Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

level1.exe malware appears on reboot


  • This topic is locked This topic is locked
20 replies to this topic

#1 user23049

user23049

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:09:12 PM

Posted 20 March 2024 - 09:19 PM

PC was sluggish so decided to do a malwarebytes scan.  Found quite a few pieces of malware which were quarantined.  Also ran SuperAntiSpyware which got leftovers.  I then did a reboot.  

 

I noticed when Windows first starts, there's two Admin Cmd prompt windows that appeared quickly and then went away.  I then got an error saying WinXBlueRay.exe cannot start.

 

I went into the msconfig startup folder and changed this exe to disabled.

 

I ran malwarebytes through again and it again found the same malware it previously removed so something is occurring upon startup.  It's placing the level1.exe here: C:\Users\Phil\AppData\Local\Desktop_inni

 

I've deleted this exe from the folder for now and have not rebooted again.  

 

Seems like a persistent infection and would like some help getting it fully removed as well as ensure nothing else is leftover.

 

Thanks

 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19.03.2024
Ran by Phil (administrator) on DELL-LAPTOP (Dell Inc. Inspiron 7559) (20-03-2024 21:25:35)
Running from C:\Users\Phil\Downloads\FRST64.exe
Loaded Profiles: Phil & SQLTELEMETRY & MSSQLSERVER
Platform: Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\crash_handler.exe <5>
(C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\PlayerLocationIcon.exe
(C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe ->) (OpenJS Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <5>
(C:\Program Files\WindowsApps\Microsoft.YourPhone_1.24021.105.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.24021.105.0_x64__8wekyb3d8bbwe\YourPhoneAppProxy.exe
(DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxCUIService.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxEM.exe
(explorer.exe ->) (Dell Inc -> Dell Inc.) [File not signed] C:\Program Files\Dell\QuickSet\quickset.exe
(explorer.exe ->) (Fresco Logic Inc -> Fresco Logic) C:\Program Files\Fresco Logic\Fresco Logic USB Display Driver\FL2000\x64\flvga_tray.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <17>
(explorer.exe ->) (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(explorer.exe ->) (Open Source Developer, XMouse Button Control -> Highresolution Enterprises) C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\WavesLocalServer.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\WavesPluginServer.exe
(Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Node.js Foundation -> Node.js) C:\Users\Phil\AppData\Roaming\Java\jre8\bin\java.exe
(rundll32.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe <2>
(services.exe ->) () [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe
(services.exe ->) (Apple Computer, Inc.) [File not signed] C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(services.exe ->) (Array Networks, Inc. -> Array Networks) C:\Program Files\Array Networks\SSL VPN Client\VPNService.exe
(services.exe ->) (Cisco Systems, Inc. -> Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe
(services.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome Remote Desktop\123.0.6312.16\remoting_host.exe <2>
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
(services.exe ->) (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxCUIService.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\IntelCpHDCPSvc.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\IntelCpHeciSvc.exe
(services.exe ->) (Intel® Wireless Display -> Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlceip.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdmig.inf_amd64_75c152d756d851ed\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Private Internet Access, Inc. -> ) C:\Program Files\Private Internet Access\pia-service.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (ShenZhen Foscam Intelligent Technology Co,Ltd -> ) C:\Program Files (x86)\IPCWebComponents\IPCPlgSvr.exe
(services.exe ->) (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.4163_none_7e304ec47c735f2e\TiWorker.exe
(svchost.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe <4>
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9278152 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [3075552 2015-04-29] (Dell Inc -> Dell Inc.) [File not signed]
HKLM\...\Run: [XMouseButtonControl] => C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe [1091568 2015-03-02] (Open Source Developer, XMouse Button Control -> Highresolution Enterprises)
HKLM\...\Run: [RtHDVBg_WAVES_SKYLAKE] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WebVPN] => C:\Program Files\Array Networks\SSL VPN Client\WebVPN.exe [1484728 2020-01-17] (Array Networks, Inc. -> Array Networks)
HKLM\...\Run: [LaunchMhttpd] => C:\Program Files\Array Networks\MotionPro VPN Client\MPInit.exe [1532344 2020-01-16] (Array Networks, Inc. -> Array Networks)
HKLM\...\Run: [flvga_tray] => C:\Program Files\Fresco Logic\Fresco Logic USB Display Driver\FL2000\x64\flvga_tray.exe [457336 2017-11-23] (Fresco Logic Inc -> Fresco Logic)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [723928 2017-01-26] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [322120 2017-04-19] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [9923856 2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [1224704 2017-05-17] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true (No File)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1160408 2017-07-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3500056 2017-07-27] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM-x32\...\Run: [flvga_tray32] => C:\Program Files\Fresco Logic\Fresco Logic USB Display Driver\FL2000\x86\flvga_tray.exe [431232 2017-11-23] (Fresco Logic Inc -> Fresco Logic)
HKLM-x32\...\Run: [LaunchMhttpd] => C:\Program Files\Array Networks\MotionPro VPN Client\MPInit.exe [1532344 2020-01-16] (Array Networks, Inc. -> Array Networks)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-08-04] (Adobe Inc. -> )
HKLM-x32\...\Run: [Cisconet] => "%AppData%\msftedit\WinXBlueRay.exe" (No File)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKLM\Software\Policies\...\system: [DisableLogonBackgroundImage] 1
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [11197680 2023-10-20] (RealDefense, LLC -> SUPERAntiSpyware)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [VideoGuardMonitor] => C:\Users\Phil\AppData\Local\Cisco\VideoGuardPlayer\VideoGuardMonitor\CiscoVideoGuardMonitor.exe [4155656 2016-06-14] (Cisco Video Technologies Israel Ltd. -> Cisco)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [31171504 2021-07-02] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [Lync] => C:\Program Files\Microsoft Office\Office15\lync.exe [28177288 2020-04-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [Trio.WakeNet] => C:\Users\Phil\AppData\Local\TrioNet\Trio.Net.exe (No File)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [rasapi32] => wscript.exe "C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT\rasapi32.js" [178 2023-09-30] () [File not signed] <==== ATTENTION
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [MicrosoftEdgeAutoLaunch_0848959D30B7A075789B21F3CF73AE30] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4060712 2024-03-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\RunOnce: [removerbat] => C:\ProgramData\remover.bat [307 2024-03-20] () [File not signed] <==== ATTENTION
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Ribbons.scr [153600 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [55432 2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\123.0.6312.58\Installer\chrmstp.exe [2024-03-19] (Google LLC -> Google LLC)
Startup: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Gqreader.lnk [2023-11-28]
ShortcutTarget: Gqreader.lnk -> C:\Users\Phil\AppData\Roaming\msftedit\WinXBluRay.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WavesLocalServer.lnk [2024-02-16]
ShortcutTarget: WavesLocalServer.lnk -> C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\WavesLocalServer.exe (Waves Inc -> Waves Audio Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WavesPluginServer.lnk [2024-02-16]
ShortcutTarget: WavesPluginServer.lnk -> C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\WavesPluginServer.exe (Waves Inc -> Waves Audio Ltd.)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {D0AF27D6-8368-4DA9-926B-288A91E56430} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {B232ECA6-D3D1-4EC4-A32D-E08E86763ED0} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe  -mode=scheduled (No File)
Task: {484B1CBC-6F11-4EC5-9BAD-B3A61D5E1965} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [40880 2021-07-02] (Garmin International, Inc. -> )
Task: {8B28A3DC-F851-49CC-AE5C-75B0DD295852} - System32\Tasks\GeoComply Service Check => C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\PlayerLocationCheckTask.cmd [1642 2024-02-21] () [File not signed] -> 
Task: {1D31A6C3-7C57-4FA5-8B5F-A51626FD4B69} - System32\Tasks\GeoComply Update Task => C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exe [6817472 2024-01-09] (GeoComply Solutions Inc. -> GeoComply)
Task: {76D5F9DF-E161-452D-8A12-2595ED40B702} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem124.0.6359.0{8357AD38-F079-4341-A798-7030F0EC8024} => C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
Task: {117E77E1-2BF4-4A8C-A5EF-AEE5D8733741} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [1698000 2015-06-05] (Intel® Software -> Intel Corporation)
Task: {5048683B-C65F-43DE-AB39-836AE917B600} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [1328392 2015-11-20] (Intel® Software -> Intel Corporation)
Task: {3D46B100-7552-4143-B86A-F2B9970703F6} - System32\Tasks\Intel\System.Windows.Presentatio00_clr0400 => C:\Windows\system32\rundll32.exe [71680 2023-11-14] (Microsoft Windows -> Microsoft Corporation) -> C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll SHEiflowfdqaa
Task: {CA1B9BF5-B927-4DEB-8A8A-D57A37594261} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4922296 2023-12-19] (Intel Corporation -> Intel Corporation)
Task: {57F4C7BD-EE60-4DCA-BED3-44916DF616EF} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4922296 2023-12-19] (Intel Corporation -> Intel Corporation)
Task: {18D9AD6F-8D24-475B-8B5C-36A6F6F4B070} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {65F73DCD-EC0C-44BE-814D-37B8092B83CF} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {7B4E0C68-BE5A-4442-A2BD-993BA50AA038} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe  --automatic (No File)
Task: {08B1DF6C-1595-4764-BA72-1D8D855A46CE} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [1626328 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {9070132A-D6CF-4990-BBCB-58F5540D4E27} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {4BDF54F0-3987-4DEF-AA67-8704AE9177F7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {D1C4A8EB-315A-4825-9DB7-4957252883A2} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\AppInstallerUpdater => C:\Windows\system32\rundll32.exe [71680 2023-11-14] (Microsoft Windows -> Microsoft Corporation) -> %windir%\system32\AppxDeploymentClient.dll,AppInstallerUpdateAllTask
Task: {1285EF45-46C2-4589-BE1B-1F5B589478BB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {163BFC57-00C4-4EFC-82F4-E3B8CA9A7709} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3633EEEE-A5BF-4403-A543-9B89FB7AA1BA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BCEBEA1C-119E-446B-BC40-C755C75A8DD1} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1483475722-1219764467-3277934236-1001 92F44938A7A458E5 => C:\Users\Phil\AppData\Local\Mozilla Firefox\firefox.exe [671648 2024-03-12] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\92F44938A7A458E5\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {721029C4-76FB-4967-BBB9-DC8094FC370A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 92F44938A7A458E5 => C:\Users\Phil\AppData\Local\Mozilla Firefox\default-browser-agent.exe [34720 2024-03-12] (Mozilla Corporation -> Mozilla Foundation)
Task: {D65748B1-D097-42BA-9B41-B4BD003B5160} - System32\Tasks\OneNote 5797 => C:\Users\Phil\AppData\Roaming\strt.cmd [444244 2024-03-05] () [File not signed] -> 
Task: {08CAD4CF-9FEA-4DB1-83B7-D9935729BC84} - System32\Tasks\OneNote 89688 => C:\Users\Phil\AppData\Roaming\strt.cmd [444244 2024-03-05] () [File not signed] -> 
Task: {63C0817E-7830-4189-BC23-F9E568C905D4} - System32\Tasks\Opera GX scheduled Autoupdate 1696112022 => C:\Users\Phil\AppData\Local\Programs\Opera GX\launcher.exe  --scheduledautoupdate $(Arg0) (No File)
Task: {44369712-8FE0-4ADE-93B5-90A17714898E} - System32\Tasks\Private Internet Access Startup => "C:\Program Files\pia_manager\pia_manager.exe"  --startup (No File)
Task: {72D88C66-E288-4856-82BB-0189C31F9503} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {3D13762D-057E-43AA-AC86-ADA65FB62FDF} - System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => C:\Windows\TEMP\DeleteFolderTask.exe  (No File) <==== ATTENTION
Task: {93D639BD-617B-4C2E-8178-42C2F35827DE} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\WINDOWS\System32\Wscript.exe [170496 2023-10-11] (Microsoft Windows -> Microsoft Corporation) -> //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs" <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\24F553: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\44C496E6B6F51405F574F6474716: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\7416C616879702351303B273163673: [DhcpNameServer] 192.168.34.212
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\757535F5445313243313: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\765647F66666D697C61677E6: [DhcpNameServer] 192.168.209.47
Tcpip\..\Interfaces\{2ace0890-853d-46fd-9bd1-a8b7f498fe12}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f0e1c8ca-7fe6-4c84-8e99-04a669df5c9c}: [DhcpNameServer] 209.222.18.222 209.222.18.218
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
 
Edge: 
=======
Edge Profile: C:\Users\Phil\AppData\Local\Microsoft\Edge\User Data\Default [2024-03-20]
Edge DownloadDir: Default -> C:\Users\Phil\Downloads
Edge Extension: (Google Docs Offline) - C:\Users\Phil\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-07]
Edge Extension: (Edge relevant text changes) - C:\Users\Phil\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-23]
 
FireFox:
========
FF DefaultProfile: csjgqetv.default
FF ProfilePath: C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\csjgqetv.default [2023-06-12]
FF ProfilePath: C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\xvi6q9b2.default-release [2024-03-20]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.15@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2018-05-19] [Legacy]
FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google Inc -> Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @IPC/npmedia3.0.0.3,version=3.0.0.3 -> C:\Program Files\webrec\Torch\3.0.0.3\npmedia3.0.0.3.dll [2016-11-03] (Amcrest Technologies LLC -> )
FF Plugin-x32: @IPCWebComponents -> C:\Program Files (x86)\IPCWebComponents\npIPCReg.dll [2016-12-26] (ShenZhen Foscam Intelligent Technology Co,Ltd -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2017-08-17] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-03-20]
CHR Extension: (lock) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aeblfdkhhhdcdjpifhhbdiojplfjncoa [2024-03-05]
CHR Extension: (PayPal Honey: Automatic Coupons & Cash Back) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2024-02-19]
CHR Extension: (uBlock Origin) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2024-02-26]
CHR Extension: (Videostream for Google Chromecast™) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2020-05-26]
CHR Extension: (Tampermonkey) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2024-01-20]
CHR Extension: (Video Downloader Professional) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2023-04-19]
CHR Extension: (Yoroi) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ffnbelfdoeiohenkjibnmadjiehjhajb [2024-03-20]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-19]
CHR Extension: (Google Docs Offline) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-20]
CHR Extension: (Lightning Extension) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hfglcknhngdnhbkccblidlkljgflofgh [2023-04-25]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2023-04-08]
CHR Extension: (SponsorBlock for YouTube - Skip Sponsorships) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mnjggcdmjocbbbhaepdhchncahnbgone [2024-03-20]
CHR Extension: (Spread3D Review for SketchUp) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ncjkndlllagaajogioiailncjbmbalci [2018-03-13]
CHR Extension: (MetaMask) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn [2024-03-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-03]
CHR Extension: (Amcrest Web View) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oddndbjhpcpopbebhonolceinkbnheih [2018-03-13]
CHR Extension: (uBlock Origin Extra) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pgdnlhfefecpicbbihgmbmffkjpaplco [2019-09-10]
CHR Profile: C:\Users\Phil\AppData\Local\Google\Chrome\User Data\System Profile [2023-11-19]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2017-07-27]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2021-01-09] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82640 2017-07-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
R2 Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed]
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\123.0.6312.16\remoting_host.exe [74016 2024-02-26] (Google LLC -> Google LLC)
R2 com.geocomply.internal-updater-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exe [11492528 2024-02-21] (GeoComply Solutions Inc. -> )
R2 com.geocomply.process-scanner-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe [11494064 2024-02-21] (GeoComply Solutions Inc. -> )
R2 com.geocomply.vm-detector-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exe [11534000 2024-02-21] (GeoComply Solutions Inc. -> )
R2 com.geocomply.wifi-scanner-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exe [11514544 2024-02-21] (GeoComply Solutions Inc. -> )
S4 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [153328 2015-06-15] (Dell Inc. -> Dell Inc.)
S4 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [119656 2016-01-15] (Dell Inc. -> Dell)
S4 Dell Help & Support; C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe [49864 2015-07-31] (Dell Inc. -> )
S4 Dell Product Registration; C:\Program Files\Dell\Product Registration\PRSvc.exe [32104 2016-01-25] (Dell Inc. -> Dell)
S4 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc. -> Dell Inc.)
R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [43784 2023-09-25] (Intel Corporation -> Intel)
R3 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [240392 2023-11-13] (Intel Corporation -> Intel)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2016-03-04] (Macrovision Europe Ltd.) [File not signed]
R2 FosCloudSvr; C:\Program Files (x86)\IPCWebComponents\IPCPlgSvr.exe [91776 2016-12-26] (ShenZhen Foscam Intelligent Technology Co,Ltd -> )
S2 GoogleUpdaterInternalService124.0.6359.0; C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
S2 GoogleUpdaterService124.0.6359.0; C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
S3 Intel® Security Assist; C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S3 Intel® WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [396992 2015-07-06] (Intel® Wireless Display -> Intel)
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R4 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [11072008 2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9343840 2023-12-20] (Malwarebytes Inc. -> Malwarebytes)
S3 MSIInstallManager; C:\Program Files (x86)\Array Networks\MPMSIInstallManager\MSIInstallManager.exe [723896 2020-01-17] (Array Networks, Inc. -> TODO: <Company name>)
S3 MsMpiLaunchSvc; C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe [23040 2016-03-04] () [File not signed]
R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [479128 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvdmig.inf_amd64_75c152d756d851ed\Display.NvContainer\NVDisplay.Container.exe [1274888 2023-11-10] (NVIDIA Corporation -> NVIDIA Corporation)
R2 Player Location Check; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe [11440816 2024-02-21] (GeoComply Solutions Inc. -> )
R2 PrivateInternetAccessService; C:\Program Files\Private Internet Access\pia-service.exe [1394400 2024-03-05] (Private Internet Access, Inc. -> )
S3 PrivateInternetAccessWireguard; C:\Program Files\Private Internet Access\pia-wgservice.exe [4455000 2024-03-05] (Private Internet Access, Inc. -> )
S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [572824 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
R2 SQLTELEMETRY; C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlceip.exe [246672 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [21242680 2024-02-19] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 VPNInstallManager; C:\Program Files\Array Networks\Install Manager\VPNInstallManager.exe [1418168 2020-01-17] (Array Networks, Inc. -> Array Networks)
R2 VPNService; C:\Program Files\Array Networks\SSL VPN Client\VPNService.exe [2422200 2020-01-17] (Array Networks, Inc. -> Array Networks)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\NisSrv.exe [3191272 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe [133688 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 FoxitReaderService; "C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe" [X]
S2 IAStorDataMgrSvc; "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe" [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BEHRINGER_2902; C:\WINDOWS\System32\Drivers\BUSB2902.sys [460864 2009-10-30] (Ploytec GmbH -> BEHRINGER)
S3 BUSB_AUDIO_WDM; C:\WINDOWS\system32\drivers\busbwdm.sys [49728 2009-10-30] (Ploytec GmbH -> BEHRINGER)
S3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [41608 2018-02-10] (Techporch Incorporated -> Dell Inc.)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-02-10] (Techporch Incorporated -> Dell Computer Corporation)
R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [19440 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> OSR Open Systems Resources, Inc.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 fl2000; C:\WINDOWS\System32\drivers\fl2000.sys [205944 2017-11-23] (Fresco Logic Inc -> Fresco Logic)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-04-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-03-20] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MpKsl84e8ac6a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4370A5BF-1229-4DE6-B7EF-28EA2BA302AD}\MpKslDrv.sys [300312 2024-03-20] (Microsoft Windows -> Microsoft Corporation)
R2 NPF; C:\Program Files (x86)\Batch Configuration\npf64.sys [36600 2019-05-20] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S4 RsFx0501; C:\WINDOWS\System32\DRIVERS\RsFx0501.sys [261784 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [27744 2021-03-09] (Daniel Terhell -> Resplendence Software Projects Sp.)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [18160 2023-08-25] (RealDefense, LLC -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [15600 2023-08-25] (RealDefense, LLC -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [315904 2023-12-13] (Microsoft Windows -> Microsoft Corporation)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 tap-pia-0901; C:\WINDOWS\System32\drivers\tap-pia-0901.sys [39944 2020-12-01] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2017-12-27] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 tapwindscribe0901; C:\WINDOWS\System32\drivers\tapwindscribe0901.sys [54896 2017-09-13] (Windscribe Limited -> The OpenVPN Project)
R1 UimBus; C:\WINDOWS\System32\drivers\UimBus.sys [102576 2015-11-10] (Paragon Software GmbH -> )
R1 Uim_DEVIM; C:\WINDOWS\System32\drivers\uim_devim.sys [25904 2015-11-10] (Paragon Software GmbH -> )
R1 Uim_IM; C:\WINDOWS\System32\drivers\uim_im.sys [701360 2015-11-10] (Paragon Software GmbH -> )
S3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [212056 2015-07-06] (Intel® Wireless Display -> Windows ® Win 7 DDK provider)
R1 veracrypt; C:\WINDOWS\System32\drivers\veracrypt.sys [831616 2021-01-03] (IDRIX SARL -> IDRIX)
R1 vpntdi; C:\WINDOWS\System32\drivers\vpntdi64.sys [65360 2017-12-13] (Array Networks, Inc. -> Array Networks)
S3 vpnva; C:\WINDOWS\System32\drivers\vpnva64-6.sys [52592 2016-02-29] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
R0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20928 2024-03-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [603416 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105752 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
R3 WinDriver6; C:\WINDOWS\system32\drivers\windrvr6.sys [285696 2007-06-17] (Microsoft Windows Hardware Compatibility Publisher -> Jungo)
S3 ysusb_w10_64; C:\WINDOWS\system32\drivers\ysusb_w10_64.sys [181784 2023-02-10] (Microsoft Windows Hardware Compatibility Publisher -> Yamaha Corporation)
S3 DrvSnSht; \??\C:\Users\Phil\AppData\Local\Temp\RarSFX0\DrvSnSht64.sys [X] <==== ATTENTION
S3 R-ImageDisk; \??\C:\Users\Phil\AppData\Local\Temp\RarSFX0\R-ImageDisk64.sys [X] <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2024-03-20 21:25 - 2024-03-20 21:26 - 000046423 _____ C:\Users\Phil\Downloads\FRST.txt
2024-03-20 21:24 - 2024-03-20 21:25 - 000000000 ____D C:\FRST
2024-03-20 21:23 - 2024-03-20 21:23 - 002390528 _____ (Farbar) C:\Users\Phil\Downloads\FRST64.exe
2024-03-20 21:08 - 2024-03-20 21:08 - 000000307 _____ C:\ProgramData\remover.bat
2024-03-20 19:46 - 2024-03-20 19:46 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2024-03-20 17:37 - 2024-03-20 17:37 - 000001463 _____ C:\Users\Phil\Desktop\Roblox Player.lnk
2024-03-17 11:07 - 2024-03-17 11:07 - 000001138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Private Internet Access.lnk
2024-03-15 20:50 - 2024-03-18 10:46 - 000001989 _____ C:\Users\Phil\Desktop\dydx.txt
2024-03-14 20:33 - 2024-03-14 20:33 - 000002302 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2024-03-14 20:33 - 2024-03-14 20:33 - 000002290 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
2024-03-14 20:33 - 2024-03-14 20:33 - 000000000 ____D C:\Program Files\Google
2024-03-13 23:05 - 2024-03-13 23:05 - 000000000 ____D C:\Users\Phil\AppData\Roaming\ReAmp Studio R1
2024-03-13 23:02 - 2024-03-13 23:02 - 003218427 _____ (Audio Assault ) C:\WINDOWS\unins000.exe
2024-03-13 23:02 - 2024-03-13 23:02 - 000060501 _____ C:\WINDOWS\unins000.dat
2024-03-13 23:02 - 2024-03-13 23:02 - 000000000 ____D C:\Users\Public\Documents\Audio Assault
2024-03-13 23:02 - 2024-03-13 23:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ReAmp Studio R1
2024-03-13 19:50 - 2024-03-13 19:50 - 000019530 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-03-13 19:50 - 2024-03-13 19:50 - 000019530 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2024-03-13 19:44 - 2024-03-13 19:44 - 000000000 ___HD C:\$WinREAgent
2024-03-12 14:23 - 2024-03-20 19:11 - 000000000 ____D C:\Users\Phil\AppData\Local\Mozilla Firefox
2024-03-11 14:38 - 2024-03-11 14:38 - 000000030 _____ C:\Users\Phil\Documents\roto tom tunings.txt
2024-03-06 18:10 - 2024-03-20 17:38 - 000002425 _____ C:\WINDOWS\system32\default_error_stack-000000-000000.txt
2024-03-05 16:16 - 2024-03-05 16:16 - 000000000 ____D C:\ProgramData\{97BAC61B-4997-4F27-8567-391BD82F596A}
2024-03-05 16:15 - 2024-03-20 21:21 - 000000000 ____D C:\Users\Phil\AppData\Local\Desktop_inni
2024-03-05 16:15 - 2024-03-05 16:15 - 000003310 _____ C:\WINDOWS\system32\Tasks\OneNote 5797
2024-03-05 16:15 - 2024-03-05 16:15 - 000000000 ____D C:\ProgramData\{3FCE7907-AA6B-470A-BFB2-C042375EDBDF}
2024-03-04 14:15 - 2024-03-04 14:15 - 000000920 _____ C:\Users\Public\Desktop\TeamViewer.lnk
2024-03-01 17:34 - 2024-03-01 17:35 - 398253515 _____ C:\Users\Phil\Downloads\044Dry_Stems.zip
2024-03-01 17:28 - 2024-03-01 17:34 - 000000000 ____D C:\Users\Phil\Downloads\044Dry_Stems
2024-02-27 16:04 - 2024-02-27 16:04 - 000214867 _____ C:\Users\Phil\Desktop\blank travel sheet (1).odt
2024-02-21 18:31 - 2024-02-21 18:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon
2024-02-21 18:31 - 2024-02-21 18:31 - 000000000 ____D C:\Program Files\LatencyMon
2024-02-21 18:31 - 2021-03-09 16:07 - 000027744 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspLLL64.sys
2024-02-21 18:30 - 2024-02-21 18:30 - 003478312 _____ (Resplendence Software Projects Sp. ) C:\Users\Phil\Desktop\LatencyMon.exe
2024-02-21 12:35 - 2024-02-22 16:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\H&R Block 2023
2024-02-21 12:35 - 2024-02-22 16:32 - 000000000 ____D C:\Program Files (x86)\HRBlock2023
2024-02-21 12:35 - 2024-02-21 12:35 - 000000000 ____D C:\Users\Phil\Documents\HRBlock
2024-02-21 12:35 - 2024-02-21 12:35 - 000000000 ____D C:\Program Files (x86)\PDF995
2024-02-21 08:25 - 2024-02-21 08:25 - 000003442 _____ C:\WINDOWS\system32\Tasks\GeoComply Update Task
2024-02-21 08:25 - 2024-02-21 08:25 - 000003212 _____ C:\WINDOWS\system32\Tasks\GeoComply Service Check
2024-02-20 15:02 - 2024-02-20 15:02 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2024-03-20 21:22 - 2016-03-04 12:29 - 000000000 ____D C:\Users\Phil\AppData\Local\ClassicShell
2024-03-20 21:16 - 2023-11-28 17:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\msftedit
2024-03-20 21:12 - 2020-08-30 06:22 - 001007224 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-03-20 21:12 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2024-03-20 21:08 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-03-20 21:08 - 2016-03-03 23:10 - 000000000 __SHD C:\Users\Phil\IntelGraphicsProfiles
2024-03-20 21:07 - 2024-01-16 01:52 - 000008192 ___SH C:\DumpStack.log.tmp
2024-03-20 21:07 - 2023-10-28 09:21 - 000000000 ____D C:\Program Files\TeamViewer
2024-03-20 21:07 - 2020-08-30 06:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-03-20 21:07 - 2020-08-30 06:10 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-03-20 21:07 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2024-03-20 21:07 - 2017-07-29 22:04 - 000000000 ____D C:\ProgramData\NVIDIA
2024-03-20 20:59 - 2023-09-25 15:13 - 000000000 ____D C:\Users\Phil\AppData\Local\Malwarebytes
2024-03-20 20:07 - 2017-08-20 22:15 - 000002370 ____H C:\Users\Phil\Documents\Default.rdp
2024-03-20 20:01 - 2019-12-07 05:50 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2024-03-20 20:00 - 2023-01-29 12:31 - 000000000 ____D C:\Users\Phil\Desktop\Desktop icons
2024-03-20 19:47 - 2015-12-11 11:58 - 000000000 ____D C:\ProgramData\Package Cache
2024-03-20 19:46 - 2017-07-29 22:03 - 000000000 ____D C:\Program Files (x86)\Intel
2024-03-20 19:00 - 2024-01-30 23:33 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Celemony Software GmbH
2024-03-20 18:56 - 2024-02-16 10:36 - 000000000 ____D C:\Users\Phil\AppData\Local\central-updater
2024-03-20 18:56 - 2024-02-16 10:21 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Waves Central
2024-03-20 17:49 - 2020-08-30 06:11 - 000000000 ____D C:\Users\SQLTELEMETRY
2024-03-20 17:49 - 2020-08-30 06:11 - 000000000 ____D C:\Users\MSSQLSERVER
2024-03-20 17:45 - 2024-02-07 10:57 - 000000000 ____D C:\Users\Phil\AppData\Roaming\OracleJDK
2024-03-20 17:37 - 2023-06-08 17:28 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2024-03-20 06:52 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-03-19 19:39 - 2021-12-15 03:44 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-03-19 19:39 - 2020-04-10 21:15 - 000000000 ____D C:\Users\Phil\AppData\Roaming\qBittorrent
2024-03-19 19:39 - 2016-03-04 12:41 - 000002340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-03-19 19:39 - 2016-03-04 12:41 - 000002299 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-03-19 13:51 - 2023-06-12 13:02 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-03-19 08:11 - 2023-06-12 13:02 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2024-03-19 08:10 - 2023-06-12 13:02 - 000001325 _____ C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-03-19 01:21 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-03-18 15:54 - 2016-03-06 12:38 - 000000000 ____D C:\Users\Phil\AppData\Local\CrashDumps
2024-03-17 20:40 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2024-03-17 16:08 - 2016-03-04 16:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Microsoft\Word
2024-03-17 15:36 - 2016-03-05 11:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Microsoft\Excel
2024-03-17 11:43 - 2016-03-05 18:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\vlc
2024-03-17 11:07 - 2020-12-03 18:58 - 000000000 ____D C:\Program Files\Private Internet Access
2024-03-16 06:53 - 2020-07-04 03:13 - 000002479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-03-15 20:52 - 2020-08-30 06:10 - 005466128 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-03-15 20:51 - 2019-12-07 05:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2024-03-15 20:51 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\servicing
2024-03-15 20:00 - 2024-02-05 18:07 - 000000000 ___HD C:\Users\Phil\AppData\Roaming\winsQ
2024-03-13 23:02 - 2023-09-25 15:46 - 000000000 ____D C:\Program Files\Common Files\VST3
2024-03-13 19:53 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-03-13 19:50 - 2020-08-30 06:16 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-03-13 12:45 - 2023-10-12 08:15 - 000000000 ____D C:\Users\Phil\Documents\Studio One
2024-03-13 01:00 - 2018-02-28 15:34 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-03-06 00:47 - 2020-08-30 06:18 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-03-06 00:47 - 2020-08-30 06:18 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-03-05 16:15 - 2024-02-05 17:30 - 000444244 _____ C:\Users\Phil\AppData\Roaming\strt.cmd
2024-03-05 16:15 - 2023-08-16 12:46 - 000000000 ____D C:\Users\Phil\AppData\Local\Zoom
2024-03-03 02:16 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2024-03-02 06:59 - 2016-03-11 21:24 - 000000000 ____D C:\Users\Phil\AppData\Local\ElevatedDiagnostics
2024-02-28 14:56 - 2020-02-25 14:30 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Ledger Live
2024-02-28 14:34 - 2018-05-24 16:35 - 000000000 ____D C:\Users\Phil\AppData\Local\D3DSCache
2024-02-28 14:32 - 2021-10-17 15:01 - 000000000 ____D C:\Program Files\Ledger Live
2024-02-21 12:35 - 2019-02-16 15:06 - 000000000 ____D C:\Users\Phil\AppData\Roaming\TaxCut
2024-02-21 12:35 - 2019-02-16 15:05 - 000000000 ____D C:\ProgramData\TaxCut
2024-02-20 15:02 - 2016-03-04 12:41 - 000000000 ____D C:\Program Files (x86)\Google
 
==================== Files in the root of some directories ========
 
2024-03-20 21:08 - 2024-03-20 21:08 - 000000307 _____ () C:\ProgramData\remover.bat
2024-02-05 17:30 - 2024-03-05 16:15 - 000444244 _____ () C:\Users\Phil\AppData\Roaming\strt.cmd
2018-09-27 10:57 - 2018-09-27 10:57 - 000000000 _____ () C:\Users\Phil\AppData\Local\oobelibMkey.log
2016-10-27 20:51 - 2022-03-02 21:50 - 000007589 _____ () C:\Users\Phil\AppData\Local\Resmon.ResmonCfg
2024-02-16 10:49 - 2024-03-20 19:00 - 000103469 _____ () C:\Users\Phil\AppData\Local\wle.log
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
 


BC AdBot (Login to Remove)

 


#2 user23049

user23049
  • Topic Starter

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:09:12 PM

Posted 20 March 2024 - 10:28 PM

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19.03.2024
Ran by Phil (20-03-2024 21:26:43)
Running from C:\Users\Phil\Downloads
Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) (2020-08-30 10:18:48)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-1483475722-1219764467-3277934236-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1483475722-1219764467-3277934236-503 - Limited - Disabled)
Guest (S-1-5-21-1483475722-1219764467-3277934236-501 - Limited - Enabled)
Phil (S-1-5-21-1483475722-1219764467-3277934236-1001 - Administrator - Enabled) => C:\Users\Phil
WDAGUtilityAccount (S-1-5-21-1483475722-1219764467-3277934236-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov)
Active Directory Authentication Library for SQL Server (HKLM\...\{4EE99065-01C6-49DD-9EC6-E08AA5B13491}) (Version: 14.0.1000.169 - Microsoft Corporation)
Add or Remove Adobe Creative Suite 3 Master Collection (HKLM-x32\...\Adobe_4dcfd9b7e901b57f81f667144603236) (Version: 1.0 - Adobe Systems Incorporated)
adobe (HKLM\...\{20FD3B0E-D450-488F-AB68-7DA0EC0E4913}) (Version: 1.0.0000 - Adobe Systems Incorporated) Hidden
Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.22 - Adobe Systems)
Adobe After Effects CS3 Presets (HKLM-x32\...\{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}) (Version: 8 - Adobe Systems Incorporated) Hidden
Adobe Anchor Service CS3 (HKLM-x32\...\{90176341-0A8B-4CCC-A78D-F862228A6B95}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Asset Services CS3 (HKLM-x32\...\{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}) (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe Audition CC 2017 (HKLM-x32\...\AUDT_10_1_1) (Version: 10.1.1 - Adobe Systems Incorporated)
Adobe Bridge CS3 (HKLM-x32\...\{9C9824D9-9000-4373-A6A5-D0E5D4831394}) (Version: 2 - Adobe Systems Incorporated) Hidden
Adobe Bridge Start Meeting (HKLM-x32\...\{08B32819-6EEF-4057-AEDA-5AB681A36A23}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe BridgeTalk Plugin CS3 (HKLM-x32\...\{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Camera Raw 4.0 (HKLM-x32\...\{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}) (Version: 4.0 - Adobe Systems Incorporated) Hidden
Adobe CMaps (HKLM-x32\...\{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color - Photoshop Specific (HKLM-x32\...\{A2D81E70-2A98-4A08-A628-94388B063C5E}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color Common Settings (HKLM-x32\...\{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color EU Extra Settings (HKLM-x32\...\{51846830-E7B2-4218-8968-B77F0FF475B8}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color JA Extra Settings (HKLM-x32\...\{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color NA Recommended Settings (HKLM-x32\...\{95655ED4-7CA5-46DF-907F-7144877A32E5}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Creative Suite 3 Master Collection (HKLM-x32\...\{8718DC03-D066-4957-94E5-50C3C5042E8E}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Default Language CS3 (HKLM-x32\...\{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Device Central CS3 (HKLM-x32\...\{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe ExtendScript Toolkit 2 (HKLM-x32\...\{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}) (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Extension Manager CS3 (HKLM-x32\...\{BE5F3842-8309-4754-92D5-83E02E6077A3}) (Version: 1.8 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 9 ActiveX (HKLM-x32\...\{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}) (Version: 9.0.45.0 - Adobe Systems, Inc.)
Adobe Flash Player 9 Plugin (HKLM-x32\...\{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}) (Version: 9.0.45.0 - Adobe Systems, Inc.)
Adobe Fonts All (HKLM-x32\...\{6ABE0BEE-D572-4FE8-B434-9E72A289431B}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Help Viewer CS3 (HKLM-x32\...\{7ACFB90E-8FD0-4397-AD3A-5195412623A3}) (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe InDesign CS3 Icon Handler (HKLM-x32\...\{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}) (Version: 5.0 - Adobe Systems Incorporated) Hidden
Adobe Linguistics CS3 (HKLM-x32\...\{54793AA1-5001-42F4-ABB6-C364617C6078}) (Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe MotionPicture Color Files (HKLM-x32\...\{6B708481-748A-4EB4-97C1-CD386244FF77}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe PDF Library Files (HKLM-x32\...\{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}) (Version: 8.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CC 2019 (HKLM-x32\...\PHSP_20_0_4) (Version: 20.0.4 - Adobe Inc.)
Adobe Premiere Pro 2023 (HKLM-x32\...\PPRO_23_2) (Version: 23.2 - Adobe Inc.)
Adobe Setup (HKLM-x32\...\{4458C442-7376-4CF9-AF58-E8CEA6722363}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe SING CS3 (HKLM-x32\...\{B671CBFD-4109-4D35-9252-3062D3CCB7B2}) (Version: 0.1 - Adobe Systems Incorporated) Hidden
Adobe Stock Photos CS3 (HKLM-x32\...\{29E5EA97-5F74-4A57-B8B2-D4F169117183}) (Version: 1.5 - Adobe Systems Incorporated) Hidden
Adobe Type Support (HKLM-x32\...\{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Update Manager CS3 (HKLM-x32\...\{E69AE897-9E0B-485C-8552-7841F48D42D8}) (Version: 5.1.0 - Adobe Systems Incorporated) Hidden
Adobe Version Cue CS3 Client (HKLM-x32\...\{D0DFF92A-492E-4C40-B862-A74A173C25C5}) (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe Video Profiles (HKLM-x32\...\{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe WAS CS3 (HKLM-x32\...\{C5BD220A-EFE8-48A5-B70E-9503D535FACE}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe WinSoft Linguistics Plugin (HKLM-x32\...\{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe XMP DVA Panels CS3 (HKLM-x32\...\{0224CACC-994D-45F8-B973-D65056EA9C2F}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe XMP Panels CS3 (HKLM-x32\...\{D5A31AB1-345D-47C7-A87B-036A669F6DF1}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
AHV content for Acrobat and Flash (HKLM-x32\...\{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}) (Version: 1 - Adobe Systems Incorporated) Hidden
Amazon.com Fire_Devices (HKLM\...\Fire_Devices Drivers) (Version: 2 - Amazon.com)
ANT Drivers Installer x64 (HKLM\...\{CBEE7F70-D77E-46DB-BB02-B64147DD6453}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Batch Configuration (HKLM-x32\...\{F9F88CAE-A8BB-493A-BC71-B19A8BA38613}) (Version: 3.0.2.6 - hikvision)
BEHRINGER USB AUDIO DRIVER (HKLM\...\USB_AUDIO_DEusb-audio.deBehringer2902) (Version:  - )
Browser for SQL Server 2017 (HKLM-x32\...\{CF8EEB96-E7E7-4EF7-A0A1-559F09953156}) (Version: 14.0.1000.169 - Microsoft Corporation)
Bruteforce Save Data (HKLM-x32\...\Bruteforce Save Data) (Version:  - )
Calibration Update Wizard (HKLM-x32\...\{5A03CEC0-8805-11D4-ADFB-00000EFB3A77}) (Version: 8.20.1 - Toyota Diagnostics)
Celemony Melodyne 5 (HKLM\...\Celemony Melodyne 5_is1) (Version: 5.3.1.018 - Celemony)
Charter TV Player (HKLM-x32\...\{076af162-8f4c-4e36-9013-1673e5cf4d24}) (Version: 6.6 - Charter)
Chrome Remote Desktop Host (HKLM-x32\...\{00B18403-87DD-4C4E-AEB5-045B05B96F35}) (Version: 123.0.6312.16 - Google LLC)
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 4.4.03034 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\{EB629A98-5E69-40E8-BA9E-C393899F959D}) (Version: 4.4.03034 - Cisco Systems, Inc.) Hidden
Cisco VideoGuard Player (HKLM-x32\...\{dfc759fd-a56f-4d04-8306-d1480137a065}) (Version: 6.6 - Cisco Systems, Inc)
Cisco Webex Meetings (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\ActiveTouchMeetingClient) (Version: 40.8.5 - Cisco Webex LLC)
Classic Shell (HKLM\...\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft)
Dell Customer Connect (HKLM-x32\...\{99E581C6-471C-46CA-989E-3B17EB7E3F27}) (Version: 1.3.2.0 - Dell Inc.)
Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)
Dell Foundation Services (HKLM\...\{AE5E3C86-2633-4DAF-A7F4-C43D1E738BAE}) (Version: 3.1.3300.0 - Dell Inc.)
Dell Help & Support (HKLM\...\{9ACDDC24-55FE-4E7A-B4BD-DD9761F2F8AB}) (Version: 2.0.360.0 - Dell Inc.) Hidden
Dell Help & Support (HKLM-x32\...\InstallShield_{9ACDDC24-55FE-4E7A-B4BD-DD9761F2F8AB}) (Version: 2.0.360.0 - Dell Inc.)
Dell Update (HKLM-x32\...\{DB82968B-57A4-4397-81A5-ECAB21B5DFCD}) (Version: 1.7.1015.0 - Dell Inc.)
Documentation Manager (HKLM\...\{E904139A-DC55-420D-94C7-5D6297F3C385}) (Version: 23.30.0.6 - Intel Corporation) Hidden
Elevated Installer (HKLM-x32\...\{0F6C59A2-5F1D-4D7C-BC90-A0A1A75F4EE9}) (Version: 7.7.1.0 - Garmin Ltd or its subsidiaries) Hidden
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 8.1.4.1208 - Foxit Software Inc.)
Fresco Logic USB Display Driver (HKLM\...\{FC11E022-A625-48EA-85EB-AF2AFEF05B06}) (Version: 2.1.34054.0 - Fresco Logic)
Garmin Express (HKLM-x32\...\{50DF005C-1D2C-467A-A39E-10ADEFA83A96}) (Version: 7.7.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{9e0ef45d-b10c-42da-9aab-16200df39d95}) (Version: 7.7.1.0 - Garmin Ltd or its subsidiaries)
GDR 2002 for SQL Server 2017 (KB4293803) (64-bit) (HKLM\...\KB4293803) (Version: 14.0.2002.14 - Microsoft Corporation)
GDR 2014 for SQL Server 2017 (KB4494351) (64-bit) (HKLM\...\KB4494351) (Version: 14.0.2014.14 - Microsoft Corporation)
GDR 2027 for SQL Server 2017 (KB4505224) (64-bit) (HKLM\...\KB4505224) (Version: 14.0.2027.2 - Microsoft Corporation)
GDR 2037 for SQL Server 2017 (KB4583456) (64-bit) (HKLM\...\KB4583456) (Version: 14.0.2037.2 - Microsoft Corporation)
GDR 2042 for SQL Server 2017 (KB5014354) (64-bit) (HKLM\...\KB5014354) (Version: 14.0.2042.3 - Microsoft Corporation)
GDR 2047 for SQL Server 2017 (KB5021127) (64-bit) (HKLM\...\KB5021127) (Version: 14.0.2047.8 - Microsoft Corporation)
GDR 2052 for SQL Server 2017 (KB5029375) (64-bit) (HKLM\...\KB5029375) (Version: 14.0.2052.1 - Microsoft Corporation)
Get Good Drums One Kit Wonder - Architects (HKLM-x32\...\Get Good Drums One Kit Wonder - Architects) (Version: 1.0.0.4 - Get Good Drums)
GetGood Drums Smash and Grab 2 (HKLM\...\Smash and Grab 2_is1) (Version: 2.0.0 - GetGood Drums)
Google Chrome (HKLM-x32\...\{93EB1D27-3378-36DD-ACEC-380FEDB2297B}) (Version: 123.0.6312.58 - Google, Inc.)
Google Earth Plug-in (HKLM-x32\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google)
Google Earth Pro (HKLM\...\{3470AD08-85F2-4B1D-8487-FC4750732087}) (Version: 7.3.6.9796 - Google)
H&R Block Massachusetts 2021 (HKLM-x32\...\{482A887B-D7E3-473D-80E2-48FA6F695194}) (Version: 1.21.4201 - H&R Block, Inc.)
H&R Block Massachusetts 2022 (HKLM-x32\...\{4E5723A6-0AA2-4415-AF75-7E2CE63713F7}) (Version: 1.22.6201 - H&R Block, Inc.)
H&R Block Massachusetts 2023 (HKLM-x32\...\{F5FBEE1C-A0E1-4B44-86EE-0BABE29D668C}) (Version: 1.23.8701 - HRB Digital, LLC.)
H&R Block Premium + Efile + State 2021 (HKLM-x32\...\{EDB7F331-6C76-4B85-A8EC-764B213E2E51}) (Version: 21.07.6002 - HRB Technology, LLC.)
H&R Block Premium + Efile + State 2022 (HKLM-x32\...\{69654063-D165-4494-A83B-C09105247E97}) (Version: 22.07.7601 - HRB Technology, LLC.)
H&R Block Premium + Efile + State 2023 (HKLM-x32\...\{B0E2C9A7-F1FC-4376-9E0F-065DC3FAC392}) (Version: 23.07.8301 - HRB Technology, LLC.)
HandBrake 1.0.1 (HKLM-x32\...\HandBrake) (Version: 1.0.1 - )
Intel Driver && Support Assistant (HKLM-x32\...\{63B67EA4-4AE1-4A45-A67D-21318B4345EF}) (Version: 23.4.39.9 - Intel) Hidden
Intel Driver && Support Assistant (HKLM-x32\...\{7D392FB7-64D5-4813-B7F7-8AA462D3968D}) (Version: 23.4.39.9 - Intel) Hidden
Intel Extreme Tuning Utility (HKLM-x32\...\{7afa48c7-9901-40fa-8f9b-f0707e2bc5b6}) (Version: 6.2.0.24 - Intel Corporation)
Intel® Chipset Device Software (HKLM\...\{8C91A5EB-2C62-4A6D-8802-CC79FD2ED390}) (Version: 10.1.1.7 - Intel Corporation) Hidden
Intel® Chipset Device Software (HKLM-x32\...\{60c073df-e736-4210-9c3a-5fc2b651cef3}) (Version: 10.1.1.7 - Intel® Corporation) Hidden
Intel® Computing Improvement Program (HKLM\...\{15E71D2B-4046-4B9D-A8BB-EBFC5CC12D86}) (Version: 2.4.10717 - Intel Corporation)
Intel® Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.2.10900.330 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{5BD7E621-9791-4D9F-A620-1BA51153B749}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{EC465D35-92DC-4DAE-9EA8-01215688F709}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Driver (HKLM\...\{AC411813-5A0B-4960-882D-481BEEDC24E0}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® ME UninstallLegacy (HKLM\...\{E9B9A1A5-6398-4C99-8FDE-10794F6505C5}) (Version: 1.0.1.0 - Intel Corporation) Hidden
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.6859 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.16.1063 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{9503AD68-6198-4081-9F57-1F346D7B58D4}) (Version: 14.8.16.1063 - Intel Corporation) Hidden
Intel® Serial IO (HKLM\...\{51788BA4-D93F-4E7B-BA13-ACC88E7803DB}) (Version: 30.100.1519.07 - Intel Corporation) Hidden
Intel® Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation)
Intel® WiDi (HKLM\...\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation)
Intel® WiDi Software Asset Manager (HKLM-x32\...\{5B5CD20C-29F0-4857-A4FA-A4F4C716B019}) (Version: 1.1.347 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{00000030-0230-1033-84C8-B8D95FA3C8C3}) (Version: 23.30.0.3 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{b82e9573-04fb-4a9d-819f-6c358a1cf31a}) (Version: 23.4.39.9 - Intel)
Intel® Driver & Support Assistant (HKLM-x32\...\{ecbee3cf-26b3-4f27-854c-e2e16b3f7fa9}) (Version: 23.4.39.9 - Intel)
Intel® PROSet/Wireless Software (HKLM-x32\...\{5a64c890-83f9-4399-b0c9-5e9a80890fdd}) (Version: 21.40.1 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{68A981A0-ED59-41E0-B45E-7A78F643120D}) (Version: 21.40.1.3406 - Intel Corporation) Hidden
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Intel® Software Installer (HKLM-x32\...\{ae13aa25-496e-45dc-86f8-939f17f479f4}) (Version: 23.30.0.6 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (HKLM\...\{7D84E343-A23D-451C-B123-0195B2D903A6}) (Version: 1.42.17.0 - Intel Corporation) Hidden
IPCWebComponents 3.3.0.31 (HKLM-x32\...\{4740E1B2-51CF-4083-8976-D6B3B5A5064F}_is1) (Version: 3.3.0.31 - )
Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Kontakt 7 PORTABLE (HKLM\...\{770F4942-15B1-41AA-9E3E-C77B2CFB1366}_is1) (Version: 7.7.1 - Native Instruments)
LatencyMon 7.31 (HKLM\...\LatencyMon_is1) (Version: 7.31 - Resplendence Software Projects Sp.)
Ledger Live 2.77.2 (HKLM\...\c62032b2-0bca-5abc-b458-fd67cfc9e49b) (Version: 2.77.2 - Ledger Live Team)
Macrium Reflect Free (HKLM\...\{0D4965D1-6B46-4F0A-B42D-B17056612AE0}) (Version: 8.0.7279 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free (HKLM\...\MacriumReflect) (Version: v8.0.7279 - Paramount Software (UK) Ltd.)
Malwarebytes version 4.6.6.294 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.6.294 - Malwarebytes)
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.9060.3 - Waves Audio Ltd.) Hidden
Mazda Toolbox (HKLM-x32\...\Mazda Toolbox) (Version:  - )
Mazda Update Toolbox (HKLM-x32\...\Mazda Update Toolbox) (Version:  - )
MetaTrader 5 (HKLM\...\MetaTrader 5) (Version: 5.00 - MetaQuotes Ltd.)
Microsoft .NET Core Host - 3.1.32 (x64) (HKLM\...\{8A8E3A04-83BC-4CDE-9259-893B666C1AB1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Host FX Resolver - 3.1.32 (x64) (HKLM\...\{ABC6B3C2-1A8D-4C5E-AC16-C2AE44F02743}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM\...\{A741B803-3F0E-4684-81EF-FC128D15A92C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM-x32\...\{784973c8-d618-4ac8-97ed-1fd52c5bdf2f}) (Version: 3.1.32.31915 - Microsoft Corporation)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Access MUI (English) 2013 (HKLM\...\{90150000-0015-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Access Setup Metadata MUI (English) 2013 (HKLM\...\{90150000-0117-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Analysis Services OLE DB Provider (HKLM\...\{0DAD8F2F-38F2-404F-BB26-3DC89F0B53C5}) (Version: 14.0.1000.397 - Microsoft Corporation) Hidden
Microsoft Analysis Services OLE DB Provider (HKLM-x32\...\{CBB32D14-5E5A-4E4A-8EDF-26586322C9E7}) (Version: 14.0.1000.397 - Microsoft Corporation) Hidden
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Build Tools 14.0 (amd64) (HKLM\...\{8C918E5B-E238-401F-9F6E-4FB84B024CA2}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Build Tools 14.0 (x86) (HKLM-x32\...\{D1437F51-786A-4F57-A99C-F8E94FBA1BD8}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Build Tools Language Resources 14.0 (amd64) (HKLM\...\{4B7958F6-4943-4903-B379-9180DC8C2105}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Build Tools Language Resources 14.0 (x86) (HKLM-x32\...\{A7E88B38-6886-4474-9D85-A8ABE5FCD80E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft DCF MUI (English) 2013 (HKLM\...\{90150000-0090-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 122.0.2365.92 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 122.0.2365.92 - Microsoft Corporation)
Microsoft Excel MUI (English) 2013 (HKLM\...\{90150000-0016-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Groove MUI (English) 2013 (HKLM\...\{90150000-00BA-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Help Viewer 2.2 (HKLM-x32\...\{5730588A-33CA-373C-9D70-F716605B57D2}) (Version: 2.2.23107 - Microsoft Corporation) Hidden
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft InfoPath MUI (English) 2013 (HKLM\...\{90150000-0044-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Lync MUI (English) 2013 (HKLM\...\{90150000-012B-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft MPI (7.0.12437.8) (HKLM\...\{8499ACD3-C1E3-45AB-BF96-DA491727EBE1}) (Version: 7.0.12437.8 - Microsoft Corporation)
Microsoft ODBC Driver 13 for SQL Server (HKLM\...\{436C9D0B-5AD2-4E54-83F0-10B7584A971E}) (Version: 14.0.2052.1 - Microsoft Corporation)
Microsoft Office 32-bit Components 2013 (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office OSM MUI (English) 2013 (HKLM\...\{90150000-00E1-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office OSM UX MUI (English) 2013 (HKLM\...\{90150000-00E2-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office Proofing (English) 2013 (HKLM\...\{90150000-002C-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - English (HKLM\...\{90150000-001F-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - Español (HKLM\...\{90150000-001F-0C0A-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (English) 2013 (HKLM\...\{90150000-00C1-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2013 (HKLM\...\{90150000-006E-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2013 (HKLM\...\{90150000-0115-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft OneNote MUI (English) 2013 (HKLM\...\{90150000-00A1-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Outlook MUI (English) 2013 (HKLM\...\{90150000-001A-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft PowerPoint MUI (English) 2013 (HKLM\...\{90150000-0018-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft Publisher MUI (English) 2013 (HKLM\...\{90150000-0019-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Microsoft SQL Server 2012 Native Client  (HKLM\...\{4D2C56FF-7F36-4B49-A97A-24F0522D41D7}) (Version: 11.3.6540.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2017 (64-bit) (HKLM\...\Microsoft SQL Server SQL2017) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2017 (HKLM-x32\...\Microsoft SQL Server SQL2017) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2017 Policies  (HKLM-x32\...\{256EDCB9-A64D-433C-A1DC-C76F02475915}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft SQL Server 2017 RsFx Driver (HKLM\...\{D5826833-5FD8-4586-BC42-22E38B15DFA4}) (Version: 14.0.2052.1 - Microsoft Corporation) Hidden
Microsoft SQL Server 2017 Setup (English) (HKLM\...\{2E1F5473-30FC-4D5B-B7F0-8EA51CC3EE81}) (Version: 14.0.2052.1 - Microsoft Corporation)
Microsoft SQL Server 2017 T-SQL Language Service  (HKLM\...\{BC247FE3-C61A-4678-86C6-15408F272D57}) (Version: 14.0.17213.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation) Hidden
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation) Hidden
Microsoft SQL Server Data-Tier Application Framework (x86) (HKLM-x32\...\{F45421F6-76C3-47EE-8823-7D064A77E1F0}) (Version: 14.0.3881.1 - Microsoft Corporation)
Microsoft SQL Server Management Studio - 17.4 (HKLM-x32\...\{ac84c935-8f13-4f73-b541-7b09a11bdea8}) (Version: 14.0.17213.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{718FFB65-F6E4-4D62-861F-ED10ED32C936}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2017 (HKLM\...\{9D78F5D4-79D2-4FC6-AC56-F364A0ABC54F}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Debug Runtime - 12.0.21005 (HKLM\...\{C596D608-3E74-3232-8CA5-DF1DCB9F10DE}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Debug Runtime - 12.0.21005 (HKLM-x32\...\{E5CAE8D2-9F9F-3BEA-AA0F-B5B40611C704}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x64 Debug Runtime - 14.0.23026 (HKLM\...\{B8E14C55-53F6-3693-A74A-77A3C6B96041}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Debug Runtime - 14.0.23026 (HKLM-x32\...\{3CB4E2E8-04EB-371A-9433-4CA0D934B260}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.34.31931 (HKLM-x32\...\{d4cecf3b-b68f-4995-8840-52ea0fab646e}) (Version: 14.34.31931.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.34.31931 (HKLM-x32\...\{6ba9fb5e-8366-4cc4-bf65-25fe9819b2fc}) (Version: 14.34.31931.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.34.31931 (HKLM\...\{EAE242B1-0A26-485A-BFEB-0292EE9F03CB}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.34.31931 (HKLM\...\{CF4C347D-954E-4543-88D2-EC17F07F466F}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.34.31931 (HKLM-x32\...\{C2662EFF-06E6-4FD1-9D6D-FDCA91025757}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.34.31931 (HKLM-x32\...\{AB1BDF73-7393-42CE-812D-9A90918814D5}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}) (Version: 10.0.50908 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2015 Shell (Isolated) (HKLM-x32\...\{6CFDA13E-A348-315B-820A-603BBCBD7684}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Isolated) (HKLM-x32\...\{d2981c27-a434-4c9a-96c7-0209e97c4eac}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Visual Studio 2015 Shell (Isolated) Resources (HKLM-x32\...\{446D0B70-F98E-39DA-9CB5-4201D05A91C6}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Minimum) (HKLM-x32\...\{030A6785-C3A9-37DA-8530-444C320629FA}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Minimum) Interop Assemblies (HKLM-x32\...\{4443D3F4-A231-35CC-8471-CB60F8A3FE3B}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Minimum) Resources (HKLM-x32\...\{7FF53256-7BAF-3EFA-91B4-DB65F37EB5E9}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio Services Hub (HKLM-x32\...\{93CC1063-02A1-4F25-A13A-C351A10D84DD}) (Version: 1.0.23107.00 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 (HKLM-x32\...\{ab213ab7-4792-4c6f-a3fa-8485d06c3475}) (Version: 14.0.23829 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 Finalizer (HKLM-x32\...\{F93E37BD-4053-37CA-A7BB-A5B74508006C}) (Version: 14.0.23829 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 Language Support - ENU Language Pack (HKLM-x32\...\{0343F10B-C31B-3A2F-B2C1-C42E84CCAF5E}) (Version: 14.0.23107.20 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 Language Support (HKLM-x32\...\{85CEB20F-C2D6-3FDC-9A9D-5957CD88E9E5}) (Version: 14.0.23107.20 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 Language Support (HKLM-x32\...\{bd4ef7af-dfb1-472e-8fa4-1b97f360a3e7}) (Version: 14.0.23107.20 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 Language Support Finalizer (HKLM-x32\...\{BF6E6B74-88F5-358F-AB6D-0A42C18F2824}) (Version: 14.0.23107.20 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 x64 Hosting Support (HKLM\...\{A8C30947-7C1B-3A31-8FD8-CEC6D3357D34}) (Version: 14.0.23829 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 x86 Hosting Support (HKLM-x32\...\{11A9EF3E-6616-31B1-82BC-1080366FA34D}) (Version: 14.0.23829 - Microsoft Corporation) Hidden
Microsoft VSS Writer for SQL Server 2017 (HKLM\...\{20B328C9-C6BB-434A-928A-00F05CD820B8}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft Word MUI (English) 2013 (HKLM\...\{90150000-001B-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
MotionPro (HKLM\...\MotionPro VPN Client) (Version: 9.4.0.0 - Array Networks)
Mozilla Firefox (x64 en-US) (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Mozilla Firefox 123.0.1 (x64 en-US)) (Version: 123.0.1 - Mozilla)
MyHarmony (HKLM-x32\...\{2AD8F8A1-ECE5-4890-BCC2-B4396370A0D4}) (Version: 1.0.308 - Logitech)
NVIDIA Graphics Driver 546.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 546.17 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
OSCAR (HKLM\...\{FC6F08E6-69BF-4469-ADE3-78199288D305}_is1) (Version: 1.5.1-Win64-dd495e23 - The OSCAR Team)
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Paragon Hard Disk Manager™ 15 Suite (HKLM\...\{29258311-EA49-11DE-967C-005056C00008}) (Version: 90.00.0003 - Paragon Software)
PdaNet+ for Android 4.18 (HKLM-x32\...\PdaNet_is1) (Version:  - June Fabrics Technology Inc)
PDF Settings (HKLM-x32\...\{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Player Location Check (HKLM-x32\...\{F0753064-8D66-41A7-9F23-7691290387BF}) (Version: 4.0.0.7 - GeoComply)
PreSonus Studio One 6 (HKLM\...\Studio One 6_is1) (Version: 6.5.0 - PreSonus)
Private Internet Access (HKLM\...\{33023371-7761-4F81-BBB1-0E0D0D175ACF}) (Version: 3.5.5+08091 - Private Internet Access, Inc.)
Private Internet Access WinTUN Driver (HKLM\...\{0419A0C0-4CC8-459E-9BAE-F3BF5D2E2CCB}) (Version: 1.0 - Private Internet Access, Inc.) Hidden
Product Registration (HKLM\...\{C1600AC7-74E3-4BB5-8B42-B13653792252}) (Version: 2.2.38.0 - Dell Inc.) Hidden
Product Registration (HKLM-x32\...\InstallShield_{C1600AC7-74E3-4BB5-8B42-B13653792252}) (Version: 2.2.38.0 - Dell Inc.)
Python 3.12.1 (64-bit) (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\{86e52725-ef45-452f-ac4c-b8958718bfea}) (Version: 3.12.1150.0 - Python Software Foundation)
Python 3.12.1 Core Interpreter (64-bit) (HKLM\...\{AC82C1A3-9597-40F2-893D-F02F778FBA4D}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Development Libraries (64-bit) (HKLM\...\{8C53CBDD-4DAF-426F-9478-6C7C2920CDDA}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Documentation (64-bit) (HKLM\...\{62667662-A580-409C-8044-55B06F774AE2}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Executables (64-bit) (HKLM\...\{44BC9F9C-15C2-46C1-B88D-3135A9DA555F}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 pip Bootstrap (64-bit) (HKLM\...\{1662F43B-2337-4FD8-8CE6-BEA38FC94DD4}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Standard Library (64-bit) (HKLM\...\{47957EE3-0E23-4075-B825-F202E913670F}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Tcl/Tk Support (64-bit) (HKLM\...\{926CDC62-3AE2-422B-9858-D6EC3BAD473F}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Test Suite (64-bit) (HKLM\...\{E309AE00-4FB1-4817-9172-7E198668375D}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{4C8D4EC3-F620-4CEE-8BAD-B59A3C6815F3}) (Version: 3.12.1150.0 - Python Software Foundation)
qBittorrent 4.3.9 (HKLM-x32\...\qBittorrent) (Version: 4.3.9 - The qBittorrent project)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.5.02 - Dell Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.21289 - Realtek Semiconduct Corp.)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 10.1.505.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8578 - Realtek Semiconductor Corp.)
ReAmp Studio R1 version 1.0.5 (HKLM\...\ReAmp Studio R1_is1) (Version: 1.0.5 - Audio Assault & Team V.R)
Roblox Player for Phil (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\roblox-player) (Version:  - Roblox Corporation)
Roslyn Language Services - x86 (HKLM-x32\...\{5B47029B-1E62-30FF-906E-694851C22782}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Roslyn Language Services - x86 (HKLM-x32\...\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0015-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0016-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0018-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0019-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-001A-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-001B-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-001F-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{835E4BED-E265-4103-AE14-0B4C70CF3FE8}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}_Office15.PROPLUSR_{1F7000D3-A917-4AD2-BA55-59E6FDAF062A}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-001F-0C0A-1000-0000000FF1CE}_Office15.PROPLUSR_{4BF13B26-3A95-4E42-900A-DEB16FDA75A0}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-002C-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{C5D14A1B-6E3E-491A-96C6-ABDEEEC4E97D}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0044-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-006E-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{D7E879E6-B505-4DA2-BFEE-53A55E7C8E38}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0090-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-00A1-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-00BA-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{1931508C-C004-4983-81E3-70BE6252904B}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-00C1-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{E4F470B2-3601-4E1C-B291-D6B580F53136}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-00E1-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-00E2-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0115-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{D7E879E6-B505-4DA2-BFEE-53A55E7C8E38}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0117-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}) (Version:  - Microsoft) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version:  - Microsoft)
SketchUp 2016 (HKLM\...\{E2B66CF6-ABA0-4E5F-B426-7478B18301AE}) (Version: 16.1.1449 - Trimble Navigation Limited)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
SQL Server 2017 Batch Parser (HKLM\...\{2C6E8311-28BD-4615-9545-6E39E8E83A4B}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Client Tools Extensions (HKLM\...\{06324A5D-66BB-4FAC-8D0B-9FEC1B230FFF}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Client Tools Extensions (HKLM\...\{200F38B2-1492-4576-B08C-78F2C2C953FC}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM\...\{9D1C0509-D490-4E9E-ACF5-A73E5C53742D}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM\...\{B777C4C0-A1CD-4AB9-99B1-AD5FBED6F8E5}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM-x32\...\{6CE9A8AA-C478-4706-BD28-95993D52B5A1}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM-x32\...\{D17B5D3D-3BC7-4AFA-AD90-600B5453826E}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Connection Info (HKLM\...\{89A7644F-E056-4EC1-BFDE-9D1A531D6855}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Connection Info (HKLM\...\{A9A443F5-56E1-4FC6-937C-5F481345A843}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Services (HKLM\...\{28EEF6BA-A23A-42D2-86BA-A6BEE723B969}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Services (HKLM\...\{DED314CA-0EFE-4593-9D66-EF75E5289A4C}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Shared (HKLM\...\{0E22DBB4-691B-400C-B52D-8DFE8EC421AA}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Shared (HKLM\...\{793F1C1E-5C83-4E33-A29B-6EAA7C1E791C}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 DMF (HKLM\...\{B9998A13-5563-496C-B95E-597FFC70B670}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 DMF (HKLM\...\{D7D28BBF-3B0E-43F0-A457-331F1CD9E9EB}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Integration Services Scale Out Management Portal (HKLM\...\{6BD8D100-B16C-409E-B0EA-BF508D7874EC}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Integration Services Scale Out Management Portal (HKLM\...\{91C5EE43-29D1-4720-AB65-5E2E0FE25990}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Management Studio Extensions (HKLM-x32\...\{6492E746-1C5D-48C2-A92A-97D431F74664}) (Version: 14.0.3006.16 - Microsoft Corporation) Hidden
SQL Server 2017 Management Studio Extensions (HKLM-x32\...\{70C24F35-7E36-45FC-B289-3D2849E5556B}) (Version: 14.0.3006.16 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects (HKLM\...\{10855B1A-F7F2-4D8A-A725-9287C73BED5A}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects (HKLM\...\{6CBBF624-696C-499E-948D-ADBAFFA2F548}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects Extensions (HKLM\...\{8C515C22-BE07-4908-985C-0AA9349E1ED4}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects Extensions (HKLM\...\{C6D92730-3EC0-47B1-8F6C-6F5635D1EFAC}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 SQL Diagnostics (HKLM\...\{DFA6A906-3024-49DE-87AD-750EAED2FA49}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 XEvent (HKLM\...\{12D2DB8D-80FF-4152-8F51-EDB3BD3C6976}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 XEvent (HKLM\...\{AA2A015C-C210-413B-95F6-BF9D3CDD6E0D}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server Management Studio (HKLM\...\{1B8CFC46-1F08-4DA7-9FEA-E1F523FBD67F}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SQL Server Management Studio (HKLM\...\{F8ADD24D-F2F2-465C-A675-F12FDB70DB82}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SQL Server Management Studio for Analysis Services (HKLM\...\{CC6997A7-1638-4E38-B6CF-E776997036B0}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SQL Server Management Studio for Reporting Services (HKLM\...\{4DDEB555-26D2-4E68-98AF-8F96232C13F2}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SSD Sampler (HKLM-x32\...\SSD4) (Version: 1.1 - Yellow Matter Entertainment)
SSMS Post Install Tasks (HKLM\...\{CFCC9F40-E234-499E-B3DA-BEF6CC724C35}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 10.0.1256 - SUPERAntiSpyware.com)
TeamViewer (HKLM\...\TeamViewer) (Version: 15.51.5 - TeamViewer)
Techstream Software (HKLM-x32\...\{937CA58A-0212-431C-8F0B-0D8305225476}) (Version: 10.30.029 - DENSO CORPORATION)
Tools for .Net 3.5 (HKLM-x32\...\{1690CE56-2231-4E59-9006-A0876D949EA8}) (Version: 3.11.50727 - Microsoft Corporation) Hidden
Toontrack EZmix 2.2.4 (HKLM\...\EZmix_is1) (Version: 2.2.4 - Toontrack & Team V.R)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Update for Skype for Business 2015 (KB4484289) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{1C76EBD9-0A70-4094-A543-00CAA3B62113}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB4484289) 64-Bit Edition (HKLM\...\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{1C76EBD9-0A70-4094-A543-00CAA3B62113}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB4484289) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{1C76EBD9-0A70-4094-A543-00CAA3B62113}) (Version:  - Microsoft)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{7B63012A-4AC6-40C6-B6AF-B24A84359DD5}) (Version: 8.93.0.0 - Microsoft Corporation)
UXP WebView Support (HKLM-x32\...\UXPW_1_1_0) (Version: 1.1.0 - Adobe Inc.)
VeraCrypt (HKLM-x32\...\VeraCrypt) (Version: 1.24-Update7 - IDRIX)
Visual C++ 2008 Runtime (x64) (HKLM-x32\...\{73E80655-FB3C-46F4-BE00-62D248BC490A}) (Version: 1.0.1 - Highresolution Enterprises) Hidden
Visual Studio 2015 Prerequisites - ENU Language Pack (HKLM\...\{83B181F2-20B8-4F00-8E71-C66E951A8D4F}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Visual Studio 2015 Prerequisites (HKLM\...\{DF32E41C-24AD-4A87-B43A-B38553B1806E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.14 - VideoLAN)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Waves Central (HKLM\...\{ab507e17-892b-5203-838d-d58d8d09c50f}) (Version: 14.4.3 - Waves Audio Ltd)
Windows Driver Package - Amazon.com (WinUSB) FireDevicesUsbDeviceClass  (10/27/2014 1.4.0000.00000) (HKLM\...\70D74CAD18BB165614511A2A67DB9EBF036D06A9) (Version: 10/27/2014 1.4.0000.00000 - Amazon.com)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Fresco Logic (fl2000) AVClass  (11/13/2017 2.1.34054.0) (HKLM\...\02B94313A3DAF5BA27BCC4FAEA0716A0F660086C) (Version: 11/13/2017 2.1.34054.0 - Fresco Logic)
Windows Driver Package - Fresco Logic (lci_proxykmd) System  (11/13/2017 2.1.34054.0) (HKLM\...\7C22E1F94C4AE5334C0BEE70551B20BEE3C293FA) (Version: 11/13/2017 2.1.34054.0 - Fresco Logic)
Windows Driver Package - Fresco Logic (WUDFRd) Display  (11/13/2017 2.1.34054.0) (HKLM\...\9328342CF3E5994E24BB0C09FBD875141BEF3984) (Version: 11/13/2017 2.1.34054.0 - Fresco Logic)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
XLN Online Installer (HKLM\...\XLN Online Installer Inno Setup ID_is1) (Version:  - )
X-Mouse Button Control 2.10.2 (HKLM-x32\...\X-Mouse Button Control) (Version: 2.10.2 - Highresolution Enterprises)
Yamaha Steinberg USB Driver (HKLM\...\{E2AEA639-BFC7-4A6E-A9F3-EB11B60C2F33}) (Version: 2.1.5 - Yamaha Corporation) Hidden
Yamaha Steinberg USB Driver (HKLM-x32\...\yUninstall_{2938B185-2D57-47B0-9FC8-C90A67BA9277}) (Version: 2.1.5 - Yamaha Corporation)
YubiKey Manager (HKLM-x32\...\yubikey-manager) (Version: 1.1.5 - Yubico AB)
Zoom (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\ZoomUMX) (Version: 5.15.7 (20303) - Zoom Video Communications, Inc.)
 
Packages:
=========
 
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.263.400.0_x64__kgqvnymyfvs32 [2024-03-13] (king.com)
Dell Shop -> C:\Program Files\WindowsApps\DellInc.DellShop_2.2.1.0_neutral__htrsf667h5kn2 [2021-04-17] (Dell Inc)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_152.1.1099.0_x64__v10z8vjag6ke6 [2024-03-10] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Movie Maker - Video Editor -> C:\Program Files\WindowsApps\21336V3TApps.MovieMaker-FREE_3.6.46.0_x64__bzg06mxvgh4fa [2024-03-10] (V3TApps)
MyIPTV Player -> C:\Program Files\WindowsApps\41879VbfnetApps.MyIPTVPlayer_4.8.2.0_x64__7casf8sqhfy78 [2023-11-02] (Vbfnet Apps) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.964.0_x64__56jybvy8sckqj [2023-11-18] (NVIDIA Corp.)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-05-08] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-12-19] (Microsoft Corporation)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.19.1262.0_x64__8wekyb3d8bbwe [2024-02-08] (Microsoft Studios) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2021-06-10] (Twitter Inc.)
WinDbg -> C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe [2024-03-08] (Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{1019ADC7-17CB-4489-AFD5-6642C7400ACE}\localserver32 -> C:\Users\Phil\AppData\Local\Webex\Webex\Applications\ptOIEx64.exe (Cisco WebEx LLC -> Cisco WebEx LLC)
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\localserver32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\FileCoAuth.exe => No File
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{BEA218D2-6950-497B-9434-61683EC065FE}\InprocServer32 -> C:\Users\Phil\AppData\Local\Programs\Python\Launcher\pyshellext.amd64.dll (Python Software Foundation -> Python Software Foundation)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat Elements\ContextMenuShim64.dll [2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
ContextMenuHandlers1: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\ConvertToPDFShellExtension_x64.dll [2016-11-14] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-04-12] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxDTCM.dll [2019-06-13] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvdmig.inf_amd64_75c152d756d851ed\nvshext.dll [2023-11-10] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat Elements\ContextMenuShim64.dll [2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
ContextMenuHandlers6: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\ConvertToPDFShellExtension_x64.dll [2016-11-14] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-04-12] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\System32\StartMenuHelper64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Amcrest Web View.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory="Profile 1" --app-id=oddndbjhpcpopbebhonolceinkbnheih
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory="Profile 1" --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Videostream for Google Chromecast™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory="Profile 1" --app-id=cnciopoikihiagdjbjpnocolokfelagl
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\e895024b613704\MetaMask.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=nkbihfbeogaeaoehlefnkodbefgpgknn
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\72dad8f9fb5925df\Data Scraper - Easy Web Scraping.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=nndknepjnldbdbepjfgmncbggmopgden
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
 
==================== Loaded Modules (Whitelisted) =============
 
0000-00-00 00:00 - 0000-00-00 00:00 - 000000000 _____ () [Access Denied] C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll
2024-02-16 10:48 - 2023-07-10 02:34 - 000039936 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\aiohttp\_helpers.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000215552 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\aiohttp\_http_parser.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000035840 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\aiohttp\_http_writer.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000024064 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\aiohttp\_websocket.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000053760 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\frozenlist\_frozenlist.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000046592 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\multidict\_multidict.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000066048 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\psutil\_psutil_windows.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000039936 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\tinyaes.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000012288 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\websockets\speedups.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000132096 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\win32api.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000068608 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\yarl\_quoting_c.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000183296 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\_cffi_backend.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 193385472 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\_pywrap_tensorflow_internal.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000018944 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\cpufeature\extension.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000100864 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\google\protobuf\internal\_api_implementation.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001601536 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\google\protobuf\pyext\_message.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000175616 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\_conv.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000045568 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\_errors.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000110080 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\_objects.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000044032 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\_proxy.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000132608 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\_selector.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000219648 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\defs.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000089600 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000117760 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5a.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000058368 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5ac.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000122368 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5d.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000072192 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5ds.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000116736 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5f.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000156672 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5fd.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000136192 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5g.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000051712 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5i.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000096256 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5l.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000106496 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5o.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000311296 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5p.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000036352 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5pl.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000061952 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5r.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000093696 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5s.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000320512 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5t.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000044032 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5z.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000052736 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\utils.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000011264 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\_devicearray.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000045056 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\_dispatcher.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000016384 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\_dynfunc.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000238592 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\_helperlib.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000027136 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\core\runtime\_nrt_python.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000019968 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\core\typeconv\_typeconv.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000024576 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\np\ufunc\_internal.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000114176 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\core\_multiarray_tests.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 002906112 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\core\_multiarray_umath.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000116736 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\fft\_pocketfft_internal.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000154624 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\linalg\_umath_linalg.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000022016 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\linalg\lapack_lite.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000254464 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_bounded_integers.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000182272 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_common.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000685056 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_generator.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000080896 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_mt19937.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000085504 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_pcg64.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000072192 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_philox.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000053760 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_sfc64.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000158208 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\bit_generator.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000588800 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\mtrand.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001278976 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\algos.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000078336 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\arrays.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000916480 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\groupby.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000154624 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\hashing.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001230848 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\hashtable.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000454656 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\index.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000046080 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\indexing.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000256000 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\internals.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001038336 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\interval.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001893376 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\join.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000067072 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\json.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000465408 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\lib.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000162816 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\missing.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000186880 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\ops.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000051200 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\ops_dispatch.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000373760 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\parsers.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000059904 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\properties.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000247808 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\reduction.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000227328 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\reshape.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000801280 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\sparse.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000069632 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\testing.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000133632 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslib.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000041984 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\base.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000052224 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\ccalendar.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000224768 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\conversion.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000101888 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\dtypes.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000241664 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\fields.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000181760 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\nattype.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000043520 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\np_datetime.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000776704 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\offsets.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000318464 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\parsing.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000346624 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\period.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000292864 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\strptime.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000371712 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\timedeltas.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000401920 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\timestamps.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000192512 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\timezones.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000216064 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\tzconversion.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000190464 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\vectorized.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000288256 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\window\aggregations.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000145408 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\window\indexers.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000180736 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\writers.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000076288 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\psutil\_psutil_windows.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000061440 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\_lib\_ccallback_c.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000049664 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\_lib\_uarray\_uarray.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000042496 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\_lib\messagestream.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000582144 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\fft\_pocketfft\pypocketfft.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000169984 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\fftpack\convolve.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000046080 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\integrate\_dop.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000022528 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\integrate\_odepack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000032768 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\integrate\_quadpack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000039936 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\integrate\lsoda.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000050176 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\integrate\vode.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000225280 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\_bspl.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000035328 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\_fitpack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000286720 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\_ppoly.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000385536 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\_rbfinterp_pythran.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000148480 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\dfitpack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000281600 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\interpnd.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000238592 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_decomp_update.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000587264 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_fblas.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001931264 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_flapack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000052224 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_flinalg.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000229376 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_interpolative.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000171008 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_matfuncs_sqrtm_triu.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000193536 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_solve_toeplitz.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000226816 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\cython_blas.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000626688 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\cython_lapack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000124928 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\ndimage\_nd_image.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000267264 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\ndimage\_ni_label.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000030720 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\__nnls.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000231936 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_bglu_dense.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000034816 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_cobyla.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000062464 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_group_columns.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000027136 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_highs\_highs_constants.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001470464 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_highs\_highs_wrapper.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000038400 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_lbfgsb.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000025600 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_lsap_module.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000142336 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_lsq\givens_elimination.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000029184 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_minpack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000038912 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_slsqp.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000251904 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_trlib\_trlib.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000016384 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_zeros.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000034304 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\minpack2.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000051200 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\moduleTNC.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000038400 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\_max_len_seq_inner.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000188928 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\_peak_finding_utils.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000212992 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\_sosfilt.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000048128 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\_spectral.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000244224 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\_upfirdn_apply.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000096768 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\sigtools.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000038912 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\spline.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000471552 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\_csparsetools.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 002177024 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\_sparsetools.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000201728 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_flow.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000224768 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_matching.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000158208 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_min_spanning_tree.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000209408 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_reordering.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000321536 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_shortest_path.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000124928 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_tools.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000118784 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_traversal.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000282624 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\linalg\dsolve\_superlu.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000143872 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\linalg\eigen\arpack\_arpack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000117248 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\linalg\isolve\_iterative.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000244736 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\_distance_pybind.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000123904 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\_distance_wrap.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000150528 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\_hausdorff.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000148992 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\_voronoi.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000518656 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\ckdtree.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000833024 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\qhull.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000481280 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\transform\rotation.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000031744 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\_comb.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000065024 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\_ellip_harm_2.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000789504 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\_ufuncs.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000107008 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\_ufuncs_cxx.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001348608 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\cython_special.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000077824 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\specfun.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000266240 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_boost\beta_ufunc.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000232448 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_boost\binom_ufunc.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000236032 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_boost\nbinom_ufunc.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000175104 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_qmc_cy.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000177664 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_sobol.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000416768 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_stats.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000167424 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\biasedurn.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000036864 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\mvn.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000032256 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\statlib.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003867648 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\compiler\tf2tensorrt\_pywrap_py_utils.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000342016 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\lite\experimental\microfrontend\python\ops\_audio_microfrontend_op.so
2024-02-16 10:48 - 2023-07-10 02:34 - 000235008 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\lite\python\analyzer_wrapper\_pywrap_analyzer_wrapper.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003292160 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\lite\python\interpreter_wrapper\_pywrap_tensorflow_interpreter_wrapper.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000990208 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\lite\python\metrics\_pywrap_tensorflow_lite_metrics_wrapper.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 002726400 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_dtensor_device.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003403776 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_mlir.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003933184 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_parallel_device.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 002702848 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_py_exception_registry.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003389440 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_quantize_training.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000109568 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_sanitizers.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 006100480 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_tfe.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000124416 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_toco_api.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003408896 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\client\_pywrap_debug_events_writer.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003390976 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\client\_pywrap_device_lib.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003414528 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\client\_pywrap_events_writer.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 006047744 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\client\_pywrap_tf_session.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003436544 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\data\experimental\service\_pywrap_server_lib.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 005432320 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\data\experimental\service\_pywrap_utils.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 002874368 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\flags_pybind.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 002728960 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_dtypes.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003445248 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_op_def_library_pybind.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003389440 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_op_def_registry.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003933184 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_proto_comparators.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000213504 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_pywrap_python_api_dispatcher.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 002696704 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_pywrap_python_op_gen.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003867136 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_test_metrics_util.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003973120 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\grappler\_pywrap_tf_cluster.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003897856 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\grappler\_pywrap_tf_optimizer.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000108544 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\lib\core\_pywrap_bfloat16.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000108544 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\lib\core\_pywrap_py_func.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003473920 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\lib\io\_pywrap_file_io.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003534336 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\lib\io\_pywrap_record_io.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000108544 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\platform\_pywrap_stacktrace_handler.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003389952 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\platform\_pywrap_tf2.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 007490048 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\profiler\internal\_pywrap_profiler.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003409408 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\profiler\internal\_pywrap_traceme.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003419648 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\saved_model\pywrap_saved_model.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003894784 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_checkpoint_reader.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000109568 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_determinism.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000109568 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_nest.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000109568 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_tensor_float_32_execution.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003874304 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_tfprof.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000108544 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_util_port.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000163328 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_utils.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 002455040 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_tf_stack.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000119296 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\fast_module_type.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000040448 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tinyaes.cp39-win_amd64.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000011776 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\websockets\speedups.cp39-win_amd64.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000134656 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\win32api.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000527872 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\win32com\shell\shell.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000042496 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\wrapt\_wrappers.cp39-win_amd64.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000249856 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\yaml\_yaml.cp39-win_amd64.pyd
0000-00-00 00:00 - 0000-00-00 00:00 - 000000000 _____ () <==== ATTENTION [zero byte File/Folder] \\?\C:\Users\Phil\AppData\Roaming\Java\jre8\bin\java.exe:jll
2017-08-13 09:49 - 2017-08-13 09:49 - 003664184 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenuDLL.dll
2017-08-13 09:49 - 2017-08-13 09:49 - 000291128 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\WINDOWS\System32\StartMenuHelper64.dll
2024-01-05 18:19 - 2024-01-05 18:19 - 002973696 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll
2015-08-01 22:19 - 2015-08-01 22:19 - 000541448 ____R (Waves Inc -> Waves Audio) [File not signed] C:\WINDOWS\SYSTEM32\MaxxAudioIntelSkylake64.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell15.msn.com/?pc=DCTE
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://192.168.1.90:1829/
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://192.168.1.85:85/
SearchScopes: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001 -> {A79BE33D-4EB3-40E2-B354-BB99B3501D8A} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2020-04-15] (Microsoft Corporation -> Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-07-26] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-07-26] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2020-04-15] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-07-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\PROGRA~2\MICROS~2\Office15\GROOVEEX.DLL => No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-07-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-07-26] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-07-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2017-08-15] (Microsoft Corporation -> Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2023-11-18 23:11 - 2023-11-18 23:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
2019-10-23 10:26 - 2020-03-13 23:45 - 000000440 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Microsoft MPI\Bin\;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT;C:\Program Files\Intel\Intel® Management Engine Components\IPT;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Microsoft SQL Server\Client SDK\ODBC\130\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\140\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\140\DTS\Binn\;C:\Program Files (x86)\Microsoft SQL Server\140\Tools\Binn\ManagementStudio\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\130\Tools\Binn\;C:\Program Files\Microsoft SQL Server\140\Tools\Binn\;C:\Program Files\Microsoft SQL Server\140\DTS\Binn\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files\dotnet\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%AppData%\Programs\Python\Python311;%AppData%\Programs\Python\Python311\Scripts;
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Phil\Pictures\20201114_122903.jpg
HKU\S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
MSCONFIG\Services: !SASCORE => 2
MSCONFIG\Services: 0008811457109852mcinstcleanup => 2
MSCONFIG\Services: dbupdate => 2
MSCONFIG\Services: dbupdatem => 3
MSCONFIG\Services: Dell Customer Connect => 2
MSCONFIG\Services: Dell Foundation Services => 2
MSCONFIG\Services: Dell Hardware Support => 2
MSCONFIG\Services: Dell Help & Support => 2
MSCONFIG\Services: Dell Product Registration => 2
MSCONFIG\Services: DellDigitalDelivery => 2
MSCONFIG\Services: DellUpdate => 2
MSCONFIG\Services: MacriumService => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: SupportAssistAgent => 2
MSCONFIG\Services: WavesSysSvc => 2
MSCONFIG\Services: XTU3SERVICE => 2
HKLM\...\StartupApproved\StartupFolder: => "WavesLocalServer.lnk"
HKLM\...\StartupApproved\StartupFolder: => "WavesPluginServer.lnk"
HKLM\...\StartupApproved\Run: => "WavesSvc"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "LaunchMhttpd"
HKLM\...\StartupApproved\Run: => "Reflect UI"
HKLM\...\StartupApproved\Run32: => "LaunchMhttpd"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Cisco AnyConnect Secure Mobility Agent for Windows"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "Adobe CCXProcess"
HKLM\...\StartupApproved\Run32: => "Cisconet"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\StartupFolder: => "Gqreader.lnk"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "VideoGuardMonitor"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "GarminExpress"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Skype for Desktop"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Lync"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Trio.WakeNet"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_0848959D30B7A075789B21F3CF73AE30"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [UDP Query User{8722BC63-D006-4454-A7FA-B546C2194CEA}C:\program files (x86)\batch configuration\batch configuration.exe] => (Allow) C:\program files (x86)\batch configuration\batch configuration.exe (HIKVISION DIGITAL TECHNOLOGY CO.,LTD. -> )
FirewallRules: [TCP Query User{2DB79FC2-EEA8-419E-90BE-400EC47D0F71}C:\program files (x86)\batch configuration\batch configuration.exe] => (Allow) C:\program files (x86)\batch configuration\batch configuration.exe (HIKVISION DIGITAL TECHNOLOGY CO.,LTD. -> )
FirewallRules: [UDP Query User{0A6C2044-7019-4EDE-BEAD-2A3D33AD18A3}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{E8D1E310-7E92-4616-96DE-DCA4A63256A4}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{57E1D170-9843-4965-8C4A-2AD53CC33047}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{6C435228-635C-443E-A6F1-2E57ED33DF7C}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{23C79370-8FC2-4078-8755-4CCC15243350}] => (Allow) C:\Users\Phil\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [UDP Query User{309DBB71-8038-46F9-B979-087D23E6F2C6}C:\windows\explorer.exe] => (Allow) C:\windows\explorer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{F1F8667A-4F3B-4D8B-94E1-91642F57D977}C:\windows\explorer.exe] => (Allow) C:\windows\explorer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{7D83116A-F056-470B-9225-C83298E82CDA}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{6AB0400C-53A7-438B-9113-E38C0C3573B8}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{AF34D3A7-5EDD-4DC6-A959-F791BAE4E444}] => (Allow) LPort=1689
FirewallRules: [{A5585E6B-687C-4830-9182-ACCD5AD46580}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{E4F687D8-9AC8-4B3F-81C4-6898D3CEDEBD}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [TCP Query User{82FE00D9-E6F0-4CB8-9B60-816AAD742BDB}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{FDE46CCA-AAFC-4479-B2E2-D11D85E783A8}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{5BF291DD-BF7B-435B-A828-C60013BC36C5}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe => No File
FirewallRules: [{8DBECFBA-ECD9-4018-B4AF-87F78802E809}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe => No File
FirewallRules: [{89450931-B77E-4934-BA32-E1C0F86D3DDD}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A28F774F-4D9D-4824-A06F-BF0A5513DA70}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C937A3E7-40B0-46E4-A6DB-6FC3F111A74C}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{974EBDCE-F93B-45F4-A781-6EE859DCEEC3}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6F508BE4-55D4-4E00-BB96-A12A44734859}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe => No File
FirewallRules: [{61F7D853-8049-4EDA-A9AD-0F321926F991}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe => No File
FirewallRules: [TCP Query User{DE8BB403-0E89-4C68-9D0B-994C01F0D883}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{68171860-2395-48E9-BFE6-772CE1BFB97E}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{37F848E4-8D94-4014-9CBF-EF41A41BB9A6}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{12C09576-213D-4A9B-8544-303D68DBCEED}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe => No File
FirewallRules: [{C065805A-2D52-40DD-B6CE-E9FE6B23C7BE}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe => No File
FirewallRules: [{7AAC6AED-1E16-4AB9-BB94-F970F1549FB6}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5048B123-5188-4CFE-80FA-D151E4F9C479}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A4D6288B-17E6-426E-9FA2-4E0FDC6D705D}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{84588CA5-B711-4486-AAFD-6E6FDB871569}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{939443F9-4C65-4E82-A297-101AB5E299FA}] => (Allow) C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe () [File not signed]
FirewallRules: [{E79003BA-6CF8-4A77-9D7B-488283EFD351}] => (Allow) C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe () [File not signed]
FirewallRules: [{8E3BE494-ABAA-4F0B-A58F-461483AEF7FC}] => (Allow) C:\Program Files\Microsoft MPI\Bin\mpiexec.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{747E94E0-55DB-48A4-892B-B64D8063D537}] => (Allow) C:\Program Files\Microsoft MPI\Bin\mpiexec.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8DE7F132-6EF4-48F3-A1AC-FC129C7CAC93}] => (Allow) C:\Program Files\Microsoft MPI\Bin\smpd.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E919378E-4501-4564-9190-DC9D94972AEC}] => (Allow) C:\Program Files\Microsoft MPI\Bin\smpd.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{FDBC39CA-FECB-4B2E-AE67-D39D966664AF}C:\program files (x86)\windscribe\wsappcontrol.exe] => (Allow) C:\program files (x86)\windscribe\wsappcontrol.exe => No File
FirewallRules: [UDP Query User{D482D82D-B617-466D-8BCE-E397D2CC700E}C:\program files (x86)\windscribe\wsappcontrol.exe] => (Allow) C:\program files (x86)\windscribe\wsappcontrol.exe => No File
FirewallRules: [{231FF233-3159-4F9B-A3A6-BAE2DB0366E9}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{CA724562-B662-46B1-95DD-F6E904B4C439}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe => No File
FirewallRules: [{DA23A761-502C-45EC-8119-F071C3291BC8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe => No File
FirewallRules: [{E59703F2-EF65-4BA6-8655-981E991DDBDF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe => No File
FirewallRules: [{0AFA2E89-C542-48BD-B424-072E6EE9E491}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe => No File
FirewallRules: [{A4146D8E-D51E-4C30-8B77-6FC0499EAEF1}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{A1667356-3898-4277-9D6F-D326CA4AE3B2}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [TCP Query User{F6FE67C7-37F3-4A95-A9F0-54D0ED909095}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{F07579D5-5EB7-4B0A-A790-855B3B84AA9E}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{0252A464-A105-434F-A606-B763FC1A7F10}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe => No File
FirewallRules: [{78D0BADE-0885-4621-B436-9172922F3226}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe => No File
FirewallRules: [TCP Query User{B592A5E8-BF72-43DE-BBCC-46E867957D23}C:\users\phil\appdata\roaming\zoom\bin_00\zoom.exe] => (Allow) C:\users\phil\appdata\roaming\zoom\bin_00\zoom.exe => No File
FirewallRules: [UDP Query User{57EC246B-FE28-4849-B067-ABD24190F601}C:\users\phil\appdata\roaming\zoom\bin_00\zoom.exe] => (Allow) C:\users\phil\appdata\roaming\zoom\bin_00\zoom.exe => No File
FirewallRules: [{BEA2890A-C0DC-4220-99A2-7C7C61852716}] => (Allow) C:\Users\Phil\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{20059C52-C50A-4EEB-9E23-AE28EA983F7A}] => (Allow) C:\Users\Phil\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{C7652C63-47AC-4FB3-9B0F-B37BBF65C06B}] => (Allow) C:\Users\Phil\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{768AEA1F-F731-4803-841C-64FB7BD314D6}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{AFEE8BB0-3FD4-494B-BFF7-9F0631EF435E}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{90B2A1E2-DE71-4232-8685-15A1AE4D709F}] => (Allow) C:\Program Files\MetaTrader 5\metatester64.exe (MetaQuotes Ltd. -> MetaQuotes Ltd.)
FirewallRules: [{E1B7C67C-3222-433A-91BC-6971560A4376}] => (Block) %ProgramFiles%\Adobe\Adobe Premiere Pro CC 2015\Adobe Premiere Pro.exe => No File
FirewallRules: [{174B8CAF-E4B2-4705-AE06-7C01A6855DD4}] => (Block) %ProgramFiles%\Adobe\Adobe Premiere Pro CC 2015\Adobe Premiere Pro.exe => No File
FirewallRules: [TCP Query User{EA3A04E1-B828-4464-91A7-1520C2B6F27F}C:\users\phil\appdata\local\mozilla firefox\firefox.exe] => (Allow) C:\users\phil\appdata\local\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{D5BC456E-2CEC-4AA1-A453-B8AC5DCBC864}C:\users\phil\appdata\local\mozilla firefox\firefox.exe] => (Allow) C:\users\phil\appdata\local\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{25E1A602-B411-4D8C-AA38-787C6509904F}C:\programdata\regid.1993-06.com.microsoft\wmiprvse.exe] => (Block) C:\programdata\regid.1993-06.com.microsoft\wmiprvse.exe => No File
FirewallRules: [UDP Query User{D70EDB31-B0DB-4037-8799-6D61480F5F9B}C:\programdata\regid.1993-06.com.microsoft\wmiprvse.exe] => (Block) C:\programdata\regid.1993-06.com.microsoft\wmiprvse.exe => No File
FirewallRules: [{C557DE62-65C1-410D-9AF9-18260D567AFB}] => (Allow) C:\Users\Phil\AppData\Local\Programs\Opera GX\102.0.4880.82\opera.exe => No File
FirewallRules: [TCP Query User{8955C64B-937F-4DFE-9DEA-C78FB77CD2E1}C:\users\phil\appdata\local\trionet\resources\triocore.exe] => (Block) C:\users\phil\appdata\local\trionet\resources\triocore.exe => No File
FirewallRules: [UDP Query User{C1BC0028-CDF2-4C1C-9CEF-975DDECB4A9E}C:\users\phil\appdata\local\trionet\resources\triocore.exe] => (Block) C:\users\phil\appdata\local\trionet\resources\triocore.exe => No File
FirewallRules: [TCP Query User{492E9C29-9880-4871-9295-67B6C13C7A37}C:\program files\presonus\studio one 6\studio one.exe] => (Allow) C:\program files\presonus\studio one 6\studio one.exe (PreSonus) [File not signed]
FirewallRules: [UDP Query User{C8317AC5-F3AD-40EE-BC6F-C2D1B9AA5580}C:\program files\presonus\studio one 6\studio one.exe] => (Allow) C:\program files\presonus\studio one 6\studio one.exe (PreSonus) [File not signed]
FirewallRules: [TCP Query User{BC5C7851-879E-4667-90A5-B0DD41E060B6}C:\program files\presonus\studio one 6\pluginscanner.exe] => (Allow) C:\program files\presonus\studio one 6\pluginscanner.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [UDP Query User{FB0D57E9-C86C-4AF0-B427-9D8DE7329588}C:\program files\presonus\studio one 6\pluginscanner.exe] => (Allow) C:\program files\presonus\studio one 6\pluginscanner.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [TCP Query User{777ADD0F-6C62-4341-B6BA-C99F7CAE6FD4}C:\program files\presonus\studio one 6\studio one.exe] => (Block) C:\program files\presonus\studio one 6\studio one.exe (PreSonus) [File not signed]
FirewallRules: [UDP Query User{2DAAAB2F-1781-47A7-B69A-19C70323BE89}C:\program files\presonus\studio one 6\studio one.exe] => (Block) C:\program files\presonus\studio one 6\studio one.exe (PreSonus) [File not signed]
FirewallRules: [{8EA52CB9-47A3-4256-A337-16B8CDD7E9DF}] => (Allow) C:\Program Files (x86)\Waves\Plug-Ins V14\TRACT.bundle\Contents\Win64\TRACT.dll (Waves Inc -> Waves Audio Ltd.)
FirewallRules: [{7EA42B83-9523-453C-99EC-D6020573D9EB}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{20517F2C-C6E0-4E95-A7AC-F1A016A271D5}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{6809A1FF-66B3-4EBB-9C4A-7C1BA8C5B686}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{5361CA3F-8EB0-4384-9756-A5419E36CC0D}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{FA438F34-15B7-4CAB-9B1F-C78624C04B74}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\123.0.6312.16\remoting_host.exe (Google LLC -> Google LLC)
FirewallRules: [{8E2B2FEB-0F75-41C7-9833-EA08351455A3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\x86\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1260ABA7-6E4B-4897-8758-608A572657F7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\x86\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{ABC7BC46-CA96-4AE5-A33C-3A1A1A91ED24}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6221E678-65CC-481C-8607-4B9F133DB975}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5687C4A5-F907-43D4-BB1D-AF85F855E121}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\arm64\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{21E11996-A798-4742-9088-8DE25E3486AA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\arm64\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B84F0F20-C060-4CD2-9E9D-86B1DD0605A7}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\122.0.2365.92\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{263E6080-DBA2-4EA3-B4E8-E47FEBB4C0EB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
 
==================== Faulty Device Manager Devices ============
 
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (03/20/2024 09:12:06 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DELL-LAPTOP)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
Error: (03/20/2024 09:08:02 PM) (Source: PlayerLocationCheck) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (03/20/2024 09:08:02 PM) (Source: com.geocomply.internal-updater-microservice) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (03/20/2024 09:08:02 PM) (Source: com.geocomply.vm-detector-microservice) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (03/20/2024 09:08:01 PM) (Source: com.geocomply.wifi-scanner-microservice) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (03/20/2024 09:08:01 PM) (Source: com.geocomply.process-scanner-microservice) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (03/20/2024 09:07:53 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.2.10900.330) TYPE: ERROR MODULE: DPTF TIME 16041 ms
 
DPTF Build Version:  8.2.10900.330
DPTF Build Date:  May 16 2016 11:32:37
Source File:  ..\..\..\Sources\Manager\WIPolicyActiveRelationshipTableChanged.cpp @ line 52
Executing Function:  WIPolicyActiveRelationshipTableChanged::execute
Message:  Unhandled exception caught during execution of work item
Framework Event:  PolicyActiveRelationshipTableChanged [44]
Policy:  Active Policy [0]
Exception Function:  Policy::executePolicyActiveRelationshipTableChanged
Exception Text:  
 
DPTF Build Version:  8.2.10900.330
DPTF Build Date:  May 16 2016 11:32:37
Source File:  ..\..\..\Sources\Manager\EsifServices.cpp @ line 457
Executing Function:  EsifServices::primitiveExecuteGet
Message:  Error returned from ESIF services interface function call
Participant:  NoParticipant
Domain:  NoDomain
ESIF Primitive:  GET_ACTIVE_RELATIONSHIP_TABLE [89]
ESIF Instance:  255
ESIF Return Code:  ESIF_E_UNSUPPORTED_ACTION_TYPE [1202]
 
Error: (03/20/2024 09:07:53 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.2.10900.330) TYPE: ERROR MODULE: DPTF TIME 16034 ms
 
DPTF Build Version:  8.2.10900.330
DPTF Build Date:  May 16 2016 11:32:37
Source File:  ..\..\..\Sources\Manager\WIPolicyActiveRelationshipTableChanged.cpp @ line 52
Executing Function:  WIPolicyActiveRelationshipTableChanged::execute
Message:  Unhandled exception caught during execution of work item
Framework Event:  PolicyActiveRelationshipTableChanged [44]
Policy:  Active Policy [0]
Exception Function:  Policy::executePolicyActiveRelationshipTableChanged
Exception Text:  
 
DPTF Build Version:  8.2.10900.330
DPTF Build Date:  May 16 2016 11:32:37
Source File:  ..\..\..\Sources\Manager\EsifServices.cpp @ line 457
Executing Function:  EsifServices::primitiveExecuteGet
Message:  Error returned from ESIF services interface function call
Participant:  NoParticipant
Domain:  NoDomain
ESIF Primitive:  GET_ACTIVE_RELATIONSHIP_TABLE [89]
ESIF Instance:  255
ESIF Return Code:  ESIF_E_UNSUPPORTED_ACTION_TYPE [1202]
 
 
System errors:
=============
Error: (03/20/2024 09:08:14 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Intel® PROSet/Wireless Zero Configuration Service service terminated with the following error: 
%%2147770990
 
Error: (03/20/2024 09:07:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The FoxitReaderService service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (03/20/2024 09:07:20 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Energy Server Service queencreek service did not shut down properly after receiving a preshutdown control.
 
Error: (03/20/2024 09:07:04 PM) (Source: DCOM) (EventID: 10010) (User: DELL-LAPTOP)
Description: The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.
 
Error: (03/20/2024 05:49:33 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Intel® PROSet/Wireless Zero Configuration Service service terminated with the following error: 
%%2147770990
 
Error: (03/20/2024 05:49:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The FoxitReaderService service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (03/20/2024 05:48:33 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Energy Server Service queencreek service did not shut down properly after receiving a preshutdown control.
 
Error: (03/20/2024 05:38:54 PM) (Source: DCOM) (EventID: 10010) (User: DELL-LAPTOP)
Description: The server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter did not register with DCOM within the required timeout.
 
 
Windows Defender:
================
Date: 2024-02-16 09:55:47
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe; file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.405.71.0, AS: 1.405.71.0, NIS: 1.405.71.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10
 
Date: 2024-02-16 09:55:47
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: Unknown
Security intelligence Version: AV: 1.405.71.0, AS: 1.405.71.0, NIS: 1.405.71.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10
 
Date: 2024-02-16 09:55:47
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.405.71.0, AS: 1.405.71.0, NIS: 1.405.71.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10
 
Date: 2024-02-01 21:40:41
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: Unknown
Security intelligence Version: AV: 1.403.3067.0, AS: 1.403.3067.0, NIS: 1.403.3067.0
Engine Version: AM: 1.1.23110.2, NIS: 1.1.23110.2
 
Date: 2024-01-31 22:38:24
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.403.3022.0, AS: 1.403.3022.0, NIS: 1.403.3022.0
Engine Version: AM: 1.1.23110.2, NIS: 1.1.23110.2
Event[0]:
 
Date: 2024-02-05 11:19:06
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.403.3263.0
Previous security intelligence Version: 1.403.3218.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.23110.2
Previous Engine Version: 1.1.23110.2
Error code: 0x80070241
Error description: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. 
 
Date: 2024-02-05 11:19:06
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.403.3263.0
Previous security intelligence Version: 1.403.3218.0
Update Source: User
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 1.1.23110.2
Previous Engine Version: 1.1.23110.2
Error code: 0x80070241
Error description: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. 
 
Date: 2023-11-16 21:53:14
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Current
Error Code: 0x80070003
Error description: The system cannot find the path specified. 
Security intelligence Version: 0.0.0.0;0.0.0.0
Engine Version: 0.0.0.0
 
Date: 2023-06-06 02:56:46
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.391.576.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.23050.3
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
CodeIntegrity:
===============
Date: 2024-03-20 21:22:47
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2024-03-20 21:07:48
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SUPERAntiSpyware\sasdifsv64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2024-03-20 21:07:45
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SUPERAntiSpyware\saskutil64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
BIOS: Dell Inc. 1.2.7 12/13/2017
Motherboard: Dell Inc. 0H87XC
Processor: Intel® Core™ i5-6300HQ CPU @ 2.30GHz
Percentage of memory in use: 41%
Total physical RAM: 16250.84 MB
Available physical RAM: 9502.43 MB
Total Virtual: 21626.84 MB
Available Virtual: 13331.25 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:953.25 GB) (Free:546.64 GB) (Model: TEAM TM8PS7001T) NTFS
Drive d: (1TB) (Fixed) (Total:931.5 GB) (Free:708.91 GB) (Model: PNY CS900 1TB SSD) NTFS
 
\\?\Volume{09964035-891e-49f6-bab9-1af2dfe5e75a}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.43 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==================== End of Addition.txt =======================


#3 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 62,343 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:12 PM

Posted 21 March 2024 - 09:25 AM

Greetings and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:

  • First, please keep in mind most of us at BleepingComputer volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.
  • It is important to not run any tools or take any steps other than those I will provide for you.
  • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
  • Please copy and paste all logs into your post unless otherwise requested.
  • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
  • If you do not reply to your topic after 5 days I will assume it has been abandoned and I will close it.

===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

Unfortunately there is evidence of unauthorized/illegal software on your computer. I am going to request you completely uninstall all Microsoft, Adobe and all other products requiring proper activation for which you do not have a valid Product Key, including all "cracked" software. If you prefer to leave the program(s) on your computer let me know that and I will be closing the Topic.

If you are willing to remove all cracked software please complete the following after removal.

===================================================

ESET Online Scanner

--------------------

Note: You can expect this process to take a long time, up to several hours or more.

  • Download ESET Free Online Scanner and save it to your Desktop
  • Right click on esetonlinescanner_enu.exe and select Run as administrator
  • Click Computer Scan
  • Click Full scan
  • Select Enable ESET to detect and quarantine potentially unwanted applications
  • Click Start scan
  • Once completed click Save scan log and save it to your Desktop as ESETScan.txt
  • Click Continue then finally click Close
  • Copy and paste the ESETScan.txt file contents in your reply

===================================================

Run a new FRST scan and copy/paste both reports in your reply.

===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:

  • ESET report
  • FRST reports

Edited by Oh My!, 21 March 2024 - 09:34 AM.

Lord, to whom shall we go? You have the words of eternal life and we have believed and have come to know that you are the Holy One of God.
John 6:68-69

The Man on the Middle Cross Said I Could Come

#4 user23049

user23049
  • Topic Starter

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:09:12 PM

Posted 21 March 2024 - 12:31 PM

Hi Gary

 

Please bare with me as this is a family shared PC and have accumulated so much stuff on it over the years.  I believe I uninstalled all Microsoft/ Adobe products.  Can you let me know if there's anything else that needs removing that you see in the logs?

 

I did run the ESET tool .  And then re-run FRST, let me know if this is what you need.  Thanks

 

3/21/2024 12:17:59 PM
Scanned files: 1253840
Detected files: 17
Cleaned files: 25
Total scan time 01:15:54
Scan status: Finished
C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\amtemu.v0.9.1-painter.exe Win32/HackTool.Crack.FS potentially unsafe application cleaned by deleting
 
C:\ProgramData\regid.1993-06.com.microsoft\client32.ini Win32/NetSupportManager.AD trojan cleaned by deleting
 
C:\ProgramData\regid.1993-06.com.microsoft\client32u.ini Win32/NetSupportManager.AD trojan cleaned by deleting
 
C:\ProgramData\regid.1993-06.com.microsoft\NSM.LIC Win32/RiskWare.RemoteAdmin.NetSupportManager.V application cleaned by deleting
 
C:\Users\Phil\AppData\Local\Temp\jcnpb1sn.pjl.exe a variant of Win64/Agent.IC trojan cleaned by deleting
 
C:\Users\Phil\AppData\Local\Temp\pfcrbzoh.umt.exe a variant of Win64/Agent.IC trojan cleaned by deleting
 
C:\Users\Phil\AppData\Local\Zoom\Level1_ds.cmd BAT/Kryptik.R trojan cleaned by deleting
 
C:\Users\Phil\AppData\Local\Zoom\Level1_SC.cmd BAT/Kryptik.R trojan cleaned by deleting
 
C:\Users\Phil\AppData\Roaming\comcomZmr\msedge_elf.dll a variant of Win64/TrojanDownloader.Rugmi.AT.gen trojan cleaned by deleting
 
C:\Users\Phil\AppData\Roaming\strt.cmd BAT/Kryptik.R trojan cleaned by deleting
 
C:\Users\Phil\Desktop\Desktop icons\vera photo book 2017\LetsGo_SC.cmd PowerShell/Kryptik.HJ trojan cleaned by deleting
 
C:\Windows\SECOH-QAD.dll Win64/HackKMS.D potentially unsafe application cleaned by deleting
 
C:\Windows\SECOH-QAD.exe Win64/HackKMS.C potentially unsafe application cleaned by deleting
 
D:\Phil\Downloads\kmspico\KMSpico 10.1.8.2 FINAL + Portable (Office and Windows 10 Activator) [TechTools.NET]\KMSpico.10.1.8.2 FINAL [TechTools.net]\KMSpico.10.1.8.2\KMSpico Install\KMSpico_setup.exe a variant of MSIL/HackTool.IdleKMS.E potentially unsafe application,MSIL/HackTool.IdleKMS.O potentially unsafe application,Win32/HackKMS.AZ potentially unsafe application cleaned by deleting
 
D:\Phil\Downloads\kmspico\KMSpico 10.1.8.2 FINAL + Portable (Office and Windows 10 Activator) [TechTools.NET]\KMSpico.10.1.8.2 FINAL [TechTools.net]\KMSpico.10.1.8.2\KMSpico Portable\AutoPico.exe a variant of MSIL/HackTool.IdleKMS.E potentially unsafe application cleaned by deleting
 
D:\Phil\Downloads\kmspico\KMSpico 10.1.8.2 FINAL + Portable (Office and Windows 10 Activator) [TechTools.NET]\KMSpico.10.1.8.2 FINAL [TechTools.net]\KMSpico.10.1.8.2\KMSpico Portable\KMSELDI.exe MSIL/HackTool.IdleKMS.O potentially unsafe application cleaned by deleting
 
Operating memory a variant of Win32/Agent.ADLM trojan retained
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21.03.2024
Ran by Phil (administrator) on DELL-LAPTOP (Dell Inc. Inspiron 7559) (21-03-2024 13:22:24)
Running from C:\Users\Phil\Downloads\FRST64.exe
Loaded Profiles: Phil & SQLTELEMETRY & MSSQLSERVER
Platform: Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\crash_handler.exe <5>
(C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\PlayerLocationIcon.exe
(C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe ->) (OpenJS Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <5>
(C:\Program Files\WindowsApps\Microsoft.YourPhone_1.24021.105.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.24021.105.0_x64__8wekyb3d8bbwe\YourPhoneAppProxy.exe
(DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxCUIService.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxEM.exe
(explorer.exe ->) (Dell Inc -> Dell Inc.) [File not signed] C:\Program Files\Dell\QuickSet\quickset.exe
(explorer.exe ->) (Fresco Logic Inc -> Fresco Logic) C:\Program Files\Fresco Logic\Fresco Logic USB Display Driver\FL2000\x64\flvga_tray.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <21>
(explorer.exe ->) (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(explorer.exe ->) (Open Source Developer, XMouse Button Control -> Highresolution Enterprises) C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(explorer.exe ->) (PreSonus) [File not signed] C:\Program Files\PreSonus\Studio One 6\Studio One.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\WavesLocalServer.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\WavesPluginServer.exe
(Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe <2>
(Node.js Foundation -> Node.js) C:\Users\Phil\AppData\Roaming\Java\jre8\bin\java.exe
(rundll32.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe <2>
(services.exe ->) (Apple Computer, Inc.) [File not signed] C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(services.exe ->) (Array Networks, Inc. -> Array Networks) C:\Program Files\Array Networks\SSL VPN Client\VPNService.exe
(services.exe ->) (Cisco Systems, Inc. -> Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe
(services.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome Remote Desktop\123.0.6312.16\remoting_host.exe <2>
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
(services.exe ->) (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe
(services.exe ->) (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxCUIService.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\IntelCpHDCPSvc.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\IntelCpHeciSvc.exe
(services.exe ->) (Intel® Wireless Display -> Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlceip.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdmig.inf_amd64_75c152d756d851ed\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Private Internet Access, Inc. -> ) C:\Program Files\Private Internet Access\pia-service.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (ShenZhen Foscam Intelligent Technology Co,Ltd -> ) C:\Program Files (x86)\IPCWebComponents\IPCPlgSvr.exe
(services.exe ->) (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2401.0.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_11.2401.2.0_x64__8wekyb3d8bbwe\Microsoft.Media.Player.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe <4>
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9278152 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [3075552 2015-04-29] (Dell Inc -> Dell Inc.) [File not signed]
HKLM\...\Run: [XMouseButtonControl] => C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe [1091568 2015-03-02] (Open Source Developer, XMouse Button Control -> Highresolution Enterprises)
HKLM\...\Run: [RtHDVBg_WAVES_SKYLAKE] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WebVPN] => C:\Program Files\Array Networks\SSL VPN Client\WebVPN.exe [1484728 2020-01-17] (Array Networks, Inc. -> Array Networks)
HKLM\...\Run: [LaunchMhttpd] => C:\Program Files\Array Networks\MotionPro VPN Client\MPInit.exe [1532344 2020-01-16] (Array Networks, Inc. -> Array Networks)
HKLM\...\Run: [flvga_tray] => C:\Program Files\Fresco Logic\Fresco Logic USB Display Driver\FL2000\x64\flvga_tray.exe [457336 2017-11-23] (Fresco Logic Inc -> Fresco Logic)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [723928 2017-01-26] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [322120 2017-04-19] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [9923856 2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [1224704 2017-05-17] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true (No File)
HKLM-x32\...\Run: [flvga_tray32] => C:\Program Files\Fresco Logic\Fresco Logic USB Display Driver\FL2000\x86\flvga_tray.exe [431232 2017-11-23] (Fresco Logic Inc -> Fresco Logic)
HKLM-x32\...\Run: [LaunchMhttpd] => C:\Program Files\Array Networks\MotionPro VPN Client\MPInit.exe [1532344 2020-01-16] (Array Networks, Inc. -> Array Networks)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-08-04] (Adobe Inc. -> )
HKLM-x32\...\Run: [Cisconet] => "%AppData%\msftedit\WinXBlueRay.exe" (No File)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKLM\Software\Policies\...\system: [DisableLogonBackgroundImage] 1
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [11197680 2023-10-20] (RealDefense, LLC -> SUPERAntiSpyware)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [VideoGuardMonitor] => C:\Users\Phil\AppData\Local\Cisco\VideoGuardPlayer\VideoGuardMonitor\CiscoVideoGuardMonitor.exe [4155656 2016-06-14] (Cisco Video Technologies Israel Ltd. -> Cisco)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [31171504 2021-07-02] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [Lync] => "C:\Program Files\Microsoft Office\Office15\lync.exe" /fromrunkey (No File)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [Trio.WakeNet] => C:\Users\Phil\AppData\Local\TrioNet\Trio.Net.exe (No File)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [rasapi32] => wscript.exe "C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT\rasapi32.js" [178 2023-09-30] () [File not signed] <==== ATTENTION
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [MicrosoftEdgeAutoLaunch_0848959D30B7A075789B21F3CF73AE30] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4060712 2024-03-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\RunOnce: [removerbat] => C:\ProgramData\remover.bat [307 2024-03-20] () [File not signed] <==== ATTENTION
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Ribbons.scr [153600 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\123.0.6312.58\Installer\chrmstp.exe [2024-03-19] (Google LLC -> Google LLC)
Startup: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Gqreader.lnk [2023-11-28]
ShortcutTarget: Gqreader.lnk -> C:\Users\Phil\AppData\Roaming\msftedit\WinXBluRay.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WavesLocalServer.lnk [2024-02-16]
ShortcutTarget: WavesLocalServer.lnk -> C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\WavesLocalServer.exe (Waves Inc -> Waves Audio Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WavesPluginServer.lnk [2024-02-16]
ShortcutTarget: WavesPluginServer.lnk -> C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\WavesPluginServer.exe (Waves Inc -> Waves Audio Ltd.)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {D0AF27D6-8368-4DA9-926B-288A91E56430} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {B232ECA6-D3D1-4EC4-A32D-E08E86763ED0} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe  -mode=scheduled (No File)
Task: {6E871D55-E95C-49CD-BA3C-F22273B9A96E} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Phil\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15145336 2024-03-21] (ESET, spol. s r.o. -> ESET)
Task: {4094FFBA-8331-4324-B066-0483EB60311D} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Phil\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15145336 2024-03-21] (ESET, spol. s r.o. -> ESET)
Task: {484B1CBC-6F11-4EC5-9BAD-B3A61D5E1965} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [40880 2021-07-02] (Garmin International, Inc. -> )
Task: {8B28A3DC-F851-49CC-AE5C-75B0DD295852} - System32\Tasks\GeoComply Service Check => C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\PlayerLocationCheckTask.cmd [1642 2024-02-21] () [File not signed] -> 
Task: {1D31A6C3-7C57-4FA5-8B5F-A51626FD4B69} - System32\Tasks\GeoComply Update Task => C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exe [6817472 2024-01-09] (GeoComply Solutions Inc. -> GeoComply)
Task: {76D5F9DF-E161-452D-8A12-2595ED40B702} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem124.0.6359.0{8357AD38-F079-4341-A798-7030F0EC8024} => C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
Task: {117E77E1-2BF4-4A8C-A5EF-AEE5D8733741} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [1698000 2015-06-05] (Intel® Software -> Intel Corporation)
Task: {5048683B-C65F-43DE-AB39-836AE917B600} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [1328392 2015-11-20] (Intel® Software -> Intel Corporation)
Task: {3D46B100-7552-4143-B86A-F2B9970703F6} - System32\Tasks\Intel\System.Windows.Presentatio00_clr0400 => C:\Windows\system32\rundll32.exe [71680 2023-11-14] (Microsoft Windows -> Microsoft Corporation) -> C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll SHEiflowfdqaa
Task: {CA1B9BF5-B927-4DEB-8A8A-D57A37594261} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4922296 2023-12-19] (Intel Corporation -> Intel Corporation)
Task: {57F4C7BD-EE60-4DCA-BED3-44916DF616EF} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4922296 2023-12-19] (Intel Corporation -> Intel Corporation)
Task: {18D9AD6F-8D24-475B-8B5C-36A6F6F4B070} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {65F73DCD-EC0C-44BE-814D-37B8092B83CF} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {7B4E0C68-BE5A-4442-A2BD-993BA50AA038} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe  --automatic (No File)
Task: {D1C4A8EB-315A-4825-9DB7-4957252883A2} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\AppInstallerUpdater => C:\Windows\system32\rundll32.exe [71680 2023-11-14] (Microsoft Windows -> Microsoft Corporation) -> %windir%\system32\AppxDeploymentClient.dll,AppInstallerUpdateAllTask
Task: {1285EF45-46C2-4589-BE1B-1F5B589478BB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {163BFC57-00C4-4EFC-82F4-E3B8CA9A7709} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3633EEEE-A5BF-4403-A543-9B89FB7AA1BA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BCEBEA1C-119E-446B-BC40-C755C75A8DD1} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1483475722-1219764467-3277934236-1001 92F44938A7A458E5 => C:\Users\Phil\AppData\Local\Mozilla Firefox\firefox.exe [671648 2024-03-12] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\92F44938A7A458E5\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {721029C4-76FB-4967-BBB9-DC8094FC370A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 92F44938A7A458E5 => C:\Users\Phil\AppData\Local\Mozilla Firefox\default-browser-agent.exe [34720 2024-03-12] (Mozilla Corporation -> Mozilla Foundation)
Task: {D65748B1-D097-42BA-9B41-B4BD003B5160} - System32\Tasks\OneNote 5797 => C:\Users\Phil\AppData\Roaming\strt.cmd  -> 
Task: {08CAD4CF-9FEA-4DB1-83B7-D9935729BC84} - System32\Tasks\OneNote 89688 => C:\Users\Phil\AppData\Roaming\strt.cmd  -> 
Task: {63C0817E-7830-4189-BC23-F9E568C905D4} - System32\Tasks\Opera GX scheduled Autoupdate 1696112022 => C:\Users\Phil\AppData\Local\Programs\Opera GX\launcher.exe  --scheduledautoupdate $(Arg0) (No File)
Task: {44369712-8FE0-4ADE-93B5-90A17714898E} - System32\Tasks\Private Internet Access Startup => "C:\Program Files\pia_manager\pia_manager.exe"  --startup (No File)
Task: {72D88C66-E288-4856-82BB-0189C31F9503} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {3D13762D-057E-43AA-AC86-ADA65FB62FDF} - System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => C:\Windows\TEMP\DeleteFolderTask.exe  (No File) <==== ATTENTION
Task: {93D639BD-617B-4C2E-8178-42C2F35827DE} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\WINDOWS\System32\Wscript.exe [170496 2023-10-11] (Microsoft Windows -> Microsoft Corporation) -> //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\44C496E6B6F51405F574F6474716: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\5374: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\7416C616879702351303B273163673: [DhcpNameServer] 192.168.34.212
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\757535F5445313243313: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\765647F66666D697C61677E6: [DhcpNameServer] 192.168.209.47
Tcpip\..\Interfaces\{2ace0890-853d-46fd-9bd1-a8b7f498fe12}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f0e1c8ca-7fe6-4c84-8e99-04a669df5c9c}: [DhcpNameServer] 209.222.18.222 209.222.18.218
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
 
Edge: 
=======
Edge Profile: C:\Users\Phil\AppData\Local\Microsoft\Edge\User Data\Default [2024-03-21]
Edge DownloadDir: Default -> C:\Users\Phil\Downloads
Edge Extension: (Google Docs Offline) - C:\Users\Phil\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-07]
Edge Extension: (Edge relevant text changes) - C:\Users\Phil\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-23]
 
FireFox:
========
FF DefaultProfile: csjgqetv.default
FF ProfilePath: C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\csjgqetv.default [2023-06-12]
FF ProfilePath: C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\xvi6q9b2.default-release [2024-03-20]
FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google Inc -> Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @IPC/npmedia3.0.0.3,version=3.0.0.3 -> C:\Program Files\webrec\Torch\3.0.0.3\npmedia3.0.0.3.dll [2016-11-03] (Amcrest Technologies LLC -> )
FF Plugin-x32: @IPCWebComponents -> C:\Program Files (x86)\IPCWebComponents\npIPCReg.dll [2016-12-26] (ShenZhen Foscam Intelligent Technology Co,Ltd -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-03-21]
CHR Extension: (lock) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aeblfdkhhhdcdjpifhhbdiojplfjncoa [2024-03-05]
CHR Extension: (PayPal Honey: Automatic Coupons & Cash Back) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2024-02-19]
CHR Extension: (uBlock Origin) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2024-02-26]
CHR Extension: (Videostream for Google Chromecast™) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2020-05-26]
CHR Extension: (Tampermonkey) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2024-01-20]
CHR Extension: (Video Downloader Professional) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2023-04-19]
CHR Extension: (Yoroi) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ffnbelfdoeiohenkjibnmadjiehjhajb [2024-03-20]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-19]
CHR Extension: (Google Docs Offline) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-20]
CHR Extension: (Lightning Extension) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hfglcknhngdnhbkccblidlkljgflofgh [2023-04-25]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2023-04-08]
CHR Extension: (SponsorBlock for YouTube - Skip Sponsorships) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mnjggcdmjocbbbhaepdhchncahnbgone [2024-03-20]
CHR Extension: (Spread3D Review for SketchUp) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ncjkndlllagaajogioiailncjbmbalci [2018-03-13]
CHR Extension: (MetaMask) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn [2024-03-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-03]
CHR Extension: (Amcrest Web View) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oddndbjhpcpopbebhonolceinkbnheih [2018-03-13]
CHR Extension: (uBlock Origin Extra) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pgdnlhfefecpicbbihgmbmffkjpaplco [2019-09-10]
CHR Profile: C:\Users\Phil\AppData\Local\Google\Chrome\User Data\System Profile [2023-11-19]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2021-01-09] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
R2 Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed]
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\123.0.6312.16\remoting_host.exe [74016 2024-02-26] (Google LLC -> Google LLC)
R2 com.geocomply.internal-updater-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exe [11492528 2024-02-21] (GeoComply Solutions Inc. -> )
R2 com.geocomply.process-scanner-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe [11494064 2024-02-21] (GeoComply Solutions Inc. -> )
R2 com.geocomply.vm-detector-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exe [11534000 2024-02-21] (GeoComply Solutions Inc. -> )
R2 com.geocomply.wifi-scanner-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exe [11514544 2024-02-21] (GeoComply Solutions Inc. -> )
S4 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [153328 2015-06-15] (Dell Inc. -> Dell Inc.)
S4 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [119656 2016-01-15] (Dell Inc. -> Dell)
S4 Dell Help & Support; C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe [49864 2015-07-31] (Dell Inc. -> )
S4 Dell Product Registration; C:\Program Files\Dell\Product Registration\PRSvc.exe [32104 2016-01-25] (Dell Inc. -> Dell)
S4 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc. -> Dell Inc.)
R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [43784 2023-09-25] (Intel Corporation -> Intel)
R3 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [240392 2023-11-13] (Intel Corporation -> Intel)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2016-03-04] (Macrovision Europe Ltd.) [File not signed]
R2 FosCloudSvr; C:\Program Files (x86)\IPCWebComponents\IPCPlgSvr.exe [91776 2016-12-26] (ShenZhen Foscam Intelligent Technology Co,Ltd -> )
S2 GoogleUpdaterInternalService124.0.6359.0; C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
S2 GoogleUpdaterService124.0.6359.0; C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
R3 Intel® Security Assist; C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S3 Intel® WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [396992 2015-07-06] (Intel® Wireless Display -> Intel)
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R4 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [11072008 2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9343840 2023-12-20] (Malwarebytes Inc. -> Malwarebytes)
S3 MSIInstallManager; C:\Program Files (x86)\Array Networks\MPMSIInstallManager\MSIInstallManager.exe [723896 2020-01-17] (Array Networks, Inc. -> TODO: <Company name>)
S3 MsMpiLaunchSvc; C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe [23040 2016-03-04] () [File not signed]
R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [479128 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvdmig.inf_amd64_75c152d756d851ed\Display.NvContainer\NVDisplay.Container.exe [1274888 2023-11-10] (NVIDIA Corporation -> NVIDIA Corporation)
R2 Player Location Check; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe [11440816 2024-02-21] (GeoComply Solutions Inc. -> )
R2 PrivateInternetAccessService; C:\Program Files\Private Internet Access\pia-service.exe [1394400 2024-03-05] (Private Internet Access, Inc. -> )
S3 PrivateInternetAccessWireguard; C:\Program Files\Private Internet Access\pia-wgservice.exe [4455000 2024-03-05] (Private Internet Access, Inc. -> )
S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [572824 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
R2 SQLTELEMETRY; C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlceip.exe [246672 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [21242680 2024-02-19] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 VPNInstallManager; C:\Program Files\Array Networks\Install Manager\VPNInstallManager.exe [1418168 2020-01-17] (Array Networks, Inc. -> Array Networks)
R2 VPNService; C:\Program Files\Array Networks\SSL VPN Client\VPNService.exe [2422200 2020-01-17] (Array Networks, Inc. -> Array Networks)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\NisSrv.exe [3191272 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe [133688 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 FoxitReaderService; "C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe" [X]
S2 IAStorDataMgrSvc; "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe" [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BEHRINGER_2902; C:\WINDOWS\System32\Drivers\BUSB2902.sys [460864 2009-10-30] (Ploytec GmbH -> BEHRINGER)
S3 BUSB_AUDIO_WDM; C:\WINDOWS\system32\drivers\busbwdm.sys [49728 2009-10-30] (Ploytec GmbH -> BEHRINGER)
S3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [41608 2018-02-10] (Techporch Incorporated -> Dell Inc.)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-02-10] (Techporch Incorporated -> Dell Computer Corporation)
R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [19440 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> OSR Open Systems Resources, Inc.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 fl2000; C:\WINDOWS\System32\drivers\fl2000.sys [205944 2017-11-23] (Fresco Logic Inc -> Fresco Logic)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-04-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-03-20] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MpKsl8d55da6b; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6DC6B031-0A2E-4D53-B6BC-C61E3FB2BBEB}\MpKslDrv.sys [300312 2024-03-20] (Microsoft Windows -> Microsoft Corporation)
R2 NPF; C:\Program Files (x86)\Batch Configuration\npf64.sys [36600 2019-05-20] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S4 RsFx0501; C:\WINDOWS\System32\DRIVERS\RsFx0501.sys [261784 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [27744 2021-03-09] (Daniel Terhell -> Resplendence Software Projects Sp.)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [18160 2023-08-25] (RealDefense, LLC -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [15600 2023-08-25] (RealDefense, LLC -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [315904 2023-12-13] (Microsoft Windows -> Microsoft Corporation)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 tap-pia-0901; C:\WINDOWS\System32\drivers\tap-pia-0901.sys [39944 2020-12-01] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2017-12-27] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 tapwindscribe0901; C:\WINDOWS\System32\drivers\tapwindscribe0901.sys [54896 2017-09-13] (Windscribe Limited -> The OpenVPN Project)
R1 UimBus; C:\WINDOWS\System32\drivers\UimBus.sys [102576 2015-11-10] (Paragon Software GmbH -> )
R1 Uim_DEVIM; C:\WINDOWS\System32\drivers\uim_devim.sys [25904 2015-11-10] (Paragon Software GmbH -> )
R1 Uim_IM; C:\WINDOWS\System32\drivers\uim_im.sys [701360 2015-11-10] (Paragon Software GmbH -> )
S3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [212056 2015-07-06] (Intel® Wireless Display -> Windows ® Win 7 DDK provider)
R1 veracrypt; C:\WINDOWS\System32\drivers\veracrypt.sys [831616 2021-01-03] (IDRIX SARL -> IDRIX)
R1 vpntdi; C:\WINDOWS\System32\drivers\vpntdi64.sys [65360 2017-12-13] (Array Networks, Inc. -> Array Networks)
S3 vpnva; C:\WINDOWS\System32\drivers\vpnva64-6.sys [52592 2016-02-29] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
R0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20928 2024-03-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [603416 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105752 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
R3 WinDriver6; C:\WINDOWS\system32\drivers\windrvr6.sys [285696 2007-06-17] (Microsoft Windows Hardware Compatibility Publisher -> Jungo)
S3 ysusb_w10_64; C:\WINDOWS\system32\drivers\ysusb_w10_64.sys [181784 2023-02-10] (Microsoft Windows Hardware Compatibility Publisher -> Yamaha Corporation)
S3 DrvSnSht; \??\C:\Users\Phil\AppData\Local\Temp\RarSFX0\DrvSnSht64.sys [X] <==== ATTENTION
S3 R-ImageDisk; \??\C:\Users\Phil\AppData\Local\Temp\RarSFX0\R-ImageDisk64.sys [X] <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2024-03-21 13:22 - 2024-03-21 13:23 - 000044296 _____ C:\Users\Phil\Downloads\FRST.txt
2024-03-21 13:22 - 2024-03-21 13:22 - 002391040 _____ (Farbar) C:\Users\Phil\Downloads\FRST64.exe
2024-03-21 13:22 - 2024-03-21 13:22 - 000000000 ____D C:\Users\Phil\Downloads\FRST-OlderVersion
2024-03-21 12:19 - 2024-03-21 12:19 - 000003846 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2024-03-21 12:19 - 2024-03-21 12:19 - 000003404 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2024-03-21 12:17 - 2024-03-21 12:17 - 000005196 _____ C:\Users\Phil\Desktop\edetscan.txt
2024-03-21 10:52 - 2024-03-21 10:56 - 000001336 _____ C:\Users\Phil\Desktop\ESET Online Scanner.lnk
2024-03-21 10:50 - 2024-03-21 10:56 - 000001442 _____ C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2024-03-21 10:50 - 2024-03-21 10:50 - 008389496 _____ (ESET) C:\Users\Phil\Desktop\esetonlinescanner.exe
2024-03-21 10:50 - 2024-03-21 10:50 - 000000000 ____D C:\Users\Phil\AppData\Local\ESET
2024-03-21 08:09 - 2024-03-21 08:09 - 159651974 _____ C:\Users\Phil\Downloads\VOCALS-3-20.zip
2024-03-21 08:09 - 2024-03-21 08:09 - 000000000 ____D C:\Users\Phil\Downloads\VOCALS-3-20
2024-03-20 21:24 - 2024-03-21 13:22 - 000000000 ____D C:\FRST
2024-03-20 21:08 - 2024-03-20 21:08 - 000000307 _____ C:\ProgramData\remover.bat
2024-03-20 19:46 - 2024-03-20 19:46 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2024-03-20 17:37 - 2024-03-20 17:37 - 000001463 _____ C:\Users\Phil\Desktop\Roblox Player.lnk
2024-03-17 11:07 - 2024-03-17 11:07 - 000001138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Private Internet Access.lnk
2024-03-15 20:50 - 2024-03-18 10:46 - 000001989 _____ C:\Users\Phil\Desktop\dydx.txt
2024-03-14 20:33 - 2024-03-14 20:33 - 000002302 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2024-03-14 20:33 - 2024-03-14 20:33 - 000002290 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
2024-03-14 20:33 - 2024-03-14 20:33 - 000000000 ____D C:\Program Files\Google
2024-03-13 23:05 - 2024-03-13 23:05 - 000000000 ____D C:\Users\Phil\AppData\Roaming\ReAmp Studio R1
2024-03-13 19:50 - 2024-03-13 19:50 - 000019530 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-03-13 19:50 - 2024-03-13 19:50 - 000019530 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2024-03-13 19:44 - 2024-03-13 19:44 - 000000000 ___HD C:\$WinREAgent
2024-03-12 14:23 - 2024-03-21 09:11 - 000000000 ____D C:\Users\Phil\AppData\Local\Mozilla Firefox
2024-03-11 14:38 - 2024-03-11 14:38 - 000000030 _____ C:\Users\Phil\Documents\roto tom tunings.txt
2024-03-06 18:10 - 2024-03-20 17:38 - 000002425 _____ C:\WINDOWS\system32\default_error_stack-000000-000000.txt
2024-03-05 16:16 - 2024-03-05 16:16 - 000000000 ____D C:\ProgramData\{97BAC61B-4997-4F27-8567-391BD82F596A}
2024-03-05 16:15 - 2024-03-20 21:21 - 000000000 ____D C:\Users\Phil\AppData\Local\Desktop_inni
2024-03-05 16:15 - 2024-03-05 16:15 - 000003310 _____ C:\WINDOWS\system32\Tasks\OneNote 5797
2024-03-05 16:15 - 2024-03-05 16:15 - 000000000 ____D C:\ProgramData\{3FCE7907-AA6B-470A-BFB2-C042375EDBDF}
2024-03-04 14:15 - 2024-03-04 14:15 - 000000920 _____ C:\Users\Public\Desktop\TeamViewer.lnk
2024-03-01 17:34 - 2024-03-01 17:35 - 398253515 _____ C:\Users\Phil\Downloads\044Dry_Stems.zip
2024-03-01 17:28 - 2024-03-01 17:34 - 000000000 ____D C:\Users\Phil\Downloads\044Dry_Stems
2024-02-27 16:04 - 2024-02-27 16:04 - 000214867 _____ C:\Users\Phil\Desktop\blank travel sheet (1).odt
2024-02-21 18:31 - 2024-02-21 18:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon
2024-02-21 18:31 - 2024-02-21 18:31 - 000000000 ____D C:\Program Files\LatencyMon
2024-02-21 18:31 - 2021-03-09 16:07 - 000027744 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspLLL64.sys
2024-02-21 18:30 - 2024-02-21 18:30 - 003478312 _____ (Resplendence Software Projects Sp. ) C:\Users\Phil\Desktop\LatencyMon.exe
2024-02-21 12:35 - 2024-02-22 16:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\H&R Block 2023
2024-02-21 12:35 - 2024-02-22 16:32 - 000000000 ____D C:\Program Files (x86)\HRBlock2023
2024-02-21 12:35 - 2024-02-21 12:35 - 000000000 ____D C:\Users\Phil\Documents\HRBlock
2024-02-21 12:35 - 2024-02-21 12:35 - 000000000 ____D C:\Program Files (x86)\PDF995
2024-02-21 08:25 - 2024-02-21 08:25 - 000003442 _____ C:\WINDOWS\system32\Tasks\GeoComply Update Task
2024-02-21 08:25 - 2024-02-21 08:25 - 000003212 _____ C:\WINDOWS\system32\Tasks\GeoComply Service Check
2024-02-20 15:02 - 2024-02-20 15:02 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2024-03-21 13:18 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-03-21 12:32 - 2024-01-30 23:33 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Celemony Software GmbH
2024-03-21 11:29 - 2024-02-05 18:32 - 000000000 ____D C:\Users\Phil\AppData\Roaming\comcomZmr
2024-03-21 11:29 - 2023-08-16 12:46 - 000000000 ____D C:\Users\Phil\AppData\Local\Zoom
2024-03-21 11:18 - 2023-09-30 18:12 - 000000000 ____D C:\ProgramData\regid.1993-06.com.microsoft
2024-03-21 10:55 - 2016-03-06 12:38 - 000000000 ____D C:\Users\Phil\AppData\Local\CrashDumps
2024-03-21 10:44 - 2023-09-25 15:46 - 000000000 ____D C:\Program Files\Common Files\VST3
2024-03-21 10:42 - 2018-05-19 16:26 - 000000000 ____D C:\ProgramData\Adobe
2024-03-21 10:40 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2024-03-21 10:40 - 2016-03-04 15:54 - 000000000 ____D C:\Program Files\Microsoft Office
2024-03-21 10:40 - 2015-10-30 05:07 - 000000000 ____D C:\WINDOWS\ShellNew
2024-03-21 10:39 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files\Common Files\System
2024-03-21 10:39 - 2015-07-10 07:04 - 000000076 _____ C:\WINDOWS\win.ini
2024-03-21 10:38 - 2017-07-09 20:59 - 000000000 ____D C:\Users\Public\Documents\Adobe
2024-03-21 10:38 - 2017-07-09 20:49 - 000000000 ____D C:\Program Files\Common Files\Adobe
2024-03-21 10:37 - 2017-07-09 20:49 - 000000000 ____D C:\Program Files\Adobe
2024-03-21 10:37 - 2016-03-04 12:29 - 000000000 ____D C:\Users\Phil\AppData\Local\ClassicShell
2024-03-21 10:35 - 2020-08-30 06:10 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-03-21 07:08 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2024-03-20 23:53 - 2016-03-04 01:48 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-03-20 23:49 - 2016-03-04 01:48 - 190470136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-03-20 22:25 - 2020-08-30 06:22 - 001007224 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-03-20 21:16 - 2023-11-28 17:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\msftedit
2024-03-20 21:08 - 2016-03-03 23:10 - 000000000 __SHD C:\Users\Phil\IntelGraphicsProfiles
2024-03-20 21:07 - 2024-01-16 01:52 - 000008192 ___SH C:\DumpStack.log.tmp
2024-03-20 21:07 - 2023-10-28 09:21 - 000000000 ____D C:\Program Files\TeamViewer
2024-03-20 21:07 - 2020-08-30 06:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-03-20 21:07 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2024-03-20 21:07 - 2017-07-29 22:04 - 000000000 ____D C:\ProgramData\NVIDIA
2024-03-20 20:59 - 2023-09-25 15:13 - 000000000 ____D C:\Users\Phil\AppData\Local\Malwarebytes
2024-03-20 20:07 - 2017-08-20 22:15 - 000002370 ____H C:\Users\Phil\Documents\Default.rdp
2024-03-20 20:01 - 2019-12-07 05:50 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2024-03-20 20:00 - 2023-01-29 12:31 - 000000000 ____D C:\Users\Phil\Desktop\Desktop icons
2024-03-20 19:47 - 2015-12-11 11:58 - 000000000 ____D C:\ProgramData\Package Cache
2024-03-20 19:46 - 2017-07-29 22:03 - 000000000 ____D C:\Program Files (x86)\Intel
2024-03-20 18:56 - 2024-02-16 10:36 - 000000000 ____D C:\Users\Phil\AppData\Local\central-updater
2024-03-20 18:56 - 2024-02-16 10:21 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Waves Central
2024-03-20 17:49 - 2020-08-30 06:11 - 000000000 ____D C:\Users\SQLTELEMETRY
2024-03-20 17:49 - 2020-08-30 06:11 - 000000000 ____D C:\Users\MSSQLSERVER
2024-03-20 17:45 - 2024-02-07 10:57 - 000000000 ____D C:\Users\Phil\AppData\Roaming\OracleJDK
2024-03-20 17:37 - 2023-06-08 17:28 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2024-03-20 06:52 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-03-19 19:39 - 2021-12-15 03:44 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-03-19 19:39 - 2020-04-10 21:15 - 000000000 ____D C:\Users\Phil\AppData\Roaming\qBittorrent
2024-03-19 19:39 - 2016-03-04 12:41 - 000002340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-03-19 19:39 - 2016-03-04 12:41 - 000002299 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-03-19 13:51 - 2023-06-12 13:02 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-03-19 08:11 - 2023-06-12 13:02 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2024-03-19 08:10 - 2023-06-12 13:02 - 000001325 _____ C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-03-19 01:21 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-03-17 20:40 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2024-03-17 16:08 - 2016-03-04 16:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Microsoft\Word
2024-03-17 15:36 - 2016-03-05 11:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Microsoft\Excel
2024-03-17 11:43 - 2016-03-05 18:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\vlc
2024-03-17 11:07 - 2020-12-03 18:58 - 000000000 ____D C:\Program Files\Private Internet Access
2024-03-16 06:53 - 2020-07-04 03:13 - 000002479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-03-15 20:52 - 2020-08-30 06:10 - 005466128 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-03-15 20:51 - 2019-12-07 05:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2024-03-15 20:51 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\servicing
2024-03-15 20:00 - 2024-02-05 18:07 - 000000000 ___HD C:\Users\Phil\AppData\Roaming\winsQ
2024-03-13 19:53 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-03-13 19:50 - 2020-08-30 06:16 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-03-13 12:45 - 2023-10-12 08:15 - 000000000 ____D C:\Users\Phil\Documents\Studio One
2024-03-13 01:00 - 2018-02-28 15:34 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-03-06 00:47 - 2020-08-30 06:18 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-03-06 00:47 - 2020-08-30 06:18 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-03-03 02:16 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2024-03-02 06:59 - 2016-03-11 21:24 - 000000000 ____D C:\Users\Phil\AppData\Local\ElevatedDiagnostics
2024-02-28 14:56 - 2020-02-25 14:30 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Ledger Live
2024-02-28 14:34 - 2018-05-24 16:35 - 000000000 ____D C:\Users\Phil\AppData\Local\D3DSCache
2024-02-28 14:32 - 2021-10-17 15:01 - 000000000 ____D C:\Program Files\Ledger Live
2024-02-21 12:35 - 2019-02-16 15:06 - 000000000 ____D C:\Users\Phil\AppData\Roaming\TaxCut
2024-02-21 12:35 - 2019-02-16 15:05 - 000000000 ____D C:\ProgramData\TaxCut
2024-02-20 15:02 - 2016-03-04 12:41 - 000000000 ____D C:\Program Files (x86)\Google
 
==================== Files in the root of some directories ========
 
2024-03-20 21:08 - 2024-03-20 21:08 - 000000307 _____ () C:\ProgramData\remover.bat
2018-09-27 10:57 - 2018-09-27 10:57 - 000000000 _____ () C:\Users\Phil\AppData\Local\oobelibMkey.log
2016-10-27 20:51 - 2022-03-02 21:50 - 000007589 _____ () C:\Users\Phil\AppData\Local\Resmon.ResmonCfg
2024-02-16 10:49 - 2024-03-21 12:33 - 000121449 _____ () C:\Users\Phil\AppData\Local\wle.log
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 


#5 user23049

user23049
  • Topic Starter

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:09:12 PM

Posted 21 March 2024 - 12:34 PM

I tried posting Addition.txt here but it keeps saying the post is too long - so instead have attached it.  Thanks

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21.03.2024
Ran by Phil (21-03-2024 13:23:39)
Running from C:\Users\Phil\Downloads
Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) (2020-08-30 10:18:48)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-1483475722-1219764467-3277934236-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1483475722-1219764467-3277934236-503 - Limited - Disabled)
Guest (S-1-5-21-1483475722-1219764467-3277934236-501 - Limited - Enabled)
Phil (S-1-5-21-1483475722-1219764467-3277934236-1001 - Administrator - Enabled) => C:\Users\Phil
WDAGUtilityAccount (S-1-5-21-1483475722-1219764467-3277934236-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov)
Active Directory Authentication Library for SQL Server (HKLM\...\{4EE99065-01C6-49DD-9EC6-E08AA5B13491}) (Version: 14.0.1000.169 - Microsoft Corporation)
Add or Remove Adobe Creative Suite 3 Master Collection (HKLM-x32\...\Adobe_4dcfd9b7e901b57f81f667144603236) (Version: 1.0 - Adobe Systems Incorporated)
adobe (HKLM\...\{20FD3B0E-D450-488F-AB68-7DA0EC0E4913}) (Version: 1.0.0000 - Adobe Systems Incorporated) Hidden
Adobe After Effects CS3 Presets (HKLM-x32\...\{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}) (Version: 8 - Adobe Systems Incorporated) Hidden
Adobe Anchor Service CS3 (HKLM-x32\...\{90176341-0A8B-4CCC-A78D-F862228A6B95}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Asset Services CS3 (HKLM-x32\...\{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}) (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe Audition CC 2017 (HKLM-x32\...\AUDT_10_1_1) (Version: 10.1.1 - Adobe Systems Incorporated)
Adobe Bridge CS3 (HKLM-x32\...\{9C9824D9-9000-4373-A6A5-D0E5D4831394}) (Version: 2 - Adobe Systems Incorporated) Hidden
Adobe Bridge Start Meeting (HKLM-x32\...\{08B32819-6EEF-4057-AEDA-5AB681A36A23}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe BridgeTalk Plugin CS3 (HKLM-x32\...\{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Camera Raw 4.0 (HKLM-x32\...\{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}) (Version: 4.0 - Adobe Systems Incorporated) Hidden
Adobe CMaps (HKLM-x32\...\{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color - Photoshop Specific (HKLM-x32\...\{A2D81E70-2A98-4A08-A628-94388B063C5E}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color Common Settings (HKLM-x32\...\{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color EU Extra Settings (HKLM-x32\...\{51846830-E7B2-4218-8968-B77F0FF475B8}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color JA Extra Settings (HKLM-x32\...\{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color NA Recommended Settings (HKLM-x32\...\{95655ED4-7CA5-46DF-907F-7144877A32E5}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Creative Suite 3 Master Collection (HKLM-x32\...\{8718DC03-D066-4957-94E5-50C3C5042E8E}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Default Language CS3 (HKLM-x32\...\{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Device Central CS3 (HKLM-x32\...\{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe ExtendScript Toolkit 2 (HKLM-x32\...\{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}) (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Extension Manager CS3 (HKLM-x32\...\{BE5F3842-8309-4754-92D5-83E02E6077A3}) (Version: 1.8 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 9 ActiveX (HKLM-x32\...\{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}) (Version: 9.0.45.0 - Adobe Systems, Inc.)
Adobe Flash Player 9 Plugin (HKLM-x32\...\{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}) (Version: 9.0.45.0 - Adobe Systems, Inc.)
Adobe Fonts All (HKLM-x32\...\{6ABE0BEE-D572-4FE8-B434-9E72A289431B}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Help Viewer CS3 (HKLM-x32\...\{7ACFB90E-8FD0-4397-AD3A-5195412623A3}) (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe InDesign CS3 Icon Handler (HKLM-x32\...\{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}) (Version: 5.0 - Adobe Systems Incorporated) Hidden
Adobe Linguistics CS3 (HKLM-x32\...\{54793AA1-5001-42F4-ABB6-C364617C6078}) (Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe MotionPicture Color Files (HKLM-x32\...\{6B708481-748A-4EB4-97C1-CD386244FF77}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe PDF Library Files (HKLM-x32\...\{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}) (Version: 8.0 - Adobe Systems Incorporated) Hidden
Adobe Setup (HKLM-x32\...\{4458C442-7376-4CF9-AF58-E8CEA6722363}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe SING CS3 (HKLM-x32\...\{B671CBFD-4109-4D35-9252-3062D3CCB7B2}) (Version: 0.1 - Adobe Systems Incorporated) Hidden
Adobe Stock Photos CS3 (HKLM-x32\...\{29E5EA97-5F74-4A57-B8B2-D4F169117183}) (Version: 1.5 - Adobe Systems Incorporated) Hidden
Adobe Type Support (HKLM-x32\...\{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Update Manager CS3 (HKLM-x32\...\{E69AE897-9E0B-485C-8552-7841F48D42D8}) (Version: 5.1.0 - Adobe Systems Incorporated) Hidden
Adobe Version Cue CS3 Client (HKLM-x32\...\{D0DFF92A-492E-4C40-B862-A74A173C25C5}) (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe Video Profiles (HKLM-x32\...\{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe WAS CS3 (HKLM-x32\...\{C5BD220A-EFE8-48A5-B70E-9503D535FACE}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe WinSoft Linguistics Plugin (HKLM-x32\...\{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe XMP DVA Panels CS3 (HKLM-x32\...\{0224CACC-994D-45F8-B973-D65056EA9C2F}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe XMP Panels CS3 (HKLM-x32\...\{D5A31AB1-345D-47C7-A87B-036A669F6DF1}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
AHV content for Acrobat and Flash (HKLM-x32\...\{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}) (Version: 1 - Adobe Systems Incorporated) Hidden
Amazon.com Fire_Devices (HKLM\...\Fire_Devices Drivers) (Version: 2 - Amazon.com)
ANT Drivers Installer x64 (HKLM\...\{CBEE7F70-D77E-46DB-BB02-B64147DD6453}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Batch Configuration (HKLM-x32\...\{F9F88CAE-A8BB-493A-BC71-B19A8BA38613}) (Version: 3.0.2.6 - hikvision)
BEHRINGER USB AUDIO DRIVER (HKLM\...\USB_AUDIO_DEusb-audio.deBehringer2902) (Version:  - )
Browser for SQL Server 2017 (HKLM-x32\...\{CF8EEB96-E7E7-4EF7-A0A1-559F09953156}) (Version: 14.0.1000.169 - Microsoft Corporation)
Bruteforce Save Data (HKLM-x32\...\Bruteforce Save Data) (Version:  - )
Calibration Update Wizard (HKLM-x32\...\{5A03CEC0-8805-11D4-ADFB-00000EFB3A77}) (Version: 8.20.1 - Toyota Diagnostics)
Celemony Melodyne 5 (HKLM\...\Celemony Melodyne 5_is1) (Version: 5.3.1.018 - Celemony)
Charter TV Player (HKLM-x32\...\{076af162-8f4c-4e36-9013-1673e5cf4d24}) (Version: 6.6 - Charter)
Chrome Remote Desktop Host (HKLM-x32\...\{00B18403-87DD-4C4E-AEB5-045B05B96F35}) (Version: 123.0.6312.16 - Google LLC)
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 4.4.03034 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\{EB629A98-5E69-40E8-BA9E-C393899F959D}) (Version: 4.4.03034 - Cisco Systems, Inc.) Hidden
Cisco VideoGuard Player (HKLM-x32\...\{dfc759fd-a56f-4d04-8306-d1480137a065}) (Version: 6.6 - Cisco Systems, Inc)
Cisco Webex Meetings (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\ActiveTouchMeetingClient) (Version: 40.8.5 - Cisco Webex LLC)
Classic Shell (HKLM\...\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft)
Dell Customer Connect (HKLM-x32\...\{99E581C6-471C-46CA-989E-3B17EB7E3F27}) (Version: 1.3.2.0 - Dell Inc.)
Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)
Dell Foundation Services (HKLM\...\{AE5E3C86-2633-4DAF-A7F4-C43D1E738BAE}) (Version: 3.1.3300.0 - Dell Inc.)
Dell Help & Support (HKLM\...\{9ACDDC24-55FE-4E7A-B4BD-DD9761F2F8AB}) (Version: 2.0.360.0 - Dell Inc.) Hidden
Dell Help & Support (HKLM-x32\...\InstallShield_{9ACDDC24-55FE-4E7A-B4BD-DD9761F2F8AB}) (Version: 2.0.360.0 - Dell Inc.)
Dell Update (HKLM-x32\...\{DB82968B-57A4-4397-81A5-ECAB21B5DFCD}) (Version: 1.7.1015.0 - Dell Inc.)
Documentation Manager (HKLM\...\{E904139A-DC55-420D-94C7-5D6297F3C385}) (Version: 23.30.0.6 - Intel Corporation) Hidden
Elevated Installer (HKLM-x32\...\{0F6C59A2-5F1D-4D7C-BC90-A0A1A75F4EE9}) (Version: 7.7.1.0 - Garmin Ltd or its subsidiaries) Hidden
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 8.1.4.1208 - Foxit Software Inc.)
Fresco Logic USB Display Driver (HKLM\...\{FC11E022-A625-48EA-85EB-AF2AFEF05B06}) (Version: 2.1.34054.0 - Fresco Logic)
Garmin Express (HKLM-x32\...\{50DF005C-1D2C-467A-A39E-10ADEFA83A96}) (Version: 7.7.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{9e0ef45d-b10c-42da-9aab-16200df39d95}) (Version: 7.7.1.0 - Garmin Ltd or its subsidiaries)
GDR 2002 for SQL Server 2017 (KB4293803) (64-bit) (HKLM\...\KB4293803) (Version: 14.0.2002.14 - Microsoft Corporation)
GDR 2014 for SQL Server 2017 (KB4494351) (64-bit) (HKLM\...\KB4494351) (Version: 14.0.2014.14 - Microsoft Corporation)
GDR 2027 for SQL Server 2017 (KB4505224) (64-bit) (HKLM\...\KB4505224) (Version: 14.0.2027.2 - Microsoft Corporation)
GDR 2037 for SQL Server 2017 (KB4583456) (64-bit) (HKLM\...\KB4583456) (Version: 14.0.2037.2 - Microsoft Corporation)
GDR 2042 for SQL Server 2017 (KB5014354) (64-bit) (HKLM\...\KB5014354) (Version: 14.0.2042.3 - Microsoft Corporation)
GDR 2047 for SQL Server 2017 (KB5021127) (64-bit) (HKLM\...\KB5021127) (Version: 14.0.2047.8 - Microsoft Corporation)
GDR 2052 for SQL Server 2017 (KB5029375) (64-bit) (HKLM\...\KB5029375) (Version: 14.0.2052.1 - Microsoft Corporation)
Get Good Drums One Kit Wonder - Architects (HKLM-x32\...\Get Good Drums One Kit Wonder - Architects) (Version: 1.0.0.4 - Get Good Drums)
GetGood Drums Smash and Grab 2 (HKLM\...\Smash and Grab 2_is1) (Version: 2.0.0 - GetGood Drums)
Google Chrome (HKLM-x32\...\{93EB1D27-3378-36DD-ACEC-380FEDB2297B}) (Version: 123.0.6312.58 - Google, Inc.)
Google Earth Plug-in (HKLM-x32\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google)
Google Earth Pro (HKLM\...\{3470AD08-85F2-4B1D-8487-FC4750732087}) (Version: 7.3.6.9796 - Google)
H&R Block Massachusetts 2021 (HKLM-x32\...\{482A887B-D7E3-473D-80E2-48FA6F695194}) (Version: 1.21.4201 - H&R Block, Inc.)
H&R Block Massachusetts 2022 (HKLM-x32\...\{4E5723A6-0AA2-4415-AF75-7E2CE63713F7}) (Version: 1.22.6201 - H&R Block, Inc.)
H&R Block Massachusetts 2023 (HKLM-x32\...\{F5FBEE1C-A0E1-4B44-86EE-0BABE29D668C}) (Version: 1.23.8701 - HRB Digital, LLC.)
H&R Block Premium + Efile + State 2021 (HKLM-x32\...\{EDB7F331-6C76-4B85-A8EC-764B213E2E51}) (Version: 21.07.6002 - HRB Technology, LLC.)
H&R Block Premium + Efile + State 2022 (HKLM-x32\...\{69654063-D165-4494-A83B-C09105247E97}) (Version: 22.07.7601 - HRB Technology, LLC.)
H&R Block Premium + Efile + State 2023 (HKLM-x32\...\{B0E2C9A7-F1FC-4376-9E0F-065DC3FAC392}) (Version: 23.07.8301 - HRB Technology, LLC.)
HandBrake 1.0.1 (HKLM-x32\...\HandBrake) (Version: 1.0.1 - )
Intel Driver && Support Assistant (HKLM-x32\...\{63B67EA4-4AE1-4A45-A67D-21318B4345EF}) (Version: 23.4.39.9 - Intel) Hidden
Intel Driver && Support Assistant (HKLM-x32\...\{7D392FB7-64D5-4813-B7F7-8AA462D3968D}) (Version: 23.4.39.9 - Intel) Hidden
Intel Extreme Tuning Utility (HKLM-x32\...\{7afa48c7-9901-40fa-8f9b-f0707e2bc5b6}) (Version: 6.2.0.24 - Intel Corporation)
Intel® Chipset Device Software (HKLM\...\{8C91A5EB-2C62-4A6D-8802-CC79FD2ED390}) (Version: 10.1.1.7 - Intel Corporation) Hidden
Intel® Chipset Device Software (HKLM-x32\...\{60c073df-e736-4210-9c3a-5fc2b651cef3}) (Version: 10.1.1.7 - Intel® Corporation) Hidden
Intel® Computing Improvement Program (HKLM\...\{15E71D2B-4046-4B9D-A8BB-EBFC5CC12D86}) (Version: 2.4.10717 - Intel Corporation)
Intel® Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.2.10900.330 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{5BD7E621-9791-4D9F-A620-1BA51153B749}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{EC465D35-92DC-4DAE-9EA8-01215688F709}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Driver (HKLM\...\{AC411813-5A0B-4960-882D-481BEEDC24E0}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® ME UninstallLegacy (HKLM\...\{E9B9A1A5-6398-4C99-8FDE-10794F6505C5}) (Version: 1.0.1.0 - Intel Corporation) Hidden
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.6859 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.16.1063 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{9503AD68-6198-4081-9F57-1F346D7B58D4}) (Version: 14.8.16.1063 - Intel Corporation) Hidden
Intel® Serial IO (HKLM\...\{51788BA4-D93F-4E7B-BA13-ACC88E7803DB}) (Version: 30.100.1519.07 - Intel Corporation) Hidden
Intel® Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation)
Intel® WiDi (HKLM\...\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation)
Intel® WiDi Software Asset Manager (HKLM-x32\...\{5B5CD20C-29F0-4857-A4FA-A4F4C716B019}) (Version: 1.1.347 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{00000030-0230-1033-84C8-B8D95FA3C8C3}) (Version: 23.30.0.3 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{b82e9573-04fb-4a9d-819f-6c358a1cf31a}) (Version: 23.4.39.9 - Intel)
Intel® Driver & Support Assistant (HKLM-x32\...\{ecbee3cf-26b3-4f27-854c-e2e16b3f7fa9}) (Version: 23.4.39.9 - Intel)
Intel® PROSet/Wireless Software (HKLM-x32\...\{5a64c890-83f9-4399-b0c9-5e9a80890fdd}) (Version: 21.40.1 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{68A981A0-ED59-41E0-B45E-7A78F643120D}) (Version: 21.40.1.3406 - Intel Corporation) Hidden
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Intel® Software Installer (HKLM-x32\...\{ae13aa25-496e-45dc-86f8-939f17f479f4}) (Version: 23.30.0.6 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (HKLM\...\{7D84E343-A23D-451C-B123-0195B2D903A6}) (Version: 1.42.17.0 - Intel Corporation) Hidden
IPCWebComponents 3.3.0.31 (HKLM-x32\...\{4740E1B2-51CF-4083-8976-D6B3B5A5064F}_is1) (Version: 3.3.0.31 - )
Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Kontakt 7 PORTABLE (HKLM\...\{770F4942-15B1-41AA-9E3E-C77B2CFB1366}_is1) (Version: 7.7.1 - Native Instruments)
LatencyMon 7.31 (HKLM\...\LatencyMon_is1) (Version: 7.31 - Resplendence Software Projects Sp.)
Ledger Live 2.77.2 (HKLM\...\c62032b2-0bca-5abc-b458-fd67cfc9e49b) (Version: 2.77.2 - Ledger Live Team)
Macrium Reflect Free (HKLM\...\{0D4965D1-6B46-4F0A-B42D-B17056612AE0}) (Version: 8.0.7279 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free (HKLM\...\MacriumReflect) (Version: v8.0.7279 - Paramount Software (UK) Ltd.)
Malwarebytes version 4.6.6.294 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.6.294 - Malwarebytes)
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.9060.3 - Waves Audio Ltd.) Hidden
Mazda Toolbox (HKLM-x32\...\Mazda Toolbox) (Version:  - )
Mazda Update Toolbox (HKLM-x32\...\Mazda Update Toolbox) (Version:  - )
MetaTrader 5 (HKLM\...\MetaTrader 5) (Version: 5.00 - MetaQuotes Ltd.)
Microsoft .NET Core Host - 3.1.32 (x64) (HKLM\...\{8A8E3A04-83BC-4CDE-9259-893B666C1AB1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Host FX Resolver - 3.1.32 (x64) (HKLM\...\{ABC6B3C2-1A8D-4C5E-AC16-C2AE44F02743}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM\...\{A741B803-3F0E-4684-81EF-FC128D15A92C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM-x32\...\{784973c8-d618-4ac8-97ed-1fd52c5bdf2f}) (Version: 3.1.32.31915 - Microsoft Corporation)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Analysis Services OLE DB Provider (HKLM\...\{0DAD8F2F-38F2-404F-BB26-3DC89F0B53C5}) (Version: 14.0.1000.397 - Microsoft Corporation) Hidden
Microsoft Analysis Services OLE DB Provider (HKLM-x32\...\{CBB32D14-5E5A-4E4A-8EDF-26586322C9E7}) (Version: 14.0.1000.397 - Microsoft Corporation) Hidden
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Build Tools 14.0 (amd64) (HKLM\...\{8C918E5B-E238-401F-9F6E-4FB84B024CA2}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Build Tools 14.0 (x86) (HKLM-x32\...\{D1437F51-786A-4F57-A99C-F8E94FBA1BD8}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Build Tools Language Resources 14.0 (amd64) (HKLM\...\{4B7958F6-4943-4903-B379-9180DC8C2105}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Build Tools Language Resources 14.0 (x86) (HKLM-x32\...\{A7E88B38-6886-4474-9D85-A8ABE5FCD80E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 122.0.2365.92 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 122.0.2365.92 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\{5730588A-33CA-373C-9D70-F716605B57D2}) (Version: 2.2.23107 - Microsoft Corporation) Hidden
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft MPI (7.0.12437.8) (HKLM\...\{8499ACD3-C1E3-45AB-BF96-DA491727EBE1}) (Version: 7.0.12437.8 - Microsoft Corporation)
Microsoft ODBC Driver 13 for SQL Server (HKLM\...\{436C9D0B-5AD2-4E54-83F0-10B7584A971E}) (Version: 14.0.2052.1 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{4D2C56FF-7F36-4B49-A97A-24F0522D41D7}) (Version: 11.3.6540.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2017 (64-bit) (HKLM\...\Microsoft SQL Server SQL2017) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2017 (HKLM-x32\...\Microsoft SQL Server SQL2017) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2017 Policies  (HKLM-x32\...\{256EDCB9-A64D-433C-A1DC-C76F02475915}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft SQL Server 2017 RsFx Driver (HKLM\...\{D5826833-5FD8-4586-BC42-22E38B15DFA4}) (Version: 14.0.2052.1 - Microsoft Corporation) Hidden
Microsoft SQL Server 2017 Setup (English) (HKLM\...\{2E1F5473-30FC-4D5B-B7F0-8EA51CC3EE81}) (Version: 14.0.2052.1 - Microsoft Corporation)
Microsoft SQL Server 2017 T-SQL Language Service  (HKLM\...\{BC247FE3-C61A-4678-86C6-15408F272D57}) (Version: 14.0.17213.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation) Hidden
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation) Hidden
Microsoft SQL Server Data-Tier Application Framework (x86) (HKLM-x32\...\{F45421F6-76C3-47EE-8823-7D064A77E1F0}) (Version: 14.0.3881.1 - Microsoft Corporation)
Microsoft SQL Server Management Studio - 17.4 (HKLM-x32\...\{ac84c935-8f13-4f73-b541-7b09a11bdea8}) (Version: 14.0.17213.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{718FFB65-F6E4-4D62-861F-ED10ED32C936}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2017 (HKLM\...\{9D78F5D4-79D2-4FC6-AC56-F364A0ABC54F}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Debug Runtime - 12.0.21005 (HKLM\...\{C596D608-3E74-3232-8CA5-DF1DCB9F10DE}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Debug Runtime - 12.0.21005 (HKLM-x32\...\{E5CAE8D2-9F9F-3BEA-AA0F-B5B40611C704}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x64 Debug Runtime - 14.0.23026 (HKLM\...\{B8E14C55-53F6-3693-A74A-77A3C6B96041}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Debug Runtime - 14.0.23026 (HKLM-x32\...\{3CB4E2E8-04EB-371A-9433-4CA0D934B260}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.34.31931 (HKLM-x32\...\{d4cecf3b-b68f-4995-8840-52ea0fab646e}) (Version: 14.34.31931.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.34.31931 (HKLM-x32\...\{6ba9fb5e-8366-4cc4-bf65-25fe9819b2fc}) (Version: 14.34.31931.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.34.31931 (HKLM\...\{EAE242B1-0A26-485A-BFEB-0292EE9F03CB}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.34.31931 (HKLM\...\{CF4C347D-954E-4543-88D2-EC17F07F466F}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.34.31931 (HKLM-x32\...\{C2662EFF-06E6-4FD1-9D6D-FDCA91025757}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.34.31931 (HKLM-x32\...\{AB1BDF73-7393-42CE-812D-9A90918814D5}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}) (Version: 10.0.50908 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2015 Shell (Isolated) (HKLM-x32\...\{6CFDA13E-A348-315B-820A-603BBCBD7684}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Isolated) (HKLM-x32\...\{d2981c27-a434-4c9a-96c7-0209e97c4eac}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Visual Studio 2015 Shell (Isolated) Resources (HKLM-x32\...\{446D0B70-F98E-39DA-9CB5-4201D05A91C6}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Minimum) (HKLM-x32\...\{030A6785-C3A9-37DA-8530-444C320629FA}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Minimum) Interop Assemblies (HKLM-x32\...\{4443D3F4-A231-35CC-8471-CB60F8A3FE3B}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Minimum) Resources (HKLM-x32\...\{7FF53256-7BAF-3EFA-91B4-DB65F37EB5E9}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio Services Hub (HKLM-x32\...\{93CC1063-02A1-4F25-A13A-C351A10D84DD}) (Version: 1.0.23107.00 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 (HKLM-x32\...\{ab213ab7-4792-4c6f-a3fa-8485d06c3475}) (Version: 14.0.23829 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 Finalizer (HKLM-x32\...\{F93E37BD-4053-37CA-A7BB-A5B74508006C}) (Version: 14.0.23829 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 Language Support - ENU Language Pack (HKLM-x32\...\{0343F10B-C31B-3A2F-B2C1-C42E84CCAF5E}) (Version: 14.0.23107.20 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 Language Support (HKLM-x32\...\{85CEB20F-C2D6-3FDC-9A9D-5957CD88E9E5}) (Version: 14.0.23107.20 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 Language Support (HKLM-x32\...\{bd4ef7af-dfb1-472e-8fa4-1b97f360a3e7}) (Version: 14.0.23107.20 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 Language Support Finalizer (HKLM-x32\...\{BF6E6B74-88F5-358F-AB6D-0A42C18F2824}) (Version: 14.0.23107.20 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 x64 Hosting Support (HKLM\...\{A8C30947-7C1B-3A31-8FD8-CEC6D3357D34}) (Version: 14.0.23829 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 x86 Hosting Support (HKLM-x32\...\{11A9EF3E-6616-31B1-82BC-1080366FA34D}) (Version: 14.0.23829 - Microsoft Corporation) Hidden
Microsoft VSS Writer for SQL Server 2017 (HKLM\...\{20B328C9-C6BB-434A-928A-00F05CD820B8}) (Version: 14.0.1000.169 - Microsoft Corporation)
MotionPro (HKLM\...\MotionPro VPN Client) (Version: 9.4.0.0 - Array Networks)
Mozilla Firefox (x64 en-US) (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Mozilla Firefox 123.0.1 (x64 en-US)) (Version: 123.0.1 - Mozilla)
MyHarmony (HKLM-x32\...\{2AD8F8A1-ECE5-4890-BCC2-B4396370A0D4}) (Version: 1.0.308 - Logitech)
NVIDIA Graphics Driver 546.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 546.17 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
OSCAR (HKLM\...\{FC6F08E6-69BF-4469-ADE3-78199288D305}_is1) (Version: 1.5.1-Win64-dd495e23 - The OSCAR Team)
Paragon Hard Disk Manager™ 15 Suite (HKLM\...\{29258311-EA49-11DE-967C-005056C00008}) (Version: 90.00.0003 - Paragon Software)
PdaNet+ for Android 4.18 (HKLM-x32\...\PdaNet_is1) (Version:  - June Fabrics Technology Inc)
PDF Settings (HKLM-x32\...\{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Player Location Check (HKLM-x32\...\{F0753064-8D66-41A7-9F23-7691290387BF}) (Version: 4.0.0.7 - GeoComply)
PreSonus Studio One 6 (HKLM\...\Studio One 6_is1) (Version: 6.5.0 - PreSonus)
Private Internet Access (HKLM\...\{33023371-7761-4F81-BBB1-0E0D0D175ACF}) (Version: 3.5.5+08091 - Private Internet Access, Inc.)
Private Internet Access WinTUN Driver (HKLM\...\{0419A0C0-4CC8-459E-9BAE-F3BF5D2E2CCB}) (Version: 1.0 - Private Internet Access, Inc.) Hidden
Product Registration (HKLM\...\{C1600AC7-74E3-4BB5-8B42-B13653792252}) (Version: 2.2.38.0 - Dell Inc.) Hidden
Product Registration (HKLM-x32\...\InstallShield_{C1600AC7-74E3-4BB5-8B42-B13653792252}) (Version: 2.2.38.0 - Dell Inc.)
Python 3.12.1 (64-bit) (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\{86e52725-ef45-452f-ac4c-b8958718bfea}) (Version: 3.12.1150.0 - Python Software Foundation)
Python 3.12.1 Core Interpreter (64-bit) (HKLM\...\{AC82C1A3-9597-40F2-893D-F02F778FBA4D}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Development Libraries (64-bit) (HKLM\...\{8C53CBDD-4DAF-426F-9478-6C7C2920CDDA}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Documentation (64-bit) (HKLM\...\{62667662-A580-409C-8044-55B06F774AE2}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Executables (64-bit) (HKLM\...\{44BC9F9C-15C2-46C1-B88D-3135A9DA555F}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 pip Bootstrap (64-bit) (HKLM\...\{1662F43B-2337-4FD8-8CE6-BEA38FC94DD4}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Standard Library (64-bit) (HKLM\...\{47957EE3-0E23-4075-B825-F202E913670F}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Tcl/Tk Support (64-bit) (HKLM\...\{926CDC62-3AE2-422B-9858-D6EC3BAD473F}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Test Suite (64-bit) (HKLM\...\{E309AE00-4FB1-4817-9172-7E198668375D}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{4C8D4EC3-F620-4CEE-8BAD-B59A3C6815F3}) (Version: 3.12.1150.0 - Python Software Foundation)
qBittorrent 4.3.9 (HKLM-x32\...\qBittorrent) (Version: 4.3.9 - The qBittorrent project)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.5.02 - Dell Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.21289 - Realtek Semiconduct Corp.)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 10.1.505.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8578 - Realtek Semiconductor Corp.)
Roblox Player for Phil (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\roblox-player) (Version:  - Roblox Corporation)
Roslyn Language Services - x86 (HKLM-x32\...\{5B47029B-1E62-30FF-906E-694851C22782}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Roslyn Language Services - x86 (HKLM-x32\...\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
SketchUp 2016 (HKLM\...\{E2B66CF6-ABA0-4E5F-B426-7478B18301AE}) (Version: 16.1.1449 - Trimble Navigation Limited)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
SQL Server 2017 Batch Parser (HKLM\...\{2C6E8311-28BD-4615-9545-6E39E8E83A4B}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Client Tools Extensions (HKLM\...\{06324A5D-66BB-4FAC-8D0B-9FEC1B230FFF}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Client Tools Extensions (HKLM\...\{200F38B2-1492-4576-B08C-78F2C2C953FC}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM\...\{9D1C0509-D490-4E9E-ACF5-A73E5C53742D}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM\...\{B777C4C0-A1CD-4AB9-99B1-AD5FBED6F8E5}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM-x32\...\{6CE9A8AA-C478-4706-BD28-95993D52B5A1}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM-x32\...\{D17B5D3D-3BC7-4AFA-AD90-600B5453826E}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Connection Info (HKLM\...\{89A7644F-E056-4EC1-BFDE-9D1A531D6855}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Connection Info (HKLM\...\{A9A443F5-56E1-4FC6-937C-5F481345A843}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Services (HKLM\...\{28EEF6BA-A23A-42D2-86BA-A6BEE723B969}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Services (HKLM\...\{DED314CA-0EFE-4593-9D66-EF75E5289A4C}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Shared (HKLM\...\{0E22DBB4-691B-400C-B52D-8DFE8EC421AA}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Shared (HKLM\...\{793F1C1E-5C83-4E33-A29B-6EAA7C1E791C}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 DMF (HKLM\...\{B9998A13-5563-496C-B95E-597FFC70B670}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 DMF (HKLM\...\{D7D28BBF-3B0E-43F0-A457-331F1CD9E9EB}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Integration Services Scale Out Management Portal (HKLM\...\{6BD8D100-B16C-409E-B0EA-BF508D7874EC}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Integration Services Scale Out Management Portal (HKLM\...\{91C5EE43-29D1-4720-AB65-5E2E0FE25990}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Management Studio Extensions (HKLM-x32\...\{6492E746-1C5D-48C2-A92A-97D431F74664}) (Version: 14.0.3006.16 - Microsoft Corporation) Hidden
SQL Server 2017 Management Studio Extensions (HKLM-x32\...\{70C24F35-7E36-45FC-B289-3D2849E5556B}) (Version: 14.0.3006.16 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects (HKLM\...\{10855B1A-F7F2-4D8A-A725-9287C73BED5A}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects (HKLM\...\{6CBBF624-696C-499E-948D-ADBAFFA2F548}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects Extensions (HKLM\...\{8C515C22-BE07-4908-985C-0AA9349E1ED4}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects Extensions (HKLM\...\{C6D92730-3EC0-47B1-8F6C-6F5635D1EFAC}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 SQL Diagnostics (HKLM\...\{DFA6A906-3024-49DE-87AD-750EAED2FA49}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 XEvent (HKLM\...\{12D2DB8D-80FF-4152-8F51-EDB3BD3C6976}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 XEvent (HKLM\...\{AA2A015C-C210-413B-95F6-BF9D3CDD6E0D}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server Management Studio (HKLM\...\{1B8CFC46-1F08-4DA7-9FEA-E1F523FBD67F}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SQL Server Management Studio (HKLM\...\{F8ADD24D-F2F2-465C-A675-F12FDB70DB82}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SQL Server Management Studio for Analysis Services (HKLM\...\{CC6997A7-1638-4E38-B6CF-E776997036B0}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SQL Server Management Studio for Reporting Services (HKLM\...\{4DDEB555-26D2-4E68-98AF-8F96232C13F2}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SSD Sampler (HKLM-x32\...\SSD4) (Version: 1.1 - Yellow Matter Entertainment)
SSMS Post Install Tasks (HKLM\...\{CFCC9F40-E234-499E-B3DA-BEF6CC724C35}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 10.0.1256 - SUPERAntiSpyware.com)
TeamViewer (HKLM\...\TeamViewer) (Version: 15.51.5 - TeamViewer)
Techstream Software (HKLM-x32\...\{937CA58A-0212-431C-8F0B-0D8305225476}) (Version: 10.30.029 - DENSO CORPORATION)
Tools for .Net 3.5 (HKLM-x32\...\{1690CE56-2231-4E59-9006-A0876D949EA8}) (Version: 3.11.50727 - Microsoft Corporation) Hidden
Toontrack EZmix 2.2.4 (HKLM\...\EZmix_is1) (Version: 2.2.4 - Toontrack & Team V.R)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{7B63012A-4AC6-40C6-B6AF-B24A84359DD5}) (Version: 8.93.0.0 - Microsoft Corporation)
UXP WebView Support (HKLM-x32\...\UXPW_1_1_0) (Version: 1.1.0 - Adobe Inc.)
VeraCrypt (HKLM-x32\...\VeraCrypt) (Version: 1.24-Update7 - IDRIX)
Visual C++ 2008 Runtime (x64) (HKLM-x32\...\{73E80655-FB3C-46F4-BE00-62D248BC490A}) (Version: 1.0.1 - Highresolution Enterprises) Hidden
Visual Studio 2015 Prerequisites - ENU Language Pack (HKLM\...\{83B181F2-20B8-4F00-8E71-C66E951A8D4F}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Visual Studio 2015 Prerequisites (HKLM\...\{DF32E41C-24AD-4A87-B43A-B38553B1806E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.14 - VideoLAN)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Waves Central (HKLM\...\{ab507e17-892b-5203-838d-d58d8d09c50f}) (Version: 14.4.3 - Waves Audio Ltd)
Windows Driver Package - Amazon.com (WinUSB) FireDevicesUsbDeviceClass  (10/27/2014 1.4.0000.00000) (HKLM\...\70D74CAD18BB165614511A2A67DB9EBF036D06A9) (Version: 10/27/2014 1.4.0000.00000 - Amazon.com)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Fresco Logic (fl2000) AVClass  (11/13/2017 2.1.34054.0) (HKLM\...\02B94313A3DAF5BA27BCC4FAEA0716A0F660086C) (Version: 11/13/2017 2.1.34054.0 - Fresco Logic)
Windows Driver Package - Fresco Logic (lci_proxykmd) System  (11/13/2017 2.1.34054.0) (HKLM\...\7C22E1F94C4AE5334C0BEE70551B20BEE3C293FA) (Version: 11/13/2017 2.1.34054.0 - Fresco Logic)
Windows Driver Package - Fresco Logic (WUDFRd) Display  (11/13/2017 2.1.34054.0) (HKLM\...\9328342CF3E5994E24BB0C09FBD875141BEF3984) (Version: 11/13/2017 2.1.34054.0 - Fresco Logic)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
XLN Online Installer (HKLM\...\XLN Online Installer Inno Setup ID_is1) (Version:  - )
X-Mouse Button Control 2.10.2 (HKLM-x32\...\X-Mouse Button Control) (Version: 2.10.2 - Highresolution Enterprises)
Yamaha Steinberg USB Driver (HKLM\...\{E2AEA639-BFC7-4A6E-A9F3-EB11B60C2F33}) (Version: 2.1.5 - Yamaha Corporation) Hidden
Yamaha Steinberg USB Driver (HKLM-x32\...\yUninstall_{2938B185-2D57-47B0-9FC8-C90A67BA9277}) (Version: 2.1.5 - Yamaha Corporation)
YubiKey Manager (HKLM-x32\...\yubikey-manager) (Version: 1.1.5 - Yubico AB)
Zoom (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\ZoomUMX) (Version: 5.15.7 (20303) - Zoom Video Communications, Inc.)

Packages:
=========

Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.263.400.0_x64__kgqvnymyfvs32 [2024-03-13] (king.com)
Dell Shop -> C:\Program Files\WindowsApps\DellInc.DellShop_2.2.1.0_neutral__htrsf667h5kn2 [2021-04-17] (Dell Inc)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_152.1.1099.0_x64__v10z8vjag6ke6 [2024-03-10] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Movie Maker - Video Editor -> C:\Program Files\WindowsApps\21336V3TApps.MovieMaker-FREE_3.6.46.0_x64__bzg06mxvgh4fa [2024-03-10] (V3TApps)
MyIPTV Player -> C:\Program Files\WindowsApps\41879VbfnetApps.MyIPTVPlayer_4.8.2.0_x64__7casf8sqhfy78 [2023-11-02] (Vbfnet Apps) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.964.0_x64__56jybvy8sckqj [2023-11-18] (NVIDIA Corp.)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-05-08] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-12-19] (Microsoft Corporation)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.19.1262.0_x64__8wekyb3d8bbwe [2024-02-08] (Microsoft Studios) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2021-06-10] (Twitter Inc.)
WinDbg -> C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe [2024-03-08] (Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{1019ADC7-17CB-4489-AFD5-6642C7400ACE}\localserver32 -> C:\Users\Phil\AppData\Local\Webex\Webex\Applications\ptOIEx64.exe (Cisco WebEx LLC -> Cisco WebEx LLC)
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\localserver32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\FileCoAuth.exe => No File
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{BEA218D2-6950-497B-9434-61683EC065FE}\InprocServer32 -> C:\Users\Phil\AppData\Local\Programs\Python\Launcher\pyshellext.amd64.dll (Python Software Foundation -> Python Software Foundation)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ContextMenuHandlers1: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\ConvertToPDFShellExtension_x64.dll [2016-11-14] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-04-12] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxDTCM.dll [2019-06-13] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvdmig.inf_amd64_75c152d756d851ed\nvshext.dll [2023-11-10] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ContextMenuHandlers6: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\ConvertToPDFShellExtension_x64.dll [2016-11-14] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-04-12] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\System32\StartMenuHelper64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Amcrest Web View.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory="Profile 1" --app-id=oddndbjhpcpopbebhonolceinkbnheih
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory="Profile 1" --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Videostream for Google Chromecast™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory="Profile 1" --app-id=cnciopoikihiagdjbjpnocolokfelagl
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\e895024b613704\MetaMask.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=nkbihfbeogaeaoehlefnkodbefgpgknn
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\72dad8f9fb5925df\Data Scraper - Easy Web Scraping.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=nndknepjnldbdbepjfgmncbggmopgden
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"

==================== Loaded Modules (Whitelisted) =============

0000-00-00 00:00 - 0000-00-00 00:00 - 000000000 _____ () [Access Denied] C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll
2024-02-16 10:48 - 2023-07-10 02:34 - 000039936 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\aiohttp\_helpers.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000215552 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\aiohttp\_http_parser.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000035840 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\aiohttp\_http_writer.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000024064 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\aiohttp\_websocket.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000053760 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\frozenlist\_frozenlist.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000046592 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\multidict\_multidict.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000066048 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\psutil\_psutil_windows.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000039936 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\tinyaes.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000012288 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\websockets\speedups.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000132096 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\win32api.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000249856 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\yaml\_yaml.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000068608 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\yarl\_quoting_c.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000183296 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\_cffi_backend.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 193385472 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\_pywrap_tensorflow_internal.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000018944 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\cpufeature\extension.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000100864 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\google\protobuf\internal\_api_implementation.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001601536 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\google\protobuf\pyext\_message.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000175616 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\_conv.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000045568 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\_errors.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000110080 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\_objects.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000044032 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\_proxy.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000132608 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\_selector.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000219648 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\defs.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000089600 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000117760 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5a.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000058368 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5ac.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000122368 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5d.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000072192 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5ds.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000116736 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5f.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000156672 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5fd.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000136192 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5g.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000051712 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5i.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000096256 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5l.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000106496 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5o.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000311296 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5p.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000036352 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5pl.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000061952 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5r.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000093696 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5s.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000320512 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5t.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000044032 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\h5z.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000052736 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\h5py\utils.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000011264 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\_devicearray.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000045056 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\_dispatcher.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000016384 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\_dynfunc.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000238592 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\_helperlib.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000027136 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\core\runtime\_nrt_python.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000019968 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\core\typeconv\_typeconv.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000024576 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numba\np\ufunc\_internal.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000114176 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\core\_multiarray_tests.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 002906112 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\core\_multiarray_umath.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000116736 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\fft\_pocketfft_internal.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000154624 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\linalg\_umath_linalg.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000022016 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\linalg\lapack_lite.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000254464 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_bounded_integers.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000182272 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_common.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000685056 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_generator.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000080896 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_mt19937.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000085504 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_pcg64.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000072192 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_philox.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000053760 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\_sfc64.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000158208 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\bit_generator.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000588800 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\numpy\random\mtrand.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001278976 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\algos.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000078336 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\arrays.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000916480 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\groupby.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000154624 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\hashing.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001230848 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\hashtable.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000454656 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\index.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000046080 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\indexing.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000256000 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\internals.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001038336 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\interval.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001893376 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\join.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000067072 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\json.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000465408 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\lib.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000162816 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\missing.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000186880 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\ops.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000051200 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\ops_dispatch.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000373760 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\parsers.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000059904 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\properties.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000247808 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\reduction.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000227328 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\reshape.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000801280 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\sparse.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000069632 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\testing.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000133632 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslib.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000041984 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\base.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000052224 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\ccalendar.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000224768 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\conversion.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000101888 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\dtypes.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000241664 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\fields.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000181760 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\nattype.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000043520 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\np_datetime.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000776704 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\offsets.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000318464 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\parsing.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000346624 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\period.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000292864 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\strptime.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000371712 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\timedeltas.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000401920 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\timestamps.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000192512 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\timezones.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000216064 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\tzconversion.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000190464 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\tslibs\vectorized.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000288256 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\window\aggregations.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000145408 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\window\indexers.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000180736 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\pandas\_libs\writers.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000076288 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\psutil\_psutil_windows.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000061440 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\_lib\_ccallback_c.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000049664 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\_lib\_uarray\_uarray.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000042496 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\_lib\messagestream.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000582144 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\fft\_pocketfft\pypocketfft.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000169984 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\fftpack\convolve.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000046080 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\integrate\_dop.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000022528 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\integrate\_odepack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000032768 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\integrate\_quadpack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000039936 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\integrate\lsoda.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000050176 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\integrate\vode.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000225280 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\_bspl.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000035328 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\_fitpack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000286720 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\_ppoly.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000385536 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\_rbfinterp_pythran.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000148480 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\dfitpack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000281600 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\interpolate\interpnd.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000238592 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_decomp_update.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000587264 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_fblas.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001931264 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_flapack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000052224 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_flinalg.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000229376 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_interpolative.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000171008 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_matfuncs_sqrtm_triu.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000193536 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\_solve_toeplitz.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000226816 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\cython_blas.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000626688 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\linalg\cython_lapack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000124928 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\ndimage\_nd_image.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000267264 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\ndimage\_ni_label.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000030720 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\__nnls.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000231936 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_bglu_dense.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000034816 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_cobyla.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000062464 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_group_columns.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000027136 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_highs\_highs_constants.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001470464 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_highs\_highs_wrapper.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000038400 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_lbfgsb.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000025600 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_lsap_module.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000142336 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_lsq\givens_elimination.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000029184 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_minpack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000038912 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_slsqp.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000251904 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_trlib\_trlib.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000016384 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\_zeros.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000034304 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\minpack2.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000051200 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\optimize\moduleTNC.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000038400 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\_max_len_seq_inner.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000188928 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\_peak_finding_utils.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000212992 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\_sosfilt.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000048128 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\_spectral.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000244224 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\_upfirdn_apply.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000096768 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\sigtools.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000038912 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\signal\spline.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000471552 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\_csparsetools.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 002177024 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\_sparsetools.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000201728 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_flow.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000224768 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_matching.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000158208 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_min_spanning_tree.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000209408 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_reordering.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000321536 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_shortest_path.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000124928 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_tools.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000118784 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\csgraph\_traversal.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000282624 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\linalg\dsolve\_superlu.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000143872 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\linalg\eigen\arpack\_arpack.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000117248 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\sparse\linalg\isolve\_iterative.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000244736 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\_distance_pybind.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000123904 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\_distance_wrap.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000150528 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\_hausdorff.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000148992 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\_voronoi.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000518656 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\ckdtree.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000833024 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\qhull.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000481280 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\spatial\transform\rotation.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000031744 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\_comb.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000065024 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\_ellip_harm_2.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000789504 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\_ufuncs.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000107008 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\_ufuncs_cxx.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 001348608 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\cython_special.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000077824 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\special\specfun.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000266240 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_boost\beta_ufunc.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000232448 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_boost\binom_ufunc.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000236032 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_boost\nbinom_ufunc.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000175104 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_qmc_cy.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000177664 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_sobol.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000416768 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\_stats.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000167424 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\biasedurn.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000036864 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\mvn.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000032256 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\scipy\stats\statlib.cp39-win_amd64.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003867648 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\compiler\tf2tensorrt\_pywrap_py_utils.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000342016 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\lite\experimental\microfrontend\python\ops\_audio_microfrontend_op.so
2024-02-16 10:48 - 2023-07-10 02:34 - 000235008 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\lite\python\analyzer_wrapper\_pywrap_analyzer_wrapper.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003292160 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\lite\python\interpreter_wrapper\_pywrap_tensorflow_interpreter_wrapper.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000990208 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\lite\python\metrics\_pywrap_tensorflow_lite_metrics_wrapper.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 002726400 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_dtensor_device.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003403776 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_mlir.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003933184 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_parallel_device.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 002702848 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_py_exception_registry.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003389440 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_quantize_training.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000109568 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_sanitizers.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 006100480 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_tfe.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 000124416 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\_pywrap_toco_api.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003408896 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\client\_pywrap_debug_events_writer.pyd
2024-02-16 10:48 - 2023-07-10 02:34 - 003390976 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\client\_pywrap_device_lib.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003414528 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\client\_pywrap_events_writer.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 006047744 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\client\_pywrap_tf_session.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003436544 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\data\experimental\service\_pywrap_server_lib.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 005432320 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\data\experimental\service\_pywrap_utils.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 002874368 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\flags_pybind.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 002728960 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_dtypes.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003445248 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_op_def_library_pybind.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003389440 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_op_def_registry.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003933184 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_proto_comparators.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000213504 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_pywrap_python_api_dispatcher.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 002696704 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_pywrap_python_op_gen.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003867136 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\framework\_test_metrics_util.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003973120 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\grappler\_pywrap_tf_cluster.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003897856 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\grappler\_pywrap_tf_optimizer.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000108544 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\lib\core\_pywrap_bfloat16.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000108544 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\lib\core\_pywrap_py_func.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003473920 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\lib\io\_pywrap_file_io.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003534336 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\lib\io\_pywrap_record_io.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000108544 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\platform\_pywrap_stacktrace_handler.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003389952 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\platform\_pywrap_tf2.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 007490048 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\profiler\internal\_pywrap_profiler.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003409408 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\profiler\internal\_pywrap_traceme.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003419648 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\saved_model\pywrap_saved_model.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003894784 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_checkpoint_reader.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000109568 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_determinism.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000109568 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_nest.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000109568 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_tensor_float_32_execution.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 003874304 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_tfprof.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000108544 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_util_port.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000163328 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_pywrap_utils.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 002455040 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\_tf_stack.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000119296 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tensorflow\python\util\fast_module_type.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000040448 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\tinyaes.cp39-win_amd64.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000011776 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\websockets\speedups.cp39-win_amd64.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000134656 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\win32api.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000527872 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\win32com\shell\shell.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000042496 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\wrapt\_wrappers.cp39-win_amd64.pyd
2024-02-16 10:49 - 2023-07-10 02:34 - 000249856 _____ () [File not signed] C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\yaml\_yaml.cp39-win_amd64.pyd
0000-00-00 00:00 - 0000-00-00 00:00 - 000000000 _____ () <==== ATTENTION [zero byte File/Folder] \\?\C:\Users\Phil\AppData\Roaming\Java\jre8\bin\java.exe:jll
2024-01-30 23:32 - 2023-03-12 01:00 - 088202240 _____ (Celemony Software GmbH) [File not signed] C:\Program Files\Common Files\Celemony\Bundles\MelodyneCore-5.3.1.018.dll
2024-01-30 23:32 - 2023-03-12 01:00 - 001353216 _____ (Celemony Software GmbH) [File not signed] C:\Program Files\Common Files\VST3\Celemony\Melodyne\Melodyne.vst3
2016-03-04 12:42 - 2019-02-21 12:00 - 000078336 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2017-08-13 09:49 - 2017-08-13 09:49 - 003664184 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenuDLL.dll
2017-08-13 09:49 - 2017-08-13 09:49 - 000291128 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\WINDOWS\System32\StartMenuHelper64.dll
2023-10-12 08:06 - 2023-09-29 00:00 - 003544064 _____ (PreSonus) [File not signed] C:\Program Files\PreSonus\Studio One 6\Extensions\presonusstore\plugins\win_x64\presonusstore.dll
2023-10-12 08:06 - 2023-09-29 00:00 - 002217472 _____ (PreSonus) [File not signed] C:\Program Files\PreSonus\Studio One 6\Extensions\soundcloud\plugins\win_x64\soundcloud.dll
2023-10-12 08:06 - 2023-09-29 00:00 - 000695296 _____ (PreSonus) [File not signed] C:\Program Files\PreSonus\Studio One 6\Extensions\soundsetbuilder\plugins\win_x64\soundsetbuilder.dll
2023-10-12 08:06 - 2023-09-29 00:00 - 000856576 _____ (Propellerhead Software AB) [File not signed] C:\Program Files\PreSonus\Studio One 6\3rd party\REX Shared Library.dll
2024-01-05 18:19 - 2024-01-05 18:19 - 002973696 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll
2024-02-02 21:42 - 2023-02-07 17:40 - 042261040 _____ (Toontrack Music AB -> Toontrack Music AB) [File not signed] C:\Program Files\Common Files\VST3\Toontrack\EZdrummer 3.vst3
2024-01-28 18:31 - 2023-01-11 12:26 - 022139424 _____ (Toontrack Music AB -> Toontrack Music AB) [File not signed] C:\Program Files\Steinberg\Vstplugins\Toontrack\EZmix.dll
2024-02-16 10:51 - 2021-08-10 21:44 - 001792000 _____ (Waves Audio Ltd.) [File not signed] C:\ProgramData\Waves Audio\Modules\WavesLicenseEngine.bundle\Contents\Win64\WavesLicenseEngine.dll
2015-08-01 22:19 - 2015-08-01 22:19 - 000541448 ____R (Waves Inc -> Waves Audio) [File not signed] C:\WINDOWS\SYSTEM32\MaxxAudioIntelSkylake64.dll
2023-01-31 14:22 - 2023-01-31 14:22 - 000180224 _____ (Yamaha Corporation) [File not signed] C:\Program Files (x86)\Yamaha\Yamaha Steinberg USB Driver\ysusb_asio64.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell15.msn.com/?pc=DCTE
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://192.168.1.90:1829/
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://192.168.1.85:85/
SearchScopes: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001 -> {A79BE33D-4EB3-40E2-B354-BB99B3501D8A} URL =
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2023-11-18 23:11 - 2023-11-18 23:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

2019-10-23 10:26 - 2020-03-13 23:45 - 000000440 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Microsoft MPI\Bin\;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT;C:\Program Files\Intel\Intel® Management Engine Components\IPT;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Microsoft SQL Server\Client SDK\ODBC\130\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\140\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\140\DTS\Binn\;C:\Program Files (x86)\Microsoft SQL Server\140\Tools\Binn\ManagementStudio\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\130\Tools\Binn\;C:\Program Files\Microsoft SQL Server\140\Tools\Binn\;C:\Program Files\Microsoft SQL Server\140\DTS\Binn\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files\dotnet\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%AppData%\Programs\Python\Python311;%AppData%\Programs\Python\Python311\Scripts;
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Phil\Pictures\20201114_122903.jpg
HKU\S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\Services: !SASCORE => 2
MSCONFIG\Services: 0008811457109852mcinstcleanup => 2
MSCONFIG\Services: dbupdate => 2
MSCONFIG\Services: dbupdatem => 3
MSCONFIG\Services: Dell Customer Connect => 2
MSCONFIG\Services: Dell Foundation Services => 2
MSCONFIG\Services: Dell Hardware Support => 2
MSCONFIG\Services: Dell Help & Support => 2
MSCONFIG\Services: Dell Product Registration => 2
MSCONFIG\Services: DellDigitalDelivery => 2
MSCONFIG\Services: DellUpdate => 2
MSCONFIG\Services: MacriumService => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: SupportAssistAgent => 2
MSCONFIG\Services: WavesSysSvc => 2
MSCONFIG\Services: XTU3SERVICE => 2
HKLM\...\StartupApproved\StartupFolder: => "WavesLocalServer.lnk"
HKLM\...\StartupApproved\StartupFolder: => "WavesPluginServer.lnk"
HKLM\...\StartupApproved\Run: => "WavesSvc"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "LaunchMhttpd"
HKLM\...\StartupApproved\Run: => "Reflect UI"
HKLM\...\StartupApproved\Run32: => "LaunchMhttpd"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Cisco AnyConnect Secure Mobility Agent for Windows"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "Adobe CCXProcess"
HKLM\...\StartupApproved\Run32: => "Cisconet"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\StartupFolder: => "Gqreader.lnk"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "VideoGuardMonitor"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "GarminExpress"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Skype for Desktop"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Lync"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Trio.WakeNet"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_0848959D30B7A075789B21F3CF73AE30"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{8722BC63-D006-4454-A7FA-B546C2194CEA}C:\program files (x86)\batch configuration\batch configuration.exe] => (Allow) C:\program files (x86)\batch configuration\batch configuration.exe (HIKVISION DIGITAL TECHNOLOGY CO.,LTD. -> )
FirewallRules: [TCP Query User{2DB79FC2-EEA8-419E-90BE-400EC47D0F71}C:\program files (x86)\batch configuration\batch configuration.exe] => (Allow) C:\program files (x86)\batch configuration\batch configuration.exe (HIKVISION DIGITAL TECHNOLOGY CO.,LTD. -> )
FirewallRules: [UDP Query User{0A6C2044-7019-4EDE-BEAD-2A3D33AD18A3}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{E8D1E310-7E92-4616-96DE-DCA4A63256A4}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{57E1D170-9843-4965-8C4A-2AD53CC33047}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{6C435228-635C-443E-A6F1-2E57ED33DF7C}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{23C79370-8FC2-4078-8755-4CCC15243350}] => (Allow) C:\Users\Phil\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [UDP Query User{309DBB71-8038-46F9-B979-087D23E6F2C6}C:\windows\explorer.exe] => (Allow) C:\windows\explorer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{F1F8667A-4F3B-4D8B-94E1-91642F57D977}C:\windows\explorer.exe] => (Allow) C:\windows\explorer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{7D83116A-F056-470B-9225-C83298E82CDA}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{6AB0400C-53A7-438B-9113-E38C0C3573B8}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{AF34D3A7-5EDD-4DC6-A959-F791BAE4E444}] => (Allow) LPort=1689
FirewallRules: [{A5585E6B-687C-4830-9182-ACCD5AD46580}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{E4F687D8-9AC8-4B3F-81C4-6898D3CEDEBD}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [TCP Query User{82FE00D9-E6F0-4CB8-9B60-816AAD742BDB}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{FDE46CCA-AAFC-4479-B2E2-D11D85E783A8}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{5BF291DD-BF7B-435B-A828-C60013BC36C5}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe => No File
FirewallRules: [{8DBECFBA-ECD9-4018-B4AF-87F78802E809}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe => No File
FirewallRules: [{6F508BE4-55D4-4E00-BB96-A12A44734859}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe => No File
FirewallRules: [{61F7D853-8049-4EDA-A9AD-0F321926F991}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe => No File
FirewallRules: [TCP Query User{DE8BB403-0E89-4C68-9D0B-994C01F0D883}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{68171860-2395-48E9-BFE6-772CE1BFB97E}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{37F848E4-8D94-4014-9CBF-EF41A41BB9A6}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{12C09576-213D-4A9B-8544-303D68DBCEED}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe => No File
FirewallRules: [{C065805A-2D52-40DD-B6CE-E9FE6B23C7BE}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe => No File
FirewallRules: [{7AAC6AED-1E16-4AB9-BB94-F970F1549FB6}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe => No File
FirewallRules: [{5048B123-5188-4CFE-80FA-D151E4F9C479}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe => No File
FirewallRules: [{A4D6288B-17E6-426E-9FA2-4E0FDC6D705D}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe => No File
FirewallRules: [{84588CA5-B711-4486-AAFD-6E6FDB871569}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe => No File
FirewallRules: [{939443F9-4C65-4E82-A297-101AB5E299FA}] => (Allow) C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe () [File not signed]
FirewallRules: [{E79003BA-6CF8-4A77-9D7B-488283EFD351}] => (Allow) C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe () [File not signed]
FirewallRules: [{8E3BE494-ABAA-4F0B-A58F-461483AEF7FC}] => (Allow) C:\Program Files\Microsoft MPI\Bin\mpiexec.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{747E94E0-55DB-48A4-892B-B64D8063D537}] => (Allow) C:\Program Files\Microsoft MPI\Bin\mpiexec.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8DE7F132-6EF4-48F3-A1AC-FC129C7CAC93}] => (Allow) C:\Program Files\Microsoft MPI\Bin\smpd.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E919378E-4501-4564-9190-DC9D94972AEC}] => (Allow) C:\Program Files\Microsoft MPI\Bin\smpd.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{FDBC39CA-FECB-4B2E-AE67-D39D966664AF}C:\program files (x86)\windscribe\wsappcontrol.exe] => (Allow) C:\program files (x86)\windscribe\wsappcontrol.exe => No File
FirewallRules: [UDP Query User{D482D82D-B617-466D-8BCE-E397D2CC700E}C:\program files (x86)\windscribe\wsappcontrol.exe] => (Allow) C:\program files (x86)\windscribe\wsappcontrol.exe => No File
FirewallRules: [{231FF233-3159-4F9B-A3A6-BAE2DB0366E9}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{CA724562-B662-46B1-95DD-F6E904B4C439}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe => No File
FirewallRules: [{DA23A761-502C-45EC-8119-F071C3291BC8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe => No File
FirewallRules: [{E59703F2-EF65-4BA6-8655-981E991DDBDF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe => No File
FirewallRules: [{0AFA2E89-C542-48BD-B424-072E6EE9E491}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe => No File
FirewallRules: [{A4146D8E-D51E-4C30-8B77-6FC0499EAEF1}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{A1667356-3898-4277-9D6F-D326CA4AE3B2}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [TCP Query User{F6FE67C7-37F3-4A95-A9F0-54D0ED909095}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{F07579D5-5EB7-4B0A-A790-855B3B84AA9E}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{0252A464-A105-434F-A606-B763FC1A7F10}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe => No File
FirewallRules: [{78D0BADE-0885-4621-B436-9172922F3226}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe => No File
FirewallRules: [TCP Query User{B592A5E8-BF72-43DE-BBCC-46E867957D23}C:\users\phil\appdata\roaming\zoom\bin_00\zoom.exe] => (Allow) C:\users\phil\appdata\roaming\zoom\bin_00\zoom.exe => No File
FirewallRules: [UDP Query User{57EC246B-FE28-4849-B067-ABD24190F601}C:\users\phil\appdata\roaming\zoom\bin_00\zoom.exe] => (Allow) C:\users\phil\appdata\roaming\zoom\bin_00\zoom.exe => No File
FirewallRules: [{BEA2890A-C0DC-4220-99A2-7C7C61852716}] => (Allow) C:\Users\Phil\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{20059C52-C50A-4EEB-9E23-AE28EA983F7A}] => (Allow) C:\Users\Phil\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{C7652C63-47AC-4FB3-9B0F-B37BBF65C06B}] => (Allow) C:\Users\Phil\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{768AEA1F-F731-4803-841C-64FB7BD314D6}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{AFEE8BB0-3FD4-494B-BFF7-9F0631EF435E}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{90B2A1E2-DE71-4232-8685-15A1AE4D709F}] => (Allow) C:\Program Files\MetaTrader 5\metatester64.exe (MetaQuotes Ltd. -> MetaQuotes Ltd.)
FirewallRules: [{E1B7C67C-3222-433A-91BC-6971560A4376}] => (Block) %ProgramFiles%\Adobe\Adobe Premiere Pro CC 2015\Adobe Premiere Pro.exe => No File
FirewallRules: [{174B8CAF-E4B2-4705-AE06-7C01A6855DD4}] => (Block) %ProgramFiles%\Adobe\Adobe Premiere Pro CC 2015\Adobe Premiere Pro.exe => No File
FirewallRules: [TCP Query User{EA3A04E1-B828-4464-91A7-1520C2B6F27F}C:\users\phil\appdata\local\mozilla firefox\firefox.exe] => (Allow) C:\users\phil\appdata\local\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{D5BC456E-2CEC-4AA1-A453-B8AC5DCBC864}C:\users\phil\appdata\local\mozilla firefox\firefox.exe] => (Allow) C:\users\phil\appdata\local\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{25E1A602-B411-4D8C-AA38-787C6509904F}C:\programdata\regid.1993-06.com.microsoft\wmiprvse.exe] => (Block) C:\programdata\regid.1993-06.com.microsoft\wmiprvse.exe => No File
FirewallRules: [UDP Query User{D70EDB31-B0DB-4037-8799-6D61480F5F9B}C:\programdata\regid.1993-06.com.microsoft\wmiprvse.exe] => (Block) C:\programdata\regid.1993-06.com.microsoft\wmiprvse.exe => No File
FirewallRules: [{C557DE62-65C1-410D-9AF9-18260D567AFB}] => (Allow) C:\Users\Phil\AppData\Local\Programs\Opera GX\102.0.4880.82\opera.exe => No File
FirewallRules: [TCP Query User{8955C64B-937F-4DFE-9DEA-C78FB77CD2E1}C:\users\phil\appdata\local\trionet\resources\triocore.exe] => (Block) C:\users\phil\appdata\local\trionet\resources\triocore.exe => No File
FirewallRules: [UDP Query User{C1BC0028-CDF2-4C1C-9CEF-975DDECB4A9E}C:\users\phil\appdata\local\trionet\resources\triocore.exe] => (Block) C:\users\phil\appdata\local\trionet\resources\triocore.exe => No File
FirewallRules: [TCP Query User{492E9C29-9880-4871-9295-67B6C13C7A37}C:\program files\presonus\studio one 6\studio one.exe] => (Allow) C:\program files\presonus\studio one 6\studio one.exe (PreSonus) [File not signed]
FirewallRules: [UDP Query User{C8317AC5-F3AD-40EE-BC6F-C2D1B9AA5580}C:\program files\presonus\studio one 6\studio one.exe] => (Allow) C:\program files\presonus\studio one 6\studio one.exe (PreSonus) [File not signed]
FirewallRules: [TCP Query User{BC5C7851-879E-4667-90A5-B0DD41E060B6}C:\program files\presonus\studio one 6\pluginscanner.exe] => (Allow) C:\program files\presonus\studio one 6\pluginscanner.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [UDP Query User{FB0D57E9-C86C-4AF0-B427-9D8DE7329588}C:\program files\presonus\studio one 6\pluginscanner.exe] => (Allow) C:\program files\presonus\studio one 6\pluginscanner.exe (PreSonus Audio Electronics, Inc. -> PreSonus)
FirewallRules: [TCP Query User{777ADD0F-6C62-4341-B6BA-C99F7CAE6FD4}C:\program files\presonus\studio one 6\studio one.exe] => (Block) C:\program files\presonus\studio one 6\studio one.exe (PreSonus) [File not signed]
FirewallRules: [UDP Query User{2DAAAB2F-1781-47A7-B69A-19C70323BE89}C:\program files\presonus\studio one 6\studio one.exe] => (Block) C:\program files\presonus\studio one 6\studio one.exe (PreSonus) [File not signed]
FirewallRules: [{8EA52CB9-47A3-4256-A337-16B8CDD7E9DF}] => (Allow) C:\Program Files (x86)\Waves\Plug-Ins V14\TRACT.bundle\Contents\Win64\TRACT.dll (Waves Inc -> Waves Audio Ltd.)
FirewallRules: [{7EA42B83-9523-453C-99EC-D6020573D9EB}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{20517F2C-C6E0-4E95-A7AC-F1A016A271D5}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{6809A1FF-66B3-4EBB-9C4A-7C1BA8C5B686}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{5361CA3F-8EB0-4384-9756-A5419E36CC0D}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{FA438F34-15B7-4CAB-9B1F-C78624C04B74}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\123.0.6312.16\remoting_host.exe (Google LLC -> Google LLC)
FirewallRules: [{8E2B2FEB-0F75-41C7-9833-EA08351455A3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\x86\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1260ABA7-6E4B-4897-8758-608A572657F7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\x86\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{ABC7BC46-CA96-4AE5-A33C-3A1A1A91ED24}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6221E678-65CC-481C-8607-4B9F133DB975}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5687C4A5-F907-43D4-BB1D-AF85F855E121}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\arm64\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{21E11996-A798-4742-9088-8DE25E3486AA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\arm64\EngHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B84F0F20-C060-4CD2-9E9D-86B1DD0605A7}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\122.0.2365.92\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{263E6080-DBA2-4EA3-B4E8-E47FEBB4C0EB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================


==================== Faulty Device Manager Devices ============

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: ========================

Application errors:
==================
Error: (03/21/2024 10:55:06 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ESETOnlineScanner.exe, version: 10.34.8.0, time stamp: 0x65f09154
Faulting module name: ntdll.dll, version: 10.0.19041.3996, time stamp: 0x9b4c0fa6
Exception code: 0xc0000005
Fault offset: 0x0005f5f3
Faulting process id: 0x381c
Faulting application start time: 0x01da7b9f72209290
Faulting application path: C:\Users\Phil\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 117d4e06-de22-4eab-8757-1603d6446510
Faulting package full name:
Faulting package-relative application ID:

Error: (03/21/2024 10:51:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ESETOnlineScanner.exe, version: 10.34.8.0, time stamp: 0x65f09154
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00004000
Faulting process id: 0x15dc
Faulting application start time: 0x01da7b9f2f0aabbb
Faulting application path: C:\Users\Phil\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe
Faulting module path: unknown
Report Id: f6934369-d703-4c97-b222-ebd70ce1bbaf
Faulting package full name:
Faulting package-relative application ID:

Error: (03/21/2024 10:42:44 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Removed Adobe Acrobat XI Pro.; Error = 0x80070422).

Error: (03/21/2024 10:42:26 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Removed Adobe Acrobat XI Pro.; Error = 0x80070422).

Error: (03/21/2024 10:40:06 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Installed PROPLUSR; Error = 0x80070422).

Error: (03/21/2024 10:39:32 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Installed PROPLUSR; Error = 0x80070422).

Error: (03/21/2024 10:39:31 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Installed PROPLUSR; Error = 0x80070422).

Error: (03/21/2024 10:39:30 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Installed PROPLUSR; Error = 0x80070422).


System errors:
=============
Error: (03/21/2024 12:10:48 PM) (Source: BTHUSB) (EventID: 16) (User: )
Description: The mutual authentication between the local Bluetooth adapter and a device with Bluetooth adapter address (8c:bf:a6:31:25:1c) failed.

Error: (03/20/2024 09:08:14 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Intel® PROSet/Wireless Zero Configuration Service service terminated with the following error:
%%2147770990

Error: (03/20/2024 09:07:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The FoxitReaderService service failed to start due to the following error:
The system cannot find the file specified.

Error: (03/20/2024 09:07:20 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Energy Server Service queencreek service did not shut down properly after receiving a preshutdown control.

Error: (03/20/2024 09:07:04 PM) (Source: DCOM) (EventID: 10010) (User: DELL-LAPTOP)
Description: The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.

Error: (03/20/2024 05:49:33 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Intel® PROSet/Wireless Zero Configuration Service service terminated with the following error:
%%2147770990

Error: (03/20/2024 05:49:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The FoxitReaderService service failed to start due to the following error:
The system cannot find the file specified.

Error: (03/20/2024 05:48:33 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Energy Server Service queencreek service did not shut down properly after receiving a preshutdown control.


Windows Defender:
================
Date: 2024-02-16 09:55:47
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!pz&threatid=2147890630&enterprise=0
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe; file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.405.71.0, AS: 1.405.71.0, NIS: 1.405.71.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10

Date: 2024-02-16 09:55:47
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!pz&threatid=2147890630&enterprise=0
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: Unknown
Security intelligence Version: AV: 1.405.71.0, AS: 1.405.71.0, NIS: 1.405.71.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10

Date: 2024-02-16 09:55:47
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!pz&threatid=2147890630&enterprise=0
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.405.71.0, AS: 1.405.71.0, NIS: 1.405.71.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10

Date: 2024-02-01 21:40:41
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!pz&threatid=2147890630&enterprise=0
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: Unknown
Security intelligence Version: AV: 1.403.3067.0, AS: 1.403.3067.0, NIS: 1.403.3067.0
Engine Version: AM: 1.1.23110.2, NIS: 1.1.23110.2

Date: 2024-01-31 22:38:24
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!pz&threatid=2147890630&enterprise=0
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.403.3022.0, AS: 1.403.3022.0, NIS: 1.403.3022.0
Engine Version: AM: 1.1.23110.2, NIS: 1.1.23110.2
Event[0]:

Date: 2024-02-05 11:19:06
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.403.3263.0
Previous security intelligence Version: 1.403.3218.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.23110.2
Previous Engine Version: 1.1.23110.2
Error code: 0x80070241
Error description: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2024-02-05 11:19:06
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.403.3263.0
Previous security intelligence Version: 1.403.3218.0
Update Source: User
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 1.1.23110.2
Previous Engine Version: 1.1.23110.2
Error code: 0x80070241
Error description: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2023-11-16 21:53:14
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Current
Error Code: 0x80070003
Error description: The system cannot find the path specified.
Security intelligence Version: 0.0.0.0;0.0.0.0
Engine Version: 0.0.0.0

Date: 2023-06-06 02:56:46
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.391.576.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.23050.3
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

CodeIntegrity:
===============
Date: 2024-03-21 13:25:17
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

BIOS: Dell Inc. 1.2.7 12/13/2017
Motherboard: Dell Inc. 0H87XC
Processor: Intel® Core™ i5-6300HQ CPU @ 2.30GHz
Percentage of memory in use: 58%
Total physical RAM: 16250.84 MB
Available physical RAM: 6779.24 MB
Total Virtual: 21626.84 MB
Available Virtual: 7382.63 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:953.25 GB) (Free:618.43 GB) (Model: TEAM TM8PS7001T) NTFS
Drive d: (1TB) (Fixed) (Total:931.5 GB) (Free:708.91 GB) (Model: PNY CS900 1TB SSD) NTFS

\\?\Volume{09964035-891e-49f6-bab9-1af2dfe5e75a}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.43 GB) FAT32

==================== MBR & Partition Table ====================

==================== End of Addition.txt =======================

Attached Files


Edited by Oh My!, 21 March 2024 - 08:23 PM.


#6 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 62,343 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:12 PM

Posted 21 March 2024 - 09:06 PM

Thank you for your efforts and updated logs.

I am still reviewing the reports, there is quite a bit we need to address. For now, please do this.
 

HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://192.168.1.90:1829/
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://192.168.1.85:85/

Do you recognize these?

===================================================

Uninstalling Programs Using Revo Uninstaller Free Portable

--------------------
  • Download Revo Uninstaller Free Portable and save it to your Desktop
  • Right click on the folder and select Extract All..., then click Extract
  • Double click on the RevoUninstaller-Portable folder
  • Right click on RevoUPort and select Run as administrator
  • Click OK on the License Agreement
  • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
PreSonus Studio One 6 
  • If the program's uninstaller appears work through the steps to remove the program(s)
  • Be sure the Advanced option is selected then click Scan
  • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
  • Once done click Finish
  • Reboot your computer
===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
SystemRestore: On
CreateRestorePoint:
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Recognize entries?
  • Program uninstalled?
  • Fixlog

Lord, to whom shall we go? You have the words of eternal life and we have believed and have come to know that you are the Holy One of God.
John 6:68-69

The Man on the Middle Cross Said I Could Come

#7 user23049

user23049
  • Topic Starter

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:09:12 PM

Posted 22 March 2024 - 12:20 PM

Hi Gary

 

Those two IP address I created about 10 years ago for IP cameras.  I've uninstalled Presonus with Revo uninstaller.  To note: upon reboot this time I did not get the cmd prompt windows that ran nor the level1.exe generated into the appdata folder. 

 

Here's the log for FRST

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 22.03.2024
Ran by Phil (22-03-2024 13:18:27) Run:1
Running from C:\Users\Phil\Downloads
Loaded Profiles: Phil & SQLTELEMETRY & MSSQLSERVER
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
SystemRestore: On
CreateRestorePoint:
End::
*****************
 
SystemRestore: On => completed
Restore point was successfully created.
 
==== End of Fixlog 13:18:37 ====


#8 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 62,343 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:12 PM

Posted 22 March 2024 - 01:27 PM

Thank you for the information.

Your system is quite infected. We need to be aggressive in cleaning it so it was important to know there is a System Restore Point.

Please do this.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
Unlock: C:\ProgramData\TractTent
Folder: C:\ProgramData\{97BAC61B-4997-4F27-8567-391BD82F596A}
File: C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll
cmd: type "C:\ProgramData\remover.bat"
cmd: type "C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT\rasapi32.js"
C:\Users\Phil\AppData\Roaming\Java\jre8\bin\java.exe:jll 
C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll
C:\ProgramData\remover.bat
C:\Users\Phil\AppData\Roaming\strt.cmd
C:\Users\Phil\AppData\Roaming\msftedit
C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT\rasapi32.js
C:\Users\Phil\AppData\Local\wle.log
C:\Users\Phil\AppData\Roaming\winsQ
C:\Users\Phil\AppData\Roaming\msftedit
C:\Users\Phil\AppData\Roaming\comcomZmr
C:\ProgramData\{97BAC61B-4997-4F27-8567-391BD82F596A}
C:\Users\Phil\AppData\Local\Desktop_inni
C:\ProgramData\{3FCE7907-AA6B-470A-BFB2-C042375EDBDF}
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION 
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION 
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION 
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION 
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Restriction <==== ATTENTION 
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\StartupFolder: => "Gqreader.lnk"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [rasapi32] => wscript.exe "C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT\rasapi32.js" [178 2023-09-30] () [File not signed] <==== ATTENTION 
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\RunOnce: [removerbat] => C:\ProgramData\remover.bat [307 2024-03-20] () [File not signed] <==== ATTENTION 
HKLM-x32\...\Run: [Adobe Creative Cloud] => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true (No File) 
HKLM-x32\...\Run: [Cisconet] => "%AppData%\msftedit\WinXBlueRay.exe" (No File) 
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [Lync] => "C:\Program Files\Microsoft Office\Office15\lync.exe" /fromrunkey (No File) 
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [Trio.WakeNet] => C:\Users\Phil\AppData\Local\TrioNet\Trio.Net.exe (No File) 
S2 FoxitReaderService; "C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe" [X] 
S2 IAStorDataMgrSvc; "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe" [X] 
S3 DrvSnSht; \??\C:\Users\Phil\AppData\Local\Temp\RarSFX0\DrvSnSht64.sys [X] <==== ATTENTION 
S3 R-ImageDisk; \??\C:\Users\Phil\AppData\Local\Temp\RarSFX0\R-ImageDisk64.sys [X] <==== ATTENTION 
Startup: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Gqreader.lnk [2023-11-28]
ShortcutTarget: Gqreader.lnk -> C:\Users\Phil\AppData\Roaming\msftedit\WinXBluRay.exe (No File)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File 
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0] 
Task: {D65748B1-D097-42BA-9B41-B4BD003B5160} - System32\Tasks\OneNote 5797 => C:\Users\Phil\AppData\Roaming\strt.cmd  -> 
Task: {08CAD4CF-9FEA-4DB1-83B7-D9935729BC84} - System32\Tasks\OneNote 89688 => C:\Users\Phil\AppData\Roaming\strt.cmd  -> 
Task: {3D46B100-7552-4143-B86A-F2B9970703F6} - System32\Tasks\Intel\System.Windows.Presentatio00_clr0400 => C:\Windows\system32\rundll32.exe [71680 2023-11-14] (Microsoft Windows -> Microsoft Corporation) -> C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll SHEiflowfdqaa
Task: {D0AF27D6-8368-4DA9-926B-288A91E56430} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION 
Task: {3D13762D-057E-43AA-AC86-ADA65FB62FDF} - System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => C:\Windows\TEMP\DeleteFolderTask.exe  (No File) <==== ATTENTION 
Task: {B232ECA6-D3D1-4EC4-A32D-E08E86763ED0} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe  -mode=scheduled (No File) 
Task: {7B4E0C68-BE5A-4442-A2BD-993BA50AA038} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe  --automatic (No File) 
Task: {63C0817E-7830-4189-BC23-F9E568C905D4} - System32\Tasks\Opera GX scheduled Autoupdate 1696112022 => C:\Users\Phil\AppData\Local\Programs\Opera GX\launcher.exe  --scheduledautoupdate $(Arg0) (No File) 
Task: {44369712-8FE0-4ADE-93B5-90A17714898E} - System32\Tasks\Private Internet Access Startup => "C:\Program Files\pia_manager\pia_manager.exe"  --startup (No File) 
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File 
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File 
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File 
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\localserver32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\FileCoAuth.exe
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File 
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\PROGRA~2\MICROS~2\Office15\GROOVEEX.DLL => No File 
SearchScopes: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001 -> {A79BE33D-4EB3-40E2-B354-BB99B3501D8A} URL =
cmd: netsh winsock reset catalog
cmd: netsh int ip reset resetlog.txt
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: bitsadmin /reset /allusers
cmd: ipconfig /flushdns
Removeproxy:
hosts:
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /CheckHealth
Emptytemp:
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • Note: This step resets your Firewall settings and you may be asked later to grant permission for legitimate programs to pass through the Firewall. If you recognize the program agree to the request.
  • Note: The Emptytemp: command will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Fixlog

Lord, to whom shall we go? You have the words of eternal life and we have believed and have come to know that you are the Holy One of God.
John 6:68-69

The Man on the Middle Cross Said I Could Come

#9 user23049

user23049
  • Topic Starter

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:09:12 PM

Posted 22 March 2024 - 01:48 PM

Thanks Gary,

Wondering why/how it's still infected as I've already run ESET scanner as well as malwarebytes??

I'll run this new FRST...

#10 user23049

user23049
  • Topic Starter

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:09:12 PM

Posted 22 March 2024 - 01:56 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 22.03.2024
Ran by Phil (22-03-2024 14:35:46) Run:2
Running from C:\Users\Phil\Downloads
Loaded Profiles: Phil & SQLTELEMETRY & MSSQLSERVER
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
SystemRestore: On
CreateRestorePoint:
CloseProcesses:
Unlock: C:\ProgramData\TractTent
Folder: C:\ProgramData\{97BAC61B-4997-4F27-8567-391BD82F596A}
File: C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll
cmd: type "C:\ProgramData\remover.bat"
cmd: type "C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT\rasapi32.js"
C:\Users\Phil\AppData\Roaming\Java\jre8\bin\java.exe:jll 
C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll
C:\ProgramData\remover.bat
C:\Users\Phil\AppData\Roaming\strt.cmd
C:\Users\Phil\AppData\Roaming\msftedit
C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT\rasapi32.js
C:\Users\Phil\AppData\Local\wle.log
C:\Users\Phil\AppData\Roaming\winsQ
C:\Users\Phil\AppData\Roaming\msftedit
C:\Users\Phil\AppData\Roaming\comcomZmr
C:\ProgramData\{97BAC61B-4997-4F27-8567-391BD82F596A}
C:\Users\Phil\AppData\Local\Desktop_inni
C:\ProgramData\{3FCE7907-AA6B-470A-BFB2-C042375EDBDF}
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION 
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION 
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION 
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION 
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Restriction <==== ATTENTION 
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\StartupFolder: => "Gqreader.lnk"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [rasapi32] => wscript.exe "C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT\rasapi32.js" [178 2023-09-30] () [File not signed] <==== ATTENTION 
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\RunOnce: [removerbat] => C:\ProgramData\remover.bat [307 2024-03-20] () [File not signed] <==== ATTENTION 
HKLM-x32\...\Run: [Adobe Creative Cloud] => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true (No File) 
HKLM-x32\...\Run: [Cisconet] => "%AppData%\msftedit\WinXBlueRay.exe" (No File) 
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [Lync] => "C:\Program Files\Microsoft Office\Office15\lync.exe" /fromrunkey (No File) 
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [Trio.WakeNet] => C:\Users\Phil\AppData\Local\TrioNet\Trio.Net.exe (No File) 
S2 FoxitReaderService; "C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe" [X] 
S2 IAStorDataMgrSvc; "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe" [X] 
S3 DrvSnSht; \??\C:\Users\Phil\AppData\Local\Temp\RarSFX0\DrvSnSht64.sys [X] <==== ATTENTION 
S3 R-ImageDisk; \??\C:\Users\Phil\AppData\Local\Temp\RarSFX0\R-ImageDisk64.sys [X] <==== ATTENTION 
Startup: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Gqreader.lnk [2023-11-28]
ShortcutTarget: Gqreader.lnk -> C:\Users\Phil\AppData\Roaming\msftedit\WinXBluRay.exe (No File)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File 
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0] 
Task: {D65748B1-D097-42BA-9B41-B4BD003B5160} - System32\Tasks\OneNote 5797 => C:\Users\Phil\AppData\Roaming\strt.cmd  -> 
Task: {08CAD4CF-9FEA-4DB1-83B7-D9935729BC84} - System32\Tasks\OneNote 89688 => C:\Users\Phil\AppData\Roaming\strt.cmd  -> 
Task: {3D46B100-7552-4143-B86A-F2B9970703F6} - System32\Tasks\Intel\System.Windows.Presentatio00_clr0400 => C:\Windows\system32\rundll32.exe [71680 2023-11-14] (Microsoft Windows -> Microsoft Corporation) -> C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll SHEiflowfdqaa
Task: {D0AF27D6-8368-4DA9-926B-288A91E56430} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION 
Task: {3D13762D-057E-43AA-AC86-ADA65FB62FDF} - System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => C:\Windows\TEMP\DeleteFolderTask.exe  (No File) <==== ATTENTION 
Task: {B232ECA6-D3D1-4EC4-A32D-E08E86763ED0} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe  -mode=scheduled (No File) 
Task: {7B4E0C68-BE5A-4442-A2BD-993BA50AA038} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe  --automatic (No File) 
Task: {63C0817E-7830-4189-BC23-F9E568C905D4} - System32\Tasks\Opera GX scheduled Autoupdate 1696112022 => C:\Users\Phil\AppData\Local\Programs\Opera GX\launcher.exe  --scheduledautoupdate $(Arg0) (No File) 
Task: {44369712-8FE0-4ADE-93B5-90A17714898E} - System32\Tasks\Private Internet Access Startup => "C:\Program Files\pia_manager\pia_manager.exe"  --startup (No File) 
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File 
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File 
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\amd64\FileSyncShell64.dll => No File 
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\localserver32 -> C:\Users\Phil\AppData\Local\Microsoft\OneDrive\19.232.1124.0008\FileCoAuth.exe
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File 
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File 
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File 
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\PROGRA~2\MICROS~2\Office15\GROOVEEX.DLL => No File 
SearchScopes: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001 -> {A79BE33D-4EB3-40E2-B354-BB99B3501D8A} URL =
cmd: netsh winsock reset catalog
cmd: netsh int ip reset resetlog.txt
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: bitsadmin /reset /allusers
cmd: ipconfig /flushdns
Removeproxy:
hosts:
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /CheckHealth
Emptytemp:
End::
*****************
 
SystemRestore: On => completed
Restore point was successfully created.
Processes closed successfully.
"C:\ProgramData\TractTent" => was unlocked
 
========================= Folder: C:\ProgramData\{97BAC61B-4997-4F27-8567-391BD82F596A} ========================
 
 
====== End of Folder: ======
 
 
========================= File: C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll ========================
 
C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll
File not signed
MD5: 50A90F1EA76FEEA8015870319923F69D
Creation and modification date: 2021-07-26 07:23 - 2021-07-26 07:23
Size: 000126976
Attributes: ----A
Company Name: 
Internal Name: irmeqlf9Engin281.dll
Original Name: irmeqlf9Engin281.dll
Product: 
Description:  
File Version: 0.0.0.0
Product Version: 0.0.0.0
Copyright:  
 
====== End of File: ======
 
 
========= type "C:\ProgramData\remover.bat" =========
 
The system cannot find the file specified.
 
 
========= End of CMD: =========
 
 
========= type "C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT\rasapi32.js" =========
 
y='Shell';new ActiveXObject(y+'.Application')[y+'Execute']("WerFault.exe",'"WerFault.exe:cpl" d7a59b09fbf8bf502',"C:\\Users\\Phil\\AppData\\Local\\Microsoft\\WinWER",'open',0);
 
 
========= End of CMD: =========
 
Could not move "C:\Users\Phil\AppData\Roaming\Java\jre8\bin\java.exe:jll" => Scheduled to move on reboot.
C:\ProgramData\TractTent\PersolAczoknt\irmeqlf9Engin281.dll => moved successfully
"C:\ProgramData\remover.bat" => not found
"C:\Users\Phil\AppData\Roaming\strt.cmd" => not found
 
"C:\Users\Phil\AppData\Roaming\msftedit" Folder move:
 
C:\Users\Phil\AppData\Roaming\msftedit => moved successfully
C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT\rasapi32.js => moved successfully
C:\Users\Phil\AppData\Local\wle.log => moved successfully
 
"C:\Users\Phil\AppData\Roaming\winsQ" Folder move:
 
C:\Users\Phil\AppData\Roaming\winsQ => moved successfully
"C:\Users\Phil\AppData\Roaming\msftedit" => not found
 
"C:\Users\Phil\AppData\Roaming\comcomZmr" Folder move:
 
C:\Users\Phil\AppData\Roaming\comcomZmr => moved successfully
 
"C:\ProgramData\{97BAC61B-4997-4F27-8567-391BD82F596A}" Folder move:
 
C:\ProgramData\{97BAC61B-4997-4F27-8567-391BD82F596A} => moved successfully
"C:\Users\Phil\AppData\Local\Desktop_inni" => not found
 
"C:\ProgramData\{3FCE7907-AA6B-470A-BFB2-C042375EDBDF}" Folder move:
 
C:\ProgramData\{3FCE7907-AA6B-470A-BFB2-C042375EDBDF} => moved successfully
HKLM\SOFTWARE\Policies\Google => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Edge => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center => removed successfully
C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Gqreader.lnk => moved successfully
"HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\Gqreader.lnk" => removed successfully
"HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Windows\CurrentVersion\Run\\rasapi32" => removed successfully
"HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\removerbat" => not found
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe Creative Cloud" => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Cisconet" => removed successfully
"HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Lync" => removed successfully
"HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Trio.WakeNet" => removed successfully
HKLM\System\CurrentControlSet\Services\FoxitReaderService => removed successfully
FoxitReaderService => service removed successfully
HKLM\System\CurrentControlSet\Services\IAStorDataMgrSvc => removed successfully
IAStorDataMgrSvc => service removed successfully
HKLM\System\CurrentControlSet\Services\DrvSnSht => removed successfully
DrvSnSht => service removed successfully
HKLM\System\CurrentControlSet\Services\R-ImageDisk => removed successfully
R-ImageDisk => service removed successfully
"C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Gqreader.lnk" => not found
"C:\Users\Phil\AppData\Roaming\msftedit\WinXBluRay.exe" => not found
HKLM\Software\Classes\PROTOCOLS\Filter\application/x-mfe-ipt => removed successfully
C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`27hfm" ADS removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D65748B1-D097-42BA-9B41-B4BD003B5160}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D65748B1-D097-42BA-9B41-B4BD003B5160}" => removed successfully
C:\WINDOWS\System32\Tasks\OneNote 5797 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneNote 5797" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{08CAD4CF-9FEA-4DB1-83B7-D9935729BC84}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{08CAD4CF-9FEA-4DB1-83B7-D9935729BC84}" => removed successfully
C:\WINDOWS\System32\Tasks\OneNote 89688 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneNote 89688" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{3D46B100-7552-4143-B86A-F2B9970703F6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D46B100-7552-4143-B86A-F2B9970703F6}" => removed successfully
C:\WINDOWS\System32\Tasks\Intel\System.Windows.Presentatio00_clr0400 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Intel\System.Windows.Presentatio00_clr0400" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D0AF27D6-8368-4DA9-926B-288A91E56430}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0AF27D6-8368-4DA9-926B-288A91E56430}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3D13762D-057E-43AA-AC86-ADA65FB62FDF}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D13762D-057E-43AA-AC86-ADA65FB62FDF}" => removed successfully
C:\WINDOWS\System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B232ECA6-D3D1-4EC4-A32D-E08E86763ED0}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B232ECA6-D3D1-4EC4-A32D-E08E86763ED0}" => removed successfully
C:\WINDOWS\System32\Tasks\AdobeGCInvoker-1.0 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeGCInvoker-1.0" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7B4E0C68-BE5A-4442-A2BD-993BA50AA038}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B4E0C68-BE5A-4442-A2BD-993BA50AA038}" => removed successfully
C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{63C0817E-7830-4189-BC23-F9E568C905D4}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{63C0817E-7830-4189-BC23-F9E568C905D4}" => removed successfully
C:\WINDOWS\System32\Tasks\Opera GX scheduled Autoupdate 1696112022 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera GX scheduled Autoupdate 1696112022" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{44369712-8FE0-4ADE-93B5-90A17714898E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{44369712-8FE0-4ADE-93B5-90A17714898E}" => removed successfully
C:\WINDOWS\System32\Tasks\Private Internet Access Startup => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Private Internet Access Startup" => removed successfully
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E} => removed successfully
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C} => removed successfully
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E} => removed successfully
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} => not found
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A79BE33D-4EB3-40E2-B354-BB99B3501D8A} => removed successfully
 
========= netsh winsock reset catalog =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
 
========= End of CMD: =========
 
 
========= netsh int ip reset resetlog.txt =========
 
Resetting Compartment Forwarding, OK!
Resetting Compartment, OK!
Resetting Control Protocol, OK!
Resetting Echo Sequence Request, OK!
Resetting Global, OK!
Resetting Interface, OK!
Resetting Anycast Address, OK!
Resetting Multicast Address, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting Potential, OK!
Resetting Prefix Policy, OK!
Resetting Proxy Neighbor, OK!
Resetting Route, OK!
Resetting Site Prefix, OK!
Resetting Subinterface, OK!
Resetting Wakeup Pattern, OK!
Resetting Resolve Neighbor, OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , failed.
Access is denied.
 
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.
 
 
 
========= End of CMD: =========
 
 
========= reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
C:\Firewall.reg => moved successfully
 
========= netsh advfirewall reset =========
 
Ok.
 
 
 
========= End of CMD: =========
 
 
========= netsh advfirewall set allprofiles state ON =========
 
Ok.
 
 
 
========= End of CMD: =========
 
 
========= bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0
BITS administration utility.
© Copyright Microsoft Corp.
 
{226B10B0-E2C0-4CBB-8470-E06B85422D54} canceled.
{0BFDEB5B-55BF-4269-8716-5F0EB7C09F8D} canceled.
{2920D704-E512-4F7D-B4B6-54989B6409BB} canceled.
3 out of 3 jobs canceled.
 
 
========= End of CMD: =========
 
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
 
========= End of CMD: =========
 
 
========= RemoveProxy: =========
 
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
 
 
========= End of RemoveProxy: =========
 
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
========= sfc /scannow =========
 
 
 
Beginning system scan.  This process will take some time.
 
 
 
Beginning verification phase of system scan.
 
 
Verification 0% complete.
Verification 1% complete.
Verification 1% complete.
Verification 2% complete.
Verification 2% complete.
Verification 3% complete.
Verification 4% complete.
Verification 4% complete.
Verification 5% complete.
Verification 5% complete.
Verification 6% complete.
Verification 7% complete.
Verification 7% complete.
Verification 8% complete.
Verification 8% complete.
Verification 9% complete.
Verification 10% complete.
Verification 10% complete.
Verification 11% complete.
Verification 11% complete.
Verification 12% complete.
Verification 13% complete.
Verification 13% complete.
Verification 14% complete.
Verification 14% complete.
Verification 15% complete.
Verification 16% complete.
Verification 16% complete.
Verification 17% complete.
Verification 17% complete.
Verification 18% complete.
Verification 19% complete.
Verification 19% complete.
Verification 20% complete.
Verification 20% complete.
Verification 21% complete.
Verification 22% complete.
Verification 22% complete.
Verification 23% complete.
Verification 23% complete.
Verification 24% complete.
Verification 25% complete.
Verification 25% complete.
Verification 26% complete.
Verification 26% complete.
Verification 27% complete.
Verification 28% complete.
Verification 28% complete.
Verification 29% complete.
Verification 29% complete.
Verification 30% complete.
Verification 31% complete.
Verification 31% complete.
Verification 32% complete.
Verification 32% complete.
Verification 33% complete.
Verification 34% complete.
Verification 34% complete.
Verification 35% complete.
Verification 35% complete.
Verification 36% complete.
Verification 37% complete.
Verification 37% complete.
Verification 38% complete.
Verification 38% complete.
Verification 39% complete.
Verification 40% complete.
Verification 40% complete.
Verification 41% complete.
Verification 41% complete.
Verification 42% complete.
Verification 43% complete.
Verification 43% complete.
Verification 44% complete.
Verification 44% complete.
Verification 45% complete.
Verification 46% complete.
Verification 46% complete.
Verification 47% complete.
Verification 47% complete.
Verification 48% complete.
Verification 49% complete.
Verification 49% complete.
Verification 50% complete.
Verification 50% complete.
Verification 51% complete.
Verification 52% complete.
Verification 52% complete.
Verification 53% complete.
Verification 53% complete.
Verification 54% complete.
Verification 55% complete.
Verification 55% complete.
Verification 56% complete.
Verification 56% complete.
Verification 57% complete.
Verification 58% complete.
Verification 58% complete.
Verification 59% complete.
Verification 59% complete.
Verification 60% complete.
Verification 61% complete.
Verification 61% complete.
Verification 62% complete.
Verification 62% complete.
Verification 63% complete.
Verification 64% complete.
Verification 64% complete.
Verification 65% complete.
Verification 65% complete.
Verification 66% complete.
Verification 67% complete.
Verification 67% complete.
Verification 68% complete.
Verification 68% complete.
Verification 69% complete.
Verification 70% complete.
Verification 70% complete.
Verification 71% complete.
Verification 71% complete.
Verification 72% complete.
Verification 73% complete.
Verification 73% complete.
Verification 74% complete.
Verification 74% complete.
Verification 75% complete.
Verification 76% complete.
Verification 76% complete.
Verification 77% complete.
Verification 77% complete.
Verification 78% complete.
Verification 79% complete.
Verification 79% complete.
Verification 80% complete.
Verification 80% complete.
Verification 81% complete.
Verification 82% complete.
Verification 82% complete.
Verification 83% complete.
Verification 83% complete.
Verification 84% complete.
Verification 85% complete.
Verification 85% complete.
Verification 86% complete.
Verification 86% complete.
Verification 87% complete.
Verification 88% complete.
Verification 88% complete.
Verification 89% complete.
Verification 89% complete.
Verification 90% complete.
Verification 91% complete.
Verification 91% complete.
Verification 92% complete.
Verification 92% complete.
Verification 93% complete.
Verification 94% complete.
Verification 94% complete.
Verification 95% complete.
Verification 95% complete.
Verification 96% complete.
Verification 97% complete.
Verification 97% complete.
Verification 98% complete.
Verification 98% complete.
Verification 99% complete.
Verification 100% complete.
 
 
Windows Resource Protection did not find any integrity violations.
 
 
 
========= End of CMD: =========
 
 
========= DISM /Online /Cleanup-Image /CheckHealth =========
 
 
Deployment Image Servicing and Management tool
Version: 10.0.19041.3636
 
Image Version: 10.0.19045.4170
 
The component store is repairable.
The operation completed successfully.
 
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
FlushDNS => completed
BITS transfer queue => 1572864 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 90196369 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 32495435 B
Edge => 0 B
Chrome => 1984872384 B
Firefox => 450843808 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 6656 B
ProgramData => 6656 B
Public => 6656 B
systemprofile => 6656 B
systemprofile32 => 7215 B
LocalService => 94815 B
NetworkService => 16659149 B
Phil => 230336865 B
SQLTELEMETRY => 230343521 B
MSSQLSERVER => 230350177 B
 
RecycleBin => 2948059187 B
EmptyTemp: => 5.8 GB temporary data Removed.
 
================================
 
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 22-03-2024 14:49:53)
 
C:\Users\Phil\AppData\Roaming\Java\jre8\bin\java.exe:jll => Could not move
 
==== End of Fixlog 14:49:53 ====


#11 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 62,343 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:12 PM

Posted 22 March 2024 - 02:16 PM

Greetings.

Automated programs will not always detect every instance of malware. A trained eye is routinely needed to evaluate a system for remaining malicious software.

Please do this.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
CloseProcesses:
cmd: DISM /Online /Cleanup-Image /RestoreHealth
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • How is your computer running?
===================================================

Run a new FRST scan and copy/paste both reports in your reply.

===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Fixlog
  • How is your computer running?
  • FRST scan reports

Lord, to whom shall we go? You have the words of eternal life and we have believed and have come to know that you are the Holy One of God.
John 6:68-69

The Man on the Middle Cross Said I Could Come

#12 user23049

user23049
  • Topic Starter

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:09:12 PM

Posted 22 March 2024 - 02:44 PM

thanks Gary, running much better!

 

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 22.03.2024
Ran by Phil (22-03-2024 15:18:45) Run:3
Running from C:\Users\Phil\Downloads
Loaded Profiles: Phil & SQLTELEMETRY & MSSQLSERVER
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
CloseProcesses:
cmd: DISM /Online /Cleanup-Image /RestoreHealth
End::
*****************
 
Processes closed successfully.
 
========= DISM /Online /Cleanup-Image /RestoreHealth =========
 
 
Deployment Image Servicing and Management tool
Version: 10.0.19041.3636
 
Image Version: 10.0.19045.4170
 
 
[==                         3.8%                           ] 
 
[==                         4.3%                           ] 
 
[===                        5.3%                           ] 
 
[===                        6.0%                           ] 
 
[===                        6.6%                           ] 
 
[====                       7.3%                           ] 
 
[====                       8.2%                           ] 
 
[=====                      9.1%                           ] 
 
[=====                      10.1%                          ] 
 
[======                     10.6%                          ] 
 
[======                     11.2%                          ] 
 
[=======                    12.2%                          ] 
 
[=======                    13.2%                          ] 
 
[========                   14.1%                          ] 
 
[========                   15.0%                          ] 
 
[========                   15.2%                          ] 
 
[=========                  16.1%                          ] 
 
[=========                  17.1%                          ] 
 
[==========                 18.0%                          ] 
 
[==========                 18.9%                          ] 
 
[===========                19.6%                          ] 
 
[===========                20.6%                          ] 
 
[============               21.5%                          ] 
 
[=============              22.5%                          ] 
 
[=============              23.0%                          ] 
 
[=============              23.6%                          ] 
 
[=============              23.7%                          ] 
 
[=============              23.7%                          ] 
 
[=============              23.8%                          ] 
 
[=============              23.8%                          ] 
 
[=============              24.0%                          ] 
 
[==============             24.4%                          ] 
 
[==============             25.4%                          ] 
 
[===============            26.3%                          ] 
 
[===============            27.3%                          ] 
 
[================           28.3%                          ] 
 
[================           29.2%                          ] 
 
[=================          30.2%                          ] 
 
[=================          30.8%                          ] 
 
[==================         31.1%                          ] 
 
[==================         31.5%                          ] 
 
[==================         32.0%                          ] 
 
[==================         32.1%                          ] 
 
[==================         32.2%                          ] 
 
[==================         32.6%                          ] 
 
[===================        33.6%                          ] 
 
[====================       34.6%                          ] 
 
[====================       35.5%                          ] 
 
[=====================      36.5%                          ] 
 
[=====================      37.4%                          ] 
 
[=====================      37.9%                          ] 
 
[======================     38.8%                          ] 
 
[======================     39.5%                          ] 
 
[=======================    39.7%                          ] 
 
[=======================    40.7%                          ] 
 
[=======================    40.8%                          ] 
 
[========================   41.8%                          ] 
 
[========================   42.0%                          ] 
 
[========================   42.1%                          ] 
 
[========================   42.4%                          ] 
 
[========================   42.4%                          ] 
 
[========================   42.8%                          ] 
 
[========================   42.9%                          ] 
 
[=========================  43.4%                          ] 
 
[=========================  43.7%                          ] 
 
[=========================  43.9%                          ] 
 
[=========================  44.2%                          ] 
 
[=========================  44.6%                          ] 
 
[========================== 45.0%                          ] 
 
[========================== 45.2%                          ] 
 
[========================== 45.8%                          ] 
 
[========================== 46.1%                          ] 
 
[========================== 46.3%                          ] 
 
[========================== 46.5%                          ] 
 
[========================== 46.5%                          ] 
 
[===========================46.6%                          ] 
 
[===========================46.8%                          ] 
 
[===========================46.8%                          ] 
 
[===========================47.1%                          ] 
 
[===========================47.3%                          ] 
 
[===========================47.6%                          ] 
 
[===========================48.1%                          ] 
 
[===========================48.5%                          ] 
 
[===========================49.1%                          ] 
 
[===========================49.3%                          ] 
 
[===========================50.3%                          ] 
 
[===========================51.2%                          ] 
 
[===========================52.2%                          ] 
 
[===========================53.2%                          ] 
 
[===========================54.0%                          ] 
 
[===========================54.0%                          ] 
 
[===========================54.0%                          ] 
 
[===========================54.0%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.4%                          ] 
 
[===========================54.4%                          ] 
 
[===========================54.5%                          ] 
 
[===========================54.5%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.7%                          ] 
 
[===========================54.9%                          ] 
 
[===========================54.9%                          ] 
 
[===========================55.0%                          ] 
 
[===========================55.1%                          ] 
 
[===========================55.2%                          ] 
 
[===========================55.2%                          ] 
 
[===========================55.2%                          ] 
 
[===========================55.2%                          ] 
 
[===========================55.3%                          ] 
 
[===========================55.4%                          ] 
 
[===========================55.4%                          ] 
 
[===========================55.5%                          ] 
 
[===========================55.5%                          ] 
 
[===========================55.5%                          ] 
 
[===========================55.6%                          ] 
 
[===========================55.6%                          ] 
 
[===========================55.7%                          ] 
 
[===========================55.8%                          ] 
 
[===========================55.8%                          ] 
 
[===========================55.8%                          ] 
 
[===========================55.8%                          ] 
 
[===========================55.9%                          ] 
 
[===========================55.9%                          ] 
 
[===========================55.9%                          ] 
 
[===========================56.1%                          ] 
 
[===========================56.1%                          ] 
 
[===========================56.2%                          ] 
 
[===========================56.3%                          ] 
 
[===========================56.5%                          ] 
 
[===========================56.5%                          ] 
 
[===========================56.6%                          ] 
 
[===========================56.7%                          ] 
 
[===========================56.7%                          ] 
 
[===========================56.8%                          ] 
 
[===========================56.9%=                         ] 
 
[===========================57.0%=                         ] 
 
[===========================57.0%=                         ] 
 
[===========================57.7%=                         ] 
 
[===========================57.9%=                         ] 
 
[===========================58.5%=                         ] 
 
[===========================59.5%==                        ] 
 
[===========================62.3%====                      ] 
 
[===========================84.9%=================         ] 
 
[==========================100.0%==========================] 
The restore operation completed successfully.
The operation completed successfully.
 
 
========= End of CMD: =========
 
 
 
The system needed a reboot.
 
==== End of Fixlog 15:22:17 ====
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22.03.2024
Ran by Phil (administrator) on DELL-LAPTOP (Dell Inc. Inspiron 7559) (22-03-2024 15:38:54)
Running from C:\Users\Phil\Downloads\FRST64.exe
Loaded Profiles: Phil & SQLTELEMETRY & MSSQLSERVER
Platform: Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\crash_handler.exe <5>
(C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\PlayerLocationIcon.exe
(C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <5>
(C:\Program Files\WindowsApps\Microsoft.YourPhone_1.24021.105.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.24021.105.0_x64__8wekyb3d8bbwe\YourPhoneAppProxy.exe
(DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxCUIService.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxEM.exe
(explorer.exe ->) (Dell Inc -> Dell Inc.) [File not signed] C:\Program Files\Dell\QuickSet\quickset.exe
(explorer.exe ->) (Fresco Logic Inc -> Fresco Logic) C:\Program Files\Fresco Logic\Fresco Logic USB Display Driver\FL2000\x64\flvga_tray.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <24>
(explorer.exe ->) (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(explorer.exe ->) (Open Source Developer, XMouse Button Control -> Highresolution Enterprises) C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(services.exe ->) () [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe
(services.exe ->) (Apple Computer, Inc.) [File not signed] C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(services.exe ->) (Array Networks, Inc. -> Array Networks) C:\Program Files\Array Networks\SSL VPN Client\VPNService.exe
(services.exe ->) (Cisco Systems, Inc. -> Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exe
(services.exe ->) (GeoComply Solutions Inc. -> ) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe
(services.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome Remote Desktop\123.0.6312.16\remoting_host.exe <2>
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
(services.exe ->) (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxCUIService.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\IntelCpHDCPSvc.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\IntelCpHeciSvc.exe
(services.exe ->) (Intel® Wireless Display -> Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlceip.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdmig.inf_amd64_75c152d756d851ed\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Private Internet Access, Inc. -> ) C:\Program Files\Private Internet Access\pia-service.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (ShenZhen Foscam Intelligent Technology Co,Ltd -> ) C:\Program Files (x86)\IPCWebComponents\IPCPlgSvr.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2401.0.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_11.2401.2.0_x64__8wekyb3d8bbwe\Microsoft.Media.Player.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9278152 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [3075552 2015-04-29] (Dell Inc -> Dell Inc.) [File not signed]
HKLM\...\Run: [XMouseButtonControl] => C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe [1091568 2015-03-02] (Open Source Developer, XMouse Button Control -> Highresolution Enterprises)
HKLM\...\Run: [RtHDVBg_WAVES_SKYLAKE] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WebVPN] => C:\Program Files\Array Networks\SSL VPN Client\WebVPN.exe [1484728 2020-01-17] (Array Networks, Inc. -> Array Networks)
HKLM\...\Run: [LaunchMhttpd] => C:\Program Files\Array Networks\MotionPro VPN Client\MPInit.exe [1532344 2020-01-16] (Array Networks, Inc. -> Array Networks)
HKLM\...\Run: [flvga_tray] => C:\Program Files\Fresco Logic\Fresco Logic USB Display Driver\FL2000\x64\flvga_tray.exe [457336 2017-11-23] (Fresco Logic Inc -> Fresco Logic)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [723928 2017-01-26] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [322120 2017-04-19] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [9923856 2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [1224704 2017-05-17] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
HKLM-x32\...\Run: [flvga_tray32] => C:\Program Files\Fresco Logic\Fresco Logic USB Display Driver\FL2000\x86\flvga_tray.exe [431232 2017-11-23] (Fresco Logic Inc -> Fresco Logic)
HKLM-x32\...\Run: [LaunchMhttpd] => C:\Program Files\Array Networks\MotionPro VPN Client\MPInit.exe [1532344 2020-01-16] (Array Networks, Inc. -> Array Networks)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-08-04] (Adobe Inc. -> )
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKLM\Software\Policies\...\system: [DisableLogonBackgroundImage] 1
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [11197680 2023-10-20] (RealDefense, LLC -> SUPERAntiSpyware)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [VideoGuardMonitor] => C:\Users\Phil\AppData\Local\Cisco\VideoGuardPlayer\VideoGuardMonitor\CiscoVideoGuardMonitor.exe [4155656 2016-06-14] (Cisco Video Technologies Israel Ltd. -> Cisco)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [31171504 2021-07-02] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Run: [MicrosoftEdgeAutoLaunch_0848959D30B7A075789B21F3CF73AE30] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4060712 2024-03-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Ribbons.scr [153600 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\123.0.6312.58\Installer\chrmstp.exe [2024-03-19] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WavesLocalServer.lnk [2024-02-16]
ShortcutTarget: WavesLocalServer.lnk -> C:\ProgramData\Waves Audio\WavesLocalServer\WavesLocalServer.bundle\Contents\Win64\WavesLocalServer.exe (Waves Inc -> Waves Audio Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WavesPluginServer.lnk [2024-02-16]
ShortcutTarget: WavesPluginServer.lnk -> C:\ProgramData\Waves Audio\WavesPluginServer\WavesPluginServerV14.2.bundle\Contents\Win64\WavesPluginServer.exe (Waves Inc -> Waves Audio Ltd.)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {6E871D55-E95C-49CD-BA3C-F22273B9A96E} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Phil\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15145336 2024-03-21] (ESET, spol. s r.o. -> ESET)
Task: {4094FFBA-8331-4324-B066-0483EB60311D} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Phil\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [15145336 2024-03-21] (ESET, spol. s r.o. -> ESET)
Task: {484B1CBC-6F11-4EC5-9BAD-B3A61D5E1965} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [40880 2021-07-02] (Garmin International, Inc. -> )
Task: {8B28A3DC-F851-49CC-AE5C-75B0DD295852} - System32\Tasks\GeoComply Service Check => C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\PlayerLocationCheckTask.cmd [1642 2024-02-21] () [File not signed] -> 
Task: {1D31A6C3-7C57-4FA5-8B5F-A51626FD4B69} - System32\Tasks\GeoComply Update Task => C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exe [6817472 2024-01-09] (GeoComply Solutions Inc. -> GeoComply)
Task: {76D5F9DF-E161-452D-8A12-2595ED40B702} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem124.0.6359.0{8357AD38-F079-4341-A798-7030F0EC8024} => C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
Task: {117E77E1-2BF4-4A8C-A5EF-AEE5D8733741} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [1698000 2015-06-05] (Intel® Software -> Intel Corporation)
Task: {5048683B-C65F-43DE-AB39-836AE917B600} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [1328392 2015-11-20] (Intel® Software -> Intel Corporation)
Task: {CA1B9BF5-B927-4DEB-8A8A-D57A37594261} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4922296 2023-12-19] (Intel Corporation -> Intel Corporation)
Task: {57F4C7BD-EE60-4DCA-BED3-44916DF616EF} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4922296 2023-12-19] (Intel Corporation -> Intel Corporation)
Task: {18D9AD6F-8D24-475B-8B5C-36A6F6F4B070} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {65F73DCD-EC0C-44BE-814D-37B8092B83CF} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {D1C4A8EB-315A-4825-9DB7-4957252883A2} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\AppInstallerUpdater => C:\Windows\system32\rundll32.exe [71680 2023-11-14] (Microsoft Windows -> Microsoft Corporation) -> %windir%\system32\AppxDeploymentClient.dll,AppInstallerUpdateAllTask
Task: {1285EF45-46C2-4589-BE1B-1F5B589478BB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {163BFC57-00C4-4EFC-82F4-E3B8CA9A7709} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3633EEEE-A5BF-4403-A543-9B89FB7AA1BA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BCEBEA1C-119E-446B-BC40-C755C75A8DD1} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1483475722-1219764467-3277934236-1001 92F44938A7A458E5 => C:\Users\Phil\AppData\Local\Mozilla Firefox\firefox.exe [671648 2024-03-12] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\92F44938A7A458E5\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {721029C4-76FB-4967-BBB9-DC8094FC370A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 92F44938A7A458E5 => C:\Users\Phil\AppData\Local\Mozilla Firefox\default-browser-agent.exe [34720 2024-03-12] (Mozilla Corporation -> Mozilla Foundation)
Task: {72D88C66-E288-4856-82BB-0189C31F9503} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1515208 2018-11-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {93D639BD-617B-4C2E-8178-42C2F35827DE} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\WINDOWS\System32\Wscript.exe [170496 2023-10-11] (Microsoft Windows -> Microsoft Corporation) -> //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\24F553: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\44C496E6B6F51405F574F6474716: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\7416C616879702351303B273163673: [DhcpNameServer] 192.168.34.212
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\757535F5445313243313: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1f5655b1-8bf3-4ffc-84dd-630250178497}\765647F66666D697C61677E6: [DhcpNameServer] 192.168.209.47
Tcpip\..\Interfaces\{2ace0890-853d-46fd-9bd1-a8b7f498fe12}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f0e1c8ca-7fe6-4c84-8e99-04a669df5c9c}: [DhcpNameServer] 209.222.18.222 209.222.18.218
 
Edge: 
=======
Edge Profile: C:\Users\Phil\AppData\Local\Microsoft\Edge\User Data\Default [2024-03-22]
Edge DownloadDir: Default -> C:\Users\Phil\Downloads
Edge Extension: (Google Docs Offline) - C:\Users\Phil\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-07]
Edge Extension: (Edge relevant text changes) - C:\Users\Phil\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-23]
 
FireFox:
========
FF DefaultProfile: csjgqetv.default
FF ProfilePath: C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\csjgqetv.default [2024-03-22]
FF ProfilePath: C:\Users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\xvi6q9b2.default-release [2024-03-22]
FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-05-10] (VideoLAN -> VideoLAN)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2016-12-08] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google Inc -> Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @IPC/npmedia3.0.0.3,version=3.0.0.3 -> C:\Program Files\webrec\Torch\3.0.0.3\npmedia3.0.0.3.dll [2016-11-03] (Amcrest Technologies LLC -> )
FF Plugin-x32: @IPCWebComponents -> C:\Program Files (x86)\IPCWebComponents\npIPCReg.dll [2016-12-26] (ShenZhen Foscam Intelligent Technology Co,Ltd -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-03-22]
CHR Extension: (lock) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aeblfdkhhhdcdjpifhhbdiojplfjncoa [2024-03-05]
CHR Extension: (PayPal Honey: Automatic Coupons & Cash Back) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2024-02-19]
CHR Extension: (uBlock Origin) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2024-02-26]
CHR Extension: (Videostream for Google Chromecast™) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2020-05-26]
CHR Extension: (Tampermonkey) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2024-01-20]
CHR Extension: (Video Downloader Professional) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2023-04-19]
CHR Extension: (Yoroi) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ffnbelfdoeiohenkjibnmadjiehjhajb [2024-03-20]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-19]
CHR Extension: (Google Docs Offline) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-20]
CHR Extension: (Lightning Extension) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hfglcknhngdnhbkccblidlkljgflofgh [2023-04-25]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2024-03-22]
CHR Extension: (SponsorBlock for YouTube - Skip Sponsorships) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mnjggcdmjocbbbhaepdhchncahnbgone [2024-03-20]
CHR Extension: (Spread3D Review for SketchUp) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ncjkndlllagaajogioiailncjbmbalci [2018-03-13]
CHR Extension: (MetaMask) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn [2024-03-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-03]
CHR Extension: (Amcrest Web View) - C:\Users\Phil\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oddndbjhpcpopbebhonolceinkbnheih [2018-03-13]
CHR Profile: C:\Users\Phil\AppData\Local\Google\Chrome\User Data\System Profile [2024-03-22]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2021-01-09] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
R2 Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed]
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\123.0.6312.16\remoting_host.exe [74016 2024-02-26] (Google LLC -> Google LLC)
R2 com.geocomply.internal-updater-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exe [11492528 2024-02-21] (GeoComply Solutions Inc. -> )
R2 com.geocomply.process-scanner-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe [11494064 2024-02-21] (GeoComply Solutions Inc. -> )
R2 com.geocomply.vm-detector-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exe [11534000 2024-02-21] (GeoComply Solutions Inc. -> )
R2 com.geocomply.wifi-scanner-microservice; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exe [11514544 2024-02-21] (GeoComply Solutions Inc. -> )
S4 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [153328 2015-06-15] (Dell Inc. -> Dell Inc.)
S4 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [119656 2016-01-15] (Dell Inc. -> Dell)
S4 Dell Help & Support; C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe [49864 2015-07-31] (Dell Inc. -> )
S4 Dell Product Registration; C:\Program Files\Dell\Product Registration\PRSvc.exe [32104 2016-01-25] (Dell Inc. -> Dell)
S4 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc. -> Dell Inc.)
R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [43784 2023-09-25] (Intel Corporation -> Intel)
R3 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [240392 2023-11-13] (Intel Corporation -> Intel)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2016-03-04] (Macrovision Europe Ltd.) [File not signed]
R2 FosCloudSvr; C:\Program Files (x86)\IPCWebComponents\IPCPlgSvr.exe [91776 2016-12-26] (ShenZhen Foscam Intelligent Technology Co,Ltd -> )
S2 GoogleUpdaterInternalService124.0.6359.0; C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
S2 GoogleUpdaterService124.0.6359.0; C:\Program Files (x86)\Google\GoogleUpdater\124.0.6359.0\updater.exe [4749088 2024-03-15] (Google LLC -> Google LLC)
S3 Intel® Security Assist; C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S3 Intel® WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [396992 2015-07-06] (Intel® Wireless Display -> Intel)
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
S4 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [11072008 2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9343840 2023-12-20] (Malwarebytes Inc. -> Malwarebytes)
S3 MSIInstallManager; C:\Program Files (x86)\Array Networks\MPMSIInstallManager\MSIInstallManager.exe [723896 2020-01-17] (Array Networks, Inc. -> TODO: <Company name>)
S3 MsMpiLaunchSvc; C:\Program Files\Microsoft MPI\Bin\msmpilaunchsvc.exe [23040 2016-03-04] () [File not signed]
R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [479128 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvdmig.inf_amd64_75c152d756d851ed\Display.NvContainer\NVDisplay.Container.exe [1274888 2023-11-10] (NVIDIA Corporation -> NVIDIA Corporation)
R2 Player Location Check; C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe [11440816 2024-02-21] (GeoComply Solutions Inc. -> )
R2 PrivateInternetAccessService; C:\Program Files\Private Internet Access\pia-service.exe [1394400 2024-03-05] (Private Internet Access, Inc. -> )
S3 PrivateInternetAccessWireguard; C:\Program Files\Private Internet Access\pia-wgservice.exe [4455000 2024-03-05] (Private Internet Access, Inc. -> )
S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [572824 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
R2 SQLTELEMETRY; C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlceip.exe [246672 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [21242680 2024-02-19] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 VPNInstallManager; C:\Program Files\Array Networks\Install Manager\VPNInstallManager.exe [1418168 2020-01-17] (Array Networks, Inc. -> Array Networks)
R2 VPNService; C:\Program Files\Array Networks\SSL VPN Client\VPNService.exe [2422200 2020-01-17] (Array Networks, Inc. -> Array Networks)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\NisSrv.exe [3191272 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe [133688 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BEHRINGER_2902; C:\WINDOWS\System32\Drivers\BUSB2902.sys [460864 2009-10-30] (Ploytec GmbH -> BEHRINGER)
S3 BUSB_AUDIO_WDM; C:\WINDOWS\system32\drivers\busbwdm.sys [49728 2009-10-30] (Ploytec GmbH -> BEHRINGER)
S3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [41608 2018-02-10] (Techporch Incorporated -> Dell Inc.)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-02-10] (Techporch Incorporated -> Dell Computer Corporation)
R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [19440 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> OSR Open Systems Resources, Inc.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 fl2000; C:\WINDOWS\System32\drivers\fl2000.sys [205944 2017-11-23] (Fresco Logic Inc -> Fresco Logic)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-04-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-03-20] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MpKsle97ab441; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{110A3399-A146-497C-9C3E-B03B9E7C9505}\MpKslDrv.sys [300312 2024-03-22] (Microsoft Windows -> Microsoft Corporation)
R2 NPF; C:\Program Files (x86)\Batch Configuration\npf64.sys [36600 2019-05-20] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S4 RsFx0501; C:\WINDOWS\System32\DRIVERS\RsFx0501.sys [261784 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [27744 2021-03-09] (Daniel Terhell -> Resplendence Software Projects Sp.)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [18160 2023-08-25] (RealDefense, LLC -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [15600 2023-08-25] (RealDefense, LLC -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [315904 2023-12-13] (Microsoft Windows -> Microsoft Corporation)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 tap-pia-0901; C:\WINDOWS\System32\drivers\tap-pia-0901.sys [39944 2020-12-01] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2017-12-27] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 tapwindscribe0901; C:\WINDOWS\System32\drivers\tapwindscribe0901.sys [54896 2017-09-13] (Windscribe Limited -> The OpenVPN Project)
R1 UimBus; C:\WINDOWS\System32\drivers\UimBus.sys [102576 2015-11-10] (Paragon Software GmbH -> )
R1 Uim_DEVIM; C:\WINDOWS\System32\drivers\uim_devim.sys [25904 2015-11-10] (Paragon Software GmbH -> )
R1 Uim_IM; C:\WINDOWS\System32\drivers\uim_im.sys [701360 2015-11-10] (Paragon Software GmbH -> )
S3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [212056 2015-07-06] (Intel® Wireless Display -> Windows ® Win 7 DDK provider)
R1 veracrypt; C:\WINDOWS\System32\drivers\veracrypt.sys [831616 2021-01-03] (IDRIX SARL -> IDRIX)
R1 vpntdi; C:\WINDOWS\System32\drivers\vpntdi64.sys [65360 2017-12-13] (Array Networks, Inc. -> Array Networks)
S3 vpnva; C:\WINDOWS\System32\drivers\vpnva64-6.sys [52592 2016-02-29] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
R0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20928 2024-03-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [603416 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105752 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
R3 WinDriver6; C:\WINDOWS\system32\drivers\windrvr6.sys [285696 2007-06-17] (Microsoft Windows Hardware Compatibility Publisher -> Jungo)
S3 ysusb_w10_64; C:\WINDOWS\system32\drivers\ysusb_w10_64.sys [181784 2023-02-10] (Microsoft Windows Hardware Compatibility Publisher -> Yamaha Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2024-03-22 13:18 - 2024-03-22 15:22 - 000010411 _____ C:\Users\Phil\Downloads\Fixlog.txt
2024-03-22 13:17 - 2024-03-22 13:17 - 002391040 _____ (Farbar) C:\Users\Phil\Downloads\FRST64.exe
2024-03-22 13:06 - 2024-03-22 13:13 - 000000000 ___RD C:\Users\Phil\Downloads\RevoUninstaller_Portable
2024-03-22 08:44 - 2024-03-22 08:45 - 009033217 _____ C:\Users\Phil\Downloads\RevoUninstaller_Portable.zip
2024-03-21 13:23 - 2024-03-21 13:25 - 000144880 _____ C:\Users\Phil\Downloads\Addition.txt
2024-03-21 13:22 - 2024-03-22 15:39 - 000038482 _____ C:\Users\Phil\Downloads\FRST.txt
2024-03-21 13:22 - 2024-03-22 13:17 - 000000000 ____D C:\Users\Phil\Downloads\FRST-OlderVersion
2024-03-21 12:19 - 2024-03-21 12:19 - 000003846 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2024-03-21 12:19 - 2024-03-21 12:19 - 000003404 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2024-03-21 12:17 - 2024-03-21 12:17 - 000005196 _____ C:\Users\Phil\Desktop\edetscan.txt
2024-03-21 10:52 - 2024-03-21 10:56 - 000001336 _____ C:\Users\Phil\Desktop\ESET Online Scanner.lnk
2024-03-21 10:50 - 2024-03-21 10:56 - 000001442 _____ C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2024-03-21 10:50 - 2024-03-21 10:50 - 008389496 _____ (ESET) C:\Users\Phil\Desktop\esetonlinescanner.exe
2024-03-21 10:50 - 2024-03-21 10:50 - 000000000 ____D C:\Users\Phil\AppData\Local\ESET
2024-03-21 08:09 - 2024-03-21 08:09 - 159651974 _____ C:\Users\Phil\Downloads\VOCALS-3-20.zip
2024-03-21 08:09 - 2024-03-21 08:09 - 000000000 ____D C:\Users\Phil\Downloads\VOCALS-3-20
2024-03-20 21:24 - 2024-03-22 15:39 - 000000000 ____D C:\FRST
2024-03-20 19:46 - 2024-03-20 19:46 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2024-03-20 17:37 - 2024-03-20 17:37 - 000001463 _____ C:\Users\Phil\Desktop\Roblox Player.lnk
2024-03-17 11:07 - 2024-03-17 11:07 - 000001138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Private Internet Access.lnk
2024-03-15 20:50 - 2024-03-18 10:46 - 000001989 _____ C:\Users\Phil\Desktop\dydx.txt
2024-03-14 20:33 - 2024-03-14 20:33 - 000002302 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2024-03-14 20:33 - 2024-03-14 20:33 - 000002290 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
2024-03-14 20:33 - 2024-03-14 20:33 - 000000000 ____D C:\Program Files\Google
2024-03-13 23:05 - 2024-03-13 23:05 - 000000000 ____D C:\Users\Phil\AppData\Roaming\ReAmp Studio R1
2024-03-13 19:50 - 2024-03-13 19:50 - 000019530 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-03-13 19:50 - 2024-03-13 19:50 - 000019530 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2024-03-13 19:44 - 2024-03-13 19:44 - 000000000 ___HD C:\$WinREAgent
2024-03-12 14:23 - 2024-03-22 13:11 - 000000000 ____D C:\Users\Phil\AppData\Local\Mozilla Firefox
2024-03-11 14:38 - 2024-03-11 14:38 - 000000030 _____ C:\Users\Phil\Documents\roto tom tunings.txt
2024-03-06 18:10 - 2024-03-20 17:38 - 000002425 _____ C:\WINDOWS\system32\default_error_stack-000000-000000.txt
2024-03-04 14:15 - 2024-03-04 14:15 - 000000920 _____ C:\Users\Public\Desktop\TeamViewer.lnk
2024-03-01 17:34 - 2024-03-01 17:35 - 398253515 _____ C:\Users\Phil\Downloads\044Dry_Stems.zip
2024-03-01 17:28 - 2024-03-01 17:34 - 000000000 ____D C:\Users\Phil\Downloads\044Dry_Stems
2024-02-27 16:04 - 2024-02-27 16:04 - 000214867 _____ C:\Users\Phil\Desktop\blank travel sheet (1).odt
2024-02-21 18:31 - 2024-02-21 18:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon
2024-02-21 18:31 - 2024-02-21 18:31 - 000000000 ____D C:\Program Files\LatencyMon
2024-02-21 18:31 - 2021-03-09 16:07 - 000027744 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspLLL64.sys
2024-02-21 18:30 - 2024-02-21 18:30 - 003478312 _____ (Resplendence Software Projects Sp. ) C:\Users\Phil\Desktop\LatencyMon.exe
2024-02-21 12:35 - 2024-02-22 16:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\H&R Block 2023
2024-02-21 12:35 - 2024-02-22 16:32 - 000000000 ____D C:\Program Files (x86)\HRBlock2023
2024-02-21 12:35 - 2024-02-21 12:35 - 000000000 ____D C:\Users\Phil\Documents\HRBlock
2024-02-21 12:35 - 2024-02-21 12:35 - 000000000 ____D C:\Program Files (x86)\PDF995
2024-02-21 08:25 - 2024-02-21 08:25 - 000003442 _____ C:\WINDOWS\system32\Tasks\GeoComply Update Task
2024-02-21 08:25 - 2024-02-21 08:25 - 000003212 _____ C:\WINDOWS\system32\Tasks\GeoComply Service Check
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2024-03-22 15:38 - 2020-08-30 06:22 - 001007224 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-03-22 15:38 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2024-03-22 15:34 - 2024-01-16 01:52 - 000008192 ___SH C:\DumpStack.log.tmp
2024-03-22 15:34 - 2023-10-28 09:21 - 000000000 ____D C:\Program Files\TeamViewer
2024-03-22 15:34 - 2020-08-30 06:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-03-22 15:34 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2024-03-22 15:34 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-03-22 15:34 - 2019-12-07 05:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2024-03-22 15:34 - 2017-07-29 22:04 - 000000000 ____D C:\ProgramData\NVIDIA
2024-03-22 15:34 - 2016-03-03 23:10 - 000000000 __SHD C:\Users\Phil\IntelGraphicsProfiles
2024-03-22 15:22 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-03-22 14:46 - 2016-07-16 12:01 - 000000000 ____D C:\Users\Phil\AppData\LocalLow\Temp
2024-03-22 14:36 - 2023-09-30 19:04 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Microsoft\Windows NT
2024-03-22 14:36 - 2020-08-30 06:18 - 000000000 ____D C:\WINDOWS\system32\Tasks\Intel
2024-03-22 13:17 - 2016-03-04 12:29 - 000000000 ____D C:\Users\Phil\AppData\Local\ClassicShell
2024-03-22 13:14 - 2020-08-30 06:11 - 000000000 ____D C:\Users\SQLTELEMETRY
2024-03-22 13:14 - 2020-08-30 06:11 - 000000000 ____D C:\Users\MSSQLSERVER
2024-03-22 13:14 - 2020-08-30 06:10 - 005460464 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-03-22 13:11 - 2023-10-12 08:14 - 000000000 ____D C:\ProgramData\PreSonus
2024-03-22 13:11 - 2023-10-12 08:07 - 000000000 ____D C:\Users\Phil\AppData\Roaming\PreSonus
2024-03-22 13:05 - 2024-01-30 23:33 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Celemony Software GmbH
2024-03-22 11:26 - 2020-08-30 06:10 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-03-22 09:18 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-03-22 09:18 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-03-22 07:08 - 2018-05-24 16:35 - 000000000 ____D C:\Users\Phil\AppData\Local\D3DSCache
2024-03-22 01:38 - 2023-10-11 15:09 - 000000000 ____D C:\Program Files\RUXIM
2024-03-21 14:54 - 2020-02-25 14:30 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Ledger Live
2024-03-21 11:29 - 2023-08-16 12:46 - 000000000 ____D C:\Users\Phil\AppData\Local\Zoom
2024-03-21 11:18 - 2023-09-30 18:12 - 000000000 ____D C:\ProgramData\regid.1993-06.com.microsoft
2024-03-21 10:55 - 2016-03-06 12:38 - 000000000 ____D C:\Users\Phil\AppData\Local\CrashDumps
2024-03-21 10:44 - 2023-09-25 15:46 - 000000000 ____D C:\Program Files\Common Files\VST3
2024-03-21 10:42 - 2018-05-19 16:26 - 000000000 ____D C:\ProgramData\Adobe
2024-03-21 10:40 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2024-03-21 10:40 - 2016-03-04 15:54 - 000000000 ____D C:\Program Files\Microsoft Office
2024-03-21 10:40 - 2015-10-30 05:07 - 000000000 ____D C:\WINDOWS\ShellNew
2024-03-21 10:39 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files\Common Files\System
2024-03-21 10:39 - 2015-07-10 07:04 - 000000076 _____ C:\WINDOWS\win.ini
2024-03-21 10:38 - 2017-07-09 20:59 - 000000000 ____D C:\Users\Public\Documents\Adobe
2024-03-21 10:38 - 2017-07-09 20:49 - 000000000 ____D C:\Program Files\Common Files\Adobe
2024-03-21 10:37 - 2017-07-09 20:49 - 000000000 ____D C:\Program Files\Adobe
2024-03-20 23:53 - 2016-03-04 01:48 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-03-20 23:49 - 2016-03-04 01:48 - 190470136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-03-20 20:59 - 2023-09-25 15:13 - 000000000 ____D C:\Users\Phil\AppData\Local\Malwarebytes
2024-03-20 20:07 - 2017-08-20 22:15 - 000002370 ____H C:\Users\Phil\Documents\Default.rdp
2024-03-20 20:01 - 2019-12-07 05:50 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2024-03-20 20:00 - 2023-01-29 12:31 - 000000000 ____D C:\Users\Phil\Desktop\Desktop icons
2024-03-20 19:47 - 2015-12-11 11:58 - 000000000 ____D C:\ProgramData\Package Cache
2024-03-20 19:46 - 2017-07-29 22:03 - 000000000 ____D C:\Program Files (x86)\Intel
2024-03-20 18:56 - 2024-02-16 10:36 - 000000000 ____D C:\Users\Phil\AppData\Local\central-updater
2024-03-20 18:56 - 2024-02-16 10:21 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Waves Central
2024-03-20 17:45 - 2024-02-07 10:57 - 000000000 ____D C:\Users\Phil\AppData\Roaming\OracleJDK
2024-03-20 17:37 - 2023-06-08 17:28 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2024-03-19 19:39 - 2021-12-15 03:44 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-03-19 19:39 - 2020-04-10 21:15 - 000000000 ____D C:\Users\Phil\AppData\Roaming\qBittorrent
2024-03-19 19:39 - 2016-03-04 12:41 - 000002340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-03-19 19:39 - 2016-03-04 12:41 - 000002299 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-03-19 13:51 - 2023-06-12 13:02 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-03-19 08:11 - 2023-06-12 13:02 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2024-03-19 08:10 - 2023-06-12 13:02 - 000001325 _____ C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-03-17 20:40 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2024-03-17 16:08 - 2016-03-04 16:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Microsoft\Word
2024-03-17 15:36 - 2016-03-05 11:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\Microsoft\Excel
2024-03-17 11:43 - 2016-03-05 18:03 - 000000000 ____D C:\Users\Phil\AppData\Roaming\vlc
2024-03-17 11:07 - 2020-12-03 18:58 - 000000000 ____D C:\Program Files\Private Internet Access
2024-03-16 06:53 - 2020-07-04 03:13 - 000002479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-03-15 20:51 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-03-15 20:51 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\servicing
2024-03-13 19:50 - 2020-08-30 06:16 - 003017216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-03-13 12:45 - 2023-10-12 08:15 - 000000000 ____D C:\Users\Phil\Documents\Studio One
2024-03-13 01:00 - 2018-02-28 15:34 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-03-06 00:47 - 2020-08-30 06:18 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-03-06 00:47 - 2020-08-30 06:18 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-03-03 02:16 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2024-03-02 06:59 - 2016-03-11 21:24 - 000000000 ____D C:\Users\Phil\AppData\Local\ElevatedDiagnostics
2024-02-28 14:32 - 2021-10-17 15:01 - 000000000 ____D C:\Program Files\Ledger Live
2024-02-21 12:35 - 2019-02-16 15:06 - 000000000 ____D C:\Users\Phil\AppData\Roaming\TaxCut
2024-02-21 12:35 - 2019-02-16 15:05 - 000000000 ____D C:\ProgramData\TaxCut
 
==================== Files in the root of some directories ========
 
2018-09-27 10:57 - 2018-09-27 10:57 - 000000000 _____ () C:\Users\Phil\AppData\Local\oobelibMkey.log
2016-10-27 20:51 - 2022-03-02 21:50 - 000007589 _____ () C:\Users\Phil\AppData\Local\Resmon.ResmonCfg
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22.03.2024
Ran by Phil (22-03-2024 15:39:59)
Running from C:\Users\Phil\Downloads
Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) (2020-08-30 10:18:48)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-1483475722-1219764467-3277934236-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1483475722-1219764467-3277934236-503 - Limited - Disabled)
Guest (S-1-5-21-1483475722-1219764467-3277934236-501 - Limited - Enabled)
Phil (S-1-5-21-1483475722-1219764467-3277934236-1001 - Administrator - Enabled) => C:\Users\Phil
WDAGUtilityAccount (S-1-5-21-1483475722-1219764467-3277934236-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov)
Active Directory Authentication Library for SQL Server (HKLM\...\{4EE99065-01C6-49DD-9EC6-E08AA5B13491}) (Version: 14.0.1000.169 - Microsoft Corporation)
Add or Remove Adobe Creative Suite 3 Master Collection (HKLM-x32\...\Adobe_4dcfd9b7e901b57f81f667144603236) (Version: 1.0 - Adobe Systems Incorporated)
adobe (HKLM\...\{20FD3B0E-D450-488F-AB68-7DA0EC0E4913}) (Version: 1.0.0000 - Adobe Systems Incorporated) Hidden
Adobe After Effects CS3 Presets (HKLM-x32\...\{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}) (Version: 8 - Adobe Systems Incorporated) Hidden
Adobe Anchor Service CS3 (HKLM-x32\...\{90176341-0A8B-4CCC-A78D-F862228A6B95}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Asset Services CS3 (HKLM-x32\...\{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}) (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe Audition CC 2017 (HKLM-x32\...\AUDT_10_1_1) (Version: 10.1.1 - Adobe Systems Incorporated)
Adobe Bridge CS3 (HKLM-x32\...\{9C9824D9-9000-4373-A6A5-D0E5D4831394}) (Version: 2 - Adobe Systems Incorporated) Hidden
Adobe Bridge Start Meeting (HKLM-x32\...\{08B32819-6EEF-4057-AEDA-5AB681A36A23}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe BridgeTalk Plugin CS3 (HKLM-x32\...\{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Camera Raw 4.0 (HKLM-x32\...\{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}) (Version: 4.0 - Adobe Systems Incorporated) Hidden
Adobe CMaps (HKLM-x32\...\{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color - Photoshop Specific (HKLM-x32\...\{A2D81E70-2A98-4A08-A628-94388B063C5E}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color Common Settings (HKLM-x32\...\{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color EU Extra Settings (HKLM-x32\...\{51846830-E7B2-4218-8968-B77F0FF475B8}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color JA Extra Settings (HKLM-x32\...\{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Color NA Recommended Settings (HKLM-x32\...\{95655ED4-7CA5-46DF-907F-7144877A32E5}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Creative Suite 3 Master Collection (HKLM-x32\...\{8718DC03-D066-4957-94E5-50C3C5042E8E}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Default Language CS3 (HKLM-x32\...\{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Device Central CS3 (HKLM-x32\...\{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe ExtendScript Toolkit 2 (HKLM-x32\...\{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}) (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Extension Manager CS3 (HKLM-x32\...\{BE5F3842-8309-4754-92D5-83E02E6077A3}) (Version: 1.8 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 9 ActiveX (HKLM-x32\...\{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}) (Version: 9.0.45.0 - Adobe Systems, Inc.)
Adobe Flash Player 9 Plugin (HKLM-x32\...\{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}) (Version: 9.0.45.0 - Adobe Systems, Inc.)
Adobe Fonts All (HKLM-x32\...\{6ABE0BEE-D572-4FE8-B434-9E72A289431B}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Help Viewer CS3 (HKLM-x32\...\{7ACFB90E-8FD0-4397-AD3A-5195412623A3}) (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe InDesign CS3 Icon Handler (HKLM-x32\...\{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}) (Version: 5.0 - Adobe Systems Incorporated) Hidden
Adobe Linguistics CS3 (HKLM-x32\...\{54793AA1-5001-42F4-ABB6-C364617C6078}) (Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe MotionPicture Color Files (HKLM-x32\...\{6B708481-748A-4EB4-97C1-CD386244FF77}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe PDF Library Files (HKLM-x32\...\{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}) (Version: 8.0 - Adobe Systems Incorporated) Hidden
Adobe Setup (HKLM-x32\...\{4458C442-7376-4CF9-AF58-E8CEA6722363}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe SING CS3 (HKLM-x32\...\{B671CBFD-4109-4D35-9252-3062D3CCB7B2}) (Version: 0.1 - Adobe Systems Incorporated) Hidden
Adobe Stock Photos CS3 (HKLM-x32\...\{29E5EA97-5F74-4A57-B8B2-D4F169117183}) (Version: 1.5 - Adobe Systems Incorporated) Hidden
Adobe Type Support (HKLM-x32\...\{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Update Manager CS3 (HKLM-x32\...\{E69AE897-9E0B-485C-8552-7841F48D42D8}) (Version: 5.1.0 - Adobe Systems Incorporated) Hidden
Adobe Version Cue CS3 Client (HKLM-x32\...\{D0DFF92A-492E-4C40-B862-A74A173C25C5}) (Version: 3 - Adobe Systems Incorporated) Hidden
Adobe Video Profiles (HKLM-x32\...\{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe WAS CS3 (HKLM-x32\...\{C5BD220A-EFE8-48A5-B70E-9503D535FACE}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe WinSoft Linguistics Plugin (HKLM-x32\...\{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe XMP DVA Panels CS3 (HKLM-x32\...\{0224CACC-994D-45F8-B973-D65056EA9C2F}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe XMP Panels CS3 (HKLM-x32\...\{D5A31AB1-345D-47C7-A87B-036A669F6DF1}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
AHV content for Acrobat and Flash (HKLM-x32\...\{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}) (Version: 1 - Adobe Systems Incorporated) Hidden
Amazon.com Fire_Devices (HKLM\...\Fire_Devices Drivers) (Version: 2 - Amazon.com)
ANT Drivers Installer x64 (HKLM\...\{CBEE7F70-D77E-46DB-BB02-B64147DD6453}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Batch Configuration (HKLM-x32\...\{F9F88CAE-A8BB-493A-BC71-B19A8BA38613}) (Version: 3.0.2.6 - hikvision)
BEHRINGER USB AUDIO DRIVER (HKLM\...\USB_AUDIO_DEusb-audio.deBehringer2902) (Version:  - )
Browser for SQL Server 2017 (HKLM-x32\...\{CF8EEB96-E7E7-4EF7-A0A1-559F09953156}) (Version: 14.0.1000.169 - Microsoft Corporation)
Bruteforce Save Data (HKLM-x32\...\Bruteforce Save Data) (Version:  - )
Calibration Update Wizard (HKLM-x32\...\{5A03CEC0-8805-11D4-ADFB-00000EFB3A77}) (Version: 8.20.1 - Toyota Diagnostics)
Celemony Melodyne 5 (HKLM\...\Celemony Melodyne 5_is1) (Version: 5.3.1.018 - Celemony)
Charter TV Player (HKLM-x32\...\{076af162-8f4c-4e36-9013-1673e5cf4d24}) (Version: 6.6 - Charter)
Chrome Remote Desktop Host (HKLM-x32\...\{00B18403-87DD-4C4E-AEB5-045B05B96F35}) (Version: 123.0.6312.16 - Google LLC)
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 4.4.03034 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\{EB629A98-5E69-40E8-BA9E-C393899F959D}) (Version: 4.4.03034 - Cisco Systems, Inc.) Hidden
Cisco VideoGuard Player (HKLM-x32\...\{dfc759fd-a56f-4d04-8306-d1480137a065}) (Version: 6.6 - Cisco Systems, Inc)
Cisco Webex Meetings (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\ActiveTouchMeetingClient) (Version: 40.8.5 - Cisco Webex LLC)
Classic Shell (HKLM\...\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft)
Dell Customer Connect (HKLM-x32\...\{99E581C6-471C-46CA-989E-3B17EB7E3F27}) (Version: 1.3.2.0 - Dell Inc.)
Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)
Dell Foundation Services (HKLM\...\{AE5E3C86-2633-4DAF-A7F4-C43D1E738BAE}) (Version: 3.1.3300.0 - Dell Inc.)
Dell Help & Support (HKLM\...\{9ACDDC24-55FE-4E7A-B4BD-DD9761F2F8AB}) (Version: 2.0.360.0 - Dell Inc.) Hidden
Dell Help & Support (HKLM-x32\...\InstallShield_{9ACDDC24-55FE-4E7A-B4BD-DD9761F2F8AB}) (Version: 2.0.360.0 - Dell Inc.)
Dell Update (HKLM-x32\...\{DB82968B-57A4-4397-81A5-ECAB21B5DFCD}) (Version: 1.7.1015.0 - Dell Inc.)
Documentation Manager (HKLM\...\{E904139A-DC55-420D-94C7-5D6297F3C385}) (Version: 23.30.0.6 - Intel Corporation) Hidden
Elevated Installer (HKLM-x32\...\{0F6C59A2-5F1D-4D7C-BC90-A0A1A75F4EE9}) (Version: 7.7.1.0 - Garmin Ltd or its subsidiaries) Hidden
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 8.1.4.1208 - Foxit Software Inc.)
Fresco Logic USB Display Driver (HKLM\...\{FC11E022-A625-48EA-85EB-AF2AFEF05B06}) (Version: 2.1.34054.0 - Fresco Logic)
Garmin Express (HKLM-x32\...\{50DF005C-1D2C-467A-A39E-10ADEFA83A96}) (Version: 7.7.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{9e0ef45d-b10c-42da-9aab-16200df39d95}) (Version: 7.7.1.0 - Garmin Ltd or its subsidiaries)
GDR 2002 for SQL Server 2017 (KB4293803) (64-bit) (HKLM\...\KB4293803) (Version: 14.0.2002.14 - Microsoft Corporation)
GDR 2014 for SQL Server 2017 (KB4494351) (64-bit) (HKLM\...\KB4494351) (Version: 14.0.2014.14 - Microsoft Corporation)
GDR 2027 for SQL Server 2017 (KB4505224) (64-bit) (HKLM\...\KB4505224) (Version: 14.0.2027.2 - Microsoft Corporation)
GDR 2037 for SQL Server 2017 (KB4583456) (64-bit) (HKLM\...\KB4583456) (Version: 14.0.2037.2 - Microsoft Corporation)
GDR 2042 for SQL Server 2017 (KB5014354) (64-bit) (HKLM\...\KB5014354) (Version: 14.0.2042.3 - Microsoft Corporation)
GDR 2047 for SQL Server 2017 (KB5021127) (64-bit) (HKLM\...\KB5021127) (Version: 14.0.2047.8 - Microsoft Corporation)
GDR 2052 for SQL Server 2017 (KB5029375) (64-bit) (HKLM\...\KB5029375) (Version: 14.0.2052.1 - Microsoft Corporation)
Get Good Drums One Kit Wonder - Architects (HKLM-x32\...\Get Good Drums One Kit Wonder - Architects) (Version: 1.0.0.4 - Get Good Drums)
GetGood Drums Smash and Grab 2 (HKLM\...\Smash and Grab 2_is1) (Version: 2.0.0 - GetGood Drums)
Google Chrome (HKLM-x32\...\{93EB1D27-3378-36DD-ACEC-380FEDB2297B}) (Version: 123.0.6312.58 - Google, Inc.)
Google Earth Plug-in (HKLM-x32\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google)
Google Earth Pro (HKLM\...\{3470AD08-85F2-4B1D-8487-FC4750732087}) (Version: 7.3.6.9796 - Google)
H&R Block Massachusetts 2021 (HKLM-x32\...\{482A887B-D7E3-473D-80E2-48FA6F695194}) (Version: 1.21.4201 - H&R Block, Inc.)
H&R Block Massachusetts 2022 (HKLM-x32\...\{4E5723A6-0AA2-4415-AF75-7E2CE63713F7}) (Version: 1.22.6201 - H&R Block, Inc.)
H&R Block Massachusetts 2023 (HKLM-x32\...\{F5FBEE1C-A0E1-4B44-86EE-0BABE29D668C}) (Version: 1.23.8701 - HRB Digital, LLC.)
H&R Block Premium + Efile + State 2021 (HKLM-x32\...\{EDB7F331-6C76-4B85-A8EC-764B213E2E51}) (Version: 21.07.6002 - HRB Technology, LLC.)
H&R Block Premium + Efile + State 2022 (HKLM-x32\...\{69654063-D165-4494-A83B-C09105247E97}) (Version: 22.07.7601 - HRB Technology, LLC.)
H&R Block Premium + Efile + State 2023 (HKLM-x32\...\{B0E2C9A7-F1FC-4376-9E0F-065DC3FAC392}) (Version: 23.07.8301 - HRB Technology, LLC.)
HandBrake 1.0.1 (HKLM-x32\...\HandBrake) (Version: 1.0.1 - )
Intel Driver && Support Assistant (HKLM-x32\...\{63B67EA4-4AE1-4A45-A67D-21318B4345EF}) (Version: 23.4.39.9 - Intel) Hidden
Intel Driver && Support Assistant (HKLM-x32\...\{7D392FB7-64D5-4813-B7F7-8AA462D3968D}) (Version: 23.4.39.9 - Intel) Hidden
Intel Extreme Tuning Utility (HKLM-x32\...\{7afa48c7-9901-40fa-8f9b-f0707e2bc5b6}) (Version: 6.2.0.24 - Intel Corporation)
Intel® Chipset Device Software (HKLM\...\{8C91A5EB-2C62-4A6D-8802-CC79FD2ED390}) (Version: 10.1.1.7 - Intel Corporation) Hidden
Intel® Chipset Device Software (HKLM-x32\...\{60c073df-e736-4210-9c3a-5fc2b651cef3}) (Version: 10.1.1.7 - Intel® Corporation) Hidden
Intel® Computing Improvement Program (HKLM\...\{15E71D2B-4046-4B9D-A8BB-EBFC5CC12D86}) (Version: 2.4.10717 - Intel Corporation)
Intel® Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.2.10900.330 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{5BD7E621-9791-4D9F-A620-1BA51153B749}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{EC465D35-92DC-4DAE-9EA8-01215688F709}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Driver (HKLM\...\{AC411813-5A0B-4960-882D-481BEEDC24E0}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® ME UninstallLegacy (HKLM\...\{E9B9A1A5-6398-4C99-8FDE-10794F6505C5}) (Version: 1.0.1.0 - Intel Corporation) Hidden
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.6859 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.16.1063 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{9503AD68-6198-4081-9F57-1F346D7B58D4}) (Version: 14.8.16.1063 - Intel Corporation) Hidden
Intel® Serial IO (HKLM\...\{51788BA4-D93F-4E7B-BA13-ACC88E7803DB}) (Version: 30.100.1519.07 - Intel Corporation) Hidden
Intel® Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation)
Intel® WiDi (HKLM\...\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation)
Intel® WiDi Software Asset Manager (HKLM-x32\...\{5B5CD20C-29F0-4857-A4FA-A4F4C716B019}) (Version: 1.1.347 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{00000030-0230-1033-84C8-B8D95FA3C8C3}) (Version: 23.30.0.3 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{b82e9573-04fb-4a9d-819f-6c358a1cf31a}) (Version: 23.4.39.9 - Intel)
Intel® Driver & Support Assistant (HKLM-x32\...\{ecbee3cf-26b3-4f27-854c-e2e16b3f7fa9}) (Version: 23.4.39.9 - Intel)
Intel® PROSet/Wireless Software (HKLM-x32\...\{5a64c890-83f9-4399-b0c9-5e9a80890fdd}) (Version: 21.40.1 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{68A981A0-ED59-41E0-B45E-7A78F643120D}) (Version: 21.40.1.3406 - Intel Corporation) Hidden
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Intel® Software Installer (HKLM-x32\...\{ae13aa25-496e-45dc-86f8-939f17f479f4}) (Version: 23.30.0.6 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (HKLM\...\{7D84E343-A23D-451C-B123-0195B2D903A6}) (Version: 1.42.17.0 - Intel Corporation) Hidden
IPCWebComponents 3.3.0.31 (HKLM-x32\...\{4740E1B2-51CF-4083-8976-D6B3B5A5064F}_is1) (Version: 3.3.0.31 - )
Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Kontakt 7 PORTABLE (HKLM\...\{770F4942-15B1-41AA-9E3E-C77B2CFB1366}_is1) (Version: 7.7.1 - Native Instruments)
LatencyMon 7.31 (HKLM\...\LatencyMon_is1) (Version: 7.31 - Resplendence Software Projects Sp.)
Ledger Live 2.77.2 (HKLM\...\c62032b2-0bca-5abc-b458-fd67cfc9e49b) (Version: 2.77.2 - Ledger Live Team)
Macrium Reflect Free (HKLM\...\{0D4965D1-6B46-4F0A-B42D-B17056612AE0}) (Version: 8.0.7279 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free (HKLM\...\MacriumReflect) (Version: v8.0.7279 - Paramount Software (UK) Ltd.)
Malwarebytes version 4.6.6.294 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.6.294 - Malwarebytes)
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.9060.3 - Waves Audio Ltd.) Hidden
Mazda Toolbox (HKLM-x32\...\Mazda Toolbox) (Version:  - )
Mazda Update Toolbox (HKLM-x32\...\Mazda Update Toolbox) (Version:  - )
MetaTrader 5 (HKLM\...\MetaTrader 5) (Version: 5.00 - MetaQuotes Ltd.)
Microsoft .NET Core Host - 3.1.32 (x64) (HKLM\...\{8A8E3A04-83BC-4CDE-9259-893B666C1AB1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Host FX Resolver - 3.1.32 (x64) (HKLM\...\{ABC6B3C2-1A8D-4C5E-AC16-C2AE44F02743}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM\...\{A741B803-3F0E-4684-81EF-FC128D15A92C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM-x32\...\{784973c8-d618-4ac8-97ed-1fd52c5bdf2f}) (Version: 3.1.32.31915 - Microsoft Corporation)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Analysis Services OLE DB Provider (HKLM\...\{0DAD8F2F-38F2-404F-BB26-3DC89F0B53C5}) (Version: 14.0.1000.397 - Microsoft Corporation) Hidden
Microsoft Analysis Services OLE DB Provider (HKLM-x32\...\{CBB32D14-5E5A-4E4A-8EDF-26586322C9E7}) (Version: 14.0.1000.397 - Microsoft Corporation) Hidden
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Build Tools 14.0 (amd64) (HKLM\...\{8C918E5B-E238-401F-9F6E-4FB84B024CA2}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Build Tools 14.0 (x86) (HKLM-x32\...\{D1437F51-786A-4F57-A99C-F8E94FBA1BD8}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Build Tools Language Resources 14.0 (amd64) (HKLM\...\{4B7958F6-4943-4903-B379-9180DC8C2105}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Build Tools Language Resources 14.0 (x86) (HKLM-x32\...\{A7E88B38-6886-4474-9D85-A8ABE5FCD80E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 122.0.2365.92 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 122.0.2365.92 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\{5730588A-33CA-373C-9D70-F716605B57D2}) (Version: 2.2.23107 - Microsoft Corporation) Hidden
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft MPI (7.0.12437.8) (HKLM\...\{8499ACD3-C1E3-45AB-BF96-DA491727EBE1}) (Version: 7.0.12437.8 - Microsoft Corporation)
Microsoft ODBC Driver 13 for SQL Server (HKLM\...\{436C9D0B-5AD2-4E54-83F0-10B7584A971E}) (Version: 14.0.2052.1 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{4D2C56FF-7F36-4B49-A97A-24F0522D41D7}) (Version: 11.3.6540.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2017 (64-bit) (HKLM\...\Microsoft SQL Server SQL2017) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2017 (HKLM-x32\...\Microsoft SQL Server SQL2017) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2017 Policies  (HKLM-x32\...\{256EDCB9-A64D-433C-A1DC-C76F02475915}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft SQL Server 2017 RsFx Driver (HKLM\...\{D5826833-5FD8-4586-BC42-22E38B15DFA4}) (Version: 14.0.2052.1 - Microsoft Corporation) Hidden
Microsoft SQL Server 2017 Setup (English) (HKLM\...\{2E1F5473-30FC-4D5B-B7F0-8EA51CC3EE81}) (Version: 14.0.2052.1 - Microsoft Corporation)
Microsoft SQL Server 2017 T-SQL Language Service  (HKLM\...\{BC247FE3-C61A-4678-86C6-15408F272D57}) (Version: 14.0.17213.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation) Hidden
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation) Hidden
Microsoft SQL Server Data-Tier Application Framework (x86) (HKLM-x32\...\{F45421F6-76C3-47EE-8823-7D064A77E1F0}) (Version: 14.0.3881.1 - Microsoft Corporation)
Microsoft SQL Server Management Studio - 17.4 (HKLM-x32\...\{ac84c935-8f13-4f73-b541-7b09a11bdea8}) (Version: 14.0.17213.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{718FFB65-F6E4-4D62-861F-ED10ED32C936}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2017 (HKLM\...\{9D78F5D4-79D2-4FC6-AC56-F364A0ABC54F}) (Version: 14.0.1000.169 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Debug Runtime - 12.0.21005 (HKLM\...\{C596D608-3E74-3232-8CA5-DF1DCB9F10DE}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Debug Runtime - 12.0.21005 (HKLM-x32\...\{E5CAE8D2-9F9F-3BEA-AA0F-B5B40611C704}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x64 Debug Runtime - 14.0.23026 (HKLM\...\{B8E14C55-53F6-3693-A74A-77A3C6B96041}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Debug Runtime - 14.0.23026 (HKLM-x32\...\{3CB4E2E8-04EB-371A-9433-4CA0D934B260}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.34.31931 (HKLM-x32\...\{d4cecf3b-b68f-4995-8840-52ea0fab646e}) (Version: 14.34.31931.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.34.31931 (HKLM-x32\...\{6ba9fb5e-8366-4cc4-bf65-25fe9819b2fc}) (Version: 14.34.31931.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.34.31931 (HKLM\...\{EAE242B1-0A26-485A-BFEB-0292EE9F03CB}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.34.31931 (HKLM\...\{CF4C347D-954E-4543-88D2-EC17F07F466F}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.34.31931 (HKLM-x32\...\{C2662EFF-06E6-4FD1-9D6D-FDCA91025757}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.34.31931 (HKLM-x32\...\{AB1BDF73-7393-42CE-812D-9A90918814D5}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}) (Version: 10.0.50908 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2015 Shell (Isolated) (HKLM-x32\...\{6CFDA13E-A348-315B-820A-603BBCBD7684}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Isolated) (HKLM-x32\...\{d2981c27-a434-4c9a-96c7-0209e97c4eac}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Visual Studio 2015 Shell (Isolated) Resources (HKLM-x32\...\{446D0B70-F98E-39DA-9CB5-4201D05A91C6}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Minimum) (HKLM-x32\...\{030A6785-C3A9-37DA-8530-444C320629FA}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Minimum) Interop Assemblies (HKLM-x32\...\{4443D3F4-A231-35CC-8471-CB60F8A3FE3B}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2015 Shell (Minimum) Resources (HKLM-x32\...\{7FF53256-7BAF-3EFA-91B4-DB65F37EB5E9}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Microsoft Visual Studio Services Hub (HKLM-x32\...\{93CC1063-02A1-4F25-A13A-C351A10D84DD}) (Version: 1.0.23107.00 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 (HKLM-x32\...\{ab213ab7-4792-4c6f-a3fa-8485d06c3475}) (Version: 14.0.23829 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 Finalizer (HKLM-x32\...\{F93E37BD-4053-37CA-A7BB-A5B74508006C}) (Version: 14.0.23829 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 Language Support - ENU Language Pack (HKLM-x32\...\{0343F10B-C31B-3A2F-B2C1-C42E84CCAF5E}) (Version: 14.0.23107.20 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 Language Support (HKLM-x32\...\{85CEB20F-C2D6-3FDC-9A9D-5957CD88E9E5}) (Version: 14.0.23107.20 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 Language Support (HKLM-x32\...\{bd4ef7af-dfb1-472e-8fa4-1b97f360a3e7}) (Version: 14.0.23107.20 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 Language Support Finalizer (HKLM-x32\...\{BF6E6B74-88F5-358F-AB6D-0A42C18F2824}) (Version: 14.0.23107.20 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 x64 Hosting Support (HKLM\...\{A8C30947-7C1B-3A31-8FD8-CEC6D3357D34}) (Version: 14.0.23829 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2015 x86 Hosting Support (HKLM-x32\...\{11A9EF3E-6616-31B1-82BC-1080366FA34D}) (Version: 14.0.23829 - Microsoft Corporation) Hidden
Microsoft VSS Writer for SQL Server 2017 (HKLM\...\{20B328C9-C6BB-434A-928A-00F05CD820B8}) (Version: 14.0.1000.169 - Microsoft Corporation)
MotionPro (HKLM\...\MotionPro VPN Client) (Version: 9.4.0.0 - Array Networks)
Mozilla Firefox (x64 en-US) (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\Mozilla Firefox 123.0.1 (x64 en-US)) (Version: 123.0.1 - Mozilla)
MyHarmony (HKLM-x32\...\{2AD8F8A1-ECE5-4890-BCC2-B4396370A0D4}) (Version: 1.0.308 - Logitech)
NVIDIA Graphics Driver 546.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 546.17 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
OSCAR (HKLM\...\{FC6F08E6-69BF-4469-ADE3-78199288D305}_is1) (Version: 1.5.1-Win64-dd495e23 - The OSCAR Team)
Paragon Hard Disk Manager™ 15 Suite (HKLM\...\{29258311-EA49-11DE-967C-005056C00008}) (Version: 90.00.0003 - Paragon Software)
PdaNet+ for Android 4.18 (HKLM-x32\...\PdaNet_is1) (Version:  - June Fabrics Technology Inc)
PDF Settings (HKLM-x32\...\{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
Player Location Check (HKLM-x32\...\{F0753064-8D66-41A7-9F23-7691290387BF}) (Version: 4.0.0.7 - GeoComply)
Private Internet Access (HKLM\...\{33023371-7761-4F81-BBB1-0E0D0D175ACF}) (Version: 3.5.5+08091 - Private Internet Access, Inc.)
Private Internet Access WinTUN Driver (HKLM\...\{0419A0C0-4CC8-459E-9BAE-F3BF5D2E2CCB}) (Version: 1.0 - Private Internet Access, Inc.) Hidden
Product Registration (HKLM\...\{C1600AC7-74E3-4BB5-8B42-B13653792252}) (Version: 2.2.38.0 - Dell Inc.) Hidden
Product Registration (HKLM-x32\...\InstallShield_{C1600AC7-74E3-4BB5-8B42-B13653792252}) (Version: 2.2.38.0 - Dell Inc.)
Python 3.12.1 (64-bit) (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\{86e52725-ef45-452f-ac4c-b8958718bfea}) (Version: 3.12.1150.0 - Python Software Foundation)
Python 3.12.1 Core Interpreter (64-bit) (HKLM\...\{AC82C1A3-9597-40F2-893D-F02F778FBA4D}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Development Libraries (64-bit) (HKLM\...\{8C53CBDD-4DAF-426F-9478-6C7C2920CDDA}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Documentation (64-bit) (HKLM\...\{62667662-A580-409C-8044-55B06F774AE2}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Executables (64-bit) (HKLM\...\{44BC9F9C-15C2-46C1-B88D-3135A9DA555F}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 pip Bootstrap (64-bit) (HKLM\...\{1662F43B-2337-4FD8-8CE6-BEA38FC94DD4}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Standard Library (64-bit) (HKLM\...\{47957EE3-0E23-4075-B825-F202E913670F}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Tcl/Tk Support (64-bit) (HKLM\...\{926CDC62-3AE2-422B-9858-D6EC3BAD473F}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python 3.12.1 Test Suite (64-bit) (HKLM\...\{E309AE00-4FB1-4817-9172-7E198668375D}) (Version: 3.12.1150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{4C8D4EC3-F620-4CEE-8BAD-B59A3C6815F3}) (Version: 3.12.1150.0 - Python Software Foundation)
qBittorrent 4.3.9 (HKLM-x32\...\qBittorrent) (Version: 4.3.9 - The qBittorrent project)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.5.02 - Dell Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.21289 - Realtek Semiconduct Corp.)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 10.1.505.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8578 - Realtek Semiconductor Corp.)
Roblox Player for Phil (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\roblox-player) (Version:  - Roblox Corporation)
Roslyn Language Services - x86 (HKLM-x32\...\{5B47029B-1E62-30FF-906E-694851C22782}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Roslyn Language Services - x86 (HKLM-x32\...\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
SketchUp 2016 (HKLM\...\{E2B66CF6-ABA0-4E5F-B426-7478B18301AE}) (Version: 16.1.1449 - Trimble Navigation Limited)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
SQL Server 2017 Batch Parser (HKLM\...\{2C6E8311-28BD-4615-9545-6E39E8E83A4B}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Client Tools Extensions (HKLM\...\{06324A5D-66BB-4FAC-8D0B-9FEC1B230FFF}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Client Tools Extensions (HKLM\...\{200F38B2-1492-4576-B08C-78F2C2C953FC}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM\...\{9D1C0509-D490-4E9E-ACF5-A73E5C53742D}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM\...\{B777C4C0-A1CD-4AB9-99B1-AD5FBED6F8E5}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM-x32\...\{6CE9A8AA-C478-4706-BD28-95993D52B5A1}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Common Files (HKLM-x32\...\{D17B5D3D-3BC7-4AFA-AD90-600B5453826E}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Connection Info (HKLM\...\{89A7644F-E056-4EC1-BFDE-9D1A531D6855}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Connection Info (HKLM\...\{A9A443F5-56E1-4FC6-937C-5F481345A843}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Services (HKLM\...\{28EEF6BA-A23A-42D2-86BA-A6BEE723B969}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Services (HKLM\...\{DED314CA-0EFE-4593-9D66-EF75E5289A4C}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Shared (HKLM\...\{0E22DBB4-691B-400C-B52D-8DFE8EC421AA}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Database Engine Shared (HKLM\...\{793F1C1E-5C83-4E33-A29B-6EAA7C1E791C}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 DMF (HKLM\...\{B9998A13-5563-496C-B95E-597FFC70B670}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 DMF (HKLM\...\{D7D28BBF-3B0E-43F0-A457-331F1CD9E9EB}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Integration Services Scale Out Management Portal (HKLM\...\{6BD8D100-B16C-409E-B0EA-BF508D7874EC}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Integration Services Scale Out Management Portal (HKLM\...\{91C5EE43-29D1-4720-AB65-5E2E0FE25990}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Management Studio Extensions (HKLM-x32\...\{6492E746-1C5D-48C2-A92A-97D431F74664}) (Version: 14.0.3006.16 - Microsoft Corporation) Hidden
SQL Server 2017 Management Studio Extensions (HKLM-x32\...\{70C24F35-7E36-45FC-B289-3D2849E5556B}) (Version: 14.0.3006.16 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects (HKLM\...\{10855B1A-F7F2-4D8A-A725-9287C73BED5A}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects (HKLM\...\{6CBBF624-696C-499E-948D-ADBAFFA2F548}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects Extensions (HKLM\...\{8C515C22-BE07-4908-985C-0AA9349E1ED4}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 Shared Management Objects Extensions (HKLM\...\{C6D92730-3EC0-47B1-8F6C-6F5635D1EFAC}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 SQL Diagnostics (HKLM\...\{DFA6A906-3024-49DE-87AD-750EAED2FA49}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 XEvent (HKLM\...\{12D2DB8D-80FF-4152-8F51-EDB3BD3C6976}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server 2017 XEvent (HKLM\...\{AA2A015C-C210-413B-95F6-BF9D3CDD6E0D}) (Version: 14.0.1000.169 - Microsoft Corporation) Hidden
SQL Server Management Studio (HKLM\...\{1B8CFC46-1F08-4DA7-9FEA-E1F523FBD67F}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SQL Server Management Studio (HKLM\...\{F8ADD24D-F2F2-465C-A675-F12FDB70DB82}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SQL Server Management Studio for Analysis Services (HKLM\...\{CC6997A7-1638-4E38-B6CF-E776997036B0}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SQL Server Management Studio for Reporting Services (HKLM\...\{4DDEB555-26D2-4E68-98AF-8F96232C13F2}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SSD Sampler (HKLM-x32\...\SSD4) (Version: 1.1 - Yellow Matter Entertainment)
SSMS Post Install Tasks (HKLM\...\{CFCC9F40-E234-499E-B3DA-BEF6CC724C35}) (Version: 14.0.17213.0 - Microsoft Corporation) Hidden
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 10.0.1256 - SUPERAntiSpyware.com)
TeamViewer (HKLM\...\TeamViewer) (Version: 15.51.5 - TeamViewer)
Techstream Software (HKLM-x32\...\{937CA58A-0212-431C-8F0B-0D8305225476}) (Version: 10.30.029 - DENSO CORPORATION)
Tools for .Net 3.5 (HKLM-x32\...\{1690CE56-2231-4E59-9006-A0876D949EA8}) (Version: 3.11.50727 - Microsoft Corporation) Hidden
Toontrack EZmix 2.2.4 (HKLM\...\EZmix_is1) (Version: 2.2.4 - Toontrack & Team V.R)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{B9A7A138-BFD5-4C73-A269-F78CCA28150E}) (Version: 8.94.0.0 - Microsoft Corporation)
UXP WebView Support (HKLM-x32\...\UXPW_1_1_0) (Version: 1.1.0 - Adobe Inc.)
VeraCrypt (HKLM-x32\...\VeraCrypt) (Version: 1.24-Update7 - IDRIX)
Visual C++ 2008 Runtime (x64) (HKLM-x32\...\{73E80655-FB3C-46F4-BE00-62D248BC490A}) (Version: 1.0.1 - Highresolution Enterprises) Hidden
Visual Studio 2015 Prerequisites - ENU Language Pack (HKLM\...\{83B181F2-20B8-4F00-8E71-C66E951A8D4F}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Visual Studio 2015 Prerequisites (HKLM\...\{DF32E41C-24AD-4A87-B43A-B38553B1806E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.14 - VideoLAN)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Waves Central (HKLM\...\{ab507e17-892b-5203-838d-d58d8d09c50f}) (Version: 14.4.3 - Waves Audio Ltd)
Windows Driver Package - Amazon.com (WinUSB) FireDevicesUsbDeviceClass  (10/27/2014 1.4.0000.00000) (HKLM\...\70D74CAD18BB165614511A2A67DB9EBF036D06A9) (Version: 10/27/2014 1.4.0000.00000 - Amazon.com)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Fresco Logic (fl2000) AVClass  (11/13/2017 2.1.34054.0) (HKLM\...\02B94313A3DAF5BA27BCC4FAEA0716A0F660086C) (Version: 11/13/2017 2.1.34054.0 - Fresco Logic)
Windows Driver Package - Fresco Logic (lci_proxykmd) System  (11/13/2017 2.1.34054.0) (HKLM\...\7C22E1F94C4AE5334C0BEE70551B20BEE3C293FA) (Version: 11/13/2017 2.1.34054.0 - Fresco Logic)
Windows Driver Package - Fresco Logic (WUDFRd) Display  (11/13/2017 2.1.34054.0) (HKLM\...\9328342CF3E5994E24BB0C09FBD875141BEF3984) (Version: 11/13/2017 2.1.34054.0 - Fresco Logic)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
XLN Online Installer (HKLM\...\XLN Online Installer Inno Setup ID_is1) (Version:  - )
X-Mouse Button Control 2.10.2 (HKLM-x32\...\X-Mouse Button Control) (Version: 2.10.2 - Highresolution Enterprises)
Yamaha Steinberg USB Driver (HKLM\...\{E2AEA639-BFC7-4A6E-A9F3-EB11B60C2F33}) (Version: 2.1.5 - Yamaha Corporation) Hidden
Yamaha Steinberg USB Driver (HKLM-x32\...\yUninstall_{2938B185-2D57-47B0-9FC8-C90A67BA9277}) (Version: 2.1.5 - Yamaha Corporation)
YubiKey Manager (HKLM-x32\...\yubikey-manager) (Version: 1.1.5 - Yubico AB)
Zoom (HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\ZoomUMX) (Version: 5.15.7 (20303) - Zoom Video Communications, Inc.)
 
Packages:
=========
 
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.264.100.0_x64__kgqvnymyfvs32 [2024-03-22] (king.com)
Dell Shop -> C:\Program Files\WindowsApps\DellInc.DellShop_2.2.1.0_neutral__htrsf667h5kn2 [2021-04-17] (Dell Inc)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_152.1.1099.0_x64__v10z8vjag6ke6 [2024-03-10] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Movie Maker - Video Editor -> C:\Program Files\WindowsApps\21336V3TApps.MovieMaker-FREE_3.6.46.0_x64__bzg06mxvgh4fa [2024-03-10] (V3TApps)
MyIPTV Player -> C:\Program Files\WindowsApps\41879VbfnetApps.MyIPTVPlayer_4.8.2.0_x64__7casf8sqhfy78 [2023-11-02] (Vbfnet Apps) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.964.0_x64__56jybvy8sckqj [2023-11-18] (NVIDIA Corp.)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-05-08] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-12-19] (Microsoft Corporation)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.19.1262.0_x64__8wekyb3d8bbwe [2024-02-08] (Microsoft Studios) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2021-06-10] (Twitter Inc.)
WinDbg -> C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe [2024-03-08] (Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{1019ADC7-17CB-4489-AFD5-6642C7400ACE}\localserver32 -> C:\Users\Phil\AppData\Local\Webex\Webex\Applications\ptOIEx64.exe (Cisco WebEx LLC -> Cisco WebEx LLC)
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
CustomCLSID: HKU\S-1-5-21-1483475722-1219764467-3277934236-1001_Classes\CLSID\{BEA218D2-6950-497B-9434-61683EC065FE}\InprocServer32 -> C:\Users\Phil\AppData\Local\Programs\Python\Launcher\pyshellext.amd64.dll (Python Software Foundation -> Python Software Foundation)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ContextMenuHandlers1: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\ConvertToPDFShellExtension_x64.dll [2016-11-14] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-01-10] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-04-12] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igfxDTCM.dll [2019-06-13] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvdmig.inf_amd64_75c152d756d851ed\nvshext.dll [2023-11-10] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-18] (Adobe Inc. -> )
ContextMenuHandlers6: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\ConvertToPDFShellExtension_x64.dll [2016-11-14] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-04-12] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\System32\StartMenuHelper64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Amcrest Web View.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory="Profile 1" --app-id=oddndbjhpcpopbebhonolceinkbnheih
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory="Profile 1" --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Videostream for Google Chromecast™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory="Profile 1" --app-id=cnciopoikihiagdjbjpnocolokfelagl
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\e895024b613704\MetaMask.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=nkbihfbeogaeaoehlefnkodbefgpgknn
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\72dad8f9fb5925df\Data Scraper - Easy Web Scraping.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=nndknepjnldbdbepjfgmncbggmopgden
ShortcutWithArgument: C:\Users\Phil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
 
==================== Loaded Modules (Whitelisted) =============
 
2016-03-04 12:42 - 2019-02-21 12:00 - 000078336 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2017-08-13 09:49 - 2017-08-13 09:49 - 003664184 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenuDLL.dll
2017-08-13 09:49 - 2017-08-13 09:49 - 000291128 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\WINDOWS\System32\StartMenuHelper64.dll
2024-01-05 18:19 - 2024-01-05 18:19 - 002973696 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll
2015-08-01 22:19 - 2015-08-01 22:19 - 000541448 ____R (Waves Inc -> Waves Audio) [File not signed] C:\WINDOWS\SYSTEM32\MaxxAudioIntelSkylake64.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell15.msn.com/?pc=DCTE
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://192.168.1.90:1829/
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://192.168.1.85:85/
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2024-03-22 14:36 - 2024-03-22 14:36 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1       localhost
 
2019-10-23 10:26 - 2020-03-13 23:45 - 000000440 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Microsoft MPI\Bin\;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT;C:\Program Files\Intel\Intel® Management Engine Components\IPT;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Microsoft SQL Server\Client SDK\ODBC\130\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\140\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\140\DTS\Binn\;C:\Program Files (x86)\Microsoft SQL Server\140\Tools\Binn\ManagementStudio\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\130\Tools\Binn\;C:\Program Files\Microsoft SQL Server\140\Tools\Binn\;C:\Program Files\Microsoft SQL Server\140\DTS\Binn\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files\dotnet\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%AppData%\Programs\Python\Python311;%AppData%\Programs\Python\Python311\Scripts;
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Phil\Pictures\20201114_122903.jpg
HKU\S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
MSCONFIG\Services: !SASCORE => 2
MSCONFIG\Services: 0008811457109852mcinstcleanup => 2
MSCONFIG\Services: dbupdate => 2
MSCONFIG\Services: dbupdatem => 3
MSCONFIG\Services: Dell Customer Connect => 2
MSCONFIG\Services: Dell Foundation Services => 2
MSCONFIG\Services: Dell Hardware Support => 2
MSCONFIG\Services: Dell Help & Support => 2
MSCONFIG\Services: Dell Product Registration => 2
MSCONFIG\Services: DellDigitalDelivery => 2
MSCONFIG\Services: DellUpdate => 2
MSCONFIG\Services: MacriumService => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: SupportAssistAgent => 2
MSCONFIG\Services: WavesSysSvc => 2
MSCONFIG\Services: XTU3SERVICE => 2
HKLM\...\StartupApproved\StartupFolder: => "WavesLocalServer.lnk"
HKLM\...\StartupApproved\StartupFolder: => "WavesPluginServer.lnk"
HKLM\...\StartupApproved\Run: => "WavesSvc"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "LaunchMhttpd"
HKLM\...\StartupApproved\Run: => "Reflect UI"
HKLM\...\StartupApproved\Run32: => "LaunchMhttpd"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Cisco AnyConnect Secure Mobility Agent for Windows"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "Adobe CCXProcess"
HKLM\...\StartupApproved\Run32: => "Cisconet"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "VideoGuardMonitor"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "GarminExpress"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Skype for Desktop"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Lync"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "Trio.WakeNet"
HKU\S-1-5-21-1483475722-1219764467-3277934236-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_0848959D30B7A075789B21F3CF73AE30"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{18F74065-1842-467E-B6B3-1C32BBFBD4F4}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{2842B45C-B791-4050-9BBA-3F4CC3716C51}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{DEAE9708-BBF3-462F-8187-F4B79BD40AA2}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
 
==================== Restore Points =========================
 
22-03-2024 13:18:27 Restore Point Created by FRST
 
==================== Faulty Device Manager Devices ============
 
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (03/22/2024 03:38:38 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DELL-LAPTOP)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
Error: (03/22/2024 03:34:35 PM) (Source: PlayerLocationCheck) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (03/22/2024 03:34:35 PM) (Source: com.geocomply.process-scanner-microservice) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (03/22/2024 03:34:34 PM) (Source: com.geocomply.vm-detector-microservice) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (03/22/2024 03:34:34 PM) (Source: com.geocomply.internal-updater-microservice) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (03/22/2024 03:34:34 PM) (Source: com.geocomply.wifi-scanner-microservice) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (03/22/2024 03:34:29 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.2.10900.330) TYPE: ERROR MODULE: DPTF TIME 15140 ms
 
DPTF Build Version:  8.2.10900.330
DPTF Build Date:  May 16 2016 11:32:37
Source File:  ..\..\..\Sources\Manager\WIPolicyActiveRelationshipTableChanged.cpp @ line 52
Executing Function:  WIPolicyActiveRelationshipTableChanged::execute
Message:  Unhandled exception caught during execution of work item
Framework Event:  PolicyActiveRelationshipTableChanged [44]
Policy:  Active Policy [0]
Exception Function:  Policy::executePolicyActiveRelationshipTableChanged
Exception Text:  
 
DPTF Build Version:  8.2.10900.330
DPTF Build Date:  May 16 2016 11:32:37
Source File:  ..\..\..\Sources\Manager\EsifServices.cpp @ line 457
Executing Function:  EsifServices::primitiveExecuteGet
Message:  Error returned from ESIF services interface function call
Participant:  NoParticipant
Domain:  NoDomain
ESIF Primitive:  GET_ACTIVE_RELATIONSHIP_TABLE [89]
ESIF Instance:  255
ESIF Return Code:  ESIF_E_UNSUPPORTED_ACTION_TYPE [1202]
 
Error: (03/22/2024 03:34:29 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel® Dynamic Platform and Thermal Framework : ESIF(8.2.10900.330) TYPE: ERROR MODULE: DPTF TIME 15138 ms
 
DPTF Build Version:  8.2.10900.330
DPTF Build Date:  May 16 2016 11:32:37
Source File:  ..\..\..\Sources\Manager\WIPolicyActiveRelationshipTableChanged.cpp @ line 52
Executing Function:  WIPolicyActiveRelationshipTableChanged::execute
Message:  Unhandled exception caught during execution of work item
Framework Event:  PolicyActiveRelationshipTableChanged [44]
Policy:  Active Policy [0]
Exception Function:  Policy::executePolicyActiveRelationshipTableChanged
Exception Text:  
 
DPTF Build Version:  8.2.10900.330
DPTF Build Date:  May 16 2016 11:32:37
Source File:  ..\..\..\Sources\Manager\EsifServices.cpp @ line 457
Executing Function:  EsifServices::primitiveExecuteGet
Message:  Error returned from ESIF services interface function call
Participant:  NoParticipant
Domain:  NoDomain
ESIF Primitive:  GET_ACTIVE_RELATIONSHIP_TABLE [89]
ESIF Instance:  255
ESIF Return Code:  ESIF_E_UNSUPPORTED_ACTION_TYPE [1202]
 
 
System errors:
=============
Error: (03/22/2024 03:34:47 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Intel® PROSet/Wireless Zero Configuration Service service terminated with the following error: 
%%2147770990
 
Error: (03/22/2024 03:18:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® Dynamic Application Loader Host Interface Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/22/2024 03:18:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Energy Server Service queencreek service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/22/2024 03:18:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (03/22/2024 03:18:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The com.geocomply.process-scanner-microservice service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 2 milliseconds: Restart the service.
 
Error: (03/22/2024 03:18:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The com.geocomply.vm-detector-microservice service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 2 milliseconds: Restart the service.
 
Error: (03/22/2024 03:18:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Player Location Check service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 1000 milliseconds: Restart the service.
 
Error: (03/22/2024 03:18:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The TeamViewer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 2000 milliseconds: Restart the service.
 
 
Windows Defender:
================
Date: 2024-02-16 09:55:47
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe; file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.405.71.0, AS: 1.405.71.0, NIS: 1.405.71.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10
 
Date: 2024-02-16 09:55:47
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: Unknown
Security intelligence Version: AV: 1.405.71.0, AS: 1.405.71.0, NIS: 1.405.71.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10
 
Date: 2024-02-16 09:55:47
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.405.71.0, AS: 1.405.71.0, NIS: 1.405.71.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10
 
Date: 2024-02-01 21:40:41
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: Unknown
Security intelligence Version: AV: 1.403.3067.0, AS: 1.403.3067.0, NIS: 1.403.3067.0
Engine Version: AM: 1.1.23110.2, NIS: 1.1.23110.2
 
Date: 2024-01-31 22:38:24
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen!pz
Severity: High
Category: Tool
Path: file:_D:\Installs\Studio One\StudioOne\3ehse3y-pso6p\PreSonus.Studio.One.6.Professional.v6.5.0.Incl.Patched.and.Keygen-R2R\r2r12854\R2R\StudioOne_Keygen.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.403.3022.0, AS: 1.403.3022.0, NIS: 1.403.3022.0
Engine Version: AM: 1.1.23110.2, NIS: 1.1.23110.2
Event[0]:
 
Date: 2024-02-05 11:19:06
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.403.3263.0
Previous security intelligence Version: 1.403.3218.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.23110.2
Previous Engine Version: 1.1.23110.2
Error code: 0x80070241
Error description: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. 
 
Date: 2024-02-05 11:19:06
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.403.3263.0
Previous security intelligence Version: 1.403.3218.0
Update Source: User
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 1.1.23110.2
Previous Engine Version: 1.1.23110.2
Error code: 0x80070241
Error description: Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. 
 
Date: 2023-11-16 21:53:14
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Current
Error Code: 0x80070003
Error description: The system cannot find the path specified. 
Security intelligence Version: 0.0.0.0;0.0.0.0
Engine Version: 0.0.0.0
 
Date: 2023-06-06 02:56:46
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.391.576.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.23050.3
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
CodeIntegrity:
===============
Date: 2024-03-22 15:37:20
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\ki132538.inf_amd64_a34b1de6c28c3534\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2024-03-22 15:34:23
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SUPERAntiSpyware\sasdifsv64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2024-03-22 15:34:20
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SUPERAntiSpyware\saskutil64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
BIOS: Dell Inc. 1.2.7 12/13/2017
Motherboard: Dell Inc. 0H87XC
Processor: Intel® Core™ i5-6300HQ CPU @ 2.30GHz
Percentage of memory in use: 39%
Total physical RAM: 16250.84 MB
Available physical RAM: 9816.05 MB
Total Virtual: 18682.84 MB
Available Virtual: 10655.7 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:953.25 GB) (Free:614.44 GB) (Model: TEAM TM8PS7001T) NTFS
Drive d: (1TB) (Fixed) (Total:931.5 GB) (Free:655.78 GB) (Model: PNY CS900 1TB SSD) NTFS
 
\\?\Volume{09964035-891e-49f6-bab9-1af2dfe5e75a}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.43 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==================== End of Addition.txt =======================


#13 user23049

user23049
  • Topic Starter

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:09:12 PM

Posted 23 March 2024 - 07:56 AM

Hi Gary,

 

No indication I can see of malware today.  How do the logs look?  All set here?

 

Thanks



#14 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 62,343 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:12 PM

Posted 23 March 2024 - 09:02 AM

Yes, I think we are all set. Are there any remaining questions or concerns you might have before I post some tool/log clean up instructions and other information for you to consider going forward?
Lord, to whom shall we go? You have the words of eternal life and we have believed and have come to know that you are the Holy One of God.
John 6:68-69

The Man on the Middle Cross Said I Could Come

#15 user23049

user23049
  • Topic Starter

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:09:12 PM

Posted 23 March 2024 - 09:03 AM

No questions. thank you for your help Gary






1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users