(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe Security intelligence Version: AV: 1.351.958.0, AS: 1.351.958.0, NIS: 1.351.958.0 2021-10-13 16:41 - 2021-10-13 17:14 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\Wireshark "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{b2522ebf-6a65-406b-9bc7-1ce57d2a2c7c}" => removed successfully 2021-10-04 10:59 - 2021-10-04 10:59 - 000000000 ____D C:\Tor Browser Task: {8c4fdb45-99dd-42f3-8984-07e5f8dff7f4} - no filepath ==================== Safe Mode (Whitelisted) ================== "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{257fa8a3-d406-4d7e-99a9-c9e255f9f6f0}" => removed successfully Task: {80442d75-04ca-4d81-8c53-a52f6d4b32b0} - no filepath 2021-10-07 17:59 - 2021-10-20 15:14 - 000000427 _____ C:\Users\Pepega\Desktop\Adjectives.txt 2021-10-02 23:03 - 2021-09-14 14:39 - 000043408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\NvModuleTracker.sys FF Extension: (Kurgzsekseta) - C:\Users\Pepega\AppData\Roaming\Mozilla\Firefox\Profiles\q42kwfcc.default-release\Extensions\{e8f3b919-d290-4270-b66f-29f3fdbb1986}.xpi [2021-10-05] 2021-10-22 22:53 - 2019-03-19 15:52 - 000000000 ____D C:\Windows\system32\NDF Engine Version: AM: 1.1.18600.4, NIS: 1.1.18600.4 Resetting , OK! Ran by Pepega (25-10-2021 08:46:25) Run:1 2021-10-22 11:43 - 2021-10-22 11:44 - 000000000 ____D C:\Riot Games 2021-10-03 16:54 - 2021-10-03 16:54 - 000000223 _____ C:\Users\Pepega\Desktop\Apex Legends.url HKU\S-1-5-21-326566074-3447909417-183555969-1001\\StartupApproved\Run: => "OneDrive" 2021-09-30 14:35 - 2021-09-30 14:35 - 001988096 _____ (GIGABYTE) [File not signed] C:\Program Files (x86)\GIGABYTE\RGBFusion\AACSSD_Lib.dll Task: {2d5dd02e-d989-436b-a3d0-b2283ce2c942} - no filepath AMD_Chipset_Drivers (HKLM-x32\\{c370a4bd-5e86-489d-b1a5-54ceee532d20}) (Version: 2.15.07.2229 - Advanced Micro Devices, Inc.) Hidden 2021-10-02 23:34 - 2021-10-02 23:34 - 000000000 ____D C:\ProgramData\Windows App Certification Kit 2021-10-02 23:25 - 2021-10-04 18:19 - 000000000 ____D C:\Windows\system32\3082 HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => could not remove, key could be protected 2021-10-02 23:20 - 2021-10-02 23:20 - 000001737 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2022 Preview.lnk "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{d4928d07-631c-4754-af4f-3f5f19729138}" => removed successfully 2021-10-02 23:04 - 2021-10-04 18:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation start CustomCLSID: HKU\S-1-5-21-326566074-3447909417-183555969-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Pepega\AppData\Local\Microsoft\OneDrive\21.170.0822.0002\amd64\FileSyncShell64.dll => No File Task: {10914230-EDDF-4324-BD6D-2A05C1496959} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1261424 2021-09-14] (NVIDIA Corporation -> NVIDIA Corporation) Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{e21ec10f-b0f2-4d8c-ac9d-e74491370460}" => removed successfully Task: {9787f435-46f9-458d-9737-9ba0cb4bc234} - no filepath at System.Windows.Forms.Clipboard.GetDataObject() 2021-10-02 23:04 - 2021-09-14 14:39 - 000078192 _____ C:\Windows\system32\FvSDK_x64.dll Task: {e0ba60f1-d26f-4185-8bb0-04b05678ff5a} - no filepath Resetting Subinterface, OK! ENE_X_AIC_HAL (HKLM-x32\\{ec10ac91-2e61-460a-b493-33f794a07682}) (Version: 1.0.4.0 - ENE TECHNOLOGY INC.) Hidden Detection Type: Concrete npcap_wifi => service removed successfully C:\Users\Pepega\AppData\Local\Update.exe ========= "%WINDIR%\SYSTEM32\lodctr.exe" /R ========= FirewallRules: [TCP Query User{3D3D13C6-EB42-4BF7-9989-E995CB143820}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.) 2021-10-16 20:39 - 2021-10-16 20:49 - 000000000 ____D C:\Program Files\Adobe I (A-Volute SAS -> Nahimic) C:\Windows\System32\NahimicService.exe 2021-10-15 11:56 - 2021-10-15 12:04 - 000000000 ____D C:\Users\Pepega\AppData\Roaming\ChangZhi2 Task: {ab7dbf26-2e26-445a-a7dd-f60ac12f19a6} - no filepath 2021-10-03 09:12 - 2021-10-03 09:12 - 000000000 ____D C:\Users\Pepega\source