The following problem description is copied from my original post at https://www.bleepingcomputer.com/forums/t/811209/problem-booting-from-dvdrw/ Suggestion from that was to repost here.
I have left a lot of info out of this post because it would be way to long so some steps I've taken are missing.
For a week or so I've been having problems booting my HP TouchSmart 520-1030, running Win10/Win11 dual boot, from bootable DVD's. This PC is not Win11 compliant but has been working seemingly OK since the dual boot was created. I had to convert the HDD from Dynamic to Basic and Legacy BIOS to UEFI so I could install Win11.
The initial problem was booting from its own latest W10 System Repair Disk following a change of the Win10 Product Key and failure of MS Word to load, which has now resolved itself but the booting problem still exists.
The issue grew to inconsistent booting from any bootable DVD/CD to no booting from any DVD/CD, Windows created or otherwise. However, all but the latest HP System Repair Disk would boot another dual boot W10/W11 PC (Acer XC-215 also non-Win11 compliant), which suggest all but one DVD/CD's are not in themselves faulty (though possibly had become incompatible if that is possible).
I tried several times to create a new System Repair Disk on the HP using both new and over-writing existing DVD’s but all attempts failed.
I tried several times to reset/rebuild the WBM/EFI but not really being sure of what I was doing I gave up with this. In desperation I reset the Win10 installation on the HP, keeping both files and Apps. This improved matters but did not resolve them completely. I got more consistent booting depending on the disk used but not as it should be and not at all with the latest HP System Repair Disk.
I swapped the DVDRW drive from the Acer into the HP and this improved the issue still further. I was now able to get consistent booting from all but the latest HP System Repair Disk. I was also able to create a new System Repair Disk on a new DVD and by over-writing the previous ‘latest HP System Repair Disk’ both of which booted the PC. They also booted the Acer now using the DVDRW drive from the HP. I tried all the DVDs in both PC’s and they all work, well almost. This suggests the DVD’s and Drives are OK albeit not always fully compatible.
This morning, I successfully booted the Acer using the HP DVDRW drive and very latest HP System Repair Disk 3 times, however, when I tried to boot the HP using the Acer DVDRW drive and very latest HP System Repair Disk it would not work but had done yesterday. Grrrrrrr
When I look at the boot options under Legacy Boot Sources on the HP a new entry has recently appeared that says ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿoPtrbae1U 0.
Would this indicate some sort of malware? See photo. If not what else could be at fault.
The DVD/CDs contain:
- Win10 Installation media of various versions both 32 & 64bit
- Win10 System Repair media from the TouchSmart and other Win10 PCs both 32 & 64bit
- Macrium Reflect rescue media from the TouchSmart
- SeaTools4DOS
- Hiren's BootCD for Win10
And are either Verbatim 4.7GB 4x DVD-RW, Verbatim 4.7GB 16x DVD +R RW or Maxell CD-R 52x.
I'm aware that Recovery USB drives are the better more reliable option but at the time my only option was the DVD route.
Photo at https://www.bleepingcomputer.com/forums/uploads/monthly_10_2025/post-1005646-0-38919200-1759931221.jpg
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-10-2025
Ran by KAA (administrator) on TOUCHSMART (Hewlett-Packard 520-1030uk) (08-10-2025 22:13:50)
Running from C:\Users\KAA\Downloads\FRST64.exe
Loaded Profiles: KAA
Platform: Microsoft Windows 10 Pro Version 22H2 19045.6332 (X64) Language: English (United Kingdom)
Default browser: C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.exe
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(C:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Mirics Semiconductor) C:\Program Files\MiricsFlexiTV\Driver\MSiBdaDemodWrapper.exe
(C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.exe ->) (Duck Duck Go, Inc. -> Microsoft Corporation) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe <20>
(explorer.exe ->) (Duck Duck Go, Inc. -> DuckDuckGo) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.exe
(explorer.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(explorer.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Andrea Electronics Corporation) [File not signed] C:\Program Files\IDT\WDM\AESTSr64.exe
(services.exe ->) (IDT, Inc.) [File not signed] C:\Program Files\IDT\WDM\stacsv64.exe
(services.exe ->) (Lenovo -> Motorola) C:\Program Files\Lenovo\Ready For Assistant\ReadyForService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Mirics Ltd.) C:\Program Files\MiricsFlexiTV\DVBT\DVBservice.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Mirics Semiconductor) C:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\NisSrv.exe
(services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Seraph Secure Inc. -> Seraph Secure Inc.) C:\Program Files\Seraph Secure\SeraphSecure.Desktop.Service.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(svchost.exe ->) (Seraph Secure Inc. -> Seraph Secure Inc.) C:\Program Files\Seraph Secure\SeraphSecure.Desktop.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2012-10-18] (Integrated Device Technology Inc. -> Hewlett-Packard) [File not signed]
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [11859680 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-10-18] (IDT, Inc.) [File not signed]
HKLM-x32\...\Run: [EKStatusMonitor] => C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe [2750840 2013-12-11] (Eastman Kodak Company -> Eastman Kodak Company)
HKLM-x32\...\Run: [Nero BackItUp] => C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\BackItUp.exe [1150320 2016-11-08] (Nero AG -> Nero AG)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [41579480 2025-09-29] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1004\...\Run: [MicrosoftEdgeAutoLaunch_70F5C52BE9DF1358C7250A17068A79C5] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1007\...\Run: [MicrosoftEdgeAutoLaunch_0312593BFFDB8261C1676A58C7A72931] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Print\Monitors\KODAK All-in-One Printer: C:\WINDOWS\system32\EKAiO2MON.dll [1649664 2013-11-19] (Microsoft Windows Hardware Compatibility Publisher -> Eastman Kodak Company)
Startup: C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2022-04-09]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2025-10-06]
GroupPolicy: Restriction - Edge <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {4E3227A3-D76B-48C7-9FBA-2F6ADC701346} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1581568 2025-08-24] (Adobe Inc. -> Adobe Inc.)
Task: {A2FFEC02-982C-4D11-A8EE-42CA7FCA65DB} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem131.0.6776.0{F668BBEF-823D-4D83-8CD3-495C7587B595} => C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\updater.exe [5507168 2024-10-14] (Google LLC -> Google LLC)
Task: {BF3C8C90-BED3-40C3-AD45-BB50418E301E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001Core{D220553E-E54C-4CD1-BC37-1A56E28B2CD4} => C:\Users\KAA\AppData\Local\Google\Update\GoogleUpdate.exe /c (No File)
Task: {A3BE9F3C-ECCA-4213-A7D3-A174A2CC35D7} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001UA{99C2A8AA-F663-43F3-A707-6DECB4586918} => C:\Users\KAA\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler (No File)
Task: {93EFB0AA-12D5-4C09-BC7C-81DCB73A5BFD} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ABO => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://ABO
Task: {CEC80FA8-A7F9-4DAB-95BF-60017DE39D86} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusError => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BatteryStatusError
Task: {8AEC054E-DC44-4E8D-8BE5-00507F16F1BB} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BCF => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BCF
Task: {92379D3F-DF65-4F74-9DA2-79406E4B59E0} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM1 => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM1
Task: {022BA1A8-53F1-4EA0-AFFA-5EFE02716F56} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM2 => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM2
Task: {8A4D5CFD-883D-4534-9FA2-B184B7ACC79D} - System32\Tasks\Hewlett-Packard\HP Diagnostics\LaunchUI => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://LaunchUI
Task: {A2B0BEEF-A0D1-4D51-BE1B-2331B82FB757} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ShowUI => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags:
Task: {444882E0-CD7F-42ED-9C3F-96A9A619F77F} - System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckError => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://SmartCheckError
Task: {96E4B330-552D-45DB-B776-B1D8D30EA8CA} - System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckTest => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://SmartCheckTest
Task: {628AA9AA-4E54-4FBB-B888-064564A0EC10} - System32\Tasks\Hewlett-Packard\HP Diagnostics\Uninstall-FastSystemTests => c:\Windows\System32\schtasks.exe [268800 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /Change /Disable /tn "\Hewlett-Packard\HP Diagnostics\FastSystemTests"
Task: {05A0D43D-AFF2-4EB1-8DF1-FDC18D7AD460} - System32\Tasks\Hewlett-Packard\HP Diagnostics\Uninstall-SmartCheckTest => c:\Windows\System32\schtasks.exe [268800 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /Change /Disable /tn "\Hewlett-Packard\HP Diagnostics\SmartCheckTest"
Task: {12442B10-DE8C-4BE5-B15D-10BB9F5FF93B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [702512 2023-07-25] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {AE9B1D97-834B-4138-ACD1-3073213B353A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [138328 2023-07-25] (HP Inc. -> HP Inc.)
Task: {F364CD9A-6B1B-4BAA-AC6B-6B4B51AF1734} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1145896 2023-07-25] (HP Inc. -> HP Inc.)
Task: {91604C30-3E13-47D9-83B7-AF74218CBD6E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1145896 2023-07-25] (HP Inc. -> HP Inc.)
Task: {101F31C9-B2DA-4D18-88AC-D52D8C7B3B4D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24610408 2020-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {EB1C9E76-8A74-4CEA-9C91-8F650066ED4D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24610408 2020-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {608D509D-EAE9-45F5-8EEF-472D00EBCDB8} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158544 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {052A3942-A1A4-41AB-97BC-2CEF3A3EC94D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158544 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {B84D226A-D7FA-4FE9-8EA3-5EC0908E9E3B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6160272 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {02EFE719-1F90-4B92-8C7F-3E512AF95D37} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6160272 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {99B55C99-93FF-45E3-9638-E0AC18708487} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C0110507-D81F-4D41-AA6B-E3EFE5F10DD1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9782ACAD-18B9-47D6-9496-1EBDB3C493E8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AE20B3B6-A636-48BF-8A9E-69701D03DB33} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D077ECA5-A77E-4C78-9405-CBABF61E1C84} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [674208 2023-12-05] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {5BC61FCA-DA32-4D1B-AF59-FE3A0A59901D} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [35232 2023-12-05] (Mozilla Corporation -> Mozilla Foundation)
Task: {73DBA20C-8F44-47BD-8CFC-39ADEB169B81} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [3867928 2020-11-15] (Nero AG -> Nero AG)
Task: {D35E1681-4F4F-4E55-8C51-D4662DBD7792} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1001 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) <==== ATTENTION
Task: {0FD11B6C-5F37-4811-89DB-3A5544C4ED9C} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1004 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) <==== ATTENTION
Task: {82878F6A-228B-4376-9E76-CFED67A17606} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1006 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) <==== ATTENTION
Task: {BB7E1583-913A-4D86-B22A-50A8D088323F} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1007 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) <==== ATTENTION
Task: {7A9F3BA0-E8AA-44E0-901E-7938721972B5} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1001 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {E0414E31-C2B4-4716-A4D8-9283C4443227} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1002 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {C6BA1144-34CC-4FE4-9F2C-C164840D2A0D} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1003 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {3D0A3660-29F7-4E00-9984-02CAFCDC653B} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1004 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {60703B05-F41E-4B4E-873D-5D16113BB983} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1006 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {0D1E8BFF-AA7E-4737-82E1-4F192A32500E} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1007 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {9C9B0D04-4B26-4776-A5FB-8B4AC424759D} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {D149F916-0061-4A21-9B7D-A8AFC26DC624} - System32\Tasks\SeraphSecureLogon => C:\Program Files\Seraph Secure\SeraphSecure.Desktop.exe [16031344 2025-08-28] (Seraph Secure Inc. -> Seraph Secure Inc.) -> C:\Program Files\Seraph Secure\\--startup
Task: {3502994E-7C1F-4E6D-A912-FEC7DCCAD126} - System32\Tasks\SeraphSecureVerify => C:\Program Files\Seraph Secure\SeraphSecure.Setup.exe [1115328 2025-08-28] (Seraph Secure Inc. -> ) -> C:\Program Files\Seraph Secure\\/silent /verify
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1a98b6d1-90ba-4524-9b29-f01366eec3f9}: [DhcpNameServer] 192.168.22.22 192.168.22.23
Tcpip\..\Interfaces\{46ce57af-c84e-4ff6-94bc-0638ec221f1e}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{46ce57af-c84e-4ff6-94bc-0638ec221f1e}: [DhcpDomain] powerhub
Tcpip\..\Interfaces\{72285048-0945-41a4-8a20-6a8203986e5b}: [DhcpNameServer] 192.168.22.22 192.168.22.23
Tcpip\..\Interfaces\{eebba993-4062-402b-807d-57da6dbf6c56}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f4242fa3-05f8-47aa-81a2-c748dd49e1cf}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default [2025-10-06]
Edge HomePage: Default -> hxxps://html.duckduckgo.com/html?q=duckduckgo
Edge StartupUrls: Default -> "hxxps://www.btwifi.com:8443/home","hxxps://html.duckduckgo.com/html?q=duckduckgo"
Edge NewTab: Default -> Active:"chrome-extension://eimldjabijllelicbnieiomiaeekbodl/index.html", Active:"chrome-extension://jonikckfpolfcdcgdficelkfffkloemh/n.html"
Edge DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
Edge DefaultSearchKeyword: Default -> duckduckgo.com
Edge DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab
Edge DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
Edge Extension: (Trocker) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjojfeillmmoeadgobbcknkgdkngbcdb [2024-08-08]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2025-09-27]
Edge Extension: (DuckDuckGo) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caoacbimdbbljakfhgikoodekdnlcgpk [2025-08-31]
Edge Extension: (NoScript) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\debdhlbmgmkkfjpcglcbjadbhhekgfjh [2022-06-09]
Edge Extension: (Windscribe VPN - Privacy & Ad Block Suite) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dkkdbpgldnmkhcliffjpajcfdjkcaddf [2025-09-27]
Edge Extension: (VT4Browsers) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\efbjojhplkelaegfbieplglfidafgoka [2024-04-19]
Edge Extension: (New Tab DuckDuckGo Redirect) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\eimldjabijllelicbnieiomiaeekbodl [2023-02-04]
Edge Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\elhekieabhbkpmcefcoobjddigjcaadp [2025-09-30]
Edge Extension: (Google Analytics Opt-out Add-on (by Google)) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2024-05-10]
Edge Extension: (Google Docs Offline) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-09-27]
Edge Extension: (APK Downloader) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\glngapejbnmnicniccdcemghaoaopdji [2025-03-15]
Edge Extension: (WOT: Website Security & Safety Checker) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\iiclaphjclecagpkkaacljnpcppnoibi [2025-03-15]
Edge Extension: (Edge relevant text changes) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge Extension: (PixelBlock) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmpmfcjnflbcoidlgapblgpgbilinlem [2024-03-12]
Edge Extension: (Blank New Tab Page) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jonikckfpolfcdcgdficelkfffkloemh [2021-01-21]
Edge Extension: (Zune Software Download [Window 10] Guide) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mbgchiachcmhdeicjkpnjifgddendfph [2022-11-01]
Edge Extension: (uBlock Origin) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2025-09-27]
Edge Extension: (AdGuard AdBlocker) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pdffkfellgipmhklpdmokmckkkfcopbh [2025-08-26]
Edge Extension: (Privacy Badger) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pkehgijcmpdhfbdbbnkijodmdjhbjlgp [2025-09-27]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF DefaultProfile: rpjp5gd5.default
FF ProfilePath: C:\Users\KAA\AppData\Roaming\Mozilla\Firefox\Profiles\rpjp5gd5.default [2021-09-14]
FF ProfilePath: C:\Users\KAA\AppData\Roaming\Mozilla\Firefox\Profiles\79xfahfv.default-release-1631788129756 [2025-08-31]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\KAA\AppData\Roaming\Mozilla\Firefox\Profiles\79xfahfv.default-release-1631788129756\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2023-12-05]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-09-29] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174584 2025-08-24] (Adobe Inc. -> Adobe Inc.)
R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2012-10-18] (Andrea Electronics Corporation) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11109232 2020-04-09] (Microsoft Corporation -> Microsoft Corporation)
S3 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [43784 2024-03-27] (Intel Corporation -> Intel)
S3 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [291592 2024-03-27] (Intel Corporation -> Intel)
S3 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [888208 2023-07-25] (HP Inc. -> HP Inc.)
S3 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [887192 2023-07-25] (HP Inc. -> HP Inc.)
S3 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [883088 2023-07-25] (HP Inc. -> HP Inc.)
S3 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [887696 2023-07-25] (HP Inc. -> HP Inc.)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [13004248 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8965728 2024-12-08] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.25080.5-0\MpDefenderCoreService.exe [2009656 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 msi2500scan; c:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe [229376 2011-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Mirics Semiconductor)
R2 MSiDVBT; c:\Program Files\MiricsFlexiTV\DVBT\DVBService.exe [2715648 2011-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Mirics Ltd.)
S3 MSSQL$ACCUCHEK360; C:\Program Files (x86)\Microsoft SQL Server\MSSQL12.ACCUCHEK360\MSSQL\Binn\sqlservr.exe [199352 2017-07-06] (Microsoft Corporation -> Microsoft Corporation)
S3 NeroBackItUpBackgroundService; C:\Program Files (x86)\Nero\Nero 2017\Nero BackItUp\NBService.exe [287088 2016-11-08] (Nero AG -> Nero AG)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [918456 2025-10-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SeraphSecure; C:\Program Files\Seraph Secure\SeraphSecure.Desktop.Service.exe [6331304 2025-08-28] (Seraph Secure Inc. -> Seraph Secure Inc.)
R2 SmartConnect; C:\Program Files\Lenovo\Ready For Assistant\ReadyForService.exe [2641400 2025-02-24] (Lenovo -> Motorola)
S3 SQLAgent$ACCUCHEK360; C:\Program Files (x86)\Microsoft SQL Server\MSSQL12.ACCUCHEK360\MSSQL\Binn\SQLAGENT.EXE [454848 2017-07-06] (Microsoft Corporation -> Microsoft Corporation)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2012-10-18] (IDT, Inc.) [File not signed]
S3 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [9216 2011-03-29] (Vodafone) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.25080.5-0\NisSrv.exe [4414464 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.25080.5-0\MsMpEng.exe [282480 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ewusbnet; C:\WINDOWS\System32\drivers\ewusbnet.sys [413696 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 ew_hwusbdev; C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys [117248 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 ew_usbenumfilter; C:\WINDOWS\System32\drivers\ew_usbenumfilter.sys [13952 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 huawei_enumerator; C:\WINDOWS\System32\drivers\ew_jubusenum.sys [85504 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 hwdatacard; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [219008 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 ITECIRfilter; C:\WINDOWS\system32\DRIVERS\ITECIRfilter.sys [36560 2015-11-24] (ITE Tech. Inc. -> ITE Tech. Inc.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333216 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
R3 lenovoDriverBus; C:\WINDOWS\System32\drivers\lenovoDriverBus.sys [103152 2025-02-24] (Lenovo -> Lenovo Inc.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2022-07-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239568 2024-12-08] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MDA_NTDRV; C:\WINDOWS\system32\MDA_NTDRV.sys [43664 2025-08-29] (Chongqing NIUBI Technology Co., Ltd. -> )
R2 Mrvdp; C:\WINDOWS\system32\drivers\mrvdp.sys [58112 2021-10-13] (Paramount Software UK Ltd -> Windows ® Win 7 DDK provider)
R3 MSi2500BDA; C:\WINDOWS\system32\DRIVERS\AVerMsiBDA.sys [228352 2011-12-12] (Microsoft Windows Hardware Compatibility Publisher -> AVerMedia TECHNOLOGIES, Inc.)
R3 NWVoltron; C:\WINDOWS\System32\drivers\NWVoltron.sys [28920 2015-07-09] (NextWindow -> )
S3 NWWakeFilterV; C:\WINDOWS\System32\drivers\NWWakeFilterV.sys [16632 2015-07-09] (NextWindow -> n/a)
S3 PSMounterEx; C:\Windows\system32\drivers\psmounterex.sys [140720 2023-10-02] (Microsoft Windows Hardware Compatibility Publisher -> Windows ® Win 7 DDK provider)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2021-03-26] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2021-03-26] (MiniTool Solution Ltd -> )
R2 RFDriveFs2; C:\Program Files\Lenovo\Ready For Assistant\drivers\FileSystem\RFDriveFs2.sys [412984 2025-02-24] (Lenovo -> Motorola)
S3 s116bus; C:\WINDOWS\System32\drivers\s116bus.sys [108296 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116mdfl; C:\WINDOWS\system32\DRIVERS\s116mdfl.sys [19720 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116mdm; C:\WINDOWS\system32\DRIVERS\s116mdm.sys [144648 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116mgmt; C:\WINDOWS\system32\DRIVERS\s116mgmt.sys [126216 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116nd5; C:\WINDOWS\System32\drivers\s116nd5.sys [31496 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116obex; C:\WINDOWS\system32\DRIVERS\s116obex.sys [123656 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116unic; C:\WINDOWS\System32\drivers\s116unic.sys [130824 2007-04-03] (MCCI Corporation -> MCCI Corporation)
R3 STHDA; C:\WINDOWS\system32\DRIVERS\stwrt64.sys [543744 2012-10-18] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
R3 tilfilter; C:\WINDOWS\System32\drivers\TIxHCIlfilter.sys [34424 2016-08-20] (Texas Instruments, Inc. -> Texas Instruments, Inc.)
R3 tiufilter; C:\WINDOWS\System32\drivers\TIxHCIufilter.sys [39032 2016-08-20] (Texas Instruments, Inc. -> Texas Instruments, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20880 2025-09-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [627104 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [159936 2020-06-17] (NGO -> MBB)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102816 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-10-08 22:13 - 2025-10-08 22:16 - 000033549 _____ C:\Users\KAA\Downloads\FRST.txt
2025-10-08 22:12 - 2025-10-08 22:15 - 000000000 ____D C:\FRST
2025-10-08 22:10 - 2025-10-08 22:10 - 002442752 _____ (Farbar) C:\Users\KAA\Downloads\FRST64.exe
2025-10-08 20:19 - 2025-10-08 20:19 - 002134016 _____ (Farbar) C:\Users\KAA\Downloads\FRST.exe
2025-10-07 17:37 - 2025-10-07 17:37 - 000000000 ___HD C:\$SysReset
2025-10-07 13:39 - 2025-10-07 13:39 - 000000762 _____ C:\Users\KAA\Documents\Win10 Reagentc info results.txt
2025-10-07 08:19 - 2025-10-07 16:41 - 000000000 _____ C:\Recovery.txt
2025-10-06 13:22 - 2025-10-06 13:22 - 000002782 _____ C:\Users\KAA\Documents\Chkdsk results.txt
2025-10-06 12:31 - 2025-10-06 12:31 - 000000000 ____D C:\WINDOWS\pss
2025-10-06 12:17 - 2025-10-06 12:17 - 000053013 _____ C:\WINDOWS\system32\sfclogs.txt
2025-10-06 11:07 - 2025-10-06 11:07 - 000000000 ____D C:\inetpub
2025-10-06 09:44 - 2025-10-06 09:44 - 000023734 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-10-06 09:37 - 2025-10-06 09:37 - 000023734 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-10-06 08:36 - 2025-10-06 08:36 - 000001036 __RSH C:\ProgramData\ntuser.pol
2025-10-06 08:04 - 2025-10-06 08:04 - 000003189 _____ C:\WINDOWS\system32\wrapperMap.json
2025-10-06 01:10 - 2025-10-06 00:54 - 000000000 ____D C:\Windows.old
2025-10-06 01:06 - 2025-10-06 01:06 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2025-10-06 01:03 - 2025-10-06 01:10 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2025-10-06 01:03 - 2025-10-06 01:03 - 000000020 ___SH C:\Users\KAA\ntuser.ini
2025-10-06 01:00 - 2025-10-06 01:02 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2025-10-06 01:00 - 2025-10-06 01:00 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2025-10-06 00:55 - 2025-10-06 11:07 - 000000000 ____D C:\Program Files\Hyper-V
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ___SD C:\WINDOWS\system32\containers
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\WINDOWS\system32\BestPractices
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files\Reference Assemblies
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files\MSBuild
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files (x86)\MSBuild
2025-10-06 00:52 - 2025-10-08 18:14 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-10-06 00:52 - 2025-10-06 08:02 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-10-06 00:52 - 2025-10-06 08:02 - 000003410 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-10-06 00:52 - 2025-10-06 00:53 - 000003598 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001UA{99C2A8AA-F663-43F3-A707-6DECB4586918}
2025-10-06 00:52 - 2025-10-06 00:53 - 000003330 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001Core{D220553E-E54C-4CD1-BC37-1A56E28B2CD4}
2025-10-06 00:52 - 2025-10-06 00:53 - 000003126 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1004
2025-10-06 00:52 - 2025-10-06 00:53 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1007
2025-10-06 00:52 - 2025-10-06 00:53 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1006
2025-10-06 00:52 - 2025-10-06 00:53 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1001
2025-10-06 00:52 - 2025-10-06 00:53 - 000002976 _____ C:\WINDOWS\system32\Tasks\SeraphSecureVerify
2025-10-06 00:52 - 2025-10-06 00:53 - 000002922 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1004
2025-10-06 00:52 - 2025-10-06 00:53 - 000002922 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1003
2025-10-06 00:52 - 2025-10-06 00:53 - 000002922 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1002
2025-10-06 00:52 - 2025-10-06 00:53 - 000002918 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-500
2025-10-06 00:52 - 2025-10-06 00:53 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1007
2025-10-06 00:52 - 2025-10-06 00:53 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1006
2025-10-06 00:52 - 2025-10-06 00:53 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1001
2025-10-06 00:52 - 2025-10-06 00:53 - 000002446 _____ C:\WINDOWS\system32\Tasks\SeraphSecureLogon
2025-10-06 00:52 - 2025-10-06 00:52 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\PowerToys
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Nero
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Hewlett-Packard
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
2025-10-06 00:48 - 2025-10-06 00:52 - 000019053 _____ C:\WINDOWS\diagwrn.xml
2025-10-06 00:48 - 2025-10-06 00:52 - 000019053 _____ C:\WINDOWS\diagerr.xml
2025-10-06 00:33 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\SystemCertificates
2025-10-06 00:33 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\Network
2025-10-06 00:33 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\Crypto
2025-10-06 00:31 - 2025-10-07 16:21 - 000982820 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-10-06 00:30 - 2025-10-06 00:30 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\SystemCertificates
2025-10-06 00:30 - 2025-10-06 00:30 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Network
2025-10-06 00:30 - 2025-10-06 00:30 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Crypto
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\SystemCertificates
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\Network
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\Crypto
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network
2025-10-06 00:21 - 2025-10-06 00:21 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\CLR Security Config
2025-10-06 00:18 - 2025-10-06 00:18 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\CLR Security Config
2025-10-06 00:18 - 2025-10-06 00:18 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\CLR Security Config
2025-10-06 00:17 - 2025-10-07 13:49 - 000000000 ____D C:\Users\Anne
2025-10-06 00:17 - 2025-10-06 15:31 - 000000000 ____D C:\Users\KAA
2025-10-06 00:17 - 2025-10-06 01:04 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows
2025-10-06 00:17 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\Windows
2025-10-06 00:17 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\Administrator
2025-10-06 00:17 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\Windows
2025-10-06 00:17 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin
2025-10-06 00:11 - 2025-10-08 18:14 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-10-06 00:11 - 2025-10-06 11:19 - 000491000 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-10-06 00:11 - 2025-10-06 00:11 - 000001162 _____ C:\WINDOWS\system32\config\VSMIDK
2025-10-05 21:53 - 2025-10-05 21:55 - 000000000 ____D C:\Users\KAA\Documents\Thunderbird Profiles copy
2025-10-05 21:33 - 2025-10-06 01:03 - 000000000 ___DC C:\WINDOWS\Panther
2025-10-03 20:43 - 2025-10-03 20:50 - 3291686912 _____ C:\Users\KAA\Downloads\HBCD_PE_x64.iso
2025-10-03 13:48 - 2025-10-03 13:48 - 001936744 _____ (Akeo Consulting) C:\Users\KAA\Downloads\rufus-4.11.exe
2025-10-01 22:34 - 2025-10-01 22:34 - 000000000 ___HD C:\$Windows.~WS
2025-09-30 17:12 - 2025-09-30 17:12 - 000182308 _____ C:\Users\KAA\Documents\xfgfx.pdf
2025-09-30 16:53 - 2025-09-30 16:53 - 000248032 _____ C:\Users\KAA\Documents\XPension docs to Guy.pdf
2025-09-28 12:26 - 2025-09-28 12:26 - 000000000 ____D C:\ProgramData\Apple Computer
2025-09-28 12:26 - 2025-09-28 12:26 - 000000000 ____D C:\ProgramData\Apple
2025-09-27 14:40 - 2025-09-27 14:41 - 000000422 _____ C:\Users\KAA\Documents\Windows 10 Pro Key from ShowKeyPlus.txt
2025-09-27 12:48 - 2025-09-27 12:49 - 000270638 _____ C:\Users\KAA\Downloads\Win10 licence_Screenshot_27-9-2025_124857_www.electronicfirst.com.jpeg
2025-09-27 11:27 - 2025-09-27 11:27 - 000000000 ____D C:\ProgramData\Office Genuine Advantage
2025-09-25 15:34 - 2025-09-25 15:34 - 000048173 _____ C:\Users\KAA\Downloads\24169 - Hive V4 Wireless Heating Hot Water Smart Thermostat.pdf
2025-09-24 16:09 - 2025-09-25 17:43 - 000012028 _____ C:\Users\KAA\Documents\Win10 licence sites.xlsx
2025-09-21 12:26 - 2025-09-21 12:23 - 001587098 _____ C:\Users\KAA\Documents\Churchill Motor policy-booklet-1124.pdf
2025-09-15 12:32 - 2025-09-15 12:32 - 000021554 _____ C:\Users\KAA\Downloads\Letter.odt
2025-09-14 16:43 - 2025-09-14 16:48 - 000000812 _____ C:\Users\KAA\Desktop\Consumer ESU Enrollment.txt
2025-09-14 16:07 - 2025-09-14 16:10 - 000000000 ____D C:\Users\KAA\Downloads\Consumer ESU Enrollment
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-10-08 20:11 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-10-08 20:10 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-10-08 20:10 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-10-08 19:25 - 2020-03-04 18:13 - 000000000 ____D C:\Users\KAA\AppData\Local\Packages
2025-10-08 18:21 - 2020-03-26 10:45 - 000001076 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2025-10-08 18:15 - 2024-12-18 17:25 - 000000000 ____D C:\Program Files\Seraph Secure
2025-10-08 18:14 - 2020-06-06 12:18 - 000008192 ___SH C:\DumpStack.log.tmp
2025-10-08 13:26 - 2023-12-04 03:51 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-10-08 13:14 - 2020-10-22 19:00 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Word
2025-10-07 16:21 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2025-10-07 16:10 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-10-07 13:05 - 2025-08-29 16:29 - 000001347 _____ C:\Users\KAA\Desktop\NIUBI Partition Editor Free Edition.lnk
2025-10-07 11:45 - 2020-03-04 18:31 - 000000000 ____D C:\ProgramData\Packages
2025-10-07 00:05 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-10-06 15:33 - 2024-02-01 14:05 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2025-10-06 12:21 - 2025-08-27 23:16 - 000053013 _____ C:\Users\KAA\Desktop\sfcdetails.txt
2025-10-06 11:39 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-10-06 11:09 - 2019-12-07 15:46 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemApps
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-10-06 11:08 - 2024-07-09 19:35 - 000000000 ____D C:\WINDOWS\system32\compatrel
2025-10-06 11:08 - 2019-12-07 15:49 - 000000000 ___SD C:\WINDOWS\system32\AppV
2025-10-06 11:08 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-10-06 11:07 - 2023-12-04 03:51 - 000000000 ____D C:\WINDOWS\InboxApps
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Portable Devices
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2025-10-06 11:07 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\en-GB
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\USOPrivate
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2025-10-06 11:07 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2025-10-06 10:50 - 2020-03-04 18:16 - 000000000 ____D C:\Users\KAA\AppData\Local\PlaceholderTileLogoFolder
2025-10-06 08:39 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-10-06 08:28 - 2019-12-07 10:14 - 000000000 __RSD C:\WINDOWS\Media
2025-10-06 08:28 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2025-10-06 08:03 - 2020-05-06 17:30 - 000000000 ____D C:\Users\KAA\AppData\Local\HP
2025-10-06 08:02 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\appcompat
2025-10-06 02:46 - 2024-10-27 13:43 - 000000000 ___RD C:\Users\KAA\Documents\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe!App
2025-10-06 01:10 - 2025-03-08 20:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Connect
2025-10-06 01:10 - 2024-12-10 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2025-10-06 01:10 - 2023-12-19 15:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium
2025-10-06 01:10 - 2023-10-22 00:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SP Driver
2025-10-06 01:10 - 2023-02-04 00:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 2017
2025-10-06 01:10 - 2023-02-04 00:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
2025-10-06 01:10 - 2022-11-03 16:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2025-10-06 01:10 - 2022-07-22 21:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zune
2025-10-06 01:10 - 2022-07-14 15:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerToys (Preview)
2025-10-06 01:10 - 2021-03-21 20:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vodafone
2025-10-06 01:10 - 2021-03-04 17:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-10-06 01:10 - 2021-02-26 14:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2025-10-06 01:10 - 2020-11-03 14:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2025-10-06 01:10 - 2020-08-23 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak
2025-10-06 01:10 - 2020-08-23 17:57 - 000000000 ____D C:\WINDOWS\SysWOW64\kodak
2025-10-06 01:10 - 2020-08-18 00:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACCU-CHEK 360
2025-10-06 01:10 - 2020-08-17 23:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2014
2025-10-06 01:10 - 2020-08-17 23:35 - 000000000 ____D C:\WINDOWS\SysWOW64\1033
2025-10-06 01:10 - 2020-08-17 23:35 - 000000000 ____D C:\WINDOWS\system32\1033
2025-10-06 01:10 - 2020-08-17 22:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\diasend® Uploader
2025-10-06 01:10 - 2020-05-29 10:32 - 000000000 ____D C:\Program Files\UNP
2025-10-06 01:10 - 2020-05-06 21:04 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2025-10-06 01:10 - 2020-05-05 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2025-10-06 01:10 - 2020-03-04 18:26 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-10-06 01:10 - 2020-03-04 18:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
2025-10-06 01:10 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2025-10-06 01:10 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\system32\WCN
2025-10-06 01:10 - 2019-12-07 10:18 - 000000000 ____D C:\WINDOWS\Setup
2025-10-06 01:10 - 2019-12-07 10:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\spool
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Registration
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-10-06 01:10 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2025-10-06 01:10 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2025-10-06 01:09 - 2019-12-07 10:14 - 000000000 __RHD C:\Users\Public\Libraries
2025-10-06 01:05 - 2020-03-28 23:29 - 000000000 ____D C:\WINDOWS\system32\kodak
2025-10-06 01:03 - 2022-12-30 18:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verbatim
2025-10-06 01:03 - 2022-11-05 18:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2025-10-06 01:03 - 2022-07-22 21:35 - 000000000 ___RD C:\Users\KAA\Podcasts
2025-10-06 01:03 - 2022-07-12 13:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2025-10-06 01:03 - 2020-08-17 23:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008
2025-10-06 01:03 - 2020-03-04 18:13 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-10-06 01:03 - 2020-03-04 18:13 - 000000000 ___RD C:\Users\KAA\3D Objects
2025-10-06 01:03 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-10-06 01:03 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-10-06 01:03 - 2019-12-07 15:47 - 000000000 ____D C:\WINDOWS\OCR
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2025-10-06 00:55 - 2023-12-04 03:46 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\HgsClientWmi.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000130544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdp4vs.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000110560 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmwpevents.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000062448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pvhdparser.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000059880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\l2bridge.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000037352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocketcontrol.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000029160 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmsifproxystub.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000022400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hnswfpdriver.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmComputeProxy.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000014848 _____ C:\WINDOWS\system32\hnsproxy.dll
2025-10-06 00:55 - 2023-12-04 03:43 - 000207216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpcivsp.sys
2025-10-06 00:55 - 2023-12-04 03:43 - 000042472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vkrnlintvsc.sys
2025-10-06 00:55 - 2023-12-04 03:43 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Synth3dVsp.sys
2025-10-06 00:55 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\schemas
2025-10-06 00:55 - 2019-12-07 10:10 - 001579818 _____ C:\WINDOWS\system32\WindowsVirtualization.V2.mof
2025-10-06 00:55 - 2019-12-07 10:10 - 001152064 _____ C:\WINDOWS\system32\WindowsHyperVCluster.V2.mof
2025-10-06 00:55 - 2019-12-07 10:10 - 000182560 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmsp.exe
2025-10-06 00:55 - 2019-12-07 10:10 - 000144967 _____ C:\WINDOWS\system32\virtmgmt.msc
2025-10-06 00:55 - 2019-12-07 10:10 - 000043640 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmplatformca.exe
2025-10-06 00:55 - 2019-12-07 10:10 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AttestationWmiProvider.dll
2025-10-06 00:55 - 2019-12-07 10:10 - 000035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\lunparser.sys
2025-10-06 00:55 - 2019-12-07 10:10 - 000016384 _____ C:\WINDOWS\system32\hgclientserviceps.dll
2025-10-06 00:55 - 2019-12-07 10:10 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\HostGuardianServiceClientResources.dll
2025-10-06 00:55 - 2019-12-07 10:10 - 000012088 _____ (Microsoft Corporation) C:\WINDOWS\system32\f1db7d81-95be-4911-935a-8ab71629112a_vmsvcext_sys.dll
2025-10-06 00:55 - 2019-12-07 10:10 - 000012088 _____ (Microsoft Corporation) C:\WINDOWS\system32\c28c7a4e-a619-4463-82b7-0fc9cc7187f5_HyperV-ComputeStorage.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000039440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\passthruparser.sys
2025-10-06 00:55 - 2019-12-07 10:09 - 000031544 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmcomputeeventlog.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000012816 _____ (Microsoft Corporation) C:\WINDOWS\system32\f989b52d-f928-44a3-9bf1-bf0c1da6a0d6_HyperV-DeviceVirtualization.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000012600 _____ (Microsoft Corporation) C:\WINDOWS\system32\d4d78066-e6db-44b7-b5cd-2eb82dce620c_HyperV-ComputeLegacy.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000012600 _____ (Microsoft Corporation) C:\WINDOWS\system32\c4d66f00-b6f0-4439-ac9b-c5ea13fe54d7_HyperV-ComputeCore.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000012304 _____ (Microsoft Corporation) C:\WINDOWS\system32\07409496-a423-4a3e-b620-2cfb01a9318d_HyperV-ComputeNetwork.dll
2025-10-06 00:55 - 2019-12-07 10:09 - 000006658 _____ C:\WINDOWS\system32\VmChipset Third-Party Notices.txt
2025-10-06 00:52 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2025-10-06 00:24 - 2025-08-29 16:29 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NIUBI Partition Editor Free Edition
2025-10-06 00:24 - 2025-03-08 20:00 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2025-10-06 00:24 - 2021-03-04 17:26 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-10-06 00:24 - 2020-10-24 10:49 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Corporation
2025-10-06 00:24 - 2020-03-24 18:53 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirusTotal Uploader 2.2
2025-10-06 00:21 - 2023-08-29 13:36 - 000000000 ____D C:\Users\Anne\AppData\Local\Packages
2025-10-06 00:18 - 2020-07-29 17:51 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Local\Packages
2025-10-06 00:18 - 2019-12-07 10:14 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows
2025-10-06 00:15 - 2020-03-04 18:25 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2025-10-06 00:15 - 2020-03-04 18:25 - 000000000 ____D C:\ProgramData\SoundResearch
2025-10-06 00:15 - 2020-03-04 18:19 - 000000000 ____D C:\Program Files\MiricsFlexiTV
2025-10-05 21:34 - 2021-03-01 22:52 - 000000000 ____D C:\Users\KAA\AppData\Local\CrashDumps
2025-10-04 17:34 - 2020-03-24 18:14 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-10-04 17:34 - 2020-03-24 18:14 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-10-03 20:43 - 2022-10-14 13:28 - 000002079 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-10-03 20:43 - 2022-10-14 13:28 - 000002067 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2025-10-03 17:55 - 2021-02-22 16:42 - 000000000 ____D C:\Users\KAA\Documents\Household
2025-10-03 17:01 - 2020-10-31 01:33 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Excel
2025-10-02 00:13 - 2021-02-09 23:02 - 000000000 ____D C:\ESD
2025-09-30 17:59 - 2023-07-22 18:21 - 000000000 ____D C:\Users\KAA\AppData\Local\Malwarebytes
2025-09-30 17:14 - 2020-08-18 00:49 - 000000000 ____D C:\Users\KAA\AppData\LocalLow\Temp
2025-09-30 17:14 - 2020-06-13 17:12 - 000000000 ____D C:\Users\KAA\AppData\LocalLow\Adobe
2025-09-28 12:18 - 2020-03-04 18:14 - 000000000 ____D C:\Users\KAA\AppData\Local\Publishers
2025-09-18 11:12 - 2020-03-04 17:44 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-09-12 11:06 - 2022-07-01 16:58 - 000000000 ____D C:\Program Files\dotnet
2025-09-12 11:06 - 2020-08-17 22:05 - 000000000 ____D C:\ProgramData\Package Cache
==================== Files in the root of some directories ========
2020-06-16 12:37 - 2020-06-16 12:37 - 002008779 _____ () C:\Program Files\ProcessExplorer.zip
2025-08-27 23:39 - 2025-08-27 23:39 - 000000028 _____ () C:\Users\KAA\AppData\Roaming\epm_user.ini
2022-10-05 16:23 - 2023-09-18 11:57 - 000007673 _____ () C:\Users\KAA\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2025
Ran by KAA (08-10-2025 22:27:46)
Running from C:\Users\KAA\Downloads
Microsoft Windows 10 Pro Version 22H2 19045.6332 (X64) (2025-10-05 23:54:21)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2603899380-3263017511-4129809722-500 - Administrator - Disabled) => C:\Users\Administrator
Anne (S-1-5-21-2603899380-3263017511-4129809722-1007 - Limited - Enabled) => C:\Users\Anne
DefaultAccount (S-1-5-21-2603899380-3263017511-4129809722-503 - Limited - Disabled)
Guest (S-1-5-21-2603899380-3263017511-4129809722-501 - Limited - Disabled)
KAA (S-1-5-21-2603899380-3263017511-4129809722-1001 - Administrator - Enabled) => C:\Users\KAA
NonStoreLogin (S-1-5-21-2603899380-3263017511-4129809722-1004 - Limited - Enabled) => C:\Users\NonStoreLogin
WDAGUtilityAccount (S-1-5-21-2603899380-3263017511-4129809722-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
ACCU-CHEK 360 (HKLM-x32\...\{33C351FC-D928-47F8-8184-D8B47F303678}) (Version: 1.0.14 - Roche) Hidden
ACCU-CHEK 360 Connection Manager (HKLM-x32\...\InstallShield_{33C351FC-D928-47F8-8184-D8B47F303678}) (Version: 1.0.14 - Roche)
ACCU-CHEK 360° (HKLM-x32\...\{C05A5601-DC01-4348-AB02-CD334E8DEFE4}) (Version: 2.2.3 - Roche Diabetes Care) Hidden
ACCU-CHEK 360° (HKLM-x32\...\InstallShield_{C05A5601-DC01-4348-AB02-CD334E8DEFE4}) (Version: 2.2.3 - Roche Diabetes Care)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-1033-7760-BC15014EA700}) (Version: 25.001.20756 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601120}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
aioscnnr (HKLM-x32\...\{EF53BFAB-4C10-40DB-A82D-9B07111715C6}) (Version: 7.6.13.10 - Your Company Name) Hidden
Belarc Advisor 11.5a (HKLM-x32\...\Belarc Advisor) (Version: 11.5.1.0 - Belarc, Inc.)
Borland Data Engine (HKLM-x32\...\{3AF6EF15-5841-4FF8-A3FC-5B2400AB9145}) (Version: 5.2.0 - Roche Diagnostics)
center (HKLM-x32\...\{56BA241F-580C-43D2-8403-947241AAE633}) (Version: 7.8.0.0 - Eastman Kodak Company) Hidden
diasend® Uploader version 3.8.0_BuildR3i05 (HKLM\...\{59A10021-5C7B-4C63-BB15-FAA9C04F8B26}_is1) (Version: 3.8.0_BuildR3i05 - Diasend)
essentials (HKLM-x32\...\{BE94C681-68E2-4561-8ABC-8D2E799168B4}) (Version: 7.8.0.0 - Eastman Kodak Company) Hidden
GDR 4237 for SQL Server 2014 (KB4019091) (HKLM-x32\...\KB4019091) (Version: 12.1.4237.0 - Microsoft Corporation)
Google Earth Pro (HKLM\...\{3470AD08-85F2-4B1D-8487-FC4750732087}) (Version: 7.3.6.9796 - Google)
Intel Driver && Support Assistant (HKLM-x32\...\{CCDC49A6-B288-4623-AA1D-332D328A8FA8}) (Version: 24.1.13.10 - Intel) Hidden
Intel® Driver & Support Assistant (HKLM-x32\...\{64f50684-bac6-488b-9bab-93616f34d6ec}) (Version: 24.1.13.10 - Intel)
ITE CIR version 5.5.2.1 (HKLM\...\{BEC1AF3C-B37F-4C91-A677-17BD6DA6A382}_is1) (Version: 5.5.2.1 - ITE, Inc.)
Kodak AIO Printer (HKLM\...\{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}) (Version: 7.8.1.0 - Eastman Kodak Company) Hidden
KODAK AiO Software (HKLM-x32\...\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 7.9.1.1 - Eastman Kodak Company)
LenovoUsbDriver 1.1.33 (HKLM-x32\...\LenovoUsbDriver) (Version: 1.1.33 - Lenovo)
Lumia UEFI Blue Driver (HKLM-x32\...\{9E37C8B7-50A6-422A-96C1-7BC43F2242F4}) (Version: 1.1.7.1439 - Nokia)
Macrium Reflect Free (HKLM\...\{A302C59F-C733-4DA0-9611-1286A9051D15}) (Version: 8.0.7783 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free (HKLM\...\MacriumReflect) (Version: v8.0.7783 - Paramount Software (UK) Ltd.)
Malwarebytes version 4.6.17.334 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.17.334 - Malwarebytes)
MediaTek SP Driver version 5.16.32.04 (HKLM\...\MediaTek SP Driver_is1) (Version: 5.16.32.04 - MediaTek.Inc.)
Microsoft .NET Core Host - 3.1.32 (x64) (HKLM\...\{8A8E3A04-83BC-4CDE-9259-893B666C1AB1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Host FX Resolver - 3.1.32 (x64) (HKLM\...\{ABC6B3C2-1A8D-4C5E-AC16-C2AE44F02743}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM\...\{A741B803-3F0E-4684-81EF-FC128D15A92C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM-x32\...\{784973c8-d618-4ac8-97ed-1fd52c5bdf2f}) (Version: 3.1.32.31915 - Microsoft Corporation)
Microsoft .NET Host - 6.0.36 (x64) (HKLM\...\{D6932D97-36F1-40B8-9CDC-CA8365B21000}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.20 (x64) (HKLM\...\{E8562B28-F84C-45AA-AE65-E31D1068377F}) (Version: 64.80.39230 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.36 (x64) (HKLM\...\{A9E32B25-994B-4856-A12B-0EBED3050410}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.20 (x64) (HKLM\...\{BB4BB73D-8784-40A3-9888-9BD29EC1B023}) (Version: 64.80.39230 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.36 (x64) (HKLM\...\{C912E33F-956A-4921-9F55-CC11AE8F09AF}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.20 (x64) (HKLM\...\{402EB961-5AED-472A-B785-B5AE9EF71286}) (Version: 64.80.39230 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 141.0.3537.57 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 141.0.3537.57 - Microsoft Corporation) Hidden
Microsoft ODBC Driver 11 for SQL Server (HKLM\...\{BE00C353-3529-4C31-AED2-AE3598D2CD2B}) (Version: 12.1.4237.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2019 - en-us (HKLM\...\ProPlus2019Volume - en-us) (Version: 16.0.12527.20482 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2603899380-3263017511-4129809722-1004\...\OneDriveSetup.exe) (Version: 22.131.0619.0001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2603899380-3263017511-4129809722-1007\...\OneDriveSetup.exe) (Version: 23.158.0730.0001 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files (HKLM-x32\...\{8F72E2D4-1E48-4534-8DB8-1E8E012899C6}) (Version: 10.3.5500.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2014 (HKLM-x32\...\Microsoft SQL Server SQLServer2014) (Version: - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{98E90D2B-FDEA-4858-97A2-3E5A15FC8E18}) (Version: 12.1.4100.1 - Microsoft Corporation)
Microsoft SQL Server 2014 RsFx Driver (HKLM-x32\...\{DDA4621B-896C-42F2-88C3-DACE4C44C2B3}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
Microsoft SQL Server 2014 Setup (English) (HKLM-x32\...\{D8BECB50-B81E-4B38-8264-CFE01DBE4FC9}) (Version: 12.1.4237.0 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{FF7DDA05-6EA7-4C01-B44A-3E57F8B9B97B}) (Version: 12.1.4100.1 - Microsoft Corporation)
Microsoft Support and Recovery Assistant (HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\fcede28c48c3b3fd) (Version: 17.0.5555.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{E3F613C1-105F-4717-BFE7-007729A95D67}) (Version: 12.1.4100.1 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visio Professional 2019 - en-us (HKLM\...\VisioPro2019Retail - en-us) (Version: 16.0.12527.20482 - Microsoft Corporation)
Microsoft Visio Viewer 2013 (HKLM\...\{95150000-0052-0409-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (HKLM-x32\...\{6C772996-BFF3-3C8C-860B-B3D48FF05D65}) (Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (HKLM-x32\...\{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}) (Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.32.31332 (HKLM-x32\...\{3746f21b-c990-4045-bb33-1cf98cff7a68}) (Version: 14.32.31332.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.32.31332 (HKLM-x32\...\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}) (Version: 14.32.31332.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332 (HKLM\...\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332 (HKLM\...\{3407B900-37F5-4CC2-B612-5CD5D580A163}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.32.31332 (HKLM-x32\...\{8972AC25-452E-4FFE-945A-EB9E28C20322}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.32.31332 (HKLM-x32\...\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{C931A1C6-A7BF-3737-874A-818881A37E1B}) (Version: 10.0.60915 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.60910 - Microsoft Corporation)
Microsoft VSS Writer for SQL Server 2014 (HKLM\...\{366CD715-2FF4-40B4-A8B4-A05E5D21A945}) (Version: 12.1.4100.1 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 6.0.36 (x64) (HKLM\...\{61D4736B-3325-4D4A-BD41-8BD206C6A86E}) (Version: 48.144.23186 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.36 (x64) (HKLM-x32\...\{0532b8f2-12d7-43de-95fc-7b87006758a8}) (Version: 6.0.36.34217 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 8.0.20 (x64) (HKLM\...\{D330A645-92DF-4389-8324-B82FE3561498}) (Version: 64.80.39251 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.20 (x64) (HKLM-x32\...\{e033dc24-62c0-4f2c-928e-99122efab19d}) (Version: 8.0.20.35221 - Microsoft Corporation)
Microsoft_VC100_CRT_SP1_x64 (HKLM\...\{680EDA59-9266-44B4-949E-0C24F65DFF82}) (Version: 10.0.40219.1 - Nokia) Hidden
Microsoft_VC100_CRT_SP1_x86 (HKLM-x32\...\{E3B64CC5-C011-40C0-92BC-7316CD5E5688}) (Version: 10.0.40219.1 - Nokia) Hidden
Mozilla Firefox (x64 en-GB) (HKLM\...\Mozilla Firefox 120.0.1 (x64 en-GB)) (Version: 120.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 102.12.0 - Mozilla)
Mozilla Thunderbird (x64 en-GB) (HKLM\...\Mozilla Thunderbird 115.5.2 (x64 en-GB)) (Version: 115.5.2 - Mozilla)
MSVC80_x64_v2 (HKLM\...\{4D668D4F-FAA2-4726-834C-31F4614F312E}) (Version: 1.0.3.0 - Nokia) Hidden
MSVC80_x86_v2 (HKLM-x32\...\{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}) (Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (HKLM\...\{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}) (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (HKLM-x32\...\{AF111648-99A1-453E-81DD-80DBBF6DAD0D}) (Version: 1.0.1.2 - Nokia) Hidden
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 2.2 - F.J. Wechselberger)
Nero BackItUp (HKLM-x32\...\{EA03E7E5-6757-4A9A-9B36-C0022BE752D2}) (Version: 18.1.1134 - Nero AG) Hidden
Nero BackItUp 2017 Essentials (HKLM-x32\...\{BE491A0E-96C6-41AB-9BCB-5A34794899A2}) (Version: 18.0.03200 - Nero AG)
Nero ControlCenter (HKLM-x32\...\{ABC88553-8770-4B97-B43E-5A90647A5B63}) (Version: 11.4.3033 - Nero AG) Hidden
Nero Core Components (HKLM-x32\...\{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}) (Version: 11.8.1064 - Nero AG) Hidden
Nero Info (HKLM-x32\...\{F030BFE8-8476-4C08-A553-233DE80A2BE1}) (Version: 21.0.3001 - Nero AG)
Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 21.0.1014 - Nero AG) Hidden
NIUBI Partition Editor Free Edition V10.2.0 (HKLM-x32\...\NIUBISoft-NPE) (Version: V10.2.0 - NIUBI Technology Co., Ltd.)
ocr (HKLM-x32\...\{BFBCF96F-7361-486A-965C-54B17AC35421}) (Version: 6.2.3.50 - Eastman Kodak Company) Hidden
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12527.20482 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12527.20482 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.12527.20482 - Microsoft Corporation) Hidden
PL-2303 USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.3.0 - Prolific Technology INC)
PowerToys (Preview) (HKLM\...\{6E97D19B-84B5-47DF-A03A-0EE9637A8498}) (Version: 0.60.1 - Microsoft Corporation) Hidden
PowerToys (Preview) x64 (HKLM-x32\...\{2b34ef9c-2147-46a9-8bf1-1a0edd1c5a51}) (Version: 0.60.1 - Microsoft Corporation)
PreReq (HKLM-x32\...\{DA5BDB2A-12F0-4343-8351-21AAEB293990}) (Version: 6.2.4.0 - Eastman Kodak Company) Hidden
Rescue and Smart Assistant (HKLM-x32\...\Rescue and Smart Assistant) (Version: 6.4.2.13 - Lenovo)
Samsung AllShare (HKLM-x32\...\{DF47ACA3-7C78-4C08-8007-AC682563C9F1}) (Version: 2.1.0.12031_10 - Samsung Electronics Co., Ltd.) Hidden
Samsung AllShare (HKLM-x32\...\InstallShield_{DF47ACA3-7C78-4C08-8007-AC682563C9F1}) (Version: 2.1.0.12031_10 - Samsung Electronics Co., Ltd.)
Seraph Secure (HKLM\...\SeraphSecure) (Version: - Seraph Secure Inc.)
Service Pack 1 for SQL Server 2014 (KB3058865) (HKLM-x32\...\KB3058865) (Version: 12.1.4100.1 - Microsoft Corporation)
Smart Connect (HKLM\...\ReadyFor) (Version: 8.0.0.002.002 - © Motorola)
Smart View (HKLM-x32\...\{1800D8A5-F7B2-4C20-868E-1CF55CBBDF21}) (Version: 1.0.0.0 - Samsung )
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
SQL Server 2014 Common Files (HKLM-x32\...\{BFB3B874-8033-4F5E-BE47-0AED2541E57C}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server 2014 Common Files (HKLM-x32\...\{F78A23CD-E9A0-46E3-88E2-CF2CC93AE7BA}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Services (HKLM-x32\...\{71E418D7-C0C5-455A-A248-1A3C3839EEEF}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Services (HKLM-x32\...\{A1ED7C85-A91A-4788-B0CC-86FA19C042E8}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Shared (HKLM-x32\...\{1D1E4532-6A52-471B-B006-EA04A2BBFCE9}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server 2014 Database Engine Shared (HKLM-x32\...\{AA2D8197-6678-4242-9222-3A03993E89B3}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
SQL Server Browser for SQL Server 2014 (HKLM-x32\...\{3204DE95-97D2-4261-A286-98A262E171D4}) (Version: 12.1.4100.1 - Microsoft Corporation)
Sql Server Customer Experience Improvement Program (HKLM-x32\...\{894F30EB-3F0A-422F-9225-EB00DC9414EA}) (Version: 12.1.4100.1 - Microsoft Corporation) Hidden
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.13.1 - Tweaking.com)
Type Label Fonts (HKLM-x32\...\{799BF338-BC01-4F7A-BC79-A67B75E772CB}) (Version: 1.1.0.1 - Microsoft)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
Verbatim GREEN BUTTON 2.01 (HKLM-x32\...\Verbatim GREEN BUTTON_is1) (Version: - Verbatim)
Verbatim Hard Drive Formatter (HKLM-x32\...\Verbatim Hard Drive Formatter_is1) (Version: - Verbatim)
Verbatim Hard Drive Info 1.04 (HKLM-x32\...\Verbatim Hard Drive Info_is1) (Version: - Verbatim)
VirusTotal Uploader 2.2 (HKLM-x32\...\VTUploader) (Version: - )
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.12 - VideoLAN)
Vodafone Mobile Broadband Lite (HKLM-x32\...\{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}) (Version: 10.2.102.30707 - Vodafone)
Windows Mobile Device Updater Component (HKLM\...\{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Windows PC Health Check (HKLM\...\{0B4830D0-7D09-4230-AACD-D5FD555FB76F}) (Version: 3.9.2402.14001 - Microsoft Corporation)
WinRAR 6.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.00.0 - win.rar GmbH)
Zune (HKLM\...\{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
Zune Language Pack (CHS) (HKLM\...\{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHT) (HKLM\...\{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CSY) (HKLM\...\{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DAN) (HKLM\...\{8B112338-2B08-4851-AF84-E7CAD74CEB32}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DEU) (HKLM\...\{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ELL) (HKLM\...\{3589A659-F732-4E65-A89A-5438C332E59D}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ESP) (HKLM\...\{6B33492E-FBBC-4EC3-8738-09E16E395A10}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FIN) (HKLM\...\{B4870774-5F3A-46D9-9DFE-06FB5599E26B}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FRA) (HKLM\...\{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (HUN) (HKLM\...\{C6BE19C6-B102-4038-B2A6-1C313872DBB4}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (IND) (HKLM\...\{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ITA) (HKLM\...\{C5D37FFA-7483-410B-982B-91E93FD3B7DA}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (JPN) (HKLM\...\{D8A781C9-3892-4E2E-9320-480CF896CFBB}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (KOR) (HKLM\...\{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (MSL) (HKLM\...\{76BA306B-2AA0-47C0-AB6B-F313AB56C136}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NLD) (HKLM\...\{6740BCB0-5863-47F4-80F4-44F394DE4FE2}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NOR) (HKLM\...\{5DEFD397-4012-46C3-B6DA-E8013E660772}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PLK) (HKLM\...\{8960A0A1-BB5A-479E-92CF-65AB9D684B43}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTB) (HKLM\...\{07EEE598-5F21-4B57-B40B-46592625B3D9}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTG) (HKLM\...\{5C93E291-A1CC-4E51-85C6-E194209FCDB4}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (RUS) (HKLM\...\{57C51D56-B287-4C11-9192-EC3C46EF76A4}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (SVE) (HKLM\...\{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Packages:
=========
AdGuard AdBlocker -> C:\Program Files\WindowsApps\Adguard.AdguardAdBlocker_3.3.8.0_neutral__m055xr0c82818 [2025-10-06] (Performix)
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2025-10-05] ()
APKPure.com -> C:\Program Files\WindowsApps\apkpure.com-D523D125_1.0.0.1_neutral__9y56rtyprpvr6 [2025-10-06] (apkpure.com)
DuckDuckGo -> C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94 [2025-10-06] (DuckDuckGo) [Startup Task]
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_2.8.1.0_x64__v10z8vjag6ke6 [2025-10-05] (HP Inc.)
HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.47.41.0_x64__v10z8vjag6ke6 [2025-10-05] (HP Inc.)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa [2025-10-06] (Apple Inc.) [Startup Task]
Microsoft Advertising SDK for JavaScript -> C:\Program Files\WindowsApps\Microsoft.Advertising.JavaScript_10.1805.2.0_x64__8wekyb3d8bbwe [2025-10-05] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for JavaScript -> C:\Program Files\WindowsApps\Microsoft.Advertising.JavaScript_10.1805.2.0_x86__8wekyb3d8bbwe [2025-10-05] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2025-10-05] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2025-10-05] (Microsoft Corporation) [MS Ad]
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2025-10-06] (Microsoft Corporation)
ShowKeyPlus -> C:\Program Files\WindowsApps\617231644CE58.ShowKeyPlus_1.1.18.0_x64__arc7y9yj6c41t [2025-10-06] (Superfly Inc.)
Vodafone Mobile Broadband -> C:\Program Files\WindowsApps\VodafoneGroupServices.VodafoneMobileBroadband_2.10.46.0_x64__cx08jceyq9bcp [2025-10-06] (Vodafone Group Services)
WSB Manager -> C:\Program Files\WindowsApps\30069NiaTomonaka.WSBManager_1.2.16.0_x64__d07890f6kbdbp [2025-10-05] (Nia Tomonaka)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{13074435-7693-4592-2533-000000000000}\localserver32 -> C:\Program Files\Lenovo\Ready For Assistant\SmartConnect.exe (Lenovo -> )
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{36B27788-A8BB-4698-A756-DF9F11F64F84}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.SvgThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{3f5d0051-61b8-0f45-6166-996cfb4f914f}\localserver32 -> C:\Program Files\PowerToys\modules\launcher\PowerToys.PowerLauncher.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{45769bcc-e8fd-42d0-947e-02beef77a1f5}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.MarkdownPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{8BC8AFC2-4E7C-4695-818E-8C1FFDCEA2AF}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.StlThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{afbd5a44-2520-4ae0-9224-6cfce8fe4400}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.MonacoPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{BFEE99B4-B74D-4348-BCA5-E757029647FF}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.GcodeThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{ddee2b8a-6807-48a6-bb20-2338174ff779}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.SvgPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2603899380-3263017511-4129809722-1001_Classes\CLSID\{ec52dea8-7c9f-4130-a77b-1737d0418507}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.GcodePreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2025-09-08] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1-x32: [MyPhoneExplorer] -> {A372C6DF-7A85-41B1-B3B0-D1E24073DCBF} => C:\Program Files (x86)\MyPhoneExplorer\DLL\ShellMgr.dll [2010-03-30] (F.J. Wechselberger) [File not signed]
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-07-22] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers3: [PowerRenameExt] -> {0440049F-D1DC-4E46-B27B-98393D79486B} => C:\Program Files\PowerToys\modules\PowerRename\PowerToys.PowerRenameExt.dll [2022-07-13] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\WINDOWS\system32\igfxpph.dll [2017-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-07-22] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\KAA\Desktop\toggleNIC.bat - Shortcut.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /c C:\Users\KAA\Desktop\toggleNIC.bat
ShortcutWithArgument: C:\Users\KAA\Desktop\ToggleNic\toggleNIC.bat - Shortcut.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /c C:\Users\KAA\Desktop\toggleNIC.bat
ShortcutWithArgument: C:\Users\KAA\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\GWAPImplicitAppShortcuts\362fff581c3a7425\uBlock Origin.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=odfafepnkmbhccpbejgmiehpchacaeak --app-url --app-launch-source=4
ShortcutWithArgument: C:\Users\KAA\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\NIC\toggleNIC.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /c C:\Users\KAA\Desktop\toggleNIC.bat
==================== Loaded Modules (Whitelisted) =============
2025-08-26 20:17 - 2025-06-03 04:34 - 005426176 _____ () [File not signed] C:\Program Files\Seraph Secure\av_libGLESv2.dll
2025-05-28 14:07 - 2024-09-11 21:05 - 001759232 _____ () [File not signed] C:\Program Files\Seraph Secure\e_sqlite3.DLL
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\Software\Classes\.reg: => <==== ATTENTION
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\Software\Classes\.bat: => <==== ATTENTION
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\Software\Classes\.cmd: => <==== ATTENTION
==================== Internet Explorer (Whitelisted) =============
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2023-07-25] (HP Inc. -> HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2023-07-25] (HP Inc. -> HP Inc.)
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2022-06-15] (Belarc, Inc. -> Belarc, Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-03-19 05:49 - 2025-10-08 22:16 - 000014427 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.0 beyondtrust.com www.beyondtrust.com
0.0.0.0 tcers.bomgar.com www.tcers.bomgar.com
0.0.0.0 helpwire.app www.helpwire.app
0.0.0.0 radmin.com www.radmin.com
0.0.0.0 download.radmin.com www.download.radmin.com
0.0.0.0 helpdesk.radmin.com www.helpdesk.radmin.com
0.0.0.0 radmin.download.it www.radmin.download.it
0.0.0.0 alpemix.com www.alpemix.com
0.0.0.0 alpemix.fileplanet.com www.alpemix.fileplanet.com
0.0.0.0 alpemix.en.softonic.com www.alpemix.en.softonic.com
0.0.0.0 alpemix.download.it www.alpemix.download.it
0.0.0.0 online.thinfinity.com www.online.thinfinity.com
0.0.0.0 screenleap.com www.screenleap.com
0.0.0.0 deskin.io www.deskin.io
0.0.0.0 dl.deskin.io www.dl.deskin.io
0.0.0.0 zulertech.com www.zulertech.com
0.0.0.0 xmpp.yuuguu.com www.xmpp.yuuguu.com
0.0.0.0 easyvista.com www.easyvista.com
0.0.0.0 pulseway.com www.pulseway.com
0.0.0.0 ultraviewer.net www.ultraviewer.net
0.0.0.0 dl2.ultraviewer.net www.dl2.ultraviewer.net
0.0.0.0 ultraviewer.fileplanet.com www.ultraviewer.fileplanet.com
0.0.0.0 ultraviewer.en.softonic.com www.ultraviewer.en.softonic.com
0.0.0.0 ultraviewer.download.it www.ultraviewer.download.it
0.0.0.0 fixme.it www.fixme.it
0.0.0.0 techinline.net www.techinline.net
0.0.0.0 techinline.com www.techinline.com
0.0.0.0 tsplus.net www.tsplus.net
0.0.0.0 tsplus.me www.tsplus.me
0.0.0.0 terminalserviceplus.com www.terminalserviceplus.com
There are 235 more lines.
2020-03-26 10:45 - 2025-10-08 18:21 - 000001076 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
172.28.153.251 8b36ffec-f862-4b4c-a91b-0dfde75633ed.mshome.net # 2025 10 2 14 10 34 24 959
172.19.138.30 dd33c185-9c2c-4997-8454-3faf0a5e0fd2.mshome.net # 2025 10 3 15 17 21 22 983
172.19.128.1 TouchSmart.mshome.net # 2030 10 1 7 17 21 22 983
24 10 1 7 22 29 38 266
172.23.160.1 TouchSmart.mshome.net # 2029 10 2 2 11 50 14 365
350
978
192.168.137.111 WIN10SE.mshome.net # 2021 2 5 26 16 58 24 674
5 26 16 50 38 804
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: 192.168.1.1
Windows Firewall is enabled.
Network Binding:
=============
Wi-Fi: 802.11n Wireless LAN Card -> netr28x.sys
vEthernet (Ethernet): Hyper-V Virtual Ethernet Adapter -> VmsProxyHNic.sys
vEthernet (Wi-Fi): Hyper-V Virtual Ethernet Adapter #2 -> VmsProxyHNic.sys
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys
vEthernet (Default Switch): Hyper-V Virtual Ethernet Adapter #3 -> VmsProxyHNic.sys
vms_vsf: Hyper-V Virtual Switch Extension Filter
ms_vfpext: Microsoft Azure VFP Switch Extension
ms_irda: IrDA Protocol
vms_vsp: Hyper-V Virtual Switch Extension Protocol
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
HKU\S-1-5-21-2603899380-3263017511-4129809722-1004\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2603899380-3263017511-4129809722-1007\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\StartupFolder: => "ACCU-CHEK 360 Connection Manager.lnk"
HKLM\...\StartupApproved\StartupFolder: => "ACCU-CHEK 360 Auto-Detect.lnk"
HKLM\...\StartupApproved\StartupFolder: => "SPDriverInstall.lnk"
HKLM\...\StartupApproved\Run: => "BeatsOSDApp"
HKLM\...\StartupApproved\Run: => "SysTrayApp"
HKLM\...\StartupApproved\Run: => "Reflect UI"
HKLM\...\StartupApproved\Run: => "Zune Launcher"
HKLM\...\StartupApproved\Run32: => "Conime"
HKLM\...\StartupApproved\Run32: => "EKStatusMonitor"
HKLM\...\StartupApproved\Run32: => "MobileBroadband"
HKLM\...\StartupApproved\Run32: => "AllShareAgent"
HKLM\...\StartupApproved\Run32: => "Intel Driver & Support Assistant"
HKLM\...\StartupApproved\Run32: => "Nero BackItUp"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\StartupFolder: => "NextPVR Tray.lnk"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\Run: => "Skype for Desktop"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\Run: => "NokiaSuite.exe"
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{886A01F6-70B4-42E1-8782-CC81971A588A}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{9E01FF9C-8841-4C2E-B39D-E615422C7A01}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{6CD4F0A9-DB89-4C58-A9E1-8D88A3FA5F8A}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{43C372E2-0CB5-41FD-9B5C-30399861979C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{4843E8DE-68BC-4789-B930-7FB449CF95B0}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{CFD184C4-892B-4D29-931A-618A15DABF94}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{F1DFAA53-690E-4D9F-93A2-C9EE21B1FD6D}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{E0978648-BA00-4D1D-A561-EBD3FC330924}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
FirewallRules: [{B668332E-37F3-47DF-9133-D26986776E29}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.WebView.exe (Duck Duck Go, Inc. -> DuckDuckGo)
FirewallRules: [{C92E24B3-0260-4E65-8083-3C4D06D90999}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.WebView.exe (Duck Duck Go, Inc. -> DuckDuckGo)
FirewallRules: [{973BD54E-3CBB-4A6E-83A5-0B94E61D7B8C}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe (Duck Duck Go, Inc. -> Microsoft Corporation)
FirewallRules: [{35D8B1C6-C486-4F78-89B7-BB574DD0B79E}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe (Duck Duck Go, Inc. -> Microsoft Corporation)
FirewallRules: [{3E80437B-C14A-4178-9535-818F5075EE2E}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.2\ABService.exe => No File
FirewallRules: [{E31B16B1-67A7-431D-B1D9-0AC32185B50A}] => (Allow) C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.2\ABService.exe => No File
FirewallRules: [{86D4A437-29B8-4AE7-B185-1E9578BC1580}] => (Allow) C:\Program Files\Rescue and Smart Assistant\Rescue and Smart Assistant.exe (Lenovo -> )
FirewallRules: [{009CA745-3B8A-413F-9BAC-6CF5538C43D0}] => (Block) C:\Program Files\Lenovo\Ready For Assistant\vaultPlugin\VaultPlugin.exe (Lenovo -> )
FirewallRules: [{6271D7B8-7DA1-4FA7-A469-FB9430D3438D}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\vaultPlugin\VaultPlugin.exe (Lenovo -> )
FirewallRules: [{9E3A3271-A463-4F9B-8970-FC862296BE78}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\vaultPlugin\VaultPlugin.exe (Lenovo -> )
FirewallRules: [{DEB3BC3A-4951-40F8-A205-617806FBA494}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\vaultPlugin\VaultPlugin.exe (Lenovo -> )
FirewallRules: [{D7E8EB43-C08D-4B9C-B641-1EEB46C9A2A8}] => (Block) C:\Program Files\Lenovo\Ready For Assistant\SmartConnect.exe (Lenovo -> )
FirewallRules: [{3474955D-EF34-410C-B03E-F519E1BD87BE}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\SmartConnect.exe (Lenovo -> )
FirewallRules: [{BBA484BF-6DC9-4CCA-8033-B8E9B5A45B75}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\SmartConnect.exe (Lenovo -> )
FirewallRules: [{079F170C-D70C-46BA-AA61-56440B9EE4B2}] => (Allow) C:\Program Files\Lenovo\Ready For Assistant\SmartConnect.exe (Lenovo -> )
FirewallRules: [{F652E44C-3D0E-41A5-9FD9-21D206EB9951}] => (Allow) C:\Program Files\Software Fix\Software Fix.exe => No File
FirewallRules: [{7FB9D48B-18AF-4E60-B289-69E51B1C3804}] => (Allow) C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe (Franz Josef Wechselberger -> F.J. Wechselberger)
FirewallRules: [{97357207-5A98-44DC-8917-C095C3163287}] => (Allow) C:\Program Files\MiniTool ShadowMaker\AgentService.exe => No File
FirewallRules: [{AD585C84-014D-49D6-9CC8-0397D22868D4}] => (Allow) C:\Program Files\MiniTool ShadowMaker\AgentService.exe => No File
FirewallRules: [{86BEA19B-326B-4594-BFBC-3D7DF43EC21A}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.61.4.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{7F97224D-407C-4189-BBD9-6B88D6D4E8DA}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.61.4.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{62CE780A-9989-4B8E-82A9-0E3678511D43}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.59.0.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{DE4E660C-5EE0-432D-AF10-4E0617304135}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.59.0.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{08063108-02E7-48BF-B935-8A5E74A23A11}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.58.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{B6E7AA43-EA5E-41BA-B869-90606248561B}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.58.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{D84C9961-BA51-4F00-B91B-848049AA75BB}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.56.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{6DB79B5F-9158-45C1-8283-E56F521B4309}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.56.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{B3626921-6125-4F0F-8E44-90BC0966B471}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.55.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{55D912A7-C9CA-486C-8C36-8BED1A34B618}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.55.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{A13DA1E7-BDBD-4018-993A-F0E659493C5D}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.55.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{6B2E13B2-0039-4188-B835-961D1C5ACC12}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.55.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{8F936F7A-5957-48DC-A630-AE6019369C62}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.54.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{90997326-CDB1-4DC2-AC2E-77D2026DC08E}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.54.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{EC9660B2-C21C-49F2-9ADA-15A82AF92B8E}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.52.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{5C6938C5-67CF-46FD-AC42-7F898E70EFDC}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.52.1.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{88CF9801-D339-4E83-8C71-82F66482A613}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.51.0.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{3DCEE8AB-C74F-4BE9-87C7-F62078A6FC5F}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.51.0.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe => No File
FirewallRules: [{D08A53F5-E3D0-4E45-8EFA-546BA7F4D27B}] => (Allow) C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\NBService.exe (Nero AG -> Nero AG)
FirewallRules: [{B588AF5A-A6A7-4F1A-AC75-07E0173282AC}] => (Allow) C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\BackItUp.exe (Nero AG -> Nero AG)
FirewallRules: [{1E31A3FA-A289-485A-AAE1-80865122893A}] => (Allow) C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\BackItUp.exe (Nero AG -> Nero AG)
FirewallRules: [{140DBF7C-E8B9-48F0-B2A6-3DD1AE84ABEC}] => (Allow) C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\NBService.exe (Nero AG -> Nero AG)
FirewallRules: [{5B0A9C44-0CB4-42A1-BB4E-FAAE2F503EBA}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe => No File
FirewallRules: [{E1AD2252-A5A8-450E-AE05-41E2EFA8F04A}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe => No File
FirewallRules: [{2C922ACF-3F99-4392-95D9-2BCD23BEE879}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe => No File
FirewallRules: [{7BC72725-7F79-45B9-9603-32B8C747C8D7}] => (Block) C:\program files (x86)\smart view\smart view.exe () [File not signed]
FirewallRules: [{D1A65C36-A696-4FA4-908E-32D1FE9C460D}] => (Block) C:\program files (x86)\smart view\smart view.exe () [File not signed]
FirewallRules: [UDP Query User{CB2FF261-6A53-4202-8752-7FE40A4BABB9}C:\program files (x86)\smart view\smart view.exe] => (Allow) C:\program files (x86)\smart view\smart view.exe () [File not signed]
FirewallRules: [TCP Query User{AF53709C-FF36-4C25-8CB2-112C981876DE}C:\program files (x86)\smart view\smart view.exe] => (Allow) C:\program files (x86)\smart view\smart view.exe () [File not signed]
FirewallRules: [{C9B70DF6-3CB5-42AC-9DE3-6A0E1C192420}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{01DF0815-250E-4BEF-A399-C43432F6D46B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{9E6EFAB9-EFA3-4B1E-B67D-E4ECCBA59176}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{480C6602-A8F0-4CD4-AA2D-AB8069EA5E9D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.65.78.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{2130C4CF-C2A2-4FE4-B3A7-A5AB302241CC}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe => No File
FirewallRules: [{FF9E6208-AA67-40C9-80EB-C1EB7D26FC83}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe => No File
FirewallRules: [{668601FD-E65F-41FC-94CF-3ED3A63163F9}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe => No File
FirewallRules: [{AC25DE7E-D61E-4603-9F00-1346E03B1B26}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe => No File
FirewallRules: [{CCD09C67-EBA8-4A82-B589-CEC6C3E27E3D}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2D3A4FBF-5DE1-4A97-A7BF-97A46016F9C0}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C4335C1C-F560-4C48-833E-808099F9295D}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E84402DC-6AF0-4C16-B437-BBBA2E29F3F0}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E4BE0E4F-F1E3-438B-B270-E9C9E71BE0FB}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3BE62FBA-BF72-4F47-B021-5281AE20D930}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{43D22646-DE88-4C38-A39A-5DB2FFD65028}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{218D2E57-4EA3-4E6B-BD5F-8345C670E7D1}] => (Allow) C:\Program Files\Zune\ZuneNSS.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{845CA16E-C8D5-4B2B-BE9D-8CD653D7DA89}] => (Allow) C:\Program Files\Zune\Zune.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0BD8F30F-DCAD-4474-86A4-FDCC6B93CCE7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{51EAB827-B429-4974-8C03-F2409E415226}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{45310DD0-4C71-4E44-97CF-F5CB64BFAFA2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{7BD9DA36-8CE8-4CD8-8EA5-B9F1988EEE6D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.85.3409.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => No File
FirewallRules: [{214C460A-661C-4B90-A6CA-B479686DF495}] => (Allow) C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{5E327218-8772-4453-801C-08A2A92971B9}] => (Allow) C:\Program Files (x86)\Samsung\AllShare\AllShare.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{99380CE1-38C5-43A0-BFFC-E2CC49F76CDF}] => (Allow) C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{BB868CEE-01FF-4592-B35B-CCC1F946D402}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{098BB6F7-E17F-4BD6-A37F-9CCEF8F82DB3}] => (Allow) LPort=3306
FirewallRules: [{B1BB24CB-E0D7-469C-AE54-38133CF2EF05}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal\WatchDog.exe => No File
FirewallRules: [{370A7F56-5ADB-44EF-964C-85A7524C7D8E}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal\WatchDog.exe => No File
FirewallRules: [{1C784120-8051-4A35-AA73-24DC0CC0314B}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal\MediaPortal.exe => No File
FirewallRules: [{E9630ABA-D040-4481-BC1F-BBD9D749571F}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal\MediaPortal.exe => No File
FirewallRules: [{44DF51B8-F089-401A-9D63-375DA2213B9B}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\WatchDogService.exe => No File
FirewallRules: [{615168E9-4783-4DC5-B229-9E3D2A9F270B}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\WatchDogService.exe => No File
FirewallRules: [{EC3A0892-9E7B-4D0F-9D39-63E633915050}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\SetupTv.exe => No File
FirewallRules: [{DFA0E5AA-0065-4295-81DD-8BFE715B82DA}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\SetupTv.exe => No File
FirewallRules: [{398CD166-1060-4B6F-88A7-3D52285DDB28}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\TvService.exe => No File
FirewallRules: [{DC46A6BD-8E3B-4294-ABB2-E406BE625F60}] => (Allow) C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\TvService.exe => No File
FirewallRules: [UDP Query User{E175FCA8-DC9E-4B1C-8CBE-B238E931CAFB}C:\program files (x86)\team mediaportal\mp2-client\mp2-client.exe] => (Block) C:\program files (x86)\team mediaportal\mp2-client\mp2-client.exe => No File
FirewallRules: [TCP Query User{79846B4A-3AC5-42D8-BF6D-568F6F9C28F1}C:\program files (x86)\team mediaportal\mp2-client\mp2-client.exe] => (Block) C:\program files (x86)\team mediaportal\mp2-client\mp2-client.exe => No File
FirewallRules: [UDP Query User{04CBBDC5-5BE7-4CFB-8E6B-9D6A47B695F9}C:\program files (x86)\team mediaportal\mp2-client\mp2-client (x64).exe] => (Block) C:\program files (x86)\team mediaportal\mp2-client\mp2-client (x64).exe => No File
FirewallRules: [TCP Query User{A9965697-E1D3-47B1-9B01-D5BB85161895}C:\program files (x86)\team mediaportal\mp2-client\mp2-client (x64).exe] => (Block) C:\program files (x86)\team mediaportal\mp2-client\mp2-client (x64).exe => No File
FirewallRules: [{6BC82F9B-CE03-4886-B2D6-0777F0C60FD0}] => (Block) C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe => No File
FirewallRules: [{E41AFD03-892C-49D8-A179-F3B04DD31ACC}] => (Block) C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe => No File
FirewallRules: [UDP Query User{C5565302-ABB4-4F46-BF94-1638E4A8E5CE}C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe] => (Allow) C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe => No File
FirewallRules: [TCP Query User{CCBBC2FB-8853-4216-83B7-52F442D8AF48}C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe] => (Allow) C:\program files (x86)\team mediaportal\mp2-server\plugins\slimtv.service3\setuptv.exe => No File
FirewallRules: [UDP Query User{586F8BE7-62D0-42FA-A7D1-4380A97F0A56}C:\program files (x86)\team mediaportal\mp2-servicemonitor\mp2-servicemonitor.exe] => (Allow) C:\program files (x86)\team mediaportal\mp2-servicemonitor\mp2-servicemonitor.exe => No File
FirewallRules: [TCP Query User{061659BD-82EA-4666-87D2-978089316F1D}C:\program files (x86)\team mediaportal\mp2-servicemonitor\mp2-servicemonitor.exe] => (Allow) C:\program files (x86)\team mediaportal\mp2-servicemonitor\mp2-servicemonitor.exe => No File
FirewallRules: [{B1D2B83A-C1F1-4883-B4DF-8F2549040318}] => (Allow) C:\Program Files\NextPVR\Client\NextPVR.exe => No File
FirewallRules: [{F3D35A4B-66C3-4F3A-A14E-E365E8EA9230}] => (Allow) C:\Program Files\NextPVR\DeviceHostWindows.exe => No File
FirewallRules: [{C0967411-F155-489F-9AB5-B78774838455}] => (Allow) C:\Program Files\NextPVR\NextPVRServer.exe => No File
FirewallRules: [{34DAF440-1FC9-4B39-B5A5-40D45940D180}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{35ADA41B-E70D-4097-A347-DE767980FEBB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4F1E3D5F-7D9A-4414-AD9E-94451F4E6DD2}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4EA02950-EB1D-478A-9F96-809B5A7DB592}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{67B336D8-0225-4B08-8B47-EF58A0DA9740}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{04990CE4-8E74-4D8F-9E11-A9120112A6C7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe => No File
FirewallRules: [{BF7543C7-F1ED-4719-B85C-50766E7E9ECB}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe => No File
FirewallRules: [{246A763E-C6CD-4F8D-9E10-96484598C5C9}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{810F8789-C83A-4DB2-8898-DC7B1A6DA423}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{A5DAE191-7958-462A-B053-2ADE0292F110}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{49E53708-8A46-4225-BA09-B54B4CB97D23}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{B060B245-D243-42C4-BDE5-5C99FBD68BD6}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company -> Eastman Kodak Company)
FirewallRules: [{AE9817B1-D68C-4BF6-9239-BE2E58D6E48D}] => (Allow) LPort=5353
FirewallRules: [{E2139D66-6BAC-49D3-AE61-C04927376151}] => (Allow) LPort=9322
FirewallRules: [{B35AC413-CBB3-4E2B-A7FD-5D94A5246B08}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.131.5.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe (Duck Duck Go, Inc. -> Microsoft Corporation)
FirewallRules: [{52A69B47-2B8C-47A0-8291-5F4E327BE8BA}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.131.5.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe (Duck Duck Go, Inc. -> Microsoft Corporation)
FirewallRules: [{C3022035-1F38-4BB0-981C-3A454BEF75FB}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.131.5.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.WebView.exe (Duck Duck Go, Inc. -> DuckDuckGo)
FirewallRules: [{51EBD1BF-29A1-4B33-BE9A-50079061393F}] => (Allow) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.131.5.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.WebView.exe (Duck Duck Go, Inc. -> DuckDuckGo)
==================== Restore Points =========================
06-10-2025 08:10:39 Windows Modules Installer
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (10/08/2025 08:09:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x1dd4
Faulting application start time: 0x01dc38870cac965c
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: 896ed98f-347d-46a1-83d0-a93c317b53f2
Faulting package full name:
Faulting package-relative application ID:
Error: (10/08/2025 06:18:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x2388
Faulting application start time: 0x01dc38778c3cc790
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: ae649420-9363-4dc2-8a74-83b2c5d78b55
Faulting package full name:
Faulting package-relative application ID:
Error: (10/07/2025 04:23:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x23e4
Faulting application start time: 0x01dc379e50404892
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: b73a93e3-f630-4804-917a-b0f6d39cef41
Faulting package full name:
Faulting package-relative application ID:
Error: (10/07/2025 04:23:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0xb9c
Faulting application start time: 0x01dc379de3a618a0
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: 83aa6845-cdce-4fbd-9513-b83cd1ad487e
Faulting package full name:
Faulting package-relative application ID:
Error: (10/07/2025 03:54:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x1580
Faulting application start time: 0x01dc379a337206fc
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: 28a18129-1ec6-4cc2-9b27-73c09a647080
Faulting package full name:
Faulting package-relative application ID:
Error: (10/07/2025 03:34:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x25c0
Faulting application start time: 0x01dc379781015a87
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: 08c35dea-24be-40e3-aa66-4185d91a5f94
Faulting package full name:
Faulting package-relative application ID:
Error: (10/07/2025 03:26:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x221c
Faulting application start time: 0x01dc37957172426c
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: 83232124-9a2f-4499-8b24-06b016cb3449
Faulting package full name:
Faulting package-relative application ID:
Error: (10/07/2025 03:06:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Faulting module name: NeroInfo.exe, version: 21.0.3.1, time stamp: 0x5fb1dbf9
Exception code: 0xc0000005
Fault offset: 0x00031fe3
Faulting process ID: 0x1f98
Faulting application start time: 0x01dc37938ed50daf
Faulting application path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Faulting module path: C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe
Report ID: d30d2ed7-72a0-4f8c-8730-12e124db9929
Faulting package full name:
Faulting package-relative application ID:
System errors:
=============
Error: (10/08/2025 06:14:39 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 17:19:33 on 08/10/2025 was unexpected.
Error: (10/07/2025 03:29:20 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume \\?\Volume{3d2441ba-8cd3-4f73-b5c7-2654bbb98741}.
The exact nature of the corruption is unknown. The file system structures need to be scanned online.
Error: (10/07/2025 03:29:11 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume \\?\Volume{e5157268-8564-11f0-a368-fe36febd0469}.
The exact nature of the corruption is unknown. The file system structures need to be scanned online.
Error: (10/07/2025 03:29:11 PM) (Source: Microsoft-Windows-Ntfs) (EventID: 98) (User: NT AUTHORITY)
Description: \\?\Volume{e5157268-8564-11f0-a368-fe36febd0469}\Device\HarddiskVolume13
Error: (10/07/2025 03:29:10 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume \\?\Volume{e5157268-8564-11f0-a368-fe36febd0469}.
The exact nature of the corruption is unknown. The file system structures need to be scanned and fixed offline.
Error: (10/07/2025 03:29:10 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume \\?\Volume{0a6bfd05-1cd1-445d-bedb-e9f0ec4b53f7}.
The exact nature of the corruption is unknown. The file system structures need to be scanned online.
Error: (10/07/2025 11:05:31 AM) (Source: Microsoft-Windows-FilterManager) (EventID: 3) (User: NT AUTHORITY)
Description: Filter Manager failed to attach to volume '\Device\Harddisk1\DR1'. This volume will be unavailable for filtering until a reboot. The final status was 0xc03a001c.
Error: (10/07/2025 12:06:43 AM) (Source: cdrom) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\CdRom0.
Windows Defender:
================
Date: 2025-10-08 21:58:21
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
Date: 2025-10-08 21:47:39
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
Date: 2025-10-08 21:40:15
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
Date: 2025-10-08 21:33:53
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
Date: 2025-10-08 21:21:58
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Stop Reason: RPC connection rundown
Event[0]:
Date: 2025-10-07 11:05:56
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
Security intelligence Attempted: Current
Error Code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, then try to start the program again. For information on installing updates, see Help and Support.
Security intelligence Version: 1.437.372.0;1.437.372.0
Engine Version: 1.1.25080.5
Date: 2025-10-06 15:33:49
Description:
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
Date: 2025-10-06 14:36:01
Description:
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
Date: 2025-10-06 13:25:37
Description:
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
Date: 2025-10-06 12:35:06
Description:
Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
CodeIntegrity:
===============
Date: 2025-10-06 11:17:24
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\aepic.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
BIOS: AMI 7.08 11/30/2011
Motherboard: PEGATRON CORPORATION 2AC3
Processor: Intel® Core i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 72%
Total physical RAM: 8096.33 MB
Available physical RAM: 2238.36 MB
Total Virtual: 9632.33 MB
Available Virtual: 3657.54 MB
==================== Drives ================================
Drive c: (Win10 Pro) (Fixed) (Total:349.9 GB) (Free:140.97 GB) (Model: ST31000524AS) NTFS
Drive g: (Win11 Pro) (Fixed) (Total:194.93 GB) (Free:139.03 GB) (Model: ST31000524AS) NTFS
\\?\Volume{e5157268-8564-11f0-a368-fe36febd0469}\ (System Reserved) (Fixed) (Total:0.57 GB) (Free:0.14 GB) NTFS
\\?\Volume{0a6bfd05-1cd1-445d-bedb-e9f0ec4b53f7}\ () (Fixed) (Total:0.63 GB) (Free:0.14 GB) NTFS
\\?\Volume{3d2441ba-8cd3-4f73-b5c7-2654bbb98741}\ () (Fixed) (Total:0.63 GB) (Free:0.11 GB) NTFS
\\?\Volume{629458e4-0000-0000-0000-010000000000}\ (PortableBaseLayer) (Fixed) (Total:8 GB) (Free:7.5 GB) NTFS
\\?\Volume{e515726a-8564-11f0-a368-fe36febd0469}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: BB2C8144)
Partition: GPT.
==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 8 GB) (Disk ID: 629458E4)
Partition 1: (Not Active) - (Size=8 GB) - (Type=07 NTFS)
==================== End of Addition.txt =======================