Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-04-2021
Ran by Etiainen (administrator) on SIONN (ASUS All Series) (05-05-2021 21:20:11)
Running from C:\Users\Etiainen\Desktop
Loaded Profiles: Etiainen
Platform: Windows 10 Pro Version 20H2 19042.928 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe
(ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.06.19\AsusFanControlService.exe
(BANDWIDTH-METER.NET) [File not signed] C:\Program Files (x86)\BandwidthMeterPro\BWMeterPro.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\ASUS\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\ASUS\Bluetooth Software\BTTray.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\ASUS\Bluetooth Software\btwdins.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Smart Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(F.lux Software LLC -> f.lux Software LLC) C:\Users\Etiainen\AppData\Local\FluxSoftware\Flux\flux.exe
(Flexera Software LLC -> InstallShield Software Corporation) [File not signed] C:\Program Files (x86)\Common Files\InstallShield\Engine\8\intel 32\iKernel.exe
(GOG Sp. z o.o. -> GOG.com) C:\Program Files (x86)\GOG Galaxy\GalaxyClient Helper.exe <3>
(GOG Sp. z o.o. -> GOG.com) C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe
(GOG Sp. z o.o. -> GOG.com) C:\Program Files (x86)\GOG Galaxy\GOG Galaxy Notifications Renderer.exe
(GOG Sp. z o.o. -> GOG.com) C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
(Logitech Inc -> Logitech) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOverlay.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe
(Logitech Inc -> Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Etiainen\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\pacjsworker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <6>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(Open Source Developer, Robin Krom -> Greenshot) C:\Program Files\Greenshot\Greenshot.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\spool\drivers\x64\3\E_YATISME.EXE
(Skype Software Sarl -> Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [123800 2016-11-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\ecmdS.exe [164808 2021-05-01] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [527792 2017-08-09] (Open Source Developer, Robin Krom -> Greenshot)
HKLM\...\Run: [EPPCCMON] => C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE [442936 2020-10-22] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [1667208 2020-11-24] (Logitech Inc -> Logitech, Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3951024 2019-10-11] (Microsoft Windows Hardware Compatibility Publisher -> Logitech, Inc.)
HKLM\...\Run: [ctfmon] => C:\Windows\System32\ctfmon.exe [11264 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646776 2020-03-12] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1319208 2019-05-31] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [6787856 2019-03-19] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
HKU\S-1-5-21-698556258-2800857270-1483192661-1001\...\Run: [f.lux] => C:\Users\Etiainen\AppData\Local\FluxSoftware\Flux\flux.exe [1511824 2021-02-04] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-698556258-2800857270-1483192661-1001\...\Run: [BandwidthMeterPro] => C:\Program Files (x86)\BandwidthMeterPro\BWMeterPro.exe [236032 2008-08-16] (BANDWIDTH-METER.NET) [File not signed]
HKU\S-1-5-21-698556258-2800857270-1483192661-1001\...\Run: [launchOnStartup] => C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [7611464 2019-09-23] (GOG Sp. z o.o. -> GOG.com)
HKU\S-1-5-21-698556258-2800857270-1483192661-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4087528 2021-04-12] (Valve -> Valve Corporation)
HKU\S-1-5-21-698556258-2800857270-1483192661-1001\...\Run: [EPLTarget\P0000000000000001] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATISME.EXE [418000 2016-07-14] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-698556258-2800857270-1483192661-1001\...\Run: [Vivaldi Update Notifier] => "C:\Users\Etiainen\AppData\Local\Vivaldi\Application\update_notifier.exe"
HKLM\...\Print\Monitors\EPSON L4160 Series 64MonitorBE: C:\Windows\system32\E_YLMBSME.DLL [184832 2017-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\Windows\system32\enppmon.dll [500736 2016-09-14] (SEIKO EPSON CORPORATION) [File not signed]
HKLM\Software\...\AppCompatFlags\Custom\H3Blade.exe: [{62a24b39-0106-4990-90ea-3a09e9dda7a6}.sdb] -> HoMM III Compatibility Database
HKLM\Software\...\AppCompatFlags\Custom\Heroes3.exe: [{62a24b39-0106-4990-90ea-3a09e9dda7a6}.sdb] -> HoMM III Compatibility Database
HKLM\Software\...\AppCompatFlags\Custom\rct2.exe: [{ac371c85-cfc0-4eba-8168-22c3d8187c1e}.sdb] -> GOG.com Rollercoaster Tycoon 2
HKLM\Software\...\AppCompatFlags\InstalledSDB\{62a24b39-0106-4990-90ea-3a09e9dda7a6}: [DatabasePath] -> C:\WINDOWS\AppPatch\CustomSDB\{62a24b39-0106-4990-90ea-3a09e9dda7a6}.sdb [2019-11-15]
HKLM\Software\...\AppCompatFlags\InstalledSDB\{ac371c85-cfc0-4eba-8168-22c3d8187c1e}: [DatabasePath] -> C:\WINDOWS\AppPatch\CustomSDB\{ac371c85-cfc0-4eba-8168-22c3d8187c1e}.sdb [2018-01-19]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.93\Installer\chrmstp.exe [2021-04-26] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{50968FF7-10C1-4fb3-98B0-CD654D6CB97E}] -> C:\Program Files\ASUS\Bluetooth Software\\BtwCP.dll [2012-12-30] (Broadcom Corporation -> Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2018-10-20]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\ASUS\Bluetooth Software\BTTray.exe (Broadcom Corporation -> Broadcom Corporation.)
BootExecute: autocheck autochk * sdnclean64.exe
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {36822BC8-08E2-4FAA-8600-71B35C7E696A} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Etiainen\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [18007456 2021-05-05] (ESET, spol. s r.o. -> ESET)
Task: {462B914C-E715-47A7-987A-40BD92BA7F1E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [5723640 2019-09-04] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {5777CC80-D97C-4973-B2D7-E2EE9EC8AFE4} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {6BB8B907-CDE9-4367-96AC-BFBE7BFF25B0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {7ECC64C7-202C-402A-8757-1AE9DFABA6F8} - System32\Tasks\InstallShield® Setup Engine Kernel => C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\iKernel.exe [72880 2020-10-16] (Flexera Software LLC -> InstallShield Software Corporation) [File not signed]
Task: {9F96ECA6-9065-4FF3-8544-4D64B82A4518} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Etiainen\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [18007456 2021-05-05] (ESET, spol. s r.o. -> ESET)
Task: {B92A9B2D-B9F7-4CE7-A688-F9E53DFE2501} - System32\Tasks\Optimize Thumbnail Cache => C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\isupdate.exe [61104 2020-09-26] (Flexera Software LLC -> InstallShield®) [File not signed]
Task: {EC6644CC-0223-4322-ABFB-8E0343C03FCA} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [696304 2021-04-21] (Mozilla Corporation -> Mozilla Foundation)
Task: {F508897C-9462-4AD5-B11E-48D57CE65D8C} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {F680C879-219E-41FF-A1FF-BF38A0271C86} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [7177168 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {FD339F63-6759-4274-ABCD-1F5A759A41F4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [6189624 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <==== ATTENTION (Restriction - ProxySettings)
AutoConfigURL: [HKLM] => hxxp://127.0.0.1:86/
AutoConfigURL: [HKLM-x32] => hxxp://127.0.0.1:86/
AutoConfigURL: [{FA83B550-CF6A-4B62-9170-FB7B04B1BF75}] => hxxp://127.0.0.1:86/
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 213.46.172.38 213.46.172.39
Tcpip\..\Interfaces\{3565e81c-3f4a-4c29-87af-0e0a326e8303}: [DhcpNameServer] 213.46.172.38 213.46.172.39
Tcpip\..\Interfaces\{8827239d-22d1-4fda-b9a9-d6c9a5c9f2ec}: [DhcpNameServer] 172.20.10.1
ManualProxies: 0hxxp://127.0.0.1:86/
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION

Edge: 
=======
DownloadDir: C:\Users\Etiainen\Downloads
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\Etiainen\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-05]

FireFox:
========
FF DefaultProfile: ivievfe7.default
FF ProfilePath: C:\Users\Etiainen\AppData\Roaming\Mozilla\Firefox\Profiles\ivievfe7.default [not found] <==== ATTENTION
FF ProfilePath: C:\Users\Etiainen\AppData\Roaming\Mozilla\Firefox\Profiles\2jgtdxq4.default-release-1618507198756 [2021-05-05]
FF Homepage: Mozilla\Firefox\Profiles\2jgtdxq4.default-release-1618507198756 -> about:blank
FF Notifications: Mozilla\Firefox\Profiles\2jgtdxq4.default-release-1618507198756 -> hxxps://calendar.google.com
FF Extension: (Cold Kitsune) - C:\Users\Etiainen\AppData\Roaming\Mozilla\Firefox\Profiles\2jgtdxq4.default-release-1618507198756\Extensions\{80d48543-83e9-40d4-af59-4cb44094bb7d}.xpi [2021-04-15]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [2017-12-14] (Adobe Systems Incorporated -> )
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-03-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [2017-12-14] (Adobe Systems Incorporated -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll [2020-04-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\plugin2\npjp2.dll [2020-04-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-03-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-04-21] (Adobe Inc. -> Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2021-05-05]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2021-04-15]

Chrome: 
=======
CHR Profile: C:\Users\Etiainen\AppData\Local\Google\Chrome\User Data\Default [2021-05-05]
CHR Notifications: Default -> hxxps://meet.google.com; hxxps://www.messenger.com
CHR Extension: (Prezentace) - C:\Users\Etiainen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-06-19]
CHR Extension: (YouTube) - C:\Users\Etiainen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-06-19]
CHR Extension: (Dokumenty Google offline) - C:\Users\Etiainen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-04-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Etiainen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Gmail) - C:\Users\Etiainen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-27]
CHR Extension: (Chrome Media Router) - C:\Users\Etiainen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-04-18]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-03-08] (Apple Inc. -> Apple Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-07-04] (ASUSTeK Computer Inc. -> )
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe [954648 2016-04-19] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.06.19\AsusFanControlService.exe [396088 2016-04-19] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 btwdins; C:\Program Files\ASUS\Bluetooth Software\btwdins.exe [960368 2012-12-30] (Broadcom Corporation -> Broadcom Corporation.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8788392 2021-04-09] (Microsoft Corporation -> Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [818304 2021-03-08] (EasyAntiCheat Oy -> Epic Games, Inc)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2954416 2021-05-01] (ESET, spol. s r.o. -> ESET)
R2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [678328 2018-06-11] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [206304 2020-10-02] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S3 FvSvc; C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe [410864 2021-01-25] (NVIDIA Corporation -> NVIDIA)
R3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [791112 2019-09-23] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6841416 2019-09-23] (GOG Sp. z o.o. -> GOG.com)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7456464 2021-05-03] (Malwarebytes Inc -> Malwarebytes)
S3 Rockstar Service; D:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1332632 2021-03-30] (Rockstar Games, Inc. -> Rockstar Games)
R2 SamsungRapidSvc; C:\WINDOWS\System32\RAPID\SamsungRapidSvc.exe [29080 2016-11-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2747312 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4583240 2020-04-26] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [940976 2019-09-04] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5361256 2021-04-15] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\NisSrv.exe [2372048 2020-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2009.7-0\MsMpEng.exe [128376 2020-10-19] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-04] (ASUSTeK Computer Inc. -> )
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2016-04-19] (ASUSTeK Computer Inc. -> )
S3 blackberryncm; C:\WINDOWS\System32\drivers\blackberryncm6_AMD64.sys [36360 2016-04-06] (Microsoft Windows Hardware Compatibility Publisher -> BlackBerry)
R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-04-07] (Bluestack Systems, Inc -> Bluestack System Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
R3 DroidCam; C:\WINDOWS\System32\drivers\droidcam.sys [32240 2020-04-10] (Microsoft Windows Hardware Compatibility Publisher -> Dev47Apps)
R3 DroidCamVideo; C:\WINDOWS\System32\drivers\droidcamvideo.sys [33768 2020-04-18] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [169400 2021-05-01] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [112576 2021-05-01] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15824 2021-03-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [192624 2021-05-01] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [43832 2021-05-01] (ESET, spol. s r.o. -> ESET)
R1 ElRawDisk; C:\WINDOWS\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation -> EldoS Corporation)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [70160 2021-05-01] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [107400 2021-05-01] (ESET, spol. s r.o. -> ESET)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220752 2021-05-05] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-06-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-05-05] (Malwarebytes Inc -> Malwarebytes)
R3 Phosgene; C:\WINDOWS\system32\DRIVERS\Phosgene.sys [34136 2015-09-02] (ADORIASOFT LLC -> Adoriasoft LLC)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2013-09-30] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] (MiniTool Solution Ltd -> )
R0 SamsungRapidDiskFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidDiskFltr.sys [272792 2016-11-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidFSFltr.sys [111512 2016-11-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S0 Spybot3ELAM; C:\WINDOWS\System32\drivers\Spybot3ELAM.sys [19904 2019-06-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Windows (R) Win 7 DDK provider)
S3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2016-12-21] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2020-10-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [428264 2020-10-19] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [69864 2020-10-19] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-05-05 21:20 - 2021-05-05 21:20 - 000026878 _____ C:\Users\Etiainen\Desktop\FRST.txt
2021-05-05 21:19 - 2021-05-05 19:32 - 002298368 _____ (Farbar) C:\Users\Etiainen\Desktop\FRST64.exe
2021-05-05 21:18 - 2021-05-05 21:18 - 000220752 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-05-05 21:13 - 2021-05-05 21:13 - 000003850 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2021-05-05 21:13 - 2021-05-05 21:13 - 000003408 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2021-05-05 20:30 - 2021-05-05 20:30 - 000003364 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-698556258-2800857270-1483192661-1001
2021-05-05 19:34 - 2021-05-05 19:36 - 000072751 _____ C:\Users\Etiainen\Downloads\Addition.txt
2021-05-05 19:34 - 2021-05-05 19:34 - 011697056 _____ (ESET) C:\Users\Etiainen\Downloads\esetonlinescanner.exe
2021-05-05 19:34 - 2021-05-05 19:34 - 000001387 _____ C:\Users\Etiainen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2021-05-05 19:34 - 2021-05-05 19:34 - 000001281 _____ C:\Users\Etiainen\Desktop\ESET Online Scanner.lnk
2021-05-05 19:33 - 2021-05-05 19:36 - 000046239 _____ C:\Users\Etiainen\Downloads\FRST.txt
2021-05-05 19:32 - 2021-05-05 19:32 - 002298368 _____ (Farbar) C:\Users\Etiainen\Downloads\FRST64.exe
2021-05-05 19:17 - 2021-05-05 19:22 - 000000000 ____D C:\Tools
2021-05-03 23:10 - 2021-05-03 23:11 - 000003126 _____ C:\Users\Etiainen\Downloads\FSS.txt
2021-05-03 23:09 - 2021-05-03 23:09 - 000909824 _____ (Farbar) C:\Users\Etiainen\Downloads\FSS.exe
2021-05-03 23:09 - 2021-05-03 23:09 - 000852798 _____ C:\Users\Etiainen\Downloads\SecurityCheck.exe
2021-05-03 22:22 - 2021-05-05 20:15 - 000000000 ____D C:\Users\Etiainen\AppData\LocalLow\IGDump
2021-05-03 22:21 - 2021-05-03 22:21 - 000002039 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-05-03 22:21 - 2021-05-03 22:21 - 000002027 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2021-05-03 22:21 - 2021-05-03 22:21 - 000002027 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2021-05-03 22:21 - 2020-06-06 20:22 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-05-03 22:19 - 2021-05-03 22:19 - 002078632 _____ (Malwarebytes) C:\Users\Etiainen\Downloads\MBSetup.exe
2021-05-03 21:33 - 2015-10-30 09:21 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20210503-213315.backup
2021-05-03 21:20 - 2021-05-03 21:20 - 000388608 _____ (Trend Micro Inc.) C:\Users\Etiainen\Downloads\HijackThis.exe
2021-05-03 21:12 - 2021-05-03 21:12 - 000000000 ____D C:\Users\Etiainen\AppData\Local\Safer-Networking Ltd
2021-05-03 21:11 - 2021-05-03 21:11 - 000001466 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2021-05-03 21:11 - 2021-05-03 21:11 - 000001454 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2021-05-03 21:11 - 2021-05-03 21:11 - 000001454 _____ C:\ProgramData\Desktop\Spybot-S&D Start Center.lnk
2021-05-03 21:11 - 2021-05-03 21:11 - 000000000 ____D C:\Safer-Networking Ltd
2021-05-03 21:11 - 2021-05-03 21:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2021-05-03 21:11 - 2019-06-21 08:34 - 000019904 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\Spybot3ELAM.sys
2021-05-03 21:11 - 2018-02-06 19:04 - 000032168 _____ (Safer-Networking Ltd.) C:\WINDOWS\system32\sdnclean64.exe
2021-05-03 21:10 - 2021-05-03 21:10 - 069300040 _____ (Safer-Networking Ltd. ) C:\Users\Etiainen\Downloads\spybotsd-2.8.68.0.exe
2021-05-03 19:06 - 2021-05-03 19:06 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-05-03 19:06 - 2021-05-03 19:06 - 000003386 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d7199027a8cf11
2021-05-02 19:09 - 2021-05-02 19:09 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2021-05-02 14:56 - 2021-05-02 14:56 - 000003414 _____ C:\WINDOWS\system32\Tasks\InstallShield® Setup Engine Kernel
2021-04-21 23:15 - 2021-04-21 23:15 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2021-04-19 23:46 - 2021-04-19 23:47 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2021-04-19 23:46 - 2021-04-19 23:46 - 000000000 ____D C:\WINDOWS\system32\lxss
2021-04-19 23:46 - 2021-04-13 11:26 - 001435856 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-04-19 23:46 - 2021-04-13 11:26 - 001435856 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2021-04-19 23:46 - 2021-04-13 11:25 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2021-04-19 23:46 - 2021-04-13 11:25 - 001855184 _____ C:\WINDOWS\system32\vulkaninfo.exe
2021-04-19 23:46 - 2021-04-13 11:25 - 001452312 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2021-04-19 23:46 - 2021-04-13 11:25 - 001191704 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2021-04-19 23:46 - 2021-04-13 11:25 - 001094864 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2021-04-19 23:46 - 2021-04-13 11:25 - 001094864 _____ C:\WINDOWS\system32\vulkan-1.dll
2021-04-19 23:46 - 2021-04-13 11:25 - 000948952 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2021-04-19 23:46 - 2021-04-13 11:25 - 000948952 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2021-04-19 23:46 - 2021-04-13 11:22 - 001514784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2021-04-19 23:46 - 2021-04-13 11:22 - 001166112 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2021-04-19 23:46 - 2021-04-13 11:22 - 000715552 _____ C:\WINDOWS\system32\nvofapi64.dll
2021-04-19 23:46 - 2021-04-13 11:22 - 000675096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2021-04-19 23:46 - 2021-04-13 11:22 - 000575776 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2021-04-19 23:46 - 2021-04-13 11:22 - 000564000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2021-04-19 23:46 - 2021-04-13 11:21 - 002106144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2021-04-19 23:46 - 2021-04-13 11:21 - 001590552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2021-04-19 23:46 - 2021-04-13 11:21 - 000811800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2021-04-19 23:46 - 2021-04-13 11:21 - 000656152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2021-04-19 23:46 - 2021-04-13 11:20 - 008317216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2021-04-19 23:46 - 2021-04-13 11:20 - 007434008 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2021-04-19 23:46 - 2021-04-13 11:20 - 004795184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2021-04-19 23:46 - 2021-04-13 11:20 - 002823456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2021-04-19 23:46 - 2021-04-13 11:20 - 001730848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6446611.dll
2021-04-19 23:46 - 2021-04-13 11:20 - 001490208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6446611.dll
2021-04-19 23:46 - 2021-04-13 11:17 - 006159176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2021-04-19 23:46 - 2021-04-13 01:48 - 000038640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2021-04-17 13:39 - 2021-04-17 13:39 - 047994883 _____ C:\Users\Etiainen\Desktop\Dark Horse White Horse - Dark Horse White Horse.zip
2021-04-16 17:04 - 2021-04-16 17:04 - 000000000 ____D C:\WINDOWS\Panther
2021-04-15 22:28 - 2021-04-26 16:51 - 000000374 _____ C:\Users\Etiainen\.vivaldi_reporting_data
2021-04-15 22:28 - 2021-04-15 22:28 - 072081576 _____ (Vivaldi Technologies AS) C:\Users\Etiainen\Downloads\Vivaldi.3.7.2218.55.x64.exe
2021-04-15 19:19 - 2021-05-03 16:46 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-04-15 19:19 - 2021-04-21 23:15 - 000001011 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-04-15 19:18 - 2021-05-03 16:46 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-04-15 19:18 - 2021-04-15 19:18 - 000333128 _____ (Mozilla) C:\Users\Etiainen\Downloads\Firefox Installer.exe
2021-04-15 19:14 - 2021-04-15 19:14 - 000060598 _____ C:\Users\Etiainen\Desktop\bookmarks-2021-04-15.json
2021-04-15 16:47 - 2021-04-15 16:47 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-04-15 16:47 - 2021-04-15 16:47 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-04-15 16:47 - 2021-04-15 16:47 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-04-13 00:29 - 2021-04-13 00:29 - 000000138 _____ C:\Users\Etiainen\Desktop\Chordata Antarctica.url
2021-04-12 17:43 - 2021-04-12 17:43 - 000000000 ____D C:\Users\Etiainen\AppData\LocalLow\Innersloth
2021-04-12 16:48 - 2021-04-12 16:48 - 000000222 _____ C:\Users\Etiainen\Desktop\Among Us.url
2021-04-11 20:29 - 2021-05-02 14:56 - 000003774 _____ C:\WINDOWS\system32\Tasks\Optimize Thumbnail Cache
2021-04-11 16:44 - 2021-04-11 16:44 - 000000855 _____ C:\Users\Etiainen\Desktop\Grand Theft Auto V.lnk
2021-04-09 22:46 - 2021-04-09 22:46 - 000000000 ____D C:\Users\Etiainen\AppData\LocalLow\Oddworld Inhabitants Inc
2021-04-07 17:07 - 2021-04-07 17:07 - 000000000 ____D C:\Users\Etiainen\AppData\Roaming\T2GP Launcher
2021-04-07 17:07 - 2021-04-07 17:07 - 000000000 ____D C:\Users\Etiainen\AppData\Local\T2GP Launcher

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-05-05 21:20 - 2019-02-13 23:44 - 000000000 ____D C:\ProgramData\Mozilla
2021-05-05 21:20 - 2017-10-11 22:58 - 000000000 ____D C:\FRST
2021-05-05 21:19 - 2020-05-14 23:48 - 000000000 ____D C:\Program Files (x86)\Steam
2021-05-05 21:19 - 2016-11-18 14:06 - 000000000 ____D C:\Users\Etiainen\AppData\LocalLow\Mozilla
2021-05-05 21:18 - 2021-03-15 13:43 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-05-05 21:18 - 2021-03-15 13:35 - 000455288 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-05-05 21:18 - 2021-03-15 13:35 - 000008192 ___SH C:\DumpStack.log.tmp
2021-05-05 21:18 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-05-05 21:18 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-05-05 21:18 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-05-05 21:18 - 2017-03-14 19:53 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2021-05-05 21:18 - 2016-09-26 07:21 - 000000000 ____D C:\ProgramData\NVIDIA
2021-05-05 20:30 - 2021-03-15 13:03 - 000002378 _____ C:\Users\Etiainen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-05-05 19:47 - 2017-03-14 19:47 - 000000000 ____D C:\Program Files (x86)\WinUtilities
2021-05-05 19:34 - 2016-04-20 23:39 - 000000000 ____D C:\Users\Etiainen\AppData\Local\ESET
2021-05-05 19:31 - 2017-10-03 19:58 - 000000000 ____D C:\Users\Etiainen\AppData\Roaming\TeamViewer
2021-05-05 19:28 - 2021-03-15 13:46 - 001693136 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-05-05 19:28 - 2021-03-15 12:43 - 000716710 _____ C:\WINDOWS\system32\perfh005.dat
2021-05-05 19:28 - 2021-03-15 12:43 - 000144908 _____ C:\WINDOWS\system32\perfc005.dat
2021-05-05 19:28 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2021-05-05 19:21 - 2020-06-06 16:11 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-05-05 19:15 - 2021-03-15 13:35 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-05-03 22:21 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-05-03 22:20 - 2019-03-01 08:33 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-05-03 22:18 - 2017-03-14 19:53 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2021-05-03 20:34 - 2016-10-12 12:39 - 000000000 ____D C:\Users\Etiainen\AppData\Local\Battle.net
2021-05-03 19:52 - 2016-06-12 23:02 - 000000000 ____D C:\Program Files\Rockstar Games
2021-05-03 19:52 - 2016-06-12 23:02 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2021-05-03 19:17 - 2016-10-12 12:39 - 000000000 ____D C:\Program Files (x86)\Battle.net
2021-05-03 16:05 - 2016-04-25 19:19 - 000000000 ____D C:\Users\Etiainen\AppData\Roaming\vlc
2021-05-02 19:09 - 2016-10-22 12:00 - 000002142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-05-02 14:52 - 2018-05-30 16:34 - 000000000 ____D C:\Users\Etiainen\AppData\Local\D3DSCache
2021-05-01 20:08 - 2020-06-06 16:12 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-05-01 20:08 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-05-01 20:08 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-05-01 20:07 - 2017-11-30 13:17 - 000192624 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2021-05-01 20:07 - 2017-11-30 13:17 - 000169400 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2021-05-01 20:07 - 2017-11-30 13:17 - 000112576 _____ (ESET) C:\WINDOWS\system32\Drivers\edevmon.sys
2021-05-01 20:07 - 2017-11-30 13:17 - 000107400 _____ (ESET) C:\WINDOWS\system32\Drivers\epfwwfp.sys
2021-05-01 20:07 - 2017-11-30 13:17 - 000070160 _____ (ESET) C:\WINDOWS\system32\Drivers\epfw.sys
2021-05-01 20:07 - 2017-11-30 13:17 - 000043832 _____ (ESET) C:\WINDOWS\system32\Drivers\ekbdflt.sys
2021-04-27 17:46 - 2016-05-09 00:01 - 000000000 ____D C:\Program Files\Microsoft Office
2021-04-27 09:58 - 2021-03-31 09:28 - 000000000 ____D C:\Users\Etiainen\AppData\Local\Deployment
2021-04-27 09:46 - 2018-07-15 09:25 - 000000000 ____D C:\Users\Etiainen\AppData\Local\Greenshot
2021-04-26 21:47 - 2019-06-19 20:55 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-04-26 16:47 - 2020-09-20 19:56 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-04-19 23:47 - 2016-04-19 20:25 - 000000000 ____D C:\Users\Etiainen\AppData\Local\NVIDIA
2021-04-19 23:46 - 2017-04-25 17:45 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2021-04-19 22:15 - 2017-03-14 18:18 - 000000000 ____D C:\Users\Etiainen\AppData\Local\Spotify
2021-04-19 22:15 - 2017-03-14 18:17 - 000000000 ____D C:\Users\Etiainen\AppData\Roaming\Spotify
2021-04-18 19:28 - 2017-12-01 00:29 - 000000000 ____D C:\Users\Etiainen\AppData\Local\Packages
2021-04-18 17:56 - 2016-05-12 12:05 - 000000000 ____D C:\Users\Etiainen\AppData\Roaming\Audacity
2021-04-16 17:17 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2021-04-15 22:28 - 2021-03-15 13:03 - 000000000 ____D C:\Users\Etiainen
2021-04-15 21:35 - 2019-12-07 11:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-04-15 21:35 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-04-15 19:18 - 2016-04-20 23:19 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2021-04-15 16:49 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2021-04-15 16:49 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-04-15 16:47 - 2021-03-15 13:36 - 002877440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2021-04-15 16:41 - 2016-04-19 20:28 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-04-15 16:38 - 2016-04-19 20:28 - 131963968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-04-14 23:43 - 2018-01-08 18:25 - 000000000 ____D C:\Users\Etiainen\AppData\Roaming\discord
2021-04-13 11:17 - 2020-10-14 20:29 - 007212248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2021-04-13 01:48 - 2020-10-14 20:29 - 001682376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2021-04-13 01:48 - 2020-10-14 20:29 - 000135592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2021-04-13 01:48 - 2020-10-14 20:29 - 000063943 _____ C:\WINDOWS\system32\nvinfo.pb
2021-04-13 00:29 - 2019-01-15 20:24 - 000000000 ____D C:\Users\Etiainen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2021-04-12 21:48 - 2017-04-25 17:45 - 005666672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2021-04-12 21:48 - 2017-04-25 17:45 - 002636656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2021-04-12 21:48 - 2017-04-25 17:45 - 001758064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2021-04-12 21:48 - 2017-04-25 17:45 - 000990064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2021-04-12 21:48 - 2017-04-25 17:45 - 000120176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2021-04-12 21:48 - 2017-04-25 17:45 - 000082288 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2021-04-11 20:29 - 2021-03-15 13:43 - 000000000 ____D C:\WINDOWS\system32\Tasks\MEGA
2021-04-11 20:29 - 2021-03-15 13:43 - 000000000 ____D C:\WINDOWS\system32\Tasks\ASUS
2021-04-11 20:29 - 2021-03-15 13:43 - 000000000 ____D C:\WINDOWS\system32\Tasks\Apple
2021-04-11 16:54 - 2016-04-21 22:10 - 000000000 ____D C:\Users\Etiainen\AppData\Local\Rockstar Games
2021-04-11 16:44 - 2020-08-22 11:15 - 000000000 ____D C:\Users\Etiainen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2021-04-11 12:39 - 2020-10-22 22:55 - 000001106 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++.lnk
2021-04-11 12:39 - 2016-04-21 16:21 - 000000000 ____D C:\Program Files (x86)\Notepad++
2021-04-07 17:41 - 2017-04-25 17:45 - 009527077 _____ C:\WINDOWS\system32\nvcoproc.bin

==================== Files in the root of some directories ========

2017-09-02 17:18 - 2002-08-29 17:33 - 000319488 ____R () C:\Users\Etiainen\AppData\Roaming\MafiaSetup.exe
2016-04-21 16:12 - 2021-03-23 19:06 - 000000128 _____ () C:\Users\Etiainen\AppData\Roaming\winscp.rnd
2016-05-03 21:40 - 2021-03-24 23:07 - 000007680 _____ () C:\Users\Etiainen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-04-19 21:17 - 2017-09-02 14:18 - 001065984 _____ () C:\Users\Etiainen\AppData\Local\file__0.localstorage
2017-03-09 00:27 - 2017-05-23 22:54 - 000007618 _____ () C:\Users\Etiainen\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================