Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-06-2022 Ran by [removed] (15-06-2022 11:12:51) Running from D:\in Microsoft Windows 10 Pro Version 21H2 19044.1706 (X64) (2021-03-20 10:29:07) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-2368218643-1526046976-4280303104-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2368218643-1526046976-4280303104-503 - Limited - Disabled) DevToolsUser (S-1-5-21-2368218643-1526046976-4280303104-1005 - Limited - Enabled) => C:\Users\DevToolsUser Gast (S-1-5-21-2368218643-1526046976-4280303104-501 - Limited - Disabled) J. Cremers (S-1-5-21-2368218643-1526046976-4280303104-1001 - Administrator - Enabled) => C:\Users\J. Cremers sshd (S-1-5-21-2368218643-1526046976-4280303104-1003 - Limited - Enabled) WDAGUtilityAccount (S-1-5-21-2368218643-1526046976-4280303104-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 4K Video Downloader 4.12 (HKLM\...\{B3C67C95-860B-4362-98C2-0444F8A9B490}) (Version: 4.12.4.3660 - Open Media LLC) 8GadgetPack (HKLM-x32\...\{2C6DC07C-5D68-4E32-B6C6-EF5F24DA9FDF}) (Version: 33.0.0 - 8GadgetPack.net) Agent Ransack (HKLM\...\{7078BFBE-F9CE-4FFD-8538-898E428BE99B}) (Version: 8.5.2951.1 - Mythicsoft Ltd) AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.116 - Advanced Micro Devices, Inc.) Hidden AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.72 - Advanced Micro Devices, Inc.) Hidden AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 4.11.0.0 - Advanced Micro Devices, Inc.) Hidden AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 5.0.0.0 - Advanced Micro Devices, Inc.) Hidden AMD Ryzen Master (HKLM\...\{02247819-03CD-414E-AC8D-FD518BFBA445}) (Version: 2.0.2.1271 - Advanced Micro Devices, Inc.) Hidden AMD Ryzen Master (HKLM\...\AMD Ryzen Master) (Version: 2.0.2.1271 - Advanced Micro Devices, Inc.) AMD SBxxx SMBus Driver Alpha (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 19.10.16 - Advanced Micro Devices, Inc.) AMD System Monitor (HKLM-x32\...\{6EFD0C42-4CC1-4716-A0CA-21C1A062CF34}) (Version: 1.0.9 - Advanced Micro Devices, Inc.) AMD_Chipset_Drivers (HKLM-x32\...\{D8561EEF-2B90-4BDB-B197-16E96924E6AA}) (Version: 1.8.19.0915 - Advanced Micro Devices, Inc.) Hidden AMD_Chipset_Drivers (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 1.8.19.0915 - Advanced Micro Devices, Inc.) AML Free Registry Cleaner 4.6 (HKLM-x32\...\{315F5FFC-1A5C-4A2A-B8E7-1C5B1174C198}_is1) (Version: - AML SOFT, Inc.) AmpliTube 4 version 4.8.2 (HKLM\...\{21B0C8E0-7EB7-4832-B764-20A7DAE86E02}_is1) (Version: 4.8.2 - IK Multimedia) Android Studio (HKLM\...\Android Studio) (Version: 3.5 - Google LLC) AnVir Task Manager Free (HKLM-x32\...\AnVir Task Manager Free) (Version: 6.0.0 - AnVir Software) APP Shop v1.0.39 (HKLM-x32\...\{90242E9B-BC60-46E3-8EE7-8E953F702280}_is1) (Version: 1.0.39 - ASRock Inc.) Arturia Analog Lab 4 (HKLM\...\Analog Lab 4_is1) (Version: 4.1.2.3657 - Arturia & Team V.R) Arturia Mellotron V (HKLM\...\Mellotron V_is1) (Version: 1.0.1.2810 - Arturia & Team V.R) ASRock Restart to UEFI v1.0.6 (HKLM-x32\...\ASRock Restart to UEFI_is1) (Version: 1.0.6 - ASRock Inc.) AutoHotkey 1.1.30.03 (HKLM\...\AutoHotkey) (Version: 1.1.30.03 - Lexikos) Balanced (HKLM-x32\...\{0EA45DD4-A825-420C-AFED-C659EFE3B84F}) (Version: 4.00.0000 - Advanced Micro Devices, Inc.) Hidden balenaEtcher 1.5.63 (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\{d2f3b6c7-6f49-59e2-b8a5-f72e33900c2b}) (Version: 1.5.63 - Balena Inc.) Basic FX Suite (HKLM\...\{984B4881-ED60-408E-AFA6-4689158A42D7}) (Version: 1.5.0 - Yamaha Corporation) Hidden Basic FX Suite (HKLM-x32\...\yUninstall_{163520fa-5394-4fcf-9d09-1a8103ac4b74}) (Version: 1.5.0 - Yamaha Corporation) Borland C++Builder 6 (HKLM-x32\...\{2864C41B-EF2D-4640-95A2-526276524519}) (Version: 6.0 - Borland Software Corporation) Bulk Rename Utility 3.4.1.0 (64-bit) (HKLM\...\Bulk Rename Utility Installation_is1) (Version: - TGRMN Software) calibre (HKLM-x32\...\{39A57915-15A6-46F1-9329-52DB18B80F93}) (Version: 5.35.0 - Kovid Goyal) ConEmu 200713.x64 (HKLM\...\{DD4FA3AB-50E1-4A8E-A39B-92D0D7460E19}) (Version: 11.200.7130 - ConEmu-Maximus5) DBeaver 21.2.1 (HKLM\...\DBeaver) (Version: 21.2.1 - DBeaver Corp) DC1A3 version 3.2.0.0 (HKLM\...\DC1A3_is1) (Version: 3.2.0.0 - ) Desktop Restore version 1.7.1 (HKLM\...\{DBD4F07A-7607-4A4F-A46C-6AA399E06E38}_is1) (Version: 1.7.1 - Jamie O'Connell) EaseUS Partition Master 13.5 (HKLM-x32\...\EaseUS Partition Master_is1) (Version: - EaseUS) eLicenser Control (HKLM-x32\...\eLicenser Control) (Version: 6.12.4.1273 - Steinberg Media Technologies GmbH) Enigma (HKLM\...\{B98565A1-84B2-33F5-802A-D967EE7610E0}) (Version: 1.1.0 - Unknown) Enigma Cycles version 0.1 (HKLM-x32\...\{5CD31D4F-F52A-4C05-B79C-D5A569DDC2BC}}_is1) (Version: 0.1 - Jan Kampherbeek) EnigmaDedVM-1.0 version 1.0 (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\{875E543F-6065-4D36-A4D1-4F9507B742FB}_is1) (Version: 1.0 - Jan Kampherbeek) Everything 1.4.1.1009 (x64) (HKLM\...\Everything) (Version: 1.4.1.1009 - voidtools) Excel (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\1fc5b090eab9aa41f8a2f5987367e6da) (Version: 1.0 - Excel) EZdrummer 2 64-bit (HKLM\...\{B9217824-0EBE-49C7-98A0-A76CC46BBB7D}) (Version: 2.0.0 - Toontrack) Fallout 4 GOTY (HKLM\...\Fallout 4 GOTY_is1) (Version: 1.10.82.0 - ) FastStone Image Viewer 7.4 (HKLM-x32\...\FastStone Image Viewer) (Version: 7.4 - FastStone Soft) FFB Racing Wheel drivers (HKLM-x32\...\{28B758EA-5C83-48B1-B352-C70F12C73F5A}) (Version: 3.TTRS.2021 - Thrustmaster) FileMenu Tools 7.6 (HKLM\...\FileMenuTools_is1) (Version: 7.6 - LopeSoft) Forza Horizon 5 Premium Edition MULTi16 - ElAmigos version 1.0 (HKLM-x32\...\{A65DBE73-F73C-48B7-8FEB-221820B54B32}_is1) (Version: 1.0 - Xbox Game Studios) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 77.0.3865.120 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.301 - Google LLC) Hidden Grand Theft Auto V (HKLM-x32\...\Grand Theft Auto V_is1) (Version: - ) Horizon Zero Dawn (HKLM-x32\...\Horizon Zero Dawn_is1) (Version: - ) HxD Hex Editor 2.4 (HKLM\...\HxD_is1) (Version: 2.4 - Maël Hörz) Inno Setup version 5.5.8 (HKLM-x32\...\Inno Setup 5_is1) (Version: 5.5.8 - jrsoftware.org) Inno Setup version 6.1.2 (HKLM-x32\...\Inno Setup 6_is1) (Version: 6.1.2 - jrsoftware.org) IrfanView 4.53 (64-bit) (HKLM\...\IrfanView64) (Version: 4.53 - Irfan Skiljan) IVGI2 version 2.2.0.0 (HKLM\...\IVGI2_is1) (Version: 2.2.0.0 - ) Java 8 Update 60 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418060F0}) (Version: 8.0.600.27 - Oracle Corporation) Java SE Development Kit 8 Update 60 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180600}) (Version: 8.0.600.27 - Oracle Corporation) Kinect for Windows Speech Recognition Language Pack (en-AU) (HKLM-x32\...\{48CEC0A3-AE10-4EE3-AC62-76D3D58792E5}) (Version: 11.0.7400.336 - Microsoft Corporation) Kits Configuration Installer (HKLM-x32\...\{6F502640-B753-C101-FFA5-B38C3FA5B29A}) (Version: 10.1.17134.12 - Microsoft) Hidden LibreOffice 6.2.8.2 (HKLM\...\{27A53987-88CB-4E92-8D62-A5AB458ACD14}) (Version: 6.2.8.2 - The Document Foundation) Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech) Macrium Reflect Free Edition (HKLM\...\{675DE35B-A619-4FD2-AAF2-6685BC27D5FD}) (Version: 7.2.4539 - Paramount Software (UK) Ltd.) Hidden Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 7.2 - Paramount Software (UK) Ltd.) MakeMKV v1.16.0 (HKLM-x32\...\MakeMKV) (Version: v1.16.0 - GuinpinSoft inc) Malwarebytes Windows Firewall Control (HKLM\...\Windows Firewall Control) (Version: 6.3.0.0 - BiniSoft.org) MediaInfo 19.09 (HKLM\...\MediaInfo) (Version: 19.09 - MediaArea.net) Medieval CUE Splitter (HKLM-x32\...\{B96D2269-568B-4CBF-9332-12FAE8B158F7}) (Version: 1.2.0 - Medieval Software) Medusa (HKLM\...\{991BED37-186A-5451-9E77-C3DCE91D56C7}_is1) (Version: - Medusa) MeldaProduction Audio Plugins 9 (HKLM-x32\...\MeldaProduction Audio Plugins 9) (Version: - MeldaProduction) Melodyne Runtime 4.1 (x64) (HKLM\...\{53EE2829-E9DB-4913-B3EA-96F10F84E98B}) (Version: 1.0.1 - Celemony Software GmbH) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 102.0.1245.39 - Microsoft Corporation) Microsoft Server Speech Platform Runtime (x64) (HKLM\...\{3B433087-E62E-4BF5-97F9-4AF6E1C2409C}) (Version: 11.0.7400.345 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219.473 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219.473 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219.473 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219.473 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61135 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61135 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61135 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61135 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30139 (HKLM-x32\...\{2c673fb6-3e65-4751-965d-33d30b68a8a6}) (Version: 14.29.30139.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29913 (HKLM-x32\...\{03d1453c-7d5c-479c-afea-8482f406e036}) (Version: 14.28.29913.0 - Microsoft Corporation) Microsoft Visual C++ 2019 X64 Additional Runtime - 14.29.30139 (HKLM\...\{7F4A9F52-173F-4B0D-B1EA-269C32EDA827}) (Version: 14.29.30139 - Microsoft Corporation) Hidden Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.29.30139 (HKLM\...\{A6D3F752-BF11-4D7C-B19C-F6F96A35CF50}) (Version: 14.29.30139 - Microsoft Corporation) Hidden Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29913 (HKLM-x32\...\{572DCD10-CF2E-43D1-8151-8BD9AC9086D0}) (Version: 14.28.29913 - Microsoft Corporation) Hidden Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29913 (HKLM-x32\...\{6236EBBD-F50F-40B3-B819-8DB0C608308C}) (Version: 14.28.29913 - Microsoft Corporation) Hidden Microsoft Windows 10 SDK Installer (HKLM-x32\...\Microsoft Windows 10 SDK Installer) (Version: 21.0 - Embarcadero Technologies Inc.) MJUCjr version 1.2.0.0 (HKLM\...\MJUCjr_is1) (Version: 1.2.0.0 - ) MKVToolNix 51.0.0 (64-bit) (HKLM-x32\...\MKVToolNix) (Version: 51.0.0 - Moritz Bunkus) Mozilla Firefox 72.0.2 (x64 en-US) (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\Mozilla Firefox 72.0.2 (x64 en-US)) (Version: 72.0.2 - Mozilla) Mozilla Thunderbird (x64 en-US) (HKLM\...\Mozilla Thunderbird 91.9.1 (x64 en-US)) (Version: 91.9.1 - Mozilla) MSI Afterburner 4.6.2 (HKLM-x32\...\Afterburner) (Version: 4.6.2 - MSI Co., LTD) MultiCommander (x64) (HKLM\...\MultiCommander x64) (Version: 9.7.0.2590 - Mathias Svensson) Native Instruments FM8 (HKLM-x32\...\Native Instruments FM8) (Version: - Native Instruments) Native Instruments Guitar Rig 6 (HKLM-x32\...\Native Instruments Guitar Rig 6) (Version: 6.2.2.137 - Native Instruments) Native Instruments Kontakt (HKLM-x32\...\Native Instruments Kontakt) (Version: 6.1.0.20 - Native Instruments) Native Instruments Native Access (HKLM-x32\...\Native Instruments Native Access) (Version: 1.14.1.156 - Native Instruments) NetTime (HKLM-x32\...\NetTime_is1) (Version: - Mark Griffiths) NewsLeecher version v7.0 Final (HKLM-x32\...\NewsLeecher_is1) (Version: v7.0 Final - ) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.7.1 - Notepad++ Team) NVIDIA Graphics Driver 512.77 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 512.77 - NVIDIA Corporation) NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) NZBGet (HKLM-x32\...\NZBGet) (Version: - nzbget.net) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 26.0.2 - OBS Project) obs-virtualcam (HKLM-x32\...\obs-virtualcam) (Version: - ) OEM Application Profile (HKLM-x32\...\{84AD2AF7-10C8-0395-66F9-FFAEB4C5DBF1}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Old Calculator for Windows 10 (HKLM-x32\...\OldCalcForWin10) (Version: 1.1 - hxxp://winaero.com) Open-Shell (HKLM\...\{1CAB353D-D3F9-4C5D-A305-33D7BF270F1B}) (Version: 4.4.142 - The Open-Shell Team) Oracle VM VirtualBox 6.0.12 (HKLM\...\{E572CA5C-A60B-4C3B-9E9E-1302BBE4DBEE}) (Version: 6.0.12 - Oracle Corporation) Outlook (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\6b0f23e57a39ebfbf2814acb1a24293d) (Version: 1.0 - Outlook) paint.net (HKLM\...\{9108ED9C-43BD-44DF-83AF-6DB198556920}) (Version: 4.3.7 - dotPDN LLC) PCM Native Reverb Bundle (HKLM-x32\...\{294B9A61-B4D6-4EDB-91BF-354619C43FE2}) (Version: 1.1.3 - Lexicon) Hidden PCM Native Reverb Bundle (HKLM-x32\...\PCM Native Reverb Bundle) (Version: - Lexicon) PlanetDance (HKLM-x32\...\Planetdance_is1) (Version: 6 - JJM Cremers) PotPlayer-64 bit (HKLM\...\PotPlayer64) (Version: 1.7.18346 - Kakao Corp.) PowerPoint (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\319814cb56b667dff88f54e08be8f51f) (Version: 1.0 - PowerPoint) Project CARS: GotY Edition (HKLM-x32\...\Project CARS: GotY Edition_is1) (Version: - ) Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 2.0.1.0 - Advanced Micro Devices, Inc.) Hidden PuTTY release 0.73 (64-bit) (HKLM\...\{44F7642C-AB7E-4468-B028-E8D08A0CBB0E}) (Version: 0.73.0.0 - Simon Tatham) Python 2.7.13 (HKLM-x32\...\{4A656C6C-D24A-473F-9747-3A8D00907A03}) (Version: 2.7.13150 - Python Software Foundation) Python 2.7.16 (64-bit) (HKLM\...\{DCD5B320-89D9-4C7C-9E8B-84496588744e}) (Version: 2.7.16150 - Python Software Foundation) qBittorrent 3.3.16 (HKLM-x32\...\qBittorrent) (Version: 3.3.16 - The qBittorrent project) Qt (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\{313a0b62-91cf-4dc9-ae19-0d214987a498}) (Version: %MAINTENANCE_TOOL_VERSION% - The Qt Company Ltd) QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements) RAD Studio 10.3 (HKLM-x32\...\{DB8A20E2-A030-4B16-B69B-16E67DFFA8C5}_is1) (Version: 20.0 - Embarcadero Technologies, Inc.) RAD Studio 10.4 (HKLM-x32\...\{5AB6556B-385E-40B5-A312-8F76E49F0899}_is1) (Version: 21.0 - Embarcadero Technologies, Inc.) RarmaRadio 2.72.8 (HKLM-x32\...\RarmaRadio_is1) (Version: 2.72.8 - ) RarmaRadio PRO (HKLM-x32\...\RarmaRadio PROv2.72.3) (Version: v2.72.3 - Friends in War) REAPER (x64) (HKLM\...\REAPER) (Version: 6.57 - Cockos Incorporated) reFX Nexus VSTi RTAS v2.2.0 (HKLM-x32\...\reFX Nexus_is1) (Version: - ) Ricochet Infinity v3.68 (HKLM-x32\...\Ricochet Infinity v3.68) (Version: - ) SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.24.0 - SAMSUNG Electronics Co., Ltd.) SDK Debuggers (HKLM-x32\...\{8238CD59-617A-FE41-8AB4-A88AF3160849}) (Version: 10.1.17134.12 - Microsoft Corporation) Hidden Shotcut (HKLM-x32\...\Shotcut) (Version: 20.04.12 - Meltytech, LLC) Sitala (HKLM\...\{74B609F8-3755-424B-BC0F-71581EDB4123}) (Version: 1.0.9 - Decomposer (DirectedEdge)) Skype version 8.79 (HKLM-x32\...\Skype_is1) (Version: 8.79 - Skype Technologies S.A.) Solar Fire v9 (HKLM-x32\...\{93397832-4E51-47E9-A10D-6C17C50E1F17}) (Version: 9.0.17 - Esoteric Technologies Pty Ltd) SpotLite (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\SpotLite) (Version: 00.01.99.02 - Quartermaster (Bond)) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Steinberg Activation Manager (HKLM\...\{0224CA8C-FD43-4397-94CE-319B9471016A}) (Version: 1.3.0 - Steinberg Media Technologies GmbH) Steinberg Cubase 5 (HKLM-x32\...\{4A19D6AC-ADE0-4A07-80FF-9C9812C45557}) (Version: 5.1.0 - Steinberg Media Technologies GmbH) Steinberg Cubase LE AI Elements 11 (HKLM\...\{3A87AFFA-4B3E-408C-9B24-E843DBF6D0FF}) (Version: 11.0.40 - Steinberg Media Technologies GmbH) Steinberg Download Assistant (HKLM-x32\...\Steinberg Download Assistant) (Version: 1.32.1 - Steinberg Media Technologies GmbH) Steinberg Drum Loop Expansion 01 (HKLM-x32\...\{490BF87E-1F75-4453-BF55-9F540543A3CA}) (Version: 1.0.0.1 - Steinberg Media Technologies GmbH) Steinberg Generic Lower Latency ASIO Driver 64bit (HKLM\...\{16D5A798-10BE-4FF3-BB71-54C012CD0D7D}) (Version: 1.0.12 - Steinberg Media Technologies GmbH) Steinberg Groove Agent ONE Content (HKLM-x32\...\{BD86F1AC-B594-46E4-85DC-1258AC9E2232}) (Version: 1.0.0.003 - Steinberg Media Technologies GmbH) Steinberg HALionOne (HKLM-x32\...\{E70E7159-93B1-470D-9FBD-D8E9EF34B538}) (Version: 1.1.0.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne Additional Content Set 01 (HKLM-x32\...\{F3AFD063-8BAD-485E-B641-E7F5A2C5AE71}) (Version: 1.0.0.001 - Steinberg Media Technologies GmbH) Steinberg HALionOne Expression Set (HKLM-x32\...\{E22AD5D3-EB60-4A8F-835C-6C10E369DCE2}) (Version: 1.0.1.0 - Steinberg Media Technologies GmbH) Steinberg HALionOne GM Drum Set (HKLM-x32\...\{AC997F93-0757-4ED4-A701-F40C2D654D09}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne GM Set (HKLM-x32\...\{F057965A-D974-4C64-ADB1-4381CD4B8956}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne Pro Set (HKLM-x32\...\{D82CDA0D-C182-42C8-8FF2-5649C98D6003}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne Studio Drum Set (HKLM-x32\...\{865D9ED1-EAC2-436D-AFA7-0B750EB5AAAB}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne Studio Set (HKLM-x32\...\{D23CBFDA-C46B-4920-BA70-FC7878A3F05A}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) Steinberg Install Assistant (HKLM\...\{2E7DF371-6034-4FC7-AE30-100AC21A1003}) (Version: 1.1.2 - Steinberg Media Technologies GmbH) Steinberg Library Manager (HKLM\...\{AA78592A-F13C-4C8E-B849-7A398001FA7F}) (Version: 3.2.20 - Steinberg Media Technologies GmbH) Steinberg LoopMash Content (HKLM-x32\...\{4D454CF8-12FD-464D-B57B-B46FE27B78BB}) (Version: 1.0.0.005 - Steinberg Media Technologies GmbH) Steinberg UR44 Applications (HKLM\...\{38724124-4198-4620-8585-A13DA3BD60FB}) (Version: 2.2.2 - Yamaha Corporation) Hidden Steinberg UR44 Applications (HKLM-x32\...\yUninstall_{f4077d77-5255-4c8b-b38e-ef626eaa4c60}) (Version: 2.2.2 - Yamaha Corporation) Strawberry Perl (HKLM-x32\...\{7F3E14F6-6F1E-1014-BAF3-DA7C31843670}) (Version: 5.22.1003 - strawberryperl.com project) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 10.0.1208 - SUPERAntiSpyware.com) System Ninja version 3.2.7 (HKLM-x32\...\{6E67710E-206D-43AB-BF21-E7CD63056C55}_is1) (Version: 3.2.7 - SingularLabs) SysTray-X (HKLM-x32\...\systray-x@Ximi1970) (Version: - ) TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.25.6 - TeamViewer) TightVNC (HKLM\...\{0C89FA04-E824-4B38-A517-D5D22F171655}) (Version: 2.8.23.0 - GlavSoft LLC.) Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.51 - Ghisler Software GmbH) UltraISO Premium V9.36 (HKLM-x32\...\UltraISO_is1) (Version: - ) UltraMon (HKLM\...\{9069EE0A-7615-4D86-AD80-CA263E936DA6}) (Version: 3.2.2 - Realtime Soft Ltd) UltraVnc (64-bit) (HKLM\...\Ultravnc2_is1) (Version: 1.3.2 - uvnc bvba) UltraVNC 1.0.8.2 (HKLM-x32\...\Ultravnc2_is1) (Version: 1.0.8.2 - 1.0.8.2) Uninstall Tool (HKLM\...\Uninstall Tool_is1) (Version: 3.5.9 - CrystalIDEA Software) Van Dale Groot woordenboek van de Nederlandse taal 14 (HKLM-x32\...\Van Dale Groot woordenboek van de Nederlandse taal 14) (Version: 14.0.16.222 - Van Dale Lexicografie) Vivaldi (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\Vivaldi) (Version: 5.3.2669.3 - Vivaldi Technologies AS.) VLC media player (HKLM\...\VLC media player) (Version: 3.0.17.4 - VideoLAN) VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.11 - VideoLAN) WACUP 1.6.1.10342 (HKLM\...\WACUP) (Version: 1.6.1.10342 - Darren Owen aka DrO) WACUP 1.7.2.11906 32-bit (x86) (HKLM-x32\...\Winamp) (Version: 1.7.2.11906 - Darren Owen aka DrO) WhoCrashed 7.01 (HKLM\...\WhoCrashed_is1) (Version: 7.01 - Resplendence Software Projects Sp.) Windows Desktop Gadgets (HKLM\...\Windows Desktop Gadgets_is1) (Version: 2.0 - hxxp://gadgetsrevived.com) Windows Help Viewer (HKLM-x32\...\{2F6F93BF-9A86-4093-B0D9-DEC64CE550E0}) (Version: 6.3.9600.16411 - Microsoft Corporation) Windows PC Health Check (HKLM\...\{8B203035-EEAB-4F30-B65A-6F805463498A}) (Version: 2.1.2106.23002 - Microsoft Corporation) Windows SDK EULA (HKLM-x32\...\{18380907-0DDE-C70B-74D1-46F0144502CD}) (Version: 10.1.17134.12 - Microsoft Corporations) Hidden Windows Software Development Kit - Windows 10.0.17134.12 (HKLM-x32\...\{5f83ccda-0498-4b97-a298-16a642bf49f2}) (Version: 10.1.17134.12 - Microsoft Corporation) WinRAR 5.80 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.80.1 - win.rar GmbH) WinSCP 5.15.4 (HKLM-x32\...\winscp3_is1) (Version: 5.15.4 - Martin Prikryl) Word (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\1b837d0bf93d01407352736c91b7bf50) (Version: 1.0 - Word) WPT Redistributables (HKLM-x32\...\{F28E1B8B-1F92-80AF-710B-3E0191A25917}) (Version: 10.1.17134.12 - Microsoft) Hidden WPTx64 (HKLM-x32\...\{711802CA-302C-6805-6D1F-D5CEF535F15E}) (Version: 10.1.17134.12 - Microsoft) Hidden WRC 9 (HKLM-x32\...\WRC 9_is1) (Version: - ) X64 Debuggers And Tools (HKLM\...\{66B288E6-3354-AB0F-920D-909DDAA653FF}) (Version: 10.1.17763.132 - Microsoft Corporation) X86 Debuggers And Tools (HKLM-x32\...\{A80F4302-E354-EFCD-3802-3CB0572D4FD1}) (Version: 10.1.17763.132 - Microsoft Corporation) Yamaha Steinberg USB Driver (HKLM\...\{D891D2FB-CABD-4817-9394-6C5F7D995507}) (Version: 2.0.3 - Yamaha Corporation) Hidden Yamaha Steinberg USB Driver (HKLM-x32\...\yUninstall_{2938B185-2D57-47B0-9FC8-C90A67BA9277}) (Version: 2.0.3 - Yamaha Corporation) Zeus beta (HKLM-x32\...\{62884C08-E6E9-4CF6-B3A9-F805370084CA}_is1) (Version: 0.27.22.127 - ) Zoom (HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\...\ZoomUMX) (Version: 5.8.7 (2058) - Zoom Video Communications, Inc.) Packages: ========= Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_1.1911.21713.0_x64__8wekyb3d8bbwe [2021-03-20] (Microsoft Corporation) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-06-14] (NVIDIA Corp.) Ubuntu 20.04 LTS -> C:\Program Files\WindowsApps\CanonicalGroupLimited.Ubuntu20.04onWindows_2004.2021.825.0_x64__79rhkp1fndgsc [2021-11-14] (Canonical Group Limited) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{03A16E1B-DE60-4BB4-AFA5-302567FEC464}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{052DB226-BE3B-44D4-B932-9C8049B2110B}\InprocServer32 -> C:\Users\J. Cremers\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Moin's Volume Gadget.gadget\dlls\VolumeControl64.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Users\J. Cremers\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter.gadget\CoreTempReader.dll (AddGadgets IT -> ) CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{0B7AD8D3-094A-44DE-A348-83C6C3FA347C}\InprocServer32 -> C:\Users\J. Cremers\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Clipboarder.gadget\Release\Clipboarder64.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\J. Cremers\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{297EC52D-618A-4CDA-9156-A218D4655B05}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{30AF2349-3701-465B-ACC1-AAEA813DE567}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{339FA1D5-707F-4CE4-8291-B2AF27C34A74}\InprocServer32 -> C:\Dopus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{3ABA744B-12A3-4E87-A25A-C19AE7914939}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{3ED6B98B-B1C0-427C-8549-CEDD8EB3CA21}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{44FE44EE-4E5C-430D-A1DF-1A67F02759EF}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{55839D91-467F-4be1-9DC1-8ADBBCC794F6}\InprocServer32 -> C:\Users\J. Cremers\AppData\Local\Microsoft\Windows Sidebar\Gadgets\VolumeControlReloadedTHLE.gadget\vcr_lib.dll (Orbmu2k) [File not signed] [File is in use] CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{55CC2006-E2FC-40C9-9FB6-02C048690FBB}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{6327E5F6-6E20-4F14-84D8-FE18FD03B164}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{6CC9D420-CD62-4C76-AE68-6A5367E97E08}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{7191AC7E-99B2-4C9B-A4F4-BA76DBB41C67}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{87B97A91-D492-4AEF-9796-20CF258F2A6A}\localserver32 -> "C:\Users\J. Cremers\AppData\Local\Vivaldi\Application\3.1.1929.3\notification_helper.exe" => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{8839E7B6-5074-4F3F-8920-E1F4B3F51A3E}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{89BB4535-5AE9-43a0-89C5-19B4697E5C5E}\InprocServer32 -> C:\Users\J. Cremers\AppData\Local\Microsoft\Windows Sidebar\Gadgets\iBattery.gadget\bin\Gadget.Interop.dll () [File not signed] CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{A075E99F-F9E9-4904-A52A-FC812D7FB86E}\InprocServer32 -> C:\Users\J. Cremers\AppData\Local\Microsoft\Windows Sidebar\Gadgets\spectrum-analyser.gadget\WASAPI\AMD64\WASAPIlib.dll (Jonathan Abbott) [File not signed] [File is in use] CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{BCA9D37C-CA60-4160-9115-97A00F24702D}\localserver32 -> C:\Users\J. Cremers\AppData\Local\Vivaldi\Application\5.3.2669.3\notification_helper.exe (Vivaldi Technologies AS -> Vivaldi Technologies AS) CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{C2D98409-B84B-4714-8488-0C383C08E4B5}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{C4AB2F2B-F6AF-4B2C-86D1-C77089AA43E5}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{C5F518C5-BB7A-4387-AC7D-0C65CD6257E9}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{CA70896A-2081-44A1-85E7-EDF726DBCEE4}\InprocServer32 -> C:\Dopus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{CB3996FE-AAA5-4826-84FA-E6355B2E775B}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{EDCC0637-E50D-49A1-97EC-5BFAF40D6A5E}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{F039B8F9-D4C0-478D-80DE-09DE7E7CD1DF}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{F4DF99D8-4B1E-400A-AD76-D1FFD0E3BC23}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File CustomCLSID: HKU\S-1-5-21-2368218643-1526046976-4280303104-1001_Classes\CLSID\{F6936069-888C-47B5-984C-93FE625E0BF4}\InprocServer32 -> C:\DirectoryOpus\dopuslib.dll => No File ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Open-Shell\ClassicExplorer64.dll [2019-10-26] (Open-Shell) [File not signed] ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Open-Shell\ClassicExplorer64.dll [2019-10-26] (Open-Shell) [File not signed] ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Notepad++\NppShell_06.dll [2016-09-21] (Notepad++ -> ) ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2019-09-20] (Paramount Software UK Ltd -> Paramount Software UK Ltd) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\WinRar\rarext.dll [2019-08-29] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\WinRar\rarext32.dll [2019-08-29] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers2: [BRUMenuHandler] -> {5D924130-4CB1-11DB-B0DE-0800200C9A66} => C:\tools\Bulk Rename Utility\BRUhere64.dll [2019-10-17] (TGRMN Software -> Bulk Rename Utility) ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2019-09-20] (Paramount Software UK Ltd -> Paramount Software UK Ltd) ContextMenuHandlers2: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => C:\UltraISO\isoshl64.dll [2009-10-22] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.) ContextMenuHandlers3: [FileMenuTools] -> {C1B2C38F-3DCA-4E3D-BC34-D5B87B636543} => C:\Tools\FileMenuTools\FileMenuTools64.dll [2019-03-10] (LopeSoft) [File not signed] ContextMenuHandlers4: [FileMenuTools] -> {C1B2C38F-3DCA-4E3D-BC34-D5B87B636543} => C:\Tools\FileMenuTools\FileMenuTools64.dll [2019-03-10] (LopeSoft) [File not signed] ContextMenuHandlers4: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => C:\UltraISO\isoshl64.dll [2009-10-22] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.) ContextMenuHandlers5: [DeskMenu] -> {7E74422F-2393-11D4-98E0-444553540000} => C:\Program Files\Desktop Restore\dkticnsr.dll [2019-02-02] (Jamie O'Connell) [File not signed] ContextMenuHandlers5: [FileMenuTools] -> {C1B2C38F-3DCA-4E3D-BC34-D5B87B636543} => C:\Tools\FileMenuTools\FileMenuTools64.dll [2019-03-10] (LopeSoft) [File not signed] ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_d5d5b9f929f4cb65\nvshext.dll [2022-05-05] (Nvidia Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [FileMenuTools] -> {C1B2C38F-3DCA-4E3D-BC34-D5B87B636543} => C:\Tools\FileMenuTools\FileMenuTools64.dll [2019-03-10] (LopeSoft) [File not signed] ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\System32\StartMenuHelper64.dll [2019-10-26] (Open-Shell) [File not signed] ContextMenuHandlers6: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => C:\UltraISO\isoshl64.dll [2009-10-22] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\WinRar\rarext.dll [2019-08-29] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\WinRar\rarext32.dll [2019-08-29] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1_S-1-5-21-2368218643-1526046976-4280303104-1001: [ kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} => -> No File ContextMenuHandlers2_S-1-5-21-2368218643-1526046976-4280303104-1001: [AgentRansack] -> {2AE9D6D8-E348-4853-B266-C78844D31B97} => C:\tools\Agent Ransack\ShellExt.dll [2020-11-19] (MYTHICSOFT LIMITED -> Mythicsoft Ltd) ContextMenuHandlers4_S-1-5-21-2368218643-1526046976-4280303104-1001: [ kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} => -> No File ContextMenuHandlers4_S-1-5-21-2368218643-1526046976-4280303104-1001: [AgentRansack] -> {2AE9D6D8-E348-4853-B266-C78844D31B97} => C:\tools\Agent Ransack\ShellExt.dll [2020-11-19] (MYTHICSOFT LIMITED -> Mythicsoft Ltd) ContextMenuHandlers4_S-1-5-21-2368218643-1526046976-4280303104-1001: [Fb2kShellExt] -> {511D48AF-9E45-4CB8-8F02-9C1BE4BC3CF8} => C:\tools\foobar2000\ShellExt64.dll [2019-12-02] (Piotr Pawłowski -> Peter Pawlowski) [File not signed] ContextMenuHandlers5_S-1-5-21-2368218643-1526046976-4280303104-1001: [AgentRansack] -> {2AE9D6D8-E348-4853-B266-C78844D31B97} => C:\tools\Agent Ransack\ShellExt.dll [2020-11-19] (MYTHICSOFT LIMITED -> Mythicsoft Ltd) ContextMenuHandlers6_S-1-5-21-2368218643-1526046976-4280303104-1001: [AgentRansack] -> {2AE9D6D8-E348-4853-B266-C78844D31B97} => C:\tools\Agent Ransack\ShellExt.dll [2020-11-19] (MYTHICSOFT LIMITED -> Mythicsoft Ltd) ==================== Codecs (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Drivers32: [msacm.voxacm160] => C:\Windows\system32\vct3216.acm [82944 2003-05-21] (Voxware, Inc.) [File not signed] HKLM\...\Drivers32: [msacm.scg726] => C:\Windows\system32\scg726.acm [13239 2000-03-14] (SHARP Corporation) [File not signed] HKLM\...\Drivers32: [msacm.alf2cd] => C:\Windows\system32\alf2cd.acm [38912 2003-05-21] (NCT Company) [File not signed] HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\system32\AC3ACM.acm [81920 2004-02-04] (fccHandler) [File not signed] HKLM\...\Drivers32: [msacm.lame] => C:\Windows\system32\lame.ax [245760 2005-08-01] () [File not signed] HKLM\...\Drivers32: [vidc.dvsd] => C:\Windows\system32\mcdvd_32.dll [261632 2003-05-21] (MainConcept) [File not signed] HKLM\...\Drivers32: [vidc.mpg4] => C:\Windows\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed] HKLM\...\Drivers32: [vidc.mp42] => C:\Windows\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed] HKLM\...\Drivers32: [vidc.mp43] => C:\Windows\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed] HKLM\...\Drivers32: [vidc.xvid] => C:\Windows\system32\xvidvfw.dll [139264 2004-07-03] () [File not signed] HKLM\...\Drivers32: [vidc.DIVX] => C:\Windows\system32\DivX.dll [638976 2003-05-22] (DivXNetworks, Inc.) [File not signed] HKLM\...\Drivers32: [vidc.VP60] => C:\Windows\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed] HKLM\...\Drivers32: [vidc.VP61] => C:\Windows\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed] HKLM\...\Drivers32: [vidc.VP62] => C:\Windows\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed] HKLM\...\Drivers32: [vidc.LAGS] => C:\Windows\system32\lagarith.dll [216064 2011-12-07] () [File not signed] ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) Shortcut: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Streamtuner2\Streamtuner2 on the Web.lnk -> hxxp://freshcode.club/projects/streamtuner Shortcut: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Streamtuner2\Extra\Reconfigure.lnk -> C:\Tools\tuner\usr\share\streamtuner2\dev\install_python_gtk.bat (No File) ShortcutWithArgument: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Excel.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=leffmjdabcgaflkikcefahmlgpodjkdm ShortcutWithArgument: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outlook.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=bjhmmnoficofgoiacjaajpkfndojknpb ShortcutWithArgument: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=opfacbhaojodjaojgocnibmklknchehf ShortcutWithArgument: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Word.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=hikhggiobiflkdfdgdajcfklmcibbopi ShortcutWithArgument: C:\Users\J. Cremers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qt\6.2.4\MinGW 11.2.0 (64-bit)\Qt 6.2.4 (MinGW 11.2.0 64-bit).lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /A /Q /K C:\Qt\6.2.4\mingw_64\bin\qtenv2.bat ==================== Loaded Modules (Whitelisted) ============= 2022-06-10 11:19 - 2016-01-02 18:19 - 000400896 _____ () [File not signed] C:\mc\Extensions\MCPictureTools\ExifWin.dll 2022-06-04 19:17 - 2022-06-04 19:17 - 000128512 _____ (Alexander Roshal) [File not signed] C:\WACUP\UNRAR.dll 2022-02-05 11:13 - 2021-11-01 16:20 - 000660992 _____ (Alpha-II Productions hxxp://www.alpha-ii.com) [File not signed] C:\WACUP\Plugins\in_snes.dll 2022-02-05 11:13 - 2021-11-01 16:20 - 000049152 _____ (Alpha-II Productions hxxp://www.alpha-ii.com) [File not signed] C:\WACUP\Plugins\SNESAPU.DLL 2021-03-20 13:14 - 2020-06-23 10:54 - 000660480 _____ (Helmut Buhler) [File not signed] C:\Program Files\Windows Sidebar\dwmapi.dll 2022-02-05 11:13 - 2004-05-15 12:37 - 000892928 _____ (Homeboy Software) [File not signed] C:\WACUP\Plugins\vis_vu_145-9x.dll 2020-06-28 10:56 - 2020-06-28 10:56 - 000039936 _____ (Jonathan Abbott) [File not signed] [File is in use] C:\Users\J. Cremers\AppData\Local\Microsoft\Windows Sidebar\Gadgets\spectrum-analyser.gadget\WASAPI\AMD64\WASAPIlib.dll 2022-06-10 11:19 - 2022-06-10 11:18 - 001104384 _____ (Mathias Svensson) [File not signed] C:\mc\Extensions\MCAudioTools\MCAudioTools.dll 2022-06-04 19:13 - 2022-06-04 19:13 - 000015872 _____ (MetaBrainz Foundation) [File not signed] C:\WACUP\Plugins\discid.dll 2022-06-10 11:19 - 2022-06-10 11:18 - 000232448 _____ (Multi Commander) [File not signed] C:\mc\Extensions\FS7Zip\FS7Zip.dll 2022-06-10 11:19 - 2022-06-10 11:17 - 000430080 _____ (Multi Commander) [File not signed] C:\mc\Extensions\FSFTP\FSFTP.dll 2022-06-10 11:19 - 2022-06-10 11:18 - 000331264 _____ (Multi Commander) [File not signed] C:\mc\Extensions\FSPortable\FSPortable.dll 2022-06-10 11:19 - 2022-06-10 11:18 - 000373760 _____ (Multi Commander) [File not signed] C:\mc\Extensions\FSRAR\FSRAR.dll 2022-06-10 11:19 - 2022-06-10 11:16 - 000262656 _____ (Multi Commander) [File not signed] C:\mc\Extensions\FSRegistry\FSRegistry.dll 2022-06-10 11:19 - 2022-06-10 11:18 - 000317952 _____ (Multi Commander) [File not signed] C:\mc\Extensions\MCLanEditor\MCLanEditor.dll 2022-06-10 11:19 - 2022-06-10 11:18 - 001573376 _____ (Multi Commander) [File not signed] C:\mc\Extensions\MCPictureTools\MCPictureTools.dll 2022-06-10 11:19 - 2022-06-10 11:16 - 000150016 _____ (Multi Commander) [File not signed] C:\mc\Extensions\MCSpecial\MCSpecial.dll 2022-06-10 11:19 - 2022-06-10 11:18 - 000841216 _____ (Multi Commander) [File not signed] C:\mc\Extensions\MCUtils\MCUtils.dll 2022-06-10 11:19 - 2022-06-10 11:18 - 000408064 _____ (Multi Commander) [File not signed] C:\mc\Extensions\MFTools\MFTools.dll 2022-06-10 11:19 - 2022-06-10 11:19 - 001217536 _____ (Multi Commander) [File not signed] C:\mc\Extensions\MultiFileViewer\MultiFileViewer.dll 2022-06-10 11:19 - 2022-06-10 11:18 - 000423936 _____ (MultiCommander) [File not signed] C:\mc\Extensions\MCVideoTools\MCVideoTools.dll 2022-02-05 11:26 - 2013-12-13 04:47 - 000418816 _____ (Nullsoft, Inc.) [File not signed] C:\WACUP\nsutil.dll 2022-02-05 11:26 - 2013-12-13 04:47 - 000112128 _____ (Nullsoft, Inc.) [File not signed] C:\WACUP\Plugins\in_midi.dll 2022-02-05 11:26 - 2013-11-26 17:40 - 000269824 _____ (Nullsoft, Inc.) [File not signed] C:\WACUP\Plugins\in_mp3.dll 2017-05-04 02:31 - 2017-05-04 02:31 - 000032256 _____ (Nullsoft, Inc.) [File not signed] C:\WACUP\Plugins\in_wav.trb 2022-02-05 11:26 - 2013-12-13 04:47 - 000024576 _____ (Nullsoft, Inc.) [File not signed] C:\WACUP\Plugins\out_disk.dll 2019-10-26 19:30 - 2019-10-26 19:30 - 000872960 _____ (Open-Shell) [File not signed] C:\Program Files\Open-Shell\ClassicExplorer64.dll 2019-10-26 19:31 - 2019-10-26 19:31 - 003388928 _____ (Open-Shell) [File not signed] C:\Program Files\Open-Shell\StartMenuDLL.dll 2019-10-18 14:02 - 2019-10-18 14:02 - 000032768 _____ (Orbmu2k) [File not signed] [File is in use] C:\Users\J. Cremers\AppData\Local\Microsoft\Windows Sidebar\Gadgets\VolumeControlReloadedTHLE.gadget\vcr_lib.dll 2022-02-05 11:13 - 2006-10-25 17:00 - 000456192 _____ (Shibatch Software) [File not signed] C:\WACUP\Plugins\in_!mpg123.dll 2022-06-05 01:15 - 2022-06-05 01:15 - 002030592 _____ (The curl library, hxxps://curl.se/) [File not signed] C:\WACUP\libcurl.dll 2022-06-07 18:28 - 2022-06-07 18:28 - 000106496 _____ (The mpg123 library, hxxps://www.mpg123.de/) [File not signed] C:\WACUP\mpg123.dll 2022-06-04 19:17 - 2022-06-04 19:17 - 000663552 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\libvorbis.dll 2022-06-08 23:12 - 2022-06-08 23:12 - 000093184 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\nde.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000028672 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_classic.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000024576 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_exclude.dll 2022-06-07 18:28 - 2022-06-07 18:28 - 000048640 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_hotkeys.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000132096 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_jumpex.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000047104 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_play_remove.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000019456 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_repeater.dll 2022-06-07 18:28 - 2022-06-07 18:28 - 000046080 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_transcode.dll 2022-06-07 18:28 - 2022-06-07 18:28 - 000035840 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_undo.dll 2022-06-07 18:28 - 2022-06-07 18:28 - 000051712 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_wc.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000030720 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_win10shell.dll 2022-06-09 01:50 - 2022-06-09 01:50 - 000115712 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\gen_win7shell.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000109056 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in__snesamp_wrapper.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 001183232 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_2sf.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000098304 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_ape.dll 2022-06-07 18:28 - 2022-06-07 18:28 - 000017408 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_audio.dll 2022-06-07 18:28 - 2022-06-07 18:28 - 000109568 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_capture.dll 2022-06-07 22:40 - 2022-06-07 22:40 - 000096768 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_cdda.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000042496 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_flac.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000359936 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_gsf.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000087552 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_magnumopus.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000783360 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_mod.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000059392 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_mp4.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000058368 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_mpc.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000184832 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_msx.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000137728 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_ncsf.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000172032 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_notyansf.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000640000 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_psf.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000193024 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_sidious.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000215552 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_snsf.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000041472 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_text.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000053760 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_tta.dll 2022-06-07 22:40 - 2022-06-07 22:40 - 000095232 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_url.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000456192 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_vermas.dll 2022-06-09 02:04 - 2022-06-09 02:04 - 001613824 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_vgmstream.dll 2022-06-07 18:28 - 2022-06-07 18:28 - 000055808 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_vorbis.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000021504 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_wav.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000024576 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_wave.dll 2022-06-07 18:28 - 2022-06-07 18:28 - 000070144 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_wv.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000067072 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\in_zip.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000429056 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\out_matrix_mixer.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000037888 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\out_notsoasio.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000039936 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\out_notsodirect.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000023040 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\out_notsowavey.dll 2022-06-07 18:30 - 2022-06-07 18:30 - 000049664 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Plugins\out_notsoyasapi.dll 2022-06-07 18:29 - 2022-06-07 18:29 - 000024576 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\System\dlmgr.w5s 2022-06-07 18:29 - 2022-06-07 18:29 - 000593408 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\System\image.w5s 2022-06-07 18:29 - 2022-06-07 18:29 - 000034304 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\System\jnetlib.w5s 2022-06-07 18:29 - 2022-06-07 18:29 - 000063488 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\System\metadata.w5s 2022-06-07 18:29 - 2022-06-07 18:29 - 000101376 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\System\skinning.w5s 2022-06-07 18:29 - 2022-06-07 18:29 - 000109056 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\System\xml.w5s 2022-06-07 18:28 - 2022-06-07 18:28 - 000245760 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\tag.dll 2022-02-04 15:56 - 2022-06-10 17:34 - 001806336 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\Winamp.dll 2022-06-10 18:12 - 2022-06-10 18:12 - 000209408 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\winamp_res.dll 2022-06-10 17:05 - 2022-06-10 17:05 - 000073728 _____ (WACUP (WinAmp Community Update Project)) [File not signed] C:\WACUP\zlib.dll 2018-01-28 20:54 - 2018-01-28 20:54 - 000106664 _____ (White-Tiger -> -) [File not signed] C:\TClock\misc\T-Clock64.DLL ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\sdpsenv.dat:naughtypirates [322] ==================== Safe Mode (Whitelisted) ================== ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Open-Shell\ClassicExplorer64.dll [2019-10-26] (Open-Shell) [File not signed] BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation) BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Open-Shell\ClassicIEDLL_64.dll [2019-10-26] (Open-Shell) [File not signed] Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Open-Shell\ClassicExplorer64.dll [2019-10-26] (Open-Shell) [File not signed] ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-03-19 06:49 - 2022-05-24 17:39 - 000476670 _____ C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 localhost 0.0.0.0 www.r2rdownload.com 0.0.0.0 www.elephantafiles.com 0.0.0.0 www.meldaproduction.com 0.0.0.0 fr.a2dfp.net 0.0.0.0 m.fr.a2dfp.net 0.0.0.0 mfr.a2dfp.net 0.0.0.0 ad.a8.net 0.0.0.0 asy.a8ww.net 0.0.0.0 static.a-ads.com 0.0.0.0 abcstats.com 0.0.0.0 a.abv.bg 0.0.0.0 adserver.abv.bg 0.0.0.0 adv.abv.bg 0.0.0.0 bimg.abv.bg 0.0.0.0 ca.abv.bg 0.0.0.0 track.acclaimnetwork.com 0.0.0.0 accuserveadsystem.com 0.0.0.0 www.accuserveadsystem.com 0.0.0.0 achmedia.com 0.0.0.0 csh.actiondesk.com 0.0.0.0 ads.activepower.net 0.0.0.0 ad.activesolutions.cz 0.0.0.0 app.activetrail.com 0.0.0.0 traffic.acwebconnecting.com 0.0.0.0 office.ad1.ru 0.0.0.0 cms.ad2click.nl 0.0.0.0 ad2games.com 0.0.0.0 content.ad20.net 0.0.0.0 core.ad20.net There are 12590 more lines. 2020-01-27 18:29 - 2020-01-27 18:29 - 000000439 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics 172.17.52.177 Thunderbird.mshome.net # 2025 1 6 25 16 29 41 665 ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Embarcadero\Studio\21.0\bin;C:\Users\Public\Documents\Embarcadero\Studio\21.0\Bpl;C:\Program Files (x86)\Embarcadero\Studio\21.0\bin64;C:\Users\Public\Documents\Embarcadero\Studio\21.0\Bpl\Win64;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Embarcadero\Studio\20.0\bin;C:\Users\Public\Documents\Embarcadero\Studio\20.0\Bpl;C:\Program Files (x86)\Embarcadero\Studio\20.0\bin64;C:\Users\Public\Documents\Embarcadero\Studio\20.0\Bpl\Win64;C:\Bcb6\Bin;C:\Bcb6\Projects\Bpl;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\PuTTY\;C:\Medusa\Python;C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\;C:\pd7\pmemo;C:\Windows\SysWOW64;C:\Users\J. Cremers\.android\avd;C:\Android\Sdk\platform-tools\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;c:\Audacity\ffmpeg; HKU\S-1-5-21-2368218643-1526046976-4280303104-1001\Control Panel\Desktop\\Wallpaper -> C:\cat4\bmp.bmp HKU\S-1-5-21-2368218643-1526046976-4280303104-1005\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg DNS Servers: 8.8.8.8 - 8.8.4.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Windows Firewall is enabled. Network Binding: ============= Ethernet: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled) Ethernet 2: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled) ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{F899F625-5B18-4251-98CF-A870C6A1C4F8}] => (Allow) C:\program files (x86)\common files\steam\steamservice.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{51FB564D-A939-4DA9-90E5-FCA7717682FA}] => (Allow) C:\windows\system32\msiexec.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{DADAF8B9-0C91-4CAF-9A18-7FED484F1C27}] => (Allow) C:\Steam\streaming_client.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{56D49455-648C-47B5-A3F8-C1DDCAF25BD7}] => (Allow) C:\Steam\steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{5B7A10AC-D847-4522-9FC3-200D5C138F94}] => (Allow) C:\Steam\steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{151FAC40-F868-43CD-BF34-61D464B11817}] => (Allow) C:\Steam\steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{7D80CEDD-9D61-4ABE-96A7-E4E69F68F708}] => (Allow) C:\steam\steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{4C6A5102-2FB6-4D08-9073-8496787E21FA}] => (Allow) C:\Tools\portable_GemistDownloader_29010\GemistDownloader.exe (HelpdeskWeb.nl) [File not signed] FirewallRules: [{48F0DDC3-A04B-4ED4-B5E5-EC0C8701FFD8}] => (Allow) D:\games\steamapps\common\f1 2019\f1_2019_dx12.exe (Codemasters Software Company Limited) [File not signed] FirewallRules: [{DDC69CDE-52C5-4FEB-956B-985BE1BA7CE6}] => (Allow) C:\program files (x86)\anvir task manager free\virustotalupload.exe () [File not signed] FirewallRules: [{F11DE16E-45CD-4A28-A94F-1CE7A3B2A3F8}] => (Allow) C:\tools\msi afterburner\rivatuner statistics server\rtss.exe => No File FirewallRules: [{AC13F0F5-6239-4263-8E50-C8EE0C9F106D}] => (Allow) C:\tools\msi afterburner\msiafterburner.exe (MICRO-STAR INTERNATIONAL CO., LTD. -> ) FirewallRules: [{BEB1A502-AFD3-4D64-9D26-87345AEBA16F}] => (Allow) C:\mc\multicrashreport.exe () [File not signed] FirewallRules: [{65574796-533F-4DB6-81E7-76E8B1FD6AD9}] => (Allow) C:\tools\hwi_640\hwinfo64.exe (Martin Malik - REALiX -> REALiX) FirewallRules: [{45DD9D79-802B-4D51-9E98-4AD162ED9FAD}] => (Allow) C:\steam\steamerrorreporter.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{7237CC41-9999-4405-8B9E-000D3B7E2405}] => (Block) C:\program files (x86)\windows media player\wmplayer.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{2C99D1E5-80BC-4769-A881-7C4E4D615406}] => (Block) C:\windows\system32\speech_onecore\common\speechruntime.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [UDP Query User{48029DA6-94AA-4111-AA60-DCDC20589FBD}F:\fontforge\bin\vcxsrv\vcxsrv.exe] => (Allow) F:\fontforge\bin\vcxsrv\vcxsrv.exe () [File not signed] FirewallRules: [TCP Query User{BE885C13-BC33-48A5-9E95-11120E61440B}F:\fontforge\bin\vcxsrv\vcxsrv.exe] => (Allow) F:\fontforge\bin\vcxsrv\vcxsrv.exe () [File not signed] FirewallRules: [{55D33BB0-81C6-455F-AAAC-709A8379F152}] => (Allow) C:\program files (x86)\teamviewer\teamviewer_service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{E7987D6C-5AB9-4FE9-A420-76D4AA708E77}] => (Allow) C:\users\j. cremers\appdata\local\packages\canonicalgrouplimited.ubuntu20.04onwindows_79rhkp1fndgsc\localstate\rootfs\usr\lib\apt\methods\http () [File not signed] FirewallRules: [{19BE985A-58DB-46D5-B79E-FFF7D694F050}] => (Allow) C:\tools\mkvtoolnix\mkvtoolnix-gui.exe (LINET Services GmbH -> ) FirewallRules: [{666F5210-5E23-4806-B5EA-C36EE20CB624}] => (Block) C:\tools\makemkv\makemkvcon64.exe (GuinpinSoft inc) [File not signed] FirewallRules: [{D3E2E41B-C355-4D6C-8FD6-AF9B191393DE}] => (Allow) C:\notepad++\updater\gup.exe (Notepad++ -> Don HO [removed]) FirewallRules: [{E1B2A25A-D765-4647-94F9-F5DD890CA805}] => (Allow) C:\Tools\NirSoft\x64\smsniff.exe (Nir Sofer -> NirSoft) FirewallRules: [{93AE18D8-2BE4-4AB4-A8B2-8C2A1DAA2CE5}] => (Allow) C:\Tools\NirSoft\x64\smsniff.exe (Nir Sofer -> NirSoft) FirewallRules: [{FB61DECC-E40C-4FAD-929C-7788FA4A3641}] => (Allow) C:\program files\internet explorer\iexplore.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{48C1CBD0-83B6-4F4C-BF6E-69E6070ED87E}] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{1E0A18C0-47AA-4456-8954-5A6258632678}] => (Allow) C:\tools\sumo\sumo.exe (KC SOFTWARES -> KC Softwares) FirewallRules: [{4EE8F709-E30B-47E8-8069-A1DB892D4814}] => (Allow) C:\Steam\steamapps\common\Black Mesa\bms.exe () [File not signed] FirewallRules: [{D7714470-C467-47D8-ADB2-0059EFFD68FF}] => (Allow) C:\Steam\steamapps\common\Black Mesa\bms.exe () [File not signed] FirewallRules: [{8024C02A-5C2E-4BC2-8417-14F074C1976C}] => (Allow) C:\steam\steamapps\common\black mesa\bms.exe () [File not signed] FirewallRules: [{CD877D68-65C6-45AE-87C7-20B23DFDDBD9}] => (Allow) C:\tools\handbrake\handbrake.exe (HandBrake Team) [File not signed] FirewallRules: [{1B724AF2-75ED-4927-BB70-7C5585DF09A2}] => (Allow) C:\Tools\Vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [{BD3F277C-6DE0-464F-BACC-C2A39DA3AF09}] => (Allow) C:\tools\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [{3635F710-A58C-44E8-94D8-F9A22793F446}] => (Block) C:\PotPlayer\PotPlayerMini64.exe (Kakao corp. -> Kakao) FirewallRules: [{35357683-5AAA-4517-A2F3-AA57573FCEDD}] => (Allow) C:\tools\cpu-z\cpuz_x64.exe (CPUID S.A.R.L.U. -> CPUID) FirewallRules: [{391B4845-9658-4ED2-BB65-259D727EE5B2}] => (Allow) C:\program files\obs-studio\bin\64bit\obs64.exe (Hugh Bailey -> OBS) FirewallRules: [{49522A4C-9F5C-4E0A-85D5-124816C12CCD}] => (Allow) C:\mc\multiupdate2.exe (Multi Commander) [File not signed] FirewallRules: [{508EE97E-3CBF-49CF-AD54-5FFC623C4352}] => (Allow) C:\tools\screentogif\screentogif.exe (Nicke Manarin -> Nicke Manarin) FirewallRules: [{D112DC09-674A-4767-B3BE-9F101FE1E376}] => (Allow) C:\mc\multiupdate.exe (Multi Commander) [File not signed] FirewallRules: [{2651D5D9-0071-449A-AFC5-80F7FC115E27}] => (Allow) C:\program files (x86)\teamviewer\teamviewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{05A7DD80-E126-4E97-9DBC-851C08BECEAF}] => (Allow) C:\Mc\MultiCommander.exe (Mathias Svensson) [File not signed] FirewallRules: [{484A21A9-93B2-4C8D-83EB-3F02BB44C46A}] => (Allow) C:\mc\multicommander.exe (Mathias Svensson) [File not signed] FirewallRules: [{FDD8C90C-0699-4984-8A4A-ECAB90EFAEC1}] => (Allow) F:\ultrasearch\ultrasearch.exe (JAM Software GmbH -> JAM Software) FirewallRules: [{67E14E2C-E2A8-4FE8-A944-9B32779FE405}] => (Allow) C:\windows\system32\backgroundtransferhost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [UDP Query User{E959775C-BFB9-4D14-8972-BA9217083ECF}C:\winamp\winamp.exe] => (Block) C:\winamp\winamp.exe (Winamp SA -> Winamp SA) FirewallRules: [TCP Query User{A619C99D-560F-4A6F-9E30-E58532407925}C:\winamp\winamp.exe] => (Block) C:\winamp\winamp.exe (Winamp SA -> Winamp SA) FirewallRules: [{3DA3A7C5-AF7D-4746-8E15-DA05F31953AD}] => (Block) D:\games\wrc 9\wrc9.exe () [File not signed] FirewallRules: [UDP Query User{A27C2BA7-A6DE-452C-B00C-48E36B546CF1}D:\games\wrc 9\wrc9.exe] => (Block) D:\games\wrc 9\wrc9.exe () [File not signed] FirewallRules: [TCP Query User{0D4CAE19-C548-4043-BAC8-512A84A18793}D:\games\wrc 9\wrc9.exe] => (Block) D:\games\wrc 9\wrc9.exe () [File not signed] FirewallRules: [{703AAF7E-9186-47AD-89DF-96BBA8FA3DD0}] => (Block) C:\games\grand theft auto v\gta5.exe (Rockstar Games) [File not signed] FirewallRules: [UDP Query User{C513397D-5655-43CE-BC43-441A5391A90F}C:\games\grand theft auto v\gta5.exe] => (Block) C:\games\grand theft auto v\gta5.exe (Rockstar Games) [File not signed] FirewallRules: [TCP Query User{279DF492-7427-4BFB-8461-6EB4717B0C99}C:\games\grand theft auto v\gta5.exe] => (Block) C:\games\grand theft auto v\gta5.exe (Rockstar Games) [File not signed] FirewallRules: [{FB7FC432-6FE0-44F2-BF98-72E75461D7C8}] => (Allow) C:\program files\superantispyware\ssupdate64.exe (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) FirewallRules: [{9862B665-6581-44B3-B47E-4DD5653A5104}] => (Allow) C:\program files\superantispyware\superantispyware.exe (Support.com Inc -> SUPERAntiSpyware) FirewallRules: [{1AB4CA17-8A66-4E25-BD2A-F20BACFC1C52}] => (Allow) G:\movie\movie.exe () [File not signed] FirewallRules: [{7F61A4AC-3564-492F-B39C-FDB436979085}] => (Allow) C:\sysinternals\procexp64.exe (Microsoft Corporation -> Sysinternals - www.sysinternals.com) FirewallRules: [{65C0B3E0-D3C7-4096-909D-BEAD11FD6950}] => (Allow) C:\windows\system32\werfault.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{B726B80D-0218-4317-A6E7-D77B620A6F87}] => (Block) D:\games\fallout 4\fallout4.exe (Bethesda Softworks) [File not signed] FirewallRules: [UDP Query User{71997D5B-CA3E-49A6-85F9-D3B46FEB174C}D:\games\fallout 4\fallout4.exe] => (Block) D:\games\fallout 4\fallout4.exe (Bethesda Softworks) [File not signed] FirewallRules: [TCP Query User{2A028152-7144-4F74-9D18-7C852261EC0E}D:\games\fallout 4\fallout4.exe] => (Block) D:\games\fallout 4\fallout4.exe (Bethesda Softworks) [File not signed] FirewallRules: [{B21DE0DB-C9CF-4D09-A782-28B42B5DF97A}] => (Block) D:\games\horizon zero dawn\horizonzerodawn.exe () [File not signed] FirewallRules: [{E59EB8B5-BDC7-4059-B54C-93813AFC2607}] => (Allow) C:\windows\immersivecontrolpanel\systemsettings.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{59B04120-44B4-4B23-AF4E-A37BA4FF80E8}] => (Allow) C:\4kvideodownloader\4kvideodownloader.exe (Open Media LLC -> Open Media LLC) FirewallRules: [{BA451700-B990-4A01-A26A-D10532ABF73C}] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{5CA332FC-0FB2-4A83-89C5-E0B797C7C020}] => (Allow) C:\putty\putty.exe (Simon Tatham -> Simon Tatham) FirewallRules: [{9C343CF2-E142-4203-8856-1D7B2C1D5993}] => (Allow) C:\windows\syswow64\werfault.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{5705BF05-18EF-4F72-9BCE-7BFFF245AD1A}] => (Allow) C:\pd\pd.exe () [File not signed] FirewallRules: [{FDA4646D-E219-4DDC-BF58-C8EE03BEE4C4}] => (Allow) C:\newsleecher\newsleecher.exe () [File not signed] FirewallRules: [{D3109B8B-7BD4-4479-9855-817D9E0521F6}] => (Allow) C:\windows\system32\net.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{DAB26396-E95B-4F54-864B-6B746717C6D1}] => (Allow) C:\android\sdk\platform-tools\adb.exe () [File not signed] FirewallRules: [{F2202C83-9969-4697-98E4-C9BDFD0C68F2}] => (Allow) C:\ultravnc\vncviewer.exe (uvnc bvba -> UltraVNC) FirewallRules: [{40A00DF7-ABC4-4BAB-99DE-E23192605A61}] => (Allow) C:\notepad++\notepad++.exe (Notepad++ -> Don HO [removed]) FirewallRules: [{24C51E7A-6895-4F15-9144-806553FC6627}] => (Allow) C:\tools\nzbget\nzbget.exe () [File not signed] FirewallRules: [{DA476EF7-A8E7-43AF-8172-DFA5EC784F9E}] => (Block) C:\program files\windows media player\wmplayer.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{4A96405B-F68B-49DB-96E4-E8F1E27A54F5}] => (Allow) C:\qbittorrent\qbittorrent.exe () [File not signed] FirewallRules: [{4E755296-4088-4D0C-86E3-9A3CD6AF6A3B}] => (Allow) F:\mirc\mirc.exe (mIRC Co. Ltd.) [File not signed] FirewallRules: [UDP Query User{02B88C6A-29A3-4ABA-9A14-96FF6B393D0C}F:\mirc\mirc.exe] => (Allow) F:\mirc\mirc.exe (mIRC Co. Ltd.) [File not signed] FirewallRules: [TCP Query User{CFB5293E-8565-4890-876C-85A3BB88C2AC}F:\mirc\mirc.exe] => (Allow) F:\mirc\mirc.exe (mIRC Co. Ltd.) [File not signed] FirewallRules: [{CF076A2C-1AFE-469E-B9B9-8AB26B6BB9E7}] => (Allow) C:\tools\hostsman\hostsxpert.exe (funkytoad.com) [File not signed] FirewallRules: [{82FD8D32-EDB1-4EBD-8D5D-F7772FF8E664}] => (Allow) C:\tools\hostsman\hm.exe (abelhadigital.com) [File not signed] FirewallRules: [{A2A2FB9D-E32C-41A3-AF51-C53771BFF9A7}] => (Block) C:\tools\extrachm.exe (ExtraToolbox) [File not signed] FirewallRules: [{DBD4BD54-3932-4FD7-A96D-4E441BC06742}] => (Allow) C:\tools\tvgids\prog\tvgids.exe () [File not signed] FirewallRules: [{2B9C14F0-8B76-439F-B308-A409582879C2}] => (Allow) C:\potplayer\potplayermini64.exe (Kakao corp. -> Kakao) FirewallRules: [{5019D725-71BC-4013-873D-E1B3A00C9A61}] => (Allow) C:\windows\explorer.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{930AEF21-BAF5-4FA7-A613-91E37358E6B1}] => (Allow) C:\virtualbox\virtualboxvm.exe (Oracle Corporation -> Oracle Corporation) FirewallRules: [{7908C31C-B32B-4E2F-B22A-255189AABBA6}] => (Allow) C:\medusa\git\mingw64\bin\git-remote-https.exe (Johannes Schindelin -> The Git Development Community) FirewallRules: [{05FBDC81-094F-4DF8-B599-7F5042E26BF9}] => (Allow) C:\windows\system32\backgroundtaskhost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{2632B232-B25B-454B-9D43-39F32948E697}] => (Allow) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{A5A8EE5F-DA27-4323-B624-CA37CE7BBA59}] => (Allow) C:\WinSCP\WinSCP.com (Martin Prikryl -> Martin Prikryl) FirewallRules: [{7DDE7EDC-CA48-4BDF-9580-F33DAAFF24E9}] => (Allow) C:\WinSCP\WinSCP.exe (Martin Prikryl -> Martin Prikryl) FirewallRules: [{A895B852-304D-4114-AA0B-043CE937D65F}] => (Allow) C:\conemu\conemu\conemuc64.exe (Open Source Developer, Maksim Moisiuk -> ConEmu-Maximus5) FirewallRules: [{56F2F1E3-0569-4B6D-AF9A-1D20009E23F0}] => (Allow) C:\winscp\winscp.exe (Martin Prikryl -> Martin Prikryl) FirewallRules: [{B190D1CE-1A2B-41B0-AED7-A16D3AE603B9}] => (Allow) C:\program files (x86)\nettime\nettimeservice.exe () [File not signed] FirewallRules: [{0910CA8D-912B-4637-BEC4-7010D802E921}] => (Block) C:\windows\system32\dashost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{39646DE8-7365-4897-897A-E20DCEA1A926}] => (Allow) C:\medusa\python\python.exe (Python Software Foundation -> Python Software Foundation) FirewallRules: [{DDAB83DF-6FDE-47B7-A520-E636044A6A5B}] => (Allow) F:\spotlite\spotlite.exe () [File not signed] FirewallRules: [{2D4B95FA-0CB8-480B-AB12-52BEDA20ACC0}] => (Allow) C:\wacup\wacup.exe (WACUP (WinAmp Community Update Project)) [File not signed] FirewallRules: [{8BDE0455-AE69-4023-938F-FC2C27EADC05}] => (Allow) C:\program files\windows sidebar\sidebar.exe (Microsoft Corporation) [File not signed] [File is in use] FirewallRules: [{85842A64-7C99-48C1-AF79-42386E3CBD16}] => (Allow) C:\windows\system32\wermgr.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{165B2301-DC6D-4531-AAB4-7E8E6F93531B}] => (Allow) C:\thunderbird\thunderbird.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{AFCAA72A-29AE-4C08-A1F1-659F7A33F420}] => (Allow) C:\Program Files\Malwarebytes\Windows Firewall Control\wfc.exe (Malwarebytes Inc -> Malwarebytes) FirewallRules: [{ED07557F-583D-4DCA-BD82-3272EC6F6561}] => (Allow) C:\windows\system32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{DB8823BA-C75D-4569-A879-A154B6B269A6}] => (Block) C:\bcb6\bin\bcb.exe (Borland Software Corporation) [File not signed] FirewallRules: [{3C0A9AFA-B1A6-4915-AFAB-32C05534FFE3}] => (Allow) C:\program files (x86)\microsoft\edgeupdate\microsoftedgeupdate.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{8C1C3EEE-CC2A-4F96-9507-19AE4E00094A}] => (Block) C:\windows\system32\cleanmgr.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{AAD2ECFE-8098-4B38-ADC9-9D0FF864A3C2}] => (Allow) C:\tools\rarmaradio\app\rarmaradio\rarmaradio.exe (Raimersoft) [File not signed] FirewallRules: [{AAA2995F-ECAF-4A0A-B25B-E1F2382818A1}] => (Allow) C:\tools\radiosure\radiosure.exe (TheBestWare Studio) [File not signed] FirewallRules: [{0670B9BD-AF37-4263-A2A6-30B87124F188}] => (Allow) C:\tools\rarmaradio\rarmaradio.exe (Raimersoft) [File not signed] FirewallRules: [{C305470E-5B88-43DD-B41F-4A8C8592FD3F}] => (Allow) C:\UltraVNC\vncviewer.exe (uvnc bvba -> UltraVNC) FirewallRules: [{89A721EE-9677-44F1-85A7-55D0927F2279}] => (Allow) C:\UltraVNC\vncviewer.exe (uvnc bvba -> UltraVNC) FirewallRules: [{17AB464A-B812-4855-A1C9-BCBBE0CEFF88}] => (Allow) F:\firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{17FBB265-A44E-4635-B898-A79A599EC8B2}] => (Allow) F:\firefox\pingsender.exe (Mozilla Corporation -> Mozilla Foundation) FirewallRules: [{2116C913-EB20-41CB-A7BC-DF8785AC96DF}] => (Allow) C:\steam\steamapps\common\dirt rally\drt.exe (Codemasters Software Company Limited) [File not signed] FirewallRules: [{5992DCF1-0F7A-4C61-B8CD-7DB879A9245C}] => (Allow) C:\program files\guillemot\tools\giwebupdater.exe (Guillemot Recherche et Développement, Inc -> Guillemot Inc.) FirewallRules: [{8741F11A-5D72-4FDE-9378-C866E178C1A0}] => (Allow) C:\steam\steamapps\common\wrc 7\wrc7.exe () [File not signed] FirewallRules: [{043AD2A1-0DB6-4CB3-8653-0FAE568046F4}] => (Allow) C:\winamp\winamp.exe (Winamp SA -> Winamp SA) FirewallRules: [{700144E4-E64E-4D91-990B-0D6025A7134A}] => (Allow) C:\Winamp\winamp.exe (Winamp SA -> Winamp SA) FirewallRules: [{8D6C1B76-C2D0-4D56-B188-DCD1BF0E4A31}] => (Allow) C:\steam\steamerrorreporter64.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{F5F36C08-FE5E-46E8-935F-90CAAAF5A552}] => (Allow) F:\tor browser\browser\torbrowser\tor\tor.exe () [File not signed] FirewallRules: [TCP Query User{7E74CB27-B5DB-4543-BD3B-D964298F83B8}C:\tools\dbeaver\dbeaver.exe] => (Allow) C:\tools\dbeaver\dbeaver.exe (DBeaver Corp -> ) FirewallRules: [UDP Query User{AD20DCC8-61B8-4AE0-93CD-6B1E7CD3E11A}C:\tools\dbeaver\dbeaver.exe] => (Allow) C:\tools\dbeaver\dbeaver.exe (DBeaver Corp -> ) FirewallRules: [{A9C6EB77-E613-465E-840D-9DBCA3E57DA7}] => (Allow) C:\tools\dbeaver\dbeaver.exe (DBeaver Corp -> ) FirewallRules: [{39D74B0E-1AB0-496B-99C5-B0774E4E37C4}] => (Allow) C:\jean\putty.exe (Simon Tatham) [File not signed] FirewallRules: [{C4D52272-D8E9-4E6F-9BD6-DC7C3DFEDA80}] => (Allow) C:\pd\ssl\testssl.exe () [File not signed] FirewallRules: [{6A8EBD31-1B27-4F9E-AB8F-63F87C4DD741}] => (Allow) C:\oracle\oracle.exe () [File not signed] FirewallRules: [{2405DCCE-5870-4B03-B901-DFC164A0A250}] => (Allow) F:\calibre\calibre\calibre.exe (Kovid Goyal -> ) FirewallRules: [TCP Query User{14139052-B4CD-46CF-9960-8655B90FA0D7}D:\games\forza horizon 5\forzahorizon5.exe] => (Block) D:\games\forza horizon 5\forzahorizon5.exe () [File not signed] FirewallRules: [UDP Query User{42F9BEC6-8A42-4505-82C6-2719855A8A50}D:\games\forza horizon 5\forzahorizon5.exe] => (Block) D:\games\forza horizon 5\forzahorizon5.exe () [File not signed] FirewallRules: [{3D72CEB9-A335-4E5F-8B13-A14EA06D8DC6}] => (Block) D:\games\forza horizon 5\forzahorizon5.exe () [File not signed] FirewallRules: [{CE672D62-F3D6-42BD-B1EC-A014569F211C}] => (Allow) D:\games\forza horizon 5\webview2\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{8945A26E-E95E-4660-8B26-E5169AC703C0}] => (Allow) C:\program files (x86)\microsoft\skype for desktop\skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{ED307686-EA51-4430-8ADB-7B5EB5235B9E}] => (Allow) C:\sysinternals\autoruns64.exe (Microsoft Corporation -> Sysinternals - www.sysinternals.com) FirewallRules: [{8641AB09-0A6C-449B-A2B0-96718F4A2F6A}] => (Allow) C:\tools\anvir\anvir.exe (Ilya Kheifets -> AnVir Software) FirewallRules: [{D35305C9-DDC4-4B5C-9F8B-42417E874B3A}] => (Allow) C:\tools\anvir\virustotalupload.exe () [File not signed] FirewallRules: [{C4671AE4-F72D-4499-ABA6-96F7682E445A}] => (Allow) C:\qBittorrent\qbittorrent.exe () [File not signed] FirewallRules: [{D4F1DE60-709F-4722-8FF0-1630A9B7C57D}] => (Allow) C:\qBittorrent\qbittorrent.exe () [File not signed] FirewallRules: [{88FB7382-3BF6-4534-9044-B874F96979E8}] => (Allow) C:\program files\common files\logishrd\unifying\lu\logitechupdate.exe (Logitech -> Logitech, Inc.) FirewallRules: [{609EDE85-B854-4BE4-83DD-26A9CF08A55E}] => (Allow) C:\tools\foobar2000\foobar2000.exe (Piotr Pawlowski) [File not signed] FirewallRules: [{BFCF3AE8-E59C-4858-ADE3-223FB9A05CFD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{A4E69297-54A2-4BBC-8442-95F5010AB0A9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{C9172D7B-5819-4954-A727-6F1B7F153F28}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{2C17227B-5E03-4C6E-AAB6-B371824115DF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{B1BD50BF-01A9-4C87-8631-B1AF9521BF32}] => (Allow) C:\windows\system32\quickassist.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{628297ED-BC60-4DA3-B942-F5A13AC7EE5A}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{1F095FA4-B315-46B0-AD88-C08B1E804E53}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{DD7C9099-90D6-46FE-8956-DDFDEA3FBA7E}] => (Allow) C:\Steam\steamapps\common\WRC 10 FIA World Rally Championship\WRC10.exe () [File not signed] FirewallRules: [{1F9A75DF-8132-4814-A7A5-1203F0E79403}] => (Allow) C:\Steam\steamapps\common\WRC 10 FIA World Rally Championship\WRC10.exe () [File not signed] FirewallRules: [{0BD6211D-C5EA-4D55-97FB-C64446729786}] => (Allow) C:\steam\steamapps\common\wrc 10 fia world rally championship\wrc10.exe () [File not signed] FirewallRules: [{E0E965CB-7490-49B7-BD0B-F8018EBC57A3}] => (Allow) C:\potplayer\potscreensaver64.scr (Kakao corp. -> ) FirewallRules: [{02D718CD-657A-475B-B0CA-0B96893A6446}] => (Allow) C:\potplayer\potplayersetup64.exe (Kakao corp. -> Kakao) FirewallRules: [{B556A181-68ED-4D49-9946-BF23F9FA2333}] => (Allow) F:\calibre\calibre.exe (Kovid Goyal -> ) FirewallRules: [{11B2E4E7-E1D4-466F-9E4D-67093738F2E6}] => (Allow) F:\rockbox\rockboxutility.exe () [File not signed] FirewallRules: [{57794574-7B21-4F46-B3E3-90CFA09A0195}] => (Allow) C:\windows\system32\driverstore\filerepository\nv_dispig.inf_amd64_31a2adf8c49e7799\display.nvcontainer\nvdisplay.container.exe => No File FirewallRules: [{22678FBB-6475-45B3-A710-37F6395E2AD8}] => (Block) F:\mkvtoolnix\mkvtoolnix-gui.exe () [File not signed] FirewallRules: [{9390770B-0C4F-4804-9D85-F1FAE326B8CC}] => (Allow) C:\program files\obs-studio\obs-plugins\64bit\obs-browser-page.exe (Hugh Bailey -> ) FirewallRules: [{556ABE66-A0F3-4169-8C9B-D9F73CE04B8C}] => (Allow) C:\tools\flameshot\flameshot.exe (SignPath Foundation -> The flameshot Org.) FirewallRules: [{AD047D9B-55BC-4F08-A8DF-070A3F89B017}] => (Allow) C:\qt\maintenancetool.exe () [File not signed] FirewallRules: [{F9DCEFF0-9F77-4F6F-9AE8-9404C5B038CD}] => (Allow) C:\android studio\bin\studio64.exe (Google LLC -> JetBrains s.r.o.) FirewallRules: [{C88373CC-E64F-4F06-9ED7-C498317408CB}] => (Block) C:\reaper\reaper.exe (Cockos Incorporated -> Cockos Incorporated) [File not signed] FirewallRules: [{5B542817-E2E3-458B-996F-2CA0759F5B5B}] => (Allow) C:\program files (x86)\steinberg\download assistant\steinberg download assistant.exe (Steinberg Media Technologies GmbH -> ) FirewallRules: [{BACEB873-BC02-4CE3-923D-FB2564AAC0B8}] => (Allow) C:\program files\steinberg\cubase le ai elements 11\cubase le ai elements 11.exe (Steinberg Media Technologies GmbH -> Steinberg Media Technologies) FirewallRules: [{70C32BEC-3548-45A9-AAC9-E2ECBEDE419F}] => (Block) C:\cubase 5\kontakt\kontakt\kontakt.exe (Native Instruments GmbH -> Native Instruments GmbH) [File not signed] FirewallRules: [{2992EF08-D880-405B-AAD7-488FBE4686EB}] => (Allow) C:\program files\native instruments\native access\native access.exe (Native Instruments GmbH -> Native Instruments GmbH) FirewallRules: [{6C91E40D-3EA9-4440-9859-B2E6293B8486}] => (Allow) C:\program files\native instruments\guitar rig 6\guitar rig 6.exe (Native Instruments GmbH -> Native Instruments GmbH) FirewallRules: [{9AF55E6C-2F8C-4233-A607-A3C954C5A4B3}] => (Allow) C:\windows\system32\devicecensus.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{4E1DEE7D-2811-4612-A413-6C553A351493}] => (Block) powershell.exe => No File FirewallRules: [{B6907DC7-1D34-49B1-B56C-7267E10B25B1}] => (Allow) C:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{49B508A5-7243-451A-BC70-7A7B74881BCA}] => (Allow) C:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{4BDBB5BA-0516-40CC-8215-C9D9865B296C}] => (Allow) C:\steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{3D169FD3-2B77-4DB1-81DE-DAE6F11E7BA3}] => (Allow) C:\users\j. cremers\appdata\local\vivaldi\application\update_notifier.exe => No File FirewallRules: [{2902A9CC-A1A5-4768-8E41-32C2042EB54C}] => (Allow) C:\programdata\microsoft\windows defender\platform\4.18.2203.5-0\mpcmdrun.exe (Microsoft Windows Publisher -> Microsoft Corporation) FirewallRules: [{D141FC89-6E7E-4215-BA5C-A87A4AE6FD40}] => (Allow) C:\windows\system32\compattelrunner.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{26A02F8B-57DA-4E4F-B415-181FEAC7100E}] => (Allow) C:\windows\system32\sihclient.exe (Microsoft Windows Publisher -> Microsoft Corporation) FirewallRules: [{47911373-2F6F-492B-84FA-AC4F0AED18C0}] => (Allow) C:\program files\greenshot\greenshot.exe => No File FirewallRules: [{344D783A-798A-48D0-B96F-30B8174F6E5E}] => (Allow) C:\Users\J. Cremers\AppData\Local\Vivaldi\Application\vivaldi.exe (Vivaldi Technologies AS -> Vivaldi Technologies AS) FirewallRules: [{BBC52A7D-34F1-4891-BB59-A6365ED43711}] => (Allow) C:\windows\system32\taskhostw.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{E2686EBC-5170-4505-8B7D-BB582375D64D}] => (Allow) C:\programdata\microsoft\windows defender\platform\4.18.2203.5-0\msmpeng.exe (Microsoft Windows Publisher -> Microsoft Corporation) FirewallRules: [{2B930E00-1B2C-47A6-90AE-23D639204022}] => (Allow) C:\windows\system32\mousocoreworker.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{EF618612-70B2-4FC4-BE32-D018BA5E997B}] => (Allow) C:\users\j. cremers\appdata\roaming\4kdownload.com\4k video downloader\4k video downloader\softwareupdate\cfb4ff8b-2e65-4bd9-ab45-56cc64bd9c7b\4kvideodownloader\4kvideodownloader.exe => No File FirewallRules: [{F1E5A001-C8E1-4449-8E84-C414E5B7E833}] => (Allow) C:\4kvideodownloader\crashpad_handler.exe (Open Media LLC -> ) FirewallRules: [{EE9FAE19-90FA-4696-B761-982B8A927F95}] => (Allow) C:\windows\syswow64\msiexec.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{E7CCDAEE-3429-4B42-849A-8331E2D2E2AE}] => (Allow) C:\sysinternals\autoruns.exe (Microsoft Corporation -> Sysinternals - www.sysinternals.com) FirewallRules: [{DFD2C3E2-0C7E-4000-9A62-8A76F77C2242}] => (Allow) C:\program files (x86)\elicenser\elcc\elcc.exe (Steinberg Media Technologies GmbH -> Steinberg Media Technologies GmbH) FirewallRules: [TCP Query User{E3DBF5A9-4BB3-4E64-911E-8FFA196E8120}D:\games\need for speed heat\needforspeedheat.exe] => (Block) D:\games\need for speed heat\needforspeedheat.exe => No File FirewallRules: [UDP Query User{64CED2CE-AB28-4527-88EA-CE5D5ECFAB71}D:\games\need for speed heat\needforspeedheat.exe] => (Block) D:\games\need for speed heat\needforspeedheat.exe => No File FirewallRules: [{8D820A7B-FEE2-4F57-BC22-01A2238AB5F9}] => (Allow) C:\program files\sitala\sitala.exe (Directed Edge, Inc. -> Directed Edge, Inc.) FirewallRules: [{01E3970C-9AE5-4DD1-A426-DC666DAD5E87}] => (Allow) C:\tools\whocrashed\whocrashedex.exe (Daniel Terhell -> Resplendence Software Projects) FirewallRules: [{6CD05D32-6ECA-4250-997F-F8FE751B5824}] => (Allow) C:\temp\setup.exe => No File FirewallRules: [{0668E387-1307-4675-A9BD-C5356345D4EE}] => (Allow) C:\windows\system32\driverstore\filerepository\nv_dispig.inf_amd64_647b4244e991951b\display.nvcontainer\nvdisplay.container.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{B1C20720-67C2-4D53-80AD-BF661ED9731B}] => (Allow) C:\windows\system32\driverstore\filerepository\nv_dispig.inf_amd64_d5d5b9f929f4cb65\display.nvcontainer\nvdisplay.container.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{14B9E172-4296-4919-9328-0216009A17CE}] => (Allow) D:\in\frst64.exe (Farbar) [File not signed] ==================== Restore Points ========================= 01-06-2022 18:54:42 Installed Sitala 04-06-2022 19:24:33 Installed Basic FX Suite 12-06-2022 14:24:37 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============ Name: PCI Device Description: PCI Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: High Definition Audio Device Description: High Definition Audio Device Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: HdAudAddService Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ======================== Application errors: ================== Error: (06/14/2022 01:55:35 PM) (Source: tmpid) (EventID: 2) (User: ) Description: CDIEffectDriver::CDIEffectDriver() CoInitialize() FAILED, ret:0x80010106, GLE:0, proc:C:\Steam\steamapps\common\WRC 10 FIA World Rally Championship\WRC10.exe Error: (06/13/2022 08:27:31 PM) (Source: tmpid) (EventID: 2) (User: ) Description: CDIEffectDriver::CDIEffectDriver() CoInitialize() FAILED, ret:0x80010106, GLE:0, proc:C:\Steam\steamapps\common\WRC 10 FIA World Rally Championship\WRC10.exe Error: (06/12/2022 05:54:14 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: ) Description: The storage optimizer couldn't complete retrim on Apps (F:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A) Error: (06/12/2022 05:53:51 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: ) Description: The storage optimizer couldn't complete retrim on Data (D:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A) Error: (06/12/2022 05:53:46 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: ) Description: The storage optimizer couldn't complete retrim on Code (G:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A) Error: (06/12/2022 05:37:16 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: ) Description: The storage optimizer couldn't complete retrim on Apps (F:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A) Error: (06/12/2022 05:36:53 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: ) Description: The storage optimizer couldn't complete retrim on Data (D:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A) Error: (06/12/2022 05:36:48 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: ) Description: The storage optimizer couldn't complete retrim on Code (G:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A) System errors: ============= Error: (06/15/2022 10:56:03 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Windows Camera Frame Server service terminated with the following error: %%2147943950 = The specified task name is invalid. Error: (06/15/2022 10:55:55 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The FrameServer service terminated with the following error: %%2147943950 = The specified task name is invalid. Error: (06/15/2022 10:55:47 AM) (Source: VBoxNetLwf) (EventID: 12) (User: ) Description: The driver detected an internal driver error on \Device\VBoxNetLwf. Error: (06/15/2022 07:24:27 AM) (Source: VBoxNetLwf) (EventID: 12) (User: ) Description: The driver detected an internal driver error on \Device\VBoxNetLwf. Error: (06/14/2022 10:50:43 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Windows Camera Frame Server service terminated with the following error: %%2147943950 = The specified task name is invalid. Error: (06/14/2022 10:50:32 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The FrameServer service terminated with the following error: %%2147943950 = The specified task name is invalid. Error: (06/14/2022 10:50:24 PM) (Source: VBoxNetLwf) (EventID: 12) (User: ) Description: The driver detected an internal driver error on \Device\VBoxNetLwf. Error: (06/14/2022 02:32:15 PM) (Source: VBoxNetLwf) (EventID: 12) (User: ) Description: The driver detected an internal driver error on \Device\VBoxNetLwf. Windows Defender: ================ Date: 2022-06-15 08:36:20 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2022-06-15 08:11:08 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2022-06-14 08:52:32 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2022-06-13 08:26:47 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2022-06-12 08:08:30 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan  ==================== Memory info =========================== BIOS: American Megatrends Inc. P3.60 07/31/2019 Motherboard: ASRock B450 Pro4 Processor: AMD Ryzen 7 3700X 8-Core Processor Percentage of memory in use: 43% Total physical RAM: 16313.79 MB Available physical RAM: 9140.61 MB Total Virtual: 17337.79 MB Available Virtual: 8040.8 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:953.3 GB) (Free:368.24 GB) (Model: SSDPR-CX400-01T) NTFS Drive d: (Data) (Fixed) (Total:3726.01 GB) (Free:2282.78 GB) (Model: TOSHIBA HDWE140) NTFS Drive e: (Usb) (Fixed) (Total:3725.99 GB) (Free:565.84 GB) (Model: WD Elements 25A3 USB Device) NTFS Drive f: (Apps) (Fixed) (Total:1863 GB) (Free:943.23 GB) (Model: ST2000DM001-1ER164) NTFS Drive g: (Code) (Fixed) (Total:931.51 GB) (Free:285.21 GB) (Model: ST1000DM003-1ER162) NTFS \\?\Volume{d259da6f-0000-0000-0000-100000000000}\ (Door systeem gereserveerd) (Fixed) (Total:0.57 GB) (Free:0.11 GB) NTFS ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: BED162C8) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ========================================================== Disk: 1 (MBR Code: Windows 7/8/10) (Size: 3726 GB) (Disk ID: 0C84C908) Partition: GPT. ========================================================== Disk: 2 (MBR Code: Windows 7/8/10) (Size: 953.9 GB) (Disk ID: D259DA6F) Partition 1: (Active) - (Size=579 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=953.3 GB) - (Type=07 NTFS) ========================================================== Disk: 3 (Protective MBR) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ========================================================== Disk: 4 (Size: 3726 GB) (Disk ID: 16F2A91F) Partition: GPT. ==================== End of Addition.txt =======================