Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-08-2022 Ran by [removed] (26-09-2022 10:21:53) Running from C:\Users\[removed]\Downloads Microsoft Windows 10 Home Version 21H2 19044.2006 (X64) (2022-03-18 12:29:50) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-389301807-2965812550-3391386861-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-389301807-2965812550-3391386861-503 - Limited - Disabled) Guest (S-1-5-21-389301807-2965812550-3391386861-501 - Limited - Disabled) Jeff GS1 MK3 (S-1-5-21-389301807-2965812550-3391386861-1001 - Administrator - Enabled) => C:\Users\Jeff GS1 MK3 WDAGUtilityAccount (S-1-5-21-389301807-2965812550-3391386861-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 21.07 (x64) (HKLM\...\7-Zip) (Version: 21.07 - Igor Pavlov) Amazon Kindle (HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\Amazon Kindle) (Version: 1.29.0.58059 - Amazon) AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 4.03.03.431 - Advanced Micro Devices, Inc.) AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.130 - Advanced Micro Devices, Inc.) Hidden AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.87 - Advanced Micro Devices, Inc.) Hidden AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.18.0.0 - Advanced Micro Devices, Inc.) Hidden AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 7.0.4.4 - Advanced Micro Devices, Inc.) Hidden AMD Ryzen Master (HKLM\...\{02247819-03CD-414E-AC8D-FD518BFBA445}) (Version: 2.8.0.1937 - Advanced Micro Devices, Inc.) Hidden AMD Ryzen Master (HKLM\...\AMD Ryzen Master) (Version: 2.8.0.1937 - Advanced Micro Devices, Inc.) AMD SBxxx SMBus Driver (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden AMD_Chipset_Drivers (HKLM-x32\...\{0fd12917-eb35-466f-b411-02c45a8a505d}) (Version: 4.03.03.431 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 6.04 - Piriform) Color Cop 5.4.3 (HKLM-x32\...\Color Cop_is1) (Version: - Jay Prall) Documentation Manager (HKLM\...\{2E843C78-FE5B-446C-A2AC-DE311FE1D78A}) (Version: 22.140.0.3 - Intel Corporation) Hidden Eraser 6.2.0.2993 (HKLM\...\{82602EDA-27BE-4358-AB3A-BD09EA51A1E6}) (Version: 6.2.2993 - The Eraser Project) FileMarker.NET Free (HKLM\...\{A5A0E0B5-578C-43CE-B201-1C01A0388DA9}_is1) (Version: 2.1 - ArcticLine Software) Foxit PhantomPDF Business (HKLM-x32\...\{8A601904-4113-40FE-9DCC-7A38CE1A8032}) (Version: 7.0.6.1126 - Foxit Software Inc.) Genshin Impact (HKLM\...\Genshin Impact) (Version: 2.16.1.0 - COGNOSPHERE PTE. LTD.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 105.0.5195.127 - Google LLC) Intel Driver && Support Assistant (HKLM-x32\...\{87B5A0A1-22D3-4A05-8310-58CCEB63EF93}) (Version: 22.6.39.9 - Intel) Hidden Intel(R) Computing Improvement Program (HKLM\...\{D17293BC-1678-4281-B94E-DBCF66AE7611}) (Version: 2.4.08919 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000140-0220-1033-84C8-B8D95FA3C8C3}) (Version: 22.140.0.4 - Intel Corporation) Intel® Driver & Support Assistant (HKLM-x32\...\{9806ff29-547d-4c1a-8db0-12c1fc51c8d9}) (Version: 22.6.39.9 - Intel) Intel® Software Installer (HKLM-x32\...\{b3bbf46b-6ffd-4f54-8d1f-26206cfe1739}) (Version: 22.140.0.3 - Intel Corporation) Hidden Java 8 Update 341 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180341F0}) (Version: 8.0.3410.10 - Oracle Corporation) Logi Bolt (HKLM\...\LogiBolt) (Version: 1.2.6024.0 - Logi) Logitech Options (HKLM\...\LogiOptions) (Version: 9.70.68 - Logitech) Logitech SetPoint 6.70 (HKLM\...\sp6) (Version: 6.70.55 - Logitech) Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech) Macro Recorder 5.8.1 (HKLM-x32\...\Macro Recorder_is1) (Version: 5.8.1 - Jitbit Software) Malwarebytes version 4.5.14.210 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.14.210 - Malwarebytes) MarkText 0.17.1 (HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\80b8d59a-8e25-5f52-8f55-48f4c6ccbd23) (Version: 0.17.1 - Jocs) Microsoft .NET Core Host - 3.1.28 (x64) (HKLM\...\{26ECE92F-518E-40AF-9108-7B7B444A46DE}) (Version: 24.112.31513 - Microsoft Corporation) Hidden Microsoft .NET Core Host FX Resolver - 3.1.28 (x64) (HKLM\...\{CDEA72F4-1367-4E0A-AC5F-0EBAF7C6825A}) (Version: 24.112.31513 - Microsoft Corporation) Hidden Microsoft .NET Core Runtime - 3.1.28 (x64) (HKLM\...\{3691148D-EF42-4812-8956-AE11FC413B8D}) (Version: 24.112.31513 - Microsoft Corporation) Hidden Microsoft .NET Core Runtime - 3.1.28 (x64) (HKLM-x32\...\{231e3b76-4d0f-4e60-9d69-f11c9c448630}) (Version: 3.1.28.31513 - Microsoft Corporation) Microsoft 365 Apps for enterprise - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.15601.20148 - Microsoft Corporation) Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 105.0.1343.50 - Microsoft Corporation) Microsoft GameInput (HKLM-x32\...\{A9CFD6A1-C0D3-7F37-C220-8B104867EF15}) (Version: 10.1.22621.1011 - Microsoft Corporation) Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 22.181.0828.0002 - Microsoft Corporation) Microsoft Teams (HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\Teams) (Version: 1.4.00.32771 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.32.31332 (HKLM-x32\...\{3746f21b-c990-4045-bb33-1cf98cff7a68}) (Version: 14.32.31332.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.32.31332 (HKLM-x32\...\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}) (Version: 14.32.31332.0 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332 (HKLM\...\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}) (Version: 14.32.31332 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332 (HKLM\...\{3407B900-37F5-4CC2-B612-5CD5D580A163}) (Version: 14.32.31332 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Additional Runtime - 14.32.31332 (HKLM-x32\...\{8972AC25-452E-4FFE-945A-EB9E28C20322}) (Version: 14.32.31332 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.32.31332 (HKLM-x32\...\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}) (Version: 14.32.31332 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{7C0242A3-8B66-35D1-9FE0-13B426ACB609}) (Version: 10.0.60729 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.60724 - Microsoft Corporation) Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 105.0.1 (x64 en-US)) (Version: 105.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 98.0.1 - Mozilla) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 8.3.3 - Notepad++ Team) Notion 2.0.29 (HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\fcdf0d7f-424b-5f10-a1c7-a8f643f21adf) (Version: 2.0.29 - Notion Labs, Inc) NVIDIA FrameView SDK 1.2.7521.31103277 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.2.7521.31103277 - NVIDIA Corporation) NVIDIA GeForce Experience 3.25.1.27 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.25.1.27 - NVIDIA Corporation) NVIDIA Graphics Driver 512.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 512.95 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.39.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.39.3 - NVIDIA Corporation) NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.15601.20064 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.15601.20148 - Microsoft Corporation) Hidden Opera GX Stable 90.0.4480.117 (HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\Opera GX 90.0.4480.117) (Version: 90.0.4480.117 - Opera Software) Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 3.0.0.0 - Advanced Micro Devices, Inc.) Hidden Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.58.822 - Rockstar Games) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.1.3.7 - Rockstar Games) RuneLite (HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\RuneLite Launcher_is1) (Version: 2.4.2 - RuneLite) Slack (HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\slack) (Version: 4.28.171 - Slack Technologies Inc.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.4.0.32771 - Microsoft Corporation) TP-Link UB500 Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 1015.1016.1016.210427 - TP-LINK TECHNOLOGIES CO., LTD.) Twinkle Tray 1.13.11 (HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\5cfff8db-b587-542d-a90b-51d2e2742b09) (Version: 1.13.11 - Xander Frangos) Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 50.0 - Ubisoft) VLC media player (HKLM\...\VLC media player) (Version: 3.0.17.3 - VideoLAN) Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation) WizTree v4.08 (HKLM\...\WizTree_is1) (Version: 4.08 - Antibody Software) Packages: ========= Cinebench -> C:\Program Files\WindowsApps\MAXONComputerGmbH.Cinebench_23.2.0.0_x64__rsne5bsk8s7tj [2022-07-13] (MAXON Computer GmbH) Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.19.3004.0_x64__8wekyb3d8bbwe [2022-09-22] (Microsoft Studios) Minecraft Launcher -> C:\Program Files\WindowsApps\Microsoft.4297127D64EC6_1.1.28.0_x64__8wekyb3d8bbwe [2022-08-27] (Microsoft Studios) Minecraft: Java Edition -> C:\Program Files\WindowsApps\Microsoft.MinecraftJavaEdition_1.0.5.0_x64__8wekyb3d8bbwe [2022-07-23] (Microsoft Studios) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-05-31] (NVIDIA Corp.) Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2022-03-19] (Microsoft Corporation) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.11.217.0_x64__dt26b99r8h8gj [2022-03-18] (Realtek Semiconductor Corp) Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.874.0_x86__zpdnekdrzrea0 [2022-09-22] (Spotify AB) [Startup Task] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-389301807-2965812550-3391386861-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Jeff GS1 MK3\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.21264.3\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-389301807-2965812550-3391386861-1001_Classes\CLSID\{80FF85DE-A5CD-4359-9A85-D916077B04DC}\InprocServer32 -> C:\Program Files\Mozilla Firefox\notificationserver.dll (Mozilla Corporation -> Mozilla Foundation) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2022-03-14] (Notepad++ -> ) ContextMenuHandlers1: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2021-09-25] (Heidi Computers Ltd -> The Eraser Project) ContextMenuHandlers1: [File Marker] -> {B70B7A24-5180-4092-B3BA-6266F914C053} => C:\Program Files (x86)\FileMarker.NET\FileMarkerShlExt64.dll [2019-07-20] (ArcticLine Software -> ArcticLine Software) ContextMenuHandlers1: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2014-11-17] (Foxit Software Incorporated -> Foxit Software Inc.) ContextMenuHandlers2: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2021-09-25] (Heidi Computers Ltd -> The Eraser Project) ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2021-09-25] (Heidi Computers Ltd -> The Eraser Project) ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-22] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers5: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2021-09-25] (Heidi Computers Ltd -> The Eraser Project) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_647b4244e991951b\nvshext.dll [2022-05-20] (Nvidia Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2021-12-26] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2021-09-25] (Heidi Computers Ltd -> The Eraser Project) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2022-09-26 08:49 - 2022-09-26 08:49 - 000663552 _____ () [File not signed] \\?\C:\Users\Jeff GS1 MK3\AppData\Local\Temp\068cce89-944d-4f1c-bcaf-f627091c43e0.tmp.node 2022-09-26 08:49 - 2022-09-26 08:49 - 001124864 _____ () [File not signed] \\?\C:\Users\Jeff GS1 MK3\AppData\Local\Temp\184397bf-c644-4af5-968f-c6ba7d7ceca1.tmp.node 2022-09-26 08:49 - 2022-09-26 08:49 - 000592384 _____ () [File not signed] \\?\C:\Users\Jeff GS1 MK3\AppData\Local\Temp\930d73a7-0206-40de-9dfa-2e56c1fc1e11.tmp.node 2022-09-26 08:49 - 2022-09-26 08:49 - 000663552 _____ () [File not signed] \\?\C:\Users\Jeff GS1 MK3\AppData\Local\Temp\bf47bc7b-c959-4a59-934d-11a14fd80bc1.tmp.node 2022-09-26 08:49 - 2022-09-26 08:49 - 000573440 _____ () [File not signed] \\?\C:\Users\Jeff GS1 MK3\AppData\Local\Temp\d72518c2-f713-4df4-8b97-c6cac5aa3eee.tmp.node 2022-09-26 08:49 - 2022-09-26 08:49 - 000619520 _____ () [File not signed] \\?\C:\Users\Jeff GS1 MK3\AppData\Local\Temp\f5d4ec26-9a66-43c2-9741-c07756507914.tmp.node 2022-09-26 08:49 - 2022-09-26 08:49 - 000581120 _____ () [File not signed] \\?\C:\Users\Jeff GS1 MK3\AppData\Local\Temp\fa7a6fca-440d-4624-a7c0-4fc6689ee9da.tmp.node 2022-08-09 15:02 - 2022-08-09 15:02 - 005998080 _____ () [File not signed] C:\Program Files (x86)\Intel\Driver and Support Assistant\irmfuu_module_win32.dll 2022-04-16 13:10 - 2021-12-01 14:35 - 002679296 _____ () [File not signed] C:\Users\Jeff GS1 MK3\AppData\Local\Programs\twinkle-tray\ffmpeg.dll 2022-04-16 13:10 - 2021-12-01 14:35 - 000439296 _____ () [File not signed] C:\Users\Jeff GS1 MK3\AppData\Local\Programs\twinkle-tray\libegl.dll 2022-04-16 13:10 - 2021-12-01 14:35 - 007938560 _____ () [File not signed] C:\Users\Jeff GS1 MK3\AppData\Local\Programs\twinkle-tray\libglesv2.dll 2022-03-18 12:45 - 2021-12-26 10:00 - 000093696 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll 2021-05-21 14:04 - 2021-05-21 14:04 - 000130048 _____ (Sam Grogan) [File not signed] [File is in use] C:\Program Files (x86)\Intel\Driver and Support Assistant\NotifyIconWin32.dll 2022-05-05 17:44 - 2022-05-05 17:44 - 002122240 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2022-08-06] (Microsoft Corporation -> Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_341\bin\ssv.dll [2022-08-12] (Oracle America, Inc. -> Oracle Corporation) BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2020-11-20] (Logitech Inc -> Logitech, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_341\bin\jp2ssv.dll [2022-08-12] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2022-08-06] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2020-11-20] (Logitech Inc -> Logitech, Inc.) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-09-06] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-09-06] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-09-06] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-09-06] (Microsoft Corporation -> Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-09-06] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-09-06] (Microsoft Corporation -> Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-09-06] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-09-06] (Microsoft Corporation -> Microsoft Corporation) (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\sharepoint.com -> hxxps://omegatherapeutics-files.sharepoint.com ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-12-07 05:14 - 2019-12-07 05:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files\dotnet\ HKU\S-1-5-21-389301807-2965812550-3391386861-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jeff GS1 MK3\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\wallpaper-mania.com_High_resolution_wallpaper_background_ID_77701481557-1.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run: => "LogiBolt" HKLM\...\StartupApproved\Run: => "Logitech Download Assistant" HKLM\...\StartupApproved\Run: => "RtkAudUService" HKLM\...\StartupApproved\Run: => "Eraser" HKLM\...\StartupApproved\Run32: => "Intel Driver & Support Assistant" HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\StartupApproved\Run: => "LogiBolt" HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\StartupApproved\Run: => "Synapse3" HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\StartupApproved\Run: => "com.squirrel.Teams.Teams" HKU\S-1-5-21-389301807-2965812550-3391386861-1001\...\StartupApproved\Run: => "Opera GX Browser Assistant" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{363D6620-8959-4A95-A4C5-B5C4C224A2A1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{2AFA39F9-EA44-462E-AA07-102750FEF3DB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{790A163B-4160-4577-A583-6179E08DA47C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{AA3B8644-17BE-4F71-BE7B-BA18F68FEBE3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{431BF8CA-62FE-40C5-84F9-CDBF3B69A146}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{041EA4B6-B623-4337-872E-64967B6C3DC8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{ACCD13AE-3B0B-4632-BE68-15BC833AB909}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Path of Exile\PathOfExileSteam.exe (Grinding Gear Games Limited -> ) FirewallRules: [{61B8B4AB-AA90-47DA-AB44-C47CE4FDE40A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Path of Exile\PathOfExileSteam.exe (Grinding Gear Games Limited -> ) FirewallRules: [{A58B29CE-CAD9-48FF-898E-F5E797BFC008}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Red Dead Redemption 2\PlayRDR2.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{D8068044-0170-40CA-9887-E95EF89D3029}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Red Dead Redemption 2\PlayRDR2.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{D55D37C2-377F-4FFB-B6B9-AAB212109009}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{728474C0-06D6-456E-84FF-CBEB74642D91}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [TCP Query User{3ADE300B-F3C0-41E4-BA7D-11B5B8E92115}C:\users\jeff gs1 mk3\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\jeff gs1 mk3\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software) FirewallRules: [UDP Query User{9B905D68-48A1-4DD1-A458-82C878C628DB}C:\users\jeff gs1 mk3\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\jeff gs1 mk3\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software) FirewallRules: [{8D10F2BA-A8EF-4344-B8F2-1483490607B7}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{A1354FFE-9F40-4EE3-AE45-F7FB7EA80705}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{D4F829CC-D793-4A00-AF73-652087A0E4B1}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{B2D2AC04-8382-4B93-93CF-4D67002B67BA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{E6CEF0E7-440C-431B-8BA5-85AB6C124A2B}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{EB4E089A-921D-42A1-942C-725C524163DE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{DA62044E-BD0F-4BA5-B686-83F99E602119}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [TCP Query User{5CB941AF-5B35-4395-90DC-7883D5F48443}C:\users\jeff gs1 mk3\appdata\local\programs\opera gx\opera.exe] => (Block) C:\users\jeff gs1 mk3\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software) FirewallRules: [UDP Query User{0DEC45E3-F877-4386-9D9D-EC21A86073AD}C:\users\jeff gs1 mk3\appdata\local\programs\opera gx\opera.exe] => (Block) C:\users\jeff gs1 mk3\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software) FirewallRules: [{E0DEB79D-660F-4DCD-A7C7-BCEAC65AA6C2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout 4\Fallout4Launcher.exe (Bethesda Softworks) [File not signed] FirewallRules: [{F3308BFA-9638-4970-BC8A-4982A5C44B12}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout 4\Fallout4Launcher.exe (Bethesda Softworks) [File not signed] FirewallRules: [TCP Query User{2B66EB2E-F066-476F-A9E3-EB10CE4B522C}C:\program files (x86)\steam\steamapps\common\red dead redemption 2\rdr2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\red dead redemption 2\rdr2.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [UDP Query User{71988F6A-859B-4B0A-AA2B-3AE3DD36763B}C:\program files (x86)\steam\steamapps\common\red dead redemption 2\rdr2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\red dead redemption 2\rdr2.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{579BC507-5F08-4CD2-997F-FA98A5D100A8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Yu-Gi-Oh! Master Duel\masterduel.exe () [File not signed] FirewallRules: [{C6A59EF3-7642-434E-968D-68C407255F88}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Yu-Gi-Oh! Master Duel\masterduel.exe () [File not signed] FirewallRules: [{CD11D019-45C9-426D-B5F3-8E417527BB57}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons and Dragons Online\DNDLauncher.exe (Standing Stone Games LLC -> Standing Stone Games, LLC.) FirewallRules: [{4DC8C94B-FDE7-4ED2-B7CA-59B4613FCA67}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons and Dragons Online\DNDLauncher.exe (Standing Stone Games LLC -> Standing Stone Games, LLC.) FirewallRules: [TCP Query User{057C3F95-7A7C-4164-884C-EE90639F51A4}C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\x64\dndclient64.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\x64\dndclient64.exe (Standing Stone Games, LLC.) [File not signed] FirewallRules: [UDP Query User{281DA805-477B-4D67-B6E1-9A5FFCF0B02C}C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\x64\dndclient64.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\x64\dndclient64.exe (Standing Stone Games, LLC.) [File not signed] FirewallRules: [{0C6EE6CF-4B6A-4569-A38C-A19BA49E5E53}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ELDEN RING\Game\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.) FirewallRules: [{766125AC-8C5B-473A-9419-6B864B0F1461}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ELDEN RING\Game\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.) FirewallRules: [TCP Query User{1B7B9837-F8D8-49D9-9410-6523E13F10CD}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [UDP Query User{876E6CBF-3869-47BE-B8AC-36326304FBDE}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{2A019936-6DA0-4467-BB42-C569557547E9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{53B95116-A65C-4D7A-9102-325818E62FF0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{6A8D3256-CD22-46BA-960A-07B4628F3B60}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{447AADB7-FF89-4104-A079-045F2CA5BA0F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{FFFE6DDD-03FE-4CE3-9CA6-908CEE2BBB79}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel Corporation -> ) FirewallRules: [{9C82D7FB-CFE5-4386-9607-6700A0FA2BCF}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel Corporation -> ) FirewallRules: [{8F037FA0-7975-47CF-8394-2AE87A416F37}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel Corporation -> ) FirewallRules: [{2383F7F9-472B-4677-9C1D-1757B8BF2FFF}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel Corporation -> ) FirewallRules: [{64C88C25-772D-4AEF-8249-6964B57DAB99}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe (Crate Entertainment, LLC) [File not signed] FirewallRules: [{E14E6010-67F2-472E-A15F-1BD3CA294D54}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe (Crate Entertainment, LLC) [File not signed] FirewallRules: [{AEC83C97-AE5F-4585-9234-BCAABA5C6511}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DDDA\DDDA.exe (Capcom U.S.A., Inc.) [File not signed] FirewallRules: [{D1A83B26-5FAA-4CFD-A4EB-20ADB9F06334}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DDDA\DDDA.exe (Capcom U.S.A., Inc.) [File not signed] FirewallRules: [{6C83C73F-95FB-4431-8ADA-EB15650E27AA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7dLauncher.exe () [File not signed] FirewallRules: [{DBA1BAEC-53D9-4BE4-8885-6357DB5B1523}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\7 Days To Die\7dLauncher.exe () [File not signed] FirewallRules: [TCP Query User{6CDDDDED-8CE2-4729-8B17-22B3744B29E4}C:\program files (x86)\steam\steamapps\common\7 days to die\7daystodie.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\7 days to die\7daystodie.exe () [File not signed] FirewallRules: [UDP Query User{D4F8E2EB-81BB-4F6B-A116-3491D56C4030}C:\program files (x86)\steam\steamapps\common\7 days to die\7daystodie.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\7 days to die\7daystodie.exe () [File not signed] FirewallRules: [{9D8B89BA-35C5-479E-B0A7-C26565A4FDCA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\x64\Grim Dawn.exe (Crate Entertainment, LLC) [File not signed] FirewallRules: [{EB8A80F0-830B-440F-849C-00E34D3DF860}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\x64\Grim Dawn.exe (Crate Entertainment, LLC) [File not signed] FirewallRules: [{A0297666-BB65-4F06-9CF7-45C7D2D6265F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ELDEN RING\Game\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.) FirewallRules: [{9663A489-4768-4F4C-8830-D928BA471E6C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ELDEN RING\Game\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.) FirewallRules: [{51743B6D-3E8D-4863-8DA7-52A4BB1E012E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stardew Valley\Stardew Valley.exe (ConcernedApe) [File not signed] FirewallRules: [{32D2D0F6-D7AA-413A-8C89-9A198EE9CF42}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stardew Valley\Stardew Valley.exe (ConcernedApe) [File not signed] FirewallRules: [{A6A2B208-0C28-4538-A5C8-545D1BB839E1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe (Bethesda Softworks -> Bethesda Softworks, Obsidian Entertainment) FirewallRules: [{98CF51D8-5990-4869-AEA0-41377D91C2CA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe (Bethesda Softworks -> Bethesda Softworks, Obsidian Entertainment) FirewallRules: [{1378F983-5D15-450F-ABC0-5B776AA5C763}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x64\Hades.exe () [File not signed] FirewallRules: [{49DF9C4E-DC60-45DB-BFA1-D446976A7431}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x64\Hades.exe () [File not signed] FirewallRules: [{E245D68F-EEA0-4DF1-B6BF-D5457F40D5F1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x64Vk\Hades.exe () [File not signed] FirewallRules: [{DFB65D34-347B-4186-9D53-90B8E4E19890}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x64Vk\Hades.exe () [File not signed] FirewallRules: [{2282124A-9A06-46D8-AE09-B2B7C8EEB53F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x86\Hades.exe () [File not signed] FirewallRules: [{564EE571-C0DB-468F-B625-F1C1FD1EFB87}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Hades\x86\Hades.exe () [File not signed] FirewallRules: [{B8DDE597-B841-463B-9477-3910D52466DD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sekiro\sekiro.exe (Activision Publishing Inc -> FromSoftware, Inc.) FirewallRules: [{25429A46-C93E-4FFC-A07D-15752D89AB79}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sekiro\sekiro.exe (Activision Publishing Inc -> FromSoftware, Inc.) FirewallRules: [{E6C0A176-7D2B-419C-8245-6BBAAB39231F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Yakuza Like a Dragon\runtime\media\startup.exe (SEGA Games Co., Ltd. -> ) FirewallRules: [{D6599F59-1692-40E7-9FCB-10BF1F804BC3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Yakuza Like a Dragon\runtime\media\startup.exe (SEGA Games Co., Ltd. -> ) FirewallRules: [{A2EDCF79-3738-4FD6-A435-6263083D22C3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheOuterWorlds\TheOuterWorlds.exe (Private Division) [File not signed] FirewallRules: [{21C0AF5E-A4D5-4ED7-B1C1-766B5C8F53F9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheOuterWorlds\TheOuterWorlds.exe (Private Division) [File not signed] FirewallRules: [{5289CF39-DF4C-4556-BB8E-DFC4F79E679F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cyberpunk 2077\REDprelauncher.exe (GOG Sp. z o.o. -> GOG.com) FirewallRules: [{1A968A81-59D3-480A-9FFF-661435D946E4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cyberpunk 2077\REDprelauncher.exe (GOG Sp. z o.o. -> GOG.com) FirewallRules: [{BA5EF189-A84D-406E-8FD1-78B135C39BC1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Borderlands 3\OakGame\Binaries\Win64\Borderlands3.exe (Gearbox Software, L.L.C. -> Gearbox Software) FirewallRules: [{2DBA7B1A-D73D-4A53-96C0-2B4C0CB9373A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Borderlands 3\OakGame\Binaries\Win64\Borderlands3.exe (Gearbox Software, L.L.C. -> Gearbox Software) FirewallRules: [TCP Query User{DB65CECB-1886-4120-8398-8EF1E07A211F}C:\program files (x86)\steam\steamapps\common\theouterworlds\indiana\binaries\win64\indiana-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\theouterworlds\indiana\binaries\win64\indiana-win64-shipping.exe (Private Division) [File not signed] FirewallRules: [UDP Query User{97362492-F3C7-4410-9C1E-92F10772F07F}C:\program files (x86)\steam\steamapps\common\theouterworlds\indiana\binaries\win64\indiana-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\theouterworlds\indiana\binaries\win64\indiana-win64-shipping.exe (Private Division) [File not signed] FirewallRules: [{FB782526-D66E-4BED-BFF3-D97DB0F621A7}] => (Block) C:\program files (x86)\steam\steamapps\common\theouterworlds\indiana\binaries\win64\indiana-win64-shipping.exe (Private Division) [File not signed] FirewallRules: [{24ED6D3A-E6EC-429F-912A-BC45EB57349F}] => (Block) C:\program files (x86)\steam\steamapps\common\theouterworlds\indiana\binaries\win64\indiana-win64-shipping.exe (Private Division) [File not signed] FirewallRules: [{88DB8C08-8433-4ED8-B74C-FDD077A860AB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tiny Tina's Wonderlands\OakGame\Binaries\Win64\Wonderlands.exe (Gearbox Software, L.L.C. -> Gearbox) FirewallRules: [{B4844679-3F83-4B10-802C-3EBAA02A8785}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tiny Tina's Wonderlands\OakGame\Binaries\Win64\Wonderlands.exe (Gearbox Software, L.L.C. -> Gearbox) FirewallRules: [{CAE3AFF1-5990-4549-89D4-C1A95413C1E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Valheim\valheim.exe () [File not signed] FirewallRules: [{6DF0B73E-3699-411D-AD92-996BF553D96E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Valheim\valheim.exe () [File not signed] FirewallRules: [{6A5A7096-015A-4ECA-B509-29815F51D31B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Far Cry New Dawn\bin\FarCryNewDawn.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment) FirewallRules: [{C6B98F93-B227-412C-9B1E-5C618C55D1DC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Far Cry New Dawn\bin\FarCryNewDawn.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment) FirewallRules: [{ADCF57FC-59AF-4847-ACFB-339D8BAFD274}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\FarCry5.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment) FirewallRules: [{F43DA3DA-DDA7-4937-8A92-4373C71A1E90}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\FarCry5.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment) FirewallRules: [{AF91CDED-8B6A-4785-AC8B-C730FA6EFE98}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\ArcadeEditor64.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft) FirewallRules: [{C74BB4DF-810D-4A23-96F6-6CAE9DD4EC32}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\ArcadeEditor64.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft) FirewallRules: [{1451E951-411C-4167-86FA-1EE903D0D3D7}] => (Allow) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.EXE (Logitech Inc -> Logitech, Inc.) FirewallRules: [{DE5C7B7E-CA9D-4F3D-B2CF-7EB985D0DF24}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{0E5A3623-77EF-4631-BD01-0ACBED435DC9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{AE89739A-905F-4E6B-9490-F0283E967AD4}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{DAD1E71F-88E3-4DB1-B5FF-77759F66DED9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{D99642D4-D1A3-4533-A464-9319BCE5823D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{5B65868A-BD16-4F9B-9BEE-DF01B04AD8CC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.874.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{76A34ADB-533B-4926-97B5-D7BCE6BE00E6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.874.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{6900C4A3-BB86-4554-BFDF-FD99FD9875DA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.874.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{39136595-B953-44DE-BC69-246D60544AA6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.874.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{6B5305FB-95F6-4EE4-9E4D-AD2BEE3FEF82}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.874.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{4A7ED0E7-D5C5-4675-BB90-3740BC356FFA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.874.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{573275B9-DDDD-4C99-8061-9E3C3464ABA5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.874.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{88DC488D-D8F7-4662-8A2B-96083A0F17A3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.194.874.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{49807A79-6045-4161-B016-8C4489995BD6}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\105.0.1343.50\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) ==================== Restore Points ========================= 15-09-2022 15:31:20 Windows Modules Installer 15-09-2022 15:31:38 Windows Modules Installer 15-09-2022 15:32:26 Windows Modules Installer 22-09-2022 22:17:38 Intel® Driver & Support Assistant 25-09-2022 11:10:39 Windows Modules Installer ==================== Faulty Device Manager Devices ============ Name: Unknown USB Device (Device Descriptor Request Failed) Description: Unknown USB Device (Device Descriptor Request Failed) Class Guid: {36fc9e60-c465-11cf-8056-444553540000} Manufacturer: (Standard USB Host Controller) Service: Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. ==================== Event log errors: ======================== Application errors: ================== Error: (09/26/2022 08:53:30 AM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: LOUQE-S1) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (09/20/2022 09:45:12 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program CCleaner64.exe version 6.4.0.10044 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 77dc Start Time: 01d8cd5af4f95c6c Termination Time: 4294967295 Application Path: C:\Program Files\CCleaner\CCleaner64.exe Report Id: 4fc71a35-7998-4387-9c2f-b31638e6ae99 Faulting package full name: Faulting package-relative application ID: Hang type: Top level window is idle Error: (09/17/2022 09:42:22 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: LOUQE-S1) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (09/17/2022 09:37:10 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: MacroRecorder.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException at MacroRecorder.PlaybackForm.ProcessCommandChain() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart() Error: (09/06/2022 10:38:22 AM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: LOUQE-S1) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (08/30/2022 07:38:21 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: LOUQE-S1) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (08/28/2022 11:37:40 AM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: LOUQE-S1) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (08/27/2022 11:50:03 AM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: LOUQE-S1) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. System errors: ============= Error: (09/26/2022 09:09:26 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NBLGGH4QGHW-Microsoft.MicrosoftStickyNotes. Error: (09/26/2022 08:50:45 AM) (Source: DCOM) (EventID: 10001) (User: LOUQE-S1) Description: Unable to start a DCOM Server: Microsoft.MicrosoftEdge_44.19041.1266.0_neutral__8wekyb3d8bbwe!MicrosoftEdge as Unavailable/Unavailable. The error: "2147942402" Happened while starting this command: "C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe" -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca Error: (09/26/2022 08:50:14 AM) (Source: DCOM) (EventID: 10001) (User: LOUQE-S1) Description: Unable to start a DCOM Server: Microsoft.MicrosoftEdge_44.19041.1266.0_neutral__8wekyb3d8bbwe!MicrosoftEdge as Unavailable/Unavailable. The error: "2147942402" Happened while starting this command: "C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe" -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca Error: (09/25/2022 11:53:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Energy Server Service queencreek service terminated unexpectedly. It has done this 1 time(s). Error: (09/25/2022 11:53:11 PM) (Source: DCOM) (EventID: 10010) (User: LOUQE-S1) Description: The server Microsoft.AAD.BrokerPlugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy!Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider did not register with DCOM within the required timeout. Error: (09/25/2022 11:53:11 PM) (Source: DCOM) (EventID: 10010) (User: LOUQE-S1) Description: The server Microsoft.AAD.BrokerPlugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy!Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider did not register with DCOM within the required timeout. Error: (09/25/2022 05:36:17 PM) (Source: BTHUSB) (EventID: 17) (User: ) Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. Error: (09/24/2022 10:11:34 AM) (Source: BTHUSB) (EventID: 17) (User: ) Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. Windows Defender: ================ Date: 2022-09-26 09:07:58 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2022-09-25 23:50:32 Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Backdoor:Win32/Bladabindi!ml&threatid=2147748148&enterprise=0 Name: Backdoor:Win32/Bladabindi!ml Severity: Severe Category: Backdoor Path: file:_C:\Users\Jeff GS1 MK3\Downloads\Jitbit_Macro_Recorder_5.8.0_2021_Tested_by_Bicfic.com.zip Detection Origin: Local machine Detection Type: FastPath Detection Source: Real-Time Protection Process Name: C:\Users\Jeff GS1 MK3\AppData\Local\Programs\Opera GX\opera.exe Security intelligence Version: AV: 1.375.986.0, AS: 1.375.986.0, NIS: 1.375.986.0 Engine Version: AM: 1.1.19600.3, NIS: 1.1.19600.3 Date: 2022-09-25 23:50:01 Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Backdoor:Win32/Bladabindi!ml&threatid=2147748148&enterprise=0 Name: Backdoor:Win32/Bladabindi!ml Severity: Severe Category: Backdoor Path: file:_C:\Users\Jeff GS1 MK3\Downloads\Jitbit_Macro_Recorder_5.8.0_2021_Tested_by_Bicfic.com.zip.opdownload Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Users\Jeff GS1 MK3\AppData\Local\Programs\Opera GX\opera.exe Security intelligence Version: AV: 1.375.986.0, AS: 1.375.986.0, NIS: 1.375.986.0 Engine Version: AM: 1.1.19600.3, NIS: 1.1.19600.3 Date: 2022-09-25 23:41:21 Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Phonzy.C!ml&threatid=2147772968&enterprise=0 Name: Trojan:Script/Phonzy.C!ml Severity: Severe Category: Trojan Path: file:_C:\Users\Jeff GS1 MK3\Downloads\Jitbit Macro Recorder Lite 4.71.0\Jitbit Macro Recorder Lite 4.71.0.exe Detection Origin: Local machine Detection Type: FastPath Detection Source: Real-Time Protection Process Name: Unknown Security intelligence Version: AV: 1.375.986.0, AS: 1.375.986.0, NIS: 1.375.986.0 Engine Version: AM: 1.1.19600.3, NIS: 1.1.19600.3 Date: 2022-09-24 13:18:37 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan  CodeIntegrity: =============== Date: 2022-09-26 09:07:59 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2022-08-31 10:16:48 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== BIOS: American Megatrends Inc. F12 01/18/2021 Motherboard: Gigabyte Technology Co., Ltd. B550I AORUS PRO AX Processor: AMD Ryzen 5 5600X 6-Core Processor Percentage of memory in use: 37% Total physical RAM: 32714.45 MB Available physical RAM: 20454.9 MB Total Virtual: 37578.45 MB Available Virtual: 23327.93 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:1862.4 GB) (Free:890.47 GB) (Model: Samsung SSD 980 PRO 2TB) NTFS Drive d: (Storage Disk) (Fixed) (Total:1863 GB) (Free:1862.18 GB) (Model: Samsung SSD 870 EVO 2TB) NTFS \\?\Volume{a256c81f-5383-4c5a-b9aa-c61a40ef3004}\ () (Fixed) (Total:0.5 GB) (Free:0.08 GB) NTFS \\?\Volume{cb92a8db-3bd1-4356-b92b-2d5c2204fce0}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ==================== ==================== End of Addition.txt =======================