Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Explorer high cpu usage, excludeproc.d running encoded powershell commands


  • This topic is locked This topic is locked
17 replies to this topic

#1 tyctxt

tyctxt

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 24 April 2022 - 03:39 AM

Hello, I am looking for the solution to my problem.

Every time i start up the computer, the windows defender notifies me with the messages below:

 

--------------------------------------

Detected: VirTool:Win32/ExcludeProc.D

CmdLine: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4ARQB4AHQAZQBuAHMAaQBvAG4AIABAACgAJwBlAHgAZQAnACwAJwBkAGwAbAAnACkAIAAtAEYAbwByAGMAZQA=

CmdLine: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwAJABlAG4AdgA6AFMAeQBzAHQAZQBtAEQAcgBpAHYAZQApACAALQBGAG8AcgBjAGUA

----------------------------------------

Detected: Behavior:Win32/ExcludeProc.A

behavior: pid:5020:23860413273102

process: pid:5020,ProcessStart:132952570460764972

----------------------------------------

 

They keep showing up every time i start up even if they are blocked by the defender. It seems that the command lines are encoded, so I tried to decode them, and the results are as follows:

"Add-MpPreference -ExclusionExtension @('exe','dll') -Force"

'Add-MpPreference -ExclusionPath @($env:UserProfile,$env:SystemDrive) -Force'

These commands are intended to avoid the defender's scanning. The pid changes but the figures after pid remain the same. 

Also, I have noticed that, the explorer.exe occupies the cpu a lot, causing the fan running noisily even though the computer is idle. As long as I opened the task manager, it is silent again. I did several full scans with different anti-malware applications, but the problem remains.

I've found a topic similar to my problem from the forum, https://www.bleepingcomputer.com/forums/t/771152/virtoolwin32excludeprocd-virusmalware-running-encoded-powershell/.

 

I have attacted the FRST.txt and Additions.txt below.

Thank you for your help!

Attached Files



BC AdBot (Login to Remove)

 


#2 tyctxt

tyctxt
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 24 April 2022 - 03:55 AM

There are two typos in the titile, the title should be "explorer high cpu usage, excludeproc.d running encoded powershell commands". I am not a native English speaker, sorry for my carelessness.

 

EDIT: Fixed typos


Edited by buddy215, 24 April 2022 - 04:06 AM.


#3 tyctxt

tyctxt
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 24 April 2022 - 06:44 AM

I monitored the "explorer.exe" process with remote process explorer (the event hides when i open task manager or something with similar functions), and the suspicious process with the high cpu usage has the command line as below:

-----------------------------------------------------------

"C:\windows\explorer.exe guqtdbluznxqj0 Xji3FXYfqqI2timPThbgZueMNpSES88mLhMz2ywydJTuL0ZzLyO7DchZ2uSJmVLEIu96CtmJ5kjUH/zpjH58umVRHGBMBHp/+1TgXkTnxFN0sh8dFwaGd75J0t7e4z2mnsLUJmq7m769OqP4MkBOrXyOOCbz/h4LY5yVpmRR4k/Dz+nAekSiCGAd+ro8hJbQlzCVYboZWje/0Ds3TWVvQjEPvp2tuJM/0QMtX6JcQleHqtiN1CuZZLO635NaSs+95JWNoUjWZimixDRfzzQCRZeX99bMii5A77f9DPY7iEJiCdAoOH5e2ezWZTQ7WdkCnlhHTNp1Kp4kba1keQBbhTW7ty8s9VZPllQGxt7/21MqWDvLaWf4t5W6EgG2FJdEHGhAhm0LqLJiliXt7BMzvK962PVPM7IRle5B6CXpsDk="

 

I wonder whether the arguments are encrypted. If they are, in what form?



#4 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 50,567 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:13 PM

Posted 24 April 2022 - 07:35 AM

Greetings tyctxt and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:

  • First, please keep in mind most of us at BleepingComputer volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.
  • It is important to not run any tools or take any steps other than those I will provide for you.
  • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
  • Please copy and paste all logs into your post unless otherwise requested.
  • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
  • If you do not reply to your topic after 5 days I will assume it has been abandoned and I will close it.

===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

Please rename FRST64 to FRST64english and run another scan. Copy and paste each report in your reply.


Edited by Oh My!, 24 April 2022 - 07:37 AM.

Gary 

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God." Where to Start

#5 tyctxt

tyctxt
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 24 April 2022 - 08:09 AM

Thank you for your reply. You can call me Eric.

I renamed it and the FRST report is in English now, but several parts of the Additions.txt are still in Chinese.

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-04-2022
Ran by YuchenTong (administrator) on TRUTHTYC (HP OMEN by HP Laptop 16-b1xxx) (24-04-2022 21:03:45)
Running from C:\Users\YuchenTong\Downloads
Loaded Profiles: YuchenTong
Platform: Microsoft Windows 11 家庭中文版 Version 21H2 22000.613 (X64) Language: 中文(简体,中国)
Default browser: Edge
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_421.20070.95.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\100.0.1185.44\msedgewebview2.exe <6>
(C:\Users\YuchenTong\Documents\Clash.for.Windows-0.12.1\Clash for Windows.exe ->) () [File not signed] C:\Users\YuchenTong\Documents\Clash.for.Windows-0.12.1\resources\static\files\clash-win64.exe
(DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_86d9ab8950580d2e\x64\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_86d9ab8950580d2e\x64\BridgeCommunication.exe
(DriverStore\FileRepository\ipf_cpu.inf_amd64_dbf4926c2b80caa5\ipf_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_dbf4926c2b80caa5\ipf_helper.exe
(ETDService.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDCtrl.exe
(explorer.exe ->) (Fndroid) [File not signed] C:\Users\YuchenTong\Documents\Clash.for.Windows-0.12.1\Clash for Windows.exe <4>
(explorer.exe ->) (LizardSystems (Vitali Ivanovich Zagorovski, IP) -> LizardSystems) C:\Program Files (x86)\LizardSystems\Remote Process Explorer\rpexplorer.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <15>
(HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_1.2.15.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityHost.exe
(HP Inc.) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\OmenCommandCenterBackground.exe
(services.exe ->) (DTS, Inc. -> DTS Inc.) C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.exe
(services.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDService.exe
(services.exe ->) (Flexera Software LLC -> Flexera) C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_54a828a51f6769c8\x64\TouchpointAnalyticsClientService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_86d9ab8950580d2e\x64\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_86d9ab8950580d2e\x64\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_86d9ab8950580d2e\x64\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_86d9ab8950580d2e\x64\SysInfoCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_7ea79942c83947c1\x64\OmenCap\OmenCap.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_d11b96206a0caf0c\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_d2ed56d70ca1fa55\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_dbf4926c2b80caa5\ipf_uf.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_12a44ce46c6debd7\AS\IAS\IntelAudioService.exe
(services.exe ->) (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvhm.inf_amd64_b5eab67518a4faa8\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_630dffb5316e4d50\RtkAudUService64.exe <2>
(services.exe ->) (Tencent Technology(Shenzhen) Company Limited -> Tencent) C:\Program Files (x86)\Common Files\Tencent\QQProtect\Bin\QQProtect.exe
(services.exe ->) (voidtools -> voidtools) C:\Program Files\Everything\Everything.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\SystemOptimizer\SystemOptimizer.exe
(svchost.exe ->) (HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPQuickDrop_2.5.9180.0_x64__v10z8vjag6ke6\HPQuickDrop.exe
(svchost.exe ->) (HP Inc.) C:\Program Files\WindowsApps\AD2F1837.myHP_1.10.53228.0_x64__v10z8vjag6ke6\HP.myHP.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.722.3302.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.722.3302.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_421.20070.95.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtkAudUService] => C:\windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_630dffb5316e4d50\RtkAudUService64.exe [3408512 2022-01-10] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HPSEU\HpseuHostLauncher.exe [530568 2021-05-15] (HP Inc. -> HP Inc.)
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4279208 2022-03-15] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\Run: [BaiduYunDetect] => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunDetectService.exe [1288696 2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\Run: [MicrosoftEdgeAutoLaunch_0817AD55560C87EB70CBDEDADDDAA235] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3540408 2022-04-21] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [35888256 2022-03-10] (Piriform Software Ltd -> Piriform Software Ltd)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {05530930-F125-4974-9C96-05B850E5D41A} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1650384 2021-12-20] (Nvidia Corporation -> NVIDIA Corporation)
Task: {07CDA7B4-6ED9-47F4-B80A-458C97C99CF8} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3339464 2021-12-20] (Nvidia Corporation -> NVIDIA Corporation)
Task: {09466250-B753-426F-942F-4854516A54A3} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1651032 2020-11-05] (HP Inc. -> HP Inc.)
Task: {0F02FA0A-C6B3-43BC-90F8-E9860CAE30C5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22866856 2022-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {13F38B07-D153-4AE0-9221-A5F9DE8A21F9} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-03-10] (Piriform Software Ltd -> Piriform)
Task: {20E8D2CD-47DC-4B0F-9F28-D85C1D1F7DA5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {25BDCE48-09D0-4693-BC97-D37C290AEB90} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM1 => cmd /c start hpdiags://BHM1
Task: {26FC49F1-ABA3-461D-8A61-B95D6DF50EDC} - System32\Tasks\Git for Windows Updater => C:\Program Files\Git\git-bash.exe [137744 2022-02-01] (Johannes Schindelin -> The Git Development Community)
Task: {2888B378-BD27-4E83-B267-C6540B31BD38} - System32\Tasks\Hewlett-Packard\HP Diagnostics\LaunchUI => cmd /c start hpdiags://LaunchUI
Task: {308E384D-F059-47BA-BE58-11C8C750CB6D} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [61336 2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Task: {329663E2-A325-4461-AC1A-1F0BA3B38BF8} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusTest => cmd /c start hpdiags://BatteryStatusTest
Task: {35A76132-97C4-45C5-94F9-04F7888D5258} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM2 => cmd /c start hpdiags://BHM2
Task: {4477E246-CA62-430B-8AC6-5835D4127DED} - System32\Tasks\GoogleUpdateTaskMachineUA{132B5BAC-C176-482F-8D1D-97FDDEB6A6DD} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2022-04-13] (Google LLC -> Google LLC)
Task: {46409E47-07BC-4606-89D9-0169366E16B8} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ABO => cmd /c start hpdiags://ABO
Task: {48FF4DD1-2C66-4683-8597-C64DA8772627} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138672 2022-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {5DC3C58F-DACA-43EA-9FA9-D8553FD4EC6E} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusError => cmd /c start hpdiags://BatteryStatusError
Task: {6AAD88A4-EE5B-4A23-A037-1FF9AC893FE0} - System32\Tasks\MicrosoftEdgeShadowStackRollbackTask => C:\Program Files (x86)\Microsoft\Edge\Application\100.0.1185.50\Installer\setup.exe [3211712 2022-04-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {6F969999-C5C5-47F9-90CE-176C23A19E4F} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe /NoUACCheck
Task: {722C51C5-8B71-4FAE-A1A3-E6B77E99E483} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1650384 2021-12-20] (Nvidia Corporation -> NVIDIA Corporation)
Task: {77ECA5DF-FF10-4FC9-9581-2F41D61495AE} - System32\Tasks\MicrosoftMalwareProtection => C:\Users\YuchenTong\AppData\Roaming\Microsoft\MicrosoftMalwareProtection.exe [1381355632 2022-03-14] () [File not signed] <==== ATTENTION
Task: {7A3038BB-B7AA-46B4-8F07-4987A551152D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22866856 2022-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {7AEC539A-A7E9-43C9-AD7D-711684BEF6A8} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138672 2022-04-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {812F3E28-02F3-4AF8-B8ED-6D9C42966775} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer.bacd823895d847ca8da24154e424012b\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe (No File)
Task: {81A7518A-6E34-4DBE-97D8-DEDB6695C226} - System32\Tasks\CCleanerSkipUAC - YuchenTong => C:\Program Files\CCleaner\CCleaner.exe [30053504 2022-03-10] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {91478CFA-FB38-4512-B593-98BF810CEBCE} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1650384 2021-12-20] (Nvidia Corporation -> NVIDIA Corporation)
Task: {98CBC342-D489-4981-BB17-2C103D904F6B} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ShowUI => cmd /c start hpdiags:
Task: {A1C6FCE0-1A2C-4A60-BFEF-B977B95C64FB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A906A7E4-2EB1-4AC8-97F8-AE788DD131E9} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BCF => cmd /c start hpdiags://BCF
Task: {AB3492F3-C131-45DA-B3CA-F93AC8A71735} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [903024 2021-12-20] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {B1AD45D6-F66F-4464-A7C1-12AE3F415B15} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1650384 2021-12-20] (Nvidia Corporation -> NVIDIA Corporation)
Task: {B41EF926-4D96-4B38-9A6B-48C8B9CEFA47} - System32\Tasks\GoogleUpdateTaskMachineCore{91B20535-4EFF-47B5-8E34-2A3E8E35FA9C} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2022-04-13] (Google LLC -> Google LLC)
Task: {BD15762A-7FFB-45B6-8071-CA46369046F2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CB8F3953-995A-4843-9885-899DE163BD75} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [138328 2022-03-28] (HP Inc. -> HP Inc.)
Task: {DFE08D6C-E5AF-49E4-868F-672568047615} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {ECA7F08C-58E4-429C-94AD-C94687571327} - System32\Tasks\SystemOptimizer => C:\Program Files\HP\SystemOptimizer\SystemOptimizer.exe [117848 2022-03-20] (HP Inc. -> HP Inc.)
Task: {F11AF681-F247-4F4D-8534-04954CE46327} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [647376 2021-12-20] (Nvidia Corporation -> NVIDIA Corporation)
Task: {F3813806-B1DB-4DD7-9F26-B63AC1695644} - System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckError => cmd /c start hpdiags://SmartCheckError
Task: {FDE73B97-F361-46DB-B4FE-BD116B54209F} - System32\Tasks\HP\Consent Manager Launcher => sc start hptouchpointanalyticsservice
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
AutoConfigURL: [{3D973137-5876-44BE-86E8-84F72C458BAF}] => hxxp://127.0.0.1:10086/SangforAppPass.11884.pac
AutoConfigURL: [{CB593C0F-A9F0-403E-89F7-0403F59D3A1F}] => hxxp://127.0.0.1:10086/SangforAppPass.31596.pac
ProxyEnable: [S-1-5-21-1919967345-4022050966-3323017305-1001] => Proxy is enabled.
ProxyServer: [S-1-5-21-1919967345-4022050966-3323017305-1001] => 127.0.0.1:7890
Tcpip\Parameters: [DhcpNameServer] 116.228.111.18 180.168.255.118
Tcpip\..\Interfaces\{3c3bfe46-39bf-46c5-b3ef-64303d09e8bb}: [DhcpNameServer] 116.228.111.18 180.168.255.118
ManualProxies: 1127.0.0.1:7890
 
Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\YuchenTong\AppData\Local\Microsoft\Edge\User Data\Default [2022-04-24]
Edge Notifications: Default -> hxxps://www.youtube.com
Edge Extension: (Octotree - GitHub code tree) - C:\Users\YuchenTong\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bkhaagjahfmjljalopjnoealnfndnagc [2022-04-08]
Edge Extension: (Adblock Plus - 免费的广告拦截器) - C:\Users\YuchenTong\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2022-03-22]
Edge Extension: (Google学术搜索按钮) - C:\Users\YuchenTong\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ldipcbpaocekfooobnbcddclnhejkcpn [2022-03-20]
 
FireFox:
========
FF ProfilePath: C:\Users\YuchenTong\AppData\Roaming\Mozilla\Firefox\Profiles\lyjgiwzf.default [2022-03-20]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-19] (VideoLAN -> VideoLAN)
FF Plugin-x32: @baidu.com/YunWebDetectPlugin -> C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\npYunWebDetect.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-03-20] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @qq.com/npqscall -> C:\Program Files (x86)\Common Files\Tencent\Npchrome\npactivex.dll [2022-03-20] (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FF Plugin-x32: @qq.com/QQPhotoDrawEx -> C:\Program Files (x86)\Tencent\Qzone\npQQPhotoDrawEx.dll [2013-08-13] (Tencent Technology(Shenzhen) Company Limited -> )
FF Plugin-x32: @qq.com/QzoneMusic -> C:\Program Files (x86)\Tencent\QzoneMusic\npQzoneMusic.dll [2016-02-26] (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FF Plugin-x32: @tencent.com/npQQMailWebKit,version=1.0.0.1 -> C:\Program Files (x86)\QQMailPlugin\npQQMailWebKit.dll [2013-04-25] (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FF Plugin-x32: @tencent.com/nptxftnWebKit,version=1.0.0.1 -> C:\Program Files (x86)\QQMailPlugin\nptxftnWebKit.dll [2013-04-08] (Tencent Technology (Shenzhen) Company Limited) [File not signed]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S4 BaiduNetdiskUtility; C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunUtilityService.exe [103928 2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11666384 2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
R2 DtsApo4Service; C:\windows\System32\DTS\PC\APO4x\DtsApo4Service.exe [224680 2021-12-18] (DTS, Inc. -> DTS Inc.)
R2 Everything; C:\Program Files\Everything\Everything.exe [2262176 2021-12-17] (voidtools -> voidtools)
R2 HPAppHelperCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_86d9ab8950580d2e\x64\AppHelperCap.exe [762888 2022-02-27] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_86d9ab8950580d2e\x64\DiagsCap.exe [760312 2022-02-27] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_86d9ab8950580d2e\x64\NetworkCap.exe [758280 2022-02-27] (HP Inc. -> HP Inc.)
R2 HPOmenCap; C:\windows\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_7ea79942c83947c1\x64\OmenCap\OmenCap.exe [698760 2022-02-14] (HP Inc. -> HP Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1149480 2018-06-07] (HP Inc. -> HP)
R2 HPSysInfoCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_86d9ab8950580d2e\x64\SysInfoCap.exe [761376 2022-02-27] (HP Inc. -> HP Inc.)
R2 HpTouchpointAnalyticsService; C:\windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_54a828a51f6769c8\x64\TouchpointAnalyticsClientService.exe [494672 2021-11-22] (HP Inc. -> HP Inc.)
R2 IntelAudioService; C:\windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_12a44ce46c6debd7\\AS\\IAS\\IntelAudioService.exe [532648 2021-12-18] (Intel Corporation -> Intel)
R2 ipfsvc; C:\windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_dbf4926c2b80caa5\ipf_uf.exe [2425024 2021-12-17] (Intel Corporation -> Intel Corporation)
R2 QPCore; C:\Program Files (x86)\Common Files\Tencent\QQProtect\Bin\QQProtect.exe [118480 2022-04-24] (Tencent Technology(Shenzhen) Company Limited -> Tencent)
S4 QQMusicService; C:\Program Files (x86)\Common Files\Tencent\QQMusic\QQMusicService.exe [185928 2022-03-09] (Tencent Technology(Shenzhen) Company Limited -> Tencent)
S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [147392 2019-04-30] (Microsoft Corporation -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe [3116848 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 WemeetUpdateSvc; C:\Program Files (x86)\Tencent\UpdateSvr\WemeetUpdateSvc.exe [475128 2022-04-17] (Tencent Technology(Shenzhen) Company Limited -> )
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe [133544 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\windows\System32\DriverStore\FileRepository\nvhm.inf_amd64_b5eab67518a4faa8\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\windows\System32\DriverStore\FileRepository\nvhm.inf_amd64_b5eab67518a4faa8\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
S2 SangforPWEx; "C:\Program Files (x86)\Sangfor\SSL\SangforPWEx\SangforPWEx.exe" [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 GlPciSD; C:\windows\System32\drivers\GlPciSD.sys [219848 2021-09-02] (GENESYS LOGIC, INC. -> Genesys Logic)
S3 GSCAuxDriver; C:\windows\System32\DriverStore\FileRepository\gscauxdriver.inf_amd64_47dea9773e9dfab7\GSCAuxDriverx64.sys [78904 2021-12-03] (Intel Corporation -> Intel Corporation)
S3 GSCx64; C:\windows\System32\DriverStore\FileRepository\gscheci.inf_amd64_1027aa064fe1f3f7\TeeDriverGSCW8x64.sys [258104 2021-12-03] (Intel Corporation -> Intel Corporation)
R3 HPCustomCapDriver; C:\windows\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_a955fa431e522f5e\x64\hpcustomcapdriver.sys [25592 2021-09-16] (HP Inc. -> HP Inc.)
R3 HPOmenCustomCapDriver; C:\windows\System32\DriverStore\FileRepository\hpomencustomcapdriver.inf_amd64_326f2e1d16385daf\x64\hpomencustomcapdriver.sys [23896 2021-09-28] (HP Inc. -> HP Inc.)
R2 HpReadHWData; C:\windows\system32\drivers\HpReadHWData.sys [47184 2022-03-10] (HP Inc. -> Windows ® Win 7 DDK provider)
S3 Hsp; C:\windows\System32\drivers\Hsp.sys [110904 2022-03-20] (Microsoft Windows -> Microsoft Corporation)
R3 iaLPSS2_GPIO2_ADL; C:\windows\System32\DriverStore\FileRepository\ialpss2_gpio2_adl.inf_amd64_c385707073e5c73f\iaLPSS2_GPIO2_ADL.sys [139912 2021-11-22] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_I2C_ADL; C:\windows\System32\DriverStore\FileRepository\ialpss2_i2c_adl.inf_amd64_8ad31c966ef4e638\iaLPSS2_I2C_ADL.sys [207504 2021-11-22] (Intel Corporation -> Intel Corporation)
S3 iaLPSS2_SPI_ADL; C:\windows\System32\DriverStore\FileRepository\ialpss2_spi_adl.inf_amd64_2d1a1b06fd89c8d4\iaLPSS2_SPI_ADL.sys [160912 2021-11-22] (Intel Corporation -> Intel Corporation)
S3 iaLPSS2_UART2_ADL; C:\windows\System32\DriverStore\FileRepository\ialpss2_uart2_adl.inf_amd64_9f84cae4176aa5ed\iaLPSS2_UART2_ADL.sys [318624 2021-11-22] (Intel Corporation -> Intel Corporation)
S3 IntcSdwBus; C:\windows\System32\DriverStore\FileRepository\intcsdwbus.inf_amd64_084c7a6ea33cd690\IntcSdwBus.sys [507544 2021-12-18] (Intel Corporation -> Intel® Corporation)
R3 IntcUSB; C:\windows\System32\DriverStore\FileRepository\intcusb.inf_amd64_d71875a1ee3042a7\IntcUSB.sys [883360 2021-12-18] (Intel Corporation -> Intel® Corporation)
R3 IntelGNA; C:\windows\System32\DriverStore\FileRepository\gna.inf_amd64_19ceb7ce67a7cf8b\gna.sys [87208 2021-10-07] (Intel Corporation -> Intel Corporation)
S3 ipf_acpi; C:\windows\System32\DriverStore\FileRepository\ipf_acpi.inf_amd64_709dd98a4001e271\ipf_acpi.sys [86720 2021-12-17] (Intel Corporation -> Intel Corporation)
R3 ipf_cpu; C:\windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_dbf4926c2b80caa5\ipf_cpu.sys [80576 2021-12-17] (Intel Corporation -> Intel Corporation)
R3 ipf_lf; C:\windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_dbf4926c2b80caa5\ipf_lf.sys [429240 2021-12-17] (Intel Corporation -> Intel Corporation)
R3 nvpcf; C:\windows\System32\drivers\nvpcf.sys [241544 2022-01-27] (Nvidia Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\windows\system32\drivers\nvvad64v.sys [48552 2021-12-20] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
U5 PROCMON24; C:\Windows\System32\Drivers\PROCMON24.sys [95632 2022-04-24] (Microsoft Windows Hardware Compatibility Publisher -> Sysinternals - www.sysinternals.com)
S3 rtcx21; C:\windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_d2a498d51a4f7bec\rtcx21x64.sys [409000 2021-06-01] (Realtek Semiconductor Corp. -> Realtek)
R1 rtf64; C:\windows\system32\DRIVERS\rtf64x64.sys [62352 2021-12-11] (Realtek Semiconductor Corp. -> Realtek)
S3 SangforVnic; C:\windows\System32\drivers\SangforVnic.sys [44008 2018-10-07] (Sangfor Technologies Co.,Ltd -> SANGFOR)
S3 uupacket; C:\Windows\System32\drivers\uupacket.sys [54400 2021-11-30] (NetEase(Hangzhou) Network Co. Ltd. -> 网易(杭州)网络有限公司)
S3 uuwfp; C:\Windows\System32\drivers\uuwfp.sys [60056 2021-11-30] (NetEase(Hangzhou) Network Co. Ltd. -> )
R3 ViGEmBus; C:\windows\System32\DriverStore\FileRepository\vigembus.inf_amd64_e84845c70c38fbe7\x64\ViGEmBus.sys [74648 2018-08-01] (HP Inc. -> Benjamin Höglinger-Stelzer)
S0 WdBoot; C:\windows\System32\drivers\wd\WdBoot.sys [49600 2022-04-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\windows\System32\drivers\wd\WdFilter.sys [443664 2022-04-08] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\windows\System32\drivers\wd\WdNisDrv.sys [90384 2022-04-08] (Microsoft Windows -> Microsoft Corporation)
S3 GSDriver; \SystemRoot\System32\drivers\GSDriver64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-04-24 19:12 - 2022-04-24 20:18 - 000001026 _____ C:\Users\YuchenTong\Desktop\a.txt
2022-04-24 18:53 - 2022-04-24 18:53 - 000011730 _____ C:\Users\YuchenTong\Downloads\{0A7ABDE6-CD0B-405D-9678-7F5A397DA5D2}
2022-04-24 16:42 - 2022-04-24 16:42 - 000001369 _____ C:\Users\YuchenTong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Git for Windows.lnk
2022-04-24 15:40 - 2022-04-24 18:33 - 000068135 _____ C:\Users\YuchenTong\Downloads\Addition.txt
2022-04-24 15:39 - 2022-04-24 21:04 - 000029427 _____ C:\Users\YuchenTong\Downloads\FRST.txt
2022-04-24 15:25 - 2022-04-24 21:04 - 000000000 ____D C:\FRST
2022-04-24 15:24 - 2022-04-24 15:25 - 002366976 _____ (Farbar) C:\Users\YuchenTong\Downloads\FRST64english.exe
2022-04-24 14:29 - 2022-04-24 14:56 - 000000000 ____D C:\Program Files\GridinSoft Anti-Malware
2022-04-24 14:29 - 2022-04-24 14:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GridinSoft Anti-Malware
2022-04-24 14:29 - 2022-04-24 14:29 - 000000000 ____D C:\ProgramData\GridinSoft
2022-04-24 14:11 - 2022-04-24 14:12 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\hpqLog
2022-04-24 13:39 - 2022-04-24 13:39 - 000989584 _____ (GridinSoft LLC) C:\Users\YuchenTong\Downloads\install-antimalware-fix.exe
2022-04-24 13:13 - 2022-04-24 13:13 - 000000112 ___SH C:\bootTel.dat
2022-04-23 22:45 - 2022-04-23 22:45 - 000082260 _____ C:\ProgramData\agent.uninstall.1650725123.bdinstall.v2.bin
2022-04-23 22:20 - 2022-04-23 22:32 - 000000000 ____D C:\ProgramData\HitmanPro
2022-04-23 22:20 - 2022-04-23 22:20 - 000000000 ____D C:\Program Files\HitmanPro
2022-04-23 22:19 - 2022-04-23 22:21 - 014239168 _____ (SurfRight B.V.) C:\Users\YuchenTong\Downloads\HitmanPro_x64.exe
2022-04-23 22:14 - 2022-04-23 22:14 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\YuchenTong\Downloads\rkill.exe
2022-04-23 22:10 - 2022-04-24 20:12 - 124518400 _____ C:\windows\system32\config\SOFTWARE
2022-04-23 22:07 - 2022-04-23 22:10 - 000000000 ____D C:\windows\Microsoft Antimalware
2022-04-23 21:20 - 2022-04-23 21:20 - 000152696 _____ C:\ProgramData\agent.1650720010.bdinstall.v2.bin
2022-04-23 21:20 - 2022-04-23 21:20 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\Bitdefender
2022-04-23 21:20 - 2022-04-23 21:20 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2022-04-23 20:34 - 2022-04-24 13:25 - 000095632 ____H (Sysinternals - www.sysinternals.com) C:\windows\system32\Drivers\PROCMON24.SYS
2022-04-23 20:34 - 2022-04-23 20:34 - 000000000 ____D C:\Users\YuchenTong\Downloads\ProcessMonitor
2022-04-23 20:05 - 2022-04-24 20:13 - 000000000 ____D C:\ProgramData\TEMP
2022-04-23 20:05 - 2022-04-23 20:05 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\LizardSystems
2022-04-23 20:05 - 2022-04-23 20:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LizardSystems
2022-04-23 20:05 - 2022-04-23 20:05 - 000000000 ____D C:\Program Files (x86)\LizardSystems
2022-04-23 19:54 - 2022-04-23 19:54 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\mbam
2022-04-23 19:37 - 2022-04-23 19:37 - 000000000 ___HD C:\$SysReset
2022-04-23 19:16 - 2022-04-23 19:16 - 000000017 _____ C:\Users\YuchenTong\AppData\Local\resmon.resmoncfg
2022-04-23 19:13 - 2022-04-23 19:13 - 000036208 _____ (Sysinternals - www.sysinternals.com) C:\windows\system32\Drivers\PROCEXP152.SYS
2022-04-23 19:13 - 2022-04-23 19:13 - 000003652 _____ C:\windows\system32\Tasks\CreateExplorerShellUnelevatedTask
2022-04-23 18:23 - 2022-04-23 18:23 - 000000000 ____D C:\Users\YuchenTong\Downloads\ProcessExplorer
2022-04-23 18:15 - 2022-04-23 19:01 - 000000000 ____D C:\Program Files (x86)\Huorong
2022-04-21 18:21 - 2022-04-24 18:18 - 000003426 _____ C:\windows\system32\Tasks\MicrosoftMalwareProtection
2022-04-21 18:20 - 2022-04-21 18:25 - 000000000 __SHD C:\Users\YuchenTong\AppData\Roaming\Windows
2022-04-21 17:16 - 2022-04-21 17:21 - 000000000 ____D C:\Users\YuchenTong\Downloads\warlock-and-boobs-0.352-win
2022-04-21 17:16 - 2022-04-21 17:19 - 000000000 ____D C:\Users\YuchenTong\Downloads\The_Tail_of_Desire_v0.77
2022-04-21 17:16 - 2022-04-21 17:16 - 000000000 ____D C:\Users\YuchenTong\Downloads\Renryuu_Ascension_22.04.17_Windows_Version
2022-04-20 15:55 - 2022-04-20 15:55 - 000000000 ____D C:\Users\YuchenTong\.templateengine
2022-04-20 15:54 - 2022-04-20 15:54 - 000001765 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blend for Visual Studio 2022.lnk
2022-04-20 15:54 - 2022-04-20 15:54 - 000000000 ____D C:\Users\YuchenTong\.dotnet
2022-04-20 15:54 - 2022-04-20 15:54 - 000000000 ____D C:\Program Files\dotnet
2022-04-20 15:54 - 2022-04-20 15:54 - 000000000 ____D C:\Program Files (x86)\NuGet
2022-04-20 15:54 - 2022-04-20 15:54 - 000000000 ____D C:\Program Files (x86)\dotnet
2022-04-20 15:50 - 2022-04-20 15:50 - 000001764 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2022.lnk
2022-04-18 17:48 - 2022-04-18 15:40 - 000046919 _____ C:\Users\YuchenTong\Downloads\CE_religion.txt
2022-04-18 12:34 - 2022-04-18 12:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Graphviz
2022-04-18 12:34 - 2022-04-18 12:34 - 000000000 ____D C:\Program Files\Graphviz
2022-04-17 21:58 - 2022-04-17 21:58 - 000930912 _____ C:\Users\YuchenTong\Downloads\pguo-PhD-grind.pdf
2022-04-17 21:49 - 2022-04-17 21:49 - 000000000 _____ C:\Users\YuchenTong\Documents\git_token.txt
2022-04-17 21:47 - 2022-04-17 21:47 - 000000050 _____ C:\Users\YuchenTong\.gitconfig
2022-04-17 14:20 - 2022-04-17 18:16 - 000000378 _____ C:\Users\YuchenTong\.bash_history
2022-04-17 14:11 - 2022-04-17 14:11 - 000240705 _____ C:\Users\YuchenTong\Downloads\Static_Taint_Analysis_in_Rust.pdf
2022-04-17 13:58 - 2022-04-17 13:58 - 014138368 _____ C:\Users\YuchenTong\libj2v8_win32_x86_64.dll
2022-04-16 19:54 - 2022-04-16 19:55 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\CMakeTools
2022-04-16 19:07 - 2022-04-16 19:19 - 000000000 ____D C:\Users\YuchenTong\.cargo
2022-04-16 19:07 - 2022-04-16 19:08 - 000000000 ____D C:\Users\YuchenTong\.rustup
2022-04-15 16:42 - 2022-04-15 16:42 - 000000053 _____ C:\Users\YuchenTong\.git-for-windows-updater
2022-04-14 12:39 - 2022-04-14 12:39 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Sublime Text
2022-04-14 12:39 - 2022-04-14 12:39 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\Sublime Text
2022-04-14 12:38 - 2022-04-14 12:38 - 000000920 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sublime Text.lnk
2022-04-14 12:38 - 2022-04-14 12:38 - 000000000 ____D C:\Program Files\Sublime Text
2022-04-14 12:29 - 2022-04-14 12:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vim 8.2
2022-04-14 12:28 - 2022-04-14 12:29 - 000000000 ____D C:\Program Files (x86)\Vim
2022-04-13 17:35 - 2022-04-13 17:35 - 000000000 ____D C:\Users\YuchenTong\AppData\LocalLow\Google
2022-04-13 17:34 - 2022-04-24 20:27 - 000000000 ____D C:\Program Files (x86)\Google
2022-04-13 17:34 - 2022-04-21 00:22 - 000003150 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineUA{132B5BAC-C176-482F-8D1D-97FDDEB6A6DD}
2022-04-13 17:34 - 2022-04-21 00:22 - 000003026 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineCore{91B20535-4EFF-47B5-8E34-2A3E8E35FA9C}
2022-04-13 17:34 - 2022-04-13 17:34 - 000002260 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2022-04-13 17:34 - 2022-04-13 17:34 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\Google
2022-04-13 17:34 - 2022-04-13 17:34 - 000000000 ____D C:\Program Files\Google
2022-04-13 14:45 - 2022-04-13 14:45 - 000015192 _____ C:\windows\system32\DrtmAuthTxt.wim
2022-04-13 14:44 - 2022-04-13 14:44 - 000000000 ___HD C:\$WinREAgent
2022-04-12 21:30 - 2021-11-04 12:26 - 1070240358 ___SH C:\windows\system32\diskparts.exe
2022-04-12 20:42 - 2022-04-12 21:49 - 000000000 ____D C:\Users\YuchenTong\Downloads\Roundscape Adorevia Version 5.8b Full.rar
2022-04-11 23:31 - 2022-04-11 23:41 - 000000000 ____D C:\Users\YuchenTong\Downloads\Legend_of_Queen_Opala_Origin-Beta-v3.13b
2022-04-11 23:28 - 2009-10-23 00:00 - 000761856 _____ C:\windows\SysWOW64\RGSS104J.dll
2022-04-11 23:28 - 2009-10-23 00:00 - 000758272 _____ C:\windows\SysWOW64\RGSS104E.dll
2022-04-10 17:15 - 2022-04-10 17:15 - 000342429 _____ C:\Users\YuchenTong\Downloads\Rust verification workshop.pptx
2022-04-10 17:14 - 2022-04-10 17:14 - 000075669 _____ C:\Users\YuchenTong\Downloads\MIRAI basics.pptx
2022-04-08 21:57 - 2022-04-22 21:23 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\User Data
2022-04-08 21:57 - 2022-04-08 21:57 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\nwjs
2022-04-08 20:41 - 2022-04-08 20:41 - 000031584 _____ (Beijing Huorong Network Technology Co., Ltd.) C:\windows\system32\Drivers\hrdevmon_win10.sys
2022-04-08 20:41 - 2022-04-08 20:41 - 000024568 _____ (Beijing Huorong Network Technology Co., Ltd.) C:\windows\system32\Drivers\hrdevmon.sys
2022-04-08 18:17 - 2022-04-08 18:18 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\ForzaHorizon4
2022-04-07 17:21 - 2022-04-07 17:21 - 000120312 _____ (Beijing Huorong Network Technology Co., Ltd.) C:\windows\system32\Drivers\hrfwdrv.sys
2022-04-07 17:01 - 2022-04-07 17:01 - 000000000 ____D C:\Users\YuchenTong\AppData\LocalLow\Fictiorama Studios
2022-04-05 23:01 - 2022-04-05 23:40 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\RenPy
2022-04-05 19:25 - 2022-04-05 19:25 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\11bitstudios
2022-04-04 20:29 - 2022-04-04 20:29 - 000000000 ____D C:\Users\Public\MTool_Game_Tmp
2022-04-04 18:23 - 2022-04-04 18:23 - 000000000 ____D C:\CloudMusic
2022-04-03 19:14 - 2022-04-03 19:14 - 002550832 _____ (The ICU Project) C:\windows\system32\icu.dll
2022-04-03 19:14 - 2022-04-03 19:14 - 002080992 _____ (The ICU Project) C:\windows\SysWOW64\icu.dll
2022-04-03 19:14 - 2022-04-03 19:14 - 000372736 _____ C:\windows\system32\hwreqchk.dll
2022-04-03 19:14 - 2022-04-03 19:14 - 000069632 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2022-04-03 19:14 - 2022-04-03 19:14 - 000032768 _____ C:\windows\system32\agentactivationruntimestarter.exe
2022-04-03 17:53 - 2022-04-03 18:32 - 000000000 ____D C:\Users\YuchenTong\.ssh
2022-04-03 17:04 - 2022-04-03 17:04 - 000000000 ____D C:\Users\YuchenTong\Documents\NetSarang Computer
2022-04-03 17:04 - 2022-04-03 17:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\CrashRpt
2022-04-03 17:04 - 2022-04-03 17:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xshell 7
2022-04-03 17:04 - 2022-04-03 17:04 - 000000000 ____D C:\Program Files (x86)\NetSarang
2022-04-03 12:58 - 2022-04-03 12:58 - 000000000 ____D C:\Users\YuchenTong\source
2022-04-03 12:53 - 2022-04-18 13:00 - 000000000 ____D C:\Users\YuchenTong\CLionProjects
2022-04-03 12:49 - 2022-04-03 12:49 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\ServiceHub
2022-04-03 12:49 - 2022-04-03 12:49 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\IdentityNexusIntegration
2022-04-02 13:25 - 2022-04-02 13:25 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\TRAGsoft
2022-04-02 13:25 - 2022-04-02 13:25 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\TRAGsoft
2022-04-01 21:48 - 2022-04-01 21:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDjView
2022-04-01 21:48 - 2022-04-01 21:48 - 000000000 ____D C:\Program Files\WinDjView
2022-03-31 23:51 - 2022-03-31 23:51 - 000000000 ____D C:\Users\YuchenTong\.conda
2022-03-31 23:29 - 2022-03-31 23:30 - 000000836 _____ C:\Users\YuchenTong\.condarc
2022-03-31 00:07 - 2022-04-21 19:09 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Notion
2022-03-31 00:07 - 2022-03-31 00:07 - 000002295 _____ C:\Users\YuchenTong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notion.lnk
2022-03-31 00:07 - 2022-03-31 00:07 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\notion-updater
2022-03-30 23:01 - 2022-03-30 23:01 - 000000000 ____D C:\ProgramData\NeteaseWinDev
2022-03-30 00:29 - 2022-03-30 00:29 - 000000000 ____D C:\Users\YuchenTong\Documents\单词
2022-03-29 21:20 - 2022-03-29 21:20 - 000000000 ____D C:\Users\YuchenTong\Documents\My Games
2022-03-29 21:20 - 2022-03-29 21:20 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\FiraxisLive
2022-03-29 21:10 - 2022-03-29 21:19 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\T2GP Launcher
2022-03-29 21:10 - 2022-03-29 21:10 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\T2GP Launcher
2022-03-29 20:06 - 2022-03-29 20:07 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\hgslpds
2022-03-29 20:06 - 2022-03-29 20:06 - 000000000 ____D C:\ProgramData\boost_interprocess_ms
2022-03-29 20:05 - 2022-03-29 20:05 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\AuntecPkg
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\Documents\Foxit Software
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\UserSystemSDK_DB
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Foxit Software
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Foxit
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\FnInformation
2022-03-29 19:03 - 2022-03-29 19:03 - 000003936 _____ C:\windows\system32\Tasks\CCleaner Update
2022-03-29 19:03 - 2022-03-29 19:03 - 000002910 _____ C:\windows\system32\Tasks\CCleanerSkipUAC - YuchenTong
2022-03-29 19:03 - 2022-03-29 19:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2022-03-29 19:02 - 2022-04-24 20:14 - 000000000 ____D C:\Program Files\CCleaner
2022-03-28 17:51 - 2022-03-28 17:51 - 000000000 ____D C:\Users\YuchenTong\Documents\FLiNGTrainer
2022-03-28 17:21 - 2022-03-28 17:21 - 000000000 ____D C:\Users\YuchenTong\AppData\LocalLow\Team 17 Digital ltd_
2022-03-28 17:08 - 2022-03-28 17:08 - 000000000 ____D C:\Users\YuchenTong\AppData\LocalLow\Alexander Goodwin
2022-03-28 00:43 - 2022-03-28 13:47 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\vlc
2022-03-27 21:41 - 2022-03-28 12:16 - 000000000 ____D C:\Users\YuchenTong\Documents\录音
2022-03-26 17:00 - 2022-03-28 19:00 - 000000000 ____D C:\Users\YuchenTong\Documents\考研复试相关
2022-03-26 12:43 - 2022-04-13 18:35 - 000000000 ____D C:\Users\YuchenTong\IdeaProjects
2022-03-26 12:43 - 2022-03-26 12:43 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\main.kts.compiled.cache
2022-03-26 12:41 - 2022-03-26 12:41 - 000000000 ____D C:\Users\YuchenTong\.android
2022-03-26 12:40 - 2022-04-03 12:52 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\JetBrains
2022-03-26 12:40 - 2022-04-03 12:52 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\JetBrains
2022-03-25 21:40 - 2022-03-25 21:40 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\karrynsprison50
2022-03-25 21:38 - 2022-03-25 21:38 - 000000000 ____D C:\Users\YuchenTong\Downloads\Karryns_Prison_v1.0.5f_FULL
2022-03-25 09:11 - 2022-03-25 09:11 - 000000000 ____D C:\Users\YuchenTong\AppData\LocalLow\TENCENT
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-04-24 20:49 - 2021-06-05 20:10 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-04-24 20:21 - 2022-03-20 14:15 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\clash_win
2022-04-24 20:20 - 2021-06-25 06:13 - 001380620 _____ C:\windows\system32\PerfStringBackup.INI
2022-04-24 20:20 - 2021-06-06 01:51 - 000391526 _____ C:\windows\system32\prfh0804.dat
2022-04-24 20:20 - 2021-06-06 01:51 - 000136224 _____ C:\windows\system32\prfc0804.dat
2022-04-24 20:20 - 2021-06-05 20:09 - 000000000 ____D C:\windows\INF
2022-04-24 20:12 - 2022-03-10 23:13 - 000000000 ____D C:\ProgramData\NVIDIA
2022-04-24 20:12 - 2021-06-25 06:08 - 000012288 ___SH C:\DumpStack.log.tmp
2022-04-24 20:12 - 2021-06-25 06:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2022-04-24 20:12 - 2021-06-05 20:10 - 000000000 ____D C:\windows\SystemTemp
2022-04-24 20:12 - 2021-06-05 20:10 - 000000000 ____D C:\windows\ServiceState
2022-04-24 20:12 - 2021-06-05 20:01 - 000786432 _____ C:\windows\system32\config\BBI
2022-04-24 20:11 - 2022-03-22 22:36 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\Everything
2022-04-24 20:11 - 2022-03-20 15:28 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Everything
2022-04-24 20:11 - 2022-03-20 14:54 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Code
2022-04-24 19:36 - 2021-06-25 06:08 - 000000000 ____D C:\windows\system32\SleepStudy
2022-04-24 16:18 - 2022-03-20 15:08 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\OGH
2022-04-24 15:55 - 2022-03-20 12:20 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\D3DSCache
2022-04-24 15:55 - 2021-06-05 20:10 - 000000000 ____D C:\windows\AppReadiness
2022-04-24 15:26 - 2022-03-20 12:22 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\CrashDumps
2022-04-24 14:52 - 2021-12-24 09:28 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2022-04-24 14:48 - 2022-03-20 16:28 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Tencent
2022-04-24 14:12 - 2022-03-20 12:22 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\HP
2022-04-24 14:12 - 2021-12-24 09:27 - 000000000 ____D C:\Program Files (x86)\HP
2022-04-24 14:11 - 2022-03-20 12:32 - 000000000 ____D C:\windows\system32\Tasks\Hewlett-Packard
2022-04-24 14:11 - 2022-03-20 12:32 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\HP
2022-04-24 13:12 - 2022-03-20 12:22 - 000000000 ___RD C:\Users\YuchenTong\OneDrive
2022-04-24 13:09 - 2022-03-20 12:20 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\Packages
2022-04-24 13:09 - 2021-06-25 06:09 - 000000000 ____D C:\ProgramData\Packages
2022-04-24 13:09 - 2021-06-05 20:10 - 000000000 ___HD C:\Program Files\WindowsApps
2022-04-23 22:12 - 2022-03-20 12:16 - 000004784 _____ C:\windows\system32\Tasks\MicrosoftEdgeShadowStackRollbackTask
2022-04-23 22:12 - 2021-06-25 06:08 - 000002431 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-04-23 21:18 - 2021-06-05 20:10 - 000000000 ___HD C:\windows\ELAMBKUP
2022-04-23 20:21 - 2022-03-20 16:29 - 000000000 ____D C:\Users\YuchenTong\Documents\WeChat Files
2022-04-23 19:08 - 2021-06-05 20:01 - 000000000 ____D C:\windows\CbsTemp
2022-04-23 19:00 - 2022-03-20 12:19 - 000000000 ____D C:\Users\YuchenTong
2022-04-23 16:23 - 2022-03-20 17:32 - 000000206 __RSH C:\ProgramData\ntuser.pol
2022-04-23 16:22 - 2022-03-20 17:31 - 000000015 _____ C:\Users\YuchenTong\AppData\Roaming\ECAgent.txt
2022-04-23 12:02 - 2022-03-20 14:49 - 000000000 ____D C:\Program Files (x86)\Steam
2022-04-22 16:28 - 2022-03-20 16:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯会议
2022-04-21 18:22 - 2022-03-20 15:13 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
2022-04-21 18:22 - 2021-06-25 06:08 - 000642192 _____ C:\windows\system32\FNTCACHE.DAT
2022-04-21 13:14 - 2022-03-20 19:06 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\paradox-launcher-v2
2022-04-21 00:22 - 2022-03-20 12:23 - 000003592 _____ C:\windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1919967345-4022050966-3323017305-1001
2022-04-21 00:22 - 2022-03-20 12:22 - 000003376 _____ C:\windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1919967345-4022050966-3323017305-1001
2022-04-21 00:22 - 2022-03-20 12:22 - 000002311 _____ C:\Users\YuchenTong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-04-20 18:31 - 2021-06-05 20:10 - 000000000 ____D C:\windows\LiveKernelReports
2022-04-20 16:17 - 2022-03-20 17:41 - 000000000 ____D C:\Users\YuchenTong\Documents\Thesis
2022-04-20 15:54 - 2022-03-20 15:23 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\.IdentityService
2022-04-20 15:54 - 2022-03-20 15:16 - 000000000 ____D C:\Program Files (x86)\Microsoft SDKs
2022-04-20 15:52 - 2022-03-20 15:16 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2022-04-20 15:50 - 2022-03-20 15:13 - 000001440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio Installer.lnk
2022-04-18 15:24 - 2022-03-20 15:24 - 000000000 ____D C:\Program Files (x86)\Netease
2022-04-18 13:01 - 2022-03-20 17:21 - 000009551 _____ C:\Users\YuchenTong\_viminfo
2022-04-18 12:21 - 2022-03-24 13:42 - 000000000 ____D C:\Users\YuchenTong\Documents\自定义 Office 模板
2022-04-17 23:46 - 2022-03-21 16:25 - 000000000 ____D C:\Users\YuchenTong\Projects
2022-04-16 17:27 - 2021-12-24 09:29 - 000000000 ____D C:\Program Files\Microsoft Office
2022-04-14 00:31 - 2022-03-20 14:54 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Visual Studio Code
2022-04-13 17:23 - 2021-06-05 20:10 - 000000000 ____D C:\windows\SystemResources
2022-04-13 17:23 - 2021-06-05 20:10 - 000000000 ____D C:\windows\bcastdvr
2022-04-13 14:46 - 2022-03-20 12:46 - 000000000 ____D C:\windows\system32\MRT
2022-04-13 14:45 - 2022-03-20 12:46 - 143823848 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2022-04-13 14:44 - 2021-06-25 06:11 - 003102208 _____ (Microsoft Corporation) C:\windows\SysWOW64\PrintConfig.dll
2022-04-10 22:44 - 2022-03-20 16:28 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\BaiduYunGuanjia
2022-04-10 22:20 - 2022-03-20 16:28 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\PLogs
2022-04-10 10:07 - 2021-06-25 06:08 - 000003132 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-04-10 10:07 - 2021-06-25 06:08 - 000003008 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2022-04-09 10:30 - 2022-03-20 17:30 - 000000000 ____D C:\Users\YuchenTong\AppData\Local\PlaceholderTileLogoFolder
2022-04-08 21:43 - 2022-03-20 17:58 - 000000000 ____D C:\ProgramData\boost_interprocess
2022-04-08 10:14 - 2022-03-20 14:03 - 000000000 ____D C:\windows\Firmware
2022-04-08 10:14 - 2021-06-25 06:08 - 000000000 ____D C:\windows\system32\Drivers\wd
2022-04-07 17:20 - 2022-03-20 19:06 - 000000000 ____D C:\Users\YuchenTong\Documents\Paradox Interactive
2022-04-05 11:02 - 2022-03-20 14:04 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2022-04-04 18:23 - 2022-03-20 19:07 - 000001261 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\网易云音乐.lnk
2022-04-03 19:16 - 2021-06-05 20:10 - 000000000 ___RD C:\windows\ImmersiveControlPanel
2022-04-03 19:16 - 2021-06-05 20:10 - 000000000 ____D C:\windows\SysWOW64\vi-VN
2022-04-03 19:16 - 2021-06-05 20:10 - 000000000 ____D C:\windows\SysWOW64\eu-ES
2022-04-03 19:16 - 2021-06-05 20:10 - 000000000 ____D C:\windows\system32\vi-VN
2022-04-03 19:16 - 2021-06-05 20:10 - 000000000 ____D C:\windows\system32\oobe
2022-04-03 19:16 - 2021-06-05 20:10 - 000000000 ____D C:\windows\system32\eu-ES
2022-04-03 19:16 - 2021-06-05 20:10 - 000000000 ____D C:\windows\system32\appraiser
2022-04-03 19:16 - 2021-06-05 20:10 - 000000000 ____D C:\windows\ShellExperiences
2022-04-03 19:16 - 2021-06-05 20:10 - 000000000 ____D C:\windows\DiagTrack
2022-04-03 17:48 - 2022-03-20 14:15 - 000000000 ____D C:\Users\YuchenTong\.config
2022-04-03 17:07 - 2022-03-20 17:40 - 000000000 ___RD C:\Users\YuchenTong\Documents\AAATYC
2022-04-03 12:58 - 2022-03-20 15:23 - 000000000 ____D C:\Users\YuchenTong\Documents\Visual Studio 2022
2022-04-01 14:22 - 2022-03-20 16:29 - 000000000 ____D C:\ProgramData\Tencent
2022-03-31 23:51 - 2022-03-20 14:37 - 000000000 ____D C:\Users\YuchenTong\anaconda3
2022-03-29 21:10 - 2022-03-10 23:13 - 000000000 ____D C:\ProgramData\Package Cache
2022-03-29 19:05 - 2021-06-25 21:47 - 000000000 ____D C:\windows\Panther
2022-03-26 22:59 - 2022-03-20 16:30 - 000000000 ____D C:\Users\YuchenTong\Documents\Tencent Files
 
==================== Files in the root of some directories ========
 
2022-04-17 13:58 - 2022-04-17 13:58 - 014138368 _____ () C:\Users\YuchenTong\libj2v8_win32_x86_64.dll
2022-03-20 17:31 - 2022-04-23 16:22 - 000000015 _____ () C:\Users\YuchenTong\AppData\Roaming\ECAgent.txt
2022-03-22 22:21 - 2022-03-22 22:21 - 000000036 _____ () C:\Users\YuchenTong\AppData\Roaming\{418C0070-7838-48BE-AF0A-485A052BBE44}
2022-04-21 18:20 - 2022-03-14 17:42 - 1381355632 ___SH () C:\Users\YuchenTong\AppData\Roaming\Microsoft\MicrosoftMalwareProtection.exe
2022-04-23 19:16 - 2022-04-23 19:16 - 000000017 _____ () C:\Users\YuchenTong\AppData\Local\resmon.resmoncfg
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================


#6 tyctxt

tyctxt
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 24 April 2022 - 08:11 AM

And Additions.txt is as below.
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2022
Ran by YuchenTong (24-04-2022 21:04:27)
Running from C:\Users\YuchenTong\Downloads
Microsoft Windows 11 家庭中文版 Version 21H2 22000.613 (X64) (2022-03-19 20:11:07)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-1919967345-4022050966-3323017305-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1919967345-4022050966-3323017305-503 - Limited - Disabled)
Guest (S-1-5-21-1919967345-4022050966-3323017305-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1919967345-4022050966-3323017305-504 - Limited - Disabled)
YuchenTong (S-1-5-21-1919967345-4022050966-3323017305-1001 - Administrator - Enabled) => C:\Users\YuchenTong
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
115电脑版 (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\115) (Version: 1.0.4.6 - 广东一一五科技股份有限公司)
7-Zip 21.07 (x64) (HKLM\...\7-Zip) (Version: 21.07 - Igor Pavlov)
Anaconda3 2021.11 (Python 3.9.7 64-bit) (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\Anaconda3 2021.11 (Python 3.9.7 64-bit)) (Version: 2021.11 - Anaconda, Inc.)
Application Verifier x64 External Package (HKLM\...\{8A4CD158-E6B3-6D91-D7DE-10098BC980E2}) (Version: 10.1.19041.685 - Microsoft) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.91 - Piriform)
ClickOnce Bootstrapper Package for Microsoft .NET Framework (HKLM-x32\...\{5A260D5A-95D3-4956-8E0A-E182CC4144ED}) (Version: 4.8.04162 - Microsoft Corporation) Hidden
CLion 2021.3.4 (HKLM-x32\...\CLion 2021.3.4) (Version: 213.7172.20 - JetBrains s.r.o.)
DiagnosticsHub_CollectionService (HKLM\...\{1F3C3AAC-9F7A-47DA-A082-0ACE770041BE}) (Version: 16.1.28901 - Microsoft Corporation) Hidden
Entity Framework 6.2.0 Tools  for Visual Studio 2022 (HKLM-x32\...\{BA73F2EE-EEB4-4A9C-BAF4-AC3599983E8B}) (Version: 6.2.0.0 - Microsoft Corporation) Hidden
Everything 1.4.1.1015 (x64) (HKLM\...\Everything) (Version: 1.4.1.1015 - voidtools)
Git (HKLM\...\Git_is1) (Version: 2.35.1.2 - The Git Development Community)
Google Earth Pro (HKLM\...\{C36E66A6-6EE5-47DB-945F-A6F03225D540}) (Version: 7.3.4.8573 - Google)
Graphviz (HKLM-x32\...\Graphviz) (Version: 3.0.0 - Graphviz)
HP Audio Switch (HKLM-x32\...\{0B1DA73D-0562-4DE1-B942-CEF286CF2EDD}) (Version: 1.0.211.0 - HP Inc.)
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP Software Framework (HKLM-x32\...\{71E18A14-1BDB-4B58-A67F-1BCDA12462FD}) (Version: 7.1.15.1 - HP)
icecap_collection_neutral (HKLM-x32\...\{04C533D3-8445-4E47-A351-A66B1DA1B631}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
icecap_collection_x64 (HKLM\...\{4CDCF412-13D2-48AD-B98C-3AB4A771A127}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
icecap_collectionresources (HKLM-x32\...\{9FC7998B-89C3-4069-9402-DE9CD1F8881F}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
icecap_collectionresourcesx64 (HKLM-x32\...\{1E763296-2BD7-43D9-9096-AA9644199A2D}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
IntelliJ IDEA 2021.3.3 (HKLM-x32\...\IntelliJ IDEA 2021.3.3) (Version: 213.7172.25 - JetBrains s.r.o.)
IntelliTraceProfilerProxy (HKLM-x32\...\{C8891AD2-C223-45CD-A9BE-617A68923B61}) (Version: 15.0.21225.01 - Microsoft Corporation) Hidden
Java™ SE Development Kit 17.0.2 (64-bit) (HKLM\...\{65BA81E7-0238-5B54-9069-A59610247B0B}) (Version: 17.0.2.0 - Oracle Corporation)
Kits Configuration Installer (HKLM-x32\...\{E75A9998-E979-760B-6AEB-49763F279EDD}) (Version: 10.1.19041.685 - Microsoft) Hidden
Microsoft .NET SDK 6.0.202 (x64) from Visual Studio (HKLM\...\{7D932616-6CDE-4A21-AF51-2434E6428FF0}) (Version: 6.2.222.17207 - Microsoft Corporation)
Microsoft 365 - zh-cn (HKLM\...\O365HomePremRetail - zh-cn) (Version: 16.0.15028.20204 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 100.0.1185.50 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 100.0.1185.44 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\OneDriveSetup.exe) (Version: 22.065.0412.0004 - Microsoft Corporation)
Microsoft OneNote - zh-cn (HKLM\...\OneNoteFreeRetail - zh-cn) (Version: 16.0.15028.20204 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2019 (HKLM\...\{3E5195F5-ED93-4406-B149-F9F66F35E851}) (Version: 15.0.2000.5 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{6A2A8076-135F-4F55-BB02-DED67C8C6934}) (Version: 4.67.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.31.31103 (HKLM-x32\...\{2aaf1df0-eb13-4099-9992-962bb4e596d1}) (Version: 14.31.31103.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.31.31103 (HKLM-x32\...\{41d7b770-418a-43b7-95a5-f925fff05789}) (Version: 14.31.31103.0 - Microsoft Corporation)
Microsoft Visual Studio Code (User) (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\{771FD6B0-FA20-440A-A002-3B3BAC16DC50}_is1) (Version: 1.66.2 - Microsoft Corporation)
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 3.1.2204.3969 - Microsoft Corporation)
MSI Development Tools (HKLM-x32\...\{7AAC93B0-F3D7-6B24-6B37-9E74980C1C81}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
MSYS2 64bit (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\{9f4fa27d-baa7-4723-9706-ca18879d9a74}) (Version: 20220319 - The MSYS2 Developers)
Notion 2.0.23 (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\fcdf0d7f-424b-5f10-a1c7-a8f643f21adf) (Version: 2.0.23 - Notion Labs, Incorporated)
NVIDIA FrameView SDK 1.2.4999.30397803 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.2.4999.30397803 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.24.0.123 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.24.0.123 - NVIDIA Corporation)
NVIDIA PhysX 系统软件 9.20.0221 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.20.0221 - NVIDIA Corporation)
NVIDIA 图形驱动程序 511.15 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 511.15 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.15028.20050 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.15028.20160 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0804-1000-0000000FF1CE}) (Version: 16.0.15028.20094 - Microsoft Corporation) Hidden
Paradox Launcher v2 (HKLM\...\{E68BBC18-9E69-436B-B20F-E294DE62ECAB}) (Version: 2.3.0 - Paradox Interactive)
PyCharm 2021.3.3 (HKLM-x32\...\PyCharm 2021.3.3) (Version: 213.7172.26 - JetBrains s.r.o.)
QQ音乐 (HKLM-x32\...\QQMusic) (Version: 18.59 - 腾讯科技(深圳)有限公司)
Remote Process Explorer version 21.04 (HKLM-x32\...\Remote Process Explorer_is1) (Version: 21.04 - LizardSystems)
RGSS-RTP Standard (HKLM-x32\...\RGSS-RTP Standard_is1) (Version: 1.04 - Enterbrain)
RPG Maker VX 1.02 (HKLM-x32\...\RPG Maker VX) (Version: 1.02 - EnterBrain)
RPG Maker VX Ace 1.00 (HKLM-x32\...\RPG Maker VX Ace) (Version: 1.00 - Enterbrain)
RPG MAKER VX Ace RTP (HKLM-x32\...\RPGVXAce_RTP_is1) (Version: 1.00 - Enterbrain)
RPG Maker VX RTP (HKLM-x32\...\RPG Maker VX RTP_is1) (Version: 1.02 - Enterbrain)
RPG Maker XP 1.03 (HKLM-x32\...\RPG Maker XP) (Version: 1.03 - Wise Studio)
Rustup: the Rust toolchain installer (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\Rustup) (Version:  - )
SDK ARM Additions (HKLM-x32\...\{FCF9D89E-6F79-64FB-B08D-B0E69FF54DEE}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
SDK ARM Redistributables (HKLM-x32\...\{72DB07D6-E166-5A3F-B6E6-4664383781B8}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Sublime Text (HKLM\...\Sublime Text_is1) (Version:  - Sublime HQ Pty Ltd)
SumatraPDF (HKLM\...\SumatraPDF) (Version: 3.3.3 - Krzysztof Kowalczyk)
Tencent QQMail Plugin (HKLM-x32\...\QQMailPlugin) (Version:  - )
Universal CRT Extension SDK (HKLM-x32\...\{4D69FB64-4443-F2DD-DE1C-F14FD98AAC59}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Universal CRT Headers Libraries and Sources (HKLM-x32\...\{6B56745A-F6A4-C51C-933A-AD96C00683EA}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Universal CRT Redistributable (HKLM-x32\...\{A57CD0A6-4297-FD30-34A4-34758B6F5F69}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Universal CRT Tools x64 (HKLM\...\{CD06199B-41C1-AE6D-7567-984CC68792C3}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Universal CRT Tools x86 (HKLM-x32\...\{BD75F257-50A4-E0CD-9942-C3550CA3E66A}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Universal General MIDI DLS Extension SDK (HKLM-x32\...\{A7E95C47-B5F4-110C-D27A-DECB03412B96}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
vcpp_crt.redist.clickonce (HKLM-x32\...\{3355CB81-69C6-402C-A17D-4F6ED56F0904}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Vim 8.2 (HKLM\...\Vim 8.2) (Version: 8.2 - Bram Moolenaar et al.)
Visual Studio Community 2022 (HKLM-x32\...\203cec07) (Version: 17.1.5 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.16 - VideoLAN)
VS Immersive Activate Helper (HKLM-x32\...\{C0ACF658-B4DC-4CBB-B8F2-9E667D69919A}) (Version: 17.0.114.0 - Microsoft Corporation) Hidden
VS JIT Debugger (HKLM\...\{43F73608-5C94-436F-A1E6-E09ACE680391}) (Version: 17.0.114.0 - Microsoft Corporation) Hidden
VS Script Debugging Common (HKLM\...\{9EC852BD-33D2-457C-99BB-ED3099B8176F}) (Version: 17.0.114.0 - Microsoft Corporation) Hidden
vs_BlendMsi (HKLM-x32\...\{2D12F791-263F-4ABA-B7A8-5485933CADCF}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsi (HKLM-x32\...\{B8B0A861-C76A-4DBA-B8D5-8830511173A3}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsires (HKLM-x32\...\{16946E6F-037E-4A92-A30C-80293603EEC9}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_clickoncesigntoolmsi (HKLM-x32\...\{15CE6C23-B92A-4B2B-8521-6FA81661068B}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_communitymsires (HKLM-x32\...\{FB7E08F6-56D3-43A6-B2EE-BCDF09A73574}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_communitysharedmsi (HKLM-x32\...\{7571C303-621A-4ACF-A392-BD6B9B3C67BF}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_communityx64msi (HKLM\...\{EB7405ED-A99C-47D4-8516-C5C35704B07C}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_CoreEditorFonts (HKLM-x32\...\{D9559A61-5275-4476-8A1A-BD571F72E094}) (Version: 17.1.32414 - Microsoft Corporation) Hidden
vs_devenvsharedmsi (HKLM-x32\...\{923446B9-70EB-4850-95D7-1A1AB5D111CD}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_devenx64vmsi (HKLM\...\{5C99AE76-BEF9-4D4B-A77A-1B63238B86B0}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_filehandler_amd64 (HKLM-x32\...\{2C910925-05EE-403B-8295-D2593E11F751}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_filehandler_x86 (HKLM-x32\...\{46F71CD4-4841-4B77-A491-9933B98F8D0D}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_FileTracker_Singleton (HKLM-x32\...\{9DCCEEF7-CC00-4054-9879-7E0A12E5CF0A}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_Graphics_Singletonx64 (HKLM\...\{16FEBEAC-D39B-4E57-917E-B3DD174DBF7F}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_Graphics_Singletonx86 (HKLM-x32\...\{24DFA481-19D7-4B5B-AB77-89BB3D984019}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_minshellinteropsharedmsi (HKLM-x32\...\{05A82EA9-8768-4E1B-B16C-FCCF299D331C}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_minshellinteropx64msi (HKLM\...\{FB59095C-C7C6-4CA6-B300-852B50AB976D}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_minshellmsires (HKLM-x32\...\{FF8BEC95-383B-4B10-A69E-AE78BA76B903}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_minshellsharedmsi (HKLM-x32\...\{FEFEDA38-9B6A-4374-8D43-7D5517152080}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_minshellx64msi (HKLM\...\{CC15CA94-9817-4914-A9ED-A694A2F27783}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_SQLClickOnceBootstrappermsi (HKLM-x32\...\{4EF9011A-8E81-4D6F-9CB9-DBF0B1B12809}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_tipsmsi (HKLM-x32\...\{874561BE-97AD-4865-8512-579D41009147}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
WinAppDeploy (HKLM-x32\...\{2ADF1977-BF31-E127-B651-AC28A8658317}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinDjView 2.1 (HKLM\...\WinDjView) (Version: 2.1 - Andrew Zhezherun)
Windows SDK AddOn (HKLM-x32\...\{E18618EC-D9DB-4BCE-B382-85ADA2CBB340}) (Version: 10.1.0.0 - Microsoft Corporation)
Windows Software Development Kit - Windows 10.0.19041.685 (HKLM-x32\...\{4591faf1-a2db-4a3d-bfda-aa5a4ebb1587}) (Version: 10.1.19041.685 - Microsoft Corporation)
WinRT Intellisense Desktop - en-us (HKLM-x32\...\{BCF7CA0F-E53C-2A4F-B128-A751EC9A1016}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense Desktop - Other Languages (HKLM-x32\...\{B42BF427-AFDB-C00F-DB60-6F51395D74A1}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - en-us (HKLM-x32\...\{3335615C-ABEB-960E-2226-4274CD28E046}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - Other Languages (HKLM-x32\...\{216D5F47-257D-6284-5849-B51037875EFA}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense Mobile - en-us (HKLM-x32\...\{443FF51E-16C3-F23B-18FC-0D1D66024B0B}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - en-us (HKLM-x32\...\{15E29AFF-CB19-A20B-9A81-B0765A63115F}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - Other Languages (HKLM-x32\...\{FF2B49B7-0254-3D6A-4BE0-EF4C59DBCC2B}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - en-us (HKLM-x32\...\{0AF3B821-474B-1885-473A-6E3FB4F1CF71}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - Other Languages (HKLM-x32\...\{8832F8ED-1035-9ABE-FD73-4E5ABAA84A5C}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Xshell 7 (HKLM-x32\...\{2C5F58B0-1BF6-4BD3-A665-C1B5206BDC17}) (Version: 7.0.0099 - NetSarang Computer, Inc.) Hidden
Xshell 7 (HKLM-x32\...\InstallShield_{2C5F58B0-1BF6-4BD3-A665-C1B5206BDC17}) (Version: 7.0.0099 - NetSarang Computer, Inc.)
百度网盘 (HKLM-x32\...\百度云管家) (Version: 7.14.1 - 北京度友科技有限公司)
欧路词典 (HKLM-x32\...\eudic) (Version: 12.0.0.0 - 欧路软件)
腾讯QQ (HKLM-x32\...\{052CFB79-9D62-42E3-8A15-DE66C2C97C3E}) (Version: 9.5.8.28186 - 腾讯科技(深圳)有限公司)
腾讯会议 (HKLM-x32\...\WeMeet) (Version: 3.7.6.404 - 腾讯科技(深圳)有限公司)
网易UU (HKLM-x32\...\NeteaseGacc) (Version: 4.22.0.50 - 网易公司)
网易云音乐 (HKLM-x32\...\网易云音乐) (Version: 2.9.8.199759 - 网易公司)
微信 (HKLM-x32\...\WeChat) (Version: 3.6.0.18 - 腾讯科技(深圳)有限公司)
 
Packages:
=========
AV1 Video Extension -> C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.1.50332.0_x64__8wekyb3d8bbwe [2022-03-20] (Microsoft Corporation)
Energy Star -> C:\Program Files\WindowsApps\AD2F1837.HPInc.EnergyStar_1.2.0.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.)
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_1.8.1.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.)
HP Privacy Settings -> C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.0.42.0_x64__v10z8vjag6ke6 [2022-03-21] (HP Inc.)
HP QuickDrop -> C:\Program Files\WindowsApps\AD2F1837.HPQuickDrop_2.5.9180.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_135.1.385.0_x64__v10z8vjag6ke6 [2022-03-22] (HP Inc.)
HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.15.66.0_x64__v10z8vjag6ke6 [2022-04-07] (HP Inc.)
HP System Event Utility -> C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_1.2.15.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.)
Intel® Graphics Command Center -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3408.0_x64__8j3eq9eme6ctt [2022-04-20] (INTEL CORP) [Startup Task]
Microsoft To Do -> C:\Program Files\WindowsApps\Microsoft.Todos_2.68.51091.0_x64__8wekyb3d8bbwe [2022-04-20] (Microsoft Corporation) [Startup Task]
Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_52.10404.374.0_x64__8wekyb3d8bbwe [2022-04-07] (Microsoft Corporation)
myHP -> C:\Program Files\WindowsApps\AD2F1837.myHP_1.10.53228.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.) [Startup Task]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-03-20] (NVIDIA Corp.)
OMEN Audio Control -> C:\Program Files\WindowsApps\AD2F1837.OMENAudioControl_1.29.257.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.)
OMEN Gaming Hub -> C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6 [2022-03-27] (HP Inc.) [Startup Task]
OMEN Light Studio -> C:\Program Files\WindowsApps\AD2F1837.OMENLightStudio_0.3.10.0_x64__v10z8vjag6ke6 [2022-04-09] (HP Inc.) [Startup Task]
Power Automate -> C:\Program Files\WindowsApps\Microsoft.PowerAutomateDesktop_10.0.3444.0_x64__8wekyb3d8bbwe [2022-04-01] (Microsoft Corporation) [Startup Task]
Python 3.10 -> C:\Program Files\WindowsApps\PythonSoftwareFoundation.Python.3.10_3.10.1264.0_x64__qbz5n2kfra8p0 [2022-03-25] (Python Software Foundation)
Snipaste -> C:\Program Files\WindowsApps\45479liulios.17062D84F7C46_2.7.3.0_x64__p7pnf6hceqser [2022-03-20] (Le Liu) [Startup Task]
惠普优享服务 -> C:\Program Files\WindowsApps\AD2F1837.E-QRcode_1.0.16.0_x64__v10z8vjag6ke6 [2022-03-21] (HP Inc.)
惠小微 -> C:\Program Files\WindowsApps\AD2F1837.19285F10D180_2.3.132.0_x64__v10z8vjag6ke6 [2022-04-20] (HP Inc.) [Startup Task]
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{3D3B1846-CC43-42AE-BFF9-D914083C2BA3}\InprocServer32 -> C:\Users\YuchenTong\AppData\Local\SumatraPDF\PdfPreview.dll () [File not signed]
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{55808EA8-81FE-43c6-AAE8-1D8149F941D3}\InprocServer32 -> C:\Users\YuchenTong\AppData\Local\SumatraPDF\PdfFilter.dll () [File not signed]
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{679F137C-3162-45da-BE3C-2F9C3D093F64}\Shell\Open\Command -> C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{679F137C-3162-45da-BE3C-2F9C3D093F64} -> [百度网盘] => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\ [0000-00-00 00:00]
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32 ->  => No File
ShellIconOverlayIdentifiers: [      .WorkspaceExt0] -> {C568C78A-652C-425B-8E6B-FFA73043302D} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ShellIconOverlayIdentifiers: [      .WorkspaceExt1] -> {2A6FE247-5DA3-4732-9626-77820518FD77} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ShellIconOverlayIdentifiers: [      .WorkspaceExt2] -> {FF895810-293B-464A-93F2-82D11E07EEC8} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ShellIconOverlayIdentifiers: [      .WorkspaceExt3] -> {D8BE1E70-244A-46F0-BC5B-077D5F29EED8} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [cloudmusic] -> {5C6A637C-9780-4D0F-A379-4732EDCCE7C3} =>  -> No File
ContextMenuHandlers1: [gvim] -> {51EEE242-AD87-11d3-9C1E-0090278BBD99} => C:\Program Files (x86)\Vim\vim82\GvimExt64\gvimext.dll [2021-05-03] (Tianmiao Hu's Developer Studio) [File not signed]
ContextMenuHandlers1: [YunShellExt] -> {6D85624F-305A-491d-8848-C1927AA0D790} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ContextMenuHandlers3: [QQShellExt] -> {53D2405C-48AB-4C8A-8F59-CE0610F13BBC} => C:\Program Files (x86)\Tencent\QQ\ShellExt\QQShellExt64.dll [2022-03-20] (Tencent Technology(Shenzhen) Company Limited -> Tencent)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [YunShellExt] -> {6D85624F-305A-491d-8848-C1927AA0D790} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\windows\System32\DriverStore\FileRepository\nvhm.inf_amd64_b5eab67518a4faa8\nvshext.dll [2022-01-27] (Nvidia Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [QQShellExt] -> {53D2405C-48AB-4C8A-8F59-CE0610F13BBC} => C:\Program Files (x86)\Tencent\QQ\ShellExt\QQShellExt64.dll [2022-03-20] (Tencent Technology(Shenzhen) Company Limited -> Tencent)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\YuchenTong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Anaconda3 (64-bit)\Anaconda Prompt (anaconda3).lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> "/K" C:\Users\YuchenTong\anaconda3\Scripts\activate.bat C:\Users\YuchenTong\anaconda3
 
==================== Loaded Modules (Whitelisted) =============
 
2022-03-10 23:23 - 2022-03-10 23:23 - 001469440 _____ () [File not signed] C:\Program Files\WindowsApps\AD2F1837.HPQuickDrop_2.5.9180.0_x64__v10z8vjag6ke6\e_sqlite3.dll
2022-03-10 23:26 - 2022-03-10 23:26 - 000009216 _____ () [File not signed] C:\Program Files\WindowsApps\AD2F1837.myHP_1.10.53228.0_x64__v10z8vjag6ke6\ImagePipelineNative.dll
2022-03-10 23:25 - 2022-03-10 23:26 - 000033280 _____ () [File not signed] C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\NvidiaApi.dll
2020-10-22 18:05 - 2020-10-22 18:05 - 002812416 _____ () [File not signed] C:\Users\YuchenTong\Documents\Clash.for.Windows-0.12.1\ffmpeg.dll
2020-10-22 18:05 - 2020-10-22 18:05 - 000465408 _____ () [File not signed] C:\Users\YuchenTong\Documents\Clash.for.Windows-0.12.1\swiftshader\libegl.dll
2020-10-22 18:05 - 2020-10-22 18:05 - 003177984 _____ () [File not signed] C:\Users\YuchenTong\Documents\Clash.for.Windows-0.12.1\swiftshader\libglesv2.dll
2022-03-22 15:05 - 2022-03-22 15:05 - 000138240 _____ () [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_32\Interop.IWs06dcaa36#\f90e72b12d0aa935d781e317202c1f9b\Interop.IWshRuntimeLibrary.ni.dll
2022-03-20 15:06 - 2022-03-20 15:06 - 000107008 _____ (Facebook, Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.myHP_1.10.53228.0_x64__v10z8vjag6ke6\yoga.dll
2022-03-22 12:59 - 2022-03-22 12:59 - 000139776 _____ (hardcodet.net) [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_32\Hardcodet.W6cab32f3#\07cc04e050bf3a2b713a6738ca1e8d65\Hardcodet.Wpf.TaskbarNotification.ni.dll
2022-03-20 15:03 - 2022-03-20 15:03 - 004086784 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.HPQuickDrop_2.5.9180.0_x64__v10z8vjag6ke6\core.pwa.dll
2022-03-20 15:03 - 2022-03-20 15:03 - 054239232 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.HPQuickDrop_2.5.9180.0_x64__v10z8vjag6ke6\HPQuickDrop.dll
2022-03-10 23:23 - 2022-03-10 23:23 - 000014336 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_1.2.15.0_x64__v10z8vjag6ke6\SystemEventUtility\NativeRpcClient.DLL
2022-03-10 23:26 - 2022-03-10 23:26 - 000014848 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.myHP_1.10.53228.0_x64__v10z8vjag6ke6\NativeRpcClient.dll
2022-03-26 18:51 - 2022-03-26 18:51 - 008441344 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\OmenCommandCenterApp_UWP.dll
2022-03-10 23:25 - 2022-03-10 23:26 - 000014848 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\NativeRpcClient.DLL
2022-03-20 14:08 - 2021-12-26 22:00 - 000093696 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2022-03-22 15:05 - 2022-03-22 15:05 - 001716736 _____ (Mark Heath & Contributors) [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_32\NAudio\343277c8ff5a08dd62ebb4ad5af2f83a\NAudio.ni.dll
2022-03-20 15:01 - 2022-03-20 15:01 - 000137168 _____ (Microsoft Windows -> Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_421.20070.95.0_x64__cw5n1h2txyewy\Dashboard\WebView2Loader.dll
2022-03-22 15:05 - 2022-03-22 15:05 - 003087360 _____ (Newtonsoft) [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\ec86693079e180f87ce3d207adb00ef8\Newtonsoft.Json.ni.dll
2022-03-21 15:32 - 2022-03-21 15:32 - 003864576 _____ (Newtonsoft) [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_64\Newtonsoft.Json\1cf4295c15101db684576474e0b8a99d\Newtonsoft.Json.ni.dll
2022-03-10 23:26 - 2022-03-10 23:26 - 001662976 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\SQLite.Interop.dll
2022-04-14 18:15 - 2022-04-14 18:15 - 000780288 _____ (The Apache Software Foundation) [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_32\log4net\e778c533c97b157a48ab38caf5383865\log4net.ni.dll
2021-05-03 06:12 - 2021-05-03 06:12 - 000075264 _____ (Tianmiao Hu's Developer Studio) [File not signed] C:\Program Files (x86)\Vim\vim82\GvimExt64\gvimext.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:341E39B2 [390]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HipsDaemon => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.baidu.com/?tn=67074732_5_dg
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.baidu.com/?tn=67074732_5_dg
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://www.baidu.com/?tn=67074732_5_dg
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://www.baidu.com/?tn=67074732_5_dg
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.baidu.com/?tn=67074732_5_dg
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://www.baidu.com/?tn=67074732_5_dg
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
SearchScopes: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
SearchScopes: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2022-03-28] (HP Inc. -> HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2022-03-20] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2022-03-28] (HP Inc. -> HP Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2021-06-05 20:08 - 2022-04-19 15:31 - 000000824 _____ C:\windows\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Common Files\Oracle\Java\javapath;C:\windows\system32;C:\windows;C:\windows\System32\Wbem;C:\windows\System32\WindowsPowerShell\v1.0\;C:\windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;".;C:\Program Files\Java\jdk-17.0.2\bin";C:\Program Files\Git\cmd;C:\Program Files\Maven\bin;C:\msys64\mingw64\bin;C:\Program Files (x86)\NetSarang\Xshell 7\;C:\Program Files (x86)\Vim\vim82;C:\Program Files\Graphviz\bin;C:\Program Files\dotnet\
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\Control Panel\Desktop\\Wallpaper -> C:\windows\web\wallpaper\HP Backgrounds\backgroundDefault.jpg
DNS Servers: 116.228.111.18 - 180.168.255.118
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
 
Network Binding:
=============
以太网: Realtek LightWeight Filter (NDIS6.40) -> nt_rtf64 (enabled) 
WLAN: Realtek LightWeight Filter (NDIS6.40) -> nt_rtf64 (enabled) 
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
MSCONFIG\Services: BaiduNetdiskUtility => 3
MSCONFIG\Services: QQMusicService => 2
MSCONFIG\Services: SangforPWEx => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: WemeetUpdateSvc => 3
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKLM\...\StartupApproved\Run32: => "WPSPhotoPreInstallSetApp"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "HPSEU_Host_Launcher"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_0817AD55560C87EB70CBDEDADDDAA235"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "BaiduYunDetect"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{7DA42E6B-2E4A-4603-BD32-33394265AF12}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{C5302DBF-3633-43E8-8AB7-8EEE79270ED5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{BC737163-9A5C-45B4-ABF1-1B21DB0EC3FB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{11BBA3E3-5B4F-455A-9318-F21B682B304D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{F970D206-F5CF-43DA-B68F-0643C7A782BF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{2CEB1D1D-2389-42FE-AB53-6D12F19F545D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{AABED6A8-8D35-4B50-AF61-4629E56B5012}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{376DE13E-169B-469F-AD3B-C60242A30A21}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MinecraftEducationEdition_1.17.3200.0_x64__8wekyb3d8bbwe\Minecraft.Windows.exe (Microsoft Corporation -> )
FirewallRules: [{0A44B6AC-7971-4D3E-91DD-762241E31550}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MinecraftEducationEdition_1.17.3200.0_x64__8wekyb3d8bbwe\Minecraft.Windows.exe (Microsoft Corporation -> )
FirewallRules: [{DF60C237-4869-49C7-ABF3-AEFC61413F89}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{EB4D9AD9-7535-47AA-88D1-40AE3F0B7AFA}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{C68430DB-90F0-47E6-A83E-6FB0EC79A8EA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{CF0A5F2F-173A-415E-8595-973A5103E25C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{407EBEE8-586E-44DA-AC79-CDB22EE88008}] => (Allow) C:\Users\YuchenTong\AppData\Roaming\Tencent\QQ\STemp\SetupEx0\QQSetupEx.exe => No File
FirewallRules: [{C264AC50-88C8-4F61-816E-3E15AEF360A1}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChat.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{F5F15141-729F-4061-AC3C-28A231AD7244}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChatBrowser.exe => No File
FirewallRules: [{8811352F-0F21-413C-BABD-F4732E9ADF5F}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChatPlayer.exe => No File
FirewallRules: [{AF764A94-8E75-4BC8-BD06-9C7D4C5122D1}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\QQ.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{D6044CF9-8F2D-43FB-BE68-F064174A71F7}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\auclt.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{C5247D6D-FB17-4CCE-8E0B-CD6FFAD096CE}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\txupd.exe => No File
FirewallRules: [{AF7A5B46-779B-4DAC-B689-B9B7765E969F}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\SetupEx\SetupEx.exe => No File
FirewallRules: [{9782185C-FD83-409B-BDA3-5BDD470AB62B}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\maLauncher.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{4F30B925-E2B9-46E6-8952-3F92D7E1C819}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\maUpdat.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{A4DB6BA3-8BC0-44E0-8756-C5C015ED7372}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\tencentdl.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{B0850279-AAE9-483D-853A-8FC76EE38A7B}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\bugreport_xf.exe => No File
FirewallRules: [{5427E81C-5694-4528-BBBD-D6EBEE366BAD}] => (Allow) C:\Program Files (x86)\Tencent\QzoneMusic\QzoneMusic.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{3861EAEE-F630-49C8-A6BE-191C9C1C252C}] => (Allow) C:\Program Files (x86)\Tencent\QzoneMusic\QzoneMusic.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{093FE8BB-0901-43B0-8F90-A8D870AFDD79}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{6B67F1BA-1B52-44EB-B85D-B66A6CA92E01}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{FAB2A499-0EF2-4DA8-88D2-40591D2EC8D0}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{E70E4EF2-E813-4B2D-9061-55B96A388EC3}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{67012569-302A-452D-A0C3-A487F621A13B}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{C7F108E5-60BF-4833-A2C1-A8C00030FF1D}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{11505E1C-E96E-4007-B5AD-4F5CB10C1BCE}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\QQMusicExternal.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{A9B90926-A38D-4E14-970A-2B5E79E8A7BA}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\moleplugin\tadb.exe => No File
FirewallRules: [{5988EB3C-59B5-4376-A6C6-97F7620E5FC8}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\QQMusic.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{E83F1526-EB2D-4695-AC4B-BBC06E782ED6}] => (Allow) C:\Program Files (x86)\Common Files\Tencent\QQMusic\QQMusicService.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{40290690-C5EE-4DFB-BA04-EBCC066528C1}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\QQMusicUp.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [TCP Query User{F2E1C50A-6D84-4D3E-8889-1A43B91C71BB}C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe] => (Allow) C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [UDP Query User{7BD18DC9-231D-4E7C-A781-5EE2B12FE770}C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe] => (Allow) C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [{327AA125-513C-4A38-BF95-397134680FF1}] => (Block) C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [{D1D80284-A1F3-43F5-AE87-BB5F9A1D67F5}] => (Block) C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [TCP Query User{34363D0E-9FD6-4774-82BC-49FE16C44C85}C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe] => (Allow) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [UDP Query User{9240DCA0-AA58-4927-84F9-1DF9B3B6BAFD}C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe] => (Allow) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{A20CDAC6-BD71-40DD-B56B-27075D32DE6B}] => (Block) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{BB5D847A-AE63-4FB0-B969-E0D8D47E9295}] => (Block) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{5795EF24-9E37-4660-A24A-09A4B33BCB6C}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{E75F919B-CE28-4E17-B87E-9566491E3B34}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{9C8D4A57-B737-41A6-8CD9-F00F3A1C800A}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{D255A953-912A-49FC-A58B-44062CE71382}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{E4B2C5D0-3CB0-4751-A3BC-B329083B62E5}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{BEF34DD4-72E5-4F0F-8326-17BDC238DD3B}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{99DA3C15-7861-4C1A-A330-5B7A89EB16D7}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{84893C49-229A-486F-82B4-9A5C30DC1EC5}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{00F79B13-3147-4C92-A761-6EAB01FFB466}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{D7B70C93-A850-4FFD-9F74-12DA065AA17C}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{DB33C006-A66E-4960-A82E-1ABBF512E561}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{8934BD8C-6C46-4737-BE82-F291942CB4AA}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{DA24735B-944E-45DE-8C3C-F50D894C75E0}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{CE6F8D98-94BC-41AF-A030-72802F9190F3}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{FE98FCB4-B513-467C-AF28-58580501F381}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\OmenCommandCenterBackground.exe (HP Inc. -> HP Inc.)
FirewallRules: [{34A24C60-05BC-42BE-9928-23C688E809E6}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\OmenCommandCenterBackground.exe (HP Inc. -> HP Inc.)
FirewallRules: [TCP Query User{47CEB3A3-1D58-4A92-9CA3-B70657680F46}C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe] => (Allow) C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
FirewallRules: [UDP Query User{C6B8D1BC-92DE-44EB-B6F7-E354C7C45506}C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe] => (Allow) C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
FirewallRules: [{52798339-0303-44C1-B25F-729F0CDA2CCD}] => (Block) C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
FirewallRules: [{FF185082-441F-4E47-93B0-06779E897EB1}] => (Block) C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
FirewallRules: [{84C1F3DE-C1B4-4AB4-A039-7D7C4A3B543C}] => (Allow) C:\Program Files (x86)\Foxit Software\FoxitREC\FoxitREC.exe => No File
FirewallRules: [{071CA9CC-73A8-4D6C-B496-E560AED35BBB}] => (Allow) C:\Program Files (x86)\Foxit Software\FoxitREC\FoxitREC.exe => No File
FirewallRules: [TCP Query User{9668B88F-6F98-4212-86E2-F27711E0A03D}C:\program files (x86)\netease\cloudmusic\cloudmusic.exe] => (Allow) C:\program files (x86)\netease\cloudmusic\cloudmusic.exe (NetEase (Hangzhou) Network Co., Ltd -> NetEase)
FirewallRules: [UDP Query User{66A86057-1953-4770-A1ED-B4F58ACED3E7}C:\program files (x86)\netease\cloudmusic\cloudmusic.exe] => (Allow) C:\program files (x86)\netease\cloudmusic\cloudmusic.exe (NetEase (Hangzhou) Network Co., Ltd -> NetEase)
FirewallRules: [{5C5511D8-FE64-464D-9063-AF8039C17ADE}] => (Block) C:\program files (x86)\netease\cloudmusic\cloudmusic.exe (NetEase (Hangzhou) Network Co., Ltd -> NetEase)
FirewallRules: [{8B3B7A11-4E9D-4E60-99B3-953DE850A264}] => (Block) C:\program files (x86)\netease\cloudmusic\cloudmusic.exe (NetEase (Hangzhou) Network Co., Ltd -> NetEase)
FirewallRules: [{62FC4BCB-D741-4E90-914A-6C5E2A4FBDD8}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\XshellCore.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [{3C611267-694B-4BEB-A738-2DE55B283956}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\XshellCore.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [{4861606D-0EFE-41BA-B406-FB38D026FD92}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\Xshell.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [{AFFFA755-4CE6-4F1C-BEC0-9FF5F3DE21C5}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\Xshell.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [{A67C93E0-E727-4778-A399-2DBC11048DDB}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\Xagent.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [{A96C2BD6-C420-4F76-A1D4-703C178D17D3}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\Xagent.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [TCP Query User{40F5216D-05C5-41FA-BAD3-9B4ECB8FAE4C}C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [UDP Query User{B25A318C-65EF-43D5-AD6A-D804E8CDC99D}C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [TCP Query User{12414319-2366-46B5-A707-FF93AA924B4F}C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe => No File
FirewallRules: [UDP Query User{14B1CED0-2B7A-4F20-8070-B08FF22EAF7E}C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe => No File
FirewallRules: [{DAF1A415-8652-4441-BB68-EA7A31779DDE}] => (Block) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [{D1476AD9-9E5C-4BE0-B4F4-6B1CE3F79BD1}] => (Block) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [TCP Query User{8655244C-E20B-4902-8651-6F13636F5B50}C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe] => (Allow) C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [UDP Query User{BCE0367A-79C1-412D-8C89-801ABF60276B}C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe] => (Allow) C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [{969D9781-DD38-4DB9-B430-6527845855C7}] => (Block) C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [{82700716-2DC1-4C2C-A31F-95CB71CBC280}] => (Block) C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [TCP Query User{62EE4435-74ED-4BEC-BEE7-21969B6BADDB}C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe] => (Allow) C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{142CBB55-F714-4B3A-9F57-7583FF133063}C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe] => (Allow) C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{EE88E1C8-CA35-4A0B-9B8B-74F2ED9B7506}] => (Block) C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{49BD33B2-2B4D-4825-B904-2AD708376B68}] => (Block) C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4A54105F-D224-47FB-B1AB-ED55784013CA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crusader Kings III\launcher\dowser.exe => No File
FirewallRules: [{A32C8932-5E39-4587-94C2-5C5DB268F55C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crusader Kings III\launcher\dowser.exe => No File
FirewallRules: [TCP Query User{AD721708-BE92-4E5D-A6CC-E4CD835B5E5A}C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [UDP Query User{6724343B-004C-4028-B1CF-77F9BD0EB442}C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [{FABCF631-6EEC-4871-B727-55313768CF50}] => (Block) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [{B4362568-E511-4425-B943-F508CC561AF2}] => (Block) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [{48CBA06F-8670-4721-8E9F-C8BBCAEF7090}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Europa Universalis IV\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [{55792C4E-7555-472C-A63E-B63CC2F0F26B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Europa Universalis IV\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [{F5C08878-CD46-49D2-9A10-6000C5E652DA}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\100.0.1185.44\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
 
==================== Restore Points =========================
 
23-04-2022 18:15:29 Install : Huorong Internet Security
23-04-2022 22:32:26 Checkpoint by HitmanPro
23-04-2022 22:32:35 Checkpoint by HitmanPro
24-04-2022 14:12:37 Removed RPGXP
24-04-2022 14:13:10 Removed RGSS-RTP Standard
24-04-2022 14:51:19 Removed HP Audio Switch
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (04/24/2022 06:35:36 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 explorer.exe 版本 10.0.22000.593 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
 
进程 ID: 14e4
 
开始时间: 01d857c69f1b5485
 
终止时间: 0
 
应用程序路径: C:\Windows\explorer.exe
 
报告 ID: 6ec662ff-f22b-45bf-8594-25659d059a83
 
错误程序包全名: 
 
错误程序包相关应用程序 ID: 
 
挂起类型: Unknown
 
Error: (04/24/2022 06:30:10 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 explorer.exe 版本 10.0.22000.593 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
 
进程 ID: 1d1c
 
开始时间: 01d857c60d5afa81
 
终止时间: 0
 
应用程序路径: C:\Windows\explorer.exe
 
报告 ID: 7ce8c847-6c2c-4dca-8d16-db5d98eb4225
 
错误程序包全名: 
 
错误程序包相关应用程序 ID: 
 
挂起类型: Unknown
 
Error: (04/24/2022 03:26:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: 错误应用程序名称: DllHost.exe,版本: 10.0.22000.1,时间戳: 0x93f44fbf
错误模块名称: ntdll.dll,版本: 10.0.22000.527,时间戳: 0x931cda92
异常代码: 0xc0000374
错误偏移量: 0x000000000010c0a9
错误进程 ID: 0x2320
错误应用程序启动时间: 0x01d857a867978429
错误应用程序路径: C:\windows\system32\DllHost.exe
错误模块路径: C:\windows\SYSTEM32\ntdll.dll
报告 ID: 6cf746ae-a3cd-4403-a3be-ef08e412a49e
错误程序包全名: 
错误程序包相对应用程序 ID:
 
Error: (04/24/2022 03:02:25 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 explorer.exe 版本 10.0.22000.593 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
 
进程 ID: 1c24
 
开始时间: 01d857a86711a04d
 
终止时间: 0
 
应用程序路径: C:\Windows\explorer.exe
 
报告 ID: 63f5213e-c01b-4e9e-9a50-16a50132905e
 
错误程序包全名: 
 
错误程序包相关应用程序 ID: 
 
挂起类型: Unknown
 
Error: (04/24/2022 02:50:15 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 gsam.exe 版本 4.2.33.5534 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
 
进程 ID: 26dc
 
开始时间: 01d857a4a1240029
 
终止时间: 4294967295
 
应用程序路径: C:\Program Files\GridinSoft Anti-Malware\gsam.exe
 
报告 ID: 9c19e33b-79f9-46e0-9d3b-295a1bb3e943
 
错误程序包全名: 
 
错误程序包相关应用程序 ID: 
 
挂起类型: Top level window is idle
 
Error: (04/24/2022 12:46:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 explorer.exe 版本 10.0.22000.593 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
 
进程 ID: 3478
 
开始时间: 01d857962cde2fb6
 
终止时间: 0
 
应用程序路径: C:\Windows\explorer.exe
 
报告 ID: 0ea12574-6c78-4bda-9fa7-731c49ad7ca2
 
错误程序包全名: 
 
错误程序包相关应用程序 ID: 
 
挂起类型: Unknown
 
Error: (04/24/2022 12:43:03 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 explorer.exe 版本 10.0.22000.593 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
 
进程 ID: 4304
 
开始时间: 01d857958f0dfafa
 
终止时间: 0
 
应用程序路径: C:\Windows\explorer.exe
 
报告 ID: 922ec38f-127d-4ed6-b1c2-ef502970cd4e
 
错误程序包全名: 
 
错误程序包相关应用程序 ID: 
 
挂起类型: Unknown
 
Error: (04/23/2022 10:32:26 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 卷影复制服务错误: 查询 IVssWriterCallback 接口时的错误。hr = 0x80070005, 拒绝访问。
此错误通常是由编写器或请求方过程中的错误安全设置造成的。
 
 
操作:
   正在搜集写入程序数据
 
上下文:
   写入程序类 ID: {e8132975-6f93-4464-a53e-1050253ae220}
   写入程序名称: System Writer
   写入程序实例 ID: {9ebd2d2b-bcad-4118-ab84-84e7bc4e097f}
 
 
System errors:
=============
Error: (04/24/2022 09:03:42 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。 
 SSPI 客户端进程 FRST64english (PID: 14680)。
 
Error: (04/24/2022 09:03:42 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。 
 SSPI 客户端进程 FRST64english (PID: 14680)。
 
Error: (04/24/2022 09:03:39 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。 
 SSPI 客户端进程 smartscreen (PID: 6624)。
 
Error: (04/24/2022 09:03:39 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。 
 SSPI 客户端进程 smartscreen (PID: 6624)。
 
Error: (04/24/2022 08:29:43 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。 
 SSPI 客户端进程 Widgets (PID: 3076)。
 
Error: (04/24/2022 08:29:43 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。 
 SSPI 客户端进程 Widgets (PID: 3076)。
 
Error: (04/24/2022 08:18:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: 由于下列错误,WinRing0_1_2_0 服务启动失败: 
WinRing0_1_2_0 不是有效的 Win32 应用程序。
 
Error: (04/24/2022 08:14:41 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。 
 SSPI 客户端进程 HP.myHP (PID: 2836)。
 
 
Windows Defender:
================
Date: 2022-04-24 20:13:45
Description: 
Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。
有关详细信息,请参阅以下内容:
名称: VirTool:Win32/ExcludeProc.D
严重性: 严重
类别: 工具
路径: CmdLine:_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4ARQB4AHQAZQBuAHMAaQBvAG4AIABAACgAJwBlAHgAZQAnACwAJwBkAGwAbAAnACkAIAAtAEYAbwByAGMAZQA=
检测起源: 未知
检测类型: 实际
检测源: 系统
用户: NT AUTHORITY\SYSTEM
进程名称: Unknown
安全智能版本: AV: 1.363.863.0, AS: 1.363.863.0, NIS: 1.363.863.0
引擎版本: AM: 1.1.19200.5, NIS: 1.1.19200.5
 
Date: 2022-04-24 20:13:45
Description: 
Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。
有关详细信息,请参阅以下内容:
名称: Behavior:Win32/ExcludeProc.A
严重性: 严重
类别: 可疑行为
路径: behavior:_pid:13980:23860413273102; process:_pid:13980,ProcessStart:132952760257624314
检测起源: 未知
检测类型: 实际
检测源: 未知
用户: 
进程名称: Unknown
安全智能版本: AV: 1.363.863.0, AS: 1.363.863.0, NIS: 1.363.863.0
引擎版本: AM: 1.1.19200.5, NIS: 1.1.19200.5
 
Date: 2022-04-24 20:13:45
Description: 
Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。
有关详细信息,请参阅以下内容:
名称: VirTool:Win32/ExcludeProc.D
严重性: 严重
类别: 工具
路径: CmdLine:_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwAJABlAG4AdgA6AFMAeQBzAHQAZQBtAEQAcgBpAHYAZQApACAALQBGAG8AcgBjAGUA
检测起源: 未知
检测类型: 实际
检测源: 系统
用户: NT AUTHORITY\SYSTEM
进程名称: Unknown
安全智能版本: AV: 1.363.863.0, AS: 1.363.863.0, NIS: 1.363.863.0
引擎版本: AM: 1.1.19200.5, NIS: 1.1.19200.5
 
Date: 2022-04-24 19:07:33
Description: 
Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。
有关详细信息,请参阅以下内容:
名称: Behavior:Win32/ExcludeProc.A
严重性: 严重
类别: 可疑行为
路径: behavior:_pid:5228:23860413273102; process:_pid:5228,ProcessStart:132952720529782387
检测起源: 未知
检测类型: 实际
检测源: 未知
用户: 
进程名称: Unknown
安全智能版本: AV: 1.363.863.0, AS: 1.363.863.0, NIS: 1.363.863.0
引擎版本: AM: 1.1.19200.5, NIS: 1.1.19200.5
 
Date: 2022-04-24 19:07:33
Description: 
Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。
有关详细信息,请参阅以下内容:
名称: VirTool:Win32/ExcludeProc.D
严重性: 严重
类别: 工具
路径: CmdLine:_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4ARQB4AHQAZQBuAHMAaQBvAG4AIABAACgAJwBlAHgAZQAnACwAJwBkAGwAbAAnACkAIAAtAEYAbwByAGMAZQA=
检测起源: 未知
检测类型: 实际
检测源: 系统
用户: NT AUTHORITY\SYSTEM
进程名称: Unknown
安全智能版本: AV: 1.363.863.0, AS: 1.363.863.0, NIS: 1.363.863.0
引擎版本: AM: 1.1.19200.5, NIS: 1.1.19200.5

CodeIntegrity:
===============
Date: 2022-04-24 15:55:25
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2022-04-24 13:16:31
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNspX64.dll that did not meet the Windows signing level requirements.
 
Date: 2022-04-24 13:15:04
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNspX64.dll that did not meet the Windows signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: AMI F.05 03/10/2022
Motherboard: HP 8A13
Processor: 12th Gen Intel® Core™ i7-12700H
Percentage of memory in use: 39%
Total physical RAM: 16051.95 MB
Available physical RAM: 9779.8 MB
Total Virtual: 18483.95 MB
Available Virtual: 10846.68 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:476.03 GB) (Free:299.05 GB) NTFS
 
\\?\Volume{c77bf65e-6864-47ed-a37f-1bd96147e216}\ (Windows RE tools) (Fixed) (Total:0.64 GB) (Free:0.06 GB) NTFS
\\?\Volume{ff68de2f-964c-4623-ae36-2e554ef0424a}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.16 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: F50B9BA9)
 
Partition: GPT.
 
==================== End of Addition.txt =======================


#7 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 50,567 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:13 PM

Posted 24 April 2022 - 09:52 AM

Thank you Eric, we will work through it.

In addition to being infected, the reports are a bit complicated. I would like to address some preliminary things before we start the cleanup process.

I would strongly recommend you remove any questionable software downloaded from other than trustworthy sources.

Do you recognize these?

115电脑版
Sangfor
NetEase(Hangzhou) Network
CloudMusic
Foxit


Please do this.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST will do it for you
Start::
CreateRestorePoint:
CloseProcesses:
Zip: C:\Users\YuchenTong\AppData\Roaming\Microsoft\MicrosoftMalwareProtection.exe
File: C:\windows\system32\diskparts.exe
Folder: C:\Users\YuchenTong\AppData\Roaming\hgslpds
Folder: C:\Users\YuchenTong\AppData\Roaming\AuntecPkg
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • The tool will create a zipped folder in the same location from where FRST was run with today's date, example: 02.17.2022_13.24.50.zip. Please upload the file here.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Recognize programs?
  • Fixlog
  • Uploaded zip file

Gary 

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God." Where to Start

#8 tyctxt

tyctxt
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 24 April 2022 - 10:21 AM

About these programs:

Actually they are quite known in China. "115电脑版" is a cloud drive frequently used in China. "Sangfor" is a VPN server provided by my college. The third and fourth are music players which are quite popular in China. Foxit is a PDF reader and provides other utilities but I remembered uninstalling it already.

 

 

 

 

Fixlog:

Fix result of Farbar Recovery Scan Tool (x64) Version: 22-04-2022
Ran by YuchenTong (24-04-2022 23:10:51) Run:2
Running from C:\Users\YuchenTong\Downloads
Loaded Profiles: YuchenTong
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
Zip: C:\Users\YuchenTong\AppData\Roaming\Microsoft\MicrosoftMalwareProtection.exe
File: C:\windows\system32\diskparts.exe
Folder: C:\Users\YuchenTong\AppData\Roaming\hgslpds
Folder: C:\Users\YuchenTong\AppData\Roaming\AuntecPkg
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
================== Zip: ===================
C:\Users\YuchenTong\AppData\Roaming\Microsoft\MicrosoftMalwareProtection.exe -> copied successfully to C:\Users\YuchenTong\Desktop\24.04.2022_23.10.56.zip
=========== Zip: End ===========
 
========================= File: C:\windows\system32\diskparts.exe ========================
 
C:\windows\system32\diskparts.exe
File not signed
MD5: A2A044787C3FD7B9B19E721F625E4B98
Creation and modification date: 2022-04-12 21:30 - 2021-11-04 12:26
Size: 1070240358
Attributes: --ASH
Company Name: 
Internal Name: 
Original Name: 
Product: 
Description: 
File Version: 
Product Version: 
Copyright: 
VirusTotal: 0
 
====== End of File: ======
 
 
========================= Folder: C:\Users\YuchenTong\AppData\Roaming\hgslpds ========================
 
2022-03-29 20:06 - 2022-03-29 21:17 - 000000449 ___AH [753A28D3CBA736B4C5048DC9BAF308C5] () C:\Users\YuchenTong\AppData\Roaming\hgslpds\.UninstallGuide.ini
2022-03-29 20:06 - 2022-03-29 20:06 - 000000032 ____A [9040B73D512929882B47F6E5E09559D1] () C:\Users\YuchenTong\AppData\Roaming\hgslpds\appListMd5
2022-03-29 20:06 - 2022-03-29 20:06 - 000000000 ____A [D41D8CD98F00B204E9800998ECF8427E] () C:\Users\YuchenTong\AppData\Roaming\hgslpds\bFirstStart.dat
2022-03-29 20:06 - 2022-03-29 20:07 - 000007083 ____A [77BE2860DFB751B88518F06987A9F706] () C:\Users\YuchenTong\AppData\Roaming\hgslpds\hgslpds_sdk.log
2022-03-29 20:06 - 2022-03-29 20:07 - 000040960 ____A [D86ECB430E5C1505A6708AF3C4ED4E94] () C:\Users\YuchenTong\AppData\Roaming\hgslpds\hiscreenrecorder.db
2022-03-29 20:06 - 2022-03-29 20:07 - 000000682 ____A [A781F043E3E9CED4CD7C88D80633D448] () C:\Users\YuchenTong\AppData\Roaming\hgslpds\installer.ini
2022-03-29 20:06 - 2022-03-29 20:07 - 000000101 ____A [D78EF92F5EA7992363C48A8DFBF84920] () C:\Users\YuchenTong\AppData\Roaming\hgslpds\嗨格式录屏大师.ini
2022-03-29 20:06 - 2022-03-29 20:06 - 000000000 ____A [D41D8CD98F00B204E9800998ECF8427E] () C:\Users\YuchenTong\AppData\Roaming\hgslpds\嗨格式录屏大师.log
2022-03-29 20:06 - 2022-03-29 20:07 - 000005810 ____A [142EA0506027B5344E4C1BFE07180D1D] () C:\Users\YuchenTong\AppData\Roaming\hgslpds\嗨格式录屏大师_ui.log
2022-03-29 20:06 - 2022-03-29 20:06 - 000000000 ____D [00000000000000000000000000000000] C:\Users\YuchenTong\AppData\Roaming\hgslpds\cachelog
 
====== End of Folder: ======
 
 
========================= Folder: C:\Users\YuchenTong\AppData\Roaming\AuntecPkg ========================
 
2022-03-29 20:05 - 2022-03-29 20:05 - 000000000 ____D [00000000000000000000000000000000] C:\Users\YuchenTong\AppData\Roaming\AuntecPkg\HIRECORDER
2022-03-29 20:05 - 2022-03-29 20:05 - 000000596 ____A [2C29D0C6802B0FB3D74C27AE02E8199C] () C:\Users\YuchenTong\AppData\Roaming\AuntecPkg\HIRECORDER\config.ini
2022-03-29 20:05 - 2022-03-29 20:05 - 043580632 ____A [52AB9F4045366781BE487DA9E43E46AA] (苏州开心盒子软件有限公司 -> 苏州开心盒子软件有限公司) C:\Users\YuchenTong\AppData\Roaming\AuntecPkg\HIRECORDER\screenrecorder_6979ADD5.exe
2022-03-29 20:05 - 2022-03-29 20:05 - 000000000 ____D [00000000000000000000000000000000] C:\Users\YuchenTong\AppData\Roaming\AuntecPkg\Jnz
2022-03-29 20:05 - 2022-03-29 20:05 - 000265216 ____A [A63247D68D6FCA6406F3FE2F73CFF1FB] () [File not signed] C:\Users\YuchenTong\AppData\Roaming\AuntecPkg\Jnz\BZUID.dll
2022-03-29 20:05 - 2022-03-29 20:05 - 000913408 ____A [E44BF532A9BD3079A0F84AF9E4FC5890] (Kunshan Aunbox software co.,Ltd) [File not signed] C:\Users\YuchenTong\AppData\Roaming\AuntecPkg\Jnz\Jnz.dll
2022-03-29 20:05 - 2022-03-29 20:05 - 000163840 ____A [5A83BB6FF1D91788FC0A9BEF6A08DB9A] (苏州开心盒子软件有限公司) [File not signed] C:\Users\YuchenTong\AppData\Roaming\AuntecPkg\Jnz\Jnz.exe
 
====== End of Folder: ======
 
 
 
The system needed a reboot.
 
==== End of Fixlog 23:11:23 ====
 
 
The zipfile is so big (70 MB) that it exceeds the 10 MB limit. Is there anyway else to upload it?
Thanks!


#9 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 50,567 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:13 PM

Posted 24 April 2022 - 01:18 PM

Thank you for the information.

Please upload the file here. Be sure to include a link to our topic and let me know when the file has been submitted.

Are you familiar with Suzhou Happy Box Software Co., Ltd.?

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST will do it for you
Start::
CloseProcesses:
File: C:\windows\system32\diskparts.exe
Task: {77ECA5DF-FF10-4FC9-9581-2F41D61495AE} - System32\Tasks\MicrosoftMalwareProtection => C:\Users\YuchenTong\AppData\Roaming\Microsoft\MicrosoftMalwareProtection.exe [1381355632 2022-03-14] () [File not signed] <==== ATTENTION
Task: {812F3E28-02F3-4AF8-B8ED-6D9C42966775} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer.bacd823895d847ca8da24154e424012b\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe (No File)
S3 GSDriver; \SystemRoot\System32\drivers\GSDriver64.sys [X]
2022-04-24 18:53 - 2022-04-24 18:53 - 000011730 _____ C:\Users\YuchenTong\Downloads\{0A7ABDE6-CD0B-405D-9678-7F5A397DA5D2}
2022-04-23 20:05 - 2022-04-24 20:13 - 000000000 ____D C:\ProgramData\TEMP
2022-04-21 18:20 - 2022-04-21 18:25 - 000000000 __SHD C:\Users\YuchenTong\AppData\Roaming\Windows
2022-04-04 20:29 - 2022-04-04 20:29 - 000000000 ____D C:\Users\Public\MTool_Game_Tmp
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\Documents\Foxit Software
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\UserSystemSDK_DB
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Foxit Software
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Foxit
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\FnInformation
2022-04-21 18:20 - 2022-03-14 17:42 - 1381355632 ___SH () C:\Users\YuchenTong\AppData\Roaming\Microsoft\MicrosoftMalwareProtection.exe
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32 ->  => No File
ContextMenuHandlers1: [cloudmusic] -> {5C6A637C-9780-4D0F-A379-4732EDCCE7C3} =>  -> No File
AlternateDataStreams: C:\ProgramData\TEMP:341E39B2 [390]
FirewallRules: [{407EBEE8-586E-44DA-AC79-CDB22EE88008}] => (Allow) C:\Users\YuchenTong\AppData\Roaming\Tencent\QQ\STemp\SetupEx0\QQSetupEx.exe => No File
FirewallRules: [{F5F15141-729F-4061-AC3C-28A231AD7244}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChatBrowser.exe => No File
FirewallRules: [{8811352F-0F21-413C-BABD-F4732E9ADF5F}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChatPlayer.exe => No File
FirewallRules: [{C5247D6D-FB17-4CCE-8E0B-CD6FFAD096CE}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\txupd.exe => No File
FirewallRules: [{AF7A5B46-779B-4DAC-B689-B9B7765E969F}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\SetupEx\SetupEx.exe => No File
FirewallRules: [{B0850279-AAE9-483D-853A-8FC76EE38A7B}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\bugreport_xf.exe => No File
FirewallRules: [{A9B90926-A38D-4E14-970A-2B5E79E8A7BA}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\moleplugin\tadb.exe => No File
FirewallRules: [TCP Query User{34363D0E-9FD6-4774-82BC-49FE16C44C85}C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe] => (Allow) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [UDP Query User{9240DCA0-AA58-4927-84F9-1DF9B3B6BAFD}C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe] => (Allow) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{A20CDAC6-BD71-40DD-B56B-27075D32DE6B}] => (Block) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{BB5D847A-AE63-4FB0-B969-E0D8D47E9295}] => (Block) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{84C1F3DE-C1B4-4AB4-A039-7D7C4A3B543C}] => (Allow) C:\Program Files (x86)\Foxit Software\FoxitREC\FoxitREC.exe => No File
FirewallRules: [{071CA9CC-73A8-4D6C-B496-E560AED35BBB}] => (Allow) C:\Program Files (x86)\Foxit Software\FoxitREC\FoxitREC.exe => No File
FirewallRules: [TCP Query User{40F5216D-05C5-41FA-BAD3-9B4ECB8FAE4C}C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [UDP Query User{B25A318C-65EF-43D5-AD6A-D804E8CDC99D}C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [TCP Query User{12414319-2366-46B5-A707-FF93AA924B4F}C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe => No File
FirewallRules: [UDP Query User{14B1CED0-2B7A-4F20-8070-B08FF22EAF7E}C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe => No File
FirewallRules: [{DAF1A415-8652-4441-BB68-EA7A31779DDE}] => (Block) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [{D1476AD9-9E5C-4BE0-B4F4-6B1CE3F79BD1}] => (Block) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [{4A54105F-D224-47FB-B1AB-ED55784013CA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crusader Kings III\launcher\dowser.exe => No File
FirewallRules: [{A32C8932-5E39-4587-94C2-5C5DB268F55C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crusader Kings III\launcher\dowser.exe => No File
FirewallRules: [TCP Query User{AD721708-BE92-4E5D-A6CC-E4CD835B5E5A}C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [UDP Query User{6724343B-004C-4028-B1CF-77F9BD0EB442}C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [{FABCF631-6EEC-4871-B727-55313768CF50}] => (Block) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [{B4362568-E511-4425-B943-F508CC561AF2}] => (Block) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Familiar with Suzhou Happy Box?
  • Fixlog
  • Uploaded file

Edited by Oh My!, 24 April 2022 - 01:51 PM.

Gary 

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God." Where to Start

#10 tyctxt

tyctxt
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 24 April 2022 - 08:56 PM

Thanks for your advice. I was sleeping.

 

  • About Suzhou Happy Box:
  • It is from a screen recorder that I have already uninstalled.

 

Fix log

Fix result of Farbar Recovery Scan Tool (x64) Version: 22-04-2022
Ran by YuchenTong (25-04-2022 09:29:54) Run:3
Running from C:\Users\YuchenTong\Downloads
Loaded Profiles: YuchenTong
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CloseProcesses:
File: C:\windows\system32\diskparts.exe
Task: {77ECA5DF-FF10-4FC9-9581-2F41D61495AE} - System32\Tasks\MicrosoftMalwareProtection => C:\Users\YuchenTong\AppData\Roaming\Microsoft\MicrosoftMalwareProtection.exe [1381355632 2022-03-14] () [File not signed] <==== ATTENTION
Task: {812F3E28-02F3-4AF8-B8ED-6D9C42966775} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer.bacd823895d847ca8da24154e424012b\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe (No File)
S3 GSDriver; \SystemRoot\System32\drivers\GSDriver64.sys [X]
2022-04-24 18:53 - 2022-04-24 18:53 - 000011730 _____ C:\Users\YuchenTong\Downloads\{0A7ABDE6-CD0B-405D-9678-7F5A397DA5D2}
2022-04-23 20:05 - 2022-04-24 20:13 - 000000000 ____D C:\ProgramData\TEMP
2022-04-21 18:20 - 2022-04-21 18:25 - 000000000 __SHD C:\Users\YuchenTong\AppData\Roaming\Windows
2022-04-04 20:29 - 2022-04-04 20:29 - 000000000 ____D C:\Users\Public\MTool_Game_Tmp
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\Documents\Foxit Software
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\UserSystemSDK_DB
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Foxit Software
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\Foxit
2022-03-29 20:04 - 2022-03-29 20:04 - 000000000 ____D C:\Users\YuchenTong\AppData\Roaming\FnInformation
2022-04-21 18:20 - 2022-03-14 17:42 - 1381355632 ___SH () C:\Users\YuchenTong\AppData\Roaming\Microsoft\MicrosoftMalwareProtection.exe
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32 ->  => No File
ContextMenuHandlers1: [cloudmusic] -> {5C6A637C-9780-4D0F-A379-4732EDCCE7C3} =>  -> No File
AlternateDataStreams: C:\ProgramData\TEMP:341E39B2 [390]
FirewallRules: [{407EBEE8-586E-44DA-AC79-CDB22EE88008}] => (Allow) C:\Users\YuchenTong\AppData\Roaming\Tencent\QQ\STemp\SetupEx0\QQSetupEx.exe => No File
FirewallRules: [{F5F15141-729F-4061-AC3C-28A231AD7244}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChatBrowser.exe => No File
FirewallRules: [{8811352F-0F21-413C-BABD-F4732E9ADF5F}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChatPlayer.exe => No File
FirewallRules: [{C5247D6D-FB17-4CCE-8E0B-CD6FFAD096CE}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\txupd.exe => No File
FirewallRules: [{AF7A5B46-779B-4DAC-B689-B9B7765E969F}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\SetupEx\SetupEx.exe => No File
FirewallRules: [{B0850279-AAE9-483D-853A-8FC76EE38A7B}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\bugreport_xf.exe => No File
FirewallRules: [{A9B90926-A38D-4E14-970A-2B5E79E8A7BA}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\moleplugin\tadb.exe => No File
FirewallRules: [TCP Query User{34363D0E-9FD6-4774-82BC-49FE16C44C85}C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe] => (Allow) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [UDP Query User{9240DCA0-AA58-4927-84F9-1DF9B3B6BAFD}C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe] => (Allow) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{A20CDAC6-BD71-40DD-B56B-27075D32DE6B}] => (Block) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{BB5D847A-AE63-4FB0-B969-E0D8D47E9295}] => (Block) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{84C1F3DE-C1B4-4AB4-A039-7D7C4A3B543C}] => (Allow) C:\Program Files (x86)\Foxit Software\FoxitREC\FoxitREC.exe => No File
FirewallRules: [{071CA9CC-73A8-4D6C-B496-E560AED35BBB}] => (Allow) C:\Program Files (x86)\Foxit Software\FoxitREC\FoxitREC.exe => No File
FirewallRules: [TCP Query User{40F5216D-05C5-41FA-BAD3-9B4ECB8FAE4C}C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [UDP Query User{B25A318C-65EF-43D5-AD6A-D804E8CDC99D}C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [TCP Query User{12414319-2366-46B5-A707-FF93AA924B4F}C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe => No File
FirewallRules: [UDP Query User{14B1CED0-2B7A-4F20-8070-B08FF22EAF7E}C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe => No File
FirewallRules: [{DAF1A415-8652-4441-BB68-EA7A31779DDE}] => (Block) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [{D1476AD9-9E5C-4BE0-B4F4-6B1CE3F79BD1}] => (Block) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [{4A54105F-D224-47FB-B1AB-ED55784013CA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crusader Kings III\launcher\dowser.exe => No File
FirewallRules: [{A32C8932-5E39-4587-94C2-5C5DB268F55C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crusader Kings III\launcher\dowser.exe => No File
FirewallRules: [TCP Query User{AD721708-BE92-4E5D-A6CC-E4CD835B5E5A}C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [UDP Query User{6724343B-004C-4028-B1CF-77F9BD0EB442}C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [{FABCF631-6EEC-4871-B727-55313768CF50}] => (Block) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [{B4362568-E511-4425-B943-F508CC561AF2}] => (Block) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
 
*****************
 
Processes closed successfully.
 
========================= File: C:\windows\system32\diskparts.exe ========================
 
C:\windows\system32\diskparts.exe
File not signed
MD5: A2A044787C3FD7B9B19E721F625E4B98
Creation and modification date: 2022-04-12 21:30 - 2021-11-04 12:26
Size: 1070240358
Attributes: --ASH
Company Name: 
Internal Name: 
Original Name: 
Product: 
Description: 
File Version: 
Product Version: 
Copyright: 
VirusTotal: 0
 
====== End of File: ======
 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{77ECA5DF-FF10-4FC9-9581-2F41D61495AE}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{77ECA5DF-FF10-4FC9-9581-2F41D61495AE}" => removed successfully
C:\windows\System32\Tasks\MicrosoftMalwareProtection => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MicrosoftMalwareProtection" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{812F3E28-02F3-4AF8-B8ED-6D9C42966775}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{812F3E28-02F3-4AF8-B8ED-6D9C42966775}" => removed successfully
C:\windows\System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\VisualStudio\Updates\BackgroundDownload" => removed successfully
HKLM\System\CurrentControlSet\Services\GSDriver => removed successfully
GSDriver => service removed successfully
"C:\Users\YuchenTong\Downloads\{0A7ABDE6-CD0B-405D-9678-7F5A397DA5D2}" => not found
C:\ProgramData\TEMP => moved successfully
C:\Users\YuchenTong\AppData\Roaming\Windows => moved successfully
C:\Users\Public\MTool_Game_Tmp => moved successfully
"C:\Users\YuchenTong\Documents\Foxit Software" => not found
C:\Users\YuchenTong\AppData\Roaming\UserSystemSDK_DB => moved successfully
C:\Users\YuchenTong\AppData\Roaming\Foxit Software => moved successfully
C:\Users\YuchenTong\AppData\Roaming\Foxit => moved successfully
C:\Users\YuchenTong\AppData\Roaming\FnInformation => moved successfully
C:\Users\YuchenTong\AppData\Roaming\Microsoft\MicrosoftMalwareProtection.exe => moved successfully
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2} => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\cloudmusic => removed successfully
"C:\ProgramData\TEMP" => ":341E39B2" ADS not found.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{407EBEE8-586E-44DA-AC79-CDB22EE88008}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F5F15141-729F-4061-AC3C-28A231AD7244}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8811352F-0F21-413C-BABD-F4732E9ADF5F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C5247D6D-FB17-4CCE-8E0B-CD6FFAD096CE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AF7A5B46-779B-4DAC-B689-B9B7765E969F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B0850279-AAE9-483D-853A-8FC76EE38A7B}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A9B90926-A38D-4E14-970A-2B5E79E8A7BA}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{34363D0E-9FD6-4774-82BC-49FE16C44C85}C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9240DCA0-AA58-4927-84F9-1DF9B3B6BAFD}C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A20CDAC6-BD71-40DD-B56B-27075D32DE6B}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BB5D847A-AE63-4FB0-B969-E0D8D47E9295}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{84C1F3DE-C1B4-4AB4-A039-7D7C4A3B543C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{071CA9CC-73A8-4D6C-B496-E560AED35BBB}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{40F5216D-05C5-41FA-BAD3-9B4ECB8FAE4C}C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{B25A318C-65EF-43D5-AD6A-D804E8CDC99D}C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{12414319-2366-46B5-A707-FF93AA924B4F}C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{14B1CED0-2B7A-4F20-8070-B08FF22EAF7E}C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DAF1A415-8652-4441-BB68-EA7A31779DDE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D1476AD9-9E5C-4BE0-B4F4-6B1CE3F79BD1}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4A54105F-D224-47FB-B1AB-ED55784013CA}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A32C8932-5E39-4587-94C2-5C5DB268F55C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{AD721708-BE92-4E5D-A6CC-E4CD835B5E5A}C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{6724343B-004C-4028-B1CF-77F9BD0EB442}C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FABCF631-6EEC-4871-B727-55313768CF50}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B4362568-E511-4425-B943-F508CC561AF2}" => removed successfully
 
 
The system needed a reboot.
 
==== End of Fixlog 09:30:11 ====
 
About the file:
The upload page still has a 10MB limit, thus I cannot successfully upload it. May I have another way to transfer it? I have uploaded it to dropfiles and I have sent you the link in personal message.
Thanks for your help!


#11 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 50,567 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:13 PM

Posted 24 April 2022 - 09:10 PM

Thank you for the information.

Please do this.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST will do it for you
Start::
C:\windows\system32\diskparts.exe
C:\Users\YuchenTong\AppData\Roaming\hgslpds
C:\Users\YuchenTong\AppData\Roaming\AuntecPkg
Emptytemp:
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • Copy/paste the following in the Search: box
SearchAll: foxit;AuntecPkg;hgslpds;HIRECORDER;screenrecorder
  • Click Search Files button
  • When completed click OK and a Search.txt document will open on your desktop
  • Copy and paste the report in your reply. If the file is too large zip and upload it here.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • Search.txt

Gary 

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God." Where to Start

#12 tyctxt

tyctxt
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 24 April 2022 - 09:25 PM

Thanks for your advice.

I have rebooted several times since last fix. It seems that the defender no longer warns me and the explorer have not gone wrong since then. I may observe the computer more to see if it recovers. Thank you so much.

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 22-04-2022
Ran by YuchenTong (25-04-2022 10:13:00) Run:4
Running from C:\Users\YuchenTong\Downloads
Loaded Profiles: YuchenTong
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
C:\windows\system32\diskparts.exe
C:\Users\YuchenTong\AppData\Roaming\hgslpds
C:\Users\YuchenTong\AppData\Roaming\AuntecPkg
Emptytemp:
 
*****************
 
C:\windows\system32\diskparts.exe => moved successfully
C:\Users\YuchenTong\AppData\Roaming\hgslpds => moved successfully
C:\Users\YuchenTong\AppData\Roaming\AuntecPkg => moved successfully
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9573204 B
Java, Flash, Steam htmlcache => 429770182 B
Windows/system/drivers => 7052494 B
Edge => 0 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 153180 B
systemprofile32 => 153180 B
LocalService => 153180 B
NetworkService => 154998 B
YuchenTong => 1727235827 B
 
RecycleBin => 0 B
EmptyTemp: => 2 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 10:13:05 ====
 

 

Farbar Recovery Scan Tool (x64) Version: 22-04-2022
Ran by YuchenTong (25-04-2022 10:17:29)
Running from C:\Users\YuchenTong\Downloads
Boot Mode: Normal
 
================== Search Files: "SearchAll: foxit;AuntecPkg;hgslpds;HIRECORDER;screenrecorder" =============
 
File:
========
C:\Program Files (x86)\Tencent\QQ\Plugin\Com.Tencent.AudioVideo\bin\ScreenRecorder.dll
[2022-03-20 16:29][2022-03-20 16:29] 000241608 _____ (Tencent) 180457A3CF7C41C39559D512C65EE190 [File is digitally signed]
 
C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\UserSystemSDK_DB\FoxitSystemDB.db
[2022-03-29 20:04][2022-03-29 20:04] 000020480 _____ () 79D1ABCB8F7FCF7DE1A2F80C1B9BA513 [File not signed]
 
C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\hgslpds\hgslpds_sdk.log
[2022-03-29 20:06][2022-03-29 20:07] 000007083 _____ () 77BE2860DFB751B88518F06987A9F706 [File not signed]
 
C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\hgslpds\hiscreenrecorder.db
[2022-03-29 20:06][2022-03-29 20:07] 000040960 _____ () D86ECB430E5C1505A6708AF3C4ED4E94 [File not signed]
 
C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\AuntecPkg\HIRECORDER\screenrecorder_6979ADD5.exe
[2022-03-29 20:05][2022-03-29 20:05] 043580632 _____ (苏州开心盒子软件有限公司 ) 52AB9F4045366781BE487DA9E43E46AA [File is digitally signed]
 
 
folder:
========
2022-03-29 20:05 - 2022-03-29 20:05 _____ C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\AuntecPkg
2022-03-29 20:04 - 2022-03-29 20:04 _____ C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\Foxit
2022-03-29 20:04 - 2022-03-29 20:04 _____ C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\Foxit Software
2022-03-29 20:06 - 2022-03-29 20:07 _____ C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\hgslpds
2022-03-29 20:04 - 2022-03-29 20:04 _____ C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\Foxit Software\FoxitREC
2022-03-29 20:04 - 2022-03-29 20:04 _____ C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\Foxit\FoxitREC
2022-03-29 20:05 - 2022-03-29 20:05 _____ C:\FRST\Quarantine\C\Users\YuchenTong\AppData\Roaming\AuntecPkg\HIRECORDER
 
Registry:
========
 
===================== Search result for "foxit" ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"FoxitREC.exe"="11001"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software\FoxitREC]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software\FoxitREC\Foxit Information]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"FoxitREC.exe"="11001"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\FoxitREC_RASAPI32]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\FoxitREC_RASMANCS]
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Apowersoft\Windows FoxitREC]
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Foxit Software]
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\DOMStorage\foxitreader.cn]
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\DOMStorage\sso.foxitreader.cn]
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone\NonPackaged\C:#Program Files (x86)#Foxit Software#FoxitREC#FoxitREC.exe]
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched]
"{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Foxit Software\FoxitREC\FoxitREC.exe"="1"
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData]
"{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Foxit Software\FoxitREC\FoxitREC.exe"="132930334607845240"
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"C:\Users\YuchenTong\Downloads\foxitrec-pd.exe"="0x534143500100000000000000070000002800000000C303024505040201000000000000000000000A0021000010245A0F035AD70100000000000000000200000028000000000000000000000000000000000000000000000000000000A9050100000000000100000001000000"
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"C:\Program Files (x86)\Foxit Software\FoxitREC\unins000.exe"="0x5341435001000000000000000700000028000000DD5029000000000003000000000000000000000A0021000010245A0F035AD70100000000000000000200000028000000000000000000000000000000000000000000000000000000040F0000000000000100000001000000"
 
 
===================== Search result for "AuntecPkg" ==========
 
 
===================== Search result for "hgslpds" ==========
 
 
===================== Search result for "HIRECORDER" ==========
 
 
===================== Search result for "screenrecorder" ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Components\613B99D5CFD7FCB4793B500086BB4113]
"{EEDBAC4F-D024-4FDD-B578-0D6CB152634C},ScreenRecorder\2052"="zn=BVM0}X%4!!!!MKKSkGimme_OnDemandData<ScreenRecorderFiles"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Components\F4CABDEE420DDDF45B87D0C61B2536C4]
"ScreenRecorder\2052"="zn=BVM0}X%4!!!!MKKSkScreenRecorderFilesIntl_2052<setlang"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Features\00006109E60040800100000000F01FEC]
"ScreenRecorderFilesIntl_2052"=""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{73720014-33A0-11E4-9B9A-00155D152105}]
""="IScreenRecorderControl"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{73720015-33A0-11E4-9B9A-00155D152105}]
""="IScreenRecorderControlCallback"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Office\FeatureListForC2RGimme]
"ScreenRecorderFilesIntl_2052"="{90160000-006E-0804-1000-0000000FF1CE}"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60040800100000000F01FEC\Features]
"ScreenRecorderFilesIntl_2052"="RlQV!vPCm9h4IFz^Zt~Z"
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched]
"C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe"="4"
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe"="0x5341435001000000000000000700000028000000A0211B00A38E1B0001000000000000000000000A7122000010245A0F035AD70100000000000000000200000028000000000000000000004000000000000000000000000000000000397D0100000000000100000001000000"
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe.FriendlyAppName"="嗨格式录屏大师"
 
[HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe.ApplicationCompany"="苏州开心盒子软件有限公司"
 
 
====== End of Search ======


#13 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 50,567 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:13 PM

Posted 24 April 2022 - 09:42 PM

Very good.

Let's run this and monitor your computer for a day.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST will do it for you
Start::
C:\Program Files (x86)\Tencent\QQ\Plugin\Com.Tencent.AudioVideo
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|FoxitREC.exe
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|FoxitREC.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Foxit Software\FoxitREC\FoxitREC.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData|{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Foxit Software\FoxitREC\FoxitREC.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\YuchenTong\Downloads\foxitrec-pd.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Foxit Software\FoxitREC\unins000.exe
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Components\613B99D5CFD7FCB4793B500086BB4113|{EEDBAC4F-D024-4FDD-B578-0D6CB152634C},ScreenRecorder\2052
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Components\F4CABDEE420DDDF45B87D0C61B2536C4|ScreenRecorder\2052
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Features\00006109E60040800100000000F01FEC|ScreenRecorderFilesIntl_2052
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{73720014-33A0-11E4-9B9A-00155D152105}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{73720015-33A0-11E4-9B9A-00155D152105}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Office\FeatureListForC2RGimme|ScreenRecorderFilesIntl_2052
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60040800100000000F01FEC\Features|ScreenRecorderFilesIntl_2052
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe.ApplicationCompany
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software\FoxitREC 
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software\FoxitREC\Foxit Information 
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\FoxitREC_RASAPI32 
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\FoxitREC_RASMANCS 
DeleteKey: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Apowersoft\Windows FoxitREC 
DeleteKey: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Foxit Software 
DeleteKey: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\DOMStorage\foxitreader.cn 
DeleteKey: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\DOMStorage\sso.foxitreader.cn 
DeleteKey: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone\NonPackaged\C:#Program Files (x86)#Foxit Software#FoxitREC#FoxitREC.exe
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog

Gary 

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God." Where to Start

#14 tyctxt

tyctxt
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:13 AM

Posted 24 April 2022 - 09:51 PM

The fixlog

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 22-04-2022
Ran by YuchenTong (25-04-2022 10:45:50) Run:5
Running from C:\Users\YuchenTong\Downloads
Loaded Profiles: YuchenTong
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
C:\Program Files (x86)\Tencent\QQ\Plugin\Com.Tencent.AudioVideo
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|FoxitREC.exe
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|FoxitREC.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Foxit Software\FoxitREC\FoxitREC.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData|{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Foxit Software\FoxitREC\FoxitREC.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\YuchenTong\Downloads\foxitrec-pd.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Foxit Software\FoxitREC\unins000.exe
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Components\613B99D5CFD7FCB4793B500086BB4113|{EEDBAC4F-D024-4FDD-B578-0D6CB152634C},ScreenRecorder\2052
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Components\F4CABDEE420DDDF45B87D0C61B2536C4|ScreenRecorder\2052
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Features\00006109E60040800100000000F01FEC|ScreenRecorderFilesIntl_2052
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{73720014-33A0-11E4-9B9A-00155D152105}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{73720015-33A0-11E4-9B9A-00155D152105}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Office\FeatureListForC2RGimme|ScreenRecorderFilesIntl_2052
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60040800100000000F01FEC\Features|ScreenRecorderFilesIntl_2052
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe.ApplicationCompany
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software\FoxitREC 
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software\FoxitREC\Foxit Information 
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\FoxitREC_RASAPI32 
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\FoxitREC_RASMANCS 
DeleteKey: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Apowersoft\Windows FoxitREC 
DeleteKey: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Foxit Software 
DeleteKey: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\DOMStorage\foxitreader.cn 
DeleteKey: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\DOMStorage\sso.foxitreader.cn 
DeleteKey: HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone\NonPackaged\C:#Program Files (x86)#Foxit Software#FoxitREC#FoxitREC.exe
 
*****************
 
C:\Program Files (x86)\Tencent\QQ\Plugin\Com.Tencent.AudioVideo => moved successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\\FoxitREC.exe" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\\FoxitREC.exe" => removed successfully
"HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Foxit Software\FoxitREC\FoxitREC.exe" => removed successfully
"HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Foxit Software\FoxitREC\FoxitREC.exe" => removed successfully
"HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\YuchenTong\Downloads\foxitrec-pd.exe" => removed successfully
"HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Foxit Software\FoxitREC\unins000.exe" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Components\613B99D5CFD7FCB4793B500086BB4113\\{EEDBAC4F-D024-4FDD-B578-0D6CB152634C},ScreenRecorder\2052" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Components\F4CABDEE420DDDF45B87D0C61B2536C4\\ScreenRecorder\2052" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Features\00006109E60040800100000000F01FEC\\ScreenRecorderFilesIntl_2052" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{73720014-33A0-11E4-9B9A-00155D152105}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{73720015-33A0-11E4-9B9A-00155D152105}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Office\FeatureListForC2RGimme\\ScreenRecorderFilesIntl_2052" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60040800100000000F01FEC\Features\\ScreenRecorderFilesIntl_2052" => removed successfully
"HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched\\C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe" => removed successfully
"HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe" => removed successfully
"HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe.FriendlyAppName" => removed successfully
"HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\YuchenTong\Downloads\screenrecorder_6979ADD5.exe.ApplicationCompany" => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software\FoxitREC" => not found
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Foxit Software\FoxitREC\Foxit Information" => not found
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\FoxitREC_RASAPI32 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\FoxitREC_RASMANCS => removed successfully
HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Apowersoft\Windows FoxitREC => removed successfully
HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Foxit Software => removed successfully
HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\DOMStorage\foxitreader.cn => removed successfully
HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\DOMStorage\sso.foxitreader.cn => removed successfully
HKEY_USERS\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone\NonPackaged\C:#Program Files (x86)#Foxit Software#FoxitREC#FoxitREC.exe => removed successfully
 
==== End of Fixlog 10:45:50 ====
 
It is so nice of you. It is impressive to see such a powerful and dedicated forum against virus and malwares.


#15 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 50,567 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:13 PM

Posted 24 April 2022 - 09:53 PM

Thank you, it is our pleasure to help.

Touch base tomorrow and let me know how things are going.
Gary 

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God." Where to Start




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users