2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ___RD C:\windows\ImmersiveControlPanel ContextMenuHandlers2: [LDVPMenu] -> {8BEEE74D-455E-4616-A97A-F6E86C317F32} => C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin64\vpshell2.dll [2022-02-25] (Symantec Corporation -> Broadcom) (Code 22) FirewallRules: [{14EE7504-6765-4301-935F-3222337EE46B}] => (Allow) D:\Steam\SteamApps\common\DRAGON BALL FighterZ\DBFighterZ.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) ======= ==================== Custom CLSID (Whitelisted): ============== FirewallRules: [{3EB112F3-D1E8-45BA-B0F2-0DAF7DD6538B}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{6155D014-6B4A-4D23-80B4-714288EEAC9F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{9AB3C1D6-AD2D-4E4F-B29F-13F0B18CA771}] => (Allow) D:\Steam\SteamApps\common\wallpaper_engine\bin\ui32.exe (Skutta, Kristjan -> ) Task: {965F133B-785C-4EF1-BD79-0764AE779AC5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [617096 2022-02-25] (Apple Inc. -> Apple Inc.) FirewallRules: [{129CCC32-5A15-4240-B199-59A11DDCBA6C}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\ElementsPanelDaemon.exe => No File IFEO\osppsvc.exe: [VerifierDlls] SppExtComObjHook.dll FolderExtensions: [] -> {117E3954-5034-453A-A18B-7B79493646E6} => C:\Program Files\StartAllBack\StartAllBackLoaderX64.dll [2022-04-07] (Stanislav Zinukhov -> ) CHR Profile: C:\Users\Tyson\AppData\Local\Google\Chrome\User Data\Default [2022-09-19] funfetti pancake mix cookies discord snake high score. (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe ==================== FirewallRules (Whitelisted) ================ Malwarebytes version 4.5.14.210 (HKLM\\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.14.210 - Malwarebytes) FirewallRules: [UDP Query User{DB96153B-F152-4C00-927D-9BBEDAD466F0}C:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games) Good luck! ==================== Alternate Data Streams (Whitelisted) ======== (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== End of FRST.txt ========================. Task: {D8D5F204-69D4-4A49-A38E-7322C9E98D27} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB" S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [584680 2022-09-13] (EasyAntiCheat Oy -> Epic Games, Inc.) ScoreSaber. The system needed a reboot. Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332 (HKLM\\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}) (Version: 14.32.31332 - Microsoft Corporation) Hidden FiveM (HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\CitizenFX_FiveM) (Version: - Cfx.re) 2022-09-13 06:48 - 2022-09-13 06:48 - 000069632 _____ (Adobe Systems) C:\windows\system32\atmlib.dll 2022-09-15 21:59 - 2022-09-15 21:59 - 000001070 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2022.lnk <==== ATTENTION 2022-08-24 14:34 - 2022-05-13 18:02 - 000000000 ____D C:\Users\Tyson\AppData\Local\Packages (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe ContextMenuHandlers6: [TeraCopy] -> {2386CB87-96FF-473D-A009-957E3BFE6F88} => C:\Program Files\TeraCopy\Context.dll [2021-04-22] (Code Sector -> Code Sector) Press J to jump to the feed. (If an entry is included in the fixlist, the registry item will be restored to default or removed. HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\Run: [EpicGamesLauncher] => D:\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32686032 2022-09-15] (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [{CC83CFDA-11EF-408C-A403-34F509C339E6}] => (Allow) D:\Steam\SteamApps\common\VRChat\launch.exe () [File not signed] FirewallRules: [UDP Query User{ABD0FEC5-FD03-416C-8BE7-242C0CB68220}D:\steam\steamapps\common\naruto to boruto\naruto\binaries\win64\naruto-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\naruto to boruto\naruto\binaries\win64\naruto-win64-shipping.exe => No File S3 USBAAPL64; C:\windows\System32\Drivers\usbaapl64.sys [54784 2022-01-07] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) ==================== Safe Mode (Whitelisted) ================== FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-09-08] (Adobe Inc. -> Adobe Systems Inc.) Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 4 InWin809.local. 2022-08-24 16:24 - 2022-08-24 16:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlestate Games A wall spawns every other apple eaten, starting on the first apple. 2022-09-18 23:40 - 2022-09-21 08:37 - 000000000 ____D C:\FRST Microsoft .NET Host - 6.0.6 (x64) (HKLM\\{F48FB46C-3334-47AA-98ED-D5A47DED33F1}) (Version: 48.27.42327 - Microsoft Corporation) Hidden Happened while starting this command: FirewallRules: [{D1CB192D-76D5-4997-A65D-7C9246999244}] => (Allow) D:\Steam\SteamApps\common\Blade & Sorcery\BladeAndSorcery.exe () [File not signed] 2022-09-13 06:48 - 2022-09-13 06:48 - 000530944 _____ (curl, hxxps://curl.se/) C:\windows\system32\curl.exe FirewallRules: [{BDBA3A23-D454-4277-921A-7ED6DB453E47}] => (Allow) D:\Steam\SteamApps\common\wallpaper_engine\launcher.exe (Skutta, Kristjan -> ) 2022-09-04 01:01 - 2022-09-04 01:01 - 000001982 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Streamlabs Desktop.lnk Task: {EBB94CF2-C9D4-41C0-A9B1-E47647F2DE6B} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-479614032-2295716511-2174497491-500 => C:\Users\Tyson\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) R3 rt25cx21; C:\windows\System32\DriverStore\FileRepository\rt25cx21x64.inf_amd64_447a9570dbb12464\rt25cx21x64.sys [620456 2022-03-25] (Realtek Semiconductor Corp. -> Realtek) (Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe 2022-09-09 23:18 - 2022-05-16 15:19 - 000000000 ____D C:\Program Files\Rainmeter S3 logi_joy_hid_lo; C:\windows\system32\drivers\logi_joy_hid_lo.sys [41280 2022-05-13] (WDKTestCert builder,132743893872553407 -> Logitech) Description: Local Hostname InWin809.local already in use; will try InWin809-2.local instead AlternateDataStreams: C:\Users\All Users:err [1670] HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\MountPoints2: {92a2dbf0-b485-11ec-8593-709cd154a389} - "G:\Office Tool Plus.exe" While you are here, be sure to find out which are the best music bots that are still working, as well as the best Game bots and moderation bots to use. NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-09-12] (NVIDIA Corp.) FF DefaultProfile: 9c4tsxuk.default (If an entry is included in the fixlist, the task (.job) file will be moved. 2022-09-15 21:55 - 2022-05-24 21:19 - 000000000 ____D C:\Program Files\Common Files\Adobe 2022-08-27 01:04 - 2022-08-27 01:04 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\Paradox Interactive 2022-08-22 04:14 - 2022-08-22 04:14 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\Corsair Task: {1575C392-0E35-416C-84D8-1184D8BF09C6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8338896 2022-04-05] (Microsoft Corporation -> Microsoft Corporation) 2022-08-27 01:05 - 2022-08-27 01:05 - 000000000 ____D C:\Users\Tyson\ansel (services.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_4.66.2001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe 2022-09-13 06:35 - 2022-01-10 22:19 - 000004562 _____ C:\windows\system32\Tasks\Adobe Acrobat Update Task 2021-06-05 22:08 - 2021-06-05 22:08 - 000000824 _____ C:\windows\system32\drivers\etc\hosts WinRAR -> C:\Program Files\WinRAR [2022-06-13] (0) Download ZIP. HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION 2022-09-21 08:28 - 2022-09-21 08:35 - 000000000 ___RD C:\Users\Tyson\OneDrive Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 4 InWin809.local. 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\SysWOW64\vi-VN BIOS: American Megatrends International, LLC. 2022-08-31 20:07 - 2022-09-01 05:48 - 000001256 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects 2022.lnk Highlight the below information then hit the. IFEO\upfc.exe: [Debugger] / (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\StartupApproved\Run: => "Discord" 2022-08-24 17:24 - 2022-08-24 17:24 - 000000000 ____D C:\Users\Tyson\AppData\LocalLow\Battlestate Games Microsoft Office Professional Plus 2021 - en-us (HKLM\\ProPlus2021Retail - en-us) (Version: 16.0.15028.20160 - Microsoft Corporation) R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [11523704 2022-06-09] (Logitech Inc -> Logitech, Inc.) ==================== Shortcuts & WMI ======================== 2022-09-13 07:02 - 2022-05-24 21:19 - 000000000 ____D C:\Program Files\Adobe Microsoft .NET Host FX Resolver - 6.0.6 (x64) (HKLM\\{089493D9-430B-4210-8A47-8F611288F461}) (Version: 48.27.42327 - Microsoft Corporation) Hidden Error: (09/21/2022 08:31:49 AM) (Source: DCOM) (EventID: 10010) (User: INWIN809) Discord Easter Egg Raging Demon Press Ctrl + / on your keyboard. 2022-08-22 04:13 - 2022-08-22 04:13 - 000000000 ____D C:\Program Files\Corsair ==================== FirewallRules (Whitelisted) ================ (services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe Streamlabs Desktop 1.10.0 (HKLM\\029c4619-0385-5543-9426-46f9987161d9) (Version: 1.10.0 - General Workings, Inc.) FirewallRules: [TCP Query User{4CE923C1-E653-43E4-8434-BCDF04B403C4}C:\users\tyson\appdata\local\medal\app-4.1712.0\medal.exe] => (Allow) C:\users\tyson\appdata\local\medal\app-4.1712.0\medal.exe (Ferox Games B.V. -> Medal B.V.) DefaultAccount (S-1-5-21-479614032-2295716511-2174497491-503 - Limited - Disabled) R3 iFiHDUSBAudioks; C:\windows\System32\drivers\iFiHDUSBAudioks_x64.sys [56056 2016-02-04] (Abbingdon Global Limited -> ) Startup: C:\Users\Tyson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2022-09-09] Error: (09/21/2022 08:32:49 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) FirewallRules: [{4AE96DAB-A7FC-4F77-8B61-5404C0996C4A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) U4 DiagTrack; no ImagePath (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 2022-09-13 06:55 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\SecurityHealth 2022-09-19 00:37 - 2022-05-13 20:46 - 000000000 ____D C:\Users\Tyson\AppData\Local\UnrealEngine S3 rtcx21; C:\windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_d2a498d51a4f7bec\rtcx21x64.sys [409000 2021-06-02] (Realtek Semiconductor Corp. -> Realtek) \\?\Volume{09976990-bd0c-4faf-ab2a-3c627bbd063a}\ (SYSTEM) (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 FirewallRules: [TCP Query User{D022303E-78DE-4FBD-8EE1-9D144739CF3C}C:\users\tyson\appdata\local\medal\app-4.1000.0\medal.exe] => (Allow) C:\users\tyson\appdata\local\medal\app-4.1000.0\medal.exe (Ferox Games B.V. -> Medal B.V.) 2022-09-18 23:08 - 2022-04-05 09:34 - 000000000 ____D C:\Program Files\Mozilla Firefox 2022-09-18 23:35 - 2022-01-03 19:51 - 000848788 _____ C:\windows\system32\PerfStringBackup.INI Task: {1DB34F4D-B0C1-4082-887A-B17E2907C476} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-05-05] (Nvidia Corporation -> NVIDIA Corporation) Microsoft Windows Desktop Runtime - 6.0.6 (x64) (HKLM\\{B9E46F95-AC34-4943-AFE2-B72EFD56C6C0}) (Version: 48.27.42342 - Microsoft Corporation) Hidden IFEO\osppsvc.exe: [VerifierDlls] SppExtComObjHook.dll FirewallRules: [{BAB0BF1E-919D-4339-8127-3E03675AEE16}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation) 2022-09-19 00:50 - 2022-05-13 23:32 - 000000000 ____D C:\Users\Tyson\AppData\Local\log Imagine a Place where you can belong to a school club, a gaming group, or a worldwide art community. AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy.lnk:F37336C997 [3314] The next screen will show you how to play the Snek Game. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ccSettings_{BEC9211B-09AC-4B5B-9D31-561ADFF81A33}.sys => ""="Driver" Epic Online Services (HKLM-x32\\{758842D2-1538-4008-A8E3-66F65A061C52}) (Version: 2.0.33.0 - Epic Games, Inc.) CustomCLSID: HKU\S-1-5-21-479614032-2295716511-2174497491-1002_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems) Edge: FirewallRules: [{409B94B3-F742-4BAE-82C4-05FFA4FB8A7D}] => (Allow) D:\Steam\SteamApps\common\VRChat\VRChat.exe () [File not signed] 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\SysWOW64\eu-ES (services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe S3 SymEvnt; C:\ProgramData\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Data\SymPlatform\SymEvnt.sys [957928 2022-09-08] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) FirewallRules: [TCP Query User{1D69C28E-A5D4-4798-8D05-4FE8A4AF90E0}C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2545_gtaprocess.exe] => (Allow) C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2545_gtaprocess.exe (TASKS ME - IT DEVELOPMENT (AILENE BULALACAO TAGOLGOL) -> Cfx.re) This is the instruction screen which showcases the controls required to play the game. FirewallRules: [{45DF7DD6-F48B-4B41-8062-75347E338848}] => (Allow) C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe (Oculus VR, LLC -> Facebook Technologies, LLC) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [159720 2022-07-01] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) (services.exe ->) (DTS, Inc. -> DTS Inc.) C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.exe 2022-09-18 23:07 - 2022-05-24 21:45 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\discord S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8885112 2022-07-15] (BattlEye Innovations e.K. FirewallRules: [TCP Query User{9A24F9FB-9043-4592-A156-345C3448A69E}C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2372_gtaprocess.exe] => (Allow) C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2372_gtaprocess.exe (TASKS ME - IT DEVELOPMENT (AILENE BULALACAO TAGOLGOL) -> Cfx.re) NVIDIA Graphics Driver 516.94 (HKLM\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 516.94 - NVIDIA Corporation) You can call this a coding game or game with coding. AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy.lnk:F37336C997 [3314] IFEO\MusNotification.exe: [Debugger] / HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SppExtComObj.exe => removed successfully FirewallRules: [{3EB112F3-D1E8-45BA-B0F2-0DAF7DD6538B}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) Username: ForCheffy or Alternate-Cheffy. Avoid hitting the borders and keep eating more food to make your snake grow longer in the game. i wonder what is the world record for the most severs joined dm me on discord my discord is nathanaf252#4008. Packages: 2022-08-27 01:03 - 2022-08-27 01:03 - 000000000 ____D C:\Users\Tyson\AppData\Local\Paradox Interactive 2022-09-09 23:18 - 2022-05-16 15:19 - 000000000 ____D C:\Program Files\Rainmeter Tcpip\..\Interfaces\{219cb33e-0f8a-4084-a685-e83afae8e96c}: [DhcpNameServer] 192.168.0.1 ==================== Drives ================================ HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\EOSnotify.exe => removed successfully 2022-08-22 04:13 - 2022-08-22 04:14 - 000000000 ____D C:\Users\Tyson\AppData\Local\Corsair Disk: 1 (MBR Code: Windows 7/8/10) (Size: 476.9 GB) (Disk ID: 2435D796) Epic Games Launcher (HKLM-x32\\{FAC47927-1A6A-4C6E-AD7D-E9756794A4BC}) (Version: 1.3.23.0 - Epic Games, Inc.) 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\SysWOW64\et-EE Restart the computer to complete this action. 2022-08-31 20:02 - 2022-09-01 05:48 - 000001056 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom.lnk FirewallRules: [{AA192DEE-9A48-4521-9235-04F4A517BF26}] => (Block) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) 2. Peace (HKLM\\Peace) (Version: 1.6.1.2 - P.E. (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 2022-09-04 01:01 - 2022-09-04 01:01 - 000001982 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Streamlabs Desktop.lnk (explorer.exe ->) (Abbingdon Global Limited -> ) C:\Program Files\iFi\USB_HD_Audio_Driver\iFiHDUSBAudio_cpl.exe FF HKLM\\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi (C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.DisplayAdapter.exe CHR Extension: (Chrome Remote Desktop) - C:\Users\Tyson\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2022-05-13] 2022-09-13 06:48 - 2022-09-13 06:48 - 000167936 _____ C:\windows\system32\DeviceUpdateCenterCsp.dll R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [239544 2022-08-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) HKLM\\Run: [CORSAIR iCUE 4 Software] => C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUE Launcher.exe [185392 2022-08-05] (Corsair Memory, Inc. -> Corsair Memory, Inc.) FirewallRules: [{CCB4F444-343C-4463-AD44-201D04996086}] => (Allow) D:\Steam\SteamApps\common\Sid Meier's Civilization V\LaunchPad\LaunchPad.exe () [File not signed] Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Platform: Microsoft Windows 11 Pro Version 21H2 22000.856 (X64) Language: English (United States) U4 DiagTrack; no ImagePath U4 DiagTrack; no ImagePath You must restart the computer in order to complete the reset. Make sure that your device volume is turned on. ==================== End of Addition.txt =======================, =================== Processes (Whitelisted) ================= 2022-09-14 00:04 - 2022-08-02 02:04 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\com.adobe.dunamis S3 WdBoot; C:\windows\system32\drivers\wd\WdBoot.sys [48536 2022-01-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Intel\Shared Libraries\redist\intel64\compiler;C:\windows\system32;C:\windows;C:\windows\System32\Wbem;C:\windows\System32\WindowsPowerShell\v1.0\;C:\windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files\dotnet\ FF HKLM-x32\\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2022-08-02] (Adobe Inc. -> Adobe Systems) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy.lnk => ":F37336C997" ADS removed successfully Task: {43785E39-08DC-4168-BDFD-88AD2F19FFB2} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [61336 2022-04-05] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2022-09-08] (Adobe Inc. -> Adobe Systems Inc.) There's a playable Discord snake game that can be accessed from a 404 error page. 2022-09-21 08:34 - 2022-05-13 20:52 - 000000000 ____D C:\Program Files (x86)\Google 2022-08-27 00:56 - 2022-06-24 16:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blackmagic Design 2022-09-18 22:47 - 2022-01-04 13:42 - 000000000 ____D C:\windows\system32\SleepStudy Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 The vast world of Gedonia is a beautiful place with a lot of unexplored areas, and you are just a simple adventurer . Here are some tips to help you improve your score on Google Snake: Try to play on a larger screen if possible, as this will give you more room to maneuver and avoid crashing into walls or your own tail. 2022-09-13 06:51 - 2022-01-03 20:17 - 144534560 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe R3 VOICEMOD_Driver; C:\windows\system32\drivers\vmdrv.sys [48136 2022-03-08] (Voicemod Sociedad Limitada -> Windows Win 7 DDK provider) Office 16 Click-to-Run Licensing Component (HKLM\\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.15028.20160 - Microsoft Corporation) Hidden The file will not be moved.) (If needed Hosts: directive could be included in the fixlist to reset Hosts.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 2022-09-04 01:01 - 2022-09-04 01:01 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\slobs-plugins FF Extension: (uBlock Origin) - C:\Users\Tyson\AppData\Roaming\Mozilla\Firefox\Profiles\xnc3cpuf.default-release\Extensions\uBlock0@raymondhill.net.xpi [2022-09-13] . 2022-09-18 10:29 - 2022-05-25 01:10 - 000002212 _____ C:\Users\Public\Desktop\Google Chrome.lnk Create fun and interactive games with Discord bots.. Latest version: 1.0.9, last published: a year ago. Drive c: (System) (Fixed) (Total:476.84 GB) (Free:138.29 GB) (Model: Samsung SSD 960 PRO 512GB) NTFS HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\RunOnce: [Uninstall 22.065.0412.0004_1\amd64] => C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Tyson\AppData\Local\Microsoft\OneDrive\22.065.0412.0004_1\amd64" (No File) 2022-08-24 16:24 - 2022-08-24 16:24 - 000000000 ____D C:\Users\Tyson\AppData\Local\Battlestate Games HKLM\SOFTWARE\Policies\Microsoft\Edge => removed successfully Guest (S-1-5-21-479614032-2295716511-2174497491-501 - Limited - Disabled) 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\appraiser xml" So we can continue to get all the new update items and it wont. ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Tyson\AppData\Local\MEGAsync\ShellExtX64.dll [2022-06-11] (Mega Limited -> ) Task: {490C8863-947E-474E-AF1E-F90A6843FD98} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22865832 2022-03-30] (Microsoft Corporation -> Microsoft Corporation) The starting point of the game. The system cannot find the file specified. Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Apple Software Update (HKLM-x32\\{B292D163-23D2-4523-A699-1ABEC1875609}) (Version: 2.7.0.3 - Apple Inc.) FF Extension: (vidIQ Vision for YouTube) - C:\Users\Tyson\AppData\Roaming\Mozilla\Firefox\Profiles\xnc3cpuf.default-release\Extensions\firefox@vid.io.xpi [2022-09-13] FF ProfilePath: C:\Users\Tyson\AppData\Roaming\Mozilla\Firefox\Profiles\xnc3cpuf.default-release [2022-09-21] Streamlabs Desktop 1.10.0 (HKLM\\029c4619-0385-5543-9426-46f9987161d9) (Version: 1.10.0 - General Workings, Inc.) keeps me and my friends online for hours. The file will not be moved unless listed separately.) Application errors: Task: {08CC3C71-04DA-4C86-AF42-1F7067326362} - System32\Tasks\GoogleUpdateTaskMachineCore{A6531C16-C0AF-4456-87D5-BD1A9B087920} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [168632 2022-05-25] (Google LLC -> Google LLC) Partition: GPT. If you'd like to include audio with the game, make sure your audio is also switched on at this point too. FirewallRules: [{2089FA96-87E2-4759-A593-A31D1EE2D411}] => (Allow) D:\Steam\SteamApps\common\Yakuza 0\media\Yakuza0.exe () [File not signed] is an interesting game to play. FirewallRules: [{A0FA9184-5645-463C-B4E7-F76F75DAF8F4}] => (Allow) D:\Steam\SteamApps\common\Devour\DEVOUR.exe () [File not signed] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\iFi (by AMR) HD USB Audio Control Panel.lnk [2022-05-13] Edge Profile: C:\Users\Tyson\AppData\Local\Microsoft\Edge\User Data\Default [2022-01-10] Error: (09/21/2022 08:33:39 AM) (Source: DCOM) (EventID: 10001) (User: INWIN809) F8d 04/27/2022 HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\SecureBootUpdates R2 sepWscSvc; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin64\sepWscSvc64.exe [1370464 2022-02-25] (Broadcom Inc -> Broadcom) 2022-08-22 04:13 - 2022-09-01 05:48 - 002439112 _____ (A-Volute) C:\windows\system32\9EarsSurroundSound.dll Simply click any of the arrow keys to begin. Percentage of memory in use: 18% 2022-09-04 01:01 - 2022-09-21 08:29 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\slobs-client 2022-09-13 06:48 - 2022-09-13 06:48 - 000041472 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll Google Snake. Motherboard: Gigabyte Technology Co., Ltd. Z690 AORUS ELITE AX DDR4 2022-08-22 04:13 - 2022-07-08 17:37 - 000486552 _____ (Sonarworks) C:\windows\system32\soundidsdkdsp.dll Service: Netwtw10 ===================== Drivers (Whitelisted) =================== C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully Task: {952FAF34-704C-433F-92B5-79B6E5925C8A} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Analyzer => C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin\SymErr.exe [91048 2022-02-25] (Symantec Corporation -> Broadcom) Commands snake/start starts a new game snake/exit exits the current game snake/leaderboard displays the top scores snake/vote gives the link to vote for Snakebot. 2022-09-21 08:32 - 2022-08-02 16:26 - 000869032 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\windows\system32\GigabyteUpdateService.exe FirewallRules: [{61077C69-0EFE-47EE-B1ED-80D2BFE923B8}] => (Allow) D:\Steam\SteamApps\common\Half-Life\hl.exe (Valve -> Valve) Task: {1575C392-0E35-416C-84D8-1184D8BF09C6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8338896 2022-04-05] (Microsoft Corporation -> Microsoft Corporation) R2 CorsairLLAccessC2D033F14715AA7325305EA42FBFC65BF867CC1D; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CorsairLLAccess64.sys [21752 2022-06-21] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) (svchost.exe ->) (Adobe Systems Incorporated) C:\Program Files\WindowsApps\AdobeNotificationClient_3.0.1.1_x86__enpm4xejd91yc\AdobeNotificationClient.exe R3 logi_joy_xlcore; C:\windows\system32\drivers\logi_joy_xlcore.sys [62904 2022-05-13] (WDKTestCert builder,132743893872553407 -> Logitech) (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_47917a79b8c7fd22\Display.NvContainer\NVDisplay.Container.exe <2> 2022-09-21 08:33 - 2021-06-05 22:10 - 000000000 ____D C:\windows\AppReadiness FirewallRules: [UDP Query User{AAEC9880-7EAD-4204-9D42-FA0448950BAB}C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_fxdk_b2545_gameruntime.exe] => (Allow) C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_fxdk_b2545_gameruntime.exe => No File (services.exe ->) (DTS, Inc. -> DTS Inc.) C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.exe S0 MbamElam; C:\windows\System32\DRIVERS\MbamElam.sys [21480 2022-07-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) 2022-08-24 16:24 - 2022-08-24 16:24 - 000000000 ____D C:\ProgramData\Battlestate Games Adobe After Effects 2022 (HKLM-x32\\AEFT_22_6) (Version: 22.6 - Adobe Inc.)