S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [2133968 2022-05-18] (Rockstar Games, Inc. -> Rockstar Games) Username: ForCheffy or Alternate-Cheffy. 2022-08-31 20:02 - 2022-09-01 05:48 - 000001056 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom.lnk AV: Symantec Endpoint Protection (Enabled - Up to date) {FC90FA28-5CE6-9068-FC99-1C67339C0047} FirewallRules: [UDP Query User{3F71C761-DD03-4569-BF52-8F36FD7E0076}D:\steam\steamapps\common\battlefield 2042\bf2042.exe] => (Allow) D:\steam\steamapps\common\battlefield 2042\bf2042.exe => No File A wall spawns every other apple eaten, starting on the first apple. IFEO\remsh.exe: [Debugger] / R2 SepMasterService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin\ccSvcHst.exe [156584 2022-02-25] (Symantec Corporation -> Broadcom) (explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgtray.exe (services.exe ->) (Symantec Corporation -> Broadcom) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin\ccSvcHst.exe <2> AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk:09A0A90EF3 [3442] now this is a bot i wish it gets verified. HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\RunOnce: [Uninstall 22.065.0412.0004_1] => C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Tyson\AppData\Local\Microsoft\OneDrive\22.065.0412.0004_1" (No File) R3 logi_joy_xlcore; C:\windows\system32\drivers\logi_joy_xlcore.sys [62904 2022-05-13] (WDKTestCert builder,132743893872553407 -> Logitech) 2022-09-04 21:33 - 2022-07-31 17:56 - 000000000 ____D C:\Users\Tyson\AppData\Local\ElevatedDiagnostics Thanks again for reading, and wishing you the best with this super fun game! FirewallRules: [TCP Query User{648940F9-C15C-4C43-9D0A-9811D09E9D84}C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_gtaprocess.exe] => (Allow) C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_gtaprocess.exe => No File 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\SecureBootUpdates HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION Vulkan Run Time Libraries 1.0.65.1 (HKLM\\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Edge Profile: C:\Users\Tyson\AppData\Local\Microsoft\Edge\User Data\Default [2022-01-10] NVIDIA PhysX System Software 9.21.0713 (HKLM\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) S3 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin64\snac64.exe [215648 2022-02-25] (Symantec Corporation -> Broadcom) FirewallRules: [UDP Query User{AC216D33-7A53-478B-A454-AAA5E89A946E}C:\program files\lghub\lghub_agent.exe] => (Allow) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) R1 SRTSPX; C:\windows\System32\Drivers\SEP\0E031CE1\0FA0.105\x64\SRTSPX64.SYS [42448 2022-02-25] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk:09A0A90EF3 [3442] ScoreSaber. Task: {01DAB107-1220-4031-BC4E-96D0E9EA813B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1555696 2022-08-03] (Adobe Inc. -> Adobe Inc.) 2022-09-19 00:28 - 2022-09-19 00:28 - 000002017 _____ C:\Users\Public\Desktop\Oculus.lnk S3 WdBoot; C:\windows\system32\drivers\wd\WdBoot.sys [48536 2022-01-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) (services.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe R2 CorsairGamingAudioConfig; C:\Windows\System32\CorsairGamingAudioCfgService64.exe [610352 2022-07-08] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) Error: (09/21/2022 08:32:48 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) R2 MBAMChameleon; C:\windows\System32\Drivers\MbamChameleon.sys [223176 2022-09-21] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) 2022-09-21 08:38 - 2022-04-05 15:06 - 000000000 ____D C:\windows\system32\Tasks\Symantec Endpoint Protection Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) 2022-08-27 00:56 - 2022-05-13 18:58 - 000000000 ____D C:\windows\system32\appmgmt Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation) R1 ccSettings_{BEC9211B-09AC-4B5B-9D31-561ADFF81A33}; C:\windows\System32\Drivers\SEP\0E031CE1\0FA0.105\x64\ccSetx64.sys [189392 2022-02-25] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) FF Extension: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2021-02-01] Eat as many apples as you can to grow as long as possible. ==================== Shortcuts & WMI ======================== Avoid hitting the borders and keep eating more food to make your snake grow longer in the game. 2022-09-16 04:26 - 2021-06-05 22:10 - 000000000 ____D C:\windows\SystemTemp 2022-09-04 21:33 - 2022-07-31 17:56 - 000000000 ____D C:\Users\Tyson\AppData\Local\ElevatedDiagnostics 2022-06-16 16:57 - 2022-06-16 16:57 - 000090112 _____ (Silicon Laboratories, Inc.) [File not signed] C:\Program Files\Corsair\CORSAIR iCUE 4 Software\SiUSBXp.dll 2022-09-21 08:33 - 2022-05-13 18:02 - 000000000 ____D C:\Users\Tyson\AppData\LocalLow\Mozilla This is just one of many, so be sure to take a look at their other Easter eggs too! (services.exe ->) (Symantec Corporation -> Broadcom) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin\ccSvcHst.exe <2> (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe Tcpip\..\Interfaces\{203ebb61-a8f5-49d4-9bc1-32351b715ebe}: [NameServer] 8.8.8.8,8.8.4.4 ==================== Internet Explorer (Whitelisted) ========== Follow the instructions. 2022-08-27 01:04 - 2022-08-27 01:06 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\paradox-launcher-v2 FirewallRules: [TCP Query User{B74EA116-49AA-4ADE-A880-3B544A114EDE}C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_fxdk_b2545_gameruntime.exe] => (Allow) C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_fxdk_b2545_gameruntime.exe => No File ==================== Restore Points ========================= 2022-09-07 20:08 - 2022-09-07 20:08 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\Insomniac Games CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Tyson\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-09-19] FirewallRules: [{0D8A7250-C942-4F44-A7AF-0761A7F3F2B6}] => (Allow) D:\Steam\SteamApps\common\Sid Meier's Civilization V\LaunchPad\LaunchPad.exe () [File not signed] 2022-09-14 00:04 - 2022-08-02 02:04 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\com.adobe.dunamis R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [923656 2022-08-02] (Adobe Inc. -> Adobe Inc.) R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [100344 2022-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) CHR Extension: (Chrome Web Store Payments) - C:\Users\Tyson\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-05-13] Discord (HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\Discord) (Version: 1.0.9004 - Discord Inc.) Task: {8B5D0AB1-09DB-4A6C-B739-540592774668} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Processor => C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin\SymErr.exe [91048 2022-02-25] (Symantec Corporation -> Broadcom) Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.32.31326 (HKLM-x32\\{817e21c1-6b3a-4bc1-8c49-67e4e1887b3a}) (Version: 14.32.31326.0 - Microsoft Corporation) All Rights Reserved. IFEO\WaaSMedic.exe: [Debugger] / Addr 192.168.0.238 HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\StartupApproved\Run: => "EpicGamesLauncher" Microsoft Office Professional Plus 2021 - en-us (HKLM\\ProPlus2021Retail - en-us) (Version: 16.0.15028.20160 - Microsoft Corporation) FirewallRules: [{7022D65E-DCEC-471F-B498-E78E42FF448E}] => (Allow) C:\Program Files\Oculus\Support\oculus-dash\dash\bin\OculusDash.exe (Oculus VR, LLC -> ) Total physical RAM: 32541.47 MB FirewallRules: [TCP Query User{2F29BC3A-D5D6-447D-BDFC-4B124ACDD023}C:\users\tyson\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\tyson\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.32.31326 (HKLM-x32\\{817e21c1-6b3a-4bc1-8c49-67e4e1887b3a}) (Version: 14.32.31326.0 - Microsoft Corporation) S3 logi_generic_hid_filter; C:\windows\system32\drivers\logi_generic_hid_filter.sys [51544 2022-05-13] (WDKTestCert builder,132743893872553407 -> Logitech) R2 SepScanService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\bin64\ccSvcHst.exe [191912 2022-02-25] (Symantec Corporation -> Broadcom) ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Tyson\AppData\Local\MEGAsync\ShellExtX64.dll [2022-06-11] (Mega Limited -> ) 2022-08-31 01:24 - 2022-05-25 01:10 - 000003496 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineUA{52819A4A-6F97-4F51-A9DF-F8722C17E431} 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\SysWOW64\vi-VN Task: {8B25E595-94B3-455C-A6D1-4938F6A5B6E4} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-05-05] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\lt-LT HKLM\\Print\Monitors\Adobe PDF Port Monitor: C:\windows\system32\AdobePDF.dll [203936 2022-08-03] (Adobe Inc. -> Adobe Systems Inc) FirewallRules: [{633B0085-9A80-4E60-BFD6-BD3739789698}] => (Allow) D:\Steam\SteamApps\common\ELDEN RING\Game\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\NisSrv.exe [2876152 2022-01-03] (Microsoft Windows Publisher -> Microsoft Corporation) FirewallRules: [{CFBB8357-8F2F-4B75-BA39-D2D9465A4522}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) Task: {658C5A85-0FD8-4A07-B8D2-05DD4D62B7DA} - System32\Tasks\GoogleUpdateTaskMachineUA{52819A4A-6F97-4F51-A9DF-F8722C17E431} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [168632 2022-05-25] (Google LLC -> Google LLC) 2022-08-22 04:13 - 2022-08-22 04:14 - 000000000 ____D C:\ProgramData\Corsair 2022-08-31 20:09 - 2022-09-01 04:04 - 000001148 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder 2022.lnk AAAA 2001:8003:3A5B:C700:0000:0000:0000:0F40 Bonjour (HKLM\\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) (If an entry is included in the fixlist, it will be removed.) (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe <2> discord snake high score. (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe In order to move the snake, you can either use the arrow keys or else the W, A, S, and D keys instead. HKLM\\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) FirewallRules: [UDP Query User{DB96153B-F152-4C00-927D-9BBEDAD466F0}C:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games) R3 iaLPSS2_I2C_ADL; C:\windows\System32\DriverStore\FileRepository\ialpss2_i2c_adl.inf_amd64_778b19a5f4d49cba\iaLPSS2_I2C_ADL.sys [202896 2021-07-29] (Intel Corporation -> Intel Corporation) 2022-09-01 05:48 - 2022-05-13 20:35 - 000000000 ____D C:\ProgramData\Riot Games 2022-09-04 01:01 - 2022-09-04 01:01 - 000001970 _____ C:\Users\Public\Desktop\Streamlabs Desktop.lnk Make sure that your device volume is turned on. 2022-09-13 06:48 - 2022-09-13 06:48 - 000299008 _____ C:\windows\system32\EsclScan.dll HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\Run: [EpicGamesLauncher] => D:\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32686032 2022-09-15] (Epic Games Inc. -> Epic Games, Inc.) -> ) FirewallRules: [UDP - Installer for ACDSee Commander Ultimate 2022] => (Allow) C:\Program Files\ACD Systems\ACDSee Ultimate\15.0\ACDSeeCommanderUltimate15.exe => No File 2022-08-22 04:13 - 2022-08-22 04:13 - 000000000 ____D C:\Program Files\Corsair HKLM\\Run: [] => [X] 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\ShellComponents 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\bcastdvr 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\bcastdvr ========= End of CMD: ========= R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [239544 2022-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) Error: (09/21/2022 08:32:49 AM) (Source: OVRServiceLauncher) (EventID: 0) (User: ) BIOS: American Megatrends International, LLC. 2022-09-13 06:48 - 2022-09-13 06:48 - 000470528 _____ (curl, hxxps://curl.se/) C:\windows\SysWOW64\curl.exe 2022-08-31 20:09 - 2022-09-01 04:04 - 000001148 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder 2022.lnk 2022-09-04 01:01 - 2022-09-21 08:29 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\slobs-client The error: 2022-09-13 06:56 - 2021-06-06 00:30 - 000000000 ____D C:\Program Files\Windows Photo Viewer (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUE.exe keep playing and try to beat your previous scores. IFEO\SppExtComObj.exe: [VerifierDlls] SppExtComObjHook.dll S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934368 2022-03-03] (Epic Games Inc. -> Epic Games, Inc.) Can you beat it? Resetting Route, OK! . Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation) 2022-08-25 16:41 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\NDF Task: {1DB34F4D-B0C1-4082-887A-B17E2907C476} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-05-05] (Nvidia Corporation -> NVIDIA Corporation) Resetting Subinterface, OK! 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\ShellComponents Malwarebytes version 4.5.14.210 (HKLM\\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.14.210 - Malwarebytes) you can put up Snake related art or any art. Task: {1903FCFD-CF35-4771-9F43-60AE3B50151B} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332 (HKLM\\{3407B900-37F5-4CC2-B612-5CD5D580A163}) (Version: 14.32.31332 - Microsoft Corporation) Hidden HKLM\\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [3071192 2022-08-18] (Riot Games, Inc. -> Riot Games, Inc.) HKLM\\Print\Monitors\Adobe PDF Port Monitor: C:\windows\system32\AdobePDF.dll [203936 2022-08-03] (Adobe Inc. -> Adobe Systems Inc) NVIDIA HD Audio Driver 1.3.39.14 (HKLM\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.39.14 - NVIDIA Corporation) R2 TeraCopyService.exe; C:\Program Files\TeraCopy\TeraCopyService.exe [114384 2021-04-22] (Code Sector -> ) 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\appraiser RealNacho1! CHR Extension: (Dark Reader) - C:\Users\Tyson\AppData\Local\Google\Chrome\User Data\Default\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2022-08-24] ==================== End of FRST.txt ========================. A place that makes it easy to talk every day and hang out more often. ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-09-07] (Adobe Inc. -> ) ContextMenuHandlers1: [LDVPMenu] -> {8BEEE74D-455E-4616-A97A-F6E86C317F32} => C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin64\vpshell2.dll [2022-02-25] (Symantec Corporation -> Broadcom) AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk:B026C77744 [3442] (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <13> keeps me and my friends online for hours. 2022-09-03 23:15 - 2022-09-04 01:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio 2022-09-21 08:06 - 2022-05-13 20:49 - 000000000 ____D C:\Steam End:: Intel Wireless Bluetooth (HKLM-x32\\{00001080-0220-1033-84C8-B8D95FA3C8C3}) (Version: 22.80.1.1 - Intel Corporation) (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe (services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe The welcome screen then shows up, including some super cute and amazing artwork! Description: Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation) (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. FirewallRules: [{5E55447F-1E66-4E0F-9634-BC53363E5B06}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed] Make sure to let me know as I'm always on the lookout for new ones! 2022-09-20 21:38 - 2022-05-13 18:02 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\vlc Error: (09/18/2022 11:28:17 PM) (Source: Bonjour Service) (EventID: 100) (User: ) FirewallRules: [TCP Query User{B29CB122-F27F-4DFE-B63F-BB985EDAA1B3}C:\program files\lghub\lghub_agent.exe] => (Allow) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom.lnk:BCD3E320D4 [3442] 2022-09-01 04:02 - 2022-05-13 20:38 - 000000000 ____D C:\Program Files\Riot Vanguard FirewallRules: [{BA49AD7D-9BA0-447E-B5CF-78D7EA91231D}] => (Allow) D:\BsgLauncher\BsgLauncher.exe (BATTLESTATE GAMES LIMITED -> Battlestate Games) FirewallRules: [{D9AD2616-687D-4831-809B-DADF4BDF4447}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe (Valve Corp. -> ) This pack is made for 0 Venom Snake 0 SCPD Mega Pack:. 2022-08-24 16:24 - 2022-08-24 16:24 - 000000613 _____ C:\Users\Public\Desktop\Battlestate Games Launcher.lnk HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ccSettings_{BEC9211B-09AC-4B5B-9D31-561ADFF81A33}.sys => ""="Driver" The welcome screen, featuring amazing artwork! FirewallRules: [TCP Query User{54CEA6F6-91B3-45B9-982F-72B6FC47EA15}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) OK, please do this. 2022-01-10 20:28 - 2022-04-07 19:15 - 000693888 _____ (Stanislav Zinukhov -> www.startisback.com) [File not signed] C:\Program Files\StartAllBack\StartAllBackX64.dll Microsoft Edge WebView2 Runtime (HKLM-x32\\Microsoft EdgeWebView) (Version: 105.0.1343.42 - Microsoft Corporation) Resetting Anycast Address, OK! ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-09-07] (Adobe Inc. -> ) 2022-08-30 07:23 - 2022-08-30 07:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft DirectX SDK (June 2010) Error: (09/20/2022 03:10:47 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Can you beat it? AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects 2022.lnk:F7B133A22A [3442] HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SihClient.exe => removed successfully (C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe 2022-09-13 06:56 - 2021-06-06 00:30 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer F8d 04/27/2022 2022-08-22 04:13 - 2022-07-08 17:37 - 000610352 _____ (Corsair Memory, Inc.) C:\windows\system32\CorsairGamingAudioCfgService64.exe ==================== End of FRST.txt ========================, ==================== Accounts: ============================= 2022-09-18 10:29 - 2022-05-25 01:10 - 000002212 _____ C:\Users\Public\Desktop\Google Chrome.lnk Task: {0F07B63F-7BBC-4F1F-BF1F-9D28D3EE4A4E} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-479614032-2295716511-2174497491-1002 => C:\Users\Tyson\AppData\Local\MEGAsync\MEGAupdater.exe [2531496 2022-06-11] (Mega Limited -> ) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2022-08-03] (Adobe Inc. -> Adobe Systems Incorporated) R0 SymEFASI; C:\windows\System32\drivers\symefasi\0704030.013\symefasi64.sys [2080248 2022-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\MountPoints2: {92a2dbf0-b485-11ec-8593-709cd154a389} - "G:\Office Tool Plus.exe" 2022-06-27 00:22 - 2022-06-27 00:22 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll (Code 22) (services.exe ->) (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Windows\System32\GigabyteUpdateService.exe Administrator (S-1-5-21-479614032-2295716511-2174497491-500 - Administrator - Disabled) 2022-09-21 08:33 - 2022-05-16 15:19 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\Rainmeter It is an almost impossible task to reach this score, however. FireFox: Task: {BFA77813-7905-4415-9C63-4ED3A2A5BBE4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8338896 2022-04-05] (Microsoft Corporation -> Microsoft Corporation) S3 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin64\snac64.exe [215648 2022-02-25] (Symantec Corporation -> Broadcom) Microsoft Visual C++ 2022 X86 Additional Runtime - 14.32.31326 (HKLM-x32\\{A250E750-DB3F-40C1-8460-8EF77C7582DA}) (Version: 14.32.31326 - Microsoft Corporation) Hidden FirewallRules: [{9A674005-76ED-49FE-B5D9-BD89D27E7EAA}] => (Allow) D:\Steam\SteamApps\common\Aim Lab\AimLab_tb.exe () [File not signed] 2. 2022-09-21 00:31 - 2022-05-24 21:45 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\discord 2022-09-19 00:36 - 2022-09-19 00:36 - 000000000 ____D C:\Users\Tyson\AppData\LocalLow\Oculus 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\SysWOW64\ca-ES Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.13.5310.0_x64__8wekyb3d8bbwe [2022-06-13] (Microsoft Studios) [MS Ad] Is your Windows properly activated and do you have a valid license? 2022-09-13 06:48 - 2022-09-13 06:48 - 000485376 _____ (Microsoft Corporation) C:\windows\SysWOW64\PhotoScreensaver.scr 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\vi-VN 2022-09-13 06:48 - 2022-09-13 06:48 - 000057344 _____ C:\windows\system32\uwfservicingapi.dll HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION 2022-09-21 08:33 - 2021-06-05 22:10 - 000000000 ____D C:\windows\AppReadiness 2022-09-13 06:48 - 2022-09-13 06:48 - 000299008 _____ C:\windows\system32\EsclScan.dll FF Extension: (Dark space - The best dynamic theme) - C:\Users\Tyson\AppData\Roaming\Mozilla\Firefox\Profiles\xnc3cpuf.default-release\Extensions\{22b0eca1-8c02-4c0d-a5d7-6604ddd9836e}.xpi [2022-09-13]