FirewallRules: [TCP Query User{2F29BC3A-D5D6-447D-BDFC-4B124ACDD023}C:\users\tyson\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\tyson\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) Follow the instructions. (explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub.exe <3> 2022-09-13 22:31 - 2022-05-13 20:49 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2022-08-22 04:13 - 2022-08-22 04:14 - 000000000 ____D C:\ProgramData\Corsair The controls are simple press Enter to start, WASD or arrow keys to move and ESC to quit Snek. CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Tyson\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-09-04] Problem: : This device is disabled. 2022-09-21 08:27 - 2022-09-21 08:27 - 000000000 ____D C:\ProgramData\Dropbox FirewallRules: [{9A674005-76ED-49FE-B5D9-BD89D27E7EAA}] => (Allow) D:\Steam\SteamApps\common\Aim Lab\AimLab_tb.exe () [File not signed] ========= bitsadmin /reset /allusers ========= FF Extension: (vidIQ Vision for YouTube) - C:\Users\Tyson\AppData\Roaming\Mozilla\Firefox\Profiles\xnc3cpuf.default-release\Extensions\firefox@vid.io.xpi [2022-09-13] Error: (09/18/2022 11:28:16 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) 2022-08-31 01:24 - 2022-05-25 01:10 - 000003496 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineUA{52819A4A-6F97-4F51-A9DF-F8722C17E431} 2022-09-04 01:01 - 2022-09-04 01:01 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\slobs-plugins 2022-09-13 06:35 - 2022-08-18 23:47 - 000002079 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk:09A0A90EF3 [3442] 2022-09-13 06:48 - 2022-09-13 06:48 - 000327680 _____ C:\windows\system32\pnpdiag.dll FirewallRules: [TCP Query User{05590699-DA42-460B-91B9-EE6B37369FBC}C:\program files\qbittorrent\qbittorrent.exe] => (Block) C:\program files\qbittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed] 100% Original DayZ files. Description: The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout. R2 DtsApo4Service; C:\windows\System32\DTS\PC\APO4x\DtsApo4Service.exe [213432 2021-02-22] (DTS, Inc. -> DTS Inc.) Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden FirewallRules: [UDP Query User{5760B17F-8A79-49E6-9CE2-783CEB6417EC}C:\users\tyson\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\tyson\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) 2022-09-15 02:39 - 2022-04-05 14:01 - 000000000 ____D C:\windows\system32\Tasks\Mozilla (explorer.exe ->) (Adobe Inc. -> Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat DC\Acrobat\acrotray.exe Edge Profile: C:\Users\Tyson\AppData\Local\Microsoft\Edge\User Data\Default [2022-01-10] Apple Mobile Device Support (HKLM\\{2B3CA448-5266-480F-85FA-2FCCB3C8712C}) (Version: 15.6.0.32 - Apple Inc.) EdgeDeflector (HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\EdgeDeflector) (Version: 1.2.3.0 - ) ==================== FirewallRules (Whitelisted) ================ 2022-09-13 06:48 - 2022-01-04 13:46 - 003103744 _____ (Microsoft Corporation) C:\windows\SysWOW64\PrintConfig.dll Description: mDNSCoreReceiveResponse: Received from 192.168.0.238:5353 16 InWin809.local. 2022-08-23 13:40 - 2022-01-04 13:42 - 000003412 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2022-09-03] (EasyAntiCheat Oy -> Epic Games, Inc) Just try tapping "up" then "right" in alternating order until you can't move. AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy.lnk:F37336C997 [3314] FirewallRules: [UDP - Installer for ACDSee Commander Ultimate 2022] => (Allow) C:\Program Files\ACD Systems\ACDSee Ultimate\15.0\ACDSeeCommanderUltimate15.exe => No File Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2022-08-03] (Adobe Inc. -> Adobe Systems Incorporated) (C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe ->) (OpenJS Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe CustomCLSID: HKU\S-1-5-21-479614032-2295716511-2174497491-1002_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems) Other top scores include: Read: are there termites in mn - second place: Daniel Cimbalista, with a score of 530,760; - third place: Michael Qureshi, with a score of 512 3. FirewallRules: [{E2EB56F8-5EDB-4A17-A5DC-64F3D20DCD5D}] => (Allow) D:\Steam\SteamApps\common\wallpaper_engine\bin\ui32.exe (Skutta, Kristjan -> ) Play with your friends or by yourself, either way, enjoy playing! 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\id-ID "HKU\S-1-5-21-479614032-2295716511-2174497491-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully FirewallRules: [TCP Query User{B29CB122-F27F-4DFE-B63F-BB985EDAA1B3}C:\program files\lghub\lghub_agent.exe] => (Allow) C:\program files\lghub\lghub_agent.exe (Logitech Inc -> Logitech, Inc.) How to Hide What Game You're Playing on Discord If a game uses Discord's Rich Presence feature, your friends can even see where you are in-game. FirewallRules: [{AEDEA38F-D316-4885-83E5-DC6351F555FD}] => (Allow) D:\Steam\SteamApps\common\Half-Life\hl.exe (Valve -> Valve) Resetting , OK! Addr 192.168.0.238 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\Provisioning The file will not be moved unless listed separately.) 0. . R3 iaLPSS2_GPIO2_ADL; C:\windows\System32\DriverStore\FileRepository\ialpss2_gpio2_adl.inf_amd64_e11257f05c0c2f89\iaLPSS2_GPIO2_ADL.sys [139928 2021-07-29] (Intel Corporation -> Intel Corporation) Paradox Launcher v2 (HKLM\\{8C5CF4CE-D589-40B4-A77F-01FD64602C50}) (Version: 2.4.0 - Paradox Interactive) FirewallRules: [{D9AD2616-687D-4831-809B-DADF4BDF4447}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe (Valve Corp. -> ) HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\WaaSMedic.exe => removed successfully 3. 2022-09-13 06:56 - 2021-06-06 00:30 - 000000000 ____D C:\Program Files\Windows Photo Viewer discord snake high score. ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Tyson\AppData\Local\MEGAsync\ShellExtX64.dll [2022-06-11] (Mega Limited -> ) 2022-06-27 00:22 - 2022-06-27 00:22 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\Policies\Explorer: [HideSCAMeetNow] 1 2022-08-27 00:56 - 2022-08-08 00:16 - 000000000 ____D C:\Program Files\Blackmagic Design 2022-09-13 06:57 - 2022-01-04 13:42 - 000473128 _____ C:\windows\system32\FNTCACHE.DAT 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\oobe The next screen will show you how to play the Snek Game. Here are the spawning limitations: 1. (services.exe ->) (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Windows\System32\GigabyteUpdateService.exe (svchost.exe ->) (Adobe Systems Incorporated) C:\Program Files\WindowsApps\AdobeNotificationClient_3.0.1.1_x86__enpm4xejd91yc\AdobeNotificationClient.exe S0 SymELAM; C:\windows\System32\Drivers\SEP\0E031CE1\0FA0.105\x64\SymELAM.sys [25576 2022-02-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Broadcom) CHR Extension: (AdBlock best ad blocker) - C:\Users\Tyson\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2022-09-04] You've been invited to join. 2022-06-10 13:06 - 2022-06-09 19:06 - 000151040 _____ () [File not signed] \\?\C:\Program Files\LGHUB\resources\app.asar.unpacked\node_modules\keytar\build\Release\keytar.node (services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe FF DefaultProfile: 9c4tsxuk.default 2022-09-14 00:04 - 2022-08-02 02:04 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\com.adobe.dunamis "HKU\S-1-5-21-479614032-2295716511-2174497491-1002\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAMeetNow" => removed successfully R3 rt25cx21; C:\windows\System32\DriverStore\FileRepository\rt25cx21x64.inf_amd64_447a9570dbb12464\rt25cx21x64.sys [620456 2022-03-25] (Realtek Semiconductor Corp. -> Realtek) 2022-09-21 08:33 - 2022-08-02 16:27 - 000091304 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\windows\system32\GigabyteDownloadAssistant.exe FirewallRules: [{7A701A64-DD53-4D45-A7DF-E8D461165756}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2.exe (Epic Games, Inc.) [File not signed] (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\SystemResources R3 logi_joy_vir_hid; C:\windows\system32\drivers\logi_joy_vir_hid.sys [21704 2022-05-13] (WDKTestCert builder,132743893872553407 -> Logitech) (If an entry is included in the fixlist, it will be removed from the registry. (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) 2022-09-13 07:02 - 2022-09-13 07:02 - 000001136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro 2022.lnk 2022-09-13 06:48 - 2022-09-13 06:48 - 000167936 _____ C:\windows\system32\DeviceUpdateCenterCsp.dll 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\bcastdvr FirewallRules: [{CF85FB9F-ED01-4253-89EB-A807F9E13088}] => (Allow) D:\Steam\SteamApps\common\DRAGON BALL FighterZ\DBFighterZ.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) Once you're on the 404 page, simply click the board with the illustration of a green snake, as shown in the screenshot. Resetting , failed. HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\StartupApproved\Run: => "EpicGamesLauncher" 2022-08-19 00:58 - 2022-08-19 00:58 - 000000000 ____D C:\Users\Tyson\AppData\Local\SolidDocuments HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\RunOnce: [Uninstall 22.065.0412.0004_1\amd64] => C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Tyson\AppData\Local\Microsoft\OneDrive\22.065.0412.0004_1\amd64" (No File) 2022-09-04 01:01 - 2022-09-04 01:01 - 000001970 _____ C:\Users\Public\Desktop\Streamlabs Desktop.lnk Tcpip\..\Interfaces\{219cb33e-0f8a-4084-a685-e83afae8e96c}: [DhcpNameServer] 192.168.0.1 FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2022-08-02] (Adobe Inc. -> Adobe Systems) Snake On Discord is a bot that I wrote in Discord.JS.
Discord Virus explained: How to Remove it? | NordVPN Task: {82D0DA1B-4BFD-4384-A5F2-C2C9C999A086} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646344 2022-05-05] (Nvidia Corporation -> NVIDIA Corporation) 2022-08-24 16:24 - 2022-08-24 16:24 - 000000000 ____D C:\Users\Tyson\AppData\Local\Battlestate Games FirewallRules: [{118ABF76-1938-4637-A892-A2851DFB8312}] => (Allow) D:\Steam\SteamApps\common\VRChat\launch.exe () [File not signed] 2022-09-16 15:59 - 2022-05-13 18:02 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\vlc Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3494672 2022-06-27] (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [UDP Query User{AAEC9880-7EAD-4204-9D42-FA0448950BAB}C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_fxdk_b2545_gameruntime.exe] => (Allow) C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_fxdk_b2545_gameruntime.exe => No File Task: {8B5D0AB1-09DB-4A6C-B739-540592774668} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Processor => C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin\SymErr.exe [91048 2022-02-25] (Symantec Corporation -> Broadcom) 2022-08-24 16:24 - 2022-08-24 16:24 - 000000000 ____D C:\ProgramData\Battlestate Games 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\SysWOW64\lv-LV 2022-09-18 23:20 - 2022-09-18 23:20 - 000001623 _____ C:\windows\system32\config\VSMIDK Epic Online Services (HKLM-x32\\{758842D2-1538-4008-A8E3-66F65A061C52}) (Version: 2.0.33.0 - Epic Games, Inc.) CHR HKLM-x32\\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\StartupApproved\Run: => "Voicemod" 2022-09-03 23:31 - 2022-09-04 01:01 - 000000000 ____D C:\ProgramData\obs-studio-hook HKLM\\Run: [RtkAudUService] => C:\windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe [1231864 2021-02-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor) CHR Extension: (Google Docs Offline) - C:\Users\Tyson\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-09-04] Spotify (HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\Spotify) (Version: 1.1.93.896.g3ae3b4f3 - Spotify AB) Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) FirewallRules: [{E9229B9B-EE8C-484B-A543-153E4D740CA5}] => (Allow) D:\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe (Koch Media GmbH) [File not signed] HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\RunOnce: [Uninstall 22.065.0412.0004_1] => C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Tyson\AppData\Local\Microsoft\OneDrive\22.065.0412.0004_1" (No File) FirewallRules: [UDP Query User{313F875B-D761-488A-B13D-512DA5FE278F}C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2545_gtaprocess.exe] => (Allow) C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2545_gtaprocess.exe (TASKS ME - IT DEVELOPMENT (AILENE BULALACAO TAGOLGOL) -> Cfx.re) 2022-08-22 04:13 - 2022-07-08 17:37 - 000063032 _____ (Corsair Memory, Inc.) C:\windows\system32\Drivers\CorsairGamingAudio64.sys eric forrester current wife. (If an entry is included in the fixlist, it will be removed from the registry. The Arena Media Brands, LLC and respective content providers to this website may receive compensation for some links to products and services on this website. This game is a winner in my eyes. 2022-09-20 21:38 - 2022-05-13 18:02 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\vlc (services.exe ->) (Code Sector -> ) C:\Program Files\TeraCopy\TeraCopyService.exe DNS Servers: 8.8.8.8 - 8.8.4.4 FirewallRules: [{7A9D3212-CA2F-4A72-82C5-B2429B2857CD}] => (Allow) D:\Steam\SteamApps\common\assettocorsa\AssettoCorsa.exe (Kunos Simulazioni) [File not signed] ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (Firebit OU -> Rainmeter) // Intel Corporation)
Yggdrasil Discord Bot R3 logi_joy_xlcore; C:\windows\system32\drivers\logi_joy_xlcore.sys [62904 2022-05-13] (WDKTestCert builder,132743893872553407 -> Logitech) HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\StartupApproved\Run: => "Discord" HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\osppsvc.exe => removed successfully Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{D3D84989-BAD2-49CF-99FF-BB5A33EA3AF1}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2\Binaries\Win64\Home2-Win64-Shipping.exe (Oculus VR, LLC -> Epic Games, Inc.) 2022-09-04 01:01 - 2022-09-04 01:01 - 000001982 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Streamlabs Desktop.lnk 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\eu-ES 2022-09-21 08:35 - 2022-05-13 21:11 - 000000001 _____ C:\windows\vgkbootstatus.dat Error: (09/21/2022 08:31:49 AM) (Source: DCOM) (EventID: 10010) (User: INWIN809) The file will not be moved unless listed separately.) (C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.DisplayAdapter.exe 2022-09-21 08:32 - 2021-06-05 22:10 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe <2> S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8885112 2022-07-15] (BattlEye Innovations e.K. 2022-09-12 09:31 - 2022-09-12 09:31 - 000001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition 2022.lnk R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [923656 2022-08-02] (Adobe Inc. -> Adobe Inc.) AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk:B026C77744 [3442] (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe ==================== One month (modified) ================== HKLM\\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [362056 2022-05-05] (Apple Inc. -> Apple Inc.) 2022-09-18 23:33 - 2022-04-05 15:06 - 000000000 ____D C:\windows\system32\Tasks\Symantec Endpoint Protection U4 DiagTrack; no ImagePath Task: {658C5A85-0FD8-4A07-B8D2-05DD4D62B7DA} - System32\Tasks\GoogleUpdateTaskMachineUA{52819A4A-6F97-4F51-A9DF-F8722C17E431} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [168632 2022-05-25] (Google LLC -> Google LLC) Also lately I've been seeing what seems to be cardboard boxes show up on the icons on my desktop, then followed by green ticks. S3 logi_joy_hid_lo; C:\windows\system32\drivers\logi_joy_hid_lo.sys [41280 2022-05-13] (WDKTestCert builder,132743893872553407 -> Logitech) 2022-08-25 16:41 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\NDF Task: {1AEAE201-6F48-4C77-82CB-E97D4A8E5F80} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138680 2022-04-05] (Microsoft Corporation -> Microsoft Corporation) 2022-09-15 02:39 - 2022-04-05 14:01 - 000000000 ____D C:\windows\system32\Tasks\Mozilla This starts the Enable Device wizard. ==================== Memory info =========================== (services.exe ->) (Brio) [File not signed] C:\Program Files\FolderSize\FolderSizeSvc.exe 2022-09-12 09:31 - 2022-05-13 18:02 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\Adobe HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\RunOnce: [Uninstall 22.065.0412.0004_1] => C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Tyson\AppData\Local\Microsoft\OneDrive\22.065.0412.0004_1" (No File) FirewallRules: [{19B257A1-CEE8-433D-8799-49D0E85924EA}] => (Allow) D:\Steam\SteamApps\common\MultiVersus\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.) FirewallRules: [{D1CB192D-76D5-4997-A65D-7C9246999244}] => (Allow) D:\Steam\SteamApps\common\Blade & Sorcery\BladeAndSorcery.exe () [File not signed] 2022-08-31 20:09 - 2022-09-01 04:04 - 000001148 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder 2022.lnk (services.exe ->) (DTS, Inc. -> DTS Inc.) C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.exe 2022-08-31 20:02 - 2022-09-01 05:48 - 000001056 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom.lnk 2022-06-27 00:22 - 2022-06-27 00:22 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll 2022-09-19 00:28 - 2022-09-19 00:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Oculus FirewallRules: [{D4532A44-809F-48B5-A848-01634FE92722}] => (Allow) D:\Steam\SteamApps\common\Saints Row IV\SaintsRowIV.exe (Koch Media GmbH) [File not signed] FF ProfilePath: C:\Users\Tyson\AppData\Roaming\Mozilla\Firefox\Profiles\9c4tsxuk.default [2022-01-10]
Task: {EBB94CF2-C9D4-41C0-A9B1-E47647F2DE6B} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-479614032-2295716511-2174497491-500 => C:\Users\Tyson\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) Please make sure to check .css-1xcaalv{transition-property:var(--top-gg-transition-property-common);transition-duration:var(--top-gg-transition-duration-fast);transition-timing-function:var(--top-gg-transition-easing-ease-out);cursor:pointer;-webkit-text-decoration:none;text-decoration:none;outline:2px solid transparent;outline-offset:2px;color:var(--top-gg-colors-brand-100);}.css-1xcaalv:hover,.css-1xcaalv[data-hover]{-webkit-text-decoration:none;text-decoration:none;color:currentColor;}.css-1xcaalv:focus,.css-1xcaalv[data-focus]{box-shadow:var(--top-gg-shadows-outline);}our guidelines before posting. Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Start:: R2 SepMasterService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin\ccSvcHst.exe [156584 2022-02-25] (Symantec Corporation -> Broadcom) The next screen will show you how to play the Snek Game. FirewallRules: [TCP Query User{D022303E-78DE-4FBD-8EE1-9D144739CF3C}C:\users\tyson\appdata\local\medal\app-4.1000.0\medal.exe] => (Allow) C:\users\tyson\appdata\local\medal\app-4.1000.0\medal.exe (Ferox Games B.V. -> Medal B.V.) ========================================================== League of Legends (HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\Riot Game league_of_legends.live) (Version: - Riot Games, Inc) You can either enter the link into your browser's address bar by copying and pasting the above link, or else simply click on the link, and it'll bring you to their 404 page. 2022-08-27 00:56 - 2022-06-24 16:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blackmagic Design IFEO\InstallAgent.exe: [Debugger] / 2022-09-12 09:31 - 2022-09-12 09:31 - 000001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition 2022.lnk Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332 (HKLM\\{3407B900-37F5-4CC2-B612-5CD5D580A163}) (Version: 14.32.31332 - Microsoft Corporation) Hidden Resetting Neighbor, OK! NVIDIA PhysX System Software 9.21.0713 (HKLM\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) Oculus (HKLM\\Oculus) (Version: <3 - Facebook Technologies, LLC) Discordo. BITSADMIN version 3.0 FiveM (HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\CitizenFX_FiveM) (Version: - Cfx.re) FirewallRules: [TCP Query User{1E1C5A66-6FEB-4586-9CA1-7B84488C446E}D:\epic games\fortnite\engine\binaries\win64\epicwebhelper.exe] => (Allow) D:\epic games\fortnite\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.) 2022-08-24 17:24 - 2022-08-24 17:24 - 000000000 ____D C:\Users\Tyson\AppData\LocalLow\Battlestate Games # SNAKES GAME. S3 rtcx21; C:\windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_d2a498d51a4f7bec\rtcx21x64.sys [409000 2021-06-02] (Realtek Semiconductor Corp. -> Realtek) <==== ATTENTION ==================== Services (Whitelisted) =================== HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION Edge: AlternateDataStreams: C:\ProgramData\Application Data:err [1670] HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION 2022-09-04 01:01 - 2022-09-04 01:01 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\obs-studio-node-server FirewallRules: [{578D2BC5-273F-42EA-9592-5F0A384CA262}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Engine\Binaries\Win64\UnrealCEFSubProcess.exe (Epic Games, Inc.) [File not signed] The file will not be moved unless listed separately.) Task: {1903FCFD-CF35-4771-9F43-60AE3B50151B} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate IFEO\SppExtComObj.exe: [VerifierDlls] SppExtComObjHook.dll (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_0797c0ea8580ae89\IntelCpHDCPSvc.exe 2022-08-22 04:14 - 2022-08-22 04:14 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\Corsair WinRAR 6.11 (64-bit) (HKLM\\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH) 2022-09-18 23:40 - 2022-09-21 08:37 - 000000000 ____D C:\FRST HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\Run: [Voicemod] => C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe [7291800 2022-03-18] (Voicemod Sociedad Limitada -> Voicemod) 2022-08-24 16:24 - 2022-08-24 16:24 - 000000613 _____ C:\Users\Public\Desktop\Battlestate Games Launcher.lnk U4 dmwappushservice; no ImagePath FirewallRules: [TCP Query User{B5E65EFE-5A2C-4ED9-B286-57FEF2B6E48B}C:\users\tyson\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\tyson\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) R1 ccSettings_{BEC9211B-09AC-4B5B-9D31-561ADFF81A33}; C:\windows\System32\Drivers\SEP\0E031CE1\0FA0.105\x64\ccSetx64.sys [189392 2022-02-25] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) IFEO\SihClient.exe: [Debugger] / If you didn't place, don't worry! NVIDIA HD Audio Driver 1.3.39.14 (HKLM\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.39.14 - NVIDIA Corporation) 2022-09-14 00:04 - 2022-08-02 02:04 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\com.adobe.dunamis 2022-08-22 04:13 - 2022-08-22 04:14 - 000000000 ____D C:\Users\Tyson\AppData\Local\Corsair Tcpip\..\Interfaces\{219cb33e-0f8a-4084-a685-e83afae8e96c}: [NameServer] 8.8.8.8,8.8.4.4 CORSAIR iCUE 4 Software (HKLM\\{B1071BDE-E9F2-4F8C-8A0F-0FB8BA5835CD}) (Version: 4.27.168 - Corsair) FirewallRules: [TCP Query User{1FD45ABC-304E-41F9-9B11-A0FFC2FD4B4D}D:\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) D:\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.) fixlist content: 2022-08-24 17:24 - 2022-08-24 17:24 - 000000000 ____D C:\Users\Tyson\AppData\LocalLow\Battlestate Games R3 iaLPSS2_I2C_ADL; C:\windows\System32\DriverStore\FileRepository\ialpss2_i2c_adl.inf_amd64_778b19a5f4d49cba\iaLPSS2_I2C_ADL.sys [202896 2021-07-29] (Intel Corporation -> Intel Corporation) Simply click any of the arrow keys to begin. The game is quite appreciative too I mean, who doesnt want to see the YOU HECKIN WON! message despite getting only a few points. Task: {1AEAE201-6F48-4C77-82CB-E97D4A8E5F80} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138680 2022-04-05] (Microsoft Corporation -> Microsoft Corporation) 2022-09-13 07:02 - 2022-05-24 21:19 - 000000000 ____D C:\Program Files\Adobe HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION 2022-08-31 01:24 - 2022-05-25 01:10 - 000003496 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineUA{52819A4A-6F97-4F51-A9DF-F8722C17E431} ==================== Hosts content: ========================= 2022-09-01 04:02 - 2022-05-13 20:38 - 000000000 ____D C:\Program Files\Riot Vanguard Wall Mode; Poison Mode; Portal Mode; Key Mode; Sokoban Mode; Minesweeper Mode; Peaceful; Cheese; Infinity/Borderless; . Description: mDNSCoreReceiveResponse: ProbeCount 0; will deregister 4 InWin809.local. FirewallRules: [TCP Query User{EB9AD1E8-E15C-4B8A-BA2B-1C2C204C5EF5}D:\riot games\valorant\riot client\riotclientservices.exe] => (Allow) D:\riot games\valorant\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.) HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\StartupApproved\Run: => "Steam" 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\lv-LV ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Tyson\AppData\Local\MEGAsync\ShellExtX64.dll [2022-06-11] (Mega Limited -> )