And Additions.txt is as below.
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2022
Ran by YuchenTong (24-04-2022 21:04:27)
Running from C:\Users\YuchenTong\Downloads
Microsoft Windows 11 家庭中文版 Version 21H2 22000.613 (X64) (2022-03-19 20:11:07)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-1919967345-4022050966-3323017305-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1919967345-4022050966-3323017305-503 - Limited - Disabled)
Guest (S-1-5-21-1919967345-4022050966-3323017305-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1919967345-4022050966-3323017305-504 - Limited - Disabled)
YuchenTong (S-1-5-21-1919967345-4022050966-3323017305-1001 - Administrator - Enabled) => C:\Users\YuchenTong
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
115电脑版 (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\115) (Version: 1.0.4.6 - 广东一一五科技股份有限公司)
7-Zip 21.07 (x64) (HKLM\...\7-Zip) (Version: 21.07 - Igor Pavlov)
Anaconda3 2021.11 (Python 3.9.7 64-bit) (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\Anaconda3 2021.11 (Python 3.9.7 64-bit)) (Version: 2021.11 - Anaconda, Inc.)
Application Verifier x64 External Package (HKLM\...\{8A4CD158-E6B3-6D91-D7DE-10098BC980E2}) (Version: 10.1.19041.685 - Microsoft) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.91 - Piriform)
ClickOnce Bootstrapper Package for Microsoft .NET Framework (HKLM-x32\...\{5A260D5A-95D3-4956-8E0A-E182CC4144ED}) (Version: 4.8.04162 - Microsoft Corporation) Hidden
CLion 2021.3.4 (HKLM-x32\...\CLion 2021.3.4) (Version: 213.7172.20 - JetBrains s.r.o.)
DiagnosticsHub_CollectionService (HKLM\...\{1F3C3AAC-9F7A-47DA-A082-0ACE770041BE}) (Version: 16.1.28901 - Microsoft Corporation) Hidden
Entity Framework 6.2.0 Tools for Visual Studio 2022 (HKLM-x32\...\{BA73F2EE-EEB4-4A9C-BAF4-AC3599983E8B}) (Version: 6.2.0.0 - Microsoft Corporation) Hidden
Everything 1.4.1.1015 (x64) (HKLM\...\Everything) (Version: 1.4.1.1015 - voidtools)
Git (HKLM\...\Git_is1) (Version: 2.35.1.2 - The Git Development Community)
Google Earth Pro (HKLM\...\{C36E66A6-6EE5-47DB-945F-A6F03225D540}) (Version: 7.3.4.8573 - Google)
Graphviz (HKLM-x32\...\Graphviz) (Version: 3.0.0 - Graphviz)
HP Audio Switch (HKLM-x32\...\{0B1DA73D-0562-4DE1-B942-CEF286CF2EDD}) (Version: 1.0.211.0 - HP Inc.)
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP Software Framework (HKLM-x32\...\{71E18A14-1BDB-4B58-A67F-1BCDA12462FD}) (Version: 7.1.15.1 - HP)
icecap_collection_neutral (HKLM-x32\...\{04C533D3-8445-4E47-A351-A66B1DA1B631}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
icecap_collection_x64 (HKLM\...\{4CDCF412-13D2-48AD-B98C-3AB4A771A127}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
icecap_collectionresources (HKLM-x32\...\{9FC7998B-89C3-4069-9402-DE9CD1F8881F}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
icecap_collectionresourcesx64 (HKLM-x32\...\{1E763296-2BD7-43D9-9096-AA9644199A2D}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
IntelliJ IDEA 2021.3.3 (HKLM-x32\...\IntelliJ IDEA 2021.3.3) (Version: 213.7172.25 - JetBrains s.r.o.)
IntelliTraceProfilerProxy (HKLM-x32\...\{C8891AD2-C223-45CD-A9BE-617A68923B61}) (Version: 15.0.21225.01 - Microsoft Corporation) Hidden
Java SE Development Kit 17.0.2 (64-bit) (HKLM\...\{65BA81E7-0238-5B54-9069-A59610247B0B}) (Version: 17.0.2.0 - Oracle Corporation)
Kits Configuration Installer (HKLM-x32\...\{E75A9998-E979-760B-6AEB-49763F279EDD}) (Version: 10.1.19041.685 - Microsoft) Hidden
Microsoft .NET SDK 6.0.202 (x64) from Visual Studio (HKLM\...\{7D932616-6CDE-4A21-AF51-2434E6428FF0}) (Version: 6.2.222.17207 - Microsoft Corporation)
Microsoft 365 - zh-cn (HKLM\...\O365HomePremRetail - zh-cn) (Version: 16.0.15028.20204 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 100.0.1185.50 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 100.0.1185.44 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\OneDriveSetup.exe) (Version: 22.065.0412.0004 - Microsoft Corporation)
Microsoft OneNote - zh-cn (HKLM\...\OneNoteFreeRetail - zh-cn) (Version: 16.0.15028.20204 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2019 (HKLM\...\{3E5195F5-ED93-4406-B149-F9F66F35E851}) (Version: 15.0.2000.5 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{6A2A8076-135F-4F55-BB02-DED67C8C6934}) (Version: 4.67.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.31.31103 (HKLM-x32\...\{2aaf1df0-eb13-4099-9992-962bb4e596d1}) (Version: 14.31.31103.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.31.31103 (HKLM-x32\...\{41d7b770-418a-43b7-95a5-f925fff05789}) (Version: 14.31.31103.0 - Microsoft Corporation)
Microsoft Visual Studio Code (User) (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\{771FD6B0-FA20-440A-A002-3B3BAC16DC50}_is1) (Version: 1.66.2 - Microsoft Corporation)
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 3.1.2204.3969 - Microsoft Corporation)
MSI Development Tools (HKLM-x32\...\{7AAC93B0-F3D7-6B24-6B37-9E74980C1C81}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
MSYS2 64bit (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\{9f4fa27d-baa7-4723-9706-ca18879d9a74}) (Version: 20220319 - The MSYS2 Developers)
Notion 2.0.23 (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\fcdf0d7f-424b-5f10-a1c7-a8f643f21adf) (Version: 2.0.23 - Notion Labs, Incorporated)
NVIDIA FrameView SDK 1.2.4999.30397803 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.2.4999.30397803 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.24.0.123 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.24.0.123 - NVIDIA Corporation)
NVIDIA PhysX 系统软件 9.20.0221 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.20.0221 - NVIDIA Corporation)
NVIDIA 图形驱动程序 511.15 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 511.15 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.15028.20050 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.15028.20160 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0804-1000-0000000FF1CE}) (Version: 16.0.15028.20094 - Microsoft Corporation) Hidden
Paradox Launcher v2 (HKLM\...\{E68BBC18-9E69-436B-B20F-E294DE62ECAB}) (Version: 2.3.0 - Paradox Interactive)
PyCharm 2021.3.3 (HKLM-x32\...\PyCharm 2021.3.3) (Version: 213.7172.26 - JetBrains s.r.o.)
QQ音乐 (HKLM-x32\...\QQMusic) (Version: 18.59 - 腾讯科技(深圳)有限公司)
Remote Process Explorer version 21.04 (HKLM-x32\...\Remote Process Explorer_is1) (Version: 21.04 - LizardSystems)
RGSS-RTP Standard (HKLM-x32\...\RGSS-RTP Standard_is1) (Version: 1.04 - Enterbrain)
RPG Maker VX 1.02 (HKLM-x32\...\RPG Maker VX) (Version: 1.02 - EnterBrain)
RPG Maker VX Ace 1.00 (HKLM-x32\...\RPG Maker VX Ace) (Version: 1.00 - Enterbrain)
RPG MAKER VX Ace RTP (HKLM-x32\...\RPGVXAce_RTP_is1) (Version: 1.00 - Enterbrain)
RPG Maker VX RTP (HKLM-x32\...\RPG Maker VX RTP_is1) (Version: 1.02 - Enterbrain)
RPG Maker XP 1.03 (HKLM-x32\...\RPG Maker XP) (Version: 1.03 - Wise Studio)
Rustup: the Rust toolchain installer (HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\Rustup) (Version: - )
SDK ARM Additions (HKLM-x32\...\{FCF9D89E-6F79-64FB-B08D-B0E69FF54DEE}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
SDK ARM Redistributables (HKLM-x32\...\{72DB07D6-E166-5A3F-B6E6-4664383781B8}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Sublime Text (HKLM\...\Sublime Text_is1) (Version: - Sublime HQ Pty Ltd)
SumatraPDF (HKLM\...\SumatraPDF) (Version: 3.3.3 - Krzysztof Kowalczyk)
Tencent QQMail Plugin (HKLM-x32\...\QQMailPlugin) (Version: - )
Universal CRT Extension SDK (HKLM-x32\...\{4D69FB64-4443-F2DD-DE1C-F14FD98AAC59}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Universal CRT Headers Libraries and Sources (HKLM-x32\...\{6B56745A-F6A4-C51C-933A-AD96C00683EA}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Universal CRT Redistributable (HKLM-x32\...\{A57CD0A6-4297-FD30-34A4-34758B6F5F69}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Universal CRT Tools x64 (HKLM\...\{CD06199B-41C1-AE6D-7567-984CC68792C3}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Universal CRT Tools x86 (HKLM-x32\...\{BD75F257-50A4-E0CD-9942-C3550CA3E66A}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Universal General MIDI DLS Extension SDK (HKLM-x32\...\{A7E95C47-B5F4-110C-D27A-DECB03412B96}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
vcpp_crt.redist.clickonce (HKLM-x32\...\{3355CB81-69C6-402C-A17D-4F6ED56F0904}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Vim 8.2 (HKLM\...\Vim 8.2) (Version: 8.2 - Bram Moolenaar et al.)
Visual Studio Community 2022 (HKLM-x32\...\203cec07) (Version: 17.1.5 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.16 - VideoLAN)
VS Immersive Activate Helper (HKLM-x32\...\{C0ACF658-B4DC-4CBB-B8F2-9E667D69919A}) (Version: 17.0.114.0 - Microsoft Corporation) Hidden
VS JIT Debugger (HKLM\...\{43F73608-5C94-436F-A1E6-E09ACE680391}) (Version: 17.0.114.0 - Microsoft Corporation) Hidden
VS Script Debugging Common (HKLM\...\{9EC852BD-33D2-457C-99BB-ED3099B8176F}) (Version: 17.0.114.0 - Microsoft Corporation) Hidden
vs_BlendMsi (HKLM-x32\...\{2D12F791-263F-4ABA-B7A8-5485933CADCF}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsi (HKLM-x32\...\{B8B0A861-C76A-4DBA-B8D5-8830511173A3}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsires (HKLM-x32\...\{16946E6F-037E-4A92-A30C-80293603EEC9}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_clickoncesigntoolmsi (HKLM-x32\...\{15CE6C23-B92A-4B2B-8521-6FA81661068B}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_communitymsires (HKLM-x32\...\{FB7E08F6-56D3-43A6-B2EE-BCDF09A73574}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_communitysharedmsi (HKLM-x32\...\{7571C303-621A-4ACF-A392-BD6B9B3C67BF}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_communityx64msi (HKLM\...\{EB7405ED-A99C-47D4-8516-C5C35704B07C}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_CoreEditorFonts (HKLM-x32\...\{D9559A61-5275-4476-8A1A-BD571F72E094}) (Version: 17.1.32414 - Microsoft Corporation) Hidden
vs_devenvsharedmsi (HKLM-x32\...\{923446B9-70EB-4850-95D7-1A1AB5D111CD}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_devenx64vmsi (HKLM\...\{5C99AE76-BEF9-4D4B-A77A-1B63238B86B0}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_filehandler_amd64 (HKLM-x32\...\{2C910925-05EE-403B-8295-D2593E11F751}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_filehandler_x86 (HKLM-x32\...\{46F71CD4-4841-4B77-A491-9933B98F8D0D}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_FileTracker_Singleton (HKLM-x32\...\{9DCCEEF7-CC00-4054-9879-7E0A12E5CF0A}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_Graphics_Singletonx64 (HKLM\...\{16FEBEAC-D39B-4E57-917E-B3DD174DBF7F}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_Graphics_Singletonx86 (HKLM-x32\...\{24DFA481-19D7-4B5B-AB77-89BB3D984019}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_minshellinteropsharedmsi (HKLM-x32\...\{05A82EA9-8768-4E1B-B16C-FCCF299D331C}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_minshellinteropx64msi (HKLM\...\{FB59095C-C7C6-4CA6-B300-852B50AB976D}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_minshellmsires (HKLM-x32\...\{FF8BEC95-383B-4B10-A69E-AE78BA76B903}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_minshellsharedmsi (HKLM-x32\...\{FEFEDA38-9B6A-4374-8D43-7D5517152080}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_minshellx64msi (HKLM\...\{CC15CA94-9817-4914-A9ED-A694A2F27783}) (Version: 17.1.32113 - Microsoft Corporation) Hidden
vs_SQLClickOnceBootstrappermsi (HKLM-x32\...\{4EF9011A-8E81-4D6F-9CB9-DBF0B1B12809}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
vs_tipsmsi (HKLM-x32\...\{874561BE-97AD-4865-8512-579D41009147}) (Version: 17.1.32112 - Microsoft Corporation) Hidden
WinAppDeploy (HKLM-x32\...\{2ADF1977-BF31-E127-B651-AC28A8658317}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinDjView 2.1 (HKLM\...\WinDjView) (Version: 2.1 - Andrew Zhezherun)
Windows SDK AddOn (HKLM-x32\...\{E18618EC-D9DB-4BCE-B382-85ADA2CBB340}) (Version: 10.1.0.0 - Microsoft Corporation)
Windows Software Development Kit - Windows 10.0.19041.685 (HKLM-x32\...\{4591faf1-a2db-4a3d-bfda-aa5a4ebb1587}) (Version: 10.1.19041.685 - Microsoft Corporation)
WinRT Intellisense Desktop - en-us (HKLM-x32\...\{BCF7CA0F-E53C-2A4F-B128-A751EC9A1016}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense Desktop - Other Languages (HKLM-x32\...\{B42BF427-AFDB-C00F-DB60-6F51395D74A1}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - en-us (HKLM-x32\...\{3335615C-ABEB-960E-2226-4274CD28E046}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense IoT - Other Languages (HKLM-x32\...\{216D5F47-257D-6284-5849-B51037875EFA}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense Mobile - en-us (HKLM-x32\...\{443FF51E-16C3-F23B-18FC-0D1D66024B0B}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - en-us (HKLM-x32\...\{15E29AFF-CB19-A20B-9A81-B0765A63115F}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense PPI - Other Languages (HKLM-x32\...\{FF2B49B7-0254-3D6A-4BE0-EF4C59DBCC2B}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - en-us (HKLM-x32\...\{0AF3B821-474B-1885-473A-6E3FB4F1CF71}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
WinRT Intellisense UAP - Other Languages (HKLM-x32\...\{8832F8ED-1035-9ABE-FD73-4E5ABAA84A5C}) (Version: 10.1.19041.685 - Microsoft Corporation) Hidden
Xshell 7 (HKLM-x32\...\{2C5F58B0-1BF6-4BD3-A665-C1B5206BDC17}) (Version: 7.0.0099 - NetSarang Computer, Inc.) Hidden
Xshell 7 (HKLM-x32\...\InstallShield_{2C5F58B0-1BF6-4BD3-A665-C1B5206BDC17}) (Version: 7.0.0099 - NetSarang Computer, Inc.)
百度网盘 (HKLM-x32\...\百度云管家) (Version: 7.14.1 - 北京度友科技有限公司)
欧路词典 (HKLM-x32\...\eudic) (Version: 12.0.0.0 - 欧路软件)
腾讯QQ (HKLM-x32\...\{052CFB79-9D62-42E3-8A15-DE66C2C97C3E}) (Version: 9.5.8.28186 - 腾讯科技(深圳)有限公司)
腾讯会议 (HKLM-x32\...\WeMeet) (Version: 3.7.6.404 - 腾讯科技(深圳)有限公司)
网易UU (HKLM-x32\...\NeteaseGacc) (Version: 4.22.0.50 - 网易公司)
网易云音乐 (HKLM-x32\...\网易云音乐) (Version: 2.9.8.199759 - 网易公司)
微信 (HKLM-x32\...\WeChat) (Version: 3.6.0.18 - 腾讯科技(深圳)有限公司)
Packages:
=========
AV1 Video Extension -> C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.1.50332.0_x64__8wekyb3d8bbwe [2022-03-20] (Microsoft Corporation)
Energy Star -> C:\Program Files\WindowsApps\AD2F1837.HPInc.EnergyStar_1.2.0.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.)
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_1.8.1.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.)
HP Privacy Settings -> C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.0.42.0_x64__v10z8vjag6ke6 [2022-03-21] (HP Inc.)
HP QuickDrop -> C:\Program Files\WindowsApps\AD2F1837.HPQuickDrop_2.5.9180.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_135.1.385.0_x64__v10z8vjag6ke6 [2022-03-22] (HP Inc.)
HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.15.66.0_x64__v10z8vjag6ke6 [2022-04-07] (HP Inc.)
HP System Event Utility -> C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_1.2.15.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.)
Intel® Graphics Command Center -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3408.0_x64__8j3eq9eme6ctt [2022-04-20] (INTEL CORP) [Startup Task]
Microsoft To Do -> C:\Program Files\WindowsApps\Microsoft.Todos_2.68.51091.0_x64__8wekyb3d8bbwe [2022-04-20] (Microsoft Corporation) [Startup Task]
Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_52.10404.374.0_x64__8wekyb3d8bbwe [2022-04-07] (Microsoft Corporation)
myHP -> C:\Program Files\WindowsApps\AD2F1837.myHP_1.10.53228.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.) [Startup Task]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-03-20] (NVIDIA Corp.)
OMEN Audio Control -> C:\Program Files\WindowsApps\AD2F1837.OMENAudioControl_1.29.257.0_x64__v10z8vjag6ke6 [2022-03-20] (HP Inc.)
OMEN Gaming Hub -> C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6 [2022-03-27] (HP Inc.) [Startup Task]
OMEN Light Studio -> C:\Program Files\WindowsApps\AD2F1837.OMENLightStudio_0.3.10.0_x64__v10z8vjag6ke6 [2022-04-09] (HP Inc.) [Startup Task]
Power Automate -> C:\Program Files\WindowsApps\Microsoft.PowerAutomateDesktop_10.0.3444.0_x64__8wekyb3d8bbwe [2022-04-01] (Microsoft Corporation) [Startup Task]
Python 3.10 -> C:\Program Files\WindowsApps\PythonSoftwareFoundation.Python.3.10_3.10.1264.0_x64__qbz5n2kfra8p0 [2022-03-25] (Python Software Foundation)
Snipaste -> C:\Program Files\WindowsApps\45479liulios.17062D84F7C46_2.7.3.0_x64__p7pnf6hceqser [2022-03-20] (Le Liu) [Startup Task]
惠普优享服务 -> C:\Program Files\WindowsApps\AD2F1837.E-QRcode_1.0.16.0_x64__v10z8vjag6ke6 [2022-03-21] (HP Inc.)
惠小微 -> C:\Program Files\WindowsApps\AD2F1837.19285F10D180_2.3.132.0_x64__v10z8vjag6ke6 [2022-04-20] (HP Inc.) [Startup Task]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{3D3B1846-CC43-42AE-BFF9-D914083C2BA3}\InprocServer32 -> C:\Users\YuchenTong\AppData\Local\SumatraPDF\PdfPreview.dll () [File not signed]
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{55808EA8-81FE-43c6-AAE8-1D8149F941D3}\InprocServer32 -> C:\Users\YuchenTong\AppData\Local\SumatraPDF\PdfFilter.dll () [File not signed]
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{679F137C-3162-45da-BE3C-2F9C3D093F64}\Shell\Open\Command -> C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{679F137C-3162-45da-BE3C-2F9C3D093F64} -> [百度网盘] => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\ [0000-00-00 00:00]
CustomCLSID: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001_Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32 -> => No File
ShellIconOverlayIdentifiers: [ .WorkspaceExt0] -> {C568C78A-652C-425B-8E6B-FFA73043302D} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ShellIconOverlayIdentifiers: [ .WorkspaceExt1] -> {2A6FE247-5DA3-4732-9626-77820518FD77} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ShellIconOverlayIdentifiers: [ .WorkspaceExt2] -> {FF895810-293B-464A-93F2-82D11E07EEC8} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ShellIconOverlayIdentifiers: [ .WorkspaceExt3] -> {D8BE1E70-244A-46F0-BC5B-077D5F29EED8} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [cloudmusic] -> {5C6A637C-9780-4D0F-A379-4732EDCCE7C3} => -> No File
ContextMenuHandlers1: [gvim] -> {51EEE242-AD87-11d3-9C1E-0090278BBD99} => C:\Program Files (x86)\Vim\vim82\GvimExt64\gvimext.dll [2021-05-03] (Tianmiao Hu's Developer Studio) [File not signed]
ContextMenuHandlers1: [YunShellExt] -> {6D85624F-305A-491d-8848-C1927AA0D790} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ContextMenuHandlers3: [QQShellExt] -> {53D2405C-48AB-4C8A-8F59-CE0610F13BBC} => C:\Program Files (x86)\Tencent\QQ\ShellExt\QQShellExt64.dll [2022-03-20] (Tencent Technology(Shenzhen) Company Limited -> Tencent)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [YunShellExt] -> {6D85624F-305A-491d-8848-C1927AA0D790} => C:\Users\YuchenTong\AppData\Roaming\baidu\BaiduNetdisk\YunShellExtV164.dll [2022-04-08] (Beijing Duyou Science and Technology Co.,Ltd. -> )
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\windows\System32\DriverStore\FileRepository\nvhm.inf_amd64_b5eab67518a4faa8\nvshext.dll [2022-01-27] (Nvidia Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [QQShellExt] -> {53D2405C-48AB-4C8A-8F59-CE0610F13BBC} => C:\Program Files (x86)\Tencent\QQ\ShellExt\QQShellExt64.dll [2022-03-20] (Tencent Technology(Shenzhen) Company Limited -> Tencent)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\YuchenTong\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Anaconda3 (64-bit)\Anaconda Prompt (anaconda3).lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> "/K" C:\Users\YuchenTong\anaconda3\Scripts\activate.bat C:\Users\YuchenTong\anaconda3
==================== Loaded Modules (Whitelisted) =============
2022-03-10 23:23 - 2022-03-10 23:23 - 001469440 _____ () [File not signed] C:\Program Files\WindowsApps\AD2F1837.HPQuickDrop_2.5.9180.0_x64__v10z8vjag6ke6\e_sqlite3.dll
2022-03-10 23:26 - 2022-03-10 23:26 - 000009216 _____ () [File not signed] C:\Program Files\WindowsApps\AD2F1837.myHP_1.10.53228.0_x64__v10z8vjag6ke6\ImagePipelineNative.dll
2022-03-10 23:25 - 2022-03-10 23:26 - 000033280 _____ () [File not signed] C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\NvidiaApi.dll
2020-10-22 18:05 - 2020-10-22 18:05 - 002812416 _____ () [File not signed] C:\Users\YuchenTong\Documents\Clash.for.Windows-0.12.1\ffmpeg.dll
2020-10-22 18:05 - 2020-10-22 18:05 - 000465408 _____ () [File not signed] C:\Users\YuchenTong\Documents\Clash.for.Windows-0.12.1\swiftshader\libegl.dll
2020-10-22 18:05 - 2020-10-22 18:05 - 003177984 _____ () [File not signed] C:\Users\YuchenTong\Documents\Clash.for.Windows-0.12.1\swiftshader\libglesv2.dll
2022-03-22 15:05 - 2022-03-22 15:05 - 000138240 _____ () [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_32\Interop.IWs06dcaa36#\f90e72b12d0aa935d781e317202c1f9b\Interop.IWshRuntimeLibrary.ni.dll
2022-03-20 15:06 - 2022-03-20 15:06 - 000107008 _____ (Facebook, Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.myHP_1.10.53228.0_x64__v10z8vjag6ke6\yoga.dll
2022-03-22 12:59 - 2022-03-22 12:59 - 000139776 _____ (hardcodet.net) [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_32\Hardcodet.W6cab32f3#\07cc04e050bf3a2b713a6738ca1e8d65\Hardcodet.Wpf.TaskbarNotification.ni.dll
2022-03-20 15:03 - 2022-03-20 15:03 - 004086784 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.HPQuickDrop_2.5.9180.0_x64__v10z8vjag6ke6\core.pwa.dll
2022-03-20 15:03 - 2022-03-20 15:03 - 054239232 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.HPQuickDrop_2.5.9180.0_x64__v10z8vjag6ke6\HPQuickDrop.dll
2022-03-10 23:23 - 2022-03-10 23:23 - 000014336 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_1.2.15.0_x64__v10z8vjag6ke6\SystemEventUtility\NativeRpcClient.DLL
2022-03-10 23:26 - 2022-03-10 23:26 - 000014848 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.myHP_1.10.53228.0_x64__v10z8vjag6ke6\NativeRpcClient.dll
2022-03-26 18:51 - 2022-03-26 18:51 - 008441344 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\OmenCommandCenterApp_UWP.dll
2022-03-10 23:25 - 2022-03-10 23:26 - 000014848 _____ (HP Inc.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\NativeRpcClient.DLL
2022-03-20 14:08 - 2021-12-26 22:00 - 000093696 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2022-03-22 15:05 - 2022-03-22 15:05 - 001716736 _____ (Mark Heath & Contributors) [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_32\NAudio\343277c8ff5a08dd62ebb4ad5af2f83a\NAudio.ni.dll
2022-03-20 15:01 - 2022-03-20 15:01 - 000137168 _____ (Microsoft Windows -> Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_421.20070.95.0_x64__cw5n1h2txyewy\Dashboard\WebView2Loader.dll
2022-03-22 15:05 - 2022-03-22 15:05 - 003087360 _____ (Newtonsoft) [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\ec86693079e180f87ce3d207adb00ef8\Newtonsoft.Json.ni.dll
2022-03-21 15:32 - 2022-03-21 15:32 - 003864576 _____ (Newtonsoft) [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_64\Newtonsoft.Json\1cf4295c15101db684576474e0b8a99d\Newtonsoft.Json.ni.dll
2022-03-10 23:26 - 2022-03-10 23:26 - 001662976 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\SQLite.Interop.dll
2022-04-14 18:15 - 2022-04-14 18:15 - 000780288 _____ (The Apache Software Foundation) [File not signed] C:\windows\assembly\NativeImages_v4.0.30319_32\log4net\e778c533c97b157a48ab38caf5383865\log4net.ni.dll
2021-05-03 06:12 - 2021-05-03 06:12 - 000075264 _____ (Tianmiao Hu's Developer Studio) [File not signed] C:\Program Files (x86)\Vim\vim82\GvimExt64\gvimext.dll
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:341E39B2 [390]
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HipsDaemon => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.baidu.com/?tn=67074732_5_dg
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.baidu.com/?tn=67074732_5_dg
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://www.baidu.com/?tn=67074732_5_dg
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://www.baidu.com/?tn=67074732_5_dg
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.baidu.com/?tn=67074732_5_dg
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://www.baidu.com/?tn=67074732_5_dg
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
SearchScopes: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
SearchScopes: HKU\S-1-5-21-1919967345-4022050966-3323017305-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://baidu.com/s?tn=67074732_4_dg&wd={searchTerms}
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2022-03-28] (HP Inc. -> HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2022-03-20] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2022-03-28] (HP Inc. -> HP Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-04-05] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2021-06-05 20:08 - 2022-04-19 15:31 - 000000824 _____ C:\windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Common Files\Oracle\Java\javapath;C:\windows\system32;C:\windows;C:\windows\System32\Wbem;C:\windows\System32\WindowsPowerShell\v1.0\;C:\windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;".;C:\Program Files\Java\jdk-17.0.2\bin";C:\Program Files\Git\cmd;C:\Program Files\Maven\bin;C:\msys64\mingw64\bin;C:\Program Files (x86)\NetSarang\Xshell 7\;C:\Program Files (x86)\Vim\vim82;C:\Program Files\Graphviz\bin;C:\Program Files\dotnet\
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\Control Panel\Desktop\\Wallpaper -> C:\windows\web\wallpaper\HP Backgrounds\backgroundDefault.jpg
DNS Servers: 116.228.111.18 - 180.168.255.118
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
Network Binding:
=============
以太网: Realtek LightWeight Filter (NDIS6.40) -> nt_rtf64 (enabled)
WLAN: Realtek LightWeight Filter (NDIS6.40) -> nt_rtf64 (enabled)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
MSCONFIG\Services: BaiduNetdiskUtility => 3
MSCONFIG\Services: QQMusicService => 2
MSCONFIG\Services: SangforPWEx => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: WemeetUpdateSvc => 3
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKLM\...\StartupApproved\Run32: => "WPSPhotoPreInstallSetApp"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "HPSEU_Host_Launcher"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_0817AD55560C87EB70CBDEDADDDAA235"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "BaiduYunDetect"
HKU\S-1-5-21-1919967345-4022050966-3323017305-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{7DA42E6B-2E4A-4603-BD32-33394265AF12}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{C5302DBF-3633-43E8-8AB7-8EEE79270ED5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{BC737163-9A5C-45B4-ABF1-1B21DB0EC3FB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{11BBA3E3-5B4F-455A-9318-F21B682B304D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{F970D206-F5CF-43DA-B68F-0643C7A782BF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{2CEB1D1D-2389-42FE-AB53-6D12F19F545D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{AABED6A8-8D35-4B50-AF61-4629E56B5012}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{376DE13E-169B-469F-AD3B-C60242A30A21}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MinecraftEducationEdition_1.17.3200.0_x64__8wekyb3d8bbwe\Minecraft.Windows.exe (Microsoft Corporation -> )
FirewallRules: [{0A44B6AC-7971-4D3E-91DD-762241E31550}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MinecraftEducationEdition_1.17.3200.0_x64__8wekyb3d8bbwe\Minecraft.Windows.exe (Microsoft Corporation -> )
FirewallRules: [{DF60C237-4869-49C7-ABF3-AEFC61413F89}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{EB4D9AD9-7535-47AA-88D1-40AE3F0B7AFA}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{C68430DB-90F0-47E6-A83E-6FB0EC79A8EA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{CF0A5F2F-173A-415E-8595-973A5103E25C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{407EBEE8-586E-44DA-AC79-CDB22EE88008}] => (Allow) C:\Users\YuchenTong\AppData\Roaming\Tencent\QQ\STemp\SetupEx0\QQSetupEx.exe => No File
FirewallRules: [{C264AC50-88C8-4F61-816E-3E15AEF360A1}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChat.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{F5F15141-729F-4061-AC3C-28A231AD7244}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChatBrowser.exe => No File
FirewallRules: [{8811352F-0F21-413C-BABD-F4732E9ADF5F}] => (Allow) C:\Program Files (x86)\Tencent\WeChat\WeChatPlayer.exe => No File
FirewallRules: [{AF764A94-8E75-4BC8-BD06-9C7D4C5122D1}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\QQ.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{D6044CF9-8F2D-43FB-BE68-F064174A71F7}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\auclt.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{C5247D6D-FB17-4CCE-8E0B-CD6FFAD096CE}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\txupd.exe => No File
FirewallRules: [{AF7A5B46-779B-4DAC-B689-B9B7765E969F}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\SetupEx\SetupEx.exe => No File
FirewallRules: [{9782185C-FD83-409B-BDA3-5BDD470AB62B}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\maLauncher.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{4F30B925-E2B9-46E6-8952-3F92D7E1C819}] => (Allow) C:\Program Files (x86)\Tencent\QQ\Bin\maUpdat.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{A4DB6BA3-8BC0-44E0-8756-C5C015ED7372}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\tencentdl.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{B0850279-AAE9-483D-853A-8FC76EE38A7B}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\135\bugreport_xf.exe => No File
FirewallRules: [{5427E81C-5694-4528-BBBD-D6EBEE366BAD}] => (Allow) C:\Program Files (x86)\Tencent\QzoneMusic\QzoneMusic.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{3861EAEE-F630-49C8-A6BE-191C9C1C252C}] => (Allow) C:\Program Files (x86)\Tencent\QzoneMusic\QzoneMusic.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{093FE8BB-0901-43B0-8F90-A8D870AFDD79}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{6B67F1BA-1B52-44EB-B85D-B66A6CA92E01}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{FAB2A499-0EF2-4DA8-88D2-40591D2EC8D0}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{E70E4EF2-E813-4B2D-9061-55B96A388EC3}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{67012569-302A-452D-A0C3-A487F621A13B}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{C7F108E5-60BF-4833-A2C1-A8C00030FF1D}] => (Allow) C:\Program Files (x86)\Tencent\WeMeet\wemeetapp.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{11505E1C-E96E-4007-B5AD-4F5CB10C1BCE}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\QQMusicExternal.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{A9B90926-A38D-4E14-970A-2B5E79E8A7BA}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\moleplugin\tadb.exe => No File
FirewallRules: [{5988EB3C-59B5-4376-A6C6-97F7620E5FC8}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\QQMusic.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{E83F1526-EB2D-4695-AC4B-BBC06E782ED6}] => (Allow) C:\Program Files (x86)\Common Files\Tencent\QQMusic\QQMusicService.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{40290690-C5EE-4DFB-BA04-EBCC066528C1}] => (Allow) C:\Program Files (x86)\Tencent\QQMusic\QQMusicUp.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [TCP Query User{F2E1C50A-6D84-4D3E-8889-1A43B91C71BB}C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe] => (Allow) C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [UDP Query User{7BD18DC9-231D-4E7C-A781-5EE2B12FE770}C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe] => (Allow) C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [{327AA125-513C-4A38-BF95-397134680FF1}] => (Block) C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [{D1D80284-A1F3-43F5-AE87-BB5F9A1D67F5}] => (Block) C:\program files\jetbrains\intellij idea 2021.3.3\bin\idea64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [TCP Query User{34363D0E-9FD6-4774-82BC-49FE16C44C85}C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe] => (Allow) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [UDP Query User{9240DCA0-AA58-4927-84F9-1DF9B3B6BAFD}C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe] => (Allow) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{A20CDAC6-BD71-40DD-B56B-27075D32DE6B}] => (Block) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{BB5D847A-AE63-4FB0-B969-E0D8D47E9295}] => (Block) C:\users\yuchentong\appdata\roaming\tencent\wechat\xplugin\plugins\xweb\712\extracted\wechatbrowser.exe => No File
FirewallRules: [{5795EF24-9E37-4660-A24A-09A4B33BCB6C}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{E75F919B-CE28-4E17-B87E-9566491E3B34}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{9C8D4A57-B737-41A6-8CD9-F00F3A1C800A}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{D255A953-912A-49FC-A58B-44062CE71382}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{E4B2C5D0-3CB0-4751-A3BC-B329083B62E5}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{BEF34DD4-72E5-4F0F-8326-17BDC238DD3B}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{99DA3C15-7861-4C1A-A330-5B7A89EB16D7}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{84893C49-229A-486F-82B4-9A5C30DC1EC5}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{00F79B13-3147-4C92-A761-6EAB01FFB466}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{D7B70C93-A850-4FFD-9F74-12DA065AA17C}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{DB33C006-A66E-4960-A82E-1ABBF512E561}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{8934BD8C-6C46-4737-BE82-F291942CB4AA}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{DA24735B-944E-45DE-8C3C-F50D894C75E0}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{CE6F8D98-94BC-41AF-A030-72802F9190F3}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\HP.Omen.OmenCommandCenter.exe (HP Inc. -> HP Inc.)
FirewallRules: [{FE98FCB4-B513-467C-AF28-58580501F381}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\OmenCommandCenterBackground.exe (HP Inc. -> HP Inc.)
FirewallRules: [{34A24C60-05BC-42BE-9928-23C688E809E6}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2203.4.0_x64__v10z8vjag6ke6\win32\OmenCommandCenterBackground.exe (HP Inc. -> HP Inc.)
FirewallRules: [TCP Query User{47CEB3A3-1D58-4A92-9CA3-B70657680F46}C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe] => (Allow) C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
FirewallRules: [UDP Query User{C6B8D1BC-92DE-44EB-B6F7-E354C7C45506}C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe] => (Allow) C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
FirewallRules: [{52798339-0303-44C1-B25F-729F0CDA2CCD}] => (Block) C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
FirewallRules: [{FF185082-441F-4E47-93B0-06779E897EB1}] => (Block) C:\users\yuchentong\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe (Beijing Duyou Science and Technology Co.,Ltd. -> Baidu.com, Inc.)
FirewallRules: [{84C1F3DE-C1B4-4AB4-A039-7D7C4A3B543C}] => (Allow) C:\Program Files (x86)\Foxit Software\FoxitREC\FoxitREC.exe => No File
FirewallRules: [{071CA9CC-73A8-4D6C-B496-E560AED35BBB}] => (Allow) C:\Program Files (x86)\Foxit Software\FoxitREC\FoxitREC.exe => No File
FirewallRules: [TCP Query User{9668B88F-6F98-4212-86E2-F27711E0A03D}C:\program files (x86)\netease\cloudmusic\cloudmusic.exe] => (Allow) C:\program files (x86)\netease\cloudmusic\cloudmusic.exe (NetEase (Hangzhou) Network Co., Ltd -> NetEase)
FirewallRules: [UDP Query User{66A86057-1953-4770-A1ED-B4F58ACED3E7}C:\program files (x86)\netease\cloudmusic\cloudmusic.exe] => (Allow) C:\program files (x86)\netease\cloudmusic\cloudmusic.exe (NetEase (Hangzhou) Network Co., Ltd -> NetEase)
FirewallRules: [{5C5511D8-FE64-464D-9063-AF8039C17ADE}] => (Block) C:\program files (x86)\netease\cloudmusic\cloudmusic.exe (NetEase (Hangzhou) Network Co., Ltd -> NetEase)
FirewallRules: [{8B3B7A11-4E9D-4E60-99B3-953DE850A264}] => (Block) C:\program files (x86)\netease\cloudmusic\cloudmusic.exe (NetEase (Hangzhou) Network Co., Ltd -> NetEase)
FirewallRules: [{62FC4BCB-D741-4E90-914A-6C5E2A4FBDD8}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\XshellCore.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [{3C611267-694B-4BEB-A738-2DE55B283956}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\XshellCore.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [{4861606D-0EFE-41BA-B406-FB38D026FD92}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\Xshell.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [{AFFFA755-4CE6-4F1C-BEC0-9FF5F3DE21C5}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\Xshell.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [{A67C93E0-E727-4778-A399-2DBC11048DDB}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\Xagent.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [{A96C2BD6-C420-4F76-A1D4-703C178D17D3}] => (Allow) C:\Program Files (x86)\NetSarang\Xshell 7\Xagent.exe (NetSarang Computer, Inc. -> NetSarang Computer, Inc.)
FirewallRules: [TCP Query User{40F5216D-05C5-41FA-BAD3-9B4ECB8FAE4C}C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [UDP Query User{B25A318C-65EF-43D5-AD6A-D804E8CDC99D}C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [TCP Query User{12414319-2366-46B5-A707-FF93AA924B4F}C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe => No File
FirewallRules: [UDP Query User{14B1CED0-2B7A-4F20-8070-B08FF22EAF7E}C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe] => (Allow) C:\program files (x86)\sangfor\ssl\sangforcsclient\sangforcsclient.exe => No File
FirewallRules: [{DAF1A415-8652-4441-BB68-EA7A31779DDE}] => (Block) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [{D1476AD9-9E5C-4BE0-B4F4-6B1CE3F79BD1}] => (Block) C:\program files (x86)\sangfor\ssl\sangforserviceclient\sangforserviceclient.exe => No File
FirewallRules: [TCP Query User{8655244C-E20B-4902-8651-6F13636F5B50}C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe] => (Allow) C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [UDP Query User{BCE0367A-79C1-412D-8C89-801ABF60276B}C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe] => (Allow) C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [{969D9781-DD38-4DB9-B430-6527845855C7}] => (Block) C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [{82700716-2DC1-4C2C-A31F-95CB71CBC280}] => (Block) C:\program files\jetbrains\clion 2021.3.4\bin\clion64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [TCP Query User{62EE4435-74ED-4BEC-BEE7-21969B6BADDB}C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe] => (Allow) C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{142CBB55-F714-4B3A-9F57-7583FF133063}C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe] => (Allow) C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{EE88E1C8-CA35-4A0B-9B8B-74F2ED9B7506}] => (Block) C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{49BD33B2-2B4D-4825-B904-2AD708376B68}] => (Block) C:\users\yuchentong\appdata\local\programs\microsoft vs code\code.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4A54105F-D224-47FB-B1AB-ED55784013CA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crusader Kings III\launcher\dowser.exe => No File
FirewallRules: [{A32C8932-5E39-4587-94C2-5C5DB268F55C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Crusader Kings III\launcher\dowser.exe => No File
FirewallRules: [TCP Query User{AD721708-BE92-4E5D-A6CC-E4CD835B5E5A}C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [UDP Query User{6724343B-004C-4028-B1CF-77F9BD0EB442}C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [{FABCF631-6EEC-4871-B727-55313768CF50}] => (Block) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [{B4362568-E511-4425-B943-F508CC561AF2}] => (Block) C:\program files (x86)\steam\steamapps\common\forzahorizon4\forzahorizon4.exe => No File
FirewallRules: [{48CBA06F-8670-4721-8E9F-C8BBCAEF7090}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Europa Universalis IV\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [{55792C4E-7555-472C-A63E-B63CC2F0F26B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Europa Universalis IV\dowser.exe (Paradox Interactive AB (publ) -> )
FirewallRules: [{F5C08878-CD46-49D2-9A10-6000C5E652DA}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\100.0.1185.44\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Restore Points =========================
23-04-2022 18:15:29 Install : Huorong Internet Security
23-04-2022 22:32:26 Checkpoint by HitmanPro
23-04-2022 22:32:35 Checkpoint by HitmanPro
24-04-2022 14:12:37 Removed RPGXP
24-04-2022 14:13:10 Removed RGSS-RTP Standard
24-04-2022 14:51:19 Removed HP Audio Switch
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (04/24/2022 06:35:36 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 explorer.exe 版本 10.0.22000.593 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
进程 ID: 14e4
开始时间: 01d857c69f1b5485
终止时间: 0
应用程序路径: C:\Windows\explorer.exe
报告 ID: 6ec662ff-f22b-45bf-8594-25659d059a83
错误程序包全名:
错误程序包相关应用程序 ID:
挂起类型: Unknown
Error: (04/24/2022 06:30:10 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 explorer.exe 版本 10.0.22000.593 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
进程 ID: 1d1c
开始时间: 01d857c60d5afa81
终止时间: 0
应用程序路径: C:\Windows\explorer.exe
报告 ID: 7ce8c847-6c2c-4dca-8d16-db5d98eb4225
错误程序包全名:
错误程序包相关应用程序 ID:
挂起类型: Unknown
Error: (04/24/2022 03:26:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: 错误应用程序名称: DllHost.exe,版本: 10.0.22000.1,时间戳: 0x93f44fbf
错误模块名称: ntdll.dll,版本: 10.0.22000.527,时间戳: 0x931cda92
异常代码: 0xc0000374
错误偏移量: 0x000000000010c0a9
错误进程 ID: 0x2320
错误应用程序启动时间: 0x01d857a867978429
错误应用程序路径: C:\windows\system32\DllHost.exe
错误模块路径: C:\windows\SYSTEM32\ntdll.dll
报告 ID: 6cf746ae-a3cd-4403-a3be-ef08e412a49e
错误程序包全名:
错误程序包相对应用程序 ID:
Error: (04/24/2022 03:02:25 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 explorer.exe 版本 10.0.22000.593 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
进程 ID: 1c24
开始时间: 01d857a86711a04d
终止时间: 0
应用程序路径: C:\Windows\explorer.exe
报告 ID: 63f5213e-c01b-4e9e-9a50-16a50132905e
错误程序包全名:
错误程序包相关应用程序 ID:
挂起类型: Unknown
Error: (04/24/2022 02:50:15 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 gsam.exe 版本 4.2.33.5534 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
进程 ID: 26dc
开始时间: 01d857a4a1240029
终止时间: 4294967295
应用程序路径: C:\Program Files\GridinSoft Anti-Malware\gsam.exe
报告 ID: 9c19e33b-79f9-46e0-9d3b-295a1bb3e943
错误程序包全名:
错误程序包相关应用程序 ID:
挂起类型: Top level window is idle
Error: (04/24/2022 12:46:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 explorer.exe 版本 10.0.22000.593 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
进程 ID: 3478
开始时间: 01d857962cde2fb6
终止时间: 0
应用程序路径: C:\Windows\explorer.exe
报告 ID: 0ea12574-6c78-4bda-9fa7-731c49ad7ca2
错误程序包全名:
错误程序包相关应用程序 ID:
挂起类型: Unknown
Error: (04/24/2022 12:43:03 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 程序 explorer.exe 版本 10.0.22000.593 已停止与 Windows 交互并关闭。若要查看是否有关于该问题的详细信息,请检查“安全性与维护”控制面板中的问题历史记录。
进程 ID: 4304
开始时间: 01d857958f0dfafa
终止时间: 0
应用程序路径: C:\Windows\explorer.exe
报告 ID: 922ec38f-127d-4ed6-b1c2-ef502970cd4e
错误程序包全名:
错误程序包相关应用程序 ID:
挂起类型: Unknown
Error: (04/23/2022 10:32:26 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 卷影复制服务错误: 查询 IVssWriterCallback 接口时的错误。hr = 0x80070005, 拒绝访问。
。
此错误通常是由编写器或请求方过程中的错误安全设置造成的。
操作:
正在搜集写入程序数据
上下文:
写入程序类 ID: {e8132975-6f93-4464-a53e-1050253ae220}
写入程序名称: System Writer
写入程序实例 ID: {9ebd2d2b-bcad-4118-ab84-84e7bc4e097f}
System errors:
=============
Error: (04/24/2022 09:03:42 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。
SSPI 客户端进程 FRST64english (PID: 14680)。
Error: (04/24/2022 09:03:42 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。
SSPI 客户端进程 FRST64english (PID: 14680)。
Error: (04/24/2022 09:03:39 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。
SSPI 客户端进程 smartscreen (PID: 6624)。
Error: (04/24/2022 09:03:39 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。
SSPI 客户端进程 smartscreen (PID: 6624)。
Error: (04/24/2022 08:29:43 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。
SSPI 客户端进程 Widgets (PID: 3076)。
Error: (04/24/2022 08:29:43 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。
SSPI 客户端进程 Widgets (PID: 3076)。
Error: (04/24/2022 08:18:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: 由于下列错误,WinRing0_1_2_0 服务启动失败:
WinRing0_1_2_0 不是有效的 Win32 应用程序。
Error: (04/24/2022 08:14:41 PM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: 创建 TLS 客户端 凭据时出现严重错误。内部错误状态为 10013。
SSPI 客户端进程 HP.myHP (PID: 2836)。
Windows Defender:
================
Date: 2022-04-24 20:13:45
Description:
Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。
有关详细信息,请参阅以下内容:
名称: VirTool:Win32/ExcludeProc.D
严重性: 严重
类别: 工具
路径: CmdLine:_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4ARQB4AHQAZQBuAHMAaQBvAG4AIABAACgAJwBlAHgAZQAnACwAJwBkAGwAbAAnACkAIAAtAEYAbwByAGMAZQA=
检测起源: 未知
检测类型: 实际
检测源: 系统
用户: NT AUTHORITY\SYSTEM
进程名称: Unknown
安全智能版本: AV: 1.363.863.0, AS: 1.363.863.0, NIS: 1.363.863.0
引擎版本: AM: 1.1.19200.5, NIS: 1.1.19200.5
Date: 2022-04-24 20:13:45
Description:
Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。
有关详细信息,请参阅以下内容:
名称: Behavior:Win32/ExcludeProc.A
严重性: 严重
类别: 可疑行为
路径: behavior:_pid:13980:23860413273102; process:_pid:13980,ProcessStart:132952760257624314
检测起源: 未知
检测类型: 实际
检测源: 未知
用户:
进程名称: Unknown
安全智能版本: AV: 1.363.863.0, AS: 1.363.863.0, NIS: 1.363.863.0
引擎版本: AM: 1.1.19200.5, NIS: 1.1.19200.5
Date: 2022-04-24 20:13:45
Description:
Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。
有关详细信息,请参阅以下内容:
名称: VirTool:Win32/ExcludeProc.D
严重性: 严重
类别: 工具
路径: CmdLine:_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwAJABlAG4AdgA6AFMAeQBzAHQAZQBtAEQAcgBpAHYAZQApACAALQBGAG8AcgBjAGUA
检测起源: 未知
检测类型: 实际
检测源: 系统
用户: NT AUTHORITY\SYSTEM
进程名称: Unknown
安全智能版本: AV: 1.363.863.0, AS: 1.363.863.0, NIS: 1.363.863.0
引擎版本: AM: 1.1.19200.5, NIS: 1.1.19200.5
Date: 2022-04-24 19:07:33
Description:
Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。
有关详细信息,请参阅以下内容:
名称: Behavior:Win32/ExcludeProc.A
严重性: 严重
类别: 可疑行为
路径: behavior:_pid:5228:23860413273102; process:_pid:5228,ProcessStart:132952720529782387
检测起源: 未知
检测类型: 实际
检测源: 未知
用户:
进程名称: Unknown
安全智能版本: AV: 1.363.863.0, AS: 1.363.863.0, NIS: 1.363.863.0
引擎版本: AM: 1.1.19200.5, NIS: 1.1.19200.5
Date: 2022-04-24 19:07:33
Description:
Microsoft Defender 防病毒 检测到恶意软件或其他可能不需要的软件。
有关详细信息,请参阅以下内容:
名称: VirTool:Win32/ExcludeProc.D
严重性: 严重
类别: 工具
路径: CmdLine:_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4ARQB4AHQAZQBuAHMAaQBvAG4AIABAACgAJwBlAHgAZQAnACwAJwBkAGwAbAAnACkAIAAtAEYAbwByAGMAZQA=
检测起源: 未知
检测类型: 实际
检测源: 系统
用户: NT AUTHORITY\SYSTEM
进程名称: Unknown
安全智能版本: AV: 1.363.863.0, AS: 1.363.863.0, NIS: 1.363.863.0
引擎版本: AM: 1.1.19200.5, NIS: 1.1.19200.5
CodeIntegrity:
===============
Date: 2022-04-24 15:55:25
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2022-04-24 13:16:31
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNspX64.dll that did not meet the Windows signing level requirements.
Date: 2022-04-24 13:15:04
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Sangfor\SSL\ClientComponent\SangforNspX64.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: AMI F.05 03/10/2022
Motherboard: HP 8A13
Processor: 12th Gen Intel® Core i7-12700H
Percentage of memory in use: 39%
Total physical RAM: 16051.95 MB
Available physical RAM: 9779.8 MB
Total Virtual: 18483.95 MB
Available Virtual: 10846.68 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:476.03 GB) (Free:299.05 GB) NTFS
\\?\Volume{c77bf65e-6864-47ed-a37f-1bd96147e216}\ (Windows RE tools) (Fixed) (Total:0.64 GB) (Free:0.06 GB) NTFS
\\?\Volume{ff68de2f-964c-4623-ae36-2e554ef0424a}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.16 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: F50B9BA9)
Partition: GPT.
==================== End of Addition.txt =======================