Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Double Check for Clean PC


  • This topic is locked This topic is locked
33 replies to this topic

#1 Shiba-INK

Shiba-INK

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 29 April 2025 - 10:56 PM

I got Lumma Stealer a little while ago, Infection disguised as a Liar's Bar Mod, and as a result had to spend a week recovering lost accounts; also ended up wiping my pc.

 

It's been smooth sailing so far, but starting earlier this week my right click menu has started to take 5-10 seconds longer to open.

While it's probably nothing the paranoia crept in so now I'm here.

 

The PC is shared by myself and my buddy Alex, I think he still downloads shady stuff after my Lumma fiasco without telling me, so I'd like to double check that the pc

is actually clean and he told me this was the site to ask, so what should I do next?


Edited by Shiba-INK, 30 April 2025 - 02:14 AM.


BC AdBot (Login to Remove)

 


#2 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 01:58 AM

Finally found the log files from FRST: 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-04-2025
Ran by Shiba (administrator) on DESKTOP-H1BDJIG (Gigabyte Technology Co., Ltd. B450 AORUS M) (29-04-2025 23:54:43)
Running from C:\Users\Shiba\Downloads\FRST64.exe
Loaded Profiles: Shiba
Platform: Microsoft Windows 11 Pro Version 24H2 26100.3775 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <5>
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\Microsoft-Edge-WebView\msedgewebview2.exe <7>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <18>
(services.exe ->) () [File not signed] C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\afwServ.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Maxon Computer GmbH -> ) C:\Program Files\Maxon\Tools\mxredirect.exe
(services.exe ->) (Maxon Computer GmbH -> Red Giant LLC) [File not signed] C:\Program Files\Red Giant\Services\Red Giant Service.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3cae04f75ee04f42\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [856288 2019-10-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [455976 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
HKLM\...\Policies\Explorer: [HideSCAMeetNow] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableActivityFeed] 0
HKLM\Software\Policies\...\system: [PublishUserActivities] 0
HKLM\Software\Policies\...\system: [UploadUserActivities] 0
HKLM\Software\Policies\...\system: [AllowClipboardHistory] 0
HKLM\Software\Policies\...\system: [AllowCrossDeviceClipboard] 0
HKU\S-1-5-21-969771734-2463923209-239459422-1000\...\Run: [RzAppEngine] => C:\Program Files\Razer\RzAppEngine\rzappengine.exe [1640880 2019-08-30] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-969771734-2463923209-239459422-1000\...\Policies\Explorer: [HideSCAMeetNow] 1
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\135.0.7049.115\Installer\chrmstp.exe [2025-04-28] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> "C:\Program Files\AVAST Software\Browser\Application\134.0.29548.179\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
IFEO\Red Giant Link.exe: [Debugger] dummy.exe
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {C2F3B73B-D815-4CBB-A871-632E0CABED3D} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [2856720 2025-04-27] (Microsoft Windows -> Microsoft Corporation)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{466459fc-1a02-418a-a69c-f2a7b9562d68}: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{466459fc-1a02-418a-a69c-f2a7b9562d68}: [DhcpDomain] home
 
Edge: 
=======
Edge Profile: C:\Users\Shiba\AppData\Local\Microsoft\Edge\User Data\Default [2025-04-29]
Edge Extension: (Google Docs Offline) - C:\Users\Shiba\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-27]
Edge Extension: (Edge relevant text changes) - C:\Users\Shiba\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-04-27]
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.451.0 -> C:\Program Files\Java\jre1.8.0_451\bin\dtplugin\npDeployJava1.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.451.0 -> C:\Program Files\Java\jre1.8.0_451\bin\plugin2\npjp2.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.451.0 -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.451.0 -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\plugin2\npjp2.dll [No File]
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1993.6\npAvastBrowserUpdate3.dll [2025-04-28] (Avast Software s.r.o. -> Gen Digital Inc.)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1993.6\npAvastBrowserUpdate3.dll [2025-04-28] (Avast Software s.r.o. -> Gen Digital Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\Shiba\AppData\Local\Google\Chrome\User Data\Default [2025-04-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Shiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-04-28]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7500072 2025-04-09] (Avast Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [193056 2025-04-28] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [807208 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2478376 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [859432 2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [193056 2025-04-28] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2024-12-21] (Avast Software s.r.o. -> AVAST Software)
R2 Focusrite Control Server; C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe [1297920 2025-01-22] () [File not signed]
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe [2009608 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 mxredirect; C:\Program Files\Maxon\Tools\mxredirect.exe [724776 2025-04-28] (Maxon Computer GmbH -> )
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3cae04f75ee04f42\Display.NvContainer\NVDisplay.Container.exe [1275560 2025-04-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 Red Giant Service; C:\Program Files\Red Giant\Services\Red Giant Service.exe [8872232 2022-06-24] (Maxon Computer GmbH -> Red Giant LLC) [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559320 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe [4538400 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe [278320 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 AvastSecureBrowserElevationService; "C:\Program Files\AVAST Software\Browser\Application\134.0.29548.179\elevation_service.exe" [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [248376 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [393272 2025-04-28] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [296528 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [84560 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [28280 2024-12-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [37944 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [282680 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [553528 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [98872 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [69688 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [942672 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1427512 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [207440 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [391760 2025-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 FocusritePCIeSwRoot; C:\WINDOWS\System32\drivers\FocusritePCIeSwRoot.sys [106704 2024-09-20] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 FocusriteUsb; C:\WINDOWS\System32\drivers\FocusriteUsb.sys [170320 2024-09-20] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 FocusriteUsbAudio; C:\WINDOWS\System32\drivers\FocusriteUsbAudio.sys [109392 2024-09-20] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 FocusriteUsbSwRoot; C:\WINDOWS\System32\drivers\FocusriteUsbSwRoot.sys [112952 2024-09-20] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [331168 2025-04-27] (Microsoft Windows -> Microsoft Corporation)
S3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [12435144 2024-10-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
S3 SIVDriver; C:\WINDOWS\system32\Drivers\SIVX64.sys [205552 2021-02-12] (RH Software Ltd -> Ray Hinchliffe)
S3 ThermalFilter; C:\WINDOWS\System32\DriverStore\FileRepository\c_thermal.inf_amd64_732a53ed1662b707\ThermalFilter.sys [75376 2025-04-27] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
R1 ViGEmBus; C:\WINDOWS\System32\drivers\ViGEmBus.sys [249400 2022-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Nefarius Software Solutions e.U.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20016 2025-04-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [605576 2025-04-27] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-04-27] (Microsoft Windows -> Microsoft Corporation)
S3 wini3ctarget; C:\WINDOWS\System32\DriverStore\FileRepository\wini3ctarget.inf_amd64_bdb09ebda2834009\wini3ctarget.sys [75168 2025-04-27] (Microsoft Windows -> Microsoft Corporation)
U4 RLM-BorisFX; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2025-04-29 23:54 - 2025-04-29 23:55 - 000015321 _____ C:\Users\Shiba\Downloads\FRST.txt
2025-04-29 23:53 - 2025-04-29 23:54 - 000000000 ____D C:\FRST
2025-04-29 23:52 - 2025-04-29 23:52 - 002405376 _____ (Farbar) C:\Users\Shiba\Downloads\FRST64.exe
2025-04-29 23:50 - 2025-04-29 23:50 - 000001985 _____ C:\Users\Shiba\Desktop\FMRS_2025_04_29__23_49_12.txt
2025-04-29 23:50 - 2025-04-29 23:50 - 000001985 _____ C:\FMRS_2025_04_29__23_49_12.txt
2025-04-29 23:48 - 2025-04-29 23:48 - 000009435 _____ C:\FMRS_2025_04_29__23_47_08.txt
2025-04-29 21:17 - 2025-04-29 21:18 - 000000000 ____D C:\Program Files\Java
2025-04-29 21:17 - 2025-04-29 21:17 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Sun
2025-04-29 21:17 - 2025-04-29 21:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2025-04-29 21:17 - 2025-04-29 21:17 - 000000000 ____D C:\Program Files\Common Files\Oracle
2025-04-29 21:17 - 2025-04-05 03:39 - 000213120 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2025-04-29 20:35 - 2025-04-29 20:39 - 000000000 ____D C:\Users\Shiba\Doctor Web
2025-04-29 20:30 - 2025-04-29 20:37 - 001426277 _____ (<hxxps://furtivex.net>) C:\Users\Shiba\Downloads\FMRS.exe
2025-04-29 20:17 - 2025-04-29 20:22 - 000000000 ____D C:\AdwCleaner
2025-04-29 20:16 - 2025-04-29 20:16 - 009568256 _____ (Malwarebytes) C:\Users\Shiba\Downloads\adwcleaner.exe
2025-04-29 13:41 - 2025-04-29 13:43 - 000000000 ____D C:\KVRT2020_Data
2025-04-29 04:37 - 2025-04-29 20:14 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-04-29 04:35 - 2025-04-29 04:45 - 000000000 ____D C:\ProgramData\Malwarebytes
2025-04-29 04:23 - 2025-04-29 04:23 - 000949472 _____ (Trellix US LLC.) C:\WINDOWS\system32\Drivers\mfehidk.sys.f974.deleteme
2025-04-29 04:23 - 2025-04-29 04:23 - 000491232 _____ (Trellix US LLC.) C:\WINDOWS\system32\Drivers\mfeaack.sys.cd77.deleteme
2025-04-29 04:23 - 2025-04-29 04:23 - 000354016 _____ (Trellix US LLC.) C:\WINDOWS\system32\Drivers\mfeavfk.sys.a33a.deleteme
2025-04-29 04:23 - 2025-04-29 04:23 - 000106720 _____ (Trellix US LLC.) C:\WINDOWS\system32\Drivers\mfeplk.sys.47f4.deleteme
2025-04-29 04:23 - 2025-04-29 04:23 - 000060128 _____ (Trellix US LLC.) C:\WINDOWS\system32\Drivers\mfeaacsk.sys.5d23.deleteme
2025-04-29 04:23 - 2025-04-29 04:23 - 000000000 ____D C:\ProgramData\McAfee
2025-04-29 04:23 - 2025-04-29 04:23 - 000000000 ____D C:\Program Files\Common Files\McAfee
2025-04-29 04:14 - 2025-04-29 04:14 - 000000000 ____D C:\Program Files\Reference Assemblies
2025-04-29 04:14 - 2025-04-29 04:14 - 000000000 ____D C:\Program Files\MSBuild
2025-04-29 04:14 - 2025-04-29 04:14 - 000000000 ____D C:\Program Files (x86)\MSBuild
2025-04-29 04:04 - 2021-02-12 10:24 - 000205552 _____ (Ray Hinchliffe) C:\WINDOWS\system32\Drivers\SIVX64.sys
2025-04-29 03:38 - 2025-04-29 03:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boris FX Sapphire 2024.5 Photoshop
2025-04-29 03:38 - 2025-04-29 03:38 - 000000000 ____D C:\Program Files\Common Files\Nuke
2025-04-29 03:34 - 2025-04-29 03:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boris FX Sapphire 2024.5 OFX
2025-04-29 03:34 - 2025-04-29 03:34 - 000000000 ____D C:\ProgramData\GenArts
2025-04-29 03:34 - 2024-04-16 12:01 - 000000000 _____ C:\WINDOWS\MSUTIL.INI
2025-04-29 02:55 - 2025-04-29 02:55 - 000000000 ____D C:\ProgramData\SafeNet Sentinel
2025-04-29 02:27 - 2025-04-29 02:27 - 000000000 ____H C:\Users\Shiba\Documents\Default.rdp
2025-04-29 01:40 - 2025-04-29 01:40 - 000000000 ____D C:\ProgramData\Focusrite
2025-04-29 01:39 - 2025-04-29 01:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focusrite
2025-04-29 01:36 - 2025-04-29 01:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focusrite Drivers
2025-04-29 01:36 - 2024-09-19 16:47 - 000099928 _____ C:\WINDOWS\SysWOW64\FocusritePal32.dll
2025-04-29 01:36 - 2024-09-19 16:46 - 000111192 _____ C:\WINDOWS\system32\FocusritePal64.dll
2025-04-29 01:16 - 2025-04-29 01:16 - 000000000 ____D C:\Program Files\dotnet
2025-04-29 01:08 - 2025-04-29 01:08 - 000000318 _____ C:\WINDOWS\system32\httpproxy.json
2025-04-29 01:08 - 2025-04-29 01:08 - 000000027 _____ C:\WINDOWS\system32\ctc.json
2025-04-29 00:56 - 2025-04-29 00:56 - 000000000 ____D C:\ProgramData\Gemma
2025-04-29 00:56 - 2025-04-29 00:56 - 000000000 ____D C:\ProgramData\Atc
2025-04-29 00:55 - 2025-04-29 01:06 - 000000000 ____D C:\ProgramData\BDLogging
2025-04-29 00:55 - 2025-04-29 00:55 - 000000000 ____D C:\WINDOWS\system32\elambkup
2025-04-29 00:55 - 2025-04-29 00:55 - 000000000 ____D C:\ProgramData\48C4687D-9760-4F5B-BAB3-60351B0841E4
2025-04-29 00:54 - 2025-04-29 04:00 - 000000000 ____D C:\Program Files\Bitdefender
2025-04-29 00:54 - 2025-04-29 03:28 - 000000000 ____D C:\ProgramData\Bitdefender
2025-04-29 00:52 - 2025-04-29 00:53 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2025-04-27 23:00 - 2025-04-08 23:48 - 000316200 _____ (Gen Digital Inc.) C:\WINDOWS\system32\aswBoot.exe
2025-04-27 22:56 - 2025-04-27 22:56 - 000000000 ____D C:\ProgramData\rgt
2025-04-27 22:55 - 2025-04-27 22:55 - 000000000 ____D C:\ProgramData\Tritik
2025-04-27 22:53 - 2025-04-27 22:53 - 000000000 ____D C:\ProgramData\Magix
2025-04-27 22:36 - 2025-04-27 22:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxon App
2025-04-27 22:35 - 2025-04-27 22:37 - 000000000 ____D C:\ProgramData\Maxon
2025-04-27 22:35 - 2025-04-27 22:35 - 000000074 _____ C:\ProgramData\WnHqYU0nH4
2025-04-27 22:33 - 2025-04-29 04:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boris FX Sapphire 2025 OFX
2025-04-27 22:33 - 2025-04-27 22:33 - 000000000 ____D C:\Users\Shiba\AppData\Local\BorisFX
2025-04-27 22:32 - 2025-04-29 03:36 - 000000000 ____D C:\Program Files\BorisFX
2025-04-27 22:32 - 2025-04-27 22:32 - 000000000 ____D C:\ProgramData\BorisFX
2025-04-27 22:25 - 2025-04-27 22:36 - 000000000 ____D C:\ProgramData\Red Giant
2025-04-27 22:25 - 2019-01-24 11:32 - 014069248 _____ (Red Giant LLC) C:\WINDOWS\system32\Universe.dll
2025-04-27 22:25 - 2015-10-23 03:54 - 005528064 _____ (Noesis Technologies) C:\WINDOWS\system32\Noesis.dll
2025-04-27 22:25 - 2000-03-10 09:53 - 000049152 ____S C:\WINDOWS\dummy.exe
2025-04-27 22:05 - 2025-04-27 22:10 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Toneboosters
2025-04-27 22:02 - 2025-04-27 22:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ToneBoosters
2025-04-27 22:02 - 2025-04-27 22:02 - 000000000 ____D C:\Program Files\ToneBoosters
2025-04-27 22:02 - 2024-11-23 09:00 - 000005528 _____ (TEAM R2R) C:\WINDOWS\system32\R2RINET.dll
2025-04-27 21:55 - 2025-04-27 21:56 - 000007510 _____ C:\WINDOWS\unins000.dat
2025-04-27 21:55 - 2025-04-27 21:55 - 001516011 _____ C:\WINDOWS\unins000.exe
2025-04-27 21:55 - 2025-04-27 21:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeverdieAudio
2025-04-27 21:54 - 2025-04-27 22:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope
2025-04-27 21:30 - 2025-04-27 21:30 - 000000000 ____D C:\Users\Public\Documents\Adobe
2025-04-27 21:24 - 2025-04-27 21:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2025-04-27 21:24 - 2025-04-27 21:24 - 000000000 ____D C:\Program Files\qBittorrent
2025-04-27 21:11 - 2025-04-27 21:11 - 000000000 ____D C:\ProgramData\obs-studio-hook
2025-04-27 21:11 - 2025-04-27 21:11 - 000000000 ____D C:\ProgramData\obs-studio
2025-04-27 21:11 - 2025-04-27 21:11 - 000000000 ____D C:\ProgramData\NeverdieAudio
2025-04-27 21:08 - 2025-04-27 22:55 - 000000000 ____D C:\ProgramData\VEGAS
2025-04-27 21:08 - 2025-04-27 21:08 - 000000000 ___HD C:\$AV_ASW
2025-04-27 21:08 - 2025-04-27 21:08 - 000000000 ____D C:\ProgramData\VEGAS Pro
2025-04-27 21:08 - 2025-04-27 21:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS
2025-04-27 21:04 - 2025-04-27 21:04 - 000000000 ____D C:\Users\Public\Documents\Blackmagic Design
2025-04-27 21:04 - 2025-04-27 21:04 - 000000000 ____D C:\ProgramData\Blackmagic Design
2025-04-27 20:56 - 2025-04-29 23:48 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2025-04-27 20:56 - 2025-04-27 23:00 - 000002206 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Premium Security.lnk
2025-04-27 20:56 - 2025-04-27 20:56 - 000000000 ____D C:\Users\Shiba\AppData\Local\DBG
2025-04-27 20:56 - 2025-04-27 20:56 - 000000000 ____D C:\ProgramData\redshift
2025-04-27 20:56 - 2025-04-27 20:56 - 000000000 ____D C:\Program Files (x86)\AVAST Software
2025-04-27 20:55 - 2025-04-29 00:42 - 000000000 ____D C:\ProgramData\Avast Software
2025-04-27 20:55 - 2025-03-27 06:19 - 000055064 _____ (Gen Digital Inc.) C:\WINDOWS\system32\icarus_rvrt.exe
2025-04-27 20:50 - 2025-04-27 20:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-04-27 20:45 - 2025-04-29 03:42 - 000000000 ____D C:\ProgramData\Reprise
2025-04-27 20:45 - 2025-04-12 05:25 - 000125048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2025-04-27 20:44 - 2025-04-29 15:58 - 000000000 ____D C:\Users\Public\Documents\Media Cache Files
2025-04-27 20:44 - 2025-04-29 15:58 - 000000000 ____D C:\Users\Public\Documents\Media Cache
2025-04-27 20:44 - 2025-04-27 20:44 - 000000000 ____D C:\Users\Public\Documents\Peak Files
2025-04-27 20:42 - 2025-04-13 23:16 - 002072456 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2025-04-27 20:42 - 2025-04-13 23:16 - 002072456 _____ C:\WINDOWS\system32\vulkaninfo.exe
2025-04-27 20:42 - 2025-04-13 23:16 - 001614216 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2025-04-27 20:42 - 2025-04-13 23:16 - 001614216 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2025-04-27 20:42 - 2025-04-13 23:16 - 001576840 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2025-04-27 20:42 - 2025-04-13 23:16 - 001576840 _____ C:\WINDOWS\system32\vulkan-1.dll
2025-04-27 20:42 - 2025-04-13 23:16 - 001389960 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2025-04-27 20:42 - 2025-04-13 23:16 - 001389960 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2025-04-27 20:42 - 2025-04-13 23:16 - 000478384 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2025-04-27 20:42 - 2025-04-13 23:16 - 000374960 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2025-04-27 20:42 - 2025-04-13 23:11 - 001259648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2025-04-27 20:42 - 2025-04-13 23:11 - 000674992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
2025-04-27 20:42 - 2025-04-13 23:11 - 000509104 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 026001536 _____ C:\WINDOWS\system32\nvidia-pcc.exe
2025-04-27 20:42 - 2025-04-13 23:10 - 002313872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 001713816 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 001569448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 001220784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 001053312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 000942224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2025-04-27 20:42 - 2025-04-13 23:10 - 000810128 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2025-04-27 20:42 - 2025-04-13 23:09 - 023033472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2025-04-27 20:42 - 2025-04-13 23:09 - 000467064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2025-04-27 20:42 - 2025-04-13 23:08 - 020517016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2025-04-27 20:42 - 2025-04-13 23:08 - 007323280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2025-04-27 20:42 - 2025-04-13 23:08 - 005913744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2025-04-27 20:42 - 2025-04-13 23:08 - 005239936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2025-04-27 20:42 - 2025-04-13 23:08 - 003993752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2025-04-27 20:42 - 2025-04-13 23:08 - 000853144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2025-04-27 20:42 - 2025-04-13 23:06 - 005601032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2025-04-27 20:42 - 2025-04-13 23:06 - 004902688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2025-04-27 20:42 - 2025-04-12 05:25 - 000142952 _____ C:\WINDOWS\system32\nvinfo.pb
2025-04-27 20:41 - 2025-04-29 01:16 - 000000000 ____D C:\ProgramData\Package Cache
2025-04-27 20:41 - 2025-04-27 20:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2025-04-27 20:41 - 2025-04-07 09:14 - 003114016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2025-04-27 20:41 - 2025-04-07 09:14 - 002403360 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2025-04-27 20:41 - 2025-04-07 09:14 - 000271392 _____ C:\WINDOWS\system32\FvSDK_x64.dll
2025-04-27 20:41 - 2025-04-07 09:14 - 000245792 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
2025-04-27 20:41 - 2025-04-07 08:52 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2025-04-27 20:41 - 2025-04-07 08:52 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2025-04-27 20:40 - 2025-04-29 13:47 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2025-04-27 20:40 - 2025-04-07 08:52 - 000059928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2025-04-27 20:36 - 2025-04-29 23:50 - 000003656 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2025-04-27 20:35 - 2025-04-27 20:35 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-04-27 20:35 - 2025-04-27 20:35 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-04-27 20:35 - 2025-04-27 20:35 - 000001032 _____ C:\Users\Public\Desktop\Steam.lnk
2025-04-27 20:35 - 2025-04-27 20:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2025-04-27 20:35 - 2025-04-27 20:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2025-04-27 20:35 - 2025-04-27 20:35 - 000000000 ____D C:\Program Files\Google
2025-04-27 18:21 - 2025-04-27 18:21 - 000000400 __RSH C:\ProgramData\ntuser.pol
2025-04-27 18:19 - 2025-04-27 18:19 - 000000000 ____D C:\WINDOWS\system32\AccountHealthAssets
2025-04-27 18:19 - 2025-04-27 18:19 - 000000000 ____D C:\inetpub
2025-04-27 18:14 - 2025-04-27 18:14 - 000000000 ____D C:\Users\Shiba\AppData\Local\Rufus
2025-04-27 16:52 - 2025-04-27 16:52 - 000070484 _____ C:\WINDOWS\SysWOW64\ctac.json
2025-04-27 16:52 - 2025-04-27 16:52 - 000070484 _____ C:\WINDOWS\system32\ctac.json
2025-04-27 16:52 - 2025-04-27 16:52 - 000029042 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-04-27 16:52 - 2025-04-27 16:52 - 000029042 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-04-27 16:52 - 2025-04-27 16:52 - 000000998 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json
2025-04-27 16:49 - 2025-04-29 02:10 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-04-27 15:34 - 2025-04-29 04:28 - 000000000 ___DC C:\WINDOWS\Panther
2025-04-27 15:34 - 2025-04-27 15:34 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2025-04-27 15:13 - 2025-04-27 18:42 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\MMC
2025-04-27 14:55 - 2025-04-27 14:55 - 000000000 ____D C:\Users\Shiba\AppData\Local\Comms
2025-04-27 14:52 - 2019-10-30 02:20 - 001126344 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtCOM64.dll
2025-04-27 14:52 - 2019-10-30 02:20 - 000481888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2025-04-27 14:52 - 2019-10-29 23:20 - 000856288 _____ (Realtek Semiconductor) C:\WINDOWS\system32\RtkAudUService64.exe
2025-04-27 14:52 - 2019-10-29 23:20 - 000821336 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64U.dll
2025-04-27 14:52 - 2019-10-29 23:20 - 000215032 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2025-04-27 14:51 - 2025-04-29 23:49 - 000000000 ____D C:\ProgramData\NVIDIA
2025-04-27 14:51 - 2025-04-29 04:28 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2025-04-27 14:51 - 2025-04-27 20:47 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2025-04-27 14:51 - 2025-04-27 20:41 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-04-27 14:51 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\NVIDIA
2025-04-27 14:51 - 2019-10-30 02:20 - 005623256 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPOU64.dll
2025-04-27 14:48 - 2025-04-29 04:46 - 000000000 ____D C:\ProgramData\Realtek
2025-04-27 14:48 - 2025-04-29 01:34 - 000000000 ____D C:\ProgramData\Razer
2025-04-27 14:48 - 2025-04-27 12:18 - 000000000 ____D C:\Program Files (x86)\Razer
2025-04-27 14:48 - 2023-06-16 07:33 - 000161920 _____ (Razer Inc) C:\WINDOWS\system32\RazerS3CoinstallerEx.dll
2025-04-27 14:46 - 2025-04-29 13:43 - 000001314 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-04-27 14:46 - 2025-04-27 20:52 - 000000000 ____D C:\Users\Shiba\AppData\Local\PlaceholderTileLogoFolder
2025-04-27 14:43 - 2025-04-29 04:35 - 000000000 ___RD C:\Users\Shiba\OneDrive
2025-04-27 14:42 - 2025-04-29 04:50 - 000836650 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-04-27 14:41 - 2025-04-27 14:41 - 000000000 ____D C:\Users\Shiba\AppData\Local\Publishers
2025-04-27 14:40 - 2025-04-29 23:52 - 000000000 ____D C:\Users\Shiba\AppData\Local\D3DSCache
2025-04-27 14:40 - 2025-04-27 14:40 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Network
2025-04-27 14:39 - 2025-04-29 20:35 - 000000000 ____D C:\Users\Shiba
2025-04-27 14:39 - 2025-04-29 04:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Packages
2025-04-27 14:39 - 2025-04-27 14:39 - 000000020 ___SH C:\Users\Shiba\ntuser.ini
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 ___SD C:\Users\Shiba\AppData\Roaming\Microsoft\SystemCertificates
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 ___SD C:\Users\Shiba\AppData\Roaming\Microsoft\Crypto
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 ___SD C:\Users\Shiba\AppData\Roaming\Microsoft\Credentials
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Vault
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 ____D C:\Users\Shiba\AppData\Local\VirtualStore
2025-04-27 14:39 - 2025-04-27 11:47 - 000000000 ___SD C:\Users\Shiba\AppData\Roaming\Microsoft\Protect
2025-04-27 14:39 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows
2025-04-27 14:39 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Spelling
2025-04-27 14:39 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Adobe
2025-04-27 14:39 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\ConnectedDevicesPlatform
2025-04-27 14:37 - 2025-04-29 04:35 - 000000000 ____D C:\ProgramData\Packages
2025-04-27 14:37 - 2025-04-27 14:37 - 000000000 _SHDL C:\Documents and Settings
2025-04-27 14:37 - 2025-04-27 14:37 - 000000000 ____D C:\WINDOWS\CSC
2025-04-27 14:36 - 2025-04-27 14:36 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-04-27 14:36 - 2025-04-27 14:36 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2025-04-27 14:35 - 2025-04-29 14:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-04-27 14:35 - 2025-04-29 04:46 - 000012288 ___SH C:\DumpStack.log.tmp
2025-04-27 14:35 - 2025-04-29 04:46 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-04-27 14:35 - 2025-04-27 18:20 - 000296880 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-04-27 14:35 - 2025-04-27 16:45 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-04-27 14:35 - 2025-04-27 14:35 - 000000000 ____D C:\WINDOWS\system32\config\BFS
2025-04-27 14:35 - 2025-04-27 14:35 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2025-04-27 13:07 - 2025-04-26 16:32 - 000000000 ____D C:\Program Files (x86)\ZeroTier
2025-04-27 13:07 - 2025-04-26 16:32 - 000000000 ____D C:\Program Files (x86)\VstPlugins
2025-04-27 13:07 - 2025-04-26 16:32 - 000000000 ____D C:\Program Files (x86)\VEGAS
2025-04-27 13:06 - 2025-04-27 13:06 - 000000000 ____D C:\Program Files (x86)\Tobias Erichsen
2025-04-27 13:06 - 2025-04-26 16:32 - 000000000 ____D C:\Program Files (x86)\Ubisoft
2025-04-27 12:18 - 2025-04-29 13:47 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2025-04-27 12:18 - 2025-04-27 20:35 - 000000000 ____D C:\Program Files (x86)\Steam
2025-04-27 12:18 - 2025-04-27 12:18 - 000000000 ____D C:\Program Files (x86)\Razer Chroma SDK
2025-04-27 12:18 - 2025-04-27 12:18 - 000000000 ____D C:\Program Files (x86)\Radmin VPN
2025-04-27 12:18 - 2025-04-27 12:18 - 000000000 ____D C:\Program Files (x86)\Overwolf
2025-04-27 12:18 - 2025-04-27 12:18 - 000000000 ____D C:\Program Files (x86)\obs-studio
2025-04-27 12:18 - 2025-04-26 16:18 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2025-04-27 12:17 - 2025-04-27 20:41 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\ImgBurn
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\Google
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\Free Video Compressor
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\Epic Games
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat_EOS
2025-04-27 12:17 - 2025-04-26 16:17 - 000000000 ____D C:\Program Files (x86)\NewBlueFX
2025-04-27 12:16 - 2025-04-27 21:56 - 000000000 ____D C:\Program Files\VSTPlugins
2025-04-27 12:16 - 2025-04-27 20:49 - 000000000 ____D C:\Program Files\WinRAR
2025-04-27 12:16 - 2025-04-27 12:16 - 000000000 ____D C:\Program Files\Voice.ai
2025-04-27 12:16 - 2025-04-27 12:16 - 000000000 ____D C:\Program Files\_uninstaller
2025-04-27 12:16 - 2025-04-27 12:16 - 000000000 ____D C:\Program Files (x86)\Battle.net
2025-04-27 12:16 - 2025-04-27 12:16 - 000000000 ____D C:\Program Files (x86)\Auburn Sounds
2025-04-27 12:16 - 2025-04-27 12:16 - 000000000 ____D C:\Program Files (x86)\Adobe
2025-04-27 12:16 - 2025-04-26 16:52 - 000000000 ____D C:\Program Files\VideoLAN
2025-04-27 12:16 - 2025-04-26 16:17 - 000000000 ____D C:\Program Files (x86)\Blackmagic Design
2025-04-27 12:15 - 2025-04-27 22:36 - 000000000 ____D C:\Program Files\Red Giant
2025-04-27 12:15 - 2025-04-27 21:40 - 000000000 ____D C:\Program Files\VEGAS
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\ToneLib
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\Tokyo Dawn Labs
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\Tobias Erichsen
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\Sonic Charge
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\Razer
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\PowerISO
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\Pinnacle
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\obs-studio
2025-04-27 12:15 - 2025-04-26 16:52 - 000000000 ____D C:\Program Files\Steinberg
2025-04-27 12:15 - 2025-04-26 16:52 - 000000000 ____D C:\Program Files\Razer Chroma SDK
2025-04-27 12:14 - 2025-04-27 22:50 - 000000000 ____D C:\Program Files\iZotope
2025-04-27 12:14 - 2025-04-27 22:02 - 000000000 ____D C:\Program Files\Common Files\VST3
2025-04-27 12:14 - 2025-04-27 21:55 - 000000000 ____D C:\Program Files\NeverdieAudio
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\NewBlueFX
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Maxon Cinema 4D 2025
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Maxon
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\FreakshowIndustries
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Focusrite
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\FabFilter
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Common Files\Steinberg
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Common Files\Sonic Charge
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2025-04-27 12:14 - 2025-04-26 16:51 - 000000000 ____D C:\Program Files\Nefarius Software Solutions
2025-04-27 12:14 - 2025-04-26 16:51 - 000000000 ____D C:\Program Files\Common Files\OFX
2025-04-27 12:14 - 2025-04-26 16:51 - 000000000 ____D C:\Program Files\Common Files\Avid
2025-04-27 12:14 - 2024-09-19 17:10 - 000170320 _____ (Focusrite Audio Engineering Ltd.) C:\WINDOWS\system32\Drivers\FocusriteUsb.sys
2025-04-27 12:14 - 2024-09-19 17:10 - 000112952 _____ (Focusrite Audio Engineering Ltd.) C:\WINDOWS\system32\Drivers\FocusriteUsbSwRoot.sys
2025-04-27 12:14 - 2024-09-19 17:10 - 000109392 _____ (Focusrite Audio Engineering Ltd.) C:\WINDOWS\system32\Drivers\FocusriteUsbAudio.sys
2025-04-27 12:14 - 2024-09-19 17:10 - 000106704 _____ (Focusrite Audio Engineering Ltd.) C:\WINDOWS\system32\Drivers\FocusritePCIeSwRoot.sys
2025-04-27 12:13 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Common Files\Adobe
2025-04-27 12:11 - 2025-04-27 20:57 - 000000000 ____D C:\Program Files\Avast Software
2025-04-27 12:11 - 2025-04-27 12:11 - 000000000 ____D C:\Program Files\Bertom Audio
2025-04-27 12:11 - 2025-04-27 12:11 - 000000000 ____D C:\Program Files\Audacity
2025-04-27 12:11 - 2025-04-27 12:11 - 000000000 ____D C:\Program Files\Antares Audio Technologies
2025-04-27 12:06 - 2025-04-27 12:10 - 000000000 ____D C:\Program Files\Adobe
2025-04-27 12:05 - 2025-04-27 12:05 - 000000000 ____D C:\XboxGames
2025-04-27 12:05 - 2025-04-27 12:05 - 000000000 ____D C:\Users\Shiba\Downloads\YO
2025-04-27 12:05 - 2025-04-27 12:05 - 000000000 ____D C:\Users\Shiba\Downloads\RUST MIDI
2025-04-27 12:03 - 2025-04-27 12:03 - 000000000 ____D C:\Users\Shiba\Downloads\OLD SCHOOL GAMES VIDEO
2025-04-27 12:03 - 2025-04-27 12:03 - 000000000 ____D C:\Users\Shiba\Downloads\MODs
2025-04-27 12:02 - 2025-04-27 12:03 - 000000000 ____D C:\Users\Shiba\Downloads\LUTS
2025-04-27 12:02 - 2025-04-27 12:02 - 000000000 ____D C:\Users\Shiba\Downloads\KONG
2025-04-27 12:02 - 2025-04-27 12:02 - 000000000 ____D C:\Users\Shiba\Downloads\KeepSakes
2025-04-27 12:02 - 2025-04-27 12:02 - 000000000 ____D C:\Users\Shiba\Downloads\BACKGROUND
2025-04-27 12:02 - 2025-04-04 14:56 - 2380545624 _____ C:\Users\Shiba\Downloads\Hotel.Transylvania.2012.1080p.BluRay.DDP.5.1.x265-EDGE2020.mkv
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\VEGAS
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\ToneLib
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Rockstar Games
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Red Giant
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\OpenIV
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\OFX Presets
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\NewBlue
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\My Games
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\iZotope
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Blackmagic Design
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Assassin's Creed Unity
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Arma 3
2025-04-27 12:01 - 2025-04-26 16:44 - 000000000 ____D C:\Users\Shiba\Documents\NeverdieAudio
2025-04-27 12:01 - 2025-04-26 16:44 - 000000000 ____D C:\Users\Shiba\Documents\FabFilter
2025-04-27 12:01 - 2025-04-26 16:44 - 000000000 ____D C:\Users\Shiba\Documents\Call of Duty
2025-04-27 12:01 - 2025-04-26 16:44 - 000000000 ____D C:\Users\Shiba\Documents\Arma 3 - Other Profiles
2025-04-27 12:01 - 2025-04-04 11:55 - 3817678232 _____ C:\Users\Shiba\Downloads\Coraline.2009.2160p.BluRay.3500MB.DDP5.1.x264-GalaxyRG.mkv
2025-04-27 12:01 - 2025-03-20 21:25 - 000000000 ____D C:\Users\Shiba\Documents\Sonic Charge
2025-04-27 12:01 - 2025-02-25 04:10 - 000000000 ____D C:\Users\Shiba\Documents\My Cheat Tables
2025-04-27 12:01 - 2025-01-12 23:01 - 000000000 ____D C:\Users\Shiba\Documents\Audacity
2025-04-27 11:59 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Adobe
2025-04-27 11:59 - 2025-04-27 11:59 - 000000000 ____D C:\Users\Shiba\Documents\Accusonus
2025-04-27 11:55 - 2025-04-27 11:58 - 000000000 ____D C:\Users\Shiba\Desktop\YouTube Recordings
2025-04-27 11:55 - 2025-04-27 11:55 - 000000000 ____D C:\Users\Shiba\Desktop\Too many files
2025-04-27 11:54 - 2025-04-29 02:45 - 000000000 ____D C:\Users\Shiba\Desktop\JORDO
2025-04-27 11:54 - 2025-04-26 16:43 - 000000000 ____D C:\Users\Shiba\Desktop\Junk & Memes
2025-04-27 11:53 - 2025-04-29 13:47 - 000001155 _____ C:\Users\Shiba\Desktop\MSI Afterburner.lnk
2025-04-27 11:53 - 2025-04-27 11:54 - 000000000 ____D C:\Users\Shiba\Desktop\Garbage WIP
2025-04-27 11:53 - 2025-04-25 12:01 - 000000223 _____ C:\Users\Shiba\Desktop\Stray.url
2025-04-27 11:53 - 2025-04-23 21:33 - 000002247 _____ C:\Users\Shiba\Desktop\Discord.lnk
2025-04-27 11:53 - 2025-04-18 13:59 - 000000222 _____ C:\Users\Shiba\Desktop\Far Cry 5.url
2025-04-27 11:53 - 2025-04-11 22:34 - 000000223 _____ C:\Users\Shiba\Desktop\It Takes Two.url
2025-04-27 11:53 - 2025-04-11 22:32 - 000000222 _____ C:\Users\Shiba\Desktop\Terraria.url
2025-04-27 11:53 - 2025-04-04 00:08 - 162197336 _____ C:\Users\Shiba\Desktop\BRUH.mp4
2025-04-27 11:53 - 2025-04-02 04:55 - 000002297 _____ C:\Users\Shiba\Desktop\Replay.lnk
2025-04-27 11:53 - 2025-03-29 00:46 - 000000222 _____ C:\Users\Shiba\Desktop\Cry of Fear.url
2025-04-27 11:53 - 2025-03-23 22:25 - 000002321 _____ C:\Users\Shiba\Desktop\Thunderstore Mod Manager.lnk
2025-04-27 11:53 - 2025-03-23 22:25 - 000002321 _____ C:\Users\Shiba\Desktop\CurseForge.lnk
2025-04-27 11:53 - 2025-03-20 21:37 - 000000222 _____ C:\Users\Shiba\Desktop\Phasmophobia.url
2025-04-27 11:53 - 2025-03-17 22:18 - 000000223 _____ C:\Users\Shiba\Desktop\R.E.P.O..url
2025-04-27 11:53 - 2025-03-17 18:53 - 000000018 _____ C:\Users\Shiba\Desktop\Write down new backup codes shiba.txt
2025-04-27 11:53 - 2025-03-13 17:18 - 000000222 _____ C:\Users\Shiba\Desktop\Arma 3.url
2025-04-27 11:53 - 2025-03-05 04:12 - 000000219 _____ C:\Users\Shiba\Desktop\Half-Life 2.url
2025-04-27 11:53 - 2025-02-24 19:20 - 000000233 _____ C:\Users\Shiba\Desktop\Assassin’s Creed Unity.url
2025-04-27 11:53 - 2025-02-24 13:32 - 000000000 _____ C:\Users\Shiba\Desktop\May Photography.txt
2025-04-27 11:53 - 2025-01-27 21:01 - 000000223 _____ C:\Users\Shiba\Desktop\Backrooms Escape Together.url
2025-04-27 11:53 - 2025-01-26 02:16 - 000000223 _____ C:\Users\Shiba\Desktop\Zort.url
2025-04-27 11:53 - 2025-01-26 02:16 - 000000223 _____ C:\Users\Shiba\Desktop\Nuclear Nightmare.url
2025-04-27 11:53 - 2025-01-25 07:50 - 000000222 _____ C:\Users\Shiba\Desktop\Valheim.url
2025-04-27 11:53 - 2025-01-24 02:26 - 000000220 _____ C:\Users\Shiba\Desktop\Garry's Mod.url
2025-04-27 11:53 - 2024-12-24 18:47 - 000000222 _____ C:\Users\Shiba\Desktop\DARK SOULS™ II Scholar of the First Sin.url
2025-04-27 11:53 - 2024-12-23 16:22 - 000000223 _____ C:\Users\Shiba\Desktop\BABBDI.url
2025-04-27 11:53 - 2024-12-23 16:18 - 000000222 _____ C:\Users\Shiba\Desktop\Awkward Dimensions Redux.url
2025-04-27 11:53 - 2024-12-21 12:37 - 000000223 _____ C:\Users\Shiba\Desktop\Lethal Company.url
2025-04-27 11:53 - 2024-12-21 12:37 - 000000223 _____ C:\Users\Shiba\Desktop\Combat Master.url
2025-04-27 11:53 - 2024-12-21 12:37 - 000000222 _____ C:\Users\Shiba\Desktop\Rust.url
2025-04-27 11:53 - 2024-12-21 12:36 - 000000223 _____ C:\Users\Shiba\Desktop\Liar's Bar.url
2025-04-27 11:53 - 2024-12-20 21:10 - 000001327 _____ C:\Users\Shiba\Desktop\Ubisoft Connect.lnk
2025-04-27 11:52 - 2025-04-28 13:03 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\vlc
2025-04-27 11:52 - 2025-04-27 11:52 - 000000000 __SHD C:\Users\Shiba\AppData\Roaming\u-data
2025-04-27 11:52 - 2025-04-27 11:52 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\VEGAS Pro
2025-04-27 11:52 - 2025-04-27 11:52 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\VEGAS
2025-04-27 11:52 - 2025-04-27 11:52 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Tonelib
2025-04-27 11:52 - 2025-04-27 11:52 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Tokyo Dawn Labs
2025-04-27 11:52 - 2025-04-26 16:41 - 000000000 ____D C:\Users\Shiba\curseforge
2025-04-27 11:52 - 2025-04-26 16:41 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\WinRAR
2025-04-27 11:52 - 2025-04-26 16:41 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Tritik
2025-04-27 11:49 - 2025-04-27 11:49 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\SCP Secret Laboratory
2025-04-27 11:49 - 2025-04-27 11:49 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Rustangelo
2025-04-27 11:49 - 2025-04-27 11:49 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\RS2V
2025-04-27 11:49 - 2025-04-26 16:40 - 000000000 ___HD C:\Users\Shiba\AppData\Roaming\s-configs
2025-04-27 11:49 - 2025-04-26 16:40 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Thunderstore Mod Manager
2025-04-27 11:47 - 2025-04-29 03:35 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\qBittorrent
2025-04-27 11:47 - 2025-04-29 01:37 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Replay
2025-04-27 11:47 - 2025-04-29 01:17 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\DS4Windows
2025-04-27 11:47 - 2025-04-27 21:56 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\obs-studio
2025-04-27 11:47 - 2025-04-27 21:56 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\NeverdieAudio
2025-04-27 11:47 - 2025-04-27 20:50 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ___RD C:\Users\Shiba\AppData\Roaming\Nuro Audio
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\NRCSDK
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxon App
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blackmagic Design
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\HTML Help
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\MAGIX
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\iZotope
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\FabFilter
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\ERModsManager
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Electronic Arts
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\EldenRing
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\EasyAntiCheat
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\discord
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\com.adobe.dunamis
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Bitdefender Security App
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Battle.net
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\audacity
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Antares
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ___HD C:\Users\Shiba\AppData\Roaming\c-data
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\NVIDIA
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\NetEase
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\MarvelRivals_Launcher
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Freakshow
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Elgato
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Blackmagic Design
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Bertom Audio
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Avast Software
2025-04-27 11:47 - 2025-04-25 16:55 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ToneLib-NoiseReducer
2025-04-27 11:47 - 2025-04-02 04:55 - 000002305 _____ C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Replay.lnk
2025-04-27 11:47 - 2025-03-07 12:22 - 000001306 _____ C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\OpenIV.lnk
2025-04-27 11:47 - 2025-03-06 14:37 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Voice ai
2025-04-27 11:46 - 2025-04-29 13:40 - 000000000 ____D C:\Users\Shiba\AppData\Local\NVIDIA
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 __SHD C:\Users\Shiba\AppData\Roaming\a-resources
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\.minecraft
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Sun
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\konza
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Adobe
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\ZeroTier
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Voice.ai
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\VEGAS Pro
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\UnrealEngineLauncher
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\UnrealEngine
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\UniSDK
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\UniCompactView
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Ubisoft Game Launcher
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\ToastNotificationManagerCompat
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Steam
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\SplitFiction
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Sony
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Smithbox
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Rockstar Games
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\replay-updater
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Red Giant
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Razer
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\qBittorrent
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Plugin.OfxStitch
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Plugin.ofx360Stabilizer
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Plugin.MxOfxRotation
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Overwolf
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\NVIDIA Corporation
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\New Technology Studio
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Netease
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Maxon
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\MarvelRivals_Launcher
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\MAGIX
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\LogMeIn
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\iZotope
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\ItTakesTwo
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\INetHistory
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\TVGS
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\semiwork
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Northwood
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Londer Software
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Kinetic Games
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\IronGate
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Hello Crime
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Facepunch Studios LTD
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\DefaultCompany
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Curve Animation
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\AlfaBravoInc
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\Local\UnrealEdge
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\Local\UniSDK_FirstOpen
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\Local\Photoshop1-26-WIN
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\NVIDIA Profile Inspector
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\numba
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\NuclearNightmare
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\NgConsentManager
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\NewBlue
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\MinecraftInstaller
2025-04-27 11:46 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\mbamtray
2025-04-27 11:46 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\MaxonApp
2025-04-27 11:46 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Marvel
2025-04-27 11:46 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Hk_project
2025-04-27 11:46 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\HarshDoorstop
2025-04-27 11:46 - 2025-02-26 22:02 - 000000000 ____D C:\Users\Shiba\AppData\Local\PeerDistRepub
2025-04-27 11:46 - 2024-12-21 00:18 - 000000000 ____D C:\Users\Shiba\AppData\Local\VEGAS
2025-04-27 11:45 - 2025-04-29 23:38 - 000000000 ____D C:\Users\Shiba\AppData\Local\CrashDumps
2025-04-27 11:45 - 2025-04-27 20:57 - 000000000 ____D C:\Users\Shiba\AppData\Local\Avast Software
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\GameAnalytics
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\EpicGamesLauncher
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Discord
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\DaVinci Resolve Welcome
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\CEF
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\cache
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Bohemia_Interactive
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Blizzard Entertainment
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Bitdefender
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\BET
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Battle.net
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\audacity
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Athena
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Arma 3 Launcher
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Arma 3
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\appsflyer
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Adobe
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Activision
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\accusonus
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Google
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Fluffy
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Epic Games
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\CrashReportClient
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\BattlEye
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Backup
2025-04-27 11:45 - 2024-12-21 14:22 - 000000000 ____D C:\Users\Shiba\AppData\Local\AWSToolkit
2025-04-08 16:01 - 2025-04-08 16:01 - 000120200 _____ () C:\WINDOWS\SysWOW64\DLLDEV32i.dll
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2025-04-29 23:48 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-04-29 23:38 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-04-29 23:38 - 2024-04-01 00:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-04-29 20:15 - 2024-04-01 00:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-04-29 04:50 - 2024-04-01 00:24 - 000000000 ____D C:\WINDOWS\INF
2025-04-29 04:24 - 2024-04-01 00:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-04-29 04:14 - 2024-10-04 16:59 - 001175072 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2025-04-29 04:14 - 2024-10-04 16:59 - 000780720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2025-04-29 04:00 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-04-29 00:59 - 2024-04-01 00:21 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2025-04-27 23:02 - 2024-04-01 00:21 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2025-04-27 20:58 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\WebThreatDefSvc
2025-04-27 20:42 - 2024-04-01 00:26 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\WINDOWS\InboxApps
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ___SD C:\WINDOWS\system32\UNP
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ___RD C:\Program Files\Windows Defender
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\UUS
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\ProgramData\USOPrivate
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-04-27 18:19 - 2024-04-01 00:21 - 000000000 ____D C:\WINDOWS\servicing
2025-04-27 16:59 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2025-04-27 16:58 - 2024-04-01 00:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2025-04-27 16:44 - 2024-04-01 00:26 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2025-04-27 15:34 - 2024-04-01 00:26 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2025-04-27 15:34 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\appcompat
2025-04-27 14:40 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\spool
2025-04-27 14:39 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2025-04-27 14:38 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\ServiceState
2025-04-27 14:37 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2025-04-27 14:35 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================


#3 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 02:02 AM

Addition: 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-04-2025
Ran by Shiba (29-04-2025 23:56:21)
Running from C:\Users\Shiba\Downloads
Microsoft Windows 11 Pro Version 24H2 26100.3775 (X64) (2025-04-27 21:37:56)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-969771734-2463923209-239459422-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-969771734-2463923209-239459422-503 - Limited - Disabled)
Guest (S-1-5-21-969771734-2463923209-239459422-501 - Limited - Disabled)
Shiba (S-1-5-21-969771734-2463923209-239459422-1000 - Administrator - Enabled) => C:\Users\Shiba
WDAGUtilityAccount (S-1-5-21-969771734-2463923209-239459422-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
FW: Avast Antivirus (Enabled) {D322394B-73F7-C65E-BBB0-3B81E063D6D4}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Avast Premium Security (HKLM\...\Avast Antivirus) (Version: 25.3.9983.2649 - Gen Digital Inc.)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 134.0.29548.179 - Gen Digital Inc.)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1993.6 - AVAST Software) Hidden
Boris FX Mocha Plug-ins 2024 for OFX (HKLM\...\{3B6C7E9D-7CAA-47F7-846E-47E8FB102747}) (Version: 11.02.32 - Boris FX, Inc.)
Boris FX Sapphire Plug-ins 2024.5 for OFX (HKLM\...\GenArts Sapphire Plug-ins for OFX_is1) (Version: 17.5 - Boris FX, Inc.)
Boris FX Sapphire Plug-ins 2024.5 for Photoshop (HKLM\...\GenArts Sapphire PS_is1) (Version: 17.5 - Boris FX, Inc.)
Focusrite Audio Drivers 4.124.3.5 (HKLM\...\Focusrite Audio Drivers_is1) (Version: 4.124.3.5 - Focusrite Audio Engineering, Ltd.)
Focusrite Control 3.20.0.220 (HKLM\...\Focusrite Control_is1) (Version: 3.20.0.220 - Focusrite Audio Engineering Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 135.0.7049.115 - Google LLC)
iZotope Nectar 4 Advanced (HKLM\...\iZotope Nectar 4 Advanced_is1) (Version: 4.0.1 - iZotope)
iZotope Plasma (HKLM\...\iZotope Plasma_is1) (Version: 1.0.1 - iZotope)
iZotope Vinyl (HKLM\...\iZotope Vinyl_is1) (Version: 1.12.1 - iZotope)
Java 8 Update 451 (64-bit) (HKLM\...\{71024AE4-039E-4CA4-87B4-2F64180451F0}) (Version: 8.0.4510.10 - Oracle Corporation)
Java 8 Update 451 (HKLM-x32\...\{71024AE4-039E-4CA4-87B4-2F32180451F0}) (Version: 8.0.4510.10 - Oracle Corporation)
Magic Bullet Suite (HKLM\...\Magic Bullet Suite v16.1.0) (Version:  - Maxon Computer GmbH)
Maxon App (HKLM\...\Maxon App v3.1.1) (Version:  - Maxon Computer GmbH)
Microsoft .NET Host - 8.0.15 (x64) (HKLM\...\{4C903F19-B4C3-4D0C-8CC9-D444C511AF1C}) (Version: 64.60.31149 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.15 (x64) (HKLM\...\{11CCC9F6-77AA-4421-9EAC-BAEC36D96817}) (Version: 64.60.31149 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.15 (x64) (HKLM\...\{8731E6E3-AF96-4515-ACEC-DBFB3DF55292}) (Version: 64.60.31149 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 122.0.2365.106 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438 (HKLM-x32\...\{b49c10dd-4d54-45f8-ad13-fa25704456a4}) (Version: 14.42.34438.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810 (HKLM-x32\...\{47109d57-d746-4f8b-9618-ed6a17cc922b}) (Version: 14.40.33810.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34438 (HKLM\...\{E528AD94-12D7-42C4-91A3-908BE28E9BD2}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34438 (HKLM\...\{2E15F519-4FDA-4834-B4EE-7EFCE7D8D4EE}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.40.33810 (HKLM-x32\...\{5EA6C998-D5AC-4ED9-89C3-9F25B17CCD3D}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.40.33810 (HKLM-x32\...\{0C3457A0-3DCE-4A33-BEF0-9B528C557771}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.15 (x64) (HKLM\...\{0E4A7820-FDA4-4250-B7AC-E7A2F7B43B64}) (Version: 64.60.31203 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.15 (x64) (HKLM-x32\...\{5625bb48-295c-4113-bc92-d6a69b19b04c}) (Version: 8.0.15.34718 - Microsoft Corporation)
MSI Afterburner 4.6.5 (HKLM-x32\...\Afterburner) (Version: 4.6.5 - MSI Co., LTD)
NeverdieAudio Speachy (HKLM\...\NeverdieAudio Speachy_is1) (Version: 1.0 - NeverdieAudio)
NVIDIA App 11.0.3.232 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.3.232 - NVIDIA Corporation)
NVIDIA FrameView SDK 1.5.10920.35420203 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.5.10920.35420203 - NVIDIA Corporation)
NVIDIA Graphics Driver 576.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 576.02 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.4.3.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.3.2 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
qBittorrent (HKLM-x32\...\qBittorrent) (Version: 5.1.0 - The qBittorrent project)
Red Giant Universe (HKLM\...\Universe_is1) (Version: 3.0.2 - Red Giant & Team V.R)
RivaTuner Statistics Server 7.3.4 (HKLM-x32\...\RTSS) (Version: 7.3.4 - Unwinder)
Speachy version 1.0.0 (HKLM-x32\...\{JUSTFUN598-SPEACHY-10}_is1) (Version: 1.0.0 - JustFun598)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
ToneBoosters Plugin Bundle (HKLM\...\ToneBoosters Plugin Bundle_is1) (Version: 1.8.9 - ToneBoosters)
VEGAS Pro 22.0 (HKLM\...\{158D228E-DAFD-493F-A502-4EEEB84A1F30}) (Version: 22.0.248.0 - VEGAS) Hidden
VEGAS Pro 22.0 (HKLM\...\MX.{158D228E-DAFD-493F-A502-4EEEB84A1F30}) (Version: 22.0.248.0 - VEGAS)
ViGEm Bus Driver (HKLM\...\{966606F3-2745-49E9-BF15-5C3EAA4E9077}) (Version: 1.22.0 - Nefarius Software Solutions e.U.)
 
Packages:
=========
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.967.0_x64__56jybvy8sckqj [2025-04-27] (NVIDIA Corp.)
Windows Feature Experience Pack -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-04-28] (Microsoft Windows)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-969771734-2463923209-239459422-1000_Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32 ->  => No File
CustomCLSID: HKU\S-1-5-21-969771734-2463923209-239459422-1000_Classes\CLSID\{d93ed569-3b3e-4bff-8355-3c44f6a52bb5}\InprocServer32 ->  => No File
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3cae04f75ee04f42\nvshext.dll [2025-04-14] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-04-09] (Avast Software s.r.o. -> Gen Digital Inc.)
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [VIDC.RTV1] => C:\WINDOWS\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Shiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\aa12cae77d0cb68b\7.1 Surround Sound.lnk -> C:\Program Files\Razer\RzAppEngine\rzappengine.exe (Razer Inc.) -> --application-host=apps.razer.com --profile-directory=Default hxxps://apps.razer.com/app-launcher/RzUiQiNlDnNMZ1NZ-HFhVAUiRz/
ShortcutWithArgument: C:\Users\Shiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\8beb69a3fbd06fbe\7.1 Surround Sound.lnk -> C:\Program Files\Razer\RzAppEngine\rzappengine.exe (Razer Inc.) -> --application-host=apps.razer.com --profile-directory=Default hxxps://apps.razer.com/app-launcher/RzUiQiNlDnNMZ1NZ-HFhVAUiRz/
ShortcutWithArgument: C:\Users\Shiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\78e1633e8ca7f001\7.1 Surround Sound.lnk -> C:\Program Files\Razer\RzAppEngine\rzappengine.exe (Razer Inc.) -> --application-host=apps.razer.com --profile-directory=Default hxxps://apps.razer.com/app-launcher/RzUiQiNlDnNMZ1NZ-HFhVAUiRz/
ShortcutWithArgument: C:\Users\Shiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\59632612248f617e\7.1 Surround Sound.lnk -> C:\Program Files\Razer\RzAppEngine\rzappengine.exe (Razer Inc.) -> --application-host=apps.razer.com --profile-directory=Default hxxps://apps.razer.com/app-launcher/RzUiQiNlDnNMZ1NZ-HFhVAUiRz/
ShortcutWithArgument: C:\Users\Shiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\3d7109d88eb163cf\7.1 Surround Sound.lnk -> C:\Program Files\Razer\RzAppEngine\rzappengine.exe (Razer Inc.) -> --application-host=apps.razer.com --profile-directory=Default hxxps://apps.razer.com/app-launcher/RzUiQiNlDnNMZ1NZ-HFhVAUiRz/
 
==================== Loaded Modules (Whitelisted) =============
 
2025-04-27 12:15 - 2025-04-27 20:41 - 000000000 ____L (NVIDIA Corporation) [symlink -> C:\Program Files\NVIDIA Corporation\NVIDIA App\MessageBus\NvMessageBusBroadcast.dll] C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem\NvMessageBusBroadcast.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Reprise:jhqduwvxlctbqqijsf`usjbm`,qtjhjlhlih [0]
AlternateDataStreams: C:\ProgramData\Reprise:jhqduwvxlctbqqijsf`usjbm`pgyjhjlhlih [0]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) =============
 
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_451\bin\ssv.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_451\bin\jp2ssv.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\ssv.dll => No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\jp2ssv.dll => No File
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2024-04-01 00:26 - 2025-04-29 20:43 - 000003660 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-969771734-2463923209-239459422-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Shiba\Downloads\BACKGROUND\rUBQIr3.jpeg
DNS Servers: 192.168.254.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [Microsoft-Windows-Unified-Telemetry-Client] => (Block) C:\WINDOWS\system32\svchost.exe (Microsoft Windows Publisher -> Microsoft Corporation)
FirewallRules: [{ED3FF90B-CB1A-45AB-BF61-C90D1B3E3E93}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25072.1611.3570.1995_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{88148E41-008F-4761-9BF2-687ED5551FDB}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25072.1611.3570.1995_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP-V2] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP-NoScope] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{15EC6D77-FB84-41F1-93F7-FE4E1E178AAD}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{16344EFD-3E69-431B-ACFE-5571A95BC07E}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{37D6985B-EDEB-4F28-A74D-15E38DDB5284}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{E7AD395E-1B8A-474E-B068-E77E00B7621E}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{D42DBA77-6791-4DEE-B982-F5AA7851EACE}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{98946207-AF1E-4488-8987-005782C57D98}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{335B8AED-7098-44A1-9F9A-01EBD7EFE208}] => (Allow) C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe () [File not signed]
 
==================== Restore Points =========================
 
29-04-2025 20:15:06 Windows Update
 
==================== Faulty Device Manager Devices ============
 
==================== Event log errors: ========================
 
Application errors:
==================
 
System errors:
=============
 
Windows Defender:
================
Date: 2025-04-27 22:57:30
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2025-04-27 21:01:53
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Patcher!MTB
Severity: High
Category: Tool
Path: containerfile:_C:\Users\Shiba\Downloads\MAGIX.VEGAS.Pro.v22.0.xxx.x64.Patch-TEAM-V.R.rar; file:_C:\Users\Shiba\Downloads\MAGIX.VEGAS.Pro.v22.0.xxx.x64.Patch-TEAM-V.R.rar->MAGIX VEGAS Pro v22.0 patch.exe; webfile:_C:\Users\Shiba\Downloads\MAGIX.VEGAS.Pro.v22.0.xxx.x64.Patch-TEAM-V.R.rar|about:internet|pid:9456,ProcessStart:133902865052093824
Detection Origin: Internet
Detection Type: Concrete
Detection Source: Downloads and attachments
Process Name: Unknown
Security intelligence Version: AV: 1.427.485.0, AS: 1.427.485.0, NIS: 1.427.485.0
Engine Version: AM: 1.1.25030.1, NIS: 1.1.25030.1 
 
Date: 2025-04-27 15:13:55
Description: 
Microsoft Defender Antivirus has detected a suspicious behavior.
Name: Behavior:Win32/ModifiedBootRecord
Severity: Low
Category: Suspicious Behavior
Path Found: file:_C:\Users\Shiba\Downloads\dmde-4-2-4-818-win64-gui\dmde.exe; process:_12232
Detection Origin: Local machine
Detection Type: Suspicious
Detection Source: Real-Time Protection
Status: Executing
Process Name: C:\Users\Shiba\Downloads\dmde-4-2-4-818-win64-gui\dmde.exe
Security intelligence ID: 23858570787236
Security intelligence Version: AV: 1.403.7.0, AS: 1.403.7.0
Engine Version: 1.1.23110.2
Fidelity Label:  Medium
Target File Name:  
 

CodeIntegrity:
===============
Date: 2025-04-29 02:39:34
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Microsoft signing level requirements. 
 
Date: 2025-04-29 02:39:33
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements. 
 
Date: 2025-04-29 02:29:57
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. 
 
 
==================== Memory info =========================== 
 
BIOS: American Megatrends International, LLC. F67d 09/02/2024
Motherboard: Gigabyte Technology Co., Ltd. B450 AORUS M
Processor: AMD Ryzen 5 3600 6-Core Processor 
Percentage of memory in use: 25%
Total physical RAM: 32691.44 MB
Available physical RAM: 24488.89 MB
Total Virtual: 37811.44 MB
Available Virtual: 29465.62 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:930.87 GB) (Free:563.53 GB) (Model: PNY CS900 1TB SSD) NTFS
Drive d: (Gamers) (Fixed) (Total:419.35 GB) (Free:419.17 GB) (Model: WDC CH SN530 SDBPTPZ-512G-1024) NTFS
Drive e: (UberFAST M.2) (Fixed) (Total:931.4 GB) (Free:88.72 GB) (Model: WD_BLACK SN770 1TB) NTFS
 
\\?\Volume{746a26ce-1ff8-41ab-8fca-facd97e9c0ce}\ () (Fixed) (Total:0.63 GB) (Free:0.07 GB) NTFS
\\?\Volume{6358cdc6-fce7-487b-9d73-6e163f98071b}\ () (Fixed) (Total:0.63 GB) (Free:0.11 GB) NTFS
\\?\Volume{c0d3af06-c080-4b6a-999e-7a9ffda8b382}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 073FFE7F)
 
Partition: GPT.
Attempted reading MBR returned 0 bytes.
 Could not read MBR for disk 2.
 
==================== End of Addition.txt =======================


#4 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 02:05 AM

DMDE, Disk Editor and Recovery Software, was software I used to restore a partition that ended up being deleted on my "UberFast M.2" drive during Win11 reinstall not too long ago btw.


Edited by Shiba-INK, 30 April 2025 - 02:19 AM.


#5 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 02:08 AM

Deleting Magix Vegas Pro 22, I knew he downloaded something.

 

Update: The install file no longer exists in C: Downloads

 

Update 2: It was in Defender Quarantine

 

Vegas Pro 22 Deleted, same with a couple pirated movies, we have a Pro 19 key from Humble Bundle so IDK why he downloaded 22 from who knows where.

 

Most of the audio-pugins have visible keys and are signed in with his Email so I'm going to leave them, they all passed a virus-total scan as well.

 

Update 3: I think I removed all the sketchy files I can find, I'll leave the rest up to whoever takes up helping me. Sidenote: I'm getting my good friend Alex his very own laptop.


Edited by Shiba-INK, 30 April 2025 - 02:35 AM.


#6 icotonev

icotonev

    Malware Hunter


  •  Avatar image
  • Malware Response Team
  • 513 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:58 AM

Posted 30 April 2025 - 06:51 AM

Hello..! BleepingComputer Forums..!  :welcome: My name is icotonev and I'm here to help you remove malware ..!
Please give me some time to examine your logs and I will get back to you as soon as possible. :)
 

Run CKScanner

  • Download CKScanner from here and save it to your desktop.
  • Doubleclick CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify that the file is saved.
  • Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

 

 

Check the operating system

  • Press Windows icon on your Desktop, together with the letter R.
  • Type cmd, and press Ctrl + Shift + Enter to run Command Prompt as administrator.
  • Copy and paste the following command and press Enter:

slmgr /dli

  • After running the command, you will get a report. Please take a screenshot of what you got and attach it in your next reply. Here is an article where you can see how do you take a screenshot with the snipping tool, in case you need it.

 

 

Scan with SecurityCheck by glax24

  • Temporarily disable Microsoft SmartScreen only if it blocks the download of the software. The program is safe
  • Download SecurityCheck by glax24 from here
  • If SmartScreen blocks the file from running click on More info and Run anyway
  • This tool is safe.   Smartscreen is overly sensitive. You can check the VirusTotal scan of the tool from here
  • Right-click  with your mouse on the Securitycheck.exe  and select "Run as administrator"  and reply YES to allow it to run
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt Close the file.  Attach it with your next reply.
  • You can find this file in a folder called SecurityCheckC:\SecurityCheck\SecurityCheck.txt

Hristo Tonev (Ico)  Member of UNITE 
 
 

 

#7 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 07:16 AM

I get a cloudflare host error for the CKScanner link

 

"Invalid SSL certificate"


Edited by Shiba-INK, 30 April 2025 - 07:22 AM.


#8 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 07:25 AM

Here's Security Check and a screenshot from the CMD

Attached Files


Edited by icotonev, 30 April 2025 - 07:57 AM.


#9 icotonev

icotonev

    Malware Hunter


  •  Avatar image
  • Malware Response Team
  • 513 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:58 AM

Posted 30 April 2025 - 07:26 AM

I get a cloudflare host error for the CKScanner link

 

"Invalid SSL certificate"

 

 

Yes it really is ..! Please continue with the next steps ..! 


Hristo Tonev (Ico)  Member of UNITE 
 
 

 

#10 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 07:37 AM

Sent both other steps just before you replied.



#11 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 07:44 AM

Here's Security Check and a screenshot from the CMD

Right here



#12 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 07:59 AM

Just in case it only sent on my end, it's happened before  :smash:

Attached Files


Edited by icotonev, 01 May 2025 - 10:50 AM.


#13 icotonev

icotonev

    Malware Hunter


  •  Avatar image
  • Malware Response Team
  • 513 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:02:58 AM

Posted 30 April 2025 - 08:03 AM



 

SecurityCheck by glax24 & Severnyj v.1.4.0.58 [15.08.24]

WebSite: www.safezone.cc
DateLog: 30.04.2025 05:20:23
Path starting: C:\Users\Shiba\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: Shiba
VersionXML: 13.73is-29.04.2025
___________________________________________________________________________
 
Windows 11 Professional (x64) Release: 24H2 (10.0.26100.3775) Lang: English(0409)
Installation date OS: 27.04.2025 21:37:56
LicenseStatus: Windows®, Professional edition The machine is permanently activated.
Boot Mode: Normal
Default Browser: C:\Program Files\Google\Chrome\Application\chrome.exe
SystemDrive: C: FS: [NTFS] Capacity: [930.9 Gb] Used: [391.6 Gb] Free: [539.3 Gb]
------------------------------- [ Windows ] -------------------------------
User Account Control enabled (Level 3)
Security Center (wscsvc) - The service is running
Remote Registry (RemoteRegistry) - The service has stopped
SSDP Discovery (SSDPSRV) - The service is running
Remote Desktop Services (TermService) - The service is running
Windows Remote Management (WS-Management) (WinRM) - The service has stopped
Background Intelligent Transfer Service (BITS) - The service has stopped
Delivery Optimization (DoSvc) - The service has stopped
Windows Security Service (SecurityHealthService) - The service is running
Update Orchestrator Service (UsoSvc) - The service is running
WaaSMedicSvc (WaaSMedicSvc) - The service has stopped
Windows Update (wuauserv) - The service has stopped
---------------------------- [ Antivirus_WMI ] ----------------------------
Avast Antivirus (disabled and out of date)
---------------------------- [ Firewall_WMI ] -----------------------------
Avast Antivirus (enabled)
---------------------- [ AntiVirusFirewallInstall ] -----------------------
Avast Premium Security v.25.3.9983.2649 Warning! Download Update
--------------------------- [ OtherUtilities ] ----------------------------
NVIDIA App 11.0.3.232 v.11.0.3.232
Microsoft Edge WebView2 Runtime v.122.0.2365.106 Warning! Download Update
If update errors occur, remove the old version, download and install the new one. Or reinstall Microsoft Edge browser.
Steam v.2.10.91.91
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810 v.14.40.33810.0 Warning! Download Update
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438 v.14.42.34438.0
--------------------------------- [ P2P ] ---------------------------------
qBittorrent v.5.1.0
-------------------------------- [ Java ] ---------------------------------
Java 8 Update 451 (64-bit) v.8.0.4510.10
Java 8 Update 451 v.8.0.4510.10
------------------------------- [ Browser ] -------------------------------
Avast Secure Browser v.134.0.29548.179 Warning! Browser installed as part of other software. Uninstall it if you do not use.
Google Chrome v.135.0.7049.115
Microsoft Edge v.122.0.2365.106 Warning! Download Update
Avast Update Helper v.1.8.1993.6 Warning! Browser installed as part of other software. Uninstall it if you do not use.
------------------ [ AntivirusFirewallProcessServices ] -------------------
aswbIDSAgent (aswbIDSAgent) - The service is running
C:\Program Files\Avast Software\Avast\aswidsagent.exe v.25.3.9983.0
C:\Program Files\Avast Software\Avast\aswEngSrv.exe v.25.3.9983.0
C:\Program Files\Avast Software\Avast\AvastUI.exe v.25.3.9983.970
C:\Program Files\Avast Software\Avast\afwServ.exe v.25.3.9983.0
AvastWscReporter (AvastWscReporter) - The service is running
C:\Program Files\Avast Software\Avast\wsc_proxy.exe v.21.4.6162.0
aswbIDSAgent (aswbIDSAgent) - The service is running
Avast Firewall Service (avast! Firewall) - The service is running
Avast Antivirus (avast! Antivirus) - The service is running
C:\Program Files\Avast Software\Avast\AvastSvc.exe v.25.3.9983.0
C:\Program Files\Avast Software\Avast\aswidsagent.exe v.25.3.9983.0
C:\Program Files\Avast Software\Avast\afwServ.exe v.25.3.9983.0
C:\Program Files\Avast Software\Avast\wsc_proxy.exe v.21.4.6162.0
C:\Program Files\Avast Software\Avast\aswEngSrv.exe v.25.3.9983.0
Microsoft Defender Core Service (MDCoreSvc) - The service is running
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe v.4.18.25030.2
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe v.4.18.25030.2
Microsoft Defender Antivirus Service (WinDefend) - The service is running
Microsoft Defender Antivirus Network Inspection Service (WdNisSvc) - The service has stopped
----------------------------- [ End of Log ] ------------------------------
 

 

 

 

  • Download the Revo Uninstaller (Free Download) and save it on your Desktop.
  • Double click on the exe file created on your Desktop to run the installer, and follow the instructions to install the program.
  • Double click the program's icon to open it.
  • Write in the search area, on the top left, the following program:

Avast Secure Browser v.134.0.29548.179 

Avast Update Helper v.1.8.1993.6 
  • Choose the Uninstall tab from the menu and let the program to create a Restore point.
  • Choose Scan, and then the Advanced mode scan.
  • Select all the Online Services items found, Delete and Next.
  • Let the procedure be completed and click on Finish.
  • Restart the computer.

 

Fresh FRST logs
 
Please run FRST tool once more, and attach for me fresh logs:

 

  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produce two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach these two logs in your next reply.
 
In your next reply, please post:
  • Fresh FRST logs

Edited by icotonev, 30 April 2025 - 08:04 AM.

Hristo Tonev (Ico)  Member of UNITE 
 
 

 

#14 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 08:15 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-04-2025
Ran by Shiba (administrator) on DESKTOP-H1BDJIG (Gigabyte Technology Co., Ltd. B450 AORUS M) (30-04-2025 06:09:00)
Running from C:\Users\Shiba\Downloads\FRST64.exe
Loaded Profiles: Shiba
Platform: Microsoft Windows 11 Pro Version 24H2 26100.3775 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
(Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\Microsoft-Edge-WebView\msedgewebview2.exe <6>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <11>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(explorer.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files\Razer\RzAppEngine\rzappengine.exe <5>
(Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2025.11030.12002.0_x64__8wekyb3d8bbwe\Photos.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) () [File not signed] C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\afwServ.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Maxon Computer GmbH -> ) C:\Program Files\Maxon\Tools\mxredirect.exe
(services.exe ->) (Maxon Computer GmbH -> Red Giant LLC) [File not signed] C:\Program Files\Red Giant\Services\Red Giant Service.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3cae04f75ee04f42\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.25032.52.0_x64__cw5n1h2txyewy\CrossDeviceService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_11.2503.5.0_x64__8wekyb3d8bbwe\Microsoft.Media.Player.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [856288 2019-10-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [454904 2025-04-30] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752208 2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
HKLM\...\Policies\Explorer: [HideSCAMeetNow] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableActivityFeed] 0
HKLM\Software\Policies\...\system: [PublishUserActivities] 0
HKLM\Software\Policies\...\system: [UploadUserActivities] 0
HKLM\Software\Policies\...\system: [AllowClipboardHistory] 0
HKLM\Software\Policies\...\system: [AllowCrossDeviceClipboard] 0
HKU\S-1-5-21-969771734-2463923209-239459422-1000\...\Run: [RzAppEngine] => C:\Program Files\Razer\RzAppEngine\rzappengine.exe [1640880 2019-08-30] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-969771734-2463923209-239459422-1000\...\Run: [MicrosoftEdgeAutoLaunch_1E1B238FE85BF2CDB3FC039B6D8A76D7] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4060608 2024-03-21] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-969771734-2463923209-239459422-1000\...\Policies\Explorer: [HideSCAMeetNow] 1
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\135.0.7049.115\Installer\chrmstp.exe [2025-04-28] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> "C:\Program Files\AVAST Software\Browser\Application\134.0.29548.179\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
IFEO\Red Giant Link.exe: [Debugger] dummy.exe
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {530A9257-543C-48CD-A2B5-B34314CB0C46} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [8702256 2025-04-25] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {AE7FD6CE-C34D-4D30-876B-3DE5350F07A2} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5286648 2025-04-30] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {A2637667-1C2F-44A7-BDD2-82E7D1513159} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2564904 2024-12-21] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {C2F3B73B-D815-4CBB-A871-632E0CABED3D} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [2856720 2025-04-27] (Microsoft Windows -> Microsoft Corporation)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
Task: {23A38425-B3E8-4321-86EB-0E3F4B358F42} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {69A81F5B-22F3-40BB-995F-A6641EE393B2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {250F2AD5-95F0-4928-BF16-58E960488334} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3F11C4EA-9583-4534-9171-C06C19FC4B21} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe [1745176 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{466459fc-1a02-418a-a69c-f2a7b9562d68}: [NameServer] 9.9.9.9,149.112.112.112
Tcpip\..\Interfaces\{466459fc-1a02-418a-a69c-f2a7b9562d68}: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{466459fc-1a02-418a-a69c-f2a7b9562d68}: [DhcpDomain] home
 
Edge: 
=======
Edge Profile: C:\Users\Shiba\AppData\Local\Microsoft\Edge\User Data\Default [2025-04-30]
Edge Extension: (Google Docs Offline) - C:\Users\Shiba\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-27]
Edge Extension: (Edge relevant text changes) - C:\Users\Shiba\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-04-27]
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.451.0 -> C:\Program Files\Java\jre1.8.0_451\bin\dtplugin\npDeployJava1.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.451.0 -> C:\Program Files\Java\jre1.8.0_451\bin\plugin2\npjp2.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.451.0 -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.451.0 -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\plugin2\npjp2.dll [No File]
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1993.6\npAvastBrowserUpdate3.dll [2025-04-28] (Avast Software s.r.o. -> Gen Digital Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\Shiba\AppData\Local\Google\Chrome\User Data\Default [2025-04-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Shiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-04-28]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7545648 2025-04-30] (Avast Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [193056 2025-04-28] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [809208 2025-04-30] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2484984 2025-04-30] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [861432 2025-04-30] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [193056 2025-04-28] (Avast Software s.r.o. -> Gen Digital Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2024-12-21] (Avast Software s.r.o. -> AVAST Software)
R2 Focusrite Control Server; C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe [1297920 2025-01-22] () [File not signed]
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpDefenderCoreService.exe [2009608 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 mxredirect; C:\Program Files\Maxon\Tools\mxredirect.exe [724776 2025-04-28] (Maxon Computer GmbH -> )
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3cae04f75ee04f42\Display.NvContainer\NVDisplay.Container.exe [1275560 2025-04-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 Red Giant Service; C:\Program Files\Red Giant\Services\Red Giant Service.exe [8872232 2022-06-24] (Maxon Computer GmbH -> Red Giant LLC) [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559320 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\NisSrv.exe [4538400 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MsMpEng.exe [278320 2025-04-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 AvastSecureBrowserElevationService; "C:\Program Files\AVAST Software\Browser\Application\134.0.29548.179\elevation_service.exe" [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [244320 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [390720 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [297568 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [85088 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [28280 2024-12-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [29792 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [279624 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [569920 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [92224 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [72256 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [881728 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [1272392 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [201792 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [391232 2025-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 FocusritePCIeSwRoot; C:\WINDOWS\System32\drivers\FocusritePCIeSwRoot.sys [106704 2024-09-20] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 FocusriteUsb; C:\WINDOWS\System32\drivers\FocusriteUsb.sys [170320 2024-09-20] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 FocusriteUsbAudio; C:\WINDOWS\System32\drivers\FocusriteUsbAudio.sys [109392 2024-09-20] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 FocusriteUsbSwRoot; C:\WINDOWS\System32\drivers\FocusriteUsbSwRoot.sys [112952 2024-09-20] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [331168 2025-04-27] (Microsoft Windows -> Microsoft Corporation)
S3 RevoProcessDetector; C:\WINDOWS\System32\DRIVERS\RevoProcessDetector.sys [19504 2024-03-28] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
S3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [12435144 2024-10-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
S3 SIVDriver; C:\WINDOWS\system32\Drivers\SIVX64.sys [205552 2021-02-12] (RH Software Ltd -> Ray Hinchliffe)
S3 ThermalFilter; C:\WINDOWS\System32\DriverStore\FileRepository\c_thermal.inf_amd64_732a53ed1662b707\ThermalFilter.sys [75376 2025-04-27] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
R1 ViGEmBus; C:\WINDOWS\System32\drivers\ViGEmBus.sys [249400 2022-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Nefarius Software Solutions e.U.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20016 2025-04-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [605576 2025-04-27] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-04-27] (Microsoft Windows -> Microsoft Corporation)
S3 wini3ctarget; C:\WINDOWS\System32\DriverStore\FileRepository\wini3ctarget.inf_amd64_bdb09ebda2834009\wini3ctarget.sys [75168 2025-04-27] (Microsoft Windows -> Microsoft Corporation)
U4 RLM-BorisFX; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2025-04-30 06:09 - 2025-04-30 06:09 - 000018585 _____ C:\Users\Shiba\Downloads\FRST.txt
2025-04-30 06:05 - 2025-04-30 06:05 - 000000000 ____D C:\Users\Shiba\AppData\Local\VS Revo Group
2025-04-30 06:05 - 2025-04-30 06:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2025-04-30 06:05 - 2025-04-30 06:05 - 000000000 ____D C:\Program Files\VS Revo Group
2025-04-30 05:39 - 2025-04-30 05:39 - 000005810 _____ C:\WINDOWS\system32\PerfStringBackup.TMP
2025-04-30 05:36 - 2025-04-30 05:37 - 000003612 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{9C0404A1-B02D-4A8E-B8EB-672862ABE1E8}
2025-04-30 05:36 - 2025-04-30 05:37 - 000003488 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{E9F057B0-4EA8-42B8-ADF2-8B33C3E9A758}
2025-04-30 05:31 - 2025-04-30 05:31 - 000320248 _____ (Gen Digital Inc.) C:\WINDOWS\system32\aswBoot.exe
2025-04-30 05:19 - 2025-04-30 05:20 - 000000000 ____D C:\SecurityCheck
2025-04-29 23:53 - 2025-04-30 06:09 - 000000000 ____D C:\FRST
2025-04-29 23:52 - 2025-04-29 23:52 - 002405376 _____ (Farbar) C:\Users\Shiba\Downloads\FRST64.exe
2025-04-29 23:50 - 2025-04-29 23:50 - 000001985 _____ C:\FMRS_2025_04_29__23_49_12.txt
2025-04-29 23:48 - 2025-04-29 23:48 - 000009435 _____ C:\FMRS_2025_04_29__23_47_08.txt
2025-04-29 21:17 - 2025-04-29 21:18 - 000000000 ____D C:\Program Files\Java
2025-04-29 21:17 - 2025-04-29 21:17 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Sun
2025-04-29 21:17 - 2025-04-29 21:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2025-04-29 21:17 - 2025-04-29 21:17 - 000000000 ____D C:\Program Files\Common Files\Oracle
2025-04-29 21:17 - 2025-04-05 03:39 - 000213120 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2025-04-29 20:35 - 2025-04-29 20:39 - 000000000 ____D C:\Users\Shiba\Doctor Web
2025-04-29 20:30 - 2025-04-29 20:37 - 001426277 _____ (<hxxps://furtivex.net>) C:\Users\Shiba\Downloads\FMRS.exe
2025-04-29 20:17 - 2025-04-29 20:22 - 000000000 ____D C:\AdwCleaner
2025-04-29 20:16 - 2025-04-29 20:16 - 009568256 _____ (Malwarebytes) C:\Users\Shiba\Downloads\adwcleaner.exe
2025-04-29 13:41 - 2025-04-29 13:43 - 000000000 ____D C:\KVRT2020_Data
2025-04-29 04:37 - 2025-04-30 05:11 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-04-29 04:35 - 2025-04-29 04:45 - 000000000 ____D C:\ProgramData\Malwarebytes
2025-04-29 04:23 - 2025-04-29 04:23 - 000949472 _____ (Trellix US LLC.) C:\WINDOWS\system32\Drivers\mfehidk.sys.f974.deleteme
2025-04-29 04:23 - 2025-04-29 04:23 - 000491232 _____ (Trellix US LLC.) C:\WINDOWS\system32\Drivers\mfeaack.sys.cd77.deleteme
2025-04-29 04:23 - 2025-04-29 04:23 - 000354016 _____ (Trellix US LLC.) C:\WINDOWS\system32\Drivers\mfeavfk.sys.a33a.deleteme
2025-04-29 04:23 - 2025-04-29 04:23 - 000106720 _____ (Trellix US LLC.) C:\WINDOWS\system32\Drivers\mfeplk.sys.47f4.deleteme
2025-04-29 04:23 - 2025-04-29 04:23 - 000060128 _____ (Trellix US LLC.) C:\WINDOWS\system32\Drivers\mfeaacsk.sys.5d23.deleteme
2025-04-29 04:23 - 2025-04-29 04:23 - 000000000 ____D C:\ProgramData\McAfee
2025-04-29 04:23 - 2025-04-29 04:23 - 000000000 ____D C:\Program Files\Common Files\McAfee
2025-04-29 04:14 - 2025-04-29 04:14 - 000000000 ____D C:\Program Files\Reference Assemblies
2025-04-29 04:14 - 2025-04-29 04:14 - 000000000 ____D C:\Program Files\MSBuild
2025-04-29 04:14 - 2025-04-29 04:14 - 000000000 ____D C:\Program Files (x86)\MSBuild
2025-04-29 04:04 - 2021-02-12 10:24 - 000205552 _____ (Ray Hinchliffe) C:\WINDOWS\system32\Drivers\SIVX64.sys
2025-04-29 03:38 - 2025-04-29 03:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boris FX Sapphire 2024.5 Photoshop
2025-04-29 03:38 - 2025-04-29 03:38 - 000000000 ____D C:\Program Files\Common Files\Nuke
2025-04-29 03:34 - 2025-04-29 03:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boris FX Sapphire 2024.5 OFX
2025-04-29 03:34 - 2025-04-29 03:34 - 000000000 ____D C:\ProgramData\GenArts
2025-04-29 03:34 - 2024-04-16 12:01 - 000000000 _____ C:\WINDOWS\MSUTIL.INI
2025-04-29 02:55 - 2025-04-29 02:55 - 000000000 ____D C:\ProgramData\SafeNet Sentinel
2025-04-29 02:27 - 2025-04-29 02:27 - 000000000 ____H C:\Users\Shiba\Documents\Default.rdp
2025-04-29 01:40 - 2025-04-29 01:40 - 000000000 ____D C:\ProgramData\Focusrite
2025-04-29 01:39 - 2025-04-29 01:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focusrite
2025-04-29 01:36 - 2025-04-29 01:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focusrite Drivers
2025-04-29 01:36 - 2024-09-19 16:47 - 000099928 _____ C:\WINDOWS\SysWOW64\FocusritePal32.dll
2025-04-29 01:36 - 2024-09-19 16:46 - 000111192 _____ C:\WINDOWS\system32\FocusritePal64.dll
2025-04-29 01:16 - 2025-04-29 01:16 - 000000000 ____D C:\Program Files\dotnet
2025-04-29 01:08 - 2025-04-29 01:08 - 000000318 _____ C:\WINDOWS\system32\httpproxy.json
2025-04-29 01:08 - 2025-04-29 01:08 - 000000027 _____ C:\WINDOWS\system32\ctc.json
2025-04-29 00:56 - 2025-04-29 00:56 - 000000000 ____D C:\ProgramData\Gemma
2025-04-29 00:56 - 2025-04-29 00:56 - 000000000 ____D C:\ProgramData\Atc
2025-04-29 00:55 - 2025-04-29 01:06 - 000000000 ____D C:\ProgramData\BDLogging
2025-04-29 00:55 - 2025-04-29 00:55 - 000000000 ____D C:\WINDOWS\system32\elambkup
2025-04-29 00:55 - 2025-04-29 00:55 - 000000000 ____D C:\ProgramData\48C4687D-9760-4F5B-BAB3-60351B0841E4
2025-04-29 00:54 - 2025-04-29 04:00 - 000000000 ____D C:\Program Files\Bitdefender
2025-04-29 00:54 - 2025-04-29 03:28 - 000000000 ____D C:\ProgramData\Bitdefender
2025-04-29 00:52 - 2025-04-29 00:53 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2025-04-27 22:56 - 2025-04-27 22:56 - 000000000 ____D C:\ProgramData\rgt
2025-04-27 22:55 - 2025-04-27 22:55 - 000000000 ____D C:\ProgramData\Tritik
2025-04-27 22:53 - 2025-04-27 22:53 - 000000000 ____D C:\ProgramData\Magix
2025-04-27 22:36 - 2025-04-27 22:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxon App
2025-04-27 22:35 - 2025-04-27 22:37 - 000000000 ____D C:\ProgramData\Maxon
2025-04-27 22:35 - 2025-04-27 22:35 - 000000074 _____ C:\ProgramData\WnHqYU0nH4
2025-04-27 22:33 - 2025-04-29 04:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boris FX Sapphire 2025 OFX
2025-04-27 22:33 - 2025-04-27 22:33 - 000000000 ____D C:\Users\Shiba\AppData\Local\BorisFX
2025-04-27 22:32 - 2025-04-29 03:36 - 000000000 ____D C:\Program Files\BorisFX
2025-04-27 22:32 - 2025-04-27 22:32 - 000000000 ____D C:\ProgramData\BorisFX
2025-04-27 22:25 - 2025-04-27 22:36 - 000000000 ____D C:\ProgramData\Red Giant
2025-04-27 22:25 - 2019-01-24 11:32 - 014069248 _____ (Red Giant LLC) C:\WINDOWS\system32\Universe.dll
2025-04-27 22:25 - 2015-10-23 03:54 - 005528064 _____ (Noesis Technologies) C:\WINDOWS\system32\Noesis.dll
2025-04-27 22:25 - 2000-03-10 09:53 - 000049152 ____S C:\WINDOWS\dummy.exe
2025-04-27 22:05 - 2025-04-27 22:10 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Toneboosters
2025-04-27 22:02 - 2025-04-27 22:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ToneBoosters
2025-04-27 22:02 - 2025-04-27 22:02 - 000000000 ____D C:\Program Files\ToneBoosters
2025-04-27 22:02 - 2024-11-23 09:00 - 000005528 _____ (TEAM R2R) C:\WINDOWS\system32\R2RINET.dll
2025-04-27 21:55 - 2025-04-27 21:56 - 000007510 _____ C:\WINDOWS\unins000.dat
2025-04-27 21:55 - 2025-04-27 21:55 - 001516011 _____ C:\WINDOWS\unins000.exe
2025-04-27 21:55 - 2025-04-27 21:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeverdieAudio
2025-04-27 21:54 - 2025-04-27 22:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope
2025-04-27 21:30 - 2025-04-27 21:30 - 000000000 ____D C:\Users\Public\Documents\Adobe
2025-04-27 21:24 - 2025-04-27 21:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2025-04-27 21:24 - 2025-04-27 21:24 - 000000000 ____D C:\Program Files\qBittorrent
2025-04-27 21:11 - 2025-04-27 21:11 - 000000000 ____D C:\ProgramData\obs-studio-hook
2025-04-27 21:11 - 2025-04-27 21:11 - 000000000 ____D C:\ProgramData\obs-studio
2025-04-27 21:11 - 2025-04-27 21:11 - 000000000 ____D C:\ProgramData\NeverdieAudio
2025-04-27 21:08 - 2025-04-27 22:55 - 000000000 ____D C:\ProgramData\VEGAS
2025-04-27 21:08 - 2025-04-27 21:08 - 000000000 ___HD C:\$AV_ASW
2025-04-27 21:08 - 2025-04-27 21:08 - 000000000 ____D C:\ProgramData\VEGAS Pro
2025-04-27 21:08 - 2025-04-27 21:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS
2025-04-27 21:04 - 2025-04-27 21:04 - 000000000 ____D C:\Users\Public\Documents\Blackmagic Design
2025-04-27 21:04 - 2025-04-27 21:04 - 000000000 ____D C:\ProgramData\Blackmagic Design
2025-04-27 20:56 - 2025-04-30 05:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2025-04-27 20:56 - 2025-04-27 23:00 - 000002206 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Premium Security.lnk
2025-04-27 20:56 - 2025-04-27 20:56 - 000000000 ____D C:\Users\Shiba\AppData\Local\DBG
2025-04-27 20:56 - 2025-04-27 20:56 - 000000000 ____D C:\ProgramData\redshift
2025-04-27 20:56 - 2025-04-27 20:56 - 000000000 ____D C:\Program Files (x86)\AVAST Software
2025-04-27 20:55 - 2025-04-30 05:35 - 000000000 ____D C:\ProgramData\Avast Software
2025-04-27 20:55 - 2025-03-27 06:19 - 000055064 _____ (Gen Digital Inc.) C:\WINDOWS\system32\icarus_rvrt.exe
2025-04-27 20:50 - 2025-04-27 20:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-04-27 20:45 - 2025-04-29 03:42 - 000000000 ____D C:\ProgramData\Reprise
2025-04-27 20:45 - 2025-04-12 05:25 - 000125048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2025-04-27 20:44 - 2025-04-30 02:55 - 000000000 ____D C:\Users\Public\Documents\Media Cache Files
2025-04-27 20:44 - 2025-04-30 02:55 - 000000000 ____D C:\Users\Public\Documents\Media Cache
2025-04-27 20:44 - 2025-04-27 20:44 - 000000000 ____D C:\Users\Public\Documents\Peak Files
2025-04-27 20:42 - 2025-04-13 23:16 - 002072456 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2025-04-27 20:42 - 2025-04-13 23:16 - 002072456 _____ C:\WINDOWS\system32\vulkaninfo.exe
2025-04-27 20:42 - 2025-04-13 23:16 - 001614216 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2025-04-27 20:42 - 2025-04-13 23:16 - 001614216 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2025-04-27 20:42 - 2025-04-13 23:16 - 001576840 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2025-04-27 20:42 - 2025-04-13 23:16 - 001576840 _____ C:\WINDOWS\system32\vulkan-1.dll
2025-04-27 20:42 - 2025-04-13 23:16 - 001389960 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2025-04-27 20:42 - 2025-04-13 23:16 - 001389960 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2025-04-27 20:42 - 2025-04-13 23:16 - 000478384 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2025-04-27 20:42 - 2025-04-13 23:16 - 000374960 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2025-04-27 20:42 - 2025-04-13 23:11 - 001259648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2025-04-27 20:42 - 2025-04-13 23:11 - 000674992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
2025-04-27 20:42 - 2025-04-13 23:11 - 000509104 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 026001536 _____ C:\WINDOWS\system32\nvidia-pcc.exe
2025-04-27 20:42 - 2025-04-13 23:10 - 002313872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 001713816 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 001569448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 001220784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 001053312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2025-04-27 20:42 - 2025-04-13 23:10 - 000942224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2025-04-27 20:42 - 2025-04-13 23:10 - 000810128 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2025-04-27 20:42 - 2025-04-13 23:09 - 023033472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2025-04-27 20:42 - 2025-04-13 23:09 - 000467064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2025-04-27 20:42 - 2025-04-13 23:08 - 020517016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2025-04-27 20:42 - 2025-04-13 23:08 - 007323280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2025-04-27 20:42 - 2025-04-13 23:08 - 005913744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2025-04-27 20:42 - 2025-04-13 23:08 - 005239936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2025-04-27 20:42 - 2025-04-13 23:08 - 003993752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2025-04-27 20:42 - 2025-04-13 23:08 - 000853144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2025-04-27 20:42 - 2025-04-13 23:06 - 005601032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2025-04-27 20:42 - 2025-04-13 23:06 - 004902688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2025-04-27 20:42 - 2025-04-12 05:25 - 000142952 _____ C:\WINDOWS\system32\nvinfo.pb
2025-04-27 20:41 - 2025-04-29 01:16 - 000000000 ____D C:\ProgramData\Package Cache
2025-04-27 20:41 - 2025-04-27 20:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2025-04-27 20:41 - 2025-04-07 09:14 - 003114016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2025-04-27 20:41 - 2025-04-07 09:14 - 002403360 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2025-04-27 20:41 - 2025-04-07 09:14 - 000271392 _____ C:\WINDOWS\system32\FvSDK_x64.dll
2025-04-27 20:41 - 2025-04-07 09:14 - 000245792 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
2025-04-27 20:41 - 2025-04-07 08:52 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2025-04-27 20:41 - 2025-04-07 08:52 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2025-04-27 20:40 - 2025-04-29 13:47 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2025-04-27 20:40 - 2025-04-07 08:52 - 000059928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2025-04-27 20:36 - 2025-04-30 04:59 - 000002586 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2025-04-27 20:35 - 2025-04-27 20:35 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-04-27 20:35 - 2025-04-27 20:35 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-04-27 20:35 - 2025-04-27 20:35 - 000001032 _____ C:\Users\Public\Desktop\Steam.lnk
2025-04-27 20:35 - 2025-04-27 20:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2025-04-27 20:35 - 2025-04-27 20:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2025-04-27 20:35 - 2025-04-27 20:35 - 000000000 ____D C:\Program Files\Google
2025-04-27 18:21 - 2025-04-27 18:21 - 000000400 __RSH C:\ProgramData\ntuser.pol
2025-04-27 18:19 - 2025-04-27 18:19 - 000000000 ____D C:\WINDOWS\system32\AccountHealthAssets
2025-04-27 18:19 - 2025-04-27 18:19 - 000000000 ____D C:\inetpub
2025-04-27 18:14 - 2025-04-27 18:14 - 000000000 ____D C:\Users\Shiba\AppData\Local\Rufus
2025-04-27 16:52 - 2025-04-27 16:52 - 000070484 _____ C:\WINDOWS\SysWOW64\ctac.json
2025-04-27 16:52 - 2025-04-27 16:52 - 000070484 _____ C:\WINDOWS\system32\ctac.json
2025-04-27 16:52 - 2025-04-27 16:52 - 000029042 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-04-27 16:52 - 2025-04-27 16:52 - 000029042 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-04-27 16:52 - 2025-04-27 16:52 - 000000998 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json
2025-04-27 16:49 - 2025-04-29 02:10 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-04-27 15:34 - 2025-04-29 04:28 - 000000000 ___DC C:\WINDOWS\Panther
2025-04-27 15:34 - 2025-04-27 15:34 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2025-04-27 15:13 - 2025-04-27 18:42 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\MMC
2025-04-27 14:55 - 2025-04-27 14:55 - 000000000 ____D C:\Users\Shiba\AppData\Local\Comms
2025-04-27 14:52 - 2019-10-30 02:20 - 001126344 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtCOM64.dll
2025-04-27 14:52 - 2019-10-30 02:20 - 000481888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2025-04-27 14:52 - 2019-10-29 23:20 - 000856288 _____ (Realtek Semiconductor) C:\WINDOWS\system32\RtkAudUService64.exe
2025-04-27 14:52 - 2019-10-29 23:20 - 000821336 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64U.dll
2025-04-27 14:52 - 2019-10-29 23:20 - 000215032 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2025-04-27 14:51 - 2025-04-30 05:34 - 000000000 ____D C:\ProgramData\NVIDIA
2025-04-27 14:51 - 2025-04-29 04:28 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2025-04-27 14:51 - 2025-04-27 20:47 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2025-04-27 14:51 - 2025-04-27 20:41 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-04-27 14:51 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\NVIDIA
2025-04-27 14:51 - 2019-10-30 02:20 - 005623256 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPOU64.dll
2025-04-27 14:48 - 2025-04-29 04:46 - 000000000 ____D C:\ProgramData\Realtek
2025-04-27 14:48 - 2025-04-29 01:34 - 000000000 ____D C:\ProgramData\Razer
2025-04-27 14:48 - 2025-04-27 12:18 - 000000000 ____D C:\Program Files (x86)\Razer
2025-04-27 14:48 - 2023-06-16 07:33 - 000161920 _____ (Razer Inc) C:\WINDOWS\system32\RazerS3CoinstallerEx.dll
2025-04-27 14:46 - 2025-04-30 05:34 - 000001460 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-04-27 14:46 - 2025-04-27 20:52 - 000000000 ____D C:\Users\Shiba\AppData\Local\PlaceholderTileLogoFolder
2025-04-27 14:43 - 2025-04-29 04:35 - 000000000 ___RD C:\Users\Shiba\OneDrive
2025-04-27 14:42 - 2025-04-29 04:50 - 000836650 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-04-27 14:41 - 2025-04-27 14:41 - 000000000 ____D C:\Users\Shiba\AppData\Local\Publishers
2025-04-27 14:40 - 2025-04-30 05:24 - 000000000 ____D C:\Users\Shiba\AppData\Local\D3DSCache
2025-04-27 14:40 - 2025-04-27 14:40 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Network
2025-04-27 14:39 - 2025-04-30 05:34 - 000000000 ____D C:\Users\Shiba
2025-04-27 14:39 - 2025-04-29 04:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Packages
2025-04-27 14:39 - 2025-04-27 14:39 - 000000020 ___SH C:\Users\Shiba\ntuser.ini
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 ___SD C:\Users\Shiba\AppData\Roaming\Microsoft\SystemCertificates
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 ___SD C:\Users\Shiba\AppData\Roaming\Microsoft\Crypto
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 ___SD C:\Users\Shiba\AppData\Roaming\Microsoft\Credentials
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Vault
2025-04-27 14:39 - 2025-04-27 14:39 - 000000000 ____D C:\Users\Shiba\AppData\Local\VirtualStore
2025-04-27 14:39 - 2025-04-27 11:47 - 000000000 ___SD C:\Users\Shiba\AppData\Roaming\Microsoft\Protect
2025-04-27 14:39 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows
2025-04-27 14:39 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Spelling
2025-04-27 14:39 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Adobe
2025-04-27 14:39 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\ConnectedDevicesPlatform
2025-04-27 14:37 - 2025-04-29 04:35 - 000000000 ____D C:\ProgramData\Packages
2025-04-27 14:37 - 2025-04-27 14:37 - 000000000 _SHDL C:\Documents and Settings
2025-04-27 14:37 - 2025-04-27 14:37 - 000000000 ____D C:\WINDOWS\CSC
2025-04-27 14:36 - 2025-04-30 05:44 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-04-27 14:36 - 2025-04-27 14:36 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2025-04-27 14:35 - 2025-04-30 05:34 - 000296960 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-04-27 14:35 - 2025-04-30 05:34 - 000012288 ___SH C:\DumpStack.log.tmp
2025-04-27 14:35 - 2025-04-30 05:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-04-27 14:35 - 2025-04-29 14:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-04-27 14:35 - 2025-04-27 16:45 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-04-27 14:35 - 2025-04-27 14:35 - 000000000 ____D C:\WINDOWS\system32\config\BFS
2025-04-27 14:35 - 2025-04-27 14:35 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2025-04-27 13:07 - 2025-04-26 16:32 - 000000000 ____D C:\Program Files (x86)\ZeroTier
2025-04-27 13:07 - 2025-04-26 16:32 - 000000000 ____D C:\Program Files (x86)\VstPlugins
2025-04-27 13:07 - 2025-04-26 16:32 - 000000000 ____D C:\Program Files (x86)\VEGAS
2025-04-27 13:06 - 2025-04-27 13:06 - 000000000 ____D C:\Program Files (x86)\Tobias Erichsen
2025-04-27 13:06 - 2025-04-26 16:32 - 000000000 ____D C:\Program Files (x86)\Ubisoft
2025-04-27 12:18 - 2025-04-29 13:47 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2025-04-27 12:18 - 2025-04-27 20:35 - 000000000 ____D C:\Program Files (x86)\Steam
2025-04-27 12:18 - 2025-04-27 12:18 - 000000000 ____D C:\Program Files (x86)\Razer Chroma SDK
2025-04-27 12:18 - 2025-04-27 12:18 - 000000000 ____D C:\Program Files (x86)\Radmin VPN
2025-04-27 12:18 - 2025-04-27 12:18 - 000000000 ____D C:\Program Files (x86)\Overwolf
2025-04-27 12:18 - 2025-04-27 12:18 - 000000000 ____D C:\Program Files (x86)\obs-studio
2025-04-27 12:18 - 2025-04-26 16:18 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2025-04-27 12:17 - 2025-04-27 20:41 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\ImgBurn
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\Google
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\Free Video Compressor
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\Epic Games
2025-04-27 12:17 - 2025-04-27 12:17 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat_EOS
2025-04-27 12:17 - 2025-04-26 16:17 - 000000000 ____D C:\Program Files (x86)\NewBlueFX
2025-04-27 12:16 - 2025-04-27 21:56 - 000000000 ____D C:\Program Files\VSTPlugins
2025-04-27 12:16 - 2025-04-27 20:49 - 000000000 ____D C:\Program Files\WinRAR
2025-04-27 12:16 - 2025-04-27 12:16 - 000000000 ____D C:\Program Files\Voice.ai
2025-04-27 12:16 - 2025-04-27 12:16 - 000000000 ____D C:\Program Files\_uninstaller
2025-04-27 12:16 - 2025-04-27 12:16 - 000000000 ____D C:\Program Files (x86)\Battle.net
2025-04-27 12:16 - 2025-04-27 12:16 - 000000000 ____D C:\Program Files (x86)\Auburn Sounds
2025-04-27 12:16 - 2025-04-27 12:16 - 000000000 ____D C:\Program Files (x86)\Adobe
2025-04-27 12:16 - 2025-04-26 16:52 - 000000000 ____D C:\Program Files\VideoLAN
2025-04-27 12:16 - 2025-04-26 16:17 - 000000000 ____D C:\Program Files (x86)\Blackmagic Design
2025-04-27 12:15 - 2025-04-27 22:36 - 000000000 ____D C:\Program Files\Red Giant
2025-04-27 12:15 - 2025-04-27 21:40 - 000000000 ____D C:\Program Files\VEGAS
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\ToneLib
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\Tokyo Dawn Labs
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\Tobias Erichsen
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\Sonic Charge
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\Razer
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\PowerISO
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\Pinnacle
2025-04-27 12:15 - 2025-04-27 12:15 - 000000000 ____D C:\Program Files\obs-studio
2025-04-27 12:15 - 2025-04-26 16:52 - 000000000 ____D C:\Program Files\Steinberg
2025-04-27 12:15 - 2025-04-26 16:52 - 000000000 ____D C:\Program Files\Razer Chroma SDK
2025-04-27 12:14 - 2025-04-27 22:50 - 000000000 ____D C:\Program Files\iZotope
2025-04-27 12:14 - 2025-04-27 22:02 - 000000000 ____D C:\Program Files\Common Files\VST3
2025-04-27 12:14 - 2025-04-27 21:55 - 000000000 ____D C:\Program Files\NeverdieAudio
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\NewBlueFX
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Maxon Cinema 4D 2025
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Maxon
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\FreakshowIndustries
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Focusrite
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\FabFilter
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Common Files\Steinberg
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Common Files\Sonic Charge
2025-04-27 12:14 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2025-04-27 12:14 - 2025-04-26 16:51 - 000000000 ____D C:\Program Files\Nefarius Software Solutions
2025-04-27 12:14 - 2025-04-26 16:51 - 000000000 ____D C:\Program Files\Common Files\OFX
2025-04-27 12:14 - 2025-04-26 16:51 - 000000000 ____D C:\Program Files\Common Files\Avid
2025-04-27 12:14 - 2024-09-19 17:10 - 000170320 _____ (Focusrite Audio Engineering Ltd.) C:\WINDOWS\system32\Drivers\FocusriteUsb.sys
2025-04-27 12:14 - 2024-09-19 17:10 - 000112952 _____ (Focusrite Audio Engineering Ltd.) C:\WINDOWS\system32\Drivers\FocusriteUsbSwRoot.sys
2025-04-27 12:14 - 2024-09-19 17:10 - 000109392 _____ (Focusrite Audio Engineering Ltd.) C:\WINDOWS\system32\Drivers\FocusriteUsbAudio.sys
2025-04-27 12:14 - 2024-09-19 17:10 - 000106704 _____ (Focusrite Audio Engineering Ltd.) C:\WINDOWS\system32\Drivers\FocusritePCIeSwRoot.sys
2025-04-27 12:13 - 2025-04-27 12:14 - 000000000 ____D C:\Program Files\Common Files\Adobe
2025-04-27 12:11 - 2025-04-27 20:57 - 000000000 ____D C:\Program Files\Avast Software
2025-04-27 12:11 - 2025-04-27 12:11 - 000000000 ____D C:\Program Files\Bertom Audio
2025-04-27 12:11 - 2025-04-27 12:11 - 000000000 ____D C:\Program Files\Audacity
2025-04-27 12:11 - 2025-04-27 12:11 - 000000000 ____D C:\Program Files\Antares Audio Technologies
2025-04-27 12:06 - 2025-04-27 12:10 - 000000000 ____D C:\Program Files\Adobe
2025-04-27 12:05 - 2025-04-30 04:59 - 000000000 ____D C:\Users\Shiba\Downloads\YO
2025-04-27 12:05 - 2025-04-27 12:05 - 000000000 ____D C:\XboxGames
2025-04-27 12:05 - 2025-04-27 12:05 - 000000000 ____D C:\Users\Shiba\Downloads\RUST MIDI
2025-04-27 12:03 - 2025-04-27 12:03 - 000000000 ____D C:\Users\Shiba\Downloads\OLD SCHOOL GAMES VIDEO
2025-04-27 12:03 - 2025-04-27 12:03 - 000000000 ____D C:\Users\Shiba\Downloads\MODs
2025-04-27 12:02 - 2025-04-27 12:03 - 000000000 ____D C:\Users\Shiba\Downloads\LUTS
2025-04-27 12:02 - 2025-04-27 12:02 - 000000000 ____D C:\Users\Shiba\Downloads\KONG
2025-04-27 12:02 - 2025-04-27 12:02 - 000000000 ____D C:\Users\Shiba\Downloads\KeepSakes
2025-04-27 12:02 - 2025-04-27 12:02 - 000000000 ____D C:\Users\Shiba\Downloads\BACKGROUND
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\VEGAS
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\ToneLib
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Rockstar Games
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Red Giant
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\OpenIV
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\OFX Presets
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\NewBlue
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\My Games
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\iZotope
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Blackmagic Design
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Assassin's Creed Unity
2025-04-27 12:01 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Arma 3
2025-04-27 12:01 - 2025-04-26 16:44 - 000000000 ____D C:\Users\Shiba\Documents\NeverdieAudio
2025-04-27 12:01 - 2025-04-26 16:44 - 000000000 ____D C:\Users\Shiba\Documents\FabFilter
2025-04-27 12:01 - 2025-04-26 16:44 - 000000000 ____D C:\Users\Shiba\Documents\Call of Duty
2025-04-27 12:01 - 2025-04-26 16:44 - 000000000 ____D C:\Users\Shiba\Documents\Arma 3 - Other Profiles
2025-04-27 12:01 - 2025-03-20 21:25 - 000000000 ____D C:\Users\Shiba\Documents\Sonic Charge
2025-04-27 12:01 - 2025-02-25 04:10 - 000000000 ____D C:\Users\Shiba\Documents\My Cheat Tables
2025-04-27 12:01 - 2025-01-12 23:01 - 000000000 ____D C:\Users\Shiba\Documents\Audacity
2025-04-27 11:59 - 2025-04-27 12:01 - 000000000 ____D C:\Users\Shiba\Documents\Adobe
2025-04-27 11:59 - 2025-04-27 11:59 - 000000000 ____D C:\Users\Shiba\Documents\Accusonus
2025-04-27 11:55 - 2025-04-27 11:58 - 000000000 ____D C:\Users\Shiba\Desktop\YouTube Recordings
2025-04-27 11:55 - 2025-04-27 11:55 - 000000000 ____D C:\Users\Shiba\Desktop\Too many files
2025-04-27 11:54 - 2025-04-30 04:59 - 000000000 ____D C:\Users\Shiba\Desktop\JORDO
2025-04-27 11:54 - 2025-04-26 16:43 - 000000000 ____D C:\Users\Shiba\Desktop\Junk & Memes
2025-04-27 11:53 - 2025-04-29 13:47 - 000001155 _____ C:\Users\Shiba\Desktop\MSI Afterburner.lnk
2025-04-27 11:53 - 2025-04-27 11:54 - 000000000 ____D C:\Users\Shiba\Desktop\Garbage WIP
2025-04-27 11:53 - 2025-04-25 12:01 - 000000223 _____ C:\Users\Shiba\Desktop\Stray.url
2025-04-27 11:53 - 2025-04-23 21:33 - 000002247 _____ C:\Users\Shiba\Desktop\Discord.lnk
2025-04-27 11:53 - 2025-04-18 13:59 - 000000222 _____ C:\Users\Shiba\Desktop\Far Cry 5.url
2025-04-27 11:53 - 2025-04-11 22:34 - 000000223 _____ C:\Users\Shiba\Desktop\It Takes Two.url
2025-04-27 11:53 - 2025-04-11 22:32 - 000000222 _____ C:\Users\Shiba\Desktop\Terraria.url
2025-04-27 11:53 - 2025-04-04 00:08 - 162197336 _____ C:\Users\Shiba\Desktop\BRUH.mp4
2025-04-27 11:53 - 2025-04-02 04:55 - 000002297 _____ C:\Users\Shiba\Desktop\Replay.lnk
2025-04-27 11:53 - 2025-03-29 00:46 - 000000222 _____ C:\Users\Shiba\Desktop\Cry of Fear.url
2025-04-27 11:53 - 2025-03-23 22:25 - 000002321 _____ C:\Users\Shiba\Desktop\Thunderstore Mod Manager.lnk
2025-04-27 11:53 - 2025-03-23 22:25 - 000002321 _____ C:\Users\Shiba\Desktop\CurseForge.lnk
2025-04-27 11:53 - 2025-03-20 21:37 - 000000222 _____ C:\Users\Shiba\Desktop\Phasmophobia.url
2025-04-27 11:53 - 2025-03-17 22:18 - 000000223 _____ C:\Users\Shiba\Desktop\R.E.P.O..url
2025-04-27 11:53 - 2025-03-17 18:53 - 000000018 _____ C:\Users\Shiba\Desktop\Write down new backup codes shiba.txt
2025-04-27 11:53 - 2025-03-13 17:18 - 000000222 _____ C:\Users\Shiba\Desktop\Arma 3.url
2025-04-27 11:53 - 2025-03-05 04:12 - 000000219 _____ C:\Users\Shiba\Desktop\Half-Life 2.url
2025-04-27 11:53 - 2025-02-24 19:20 - 000000233 _____ C:\Users\Shiba\Desktop\Assassin’s Creed Unity.url
2025-04-27 11:53 - 2025-02-24 13:32 - 000000000 _____ C:\Users\Shiba\Desktop\May Photography.txt
2025-04-27 11:53 - 2025-01-27 21:01 - 000000223 _____ C:\Users\Shiba\Desktop\Backrooms Escape Together.url
2025-04-27 11:53 - 2025-01-26 02:16 - 000000223 _____ C:\Users\Shiba\Desktop\Zort.url
2025-04-27 11:53 - 2025-01-26 02:16 - 000000223 _____ C:\Users\Shiba\Desktop\Nuclear Nightmare.url
2025-04-27 11:53 - 2025-01-25 07:50 - 000000222 _____ C:\Users\Shiba\Desktop\Valheim.url
2025-04-27 11:53 - 2025-01-24 02:26 - 000000220 _____ C:\Users\Shiba\Desktop\Garry's Mod.url
2025-04-27 11:53 - 2024-12-24 18:47 - 000000222 _____ C:\Users\Shiba\Desktop\DARK SOULS™ II Scholar of the First Sin.url
2025-04-27 11:53 - 2024-12-23 16:22 - 000000223 _____ C:\Users\Shiba\Desktop\BABBDI.url
2025-04-27 11:53 - 2024-12-23 16:18 - 000000222 _____ C:\Users\Shiba\Desktop\Awkward Dimensions Redux.url
2025-04-27 11:53 - 2024-12-21 12:37 - 000000223 _____ C:\Users\Shiba\Desktop\Lethal Company.url
2025-04-27 11:53 - 2024-12-21 12:37 - 000000223 _____ C:\Users\Shiba\Desktop\Combat Master.url
2025-04-27 11:53 - 2024-12-21 12:37 - 000000222 _____ C:\Users\Shiba\Desktop\Rust.url
2025-04-27 11:53 - 2024-12-21 12:36 - 000000223 _____ C:\Users\Shiba\Desktop\Liar's Bar.url
2025-04-27 11:53 - 2024-12-20 21:10 - 000001327 _____ C:\Users\Shiba\Desktop\Ubisoft Connect.lnk
2025-04-27 11:52 - 2025-04-28 13:03 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\vlc
2025-04-27 11:52 - 2025-04-27 11:52 - 000000000 __SHD C:\Users\Shiba\AppData\Roaming\u-data
2025-04-27 11:52 - 2025-04-27 11:52 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\VEGAS Pro
2025-04-27 11:52 - 2025-04-27 11:52 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\VEGAS
2025-04-27 11:52 - 2025-04-27 11:52 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Tonelib
2025-04-27 11:52 - 2025-04-27 11:52 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Tokyo Dawn Labs
2025-04-27 11:52 - 2025-04-26 16:41 - 000000000 ____D C:\Users\Shiba\curseforge
2025-04-27 11:52 - 2025-04-26 16:41 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\WinRAR
2025-04-27 11:52 - 2025-04-26 16:41 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Tritik
2025-04-27 11:49 - 2025-04-27 11:49 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\SCP Secret Laboratory
2025-04-27 11:49 - 2025-04-27 11:49 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Rustangelo
2025-04-27 11:49 - 2025-04-27 11:49 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\RS2V
2025-04-27 11:49 - 2025-04-26 16:40 - 000000000 ___HD C:\Users\Shiba\AppData\Roaming\s-configs
2025-04-27 11:49 - 2025-04-26 16:40 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Thunderstore Mod Manager
2025-04-27 11:47 - 2025-04-30 03:23 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Replay
2025-04-27 11:47 - 2025-04-29 03:35 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\qBittorrent
2025-04-27 11:47 - 2025-04-29 01:17 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\DS4Windows
2025-04-27 11:47 - 2025-04-27 21:56 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\obs-studio
2025-04-27 11:47 - 2025-04-27 21:56 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\NeverdieAudio
2025-04-27 11:47 - 2025-04-27 20:50 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ___RD C:\Users\Shiba\AppData\Roaming\Nuro Audio
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\NRCSDK
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxon App
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blackmagic Design
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\HTML Help
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\MAGIX
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\iZotope
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\FabFilter
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\ERModsManager
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Electronic Arts
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\EldenRing
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\EasyAntiCheat
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\discord
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\com.adobe.dunamis
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Bitdefender Security App
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Battle.net
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\audacity
2025-04-27 11:47 - 2025-04-27 11:47 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Antares
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ___HD C:\Users\Shiba\AppData\Roaming\c-data
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\NVIDIA
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\NetEase
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\MarvelRivals_Launcher
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Freakshow
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Elgato
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Blackmagic Design
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Bertom Audio
2025-04-27 11:47 - 2025-04-26 16:38 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Avast Software
2025-04-27 11:47 - 2025-04-25 16:55 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ToneLib-NoiseReducer
2025-04-27 11:47 - 2025-04-02 04:55 - 000002305 _____ C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Replay.lnk
2025-04-27 11:47 - 2025-03-07 12:22 - 000001306 _____ C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\OpenIV.lnk
2025-04-27 11:47 - 2025-03-06 14:37 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Voice ai
2025-04-27 11:46 - 2025-04-29 13:40 - 000000000 ____D C:\Users\Shiba\AppData\Local\NVIDIA
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 __SHD C:\Users\Shiba\AppData\Roaming\a-resources
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Roaming\.minecraft
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Sun
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\konza
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Adobe
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\ZeroTier
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Voice.ai
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\VEGAS Pro
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\UnrealEngineLauncher
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\UnrealEngine
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\UniSDK
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\UniCompactView
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Ubisoft Game Launcher
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\ToastNotificationManagerCompat
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Steam
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\SplitFiction
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Sony
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Smithbox
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Rockstar Games
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\replay-updater
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Red Giant
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Razer
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\qBittorrent
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Plugin.OfxStitch
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Plugin.ofx360Stabilizer
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Plugin.MxOfxRotation
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Overwolf
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\NVIDIA Corporation
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\New Technology Studio
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Netease
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\Maxon
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\MarvelRivals_Launcher
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\MAGIX
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\LogMeIn
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\iZotope
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\ItTakesTwo
2025-04-27 11:46 - 2025-04-27 11:46 - 000000000 ____D C:\Users\Shiba\AppData\Local\INetHistory
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\TVGS
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\semiwork
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Northwood
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Londer Software
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Kinetic Games
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\IronGate
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Hello Crime
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Facepunch Studios LTD
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\DefaultCompany
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\Curve Animation
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\LocalLow\AlfaBravoInc
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\Local\UnrealEdge
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\Local\UniSDK_FirstOpen
2025-04-27 11:46 - 2025-04-26 16:37 - 000000000 ____D C:\Users\Shiba\AppData\Local\Photoshop1-26-WIN
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\NVIDIA Profile Inspector
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\numba
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\NuclearNightmare
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\NgConsentManager
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\NewBlue
2025-04-27 11:46 - 2025-04-26 16:36 - 000000000 ____D C:\Users\Shiba\AppData\Local\MinecraftInstaller
2025-04-27 11:46 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\mbamtray
2025-04-27 11:46 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\MaxonApp
2025-04-27 11:46 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Marvel
2025-04-27 11:46 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Hk_project
2025-04-27 11:46 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\HarshDoorstop
2025-04-27 11:46 - 2025-02-26 22:02 - 000000000 ____D C:\Users\Shiba\AppData\Local\PeerDistRepub
2025-04-27 11:46 - 2024-12-21 00:18 - 000000000 ____D C:\Users\Shiba\AppData\Local\VEGAS
2025-04-27 11:45 - 2025-04-29 23:38 - 000000000 ____D C:\Users\Shiba\AppData\Local\CrashDumps
2025-04-27 11:45 - 2025-04-27 20:57 - 000000000 ____D C:\Users\Shiba\AppData\Local\Avast Software
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\GameAnalytics
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\EpicGamesLauncher
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Discord
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\DaVinci Resolve Welcome
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\CEF
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\cache
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Bohemia_Interactive
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Blizzard Entertainment
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Bitdefender
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\BET
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Battle.net
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\audacity
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Athena
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Arma 3 Launcher
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Arma 3
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\appsflyer
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Adobe
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\Activision
2025-04-27 11:45 - 2025-04-27 11:45 - 000000000 ____D C:\Users\Shiba\AppData\Local\accusonus
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Google
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Fluffy
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Epic Games
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\CrashReportClient
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\BattlEye
2025-04-27 11:45 - 2025-04-26 16:35 - 000000000 ____D C:\Users\Shiba\AppData\Local\Backup
2025-04-27 11:45 - 2024-12-21 14:22 - 000000000 ____D C:\Users\Shiba\AppData\Local\AWSToolkit
2025-04-08 16:01 - 2025-04-08 16:01 - 000120200 _____ () C:\WINDOWS\SysWOW64\DLLDEV32i.dll
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2025-04-30 06:05 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-04-30 06:01 - 2024-04-01 00:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-04-30 05:39 - 2024-04-01 00:24 - 000000000 ____D C:\WINDOWS\INF
2025-04-30 05:34 - 2024-04-01 00:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-04-30 05:34 - 2024-04-01 00:21 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2025-04-30 00:04 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-04-29 20:15 - 2024-04-01 00:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-04-29 04:14 - 2024-10-04 16:59 - 001175072 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2025-04-29 04:14 - 2024-10-04 16:59 - 000780720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2025-04-29 04:00 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-04-29 00:59 - 2024-04-01 00:21 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2025-04-27 20:58 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\WebThreatDefSvc
2025-04-27 20:42 - 2024-04-01 00:26 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\WINDOWS\InboxApps
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-04-27 18:19 - 2024-04-01 01:03 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ___SD C:\WINDOWS\system32\UNP
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ___RD C:\Program Files\Windows Defender
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\UUS
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SystemApps
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\setup
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\ProgramData\USOPrivate
2025-04-27 18:19 - 2024-04-01 00:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-04-27 18:19 - 2024-04-01 00:21 - 000000000 ____D C:\WINDOWS\servicing
2025-04-27 16:59 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2025-04-27 16:58 - 2024-04-01 00:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2025-04-27 16:44 - 2024-04-01 00:26 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2025-04-27 15:34 - 2024-04-01 00:26 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2025-04-27 15:34 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\appcompat
2025-04-27 14:40 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\spool
2025-04-27 14:39 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2025-04-27 14:38 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\ServiceState
2025-04-27 14:37 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2025-04-27 14:35 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-04-2025
Ran by Shiba (30-04-2025 06:10:43)
Running from C:\Users\Shiba\Downloads
Microsoft Windows 11 Pro Version 24H2 26100.3775 (X64) (2025-04-27 21:37:56)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-969771734-2463923209-239459422-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-969771734-2463923209-239459422-503 - Limited - Disabled)
Guest (S-1-5-21-969771734-2463923209-239459422-501 - Limited - Disabled)
Shiba (S-1-5-21-969771734-2463923209-239459422-1000 - Administrator - Enabled) => C:\Users\Shiba
WDAGUtilityAccount (S-1-5-21-969771734-2463923209-239459422-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
FW: Avast Antivirus (Enabled) {D322394B-73F7-C65E-BBB0-3B81E063D6D4}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Avast Premium Security (HKLM\...\Avast Antivirus) (Version: 25.4.10068.2727 - Gen Digital Inc.)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1993.6 - AVAST Software) Hidden
Boris FX Mocha Plug-ins 2024 for OFX (HKLM\...\{3B6C7E9D-7CAA-47F7-846E-47E8FB102747}) (Version: 11.02.32 - Boris FX, Inc.)
Boris FX Sapphire Plug-ins 2024.5 for OFX (HKLM\...\GenArts Sapphire Plug-ins for OFX_is1) (Version: 17.5 - Boris FX, Inc.)
Boris FX Sapphire Plug-ins 2024.5 for Photoshop (HKLM\...\GenArts Sapphire PS_is1) (Version: 17.5 - Boris FX, Inc.)
Focusrite Audio Drivers 4.124.3.5 (HKLM\...\Focusrite Audio Drivers_is1) (Version: 4.124.3.5 - Focusrite Audio Engineering, Ltd.)
Focusrite Control 3.20.0.220 (HKLM\...\Focusrite Control_is1) (Version: 3.20.0.220 - Focusrite Audio Engineering Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 135.0.7049.115 - Google LLC)
iZotope Nectar 4 Advanced (HKLM\...\iZotope Nectar 4 Advanced_is1) (Version: 4.0.1 - iZotope)
iZotope Plasma (HKLM\...\iZotope Plasma_is1) (Version: 1.0.1 - iZotope)
iZotope Vinyl (HKLM\...\iZotope Vinyl_is1) (Version: 1.12.1 - iZotope)
Java 8 Update 451 (64-bit) (HKLM\...\{71024AE4-039E-4CA4-87B4-2F64180451F0}) (Version: 8.0.4510.10 - Oracle Corporation)
Java 8 Update 451 (HKLM-x32\...\{71024AE4-039E-4CA4-87B4-2F32180451F0}) (Version: 8.0.4510.10 - Oracle Corporation)
Magic Bullet Suite (HKLM\...\Magic Bullet Suite v16.1.0) (Version:  - Maxon Computer GmbH)
Maxon App (HKLM\...\Maxon App v3.1.1) (Version:  - Maxon Computer GmbH)
Microsoft .NET Host - 8.0.15 (x64) (HKLM\...\{4C903F19-B4C3-4D0C-8CC9-D444C511AF1C}) (Version: 64.60.31149 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.15 (x64) (HKLM\...\{11CCC9F6-77AA-4421-9EAC-BAEC36D96817}) (Version: 64.60.31149 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.15 (x64) (HKLM\...\{8731E6E3-AF96-4515-ACEC-DBFB3DF55292}) (Version: 64.60.31149 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 135.0.3179.98 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 135.0.3179.98 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438 (HKLM-x32\...\{b49c10dd-4d54-45f8-ad13-fa25704456a4}) (Version: 14.42.34438.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810 (HKLM-x32\...\{47109d57-d746-4f8b-9618-ed6a17cc922b}) (Version: 14.40.33810.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34438 (HKLM\...\{E528AD94-12D7-42C4-91A3-908BE28E9BD2}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34438 (HKLM\...\{2E15F519-4FDA-4834-B4EE-7EFCE7D8D4EE}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.40.33810 (HKLM-x32\...\{5EA6C998-D5AC-4ED9-89C3-9F25B17CCD3D}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.40.33810 (HKLM-x32\...\{0C3457A0-3DCE-4A33-BEF0-9B528C557771}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.15 (x64) (HKLM\...\{0E4A7820-FDA4-4250-B7AC-E7A2F7B43B64}) (Version: 64.60.31203 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.15 (x64) (HKLM-x32\...\{5625bb48-295c-4113-bc92-d6a69b19b04c}) (Version: 8.0.15.34718 - Microsoft Corporation)
MSI Afterburner 4.6.5 (HKLM-x32\...\Afterburner) (Version: 4.6.5 - MSI Co., LTD)
NeverdieAudio Speachy (HKLM\...\NeverdieAudio Speachy_is1) (Version: 1.0 - NeverdieAudio)
NVIDIA App 11.0.3.232 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.3.232 - NVIDIA Corporation)
NVIDIA FrameView SDK 1.5.10920.35420203 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.5.10920.35420203 - NVIDIA Corporation)
NVIDIA Graphics Driver 576.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 576.02 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.4.3.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.3.2 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
qBittorrent (HKLM-x32\...\qBittorrent) (Version: 5.1.0 - The qBittorrent project)
Red Giant Universe (HKLM\...\Universe_is1) (Version: 3.0.2 - Red Giant & Team V.R)
Revo Uninstaller 2.5.8 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.5.8 - VS Revo Group, Ltd.)
RivaTuner Statistics Server 7.3.4 (HKLM-x32\...\RTSS) (Version: 7.3.4 - Unwinder)
Speachy version 1.0.0 (HKLM-x32\...\{JUSTFUN598-SPEACHY-10}_is1) (Version: 1.0.0 - JustFun598)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
ToneBoosters Plugin Bundle (HKLM\...\ToneBoosters Plugin Bundle_is1) (Version: 1.8.9 - ToneBoosters)
VEGAS Pro 22.0 (HKLM\...\{158D228E-DAFD-493F-A502-4EEEB84A1F30}) (Version: 22.0.248.0 - VEGAS) Hidden
ViGEm Bus Driver (HKLM\...\{966606F3-2745-49E9-BF15-5C3EAA4E9077}) (Version: 1.22.0 - Nefarius Software Solutions e.U.)
 
Packages:
=========
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.967.0_x64__56jybvy8sckqj [2025-04-27] (NVIDIA Corp.)
Windows Feature Experience Pack -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-04-28] (Microsoft Windows)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-969771734-2463923209-239459422-1000_Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32 ->  => No File
CustomCLSID: HKU\S-1-5-21-969771734-2463923209-239459422-1000_Classes\CLSID\{d93ed569-3b3e-4bff-8355-3c44f6a52bb5}\InprocServer32 ->  => No File
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-04-30] (Avast Software s.r.o. -> Gen Digital Inc.)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-04-30] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-04-30] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-04-30] (Avast Software s.r.o. -> Gen Digital Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3cae04f75ee04f42\nvshext.dll [2025-04-14] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-04-30] (Avast Software s.r.o. -> Gen Digital Inc.)
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [VIDC.RTV1] => C:\WINDOWS\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Shiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\aa12cae77d0cb68b\7.1 Surround Sound.lnk -> C:\Program Files\Razer\RzAppEngine\rzappengine.exe (Razer Inc.) -> --application-host=apps.razer.com --profile-directory=Default hxxps://apps.razer.com/app-launcher/RzUiQiNlDnNMZ1NZ-HFhVAUiRz/
ShortcutWithArgument: C:\Users\Shiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\8beb69a3fbd06fbe\7.1 Surround Sound.lnk -> C:\Program Files\Razer\RzAppEngine\rzappengine.exe (Razer Inc.) -> --application-host=apps.razer.com --profile-directory=Default hxxps://apps.razer.com/app-launcher/RzUiQiNlDnNMZ1NZ-HFhVAUiRz/
ShortcutWithArgument: C:\Users\Shiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\78e1633e8ca7f001\7.1 Surround Sound.lnk -> C:\Program Files\Razer\RzAppEngine\rzappengine.exe (Razer Inc.) -> --application-host=apps.razer.com --profile-directory=Default hxxps://apps.razer.com/app-launcher/RzUiQiNlDnNMZ1NZ-HFhVAUiRz/
ShortcutWithArgument: C:\Users\Shiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\59632612248f617e\7.1 Surround Sound.lnk -> C:\Program Files\Razer\RzAppEngine\rzappengine.exe (Razer Inc.) -> --application-host=apps.razer.com --profile-directory=Default hxxps://apps.razer.com/app-launcher/RzUiQiNlDnNMZ1NZ-HFhVAUiRz/
ShortcutWithArgument: C:\Users\Shiba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\3d7109d88eb163cf\7.1 Surround Sound.lnk -> C:\Program Files\Razer\RzAppEngine\rzappengine.exe (Razer Inc.) -> --application-host=apps.razer.com --profile-directory=Default hxxps://apps.razer.com/app-launcher/RzUiQiNlDnNMZ1NZ-HFhVAUiRz/
 
==================== Loaded Modules (Whitelisted) =============
 
2025-04-27 12:15 - 2025-04-27 20:41 - 000000000 ____L (NVIDIA Corporation) [symlink -> C:\Program Files\NVIDIA Corporation\NVIDIA App\MessageBus\NvMessageBusBroadcast.dll] C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem\NvMessageBusBroadcast.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Reprise:jhqduwvxlctbqqijsf`usjbm`,qtjhjlhlih [0]
AlternateDataStreams: C:\ProgramData\Reprise:jhqduwvxlctbqqijsf`usjbm`pgyjhjlhlih [0]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) =============
 
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_451\bin\ssv.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_451\bin\jp2ssv.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\ssv.dll => No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_451\bin\jp2ssv.dll => No File
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2024-04-01 00:26 - 2025-04-29 20:43 - 000003660 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-969771734-2463923209-239459422-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Shiba\Downloads\BACKGROUND\rUBQIr3.jpeg
DNS Servers: 9.9.9.9 - 149.112.112.112
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [Microsoft-Windows-Unified-Telemetry-Client] => (Block) C:\WINDOWS\system32\svchost.exe (Microsoft Windows Publisher -> Microsoft Corporation)
FirewallRules: [{ED3FF90B-CB1A-45AB-BF61-C90D1B3E3E93}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25072.1611.3570.1995_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{88148E41-008F-4761-9BF2-687ED5551FDB}] => (Allow) C:\Program Files\WindowsApps\MSTeams_25072.1611.3570.1995_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP-V2] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [FPS-SpoolWorker-In-TCP-NoScope] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{15EC6D77-FB84-41F1-93F7-FE4E1E178AAD}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{16344EFD-3E69-431B-ACFE-5571A95BC07E}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{37D6985B-EDEB-4F28-A74D-15E38DDB5284}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{E7AD395E-1B8A-474E-B068-E77E00B7621E}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{D42DBA77-6791-4DEE-B982-F5AA7851EACE}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{98946207-AF1E-4488-8987-005782C57D98}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{335B8AED-7098-44A1-9F9A-01EBD7EFE208}] => (Allow) C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe () [File not signed]
FirewallRules: [{A1F2DEE9-9EC7-4FAF-B629-AFF4F287D044}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\135.0.3179.98\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
 
==================== Restore Points =========================
 
29-04-2025 20:15:06 Windows Update
30-04-2025 01:56:35 2025 Latest Backup 4/30/25
30-04-2025 05:11:10 Windows Modules Installer
30-04-2025 06:05:55 Revo Uninstaller's restore point - Avast Secure Browser
 
==================== Faulty Device Manager Devices ============
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (04/30/2025 06:05:55 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied..This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {e5f15332-9929-43e2-9e17-a9bd25ab727d}
 
 
System errors:
=============
 
Windows Defender:
================
Date: 2025-04-30 05:11:08
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2025-04-30 00:11:38
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2025-04-27 22:57:30
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2025-04-27 21:01:53
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Patcher!MTB
Severity: High
Category: Tool
Path: containerfile:_C:\Users\Shiba\Downloads\MAGIX.VEGAS.Pro.v22.0.xxx.x64.Patch-TEAM-V.R.rar; file:_C:\Users\Shiba\Downloads\MAGIX.VEGAS.Pro.v22.0.xxx.x64.Patch-TEAM-V.R.rar->MAGIX VEGAS Pro v22.0 patch.exe; webfile:_C:\Users\Shiba\Downloads\MAGIX.VEGAS.Pro.v22.0.xxx.x64.Patch-TEAM-V.R.rar|about:internet|pid:9456,ProcessStart:133902865052093824
Detection Origin: Internet
Detection Type: Concrete
Detection Source: Downloads and attachments
Process Name: Unknown
Security intelligence Version: AV: 1.427.485.0, AS: 1.427.485.0, NIS: 1.427.485.0
Engine Version: AM: 1.1.25030.1, NIS: 1.1.25030.1 
 
Date: 2025-04-27 15:13:55
Description: 
Microsoft Defender Antivirus has detected a suspicious behavior.
Name: Behavior:Win32/ModifiedBootRecord
Severity: Low
Category: Suspicious Behavior
Path Found: file:_C:\Users\Shiba\Downloads\dmde-4-2-4-818-win64-gui\dmde.exe; process:_12232
Detection Origin: Local machine
Detection Type: Suspicious
Detection Source: Real-Time Protection
Status: Executing
Process Name: C:\Users\Shiba\Downloads\dmde-4-2-4-818-win64-gui\dmde.exe
Security intelligence ID: 23858570787236
Security intelligence Version: AV: 1.403.7.0, AS: 1.403.7.0
Engine Version: 1.1.23110.2
Fidelity Label:  Medium
Target File Name:  
 

CodeIntegrity:
===============
Date: 2025-04-29 02:39:34
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.25030.2-0\MpCmdRun.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Microsoft signing level requirements. 
 
Date: 2025-04-29 02:39:33
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements. 
 
Date: 2025-04-29 02:29:57
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. 
 
 
==================== Memory info =========================== 
 
BIOS: American Megatrends International, LLC. F67d 09/02/2024
Motherboard: Gigabyte Technology Co., Ltd. B450 AORUS M
Processor: AMD Ryzen 5 3600 6-Core Processor 
Percentage of memory in use: 21%
Total physical RAM: 32691.44 MB
Available physical RAM: 25777.15 MB
Total Virtual: 37811.44 MB
Available Virtual: 30839.77 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:930.87 GB) (Free:537.61 GB) (Model: PNY CS900 1TB SSD) NTFS
Drive d: (Gamers) (Fixed) (Total:419.35 GB) (Free:419.17 GB) (Model: WDC CH SN530 SDBPTPZ-512G-1024) NTFS
Drive e: (UberFAST M.2) (Fixed) (Total:931.4 GB) (Free:82.38 GB) (Model: WD_BLACK SN770 1TB) NTFS
 
\\?\Volume{746a26ce-1ff8-41ab-8fca-facd97e9c0ce}\ () (Fixed) (Total:0.63 GB) (Free:0.07 GB) NTFS
\\?\Volume{6358cdc6-fce7-487b-9d73-6e163f98071b}\ () (Fixed) (Total:0.63 GB) (Free:0.11 GB) NTFS
\\?\Volume{c0d3af06-c080-4b6a-999e-7a9ffda8b382}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 073FFE7F)
 
Partition: GPT.
Attempted reading MBR returned 0 bytes.
 Could not read MBR for disk 2.
 
==================== End of Addition.txt =======================


#15 Shiba-INK

Shiba-INK
  • Topic Starter

  •  Avatar image
  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:58 PM

Posted 30 April 2025 - 08:18 AM

Quick side note: I deleted both my licensed Vegas Pro 19 and the likely pirated Vegas Pro 22 folders with the Avast Shredder, but 22 still shows up in Revo and fails to uninstall.

 

NVM, Revo helped me find the registry key left behind and 22 left the uninstall list once removed. I also updated Edge, Avast, and Visual C++ while I had the time.

Attached Files


Edited by Shiba-INK, 30 April 2025 - 08:37 AM.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users