Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Windows security will not scan, threat service has stopped. Restart it now.


  • Please log in to reply
93 replies to this topic

#1 kdubb666

kdubb666

  •  Avatar image
  • Members
  • 51 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 02 September 2023 - 04:13 PM

I followed the tutorial command prompt (DISM /Online /Cleanup-Image /RestoreHealth)...

 

this is what I get:

 

 Deployment Image Servicing and Management tool

Version: 10.0.19041.844
 
Image Version: 10.0.19045.3393
 
 
Error: 193
 
%1 is not a valid Win32 application.
 


BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:23 PM

Posted 02 September 2023 - 04:30 PM

Greetings and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:
  • First, please keep in mind most of us at BleepingComputer volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.
  • It is important to not run any tools or take any steps other than those I will provide for you.
  • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
  • Please copy and paste all logs into your post unless otherwise requested.
  • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
  • If you do not reply to your topic after 5 days I will assume it has been abandoned and I will close it.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

Thank you for your patience thus far.

Please do this.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Download Farbar Recover Scan Tool for 64 bit systems and save it to your Desktop. <<< Important
  • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
  • Right click on the icon and select Run as administrator
  • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
  • Click Yes to the disclaimer
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of each report in separate reply windows
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FRST.txt
  • Addition.txt

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#3 kdubb666

kdubb666
  • Topic Starter

  •  Avatar image
  • Members
  • 51 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 03 September 2023 - 08:52 PM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-08-2023
Ran by kelle (administrator) on DESKTOP-HSAVGOG (ASUS System Product Name) (03-09-2023 20:21:23)
Running from C:\Users\kelle\Downloads\FRST64.exe
Loaded Profiles: kelle
Platform: Microsoft Windows 10 Enterprise Version 22H2 19045.3393 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe ->) (ASUSTeK COMPUTER INC. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Riot Games\League of Legends\LeagueClient.exe ->) (Riot Games, Inc. -> ) C:\Riot Games\League of Legends\LeagueCrashHandler64.exe
(C:\Riot Games\League of Legends\LeagueClient.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Riot Games\League of Legends\LeagueClientUx.exe
(C:\Riot Games\League of Legends\LeagueClientUx.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Riot Games\League of Legends\LeagueClientUxRender.exe <6>
(C:\Riot Games\Riot Client\RiotClientServices.exe ->) () [File not signed] C:\Riot Games\Riot Client\RiotClientCrashHandler.exe
(C:\Riot Games\Riot Client\RiotClientServices.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Riot Games\League of Legends\LeagueClient.exe
(cmd.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(DriverStore\FileRepositoryΑ195.inf_amd64_09ef84849323988b\B391209\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepositoryΑ195.inf_amd64_09ef84849323988b\B391209\atieclxx.exe
(explorer.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\79.0.2.0\crashpad_handler.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <17>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.292\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.292\GoogleCrashHandler64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPDU.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepositoryΑ195.inf_amd64_09ef84849323988b\B391209\atiesrxx.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe
(services.exe ->) (EXPRSVPN LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\services\ExpressVPN.AppService.exe
(services.exe ->) (EXPRSVPN LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\services\ExpressVPN.SystemService.exe
(services.exe ->) (EXPRSVPN LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\services\ExpressVPN.VpnService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\NTK\NTKDaemon.exe
(services.exe ->) (PACE Anti-Piracy, Inc. -> PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
(svchost.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe <2>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2309.1001.3.0_x64__8wekyb3d8bbwe\XboxPcApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2309.1001.3.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\GameBarPresenceWriter.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Riot Games\Riot Client\RiotClientServices.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [1138416 2020-07-23] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [3022640 2023-08-10] (Riot Games, Inc. -> Riot Games, Inc.)
HKLM\...\Run: [SteelSeriesGG] => C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe [12824488 2022-07-06] (SteelSeries ApS -> SteelSeries ApS)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3571168 2023-06-14] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [ExpressVPNNotificationService] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationServiceStarter.exe [381288 2023-05-23] (EXPRSVPN LLC -> ExpressVPN)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [1129440 2023-08-01] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-08-04] (Adobe Inc. -> )
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\79.0.2.0\GoogleDriveFS.exe [147244312 2023-08-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\79.0.2.0\GoogleDriveFS.exe [147244312 2023-08-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2607536 2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [Discord] => C:\Users\kelle\AppData\Local\Discord\Update.exe [1525016 2023-07-31] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [37080528 2023-08-11] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [Opera GX Stable] => C:\Users\kelle\AppData\Local\Programs\Opera GX\launcher.exe [2658712 2023-07-19] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [Opera GX Browser Assistant] => C:\Users\kelle\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [com.squirrel.splice.Splice] => C:\Users\kelle\AppData\Local\splice\app-4.2.77773\Splice.exe (No File)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1785864 2023-08-03] (Overwolf Ltd -> Overwolf Ltd.)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [Battle.net] => C:\Program Files (x86)\Battle.net\Battle.net.exe [1090176 2023-09-02] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [Grammarly] => C:\Users\kelle\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe [941608 2022-04-22] (Grammarly, Inc. -> )
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\79.0.2.0\GoogleDriveFS.exe [147244312 2023-08-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [Voicemod] => C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe [7442264 2022-10-05] (Voicemod Sociedad Limitada -> Voicemod)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [Surfshark] => C:\Program Files (x86)\Surfshark\Surfshark.exe  (No File)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [RiotClient] => C:\Riot Games\Riot Client\RiotClientServices.exe [70910904 2023-09-02] (Riot Games, Inc. -> Riot Games, Inc.)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4374376 2023-07-28] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [Opera Browser Assistant] => c:\users\kelle\appdata\local\programs\opera\assistant\browser_assistant.exe [3955608 2023-06-20] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [AMDNoiseSuppression] => "C:\WINDOWS\system32\AMD\ANR\AMDNoiseSuppression.exe" (No File)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [MicrosoftEdgeAutoLaunch_7463FF2906FF297BC5194F0B09A1BF9F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4108328 2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Run: [ExpressVPN] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPN.exe [854888 2023-05-23] (EXPRSVPN LLC -> ExpressVPN)
HKU\S-1-5-21-2005890046-4045795175-162804841-1002\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2607536 2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2005890046-4045795175-162804841-1002\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\79.0.2.0\GoogleDriveFS.exe [147244312 2023-08-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\79.0.2.0\GoogleDriveFS.exe [147244312 2023-08-09] (Google LLC -> Google, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\116.0.5845.141\Installer\chrmstp.exe [2023-09-01] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files\Google\Chrome\Application\115.0.5790.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ROCCAT Swarm Monitor.lnk [2022-01-16]
ShortcutTarget: ROCCAT Swarm Monitor.lnk -> C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ROCCAT_Swarm_Monitor.exe (Voyetra Turtle Beach, Inc. -> ROCCAT)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Roccat Talk.lnk [2022-01-16]
ShortcutTarget: Roccat Talk.lnk -> C:\Program Files (x86)\ROCCAT\Roccat Talk\Roccat Talk.exe (ROCCAT GmbH Co., Ltd.) [File not signed]
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {81A80287-5937-42F2-A230-4ABA75A76AD5} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3571168 2023-06-14] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {491D9D4C-FC82-4017-81C5-E039C56EFF32} - System32\Tasks\Adobe-Genuine-Software-Integrity-Scheduler-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3807712 2023-06-14] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {CB44D013-85CC-4E4E-8C0F-3AEA1EB01806} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1024440 2023-04-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {1659D8DA-AF5D-4D65-BEFF-07710DBEACDB} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [307568 2022-08-05] (ASUSTeK COMPUTER INC. -> ASUS)
Task: {EDA06115-F256-401E-9969-1988BD2FD09A} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe [1856368 2022-08-05] (ASUSTeK COMPUTER INC. -> ASUS)
Task: {5A8FB2F4-E43D-4809-B420-B62CC17F6A64} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d8c28c4bffb418 => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [153112 2022-09-07] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
Task: {DFB0E566-9662-46D3-A065-01841F088AFC} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [153112 2022-09-07] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
Task: {8BB47EAF-3ADE-4B29-8B96-006240838392} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe [43509488 2022-07-08] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
Task: {55D2BEEA-6AC0-4B2D-9CDE-E89A19E5F93F} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe  (No File)
Task: {2560948B-86E9-4791-ADBE-352342E22D2A} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\kelle\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe  LOGON (No File)
Task: {F41A55F5-0043-4374-9653-C3ABB5522BE6} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\kelle\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe  SCHED (No File)
Task: {60076E9B-E11E-46F3-ABE0-753649C20DFA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2022-01-06] (Google LLC -> Google LLC)
Task: {0C96C0F8-24E5-49E0-A534-0902EA307E4C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2022-01-06] (Google LLC -> Google LLC)
Task: {F96AD191-5DDC-430C-8437-2BC40B47FCBC} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe [818008 2021-09-15] (Intel Corporation -> Intel® Corporation)
Task: {6DDE32EA-FAD9-42F5-AB3B-378221913768} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26913464 2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {654DCA25-9451-4D47-A83F-001A1EDDEACD} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26913464 2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {9A6B5F69-8A4E-42A5-875C-3933AD5823F9} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158872 2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {447584BE-EF23-450E-B396-59340DCD450F} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158872 2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {81CD7C39-643B-4F37-8C27-D2EDF70E28EB} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [167864 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {9042EC79-2D3B-4F6A-8E42-E0580C62F86B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4DCE5801-AC02-4B7D-BC4D-EA9527F57F45} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {28A16747-2499-418C-9E10-FC3042B05BAF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6C57B982-B0B2-4418-9918-67F0FC4C9A0D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D69CDEF2-975E-496C-980A-F98B4F1CD028} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1024440 2023-04-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {5F6F24EA-C298-405E-B87C-AA9AFAFE9DE1} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4130208 2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {F63465C3-BF59-45CE-9ECD-68592700767B} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2005890046-4045795175-162804841-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4130208 2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {15F9B23A-CA9B-43B4-9683-DCC450D2843B} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2005890046-4045795175-162804841-1002 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4130208 2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {B1FD01A8-5FD0-4D9A-B6F2-239FBB10B742} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1648601335 => C:\Users\kelle\AppData\Local\Programs\Opera GX\launcher.exe [2658712 2023-07-19] (Opera Norway AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\kelle\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {981A7F2A-8C25-4C05-9947-E68532A4518E} - System32\Tasks\Opera GX scheduled Autoupdate 1648250556 => C:\Users\kelle\AppData\Local\Programs\Opera GX\launcher.exe [2658712 2023-07-19] (Opera Norway AS -> Opera Software)
Task: {43423329-D6FE-4AA2-86A6-63334CFE8ABD} - System32\Tasks\Opera scheduled assistant Autoupdate 1646700733 => c:\users\kelle\appdata\local\programs\opera\launcher.exe [2717592 2023-07-17] (Opera Norway AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="c:\users\kelle\appdata\local\programs\opera\assistant" $(Arg0)
Task: {6024192D-9A74-4C53-8EF2-347877868406} - System32\Tasks\Opera scheduled Autoupdate 1640805255 => c:\users\kelle\appdata\local\programs\opera\launcher.exe [2717592 2023-07-17] (Opera Norway AS -> Opera Software)
Task: {C9F71E74-6953-4113-ACBB-7BF2E0BD105A} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2641416 2023-08-03] (Overwolf Ltd -> Overwolf LTD)
Task: {8344094C-AE36-4D2F-A1AB-A626E8D1586A} - System32\Tasks\ROCCAT DEVICE SERVICE => C:\Program Files (x86)\ROCCAT\ROCCAT Swarm\ROCCAT_dev_service.exe [442888 2021-04-19] (Voyetra Turtle Beach, Inc. -> ROCCAT)
Task: {29629152-12DB-4330-9CA4-3EC6AEDD66E0} - System32\Tasks\StartAUEP => C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe [710584 2023-04-24] (Advanced Micro Devices Inc. -> AMD)
Task: {C9FC7FF4-0E58-444B-84BA-E09D1595A474} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [56760 2023-04-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {DCF8F6B7-9274-4639-A3F7-D97902AEA04E} - System32\Tasks\StartCNBM => C:\Program Files\AMD\CNext\CNext\cncmd.exe [56760 2023-04-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {88F3EE41-1217-4563-81BC-0D45C7C52C68} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [291768 2023-04-24] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\Intel PTT EK Recertification.job => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1abde035-12ef-4ab2-8f00-eed6590f49a9}: [NameServer] 100.64.100.1
Tcpip\..\Interfaces\{4417db41-4c91-4554-9e10-431cdabc48e3}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5fc857ac-1d75-4672-9211-a85de847b2a6}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{fd4c5418-4faf-43f9-82d7-96f3bc0abc8e}: [DhcpNameServer] 192.168.1.1
 
Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\kelle\AppData\Local\Microsoft\Edge\User Data\Default [2023-08-06]
Edge HomePage: Default -> hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=87fptxqjxp1acegikmwv4001420&param1=y6bdVFVIsvuYsgEClQfz8OwmhzNKyrgL6nqJxNEJ6irMs4BrcPo5CkKkmgifaFb4pbBW%2FrMNfFKk3%2BcqCLXhzeyiFYp0Kvs%2BM1WDdsFBk6OPUQOVQdeeSYS5%2BuD9hh%2FCgdIdn8p5Geh37NBU6tTlSIO436xrcvCLrzN7z1%2F%2Bx6xBAPzyqoVzucnvfff3FSYLoVwclr8DQe4GfUpII3qTpYpRoE6m9uxszrwtQ8kmt8p29VBiuDLzNtY%2BCy3fXWzwiIv69Z0rbwv%2FtsBkcv1zOO8%2F1ajXdKNnwSP3gQtco73zvURoedNpYCJYg36Y%2FD9qjmIgJEKNTP2DfMVupcFlKr3RMKuqrc1d%2F2EbDgA%2FUqMQ2E0flna8VE9ZbaaN5AC46TtSEZDARAvXeJql5%2B5%2B%2Fw%3D%3D
Edge StartupUrls: Default -> "hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=87fptxqjxp1acegikmwv4001420&param1=y6bdVFVIsvuYsgEClQfz8OwmhzNKyrgL6nqJxNEJ6irMs4BrcPo5CkKkmgifaFb4pbBW%2FrMNfFKk3%2BcqCLXhzQIGv33k1da8drylKds1dAS2vqQdE%2FZKCoIwfT99mQ4grO5NhNUdjQQwFjaOYwtUooX4HQPbwLppOrzZ%2Bhi5cnEXByHlPg%2BYpW7NDMeYhSdbFcWy38jv6pKdFsR58p%2BzUPgm51Os8O1eVEAnxJW2AVAfltIVokE2yJCdYqYjdxxlGiVGrvfcWZgzjLiG4%2BLUde9Kj%2BZN6kOPoftLKmEqeIxhiBBddo8RkkudgEo1qE5qGI2tMWc8rDzKt2mn31w9yhM4%2Fj13VBcEi01C0in5ssgavNEsRqYpuvTjf7tFIgAjdlumlqpoxppgAJej5a9WuA%3D%3D"
Edge Extension: (Google Docs Offline) - C:\Users\kelle\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-07-31]
Edge Extension: (Edge relevant text changes) - C:\Users\kelle\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-07-31]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
 
FireFox:
========
FF DefaultProfile: bdwb1rcu.default
FF ProfilePath: C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\bdwb1rcu.default [2022-06-15]
FF ProfilePath: C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\wyt3w4oj.default-release [2022-10-28]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2023-08-01] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2023-08-01] (Adobe Inc. -> Adobe Systems)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default [2023-09-03]
CHR Notifications: Default -> hxxps://mail.google.com; hxxps://my.norton.com; hxxps://www.facebook.com; hxxps://www.netflix.com
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.youtube.com/"
CHR Extension: (Google Translate) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-06-12]
CHR Extension: (PayPal Honey: Automatic Coupons & Cash Back) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2023-08-22]
CHR Extension: (Tampermonkey) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2023-06-02]
CHR Extension: (Dark Mode) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmghijelimhndkbmpgbldicpogfkceaj [2023-02-06]
CHR Extension: (Myinstants Soundboard) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\fggacdedkdoacbemcilniodecinpfkgi [2022-01-06]
CHR Extension: (Google Docs Offline) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-09-01]
CHR Extension: (CDKeys.com) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\hegpcfedlbjmemdiemgmmemcbefkhgbb [2022-09-05]
CHR Extension: (Volume Control for Google Chrome™) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnlfnonibbbggmlaacojkhhppaonibdp [2023-08-23]
CHR Extension: (Visual Effects for Google Meet) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\hodiladlefdpcbemnbbcpclbmknkiaem [2023-06-13]
CHR Extension: (QuillBot: AI Grammar and Writing Tool) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\iidnbdjijdkbmajdffnidomddglmieko [2023-09-02]
CHR Extension: (Chrome Remote Desktop) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2022-12-26]
CHR Extension: (Volume Master) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\jghecgabfgfdldnmbfkhmffcabddioke [2023-08-23]
CHR Extension: (Zoom Chrome Extension) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgjfgplpablkjnlkjmjdecgdpfankdle [2023-09-01]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-08-16]
CHR Extension: (Bass Boost: HD Audio) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\mghabdfikjldejcdcmclcmpcmknjahli [2022-01-06]
CHR Extension: (Shazam: Find song names from your browser) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmioliijnhnoblpgimnlajmefafdfilb [2023-06-27]
CHR Extension: (Capital One Shopping: Add to Chrome for Free) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nenlahapcbofgnanklpelkaejcehkggg [2023-09-03]
CHR Extension: (Ears: Bass Boost, EQ Any Audio!) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfdfiepdkbnoanddpianalelglmfooik [2023-04-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-01-06]
CHR Profile: C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Guest Profile [2023-07-23]
CHR Profile: C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 1 [2023-07-23]
CHR Extension: (Google Docs Offline) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-04-03]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-04-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-02-02]
CHR Profile: C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 2 [2023-07-23]
CHR Extension: (Google Docs Offline) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-05-14]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-02-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-05-14]
CHR Profile: C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 3 [2023-07-23]
CHR Extension: (Google Docs Offline) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-03-12]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-03-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-03-12]
CHR Profile: C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 4 [2023-07-23]
CHR Extension: (Google Docs Offline) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-05-10]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-05-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-05-10]
CHR Profile: C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 5 [2023-07-23]
CHR Extension: (Google Docs Offline) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-07-05]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-07-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-07-05]
CHR Profile: C:\Users\kelle\AppData\Local\Google\Chrome\User Data\System Profile [2023-08-31]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKU\S-1-5-21-2005890046-4045795175-162804841-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKU\S-1-5-21-2005890046-4045795175-162804841-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
 
Opera: 
=======
OPR Profile: C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable [2023-08-06]
OPR Notifications: Opera Stable -> hxxps://mail.google.com; hxxps://my.norton.com; hxxps://www.facebook.com; hxxps://www.instagram.com; hxxps://www.reddit.com
OPR DefaultSearchURL: Opera Stable -> hxxps://www.google.com/search?client=opera&q={searchTerms}&sourceid=opera&ie={inputEncoding}&oe={outputEncoding}
OPR DefaultSearchKeyword: Opera Stable -> g
OPR Session Restore: Opera Stable -> is enabled.
OPR Extension: (Norton Password Manager) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\admmjipmmciaobhojoghlmleefbicajg [2023-08-06]
OPR Extension: (Translator) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\cnbpedcoekjafichoehopgaaldogogch [2023-08-06]
OPR Extension: (Web Translator - Select to Translate) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\eggeoellnjnnglaibpcmggjnjifeebpi [2022-01-30]
OPR Extension: (Tab Wrangler) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\egnjhciaieeiiohknchakcodbpgjnchh [2022-01-30]
OPR Extension: (Rich Hints Agent) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2023-08-06]
OPR Extension: (Opera Wallet) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\gojhcdgcpbpfigcaejpfhfegekdgiblk [2023-08-06]
OPR Extension: (Mouse Tooltip Translator) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\hmigninkgibhdckiaphhmbgcghochdjc [2023-08-06]
OPR Extension: (Aria) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\igpdmclhhlcpoindmhkhillbfhdgoegm [2023-08-06]
OPR Extension: (Chrome Remote Desktop) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2023-08-06]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2021-12-29]
OPR Extension: (Turbo Download Manager (3rd edition)) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\lejgoophpfnabjcnfbphcndcjfpinbfk [2021-12-31]
OPR Extension: (Amazon Assistant for Opera) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\mmmbddcnnndpbdflpccgcknaaabgldak [2022-01-01]
OPR Extension: (Page Translator) - C:\Users\kelle\AppData\Roaming\Opera Software\Opera Stable\Extensions\nmkhfdafcfffmbgogcgkocbmnjjlghlc [2022-01-18]
OPR Extension: (opera-intro) - C:\Users\kelle\AppData\Local\Programs\Opera\100.0.4815.76\resources\opera_intro_extension [2023-08-06]
StartMenuInternet: (HKU\S-1-5-21-2005890046-4045795175-162804841-1001) Opera GXStable - "C:\Users\kelle\AppData\Local\Programs\Opera GX\Launcher.exe"
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [944096 2023-08-01] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3966432 2023-06-14] (Adobe Inc. -> Adobe Systems, Incorporated)
S4 ArmouryCrateService; C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe [382112 2022-07-27] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
S4 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.15\atkexComSvc.exe [468504 2022-07-22] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [153112 2022-09-07] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S4 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [181576 2021-09-30] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.)
S4 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\2.03.08\AsusFanControlService.exe [1438744 2022-07-22] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [153112 2022-09-07] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S2 AsusUpdateCheck; C:\WINDOWS\System32\AsusUpdateCheck.exe [1132000 2023-09-03] (ASUSTeK COMPUTER INC. -> )
R2 AUEPLauncher; C:\Program Files\AMD\CIM\..\Performance Profile Client\AUEPDU.exe [509880 ] (Advanced Micro Devices Inc. -> AMD)
S4 Backupper Service; C:\Program Files (x86)\AOMEI\AOMEI Backupper\6.9.1\ABService.exe [1092656 2022-03-16] (AOMEI International Network Limited -> AOMEI International Network Limited)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [9880840 2023-07-14] (BattlEye Innovations e.K. -> )
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\116.0.5845.9\remoting_host.exe [74520 2023-06-26] (Google LLC -> Google LLC)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11817440 2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [10933864 2023-08-19] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1134624 2023-08-19] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [943528 2023-06-28] (EasyAntiCheat Oy -> Epic Games, Inc.)
S4 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934368 2021-10-01] (Epic Games Inc. -> Epic Games, Inc.)
S4 EQU8_19; C:\ProgramData\EQU8\Totally Accurate Battlegrounds\bin\anticheat.x64.equ8.exe [8344720 2022-03-17] (Int3 Software AB -> Int3 Software AB)
R2 ExpressVPN App Service; C:\Program Files (x86)\ExpressVPN\services\ExpressVPN.AppService.exe [437096 2023-05-23] (EXPRSVPN LLC -> ExpressVPN)
R2 ExpressVPN System Service; C:\Program Files (x86)\ExpressVPN\services\ExpressVPN.SystemService.exe [437096 2023-05-23] (EXPRSVPN LLC -> ExpressVPN)
R2 ExpressVPN VPN Service; C:\Program Files (x86)\ExpressVPN\services\ExpressVPN.VpnService.exe [437096 2023-05-23] (EXPRSVPN LLC -> ExpressVPN)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncHelper.exe [3516832 2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
S4 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [3887504 2022-07-25] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
R2 NTKDaemonService; C:\Program Files\Common Files\Native Instruments\NTK\NTKDaemon.exe [16847584 2023-05-17] (Native Instruments GmbH -> Native Instruments GmbH)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\23.169.0813.0001\OneDriveUpdaterService.exe [3853840 2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
S4 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2641416 2023-08-03] (Overwolf Ltd -> Overwolf LTD)
R2 ROG Live Service; C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe [1665648 2023-07-25] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402264 2023-09-01] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 SteelSeriesUpdateService; C:\Program Files\SteelSeries\GG\SteelSeriesUpdateService.exe [35240 2022-07-06] (SteelSeries ApS -> )
S4 SyncoveryVSSService; C:\Program Files\Syncovery\SyncoveryVSS.exe [2798888 2018-06-21] (Super Flexible Software Ltd. & Co. KG -> )
S4 ucldr_battlegrounds_gl; C:\Program Files\Common Files\UNCHEATER\ucldr_battlegrounds_gl.exe [6020336 2022-03-16] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [9437496 2023-08-10] (Riot Games, Inc. -> Riot Games, Inc.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe [3121008 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe [133688 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [8971056 2022-04-07] (PUBG CORPORATION -> PUBG Corporation)
S3 Denuvo Anti-Cheat Update Service; "C:\Program Files\Denuvo Anti-Cheat\denuvo-anti-cheat-update-service.exe" [X]
S4 OVRLibraryService; "C:\Program Files\Oculus\Support\oculus-librarian\OVRLibraryService.exe" [X]
S4 OVRService; "C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe" [X]
R2 PaceLicenseDServices; "C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe" -u hxxps://activation.paceap.com/InitiateActivation
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 ambakdrv; C:\WINDOWS\System32\ambakdrv.sys [51120 2019-05-14] (CHENGDU AOMEI Tech Co., Ltd. -> )
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [25560 2023-04-12] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [27256 2022-01-27] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_1a1a381a2c0e293c\amdsafd.sys [113056 2022-08-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
S3 AmdTools64; C:\WINDOWS\System32\drivers\AmdTools64.sys [58216 2018-03-23] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepositoryΑ195.inf_amd64_09ef84849323988b\B391209\amdkmdag.sys [100046272 2023-05-03] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R2 ammntdrv; C:\WINDOWS\system32\ammntdrv.sys [172928 2022-04-17] (AOMEI International Network Limited -> )
R2 amwrtdrv; C:\WINDOWS\system32\amwrtdrv.sys [32176 2022-04-17] (AOMEI International Network Limited -> )
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R1 Asusgio3; C:\WINDOWS\system32\drivers\AsIO3.sys [43168 2021-09-30] (ASUSTeK Computer Inc. -> )
S3 atvi-brynhildr; C:\ProgramData\Battle.net_components\brynhildr_odin\brynhildr.sys [2355952 2022-05-04] (Activision Publishing Inc -> Activision Blizzard, Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [287744 2022-05-12] (Microsoft Corporation) [File not signed]
S3 expressvpnsplittunnel; C:\Program Files (x86)\ExpressVPN\splittunnel\driver\expressvpnsplittunnel.sys [46712 2023-05-23] (ExprsVPN LLC -> ExpressVPN)
R3 expressvpntun; C:\WINDOWS\System32\drivers\expressvpn-tun.sys [56552 2023-05-23] (Express VPN International Ltd. -> ExpressVPN)
R1 googledrivefs31092; C:\WINDOWS\System32\DRIVERS\googledrivefs31092.sys [384600 2023-02-08] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [42000 2022-06-14] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 KMWDFILTER; C:\WINDOWS\System32\drivers\KMWDFILTER.sys [30208 2009-04-29] (MLK Technologies Limited -> Windows ® Codename Longhorn DDK provider)
S3 ksophon_x64; C:\WINDOWS\system32\drivers\ksophon_x64.sys [9986168 2022-12-21] (PROXIMA BETA PTE. LIMITED -> PROXIMA BETE)
S3 LGJoyHidFilter; C:\WINDOWS\system32\drivers\LGJoyHidFilter.sys [57368 2018-10-05] (Logitech Inc -> Logitech Inc.)
S3 LGJoyHidLo; C:\WINDOWS\system32\drivers\LGJoyHidLo.sys [47256 2018-10-05] (Logitech Inc -> Logitech Inc.)
S3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2018-10-05] (Logitech Inc -> Logitech Inc.)
S3 LGSHidFilt; C:\WINDOWS\System32\drivers\LGSHidFilt.Sys [64280 2018-10-05] (Logitech -> Logitech Inc.)
S3 LGSUsbFilt; C:\WINDOWS\System32\drivers\LGSUsbFilt.Sys [41752 2018-10-05] (Logitech -> Logitech Inc.)
S3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [37200 2021-11-20] (Logitech Inc -> Logitech)
S3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [25928 2021-11-20] (Logitech Inc -> Logitech)
S3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [66896 2021-11-20] (Logitech Inc -> Logitech)
S3 NDivert; C:\WINDOWS\System32\drivers\NDivert.sys [105184 2021-02-05] (TEFINCOM S.A. -> )
R3 oculusvad_oculusvad; C:\WINDOWS\System32\drivers\oculusvad.sys [75280 2021-10-22] (Microsoft Windows Hardware Compatibility Publisher -> Windows ® Win 7 DDK provider)
R3 Oculus_ViGEmBus; C:\WINDOWS\System32\drivers\Oculus_ViGEmBus.sys [32856 2021-10-22] (Oculus VR, LLC -> Facebook Inc.)
S3 rzbtendpt; C:\WINDOWS\System32\drivers\rzbtendpt.sys [51912 2015-08-13] (Razer Inc. -> Razer Inc)
S3 rzdaendpt; C:\WINDOWS\System32\drivers\rzdaendpt.sys [43720 2015-08-13] (Razer Inc. -> Razer Inc)
S3 rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [50392 2015-08-13] (Razer Inc. -> Razer Inc)
S3 rzhnet; C:\WINDOWS\System32\Drivers\rzhnet.sys [29912 2015-08-13] (Razer Inc. -> Razer Inc)
S3 rzjstk; C:\WINDOWS\System32\drivers\rzjstk.sys [36568 2015-08-13] (Razer Inc. -> Razer Inc)
S3 rzkeypadendpt; C:\WINDOWS\System32\drivers\rzkeypadendpt.sys [46280 2015-08-13] (Razer Inc. -> Razer Inc)
S3 rzmpos; C:\WINDOWS\System32\drivers\rzmpos.sys [48840 2015-08-13] (Razer Inc. -> Razer Inc)
S3 rzp1endpt; C:\WINDOWS\System32\drivers\rzp1endpt.sys [52424 2015-08-13] (Razer Inc. -> Razer Inc)
S3 rzvkeyboard; C:\WINDOWS\System32\drivers\rzvkeyboard.sys [44232 2015-08-13] (Razer Inc. -> Razer Inc)
S3 rzvmouse; C:\WINDOWS\System32\drivers\rzvmouse.sys [42712 2015-08-13] (Razer Inc. -> Razer Inc)
R3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [47784 2022-01-31] (SteelSeries ApS -> SteelSeries ApS)
R3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [43960 2022-07-06] (Microsoft Windows Hardware Compatibility Publisher -> SteelSeries ApS)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64872 2019-09-26] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated)
R3 SteamStreamingMicrophone; C:\WINDOWS\system32\drivers\SteamStreamingMicrophone.sys [40736 2020-06-01] (Valve Corp. -> )
R3 SteamStreamingSpeakers; C:\WINDOWS\system32\drivers\SteamStreamingSpeakers.sys [40736 2020-06-01] (Valve Corp. -> )
R3 SteelSeries_Sonar_VAD; C:\WINDOWS\System32\DriverStore\FileRepository\steelseries-sonar-vad.inf_amd64_6f6e907eca1efa31\SteelSeries-Sonar-VAD.sys [89568 2022-03-23] (SteelSeries ApS -> Windows ® Win 7 DDK provider)
S3 synusb64; C:\WINDOWS\System32\drivers\synusb64.sys [30352 2011-12-14] (Steinberg Media Technologies GmbH -> Steinberg Media Technologies GmbH)
R3 tapexpressvpn; C:\WINDOWS\System32\drivers\tapexpressvpn.sys [61496 2023-05-23] (ExprsVPN LLC -> The OpenVPN Project)
R3 tapsurfshark; C:\WINDOWS\System32\drivers\tapsurfshark.sys [38728 2022-08-31] (WDKTestCert Lenovo,131775874531219913 -> The OpenVPN Project)
R3 VBAudioVACMME; C:\WINDOWS\System32\drivers\vbaudio_cable64_win7.sys [41192 2019-11-11] (Vincent Burel -> Windows ® Win 7 DDK provider)
R1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [26953656 2023-08-09] (Riot Games, Inc. -> Riot Games, Inc.)
R3 VOICEMOD_Driver; C:\WINDOWS\system32\drivers\mvvad.sys [48144 2022-07-26] (Voicemod Sociedad Limitada -> Windows ® Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55872 2023-08-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [574872 2023-08-30] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105864 2023-08-30] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2023-03-09] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [1431256 2022-12-25] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S2 AMDRyzenMasterDriverV19; \??\C:\WINDOWS\system32\AMDRyzenMasterDriver.sys [X]
S3 GPUZ-v2; \??\C:\Users\kelle\AppData\Local\Temp\GPUZ-v2.sys [X] <==== ATTENTION
S3 MpKsl55aaa8ad; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{64C1498B-F058-4BFB-B1D2-5F2D03DCBCFB}\MpKslDrv.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2023-09-03 20:21 - 2023-09-03 20:22 - 000050931 _____ C:\Users\kelle\Downloads\FRST.txt
2023-09-03 20:21 - 2023-09-03 20:21 - 000000000 ____D C:\FRST
2023-09-03 20:20 - 2023-09-03 20:20 - 002382336 _____ (Farbar) C:\Users\kelle\Downloads\FRST64.exe
2023-09-02 20:01 - 2023-09-02 20:01 - 035534879 _____ C:\Users\kelle\Downloads\[fadr.com] Stems - Lindy Hip - Makin Whoopee.zip
2023-09-02 19:58 - 2023-09-02 19:59 - 043019600 _____ C:\Users\kelle\Downloads\YTMp3_v4.7.0_ytmp3web_release (1).apk
2023-09-02 14:20 - 2023-09-02 14:20 - 000000000 ____D C:\Users\mom\AppData\Roaming\Microsoft\Spelling
2023-09-02 14:19 - 2023-09-02 14:19 - 000000000 ____D C:\Users\mom\AppData\Local\Comms
2023-09-02 14:19 - 2023-09-02 14:19 - 000000000 ____D C:\Users\mom\AppData\Local\CEF
2023-09-02 13:54 - 2023-09-02 13:54 - 000007140 _____ C:\Users\kelle\Downloads\Windows_Defender_Firewall.reg
2023-09-02 13:53 - 2023-09-02 13:53 - 000007966 _____ C:\Users\kelle\Downloads\Windows_Defender_Advanced_Threat_Protection_Service.reg
2023-09-02 13:46 - 2023-09-02 13:46 - 000004540 _____ C:\Users\kelle\Downloads\Windows_PushToInstall_Service.reg
2023-09-01 19:58 - 2023-09-01 20:23 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2023-09-01 19:36 - 2023-09-01 20:26 - 000000000 ____D C:\Users\kelle\AppData\LocalLow\IGDump
2023-09-01 19:35 - 2023-09-01 19:35 - 002606880 _____ (Malwarebytes) C:\Users\kelle\Downloads\MBSetup-4.4.exe
2023-09-01 19:23 - 2023-09-01 19:23 - 000000000 ___HD C:\$SysReset
2023-09-01 18:37 - 2023-09-01 18:37 - 000000000 ___HD C:\$WinREAgent
2023-09-01 18:37 - 2023-07-25 02:01 - 000392704 _____ C:\WINDOWS\SysWOW64\poqexec.exe
2023-09-01 18:22 - 2023-09-01 18:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baby Audio Transit
2023-09-01 18:17 - 2023-09-01 18:17 - 000138200 _____ (Distributed Creation, Inc.) C:\Users\kelle\Downloads\InstallSplice (2).exe
2023-09-01 18:17 - 2023-09-01 18:17 - 000138200 _____ (Distributed Creation, Inc.) C:\Users\kelle\Downloads\InstallSplice (1).exe
2023-09-01 18:17 - 2023-09-01 18:17 - 000000000 ____D C:\Users\kelle\AppData\Local\splice
2023-08-29 18:56 - 2023-08-29 18:56 - 009714227 _____ C:\Users\kelle\Downloads\LIMBO  Airplane Mode  Vocals Only.mp4
2023-08-29 18:54 - 2023-08-29 18:57 - 011071044 _____ C:\Users\kelle\Downloads\LIMBO  Airplane Mode  Vocals Only.mp3.vdjstems
2023-08-26 15:35 - 2023-08-26 15:35 - 043019600 _____ C:\Users\kelle\Downloads\YTMp3_v4.7.0_ytmp3web_release.apk
2023-08-26 13:31 - 2023-08-26 13:31 - 001111865 _____ C:\Users\kelle\Downloads\ECR_127_9L_4bar_skate(3).audioloop
2023-08-26 13:31 - 2023-08-26 13:31 - 000080107 _____ C:\Users\kelle\Downloads\ECR_127_9L_4bar_skate(2).audioloop
2023-08-26 13:31 - 2023-08-26 13:31 - 000065429 _____ C:\Users\kelle\Downloads\ECR_127_9L_4bar_skate.audioloop
2023-08-26 12:38 - 2023-08-26 12:38 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Cableguys
2023-08-26 12:38 - 2023-08-26 12:38 - 000000000 ____D C:\Program Files\CableGuys
2023-08-26 11:57 - 2023-08-26 11:57 - 004319006 _____ C:\Users\kelle\Downloads\bandicam 2023-08-25 22-22-28-331.wav
2023-08-26 11:47 - 2023-08-31 23:44 - 000000000 ____D C:\Users\kelle\AppData\Local\VirtualDJ
2023-08-26 11:47 - 2023-08-31 23:44 - 000000000 ____D C:\Program Files\VirtualDJ
2023-08-25 21:40 - 2023-09-01 18:22 - 000000000 ____D C:\Users\kelle\AppData\Roaming\af854ba56b229a56c422472ee764eba8
2023-08-25 21:40 - 2023-08-25 21:40 - 000000000 ____D C:\ProgramData\BABY Audio
2023-08-25 21:40 - 2023-08-25 21:40 - 000000000 ____D C:\Program Files\Baby Audio
2023-08-25 21:25 - 2023-08-25 21:25 - 204322523 _____ C:\Users\kelle\Downloads\MullvadVPN-2023.4.pkg
2023-08-24 22:25 - 2023-08-24 22:25 - 003096184 _____ C:\Users\kelle\Downloads\Blue Avenue-G#m-94bpm-444hz.m4a
2023-08-24 22:22 - 2023-08-24 22:22 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Moises
2023-08-24 20:37 - 2023-08-31 23:44 - 000000000 ____D C:\Users\kelle\AppData\Local\descript-updater
2023-08-24 20:37 - 2023-08-31 23:25 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Descript
2023-08-20 22:42 - 2021-02-28 05:49 - 000508764 _____ C:\Users\kelle\Downloads\Hard Sweep Down 1 (JW2).wav
2023-08-20 22:07 - 2023-08-20 22:07 - 000001648 _____ C:\Users\kelle\Downloads\Marc_et_Claude_-_I_Need_Your_Loving__traxxboy_20071019235708.mid
2023-08-19 23:21 - 2023-08-19 23:22 - 000000000 ____D C:\Users\kelle\AppData\Local\DeadByDaylight
2023-08-19 13:53 - 2023-08-19 13:53 - 000000000 ____D C:\Users\kelle\AppData\Local\BBQGame
2023-08-17 23:00 - 2023-08-17 23:00 - 1375893168 _____ C:\Users\kelle\Downloads\zgjwc.zip
2023-08-13 20:56 - 2023-08-13 22:07 - 000000000 ____D C:\Users\kelle\AppData\Local\Palia
2023-08-13 20:56 - 2023-08-13 20:56 - 014219672 _____ C:\Users\kelle\Downloads\PaliaInstaller.exe
2023-08-13 00:27 - 2023-08-13 00:27 - 000338614 _____ C:\Users\kelle\Downloads\cartoon-mixed-fx-metronome.wav
2023-08-13 00:15 - 2023-08-13 00:15 - 042901528 _____ C:\Users\kelle\Downloads\YTMp3_YTMP3WEB_v4.6.1 (1).apk
2023-08-11 18:31 - 2023-08-11 18:31 - 000010040 _____ C:\Users\kelle\Downloads\modcgf.zip
2023-08-11 18:28 - 2023-08-11 18:28 - 000000000 ____D C:\Users\kelle\Downloads\s
2023-08-11 18:27 - 2023-07-30 21:40 - 000628005 _____ C:\Users\kelle\Downloads\- Obscure UI - Activity Tracker.tmod
2023-08-11 18:24 - 2023-08-11 18:24 - 071734037 _____ C:\Users\kelle\Downloads\mods.zip
2023-08-11 01:21 - 2023-08-11 01:21 - 000016078 _____ C:\Users\kelle\Downloads\87563.mid
2023-08-10 19:02 - 2023-08-10 19:02 - 000396950 _____ C:\Users\kelle\Downloads\jazz_drum_kit.zip
2023-08-10 18:44 - 2023-08-10 18:44 - 042901528 _____ C:\Users\kelle\Downloads\YTMp3_YTMP3WEB_v4.6.1.apk
2023-08-06 20:17 - 2023-09-03 09:49 - 000000000 ____D C:\Users\kelle\AppData\Local\Discord
2023-08-06 20:17 - 2023-08-06 20:17 - 095781656 _____ (Discord Inc.) C:\Users\kelle\Downloads\DiscordSetup.exe
2023-08-06 15:53 - 2023-08-06 15:53 - 001372712 _____ (Google LLC) C:\Users\kelle\Downloads\ChromeSetup (1).exe
2023-08-06 15:52 - 2023-08-06 15:52 - 001372712 _____ (Google LLC) C:\Users\kelle\Downloads\ChromeSetup.exe
2023-08-06 15:37 - 2023-09-03 20:12 - 000000000 ___HD C:\Users\kelle\Downloads\.opera
2023-08-06 15:37 - 2023-09-03 20:12 - 000000000 ___HD C:\Users\kelle\.opera
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2023-09-03 20:05 - 2021-12-29 15:48 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-09-03 20:02 - 2021-12-29 14:11 - 000000000 ____D C:\Users\kelle\AppData\Local\D3DSCache
2023-09-03 19:44 - 2021-12-31 21:16 - 000000000 ____D C:\ProgramData\Riot Games
2023-09-03 19:41 - 2022-01-02 00:09 - 000000000 ____D C:\Program Files (x86)\Google
2023-09-03 19:41 - 2021-12-31 18:49 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-09-03 18:58 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-09-03 18:35 - 2023-07-24 00:11 - 000003118 _____ C:\WINDOWS\system32\Tasks\AMDInstallLauncher
2023-09-03 18:34 - 2022-02-02 19:25 - 000000000 ____D C:\Users\kelle\AppData\Local\CrashDumps
2023-09-03 18:29 - 2021-12-29 15:47 - 000000000 ____D C:\WINDOWS\INF
2023-09-03 18:29 - 2021-12-29 14:10 - 000840598 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-09-03 17:51 - 2021-12-29 15:48 - 000000000 ___HD C:\Program Files\WindowsApps
2023-09-03 17:51 - 2021-12-29 14:11 - 000000000 ____D C:\Users\kelle\AppData\Local\Packages
2023-09-03 17:51 - 2021-12-29 14:11 - 000000000 ____D C:\ProgramData\Packages
2023-09-03 17:43 - 2023-03-12 01:33 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat
2023-09-03 17:40 - 2022-09-05 06:23 - 001180016 _____ () C:\WINDOWS\system32\wpbbin.exe
2023-09-03 17:40 - 2022-09-05 06:23 - 001132000 _____ C:\WINDOWS\system32\AsusUpdateCheck.exe
2023-09-03 17:40 - 2021-12-29 16:00 - 000008192 ___SH C:\DumpStack.log.tmp
2023-09-03 17:40 - 2021-12-29 16:00 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-09-03 17:40 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\ServiceState
2023-09-03 17:39 - 2021-12-29 16:00 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2023-09-03 17:39 - 2021-12-29 15:44 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2023-09-03 17:35 - 2021-12-29 16:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-09-03 17:28 - 2021-12-29 14:08 - 000000000 ____D C:\Users\kelle
2023-09-03 17:18 - 2023-06-19 23:40 - 000000000 ____D C:\Program Files (x86)\Steam
2023-09-03 17:16 - 2022-05-01 12:21 - 000000000 ____D C:\Program Files\Riot Vanguard
2023-09-03 16:08 - 2022-11-14 20:06 - 000004166 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{6994635F-AD5F-42F1-8E3C-76C59791DC67}
2023-09-03 12:36 - 2021-12-29 15:20 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2023-09-03 10:41 - 2021-12-30 15:06 - 000000000 ____D C:\Users\kelle\AppData\Local\Ubisoft Game Launcher
2023-09-03 10:31 - 2021-12-31 16:22 - 000000000 ____D C:\Users\kelle\AppData\Roaming\discord
2023-09-03 01:02 - 2022-09-07 02:36 - 000000000 ____D C:\Program Files\ASUS
2023-09-02 21:28 - 2022-01-05 23:32 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Celemony Software GmbH
2023-09-02 19:45 - 2022-01-18 20:56 - 000000000 ____D C:\Users\kelle\OneDrive\Documents\XLN Online Installer
2023-09-02 18:31 - 2022-04-18 11:03 - 000000000 ____D C:\Program Files (x86)\Battle.net
2023-09-02 17:24 - 2022-04-18 11:04 - 000000000 ____D C:\Users\kelle\AppData\Local\Battle.net
2023-09-02 14:22 - 2022-06-14 12:39 - 000000000 ____D C:\Users\mom\AppData\Local\D3DSCache
2023-09-02 14:20 - 2022-06-14 12:39 - 000000000 ____D C:\Users\mom\AppData\Local\Packages
2023-09-02 14:20 - 2021-12-29 15:48 - 000000000 ___RD C:\WINDOWS\PrintDialog
2023-09-02 14:19 - 2022-06-14 12:39 - 000002348 _____ C:\Users\mom\Desktop\Microsoft Edge.lnk
2023-09-02 14:19 - 2022-06-14 12:39 - 000000000 ____D C:\Users\mom\AppData\Local\Google
2023-09-02 14:19 - 2022-06-14 12:39 - 000000000 ____D C:\Users\mom\AppData\Local\AMD
2023-09-02 12:53 - 2021-12-29 15:48 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-09-02 12:43 - 2022-05-02 16:42 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2023-09-02 12:43 - 2022-04-13 20:31 - 000000000 ____D C:\Users\kelle\AppData\Local\SpliceSettings
2023-09-02 00:58 - 2022-06-14 12:40 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2005890046-4045795175-162804841-1002
2023-09-02 00:58 - 2022-05-02 16:39 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2023-09-02 00:58 - 2022-05-02 16:39 - 000002132 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-09-02 00:58 - 2021-12-29 14:13 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2005890046-4045795175-162804841-1001
2023-09-01 20:14 - 2023-02-26 03:46 - 000000000 ____D C:\Users\kelle\OneDrive\Documents\Bandicam
2023-09-01 19:08 - 2021-12-29 15:48 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-09-01 19:05 - 2022-06-14 11:42 - 001223810 _____ C:\WINDOWS\ntbtlog.txt
2023-09-01 19:04 - 2022-06-14 11:42 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2023-09-01 18:52 - 2023-07-24 00:12 - 000455488 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-09-01 18:52 - 2021-12-29 15:48 - 000000000 ___SD C:\WINDOWS\system32\AppV
2023-09-01 18:52 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2023-09-01 18:52 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\SystemResources
2023-09-01 18:52 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2023-09-01 18:52 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\system32\oobe
2023-09-01 18:52 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\system32\appraiser
2023-09-01 18:51 - 2022-05-07 00:17 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-09-01 18:51 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\ShellExperiences
2023-09-01 18:51 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2023-09-01 18:51 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-09-01 18:51 - 2021-12-29 15:45 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-09-01 18:47 - 2021-12-29 14:04 - 003014144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2023-09-01 18:28 - 2022-02-02 15:49 - 000000000 ____D C:\Users\kelle\AppData\Roaming\qBittorrent
2023-09-01 18:22 - 2022-05-06 19:49 - 000000000 ____D C:\Program Files\Vstplugins
2023-09-01 18:22 - 2022-01-05 23:27 - 000000000 ____D C:\Program Files\Common Files\VST3
2023-09-01 18:19 - 2022-06-10 16:57 - 000004608 _____ C:\Users\kelle\PaceKeyChain
2023-09-01 18:17 - 2022-04-13 20:31 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Splice
2023-09-01 18:17 - 2021-12-31 16:22 - 000000000 ____D C:\Users\kelle\AppData\Local\SquirrelTemp
2023-09-01 17:58 - 2022-12-16 22:19 - 000000000 ___HD C:\adobeTemp
2023-09-01 17:58 - 2022-12-16 22:15 - 000000000 ___RD C:\Users\kelle\Creative Cloud Files
2023-09-01 17:58 - 2022-05-28 20:04 - 000000000 ____D C:\Program Files\Adobe
2023-09-01 17:58 - 2021-12-29 16:00 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-09-01 07:58 - 2022-03-07 19:51 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-09-01 07:58 - 2022-01-06 20:47 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-08-31 23:58 - 2022-10-20 21:43 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2023-08-31 23:58 - 2022-10-20 21:43 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2023-08-31 23:58 - 2022-03-18 21:20 - 002807296 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2023-08-31 23:58 - 2022-03-18 21:20 - 000493056 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2023-08-31 23:58 - 2022-03-18 21:20 - 000247288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2023-08-31 23:58 - 2022-03-18 21:20 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2023-08-31 23:58 - 2022-03-18 21:20 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2023-08-31 23:58 - 2022-03-18 21:20 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2023-08-31 23:55 - 2022-05-02 16:37 - 000000000 ____D C:\Program Files\Microsoft Office
2023-08-31 23:44 - 2023-07-31 22:29 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Trove
2023-08-31 23:44 - 2023-02-20 03:25 - 000000000 ____D C:\ProgramData\EA Desktop
2023-08-31 23:44 - 2023-01-25 21:49 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2023-08-31 23:44 - 2022-06-14 12:39 - 000000000 ____D C:\Users\mom
2023-08-31 23:44 - 2022-04-18 11:04 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Battle.net
2023-08-31 23:44 - 2022-04-15 13:31 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2023-08-31 23:44 - 2022-04-15 13:31 - 000000000 ____D C:\Program Files (x86)\Overwolf
2023-08-31 23:44 - 2022-04-15 13:30 - 000000000 ____D C:\Users\kelle\AppData\Local\Overwolf
2023-08-31 23:44 - 2022-03-14 19:22 - 000000000 ____D C:\Users\kelle\AppData\Roaming\audacity
2023-08-31 23:44 - 2022-01-20 13:53 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat_EOS
2023-08-31 23:44 - 2022-01-02 17:37 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
2023-08-31 23:44 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2023-08-31 23:44 - 2021-12-29 15:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2023-08-31 23:44 - 2021-12-29 15:00 - 000000000 ____D C:\Program Files\7-Zip
2023-08-31 23:32 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\registration
2023-08-31 23:27 - 2022-06-01 21:28 - 000000000 ____D C:\Program Files (x86)\NCH Software
2023-08-31 22:36 - 2022-06-01 21:28 - 000000000 ____D C:\WINDOWS\system32\Tasks\NCH Software
2023-08-31 22:36 - 2021-12-29 14:13 - 000000000 ___RD C:\Users\kelle\OneDrive
2023-08-30 15:42 - 2021-12-29 16:00 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2023-08-30 13:42 - 2021-12-29 14:08 - 000000000 ___SD C:\Users\kelle\AppData\Roaming\Microsoft\Credentials
2023-08-24 22:35 - 2022-06-01 21:28 - 000000000 ____D C:\ProgramData\NCH Software
2023-08-23 00:46 - 2022-09-05 06:23 - 000000000 ____D C:\ProgramData\ASUS
2023-08-19 23:21 - 2022-01-02 17:39 - 000000000 ____D C:\Users\kelle\AppData\Roaming\EasyAntiCheat
2023-08-19 00:55 - 2022-06-30 19:16 - 000000000 ____D C:\Users\kelle\AppData\Roaming\PreSonus
2023-08-17 23:43 - 2023-07-31 23:32 - 000000000 ____D C:\Users\kelle\AppData\Local\Deployment
2023-08-15 19:54 - 2022-01-11 23:48 - 000000000 ____D C:\Users\kelle\AppData\Local\AMD_Common
2023-08-14 12:40 - 2023-07-31 23:32 - 000000000 ____D C:\Users\kelle\AppData\Local\Apps\2.0
2023-08-13 20:59 - 2021-12-29 22:15 - 000000000 ____D C:\ProgramData\Package Cache
2023-08-13 15:17 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2023-08-11 17:27 - 2022-02-28 20:05 - 000000000 ____D C:\WINDOWS\system32\SteelSeries
2023-08-09 17:29 - 2022-04-06 17:48 - 000000000 ____D C:\Users\kelle\AppData\Roaming\steelseries-gg-client
2023-08-09 11:42 - 2022-07-12 09:32 - 000002057 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2023-08-08 17:41 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\system32\setup
2023-08-08 17:41 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\system32\migwiz
2023-08-08 17:41 - 2021-12-29 15:48 - 000000000 ____D C:\WINDOWS\appcompat
2023-08-08 16:04 - 2021-12-30 09:41 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-08-08 12:41 - 2021-12-30 09:41 - 175983240 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-08-06 20:17 - 2021-12-31 16:22 - 000000000 ____D C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2023-08-06 15:33 - 2021-12-31 21:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
2023-08-06 15:18 - 2022-01-01 23:39 - 000000000 ____D C:\Users\kelle\AppData\Roaming\WeMod
2023-08-06 15:17 - 2021-12-31 21:17 - 000000000 ____D C:\Riot Games
2023-08-06 14:22 - 2021-12-31 21:16 - 000000000 ____D C:\Users\kelle\AppData\Local\Riot Games
 
==================== Files in the root of some directories ========
 
2022-11-12 16:54 - 2022-11-12 16:54 - 000000000 _____ () C:\ProgramData\18578398722191403182.exe
2022-11-12 16:54 - 2022-11-12 16:54 - 000000000 _____ () C:\ProgramData\85718441354253509641.exe
2022-05-19 15:55 - 2022-05-19 15:55 - 000003953 _____ () C:\Program Files (x86)\unins000.dat
2022-05-19 15:55 - 2022-05-19 15:55 - 003218731 _____ (                                                            ) C:\Program Files (x86)\unins000.exe
2023-06-14 22:26 - 2023-06-14 22:58 - 000001583 _____ () C:\Users\kelle\AppData\Roaming\coolcam.ini
2022-11-30 17:37 - 2023-07-24 16:46 - 000000016 _____ () C:\Users\kelle\AppData\Roaming\msregsvv.dll
2022-04-10 21:34 - 2022-04-10 21:35 - 000007507 _____ () C:\Users\kelle\AppData\Roaming\rcm_install.log
2022-12-21 22:36 - 2022-12-21 22:36 - 000001004 _____ () C:\Users\kelle\AppData\Roaming\tof_launcher.reg
2022-03-20 10:16 - 2022-03-20 10:16 - 000006246 _____ () C:\Users\kelle\AppData\Local\2240114613
2023-03-10 14:59 - 2023-03-10 14:59 - 000006598 _____ () C:\Users\kelle\AppData\Local\92557321650
2022-12-16 22:32 - 2022-12-16 22:32 - 000000000 _____ () C:\Users\kelle\AppData\Local\oobelibMkey.log
2022-04-27 20:06 - 2022-04-27 20:19 - 000000683 _____ () C:\Users\kelle\AppData\Local\Params.xml
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-08-2023
Ran by kelle (03-09-2023 20:24:56)
Running from C:\Users\kelle\Downloads
Microsoft Windows 10 Enterprise Version 22H2 19045.3393 (X64) (2021-12-29 19:03:20)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-2005890046-4045795175-162804841-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2005890046-4045795175-162804841-503 - Limited - Disabled)
Guest (S-1-5-21-2005890046-4045795175-162804841-501 - Limited - Disabled)
kelle (S-1-5-21-2005890046-4045795175-162804841-1001 - Administrator - Enabled) => C:\Users\kelle
mom (S-1-5-21-2005890046-4045795175-162804841-1002 - Administrator - Enabled) => C:\Users\mom
WDAGUtilityAccount (S-1-5-21-2005890046-4045795175-162804841-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 21.07 (x64) (HKLM\...\7-Zip) (Version: 21.07 - Igor Pavlov)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 5.11.0.522.1 - Adobe Inc.)
Adobe Genuine Service (HKLM-x32\...\AdobeGenuineService) (Version: 8.3.0.49 - Adobe Inc.)
Adobe Photoshop 2023 (HKLM-x32\...\PHSP_24_1) (Version: 24.1.0.166 - Adobe Inc.)
AirEQ Premium (HKLM\...\Eiosis AirEQ Premium_is1) (Version: 1.2.6.0 - Eiosis)
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 5.05.16.529 - Advanced Micro Devices, Inc.)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.130 - Advanced Micro Devices, Inc.) Hidden
AMD I2C Driver (HKLM-x32\...\{B31D92D9-2914-46B0-9738-F668A563DE73}) (Version: 1.2.0.121 - Advanced Micro Devices, Inc.) Hidden
AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.90 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.24.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 8.0.0.13 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 23.Q1.1 - Advanced Micro Devices, Inc.)
AMD_Chipset_Drivers (HKLM-x32\...\{fa489a41-09bb-480e-95ff-0856f05112eb}) (Version: 5.05.16.529 - Advanced Micro Devices, Inc.) Hidden
Antares Auto-Tune Unlimited (HKLM\...\Antares Auto-Tune Unlimited_is1) (Version: 2021.12 - Antares & Team V.R)
AnthemScore (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\{284ec104-f783-4a62-b6e1-558ec625f67c}) (Version: 1.0.4 - Lunaverus)
AnthemScore (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\{7a91ea63-3473-40ef-8ed7-793b28c3ba45}) (Version: 1.0.4 - Lunaverus)
AOMEI Backupper (HKLM-x32\...\{A83692F5-3E9B-4E95-9E7E-B5DF5536CE9D}_is1) (Version: 6.9.1 - AOMEI International Network Limited.)
Apex Legends (HKLM-x32\...\{D7FBF176-382D-484E-863A-DFD1124A2A1C}) (Version: 1.1.3.2 - Electronic Arts, Inc.)
ARMOURY CRATE Lite Service (HKLM\...\{EF3944FF-2501-4568-B15C-5701E726719E}) (Version: 5.2.10 - ASUS)
Arturia Software Center 2.4.3 (HKLM-x32\...\Arturia Software Center_is1) (Version: 2.4.3 - Arturia)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
ASUS Aura SDK (HKLM\...\{CF8E6E00-9C03-4440-81C0-21FACB921A6B}) (Version: 3.04.17 - ASUSTek COMPUTER INC.) Hidden
ASUS Framework Service (HKLM-x32\...\{339A6383-7862-46DA-8A9D-E84180EF9424}) (Version: 3.1.0.2 - ASUSTeK Computer Inc.)
ASUS Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.107.103 - ASUSTeK Computer Inc.) Hidden
Audacity 3.1.3 (HKLM\...\Audacity_is1) (Version: 3.1.3 - Audacity Team)
Audiodope 0.26 (HKLM-x32\...\Audiodope_is1) (Version:  - Audiodope Team)
AURA lighting effect add-on (HKLM-x32\...\{1E2EA04B-FCA7-457E-B6F4-F33E1858E859}) (Version: 0.0.24 - ASUS)
AURA lighting effect add-on x64 (HKLM\...\{C5A4A164-4428-4931-B728-96EEF0FA3C44}) (Version: 0.0.24 - ASUS)
AURA Service (HKLM-x32\...\{0E536061-3B55-4D45-BF58-0BDA261C94B0}) (Version: 3.05.66 - ASUSTeK Computer Inc.) Hidden
AURA Service (HKLM-x32\...\{d4425362-eb40-415b-bb0d-5933fa345e9c}) (Version: 3.05.66 - ASUSTeK Computer Inc.)
Authy Desktop (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\authy) (Version: 2.2.3 - Twilio Inc.)
B-3 V2 2.6.1 (HKLM-x32\...\B-3 V2_is1) (Version: 2.6.1 - Arturia)
Baby Audio Transit version 1.0 (HKLM\...\Baby Audio Transit_is1) (Version: 1.0 - )
Bandicam (HKLM-x32\...\Bandicam) (Version: 6.0.6.2034 - Bandicam.com)
Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version:  - Bandicam.com)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Beatmaker v1.2.1 (HKLM\...\Beatmaker_is1) (Version: 1.2.1 - )
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Bus FORCE 1.2.0 (HKLM-x32\...\Bus FORCE_is1) (Version: 1.2.0 - Arturia)
Celemony Melodyne 5 (HKLM\...\Melodyne 5_is1) (Version: 5.2.0.006 - Celemony)
Chorus DIMENSION-D 1.3.0 (HKLM-x32\...\Chorus DIMENSION-D_is1) (Version: 1.3.0 - Arturia)
Chorus JUN-6 1.3.0 (HKLM-x32\...\Chorus JUN-6_is1) (Version: 1.3.0 - Arturia)
Chrome Remote Desktop Host (HKLM-x32\...\{C17C2857-FF33-4EA0-8220-14A17DF82668}) (Version: 116.0.5845.9 - Google LLC)
Cinematic Vol 2 Exp (HKLM\...\Slate Digital Cinematic Vol 2 Exp_is1) (Version: 2.0.0.0 - Slate Digital)
Circuit Breaker Exp (HKLM\...\Slate Digital Circuit Breaker Exp_is1) (Version: 2.5.0.1 - Slate Digital)
Clavinet V 1.10.1 (HKLM-x32\...\Clavinet V_is1) (Version: 1.10.1 - Arturia)
Clone version 1.0.0 (HKLM\...\Clone_is1) (Version: 1.0.0 - )
Comp DIODE-609 1.2.0 (HKLM-x32\...\Comp DIODE-609_is1) (Version: 1.2.0 - Arturia)
Comp FET-76 1.5.0 (HKLM-x32\...\Comp FET-76_is1) (Version: 1.5.0 - Arturia)
Comp TUBE-STA 1.5.0 (HKLM-x32\...\Comp TUBE-STA_is1) (Version: 1.5.0 - Arturia)
Comp VCA-65 1.5.0 (HKLM-x32\...\Comp VCA-65_is1) (Version: 1.5.0 - Arturia)
Crescendo Music Notation Editor (HKLM-x32\...\Crescendo) (Version: 8.33 - NCH Software)
CurseForge (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Overwolf_cchhcaiapeikjbdbpfplgmpobbcdkdaphclbmkbj) (Version: 0.213.2.7331 - Overwolf app)
Custom Shop version 1.8.0 (HKLM-x32\...\{21BAD046-50EC-49E2-BE7B-F9729704F2C3}_is1) (Version: 1.8.0 - IK Multimedia)
Delay BRIGADE 1.5.0 (HKLM-x32\...\Delay BRIGADE_is1) (Version: 1.5.0 - Arturia)
Delay ETERNITY 1.5.0 (HKLM-x32\...\Delay ETERNITY_is1) (Version: 1.5.0 - Arturia)
Delay TAPE-201 1.5.0 (HKLM-x32\...\Delay TAPE-201_is1) (Version: 1.5.0 - Arturia)
Denuvo Anti-Cheat (HKLM\...\Denuvo Anti-Cheat) (Version: 4.3.10.8362 - Denuvo GmbH)
Detroit Vol 2 Exp (HKLM\...\Slate Digital Detroit Vol 2 Exp_is1) (Version: 2.0.0.0 - Slate Digital)
discoDSP Discovery Pro (HKLM-x32\...\discoDSP Discovery Pro R6.4.3_is1) (Version: 6.4.3 - )
Discord (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Discord) (Version: 1.0.9016 - Discord Inc.)
Docs (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\e1a664b81896c7fa1da974408b7f5e17) (Version: 1.0 - Google\Chrome)
Dodo MIDI version 2.0 (HKLM-x32\...\Dodo MIDI_is1) (Version: 2.0 - )
E2Deesser (HKLM\...\Eiosis E2Deesser_is1) (Version: 1.1.5.0 - Eiosis)
EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.4.0.5517 - Electronic Arts) Hidden
EA app (HKLM-x32\...\{cd40d620-57ac-41f7-a40f-98f39ab12a2f}) (Version: 13.4.0.5517 - Electronic Arts)
Epic Games Launcher (HKLM-x32\...\{209F4B4B-3DF2-4825-9906-D4D6A80EC09E}) (Version: 1.3.0.0 - Epic Games, Inc.)
Epic Online Services (HKLM-x32\...\{32C68D93-D32F-4B01-8250-61642BFC22F8}) (Version: 2.0.28.0 - Epic Games, Inc.)
EQ SITRAL-295 1.2.0 (HKLM-x32\...\EQ SITRAL-295_is1) (Version: 1.2.0 - Arturia)
ExpressVPN (HKLM-x32\...\{665fe0dd-e156-4620-9f2a-092367e44813}) (Version: 12.50.0.4 - ExpressVPN)
ExpressVPN (HKLM-x32\...\{E5B9C3E5-889C-4F22-A959-F4B899ED7835}) (Version: 12.50.0.4 - ExpressVPN) Hidden
FabFilter Total Bundle (HKLM\...\FabFilter Total Bundle_is1) (Version: 2020.05.18 - FabFilter)
FG-X 2 (HKLM\...\Slate Digital FG-X 2_is1) (Version: 1.0.3.0 - Slate Digital)
Filter M12 1.6.0 (HKLM-x32\...\Filter M12_is1) (Version: 1.6.0 - Arturia)
Filter MINI 1.7.0 (HKLM-x32\...\Filter MINI_is1) (Version: 1.7.0 - Arturia)
Filter SEM 1.6.0 (HKLM-x32\...\Filter SEM_is1) (Version: 1.6.0 - Arturia)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version:  - Image-Line)
Flanger BL-20 1.3.0 (HKLM-x32\...\Flanger BL-20_is1) (Version: 1.3.0 - Arturia)
GeeGeeClient (HKLM-x32\...\{4098FA2E-B92A-491F-A3FE-08D0B4F48358}) (Version: 1.1.20.0 - WonderPeople)
Gmail (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\1712bce321bf96600c75026c346c5ae9) (Version: 1.0 - Google\Chrome)
Google Chrome (HKLM-x32\...\{D0A8BBD8-0F9E-3D3C-9AE7-953A5ABCEA09}) (Version: 116.0.5845.141 - Google LLC)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 79.0.2.0 - Google LLC)
Google Drive (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\bbafe169dcc96c3092a18a0d6b06f5bf) (Version: 1.0 - Google\Chrome)
Grammarly for Windows (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Grammarly Desktop Integrations) (Version: 1.0.6.191 - )
IK Multimedia Authorization Manager version 1.0.19 (HKLM\...\{85BC0DCB-69E5-4279-AA25-F108EF896588}_is1) (Version: 1.0.19 - IK Multimedia)
Infinity EQ (HKLM\...\Slate Digital Infinity EQ_is1) (Version: 1.1.7.0 - Slate Digital)
Intel® Hardware Accelerated Execution Manager (HKLM\...\{754CC9DC-3DB4-4FB2-B71E-87331DB9EA17}) (Version: 7.5.4 - Intel Corporation)
iZotope Meter Tap 3 (HKLM\...\Meter Tap 3_is1) (Version: 1.0.4 - iZotope)
iZotope Ozone 9 (HKLM\...\Ozone 9_is1) (Version: 9.11.1 - iZotope)
Kilohearts Plugins (HKLM\...\{258C71F6-42C5-4CEC-B62C-00C23BF73831}_is1) (Version: 2022.12.20 - Kilohearts AB)
Kontakt 5 NO INSTALL (HKLM\...\{4B3E0D95-3270-4B88-9EDE-A065680EF65C}_is1) (Version: 5.6.6.16 - Native Instruments)
KORG ARP ODYSSEY (HKLM\...\KORG ARP ODYSSEY_is1) (Version: 1.5.0 - KORG)
Kuassa Efektor CP3603 (HKLM\...\Efektor CP3603_is1) (Version: 1.1.0 - Kuassa)
Kuassa Efektor Distortion Bundle (HKLM\...\Efektor Distortion Bundle_is1) (Version: 1.1.0 - Kuassa)
Kuassa Efektor DL3606 (HKLM\...\Efektor DL3606_is1) (Version: 1.1.1 - Kuassa)
Kuassa Efektor Modulation Bundle (HKLM\...\Efektor Modulation Bundle_is1) (Version: 1.1.1 - Kuassa)
Kuassa Efektor RV3604 (HKLM\...\Efektor RV3604_is1) (Version: 1.1.0 - Kuassa)
Kuassa Efektor WF3607 (HKLM\...\Efektor WF3607_is1) (Version: 1.1.0 - Kuassa)
Kuassa Efektor Whammo (HKLM\...\Efektor Whammo_is1) (Version: 1.0.0 - Kuassa)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Riot Game league_of_legends.live) (Version:  - Riot Games, Inc)
Line 6 Helix Native v3.1.5 (HKLM\...\Line 6 Helix Native v3.1.5_is1) (Version: 3.1.5 - Yamaha Guitar Group, Line 6 & Team V.R)
Lustrous Plates version 1.2.2 (HKLM\...\{39AAAED0-CFDF-22E3-AEC7-FBBBA7CE0713}_is1) (Version: 1.2.2 - LiquidSonics)
Massive X (HKLM\...\Massive X_is1) (Version: 1.2.1 - Native Instruments & Team V.R)
MediaHuman YouTube to MP3 Converter 3.9.9.70 (HKLM-x32\...\MediaHuman YouTube to MP3 Converter_is1) (Version: 3.9.9.70 - MediaHuman)
Melodyne 5 (HKLM-x32\...\{16DF894D-FC3F-4B87-908D-671E201CD7A8}) (Version: 5.02.00006 - Celemony Software GmbH)
MetaTune (HKLM\...\Slate Digital MetaTune_is1) (Version: 1.1.6.0 - Slate Digital)
Microsoft .NET Host - 5.0.14 (x64) (HKLM\...\{61A6E3A7-F406-418A-B2A6-0606DB55B325}) (Version: 40.56.30907 - Microsoft Corporation) Hidden
Microsoft .NET Host - 6.0.5 (x64) (HKLM\...\{F3B3A61B-DC16-429A-A260-DBAFE66741A9}) (Version: 48.23.40665 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 5.0.14 (x64) (HKLM\...\{8D88F0E2-CE9B-4A6D-8309-FDC562195F5B}) (Version: 40.56.30907 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.5 (x64) (HKLM\...\{3E6CCD41-6B96-47BD-8E1E-D7B593CEE976}) (Version: 48.23.40665 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 5.0.14 (x64) (HKLM\...\{B810ACDF-1C0C-4108-9B92-12F1674FA444}) (Version: 40.56.30907 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.5 (x64) (HKLM\...\{089A177D-98AE-4195-A115-D3C45613B875}) (Version: 48.23.40665 - Microsoft Corporation) Hidden
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.16731.20170 - Microsoft Corporation)
Microsoft Access 2019 - en-us (HKLM\...\Access2019Retail - en-us) (Version: 16.0.16731.20170 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 116.0.1938.69 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 116.0.1938.69 - Microsoft Corporation)
Microsoft GameInput (HKLM-x32\...\{1F2B6AF3-C260-8666-5950-E3FEDBC851D6}) (Version: 10.1.22621.3036 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 23.169.0813.0001 - Microsoft Corporation)
Microsoft Publisher 2019 - en-us (HKLM\...\Publisher2019Retail - en-us) (Version: 16.0.16731.20170 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{BB052C53-34CB-42DE-AF41-66FDFCEEC868}) (Version: 3.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 (HKLM-x32\...\{8bdfe669-9705-4184-9368-db9ce581e0e7}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 (HKLM-x32\...\{410c0ee1-00bb-41b6-9772-e12c2828b02f}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532 (HKLM\...\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532 (HKLM\...\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 (HKLM-x32\...\{C2C59CAB-8766-4ABD-A8EF-1151A36C41E5}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 (HKLM-x32\...\{73F77E4E-5A17-46E5-A5FC-8A061047725F}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 5.0.14 (x64) (HKLM\...\{4CD6FFC6-FA14-4016-A7A6-B7E3D6286331}) (Version: 40.56.30911 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 5.0.14 (x64) (HKLM-x32\...\{d21a4f20-968a-4b0c-bf04-a38da5f06e41}) (Version: 5.0.14.30911 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 6.0.5 (x64) (HKLM\...\{DE578B32-084A-49E7-8E55-6F58A37578C0}) (Version: 48.23.40699 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.5 (x64) (HKLM-x32\...\{0f711ee3-eb88-456d-acb4-c2ee31add211}) (Version: 6.0.5.31215 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
MIDI Control Center 1.1.0 (HKLM-x32\...\MIDI Control Center_is1) (Version: 1.1.0 - Arturia)
Minion (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\{Minion}}_is1) (Version: 3.0 - Good Game Mods LLC)
Miroslav Philharmonik 2 version 2.0.5 (HKLM\...\{CF8EE134-AD62-4D47-81A5-A42CAE3B1710}_is1) (Version: 2.0.5 - IK Multimedia)
Monolith Exp (HKLM\...\Slate Digital Monolith Exp_is1) (Version: 2.5.0.1 - Slate Digital)
MO-TT (HKLM\...\Slate Digital MO-TT_is1) (Version: 1.1.6.0 - Slate Digital)
Movavi Screen Recorder 23 (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Movavi Screen Recorder 23) (Version: 23.1.0 - Movavi)
MuseScore 3 (HKLM\...\{FF67E071-104C-4C42-9301-184442745671}) (Version: 3.6.2.548021803 - Werner Schweer and Others)
Native Access 3.4.0 (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\c410b7d2-8fce-53b3-8332-e98b6e89a16a) (Version: 3.4.0 - Native Instruments)
Native Instruments Battery 4 (HKLM-x32\...\Native Instruments Battery 4) (Version: 4.3.0.0 - Native Instruments)
Native Instruments Battery Now Library (HKLM-x32\...\Native Instruments Battery Now Library) (Version: 1.0.26.1 - Native Instruments)
Native Instruments Community Drive 2021 (HKLM-x32\...\Native Instruments Community Drive 2021) (Version: 1.0.0.7 - Native Instruments)
Native Instruments Creator Tools (HKLM-x32\...\Native Instruments Creator Tools) (Version: 1.4.0.0 - Native Instruments)
Native Instruments Feel It (HKLM-x32\...\Native Instruments Feel It) (Version: 1.0.0.5 - Native Instruments)
Native Instruments Kontakt (HKLM-x32\...\Native Instruments Kontakt) (Version: 6.8.0.0 - Native Instruments)
Native Instruments Kontakt 7 (HKLM-x32\...\Native Instruments Kontakt 7) (Version: 7.5.1.0 - Native Instruments)
Native Instruments Massive X (HKLM-x32\...\Native Instruments Massive X) (Version: 1.3.5.238 - Native Instruments)
Native Instruments NTKDaemon (HKLM-x32\...\Native Instruments NTKDaemon) (Version: 1.12.0.0 - Native Instruments)
Native Instruments Reaktor 6 (HKLM-x32\...\Native Instruments Reaktor 6) (Version: 6.4.3.0 - Native Instruments)
Neuratron AudioScore Ultimate Demo (HKLM-x32\...\Neuratron AudioScore Ultimate Demo) (Version: 7.0.1 - Neuratron Ltd)
Noiiz Filter version 1.0.2 (HKLM-x32\...\{ED1CBD93-307A-4213-988D-968E874E5682}}_is1) (Version: 1.0.2 - Noiiz)
Noiiz Player version 1.1.2 (HKLM-x32\...\{EEEB9799-BD52-41A6-A3FB-9086A3732DF6}}_is1) (Version: 1.1.2 - Noiiz)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 29.1.2 - OBS Project)
Oculus (HKLM\...\Oculus) (Version: <3 - Facebook Technologies, LLC)
Oculus Developer Hub 2.1.1 (HKLM\...\40f538b8-99de-5e78-aeed-1ff8cd18d902) (Version: 2.1.1 - Facebook Technologies, LLC)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.16731.20052 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.16731.20170 - Microsoft Corporation) Hidden
Opera GX Stable 100.0.4815.82 (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Opera GX 100.0.4815.82) (Version: 100.0.4815.82 - Opera Software)
Opera Stable 100.0.4815.76 (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Opera 100.0.4815.76) (Version: 100.0.4815.76 - Opera Software)
Overwatch (HKLM-x32\...\Overwatch) (Version:  - Blizzard Entertainment)
Overwatch Beta (HKLM-x32\...\Overwatch Beta) (Version:  - Blizzard Entertainment)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.230.0.10 - Overwolf Ltd.)
PACE License Support Win64 (HKLM\...\{05BDA3E7-1473-4651-8467-4A2A8F7F470B}) (Version: 5.8.1.4359 - PACE Anti-Piracy, Inc.) Hidden
PACE License Support Win64 (HKLM-x32\...\InstallShield_{05BDA3E7-1473-4651-8467-4A2A8F7F470B}) (Version: 5.8.1.4359 - PACE Anti-Piracy, Inc.)
Palia (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Palia) (Version: 0.166.0 - Singularity 6 Corporation)
Phaser BI-TRON 1.3.0 (HKLM-x32\...\Phaser BI-TRON_is1) (Version: 1.3.0 - Arturia)
Piano V2 2.9.1 (HKLM-x32\...\Piano V2_is1) (Version: 2.9.1 - Arturia)
Pre 1973 1.6.0 (HKLM-x32\...\Pre 1973_is1) (Version: 1.6.0 - Arturia)
Pre TridA 1.6.0 (HKLM-x32\...\Pre TridA_is1) (Version: 1.6.0 - Arturia)
Pre V76 1.6.0 (HKLM-x32\...\Pre V76_is1) (Version: 1.6.0 - Arturia)
PreSonus Studio One 5 (HKLM\...\PreSonus Studio One 5) (Version: 5.5.2.86528 - PreSonus Audio Electronics)
Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 3.0.0.0 - Advanced Micro Devices, Inc.) Hidden
qBittorrent 4.4.5 (HKLM-x32\...\qBittorrent) (Version: 4.4.5 - The qBittorrent project)
QModManager (Below Zero) (HKLM-x32\...\{A535470D-3403-46A2-8D44-28AD4B90C9A3}_is1) (Version: 4.3.0 - QModManager)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9235.1 - Realtek Semiconductor Corp.)
Repeater (64bit) (HKLM\...\{0FD4B492-4485-4A36-BFC2-04CD539298B2}) (Version: 1.2.2.0 - D16 Group Audio Software)
Rev INTENSITY 1.4.0 (HKLM-x32\...\Rev INTENSITY_is1) (Version: 1.4.0 - Arturia)
Rev PLATE-140 1.5.0 (HKLM-x32\...\Rev PLATE-140_is1) (Version: 1.5.0 - Arturia)
Rev SPRING-636 1.4.0 (HKLM-x32\...\Rev SPRING-636_is1) (Version: 1.4.0 - Arturia)
Riot Client  (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Riot Game Riot_Client.) (Version:  - Riot Games, Inc)
Riot Repair Tool 1.1.3 (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\980795d3-660d-5bf1-af59-4286bb5d9647) (Version: 1.1.3 - Riot Games Inc.)
Riot Vanguard (HKLM\...\Riot Vanguard) (Version:  - Riot Games, Inc.)
ROCCAT Swarm (HKLM-x32\...\{9D12397F-45AF-4517-B492-1D1E2FA475EE}) (Version: 1.93.990 - ROCCAT GmbH) Hidden
ROCCAT Swarm (HKLM-x32\...\InstallShield_{9D12397F-45AF-4517-B492-1D1E2FA475EE}) (Version: 1.93.990 - ROCCAT GmbH)
Roccat Talk (HKLM-x32\...\{605D671E-1D1E-4840-84D9-BFACE17F160D}) (Version: 1.00.0015 - Roccat GmbH)
ROG Live Service (HKLM\...\{2D87BFB6-C184-4A59-9BBE-3E20CE797631}) (Version: 2.1.5.0 - ASUSTek COMPUTER INC.)
Roland Cloud Manager (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\{73160e3c-2a5e-4ca9-bf05-382e2c3e2063}) (Version: 2.6.4 - Roland Virtual Sonics)
Roland Legendary & AIRA Series (HKLM\...\Roland Legendary & AIRA Series_is1) (Version: 2019.3 - Roland VS & Team V.R)
Roland VS SRX DANCE TRAX (HKLM\...\SRX DANCE TRAX_is1) (Version: 1.0.4 - Roland VS)
ScoreCloud Studio (HKLM-x32\...\ScoreCloud) (Version: 4.6.2 - DoReMIR Music Research)
SD-1 Vol 2 Exp (HKLM\...\Slate Digital SD-1 Vol 2 Exp_is1) (Version: 2.0.0.0 - Slate Digital)
Serato Sample (HKLM\...\{D381316B-20C8-4DB4-862A-6881F891DD71}) (Version: 1.4.0.61 - Serato) Hidden
Serato Sample (HKLM-x32\...\{861b1eac-cda6-484c-af92-f1047e0fef82}) (Version: 1.4.0.61 - )
Serum by Xfer Records (HKLM-x32\...\Serum) (Version:  - )
Sheets (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\7c66cdc45fc474e9c1a9f00bd10f7f44) (Version: 1.0 - Google\Chrome)
SideQuest 0.10.26 (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\4924ec51-3e48-5cb7-b145-2119467094c7) (Version: 0.10.26 - Shane Harris)
Slate Digital Connect 1.7.0 (HKLM\...\802e6e26-2d99-58eb-bb7c-666b9638993c) (Version: 1.7.0 - Slate Digital)
Slate Digital Fresh Air (HKLM\...\{af2fe7e8-08f8-4c81-b875-ec4c7a97a204}Slate Digi~4955043A_is1) (Version: 1.0.8 - Slate Digital)
Slate Digital Murda Melodies (HKLM\...\{af2fe7e8-08f8-4c81-b875-ec4c7a97a204}Slate Digi~487BC8ED_is1) (Version: 1.0.8 - Slate Digital)
Slate Digital Storch Filter (HKLM\...\{af2fe7e8-08f8-4c81-b875-ec4c7a97a204}Slate Digi~0AC0AAD2_is1) (Version: 1.0.1 - Slate Digital)
Slides (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\82f7a1d2409d8e39dfd5089e4db4e5cd) (Version: 1.0 - Google\Chrome)
Sonic Academy ANA 2 Slate Bundle 2.5.1 (HKLM-x32\...\Sonic Academy ANA 2 Slate Bundle) (Version: 2.5.1 - Sonic Academy)
Spitfire Audio version 3.3.23 (HKLM-x32\...\{ABC5F486-25BD-4BAA-9FA1-A84152CBB563}_is1) (Version: 3.3.23 - Spitfire Audio Holdings Ltd)
Splice (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\splice) (Version: 4.3.78461 - Distributed Creation, Inc.)
Splitter Studio (HKLM\...\{21F45639-B1A4-4C5F-B326-7BB03FB8F253}) (Version: 0.6.7.0 - Splitter AB)
Splitter Studio 0.3.37 (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\e26678d1-c17d-5f02-9d97-ca1055cc7bb1) (Version: 0.3.37 - )
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SteelSeries GG 21.0.0 (HKLM\...\SteelSeries GG) (Version: 21.0.0 - SteelSeries ApS)
Streamlabs Desktop 1.10.0 (HKLM\...\029c4619-0385-5543-9426-46f9987161d9) (Version: 1.10.0 - General Workings, Inc.)
Sugar Bytes - Aparillo 1.1.0 (HKLM\...\Aparillo_is1) (Version: 1.1.0 - Sugar Bytes)
Sugar Bytes - Cyclop 1.3.4 (HKLM\...\Cyclop_is1) (Version: 1.3.4 - Sugar Bytes)
Sugar Bytes - Egoist 1.6.1 (HKLM\...\Egoist_is1) (Version: 1.6.1 - Sugar Bytes)
Sugar Bytes - Factory 1.1.1 (HKLM\...\Factory_is1) (Version: 1.1.1 - Sugar Bytes)
Sugar Bytes - Nest 1.0.7 (HKLM\...\Nest_is1) (Version: 1.0.7 - Sugar Bytes)
Sugar Bytes - Obscurium 1.1.3 (HKLM\...\Obscurium_is1) (Version: 1.1.3 - Sugar Bytes)
Sugar Bytes - Thesys 1.7.2 (HKLM\...\Thesys_is1) (Version: 1.7.2 - Sugar Bytes)
Sugar Bytes - Unique 1.5.8 (HKLM\...\Unique_is1) (Version: 1.5.8 - Sugar Bytes)
Surfshark TAP Driver Windows (HKLM-x32\...\{15C72941-C198-49E4-8CF3-4B27C64E0217}) (Version: 1.0.1 - Surfshark)
SWAM Solo Brass Bundle (HKLM\...\{133115C8-9BB3-4F0F-9B8E-82E9C71413A7}_is1) (Version: 1.6.2 - Audio Modeling & Team V.R)
Synapse Audio DUNE 3 (HKLM\...\DUNE 3_is1) (Version: 3.4.0.4 - Synapse Audio)
Syncovery 9.47g (HKLM\...\Syncovery x64_is1) (Version: 9.47g - Super Flexible Software)
Syncrosoft License Control (HKLM-x32\...\Syncrosoft License Control) (Version:  - SIA Syncrosoft)
Telegram Desktop (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 3.7 - Telegram FZ-LLC)
The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: 2.6.3.0 - Zenimax Online Studios)
The Sims 4 (HKLM-x32\...\The Sims 4_is1) (Version:  - )
theTape version 1.0.0 (HKLM\...\theTape_is1) (Version: 1.0.0 - )
TroveTools .NET (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\0ad522f4516a2a4e) (Version: 1.2.0.5 - Dazo)
TSR CC Manager 1.1.2 (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\a49330da-1613-561d-8ac8-0b807a98141c) (Version: 1.1.2 - )
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 128.0.10632 - Ubisoft)
UE Prerequisites (x64) (HKLM\...\{E171B21A-DA58-432D-A74B-D13B204BA477}) (Version: 1.0.16.0 - Epic Games, Inc.) Hidden
UE Prerequisites (x64) (HKLM-x32\...\{aad8a4b2-74da-409d-abb6-79a299008692}) (Version: 1.0.16.0 - Epic Games, Inc.) Hidden
uJAM Bundle (HKLM\...\{5E1D9664-3700-4028-920D-03281C7C7CEE}_is1) (Version: 2022.10 - NXTGN Music Technology GmbH)
Ultra Multisample Exp (HKLM\...\Slate Digital Ultra Multisample Exp_is1) (Version: 2.5.0.0 - Slate Digital)
uTorrent Web (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\utweb) (Version: 1.2.8 - Rainberry, Inc.)
UXP WebView Support (HKLM-x32\...\UXPW_1_1_0) (Version: 1.1.0 - Adobe Inc.)
VALORANT (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Riot Game valorant.live) (Version:  - Riot Games, Inc)
VBCABLE, The Virtual Audio Cable (HKLM\...\VB:VBCABLE {87459874-1236-4469}) (Version:  - VB-Audio Software)
VerbSuite Classics (HKLM\...\Slate Digital VerbSuite Classics_is1) (Version: 1.1.5.0 - Slate Digital)
VerbSuite Classics FG-224 Expansion (HKLM\...\Slate Digital VerbSuite Classics FG-224 Expansion_is1) (Version: 1.0.0.6 - Slate Digital)
Vintage Analog Vol 2 Exp (HKLM\...\Slate Digital Vintage Analog Vol 2 Exp_is1) (Version: 2.0.0.0 - Slate Digital)
Virtual Tape Machines (HKLM\...\Slate Digital Virtual Tape Machines_is1) (Version: 1.2.5.0 - Slate Digital)
Vital version 1.0.7 (HKLM\...\Vital_is1) (Version: 1.0.7 - )
Voicemod (HKLM\...\{8435A407-F778-4647-9CDB-46E5EC50BAD0}_is1) (Version: 2.37.0.0 - Voicemod S.L.)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vybz version 1.1.0 (HKLM\...\Vybz_is1) (Version: 1.1.0 - )
Warzone Tracker (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\Overwolf_ajefnnebkfaanecegnngplpimonhdijkiomojilk) (Version: 0.12.0 - Overwolf app)
WeMod (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\WeMod) (Version: 8.10.3 - WeMod)
WinDirStat 1.1.2 (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\WinDirStat) (Version:  - )
Windows Migration Assistant (HKLM-x32\...\{DA726B16-1892-4C34-9049-F47644A5AE19}) (Version: 2.4.0.3 - Apple Inc.)
Windows PC Health Check (HKLM\...\{014B7442-C784-45D3-A152-F7D2C651F28A}) (Version: 3.3.2110.22002 - Microsoft Corporation)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
WinRAR 6.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH)
XLN Audio RC-20 Retro Color (HKLM\...\RC-20 Retro Color_is1) (Version: 1.2.6.2 - XLN Audio)
XLN Online Installer (HKLM\...\XLN Online Installer Inno Setup ID_is1) (Version:  - )
Yousician Launcher version 2.11 (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\{EF45EAE9-523E-47C3-8634-A81923B11DD5}_is1) (Version: 2.11 - Yousician)
YouTube (HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\157cfd77d6ef856a2aaf871c674597a0) (Version: 1.0 - Google\Chrome)
 
Packages:
=========
Adobe Notification Client -> C:\Program Files\WindowsApps\AdobeNotificationClient_3.0.1.1_x86__enpm4xejd91yc [2023-08-31] (Adobe Systems Incorporated)
ARMOURY CRATE -> C:\Program Files\WindowsApps\B9ECED6F.ArmouryCrate_5.6.10.0_x64__qmba6cd70vzyy [2023-08-31] (ASUSTeK COMPUTER INC.)
Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe [2023-09-02] (Microsoft Corporation)
Crunchyroll -> C:\Program Files\WindowsApps\15EF7777.Crunchyroll_1.3.1.0_x64__mgdgtskya6f22 [2023-08-31] (Ellation, Inc.)
Deep Rock Galactic -> C:\Program Files\WindowsApps\CoffeeStainStudios.DeepRockGalactic_38.1.24023.0_x64__496a1srhmar9w [2023-09-03] (Coffee Stain Publishing)
EarTrumpet -> C:\Program Files\WindowsApps\40459File-New-Project.EarTrumpet_2.3.0.0_x86__1sdd7yawvg6ne [2023-08-31] (File-New-Project) [Startup Task]
Forza Horizon 5 -> C:\Program Files\WindowsApps\Microsoft.624F8B84B80_3.607.493.0_x64__8wekyb3d8bbwe [2023-08-19] (Microsoft Studios)
Microsoft Defender -> C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2307.24001.0_x64__8wekyb3d8bbwe [2023-09-02] (Microsoft Corporation) [Startup Task]
Minecraft Launcher -> C:\Program Files\WindowsApps\Microsoft.4297127D64EC6_1.2.16.0_x64__8wekyb3d8bbwe [2023-06-07] (Microsoft Studios)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2023-08-31] (Microsoft Corporation)
RecForth -> C:\Program Files\WindowsApps\IOForth.Screenrecord-screenrecorder_1.1.11.0_x64__pxs7cjhtcq1xt [2023-08-31] (IOForth)
Screen Recorder for Windows 11 -> C:\Program Files\WindowsApps\45907smallapp.ScreenRecorderforWindows11_1.0.5.0_x64__z9hw59krvrfng [2023-08-31] (screen recorder app)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.17.8180.0_x64__8wekyb3d8bbwe [2023-09-02] (Microsoft Studios) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0 [2023-09-02] (Spotify AB) [Startup Task]
TranslucentTB -> C:\Program Files\WindowsApps\28017CharlesMilette.TranslucentTB_2023.1.0.0_x64__v826wp6bftszj [2023-08-31] (Charles Milette) [Startup Task]
VidForth -> C:\Program Files\WindowsApps\IOForth.DVDPlayer-FreeDVDPlayerMediaPlayerVideoPla_1.0.5.0_x64__pxs7cjhtcq1xt [2023-08-31] (IOForth)
Windows Package Manager Source (winget) -> C:\Program Files\WindowsApps\Microsoft.Winget.Source_2023.903.1737.243_neutral__8wekyb3d8bbwe [2023-09-03] (Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2005890046-4045795175-162804841-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-34BF2E7968AA} -> [Creative Cloud Files] => C:\Users\kelle\Creative Cloud Files [2022-12-16 22:15]
CustomCLSID: HKU\S-1-5-21-2005890046-4045795175-162804841-1001_Classes\CLSID\{2F81B25E-7507-4844-BFF2-77D2CC24CED4}\localserver32 -> C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Inc. -> Adobe Inc.)
CustomCLSID: HKU\S-1-5-21-2005890046-4045795175-162804841-1001_Classes\CLSID\{89b2b650-c4dd-d68b-46e7-3176f1973c8b}\localserver32 -> C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voicemod Sociedad Limitada -> Voicemod)
CustomCLSID: HKU\S-1-5-21-2005890046-4045795175-162804841-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems)
ShellIconOverlayIdentifiers: [     OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [     OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [     OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [     OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [     OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [     OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [     OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\79.0.2.0\drivefsext.dll [2023-08-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [    GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\79.0.2.0\drivefsext.dll [2023-08-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [    GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\79.0.2.0\drivefsext.dll [2023-08-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [    GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\79.0.2.0\drivefsext.dll [2023-08-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-08-01] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-08-01] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-08-01] (Adobe Inc. -> )
ShellIconOverlayIdentifiers-x32: [     OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [     OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [     OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [     OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [     OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [     OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [     OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-08-01] (Adobe Inc. -> )
ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\79.0.2.0\drivefsext.dll [2023-08-09] (Google LLC -> Google, Inc.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\79.0.2.0\drivefsext.dll [2023-08-09] (Google LLC -> Google, Inc.)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\23.169.0813.0001\FileSyncShell64.dll [2023-09-02] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\79.0.2.0\drivefsext.dll [2023-08-09] (Google LLC -> Google, Inc.)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-08-01] (Adobe Inc. -> )
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [vidc.i420] => C:\WINDOWS\system32\lvcod64.dll [175392 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Drivers32: [vidc.mjpg] => C:\WINDOWS\system32\bdmjpeg64.dll [75248 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\WINDOWS\system32\bdmpegv64.dll [75272 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\WINDOWS\system32\bdmpega64.acm [75784 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Drivers32: [vidc.VP60] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2014-09-16] (Electronic Arts -> On2.com)
HKLM\...\Drivers32: [vidc.VP61] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2014-09-16] (Electronic Arts -> On2.com)
HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\SysWOW64\bdmjpeg.dll [71152 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\SysWOW64\bdmpegv.dll [71176 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\SysWOW64\bdmpega.acm [71176 2017-01-26] (Bandicam Company -> )
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=mpnpojknpmmopombnjdcgaaiekajbnjb
ShortcutWithArgument: C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=fmgjjmmmlfnkbppncabfkddbjimcfncm
ShortcutWithArgument: C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=aghbiahbpaijignceidepookljebhfak
ShortcutWithArgument: C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=fhihpiojkbmbpdjeoajapmgkhlnakfjf
ShortcutWithArgument: C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=kefjledonklijopmnomlcbpllchaibag
ShortcutWithArgument: C:\Users\kelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml
ShortcutWithArgument: C:\Users\kelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\kellen - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default"
 
==================== Loaded Modules (Whitelisted) =============
 
2022-09-07 02:36 - 2022-06-20 15:14 - 000520704 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ac_node_addon\prebuilds\win32-ia32\node.napi.node
2022-09-07 02:36 - 2022-06-08 10:33 - 000479744 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ffi-napi\prebuilds\win32-ia32\node.napi.node
2022-09-07 02:36 - 2022-06-08 10:33 - 000470016 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ref-napi\prebuilds\win32-ia32\node.napi.node
2022-09-07 02:36 - 2022-06-08 10:33 - 000832512 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\usb-detection\prebuilds\win32-ia32\node.napi.node
2022-09-07 02:36 - 2022-06-08 10:33 - 000081920 _____ () [File not signed] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\WindowID\WindowID.dll
2023-04-20 17:41 - 2023-04-20 17:41 - 000912896 _____ () [File not signed] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-core.dll
2023-04-20 17:41 - 2023-04-20 17:41 - 003109888 _____ () [File not signed] C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-s3.dll
2021-12-29 15:01 - 2021-12-26 09:00 - 000093696 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData:482EE99B1E21CE8C [217]
AlternateDataStreams: C:\Users\All Users:482EE99B1E21CE8C [217]
AlternateDataStreams: C:\ProgramData\agent.update.1642639452.bdinstall.v2.bin:2BD3E35EE7 [3322]
AlternateDataStreams: C:\ProgramData\Application Data:482EE99B1E21CE8C [217]
AlternateDataStreams: C:\ProgramData\PACE:7C1C1EBD546D84A3 [217]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk:DC8F23BC3A [3322]
AlternateDataStreams: C:\Users\kelle\Application Data:671890e017d8a4fb26004192461213ff [394]
AlternateDataStreams: C:\Users\kelle\AppData\Roaming:671890e017d8a4fb26004192461213ff [394]
AlternateDataStreams: C:\Users\kelle\AppData\Local\Temp:$DATA​ [16]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [7476]
 
==================== Safe Mode (Whitelisted) ==================
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-08-31] (Microsoft Corporation -> Microsoft Corporation)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2021-12-29 15:48 - 2023-07-29 13:36 - 000002416 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1       localhost
0.0.0.0 door.event-bus.io
109.94.209.70      *.fitgirl-repacks.xyz           # Fake FitGirl site
127.0.0.1 checkhost.local
109.94.209.70      *.fitgirl-repacks.xyz           # Fake FitGirl site
109.94.209.70      *.fitgirl-repacks.xyz           # Fake FitGirl site
109.94.209.70      www.fitgirl-repacks-site.org    # Fake FitGirl site
127.0.0.1 checkhost.local
109.94.209.70      *.fitgirl-repacks.xyz           # Fake FitGirl site
109.94.209.70      *.fitgirl-repacks.xyz           # Fake FitGirl site
109.94.209.70      fitgirlrepacks.in               # Fake FitGirl site
109.94.209.70      www.fitgirlrepacks.in           # Fake FitGirl site
109.94.209.70      fitgirlrepacks.co               # Fake FitGirl site
109.94.209.70      fitgirl-repacks.cc              # Fake FitGirl site
109.94.209.70      fitgirl-repacks.to              # Fake FitGirl site
109.94.209.70      fitgirl-repack.com              # Fake FitGirl site
109.94.209.70      fitgirl-repacks.website         # Fake FitGirl site
109.94.209.70      www.fitgirlrepacks.co           # Fake FitGirl site
109.94.209.70      www.fitgirl-repacks.cc          # Fake FitGirl site
109.94.209.70      www.fitgirl-repacks.to          # Fake FitGirl site
109.94.209.70      www.fitgirl-repack.com          # Fake FitGirl site
109.94.209.70      www.fitgirl-repacks.website     # Fake FitGirl site
109.94.209.70      ww9.fitgirl-repacks.xyz         # Fake FitGirl site
109.94.209.70      *.fitgirl-repacks.xyz           # Fake FitGirl site
109.94.209.70      fitgirl-repacks.xyz             # Fake FitGirl site
109.94.209.70      fitgirl-repack.net              # Fake FitGirl site
109.94.209.70      www.fitgirl-repack.net          # Fake FitGirl site
109.94.209.70      fitgirlpack.site                # Fake FitGirl site
109.94.209.70      www.fitgirlpack.site            # Fake FitGirl site
109.94.209.70      fitgirl-repack.org              # Fake FitGirl site
 
2022-06-14 16:47 - 2022-06-14 16:49 - 000000445 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Oculus\Support\oculus-runtime;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\AOMEI\AOMEI Backupper\6.9.1;C:\Program Files\dotnet\
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\Control Panel\Desktop\\Wallpaper -> 
HKU\S-1-5-21-2005890046-4045795175-162804841-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: )
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
MSCONFIG\Services: AdobeUpdateService => 2
MSCONFIG\Services: AGMService => 2
MSCONFIG\Services: AGSService => 2
MSCONFIG\Services: AMD Crash Defender Service => 2
MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: ArmouryCrateService => 2
MSCONFIG\Services: asComSvc => 2
MSCONFIG\Services: asus => 2
MSCONFIG\Services: AsusCertService => 2
MSCONFIG\Services: AsusFanControlService => 2
MSCONFIG\Services: asusm => 3
MSCONFIG\Services: AsusUpdateCheck => 2
MSCONFIG\Services: AUEPLauncher => 2
MSCONFIG\Services: Backupper Service => 2
MSCONFIG\Services: BEService => 3
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: chromoting => 2
MSCONFIG\Services: EABackgroundService => 3
MSCONFIG\Services: EasyAntiCheat => 3
MSCONFIG\Services: EasyAntiCheat_EOS => 3
MSCONFIG\Services: EpicOnlineServices => 3
MSCONFIG\Services: EQU8_19 => 3
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: Intel® Capability Licensing Service TCP IP Interface => 3
MSCONFIG\Services: Intel® TPM Provisioning Service => 2
MSCONFIG\Services: jhi_service => 2
MSCONFIG\Services: LightingService => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MullvadVPN => 2
MSCONFIG\Services: Origin Client Service => 3
MSCONFIG\Services: Origin Web Helper Service => 2
MSCONFIG\Services: OverwolfUpdater => 3
MSCONFIG\Services: OVRLibraryService => 3
MSCONFIG\Services: OVRService => 2
MSCONFIG\Services: PaceLicenseDServices => 2
MSCONFIG\Services: ROG Live Service => 2
MSCONFIG\Services: RstMwService => 2
MSCONFIG\Services: RtkAudioUniversalService => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: SteelSeriesUpdateService => 3
MSCONFIG\Services: Surfshark Service => 2
MSCONFIG\Services: SyncoveryVSSService => 2
MSCONFIG\Services: ucldr_battlegrounds_gl => 3
MSCONFIG\Services: WMIRegistrationService => 2
MSCONFIG\Services: XTU3SERVICE => 2
MSCONFIG\Services: zksvc => 3
HKLM\...\StartupApproved\StartupFolder: => "ROCCAT Swarm Monitor.lnk"
HKLM\...\StartupApproved\StartupFolder: => "Roccat Talk.lnk"
HKLM\...\StartupApproved\Run: => "Riot Vanguard"
HKLM\...\StartupApproved\Run: => "SteelSeriesGG"
HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "ExpressVPNNotificationService"
HKLM\...\StartupApproved\Run32: => "Adobe CCXProcess"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\StartupFolder: => "Roland Cloud Manager.lnk"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Tone"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "qBittorrent"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Battle.net"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Grammarly"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Opera GX Browser Assistant"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Opera GX Stable"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Overwolf"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "GoogleDriveFS"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Voicemod"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "Speech Recognition"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "ExpressVPN"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_7463FF2906FF297BC5194F0B09A1BF9F"
HKU\S-1-5-21-2005890046-4045795175-162804841-1001\...\StartupApproved\Run: => "RiotClient"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{82D1F85D-7583-4535-AEC9-DBEC81213686}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper\6.9.1\ABService.exe (AOMEI International Network Limited -> AOMEI International Network Limited)
FirewallRules: [{6C5E0ED0-2C5B-4E8D-BA14-4F01F66A4C51}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper\6.9.1\ABService.exe (AOMEI International Network Limited -> AOMEI International Network Limited)
FirewallRules: [{357D6A66-DCDE-4B1D-AA3D-222F1256ADD0}] => (Allow) C:\Program Files\Oculus\Support\oculus-dash\dash\bin\OculusDash.exe => No File
FirewallRules: [{8C4D8691-53D7-4080-A3F8-19F5D1467BFD}] => (Allow) C:\Program Files\Oculus\Support\oculus-dash\dash\bin\OculusDash.exe => No File
FirewallRules: [{8472DBEF-C9AC-4067-A848-3707201E3E89}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2.exe => No File
FirewallRules: [{0B8567C2-57CD-4A21-98F8-060A90767F6C}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2.exe => No File
FirewallRules: [{CE6C5C59-419E-45CC-994D-3E5679310199}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2\Binaries\Win64\Home2-Win64-Shipping.exe => No File
FirewallRules: [{D65E9CD8-B24B-4BDB-8A8B-2A6560956BE9}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2\Binaries\Win64\Home2-Win64-Shipping.exe => No File
FirewallRules: [{D1B93BC3-8198-44AC-A03D-BE7E70FE2BD1}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Engine\Binaries\Win64\UnrealCEFSubProcess.exe => No File
FirewallRules: [{F4A7AA15-CCB8-4983-AE00-5782600D9FD7}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Engine\Binaries\Win64\UnrealCEFSubProcess.exe => No File
FirewallRules: [TCP Query User{0621E26A-134D-49CA-AFBF-EDC61EB525AA}C:\program files\oculus\support\oculus-runtime\ovrserver_x64.exe] => (Block) C:\program files\oculus\support\oculus-runtime\ovrserver_x64.exe => No File
FirewallRules: [UDP Query User{D7592EC7-8B83-4039-B20C-DE2831BE609A}C:\program files\oculus\support\oculus-runtime\ovrserver_x64.exe] => (Block) C:\program files\oculus\support\oculus-runtime\ovrserver_x64.exe => No File
FirewallRules: [TCP Query User{B1EEF392-AA7D-48D7-A920-A033303E8B88}X:\overwatch\_retail_\overwatch.exe] => (Allow) X:\overwatch\_retail_\overwatch.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [UDP Query User{581F5B6B-8DAC-47EF-9CCC-CFF1984C2079}X:\overwatch\_retail_\overwatch.exe] => (Allow) X:\overwatch\_retail_\overwatch.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [TCP Query User{4614E130-14FF-49E1-BD4C-E89534327891}C:\users\kelle\appdata\local\programs\opera gx\opera.exe] => (Block) C:\users\kelle\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [UDP Query User{5CC7EF4D-05D0-4676-9074-B3509372F437}C:\users\kelle\appdata\local\programs\opera gx\opera.exe] => (Block) C:\users\kelle\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [TCP Query User{EEC1D345-2163-4A32-B0F0-1843559E5974}C:\users\kelle\appdata\local\programs\opera gx\opera.exe] => (Block) C:\users\kelle\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [UDP Query User{DF7CA193-002E-469C-8881-9F199A5994C2}C:\users\kelle\appdata\local\programs\opera gx\opera.exe] => (Block) C:\users\kelle\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [TCP Query User{F34B7E29-1266-412B-A577-1A90E14EBEB2}X:\overwatch\_beta_\overwatch.exe] => (Allow) X:\overwatch\_beta_\overwatch.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [UDP Query User{B7112E50-E06F-4E1D-9DF8-1D7E7B031F3F}X:\overwatch\_beta_\overwatch.exe] => (Allow) X:\overwatch\_beta_\overwatch.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [TCP Query User{4B1828BF-B3DD-408B-807B-DBE3A45A8902}C:\program files\dis\qbittorrent\qbittorrent.exe] => (Allow) C:\program files\dis\qbittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [UDP Query User{41D8623C-36F3-4BF1-A6C4-B5F1FEBDB803}C:\program files\dis\qbittorrent\qbittorrent.exe] => (Allow) C:\program files\dis\qbittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{CC6E3649-C32D-4BE5-83B8-AF432F894A79}] => (Block) C:\program files\dis\qbittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{1B526E8B-0863-48B7-9D98-371604B3F46D}] => (Block) C:\program files\dis\qbittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [TCP Query User{7464FD00-A41B-4863-8223-EA08438C3E67}C:\program files\oculus\support\oculus-runtime\ovrserver_x64.exe] => (Allow) C:\program files\oculus\support\oculus-runtime\ovrserver_x64.exe => No File
FirewallRules: [UDP Query User{06E07E77-C84B-4362-BD37-82C14151BBDF}C:\program files\oculus\support\oculus-runtime\ovrserver_x64.exe] => (Allow) C:\program files\oculus\support\oculus-runtime\ovrserver_x64.exe => No File
FirewallRules: [{8D4DA33B-025E-476E-A1F3-528EC255E194}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{4B884888-AE9A-4DD5-A12B-47EBCE5F6CA5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{142FB36E-3329-4767-955F-C70F486724EC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A5705388-EE07-4F5B-ABC4-2CFA18CB4963}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F9CEAE67-03D4-4F05-957A-C9F5EAAF04F8}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Windows Migration Assistant\MigrationAssistant.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{43718ECF-1E9D-49B9-98FF-A2D42F531D6B}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Windows Migration Assistant\MigrationAssistant.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [TCP Query User{ACC437A6-95A9-403D-8615-8B06E7B423CC}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [UDP Query User{A8B22561-BDDA-45A7-907E-69666F697362}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{A86B0D8A-B01C-4516-81F8-DBA0040EACF9}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{ECE1E75B-BE71-4ECE-9559-8812FA3BFF97}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{6AC52C6B-4731-4151-8BCF-9A5DE09B07F8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\bin\win32\vrstartup.exe => No File
FirewallRules: [{CEFB717F-AEFA-472E-AE32-6185A3FF03A8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\bin\win32\vrstartup.exe => No File
FirewallRules: [{37EA92E1-C564-4A3D-A41D-E2DE48264C4B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\launcher.exe => No File
FirewallRules: [{0DDBAB64-C879-43FA-8EDE-E36E1A8E4AC0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\launcher.exe => No File
FirewallRules: [TCP Query User{561F5DB9-F6BE-47E4-8C61-46E637EE8A7E}X:\steamlibrary\steamapps\common\naraka bladepoint\narakabladepoint.exe] => (Allow) X:\steamlibrary\steamapps\common\naraka bladepoint\narakabladepoint.exe => No File
FirewallRules: [UDP Query User{29E00DF7-07D7-4956-9D38-1920609BD292}X:\steamlibrary\steamapps\common\naraka bladepoint\narakabladepoint.exe] => (Allow) X:\steamlibrary\steamapps\common\naraka bladepoint\narakabladepoint.exe => No File
FirewallRules: [TCP Query User{B5A70CBA-9EC9-464D-87A0-B31626EEE30D}X:\steamlibrary\steamapps\common\crsed\win64\cuisine_royale.exe] => (Allow) X:\steamlibrary\steamapps\common\crsed\win64\cuisine_royale.exe => No File
FirewallRules: [UDP Query User{61AF9642-E789-46F6-BFD5-819437AE6A33}X:\steamlibrary\steamapps\common\crsed\win64\cuisine_royale.exe] => (Allow) X:\steamlibrary\steamapps\common\crsed\win64\cuisine_royale.exe => No File
FirewallRules: [TCP Query User{A8FC6471-B4FE-49D1-885E-F9FBD3B855A6}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{37D734AD-E490-4E73-A9BE-E5867F236BF3}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{7F86466E-F7B1-430A-A584-E1AF633D66C2}X:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe] => (Allow) X:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe => No File
FirewallRules: [UDP Query User{38D6524F-F1E3-415D-A76D-29C420CF808B}X:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe] => (Allow) X:\steamlibrary\steamapps\common\smite\binaries\win64\smite.exe => No File
FirewallRules: [TCP Query User{597970E8-60DE-4CCF-8630-96E675B63BDC}X:\steamlibrary\steamapps\common\new world\bin64\newworld.exe] => (Allow) X:\steamlibrary\steamapps\common\new world\bin64\newworld.exe => No File
FirewallRules: [UDP Query User{67DFB0C7-EC9F-4F91-936E-BC90121E0B39}X:\steamlibrary\steamapps\common\new world\bin64\newworld.exe] => (Allow) X:\steamlibrary\steamapps\common\new world\bin64\newworld.exe => No File
FirewallRules: [TCP Query User{5CE0CA08-FC00-4533-BE99-961044A4348D}X:\studio one 5\studio one.exe] => (Allow) X:\studio one 5\studio one.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [UDP Query User{E86649DE-C4FB-4C9E-898F-DBE9C6BCE30F}X:\studio one 5\studio one.exe] => (Allow) X:\studio one 5\studio one.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [TCP Query User{8DB6F70D-74E8-4460-961C-3F6117C15A3D}X:\studio one 5\pluginscanner.exe] => (Allow) X:\studio one 5\pluginscanner.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [UDP Query User{F43D0A2E-769D-4A43-829C-F09695B0A9E3}X:\studio one 5\pluginscanner.exe] => (Allow) X:\studio one 5\pluginscanner.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [{E8F47734-38D5-45A4-B99C-236C247E03D4}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper\6.9.1\ABService.exe (AOMEI International Network Limited -> AOMEI International Network Limited)
FirewallRules: [{56700D0C-48D3-4FDF-AF8F-B2A99E7BF753}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper\6.9.1\ABService.exe (AOMEI International Network Limited -> AOMEI International Network Limited)
FirewallRules: [{D3FD672C-9CE8-4729-A194-857BDBC220EF}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
FirewallRules: [{3A14EEB1-0E6F-4171-827B-187119426A3F}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmouryHtmlDebugServer.exe (ASUSTeK COMPUTER INC. -> ASUS)
FirewallRules: [{07DC82B1-868C-49D2-A5BD-0A4943680E47}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe (ASUSTeK COMPUTER INC. -> ASUS)
FirewallRules: [TCP Query User{201D5EA6-1146-4486-B4FF-A3C5DA59E5A5}C:\program files\qbittorrent\qbittorrent.exe] => (Block) C:\program files\qbittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [UDP Query User{5065EDAD-18F5-4528-A27F-B2F699529519}C:\program files\qbittorrent\qbittorrent.exe] => (Block) C:\program files\qbittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{81A5B2CF-3A46-4ED4-A98B-5AE618FC5AC8}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{6989DA93-2FF3-466E-9C9D-FF6E64735F46}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [TCP Query User{721A6F01-5975-471F-B0C8-8B3AE7A81055}X:\studio one 5\studio one.exe] => (Allow) X:\studio one 5\studio one.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [UDP Query User{146A7454-C3F8-4121-9A44-AA663CC377E9}X:\studio one 5\studio one.exe] => (Allow) X:\studio one 5\studio one.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [{22B3555F-32B3-4463-BB86-677A5E859B52}] => (Allow) X:\SteamLibrary\steamapps\common\Bloons TD Battles 2\btdb2_game.exe (Ninja Kiwi Ltd.) [File not signed]
FirewallRules: [{E41A26B9-1097-4F50-8FAE-2A317655B332}] => (Allow) X:\SteamLibrary\steamapps\common\Bloons TD Battles 2\btdb2_game.exe (Ninja Kiwi Ltd.) [File not signed]
FirewallRules: [{632DE93E-02CE-4B3D-BC46-34FF9F42E2D5}] => (Allow) X:\SteamLibrary\steamapps\common\BloonsTD6\BloonsTD6.exe (Unity Technologies ApS) [File not signed]
FirewallRules: [{99FE621D-E7BC-4D15-BA16-BFC8E4562B9F}] => (Allow) X:\SteamLibrary\steamapps\common\BloonsTD6\BloonsTD6.exe (Unity Technologies ApS) [File not signed]
FirewallRules: [TCP Query User{84ABFDC6-81C5-45A5-A261-2D037DBB907C}X:\call of duty\_retail_\cod.exe] => (Allow) X:\call of duty\_retail_\cod.exe => No File
FirewallRules: [UDP Query User{81DEBB39-7395-48BE-9EAE-8A343E3B638C}X:\call of duty\_retail_\cod.exe] => (Allow) X:\call of duty\_retail_\cod.exe => No File
FirewallRules: [TCP Query User{ACD8CCFE-D029-43C0-BC4D-3882C5DC368F}X:\call of duty\_retail_\sp22\sp22-cod.exe] => (Allow) X:\call of duty\_retail_\sp22\sp22-cod.exe => No File
FirewallRules: [UDP Query User{3E40046F-AE8B-49AF-B281-BB4585DC4EAA}X:\call of duty\_retail_\sp22\sp22-cod.exe] => (Allow) X:\call of duty\_retail_\sp22\sp22-cod.exe => No File
FirewallRules: [{B7F0EF54-03DB-4676-BE73-0BF5DAFCF85C}] => (Allow) C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voicemod Sociedad Limitada -> Voicemod)
FirewallRules: [TCP Query User{124CF568-2BD8-47C1-A2DC-D2E6ECC1B447}X:\studio one 5\pluginscanner.exe] => (Allow) X:\studio one 5\pluginscanner.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [UDP Query User{280E2B79-C845-4B38-ACF0-CFABB033303C}X:\studio one 5\pluginscanner.exe] => (Allow) X:\studio one 5\pluginscanner.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [TCP Query User{57FD3B32-C539-4D3B-829E-8AB74FBC0107}C:\users\kelle\appdata\local\splice\app-4.2.17404\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.17404\splice.exe => No File
FirewallRules: [UDP Query User{F344B05E-E8DC-4DCC-89E6-055E08182199}C:\users\kelle\appdata\local\splice\app-4.2.17404\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.17404\splice.exe => No File
FirewallRules: [TCP Query User{E097DE66-BB86-4196-87BD-CD4482FB0363}C:\users\kelle\appdata\local\splice\app-4.2.27408\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.27408\splice.exe => No File
FirewallRules: [UDP Query User{42F42FAD-F1A7-41E8-A575-799BF6CE9CBF}C:\users\kelle\appdata\local\splice\app-4.2.27408\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.27408\splice.exe => No File
FirewallRules: [{1C58B83E-74EE-4811-BCAB-AEE44A8B48DF}] => (Allow) C:\Users\kelle\AppData\Local\tofMiniLoader\tofMiniLoader.exe (PROXIMA BETA PTE. LIMITED -> )
FirewallRules: [{9D0A3482-2DEA-4502-9E80-18ABFDEADE26}] => (Allow) C:\Users\kelle\AppData\Local\tofMiniLoader\tofMiniLoader.exe (PROXIMA BETA PTE. LIMITED -> )
FirewallRules: [{6C25F4D8-559B-405F-86CC-E610BADEF9ED}] => (Allow) E:\Tower Of Fantasy\Launcher\intl_service\intl_service.exe => No File
FirewallRules: [{DD8BC81A-EE26-4AB7-AF92-F779878AEAE9}] => (Allow) E:\Tower Of Fantasy\Hotta\Binaries\Win64\INTLWebViewHelper.exe => No File
FirewallRules: [TCP Query User{07B6069A-81EE-4FF0-AE74-DDA8D22719CB}X:\paladins\binaries\win64\paladins.exe] => (Allow) X:\paladins\binaries\win64\paladins.exe => No File
FirewallRules: [UDP Query User{F7CB721D-5143-491C-8FA1-988AAC631A24}X:\paladins\binaries\win64\paladins.exe] => (Allow) X:\paladins\binaries\win64\paladins.exe => No File
FirewallRules: [TCP Query User{0E0516A1-1DD1-4BF4-8BB9-1FADE618AC59}X:\paragon\overprime\binaries\win64\paragonclient-win64-shipping.exe] => (Allow) X:\paragon\overprime\binaries\win64\paragonclient-win64-shipping.exe => No File
FirewallRules: [UDP Query User{63B9C7C1-D210-4696-A1CF-DAF4DB6E3609}X:\paragon\overprime\binaries\win64\paragonclient-win64-shipping.exe] => (Allow) X:\paragon\overprime\binaries\win64\paragonclient-win64-shipping.exe => No File
FirewallRules: [TCP Query User{3C6743AC-56E9-45D3-8E87-112EE23C6089}C:\users\kelle\appdata\local\splice\app-4.2.37448\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.37448\splice.exe => No File
FirewallRules: [UDP Query User{0D8C9896-C027-42B0-9C73-9926C93CDC16}C:\users\kelle\appdata\local\splice\app-4.2.37448\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.37448\splice.exe => No File
FirewallRules: [TCP Query User{D5D4B92F-551D-4D8B-9F63-C5D287BFC52E}C:\users\kelle\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Allow) C:\users\kelle\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe
FirewallRules: [UDP Query User{C674A1B4-AFFA-4C2E-9E83-4FC4FA6CDA85}C:\users\kelle\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Allow) C:\users\kelle\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe
FirewallRules: [{B4743A6D-1D7B-4695-8F2D-2405DDAE3582}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{74CA7456-9448-47F9-A2C6-EC581A193C27}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{F5CA8B11-84D0-4AFB-B200-FA930DCCEEA5}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{CEDDB222-2039-4C7D-AB3E-FC57CB22AFEE}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{5007D4B6-B0E8-4D6D-BA7F-CBA1D47641C4}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [TCP Query User{4DAF50D1-8F18-4F0E-93DA-1255068CA51D}C:\users\kelle\appdata\local\splice\app-4.2.47597\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.47597\splice.exe => No File
FirewallRules: [UDP Query User{43EC58CC-0473-4D6B-A017-143DB5E47CA6}C:\users\kelle\appdata\local\splice\app-4.2.47597\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.47597\splice.exe => No File
FirewallRules: [{A0916B56-2CF0-4B3F-8641-ECA841B5AFED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\bin\diagnostics32.exe => No File
FirewallRules: [{2407EE27-EC1F-442A-A693-A765BE4D4270}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\bin\diagnostics32.exe => No File
FirewallRules: [TCP Query User{3AB331A9-9B28-48DE-8A13-6062DD6F6827}C:\program files\plitch\plitch.exe] => (Allow) C:\program files\plitch\plitch.exe => No File
FirewallRules: [UDP Query User{EEBDAC82-ED9F-4766-81B6-E805E81C0BDD}C:\program files\plitch\plitch.exe] => (Allow) C:\program files\plitch\plitch.exe => No File
FirewallRules: [TCP Query User{11D58F0E-A3F8-47C3-BD28-8968F2618B23}X:\steamlibrary\steamapps\common\destiny 2\destiny2.exe] => (Allow) X:\steamlibrary\steamapps\common\destiny 2\destiny2.exe => No File
FirewallRules: [UDP Query User{A51B2950-17C1-432C-8FCF-C04F13DF0881}X:\steamlibrary\steamapps\common\destiny 2\destiny2.exe] => (Allow) X:\steamlibrary\steamapps\common\destiny 2\destiny2.exe => No File
FirewallRules: [TCP Query User{98E2E115-B733-434E-BB0C-942F04C496DB}C:\users\kelle\appdata\local\splice\app-4.2.57696\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.57696\splice.exe => No File
FirewallRules: [UDP Query User{1E935044-4BA8-413E-A9DC-B3BC1856CAEB}C:\users\kelle\appdata\local\splice\app-4.2.57696\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.57696\splice.exe => No File
FirewallRules: [TCP Query User{B425EAD9-C995-4070-B7F9-9A407A359C32}E:\xboxgames\high on life\content\oregon\binaries\wingdk\oregon-wingdk-shipping.exe] => (Allow) E:\xboxgames\high on life\content\oregon\binaries\wingdk\oregon-wingdk-shipping.exe => No File
FirewallRules: [UDP Query User{F984D736-7E66-4049-8DA0-304F441F971B}E:\xboxgames\high on life\content\oregon\binaries\wingdk\oregon-wingdk-shipping.exe] => (Allow) E:\xboxgames\high on life\content\oregon\binaries\wingdk\oregon-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{62FA2B70-D4A3-49AB-B9FC-361FFE79D6CC}E:\xboxgames\atomic heart\content\atomicheart\binaries\wingdk\atomicheart-wingdk-shipping.exe] => (Allow) E:\xboxgames\atomic heart\content\atomicheart\binaries\wingdk\atomicheart-wingdk-shipping.exe => No File
FirewallRules: [UDP Query User{3688486B-5767-44EB-8893-A1E638B3EF79}E:\xboxgames\atomic heart\content\atomicheart\binaries\wingdk\atomicheart-wingdk-shipping.exe] => (Allow) E:\xboxgames\atomic heart\content\atomicheart\binaries\wingdk\atomicheart-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{F7CCC3DB-4B8D-4D72-9C1D-3666498758CE}X:\xboxgames\high on life\content\oregon\binaries\wingdk\oregon-wingdk-shipping.exe] => (Allow) X:\xboxgames\high on life\content\oregon\binaries\wingdk\oregon-wingdk-shipping.exe => No File
FirewallRules: [UDP Query User{6EA82E92-DEC8-4365-9F16-9DD05C2233F0}X:\xboxgames\high on life\content\oregon\binaries\wingdk\oregon-wingdk-shipping.exe] => (Allow) X:\xboxgames\high on life\content\oregon\binaries\wingdk\oregon-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{B781CC15-48F0-40DA-9F8A-DB79EBADA0C6}C:\users\kelle\appdata\local\splice\app-4.2.67720\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.67720\splice.exe => No File
FirewallRules: [UDP Query User{B0BDC5AF-50A4-46D6-A8F0-DCFB55CBA2B9}C:\users\kelle\appdata\local\splice\app-4.2.67720\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.67720\splice.exe => No File
FirewallRules: [TCP Query User{DB19E361-7B6E-42B5-A413-681193A47499}C:\users\kelle\appdata\local\splice\app-4.2.77773\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.77773\splice.exe => No File
FirewallRules: [UDP Query User{F800657C-84D6-4358-9E41-E819FD50DC0C}C:\users\kelle\appdata\local\splice\app-4.2.77773\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.77773\splice.exe => No File
FirewallRules: [{B55DD263-6961-4090-813A-FF8E12E42F7D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3408.0_x64__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{FBCC3BCF-4D2E-4685-8B9B-A51D7ED10580}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3408.0_x64__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{5F493E42-0B75-4D8A-8BE8-687BD1C5073E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3408.0_x64__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{C9C22ADC-4CFD-43A1-AE43-4FB069871770}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3408.0_x64__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{84092A25-E9BD-406D-8751-B6F18B157414}] => (Allow) C:\Program Files\PreSonus\Studio One 5\Studio One.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [{199BD59A-61F7-4F97-9388-C92071A40A03}] => (Allow) C:\Program Files\PreSonus\Studio One 5\PlugInScanner.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [{7A42F9AB-388B-46C5-BFC7-A428171F2E17}] => (Allow) X:\SteamLibrary\steamapps\common\Warframe\Tools\Launcher.exe => No File
FirewallRules: [{78739DC3-0133-423E-A48C-EB02B958037D}] => (Allow) X:\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe => No File
FirewallRules: [{E36E028C-275A-450A-AD0C-43C1DF481EB0}] => (Allow) X:\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe => No File
FirewallRules: [{83B43CE2-AE99-418E-93F8-495016F07D12}] => (Allow) X:\SteamLibrary\steamapps\common\Warframe\Tools\RemoteCrashSender.exe => No File
FirewallRules: [{3A2072D2-1FDF-4F8B-81EE-EFE359E328ED}] => (Allow) X:\SteamLibrary\steamapps\common\Warframe\Tools\Launcher.exe => No File
FirewallRules: [{D3AD22E4-27D0-4B6A-A000-B9F4DF7EA253}] => (Allow) X:\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe => No File
FirewallRules: [{1D3CD7FB-1B29-4937-87B6-59EE5BF93C86}] => (Allow) X:\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe => No File
FirewallRules: [{62CDC692-F0D5-483B-853A-85756F7B0D04}] => (Allow) X:\SteamLibrary\steamapps\common\Warframe\Tools\RemoteCrashSender.exe => No File
FirewallRules: [{B6697DFF-A55C-411A-8FA7-F4FED5D37DE4}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{37B30656-C63B-4EE3-9EEA-00927608F5AB}C:\users\kelle\appdata\local\splice\app-4.2.87912\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.87912\splice.exe => No File
FirewallRules: [UDP Query User{F73F211B-AA8C-4753-AD10-0A191D27754E}C:\users\kelle\appdata\local\splice\app-4.2.87912\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.87912\splice.exe => No File
FirewallRules: [TCP Query User{BA5E68CF-7699-4698-B1DE-BF9C4D1A4033}C:\users\kelle\appdata\local\splice\app-4.2.97993\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.97993\splice.exe => No File
FirewallRules: [UDP Query User{3FD3DED5-CDCE-4026-8F78-82E5F765C6FF}C:\users\kelle\appdata\local\splice\app-4.2.97993\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.97993\splice.exe => No File
FirewallRules: [TCP Query User{620194ED-B1BA-4F51-8466-30120B41165B}C:\users\kelle\appdata\local\splice\app-4.2.97998\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.97998\splice.exe => No File
FirewallRules: [UDP Query User{F0D56300-CCC2-4841-A8C6-4A1E4DA26685}C:\users\kelle\appdata\local\splice\app-4.2.97998\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.2.97998\splice.exe => No File
FirewallRules: [TCP Query User{48D6E39F-282F-436A-ABEE-25C9E271ADEC}C:\users\kelle\appdata\local\splice\app-4.3.18047\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.18047\splice.exe => No File
FirewallRules: [UDP Query User{030C67F4-FF8A-45D2-A48A-98F0FEA5E155}C:\users\kelle\appdata\local\splice\app-4.3.18047\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.18047\splice.exe => No File
FirewallRules: [TCP Query User{D966F240-DAA3-47A1-AB78-338167CAFE95}C:\users\kelle\appdata\local\splice\app-4.3.28125\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.28125\splice.exe => No File
FirewallRules: [UDP Query User{64AAB934-76D9-4721-8FDE-004B85D86C8A}C:\users\kelle\appdata\local\splice\app-4.3.28125\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.28125\splice.exe => No File
FirewallRules: [{BCF9CFDF-4422-4E6F-B386-1ACF9B3E63BD}] => (Allow) X:\Riot Games\VALORANT\live\VALORANT.exe => No File
FirewallRules: [{F960E1F3-85A6-4581-B58D-34B7D8B3C05D}] => (Allow) c:\users\kelle\appdata\local\programs\opera\99.0.4788.88\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [TCP Query User{0F0244CE-E500-458B-882C-D76105E47435}C:\users\kelle\appdata\local\splice\app-4.3.38165\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.38165\splice.exe => No File
FirewallRules: [UDP Query User{830D52AA-E2CF-461F-857F-836C1BC8D378}C:\users\kelle\appdata\local\splice\app-4.3.38165\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.38165\splice.exe => No File
FirewallRules: [TCP Query User{DCB1ACA4-6DF5-45D6-AE6A-8B9920AAF444}C:\users\kelle\appdata\local\discord\app-1.0.9013\discord.exe] => (Allow) C:\users\kelle\appdata\local\discord\app-1.0.9013\discord.exe => No File
FirewallRules: [UDP Query User{051C24C1-5A4D-497B-BD43-D1095D088E6E}C:\users\kelle\appdata\local\discord\app-1.0.9013\discord.exe] => (Allow) C:\users\kelle\appdata\local\discord\app-1.0.9013\discord.exe => No File
FirewallRules: [{D283FB99-F62C-460D-8279-FE55026B096F}] => (Block) C:\users\kelle\appdata\local\discord\app-1.0.9013\discord.exe => No File
FirewallRules: [{D6102F81-0F2F-41FF-8656-5A5BEE24E48D}] => (Block) C:\users\kelle\appdata\local\discord\app-1.0.9013\discord.exe => No File
FirewallRules: [{08A1375E-76AC-422D-9D63-461DA8ED548F}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\116.0.5845.9\remoting_host.exe (Google LLC -> Google LLC)
FirewallRules: [{93C9AA35-DC5F-48D5-87BC-6B46C8138012}] => (Allow) X:\SteamLibrary\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix_BE.exe (BattlEye Innovations e.K. -> BattlEye Innovations)
FirewallRules: [{666D798D-3001-4EA0-AEFF-DB058E25208E}] => (Allow) X:\SteamLibrary\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix_BE.exe (BattlEye Innovations e.K. -> BattlEye Innovations)
FirewallRules: [{393DEFAB-6833-46E9-9C13-59565BDED969}] => (Allow) X:\SteamLibrary\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{6155FDE8-1260-4056-98C9-4430A44AEA27}] => (Allow) X:\SteamLibrary\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{B1C94721-1005-4F47-9978-5027D58891D1}] => (Allow) X:\SteamLibrary\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix_Vulkan.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{5373B5D9-B1B4-4664-B29D-FCA07FD4EA62}] => (Allow) X:\SteamLibrary\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix_Vulkan.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [TCP Query User{8304DD55-474E-41D4-B45C-A209A997A44D}C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0_c7675263_d1637483_s52558_58222837\19448995\rainbowsix.exe] => (Allow) C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0_c7675263_d1637483_s52558_58222837\19448995\rainbowsix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [UDP Query User{26DBBACB-BD44-4307-AFDE-688AC6510F44}C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0_c7675263_d1637483_s52558_58222837\19448995\rainbowsix.exe] => (Allow) C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0_c7675263_d1637483_s52558_58222837\19448995\rainbowsix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [TCP Query User{26A311B3-2DAC-4822-B181-501FB4CDA760}C:\users\kelle\appdata\local\splice\app-4.3.48217\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.48217\splice.exe => No File
FirewallRules: [UDP Query User{87A8BCAD-0C13-419B-BB5B-8C94B9F42BF5}C:\users\kelle\appdata\local\splice\app-4.3.48217\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.48217\splice.exe => No File
FirewallRules: [TCP Query User{FC3223BC-04AB-4D87-A69B-82981E17D2E8}C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0_c7675263_d1637483_s52558_58222837\19448995\rainbowsix.exe] => (Block) C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0_c7675263_d1637483_s52558_58222837\19448995\rainbowsix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [UDP Query User{04049FF8-77BF-43BC-9D62-2A7246B6E82C}C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0_c7675263_d1637483_s52558_58222837\19448995\rainbowsix.exe] => (Block) C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0_c7675263_d1637483_s52558_58222837\19448995\rainbowsix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [TCP Query User{5B721FD8-42F2-4DA6-8A6D-0E7D53CE73F6}C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0.1_c7694411_d1804656_s52750_58816277\1493971732\rainbowsix.exe] => (Allow) C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0.1_c7694411_d1804656_s52750_58816277\1493971732\rainbowsix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [UDP Query User{18B7616F-6844-4A04-8704-71E7B34BCD34}C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0.1_c7694411_d1804656_s52750_58816277\1493971732\rainbowsix.exe] => (Allow) C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0.1_c7694411_d1804656_s52750_58816277\1493971732\rainbowsix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{C67842DB-8CBF-4522-B8D7-DF35F887BE76}] => (Allow) c:\users\kelle\appdata\local\programs\opera\100.0.4815.76\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [TCP Query User{C50D9DAF-5194-4994-B0E0-668D7875624E}X:\diablo iv\diablo iv.exe] => (Allow) X:\diablo iv\diablo iv.exe => No File
FirewallRules: [UDP Query User{073FFB04-1F09-466D-BE8C-70DCD59C8589}X:\diablo iv\diablo iv.exe] => (Allow) X:\diablo iv\diablo iv.exe => No File
FirewallRules: [{67F9B413-9B5B-44F0-8E4D-8BBBC475BA09}] => (Block) X:\diablo iv\diablo iv.exe => No File
FirewallRules: [{03D87F8E-2C10-4AE1-A0CD-924189A851A1}] => (Block) X:\diablo iv\diablo iv.exe => No File
FirewallRules: [{780A69D9-CBCD-460B-A252-F7795649AD5F}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{A1DF53BA-BF78-445A-9938-611D380F4B9C}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{F1533A7A-157C-4AF8-9B34-C931A604F1F2}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{1787E364-3C46-4211-AF27-BCEB372025A1}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{EA3F0C13-D73D-4190-83E0-20025726D69F}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{09295963-76A6-4C80-BCE3-7D872A022744}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe (Electronic Arts, Inc. -> Electronic Arts)
FirewallRules: [{20194318-F8F7-4487-8EF4-A7C60E19A97F}] => (Allow) X:\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [{9E504F1D-362A-4398-AE3D-E3BC7FE1DA84}] => (Allow) X:\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [TCP Query User{2D4F7CB3-155D-418A-9854-8279297C6701}C:\users\kelle\appdata\local\splice\app-4.3.58276\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.58276\splice.exe => No File
FirewallRules: [UDP Query User{AB9F4FBE-A966-4605-A19B-D8A136A323C5}C:\users\kelle\appdata\local\splice\app-4.3.58276\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.58276\splice.exe => No File
FirewallRules: [{540937A7-5243-44EC-9409-F5FC05EF4F5E}] => (Allow) X:\SteamLibrary\steamapps\common\OmegaStrikers\OmegaStrikers.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{3D904EBB-ED4B-46AC-931A-B52EE233B2BA}] => (Allow) X:\SteamLibrary\steamapps\common\OmegaStrikers\OmegaStrikers.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{9A861434-826D-4AA7-B4E8-7673DA18B707}] => (Allow) X:\SteamLibrary\steamapps\common\Trove\GlyphClient.exe (gamigo AG -> gamigo US Inc.)
FirewallRules: [{ADB3706B-BE64-4923-B0E2-73EBBA3E7633}] => (Allow) X:\SteamLibrary\steamapps\common\Trove\GlyphClient.exe (gamigo AG -> gamigo US Inc.)
FirewallRules: [TCP Query User{808A8C1B-AF85-4BEB-934D-3F18BD5526C2}C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0.1_c7718154_d1809049_s52750_59407467\3218226319\rainbowsix.exe] => (Allow) C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0.1_c7718154_d1809049_s52750_59407467\3218226319\rainbowsix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [UDP Query User{5289DE19-28EB-49AB-8672-D19B26C082F7}C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0.1_c7718154_d1809049_s52750_59407467\3218226319\rainbowsix.exe] => (Allow) C:\users\kelle\appdata\local\ubisoft\r6siege\y8s2.3.0.1_c7718154_d1809049_s52750_59407467\3218226319\rainbowsix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [TCP Query User{38E122B3-91FC-4847-971B-73B9348C2BAE}C:\users\kelle\appdata\local\splice\app-4.3.68353\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.68353\splice.exe => No File
FirewallRules: [UDP Query User{067006DD-31F8-41DE-BEA3-01F420720356}C:\users\kelle\appdata\local\splice\app-4.3.68353\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.68353\splice.exe => No File
FirewallRules: [{5C02C6AD-2C54-43C9-8DCF-85357BB8F9DD}] => (Allow) C:\Program Files (x86)\Overwolf\0.228.0.21\OverwolfBrowser.exe => No File
FirewallRules: [{77898025-D591-486E-980C-7CFC42AB64E0}] => (Allow) C:\Program Files (x86)\Overwolf\0.228.0.21\OverwolfBrowser.exe => No File
FirewallRules: [{C67D1783-1139-41FE-B654-A41844E1CE8D}] => (Block) C:\Program Files (x86)\Overwolf\0.228.0.21\OverwolfBrowser.exe => No File
FirewallRules: [{C8DC0ACD-F25A-4D09-B586-62750B957504}] => (Block) C:\Program Files (x86)\Overwolf\0.228.0.21\OverwolfBrowser.exe => No File
FirewallRules: [{6CAF1D58-CDAA-48D6-8437-4F405AAFAD15}] => (Allow) C:\Program Files (x86)\Overwolf\0.230.0.10\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{F1A2DBFF-4994-4C05-84B8-EBDA0806FD1F}] => (Allow) C:\Program Files (x86)\Overwolf\0.230.0.10\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [TCP Query User{F11FB4A8-3537-48B1-8B95-2D0C24415253}X:\xboxgames\the texas chain saw massacre - pc edition\content\bbqgame\binaries\wingdk\bbqclient-wingdk-shipping.exe] => (Allow) X:\xboxgames\the texas chain saw massacre - pc edition\content\bbqgame\binaries\wingdk\bbqclient-wingdk-shipping.exe => No File
FirewallRules: [UDP Query User{32DFF3C9-B6AC-467F-8AD4-3883A0601118}X:\xboxgames\the texas chain saw massacre - pc edition\content\bbqgame\binaries\wingdk\bbqclient-wingdk-shipping.exe] => (Allow) X:\xboxgames\the texas chain saw massacre - pc edition\content\bbqgame\binaries\wingdk\bbqclient-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{1D5D747F-08FB-4246-A8BD-083621886DF4}X:\xboxgames\forza horizon 5\content\forzahorizon5.exe] => (Allow) X:\xboxgames\forza horizon 5\content\forzahorizon5.exe (Access Denied)  [File not signed]
FirewallRules: [UDP Query User{B9D9FAB7-FA15-4F36-9B70-6EFF5AE4DEC6}X:\xboxgames\forza horizon 5\content\forzahorizon5.exe] => (Allow) X:\xboxgames\forza horizon 5\content\forzahorizon5.exe (Access Denied)  [File not signed]
FirewallRules: [TCP Query User{FFF2871C-1A59-4E8A-AEDB-B696F92EC0DA}X:\xboxgames\dead by daylight\content\deadbydaylight\binaries\wingdk\deadbydaylight-wingdk-shipping.exe] => (Allow) X:\xboxgames\dead by daylight\content\deadbydaylight\binaries\wingdk\deadbydaylight-wingdk-shipping.exe => No File
FirewallRules: [UDP Query User{80D51EB4-A7DA-4E07-9B74-8C4C4C285386}X:\xboxgames\dead by daylight\content\deadbydaylight\binaries\wingdk\deadbydaylight-wingdk-shipping.exe] => (Allow) X:\xboxgames\dead by daylight\content\deadbydaylight\binaries\wingdk\deadbydaylight-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{82225EB9-622D-4FE8-93D2-DCACD7746904}X:\fortnite\engine\binaries\win64\epicwebhelper.exe] => (Allow) X:\fortnite\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{357AAA48-43F8-48EC-9676-C8A9D2B87AE7}X:\fortnite\engine\binaries\win64\epicwebhelper.exe] => (Allow) X:\fortnite\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{AF290C00-BFBD-49B1-AB49-0FDEB7B550DD}] => (Allow) X:\SteamLibrary\steamapps\common\Paladins\Binaries\Win64\PaladinsEAC.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [{A1ED8117-22A3-4638-8D5F-4FF441B7637D}] => (Allow) X:\SteamLibrary\steamapps\common\Paladins\Binaries\Win64\PaladinsEAC.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [TCP Query User{89BF1679-D1FB-4EE5-BB1D-E811F798EEAF}X:\steamlibrary\steamapps\common\paladins\binaries\win64\paladins.exe] => (Allow) X:\steamlibrary\steamapps\common\paladins\binaries\win64\paladins.exe (Hirez Studios, Inc.) [File not signed]
FirewallRules: [UDP Query User{4D2E4A91-AEF4-43D7-A867-0A898D9EB0C1}X:\steamlibrary\steamapps\common\paladins\binaries\win64\paladins.exe] => (Allow) X:\steamlibrary\steamapps\common\paladins\binaries\win64\paladins.exe (Hirez Studios, Inc.) [File not signed]
FirewallRules: [{75A7BF8B-98E0-43BC-81F2-3B813C24C8A9}] => (Allow) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{94923F3F-DE18-4D71-AF0E-1BD01C788E16}] => (Allow) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{DEAE5B5B-0329-4D14-9706-580EF8A6F3B6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.102.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{97B70B45-48A8-4DFE-853A-173ED1D06C93}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.102.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C06F937F-2B5B-4143-9CB1-A668293CE2BE}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.102.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2C1294FA-26AD-4293-A7B6-BF0DE50A68B8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.102.3211.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{97509A24-846D-48CD-BE6D-3EA7C0E41A12}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\116.0.1938.62\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{DB397DAD-5FAB-40B8-8686-99121387BD50}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{BCBFA1B1-2B06-4A6B-B9A8-1B22C7B74EFF}C:\users\kelle\appdata\local\splice\app-4.3.78461\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.78461\splice.exe (Splice) [File not signed]
FirewallRules: [UDP Query User{C40B9C55-E8FC-4EA3-BFAE-08C035944E6D}C:\users\kelle\appdata\local\splice\app-4.3.78461\splice.exe] => (Allow) C:\users\kelle\appdata\local\splice\app-4.3.78461\splice.exe (Splice) [File not signed]
FirewallRules: [TCP Query User{B331427E-273F-407D-9DBC-FF22249A6ED8}C:\users\kelle\appdata\local\ubisoft\r6siege\y8s3.0.0_c7762708_d1817452_s53484_60683101\1359034912\rainbowsix.exe] => (Allow) C:\users\kelle\appdata\local\ubisoft\r6siege\y8s3.0.0_c7762708_d1817452_s53484_60683101\1359034912\rainbowsix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [UDP Query User{776CE8BA-EC14-4081-94E4-485247EFCDEA}C:\users\kelle\appdata\local\ubisoft\r6siege\y8s3.0.0_c7762708_d1817452_s53484_60683101\1359034912\rainbowsix.exe] => (Allow) C:\users\kelle\appdata\local\ubisoft\r6siege\y8s3.0.0_c7762708_d1817452_s53484_60683101\1359034912\rainbowsix.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{E9A5D2F8-04B2-4D4A-8A0C-E441ABAC254B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{3C349C6E-8754-459A-92FB-4B70E0446B2E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{0573B985-59A0-4FF6-A091-768BC3137105}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{9A1A3BC2-E889-46B2-9005-ADEE260FC343}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{18D98902-E0E5-4268-814E-9D8650D14A78}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{CA6236C9-129D-4FF8-A44E-069DC1C2EC02}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{20ED2B91-0001-4D61-8CF6-3AC9BD66A5A9}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{804C4109-0020-48BD-925A-BF6F7F50B557}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{BB6BAA37-4513-4A8E-B80C-AEEA3D63487F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{51844D42-48F4-4F2F-9D2E-2E051096E736}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{43063FFD-D219-406C-93E2-B7432E9B5B92}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\116.0.1938.69\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F1D606EE-4CD1-4F47-8497-6DD3028E2D09}] => (Allow) X:\SteamLibrary\steamapps\common\Farlight 84\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.)
FirewallRules: [{3D9054B4-1B0B-4B45-B17B-897335D837EF}] => (Allow) X:\SteamLibrary\steamapps\common\Farlight 84\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.)
FirewallRules: [TCP Query User{364225FF-9A80-4544-AE67-6DAD9B6C4964}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [UDP Query User{940E1A28-1CD0-463B-97B7-4977081A637D}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [TCP Query User{5DF45A37-5830-4561-9B20-1A87165354D2}E:\xboxgames\deep rock galactic\content\fsd\binaries\wingdk\fsd-wingdk-shipping.exe] => (Allow) E:\xboxgames\deep rock galactic\content\fsd\binaries\wingdk\fsd-wingdk-shipping.exe (Access Denied)  [File not signed]
FirewallRules: [UDP Query User{30517B44-D1DA-4CDA-98D0-F68E5A6757FA}E:\xboxgames\deep rock galactic\content\fsd\binaries\wingdk\fsd-wingdk-shipping.exe] => (Allow) E:\xboxgames\deep rock galactic\content\fsd\binaries\wingdk\fsd-wingdk-shipping.exe (Access Denied)  [File not signed]
 
==================== Restore Points =========================
 
01-09-2023 18:38:10 Windows Modules Installer
 
==================== Faulty Device Manager Devices ============
 
Name: Network Controller
Description: Network Controller
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Generic Bluetooth Adapter
Description: Generic Bluetooth Adapter
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: GenericAdapter
Service: BTHUSB
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. 
 
Name: eLicenser
Description: eLicenser
Class Guid: {5c69eefe-3c1e-44ef-8501-f475f902fca7}
Manufacturer: Steinberg Media Technologies GmbH
Service: synusb64
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (09/03/2023 06:34:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Radeonsoftware.exe, version: 10.1.2.1963, time stamp: 0x6446a9e2
Faulting module name: Qt5WebEngineCore.dll, version: 5.15.10.0, time stamp: 0x62aa010c
Exception code: 0x80000003
Fault offset: 0x0000000001d6e51d
Faulting process id: 0x3280
Faulting application start time: 0x01d9deb8014c3489
Faulting application path: C:\Program Files\AMD\CNext\CNext\Radeonsoftware.exe
Faulting module path: C:\Program Files\AMD\CNext\CNext\Qt5WebEngineCore.dll
Report Id: 1eb25ed7-bc55-4e0c-a04b-296234a9d8f4
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (09/03/2023 05:43:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EAConnect_microsoft.exe, version: 13.4.0.5517, time stamp: 0x64d69a74
Faulting module name: EAConnect_microsoft.exe, version: 13.4.0.5517, time stamp: 0x64d69a74
Exception code: 0xc0000005
Fault offset: 0x00000000002dcd5c
Faulting process id: 0x32dc
Faulting application start time: 0x01d9deb80beef520
Faulting application path: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe
Faulting module path: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe
Report Id: 8305fed9-6cf1-4975-91e8-58da79f107ee
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (09/03/2023 05:40:47 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-HSAVGOG$ via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep failed:
 
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Sun, 03 Sep 2023 22:40:47 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: cb16f533-f9e9-4a56-b153-d2db5b618028
 
Method: GET(453ms)
Stage: GetCACaps
Not found (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
 
Error: (09/03/2023 05:39:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EAConnect_microsoft.exe, version: 13.4.0.5517, time stamp: 0x64d69a74
Faulting module name: EAConnect_microsoft.exe, version: 13.4.0.5517, time stamp: 0x64d69a74
Exception code: 0xc0000005
Fault offset: 0x00000000002dcd5c
Faulting process id: 0x2ef8
Faulting application start time: 0x01d9deb76ecbf122
Faulting application path: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe
Faulting module path: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe
Report Id: 9bca3150-f1f6-4f7f-9c4d-f24a9f6f6291
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (09/03/2023 05:35:35 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-HSAVGOG$ via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep failed:
 
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Sun, 03 Sep 2023 22:35:34 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 4536ab18-5f10-4c0c-a079-a228338a25a8
 
Method: GET(578ms)
Stage: GetCACaps
Not found (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
 
Error: (09/03/2023 05:30:00 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-HSAVGOG$ via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep failed:
 
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Sun, 03 Sep 2023 22:29:59 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 5e70e5c9-3d03-4cae-9022-a2f9c0bb0cbd
 
Method: GET(329ms)
Stage: GetCACaps
Not found (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
 
Error: (09/03/2023 05:19:26 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW.  hr = 0x80070006, The handle is invalid.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (09/03/2023 05:13:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EAConnect_microsoft.exe, version: 13.4.0.5517, time stamp: 0x64d69a74
Faulting module name: EAConnect_microsoft.exe, version: 13.4.0.5517, time stamp: 0x64d69a74
Exception code: 0xc0000005
Fault offset: 0x00000000002dcd5c
Faulting process id: 0x27c8
Faulting application start time: 0x01d9deb3de042b32
Faulting application path: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe
Faulting module path: C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe
Report Id: 854ae63c-eed6-4364-89bb-39bf666bb9a4
Faulting package full name: 
Faulting package-relative application ID:
 
 
System errors:
=============
Error: (09/03/2023 07:45:46 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.397.288.0).
 
Error: (09/03/2023 07:45:46 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.397.288.0).
 
Error: (09/03/2023 07:45:45 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.397.288.0).
 
Error: (09/03/2023 07:45:44 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.397.288.0).
 
Error: (09/03/2023 07:45:43 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.397.288.0).
 
Error: (09/03/2023 07:45:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246007: Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.397.288.0).
 
Error: (09/03/2023 05:45:48 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Microsoft Defender Antivirus Service service terminated with the following error: 
General access denied error
 
Error: (09/03/2023 05:45:47 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Microsoft Defender Antivirus Service service terminated with the following error: 
General access denied error
 
 
Windows Defender:
================
Date: 2023-09-01 18:08:20
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-09-01 17:57:13
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-09-01 07:58:34
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-08-30 18:55:28
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-08-30 17:33:28
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]:
 
Date: 2023-08-31 23:46:58
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Current
Error Code: 0x80070003
Error description: The system cannot find the path specified. 
Security intelligence Version: 0.0.0.0;0.0.0.0
Engine Version: 0.0.0.0
 
Date: 2023-08-31 23:46:58
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 
Update Source: Security intelligence Update Folder
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 
Previous Engine Version: 
Error code: 0x80070002
Error description: The system cannot find the file specified. 
 
Date: 2023-08-31 23:46:58
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 
Update Source: Security intelligence Update Folder
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 
Previous Engine Version: 
Error code: 0x80070002
Error description: The system cannot find the file specified. 
 
Date: 2023-08-24 00:19:42
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Current
Error Code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. 
Security intelligence Version: 1.395.1148.0;1.395.1148.0
Engine Version: 1.1.23070.1005
 
Date: 2023-08-15 00:25:00
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.395.420.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.23070.1005
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
CodeIntegrity:
===============
Date: 2023-09-03 20:01:27
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements.
 
Date: 2023-09-03 19:58:25
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. 2803 04/28/2022
Motherboard: ASUSTeK COMPUTER INC. ROG STRIX B550-F GAMING WIFI II
Processor: AMD Ryzen 7 5700G with Radeon Graphics 
Percentage of memory in use: 32%
Total physical RAM: 32559.55 MB
Available physical RAM: 22127.91 MB
Total Virtual: 41263.55 MB
Available Virtual: 26269.34 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:446.14 GB) (Free:18.82 GB) (Model: SATA SSD) NTFS
Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.05 GB) (Model: WDC WD10EARS-00MVWB0) NTFS ==>[system with boot components (obtained from drive)]
Drive e: () (Fixed) (Total:930.55 GB) (Free:415.58 GB) (Model: WDC WD10EARS-00MVWB0) NTFS
Drive x: (SSD M.2 1TB) (Fixed) (Total:931.5 GB) (Free:221.61 GB) NTFS
 
\\?\Volume{9e00943f-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.49 GB) (Free:0.46 GB) NTFS
\\?\Volume{a003f914-0000-0000-0000-60a9e8000000}\ () (Fixed) (Total:0.87 GB) (Free:0.34 GB) NTFS
\\?\Volume{9e00943f-0000-0000-0000-70a86f000000}\ () (Fixed) (Total:0.5 GB) (Free:0.04 GB) NTFS
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: A003F914)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=930.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=886 MB) - (Type=27)
 
==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 447.1 GB) (Disk ID: 9E00943F)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=446.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=509 MB) - (Type=27)
 
==========================================================
Disk: 2 (Size: 931.5 GB) (Disk ID: 0D213521)
 
Partition: GPT.
 
==================== End of Addition.txt =======================


#4 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:23 PM

Posted 04 September 2023 - 12:27 PM

Please do this.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
CreateRestorePoint:
CloseProcesses:
cmd: sfc /scannow
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Windows Update Troubleshooter - Windows 10

--------------------
  • Click Start, type Troubleshooter and hit Enter
  • Click Additional (or Other) troubleshooters
  • Select Windows Update
  • Report the results
  • Check Windows Update. If you receive an error message report the error information in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Fixlog
  • Windows Update status

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#5 kdubb666

kdubb666
  • Topic Starter

  •  Avatar image
  • Members
  • 51 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 04 September 2023 - 02:11 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 28-08-2023
Ran by kelle (04-09-2023 13:54:57) Run:1
Running from C:\Users\kelle\Downloads
Loaded Profiles: kelle
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
CreateRestorePoint:
CloseProcesses:
cmd: sfc /scannow
End::
*****************
 
Restore point was successfully created.
Processes closed successfully.
 
========= sfc /scannow =========
 
 
 
Windows Resource Protection could not start the repair service.
 
 
 
========= End of CMD: =========
 
 
 
The system needed a reboot.
 
==== End of Fixlog 13:55:14 ====
 
Windows Update
Publisher details
Issues found
Check for Windows Update issues
Detects issues related to Windows Update.
Detected
Resolve Windows Update issues
Completed
Potential issues that were checked
Some security settings are missing or have been changed
Issue not present
 
Check for missing or corrupt files
Issue not present
 
Service registration is missing or corrupt
Issue not present
 
Issues found
Detection details
6
Check for Windows Update issues
Detected
Detects issues related to Windows Update.
Resolve Windows Update issues
Completed
Resolves common Windows Update issues.
WaaSMedicService
Issues remediated by :AutomaticCorruptionRepairPlugin;ResetRepairPlugin
Potential issues that were checked
Detection details
  Some security settings are missing or have been changed
Issue not present
 
 
  Check for missing or corrupt files
Issue not present
 
 
  Service registration is missing or corrupt
Issue not present
 
 
Detection details
IsPostback_RC_PendingUpdates
IsPostback: False
WaaSMedicService
Issue found by :AutomaticCorruptionRepairPlugin;ResetRepairPlugin
IsPostback_RC_PendingUpdates
IsPostback: True
Service Status
Problem with BITS service : The requested service has already been started. System.Management.Automation.RemoteException More help is available by typing NET HELPMSG 2182. System.Management.Automation.RemoteException
Service Status
Problem with BITS service : The requested service has already been started. System.Management.Automation.RemoteException More help is available by typing NET HELPMSG 2182. System.Management.Automation.RemoteException Collection information Computer Name: DESKTOP-HSAVGOG Windows Version:
10.0
Architecture:
x64
Time:
Monday, September 4, 2023 2:06:05 PM
Publisher details
Background Intelligent Transfer Service Find and fix problems that may prevent background downloads from working Package Version:
3.5
Publisher:
Microsoft Windows
Windows Network Diagnostics Detects problems with network connectivity. Package Version:
4.0
Publisher:
Microsoft Windows
Windows Update Resolve problems that prevent you from updating Windows. Package Version:
9.3
Publisher:
Microsoft Windows
Windows Update Resolve problems that prevent you from updating Windows. Package Version:
9.2
Publisher:
Microsoft Corporation


#6 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:23 PM

Posted 04 September 2023 - 03:37 PM

Greetings.

Did you attempt Windows Update?

Please do this. Be patient since the process may take awhile.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
CloseProcesses:
cmd: sc config trustedinstaller start= auto
cmd: net start trustedinstaller
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /CheckHealth
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Fixlog

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#7 kdubb666

kdubb666
  • Topic Starter

  •  Avatar image
  • Members
  • 51 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 05 September 2023 - 11:38 AM

I did try the windows troubleshooter. It said troubleshooting could not identify the problem 



#8 kdubb666

kdubb666
  • Topic Starter

  •  Avatar image
  • Members
  • 51 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 05 September 2023 - 11:48 AM

Fix result of Farbar Recovery Scan Tool (x64) Version: 28-08-2023
Ran by kelle (05-09-2023 11:38:50) Run:2
Running from C:\Users\kelle\Downloads
Loaded Profiles: kelle
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
CloseProcesses:
cmd: sc config trustedinstaller start= auto
cmd: net start trustedinstaller
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /CheckHealth
End::
*****************
 
Processes closed successfully.
 
========= sc config trustedinstaller start= auto =========
 
[SC] ChangeServiceConfig SUCCESS
 
 
========= End of CMD: =========
 
 
========= net start trustedinstaller =========
 
The Windows Modules Installer service is starting.
The Windows Modules Installer service was started successfully.
 
 
 
========= End of CMD: =========
 
 
========= sfc /scannow =========
 
 
 
Windows Resource Protection could not start the repair service.
 
 
 
========= End of CMD: =========
 
 
========= DISM /Online /Cleanup-Image /CheckHealth =========
 
 
Deployment Image Servicing and Management tool
Version: 10.0.19041.844
 
Image Version: 10.0.19045.3393
 
The component store cannot be repaired.
The operation completed successfully.
 
 
========= End of CMD: =========
 
 
 
The system needed a reboot.
 
==== End of Fixlog 11:38:55 ====


#9 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:23 PM

Posted 05 September 2023 - 01:20 PM

You may need more specialized help but let's see what we can do.

Please do this.

===================================================

ComponentsScanner by Sysnative

--------------------
  • Right click on ComponentsScanner, select Save Link As... and save it to your Desktop
  • Right click on the file and select Run as administrator
  • Review the terms and if you agree press any key to continue
  • Once completed review the request to upload anonymous information to Sysnative for research and development and either press Y or N
  • Press any key to continue
  • A ComponentsScanner.txt will be placed on the Desktop
  • Copy and paste the contents of the report in your reply
===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST will do it for you
Start::
Zip: C:\Windows\Logs\CBS
End::
  • Click Fix
  • When completed he tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • The tool will create a zipped folder in the same location from where FRST was run with today's date, example: 06.11.2016_13.24.50.zip. Upload the file to GoFile or the file hosting site of your choice and post the download link in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • ComponentsScanner.txt
  • Download link

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#10 kdubb666

kdubb666
  • Topic Starter

  •  Avatar image
  • Members
  • 51 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 05 September 2023 - 01:58 PM

ComponentsScanner Version 1.5.1.0 by sysnative.com
Windows Version: Windows 10 22H2 x64 (10.0.19045.3393)
Start time: 2023-09-05T13:57:27
Hive scanned: %windir%\System32\config\COMPONENTS
Number of keys: 112105
Number of values: 296157
 
==== Critical Errors ====
None
 
==== Corrupt Key Names ====
None
 
==== Corrupt Value Names ====
None
 
==== Corrupt Value Data Type ====
None
 
==== Corrupt Value Data ====
None
 
==== Repair Log ====
No possible repairs
 
==== Warnings ====
None
 
 
Storing 0KB in C:\Users\kelle\AppData\Local\Sysnative\ComponentsScanner
 
Finish Time: 2023-09-05T13:57:57. Corruption scan time: 12.0504976s
===========================EOF===========================


#11 kdubb666

kdubb666
  • Topic Starter

  •  Avatar image
  • Members
  • 51 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 05 September 2023 - 01:59 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 28-08-2023
Ran by kelle (05-09-2023 13:59:14) Run:3
Running from C:\Users\kelle\Downloads
Loaded Profiles: kelle
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
Zip: C:\Windows\Logs\CBS
End::
*****************
 
================== Zip: ===================
C:\Windows\Logs\CBS -> copied successfully to C:\Users\kelle\OneDrive\Desktop\05.09.2023_13.59.14.zip
=========== Zip: End ===========
 
==== End of Fixlog 13:59:15 ====


#12 kdubb666

kdubb666
  • Topic Starter

  •  Avatar image
  • Members
  • 51 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 05 September 2023 - 02:13 PM

https://gofile.io/d/7Nsf2Z



#13 kdubb666

kdubb666
  • Topic Starter

  •  Avatar image
  • Members
  • 51 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 05 September 2023 - 02:17 PM

maybe that is not the correct info I uploaded to gofile...sorry

 

https://gofile.io/d/AErPkG



#14 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:23 PM

Posted 05 September 2023 - 02:32 PM

Thank you for the report. There is a lot of information to review so please allow me a bit of time to work through the reports.

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#15 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:23 PM

Posted 05 September 2023 - 05:28 PM

The CBS reports indicate there is a serious corruption within the operating system. The resolution to that is to perform an In-Place Upgrade, also known as a Repair Installation.

Please do this.

===================================================

Windows 10 In-Place Upgrade Using Windows Media Creation Tool

--------------

Note: Though this process should not affect your files I highly recommend backing up your data files (documents, photos, music, etc.) prior to starting the process. This process will take some time to complete.
  • Navigate to Microsoft's Download Windows 10 page
  • Click Update now
  • Click Save File and save it to your Desktop
  • Right click on the Windows10Upgrade icon and select Run as administrator
  • Click Accept on the license terms screen
  • Select Upgrade this PC now and click Next
  • Once the process completes click Accept
  • On the Ready to install screen confirm Install Widows 10 and Keep personal files and apps are checked. If not click Change what to keep and include those 2 <<<Important<<<
  • Click Install
  • Once completed you will be greeted with a Welcome Back message. Close the browser window and you should be back at your Desktop as it was prior to the process
  • Report the results in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Results?

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start





3 user(s) are reading this topic

0 members, 3 guests, 0 anonymous users