R3 CorsairVHidDriver; C:\windows\System32\drivers\CorsairVHidDriver.sys [22968 2022-08-01] (Microsoft Windows Hardware Compatibility Publisher -> Corsair) Become a simple traveller and adventure seeker, explore huge world of Gedonia, progress your character any way you want, discover hidden treasures and mysteries and fight vast array of enemies. ==================== Faulty Device Manager Devices ============ 2022-08-22 04:14 - 2022-08-22 04:14 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\Corsair 2022-09-19 00:28 - 2022-09-19 00:28 - 000002017 _____ C:\Users\Public\Desktop\Oculus.lnk Origin (HKLM-x32\\Origin) (Version: 10.5.113.50894 - Electronic Arts, Inc.) 2022-09-13 06:57 - 2022-01-04 13:42 - 000473128 _____ C:\windows\system32\FNTCACHE.DAT 2022-08-27 00:56 - 2022-06-24 16:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blackmagic Design 2022-09-04 17:23 - 2021-06-05 22:10 - 000000000 ____D C:\windows\LiveKernelReports The file which is running by the task will not be moved.) AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:41964AA945 [3314] 2022-09-04 01:01 - 2022-09-04 01:01 - 000001982 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Streamlabs Desktop.lnk window.__mirage2 = {petok:"IWw0apYLnp8QXihy_VE.WonRt7er52GCV8mDXMrEjl0-1800-0"}; Task: {56640CC7-1B14-4DE5-A992-AEE87C843206} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-05-05] (Nvidia Corporation -> NVIDIA Corporation) Afficher/masquer la navigation. (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_47917a79b8c7fd22\Display.NvContainer\NVDisplay.Container.exe <2> 2022-09-01 04:04 - 2022-07-15 08:57 - 000002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk AV: Symantec Endpoint Protection (Enabled - Up to date) {FC90FA28-5CE6-9068-FC99-1C67339C0047} IFEO\EOSnotify.exe: [Debugger] / R2 CorsairLLAccessC2D033F14715AA7325305EA42FBFC65BF867CC1D; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CorsairLLAccess64.sys [21752 2022-06-21] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) U4 dmwappushservice; no ImagePath C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk => ":B026C77744" ADS removed successfully 2022-09-16 15:59 - 2022-05-13 18:02 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\vlc Error: (09/19/2022 03:05:44 AM) (Source: Application Error) (EventID: 1000) (User: ) HKU\S-1-5-21-479614032-2295716511-2174497491-1002\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION High Score Modes. Task: {08CC3C71-04DA-4C86-AF42-1F7067326362} - System32\Tasks\GoogleUpdateTaskMachineCore{A6531C16-C0AF-4456-87D5-BD1A9B087920} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [168632 2022-05-25] (Google LLC -> Google LLC) 2022-09-19 00:31 - 2022-09-19 01:57 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\OculusClient 2022-08-23 13:40 - 2022-01-04 13:42 - 000003412 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2022-08-22 04:14 - 2022-08-22 04:14 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\Corsair Description: The Microsoft Update Health Service service failed to start due to the following error: 2022-09-16 04:26 - 2022-08-17 23:25 - 000000000 ____D C:\Users\Tyson\AppData\Roaming\EasyAntiCheat 2022-09-04 01:01 - 2022-09-20 19:17 - 000000000 ____D C:\Program Files\Streamlabs OBS 2022-09-18 23:08 - 2022-04-05 09:34 - 000000000 ____D C:\Program Files\Mozilla Firefox FirewallRules: [{1412F75F-1473-49FA-97D0-605B814B5951}] => (Allow) D:\Steam\SteamApps\common\SteamVR\bin\win32\vrstartup.exe (Valve Corp. -> Valve Corporation) CHR Extension: (Grammarly: Grammar Checker and Writing App) - C:\Users\Tyson\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2022-09-13] Task: {1AEAE201-6F48-4C77-82CB-E97D4A8E5F80} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138680 2022-04-05] (Microsoft Corporation -> Microsoft Corporation) 2022-08-22 04:13 - 2022-08-22 04:14 - 000000000 ____D C:\ProgramData\Corsair Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.) ================== FirewallRules: [{E73436CE-7963-4E98-A7AE-B620A32AEA57}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [10450928 2022-08-18] (Riot Games, Inc. -> Riot Games, Inc.) Wrapping Up: Discord Easter Eggs. BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2022-08-03] (Adobe Inc. -> Adobe Systems Incorporated) Available Virtual: 121042.92 MB ======= 2022-08-27 01:03 - 2022-08-27 01:03 - 000000000 ____D C:\Users\Tyson\AppData\Local\Paradox Interactive S3 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.3.7393.4000.105\Bin64\snac64.exe [215648 2022-02-25] (Symantec Corporation -> Broadcom) 2022-09-18 23:19 - 2022-09-18 23:21 - 000000000 ____D C:\AdwCleaner 2022-08-25 16:41 - 2021-06-05 22:10 - 000000000 ____D C:\windows\system32\NDF Intel Chipset Device Software (HKLM\\{C6A1126A-6ED6-4231-BA48-4DA77986FA1C}) (Version: 10.1.18950.8298 - Intel Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) It lets you play the iconic video game, Snake, within your Discord server! FirewallRules: [{BCA7A946-F51A-4015-ACB0-502C2D5DB19C}] => (Allow) C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voicemod Sociedad Limitada -> Voicemod) Resetting Compartment Forwarding, OK! //) (Brio) [File not signed] C:\Program Files\FolderSize\FolderSize.exe FirewallRules: [{BF7B5D38-83F1-406F-A470-CEEDC8D793B2}] => (Allow) D:\Steam\SteamApps\common\FPSAimTrainer\FPSAimTrainer.exe (Int3 Software AB -> Int3 Software AB) ==================== Association (Whitelisted) ================= 2022-08-31 01:24 - 2022-05-25 01:10 - 000003496 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineUA{52819A4A-6F97-4F51-A9DF-F8722C17E431} It has done this 1 time(s). The game is quite appreciative too I mean, who doesnt want to see the YOU HECKIN WON! message despite getting only a few points. CHR HKLM-x32\\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] 2022-09-19 00:28 - 2022-09-19 00:28 - 000075280 _____ (Windows Win 7 DDK provider) C:\windows\system32\Drivers\oculusvad.sys Fault offset: 0x000000000001d7d1 Streamlabs Desktop 1.10.0 (HKLM\\029c4619-0385-5543-9426-46f9987161d9) (Version: 1.10.0 - General Workings, Inc.) Adobe Lightroom (HKLM-x32\\LRCC_5_5) (Version: 5.5 - Adobe Inc.) 2022-09-19 03:05 - 2022-05-13 18:58 - 000000000 ____D C:\Users\Tyson\AppData\Local\CrashDumps Task: {0F07B63F-7BBC-4F1F-BF1F-9D28D3EE4A4E} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-479614032-2295716511-2174497491-1002 => C:\Users\Tyson\AppData\Local\MEGAsync\MEGAupdater.exe [2531496 2022-06-11] (Mega Limited -> ) 2022-08-22 04:13 - 2022-08-22 04:14 - 000000000 ____D C:\ProgramData\Corsair (If an entry is included in the fixlist, the task (.job) file will be moved. (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.) C:\Windows\System32\CorsairGamingAudioCfgService64.exe 2022-09-21 08:06 - 2022-05-13 20:49 - 000000000 ____D C:\Steam R3 logi_joy_bus_enum; C:\windows\system32\drivers\logi_joy_bus_enum.sys [33528 2022-05-13] (WDKTestCert builder,132743893872553407 -> Logitech) R1 ccSettings_{BEC9211B-09AC-4B5B-9D31-561ADFF81A33}; C:\windows\System32\Drivers\SEP\0E031CE1\0FA0.105\x64\ccSetx64.sys [189392 2022-02-25] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) S3 OVRLibraryService; C:\Program Files\Oculus\Support\oculus-librarian\OVRLibraryService.exe [148032 2022-09-19] (Oculus VR, LLC -> Facebook Technologies, LLC) FirewallRules: [TCP Query User{05590699-DA42-460B-91B9-EE6B37369FBC}C:\program files\qbittorrent\qbittorrent.exe] => (Block) C:\program files\qbittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed] R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11666384 2022-03-29] (Microsoft Corporation -> Microsoft Corporation) S0 MbamElam; C:\windows\System32\DRIVERS\MbamElam.sys [21480 2022-07-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) While you are here, be sure to find out which are the best music bots that are still working, as well as the best Game bots and moderation bots to use. FirewallRules: [{19B257A1-CEE8-433D-8799-49D0E85924EA}] => (Allow) D:\Steam\SteamApps\common\MultiVersus\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.) S3 WdBoot; C:\windows\system32\drivers\wd\WdBoot.sys [48536 2022-01-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) 2022-09-16 04:26 - 2021-06-05 22:10 - 000000000 ____D C:\windows\SystemTemp IFEO\Windows10Upgrade.exe: [Debugger] / Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden FirewallRules: [{F43DA5C1-2526-4139-860C-C0510F062FCA}] => (Block) %SystemRoot%\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe => No File 2022-09-18 23:28 - 2022-05-13 18:22 - 000000000 ____D C:\ProgramData\NVIDIA HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION S2 CorsairUniwillService; C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueUniwillService.exe [107568 2022-08-05] (Corsair Memory, Inc. -> Corsair Memory, Inc.) ========= netsh advfirewall set allprofiles state ON ========= Guest (S-1-5-21-479614032-2295716511-2174497491-501 - Limited - Disabled) The welcome screen then shows up, including some super cute and amazing artwork! The vast world of Gedonia is a beautiful place with a lot of unexplored areas, and you are just a simple adventurer . Error: (09/21/2022 08:31:49 AM) (Source: DCOM) (EventID: 10010) (User: INWIN809) ==================== SigCheck ============================ HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" A wall spawns every other apple eaten, starting on the first apple. HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\StartupApproved\Run: => "Spotify" Tyson (S-1-5-21-479614032-2295716511-2174497491-1002 - Administrator - Enabled) => C:\Users\Tyson WinRAR 6.11 (64-bit) (HKLM\\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH) System errors: (If an entry is included in the fixlist, the file/folder will be moved.) FirewallRules: [{97FE1736-9F1F-4227-BCEC-4CCA75EEFCB4}] => (Allow) D:\Steam\SteamApps\common\wallpaper_engine\bin\diagnostics32.exe (Skutta, Kristjan -> ) (services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe Description: The Microsoft Update Health Service service failed to start due to the following error: 2022-09-13 06:48 - 2022-09-13 06:48 - 000069632 _____ (Adobe Systems) C:\windows\system32\atmlib.dll AAAA 2001:8003:3A5B:C700:0000:0000:0000:0F40 ShortcutTarget: MEGAsync.lnk -> C:\Users\Tyson\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6215960 2022-09-13] (Microsoft Windows Publisher -> Microsoft Corporation) Do you have other Discord Easter eggs you'd like to share in the comments section? R0 SymEFASI; C:\windows\System32\drivers\symefasi\0704030.013\symefasi64.sys [2080248 2022-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) Discord Virus is the collective term given to the malware programs found on the Discord app or distributed via Discord. FirewallRules: [{2089FA96-87E2-4759-A593-A31D1EE2D411}] => (Allow) D:\Steam\SteamApps\common\Yakuza 0\media\Yakuza0.exe () [File not signed] C:\windows\system32\GroupPolicy\User => moved successfully Boot Mode: Normal 2022-08-19 00:58 - 2022-08-19 00:58 - 000000000 ____D C:\Users\Tyson\AppData\Local\SolidDocuments Adobe Media Encoder 2022 (HKLM-x32\\AME_22_6) (Version: 22.6 - Adobe Inc.) FirewallRules: [{B16335B7-1027-4EFC-88D0-277ADCD2D0A1}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-479614032-2295716511-2174497491-1002\\Run: [Voicemod] => C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe [7291800 2022-03-18] (Voicemod Sociedad Limitada -> Voicemod) Epic Games Launcher (HKLM-x32\\{FAC47927-1A6A-4C6E-AD7D-E9756794A4BC}) (Version: 1.3.23.0 - Epic Games, Inc.) IFEO\osppsvc.exe: [VerifierDlls] SppExtComObjHook.dll The following corrective action will be taken in 60000 milliseconds: Restart the service. The "AlternateShell" will be restored.) I also just saw magnifying glasses appear on the icons after the other two for the first time. CPUID HWMonitor 1.46 (HKLM\\CPUID HWMonitor_is1) (Version: 1.46 - CPUID, Inc.) FirewallRules: [TCP Query User{D022303E-78DE-4FBD-8EE1-9D144739CF3C}C:\users\tyson\appdata\local\medal\app-4.1000.0\medal.exe] => (Allow) C:\users\tyson\appdata\local\medal\app-4.1000.0\medal.exe (Ferox Games B.V. -> Medal B.V.) FirewallRules: [{80040ED2-A504-49E9-A1AE-1BD99B078EE2}] => (Allow) D:\Steam\SteamApps\common\Yakuza 0\media\Yakuza0.exe () [File not signed] 2022-09-21 08:28 - 2022-09-21 08:35 - 000000000 ___RD C:\Users\Tyson\OneDrive (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe HKLM\\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [3071192 2022-08-18] (Riot Games, Inc. -> Riot Games, Inc.) 2022-09-18 23:09 - 2021-06-05 22:10 - 000000000 ___HD C:\Program Files\WindowsApps ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-09-07] (Adobe Inc. -> ) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-09-12] (NVIDIA Corp.) (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe CHR Profile: C:\Users\Tyson\AppData\Local\Google\Chrome\User Data\Default [2022-09-19] All Rights Reserved. "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAMeetNow" => removed successfully (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_0797c0ea8580ae89\IntelCpHDCPSvc.exe The file will not be moved.) FirewallRules: [TCP Query User{9A24F9FB-9043-4592-A156-345C3448A69E}C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2372_gtaprocess.exe] => (Allow) C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2372_gtaprocess.exe (TASKS ME - IT DEVELOPMENT (AILENE BULALACAO TAGOLGOL) -> Cfx.re) ======= (If an entry is included in the fixlist, it will be removed.) 2022-09-13 06:48 - 2022-09-13 06:48 - 000485376 _____ (Microsoft Corporation) C:\windows\SysWOW64\PhotoScreensaver.scr ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Tyson\AppData\Local\MEGAsync\ShellExtX64.dll [2022-06-11] (Mega Limited -> ) Glutted snake dies when eating an apple. 2022-09-18 10:29 - 2022-05-25 01:10 - 000002253 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk (explorer.exe ->) (Abbingdon Global Limited -> ) C:\Program Files\iFi\USB_HD_Audio_Driver\iFiHDUSBAudio_cpl.exe R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [527864 2022-06-28] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) Would anyone be able to help me out? Adobe Notification Client -> C:\Program Files\WindowsApps\AdobeNotificationClient_3.0.1.1_x86__enpm4xejd91yc [2022-06-13] (Adobe Systems Incorporated) The most important aspect is knowing how to access the game and the steps required to find it. (Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe 2022-09-13 06:56 - 2021-06-05 22:10 - 000000000 ____D C:\windows\SysWOW64\oobe 2022-08-28 02:33 - 2022-08-28 02:33 - 000000000 ____D C:\Users\Tyson\.insomniac (If an entry is included in the fixlist, it will be removed.) FirewallRules: [UDP Query User{CFFD12EB-329C-4BD6-BE1F-205E9C4B6BD9}C:\users\tyson\appdata\local\fivem\fivem.exe] => (Allow) C:\users\tyson\appdata\local\fivem\fivem.exe (TASKS ME - IT DEVELOPMENT (AILENE BULALACAO TAGOLGOL) -> Cfx.re) CustomCLSID: HKU\S-1-5-21-479614032-2295716511-2174497491-1002_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems) Microsoft Office Professional Plus 2021 - en-us (HKLM\\ProPlus2021Retail - en-us) (Version: 16.0.15028.20160 - Microsoft Corporation) the best snake game there is. Intel Serial IO (HKLM\\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.2131.26 - Intel Corporation) FirewallRules: [UDP Query User{5760B17F-8A79-49E6-9CE2-783CEB6417EC}C:\users\tyson\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\tyson\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [100424 2022-05-02] (Apple Inc. -> Apple Inc.) FirewallRules: [UDP Query User{AAEC9880-7EAD-4204-9D42-FA0448950BAB}C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_fxdk_b2545_gameruntime.exe] => (Allow) C:\users\tyson\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_fxdk_b2545_gameruntime.exe => No File HKLM\\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [362056 2022-05-05] (Apple Inc. -> Apple Inc.)