Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2021 Ran by [removed] (24-08-2021 09:55:57) Running from C:\Users\[removed]\Desktop Windows 10 Pro Version 21H1 19043.1165 (X64) (2021-08-10 12:10:22) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-942201848-496926140-1053970402-500 - Administrator - Disabled) Annie (S-1-5-21-942201848-496926140-1053970402-1003 - Administrator - Enabled) => C:\Users\Annie DefaultAccount (S-1-5-21-942201848-496926140-1053970402-503 - Limited - Disabled) Guest (S-1-5-21-942201848-496926140-1053970402-501 - Limited - Disabled) James (S-1-5-21-942201848-496926140-1053970402-1001 - Administrator - Enabled) => C:\Users\James John (S-1-5-21-942201848-496926140-1053970402-1002 - Limited - Enabled) => C:\Users\John WDAGUtilityAccount (S-1-5-21-942201848-496926140-1053970402-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ESET Security (Enabled - Up to date) {89B55CC4-3881-78B2-11E2-479AE0371896} AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440} AV: ESET Security (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70} AS: ESET Security (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Firewall (Enabled) {B066057A-E576-007C-D591-56C163D3B33B} FW: ESET Firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B} FW: ESET Firewall (Enabled) {B18EDDE1-72EE-79EA-3ABD-EEAF1EE45FED} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) ACDSee Photo Studio Ultimate 2018 (HKLM\...\{35035ABF-4733-478B-88AC-CB25FF451926}) (Version: 11.2.0.1309 - ACD Systems International Inc.) Acronis Drivers (HKLM\...\{7C36ADC0-5219-4D31-90D1-4211321481EF}) (Version: 25.8.39216 - Acronis) Hidden Acronis True Image (HKLM-x32\...\{F0A1A9E1-CD4B-4504-836F-1946F5815ECB}) (Version: 25.8.39216 - Acronis) Hidden Acronis True Image (HKLM-x32\...\{F0A1A9E1-CD4B-4504-836F-1946F5815ECB}Visible) (Version: 25.8.39216 - Acronis) AOMEI Partition Assistant 9.4 (HKLM-x32\...\{02F850ED-FD0E-4ED1-BE0B-54981f5BD3D4}_is1) (Version: - AOMEI International Network Limited.) ASUS Device Activation (HKLM-x32\...\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}) (Version: 1.0.4.0 - ASUSTeK COMPUTER INC.) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.6.8 - ASUSTeK COMPUTER INC.) ASUS PTP Driver (HKLM-x32\...\{7618E419-9124-4E6C-9AF4-487A6DDEC1C5}) (Version: 11.0.10 - ASUS) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0050 - ASUS) Audacity 3.0.2 (HKLM-x32\...\Audacity_is1) (Version: 3.0.2 - Audacity Team) Audacity 3.0.3 (64-bit) (HKLM\...\Audacity_is1) (Version: 3.0.3 - Audacity Team) AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.1.21 - ICEpower a/s) BlackVue 3.04 (HKLM-x32\...\BlackVue) (Version: 3.04 - PittaSoft, Inc.) Blisk (HKU\S-1-5-21-942201848-496926140-1053970402-1001\...\Blisk) (Version: 15.1.151.108 - The Blisk Authors) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Core FTP LE (x64) (HKLM-x32\...\CoreFTP(x64)) (Version: - ) Digiguide TV Guide (HKLM-x32\...\Digiguide TV Guide) (Version: - EBS New Media Limited) Documentation Manager (HKLM\...\{61BA0F7D-9851-4948-8473-0236129D7A55}) (Version: 22.60.0.6 - Intel Corporation) Hidden EPSON XP-750 Series Printer Uninstall (HKLM\...\EPSON XP-750 Series) (Version: - SEIKO EPSON Corporation) ESET Security (HKLM\...\{30AAEA0C-2993-4ED6-8ABC-48499DA53D87}) (Version: 14.2.24.0 - ESET, spol. s r.o.) Filemail Desktop version 2.9922 (HKLM-x32\...\{1dd2678e-fa13-4410-86d6-5a7c0c858917}_is1) (Version: 2.9922 - Filemail AS) FileZilla Client 3.55.1 (HKLM-x32\...\FileZilla Client) (Version: 3.55.1 - Tim Kosse) Foxit PDF Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 11.0.1.49938 - Foxit Software Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 92.0.4515.159 - Google LLC) Icon Shepherd (HKLM\...\Icon Shepherd_is1) (Version: 19.10.2 - WinAbility Software Corp.) inSSIDer (HKU\S-1-5-21-942201848-496926140-1053970402-1001\...\inSSIDer) (Version: 5.4.0 - MetaGeek, LLC) Intel Driver && Support Assistant (HKLM-x32\...\{10BECC47-44EA-43BF-90F7-6A392DD15F06}) (Version: 21.4.29.8 - Intel) Hidden Intel(R) Chipset Device Software (HKLM-x32\...\{fb610cea-ba50-4d4b-a717-cf025419035c}) (Version: 10.1.1.13 - Intel(R) Corporation) Hidden Intel(R) Computing Improvement Program (HKLM\...\{D40D4164-EEDB-4F0F-85C6-2058A9E34CC7}) (Version: 2.4.04370 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.6.1194 - Intel Corporation) Intel(R) Memory and Storage Tool (HKLM\...\{311A0CC7-8165-4A89-9350-39844FACD15A}) (Version: 1.9.147 - Intel) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4550 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000060-0220-1033-84C8-B8D95FA3C8C3}) (Version: 22.60.0.6 - Intel Corporation) Intel® Driver & Support Assistant (HKLM-x32\...\{0a6e5067-9368-4f32-be84-aac5f85dc5c3}) (Version: 21.4.29.8 - Intel) Intel® PROSet/Wireless Software (HKLM-x32\...\{0961a92c-ad83-40dd-a0fc-29ba41e5349d}) (Version: 20.50.3 - Intel Corporation) Intel® Security Assist (HKLM-x32\...\{B294CE94-FE0F-4427-910C-180AF9FCFED1}) (Version: 1.0.1.620 - Intel Corporation) Intel® Software Installer (HKLM-x32\...\{342d63b4-21a3-437b-92d6-e2fe69d81340}) (Version: 22.60.0.6 - Intel Corporation) Hidden Intel® SSD Toolbox (HKLM-x32\...\{06D085C8-1F00-11B2-96A7-8f0CE39193ED}) (Version: 3.5.14.400 - Intel Corporation) IrfanView 4.58 (64-bit) (HKLM\...\IrfanView64) (Version: 4.58 - Irfan Skiljan) ISO to USB (HKLM-x32\...\{D08A30AC-A663-4EA8-8D81-B98E17F19F1C}_is1) (Version: - isotousb.com) LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) LibreOffice 7.1.2.2 (HKLM\...\{07426A34-E0CD-4EC4-843B-F7A47C7BC835}) (Version: 7.1.2.2 - The Document Foundation) Logitech Options (HKLM\...\LogiOptions) (Version: 8.36.86 - Logitech) Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 92.0.902.78 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-942201848-496926140-1053970402-1003\...\OneDriveSetup.exe) (Version: 19.043.0304.0013 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{852D8FE5-BC66-4061-B1C4-CADF51E5B27D}) (Version: 2.82.0.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32\...\{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.24.28127 (HKLM-x32\...\{e31cb1a4-76b5-46a5-a084-3fa419e82201}) (Version: 14.24.28127.4 - Microsoft Corporation) Mozilla Firefox (x64 en-GB) (HKLM\...\Mozilla Firefox 91.0.1 (x64 en-GB)) (Version: 91.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 84.0.2 - Mozilla) Mozilla Thunderbird 78.13.0 (x64 en-GB) (HKLM\...\Mozilla Thunderbird 78.13.0 (x64 en-GB)) (Version: 78.13.0 - Mozilla) Nero Core (HKLM-x32\...\{85EFC653-C416-4759-BFD0-0A0095B3FFAC}) (Version: 1.2.00200 - Nero AG) Nero Info (HKLM-x32\...\{F030BFE8-8476-4C08-A553-233DE80A2BE1}) (Version: 20.0.1011 - Nero AG) Nero MediaHome 2019 Free (HKLM-x32\...\{134DC8B5-5D4C-4828-95AD-B12D0570D785}) (Version: 20.0.00200 - Nero AG) NetDrive2 (HKLM-x32\...\NetDrive2) (Version: 2.5.0.0 - Bdrive Inc.) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 8.1.2 - Notepad++ Team) NVIDIA FrameView SDK 1.1.4923.29968894 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.1.4923.29968894 - NVIDIA Corporation) NVIDIA GeForce Experience 3.23.0.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.23.0.74 - NVIDIA Corporation) NVIDIA Graphics Driver 471.68 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 471.68 - NVIDIA Corporation) NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation) PeaZip 7.0.1 (WIN64) (HKLM\...\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version: 7.0.1 - Giorgio Tani) Postimage version 1.0.1 (HKLM-x32\...\{B8BAF53F-4680-44A4-AF64-9934F924676B}_is1) (Version: 1.0.1 - Postimage) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31233 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7960 - Realtek Semiconductor Corp.) SecretFolder version 7.1.0.0 (HKLM-x32\...\SecretFolder_is1) (Version: 7.1.0.0 - hxxp://ohsoft.net/) SecureSafe Pro Password Generator (HKLM-x32\...\{46874606-71F9-4754-9A14-C74BAD394032}_is1) (Version: 5.4 - OrangeCat Software, LLC) Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform) Stardock Start10 (HKLM-x32\...\Stardock Start10) (Version: 1.97 - Stardock Software, Inc.) TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - ) Wampserver64 3.1.4 (HKLM\...\{wampserver64}_is1) (Version: 3.1.4 - Dominique Ottello aka Otomatic) Windows Driver Package - ASUS (AsusPTPDrv) HIDClass (04/28/2016 11.0.0.10) (HKLM\...\2E5C3DB999A508D7469B1F0294BCAF149A6B7ABB) (Version: 04/28/2016 11.0.0.10 - ASUS) Windows PC Health Check (HKLM\...\{00DC4B60-5FC9-4629-8147-EF81ADF0EEA6}) (Version: 2.3.2106.25001 - Microsoft Corporation) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.1.0 - ASUS) Zoom (HKU\S-1-5-21-942201848-496926140-1053970402-1001\...\ZoomUMX) (Version: 5.4.9 (59931.0110) - Zoom Video Communications, Inc.) Zoom (HKU\S-1-5-21-942201848-496926140-1053970402-1003\...\ZoomUMX) (Version: 5.5.2 (12494.0204) - Zoom Video Communications, Inc.) Packages: ========= Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.9.253.0_x64__rz1tebttyb220 [2021-08-07] (Dolby Laboratories) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-08-10] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-08-10] (Microsoft Corporation) [MS Ad] Nero DVD Player -> C:\Program Files\WindowsApps\NeroAG.NeroDVDPlayer_1.0.23.0_x86__k5ye2zvjqqeaw [2021-08-06] (NeroAG) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.961.0_x64__56jybvy8sckqj [2021-08-10] (NVIDIA Corp.) Speedtest by Ookla -> C:\Program Files\WindowsApps\Ookla.SpeedtestbyOokla_1.13.156.0_x64__43tkc6nmykmb6 [2021-08-13] (Ookla) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-942201848-496926140-1053970402-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\James\AppData\Local\Microsoft\OneDrive\18.212.1021.0008\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-942201848-496926140-1053970402-1001_Classes\CLSID\{233525e0-5434-46ef-b464-fd7e45e2e145}\localserver32 -> C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe (Intel Corporation -> Intel) CustomCLSID: HKU\S-1-5-21-942201848-496926140-1053970402-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\James\AppData\Local\Microsoft\OneDrive\18.212.1021.0008\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-942201848-496926140-1053970402-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\James\AppData\Local\Microsoft\OneDrive\18.212.1021.0008\amd64\FileSyncShell64.dll => No File SSODL: EldosMountNotificator-cbfs5 - {A9C1259A-D6AB-4B59-8862-4905FA3DC1E8} - C:\Windows\system32\cbfsMntNtf5.dll (EldoS Corporation -> EldoS Corporation) SSODL: EldosMountNotificator-cbfs6 - {91022128-7C69-4406-8D92-368AA5FF5990} - C:\WINDOWS\system32\cbfsMntNtf6.dll (EldoS Corporation -> /n software, Inc.) SSODL: CallbackTechMountNotificator-cbfsconnect2017 - {9313A274-1EBE-4C93-A1D5-AECEA2374702} - C:\WINDOWS\system32\cbfsconnectMntNtf2017.dll (Callback Technologies, Inc. -> Callback Technologies, Inc.) SSODL-x32: EldosMountNotificator-cbfs5 - {A9C1259A-D6AB-4B59-8862-4905FA3DC1E8} - C:\Windows\SysWOW64\cbfsMntNtf5.dll (EldoS Corporation -> EldoS Corporation) SSODL-x32: EldosMountNotificator-cbfs6 - {91022128-7C69-4406-8D92-368AA5FF5990} - C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll (EldoS Corporation -> /n software, Inc.) SSODL-x32: CallbackTechMountNotificator-cbfsconnect2017 - {9313A274-1EBE-4C93-A1D5-AECEA2374702} - C:\WINDOWS\SysWOW64\cbfsconnectMntNtf2017.dll (Callback Technologies, Inc. -> Callback Technologies, Inc.) ShellServiceObjects: Virtual Storage Mount Notification -> {91022128-7C69-4406-8D92-368AA5FF5990} => C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-09-21] (EldoS Corporation -> /n software, Inc.) ShellServiceObjects: Virtual Storage Mount Notification -> {9313A274-1EBE-4C93-A1D5-AECEA2374702} => C:\WINDOWS\system32\cbfsconnectMntNtf2017.dll [2020-05-08] (Callback Technologies, Inc. -> Callback Technologies, Inc.) ShellServiceObjects: Virtual Storage Mount Notification -> {A9C1259A-D6AB-4B59-8862-4905FA3DC1E8} => C:\Windows\system32\cbfsMntNtf5.dll [2015-10-04] (EldoS Corporation -> EldoS Corporation) ShellServiceObjects-x32: Virtual Storage Mount Notification -> {91022128-7C69-4406-8D92-368AA5FF5990} => C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll [2016-09-21] (EldoS Corporation -> /n software, Inc.) ShellServiceObjects-x32: Virtual Storage Mount Notification -> {9313A274-1EBE-4C93-A1D5-AECEA2374702} => C:\WINDOWS\SysWOW64\cbfsconnectMntNtf2017.dll [2020-05-08] (Callback Technologies, Inc. -> Callback Technologies, Inc.) ShellServiceObjects-x32: Virtual Storage Mount Notification -> {A9C1259A-D6AB-4B59-8862-4905FA3DC1E8} => C:\Windows\SysWOW64\cbfsMntNtf5.dll [2015-10-04] (EldoS Corporation -> EldoS Corporation) ShellIconOverlayIdentifiers: [ AcronisDrive] -> {5D74FD4B-4EFB-4586-8022-8637BBE40970} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> ) ShellIconOverlayIdentifiers: [ AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> ) ShellIconOverlayIdentifiers: [ AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> ) ShellIconOverlayIdentifiers: [ AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_8_39216.dll [2021-03-23] (Acronis International GmbH -> ) ShellIconOverlayIdentifiers: [ ExpanDriveOverlay01] -> {468B1711-612C-460A-9685-C7F0C336EF65} => C:\ProgramData\ExpanDrive\ExpanDriveOverlays_x64.2.dll [2021-05-31] () [File not signed] ShellIconOverlayIdentifiers: [ ExpanDriveOverlay02] -> {468B1712-612C-460A-9685-C7F0C336EF65} => C:\ProgramData\ExpanDrive\ExpanDriveOverlays_x64.2.dll [2021-05-31] () [File not signed] ShellIconOverlayIdentifiers: [ ExpanDriveOverlay03] -> {468B1713-612C-460A-9685-C7F0C336EF65} => C:\ProgramData\ExpanDrive\ExpanDriveOverlays_x64.2.dll [2021-05-31] () [File not signed] ShellIconOverlayIdentifiers: [ AAASyncNo] -> {CD0DD5EC-23D2-4AE0-A111-C7B89038E695} => C:\ProgramData\Sync.Com DLL\overlay.dll [2018-11-29] (Sync.com Inc.) [File not signed] ShellIconOverlayIdentifiers: [ AAASyncProg] -> {9A1FA446-6778-4A02-883B-3100549CF193} => C:\ProgramData\Sync.Com DLL\overlay.dll [2018-11-29] (Sync.com Inc.) [File not signed] ShellIconOverlayIdentifiers: [ AAASyncRoot] -> {B57A832B-F40A-4A9D-A0F5-49E7D17B8EE4} => C:\ProgramData\Sync.Com DLL\overlay.dll [2018-11-29] (Sync.com Inc.) [File not signed] ShellIconOverlayIdentifiers: [ AAASyncSkip] -> {AFE40DBB-AB20-4979-B0D2-483B6866C8C9} => C:\ProgramData\Sync.Com DLL\overlay.dll [2018-11-29] (Sync.com Inc.) [File not signed] ShellIconOverlayIdentifiers: [ AAASyncYes] -> {9C569020-57C0-4CE0-9605-8AD42F4B1C7F} => C:\ProgramData\Sync.Com DLL\overlay.dll [2018-11-29] (Sync.com Inc.) [File not signed] ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs5] -> {4577C548-0856-47B4-A528-DA6ECA38E763} => C:\Windows\system32\cbfsMntNtf5.dll [2015-10-04] (EldoS Corporation -> EldoS Corporation) ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs6] -> {C4C3A03F-D3CD-4CDE-9706-A58AF5F3EE16} => C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-09-21] (EldoS Corporation -> /n software, Inc.) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs5] -> {4577C548-0856-47B4-A528-DA6ECA38E763} => C:\Windows\system32\cbfsMntNtf5.dll [2015-10-04] (EldoS Corporation -> EldoS Corporation) ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs6] -> {C4C3A03F-D3CD-4CDE-9706-A58AF5F3EE16} => C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-09-21] (EldoS Corporation -> /n software, Inc.) ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2018-11-29] (Artem Izmaylov -> AIMP DevTeam) ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2021-03-22] (Notepad++ -> ) ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2021-08-14] (ESET, spol. s r.o. -> ESET) ContextMenuHandlers1: [ExpanDriveContextMenus] -> {00472127-8960-4878-909F-A59FEA944CFA} => C:\ProgramData\ExpanDrive\ExpanDriveContextMenus_x64.dll [2021-05-31] () [File not signed] ContextMenuHandlers1: [PicaViewCtxMenuShlExt] -> {F3CBBA61-EE3F-4D6D-B1C6-B3474E579936} => C:\Program Files\Common Files\ACD Systems\PicaView\ACDSeePV.dll [2015-08-28] (ACD Systems International -> ACD Systems International Inc.) ContextMenuHandlers1: [SyncComContextShlExt] -> {0dcd9583-eb2f-4e08-a146-885c923c0833} => C:\ProgramData\Sync.Com DLL\rclick.dll [2018-11-29] (Sync.com Inc.) [File not signed] ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2021-08-14] (ESET, spol. s r.o. -> ESET) ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2018-11-29] (Artem Izmaylov -> AIMP DevTeam) ContextMenuHandlers4: [SyncComContextShlExt] -> {0dcd9583-eb2f-4e08-a146-885c923c0833} => C:\ProgramData\Sync.Com DLL\rclick.dll [2018-11-29] (Sync.com Inc.) [File not signed] ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9f310939ec1eebf9\igfxDTCM.dll [2019-10-30] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_72035dd8d03aecee\nvshext.dll [2021-08-06] (Nvidia Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2021-08-14] (ESET, spol. s r.o. -> ESET) ContextMenuHandlers6: [ExpanDriveContextMenus] -> {00472127-8960-4878-909F-A59FEA944CFA} => C:\ProgramData\ExpanDrive\ExpanDriveContextMenus_x64.dll [2021-05-31] () [File not signed] ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\James\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\d249d9ddd424b688\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default ShortcutWithArgument: C:\Users\James\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\980b6e4d5257aa74\mobile browser emulator.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=lbofcampnkjmiomohpbaihdcbjhbfepf ==================== Loaded Modules (Whitelisted) ============= 2021-04-21 10:15 - 2010-06-29 10:58 - 000104448 _____ () [File not signed] C:\Program Files (x86)\ASUS\AXSP\1.00.19\ATKEX.dll 2021-04-13 12:36 - 2021-04-13 12:36 - 005745664 _____ () [File not signed] C:\Program Files (x86)\Intel\Driver and Support Assistant\irmfuu_module.dll 2018-02-21 07:20 - 2018-02-21 07:20 - 000120320 _____ () [File not signed] C:\Program Files\NetDrive2\jansson.dll 2018-02-21 07:20 - 2018-02-21 07:20 - 000207360 _____ () [File not signed] C:\Program Files\NetDrive2\libevent.dll 2018-02-21 07:20 - 2018-02-21 07:20 - 001103360 _____ () [File not signed] C:\Program Files\NetDrive2\libxml2.dll 2018-02-21 07:20 - 2018-02-21 07:20 - 000068096 _____ () [File not signed] C:\Program Files\NetDrive2\zlib.dll 2021-05-31 12:01 - 2021-05-31 12:01 - 000642048 _____ () [File not signed] C:\ProgramData\ExpanDrive\ExpanDriveContextMenus_x64.dll 2021-05-31 12:01 - 2021-05-31 12:01 - 000447488 _____ () [File not signed] C:\ProgramData\ExpanDrive\ExpanDriveOverlays_x64.2.dll 2012-05-03 11:47 - 2012-05-03 11:47 - 001681408 _____ (/n software inc. - www.nsoftware.com) [File not signed] C:\Program Files\ACD Systems\ACDSee Ultimate\11.0\ipworksssl8.dll 2018-02-21 07:20 - 2018-02-21 07:20 - 000984576 _____ (Free Software Foundation) [File not signed] C:\Program Files\NetDrive2\iconv.dll 2021-05-21 14:04 - 2021-05-21 14:04 - 000130048 _____ (Sam Grogan) [File not signed] [File is in use] C:\Program Files (x86)\Intel\Driver and Support Assistant\NotifyIconWin32.dll 2018-11-29 19:44 - 2018-11-29 19:44 - 001462272 _____ (Sync.com Inc.) [File not signed] C:\ProgramData\Sync.Com DLL\overlay.dll 2018-02-21 07:20 - 2018-02-21 07:20 - 000320000 _____ (The cURL library, hxxps://curl.haxx.se/) [File not signed] C:\Program Files\NetDrive2\libcurl.dll 2019-09-23 09:44 - 2019-09-23 09:44 - 025338368 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Acronis\TrueImageHome\icudt54.dll 2019-09-23 09:44 - 2019-09-23 09:44 - 002056704 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Acronis\TrueImageHome\icuin54.dll 2019-09-23 09:44 - 2019-09-23 09:44 - 001425408 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Acronis\TrueImageHome\icuuc54.dll 2018-02-21 07:20 - 2018-02-21 07:20 - 000135168 _____ (The libssh2 library, hxxps://www.libssh2.org/) [File not signed] C:\Program Files\NetDrive2\libssh2.dll 2018-02-21 07:20 - 2018-02-21 07:20 - 001204224 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\NetDrive2\LIBEAY32.dll 2018-02-21 07:20 - 2018-02-21 07:20 - 000295936 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\NetDrive2\SSLEAY32.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== BHO: No Name -> {9313A274-1EBE-4C93-A1D5-AECEA2374702}' -> No File BHO-x32: No Name -> {9313A274-1EBE-4C93-A1D5-AECEA2374702}' -> No File ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2018-09-15 08:31 - 2018-11-28 20:30 - 000000039 _____ C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 localhost 2020-06-06 10:48 - 2021-08-23 19:28 - 000000500 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;%systemdrive%\Program Files (x86)\FilExile;C:\Program Files (x86)\Common Files\Acronis\VirtualFile\;C:\Program Files (x86)\Common Files\Acronis\VirtualFile64\;C:\Program Files (x86)\Common Files\Acronis\FileProtector\;C:\Program Files (x86)\Common Files\Acronis\FileProtector64\;C:\Program Files (x86)\Common Files\Acronis\SnapAPI\;C:\Program Files\Intel\Intel(R) Memory and Storage Tool\ HKU\S-1-5-21-942201848-496926140-1053970402-1001\Control Panel\Desktop\\Wallpaper -> HKU\S-1-5-21-942201848-496926140-1053970402-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg HKU\S-1-5-21-942201848-496926140-1053970402-1003\Control Panel\Desktop\\Wallpaper -> DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{EB32ECC4-1FDC-40AD-9A8A-813B71B05A3C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{78EB9072-2887-4741-8859-650E973EDA57}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{6080A178-50A0-412E-928B-0C6B3B02D14E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{CC03D2D2-2E0D-4F42-9E20-AA191D56BB74}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{2FD6EB46-8BEE-41E8-AA2B-88F9F5961972}] => (Allow) C:\Program Files (x86)\Acronis\Agent\bin\task-manager.exe (Acronis International GmbH -> Acronis International GmbH) FirewallRules: [{2FCD4954-8F57-4B15-9692-DA0BB22195F2}] => (Allow) C:\Program Files (x86)\Acronis\Agent\bin\bckp_amgr.exe (Acronis International GmbH -> Acronis International GmbH) FirewallRules: [{CB588107-1030-44DB-86FD-CDDE13837EB2}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\Home\report_sender.exe (Acronis International GmbH -> ) FirewallRules: [{0EDCF63E-0EA7-4F5E-95AC-1B81FE9084D2}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\LicenseActivator.exe (Acronis International GmbH -> ) FirewallRules: [{2C917129-8183-41FC-A419-F13F44320D6D}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\ga_service.exe (Acronis International GmbH -> ) FirewallRules: [{08D7678A-F6CB-4250-BDED-3445E8589E2B}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe (Acronis International GmbH -> ) FirewallRules: [{CDABDD64-ECA8-4F44-8FDA-1D41959081B4}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe (Acronis International GmbH -> Acronis International GmbH) FirewallRules: [{4283ADFD-102A-4C4D-8601-E60257AB4CD0}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\acronis_drive.exe (Acronis International GmbH -> ) FirewallRules: [{B40ACB5F-9A40-4A88-8AB5-D220F253A5F0}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\SystemReport.exe (Acronis International GmbH -> ) FirewallRules: [{4177569C-76A1-4B81-80C9-270A23595D8F}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\MediaBuilder.exe (Acronis International GmbH -> ) FirewallRules: [{B23F4562-3CE9-4964-811D-B90CDEE47398}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\TrueImageHome\TrueImageHomeService.exe (Acronis International GmbH -> ) FirewallRules: [{DFF10597-C63C-4B4B-AEA0-0F0C4E7A845A}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageTools.exe (Acronis International GmbH -> ) FirewallRules: [{E31587A0-B072-41E5-A262-21AD64077518}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis International GmbH -> ) FirewallRules: [{16EB7541-9FA7-4DAA-864E-3BB0A48F8B2E}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImage.exe (Acronis International GmbH -> ) FirewallRules: [{6D352D4B-743A-4D30-90D6-B2F6B711C67A}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe (Acronis International GmbH -> Acronis International GmbH) FirewallRules: [{046DB455-1D11-42B5-BB56-B7BF3A0BBC9A}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Acronis International GmbH -> ) FirewallRules: [{38E5E212-BA3D-416E-9D56-4244124C4F74}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.153.608.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{A0D110F7-B46C-4F10-BDB1-6B48B2A452D3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.153.608.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{86E120B1-6F5B-4848-8216-BDBAEB197E36}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.153.608.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{FEDA084A-3D82-4960-B1EE-FAE2B83E473D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.153.608.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{6A8929B3-F187-4FDA-9D3C-3DF09C0D1A53}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.153.608.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{1CF180BB-E63F-48B3-9107-627A848BAFA4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.153.608.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{D7A983B0-21E4-4E29-A159-C9A78E5F715B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.153.608.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{D837F595-3FCA-4A97-A551-8D3D18EF1CFB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.153.608.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{11548284-946F-451B-B2E5-E22D119E8857}] => (Allow) C:\Users\Annie\AppData\Roaming\Zoom\bin\airhost.exe => No File FirewallRules: [{86F1714E-7DC1-4F15-95A0-567390E0CDFA}] => (Allow) C:\Users\Annie\AppData\Roaming\Zoom\bin\airhost.exe => No File FirewallRules: [{FC02851E-2A18-4BAB-A6ED-128E3EEAE14D}] => (Allow) C:\Users\Annie\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{EDC7EB27-1CA4-4EFE-91BA-69AE9F228912}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{DB76B518-5731-4E9E-9270-9D1939B76CA2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{0A22C7DA-1A9D-4561-92A3-08AE21EBEFC5}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{971682A5-BF11-4DF6-8C7C-2DBF87880E6A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{96ACC7C1-EEBB-40F0-B560-BB069CB4205C}] => (Allow) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.EXE (Logitech Inc -> Logitech, Inc.) FirewallRules: [{4038DA04-872A-4874-8BB6-B11EF21C1D83}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe (Acronis International GmbH -> ) FirewallRules: [{EB7015C7-CBFE-4BD7-B706-154407DC9868}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> ) FirewallRules: [{C6502313-FC92-4EB3-BE8B-B3D107979C94}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> ) FirewallRules: [{7BC4476E-8EEC-45E6-96F6-600862D8ABAE}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> ) FirewallRules: [{89D1093B-EEF4-4F06-ABA4-0D620008726B}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> ) FirewallRules: [{B2337348-226D-4070-B5E0-CBD20853B33F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{16AFA650-A00F-4483-8139-CAB1FADC047A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{3F40E945-2635-4D1A-A4AD-3794D934F519}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{9E97313E-66E2-4290-BE6E-807503483BAE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{CDDBDF0B-7F5E-42E0-A14B-DABCC2A027DC}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{C83A7387-7839-4344-9D2D-FEA2C30E5C8C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{3B483740-D77C-4AD5-9BDE-18F1E32384BB}] => (Allow) C:\Program Files\NetDrive2\nd2cmd.exe (Bdrive Inc. -> Bdrive Inc) FirewallRules: [{CCB2D0BC-8F4B-4AB3-B851-F25290348482}] => (Allow) C:\Program Files\NetDrive2\nd2cmd.exe (Bdrive Inc. -> Bdrive Inc) FirewallRules: [{188C8A06-6BE6-4021-8E7A-388E8990C049}] => (Allow) C:\Program Files\NetDrive2\NetDrive2.exe (Bdrive Inc. -> Bdrive Inc) FirewallRules: [{1056B7BD-4C2F-4FE7-B440-BF329FA01F1D}] => (Allow) C:\Program Files\NetDrive2\NetDrive2.exe (Bdrive Inc. -> Bdrive Inc) FirewallRules: [{1D8E2EB0-3A17-40B8-8BC8-F9CCA9012F92}] => (Allow) C:\Program Files\NetDrive2\nd2svc.exe (Bdrive Inc. -> ) FirewallRules: [{AA13D32D-C96C-4AC0-89AE-96549922704E}] => (Allow) C:\Program Files\NetDrive2\nd2svc.exe (Bdrive Inc. -> ) FirewallRules: [UDP - Installer for ACDSee Commander Ultimate 2018] => (Allow) C:\Program Files\ACD Systems\ACDSee Ultimate\11.0\ACDSeeCommanderUltimate11.exe (ACD Systems International Inc. -> ) FirewallRules: [TCP - Installer for ACDSee Commander Ultimate 2018] => (Allow) C:\Program Files\ACD Systems\ACDSee Ultimate\11.0\ACDSeeCommanderUltimate11.exe (ACD Systems International Inc. -> ) FirewallRules: [UDP Query User{93EA229A-FF0F-4124-856A-53133D14D6A0}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe => No File FirewallRules: [TCP Query User{506943DD-7ABF-4287-8DBA-1101004BC9EA}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe => No File FirewallRules: [{1D79E909-20CD-4592-8F0A-F7C703E7177A}] => (Block) C:\xampp\apache\bin\httpd.exe => No File FirewallRules: [{F98FA8E7-C5B7-4374-A975-E368D998F65B}] => (Block) C:\xampp\apache\bin\httpd.exe => No File FirewallRules: [UDP Query User{341F053F-975B-4B23-BA2E-BC4523F9BA18}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe => No File FirewallRules: [TCP Query User{38C1BA8B-933B-40E2-A559-76603C3ED4A8}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe => No File FirewallRules: [{CD942058-4BC7-400B-93AF-2CD2C0129314}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{ECD2ACC2-80D6-48BB-A246-FE31796F9910}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{5943ED0A-AF5F-45B5-BC7D-B9E37FFBFDFB}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> ) FirewallRules: [{20EA990F-D2B6-43EB-A612-D842FEF43A4C}] => (Allow) C:\Users\James\AppData\Local\Temp\B23B5F33-A30E-49B7-8ACC-72E3DC70DFBD\ga_service.exe => No File FirewallRules: [{BD795657-DF77-4BE1-BB97-EEED31E261FE}] => (Block) C:\Users\James\Desktop\Tools\CCleaner64.exe (Piriform Software Ltd -> Piriform Software Ltd) FirewallRules: [{0AE89572-703F-4AD0-A970-B87D6921D0C3}] => (Allow) C:\Users\James\AppData\Local\URBrowser\Application\urbrowser.exe (AdaptiveBee SASU -> The Adaptive Bee team) FirewallRules: [{F6135B9D-6D35-4226-898E-9486742742DF}] => (Allow) C:\Program Files (x86)\Nero\Nero 2019\Nero MediaHome\NMDllHost.exe (Nero AG -> Nero AG) FirewallRules: [{85EDE9E0-6C96-459D-AE8E-35EF8CE83BE6}] => (Allow) C:\Program Files (x86)\Nero\Nero 2019\Nero MediaHome\MediaHome.exe (Nero AG -> Nero AG) FirewallRules: [{FAAB42CE-2A37-4134-8185-A0D49252C8E5}] => (Allow) C:\Program Files\UrBackup\UrBackupClientBackend.exe => No File FirewallRules: [{180CA5F0-41D7-4EA6-BC75-55D8BB7C8AC5}] => (Allow) C:\Program Files (x86)\Acronis\Agent\aakore.exe (Acronis International GmbH -> Acronis International GmbH) FirewallRules: [{A33BCD4E-25BF-416D-987B-AC563DDEF6F5}] => (Allow) C:\Program Files\Acronis\CyberProtect\cyber-protect-service.exe (Acronis International GmbH -> Acronis International GmbH) FirewallRules: [{909AE2AB-DEE0-4ADF-A20B-34CBFB991A82}] => (Allow) C:\Users\James\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{D33CA009-AE05-4D3D-8AD8-050A62DB38C4}] => (Allow) C:\Users\James\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{9A7D50B3-A8FC-4F0B-BA5C-7CEC0C3A5C6C}] => (Allow) C:\Users\James\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{123F4FCA-CBB1-4169-9B59-1437152E6B37}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{33F424C2-D22A-4E91-91D5-29FECF480FEF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{09C111DE-6743-40A3-A1D0-5052115FF648}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{C2AC5CF5-394E-470B-BA19-65F603C371CD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.75.140.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{E5A5A932-0759-4882-855F-FF3450EB15C2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{3766F929-CE56-4F9A-9CF6-537816342FD2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.166.580.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{3FCFE3A1-9EA7-4DDF-A622-9BC5169B687A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.166.580.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{2DC26344-92A5-45D8-8343-EA32357930EB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.166.580.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{AA3C8BB7-A1CA-4FA1-BDC2-53E7F57E4969}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.166.580.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{0D485041-7BE9-4DE7-9394-529F987A4B15}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.166.580.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{693F3243-D8E2-4D18-AE19-053AB668DF41}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.166.580.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{7391D869-E165-4B89-8109-77DFC29246E1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.166.580.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{64E7FBA5-33FD-4A33-8D66-2AE9C3ABDD9A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.166.580.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) ==================== Restore Points ========================= ATTENTION: System Restore is disabled (Total:237.2 GB) (Free:179.35 GB) (76%) ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (08/24/2021 09:36:54 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: wmiprvse.exe, version: 10.0.19041.546, time stamp: 0x5da7ab91 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0x80131623 Fault offset: 0x00007ffbe8be200f Faulting process ID: 0x369c Faulting application start time: 0x01d798c3304f5f5c Faulting application path: C:\WINDOWS\system32\wbem\wmiprvse.exe Faulting module path: unknown Report ID: 0cde12a1-b3b1-46e8-b1af-1a47a65b7c9c Faulting package full name: Faulting package-relative application ID: Error: (08/24/2021 09:36:53 AM) (Source: .NET Runtime) (EventID: 1025) (User: ) Description: Application: wmiprvse.exe Framework Version: v4.0.30319 Description: The application requested process termination through System.Environment.FailFast(string message). Message: Unexpected exception thrown from the provider: System.IO.FileLoadException: File name: 'Microsoft.AppV.AppvClientComConsumer, Version=10.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35' at Microsoft.AppV.AppvPublishingServerWMI.AppvPublishingServer.EnumeratePublishingServers() Stack: at System.Environment.FailFast(System.String) at WmiNative.WbemProvider.WmiNative.IWbemServices.CreateInstanceEnumAsync(System.String, Int32, WmiNative.IWbemContext, WmiNative.IWbemObjectSink) Error: (08/24/2021 09:36:52 AM) (Source: Microsoft Security Client) (EventID: 3002) (User: ) Description: Event-ID 3002 Error: (08/24/2021 09:36:52 AM) (Source: Microsoft Security Client) (EventID: 2002) (User: ) Description: Event-ID 2002 Error: (08/24/2021 09:36:52 AM) (Source: Microsoft Security Client) (EventID: 2003) (User: ) Description: Event-ID 2003 Error: (08/24/2021 07:38:49 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 25 4.1.A.A.8.A.C.9.A.3.4.F.8.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa. PTR DESKTOP-HAB2RL1-2.local. Error: (08/24/2021 07:38:49 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.1.110:5353 23 4.1.A.A.8.A.C.9.A.3.4.F.8.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa. PTR DESKTOP-HAB2RL1.local. Error: (08/24/2021 07:38:49 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 25 110.1.168.192.in-addr.arpa. PTR DESKTOP-HAB2RL1-2.local. System errors: ============= Error: (08/24/2021 09:54:17 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-HAB2RL1) Description: DCOM got error "5" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} Error: (08/24/2021 09:54:17 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The WSearch service failed to start due to the following error: Access is denied. Error: (08/24/2021 09:54:17 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-HAB2RL1) Description: DCOM got error "5" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} Error: (08/24/2021 09:54:17 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The WSearch service failed to start due to the following error: Access is denied. Error: (08/24/2021 09:53:57 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-HAB2RL1) Description: DCOM got error "5" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} Error: (08/24/2021 09:53:57 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The WSearch service failed to start due to the following error: Access is denied. Error: (08/24/2021 09:53:57 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-HAB2RL1) Description: DCOM got error "5" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error: (08/24/2021 09:53:57 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The WSearch service failed to start due to the following error: Access is denied. Windows Defender: ================ Date: 2021-08-24 08:33:56 Description: Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest security intelligence updates in order to enable real-time protection. Date: 2021-08-24 07:35:37 Description: Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest security intelligence updates in order to enable real-time protection. Date: 2021-08-23 20:24:22 Description: Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest security intelligence updates in order to enable real-time protection. Date: 2021-08-23 17:42:32 Description: Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest security intelligence updates in order to enable real-time protection. Date: 2021-08-23 10:35:15 Description: Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest security intelligence updates in order to enable real-time protection. CodeIntegrity: =============== Date: 2021-08-24 08:37:24 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\ESET\ESET Security\ecmds.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2021-08-24 08:37:24 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== BIOS: American Megatrends Inc. UX510UWK.305 04/17/2019 Motherboard: ASUSTeK COMPUTER INC. UX510UWK Processor: Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz Percentage of memory in use: 74% Total physical RAM: 8078.7 MB Available physical RAM: 2090.22 MB Total Virtual: 9358.7 MB Available Virtual: 2688.57 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:237.2 GB) (Free:179.35 GB) (Protected) NTFS \\?\Volume{37c237b3-04cb-4f6e-9cd6-ac2ca7b2c68f}\ (Recovery) (Fixed) (Total:0.49 GB) (Free:0.37 GB) NTFS \\?\Volume{f255e0fb-38e8-41f7-8d55-efd1e63f3d1a}\ () (Fixed) (Total:0.56 GB) (Free:0.09 GB) NTFS \\?\Volume{cfe584b6-42bf-4288-b7f6-e07bc09cc861}\ () (Fixed) (Total:0.1 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ==================== ==================== End of Addition.txt =======================