Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Problem booting PC from DVDRW for system repair


  • This topic is locked This topic is locked
27 replies to this topic

#1 tamarisk

tamarisk

  •  Avatar image
  • Members
  • 266 posts
  • OFFLINE
  •  
  • Local time:09:06 PM

Posted 08 October 2025 - 05:11 PM

The following problem description is copied from my original post at   https://www.bleepingcomputer.com/forums/t/811209/problem-booting-from-dvdrw/ Suggestion from that was to repost here.

 

 

I have left a lot of info out of this post because it would be way to long so some steps I've taken are missing.

 

For a week or so I've been having problems booting my HP TouchSmart 520-1030, running Win10/Win11 dual boot, from bootable DVD's. This PC is not Win11 compliant but has been working seemingly OK since the dual boot was created. I had to convert the HDD from Dynamic to Basic and Legacy BIOS to UEFI so I could install Win11.

 

The initial problem was booting from its own latest W10 System Repair Disk following a change of the Win10 Product Key and failure of MS Word to load, which has now resolved itself but the booting problem still exists.

 

The issue grew to inconsistent booting from any bootable DVD/CD to no booting from any DVD/CD, Windows created or otherwise. However, all but the latest HP System Repair Disk would boot another dual boot W10/W11 PC (Acer XC-215 also non-Win11 compliant), which suggest all but one DVD/CD's are not in themselves faulty (though possibly had become incompatible if that is possible).

 

I tried several times to create a new System Repair Disk on the HP using both new and over-writing existing DVD’s but all attempts failed.

 

I tried several times to reset/rebuild the WBM/EFI but not really being sure of what I was doing I gave up with this. In desperation I reset the Win10 installation on the HP, keeping both files and Apps. This improved matters but did not resolve them completely. I got more consistent booting depending on the disk used but not as it should be and not at all with the latest HP System Repair Disk.

 

I swapped the DVDRW drive from the Acer into the HP and this improved the issue still further. I was now able to get consistent booting from all but the latest HP System Repair Disk. I was also able to create a new System Repair Disk on a new DVD and by over-writing the previous ‘latest HP System Repair Disk’ both of which booted the PC. They also booted the Acer now using the DVDRW drive from the HP. I tried all the DVDs in both PC’s and they all work, well almost. This suggests the DVD’s and Drives are OK albeit not always fully compatible.

 

This morning, I successfully booted the Acer using the HP DVDRW drive and very latest HP System Repair Disk 3 times, however, when I tried to boot the HP using the Acer DVDRW drive and very latest HP System Repair Disk it would not work but had done yesterday. Grrrrrrr

 

When I look at the boot options under Legacy Boot Sources on the HP a new entry has recently appeared that says ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿoPtrbae1U 0.

 

Would this indicate some sort of malware? See photo. If not what else could be at fault.

 

The DVD/CDs contain:

  • Win10 Installation media of various versions both 32 & 64bit
  • Win10 System Repair media from the TouchSmart and other Win10 PCs both 32 & 64bit
  • Macrium Reflect rescue media from the TouchSmart
  • SeaTools4DOS
  • Hiren's BootCD for Win10

And are either Verbatim 4.7GB 4x DVD-RW, Verbatim 4.7GB 16x DVD +R RW or Maxell CD-R 52x.

 

I'm aware that Recovery USB drives are the better more reliable option but at the time my only option was the DVD route.

 

Photo at https://www.bleepingcomputer.com/forums/uploads/monthly_10_2025/post-1005646-0-38919200-1759931221.jpg

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-10-2025
Ran by KAA (administrator) on TOUCHSMART (Hewlett-Packard 520-1030uk) (08-10-2025 22:13:50)
Running from C:\Users\KAA\Downloads\FRST64.exe
Loaded Profiles: KAA
Platform: Microsoft Windows 10 Pro Version 22H2 19045.6332 (X64) Language: English (United Kingdom)
Default browser: C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.exe
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(C:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Mirics Semiconductor) C:\Program Files\MiricsFlexiTV\Driver\MSiBdaDemodWrapper.exe
(C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.exe ->) (Duck Duck Go, Inc. -> Microsoft Corporation) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe <20>
(explorer.exe ->) (Duck Duck Go, Inc. -> DuckDuckGo) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.exe
(explorer.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(explorer.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Andrea Electronics Corporation) [File not signed] C:\Program Files\IDT\WDM\AESTSr64.exe
(services.exe ->) (IDT, Inc.) [File not signed] C:\Program Files\IDT\WDM\stacsv64.exe
(services.exe ->) (Lenovo -> Motorola) C:\Program Files\Lenovo\Ready For Assistant\ReadyForService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Mirics Ltd.) C:\Program Files\MiricsFlexiTV\DVBT\DVBservice.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Mirics Semiconductor) C:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\NisSrv.exe
(services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Seraph Secure Inc. -> Seraph Secure Inc.) C:\Program Files\Seraph Secure\SeraphSecure.Desktop.Service.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(svchost.exe ->) (Seraph Secure Inc. -> Seraph Secure Inc.) C:\Program Files\Seraph Secure\SeraphSecure.Desktop.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2012-10-18] (Integrated Device Technology Inc. -> Hewlett-Packard) [File not signed]
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [11859680 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-10-18] (IDT, Inc.) [File not signed]
HKLM-x32\...\Run: [EKStatusMonitor] => C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe [2750840 2013-12-11] (Eastman Kodak Company -> Eastman Kodak Company)
HKLM-x32\...\Run: [Nero BackItUp] => C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\BackItUp.exe [1150320 2016-11-08] (Nero AG -> Nero AG)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [41579480 2025-09-29] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1004\...\Run: [MicrosoftEdgeAutoLaunch_70F5C52BE9DF1358C7250A17068A79C5] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1007\...\Run: [MicrosoftEdgeAutoLaunch_0312593BFFDB8261C1676A58C7A72931] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Print\Monitors\KODAK All-in-One Printer: C:\WINDOWS\system32\EKAiO2MON.dll [1649664 2013-11-19] (Microsoft Windows Hardware Compatibility Publisher -> Eastman Kodak Company)
Startup: C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2022-04-09]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2025-10-06]
GroupPolicy: Restriction - Edge <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {4E3227A3-D76B-48C7-9FBA-2F6ADC701346} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1581568 2025-08-24] (Adobe Inc. -> Adobe Inc.)
Task: {A2FFEC02-982C-4D11-A8EE-42CA7FCA65DB} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem131.0.6776.0{F668BBEF-823D-4D83-8CD3-495C7587B595} => C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\updater.exe [5507168 2024-10-14] (Google LLC -> Google LLC)
Task: {BF3C8C90-BED3-40C3-AD45-BB50418E301E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001Core{D220553E-E54C-4CD1-BC37-1A56E28B2CD4} => C:\Users\KAA\AppData\Local\Google\Update\GoogleUpdate.exe  /c (No File)
Task: {A3BE9F3C-ECCA-4213-A7D3-A174A2CC35D7} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001UA{99C2A8AA-F663-43F3-A707-6DECB4586918} => C:\Users\KAA\AppData\Local\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler (No File)
Task: {93EFB0AA-12D5-4C09-BC7C-81DCB73A5BFD} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ABO => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://ABO
Task: {CEC80FA8-A7F9-4DAB-95BF-60017DE39D86} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusError => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BatteryStatusError
Task: {8AEC054E-DC44-4E8D-8BE5-00507F16F1BB} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BCF => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BCF
Task: {92379D3F-DF65-4F74-9DA2-79406E4B59E0} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM1 => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM1
Task: {022BA1A8-53F1-4EA0-AFFA-5EFE02716F56} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM2 => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM2
Task: {8A4D5CFD-883D-4534-9FA2-B184B7ACC79D} - System32\Tasks\Hewlett-Packard\HP Diagnostics\LaunchUI => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://LaunchUI
Task: {A2B0BEEF-A0D1-4D51-BE1B-2331B82FB757} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ShowUI => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags:
Task: {444882E0-CD7F-42ED-9C3F-96A9A619F77F} - System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckError => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://SmartCheckError
Task: {96E4B330-552D-45DB-B776-B1D8D30EA8CA} - System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckTest => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://SmartCheckTest
Task: {628AA9AA-4E54-4FBB-B888-064564A0EC10} - System32\Tasks\Hewlett-Packard\HP Diagnostics\Uninstall-FastSystemTests => c:\Windows\System32\schtasks.exe [268800 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /Change /Disable /tn "\Hewlett-Packard\HP Diagnostics\FastSystemTests"
Task: {05A0D43D-AFF2-4EB1-8DF1-FDC18D7AD460} - System32\Tasks\Hewlett-Packard\HP Diagnostics\Uninstall-SmartCheckTest => c:\Windows\System32\schtasks.exe [268800 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /Change /Disable /tn "\Hewlett-Packard\HP Diagnostics\SmartCheckTest"
Task: {12442B10-DE8C-4BE5-B15D-10BB9F5FF93B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [702512 2023-07-25] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {AE9B1D97-834B-4138-ACD1-3073213B353A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [138328 2023-07-25] (HP Inc. -> HP Inc.)
Task: {F364CD9A-6B1B-4BAA-AC6B-6B4B51AF1734} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1145896 2023-07-25] (HP Inc. -> HP Inc.)
Task: {91604C30-3E13-47D9-83B7-AF74218CBD6E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1145896 2023-07-25] (HP Inc. -> HP Inc.)
Task: {101F31C9-B2DA-4D18-88AC-D52D8C7B3B4D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24610408 2020-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {EB1C9E76-8A74-4CEA-9C91-8F650066ED4D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24610408 2020-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {608D509D-EAE9-45F5-8EEF-472D00EBCDB8} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158544 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {052A3942-A1A4-41AB-97BC-2CEF3A3EC94D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158544 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {B84D226A-D7FA-4FE9-8EA3-5EC0908E9E3B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6160272 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {02EFE719-1F90-4B92-8C7F-3E512AF95D37} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6160272 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {99B55C99-93FF-45E3-9638-E0AC18708487} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C0110507-D81F-4D41-AA6B-E3EFE5F10DD1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9782ACAD-18B9-47D6-9496-1EBDB3C493E8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AE20B3B6-A636-48BF-8A9E-69701D03DB33} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D077ECA5-A77E-4C78-9405-CBABF61E1C84} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [674208 2023-12-05] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {5BC61FCA-DA32-4D1B-AF59-FE3A0A59901D} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [35232 2023-12-05] (Mozilla Corporation -> Mozilla Foundation)
Task: {73DBA20C-8F44-47BD-8CFC-39ADEB169B81} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [3867928 2020-11-15] (Nero AG -> Nero AG)
Task: {D35E1681-4F4F-4E55-8C51-D4662DBD7792} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1001 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  /reporting (No File) <==== ATTENTION
Task: {0FD11B6C-5F37-4811-89DB-3A5544C4ED9C} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1004 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  /reporting (No File) <==== ATTENTION
Task: {82878F6A-228B-4376-9E76-CFED67A17606} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1006 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  /reporting (No File) <==== ATTENTION
Task: {BB7E1583-913A-4D86-B22A-50A8D088323F} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1007 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  /reporting (No File) <==== ATTENTION
Task: {7A9F3BA0-E8AA-44E0-901E-7938721972B5} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1001 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (No File) <==== ATTENTION
Task: {E0414E31-C2B4-4716-A4D8-9283C4443227} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1002 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (No File) <==== ATTENTION
Task: {C6BA1144-34CC-4FE4-9F2C-C164840D2A0D} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1003 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (No File) <==== ATTENTION
Task: {3D0A3660-29F7-4E00-9984-02CAFCDC653B} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1004 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (No File) <==== ATTENTION
Task: {60703B05-F41E-4B4E-873D-5D16113BB983} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1006 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (No File) <==== ATTENTION
Task: {0D1E8BFF-AA7E-4737-82E1-4F192A32500E} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1007 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (No File) <==== ATTENTION
Task: {9C9B0D04-4B26-4776-A5FB-8B4AC424759D} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (No File) <==== ATTENTION
Task: {D149F916-0061-4A21-9B7D-A8AFC26DC624} - System32\Tasks\SeraphSecureLogon => C:\Program Files\Seraph Secure\SeraphSecure.Desktop.exe [16031344 2025-08-28] (Seraph Secure Inc. -> Seraph Secure Inc.) -> C:\Program Files\Seraph Secure\\--startup
Task: {3502994E-7C1F-4E6D-A912-FEC7DCCAD126} - System32\Tasks\SeraphSecureVerify => C:\Program Files\Seraph Secure\SeraphSecure.Setup.exe [1115328 2025-08-28] (Seraph Secure Inc. -> ) -> C:\Program Files\Seraph Secure\\/silent /verify
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1a98b6d1-90ba-4524-9b29-f01366eec3f9}: [DhcpNameServer] 192.168.22.22 192.168.22.23
Tcpip\..\Interfaces\{46ce57af-c84e-4ff6-94bc-0638ec221f1e}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{46ce57af-c84e-4ff6-94bc-0638ec221f1e}: [DhcpDomain] powerhub
Tcpip\..\Interfaces\{72285048-0945-41a4-8a20-6a8203986e5b}: [DhcpNameServer] 192.168.22.22 192.168.22.23
Tcpip\..\Interfaces\{eebba993-4062-402b-807d-57da6dbf6c56}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f4242fa3-05f8-47aa-81a2-c748dd49e1cf}: [DhcpNameServer] 192.168.1.1
 
Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default [2025-10-06]
Edge HomePage: Default -> hxxps://html.duckduckgo.com/html?q=duckduckgo
Edge StartupUrls: Default -> "hxxps://www.btwifi.com:8443/home","hxxps://html.duckduckgo.com/html?q=duckduckgo"
Edge NewTab: Default ->  Active:"chrome-extension://eimldjabijllelicbnieiomiaeekbodl/index.html", Active:"chrome-extension://jonikckfpolfcdcgdficelkfffkloemh/n.html"
Edge DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
Edge DefaultSearchKeyword: Default -> duckduckgo.com
Edge DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab
Edge DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
Edge Extension: (Trocker) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjojfeillmmoeadgobbcknkgdkngbcdb [2024-08-08]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2025-09-27]
Edge Extension: (DuckDuckGo) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caoacbimdbbljakfhgikoodekdnlcgpk [2025-08-31]
Edge Extension: (NoScript) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\debdhlbmgmkkfjpcglcbjadbhhekgfjh [2022-06-09]
Edge Extension: (Windscribe VPN - Privacy & Ad Block Suite) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dkkdbpgldnmkhcliffjpajcfdjkcaddf [2025-09-27]
Edge Extension: (VT4Browsers) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\efbjojhplkelaegfbieplglfidafgoka [2024-04-19]
Edge Extension: (New Tab DuckDuckGo Redirect) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\eimldjabijllelicbnieiomiaeekbodl [2023-02-04]
Edge Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\elhekieabhbkpmcefcoobjddigjcaadp [2025-09-30]
Edge Extension: (Google Analytics Opt-out Add-on (by Google)) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2024-05-10]
Edge Extension: (Google Docs Offline) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-09-27]
Edge Extension: (APK Downloader) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\glngapejbnmnicniccdcemghaoaopdji [2025-03-15]
Edge Extension: (WOT: Website Security & Safety Checker) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\iiclaphjclecagpkkaacljnpcppnoibi [2025-03-15]
Edge Extension: (Edge relevant text changes) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge Extension: (PixelBlock) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmpmfcjnflbcoidlgapblgpgbilinlem [2024-03-12]
Edge Extension: (Blank New Tab Page) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jonikckfpolfcdcgdficelkfffkloemh [2021-01-21]
Edge Extension: (Zune Software Download [Window 10] Guide) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mbgchiachcmhdeicjkpnjifgddendfph [2022-11-01]
Edge Extension: (uBlock Origin) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2025-09-27]
Edge Extension: (AdGuard AdBlocker) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pdffkfellgipmhklpdmokmckkkfcopbh [2025-08-26]
Edge Extension: (Privacy Badger) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pkehgijcmpdhfbdbbnkijodmdjhbjlgp [2025-09-27]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
 
FireFox:
========
FF DefaultProfile: rpjp5gd5.default
FF ProfilePath: C:\Users\KAA\AppData\Roaming\Mozilla\Firefox\Profiles\rpjp5gd5.default [2021-09-14]
FF ProfilePath: C:\Users\KAA\AppData\Roaming\Mozilla\Firefox\Profiles\79xfahfv.default-release-1631788129756 [2025-08-31]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\KAA\AppData\Roaming\Mozilla\Firefox\Profiles\79xfahfv.default-release-1631788129756\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2023-12-05]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-09-29] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
 
Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174584 2025-08-24] (Adobe Inc. -> Adobe Inc.)
R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2012-10-18] (Andrea Electronics Corporation) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11109232 2020-04-09] (Microsoft Corporation -> Microsoft Corporation)
S3 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [43784 2024-03-27] (Intel Corporation -> Intel)
S3 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [291592 2024-03-27] (Intel Corporation -> Intel)
S3 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [888208 2023-07-25] (HP Inc. -> HP Inc.)
S3 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [887192 2023-07-25] (HP Inc. -> HP Inc.)
S3 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [883088 2023-07-25] (HP Inc. -> HP Inc.)
S3 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [887696 2023-07-25] (HP Inc. -> HP Inc.)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [13004248 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8965728 2024-12-08] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.25080.5-0\MpDefenderCoreService.exe [2009656 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 msi2500scan; c:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe [229376 2011-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Mirics Semiconductor)
R2 MSiDVBT; c:\Program Files\MiricsFlexiTV\DVBT\DVBService.exe [2715648 2011-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Mirics Ltd.)
S3 MSSQL$ACCUCHEK360; C:\Program Files (x86)\Microsoft SQL Server\MSSQL12.ACCUCHEK360\MSSQL\Binn\sqlservr.exe [199352 2017-07-06] (Microsoft Corporation -> Microsoft Corporation)
S3 NeroBackItUpBackgroundService; C:\Program Files (x86)\Nero\Nero 2017\Nero BackItUp\NBService.exe [287088 2016-11-08] (Nero AG -> Nero AG)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [918456 2025-10-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SeraphSecure; C:\Program Files\Seraph Secure\SeraphSecure.Desktop.Service.exe [6331304 2025-08-28] (Seraph Secure Inc. -> Seraph Secure Inc.)
R2 SmartConnect; C:\Program Files\Lenovo\Ready For Assistant\ReadyForService.exe [2641400 2025-02-24] (Lenovo -> Motorola)
S3 SQLAgent$ACCUCHEK360; C:\Program Files (x86)\Microsoft SQL Server\MSSQL12.ACCUCHEK360\MSSQL\Binn\SQLAGENT.EXE [454848 2017-07-06] (Microsoft Corporation -> Microsoft Corporation)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2012-10-18] (IDT, Inc.) [File not signed]
S3 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [9216 2011-03-29] (Vodafone) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.25080.5-0\NisSrv.exe [4414464 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.25080.5-0\MsMpEng.exe [282480 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 ewusbnet; C:\WINDOWS\System32\drivers\ewusbnet.sys [413696 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 ew_hwusbdev; C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys [117248 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 ew_usbenumfilter; C:\WINDOWS\System32\drivers\ew_usbenumfilter.sys [13952 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 huawei_enumerator; C:\WINDOWS\System32\drivers\ew_jubusenum.sys [85504 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 hwdatacard; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [219008 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 ITECIRfilter; C:\WINDOWS\system32\DRIVERS\ITECIRfilter.sys [36560 2015-11-24] (ITE Tech. Inc. -> ITE Tech. Inc.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333216 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
R3 lenovoDriverBus; C:\WINDOWS\System32\drivers\lenovoDriverBus.sys [103152 2025-02-24] (Lenovo -> Lenovo Inc.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2022-07-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239568 2024-12-08] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MDA_NTDRV; C:\WINDOWS\system32\MDA_NTDRV.sys [43664 2025-08-29] (Chongqing NIUBI Technology Co., Ltd. -> )
R2 Mrvdp; C:\WINDOWS\system32\drivers\mrvdp.sys [58112 2021-10-13] (Paramount Software UK Ltd -> Windows ® Win 7 DDK provider)
R3 MSi2500BDA; C:\WINDOWS\system32\DRIVERS\AVerMsiBDA.sys [228352 2011-12-12] (Microsoft Windows Hardware Compatibility Publisher -> AVerMedia TECHNOLOGIES, Inc.)
R3 NWVoltron; C:\WINDOWS\System32\drivers\NWVoltron.sys [28920 2015-07-09] (NextWindow -> )
S3 NWWakeFilterV; C:\WINDOWS\System32\drivers\NWWakeFilterV.sys [16632 2015-07-09] (NextWindow -> n/a)
S3 PSMounterEx; C:\Windows\system32\drivers\psmounterex.sys [140720 2023-10-02] (Microsoft Windows Hardware Compatibility Publisher -> Windows ® Win 7 DDK provider)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2021-03-26] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2021-03-26] (MiniTool Solution Ltd -> )
R2 RFDriveFs2; C:\Program Files\Lenovo\Ready For Assistant\drivers\FileSystem\RFDriveFs2.sys [412984 2025-02-24] (Lenovo -> Motorola)
S3 s116bus; C:\WINDOWS\System32\drivers\s116bus.sys [108296 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116mdfl; C:\WINDOWS\system32\DRIVERS\s116mdfl.sys [19720 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116mdm; C:\WINDOWS\system32\DRIVERS\s116mdm.sys [144648 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116mgmt; C:\WINDOWS\system32\DRIVERS\s116mgmt.sys [126216 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116nd5; C:\WINDOWS\System32\drivers\s116nd5.sys [31496 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116obex; C:\WINDOWS\system32\DRIVERS\s116obex.sys [123656 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116unic; C:\WINDOWS\System32\drivers\s116unic.sys [130824 2007-04-03] (MCCI Corporation -> MCCI Corporation)
R3 STHDA; C:\WINDOWS\system32\DRIVERS\stwrt64.sys [543744 2012-10-18] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
R3 tilfilter; C:\WINDOWS\System32\drivers\TIxHCIlfilter.sys [34424 2016-08-20] (Texas Instruments, Inc. -> Texas Instruments, Inc.)
R3 tiufilter; C:\WINDOWS\System32\drivers\TIxHCIufilter.sys [39032 2016-08-20] (Texas Instruments, Inc. -> Texas Instruments, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20880 2025-09-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [627104 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [159936 2020-06-17] (NGO -> MBB)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102816 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2025-10-08 22:13 - 2025-10-08 22:16 - 000033549 _____ C:\Users\KAA\Downloads\FRST.txt
2025-10-08 22:12 - 2025-10-08 22:15 - 000000000 ____D C:\FRST
2025-10-08 22:10 - 2025-10-08 22:10 - 002442752 _____ (Farbar) C:\Users\KAA\Downloads\FRST64.exe
2025-10-08 20:19 - 2025-10-08 20:19 - 002134016 _____ (Farbar) C:\Users\KAA\Downloads\FRST.exe
2025-10-07 17:37 - 2025-10-07 17:37 - 000000000 ___HD C:\$SysReset
2025-10-07 13:39 - 2025-10-07 13:39 - 000000762 _____ C:\Users\KAA\Documents\Win10 Reagentc info results.txt
2025-10-07 08:19 - 2025-10-07 16:41 - 000000000 _____ C:\Recovery.txt
2025-10-06 13:22 - 2025-10-06 13:22 - 000002782 _____ C:\Users\KAA\Documents\Chkdsk results.txt
2025-10-06 12:31 - 2025-10-06 12:31 - 000000000 ____D C:\WINDOWS\pss
2025-10-06 12:17 - 2025-10-06 12:17 - 000053013 _____ C:\WINDOWS\system32\sfclogs.txt
2025-10-06 11:07 - 2025-10-06 11:07 - 000000000 ____D C:\inetpub
2025-10-06 09:44 - 2025-10-06 09:44 - 000023734 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-10-06 09:37 - 2025-10-06 09:37 - 000023734 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-10-06 08:36 - 2025-10-06 08:36 - 000001036 __RSH C:\ProgramData\ntuser.pol
2025-10-06 08:04 - 2025-10-06 08:04 - 000003189 _____ C:\WINDOWS\system32\wrapperMap.json
2025-10-06 01:10 - 2025-10-06 00:54 - 000000000 ____D C:\Windows.old
2025-10-06 01:06 - 2025-10-06 01:06 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2025-10-06 01:03 - 2025-10-06 01:10 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2025-10-06 01:03 - 2025-10-06 01:03 - 000000020 ___SH C:\Users\KAA\ntuser.ini
2025-10-06 01:00 - 2025-10-06 01:02 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2025-10-06 01:00 - 2025-10-06 01:00 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2025-10-06 00:55 - 2025-10-06 11:07 - 000000000 ____D C:\Program Files\Hyper-V
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ___SD C:\WINDOWS\system32\containers
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\WINDOWS\system32\BestPractices
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files\Reference Assemblies
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files\MSBuild
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files (x86)\MSBuild
2025-10-06 00:52 - 2025-10-08 18:14 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-10-06 00:52 - 2025-10-06 08:02 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-10-06 00:52 - 2025-10-06 08:02 - 000003410 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-10-06 00:52 - 2025-10-06 00:53 - 000003598 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001UA{99C2A8AA-F663-43F3-A707-6DECB4586918}
2025-10-06 00:52 - 2025-10-06 00:53 - 000003330 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001Core{D220553E-E54C-4CD1-BC37-1A56E28B2CD4}
2025-10-06 00:52 - 2025-10-06 00:53 - 000003126 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1004
2025-10-06 00:52 - 2025-10-06 00:53 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1007
2025-10-06 00:52 - 2025-10-06 00:53 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1006
2025-10-06 00:52 - 2025-10-06 00:53 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1001
2025-10-06 00:52 - 2025-10-06 00:53 - 000002976 _____ C:\WINDOWS\system32\Tasks\SeraphSecureVerify
2025-10-06 00:52 - 2025-10-06 00:53 - 000002922 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1004
2025-10-06 00:52 - 2025-10-06 00:53 - 000002922 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1003
2025-10-06 00:52 - 2025-10-06 00:53 - 000002922 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1002
2025-10-06 00:52 - 2025-10-06 00:53 - 000002918 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-500
2025-10-06 00:52 - 2025-10-06 00:53 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1007
2025-10-06 00:52 - 2025-10-06 00:53 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1006
2025-10-06 00:52 - 2025-10-06 00:53 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1001
2025-10-06 00:52 - 2025-10-06 00:53 - 000002446 _____ C:\WINDOWS\system32\Tasks\SeraphSecureLogon
2025-10-06 00:52 - 2025-10-06 00:52 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\PowerToys
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Nero
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Hewlett-Packard
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
2025-10-06 00:48 - 2025-10-06 00:52 - 000019053 _____ C:\WINDOWS\diagwrn.xml
2025-10-06 00:48 - 2025-10-06 00:52 - 000019053 _____ C:\WINDOWS\diagerr.xml
2025-10-06 00:33 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\SystemCertificates
2025-10-06 00:33 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\Network
2025-10-06 00:33 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\Crypto
2025-10-06 00:31 - 2025-10-07 16:21 - 000982820 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-10-06 00:30 - 2025-10-06 00:30 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\SystemCertificates
2025-10-06 00:30 - 2025-10-06 00:30 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Network
2025-10-06 00:30 - 2025-10-06 00:30 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Crypto
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\SystemCertificates
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\Network
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\Crypto
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network
2025-10-06 00:21 - 2025-10-06 00:21 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\CLR Security Config
2025-10-06 00:18 - 2025-10-06 00:18 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\CLR Security Config
2025-10-06 00:18 - 2025-10-06 00:18 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\CLR Security Config
2025-10-06 00:17 - 2025-10-07 13:49 - 000000000 ____D C:\Users\Anne
2025-10-06 00:17 - 2025-10-06 15:31 - 000000000 ____D C:\Users\KAA
2025-10-06 00:17 - 2025-10-06 01:04 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows
2025-10-06 00:17 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\Windows
2025-10-06 00:17 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\Administrator
2025-10-06 00:17 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\Windows
2025-10-06 00:17 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin
2025-10-06 00:11 - 2025-10-08 18:14 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-10-06 00:11 - 2025-10-06 11:19 - 000491000 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-10-06 00:11 - 2025-10-06 00:11 - 000001162 _____ C:\WINDOWS\system32\config\VSMIDK
2025-10-05 21:53 - 2025-10-05 21:55 - 000000000 ____D C:\Users\KAA\Documents\Thunderbird Profiles copy
2025-10-05 21:33 - 2025-10-06 01:03 - 000000000 ___DC C:\WINDOWS\Panther
2025-10-03 20:43 - 2025-10-03 20:50 - 3291686912 _____ C:\Users\KAA\Downloads\HBCD_PE_x64.iso
2025-10-03 13:48 - 2025-10-03 13:48 - 001936744 _____ (Akeo Consulting) C:\Users\KAA\Downloads\rufus-4.11.exe
2025-10-01 22:34 - 2025-10-01 22:34 - 000000000 ___HD C:\$Windows.~WS
2025-09-30 17:12 - 2025-09-30 17:12 - 000182308 _____ C:\Users\KAA\Documents\xfgfx.pdf
2025-09-30 16:53 - 2025-09-30 16:53 - 000248032 _____ C:\Users\KAA\Documents\XPension docs to Guy.pdf
2025-09-28 12:26 - 2025-09-28 12:26 - 000000000 ____D C:\ProgramData\Apple Computer
2025-09-28 12:26 - 2025-09-28 12:26 - 000000000 ____D C:\ProgramData\Apple
2025-09-27 14:40 - 2025-09-27 14:41 - 000000422 _____ C:\Users\KAA\Documents\Windows 10 Pro Key from ShowKeyPlus.txt
2025-09-27 12:48 - 2025-09-27 12:49 - 000270638 _____ C:\Users\KAA\Downloads\Win10 licence_Screenshot_27-9-2025_124857_www.electronicfirst.com.jpeg
2025-09-27 11:27 - 2025-09-27 11:27 - 000000000 ____D C:\ProgramData\Office Genuine Advantage
2025-09-25 15:34 - 2025-09-25 15:34 - 000048173 _____ C:\Users\KAA\Downloads\24169 - Hive V4 Wireless Heating  Hot Water Smart Thermostat.pdf
2025-09-24 16:09 - 2025-09-25 17:43 - 000012028 _____ C:\Users\KAA\Documents\Win10 licence sites.xlsx
2025-09-21 12:26 - 2025-09-21 12:23 - 001587098 _____ C:\Users\KAA\Documents\Churchill Motor policy-booklet-1124.pdf
2025-09-15 12:32 - 2025-09-15 12:32 - 000021554 _____ C:\Users\KAA\Downloads\Letter.odt
2025-09-14 16:43 - 2025-09-14 16:48 - 000000812 _____ C:\Users\KAA\Desktop\Consumer ESU Enrollment.txt
2025-09-14 16:07 - 2025-09-14 16:10 - 000000000 ____D C:\Users\KAA\Downloads\Consumer ESU Enrollment
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2025-10-08 20:11 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-10-08 20:10 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-10-08 20:10 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-10-08 19:25 - 2020-03-04 18:13 - 000000000 ____D C:\Users\KAA\AppData\Local\Packages
2025-10-08 18:21 - 2020-03-26 10:45 - 000001076 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2025-10-08 18:15 - 2024-12-18 17:25 - 000000000 ____D C:\Program Files\Seraph Secure
2025-10-08 18:14 - 2020-06-06 12:18 - 000008192 ___SH C:\DumpStack.log.tmp
2025-10-08 13:26 - 2023-12-04 03:51 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-10-08 13:14 - 2020-10-22 19:00 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Word
2025-10-07 16:21 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2025-10-07 16:10 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-10-07 13:05 - 2025-08-29 16:29 - 000001347 _____ C:\Users\KAA\Desktop\NIUBI Partition Editor Free Edition.lnk
2025-10-07 11:45 - 2020-03-04 18:31 - 000000000 ____D C:\ProgramData\Packages
2025-10-07 00:05 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-10-06 15:33 - 2024-02-01 14:05 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2025-10-06 12:21 - 2025-08-27 23:16 - 000053013 _____ C:\Users\KAA\Desktop\sfcdetails.txt
2025-10-06 11:39 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-10-06 11:09 - 2019-12-07 15:46 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemApps
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-10-06 11:08 - 2024-07-09 19:35 - 000000000 ____D C:\WINDOWS\system32\compatrel
2025-10-06 11:08 - 2019-12-07 15:49 - 000000000 ___SD C:\WINDOWS\system32\AppV
2025-10-06 11:08 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-10-06 11:07 - 2023-12-04 03:51 - 000000000 ____D C:\WINDOWS\InboxApps
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Portable Devices
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2025-10-06 11:07 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\en-GB
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\USOPrivate
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2025-10-06 11:07 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2025-10-06 10:50 - 2020-03-04 18:16 - 000000000 ____D C:\Users\KAA\AppData\Local\PlaceholderTileLogoFolder
2025-10-06 08:39 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-10-06 08:28 - 2019-12-07 10:14 - 000000000 __RSD C:\WINDOWS\Media
2025-10-06 08:28 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2025-10-06 08:03 - 2020-05-06 17:30 - 000000000 ____D C:\Users\KAA\AppData\Local\HP
2025-10-06 08:02 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\appcompat
2025-10-06 02:46 - 2024-10-27 13:43 - 000000000 ___RD C:\Users\KAA\Documents\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe!App
2025-10-06 01:10 - 2025-03-08 20:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Connect
2025-10-06 01:10 - 2024-12-10 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2025-10-06 01:10 - 2023-12-19 15:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium
2025-10-06 01:10 - 2023-10-22 00:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SP Driver
2025-10-06 01:10 - 2023-02-04 00:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 2017
2025-10-06 01:10 - 2023-02-04 00:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
2025-10-06 01:10 - 2022-11-03 16:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2025-10-06 01:10 - 2022-07-22 21:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zune
2025-10-06 01:10 - 2022-07-14 15:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerToys (Preview)
2025-10-06 01:10 - 2021-03-21 20:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vodafone
2025-10-06 01:10 - 2021-03-04 17:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-10-06 01:10 - 2021-02-26 14:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2025-10-06 01:10 - 2020-11-03 14:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2025-10-06 01:10 - 2020-08-23 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak
2025-10-06 01:10 - 2020-08-23 17:57 - 000000000 ____D C:\WINDOWS\SysWOW64\kodak
2025-10-06 01:10 - 2020-08-18 00:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACCU-CHEK 360
2025-10-06 01:10 - 2020-08-17 23:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2014
2025-10-06 01:10 - 2020-08-17 23:35 - 000000000 ____D C:\WINDOWS\SysWOW64\1033
2025-10-06 01:10 - 2020-08-17 23:35 - 000000000 ____D C:\WINDOWS\system32\1033
2025-10-06 01:10 - 2020-08-17 22:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\diasend® Uploader
2025-10-06 01:10 - 2020-05-29 10:32 - 000000000 ____D C:\Program Files\UNP
2025-10-06 01:10 - 2020-05-06 21:04 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2025-10-06 01:10 - 2020-05-05 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2025-10-06 01:10 - 2020-03-04 18:26 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-10-06 01:10 - 2020-03-04 18:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
2025-10-06 01:10 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2025-10-06 01:10 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\system32\WCN
2025-10-06 01:10 - 2019-12-07 10:18 - 000000000 ____D C:\WINDOWS\Setup
2025-10-06 01:10 - 2019-12-07 10:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\spool
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Registration
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-10-06 01:10 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2025-10-06 01:10 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2025-10-06 01:09 - 2019-12-07 10:14 - 000000000 __RHD C:\Users\Public\Libraries
2025-10-06 01:05 - 2020-03-28 23:29 - 000000000 ____D C:\WINDOWS\system32\kodak
2025-10-06 01:03 - 2022-12-30 18:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verbatim
2025-10-06 01:03 - 2022-11-05 18:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2025-10-06 01:03 - 2022-07-22 21:35 - 000000000 ___RD C:\Users\KAA\Podcasts
2025-10-06 01:03 - 2022-07-12 13:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2025-10-06 01:03 - 2020-08-17 23:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008
2025-10-06 01:03 - 2020-03-04 18:13 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-10-06 01:03 - 2020-03-04 18:13 - 000000000 ___RD C:\Users\KAA\3D Objects
2025-10-06 01:03 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-10-06 01:03 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-10-06 01:03 - 2019-12-07 15:47 - 000000000 ____D C:\WINDOWS\OCR
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2025-10-06 00:55 - 2023-12-04 03:46 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\HgsClientWmi.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000130544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdp4vs.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000110560 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmwpevents.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000062448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pvhdparser.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000059880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\l2bridge.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000037352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocketcontrol.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000029160 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmsifproxystub.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000022400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hnswfpdriver.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmComputeProxy.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000014848 _____ C:\WINDOWS\system32\hnsproxy.dll
2025-10-06 00:55 - 2023-12-04 03:43 - 000207216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpcivsp.sys
2025-10-06 00:55 - 2023-12-04 03:43 - 000042472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vkrnlintvsc.sys
2025-10-06 00:55 - 2023-12-04 03:43 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Synth3dVsp.sys
2025-10-06 00:55 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\schemas
2025-10-06 00:55 - 2019-12-07 10:10 - 001579818 _____ C:\WINDOWS\system32\WindowsVirtualization.V2.mof
2025-10-06 00:55 - 2019-12-07 10:10 - 001152064 _____ C:\WINDOWS\system32\WindowsHyperVCluster.V2.mof
2025-10-06 00:55 - 2019-12-07 10:10 - 000182560 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmsp.exe
2025-10-06 00:55 - 2019-12-07 10:10 - 000144967 _____ C:\WINDOWS\system32\virtmgmt.msc
2025-10-06 00:55 - 2019-12-07 10:10 - 000043640 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmplatformca.exe
2025-10-06 00:55 - 2019-12-07 10:10 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AttestationWmiProvider.dll
2025-10-06 00:55 - 2019-12-07 10:10 - 000035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\lunparser.sys
2025-10-06 00:55 - 2019-12-07 10:10 - 000016384 _____ C:\WINDOWS\system32\hgclientserviceps.dll
2025-10-06 00:55 - 2019-12-07 10:10 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\HostGuardianServiceClientResources.dll
2025-10-06 00:55 - 2019-12-07 10:10 - 000012088 _____ (Microsoft Corporation) C:\WINDOWS\system32\f1db7d81-95be-4911-935a-8ab71629112a_vmsvcext_sys.dll
2025-10-06 00:55 - 2019-12-07 10:10 - 000012088 _____ (Microsoft Corporation) C:\WINDOWS\system32\c28c7a4e-a619-4463-82b7-0fc9cc7187f5_HyperV-ComputeStorage.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000039440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\passthruparser.sys
2025-10-06 00:55 - 2019-12-07 10:09 - 000031544 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmcomputeeventlog.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000012816 _____ (Microsoft Corporation) C:\WINDOWS\system32\f989b52d-f928-44a3-9bf1-bf0c1da6a0d6_HyperV-DeviceVirtualization.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000012600 _____ (Microsoft Corporation) C:\WINDOWS\system32\d4d78066-e6db-44b7-b5cd-2eb82dce620c_HyperV-ComputeLegacy.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000012600 _____ (Microsoft Corporation) C:\WINDOWS\system32\c4d66f00-b6f0-4439-ac9b-c5ea13fe54d7_HyperV-ComputeCore.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000012304 _____ (Microsoft Corporation) C:\WINDOWS\system32\07409496-a423-4a3e-b620-2cfb01a9318d_HyperV-ComputeNetwork.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000006658 _____ C:\WINDOWS\system32\VmChipset Third-Party Notices.txt
2025-10-06 00:52 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2025-10-06 00:24 - 2025-08-29 16:29 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NIUBI Partition Editor Free Edition
2025-10-06 00:24 - 2025-03-08 20:00 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2025-10-06 00:24 - 2021-03-04 17:26 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-10-06 00:24 - 2020-10-24 10:49 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Corporation
2025-10-06 00:24 - 2020-03-24 18:53 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirusTotal Uploader 2.2
2025-10-06 00:21 - 2023-08-29 13:36 - 000000000 ____D C:\Users\Anne\AppData\Local\Packages
2025-10-06 00:18 - 2020-07-29 17:51 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Local\Packages
2025-10-06 00:18 - 2019-12-07 10:14 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows
2025-10-06 00:15 - 2020-03-04 18:25 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2025-10-06 00:15 - 2020-03-04 18:25 - 000000000 ____D C:\ProgramData\SoundResearch
2025-10-06 00:15 - 2020-03-04 18:19 - 000000000 ____D C:\Program Files\MiricsFlexiTV
2025-10-05 21:34 - 2021-03-01 22:52 - 000000000 ____D C:\Users\KAA\AppData\Local\CrashDumps
2025-10-04 17:34 - 2020-03-24 18:14 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-10-04 17:34 - 2020-03-24 18:14 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-10-03 20:43 - 2022-10-14 13:28 - 000002079 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-10-03 20:43 - 2022-10-14 13:28 - 000002067 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2025-10-03 17:55 - 2021-02-22 16:42 - 000000000 ____D C:\Users\KAA\Documents\Household
2025-10-03 17:01 - 2020-10-31 01:33 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Excel
2025-10-02 00:13 - 2021-02-09 23:02 - 000000000 ____D C:\ESD
2025-09-30 17:59 - 2023-07-22 18:21 - 000000000 ____D C:\Users\KAA\AppData\Local\Malwarebytes
2025-09-30 17:14 - 2020-08-18 00:49 - 000000000 ____D C:\Users\KAA\AppData\LocalLow\Temp
2025-09-30 17:14 - 2020-06-13 17:12 - 000000000 ____D C:\Users\KAA\AppData\LocalLow\Adobe
2025-09-28 12:18 - 2020-03-04 18:14 - 000000000 ____D C:\Users\KAA\AppData\Local\Publishers
2025-09-18 11:12 - 2020-03-04 17:44 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-09-12 11:06 - 2022-07-01 16:58 - 000000000 ____D C:\Program Files\dotnet
2025-09-12 11:06 - 2020-08-17 22:05 - 000000000 ____D C:\ProgramData\Package Cache
 
==================== Files in the root of some directories ========
 
2020-06-16 12:37 - 2020-06-16 12:37 - 002008779 _____ () C:\Program Files\ProcessExplorer.zip
2025-08-27 23:39 - 2025-08-27 23:39 - 000000028 _____ () C:\Users\KAA\AppData\Roaming\epm_user.ini
2022-10-05 16:23 - 2023-09-18 11:57 - 000007673 _____ () C:\Users\KAA\AppData\Local\Resmon.ResmonCfg
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2025
Ran by KAA (08-10-2025 22:27:46)
Running from C:\Users\KAA\Downloads
Microsoft Windows 10 Pro Version 22H2 19045.6332 (X64) (2025-10-05 23:54:21)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-2603899380-3263017511-4129809722-500 - Administrator - Disabled) => C:\Users\Administrator
Anne (S-1-5-21-2603899380-3263017511-4129809722-1007 - Limited - Enabled) => C:\Users\Anne
DefaultAccount (S-1-5-21-2603899380-3263017511-4129809722-503 - Limited - Disabled)
Guest (S-1-5-21-2603899380-3263017511-4129809722-501 - Limited - Disabled)
KAA (S-1-5-21-2603899380-3263017511-4129809722-1001 - Administrator - Enabled) => C:\Users\KAA
NonStoreLogin (S-1-5-21-2603899380-3263017511-4129809722-1004 - Limited - Enabled) => C:\Users\NonStoreLogin
WDAGUtilityAccount (S-1-5-21-2603899380-3263017511-4129809722-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
ACCU-CHEK 360 (HKLM-x32\...\{33C351FC-D928-47F8-8184-D8B47F303678}) (Version: 1.0.14 - Roche) Hidden
ACCU-CHEK 360 Connection Manager (HKLM-x32\...\InstallShield_{33C351FC-D928-47F8-8184-D8B47F303678}) (Version: 1.0.14 - Roche)
ACCU-CHEK 360° (HKLM-x32\...\{C05A5601-DC01-4348-AB02-CD334E8DEFE4}) (Version: 2.2.3 - Roche Diabetes Care) Hidden
ACCU-CHEK 360° (HKLM-x32\...\InstallShield_{C05A5601-DC01-4348-AB02-CD334E8DEFE4}) (Version: 2.2.3 - Roche Diabetes Care)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-1033-7760-BC15014EA700}) (Version: 25.001.20756 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601120}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
aioscnnr (HKLM-x32\...\{EF53BFAB-4C10-40DB-A82D-9B07111715C6}) (Version: 7.6.13.10 - Your Company Name) Hidden
Belarc Advisor 11.5a (HKLM-x32\...\Belarc Advisor) (Version: 11.5.1.0 - Belarc, Inc.)
Borland Data Engine (HKLM-x32\...\{3AF6EF15-5841-4FF8-A3FC-5B2400AB9145}) (Version: 5.2.0 - Roche Diagnostics)
center (HKLM-x32\...\{56BA241F-580C-43D2-8403-947241AAE633}) (Version: 7.8.0.0 - Eastman Kodak Company) Hidden
diasend® Uploader version 3.8.0_BuildR3i05 (HKLM\...\{59A10021-5C7B-4C63-BB15-FAA9C04F8B26}_is1) (Version: 3.8.0_BuildR3i05 - Diasend)
essentials (HKLM-x32\...\{BE94C681-68E2-4561-8ABC-8D2E799168B4}) (Version: 7.8.0.0 - Eastman Kodak Company) Hidden
GDR 4237 for SQL Server 2014 (KB4019091) (HKLM-x32\...\KB4019091) (Version: 12.1.4237.0 - Microsoft Corporation)
Google Earth Pro (HKLM\...\{3470AD08-85F2-4B1D-8487-FC4750732087}) (Version: 7.3.6.9796 - Google)
Intel Driver && Support Assistant (HKLM-x32\...\{CCDC49A6-B288-4623-AA1D-332D328A8FA8}) (Version: 24.1.13.10 - Intel) Hidden
Intel® Driver & Support Assistant (HKLM-x32\...\{64f50684-bac6-488b-9bab-93616f34d6ec}) (Version: 24.1.13.10 - Intel)
ITE CIR version 5.5.2.1 (HKLM\...\{BEC1AF3C-B37F-4C91-A677-17BD6DA6A382}_is1) (Version: 5.5.2.1 - ITE, Inc.)
Kodak AIO Printer (HKLM\...\{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}) (Version: 7.8.1.0 - Eastman Kodak Company) Hidden
KODAK AiO Software (HKLM-x32\...\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 7.9.1.1 - Eastman Kodak Company)
LenovoUsbDriver 1.1.33 (HKLM-x32\...\LenovoUsbDriver) (Version: 1.1.33 - Lenovo)
Lumia UEFI Blue Driver (HKLM-x32\...\{9E37C8B7-50A6-422A-96C1-7BC43F2242F4}) (Version: 1.1.7.1439 - Nokia)
Macrium Reflect Free (HKLM\...\{A302C59F-C733-4DA0-9611-1286A9051D15}) (Version: 8.0.7783 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free (HKLM\...\MacriumReflect) (Version: v8.0.7783 - Paramount Software (UK) Ltd.)
Malwarebytes version 4.6.17.334 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.17.334 - Malwarebytes)
MediaTek SP Driver version 5.16.32.04 (HKLM\...\MediaTek SP Driver_is1) (Version: 5.16.32.04 - MediaTek.Inc.)
Microsoft .NET Core Host - 3.1.32 (x64) (HKLM\...\{8A8E3A04-83BC-4CDE-9259-893B666C1AB1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Host FX Resolver - 3.1.32 (x64) (HKLM\...\{ABC6B3C2-1A8D-4C5E-AC16-C2AE44F02743}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM\...\{A741B803-3F0E-4684-81EF-FC128D15A92C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM-x32\...\{784973c8-d618-4ac8-97ed-1fd52c5bdf2f}) (Version: 3.1.32.31915 - Microsoft Corporation)
Microsoft .NET Host - 6.0.36 (x64) (HKLM\...\{D6932D97-36F1-40B8-9CDC-CA8365B21000}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.20 (x64) (HKLM\...\{E8562B28-F84C-45AA-AE65-E31D1068377F}) (Version: 64.80.39230 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.36 (x64) (HKLM\...\{A9E32B25-994B-4856-A12B-0EBED3050410}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.20 (x64) (HKLM\...\{BB4BB73D-8784-40A3-9888-9BD29EC1B023}) (Version: 64.80.39230 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.36 (x64) (HKLM\...\{C912E33F-956A-4921-9F55-CC11AE8F09AF}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.20 (x64) (HKLM\...\{402EB961-5AED-472A-B785-B5AE9EF71286}) (Version: 64.80.39230 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 141.0.3537.57 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 141.0.3537.57 - Microsoft Corporation) Hidden
Microsoft ODBC Driver 11 for SQL Server (HKLM\...\{BE00C353-3529-4C31-AED2-AE3598D2CD2B}) (Version: 12.1.4237.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2019 - en-us (HKLM\...\ProPlus2019Volume - en-us) (Version: 16.0.12527.20482 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2603899380-3263017511-4129809722-1004\...\OneDriveSetup.exe) (Version: 22.131.0619.0001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2603899380-3263017511-4129809722-1007\...\OneDriveSetup.exe) (Version: 23.158.0730.0001 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM-x32\...\{8F72E2D4-1E48-4534-8DB8-1E8E012899C6}) (Version: 10.3.5500.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2014 (HKLM-x32\...\Microsoft SQL Server SQLServer2014) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (x64) (HKLM\...\{98E90D2B-FDEA-4858-97A2-3E5A15FC8E18}) (Version: 12.1.4100.1 - Microsoft Corporation)
Microsoft SQL Server 2014 RsFx Driver (HKLM-x32\...\{DDA4621B-896C-42F2-88C3-DACE4C44C2B3}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
Microsoft SQL Server 2014 Setup (English) (HKLM-x32\...\{D8BECB50-B81E-4B38-8264-CFE01DBE4FC9}) (Version: 12.1.4237.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom  (HKLM\...\{FF7DDA05-6EA7-4C01-B44A-3E57F8B9B97B}) (Version: 12.1.4100.1 - Microsoft Corporation)
Microsoft Support and Recovery Assistant (HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\fcede28c48c3b3fd) (Version: 17.0.5555.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{E3F613C1-105F-4717-BFE7-007729A95D67}) (Version: 12.1.4100.1 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visio Professional 2019 - en-us (HKLM\...\VisioPro2019Retail - en-us) (Version: 16.0.12527.20482 - Microsoft Corporation)
Microsoft Visio Viewer 2013 (HKLM\...\{95150000-0052-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (HKLM-x32\...\{6C772996-BFF3-3C8C-860B-B3D48FF05D65}) (Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (HKLM-x32\...\{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}) (Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.32.31332 (HKLM-x32\...\{3746f21b-c990-4045-bb33-1cf98cff7a68}) (Version: 14.32.31332.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.32.31332 (HKLM-x32\...\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}) (Version: 14.32.31332.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332 (HKLM\...\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332 (HKLM\...\{3407B900-37F5-4CC2-B612-5CD5D580A163}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.32.31332 (HKLM-x32\...\{8972AC25-452E-4FFE-945A-EB9E28C20322}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.32.31332 (HKLM-x32\...\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{C931A1C6-A7BF-3737-874A-818881A37E1B}) (Version: 10.0.60915 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.60910 - Microsoft Corporation)
Microsoft VSS Writer for SQL Server 2014 (HKLM\...\{366CD715-2FF4-40B4-A8B4-A05E5D21A945}) (Version: 12.1.4100.1 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 6.0.36 (x64) (HKLM\...\{61D4736B-3325-4D4A-BD41-8BD206C6A86E}) (Version: 48.144.23186 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.36 (x64) (HKLM-x32\...\{0532b8f2-12d7-43de-95fc-7b87006758a8}) (Version: 6.0.36.34217 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.20 (x64) (HKLM\...\{D330A645-92DF-4389-8324-B82FE3561498}) (Version: 64.80.39251 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.20 (x64) (HKLM-x32\...\{e033dc24-62c0-4f2c-928e-99122efab19d}) (Version: 8.0.20.35221 - Microsoft Corporation)
Microsoft_VC100_CRT_SP1_x64 (HKLM\...\{680EDA59-9266-44B4-949E-0C24F65DFF82}) (Version: 10.0.40219.1 - Nokia) Hidden
Microsoft_VC100_CRT_SP1_x86 (HKLM-x32\...\{E3B64CC5-C011-40C0-92BC-7316CD5E5688}) (Version: 10.0.40219.1 - Nokia) Hidden
Mozilla Firefox (x64 en-GB) (HKLM\...\Mozilla Firefox 120.0.1 (x64 en-GB)) (Version: 120.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 102.12.0 - Mozilla)
Mozilla Thunderbird (x64 en-GB) (HKLM\...\Mozilla Thunderbird 115.5.2 (x64 en-GB)) (Version: 115.5.2 - Mozilla)
MSVC80_x64_v2 (HKLM\...\{4D668D4F-FAA2-4726-834C-31F4614F312E}) (Version: 1.0.3.0 - Nokia) Hidden
MSVC80_x86_v2 (HKLM-x32\...\{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}) (Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (HKLM\...\{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}) (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (HKLM-x32\...\{AF111648-99A1-453E-81DD-80DBBF6DAD0D}) (Version: 1.0.1.2 - Nokia) Hidden
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 2.2 - F.J. Wechselberger)
Nero BackItUp (HKLM-x32\...\{EA03E7E5-6757-4A9A-9B36-C0022BE752D2}) (Version: 18.1.1134 - Nero AG) Hidden
Nero BackItUp 2017 Essentials (HKLM-x32\...\{BE491A0E-96C6-41AB-9BCB-5A34794899A2}) (Version: 18.0.03200 - Nero AG)
Nero ControlCenter (HKLM-x32\...\{ABC88553-8770-4B97-B43E-5A90647A5B63}) (Version: 11.4.3033 - Nero AG) Hidden
Nero Core Components (HKLM-x32\...\{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}) (Version: 11.8.1064 - Nero AG) Hidden
Nero Info (HKLM-x32\...\{F030BFE8-8476-4C08-A553-233DE80A2BE1}) (Version: 21.0.3001 - Nero AG)
Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 21.0.1014 - Nero AG) Hidden
NIUBI Partition Editor Free Edition V10.2.0 (HKLM-x32\...\NIUBISoft-NPE) (Version: V10.2.0 - NIUBI Technology Co., Ltd.)
ocr (HKLM-x32\...\{BFBCF96F-7361-486A-965C-54B17AC35421}) (Version: 6.2.3.50 - Eastman Kodak Company) Hidden
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12527.20482 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12527.20482 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.12527.20482 - Microsoft Corporation) Hidden
PL-2303 USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.3.0 - Prolific Technology INC)
PowerToys (Preview) (HKLM\...\{6E97D19B-84B5-47DF-A03A-0EE9637A8498}) (Version: 0.60.1 - Microsoft Corporation) Hidden
PowerToys (Preview) x64 (HKLM-x32\...\{2b34ef9c-2147-46a9-8bf1-1a0edd1c5a51}) (Version: 0.60.1 - Microsoft Corporation)
PreReq (HKLM-x32\...\{DA5BDB2A-12F0-4343-8351-21AAEB293990}) (Version: 6.2.4.0 - Eastman Kodak Company) Hidden
Rescue and Smart Assistant (HKLM-x32\...\Rescue and Smart Assistant) (Version: 6.4.2.13 - Lenovo)
Samsung AllShare (HKLM-x32\...\{DF47ACA3-7C78-4C08-8007-AC682563C9F1}) (Version: 2.1.0.12031_10 - Samsung Electronics Co., Ltd.) Hidden
Samsung AllShare (HKLM-x32\...\InstallShield_{DF47ACA3-7C78-4C08-8007-AC682563C9F1}) (Version: 2.1.0.12031_10 - Samsung Electronics Co., Ltd.)
Seraph Secure (HKLM\...\SeraphSecure) (Version:  - Seraph Secure Inc.)
Service Pack 1 for SQL Server 2014 (KB3058865) (HKLM-x32\...\KB3058865) (Version: 12.1.4100.1 - Microsoft Corporation)
Smart Connect (HKLM\...\ReadyFor) (Version: 8.0.0.002.002 - © Motorola)
Smart View (HKLM-x32\...\{1800D8A5-F7B2-4C20-868E-1CF55CBBDF21}) (Version: 1.0.0.0 - Samsung )
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
SQL Server 2014 Common Files (HKLM-x32\...\{BFB3B874-8033-4F5E-BE47-0AED2541E57C}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server 2014 Common Files (HKLM-x32\...\{F78A23CD-E9A0-46E3-88E2-CF2CC93AE7BA}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Services (HKLM-x32\...\{71E418D7-C0C5-455A-A248-1A3C3839EEEF}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Services (HKLM-x32\...\{A1ED7C85-A91A-4788-B0CC-86FA19C042E8}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Shared (HKLM-x32\...\{1D1E4532-6A52-471B-B006-EA04A2BBFCE9}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Shared (HKLM-x32\...\{AA2D8197-6678-4242-9222-3A03993E89B3}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server Browser for SQL Server 2014 (HKLM-x32\...\{3204DE95-97D2-4261-A286-98A262E171D4}) (Version: 12.1.4100.1 - Microsoft Corporation)
Sql Server Customer Experience Improvement Program (HKLM-x32\...\{894F30EB-3F0A-422F-9225-EB00DC9414EA}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.13.1 - Tweaking.com)
Type Label Fonts (HKLM-x32\...\{799BF338-BC01-4F7A-BC79-A67B75E772CB}) (Version: 1.1.0.1 - Microsoft)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
Verbatim GREEN BUTTON 2.01 (HKLM-x32\...\Verbatim GREEN BUTTON_is1) (Version:  - Verbatim)
Verbatim Hard Drive Formatter (HKLM-x32\...\Verbatim Hard Drive Formatter_is1) (Version:  - Verbatim)
Verbatim Hard Drive Info 1.04 (HKLM-x32\...\Verbatim Hard Drive Info_is1) (Version:  - Verbatim)
VirusTotal Uploader 2.2 (HKLM-x32\...\VTUploader) (Version:  - )
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.12 - VideoLAN)
Vodafone Mobile Broadband Lite (HKLM-x32\...\{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}) (Version: 10.2.102.30707 - Vodafone)
Windows Mobile Device Updater Component (HKLM\...\{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Windows PC Health Check (HKLM\...\{0B4830D0-7D09-4230-AACD-D5FD555FB76F}) (Version: 3.9.2402.14001 - Microsoft Corporation)
WinRAR 6.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.00.0 - win.rar GmbH)
Zune (HKLM\...\{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
Zune Language Pack (CHS) (HKLM\...\{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHT) (HKLM\...\{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CSY) (HKLM\...\{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DAN) (HKLM\...\{8B112338-2B08-4851-AF84-E7CAD74CEB32}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DEU) (HKLM\...\{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ELL) (HKLM\...\{3589A659-F732-4E65-A89A-5438C332E59D}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ESP) (HKLM\...\{6B33492E-FBBC-4EC3-8738-09E16E395A10}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FIN) (HKLM\...\{B4870774-5F3A-46D9-9DFE-06FB5599E26B}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FRA) (HKLM\...\{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (HUN) (HKLM\...\{C6BE19C6-B102-4038-B2A6-1C313872DBB4}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (IND) (HKLM\...\{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ITA) (HKLM\...\{C5D37FFA-7483-410B-982B-91E93FD3B7DA}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (JPN) (HKLM\...\{D8A781C9-3892-4E2E-9320-480CF896CFBB}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (KOR) (HKLM\...\{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (MSL) (HKLM\...\{76BA306B-2AA0-47C0-AB6B-F313AB56C136}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NLD) (HKLM\...\{6740BCB0-5863-47F4-80F4-44F394DE4FE2}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NOR) (HKLM\...\{5DEFD397-4012-46C3-B6DA-E8013E660772}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PLK) (HKLM\...\{8960A0A1-BB5A-479E-92CF-65AB9D684B43}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTB) (HKLM\...\{07EEE598-5F21-4B57-B40B-46592625B3D9}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTG) (HKLM\...\{5C93E291-A1CC-4E51-85C6-E194209FCDB4}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (RUS) (HKLM\...\{57C51D56-B287-4C11-9192-EC3C46EF76A4}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (SVE) (HKLM\...\{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
 
Packages:
=========
AdGuard AdBlocker -> C:\Program Files\WindowsApps\Adguard.AdguardAdBlocker_3.3.8.0_neutral__m055xr0c82818 [2025-10-06] (Performix)
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2025-10-05] ()
APKPure.com -> C:\Program Files\WindowsApps\apkpure.com-D523D125_1.0.0.1_neutral__9y56rtyprpvr6 [2025-10-06] (apkpure.com)
DuckDuckGo -> C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94 [2025-10-06] (DuckDuckGo) [Startup Task]
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_2.8.1.0_x64__v10z8vjag6ke6 [2025-10-05] (HP Inc.)
HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.47.41.0_x64__v10z8vjag6ke6 [2025-10-05] (HP Inc.)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa [2025-10-06] (Apple Inc.) [Startup Task]
Microsoft Advertising SDK for JavaScript -> C:\Program Files\WindowsApps\Microsoft.Advertising.JavaScript_10.1805.2.0_x64__8wekyb3d8bbwe [2025-10-05] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for JavaScript -> C:\Program Files\WindowsApps\Microsoft.Advertising.JavaScript_10.1805.2.0_x86__8wekyb3d8bbwe [2025-10-05] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2025-10-05] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2025-10-05] (Microsoft Corporation) [MS Ad]
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2025-10-06] (Microsoft Corporation)
ShowKeyPlus -> C:\Program Files\WindowsApps\617231644CE58.ShowKeyPlus_1.1.18.0_x64__arc7y9yj6c41t [2025-10-06] (Superfly Inc.)
Vodafone Mobile Broadband -> C:\Program Files\WindowsApps\VodafoneGroupServices.VodafoneMobileBroadband_2.10.46.0_x64__cx08jceyq9bcp [2025-10-06] (Vodafone Group Services)
WSB Manager -> C:\Program Files\WindowsApps\30069NiaTomonaka.WSBManager_1.2.16.0_x64__d07890f6kbdbp [2025-10-05] (Nia Tomonaka)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{13074435-7693-4592-2533-000000000000}\localserver32 -> C:\Program Files\Lenovo\Ready For Assistant\SmartConnect.exe (Lenovo -> )
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{36B27788-A8BB-4698-A756-DF9F11F64F84}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.SvgThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{3f5d0051-61b8-0f45-6166-996cfb4f914f}\localserver32 -> C:\Program Files\PowerToys\modules\launcher\PowerToys.PowerLauncher.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{45769bcc-e8fd-42d0-947e-02beef77a1f5}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.MarkdownPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{8BC8AFC2-4E7C-4695-818E-8C1FFDCEA2AF}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.StlThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{afbd5a44-2520-4ae0-9224-6cfce8fe4400}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.MonacoPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{BFEE99B4-B74D-4348-BCA5-E757029647FF}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.GcodeThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{ddee2b8a-6807-48a6-bb20-2338174ff779}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.SvgPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{ec52dea8-7c9f-4130-a77b-1737d0418507}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.GcodePreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2025-09-08] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1-x32: [MyPhoneExplorer] -> {A372C6DF-7A85-41B1-B3B0-D1E24073DCBF} => C:\Program Files (x86)\MyPhoneExplorer\DLL\ShellMgr.dll [2010-03-30] (F.J. Wechselberger) [File not signed]
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-07-22] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers3: [PowerRenameExt] -> {0440049F-D1DC-4E46-B27B-98393D79486B} => C:\Program Files\PowerToys\modules\PowerRename\PowerToys.PowerRenameExt.dll [2022-07-13] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\WINDOWS\system32\igfxpph.dll [2017-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-07-22] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\KAA\Desktop\toggleNIC.bat - Shortcut.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /c C:\Users\KAA\Desktop\toggleNIC.bat
ShortcutWithArgument: C:\Users\KAA\Desktop\ToggleNic\toggleNIC.bat - Shortcut.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /c C:\Users\KAA\Desktop\toggleNIC.bat
ShortcutWithArgument: C:\Users\KAA\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\GWAPImplicitAppShortcuts\362fff581c3a7425\uBlock Origin.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=odfafepnkmbhccpbejgmiehpchacaeak --app-url --app-launch-source=4
ShortcutWithArgument: C:\Users\KAA\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\NIC\toggleNIC.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /c C:\Users\KAA\Desktop\toggleNIC.bat
 
==================== Loaded Modules (Whitelisted) =============
 
2025-08-26 20:17 - 2025-06-03 04:34 - 005426176 _____ () [File not signed] C:\Program Files\Seraph Secure\av_libGLESv2.dll
2025-05-28 14:07 - 2024-09-11 21:05 - 001759232 _____ () [File not signed] C:\Program Files\Seraph Secure\e_sqlite3.DLL
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
==================== Association (Whitelisted) =================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\Software\Classes\.reg:  =>  <==== ATTENTION
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\Software\Classes\.bat:  =>  <==== ATTENTION
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\Software\Classes\.cmd:  =>  <==== ATTENTION
 
==================== Internet Explorer (Whitelisted) =============
 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2023-07-25] (HP Inc. -> HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2023-07-25] (HP Inc. -> HP Inc.)
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2022-06-15] (Belarc, Inc. -> Belarc, Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2019-03-19 05:49 - 2025-10-08 22:16 - 000014427 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.0 beyondtrust.com www.beyondtrust.com
0.0.0.0 tcers.bomgar.com www.tcers.bomgar.com
0.0.0.0 helpwire.app www.helpwire.app
0.0.0.0 radmin.com www.radmin.com
0.0.0.0 download.radmin.com www.download.radmin.com
0.0.0.0 helpdesk.radmin.com www.helpdesk.radmin.com
0.0.0.0 radmin.download.it www.radmin.download.it
0.0.0.0 alpemix.com www.alpemix.com
0.0.0.0 alpemix.fileplanet.com www.alpemix.fileplanet.com
0.0.0.0 alpemix.en.softonic.com www.alpemix.en.softonic.com
0.0.0.0 alpemix.download.it www.alpemix.download.it
0.0.0.0 online.thinfinity.com www.online.thinfinity.com
0.0.0.0 screenleap.com www.screenleap.com
0.0.0.0 deskin.io www.deskin.io
0.0.0.0 dl.deskin.io www.dl.deskin.io
0.0.0.0 zulertech.com www.zulertech.com
0.0.0.0 xmpp.yuuguu.com www.xmpp.yuuguu.com
0.0.0.0 easyvista.com www.easyvista.com
0.0.0.0 pulseway.com www.pulseway.com
0.0.0.0 ultraviewer.net www.ultraviewer.net
0.0.0.0 dl2.ultraviewer.net www.dl2.ultraviewer.net
0.0.0.0 ultraviewer.fileplanet.com www.ultraviewer.fileplanet.com
0.0.0.0 ultraviewer.en.softonic.com www.ultraviewer.en.softonic.com
0.0.0.0 ultraviewer.download.it www.ultraviewer.download.it
0.0.0.0 fixme.it www.fixme.it
0.0.0.0 techinline.net www.techinline.net
0.0.0.0 techinline.com www.techinline.com
0.0.0.0 tsplus.net www.tsplus.net
0.0.0.0 tsplus.me www.tsplus.me
0.0.0.0 terminalserviceplus.com www.terminalserviceplus.com
 
There are 235 more lines.
 
 
2020-03-26 10:45 - 2025-10-08 18:21 - 000001076 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
172.28.153.251 8b36ffec-f862-4b4c-a91b-0dfde75633ed.mshome.net # 2025 10 2 14 10 34 24 959
172.19.138.30 dd33c185-9c2c-4997-8454-3faf0a5e0fd2.mshome.net # 2025 10 3 15 17 21 22 983
172.19.128.1 TouchSmart.mshome.net # 2030 10 1 7 17 21 22 983
24 10 1 7 22 29 38 266
172.23.160.1 TouchSmart.mshome.net # 2029 10 2 2 11 50 14 365
350
978
192.168.137.111 WIN10SE.mshome.net # 2021 2 5 26 16 58 24 674
5 26 16 50 38 804
 
==================== Network ===========================
 
(Currently there is no automatic fix for this section.)
 
DNS Servers: 192.168.1.1
Windows Firewall is enabled.
 
Network Binding:
=============
Wi-Fi: 802.11n Wireless LAN Card -> netr28x.sys
vEthernet (Ethernet): Hyper-V Virtual Ethernet Adapter -> VmsProxyHNic.sys
vEthernet (Wi-Fi): Hyper-V Virtual Ethernet Adapter #2 -> VmsProxyHNic.sys
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
vEthernet (Default Switch): Hyper-V Virtual Ethernet Adapter #3 -> VmsProxyHNic.sys
 
vms_vsf: Hyper-V Virtual Switch Extension Filter
ms_vfpext: Microsoft Azure VFP Switch Extension
ms_irda: IrDA Protocol
vms_vsp: Hyper-V Virtual Switch Extension Protocol
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
HKU\S-1-5-21-2603899380-3263017511-4129809722-1004\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2603899380-3263017511-4129809722-1007\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
 
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
HKLM\...\StartupApproved\StartupFolder: => "ACCU-CHEK 360 Connection Manager.lnk"
HKLM\...\StartupApproved\StartupFolder: => "ACCU-CHEK 360 Auto-Detect.lnk"
HKLM\...\StartupApproved\StartupFolder: => "SPDriverInstall.lnk"
HKLM\...\StartupApproved\Run: => "BeatsOSDApp"
HKLM\...\StartupApproved\Run: => "SysTrayApp"
HKLM\...\StartupApproved\Run: => "Reflect UI"
HKLM\...\StartupApproved\Run: => "Zune Launcher"
HKLM\...\StartupApproved\Run32: => "Conime"
HKLM\...\StartupApproved\Run32: => "EKStatusMonitor"
HKLM\...\StartupApproved\Run32: => "MobileBroadband"
HKLM\...\StartupApproved\Run32: => "AllShareAgent"
HKLM\...\StartupApproved\Run32: => "Intel Driver & Support Assistant"
HKLM\...\StartupApproved\Run32: => "Nero BackItUp"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\StartupFolder: => "NextPVR Tray.lnk"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\Run: => "Skype for Desktop"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\Run: => "NokiaSuite.exe"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{886A01F6-70B4-42E1-8782-CC81971A588A}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{9E01FF9C-8841-4C2E-B39D-E615422C7A01}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{6CD4F0A9-DB89-4C58-A9E1-8D88A3FA5F8A}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{43C372E2-0CB5-41FD-9B5C-30399861979C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{4843E8DE-68BC-4789-B930-7FB449CF95B0}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{CFD184C4-892B-4D29-931A-618A15DABF94}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{F1DFAA53-690E-4D9F-93A2-C9EE21B1FD6D}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{E0978648-BA00-4D1D-A561-EBD3FC330924}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{B668332E-37F3-47DF-9133-D26986776E29}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.WebView.exe (Duck Duck Go, Inc. -> DuckDuckGo)
FirewallRules: [{C92E24B3-0260-4E65-8083-3C4D06D90999}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.WebView.exe (Duck Duck Go, Inc. -> DuckDuckGo)
FirewallRules: [{973BD54E-3CBB-4A6E-83A5-0B94E61D7B8C}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe (Duck Duck Go, Inc. -> Microsoft Corporation)
FirewallRules: [{35D8B1C6-C486-4F78-89B7-BB574DD0B79E}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe (Duck Duck Go, Inc. -> Microsoft Corporation)
FirewallRules: [{3E80437B-C14A-4178-9535-818F5075EE2E}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.2\ABService.exe => No File
FirewallRules: [{E31B16B1-67A7-431D-B1D9-0AC32185B50A}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.2\ABService.exe => No File
FirewallRules: [{86D4A437-29B8-4AE7-B185-1E9578BC1580}] => (Allow) C:\Program Files\Rescue and Smart Assistant\Rescue and Smart Assistant.exe (Lenovo -> )
FirewallRules: [{009CA745-3B8A-413F-9BAC-6CF5538C43D0}] => (Block) C:\Program Files\Lenovo\Ready For Assistant\vaultPlugin\VaultPlugin.exe (Lenovo -> )
FirewallRules: [{6271D7B8-7DA1-4FA7-A469-FB9430D3438D}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\vaultPlugin\VaultPlugin.exe (Lenovo -> )
FirewallRules: [{9E3A3271-A463-4F9B-8970-FC862296BE78}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\vaultPlugin\VaultPlugin.exe (Lenovo -> )
FirewallRules: [{DEB3BC3A-4951-40F8-A205-617806FBA494}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\vaultPlugin\VaultPlugin.exe (Lenovo -> )
FirewallRules: [{D7E8EB43-C08D-4B9C-B641-1EEB46C9A2A8}] => (Block) C:\Program Files\Lenovo\Ready For Assistant\SmartConnect.exe (Lenovo -> )
FirewallRules: [{3474955D-EF34-410C-B03E-F519E1BD87BE}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\SmartConnect.exe (Lenovo -> )
FirewallRules: [{BBA484BF-6DC9-4CCA-8033-B8E9B5A45B75}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\SmartConnect.exe (Lenovo -> )
FirewallRules: [{079F170C-D70C-46BA-AA61-56440B9EE4B2}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\SmartConnect.exe (Lenovo -> )
FirewallRules: [{F652E44C-3D0E-41A5-9FD9-21D206EB9951}] => (Allow) C:\Program Files\Software Fix\Software Fix.exe => No File
FirewallRules: [{7FB9D48B-18AF-4E60-B289-69E51B1C3804}] => (Allow) C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [{97357207-5A98-44DC-8917-C095C3163287}] => (Allow) C:\Program Files\MiniTool ShadowMaker\AgentService.exe => No File
FirewallRules: [{AD585C84-014D-49D6-9CC8-0397D22868D4}] => (Allow) C:\Program Files\MiniTool ShadowMaker\AgentService.exe => No File
FirewallRules: [{86BEA19B-326B-4594-BFBC-3D7DF43EC21A}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.61.4.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{7F97224D-407C-4189-BBD9-6B88D6D4E8DA}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.61.4.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{62CE780A-9989-4B8E-82A9-0E3678511D43}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.59.0.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{DE4E660C-5EE0-432D-AF10-4E0617304135}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.59.0.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{08063108-02E7-48BF-B935-8A5E74A23A11}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.58.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{B6E7AA43-EA5E-41BA-B869-90606248561B}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.58.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{D84C9961-BA51-4F00-B91B-848049AA75BB}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.56.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{6DB79B5F-9158-45C1-8283-E56F521B4309}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.56.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{B3626921-6125-4F0F-8E44-90BC0966B471}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.55.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{55D912A7-C9CA-486C-8C36-8BED1A34B618}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.55.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{A13DA1E7-BDBD-4018-993A-F0E659493C5D}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.55.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{6B2E13B2-0039-4188-B835-961D1C5ACC12}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.55.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{8F936F7A-5957-48DC-A630-AE6019369C62}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.54.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{90997326-CDB1-4DC2-AC2E-77D2026DC08E}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.54.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{EC9660B2-C21C-49F2-9ADA-15A82AF92B8E}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.52.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{5C6938C5-67CF-46FD-AC42-7F898E70EFDC}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.52.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{88CF9801-D339-4E83-8C71-82F66482A613}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.51.0.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{3DCEE8AB-C74F-4BE9-87C7-F62078A6FC5F}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.51.0.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{D08A53F5-E3D0-4E45-8EFA-546BA7F4D27B}] => (Allow) C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\NBService.exe (Nero AG -> Nero AG)
FirewallRules: [{B588AF5A-A6A7-4F1A-AC75-07E0173282AC}] => (Allow) C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\BackItUp.exe (Nero AG -> Nero AG)
FirewallRules: [{1E31A3FA-A289-485A-AAE1-80865122893A}] => (Allow) C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\BackItUp.exe (Nero AG -> Nero AG)
FirewallRules: [{140DBF7C-E8B9-48F0-B2A6-3DD1AE84ABEC}] => (Allow) C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\NBService.exe (Nero AG -> Nero AG)
FirewallRules: [{5B0A9C44-0CB4-42A1-BB4E-FAAE2F503EBA}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe => No File
FirewallRules: [{E1AD2252-A5A8-450E-AE05-41E2EFA8F04A}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe => No File
FirewallRules: [{2C922ACF-3F99-4392-95D9-2BCD23BEE879}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe => No File
FirewallRules: [{7BC72725-7F79-45B9-9603-32B8C747C8D7}] => (Block) C:\program files (x86)\smart view\smart view.exe () [File not signed]
FirewallRules: [{D1A65C36-A696-4FA4-908E-32D1FE9C460D}] => (Block) C:\program files (x86)\smart view\smart view.exe () [File not signed]
FirewallRules: [UDP Query User{CB2FF261-6A53-4202-8752-7FE40A4BABB9}C:\program files (x86)\smart view\smart view.exe] => (Allow) C:\program files (x86)\smart view\smart view.exe () [File not signed]
FirewallRules: [TCP Query User{AF53709C-FF36-4C25-8CB2-112C981876DE}C:\program files (x86)\smart view\smart view.exe] => (Allow) C:\program files (x86)\smart view\smart view.exe () [File not signed]
FirewallRules: [{C9B70DF6-3CB5-42AC-9DE3-6A0E1C192420}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{01DF0815-250E-4BEF-A399-C43432F6D46B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{9E6EFAB9-EFA3-4B1E-B67D-E4ECCBA59176}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{480C6602-A8F0-4CD4-AA2D-AB8069EA5E9D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{2130C4CF-C2A2-4FE4-B3A7-A5AB302241CC}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe => No File
FirewallRules: [{FF9E6208-AA67-40C9-80EB-C1EB7D26FC83}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe => No File
FirewallRules: [{668601FD-E65F-41FC-94CF-3ED3A63163F9}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe => No File
FirewallRules: [{AC25DE7E-D61E-4603-9F00-1346E03B1B26}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe => No File
FirewallRules: [{CCD09C67-EBA8-4A82-B589-CEC6C3E27E3D}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2D3A4FBF-5DE1-4A97-A7BF-97A46016F9C0}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C4335C1C-F560-4C48-833E-808099F9295D}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E84402DC-6AF0-4C16-B437-BBBA2E29F3F0}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E4BE0E4F-F1E3-438B-B270-E9C9E71BE0FB}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3BE62FBA-BF72-4F47-B021-5281AE20D930}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{43D22646-DE88-4C38-A39A-5DB2FFD65028}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{218D2E57-4EA3-4E6B-BD5F-8345C670E7D1}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{845CA16E-C8D5-4B2B-BE9D-8CD653D7DA89}] => (Allow) C:\Program Files\Zune\Zune.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0BD8F30F-DCAD-4474-86A4-FDCC6B93CCE7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{51EAB827-B429-4974-8C03-F2409E415226}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{45310DD0-4C71-4E44-97CF-F5CB64BFAFA2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{7BD9DA36-8CE8-4CD8-8EA5-B9F1988EEE6D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{214C460A-661C-4B90-A6CA-B479686DF495}] => (Allow) C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{5E327218-8772-4453-801C-08A2A92971B9}] => (Allow) C:\Program Files (x86)\Samsung\AllShare\AllShare.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{99380CE1-38C5-43A0-BFFC-E2CC49F76CDF}] => (Allow) C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{BB868CEE-01FF-4592-B35B-CCC1F946D402}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{098BB6F7-E17F-4BD6-A37F-9CCEF8F82DB3}] => (Allow) LPort=3306
FirewallRules: [{B1BB24CB-E0D7-469C-AE54-38133CF2EF05}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal\WatchDog.exe => No File
FirewallRules: [{370A7F56-5ADB-44EF-964C-85A7524C7D8E}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal\WatchDog.exe => No File
FirewallRules: [{1C784120-8051-4A35-AA73-24DC0CC0314B}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal\MediaPortal.exe => No File
FirewallRules: [{E9630ABA-D040-4481-BC1F-BBD9D749571F}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal\MediaPortal.exe => No File
FirewallRules: [{44DF51B8-F089-401A-9D63-375DA2213B9B}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\WatchDogService.exe => No File
FirewallRules: [{615168E9-4783-4DC5-B229-9E3D2A9F270B}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\WatchDogService.exe => No File
FirewallRules: [{EC3A0892-9E7B-4D0F-9D39-63E633915050}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\SetupTv.exe => No File
FirewallRules: [{DFA0E5AA-0065-4295-81DD-8BFE715B82DA}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\SetupTv.exe => No File
FirewallRules: [{398CD166-1060-4B6F-88A7-3D52285DDB28}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\TvService.exe => No File
FirewallRules: [{DC46A6BD-8E3B-4294-ABB2-E406BE625F60}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\TvService.exe => No File
FirewallRules: [UDP Query User{E175FCA8-DC9E-4B1C-8CBE-B238E931CAFB}C:\program files (x86)\team mediaportal\mp2-client\mp2-client.exe] => (Block) C:\program files (x86)\team mediaportal\mp2-client\mp2-client.exe => No File
FirewallRules: [TCP Query User{79846B4A-3AC5-42D8-BF6D-568F6F9C28F1}C:\program files (x86)\team mediaportal\mp2-client\mp2-client.exe] => (Block) C:\program files (x86)\team mediaportal\mp2-client\mp2-client.exe => No File
FirewallRules: [UDP Query User{04CBBDC5-5BE7-4CFB-8E6B-9D6A47B695F9}C:\program files (x86)\team mediaportal\mp2-client\mp2-client (x64).exe] => (Block) C:\program files (x86)\team mediaportal\mp2-client\mp2-client (x64).exe => No File
FirewallRules: [TCP Query User{A9965697-E1D3-47B1-9B01-D5BB85161895}C:\program files (x86)\team mediaportal\mp2-client\mp2-client (x64).exe] => (Block) C:\program files (x86)\team mediaportal\mp2-client\mp2-client (x64).exe => No File
FirewallRules: [{6BC82F9B-CE03-4886-B2D6-0777F0C60FD0}] => (Block) C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe => No File
FirewallRules: [{E41AFD03-892C-49D8-A179-F3B04DD31ACC}] => (Block) C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe => No File
FirewallRules: [UDP Query User{C5565302-ABB4-4F46-BF94-1638E4A8E5CE}C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe] => (Allow) C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe => No File
FirewallRules: [TCP Query User{CCBBC2FB-8853-4216-83B7-52F442D8AF48}C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe] => (Allow) C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe => No File
FirewallRules: [UDP Query User{586F8BE7-62D0-42FA-A7D1-4380A97F0A56}C:\program files (x86)\team mediaportal\mp2-servicemonitor\mp2-servicemonitor.exe] => (Allow) C:\program files (x86)\team mediaportal\mp2-servicemonitor\mp2-servicemonitor.exe => No File
FirewallRules: [TCP Query User{061659BD-82EA-4666-87D2-978089316F1D}C:\program files (x86)\team mediaportal\mp2-servicemonitor\mp2-servicemonitor.exe] => (Allow) C:\program files (x86)\team mediaportal\mp2-servicemonitor\mp2-servicemonitor.exe => No File
FirewallRules: [{B1D2B83A-C1F1-4883-B4DF-8F2549040318}] => (Allow) C:\Program Files\NextPVR\Client\NextPVR.exe => No File
FirewallRules: [{F3D35A4B-66C3-4F3A-A14E-E365E8EA9230}] => (Allow) C:\Program Files\NextPVR\DeviceHostWindows.exe => No File
FirewallRules: [{C0967411-F155-489F-9AB5-B78774838455}] => (Allow) C:\Program Files\NextPVR\NextPVRServer.exe => No File
FirewallRules: [{34DAF440-1FC9-4B39-B5A5-40D45940D180}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{35ADA41B-E70D-4097-A347-DE767980FEBB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4F1E3D5F-7D9A-4414-AD9E-94451F4E6DD2}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4EA02950-EB1D-478A-9F96-809B5A7DB592}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{67B336D8-0225-4B08-8B47-EF58A0DA9740}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{04990CE4-8E74-4D8F-9E11-A9120112A6C7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe => No File
FirewallRules: [{BF7543C7-F1ED-4719-B85C-50766E7E9ECB}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe => No File
FirewallRules: [{246A763E-C6CD-4F8D-9E10-96484598C5C9}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{810F8789-C83A-4DB2-8898-DC7B1A6DA423}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{A5DAE191-7958-462A-B053-2ADE0292F110}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{49E53708-8A46-4225-BA09-B54B4CB97D23}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{B060B245-D243-42C4-BDE5-5C99FBD68BD6}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{AE9817B1-D68C-4BF6-9239-BE2E58D6E48D}] => (Allow) LPort=5353
FirewallRules: [{E2139D66-6BAC-49D3-AE61-C04927376151}] => (Allow) LPort=9322
FirewallRules: [{B35AC413-CBB3-4E2B-A7FD-5D94A5246B08}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.131.5.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe (Duck Duck Go, Inc. -> Microsoft Corporation)
FirewallRules: [{52A69B47-2B8C-47A0-8291-5F4E327BE8BA}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.131.5.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe (Duck Duck Go, Inc. -> Microsoft Corporation)
FirewallRules: [{C3022035-1F38-4BB0-981C-3A454BEF75FB}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.131.5.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.WebView.exe (Duck Duck Go, Inc. -> DuckDuckGo)
FirewallRules: [{51EBD1BF-29A1-4B33-BE9A-50079061393F}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.131.5.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.WebView.exe (Duck Duck Go, Inc. -> DuckDuckGo)
 
==================== Restore Points =========================
 
06-10-2025 08:10:39 Windows Modules Installer
 
==================== Faulty Device Manager Devices ============
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (10/08/2025 08:09:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x1dd4
Faulting application start time: 0x01dc38870cac965c
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: 896ed98f-347d-46a1-83d0-a93c317b53f2
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (10/08/2025 06:18:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x2388
Faulting application start time: 0x01dc38778c3cc790
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: ae649420-9363-4dc2-8a74-83b2c5d78b55
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (10/07/2025 04:23:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x23e4
Faulting application start time: 0x01dc379e50404892
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: b73a93e3-f630-4804-917a-b0f6d39cef41
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (10/07/2025 04:23:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0xb9c
Faulting application start time: 0x01dc379de3a618a0
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: 83aa6845-cdce-4fbd-9513-b83cd1ad487e
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (10/07/2025 03:54:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x1580
Faulting application start time: 0x01dc379a337206fc
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: 28a18129-1ec6-4cc2-9b27-73c09a647080
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (10/07/2025 03:34:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x25c0
Faulting application start time: 0x01dc379781015a87
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: 08c35dea-24be-40e3-aa66-4185d91a5f94
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (10/07/2025 03:26:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x221c
Faulting application start time: 0x01dc37957172426c
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: 83232124-9a2f-4499-8b24-06b016cb3449
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (10/07/2025 03:06:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x1f98
Faulting application start time: 0x01dc37938ed50daf
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: d30d2ed7-72a0-4f8c-8730-12e124db9929
Faulting package full name: 
Faulting package-relative application ID:
 
 
System errors:
=============
Error: (10/08/2025 06:14:39 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 17:19:33 on ‎08/‎10/‎2025 was unexpected.
 
Error: (10/07/2025 03:29:20 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume \\?\Volume{3d2441ba-8cd3-4f73-b5c7-2654bbb98741}.
 
The exact nature of the corruption is unknown.  The file system structures need to be scanned online.
 
Error: (10/07/2025 03:29:11 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume \\?\Volume{e5157268-8564-11f0-a368-fe36febd0469}.
 
The exact nature of the corruption is unknown.  The file system structures need to be scanned online.
 
Error: (10/07/2025 03:29:11 PM) (Source: Microsoft-Windows-Ntfs) (EventID: 98) (User: NT AUTHORITY)
Description: \\?\Volume{e5157268-8564-11f0-a368-fe36febd0469}\Device\HarddiskVolume13
 
Error: (10/07/2025 03:29:10 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume \\?\Volume{e5157268-8564-11f0-a368-fe36febd0469}.
 
The exact nature of the corruption is unknown.  The file system structures need to be scanned and fixed offline.
 
Error: (10/07/2025 03:29:10 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume \\?\Volume{0a6bfd05-1cd1-445d-bedb-e9f0ec4b53f7}.
 
The exact nature of the corruption is unknown.  The file system structures need to be scanned online.
 
Error: (10/07/2025 11:05:31 AM) (Source: Microsoft-Windows-FilterManager) (EventID: 3) (User: NT AUTHORITY)
Description: Filter Manager failed to attach to volume '\Device\Harddisk1\DR1'.  This volume will be unavailable for filtering until a reboot.  The final status was 0xc03a001c.
 
Error: (10/07/2025 12:06:43 AM) (Source: cdrom) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\CdRom0.
 
 
Windows Defender:
================
Date: 2025-10-08 21:58:21
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
 
Date: 2025-10-08 21:47:39
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
 
Date: 2025-10-08 21:40:15
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
 
Date: 2025-10-08 21:33:53
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
 
Date: 2025-10-08 21:21:58
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
Event[0]:
 
Date: 2025-10-07 11:05:56
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Current
Error Code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, then try to start the program again. For information on installing updates, see Help and Support. 
Security intelligence Version: 1.437.372.0;1.437.372.0
Engine Version: 1.1.25080.5
 
Date: 2025-10-06 15:33:49
Description: 
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode 
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
 
Date: 2025-10-06 14:36:01
Description: 
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode 
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
 
Date: 2025-10-06 13:25:37
Description: 
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode 
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
 
Date: 2025-10-06 12:35:06
Description: 
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode 
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
 
CodeIntegrity:
===============
Date: 2025-10-06 11:17:24
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\aepic.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
BIOS: AMI 7.08 11/30/2011
Motherboard: PEGATRON CORPORATION 2AC3
Processor: Intel® Core™ i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 72%
Total physical RAM: 8096.33 MB
Available physical RAM: 2238.36 MB
Total Virtual: 9632.33 MB
Available Virtual: 3657.54 MB
 
==================== Drives ================================
 
Drive c: (Win10 Pro) (Fixed) (Total:349.9 GB) (Free:140.97 GB) (Model: ST31000524AS) NTFS
Drive g: (Win11 Pro) (Fixed) (Total:194.93 GB) (Free:139.03 GB) (Model: ST31000524AS) NTFS
 
\\?\Volume{e5157268-8564-11f0-a368-fe36febd0469}\ (System Reserved) (Fixed) (Total:0.57 GB) (Free:0.14 GB) NTFS
\\?\Volume{0a6bfd05-1cd1-445d-bedb-e9f0ec4b53f7}\ () (Fixed) (Total:0.63 GB) (Free:0.14 GB) NTFS
\\?\Volume{3d2441ba-8cd3-4f73-b5c7-2654bbb98741}\ () (Fixed) (Total:0.63 GB) (Free:0.11 GB) NTFS
\\?\Volume{629458e4-0000-0000-0000-010000000000}\ (PortableBaseLayer) (Fixed) (Total:8 GB) (Free:7.5 GB) NTFS
\\?\Volume{e515726a-8564-11f0-a368-fe36febd0469}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: BB2C8144)
 
Partition: GPT.
 
==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 8 GB) (Disk ID: 629458E4)
Partition 1: (Not Active) - (Size=8 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt =======================

 



BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  •  Avatar image
  • Bots
  • 13,155 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:06 PM

Posted 13 October 2025 - 05:15 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Team better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> https://www.bleepingcomputer.com/logreply/811216 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new FRST log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another team member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download FRST by Farbar from the following link if you no longer have it available and save it to your destop.

    FRST Download Link

  • When you go to the above page, there will be 32-bit and 64-bit downloads available. Please click on the appropriate one for your version of Windows. If you are unsure as to whether your Windows is 32-bit or 64-bit, please see this tutorial.
  • Double click on the FRST icon and allow it to run.
  • Agree to the usage agreement and FRST will open. Do not make any changes and click on the Scan button.
  • Notepad will open with the results.
  • Post the new logs as explained in the prep guide.
  • Close the program window, and delete the program from your desktop.


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 tamarisk

tamarisk
  • Topic Starter

  •  Avatar image
  • Members
  • 266 posts
  • OFFLINE
  •  
  • Local time:09:06 PM

Posted 14 October 2025 - 05:07 AM

I have not attached new FRST logs because I have not used the PC since attaching FRST logs to my original request for help. Although the PC has not been use it has been switched on twice.

 

I don't believe I have the original Windows installation media, though I do have several versions of it created before the current issue.

 

Thanks for your help.



#4 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 17,055 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:05:06 PM

Posted 20 October 2025 - 11:24 AM

Welcome.

 

Please read this post completely before beginning. If there's anything that you do not understand, please don't hesitate to ask before proceeding.
 
Please take note of the guidelines for this fix:

  • Please note that I am a volunteer. I do have a family, a career, and other endeavors that may prevent immediate responses that meet your schedule. Do note that the differences in time zones could present a problem as well. Your patience and understanding will be greatly appreciated.
  • First of all, the procedures we are about to perform are specific to your problem and should only be used on this specific computer.
  • Do not make any changes to your computer that include installing/uninstalling programs, deleting files, modifying the registry, nor running scanners or tools of any kind unless specifically requested by me.
  • Please read ALL instructions carefully and perform the steps fully and in the order they are written.
  • If things appear to be better, let me know. Just because the symptoms no longer exist as before, does not mean that you are clean.
  • Continue to read and follow my instructions until I tell you that your machine is clean.
  • If you have any questions at all, please do not hesitate to ask before performing the task that I ask of you, and please wait for my reply before you proceed.
  • Scanning with programs and reading the logs do take a fair amount of time. Again, your patience will be necessary.  :)

Let's begin... 

 

FRST Fix

This fix will empty these folders: (It may take up to an hour to complete. Please be patient)

  • Windows Temp
  • Users Temp folders
  • Edge, IE, FF, Chrome, and Opera caches, HTML5 storages, Cookies and History
  • Recently opened files cache
  • Discord cache
  • Java cache
  • Steam HTML cache
  • Explorer thumbnail and icon cache
  • BITS transfer queue (qmgr*.dat files)
  • Recycle Bin
  • Scheduled Tasks will be listed.

Important: items are permanently deleted. They are not moved to quarantine. If you have any questions or concerns, please ask before running this fix.

The system will be rebooted after the fix has run. The script may take an hour to complete.

 

FRST64 will appear as C:\Users\KAA\Downloads\FRST64.exe

Download the enclosed file. Attached File  Fixlist.txt   52.59KB   6 downloads

  • Save it in the same location FRST64.exe is saved. 
  • Start FRST64.exe with Administrator privileges 
  • This time around Press the Fix button and wait
  • The script make take about an hour to complete. Be patient.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please attach this file in your next reply. 

 

**************************************************************************

 

Furtivex Malware Removal Script

 

DoesNotBelong

Temporarily disable Smart Screen and your antivirus [ only if needed ] to download and run the following tool:

 

Please download DoesNotBelong.exe and save it to your desktop.

 

Note: Please save all your existing work / windows as this tool will attempt to close all non-essential processes during the course of its scan. This includes the internet browser you're currently using to view this message and Windows explorer (temporarily).

  • Right-click DoesNotBelong.exe and then click Run as administrator.
  • Click Yes to the Disclaimer
  • The script will begin to run. Be patient.
  • When the scan is finished, a log entitled DoesNotBelong_[date]_[time].txt will be on the desktop and at C:
  • Attach DoesNotBelong_[date]_[time].txt to your next reply

*********************

Dr.Web CureIt!
Please download the Dr.Web CureIt! anti-virus utility
https://free.drweb.com/
 
You will need to send them an email to obtain a link to download the scanner, please do so

  • The downloaded file will normally have a unique name such as:  q7a9tr4p.exe
  • Close all open applications and locate the downloaded file and double-click to run it
  • The program will take a moment to launch and bring up the License and Update screen
  • Place a check mark to agree to the terms and then click on the Continue button
  • Click the underlined link Select objects for scanning
  • On the top left click the Scanning objects that should automatically check all objects
  • Click the small wrench and make sure there is a check on Automatically apply actions to threats
  • Then click the large button on bottom right Start scanning
  • Once the scan has completed there will be a link named Open report click that and a log named cureit.log should open in Notepad
  • The log is saved in the folder named Doctor Web in the top of your user profile folders
  • Please attach that log on your next reply
Please download HWiNFO the Professional System Information and Diagnostics program.
 
HWiNFO Portable for Windows
 
  • Unzip the program to its own folder such as: C:\HWiNFO
  • Go to the new folder and locate the file C:\HWiNFO\HWiNFO64.exe and double-click to run it.
  • Click the RUN button.
  • Ignore the update, click close.
  • Click on Save Report and choose HTML and click Next, then Finish
  • By default, it will create a new report named COMPUTER.HTM in the same folder as the program. C:\HWiNFO
  • Please zip that file and attach it to your next reply
 
Thank you

No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed

 


#5 tamarisk

tamarisk
  • Topic Starter

  •  Avatar image
  • Members
  • 266 posts
  • OFFLINE
  •  
  • Local time:09:06 PM

Posted 21 October 2025 - 03:11 PM

Firstly thank you for your assistance JSntgRvr, it is very much appreciated.

 

I've attached the logs as requested.

 

Please note in case it is relevant:

 

  • Had difficulty connecting to BC, webpage kept saying site was offline try again later. Don't know if this was genuine or malware causing an issue.
  • Just realised the DVDrw drive connected during these scans is the one from the second PC(Acer) and not the one with which I had the original problem. Please advise if I should reinstall the original DVDrw drive then rerun the scans
  • Defender kept notifying that virus protection was out of date (not noticed this before)
  • Defender then updated itself without input from me and without further out of date notifications
  • Defender flagged FRST Fix as malware but ran anyway. I can't now find notification to provide further details
  • Cureit.log file was too big to attach so I zipped it, hope that is OK
  • hwi_630. zip was not available so used hwi_832.zip instead, hope that's OK 
  • Defender notification "Protected memory access blocked" by Controlled folder access for HWiNFO64.exe on Protected folder:\Device\CdRom0 
  • HWiNFO log file seemed very small to require zipping but I zipped it anyway.

 

The FRST Fix list of items to be cleared lists Discord cache and Steam HTML cache. If these items are generic to any PC then no problem but if they are specific to my PC then they could be removed if it helps as I don't use either service as far as I'm aware. I have used Discord but not for years and the PC doesn't get used for non-Microsoft games.

 

Regards

 

Attached File  Fixlog.txt   88.19KB   5 downloads

Attached File  DoesNotBelong_2025_10_21__13_48_04.txt   65.26KB   4 downloads

Attached File  cureit.zip   1.26MB   4 downloads

Attached File  TOUCHSMART.zip   19.96KB   3 downloads


Edited by tamarisk, 21 October 2025 - 03:24 PM.


#6 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 17,055 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:05:06 PM

Posted 27 October 2025 - 06:00 PM

Sorry for the delay. Somehow, I missed the notification. Are you still having these problems?

 

The FRST Fix did not finished. Lets take it from where it stopped.

 

FRST64 will appear as C:\Users\KAA\Downloads\FRST64.exe

Download the enclosed file. Attached File  Fixlist.txt   30.19KB   3 downloads

  • Save it in the same location FRST64.exe is saved. 
  • Start FRST64.exe with Administrator privileges 
  • This time around Press the Fix button and wait
  • The script make take about an hour to complete. Be patient.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please attach this file in your next reply. 


No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed

 


#7 tamarisk

tamarisk
  • Topic Starter

  •  Avatar image
  • Members
  • 266 posts
  • OFFLINE
  •  
  • Local time:09:06 PM

Posted 27 October 2025 - 08:34 PM

Sorry for the delay. Somehow, I missed the notification. Are you still having these problems?

 

No worries and yes I still have the problem.

 

Please find attached Fixlog.txt file

 

Attached File  Fixlog.txt   296.01KB   2 downloads

 



#8 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 17,055 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:05:06 PM

Posted 28 October 2025 - 09:06 AM

Once again, the FRST Fix did not finished. Lets take it from where it stopped this time.

 

FRST64 will appear as C:\Users\KAA\Downloads\FRST64.exe

Download the enclosed file. Attached File  Fixlist.txt   11.17KB   5 downloads

  • Save it in the same location FRST64.exe is saved. 
  • Start FRST64.exe with Administrator privileges 
  • This time around Press the Fix button and wait
  • The script make take about an hour to complete. Be patient.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please attach this file in your next reply. 


Edited by JSntgRvr, 28 October 2025 - 09:07 AM.

No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed

 


#9 tamarisk

tamarisk
  • Topic Starter

  •  Avatar image
  • Members
  • 266 posts
  • OFFLINE
  •  
  • Local time:09:06 PM

Posted 28 October 2025 - 12:42 PM

Is it normal for FRST Fix not to finish or does this indicate a problem?

 

I've been having intermittent problems downloading and running FRST64. Sometimes Windows Security flags the file as a Severe or High or Low threat and immediately deletes the download with no 'Action' available to 'Allow' it. By disabling the 'Virus and threat protection' I can download FRST64 but then it fails to run because it is detected as a threat and immediately deleted even when run as administrator. The most recent download and running of FRST64 was done without any problem and with the 'Virus and threat protection' enabled. This seems very inconsistent and confusing; Please advise if this is to be expected?

 

When I switched the PC on today I checked to BIOS boot options and the rogue listing under Legacy Boot Sources, previously shown as   ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿoPtrbae1U 0,    was not there. See photo here. So something has changed.

 

Please find attached latest FRST Fixlog.

 

Attached File  Fixlog.txt   296.01KB   4 downloads


Edited by tamarisk, 28 October 2025 - 12:44 PM.


#10 tamarisk

tamarisk
  • Topic Starter

  •  Avatar image
  • Members
  • 266 posts
  • OFFLINE
  •  
  • Local time:09:06 PM

Posted 28 October 2025 - 02:23 PM

Test, please ignore. I'm having login and posting issues.



#11 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 17,055 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:05:06 PM

Posted 28 October 2025 - 04:02 PM

The latest Fixlog does not respond to the latest Fixlist script suggested. Please try again.


No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed

 


#12 tamarisk

tamarisk
  • Topic Starter

  •  Avatar image
  • Members
  • 266 posts
  • OFFLINE
  •  
  • Local time:09:06 PM

Posted 28 October 2025 - 09:47 PM

Sorry, I think I used the wrong Fixlist.

 

Latest Fixlog attached from scan 29/10/2025 @ 02:28

 

Attached File  Fixlog.txt   201KB   2 downloads



#13 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 17,055 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:05:06 PM

Posted 29 October 2025 - 04:13 PM

The script ran well. No malware was detected. No integrity violations were found. Have you tried the bootable CD on another computer? See if there is a new Driver at HP for the Optical Drive.

 

 Official HP® Laptop Drivers and Software Download | HP® Support.

 

Keep me posted.


No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed

 


#14 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 17,055 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:05:06 PM

Posted 29 October 2025 - 04:19 PM

How to Boot from DVD on Laptop
 
To boot from a DVD on a laptop, follow these steps:
 
  1. Check Power Connection: Ensure the laptop is powered on and the power connection is secure.
  2. Recheck Boot Order in BIOS: Access the BIOS settings and set the DVD drive as the first boot option.
  3. Clean the Disc: If the DVD is old or dusty, clean it to remove any dirt that may affect the reading.
  4. Create a Bootable DVD: If the DVD is not bootable, create a bootable DVD using a CD/DVD burning software.
  5. Use UEFI Settings: If using a laptop with UEFI, ensure that the Secure Boot feature is disabled and the DVD drive is added to the boot list in the UEFI settings. 
 
 
If these steps do not resolve the issue, consider seeking professional assistance or checking for hardware issues related to the DVD drive.

No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed

 


#15 tamarisk

tamarisk
  • Topic Starter

  •  Avatar image
  • Members
  • 266 posts
  • OFFLINE
  •  
  • Local time:09:06 PM

Posted 29 October 2025 - 08:07 PM

The script ran well. No malware was detected. No integrity violations were found. Have you tried the bootable CD on another computer? See if there is a new Driver at HP for the Optical Drive.

 

Thank you that's great, but I have some questions:

 

Does this mean the problem was:

  • not caused by a virus/malware infection?
  • it may have been infected but is now clean?
  • it was infected but it is now clean?

 

In my original post, see https://www.bleepingcomputer.com/forums/t/811209/problem-booting-from-dvdrw/ (post #2) in answer to my question "Would this indicate some sort of malware" Pkshadow said "Yes, Suggest Open a Topic in the Malware Removal Forum though if is in your Bios you have problems." 

  • Did the scans run look for malware/virus/problems in the BIOS/boot sector?

 

See if there is a new Driver at HP for the Optical Drive.

 

 Official HP® Laptop Drivers and Software Download | HP® Support.

 

HP no longer support the PC or DVD drive so there does not seem to be any new drivers available. DVD drive is an HP DVDRAM GT50N, Device manager- Properties-Details tab-Device instance path: SCSI\CDROM&VEN_HP&PROD_DVDRAM_GT50N\4&2ED17E1&0&010000

 

I'll have to get back to you regarding further problems tomorrow.






1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users