\"50553\":1576521192832,\"50555\":1576522412673,\"50561\":1576529422983,\"50572\":1576594386344,\"50579\":1576594386344,\"50600\":1576594386344}");
user_pref("browser.newtabpage.activity-stream.impressionId", "{e6899aa6-c782-48d9-bf72-85d0bb12c506}");
user_pref("browser.newtabpage.pinned", "[]");
user_pref("browser.newtabpage.storageVersion", 1);
user_pref("browser.newtabpage.url", "https://defaultsearch.co/homepage?hp=1&pId=AC191101&iDate=2020-05-09 10:03:19&bName=&bitmask=0600");
user_pref("browser.pageActions.persistedActions", "{\"version\":1,\"ids\":[\"bookmark\",\"pinTab\",\"bookmarkSeparator\",\"copyURL\",\"emailLink\",\"addSearchEngine\",\"sendToDevice\",\"shareURL\",\"pocket\"],\"idsInUrlbar\":[\"pocket\",\"bookmark\"]}");
user_pref("browser.pagethumbnails.storage_version", 3);
user_pref("browser.protections_panel.infoMessage.seen", true);
user_pref("browser.region.update.updated", 1619191489);
user_pref("browser.rights.3.shown", true);
user_pref("browser.safebrowsing.provider.google4.lastupdatetime", "1619366974266");
user_pref("browser.safebrowsing.provider.google4.nextupdatetime", "1619368747266");
user_pref("browser.safebrowsing.provider.mozilla.lastupdatetime", "1619357787501");
user_pref("browser.safebrowsing.provider.mozilla.nextupdatetime", "1619379387501");
user_pref("browser.search.hiddenOneOffs", "DuckDuckGo");
user_pref("browser.search.region", "DE");
user_pref("browser.sessionstore.upgradeBackup.latestBuildID", "20210415204500");
user_pref("browser.shell.didSkipDefaultBrowserCheckOnFirstRun", true);
user_pref("browser.shell.mostRecentDateSetAsDefault", "1619366973");
user_pref("browser.slowStartup.averageTime", 1204);
user_pref("browser.slowStartup.samples", 1);
user_pref("browser.startup.homepage_override.buildID", "20210415204500");
user_pref("browser.startup.homepage_override.mstone", "88.0");
user_pref("browser.startup.lastColdStartupCheck", 1619366973);
user_pref("browser.toolbars.bookmarks.visibility", "never");
user_pref("browser.topsites.migratedToRemoteSetting.id", 1);
user_pref("browser.uiCustomization.state", "{\"placements\":{\"widget-overflow-fixed-list\":[],\"nav-bar\":[\"back-button\",\"forward-button\",\"stop-reload-button\",\"home-button\",\"customizableui-special-spring1\",\"urlbar-container\",\"customizableui-special-spring2\",\"downloads-button\",\"library-button\",\"sidebar-button\",\"fxa-toolbar-menu-button\",\"ublock0_raymondhill_net-browser-action\",\"_1c56fa07-34c5-4e5c-b765-89b79fe53e74_-browser-action\",\"_75afe46a-7a50-4c6b-b866-c43a1075b071_-browser-action\",\"user-agent-switcher_ninetailed_ninja-browser-action\",\"_f209234a-76f0-4735-9920-eb62507a54cd_-browser-action\",\"jid1-93cwpmrbvpjrqa_jetpack-browser-action\",\"https-everywhere_eff_org-browser-action\",\"firefox_tampermonkey_net-browser-action\",\"_446900e4-71c2-419f-a6a7-df9c091e268b_-browser-action\"],\"toolbar-menubar\":[\"menubar-items\"],\"TabsToolbar\":[\"tabbrowser-tabs\",\"new-tab-button\",\"alltabs-button\"],\"PersonalToolbar\":[\"personal-bookmarks\",\"managed-bookmarks\"]},\"seen\":[\"developer-button\",\"ublock0_raymondhill_net-browser-action\",\"_1c56fa07-34c5-4e5c-b765-89b79fe53e74_-browser-action\",\"_75afe46a-7a50-4c6b-b866-c43a1075b071_-browser-action\",\"user-agent-switcher_ninetailed_ninja-browser-action\",\"_f209234a-76f0-4735-9920-eb62507a54cd_-browser-action\",\"jid1-93cwpmrbvpjrqa_jetpack-browser-action\",\"https-everywhere_eff_org-browser-action\",\"firefox_tampermonkey_net-browser-action\",\"_446900e4-71c2-419f-a6a7-df9c091e268b_-browser-action\"],\"dirtyAreaCache\":[\"nav-bar\",\"toolbar-menubar\",\"TabsToolbar\",\"PersonalToolbar\"],\"currentVersion\":16,\"newElementCount\":3}");
user_pref("browser.urlbar.placeholderName", "Google");
user_pref("browser.urlbar.placeholderName.private", "Google");
user_pref("browser.urlbar.resultBuckets", "{\"children\":[{\"maxResultCount\":1,\"children\":[{\"group\":\"heuristicTest\"},{\"group\":\"heuristicExtension\"},{\"group\":\"heuristicSearchTip\"},{\"group\":\"heuristicOmnibox\"},{\"group\":\"heuristicUnifiedComplete\"},{\"group\":\"heuristicAutofill\"},{\"group\":\"heuristicTokenAliasEngine\"},{\"group\":\"heuristicFallback\"}]},{\"group\":\"extension\",\"maxResultCount\":5},{\"flexChildren\":true,\"children\":[{\"flexChildren\":true,\"children\":[{\"flex\":2,\"group\":\"formHistory\"},{\"flex\":4,\"group\":\"remoteSuggestion\"},{\"flex\":0,\"group\":\"tailSuggestion\"}],\"flex\":2},{\"group\":\"general\",\"flex\":1}]}]}");
user_pref("browser.urlbar.tabToSearch.onboard.interactionsLeft", 2);
user_pref("browser.urlbar.tipShownCount.searchTip_onboard", 4);
user_pref("browser.urlbar.tipShownCount.searchTip_redirect", 4);
user_pref("browser.urlbar.tipShownCount.tabToSearch", 60);
user_pref("datareporting.healthreport.uploadEnabled", false);
user_pref("datareporting.policy.dataSubmissionPolicyAcceptedVersion", 2);
user_pref("datareporting.policy.dataSubmissionPolicyNotifiedTime", "1564828539962");
user_pref("devtools.debugger.prefs-schema-version", 11);
user_pref("devtools.onboarding.telemetry.logged", true);
user_pref("devtools.responsive.html.displayedDeviceList", "{\"added\":[\"bingbot\"],\"removed\":[\"iPhone 6/7/8\",\"iPad\",\"Kindle Fire HDX\"]}");
user_pref("devtools.responsive.reloadNotification.enabled", false);
user_pref("devtools.toolsidebar-height.inspector", 350);
user_pref("devtools.toolsidebar-width.inspector", 700);
user_pref("devtools.toolsidebar-width.inspector.splitsidebar", 350);
user_pref("distribution.iniFile.exists.appversion", "88.0");
user_pref("distribution.iniFile.exists.value", false);
user_pref("doh-rollout.balrog-migration-done", true);
user_pref("doh-rollout.doneFirstRun", true);
user_pref("dom.push.userAgentID", "ea080b3f21194cfb96c774433e00c373");
user_pref("dom.security.https_only_mode", true);
user_pref("dom.security.https_only_mode_ever_enabled", true);
user_pref("extensions.activeThemeID", "firefox-compact-dark@mozilla.org");
user_pref("extensions.blocklist.lastModified", "Tue, 21 Jan 2020 16:26:51 GMT");
user_pref("extensions.blocklist.pingCountTotal", 173);
user_pref("extensions.blocklist.pingCountVersion", -1);
user_pref("extensions.databaseSchema", 33);
user_pref("extensions.fxmonitor.firstAlertShown", true);
user_pref("extensions.getAddons.cache.lastUpdate", 1619364440);
user_pref("extensions.getAddons.databaseSchema", 6);
user_pref("extensions.incognito.migrated", true);
user_pref("extensions.lastAppBuildId", "20210415204500");
user_pref("extensions.lastAppVersion", "88.0");
user_pref("extensions.lastPlatformVersion", "88.0");
user_pref("extensions.pendingOperations", false);
user_pref("extensions.pictureinpicture.enable_picture_in_picture_overrides", true);
user_pref("extensions.privatebrowsing.notification", true);
user_pref("extensions.reset_default_search.runonce.1", true);
user_pref("extensions.reset_default_search.runonce.3", false);
user_pref("extensions.systemAddonSet", "{\"schema\":1,\"addons\":{}}");
user_pref("extensions.ui.dictionary.hidden", false);
user_pref("extensions.ui.extension.hidden", false);
user_pref("extensions.ui.lastCategory", "addons://list/extension");
user_pref("extensions.ui.locale.hidden", false);
user_pref("extensions.webcompat.enable_picture_in_picture_overrides", true);
user_pref("extensions.webcompat.enable_shims", true);
user_pref("extensions.webcompat.perform_injections", true);
user_pref("extensions.webcompat.perform_ua_overrides", true);
user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.doh-rollout@mozilla.org", true);
user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.firefox@tampermonkey.net", true);
user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.jid1-93CWPmRbVPjRQA@jetpack", true);
user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.screenshots@mozilla.org", true);
user_pref("extensions.webextensions.ExtensionStorageIDB.migrated.uBlock0@raymondhill.net", true);
user_pref("extensions.webextensions.uuids", "{\"formautofill@mozilla.org\":\"bf64ff84-a91b-46aa-ab8c-84a9ebc1a068\",\"fxmonitor@mozilla.org\":\"a8403fd3-24d0-463b-a01d-3f4aceb7eae9\",\"screenshots@mozilla.org\":\"4015147a-1a99-41be-88eb-79fbbabe3254\",\"webcompat-reporter@mozilla.org\":\"368e8379-7652-4888-857c-f984723a0030\",\"webcompat@mozilla.org\":\"a6c75f4d-f27d-4b15-ab58-fcc7efb854bd\",\"default-theme@mozilla.org\":\"d5c62600-b26b-4755-aa7a-b0d15f1819be\",\"google@search.mozilla.org\":\"edfb824a-e5c0-490f-a38d-51c4814a3078\",\"amazon@search.mozilla.org\":\"ba8c2479-d4b9-46d2-a5f7-516b1ecd2919\",\"bing@search.mozilla.org\":\"d0eee53f-b3c4-4688-a225-34ecd418f332\",\"ddg@search.mozilla.org\":\"ecf5ec01-8e68-43d3-8726-01cfa89d47a1\",\"ebay@search.mozilla.org\":\"aa71252a-ea04-4355-9830-557e79a2c09f\",\"ecosia@search.mozilla.org\":\"5cbf7a6e-372a-4dc6-b2b5-ed9d324a5bbc\",\"leo_ende_de@search.mozilla.org\":\"85f00478-0c31-4c6a-b840-124da1903180\",\"wikipedia@search.mozilla.org\":\"f80e43d0-8cc9-4d6e-aaaa-454290060c9c\",\"uBlock0@raymondhill.net\":\"386f5184-83ea-4d5f-9461-09b9c9681afa\",\"firefox-compact-dark@mozilla.org\":\"d1e72f9d-c32d-451e-8bad-e6b0ff986fbb\",\"amazondotcom@search.mozilla.org\":\"2d6e6a1b-8d6a-4ce2-a948-661b06102011\",\"twitter@search.mozilla.org\":\"b8f49636-b40a-4e83-9efc-44ba703b3bbe\",\"doh-rollout@mozilla.org\":\"26b0147f-47d6-4e35-9f0d-c6f62b88595c\",\"jid1-93CWPmRbVPjRQA@jetpack\":\"691c3372-a621-4d0a-8018-9df0c235192a\",\"firefox@tampermonkey.net\":\"97acb09e-8142-4108-8c34-299096190f13\",\"reset-search-defaults@mozilla.com\":\"e57c2f04-98e8-4423-acf1-61e9f0ae5bc9\",\"pictureinpicture@mozilla.org\":\"14043934-136e-44dc-84c5-a23bb9e8a05a\"}");
user_pref("findbar.entireword", true);
user_pref("findbar.highlightAll", true);
user_pref("fission.experiment.max-origins.last-disqualified", 0);
user_pref("fission.experiment.max-origins.last-qualified", 1614353704);
user_pref("fission.experiment.max-origins.qualified", true);
user_pref("font.internaluseonly.changed", false);
user_pref("general.smoothScroll.mouseWheel.migrationPercent", 0);
user_pref("gfx-shader-check.build-version", "20210415204500");
user_pref("gfx-shader-check.device-id", "0x1f07");
user_pref("gfx-shader-check.driver-version", "27.21.14.6611");
user_pref("gfx.crash-guard.status.wmfvpxvideo", 2);
user_pref("gfx.crash-guard.wmfvpxvideo.appVersion", "88.0");
user_pref("gfx.crash-guard.wmfvpxvideo.deviceID", "0x1f07");
user_pref("gfx.crash-guard.wmfvpxvideo.driverVersion", "27.21.14.6611");
user_pref("identity.fxaccounts.toolbar.accessed", true);
user_pref("idle.lastDailyNotification", 1619364753);
user_pref("intl.locale.requested", "en-US,de");
user_pref("layers.mlgpu.sanity-test-failed", true);
user_pref("media.benchmark.vp9.fps", 356);
user_pref("media.benchmark.vp9.versioncheck", 5);
user_pref("media.gmp-gmpopenh264.abi", "x86_64-msvc-x64");
user_pref("media.gmp-gmpopenh264.lastUpdate", 1572078457);
user_pref("media.gmp-gmpopenh264.version", "1.8.1.1");
user_pref("media.gmp-manager.buildID", "20210415204500");
user_pref("media.gmp-manager.lastCheck", 1619293944);
user_pref("media.gmp-widevinecdm.abi", "x86_64-msvc-x64");
user_pref("media.gmp-widevinecdm.lastUpdate", 1618927287);
user_pref("media.gmp-widevinecdm.version", "4.10.2209.1");
user_pref("media.gmp.storage.version.observed", 1);
user_pref("media.hardware-video-decoding.failed", false);
user_pref("media.peerconnection.ice.default_address_only", true);
user_pref("media.peerconnection.ice.no_host", true);
user_pref("media.peerconnection.ice.proxy_only_if_behind_proxy", true);
user_pref("media.videocontrols.picture-in-picture.video-toggle.has-used", true);
user_pref("network.captive-portal-service.enabled", false);
user_pref("network.dns.disablePrefetch", true);
user_pref("network.http.speculative-parallel-limit", 0);
user_pref("network.predictor.cleaned-up", true);
user_pref("network.predictor.enabled", false);
user_pref("network.prefetch-next", false);
user_pref("network.trr.blocklist_cleanup_done", true);
user_pref("network.trr.mode", 2);
user_pref("pdfjs.enabledCache.state", true);
user_pref("pdfjs.migrationVersion", 2);
user_pref("pdfjs.previousHandler.alwaysAskBeforeHandling", true);
user_pref("pdfjs.previousHandler.preferredAction", 4);
user_pref("permissions.eventTelemetry.salt", "{441a2b64-f178-4d7f-91ed-34c332c597f7}");
user_pref("places.database.lastMaintenance", 1619102331);
user_pref("places.history.expiration.transient_current_max_pages", 147549);
user_pref("plugin.disable_full_page_plugin_for_types", "application/pdf");
user_pref("pref.general.disable_button.default_browser", false);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_bgcolor", false);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_bgimages", false);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_duplex", 0);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_edge_bottom", 0);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_edge_left", 0);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_edge_right", 0);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_edge_top", 0);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_evenpages", true);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_footercenter", "");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_footerleft", "&PT");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_footerright", "&D");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_headercenter", "");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_headerleft", "&T");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_headerright", "&U");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_in_color", true);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_margin_bottom", "0.5");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_margin_left", "0.5");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_margin_right", "0.5");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_margin_top", "0.5");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_oddpages", true);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_orientation", 0);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_page_delay", 50);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_paper_data", 1);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_paper_height", "11.6929");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_paper_id", "9");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_paper_name", "");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_paper_size_unit", 0);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_paper_width", "8.26772");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_resolution", 360);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_reversed", false);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_scaling", "1");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_shrink_to_fit", true);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_to_file", false);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_to_filename", "");
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_unwriteable_margin_bottom", 12);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_unwriteable_margin_left", 12);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_unwriteable_margin_right", 12);
user_pref("print.printer_EPSON127DF5_(XP-540_Series).print_unwriteable_margin_top", 12);
user_pref("print.printer_Microsoft_Print_to_PDF.print_bgcolor", false);
user_pref("print.printer_Microsoft_Print_to_PDF.print_bgimages", false);
user_pref("print.printer_Microsoft_Print_to_PDF.print_duplex", 0);
user_pref("print.printer_Microsoft_Print_to_PDF.print_edge_bottom", 0);
user_pref("print.printer_Microsoft_Print_to_PDF.print_edge_left", 0);
user_pref("print.printer_Microsoft_Print_to_PDF.print_edge_right", 0);
user_pref("print.printer_Microsoft_Print_to_PDF.print_edge_top", 0);
user_pref("print.printer_Microsoft_Print_to_PDF.print_evenpages", true);
user_pref("print.printer_Microsoft_Print_to_PDF.print_footercenter", "");
user_pref("print.printer_Microsoft_Print_to_PDF.print_footerleft", "&PT");
user_pref("print.printer_Microsoft_Print_to_PDF.print_footerright", "&D");
user_pref("print.printer_Microsoft_Print_to_PDF.print_headercenter", "");
user_pref("print.printer_Microsoft_Print_to_PDF.print_headerleft", "&T");
user_pref("print.printer_Microsoft_Print_to_PDF.print_headerright", "&U");
user_pref("print.printer_Microsoft_Print_to_PDF.print_in_color", true);
user_pref("print.printer_Microsoft_Print_to_PDF.print_margin_bottom", "0.5");
user_pref("print.printer_Microsoft_Print_to_PDF.print_margin_left", "0.5");
user_pref("print.printer_Microsoft_Print_to_PDF.print_margin_right", "0.5");
user_pref("print.printer_Microsoft_Print_to_PDF.print_margin_top", "0.5");
user_pref("print.printer_Microsoft_Print_to_PDF.print_oddpages", true);
user_pref("print.printer_Microsoft_Print_to_PDF.print_orientation", 0);
user_pref("print.printer_Microsoft_Print_to_PDF.print_page_delay", 50);
user_pref("print.printer_Microsoft_Print_to_PDF.print_paper_data", 1);
user_pref("print.printer_Microsoft_Print_to_PDF.print_paper_height", "297");
user_pref("print.printer_Microsoft_Print_to_PDF.print_paper_id", "9");
user_pref("print.printer_Microsoft_Print_to_PDF.print_paper_name", "");
user_pref("print.printer_Microsoft_Print_to_PDF.print_paper_size_unit", 1);
user_pref("print.printer_Microsoft_Print_to_PDF.print_paper_width", "210");
user_pref("print.printer_Microsoft_Print_to_PDF.print_resolution", 600);
user_pref("print.printer_Microsoft_Print_to_PDF.print_reversed", false);
user_pref("print.printer_Microsoft_Print_to_PDF.print_scaling", "1");
user_pref("print.printer_Microsoft_Print_to_PDF.print_shrink_to_fit", true);
user_pref("print.printer_Microsoft_Print_to_PDF.print_to_file", false);
user_pref("print.printer_Microsoft_Print_to_PDF.print_to_filename", "");
user_pref("print.printer_Microsoft_Print_to_PDF.print_unwriteable_margin_bottom", 0);
user_pref("print.printer_Microsoft_Print_to_PDF.print_unwriteable_margin_left", 0);
user_pref("print.printer_Microsoft_Print_to_PDF.print_unwriteable_margin_right", 0);
user_pref("print.printer_Microsoft_Print_to_PDF.print_unwriteable_margin_top", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_bgcolor", false);
user_pref("print.printer_Mozilla_Save_to_PDF.print_bgimages", false);
user_pref("print.printer_Mozilla_Save_to_PDF.print_duplex", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_edge_bottom", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_edge_left", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_edge_right", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_edge_top", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_footercenter", "");
user_pref("print.printer_Mozilla_Save_to_PDF.print_footerleft", "&PT");
user_pref("print.printer_Mozilla_Save_to_PDF.print_footerright", "&D");
user_pref("print.printer_Mozilla_Save_to_PDF.print_headercenter", "");
user_pref("print.printer_Mozilla_Save_to_PDF.print_headerleft", "&T");
user_pref("print.printer_Mozilla_Save_to_PDF.print_headerright", "&U");
user_pref("print.printer_Mozilla_Save_to_PDF.print_in_color", true);
user_pref("print.printer_Mozilla_Save_to_PDF.print_margin_bottom", "0.5");
user_pref("print.printer_Mozilla_Save_to_PDF.print_margin_left", "0.5");
user_pref("print.printer_Mozilla_Save_to_PDF.print_margin_right", "0.5");
user_pref("print.printer_Mozilla_Save_to_PDF.print_margin_top", "0.5");
user_pref("print.printer_Mozilla_Save_to_PDF.print_orientation", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_page_delay", 50);
user_pref("print.printer_Mozilla_Save_to_PDF.print_paper_height", "11");
user_pref("print.printer_Mozilla_Save_to_PDF.print_paper_id", "na_letter");
user_pref("print.printer_Mozilla_Save_to_PDF.print_paper_size_unit", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_paper_width", "8.5");
user_pref("print.printer_Mozilla_Save_to_PDF.print_resolution", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_reversed", false);
user_pref("print.printer_Mozilla_Save_to_PDF.print_scaling", "1");
user_pref("print.printer_Mozilla_Save_to_PDF.print_shrink_to_fit", true);
user_pref("print.printer_Mozilla_Save_to_PDF.print_to_file", true);
user_pref("print.printer_Mozilla_Save_to_PDF.print_to_filename", "C:\\Users\\Lem0th\\Downloads\\Jagex Games Studio.pdf");
user_pref("print.printer_Mozilla_Save_to_PDF.print_unwriteable_margin_bottom", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_unwriteable_margin_left", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_unwriteable_margin_right", 0);
user_pref("print.printer_Mozilla_Save_to_PDF.print_unwriteable_margin_top", 0);
user_pref("print_printer", "Microsoft Print to PDF");
user_pref("privacy.purge_trackers.date_in_cookie_database", "0");
user_pref("privacy.purge_trackers.last_purge", "1619364755788");
user_pref("privacy.sanitize.pending", "[{\"id\":\"newtab-container\",\"itemsToClear\":[],\"options\":{}}]");
user_pref("privacy.socialtracking.notification.counter", 2);
user_pref("privacy.socialtracking.notification.lastShown", "1572280869704");
user_pref("privacy.trackingprotection.enabled", true);
user_pref("privacy.trackingprotection.socialtracking.enabled", true);
user_pref("sanity-test.advanced-layers", false);
user_pref("sanity-test.device-id", "0x1f07");
user_pref("sanity-test.driver-version", "27.21.14.6611");
user_pref("sanity-test.running", false);
user_pref("sanity-test.version", "20210415204500");
user_pref("sanity-test.webrender.force-disabled", false);
user_pref("security.disable_button.openCertManager", false);
user_pref("security.remote_settings.crlite_filters.checked", 1619359347);
user_pref("security.remote_settings.intermediates.checked", 1619359347);
user_pref("security.sandbox.content.tempDirSuffix", "{2acfd792-b93f-49d9-b4ef-9d772c8cdef8}");
user_pref("security.sandbox.plugin.tempDirSuffix", "{ff4693ef-2a69-48c6-ae55-ea54ebe2d53e}");
user_pref("security.ssl.errorReporting.automatic", true);
user_pref("services.blocklist.addons-mlbf.checked", 1619359347);
user_pref("services.blocklist.addons.checked", 1597160658);
user_pref("services.blocklist.gfx.checked", 1619359347);
user_pref("services.blocklist.pinning.checked", 1619359347);
user_pref("services.blocklist.plugins.checked", 1619359347);
user_pref("services.settings.clock_skew_seconds", 1);
user_pref("services.settings.last_etag", "\"1619359120525\"");
user_pref("services.settings.last_update_seconds", 1619359970);
user_pref("services.settings.main.anti-tracking-url-decoration.last_check", 1619359347);
user_pref("services.settings.main.cfr-fxa.last_check", 1619359347);
user_pref("services.settings.main.cfr.last_check", 1619359347);
user_pref("services.settings.main.fxmonitor-breaches.last_check", 1619359347);
user_pref("services.settings.main.hijack-blocklists.last_check", 1619359347);
user_pref("services.settings.main.language-dictionaries.last_check", 1619359347);
user_pref("services.settings.main.message-groups.last_check", 1619359347);
user_pref("services.settings.main.messaging-experiments.last_check", 1605290424);
user_pref("services.settings.main.nimbus-desktop-experiments.last_check", 1619359347);
user_pref("services.settings.main.normandy-recipes-capabilities.last_check", 1619359347);
user_pref("services.settings.main.normandy-recipes.last_check", 1575651913);
user_pref("services.settings.main.onboarding.last_check", 1566400579);
user_pref("services.settings.main.partitioning-exempt-urls.last_check", 1619359347);
user_pref("services.settings.main.password-recipes.last_check", 1619359347);
user_pref("services.settings.main.pioneer-study-addons-v1.last_check", 1619359347);
user_pref("services.settings.main.pioneer-study-addons.last_check", 1619359347);
user_pref("services.settings.main.public-suffix-list.last_check", 1619359347);
user_pref("services.settings.main.search-config.last_check", 1619359347);
user_pref("services.settings.main.search-default-override-allowlist.last_check", 1619359347);
user_pref("services.settings.main.search-telemetry.last_check", 1619359347);
user_pref("services.settings.main.sites-classification.last_check", 1619359347);
user_pref("services.settings.main.tippytop.last_check", 1619359347);
user_pref("services.settings.main.top-sites.last_check", 1619359347);
user_pref("services.settings.main.url-classifier-skip-urls.last_check", 1619359347);
user_pref("services.settings.main.websites-with-shared-credential-backends.last_check", 1619359347);
user_pref("services.settings.main.whats-new-panel.last_check", 1619359347);
user_pref("services.settings.security.onecrl.checked", 1619359347);
user_pref("services.sync.clients.lastSync", "0");
user_pref("services.sync.declinedEngines", "");
user_pref("services.sync.globalScore", 0);
user_pref("services.sync.nextSync", 0);
user_pref("services.sync.tabs.lastSync", "0");
user_pref("signon.importedFromSqlite", true);
user_pref("signon.suggestImportCount", 1);
user_pref("signon.usage.hasEntry", true);
user_pref("signon.usage.lastUsed", 1608064879);
user_pref("storage.vacuum.last.index", 1);
user_pref("storage.vacuum.last.places.sqlite", 1619276275);
user_pref("toolkit.startup.last_success", 1619366971);
user_pref("toolkit.telemetry.cachedClientID", "c0ffeec0-ffee-c0ff-eec0-ffeec0ffeec0");
user_pref("toolkit.telemetry.pioneer-new-studies-available", true);
user_pref("toolkit.telemetry.previousBuildID", "20210415204500");
user_pref("toolkit.telemetry.reportingpolicy.firstRun", false);
user_pref("trailhead.firstrun.didSeeAboutWelcome", true);
user_pref("ui.osk.debug.keyboardDisplayReason", "IKPOS: Touch screen not found.");
========= End of CMD: =========
C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\prefs.js => moved successfully
C:\Users\Lem0th\AppData\Roaming\Mozilla\Firefox\Profiles\40a0sgm9.default-release\Extensions\jid1-93CWPmRbVPjRQA@jetpack.xpi => moved successfully
HKLM\System\CurrentControlSet\Services\ALSysIO => removed successfully
ALSysIO => service removed successfully
HKLM\System\CurrentControlSet\Services\SaferVPNNetfilter2 => removed successfully
SaferVPNNetfilter2 => service removed successfully
C:\Users\Lem0th\AppData\Roaming\prio.ini => moved successfully
C:\Users\Lem0th\AppData\Roaming\822f02e4-9e9a-4077-a765-71edfca16ad0 => moved successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\PowerISO => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\PowerISO => removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA2FFF0C-1001-440D-9B9F-6ED7094288B7}' => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA2FFF0C-1001-440D-9B9F-6ED7094288B7}' => removed successfully
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
========= netsh winsock reset =========
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
========= End of CMD: =========
========= netsh advfirewall reset =========
Ok.
========= End of CMD: =========
========= netsh advfirewall set allprofiles state ON =========
Ok.
========= End of CMD: =========
========= Bitsadmin /Reset /Allusers =========
BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.
0 out of 0 jobs canceled.
========= End of CMD: =========
========= Set-MpPreference -PUAProtection Enabled =========
========= End of Powershell: =========
========= Set-MpPreference -DisableScanningNetworkFiles 0 =========
========= End of Powershell: =========
========= RemoveProxy: =========
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-2331486850-4249055999-2076793073-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-2331486850-4249055999-2076793073-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
========= End of RemoveProxy: =========
SystemRestore: On => completed
=========== EmptyTemp: ==========
BITS transfer queue => 10772480 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 2095863473 B
Java, Flash, Steam htmlcache => 591574184 B
Windows/system/drivers => 9646694 B
Edge => 3672016 B
Chrome => 18669749 B
Firefox => 1831616022 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 432 B
LocalService => 109692 B
NetworkService => 24095760 B
Lem0th => 498589736 B
RecycleBin => 20804056753 B
EmptyTemp: => 24.1 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 18:19:41 ==== |