Just as the title says, for the past few days, my computer has been acting weird. There's a chance that it is noting and that it's just hardware related problems, but I just want to be sure.
FRST log
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-11-2020
Ran by quoih (administrator) on DESKTOP-RGPP5SJ (Gigabyte Technology Co., Ltd. B450M DS3H) (30-11-2020 15:51:28)
Running from C:\Users\quoih\Downloads
Loaded Profiles: quoih
Platform: Windows 10 Pro Version 2004 19041.630 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0346830.inf_amd64_35731e557194973d\B345901\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0346830.inf_amd64_35731e557194973d\B345901\atiesrxx.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <13>
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\quoih\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\quoih\AppData\Local\Microsoft\Teams\current\Teams.exe <9>
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_2.2011.11613.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\commsapps.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2010.7-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2010.7-0\NisSrv.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [856288 2019-10-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [100580600 2020-08-04] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3883136046-2417711927-3391061525-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\quoih\AppData\Local\Microsoft\Teams\Update.exe [2453688 2020-11-22] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3883136046-2417711927-3391061525-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [33131408 2020-11-24] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-3883136046-2417711927-3391061525-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3424032 2020-10-28] (Valve -> Valve Corporation)
HKU\S-1-5-18\...\Run: [] => [X]
HKLM\...\Print\Monitors\HP E311 Status Monitor: C:\Windows\system32\hpinkstsE311LM.dll [392200 2019-03-15] (HP Inc -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\86.0.4240.198\Installer\chrmstp.exe [2020-11-16] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {15766335-F02F-4FEE-8FC7-74D0D92883F9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-09-30] (Google LLC -> Google LLC)
Task: {2BCC60C7-3D44-47CC-B73A-3339721F38CF} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939528 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {36A4A1A6-0DDD-4498-9F22-D12F84291FDD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MpCmdRun.exe [541576 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3821916F-D607-4523-9DEB-B4E80A170B2A} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\quoih\Downloads\esetonlinescanner.exe
Task: {631E5E29-8502-4C50-961A-6DD1FC4EA222} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144744 2020-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {6C7A1A5B-6556-423A-A90D-0BDA75671429} - System32\Tasks\Agent Activation Runtime\S-1-5-21-3883136046-2417711927-3391061525-1001 => C:\Windows\System32\AgentActivationRuntimeStarter.exe [13312 2020-10-16] (Microsoft Windows -> )
Task: {7CDBA46C-EA57-4BE0-98E9-2CF992208565} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144744 2020-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {98AD4DD4-C59D-4C19-A370-55F9DC0BCC3D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5153176 2020-10-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {9CC4A705-8657-4ED1-9835-D11238C3128D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939528 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {A27B9162-2127-4083-86E5-B3F52ED1886A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MpCmdRun.exe [541576 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CC59EB1F-2A4B-4421-8B9F-294886AB4DEF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-09-30] (Google LLC -> Google LLC)
Task: {E9BBDDCE-1E0C-4CEE-940D-09A80C618650} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5153176 2020-10-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {EA1BF631-4EA5-4E40-AD88-2664A41DFA67} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MpCmdRun.exe [541576 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F984BCC3-C502-4C3E-AFE1-7EA0C392C360} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MpCmdRun.exe [541576 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{1e8ea9cb-f807-4fb2-9c45-29d4a2e46527}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{9123a897-e22e-4573-815d-dff3eabe552b}: [DhcpNameServer] 192.168.0.1
Edge:
======
Edge DefaultProfile: Default
Edge Profile: C:\Users\quoih\AppData\Local\Microsoft\Edge\User Data\Default [2020-11-11]
Edge Extension: (Outlook) - C:\Users\quoih\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjhmmnoficofgoiacjaajpkfndojknpb [2020-11-07]
Edge Extension: (Word) - C:\Users\quoih\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hikhggiobiflkdfdgdajcfklmcibbopi [2020-11-07]
Edge Extension: (Excel) - C:\Users\quoih\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\leffmjdabcgaflkikcefahmlgpodjkdm [2020-11-07]
Edge Extension: (PowerPoint) - C:\Users\quoih\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\opfacbhaojodjaojgocnibmklknchehf [2020-11-07]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-09-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-09-30] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR Profile: C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default [2020-11-30]
CHR DownloadDir: C:\Users\quoih\Downloads
CHR Extension: (Charcoal: Dark Mode for Messenger) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaekanoannlhnajolbijaoflfhikcgng [2020-11-23]
CHR Extension: (Slides) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-09-30]
CHR Extension: (Just Black) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\aghfnjkcakhmadgdomlmlhhaocbkloab [2020-09-30]
CHR Extension: (Docs) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-09-30]
CHR Extension: (Google Drive) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-21]
CHR Extension: (YouTube) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-09-30]
CHR Extension: (uBlock Origin) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2020-11-29]
CHR Extension: (Timer) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\edebbhkhcaafmolanelponjjanocpacd [2020-09-30]
CHR Extension: (Dark Reader) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2020-11-26]
CHR Extension: (Sheets) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-09-30]
CHR Extension: (Word Online) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2020-09-30]
CHR Extension: (Google Docs Offline) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-17]
CHR Extension: (Google Play) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2020-09-30]
CHR Extension: (Google Keep Chrome Extension) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2020-11-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-09-30]
CHR Extension: (Gmail) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
CHR Extension: (Chrome Media Router) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-14]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8895512 2020-11-27] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9057136 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7269976 2020-11-06] (Malwarebytes Inc -> Malwarebytes)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5101992 2020-11-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\NisSrv.exe [2467088 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MsMpEng.exe [128376 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [217600 2020-11-06] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [19912 2020-11-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-11-25] (Malwarebytes Inc -> Malwarebytes)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [48536 2020-11-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [429288 2020-11-06] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [71912 2020-11-06] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-30 15:51 - 2020-11-30 15:51 - 000015668 _____ C:\Users\quoih\Downloads\FRST.txt
2020-11-30 15:48 - 2020-11-30 15:51 - 000000000 ____D C:\FRST
2020-11-30 15:47 - 2020-11-30 15:47 - 002290176 _____ (Farbar) C:\Users\quoih\Downloads\FRST64.exe
2020-11-27 12:09 - 2020-11-27 12:09 - 002502037 _____ C:\Users\quoih\Downloads\RapportPhys.pdf
2020-11-26 13:52 - 2020-11-27 09:00 - 000844172 _____ C:\Users\quoih\Downloads\Soviet Invasion of Afghanistan (1979-1989).pptx
2020-11-25 13:07 - 2020-11-25 13:16 - 000284124 _____ C:\Users\quoih\Downloads\Anaglyphe- kenHo- Modifiable.xlsx
2020-11-25 12:44 - 2020-11-27 11:57 - 000032069 _____ C:\Users\quoih\Downloads\Physique.xlsx
2020-11-24 15:32 - 2020-11-24 15:32 - 000000112 ___SH C:\bootTel.dat
2020-11-21 16:44 - 2020-11-21 16:44 - 000000000 ____D C:\Users\quoih\AppData\Local\Frontier_Developments
2020-11-20 14:08 - 2020-11-20 14:08 - 000047786 _____ C:\Users\quoih\Downloads\questionnaire_interpretation_pensees_TOC.pdf
2020-11-18 14:08 - 2020-11-18 14:08 - 000000000 ____D C:\Users\quoih\Downloads\2020-11-18_140805
2020-11-18 14:07 - 2020-11-18 14:07 - 002690065 _____ C:\Users\quoih\Downloads\ken_MathExam.pdf
2020-11-17 12:39 - 2020-11-21 16:55 - 000001229 _____ C:\Users\quoih\Downloads\MaBylog.txt
2020-11-13 13:37 - 2020-11-13 13:37 - 000001229 _____ C:\Users\quoih\Downloads\MBblog.txt
2020-11-13 09:27 - 2020-11-13 09:27 - 000098012 _____ C:\Users\quoih\Downloads\texte_explicatif_TOC.pdf
2020-11-13 09:26 - 2020-11-13 09:26 - 000363520 _____ C:\Windows\system32\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-11-13 09:26 - 2020-11-13 09:26 - 000266240 _____ C:\Windows\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-11-13 09:26 - 2020-11-13 09:26 - 000197632 _____ C:\Windows\system32\IHDS.dll
2020-11-13 09:26 - 2020-11-13 09:26 - 000152576 _____ C:\Windows\system32\EoAExperiences.exe
2020-11-13 09:26 - 2020-11-13 09:26 - 000009265 _____ C:\Windows\system32\DrtmAuthTxt.wim
2020-11-13 09:17 - 2020-11-13 09:17 - 000000000 _____ C:\Users\quoih\New
2020-11-13 09:11 - 2020-11-13 09:11 - 000430606 _____ C:\Users\quoih\Downloads\Chap9-NYC-a20.pdf
2020-11-12 15:00 - 2020-11-12 15:05 - 000000000 ____D C:\Users\quoih\AppData\Local\Textorcist
2020-11-12 15:00 - 2020-11-12 15:00 - 000000309 _____ C:\Users\quoih\Desktop\The Textorcist.url
2020-11-11 20:48 - 2020-11-11 20:48 - 000381057 _____ C:\Users\quoih\Downloads\Cahier-Elevedevoirpartie2.pdf
2020-11-11 10:20 - 2020-11-11 10:20 - 000000000 ____D C:\Users\quoih\AppData\Roaming\Kalypso Media
2020-11-11 10:20 - 2020-11-11 10:20 - 000000000 ____D C:\Users\quoih\AppData\LocalLow\Realmforge Studios GmbH
2020-11-11 10:20 - 2020-11-11 10:20 - 000000000 ____D C:\Users\quoih\AppData\Local\Kalypso Media
2020-11-11 10:20 - 2020-11-11 10:20 - 000000000 ____D C:\Users\quoih\AppData\Local\Epic Games
2020-11-11 10:17 - 2020-11-11 10:17 - 000000304 _____ C:\Users\quoih\Desktop\Dungeons 3.url
2020-11-11 09:52 - 2020-11-11 09:52 - 000000281 _____ C:\Users\quoih\Desktop\Into The Breach.url
2020-11-10 21:52 - 2020-11-10 21:52 - 000001229 _____ C:\Users\quoih\Downloads\mblog.txt
2020-11-10 18:42 - 2020-11-30 15:46 - 091226112 _____ C:\Windows\system32\config\SOFTWARE
2020-11-10 14:34 - 2020-11-10 14:34 - 000000000 ____D C:\Users\quoih\Documents\Escape from Tarkov
2020-11-10 14:34 - 2020-11-10 14:34 - 000000000 ____D C:\Users\quoih\AppData\LocalLow\Battlestate Games
2020-11-10 11:48 - 2020-11-10 11:48 - 000000000 ____D C:\Users\quoih\.m2
2020-11-10 11:45 - 2020-11-10 11:45 - 000000000 ____D C:\Users\quoih\AppData\Roaming\Teams
2020-11-10 11:22 - 2020-11-26 14:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlestate Games
2020-11-10 11:22 - 2020-11-10 11:25 - 000000000 ____D C:\Battlestate Games
2020-11-10 11:22 - 2020-11-10 11:22 - 000000000 ____D C:\Users\quoih\AppData\Roaming\Battlestate Games
2020-11-10 11:22 - 2020-11-10 11:22 - 000000000 ____D C:\Users\quoih\AppData\Local\Battlestate Games
2020-11-10 11:22 - 2020-11-10 11:22 - 000000000 ____D C:\ProgramData\Battlestate Games
2020-11-10 11:21 - 2020-11-10 11:21 - 073316360 _____ (Battlestate Games ) C:\Users\quoih\Downloads\BsgLauncher.10.4.1.1205.exe
2020-11-08 12:09 - 2020-11-08 12:09 - 000000000 ____D C:\Users\quoih\AppData\Local\ElevatedDiagnostics
2020-11-07 11:25 - 2020-11-08 13:47 - 000003804 _____ C:\Windows\system32\Tasks\EOSv3 Scheduler onLogOn
2020-11-07 10:37 - 2020-11-07 10:37 - 000002920 _____ C:\Users\quoih\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2020-11-07 10:37 - 2020-11-07 10:37 - 000002914 _____ C:\Users\quoih\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2020-11-07 10:37 - 2020-11-07 10:37 - 000002910 _____ C:\Users\quoih\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2020-11-07 10:37 - 2020-11-07 10:37 - 000002908 _____ C:\Users\quoih\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Word.lnk
2020-11-07 10:36 - 2020-11-29 10:48 - 000003480 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-11-07 10:36 - 2020-11-29 10:48 - 000003356 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-11-07 10:36 - 2020-11-25 11:27 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-11-07 10:36 - 2020-11-25 11:27 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-11-07 10:36 - 2020-11-25 11:27 - 000002276 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2020-11-07 09:54 - 2020-11-07 09:54 - 000000000 ____D C:\Windows\system32\appmgmt
2020-11-06 09:57 - 2020-11-25 14:30 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2020-11-06 09:57 - 2020-11-06 09:56 - 000019912 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2020-11-03 10:34 - 2020-11-06 09:57 - 000217600 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2020-10-31 09:00 - 2020-11-01 09:15 - 000000000 ____D C:\Users\quoih\AppData\Local\Steam
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-30 15:49 - 2020-09-30 13:08 - 000795738 _____ C:\Windows\system32\PerfStringBackup.INI
2020-11-30 15:49 - 2019-12-07 04:13 - 000000000 ____D C:\Windows\INF
2020-11-30 15:47 - 2020-10-29 16:49 - 000000000 ____D C:\Program Files (x86)\Steam
2020-11-30 15:47 - 2020-10-06 10:04 - 000000000 ____D C:\Users\quoih\AppData\Local\CrashDumps
2020-11-30 15:46 - 2020-09-30 16:01 - 000008192 ___SH C:\DumpStack.log.tmp
2020-11-30 15:46 - 2020-09-30 16:01 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-11-30 15:46 - 2020-09-30 13:07 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2020-11-30 15:46 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-30 15:46 - 2019-12-07 04:03 - 000786432 _____ C:\Windows\system32\config\BBI
2020-11-30 08:55 - 2020-10-26 07:31 - 000000000 ____D C:\Users\quoih\git
2020-11-30 08:08 - 2020-10-04 11:23 - 000000000 ____D C:\Users\quoih\.p2
2020-11-29 14:50 - 2020-10-04 11:46 - 000000000 ____D C:\Users\quoih\eclipse-workspace
2020-11-27 11:42 - 2020-09-30 16:01 - 000000000 ____D C:\Windows\system32\SleepStudy
2020-11-25 11:27 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-25 11:27 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\AppReadiness
2020-11-24 15:37 - 2019-12-07 04:03 - 000000000 ____D C:\Windows\CbsTemp
2020-11-24 15:28 - 2020-09-30 13:05 - 000000000 ____D C:\Users\quoih
2020-11-23 13:25 - 2020-09-30 13:07 - 000000000 ____D C:\Users\quoih\AppData\Local\Packages
2020-11-22 11:57 - 2020-10-07 15:59 - 000002368 _____ C:\Users\quoih\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-11-22 11:57 - 2020-10-07 15:59 - 000002360 _____ C:\Users\quoih\Desktop\Microsoft Teams.lnk
2020-11-21 16:49 - 2020-10-21 09:59 - 000000000 ____D C:\Program Files\Epic Games
2020-11-20 13:31 - 2020-09-30 13:07 - 000000000 ____D C:\Users\quoih\AppData\Local\D3DSCache
2020-11-18 17:47 - 2020-09-30 13:08 - 000000000 ____D C:\Program Files (x86)\Razer
2020-11-16 16:56 - 2020-09-30 21:48 - 000000000 ____D C:\Users\quoih\AppData\LocalLow\miHoYo
2020-11-16 16:56 - 2020-09-30 17:41 - 000000000 ____D C:\Users\quoih\AppData\Local\miHoYo
2020-11-16 11:44 - 2020-09-30 13:20 - 000002207 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-16 11:44 - 2020-09-30 13:20 - 000002166 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-11-16 11:44 - 2020-09-30 13:20 - 000002166 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-11-14 13:12 - 2020-09-30 17:49 - 000000000 ____D C:\Program Files\Microsoft Office
2020-11-13 09:35 - 2020-09-30 16:01 - 000439016 _____ C:\Windows\system32\FNTCACHE.DAT
2020-11-13 09:34 - 2019-12-07 04:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SystemResources
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\setup
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\oobe
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\migwiz
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\ShellExperiences
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\bcastdvr
2020-11-13 09:26 - 2020-09-30 13:04 - 002876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2020-11-10 18:42 - 2020-09-30 18:24 - 000000000 ____D C:\Windows\Microsoft Antimalware
2020-11-09 17:11 - 2019-12-07 04:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2020-11-08 12:08 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\NDF
2020-11-06 09:57 - 2020-09-30 16:34 - 000001993 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-11-06 09:57 - 2020-09-30 16:34 - 000001981 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-11-06 09:57 - 2020-09-30 16:34 - 000001981 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-11-06 09:56 - 2020-09-30 16:34 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2020-11-06 08:59 - 2020-09-30 16:01 - 000000000 ____D C:\Windows\system32\Drivers\wd
2020-10-31 09:00 - 2020-09-30 13:07 - 000000000 ____D C:\Users\quoih\AppData\Local\AMD
==================== Files in the root of some directories ========
2020-10-30 08:14 - 2020-10-30 08:14 - 000000116 _____ () C:\Users\quoih\AppData\Roaming\debug.log
2020-10-04 18:21 - 2020-10-04 18:21 - 000007602 _____ () C:\Users\quoih\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
FRST log
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-11-2020
Ran by quoih (administrator) on DESKTOP-RGPP5SJ (Gigabyte Technology Co., Ltd. B450M DS3H) (30-11-2020 15:51:28)
Running from C:\Users\quoih\Downloads
Loaded Profiles: quoih
Platform: Windows 10 Pro Version 2004 19041.630 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0346830.inf_amd64_35731e557194973d\B345901\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0346830.inf_amd64_35731e557194973d\B345901\atiesrxx.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <13>
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\quoih\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\quoih\AppData\Local\Microsoft\Teams\current\Teams.exe <9>
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_2.2011.11613.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\commsapps.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13228.41011.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2010.7-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2010.7-0\NisSrv.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [856288 2019-10-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [100580600 2020-08-04] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3883136046-2417711927-3391061525-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\quoih\AppData\Local\Microsoft\Teams\Update.exe [2453688 2020-11-22] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-3883136046-2417711927-3391061525-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [33131408 2020-11-24] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-3883136046-2417711927-3391061525-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3424032 2020-10-28] (Valve -> Valve Corporation)
HKU\S-1-5-18\...\Run: [] => [X]
HKLM\...\Print\Monitors\HP E311 Status Monitor: C:\Windows\system32\hpinkstsE311LM.dll [392200 2019-03-15] (HP Inc -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\86.0.4240.198\Installer\chrmstp.exe [2020-11-16] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {15766335-F02F-4FEE-8FC7-74D0D92883F9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-09-30] (Google LLC -> Google LLC)
Task: {2BCC60C7-3D44-47CC-B73A-3339721F38CF} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939528 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {36A4A1A6-0DDD-4498-9F22-D12F84291FDD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MpCmdRun.exe [541576 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3821916F-D607-4523-9DEB-B4E80A170B2A} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\quoih\Downloads\esetonlinescanner.exe
Task: {631E5E29-8502-4C50-961A-6DD1FC4EA222} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144744 2020-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {6C7A1A5B-6556-423A-A90D-0BDA75671429} - System32\Tasks\Agent Activation Runtime\S-1-5-21-3883136046-2417711927-3391061525-1001 => C:\Windows\System32\AgentActivationRuntimeStarter.exe [13312 2020-10-16] (Microsoft Windows -> )
Task: {7CDBA46C-EA57-4BE0-98E9-2CF992208565} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144744 2020-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {98AD4DD4-C59D-4C19-A370-55F9DC0BCC3D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5153176 2020-10-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {9CC4A705-8657-4ED1-9835-D11238C3128D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22939528 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {A27B9162-2127-4083-86E5-B3F52ED1886A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MpCmdRun.exe [541576 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CC59EB1F-2A4B-4421-8B9F-294886AB4DEF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-09-30] (Google LLC -> Google LLC)
Task: {E9BBDDCE-1E0C-4CEE-940D-09A80C618650} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5153176 2020-10-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {EA1BF631-4EA5-4E40-AD88-2664A41DFA67} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MpCmdRun.exe [541576 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F984BCC3-C502-4C3E-AFE1-7EA0C392C360} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MpCmdRun.exe [541576 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{1e8ea9cb-f807-4fb2-9c45-29d4a2e46527}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{9123a897-e22e-4573-815d-dff3eabe552b}: [DhcpNameServer] 192.168.0.1
Edge:
======
Edge DefaultProfile: Default
Edge Profile: C:\Users\quoih\AppData\Local\Microsoft\Edge\User Data\Default [2020-11-11]
Edge Extension: (Outlook) - C:\Users\quoih\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjhmmnoficofgoiacjaajpkfndojknpb [2020-11-07]
Edge Extension: (Word) - C:\Users\quoih\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hikhggiobiflkdfdgdajcfklmcibbopi [2020-11-07]
Edge Extension: (Excel) - C:\Users\quoih\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\leffmjdabcgaflkikcefahmlgpodjkdm [2020-11-07]
Edge Extension: (PowerPoint) - C:\Users\quoih\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\opfacbhaojodjaojgocnibmklknchehf [2020-11-07]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-09-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-09-30] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR Profile: C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default [2020-11-30]
CHR DownloadDir: C:\Users\quoih\Downloads
CHR Extension: (Charcoal: Dark Mode for Messenger) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaekanoannlhnajolbijaoflfhikcgng [2020-11-23]
CHR Extension: (Slides) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-09-30]
CHR Extension: (Just Black) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\aghfnjkcakhmadgdomlmlhhaocbkloab [2020-09-30]
CHR Extension: (Docs) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-09-30]
CHR Extension: (Google Drive) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-21]
CHR Extension: (YouTube) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-09-30]
CHR Extension: (uBlock Origin) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2020-11-29]
CHR Extension: (Timer) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\edebbhkhcaafmolanelponjjanocpacd [2020-09-30]
CHR Extension: (Dark Reader) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2020-11-26]
CHR Extension: (Sheets) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-09-30]
CHR Extension: (Word Online) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2020-09-30]
CHR Extension: (Google Docs Offline) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-17]
CHR Extension: (Google Play) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2020-09-30]
CHR Extension: (Google Keep Chrome Extension) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2020-11-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-09-30]
CHR Extension: (Gmail) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
CHR Extension: (Chrome Media Router) - C:\Users\quoih\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-14]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8895512 2020-11-27] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9057136 2020-11-04] (Microsoft Corporation -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7269976 2020-11-06] (Malwarebytes Inc -> Malwarebytes)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5101992 2020-11-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\NisSrv.exe [2467088 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MsMpEng.exe [128376 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [217600 2020-11-06] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [19912 2020-11-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-11-25] (Malwarebytes Inc -> Malwarebytes)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [48536 2020-11-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [429288 2020-11-06] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [71912 2020-11-06] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-30 15:51 - 2020-11-30 15:51 - 000015668 _____ C:\Users\quoih\Downloads\FRST.txt
2020-11-30 15:48 - 2020-11-30 15:51 - 000000000 ____D C:\FRST
2020-11-30 15:47 - 2020-11-30 15:47 - 002290176 _____ (Farbar) C:\Users\quoih\Downloads\FRST64.exe
2020-11-27 12:09 - 2020-11-27 12:09 - 002502037 _____ C:\Users\quoih\Downloads\RapportPhys.pdf
2020-11-26 13:52 - 2020-11-27 09:00 - 000844172 _____ C:\Users\quoih\Downloads\Soviet Invasion of Afghanistan (1979-1989).pptx
2020-11-25 13:07 - 2020-11-25 13:16 - 000284124 _____ C:\Users\quoih\Downloads\Anaglyphe- kenHo- Modifiable.xlsx
2020-11-25 12:44 - 2020-11-27 11:57 - 000032069 _____ C:\Users\quoih\Downloads\Physique.xlsx
2020-11-24 15:32 - 2020-11-24 15:32 - 000000112 ___SH C:\bootTel.dat
2020-11-21 16:44 - 2020-11-21 16:44 - 000000000 ____D C:\Users\quoih\AppData\Local\Frontier_Developments
2020-11-20 14:08 - 2020-11-20 14:08 - 000047786 _____ C:\Users\quoih\Downloads\questionnaire_interpretation_pensees_TOC.pdf
2020-11-18 14:08 - 2020-11-18 14:08 - 000000000 ____D C:\Users\quoih\Downloads\2020-11-18_140805
2020-11-18 14:07 - 2020-11-18 14:07 - 002690065 _____ C:\Users\quoih\Downloads\ken_MathExam.pdf
2020-11-17 12:39 - 2020-11-21 16:55 - 000001229 _____ C:\Users\quoih\Downloads\MaBylog.txt
2020-11-13 13:37 - 2020-11-13 13:37 - 000001229 _____ C:\Users\quoih\Downloads\MBblog.txt
2020-11-13 09:27 - 2020-11-13 09:27 - 000098012 _____ C:\Users\quoih\Downloads\texte_explicatif_TOC.pdf
2020-11-13 09:26 - 2020-11-13 09:26 - 000363520 _____ C:\Windows\system32\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-11-13 09:26 - 2020-11-13 09:26 - 000266240 _____ C:\Windows\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-11-13 09:26 - 2020-11-13 09:26 - 000197632 _____ C:\Windows\system32\IHDS.dll
2020-11-13 09:26 - 2020-11-13 09:26 - 000152576 _____ C:\Windows\system32\EoAExperiences.exe
2020-11-13 09:26 - 2020-11-13 09:26 - 000009265 _____ C:\Windows\system32\DrtmAuthTxt.wim
2020-11-13 09:17 - 2020-11-13 09:17 - 000000000 _____ C:\Users\quoih\New
2020-11-13 09:11 - 2020-11-13 09:11 - 000430606 _____ C:\Users\quoih\Downloads\Chap9-NYC-a20.pdf
2020-11-12 15:00 - 2020-11-12 15:05 - 000000000 ____D C:\Users\quoih\AppData\Local\Textorcist
2020-11-12 15:00 - 2020-11-12 15:00 - 000000309 _____ C:\Users\quoih\Desktop\The Textorcist.url
2020-11-11 20:48 - 2020-11-11 20:48 - 000381057 _____ C:\Users\quoih\Downloads\Cahier-Elevedevoirpartie2.pdf
2020-11-11 10:20 - 2020-11-11 10:20 - 000000000 ____D C:\Users\quoih\AppData\Roaming\Kalypso Media
2020-11-11 10:20 - 2020-11-11 10:20 - 000000000 ____D C:\Users\quoih\AppData\LocalLow\Realmforge Studios GmbH
2020-11-11 10:20 - 2020-11-11 10:20 - 000000000 ____D C:\Users\quoih\AppData\Local\Kalypso Media
2020-11-11 10:20 - 2020-11-11 10:20 - 000000000 ____D C:\Users\quoih\AppData\Local\Epic Games
2020-11-11 10:17 - 2020-11-11 10:17 - 000000304 _____ C:\Users\quoih\Desktop\Dungeons 3.url
2020-11-11 09:52 - 2020-11-11 09:52 - 000000281 _____ C:\Users\quoih\Desktop\Into The Breach.url
2020-11-10 21:52 - 2020-11-10 21:52 - 000001229 _____ C:\Users\quoih\Downloads\mblog.txt
2020-11-10 18:42 - 2020-11-30 15:46 - 091226112 _____ C:\Windows\system32\config\SOFTWARE
2020-11-10 14:34 - 2020-11-10 14:34 - 000000000 ____D C:\Users\quoih\Documents\Escape from Tarkov
2020-11-10 14:34 - 2020-11-10 14:34 - 000000000 ____D C:\Users\quoih\AppData\LocalLow\Battlestate Games
2020-11-10 11:48 - 2020-11-10 11:48 - 000000000 ____D C:\Users\quoih\.m2
2020-11-10 11:45 - 2020-11-10 11:45 - 000000000 ____D C:\Users\quoih\AppData\Roaming\Teams
2020-11-10 11:22 - 2020-11-26 14:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlestate Games
2020-11-10 11:22 - 2020-11-10 11:25 - 000000000 ____D C:\Battlestate Games
2020-11-10 11:22 - 2020-11-10 11:22 - 000000000 ____D C:\Users\quoih\AppData\Roaming\Battlestate Games
2020-11-10 11:22 - 2020-11-10 11:22 - 000000000 ____D C:\Users\quoih\AppData\Local\Battlestate Games
2020-11-10 11:22 - 2020-11-10 11:22 - 000000000 ____D C:\ProgramData\Battlestate Games
2020-11-10 11:21 - 2020-11-10 11:21 - 073316360 _____ (Battlestate Games ) C:\Users\quoih\Downloads\BsgLauncher.10.4.1.1205.exe
2020-11-08 12:09 - 2020-11-08 12:09 - 000000000 ____D C:\Users\quoih\AppData\Local\ElevatedDiagnostics
2020-11-07 11:25 - 2020-11-08 13:47 - 000003804 _____ C:\Windows\system32\Tasks\EOSv3 Scheduler onLogOn
2020-11-07 10:37 - 2020-11-07 10:37 - 000002920 _____ C:\Users\quoih\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2020-11-07 10:37 - 2020-11-07 10:37 - 000002914 _____ C:\Users\quoih\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2020-11-07 10:37 - 2020-11-07 10:37 - 000002910 _____ C:\Users\quoih\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2020-11-07 10:37 - 2020-11-07 10:37 - 000002908 _____ C:\Users\quoih\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Word.lnk
2020-11-07 10:36 - 2020-11-29 10:48 - 000003480 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-11-07 10:36 - 2020-11-29 10:48 - 000003356 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-11-07 10:36 - 2020-11-25 11:27 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-11-07 10:36 - 2020-11-25 11:27 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-11-07 10:36 - 2020-11-25 11:27 - 000002276 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2020-11-07 09:54 - 2020-11-07 09:54 - 000000000 ____D C:\Windows\system32\appmgmt
2020-11-06 09:57 - 2020-11-25 14:30 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2020-11-06 09:57 - 2020-11-06 09:56 - 000019912 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2020-11-03 10:34 - 2020-11-06 09:57 - 000217600 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2020-10-31 09:00 - 2020-11-01 09:15 - 000000000 ____D C:\Users\quoih\AppData\Local\Steam
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-30 15:49 - 2020-09-30 13:08 - 000795738 _____ C:\Windows\system32\PerfStringBackup.INI
2020-11-30 15:49 - 2019-12-07 04:13 - 000000000 ____D C:\Windows\INF
2020-11-30 15:47 - 2020-10-29 16:49 - 000000000 ____D C:\Program Files (x86)\Steam
2020-11-30 15:47 - 2020-10-06 10:04 - 000000000 ____D C:\Users\quoih\AppData\Local\CrashDumps
2020-11-30 15:46 - 2020-09-30 16:01 - 000008192 ___SH C:\DumpStack.log.tmp
2020-11-30 15:46 - 2020-09-30 16:01 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-11-30 15:46 - 2020-09-30 13:07 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2020-11-30 15:46 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-30 15:46 - 2019-12-07 04:03 - 000786432 _____ C:\Windows\system32\config\BBI
2020-11-30 08:55 - 2020-10-26 07:31 - 000000000 ____D C:\Users\quoih\git
2020-11-30 08:08 - 2020-10-04 11:23 - 000000000 ____D C:\Users\quoih\.p2
2020-11-29 14:50 - 2020-10-04 11:46 - 000000000 ____D C:\Users\quoih\eclipse-workspace
2020-11-27 11:42 - 2020-09-30 16:01 - 000000000 ____D C:\Windows\system32\SleepStudy
2020-11-25 11:27 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-25 11:27 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\AppReadiness
2020-11-24 15:37 - 2019-12-07 04:03 - 000000000 ____D C:\Windows\CbsTemp
2020-11-24 15:28 - 2020-09-30 13:05 - 000000000 ____D C:\Users\quoih
2020-11-23 13:25 - 2020-09-30 13:07 - 000000000 ____D C:\Users\quoih\AppData\Local\Packages
2020-11-22 11:57 - 2020-10-07 15:59 - 000002368 _____ C:\Users\quoih\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-11-22 11:57 - 2020-10-07 15:59 - 000002360 _____ C:\Users\quoih\Desktop\Microsoft Teams.lnk
2020-11-21 16:49 - 2020-10-21 09:59 - 000000000 ____D C:\Program Files\Epic Games
2020-11-20 13:31 - 2020-09-30 13:07 - 000000000 ____D C:\Users\quoih\AppData\Local\D3DSCache
2020-11-18 17:47 - 2020-09-30 13:08 - 000000000 ____D C:\Program Files (x86)\Razer
2020-11-16 16:56 - 2020-09-30 21:48 - 000000000 ____D C:\Users\quoih\AppData\LocalLow\miHoYo
2020-11-16 16:56 - 2020-09-30 17:41 - 000000000 ____D C:\Users\quoih\AppData\Local\miHoYo
2020-11-16 11:44 - 2020-09-30 13:20 - 000002207 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-16 11:44 - 2020-09-30 13:20 - 000002166 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-11-16 11:44 - 2020-09-30 13:20 - 000002166 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-11-14 13:12 - 2020-09-30 17:49 - 000000000 ____D C:\Program Files\Microsoft Office
2020-11-13 09:35 - 2020-09-30 16:01 - 000439016 _____ C:\Windows\system32\FNTCACHE.DAT
2020-11-13 09:34 - 2019-12-07 04:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SystemResources
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\setup
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\oobe
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\migwiz
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\ShellExperiences
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2020-11-13 09:34 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\bcastdvr
2020-11-13 09:26 - 2020-09-30 13:04 - 002876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2020-11-10 18:42 - 2020-09-30 18:24 - 000000000 ____D C:\Windows\Microsoft Antimalware
2020-11-09 17:11 - 2019-12-07 04:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2020-11-08 12:08 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\NDF
2020-11-06 09:57 - 2020-09-30 16:34 - 000001993 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-11-06 09:57 - 2020-09-30 16:34 - 000001981 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-11-06 09:57 - 2020-09-30 16:34 - 000001981 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-11-06 09:56 - 2020-09-30 16:34 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2020-11-06 08:59 - 2020-09-30 16:01 - 000000000 ____D C:\Windows\system32\Drivers\wd
2020-10-31 09:00 - 2020-09-30 13:07 - 000000000 ____D C:\Users\quoih\AppData\Local\AMD
==================== Files in the root of some directories ========
2020-10-30 08:14 - 2020-10-30 08:14 - 000000116 _____ () C:\Users\quoih\AppData\Roaming\debug.log
2020-10-04 18:21 - 2020-10-04 18:21 - 000007602 _____ () C:\Users\quoih\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================