Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-08-2022
Ran by ZALMAN (administrator) on DESKTOP-T24R4MM (Gigabyte Technology Co., Ltd. B560M H) (12-09-2022 15:12:18)
Running from C:\Users\ZALMAN\Desktop
Loaded Profiles: ZALMAN
Platform: Microsoft Windows 10 Pro Version 21H2 19044.1889 (X64) Language: Slovenčina (Slovensko)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(D:\Programy\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe ->) (Epic Games Inc. -> Epic Games, Inc.) D:\Programy\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <3>
(D:\Programy\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) D:\Programy\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <8>
(Discord Inc. -> Discord Inc.) C:\Users\ZALMAN\AppData\Local\Discord\app-1.0.9006\Discord.exe <6>
(explorer.exe ->) (Epic Games Inc. -> Epic Games, Inc.) D:\Programy\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(explorer.exe ->) (Logitech -> Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) D:\Programy\Steam\steam.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\afwServ.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\ProgramData\SOLIDWORKS Electrical\MSSQL12.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmdi.inf_amd64_4a922d3e93437ff6\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe <2>
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe [1231864 2021-02-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech -> Logitech Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [213728 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [362056 2022-05-05] (Apple Inc. -> Apple Inc.)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-1376666150-4259590915-1670796979-1001\...\Run: [Steam] => D:\Programy\Steam\steam.exe [4234600 2022-08-20] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-1376666150-4259590915-1670796979-1001\...\Run: [EpicGamesLauncher] => D:\Programy\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32681424 2022-09-06] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1376666150-4259590915-1670796979-1001\...\Run: [Discord] => C:\Users\ZALMAN\AppData\Local\Discord\Update.exe [1512104 2021-05-24] (Discord Inc. -> GitHub)
HKU\S-1-5-21-1376666150-4259590915-1670796979-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\ZALMAN\AppData\Local\Microsoft\Teams\Update.exe [2576128 2022-09-03] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-1376666150-4259590915-1670796979-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [38274576 2022-08-12] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1376666150-4259590915-1670796979-1001\...\Run: [MicrosoftEdgeAutoLaunch_2C389501B3AB7759959FF5C63C776684] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3795360 2022-09-08] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1376666150-4259590915-1670796979-1001\...\Policies\Explorer: [] 
HKU\S-1-5-21-1376666150-4259590915-1670796979-1001\...\MountPoints2: {339d1103-0345-11ec-be6a-18c04df9641d} - "F:\Lenovo_Suite.exe" 
HKU\S-1-5-21-1376666150-4259590915-1670796979-1001\...\MountPoints2: {70d30c5d-9967-11ec-bead-18c04df9641d} - "F:\HiSuiteDownLoader.exe" 
HKLM\...\Windows x64\Print Processors\Canon MG3600 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDCT.DLL [30208 2015-03-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3600 series: C:\Windows\system32\CNMLMCT.DLL [406528 2015-03-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0300B4BF-2F3D-4360-A349-3E5624A63177} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342080 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {1B5DAFB0-900F-4331-BE3C-83E9ED3A1DC5} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-08-12] (Piriform Software Ltd -> Piriform)
Task: {1BD42298-9DFD-4DB0-B9D7-62477E541907} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {23E8E5D7-21D5-40E5-85F8-D5D7167C6697} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {2DB0FE9F-555F-40F0-AEC9-9D5674EE322A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {3468AE09-D638-41A4-9D18-37BAC6376719} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [142232 2022-09-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {36341239-DCC1-452F-9E8C-C8B6244EF064} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {65C42BFA-4813-4989-BBBD-D3AEFF7AD827} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {7610B590-E69B-4B1C-A04A-D98ED403923C} - System32\Tasks\CCleanerSkipUAC - ZALMAN => C:\Program Files\CCleaner\CCleaner.exe [31990800 2022-08-12] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {899D3D7E-5A75-4448-A0B6-9DB78503B399} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-01] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {9239E905-F906-4258-924D-7B5111CF18DF} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646344 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {92FC8D0D-EF60-44E6-8955-84B87AAFFB2C} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [142232 2022-09-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {A4030ABE-38B4-4EC7-AEC9-4BF59B464DA1} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {A9943920-F41C-421A-948C-50733F02428B} - System32\Tasks\Intel PTT EK Recertification => C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe [818008 2021-09-15] (Intel Corporation -> Intel(R) Corporation)
Task: {AD73D383-B2B6-451B-9CB3-E5BF87577E8A} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4943072 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
Task: {B305C7A9-25A5-490C-953A-E452489526E3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [617096 2022-02-25] (Apple Inc. -> Apple Inc.)
Task: {B5042B70-BD78-43BC-833C-49CF3DC020E6} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [932808 2022-09-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {CBF971F3-374B-4319-ABEA-6BCBBED17637} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8516576 2022-09-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {CD9DE041-7B42-4645-AF7F-4403AFF93764} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {CEDADF4A-EE5B-4429-8DBF-7633BBDF87F4} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation)
Task: {D36EA7E3-E19F-454E-802B-FE687E609A8C} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23706576 2022-09-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {DB69AF8B-9525-4CD1-B9E2-CDE581BC28F5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23706576 2022-09-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {E0B3F0B9-F862-46F7-9C13-B11E83A0845F} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2250576 2022-05-24] (Avast Software s.r.o. -> Avast Software)
Task: {EFB77096-5080-43AA-BBC7-7C2105697EDC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8516576 2022-09-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {F97FFBD0-5660-4C62-8383-633F25E0DB56} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [64408 2022-09-09] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
Task: C:\Windows\Tasks\Intel PTT EK Recertification.job => C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll => No File 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 195.146.128.62
Tcpip\..\Interfaces\{2dc7ba16-4201-4404-998a-36a6f6b680c8}: [DhcpNameServer] 192.168.1.1 195.146.128.62

Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\ZALMAN\AppData\Local\Microsoft\Edge\User Data\Default [2022-09-12]

FireFox:
========
FF DefaultProfile: uswc131q.default
FF ProfilePath: C:\Users\ZALMAN\AppData\Roaming\Mozilla\Firefox\Profiles\uswc131q.default [2022-01-17]
FF ProfilePath: C:\Users\ZALMAN\AppData\Roaming\Mozilla\Firefox\Profiles\rcfitc31.default-release [2022-09-12]
FF Extension: (AdGuard blokovač reklamy) - C:\Users\ZALMAN\AppData\Roaming\Mozilla\Firefox\Profiles\rcfitc31.default-release\Extensions\adguardadblocker@adguard.com.xpi [2022-08-29]
FF Extension: (HTTPS Everywhere) - C:\Users\ZALMAN\AppData\Roaming\Mozilla\Firefox\Profiles\rcfitc31.default-release\Extensions\https-everywhere@eff.org.xpi [2021-08-22]
FF Extension: (Surfshark VPN Extension) - C:\Users\ZALMAN\AppData\Roaming\Mozilla\Firefox\Profiles\rcfitc31.default-release\Extensions\{732216ec-0dab-43bb-ac85-4b5e1977599d}.xpi [2022-07-27]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-07-08] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-03-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-07-08] (Microsoft Corporation -> Microsoft Corporation)

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [100424 2022-05-02] (Apple Inc. -> Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [8523800 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [589536 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2014432 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [589536 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2022-03-17] (Avast Software s.r.o. -> AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8885112 2022-05-17] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12126112 2022-09-09] (Microsoft Corporation -> Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811496 2022-06-21] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2022-07-11] (Epic Games Inc. -> Epic Games, Inc.)
R2 MSSQL$TEW_SQLEXPRESS; C:\ProgramData\SOLIDWORKS Electrical\MSSQL12.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe [372416 2015-04-20] (Microsoft Corporation -> Microsoft Corporation)
R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4490376 2020-09-18] (Logitech Inc -> Logitech)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2579272 2022-08-09] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3497808 2022-08-09] (Electronic Arts, Inc. -> Electronic Arts)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6255896 2022-08-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 SQLAgent$TEW_SQLEXPRESS; C:\ProgramData\SOLIDWORKS Electrical\MSSQL12.TEW_SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [613056 2015-04-20] (Microsoft Corporation -> Microsoft Corporation)
S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\UNCHEATER\ucldr_battlegrounds_gl.exe [7152880 2022-01-12] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2107.4-0\NisSrv.exe [2727416 2021-08-19] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2107.4-0\MsMpEng.exe [136656 2021-08-19] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [8737992 2022-01-20] (PUBG CORPORATION -> PUBG Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvmdi.inf_amd64_4a922d3e93437ff6\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvmdi.inf_amd64_4a922d3e93437ff6\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AppleKmdfFilter; C:\Windows\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [41760 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [237632 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [389064 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [257992 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [104904 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswElam; C:\Windows\System32\drivers\aswElam.sys [24528 2022-08-01] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [47936 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [274976 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [553880 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [113920 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [88984 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [861936 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [671216 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [221464 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [327408 2022-08-26] (Avast Software s.r.o. -> AVAST Software)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2019-04-02] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.)
R3 iaLPSS2_GPIO2_TGL; C:\Windows\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_cb8dd04b85ac9a58\iaLPSS2_GPIO2_TGL.sys [128680 2020-12-23] (Intel Corporation -> Intel Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [48552 2021-11-01] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
S4 RsFx0310; C:\Windows\System32\DRIVERS\RsFx0310.sys [249024 2015-04-20] (Microsoft Corporation -> Microsoft Corporation)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2021-03-18] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [49568 2021-08-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [434424 2021-08-19] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [78072 2021-08-19] (Microsoft Windows -> Microsoft Corporation)
S3 xhunter1; C:\Windows\xhunter1.sys [2522256 2022-01-20] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-09-12 15:12 - 2022-09-12 15:12 - 000024761 _____ C:\Users\ZALMAN\Desktop\FRST.txt
2022-09-12 15:11 - 2022-09-12 15:11 - 002371072 _____ (Farbar) C:\Users\ZALMAN\Desktop\FRST64.exe
2022-09-12 15:08 - 2022-09-12 15:08 - 000000000 ____D C:\Program Files (x86)\Epic Games
2022-09-08 18:03 - 2022-09-10 09:44 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-08-26 14:26 - 2022-08-26 14:26 - 000270560 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2022-08-26 14:26 - 2022-08-26 14:26 - 000221464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2022-09-12 15:12 - 2022-01-10 22:31 - 000000000 ____D C:\FRST
2022-09-12 15:12 - 2021-08-20 15:55 - 000000000 ____D C:\Users\ZALMAN\AppData\LocalLow\Mozilla
2022-09-12 15:11 - 2022-02-08 18:43 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-09-12 15:10 - 2021-08-19 16:32 - 000000000 ____D C:\ProgramData\NVIDIA
2022-09-12 15:09 - 2021-08-20 16:09 - 000000000 ____D C:\Users\ZALMAN\AppData\Local\CrashDumps
2022-09-12 15:08 - 2021-12-17 14:55 - 000000000 ____D C:\Users\ZALMAN\AppData\Roaming\vlc
2022-09-12 15:08 - 2021-09-23 09:51 - 000000000 ____D C:\Program Files\CCleaner
2022-09-12 15:08 - 2021-08-20 16:08 - 000000000 ____D C:\ProgramData\Epic
2022-09-12 15:06 - 2021-08-20 18:43 - 000000000 ____D C:\Users\ZALMAN\AppData\Roaming\discord
2022-09-12 15:05 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-09-12 15:04 - 2021-09-23 09:51 - 000002988 _____ C:\Windows\system32\Tasks\CCleaner Update
2022-09-12 15:04 - 2021-09-23 09:51 - 000002256 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC - ZALMAN
2022-09-12 15:04 - 2019-12-07 08:59 - 000003560 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-09-12 15:04 - 2019-12-07 08:59 - 000003336 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2022-09-12 14:54 - 2022-03-17 14:55 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2022-09-12 14:47 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2022-09-12 14:32 - 2019-12-07 08:59 - 000000000 ____D C:\Windows\system32\SleepStudy
2022-09-12 14:16 - 2021-08-20 18:43 - 000000000 ____D C:\Users\ZALMAN\AppData\Local\Discord
2022-09-11 21:35 - 2022-03-17 14:52 - 000000000 ____D C:\ProgramData\Avast Software
2022-09-11 21:34 - 2019-12-07 08:59 - 000008192 ___SH C:\DumpStack.log.tmp
2022-09-11 21:34 - 2019-12-07 08:59 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-09-11 15:21 - 2019-12-07 11:03 - 000262144 _____ C:\Windows\system32\config\BBI
2022-09-11 10:32 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-09-11 10:32 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2022-09-11 10:32 - 2019-12-07 08:59 - 000002447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-09-10 09:44 - 2021-08-20 15:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-09-09 17:13 - 2021-08-22 14:38 - 000000000 ____D C:\Users\ZALMAN\AppData\Roaming\qBittorrent
2022-09-09 14:35 - 2022-02-04 23:21 - 000000000 ____D C:\Users\ZALMAN\AppData\Roaming\Origin
2022-09-09 14:35 - 2022-02-04 23:21 - 000000000 ____D C:\ProgramData\Origin
2022-09-09 14:32 - 2022-02-04 23:21 - 000000000 ____D C:\Users\ZALMAN\AppData\Local\Origin
2022-09-09 10:54 - 2021-09-07 19:46 - 000000000 ____D C:\Program Files\Microsoft Office
2022-09-08 18:45 - 2021-09-24 16:12 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2022-09-08 18:45 - 2021-08-20 15:55 - 000001008 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-09-06 15:38 - 2022-03-17 14:56 - 000000000 ____D C:\Users\ZALMAN\AppData\Local\Avast Software
2022-09-06 15:13 - 2019-12-07 09:01 - 000000000 ____D C:\Users\ZALMAN\AppData\Local\Packages
2022-09-03 14:44 - 2021-09-08 18:48 - 000002376 _____ C:\Users\ZALMAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2022-08-26 18:20 - 2022-02-23 19:36 - 000000000 ____D C:\Users\ZALMAN\AppData\Roaming\TS3Client
2022-08-26 14:26 - 2022-03-17 14:54 - 000861936 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000671216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000553880 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNetHub.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000389064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriver.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000327408 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000274976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000257992 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000237632 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000113920 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000104904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000088984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000047936 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000041760 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys
2022-08-26 14:26 - 2022-03-17 14:54 - 000003990 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2022-08-26 14:26 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2022-08-21 19:34 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\LiveKernelReports
2022-08-21 19:34 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2022-08-20 20:03 - 2022-07-06 18:02 - 000001716 _____ C:\Users\ZALMAN\Desktop\SMC.lnk
2022-08-20 19:53 - 2022-07-10 18:53 - 000001716 _____ C:\Users\ZALMAN\Desktop\F1 Server.lnk
2022-08-16 22:24 - 2019-12-07 09:01 - 000000000 ____D C:\Users\ZALMAN
2022-08-16 18:33 - 2021-08-20 16:11 - 000000000 ____D C:\Users\ZALMAN\AppData\Local\D3DSCache
2022-08-16 18:00 - 2021-10-23 17:58 - 000049064 _____ C:\Windows\system32\perfh01B.dat
2022-08-16 18:00 - 2021-10-23 17:58 - 000012206 _____ C:\Windows\system32\perfc01B.dat
2022-08-16 18:00 - 2021-08-19 15:40 - 001027750 _____ C:\Windows\system32\PerfStringBackup.INI
2022-08-16 17:52 - 2021-08-20 16:00 - 000003458 _____ C:\Windows\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-08-16 17:52 - 2021-08-20 16:00 - 000003212 _____ C:\Windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-08-16 17:52 - 2021-08-20 16:00 - 000003044 _____ C:\Windows\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-08-16 17:52 - 2021-08-20 16:00 - 000003008 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-08-16 17:52 - 2021-08-20 16:00 - 000003008 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-08-16 17:52 - 2021-08-20 16:00 - 000003008 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-08-16 17:52 - 2021-08-20 16:00 - 000003008 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-08-16 17:52 - 2021-08-20 16:00 - 000002974 _____ C:\Windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-08-16 17:52 - 2021-08-20 16:00 - 000002804 _____ C:\Windows\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2022-08-13 15:40 - 2022-08-09 19:45 - 000000000 ____D C:\Program Files (x86)\Origin Games
2022-08-13 15:40 - 2022-02-08 21:46 - 000000000 ____D C:\Program Files (x86)\Origin

==================== Files in the root of some directories ========

2021-10-27 09:58 - 2022-03-29 20:50 - 000000032 _____ () C:\Users\ZALMAN\AppData\Roaming\.machineId
2022-02-16 22:59 - 2022-07-27 13:33 - 000000081 _____ () C:\Users\ZALMAN\AppData\Local\.bidstack.fault
2021-11-01 13:04 - 2021-11-27 16:17 - 000000000 _____ () C:\Users\ZALMAN\AppData\Local\Temptable.xml

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================