Here are the Farbar files:Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-09-2020

Ran by Tosh (administrator) on DESKTOP-8QAAIOR (TOSHIBA Satellite C55-A) (11-10-2020 23:06:47)
Running from C:\Users\Tosh\Desktop
Loaded Profiles: Tosh
Platform: Windows 10 Pro Version 1903 18362.30 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Safe Mode (minimal)
Tutorial for Farbar Recovery Scan Tool:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {E0B9BAA3-F611-4D77-A55E-F33450256417} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [123600 2020-07-20] (Mozilla Corporation -> Mozilla Foundation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{3e3cd304-212b-4bd5-817b-c38a53955a43}: [NameServer],

FF DefaultProfile: gvoj526c.default
FF ProfilePath: C:\Users\Tosh\AppData\Roaming\Mozilla\Firefox\Profiles\gvoj526c.default [2020-10-06]
FF ProfilePath: C:\Users\Tosh\AppData\Roaming\Mozilla\Firefox\Profiles\pc3vawjg.default-release [2020-10-07]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5773592 2019-03-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [746504 2020-07-10] (Oracle Corporation -> Oracle Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-18] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-18] (Microsoft Corporation -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [237840 2020-07-11] (Oracle Corporation -> Oracle Corporation)
S1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [247232 2020-07-11] (Oracle Corporation -> Oracle Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46472 2019-03-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [333784 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [62432 2019-03-18] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Three months (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-10-11 23:11 - 2020-10-11 23:11 - 000000000 ____D C:\Users\Tosh\Desktop\features
2020-10-11 23:11 - 2020-10-11 23:11 - 000000000 ____D C:\Users\Tosh\Desktop\browser
2020-10-11 23:06 - 2020-10-11 23:10 - 000004685 _____ C:\Users\Tosh\Desktop\FRST.txt
2020-10-11 23:06 - 2020-09-30 23:11 - 002299392 _____ (Farbar) C:\Users\Tosh\Desktop\FRST64.exe
2020-10-11 23:06 - 2016-07-08 19:42 - 477640174 _____ C:\Users\Tosh\Desktop\BaseSystem.dmg
2020-10-11 23:05 - 2020-10-01 23:43 - 3774416660 _____ C:\Users\Tosh\Desktop\macOS Catalina Image File by Techbland.rar
2020-10-11 22:56 - 2020-10-11 22:56 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2020-10-11 22:55 - 2020-10-11 23:10 - 000193232 _____ C:\Windows\ntbtlog.txt
2020-10-08 13:25 - 2020-09-01 19:27 - 000000104 _____ C:\Users\Tosh\Desktop\kali-linux-2020.3-installer-amd64.iso.txt.sha256sum
2020-10-08 13:25 - 2020-08-13 00:39 - 004280352 _____ C:\Users\Tosh\Desktop\
2020-10-08 13:23 - 2020-09-01 19:27 - 3964551168 _____ C:\Users\Tosh\Desktop\kali-linux-2020.3-installer-amd64.iso
2020-10-08 13:11 - 2020-10-08 13:11 - 000000000 ___HD C:\Users\Tosh\MicrosoftEdgeBackups
2020-10-07 14:10 - 2020-10-08 04:57 - 001305038 _____ C:\Users\Tosh\Desktop\TransmogProvider.dll
2020-10-07 13:41 - 2020-10-07 13:41 - 000000000 ____D C:\Users\Tosh\AppData\Local\Apps\2.0
2020-10-07 08:16 - 2020-10-07 08:16 - 000000000 ____D C:\Users\Tosh\AppData\Local\ElevatedDiagnostics
2020-10-07 08:12 - 2020-10-07 08:12 - 000000000 ____D C:\Users\Tosh\AppData\Local\PeerDistRepub
2020-10-07 08:11 - 2020-10-07 08:11 - 000000000 ____D C:\Windows\system32\Tasks\S-1-5-21-617748592-3028831530-4159234170-1001
2020-10-07 07:50 - 2020-10-07 13:00 - 000000000 ____D C:\Users\Tosh\AppData\Local\Packages
2020-10-07 06:28 - 2020-10-07 06:28 - 000001890 _____ C:\Windows\diagwrn.xml
2020-10-07 06:28 - 2020-10-07 06:28 - 000001890 _____ C:\Windows\diagerr.xml
2020-10-07 06:12 - 2020-10-07 06:12 - 000000000 ____D C:\Users\Tosh\AppData\Local\Microsoft_Corporation
2020-10-06 19:54 - 2020-10-06 19:54 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2020-10-06 19:54 - 2020-10-06 19:54 - 000000000 ____D C:\Program Files (x86)\ASUS
2020-10-06 19:54 - 2003-04-21 21:46 - 000061440 _____ (Printing Communications Assoc., Inc. (PCAUSA)) C:\Windows\SysWOW64\ASIW32N50.dll
2020-10-06 19:54 - 2002-09-10 19:35 - 000016302 _____ (Printing Communications Assoc., Inc. (PCAUSA)) C:\Windows\SysWOW64\ASINDIS5.sys
2020-10-06 19:54 - 2001-04-16 05:48 - 000015577 _____ C:\Windows\SysWOW64\ASINDIS3.vxd
2020-10-06 18:06 - 2020-10-06 18:07 - 000000000 ____D C:\Users\Tosh\Desktop\firefox
2020-10-06 18:06 - 2020-10-06 18:06 - 000000000 ____D C:\Users\Tosh\VirtualBox VMs
2020-10-06 18:05 - 2020-09-21 16:31 - 1909662002 _____ C:\Users\Tosh\Desktop\InstallMacOSX.dmg
2020-10-06 18:04 - 2020-10-07 05:43 - 000000000 ____D C:\Users\Tosh\.VirtualBox
2020-10-06 18:04 - 2020-10-06 18:10 - 000001957 _____ C:\Windows\system32\VBoxSDS.log.1
2020-10-06 18:04 - 2020-10-06 18:04 - 000000000 ____D C:\Users\Tosh\AppData\Roaming\WinRAR
2020-10-06 18:04 - 2018-04-02 00:34 - 006271164 _____ (Acresso Software Inc. ) C:\Users\Tosh\Desktop\Rescue.exe
2020-10-06 18:03 - 2020-09-21 16:32 - 345393604 _____ C:\Users\Tosh\Desktop\video.mp4
2020-10-06 18:03 - 2020-07-28 01:53 - 007375191 _____ C:\Users\Tosh\Desktop\
2020-10-06 18:03 - 2020-07-26 10:46 - 022679552 _____ C:\Users\Tosh\Desktop\tomato-RT-N66U_AT-RT-AC6x-3.5-140-AIO-64K.trx
2020-10-06 18:02 - 2020-10-06 18:02 - 000000000 ____D C:\Users\Tosh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2020-10-06 18:02 - 2020-10-06 18:02 - 000000000 ____D C:\Program Files\WinRAR
2020-10-06 18:02 - 2020-08-13 18:47 - 001841997 _____ ( C:\Users\Tosh\Desktop\YUMI-
2020-10-06 18:01 - 2020-10-06 18:01 - 000000000 ____D C:\Program Files (x86)\DAMN NFO Viewer
2020-10-06 18:00 - 2020-10-06 18:01 - 000000000 ____D C:\Program Files\Kodi
2020-10-06 18:00 - 2020-10-06 18:00 - 000000000 ____D C:\Program Files\Malwarebytes
2020-10-06 17:59 - 2020-10-06 17:59 - 000001149 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
2020-10-06 17:59 - 2020-08-14 13:45 - 040732864 _____ C:\Users\Tosh\Desktop\vlc-3.0.11-win32.exe
2020-10-06 17:59 - 2020-08-13 00:39 - 001155640 _____ (Akeo Consulting) C:\Users\Tosh\Desktop\rufus-3.11.exe
2020-10-06 17:59 - 2020-07-11 11:47 - 001030096 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2020-10-06 17:59 - 2020-07-11 11:47 - 000187456 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2020-10-06 17:58 - 2020-10-06 17:58 - 000000000 ____D C:\Program Files\Oracle
2020-10-06 17:30 - 2020-10-08 04:29 - 000000000 ____D C:\Users\Tosh\Desktop\New folder (2)
2020-10-06 17:29 - 2020-10-07 12:59 - 000000000 ____D C:\Users\Tosh\AppData\LocalLow\Mozilla
2020-10-06 17:29 - 2020-10-06 17:29 - 000000993 _____ C:\Users\Public\Desktop\Firefox.lnk
2020-10-06 17:29 - 2020-10-06 17:29 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2020-10-06 17:29 - 2020-10-06 17:29 - 000000000 ____D C:\Users\Tosh\AppData\Roaming\Mozilla
2020-10-06 17:29 - 2020-10-06 17:29 - 000000000 ____D C:\Users\Tosh\AppData\Local\Mozilla
2020-10-06 17:29 - 2020-10-06 17:29 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-10-06 17:29 - 2020-10-06 17:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-10-06 17:17 - 2020-10-08 03:32 - 000000000 ____D C:\UBIOS
2020-10-06 17:15 - 2020-10-11 23:08 - 000000000 ____D C:\FRST
2020-10-06 17:14 - 2020-10-06 17:14 - 000000000 ____D C:\Users\Tosh\AppData\Roaming\WinBatch
2020-10-06 17:13 - 2020-10-06 17:13 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2020-10-06 17:07 - 2020-10-06 17:07 - 000000028 _____ C:\Users\Tosh\Documents\hacked.txt
2020-10-06 16:57 - 2020-10-06 17:41 - 000000000 ____D C:\Users\Tosh\Desktop\New folder
2020-10-06 12:37 - 2020-10-06 19:48 - 000000000 ____D C:\Users\Tosh\AppData\Local\Comms
2020-10-06 12:37 - 2020-10-06 12:37 - 000000000 ___RD C:\Users\Tosh\OneDrive
2020-10-06 10:17 - 2020-10-07 06:28 - 000000000 ____D C:\Windows\Panther
2020-10-06 09:34 - 2020-10-06 09:34 - 000001446 _____ C:\Users\Tosh\Desktop\Microsoft Edge.lnk
2020-10-06 09:34 - 2020-10-06 09:34 - 000000000 ____D C:\Users\Tosh\AppData\Local\MicrosoftEdge
2020-10-06 09:33 - 2020-10-06 09:33 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-10-06 09:33 - 2020-10-06 09:33 - 000000000 ___RD C:\Users\Tosh\3D Objects
2020-10-06 09:33 - 2020-10-06 09:33 - 000000000 ____D C:\Users\Tosh\AppData\Roaming\Adobe
2020-10-06 09:33 - 2020-10-06 09:33 - 000000000 ____D C:\Users\Tosh\AppData\Local\VirtualStore
2020-10-06 09:33 - 2020-10-06 09:33 - 000000000 ____D C:\Users\Tosh\AppData\Local\Publishers
2020-10-06 09:33 - 2020-10-06 09:33 - 000000000 ____D C:\Users\Tosh\AppData\Local\ConnectedDevicesPlatform
2020-10-06 09:32 - 2020-10-08 13:11 - 000000000 ____D C:\Users\Tosh
2020-10-06 09:32 - 2020-10-06 09:32 - 000000020 ___SH C:\Users\Tosh\ntuser.ini
2020-10-06 09:31 - 2020-10-11 22:59 - 000795988 _____ C:\Windows\system32\PerfStringBackup.INI
2020-10-06 09:29 - 2020-10-06 09:29 - 000000000 ____D C:\Windows\minidump
2020-10-06 09:29 - 2020-10-06 09:29 - 000000000 ____D C:\Windows\CSC
2020-10-06 09:26 - 2020-10-06 09:26 - 000000000 _SHDL C:\Documents and Settings
2020-10-06 09:21 - 2019-03-18 21:43 - 002873856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2020-10-06 09:20 - 2020-10-06 09:20 - 000016713 _____ C:\Users\Tosh\Desktop\Microsoft.UI.Xaml.2.0_2.1810.18004.0_x64__8wekyb3d8bbwe.xml
2020-10-06 09:18 - 2020-10-11 22:55 - 000000000 ____D C:\Windows\system32\SleepStudy
2020-10-06 09:18 - 2020-10-08 03:20 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-10-06 09:18 - 2020-10-06 09:18 - 000257824 _____ C:\Windows\system32\FNTCACHE.DAT
2020-10-06 09:18 - 2020-10-06 09:18 - 000000000 ____D C:\Windows\system32\Drivers\wd
2020-10-06 09:18 - 2020-10-06 09:18 - 000000000 ____D C:\Windows\ServiceProfiles

==================== Three months (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-10-11 22:59 - 2019-03-18 21:50 - 000000000 ____D C:\Windows\INF
2020-10-09 23:41 - 2019-03-18 21:52 - 000000000 ____D C:\Windows\AppReadiness
2020-10-08 13:13 - 2019-03-18 21:52 - 000000000 ____D C:\Windows\system32\NDF
2020-10-08 05:00 - 2019-03-18 21:52 - 000000000 ____D C:\Windows\Registration
2020-10-08 04:57 - 2019-03-18 21:37 - 000000000 ____D C:\Windows\CbsTemp
2020-10-07 08:17 - 2019-03-18 21:37 - 000524288 _____ C:\Windows\system32\config\BBI
2020-10-06 16:54 - 2019-03-18 21:52 - 000000000 ____D C:\Windows\schemas
2020-10-06 12:37 - 2019-03-18 21:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-10-06 12:36 - 2019-03-18 21:52 - 000000000 ____D C:\Windows\ServiceState
2020-10-06 12:35 - 2019-03-18 21:52 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2020-10-06 10:17 - 2019-03-18 21:49 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2020-10-06 09:32 - 2019-03-18 21:52 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2020-10-06 09:30 - 2019-03-18 21:52 - 000000000 ____D C:\Windows\system32\spool
2020-10-06 09:30 - 2019-03-18 21:52 - 000000000 ____D C:\Windows\system32\FxsTmp
2020-10-06 09:20 - 2019-03-18 21:52 - 000000000 ___RD C:\Windows\PrintDialog
2020-10-06 09:20 - 2019-03-18 21:52 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2020-10-06 09:19 - 2019-03-18 21:52 - 000000000 ____D C:\Windows\appcompat
2020-10-06 09:19 - 2019-03-18 21:37 - 000032768 _____ C:\Windows\system32\config\ELAM

==================== SigCheckExt =========================

2020-10-06 19:54 - 2003-04-21 21:46 - 000061440 _____ (Printing Communications Assoc., Inc. (PCAUSA)) C:\Windows\SysWOW64\ASIW32N50.dll
2020-10-11 23:06 - 2020-09-30 23:11 - 002299392 _____ (Farbar) C:\Users\Tosh\Desktop\FRST64.exe
2020-10-06 18:04 - 2018-04-02 00:34 - 006271164 _____ (Acresso Software Inc. ) C:\Users\Tosh\Desktop\Rescue.exe
2020-10-07 14:10 - 2020-10-08 04:57 - 001305038 _____ C:\Users\Tosh\Desktop\TransmogProvider.dll
2020-10-06 18:02 - 2020-08-13 18:47 - 001841997 _____ ( C:\Users\Tosh\Desktop\YUMI-

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== BCD ================================

Windows Boot Manager
identifier {bootmgr}
device partition=\Device\HarddiskVolume1
description Windows Boot Manager
locale en-US
inherit {globalsettings}
default {current}
resumeobject {c6b31de5-07f7-11eb-94b9-c96f09563efa}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 30

Windows Boot Loader
identifier {current}
device partition=C:
path \Windows\system32\winload.exe
description Windows 10
locale en-US
inherit {bootloadersettings}
recoverysequence {c6b31de7-07f7-11eb-94b9-c96f09563efa}
displaymessageoverride Recovery
recoveryenabled Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \Windows
resumeobject {c6b31de5-07f7-11eb-94b9-c96f09563efa}
nx OptIn
bootmenupolicy Standard

Windows Boot Loader
identifier {c6b31de7-07f7-11eb-94b9-c96f09563efa}
device ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{c6b31de8-07f7-11eb-94b9-c96f09563efa}
path \windows\system32\winload.exe
description Windows Recovery Environment
locale en-us
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{c6b31de8-07f7-11eb-94b9-c96f09563efa}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes

Resume from Hibernate
identifier {c6b31de5-07f7-11eb-94b9-c96f09563efa}
device partition=C:
path \Windows\system32\winresume.exe
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {c6b31de7-07f7-11eb-94b9-c96f09563efa}
recoveryenabled Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No

Windows Memory Tester
identifier {memdiag}
device partition=\Device\HarddiskVolume1
path \boot\memtest.exe
description Windows Memory Diagnostic
locale en-US
inherit {globalsettings}
badmemoryaccess Yes

EMS Settings
identifier {emssettings}
bootems No

Debugger Settings
identifier {dbgsettings}
debugtype Local

RAM Defects
identifier {badmemory}

Global Settings
identifier {globalsettings}
inherit {dbgsettings}

Boot Loader Settings
identifier {bootloadersettings}
inherit {globalsettings}

Hypervisor Settings
identifier {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200

Resume Loader Settings
identifier {resumeloadersettings}
inherit {globalsettings}

Device options
identifier {c6b31de8-07f7-11eb-94b9-c96f09563efa}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume1
ramdisksdipath \Recovery\WindowsRE\boot.sdi

==================== End of FRST.txt ========================

