Hello and thank you, here are the logs:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-06-2021
Ran by katra (administrator) on DESKTOP-AKN8A88 (Microsoft Corporation Surface Go) (16-06-2021 13:42:24)
Running from C:\Users\katra\OneDrive\Desktop
Loaded Profiles: katra
Platform: Windows 10 Home Version 20H2 19042.1052 (X64) Language: English (United States) -> English (United Kingdom)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationService.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <31>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_dc16e5f1dbf8051f\IntelCpHDCPSvc.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_dc16e5f1dbf8051f\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Hardware Compatibility Publisher -> ) C:\Windows\WirelessPowerBackoffService.exe
(Microsoft Windows Hardware Compatibility Publisher -> Windows ® Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\NisSrv.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(ShareX Team) [File not signed] C:\Program Files\ShareX\ShareX.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [672192 2018-05-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [ExpressVPNNotificationService] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationServiceStarter.exe [465120 2020-08-20] (Express Vpn LLC -> ExpressVPN)
HKU\S-1-5-21-481405570-3132218789-2497384090-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [33698888 2021-04-22] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-481405570-3132218789-2497384090-1001\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe [5549280 2021-05-28] (Adobe Inc. -> Adobe Systems Incorporated)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\91.0.4472.101\Installer\chrmstp.exe [2021-06-10] (Google LLC -> Google LLC)
Startup: C:\Users\katra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShareX.lnk [2019-07-30]
ShortcutTarget: ShareX.lnk -> C:\Program Files\ShareX\ShareX.exe (ShareX Team) [File not signed]
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0A56FCA2-C164-4265-BC99-97543EA17BF6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3464B2D4-A66B-4E00-AD5D-0FC39FD67CA1} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-04-22] (Piriform Software Ltd -> Piriform)
Task: {5992B244-9B36-4194-A86F-0E9DC2126940} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-26] (Adobe Inc. -> Adobe Inc.)
Task: {5A6A4293-F187-4144-8163-D4EE9EB730D8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {624803BC-D704-400C-83AC-9F07B1E658FC} - System32\Tasks\OneDrive Standalone Update Task v2 => C:\Users\katra\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {88582656-4486-4657-914C-46102D428173} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-03-31] (Google Inc -> Google LLC)
Task: {BADFD88A-60AA-4C03-9725-907DD60B1A0D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C840488A-4B53-4C03-82CB-FAF6A426B599} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [28082760 2021-04-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {E7D18765-B130-4E93-AFC6-9615E040F185} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-03-31] (Google Inc -> Google LLC)
Task: {EA2AF92C-55AE-4810-8ABC-6C11CDAE4419} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-481405570-3132218789-2497384090-1001] => 36.90.181.93:8080
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 207.164.234.129
Tcpip\..\Interfaces\{221a9511-aa44-4253-a18f-706f5098cc34}: [DhcpNameServer] 192.168.2.1 207.164.234.129
Tcpip\..\Interfaces\{a64836e6-e9d8-4cf8-91c3-4f83ab638da2}: [DhcpNameServer] 13.6.0.99
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\katra\AppData\Local\Microsoft\Edge\User Data\Default [2021-06-10]
Edge DownloadDir: Default -> C:\Users\katra\OneDrive\Desktop
Edge HomePage: Default -> hxxps://www.google.ca/
FireFox:
========
FF DefaultProfile: 49bfheou.default
FF ProfilePath: C:\Users\katra\AppData\Roaming\Mozilla\Firefox\Profiles\49bfheou.default [2021-04-29]
FF ProfilePath: C:\Users\katra\AppData\Roaming\Mozilla\Firefox\Profiles\s9qipza1.default-release [2021-06-16]
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-05-28] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default [2021-06-16]
CHR DownloadDir: C:\Users\katra\OneDrive\Desktop
CHR Notifications: Default -> hxxps://meet.google.com; hxxps://my.questrade.com; hxxps://www.easemytrip.com; hxxps://www.flydubai.com
CHR HomePage: Default -> hxxps://www.google.ca/
CHR StartupUrls: Default -> "hxxps://www.adda52rummy.com/"
CHR Extension: (Slides) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-03-31]
CHR Extension: (Google Drive) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aghbiahbpaijignceidepookljebhfak [2021-01-17]
CHR Extension: (Docs) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-03-31]
CHR Extension: (Google Drive) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-26]
CHR Extension: (YouTube) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-03-31]
CHR Extension: (Adobe Acrobat) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2021-04-29]
CHR Extension: (Sheets) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-03-31]
CHR Extension: (Google Docs Offline) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-05-19]
CHR Extension: (Voot Lite) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjbbefopkdpjpobcbfmbomcmmmmajdob [2020-09-02]
CHR Extension: (Better YouTube Watch History) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lleajdkalfbohpinoaekajagdefaeckd [2019-03-31]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-01-24]
CHR Extension: (AVG Online Security) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbmoafcmbajniiapeidgficgifbfmjfo [2021-02-12]
CHR Extension: (Video Speed Controller) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffaoalbilbmmfgbnbgppjihopabppdk [2020-09-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Gmail) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-26]
CHR Extension: (Chrome Media Router) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-04]
CHR Profile: C:\Users\katra\AppData\Local\Google\Chrome\User Data\Guest Profile [2021-06-04]
CHR HKU\S-1-5-21-481405570-3132218789-2497384090-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-26] (Adobe Inc. -> Adobe Inc.)
R2 ExpressVPNService; C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe [437472 2020-08-20] (Express Vpn LLC -> ExpressVPN)
S2 PanelCalibration Service; C:\WINDOWS\wpcsc64Service.exe [94896 2018-10-07] (Microsoft Windows Hardware Compatibility Publisher -> )
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12871464 2021-04-29] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\NisSrv.exe [2644776 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MsMpEng.exe [136656 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
U2 WirelessPowerBackoffService; C:\WINDOWS\WirelessPowerBackoffService.exe [152240 2018-10-07] (Microsoft Windows Hardware Compatibility Publisher -> )
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 expressvpnsplittunnel; C:\Program Files (x86)\ExpressVPN\splittunnel\expressvpnsplittunnel.sys [37024 2020-08-20] (ExprsVPN LLC -> ExpressVPN)
R3 QIOMem; C:\WINDOWS\System32\drivers\QIOMem.sys [33160 2018-10-07] (WDKTestCert TX7,131534493142891343 -> Surface)
R3 Surface1824DigitizerIntegration; C:\WINDOWS\System32\drivers\Surface1824DigitizerIntegration.sys [36312 2018-05-31] (Microsoft Corporation -> Microsoft Corporation)
R3 SurfaceSystemTelemetry; C:\WINDOWS\System32\drivers\SurfaceSystemTelemetryDriver.sys [159088 2019-12-17] (OEMTest OS Driver Leaf -> Microsoft Corporation)
R3 tapexpressvpn; C:\WINDOWS\System32\drivers\tapexpressvpn.sys [52904 2020-08-20] (ExprsVPN LLC -> The OpenVPN Project)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49568 2021-06-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [425184 2021-06-12] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [76000 2021-06-12] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-06-16 13:42 - 2021-06-16 13:42 - 000000000 ____D C:\FRST
2021-06-08 21:39 - 2021-06-08 21:39 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-06-08 21:39 - 2021-06-08 21:39 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-06-08 21:39 - 2021-06-08 21:39 - 001314120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-06-08 21:39 - 2021-06-08 21:39 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-06-08 21:39 - 2021-06-08 21:39 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-06-08 21:39 - 2021-06-08 21:39 - 000011353 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-06-08 21:38 - 2021-06-08 21:38 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2021-06-08 21:38 - 2021-06-08 21:38 - 001864192 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll
2021-06-08 21:38 - 2021-06-08 21:38 - 001823792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-06-08 21:38 - 2021-06-08 21:38 - 001393496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-06-08 21:38 - 2021-06-08 21:38 - 000657464 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2021-06-08 21:38 - 2021-06-08 21:38 - 000563712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-06-08 21:38 - 2021-06-08 21:38 - 000468440 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2021-06-08 21:38 - 2021-06-08 21:38 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-06-08 21:38 - 2021-06-08 21:38 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-06-08 21:38 - 2021-06-08 21:38 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-06-08 21:38 - 2021-06-08 21:38 - 000097280 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-06-08 21:37 - 2021-06-08 21:37 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll
2021-06-04 21:26 - 2021-06-04 21:26 - 000001178 _____ C:\Users\Public\Desktop\Adda52Poker.lnk
2021-06-04 21:26 - 2021-06-04 21:26 - 000001178 _____ C:\ProgramData\Desktop\Adda52Poker.lnk
2021-06-04 21:26 - 2021-06-04 21:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adda52Poker
2021-06-04 21:26 - 2021-06-04 21:26 - 000000000 ____D C:\Program Files (x86)\Adda52Poker
2021-06-01 03:12 - 2021-06-01 12:34 - 000000000 ____D C:\Users\katra\AppData\Local\PokerClient
2021-06-01 02:18 - 2021-06-04 20:54 - 000000000 ____D C:\AmericasCardroom
2021-06-01 02:18 - 2021-06-01 04:00 - 000000000 ____D C:\Users\katra\AppData\Roaming\Loading
2021-05-19 13:55 - 2021-05-19 09:12 - 000676864 _____ C:\Users\katra\OneDrive\Documents\Yasnep.exe
2021-05-19 13:45 - 2021-05-19 13:45 - 000000000 ____H C:\Users\katra\OneDrive\Documents\Default.rdp
2021-05-18 07:35 - 2021-06-13 23:37 - 000000000 ____D C:\Users\katra\AppData\Roaming\GGPCOM
2021-05-18 07:35 - 2021-05-18 07:35 - 000000000 ____D C:\Users\katra\OneDrive\Documents\POKER-GGPCOM-LIVE
2021-05-18 07:35 - 2021-05-18 07:35 - 000000000 ____D C:\Users\katra\AppData\Roaming\Macromedia
2021-05-18 07:32 - 2021-06-13 23:37 - 000000000 ____D C:\Program Files (x86)\GGPoker
2021-05-18 07:32 - 2021-05-18 07:32 - 000002513 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GGPoker.lnk
2021-05-18 07:32 - 2021-05-18 07:32 - 000002501 _____ C:\Users\Public\Desktop\GGPoker.lnk
2021-05-18 07:32 - 2021-05-18 07:32 - 000002501 _____ C:\ProgramData\Desktop\GGPoker.lnk
2021-05-18 07:32 - 2021-05-18 07:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GGPoker
2021-05-18 01:05 - 2021-06-12 20:13 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-05-18 01:05 - 2021-06-12 20:13 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-05-18 01:05 - 2021-06-12 20:13 - 000002276 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2021-05-18 01:05 - 2021-05-18 01:06 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-05-18 01:05 - 2021-05-18 01:06 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-05-17 09:37 - 2021-05-17 09:37 - 001687040 _____ C:\WINDOWS\system32\libcrypto.dll
2021-05-17 09:37 - 2021-05-17 09:37 - 001163776 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-05-17 09:37 - 2021-05-17 09:37 - 000700928 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2021-05-17 09:36 - 2021-05-17 09:36 - 000165888 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-05-17 09:36 - 2021-05-17 09:36 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2021-05-17 09:36 - 2021-05-17 09:36 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-06-16 13:42 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2021-06-16 13:40 - 2021-04-29 12:31 - 000004166 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{8BA96C7B-6AC0-4E38-9408-9CEE7F3EFBD7}
2021-06-16 13:40 - 2020-12-02 17:05 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-06-16 13:40 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2021-06-16 13:40 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-06-16 13:40 - 2019-03-31 16:14 - 000000000 ____D C:\Program Files\CCleaner
2021-06-15 13:36 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-06-15 13:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-06-14 23:39 - 2019-07-30 17:22 - 000000000 ____D C:\Users\katra\OneDrive\Documents\ShareX
2021-06-13 21:47 - 2020-12-02 17:14 - 000795738 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-06-13 21:39 - 2020-12-16 23:03 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-06-13 21:39 - 2020-12-02 17:16 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-06-13 21:39 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-06-13 21:39 - 2019-06-26 20:11 - 000000000 ____D C:\Intel
2021-06-13 21:38 - 2020-12-02 17:05 - 000008192 ___SH C:\DumpStack.log.tmp
2021-06-13 21:38 - 2019-12-07 05:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-06-13 21:38 - 2019-06-22 16:59 - 000041448 _____ C:\WINDOWS\system32\OV8865_REAR.aiqd
2021-06-13 21:38 - 2019-03-31 15:55 - 000041448 _____ C:\WINDOWS\system32\OV7251_FRONT.aiqd
2021-06-13 21:38 - 2019-03-31 15:55 - 000041448 _____ C:\WINDOWS\system32\OV5693_FRONT.aiqd
2021-06-12 12:29 - 2020-12-02 17:16 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2021-06-12 11:59 - 2018-06-22 18:13 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-06-11 21:53 - 2020-10-01 03:41 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-06-10 18:44 - 2019-03-31 16:04 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-06-10 16:53 - 2021-04-25 11:55 - 000000000 ____D C:\Program Files (x86)\TheSpartanPoker.com
2021-06-10 16:06 - 2019-07-30 17:29 - 000000000 ____D C:\Users\katra\AppData\Roaming\vlc
2021-06-09 16:40 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-06-09 16:36 - 2020-12-02 17:05 - 000257904 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-06-09 16:35 - 2020-12-03 06:06 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2021-06-09 16:35 - 2020-12-03 06:06 - 000000000 ____D C:\WINDOWS\en-GB
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-06-09 04:03 - 2021-04-29 12:58 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-06-08 21:44 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-06-08 21:23 - 2019-03-31 18:06 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-06-08 21:19 - 2019-03-31 18:06 - 132447432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-06-04 20:57 - 2021-04-29 13:39 - 000000000 ____D C:\ProgramData\Mozilla
2021-06-04 20:55 - 2019-03-31 19:16 - 000000000 ____D C:\Program Files (x86)\PokerStars.IN
2021-06-04 20:54 - 2019-03-31 19:16 - 000000000 ____D C:\Users\katra\AppData\Local\PokerStars.IN
2021-06-01 00:27 - 2020-12-02 17:08 - 000000000 ____D C:\Users\katra
2021-05-31 21:48 - 2019-04-01 17:57 - 000000000 ____D C:\Users\katra\AppData\Local\D3DSCache
2021-05-26 14:50 - 2019-07-30 17:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShareX
2021-05-26 14:50 - 2019-07-30 17:22 - 000000000 ____D C:\Program Files\ShareX
2021-05-25 07:48 - 2020-10-01 03:41 - 000470328 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
2021-05-25 07:48 - 2020-02-19 15:59 - 000725304 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2021-05-21 14:55 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-05-20 08:59 - 2021-05-16 05:32 - 000000000 ____D C:\Users\katra\AppData\Local\PokerStars
2021-05-19 13:53 - 2020-12-16 23:04 - 000000000 ____D C:\Users\katra\AppData\Local\TeamViewer
2021-05-18 01:08 - 2019-03-31 15:47 - 000000000 ____D C:\Users\katra\AppData\Local\Packages
2021-05-18 01:01 - 2019-12-07 05:50 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2021-05-17 09:42 - 2019-12-07 05:52 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-06-2021
Ran by katra (administrator) on DESKTOP-AKN8A88 (Microsoft Corporation Surface Go) (16-06-2021 13:42:24)
Running from C:\Users\katra\OneDrive\Desktop
Loaded Profiles: katra
Platform: Windows 10 Home Version 20H2 19042.1052 (X64) Language: English (United States) -> English (United Kingdom)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationService.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <31>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b8e01d9e8716d2a7\igfxCUIService.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_dc16e5f1dbf8051f\IntelCpHDCPSvc.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_dc16e5f1dbf8051f\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Hardware Compatibility Publisher -> ) C:\Windows\WirelessPowerBackoffService.exe
(Microsoft Windows Hardware Compatibility Publisher -> Windows ® Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\NisSrv.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(ShareX Team) [File not signed] C:\Program Files\ShareX\ShareX.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [672192 2018-05-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [ExpressVPNNotificationService] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationServiceStarter.exe [465120 2020-08-20] (Express Vpn LLC -> ExpressVPN)
HKU\S-1-5-21-481405570-3132218789-2497384090-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [33698888 2021-04-22] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-481405570-3132218789-2497384090-1001\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe [5549280 2021-05-28] (Adobe Inc. -> Adobe Systems Incorporated)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\91.0.4472.101\Installer\chrmstp.exe [2021-06-10] (Google LLC -> Google LLC)
Startup: C:\Users\katra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShareX.lnk [2019-07-30]
ShortcutTarget: ShareX.lnk -> C:\Program Files\ShareX\ShareX.exe (ShareX Team) [File not signed]
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0A56FCA2-C164-4265-BC99-97543EA17BF6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3464B2D4-A66B-4E00-AD5D-0FC39FD67CA1} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-04-22] (Piriform Software Ltd -> Piriform)
Task: {5992B244-9B36-4194-A86F-0E9DC2126940} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-26] (Adobe Inc. -> Adobe Inc.)
Task: {5A6A4293-F187-4144-8163-D4EE9EB730D8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {624803BC-D704-400C-83AC-9F07B1E658FC} - System32\Tasks\OneDrive Standalone Update Task v2 => C:\Users\katra\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {88582656-4486-4657-914C-46102D428173} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-03-31] (Google Inc -> Google LLC)
Task: {BADFD88A-60AA-4C03-9725-907DD60B1A0D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C840488A-4B53-4C03-82CB-FAF6A426B599} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [28082760 2021-04-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {E7D18765-B130-4E93-AFC6-9615E040F185} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-03-31] (Google Inc -> Google LLC)
Task: {EA2AF92C-55AE-4810-8ABC-6C11CDAE4419} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-481405570-3132218789-2497384090-1001] => 36.90.181.93:8080
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 207.164.234.129
Tcpip\..\Interfaces\{221a9511-aa44-4253-a18f-706f5098cc34}: [DhcpNameServer] 192.168.2.1 207.164.234.129
Tcpip\..\Interfaces\{a64836e6-e9d8-4cf8-91c3-4f83ab638da2}: [DhcpNameServer] 13.6.0.99
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\katra\AppData\Local\Microsoft\Edge\User Data\Default [2021-06-10]
Edge DownloadDir: Default -> C:\Users\katra\OneDrive\Desktop
Edge HomePage: Default -> hxxps://www.google.ca/
FireFox:
========
FF DefaultProfile: 49bfheou.default
FF ProfilePath: C:\Users\katra\AppData\Roaming\Mozilla\Firefox\Profiles\49bfheou.default [2021-04-29]
FF ProfilePath: C:\Users\katra\AppData\Roaming\Mozilla\Firefox\Profiles\s9qipza1.default-release [2021-06-16]
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-05-28] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default [2021-06-16]
CHR DownloadDir: C:\Users\katra\OneDrive\Desktop
CHR Notifications: Default -> hxxps://meet.google.com; hxxps://my.questrade.com; hxxps://www.easemytrip.com; hxxps://www.flydubai.com
CHR HomePage: Default -> hxxps://www.google.ca/
CHR StartupUrls: Default -> "hxxps://www.adda52rummy.com/"
CHR Extension: (Slides) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-03-31]
CHR Extension: (Google Drive) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aghbiahbpaijignceidepookljebhfak [2021-01-17]
CHR Extension: (Docs) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-03-31]
CHR Extension: (Google Drive) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-26]
CHR Extension: (YouTube) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-03-31]
CHR Extension: (Adobe Acrobat) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2021-04-29]
CHR Extension: (Sheets) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-03-31]
CHR Extension: (Google Docs Offline) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-05-19]
CHR Extension: (Voot Lite) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjbbefopkdpjpobcbfmbomcmmmmajdob [2020-09-02]
CHR Extension: (Better YouTube Watch History) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lleajdkalfbohpinoaekajagdefaeckd [2019-03-31]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-01-24]
CHR Extension: (AVG Online Security) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbmoafcmbajniiapeidgficgifbfmjfo [2021-02-12]
CHR Extension: (Video Speed Controller) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffaoalbilbmmfgbnbgppjihopabppdk [2020-09-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Gmail) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-26]
CHR Extension: (Chrome Media Router) - C:\Users\katra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-04]
CHR Profile: C:\Users\katra\AppData\Local\Google\Chrome\User Data\Guest Profile [2021-06-04]
CHR HKU\S-1-5-21-481405570-3132218789-2497384090-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-26] (Adobe Inc. -> Adobe Inc.)
R2 ExpressVPNService; C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe [437472 2020-08-20] (Express Vpn LLC -> ExpressVPN)
S2 PanelCalibration Service; C:\WINDOWS\wpcsc64Service.exe [94896 2018-10-07] (Microsoft Windows Hardware Compatibility Publisher -> )
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12871464 2021-04-29] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\NisSrv.exe [2644776 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MsMpEng.exe [136656 2021-06-12] (Microsoft Windows Publisher -> Microsoft Corporation)
U2 WirelessPowerBackoffService; C:\WINDOWS\WirelessPowerBackoffService.exe [152240 2018-10-07] (Microsoft Windows Hardware Compatibility Publisher -> )
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 expressvpnsplittunnel; C:\Program Files (x86)\ExpressVPN\splittunnel\expressvpnsplittunnel.sys [37024 2020-08-20] (ExprsVPN LLC -> ExpressVPN)
R3 QIOMem; C:\WINDOWS\System32\drivers\QIOMem.sys [33160 2018-10-07] (WDKTestCert TX7,131534493142891343 -> Surface)
R3 Surface1824DigitizerIntegration; C:\WINDOWS\System32\drivers\Surface1824DigitizerIntegration.sys [36312 2018-05-31] (Microsoft Corporation -> Microsoft Corporation)
R3 SurfaceSystemTelemetry; C:\WINDOWS\System32\drivers\SurfaceSystemTelemetryDriver.sys [159088 2019-12-17] (OEMTest OS Driver Leaf -> Microsoft Corporation)
R3 tapexpressvpn; C:\WINDOWS\System32\drivers\tapexpressvpn.sys [52904 2020-08-20] (ExprsVPN LLC -> The OpenVPN Project)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49568 2021-06-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [425184 2021-06-12] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [76000 2021-06-12] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-06-16 13:42 - 2021-06-16 13:42 - 000000000 ____D C:\FRST
2021-06-08 21:39 - 2021-06-08 21:39 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-06-08 21:39 - 2021-06-08 21:39 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-06-08 21:39 - 2021-06-08 21:39 - 001314120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-06-08 21:39 - 2021-06-08 21:39 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-06-08 21:39 - 2021-06-08 21:39 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-06-08 21:39 - 2021-06-08 21:39 - 000011353 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-06-08 21:38 - 2021-06-08 21:38 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2021-06-08 21:38 - 2021-06-08 21:38 - 001864192 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll
2021-06-08 21:38 - 2021-06-08 21:38 - 001823792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-06-08 21:38 - 2021-06-08 21:38 - 001393496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-06-08 21:38 - 2021-06-08 21:38 - 000657464 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2021-06-08 21:38 - 2021-06-08 21:38 - 000563712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-06-08 21:38 - 2021-06-08 21:38 - 000468440 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2021-06-08 21:38 - 2021-06-08 21:38 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-06-08 21:38 - 2021-06-08 21:38 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-06-08 21:38 - 2021-06-08 21:38 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-06-08 21:38 - 2021-06-08 21:38 - 000097280 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-06-08 21:37 - 2021-06-08 21:37 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll
2021-06-04 21:26 - 2021-06-04 21:26 - 000001178 _____ C:\Users\Public\Desktop\Adda52Poker.lnk
2021-06-04 21:26 - 2021-06-04 21:26 - 000001178 _____ C:\ProgramData\Desktop\Adda52Poker.lnk
2021-06-04 21:26 - 2021-06-04 21:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adda52Poker
2021-06-04 21:26 - 2021-06-04 21:26 - 000000000 ____D C:\Program Files (x86)\Adda52Poker
2021-06-01 03:12 - 2021-06-01 12:34 - 000000000 ____D C:\Users\katra\AppData\Local\PokerClient
2021-06-01 02:18 - 2021-06-04 20:54 - 000000000 ____D C:\AmericasCardroom
2021-06-01 02:18 - 2021-06-01 04:00 - 000000000 ____D C:\Users\katra\AppData\Roaming\Loading
2021-05-19 13:55 - 2021-05-19 09:12 - 000676864 _____ C:\Users\katra\OneDrive\Documents\Yasnep.exe
2021-05-19 13:45 - 2021-05-19 13:45 - 000000000 ____H C:\Users\katra\OneDrive\Documents\Default.rdp
2021-05-18 07:35 - 2021-06-13 23:37 - 000000000 ____D C:\Users\katra\AppData\Roaming\GGPCOM
2021-05-18 07:35 - 2021-05-18 07:35 - 000000000 ____D C:\Users\katra\OneDrive\Documents\POKER-GGPCOM-LIVE
2021-05-18 07:35 - 2021-05-18 07:35 - 000000000 ____D C:\Users\katra\AppData\Roaming\Macromedia
2021-05-18 07:32 - 2021-06-13 23:37 - 000000000 ____D C:\Program Files (x86)\GGPoker
2021-05-18 07:32 - 2021-05-18 07:32 - 000002513 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GGPoker.lnk
2021-05-18 07:32 - 2021-05-18 07:32 - 000002501 _____ C:\Users\Public\Desktop\GGPoker.lnk
2021-05-18 07:32 - 2021-05-18 07:32 - 000002501 _____ C:\ProgramData\Desktop\GGPoker.lnk
2021-05-18 07:32 - 2021-05-18 07:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GGPoker
2021-05-18 01:05 - 2021-06-12 20:13 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-05-18 01:05 - 2021-06-12 20:13 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-05-18 01:05 - 2021-06-12 20:13 - 000002276 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2021-05-18 01:05 - 2021-05-18 01:06 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-05-18 01:05 - 2021-05-18 01:06 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-05-17 09:37 - 2021-05-17 09:37 - 001687040 _____ C:\WINDOWS\system32\libcrypto.dll
2021-05-17 09:37 - 2021-05-17 09:37 - 001163776 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-05-17 09:37 - 2021-05-17 09:37 - 000700928 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2021-05-17 09:36 - 2021-05-17 09:36 - 000165888 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-05-17 09:36 - 2021-05-17 09:36 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2021-05-17 09:36 - 2021-05-17 09:36 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-06-16 13:42 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2021-06-16 13:40 - 2021-04-29 12:31 - 000004166 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{8BA96C7B-6AC0-4E38-9408-9CEE7F3EFBD7}
2021-06-16 13:40 - 2020-12-02 17:05 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-06-16 13:40 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2021-06-16 13:40 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-06-16 13:40 - 2019-03-31 16:14 - 000000000 ____D C:\Program Files\CCleaner
2021-06-15 13:36 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-06-15 13:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-06-14 23:39 - 2019-07-30 17:22 - 000000000 ____D C:\Users\katra\OneDrive\Documents\ShareX
2021-06-13 21:47 - 2020-12-02 17:14 - 000795738 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-06-13 21:39 - 2020-12-16 23:03 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-06-13 21:39 - 2020-12-02 17:16 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-06-13 21:39 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-06-13 21:39 - 2019-06-26 20:11 - 000000000 ____D C:\Intel
2021-06-13 21:38 - 2020-12-02 17:05 - 000008192 ___SH C:\DumpStack.log.tmp
2021-06-13 21:38 - 2019-12-07 05:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-06-13 21:38 - 2019-06-22 16:59 - 000041448 _____ C:\WINDOWS\system32\OV8865_REAR.aiqd
2021-06-13 21:38 - 2019-03-31 15:55 - 000041448 _____ C:\WINDOWS\system32\OV7251_FRONT.aiqd
2021-06-13 21:38 - 2019-03-31 15:55 - 000041448 _____ C:\WINDOWS\system32\OV5693_FRONT.aiqd
2021-06-12 12:29 - 2020-12-02 17:16 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2021-06-12 11:59 - 2018-06-22 18:13 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-06-11 21:53 - 2020-10-01 03:41 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-06-10 18:44 - 2019-03-31 16:04 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-06-10 16:53 - 2021-04-25 11:55 - 000000000 ____D C:\Program Files (x86)\TheSpartanPoker.com
2021-06-10 16:06 - 2019-07-30 17:29 - 000000000 ____D C:\Users\katra\AppData\Roaming\vlc
2021-06-09 16:40 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-06-09 16:36 - 2020-12-02 17:05 - 000257904 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-06-09 16:35 - 2020-12-03 06:06 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2021-06-09 16:35 - 2020-12-03 06:06 - 000000000 ____D C:\WINDOWS\en-GB
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-06-09 16:35 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-06-09 04:03 - 2021-04-29 12:58 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-06-08 21:44 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-06-08 21:23 - 2019-03-31 18:06 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-06-08 21:19 - 2019-03-31 18:06 - 132447432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-06-04 20:57 - 2021-04-29 13:39 - 000000000 ____D C:\ProgramData\Mozilla
2021-06-04 20:55 - 2019-03-31 19:16 - 000000000 ____D C:\Program Files (x86)\PokerStars.IN
2021-06-04 20:54 - 2019-03-31 19:16 - 000000000 ____D C:\Users\katra\AppData\Local\PokerStars.IN
2021-06-01 00:27 - 2020-12-02 17:08 - 000000000 ____D C:\Users\katra
2021-05-31 21:48 - 2019-04-01 17:57 - 000000000 ____D C:\Users\katra\AppData\Local\D3DSCache
2021-05-26 14:50 - 2019-07-30 17:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShareX
2021-05-26 14:50 - 2019-07-30 17:22 - 000000000 ____D C:\Program Files\ShareX
2021-05-25 07:48 - 2020-10-01 03:41 - 000470328 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
2021-05-25 07:48 - 2020-02-19 15:59 - 000725304 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2021-05-21 14:55 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-05-20 08:59 - 2021-05-16 05:32 - 000000000 ____D C:\Users\katra\AppData\Local\PokerStars
2021-05-19 13:53 - 2020-12-16 23:04 - 000000000 ____D C:\Users\katra\AppData\Local\TeamViewer
2021-05-18 01:08 - 2019-03-31 15:47 - 000000000 ____D C:\Users\katra\AppData\Local\Packages
2021-05-18 01:01 - 2019-12-07 05:50 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-05-18 01:01 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2021-05-17 09:42 - 2019-12-07 05:52 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt =======================