Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-01-2023 Ran by [removed] (20-01-2023 13:36:37) Running from C:\Users\[removed]\Desktop Microsoft Windows 10 Enterprise Version 1809 17763.1577 (X64) (2019-05-13 21:13:09) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-266282535-48708807-158023499-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-266282535-48708807-158023499-503 - Limited - Disabled) Guest (S-1-5-21-266282535-48708807-158023499-501 - Limited - Disabled) Mark (S-1-5-21-266282535-48708807-158023499-1001 - Administrator - Enabled) => C:\Users\Mark WDAGUtilityAccount (S-1-5-21-266282535-48708807-158023499-504 - Limited - Disabled) zeroone13 (S-1-5-21-266282535-48708807-158023499-1002 - Administrator - Enabled) => C:\Users\zeroone13 ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Enabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) @BIOS (HKLM-x32\...\{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 4.22.0718.1 - GIGABYTE) Hidden @BIOS (HKLM-x32\...\InstallShield_{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 4.22.0718.1 - GIGABYTE) «Metal Gear Rising - Revengeance» 1.0.u2 (HKLM-x32\...\«Metal Gear Rising - Revengeance»_is1) (Version: 1.0.u2 - Konami) 5KPlayer (HKLM-x32\...\5KPlayer) (Version: 6.9 - DearMob, Inc.) 7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov) 7-Zip 22.00 (x64 edition) (HKLM\...\{23170F69-40C1-2702-2200-000001000000}) (Version: 22.00.00.0 - Igor Pavlov) A.O.M. Total Bundle (HKLM\...\A.O.M. Total Bundle_is1) (Version: 1.10.0 - A.O.M.) Ace Combat 7: Skies Unknown (HKLM-x32\...\Ace Combat 7: Skies Unknown_is1) (Version: - ) ACID Pro 8.0 (x64) (HKLM\...\{12373680-286F-11E9-B67A-001B21B1DCED}) (Version: 8.0.8.29 - MAGIX) Activation-Patch (HKLM-x32\...\{B903CCB0-DF83-4ED7-81FB-9F27D02654B8}) (Version: 1.0.0 - FTU APPS) AdGuard (HKLM-x32\...\{685F6AB3-7C61-42D1-AE5B-3864E48D1035}) (Version: 7.10.3952.0 - Adguard Software Ltd) Adobe Premiere Pro 2021 (HKLM-x32\...\PPRO_15_4_1) (Version: 15.4.1 - Adobe Inc.) Advanced Installer 18.8 (HKLM-x32\...\{9C042F88-07E8-4141-826A-0B0CFCF5D61A}) (Version: 18.8 - Caphyon) Aegisub 3.2.2 (HKLM\...\{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1) (Version: 3.2.2 - Aegisub Team) AHD Subtitles Maker Pro version 5.21.23 (HKLM-x32\...\{CA69934C-EACB-4B41-A5F6-7F2A2873987E}_is1) (Version: 5.21.23 - AHD, Inc.) AIDA64 Engineer v6.80 (HKLM-x32\...\AIDA64 Engineer_is1) (Version: 6.80 - FinalWire Ltd.) AIDA64 Extreme v6.30 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 6.30 - FinalWire Ltd.) AIMP (HKLM-x32\...\AIMP) (Version: 5.03.2398 - AIMP DevTeam) AIMP Control Plugin 1.0.13 (HKLM-x32\...\{F171581D-00CD-4E77-8982-B1B68FDCAAFA}_is1) (Version: 1.0.13 - Alexey Ivanov) Amazing SD Memory Card Data Recovery version 9.1.1.8 (HKLM-x32\...\{AmazingSdCardRecovery}_is1) (Version: 9.1.1.8 - www.Amazing-Share.com) AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 22.11.2 - Advanced Micro Devices, Inc.) AMD System Monitor (HKLM-x32\...\{6EFD0C42-4CC1-4716-A0CA-21C1A062CF34}) (Version: 1.0.9 - Advanced Micro Devices, Inc.) AmpliTube 4 version 4.10.0 (HKLM\...\{21B0C8E0-7EB7-4832-B764-20A7DAE86E02}_is1) (Version: 4.10.0 - IK Multimedia) AmpliTube 5 version 5.0.1 (HKLM\...\{D831D61F-EBF5-4158-AEE1-F58A7B8C04C8}_is1) (Version: 5.0.1 - IK Multimedia) ANNO Mutationem (HKLM-x32\...\DOGE_ANNOMutationem) (Version: - ) AOMEI Partition Assistant 9.6 (HKLM-x32\...\{02F850ED-FD0E-4ED1-BE0B-54981f5BD3D4}_is1) (Version: 9.6.0 - AOMEI International Network Limited.) APP Center (HKLM-x32\...\{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 3.22.1031.1 - Gigabyte) Hidden APP Center (HKLM-x32\...\InstallShield_{D50BEE9A-0EC6-4A58-BF90-35BDC6D6495D}) (Version: 3.22.1031.1 - Gigabyte) ARIA Engine v1.9.3.3 (HKLM\...\ARIA Engine_is1) (Version: v1.9.3.3 - Plogue Art et Technologie, Inc) ARP 2600 V3 3.7.1 (HKLM-x32\...\ARP 2600 V3_is1) (Version: 3.7.1 - Arturia) ARP 2600 V3 3.7.1 1263 MORiA version 3.7.1 (1263) (HKLM-x32\...\{A7BAD701-B255-48BD-AF1F-992F4CF19AEC}_is1) (Version: 3.7.1 (1263) - Arturia, Inc.) Arturia Analog Lab V (HKLM\...\Analog Lab V_is1) (Version: 5.4.7.1882 - Arturia & Team V.R) Arturia Matrix-12 V2 (HKLM\...\Matrix-12 V2_is1) (Version: 2.4.1.2810 - Arturia & Team V.R) Arturia Software Center 2.0.4 (HKLM-x32\...\Arturia Software Center_is1) (Version: 2.0.4 - Arturia) ASIO Bridge and Hi-Fi Cable (HKLM-x32\...\VB:ASIOBridge {17359A74-1236-5467}) (Version: - VB-Audio Software) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach) Asoftis IP Changer (HKLM-x32\...\Asoftis IP Changer_is1) (Version: 1.4 - Asoftis) Audacity 2.4.2 (HKLM-x32\...\Audacity_is1) (Version: 2.4.2 - Audacity Team) Audeze HQ (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\{78e9474a-5774-4f1b-a662-acf65981dd22}) (Version: 0.0.1 - Audeze LLC) Audeze Reveal+ 2.0.0 (HKLM\...\{517F707C-66C0-44F5-B4D4-43D97DF7AAC1}_is1) (Version: 2.0.0 - Embody) Audials 2021 (HKLM-x32\...\{32322236-9FFB-46AE-9507-42777EF94F45}) (Version: 21.0.130.0 - Audials AG) Audient USB Audio Driver v4.0.8 (HKLM-x32\...\Software_Audient_audientusbaudio_Setup) (Version: 4.0.8 - Audient) Audio Suite (HKLM-x32\...\Suite) (Version: 1.00 - NCH Software) Audirvana Plus (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\1bb2007885c6d03d) (Version: 1.3.10.1070 - Audirvana) AxCrypt 2.1.1573.0 (HKLM\...\{902A739B-1DAE-6E68-81B1-674E343E1CF1}) (Version: 2.1.1573.0 - AxCrypt AB) Hidden AxCrypt 2.1.1573.0 (HKLM-x32\...\{4802bd28-932d-4070-99e2-068ea74d872d}) (Version: 2.1.1573.0 - AxCrypt AB) AXE I/O Control Panel v1.2.0 (HKLM-x32\...\Software_IKMultimedia_IKMultimedia_UsbAudio_Driver_Setup) (Version: 1.2.0 - IK Multimedia) Band-in-a-Box File Associations (HKLM-x32\...\BBAssociations_is1) (Version: - PG Music Inc.) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) BIAS Amp 2 (HKLM\...\BIAS AMP 2 Pack (64bit)_is1) (Version: 2.2.7.1388 - Positive Grid & Team V.R) BIAS FX 2 Plugins Pack (32bit) (HKLM-x32\...\{201CBF9D-8570-4CD4-A4D7-DEEBADC56785}) (Version: 2.1.9.4900 - PositiveGrid) BIAS FX 2 Plugins Pack (64bit) (HKLM\...\{81FCC6D7-A21E-4D7D-B47A-4DA73E709E80}_is1) (Version: - PositiveGrid) Branding64 (HKLM\...\{0DB6E0DC-607A-42C1-A3CE-7567A9F85AF4}) (Version: 1.00.0008 - Advanced Micro Devices, Inc.) Hidden Brigador: Up-Armored Edition (HKLM-x32\...\1356485086_is1) (Version: v1.62c - GOG.com) Cabalistic Oracle (HKLM-x32\...\Cabalistic Oracle_is1) (Version: 2.1 - ) calibre 64bit (HKLM\...\{920D5F38-267F-4FC1-BFEA-60E94B3090E2}) (Version: 4.2.0 - Kovid Goyal) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.2.0 - Canon Inc.) Canon TS3100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS3100_series) (Version: 1.01 - Canon Inc.) CCleaner (HKLM\...\CCleaner) (Version: 6.07 - Piriform) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.) Classic Shell (HKLM\...\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft) CMEDIA USB2.0 Audio Device (HKLM-x32\...\{62560967-F20C-4A63-A8ED-0ED369D4D727}) (Version: 1.00.0006 - C-Media Electronics, Inc.) Combo384 Amanero version 1.0.62 (HKLM-x32\...\Combo384 Amanero_is1) (Version: 1.0.62 - ) Combo384_ASIO64 (HKLM\...\{307CB2B4-FC33-4DD8-99AA-77DE639F9519}) (Version: 1.0.3 - Amanero) COMEI Partition Assistant 9.0.0.0 (HKLM-x32\...\{8502F0ED-FD0E-4ED1-BE0B-54981f5BD3D4}_is1) (Version: - COMEI International Network Limited.) Control (HKLM-x32\...\Control_is1) (Version: v.1.0 Update 2 - Decepticon) Core Temp 1.17.1 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.17.1 - ALCPU) CoyoteWT 1.3 (HKLM-x32\...\CoyoteWT_is1) (Version: - Coyote Electronics Inc.) CPUID CPU-Z 1.88 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.88 - CPUID, Inc.) Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.45 - Creative Technology Limited) Creative System Information (HKLM-x32\...\SysInfo) (Version: 1.10 - Creative Technology Limited) CULTIC (HKLM-x32\...\CULTIC_is1) (Version: - ) Custom Cursor version 1.0.3 (HKLM-x32\...\{C8D6928F-1E7E-4DEC-998A-1B8B86FBBAD1}_is1) (Version: 1.0.3 - Blife) Custom Shop 2.0.0 (HKLM\...\5b86c39c-6f2f-52a0-a1b0-9b9fc743254c) (Version: 2.0.0 - IK Multimedia) Custom Shop version 1.8.0 (HKLM-x32\...\{21BAD046-50EC-49E2-BE7B-F9729704F2C3}_is1) (Version: 1.8.0 - IK Multimedia) Custom Shop version 2.0.0 (64-bit) (HKLM\...\{21BAD046-50EC-49E2-BE7B-F9729704F2C3}_is1) (Version: 2.0.0 - IK Multimedia) Cyberpunk 2077 (HKLM-x32\...\Cyberpunk 2077_is1) (Version: 0.0.0 - DODI-Repacks) DAEMON X MACHINA Deluxe Edition (HKLM-x32\...\DAEMON X MACHINA Deluxe Edition_is1) (Version: - ) Deathloop: Deluxe Edition (HKLM-x32\...\Deathloop: Deluxe Edition_is1) (Version: 1.769.0.5 build 7848766 - RePack) Deluge 1.3.15 (HKLM-x32\...\Deluge) (Version: - ) Devil May Cry 5 (HKLM-x32\...\Devil May Cry 5_is1) (Version: - ) Disco Elysium: The Final Cut (HKLM-x32\...\Disco Elysium: The Final Cut_is1) (Version: - ) Disk Drill 4.0.534.0 (HKLM-x32\...\{ebc75dee-2d49-45b8-ace5-18a337d02f3e}) (Version: 4.0.534.0 - CleverFiles) Disk Drill 4.0.534.0 (x64) (HKLM\...\{6D8F5E9E-C597-45CE-8FE1-4F426D3674C5}) (Version: 4.0.534.0 - CleverFiles) Hidden Disk Drill Pro 4.0.534.0 1.0.0 (HKLM-x32\...\Disk Drill Pro 4.0.534.0 1.0.0) (Version: 1.0.0 - Crackingpatching.com Team) Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.03 - Creative Technology Limited) dr.fone (Version 10.5.0) (HKLM-x32\...\{E8F86DA8-B8E4-42C7-AFD4-EBB692AC43FD}_is1) (Version: 10.5.0.316 - Wondershare Technology Co.,Ltd.) Drumaxx (HKLM-x32\...\Drumaxx) (Version: - Image-Line) EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version: - EaseUS) EaseUS Partition Master (HKLM-x32\...\EaseUS Partition Master_is1) (Version: - EaseUS) EaseUS Todo Backup Free 11.5 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 11.5 - CHENGDU YIWO Tech Development Co., Ltd) EaseUS Todo PCTrans 9.10 (HKLM-x32\...\EaseUS Todo PCTrans_is1) (Version: - EaseUS) EasyTune (HKLM-x32\...\{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.22.1227 - GIGABYTE) Hidden EasyTune (HKLM-x32\...\InstallShield_{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.22.1227 - GIGABYTE) EasyTuneEngineService (HKLM-x32\...\{964575C3-5820-4642-A89A-754255B5EFE1}) (Version: 1.22.1227 - GIGABYTE) Hidden EasyTuneEngineService (HKLM-x32\...\InstallShield_{964575C3-5820-4642-A89A-754255B5EFE1}) (Version: 1.22.1227 - GIGABYTE) Efx FRAGMENTS 1.0.0 (HKLM-x32\...\Efx FRAGMENTS_is1) (Version: 1.0.0 - Arturia) ELDEN RING (HKLM-x32\...\ELDEN RING_is1) (Version: 0.0.0 - DODI-Repacks) Eldest Souls (HKLM-x32\...\1112497208_is1) (Version: 1.0.466-master - GOG.com) EQ APO - GUI (HKLM-x32\...\{D24648E4-D47C-4707-AE59-72F99C06CF5A}) (Version: 1.2.5 - GSUN) Equalizer APO (HKLM\...\EqualizerAPO) (Version: 1.2 - ) Everything 1.4.1.1015 (x86) (HKLM-x32\...\Everything) (Version: 1.4.1.1015 - voidtools) F1 22 Champions Edition (HKLM-x32\...\F1 22 Champions Edition_is1) (Version: 0.0.0 - DODI-Repacks) Fallen Angel (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\Fallen Angel) (Version: - HOODLUM) Far Cry 6 (HKLM-x32\...\Far Cry 6_is1) (Version: - ) FastCopy (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\FastCopy) (Version: 3.92 - H.Shirouzu) FileASSASSIN (HKLM-x32\...\FileASSASSIN) (Version: 1.06 - Malwarebytes) Final Fantasy VII Remake Intergrade (HKLM-x32\...\Final Fantasy VII Remake Intergrade_is1) (Version: 0.0.0 - DODI-Repacks) Final Fantasy VII: Remake (HKLM-x32\...\Final Fantasy VII: Remake_is1) (Version: - ) FINAL FANTASY XIV ONLINE (HKLM-x32\...\{2B41E132-07DF-4925-A3D3-F2D1765CCDFE}) (Version: 1.0.0000 - SQUARE ENIX CO., LTD.) FL Studio 20 (HKLM-x32\...\FL Studio 20) (Version: - Image-Line) FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version: - Image-Line) FLAC Frontend (HKLM-x32\...\{315E5E8B-0560-413A-B604-622A4C8BECBD}) (Version: 2.1.1 - Xiph.org) Flash Drive Tester v1.14 (HKLM-x32\...\{272C8DEE-F54F-406C-9AA6-B4DE2985A47C}) (Version: 1.14 - Virtual Console) Free Netflix Download version 5.0.26.430 (HKLM-x32\...\Free Netflix Download_is1) (Version: 5.0.26.430 - FreeGrabApp LLC) Free SRT-File Translator (HKLM-x32\...\{8850D4C9-DBCB-4664-B349-B32EBD4BF3D4}) (Version: 2.9.23 - Pappsegull Sweden) Free USB Flash Drive Data Recovery version 8.8 (HKLM-x32\...\{RCYUSBDriveDataRecovery}_is1) (Version: 8.8 - www.rcysoft.com) Game Boost (HKLM-x32\...\{644B5310-D2AA-42A8-9F3B-7B92C856C8D7}) (Version: 1.00.0007 - Gigabyte) Hidden Game Boost (HKLM-x32\...\InstallShield_{644B5310-D2AA-42A8-9F3B-7B92C856C8D7}) (Version: 1.00.0007 - Gigabyte) Gigabyte Speed 12.00 (HKLM\...\Gigabyte Speed) (Version: 12.00 - cFos Software GmbH, Bonn) GigabyteFirmwareUpdateUtility (HKLM-x32\...\{1CBA99CE-1AB3-4366-AFB4-7F7B75EBBE35}) (Version: 1.20.0720.1 - GIGABYTE) Hidden GigabyteFirmwareUpdateUtility (HKLM-x32\...\InstallShield_{1CBA99CE-1AB3-4366-AFB4-7F7B75EBBE35}) (Version: 1.20.0720.1 - GIGABYTE) GNU Privacy Guard (HKLM-x32\...\GnuPG) (Version: 2.2.11 - The GnuPG Project) Godmode (HKLM-x32\...\Godmode) (Version: v1.0.1.27 Beta - PeusensSoftware) Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 57.0.5.0 - Google LLC) Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden Gpg4win (3.1.5) (HKLM-x32\...\Gpg4win) (Version: 3.1.5 - The Gpg4win Project) Greenshot 1.2.10.6 (HKLM\...\Greenshot_is1) (Version: 1.2.10.6 - Greenshot) Haak v1.1.0 (HKLM-x32\...\Haak-v1.1.0_is1) (Version: 0 - ) HeadRush MX5 1.0.4 (HKLM\...\{824B8606-04EC-40D1-BB58-22B2879E3F46}) (Version: 1.0.4 - HeadRush) Hellish Quart (HKLM-x32\...\1731372333_is1) (Version: 0.2603 - GOG.com) HID Report Listener (HKLM-x32\...\{8B020537-B753-4A02-BEC4-31ADE11E61BF}) (Version: 1.1.6305.15555 - DSDCS) HitmanPro 3.8 (HKLM\...\HitmanPro38) (Version: 3.8.30.326 - SurfRight B.V.) Honeyview (HKLM\...\Honeyview) (Version: 5.38 - Bandisoft.com) HR Audio Player (HKLM-x32\...\{187473B9-69E3-460D-A2FD-1070349DDA0C}) (Version: 1.0.0.21 - TEAC) Hyper Scape (HKLM-x32\...\Uplay Install 11957) (Version: - Ubisoft) IDA Pro 7.3 version 7.3 (HKLM\...\{A9F308DD-902C-4B05-B478-524AEF0BDE90}_is1) (Version: 7.3 - Team-IRA) IDM Crack 6.37 build 7 beta (HKLM-x32\...\IDM Crack 6.37 build 7 beta) (Version: 6.37 build 7 beta - Crackingpatching.com Team) IJ Network Device Setup Utility (HKLM-x32\...\IJ Network Device Setup Utility) (Version: 1.8.1 - Canon Inc.) IK Multimedia Authorization Manager version 1.0.26 (HKLM\...\{85BC0DCB-69E5-4279-AA25-F108EF896588}_is1) (Version: 1.0.26 - IK Multimedia) IK Product Manager 1.0.1 (HKLM\...\a401809f-3509-5ed7-a6dc-34dc618bf372) (Version: 1.0.1 - IK Multimedia) IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line) IL MiniHost Modular (HKLM-x32\...\IL MiniHost Modular) (Version: - Image-Line) InputMapper 1.7 (HKLM-x32\...\{E42A4987-1F86-4E8F-A708-60CAAC1E3DA7}) (Version: 1.7.7452.13622 - DSDCS) Hidden InputMapper 1.7 (HKLM-x32\...\InputMapper 1.7 1.7.7452.13622) (Version: 1.7.7452.13622 - DSDCS) inSSIDer Office (HKLM-x32\...\{F7F37748-A121-4B38-8192-6453E1FF5ADD}) (Version: 4.4.0.6 - MetaGeek, LLC) Instant Audio Quick Bass (HKLM\...\Quick Bass_is1) (Version: 1.0.0 - Instant Audio) IObit Uninstaller 12 (HKLM-x32\...\IObitUninstall) (Version: 12.2.0.7 - IObit) IsoBuster 4.6 (HKLM-x32\...\IsoBuster_is1) (Version: 4.6 - Smart Projects) Java(TM) SE Development Kit 12.0.1 (64-bit) (HKLM\...\{0D60E96D-0B74-55A5-ACA5-0F6786FDF256}) (Version: 12.0.1.0 - Oracle Corporation) JoyToKey version 6.8 (HKLM-x32\...\{EBF21C82-423E-49FD-BCBD-88C08397CB44}_is1) (Version: 6.8 - JTK software) JRiver Media Center 25 (64-bit) (HKLM\...\Media Center 25 (64-bit)) (Version: 25 - JRiver, Inc.) K-Lite Mega Codec Pack 17.3.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 17.3.0 - KLCP) KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.2.2.69 - PandoraTV) KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - ) KORG TRITON (HKLM\...\TRITON_is1) (Version: 1.0.1 - KORG) LatencyMon 6.71 (HKLM\...\LatencyMon_is1) (Version: - Resplendence Software Projects Sp.) LockHunter 3.2, 32/64 bit (HKLM\...\LockHunter_is1) (Version: - Crystal Rich Ltd) Logitech Camera Settings (HKLM-x32\...\LogiUCDPP) (Version: 2.10.4.0 - Logitech Europe S.A.) Malwarebytes version 4.5.19.229 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.19.229 - Malwarebytes) Medieval CUE Splitter (HKLM-x32\...\{B96D2269-568B-4CBF-9332-12FAE8B158F7}) (Version: 1.2.0 - Medieval Software) MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited) METAL GEAR SOLID 4 - GUNS OF THE PATRIOTS version (Gnarly 1.0) (HKLM\...\METAL GEAR SOLID 4 - GUNS OF THE PATRIOTS_is1) (Version: (Gnarly 1.0) - ) Microsoft .NET Host - 5.0.15 (x64) (HKLM\...\{FCEBE299-E0D2-4F08-AC41-16A836D35AD8}) (Version: 40.60.31015 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 5.0.15 (x64) (HKLM\...\{00AE1248-489D-48B6-805D-714F8F123521}) (Version: 40.60.31015 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 5.0.15 (x64) (HKLM\...\{6C4FCC4E-D663-484F-A7E2-44047806BFC5}) (Version: 40.60.31015 - Microsoft Corporation) Hidden Microsoft OneDrive (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\OneDriveSetup.exe) (Version: 22.253.1204.0001 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-266282535-48708807-158023499-1002\...\OneDriveSetup.exe) (Version: 21.220.1024.0005 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{0767C1F2-C4E8-4EA8-9109-340791134967}) (Version: 2.84.0.0 - Microsoft Corporation) Microsoft Visual Basic/C++ Runtime (x86) (HKLM-x32\...\{C5E3A69D-D391-45A6-A8FB-00B01E2B010D}) (Version: 1.1.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61135 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61135 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61135 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61135 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.11.25325 (HKLM-x32\...\{6c6356fe-cbfa-4944-9bed-a9e99f45cb7a}) (Version: 14.11.25325.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.11.25325 (HKLM-x32\...\{404c9c27-8377-4fd1-b607-7ca635db4e49}) (Version: 14.11.25325.0 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.34.31921 (HKLM\...\{EB61ACFC-A91D-47FD-A4FF-17E29ED06794}) (Version: 14.34.31921 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.34.31921 (HKLM\...\{5CD0C440-0D9B-435D-B5CF-CC20E04C669B}) (Version: 14.34.31921 - Microsoft Corporation) Microsoft Visual C++ 2022 X86 Additional Runtime - 14.34.31921 (HKLM-x32\...\{9619B693-BC3A-4145-84B9-B3C77E02DCD0}) (Version: 14.34.31921 - Microsoft Corporation) Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.34.31921 (HKLM-x32\...\{C6B0A391-5EFD-4AD5-85E0-670A7FACA5FA}) (Version: 14.34.31921 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{47C2CCDB-7A04-3797-992B-A84D3E90258F}) (Version: 10.0.60833 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 5.0.15 (x64) (HKLM\...\{CA657E97-EF38-4C2D-9CA7-6D51E39F53E8}) (Version: 40.60.31016 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 5.0.15 (x64) (HKLM-x32\...\{1e198010-5aa4-4fa4-b886-a31eb45f4661}) (Version: 5.0.15.31016 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Mini V3 3.7.1 (HKLM-x32\...\Mini V3_is1) (Version: 3.7.1 - Arturia) MKVToolNix 29.0.0 (64-bit) (HKLM-x32\...\MKVToolNix) (Version: 29.0.0 - Moritz Bunkus) Monero GUI Wallet version 0.16.0.3 (HKLM\...\Monero GUI Wallet_is1) (Version: 0.16.0.3 - The Monero Developer Community) Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 108.0.2 (x64 en-US)) (Version: 108.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 107.0.1 - Mozilla) MPC-BE x64 1.5.8.6302 (HKLM\...\{FE09AF6D-78B2-4093-B012-FCDAF78693CE}_is1) (Version: 1.5.8.6302 - MPC-BE Team) Mullvad VPN 2019.1.0 (HKLM\...\Mullvad VPN) (Version: 2019.1.0 - Mullvad VPN) MultiPack Visual C++ Installer V2.8 (HKLM-x32\...\{93E81C5A-55A6-4686-AA8E-532F506EA91A}_is1) (Version: 2.8 - BobSpwg) MusicBee 3.3.7491 (HKLM-x32\...\MusicBee) (Version: 3.3.7491 - Steven Mayall) MusicBrainz Picard (HKLM-x32\...\MusicBrainz Picard) (Version: 2.0.4 - MusicBrainz) NieR Replicant™ ver.1.22474487139... (HKLM-x32\...\NieR Replicant™ ver.1.22474487139..._is1) (Version: 1.22474487139 - RePack) No More Heroes 2 (HKLM-x32\...\No More Heroes 2_is1) (Version: - ) NordUpdater (HKLM\...\{6E35DB82-3D19-4DD6-B8CB-F082815FDE18}_is1) (Version: 1.3.0.160 - Nord Security) NordVPN (HKLM\...\{19465C24-3D5D-4327-B99F-3CC0A1D38151}_is1) (Version: 7.4.6.0 - Nord Security) NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 8.4.2 - Notepad++ Team) Npcap (HKLM-x32\...\NpcapInst) (Version: 0.9997 - Nmap Project) Numerology Calculator (HKLM-x32\...\Numerology Calculator_is1) (Version: 3.41 - ) Numerology Calculator Select (HKLM-x32\...\Numerology Calculator Select_is1) (Version: 1.41 - ) One Commander V2 (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\563b5c94f3a09e20) (Version: 2.5.7.100 - One Commander V2) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Opera GX Stable 94.0.4606.69 (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\Opera GX 94.0.4606.69) (Version: 94.0.4606.69 - Opera Software) Origin (HKLM-x32\...\Origin) (Version: 10.5.115.51547 - Electronic Arts, Inc.) OSDownloader (HKLM-x32\...\{C02C8C82-197C-46C1-AD18-EB0F5BF49F8A}_is1) (Version: 1.5 - OpenSubtitles.org) Overloud TH-U (HKLM\...\{B7B70E5E-3373-4799-B37F-06E603B0FC2B}_is1) (Version: 1.1.8 - Overloud) Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Panda USB Vaccine 1.0.1.4 (HKLM-x32\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version: - Panda Security) PC Remote Controller (HKLM-x32\...\{64351801-5DEA-49A8-9C3D-AE6F7D567A56}) (Version: 4.1.0 - RNStudio) PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2) (Version: - ) Peace (HKLM\...\Peace) (Version: 1.6.3.6 - P.E. Verbeek) PeerBlock 1.2 (r693) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.2.0.693 - PeerBlock, LLC) PG Music DirectX Plugins (64-bit) 2.0.0.0 (HKLM\...\PG_DX_Plugins_64_is1) (Version: - PG Music Inc.) PG Music DirectX Plugins 2.0.0.0 (HKLM-x32\...\PG_DX_Plugins_is1) (Version: - PG Music Inc.) Plex (HKLM-x32\...\Plex) (Version: 1.4.1 - Plex, Inc.) Plex Media Server (HKLM-x32\...\{31f2ca4b-f84d-4930-bc76-30d3ddb40bbc}) (Version: 1.18.3.2156 - Plex, Inc.) Plex Media Server (HKLM-x32\...\{8CC5692D-EC4C-49F9-82ED-92065D829FBB}) (Version: 1.18.2156 - Plex, Inc.) Hidden Plitch 1.2.6 (HKLM\...\d45b2222-59a8-54dc-8e4a-f1dc396456dc) (Version: 1.2.6 - MegaDev GmbH) Plogue sforzando v1.933 (HKLM\...\__ARIA_1014___is1) (Version: v1.933 - Plogue) PotPlayer (HKLM-x32\...\PotPlayer) (Version: 221102 - Kakao Corp.) powerOff version 1.5 (HKLM-x32\...\{A99C48CB-3323-443F-88FB-F6FF96326429}_is1) (Version: 1.5 - ) Process Hacker 2.39 (r124) (HKLM\...\Process_Hacker2_is1) (Version: 2.39.0.124 - wj32) Pushbullet version 338 (HKLM-x32\...\{7578F204-49E7-4830-B051-14C23F408BFE}_is1) (Version: 338 - Pushbullet Inc) Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9313.1 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.56.119.2022 - Realtek) Realtek USB Wireless LAN Driver (HKLM-x32\...\InstallShield_{DBCC4C27-F949-482b-B786-7B3B67587CD2}) (Version: Drv_3.00.0011 - REALTEK Semiconductor Corp.) Realtek USB Wireless LAN Utility (HKLM-x32\...\{9C049509-055C-4CFF-A116-1D12312225EB}) (Version: UI_1.00.0287 - REALTEK Semiconductor Corp.) REAPER (x64) (HKLM\...\REAPER) (Version: - ) Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform) Reference 4 Measure (HKLM\...\{FB394C84-0DF7-4804-A245-C8C97BDD549A}) (Version: 4.4.8.2 - Sonarworks) ReiBoot for Android (HKLM-x32\...\{ReibootforAndroid}_is1) (Version: 2.1.1.5 - Tenorshare, Inc.) RenderDoc (HKLM\...\{2D260B7F-0A00-476B-96E3-FAF8F9F1F1FA}) (Version: 1.1.0 - Baldur Karlsson) Resident Evil Village (HKLM-x32\...\Resident Evil Village_R.G. Mechanics_is1) (Version: - R.G. Mechanics, Lazali) Reveal version 1.0.2 (HKLM\...\{76AAAED0-CFDF-40E3-AEC7-FBEBCCCE0708}_is1) (Version: 1.0.2 - Audeze) reWASD (HKLM\...\reWASD) (Version: 6.4.0.6988 - Disc Soft Ltd) RyzenMasterSDK (HKLM\...\{0A9AA86E-E4A5-4360-B374-62FB9A845667}) (Version: 1.2.3.5 - Advanced Micro Devices, Inc.) Hidden SD Card Formatter (HKLM-x32\...\{A61131DC-B92D-4AD8-A925-E2D6D5FE217C}) (Version: 5.0.1 - SD Association) SD Gundam Battle Alliance (HKLM-x32\...\SD Gundam Battle Alliance_is1) (Version: - ) Sekiro Shadows Die Twice GOTY Edition (HKLM-x32\...\Sekiro Shadows Die Twice GOTY Edition_is1) (Version: - ) Settings (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\Settings) (Version: 1.1.0A - Settings) Shanling Audio Driver v2.29.0 (HKLM-x32\...\Shanling Audio Driver v2.29.0) (Version: 2.29.0 - Shanling) Sifu (HKLM-x32\...\Sifu_is1) (Version: 0.0.0 - DODI-Repacks) SIGNALIS (HKLM-x32\...\SIGNALIS) (Version: - DARKSiDERS) Signalyst HQPlayer 4 Pro (HKLM-x32\...\HQPlayer 4 Pro) (Version: - Signalyst) SIV (HKLM-x32\...\{AAA057C3-10DC-4EB9-A3D6-8208C1BB7411}) (Version: 1.22.1227 - GIGABYTE) Hidden SIV (HKLM-x32\...\InstallShield_{AAA057C3-10DC-4EB9-A3D6-8208C1BB7411}) (Version: 1.22.1227 - GIGABYTE) Smart Backup (x64) (HKLM-x32\...\{BC1FA5CF-A36F-4C61-9638-09D0B431B006}) (Version: 3.21.0326.1 - GIGABYTE) Smart Defrag 6 (HKLM-x32\...\Smart Defrag_is1) (Version: 6.6.0 - IObit) Sonarworks Reference 4 Systemwide (HKLM\...\{0FC5564F-16F7-41DE-ADAC-9C61E1DDEC95}) (Version: 4.4.8.2 - Sonarworks) SoulseekQt version 2017.2.20 (HKLM-x32\...\{8A4E1646-488C-4E5B-AC31-F784400E8D2D}_is1) (Version: 2017.2.20 - Soulseek LLC) Sound Blaster Audigy 5_Audigy Rx (HKLM-x32\...\{81440118-F1CE-4C87-BC8B-F1EB8D3FA190}) (Version: 1.0 - Creative Technology Limited) Sound Blaster Audigy 5_Rx (HKLM-x32\...\{18F11181-EA1A-42AE-AF89-4867C7F7A6FA}) (Version: 1.0 - Creative Technology Limited) SoundToys 5 (HKLM\...\{9849534C-052E-4389-BE26-C92C948B8C16}) (Version: 5.0.1.10839 - SoundToys) SPlayer (HKLM-x32\...\SPlayer) (Version: - ) SpywareBlaster 6.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 6.0.0 - BrightFort LLC) Star Wars Jedi: Fallen Order (HKLM-x32\...\Star Wars Jedi: Fallen Order_is1) (Version: - ) STAR WARS™: Squadrons (HKLM-x32\...\{04e47f47-22cd-436d-a373-472125e7fcd6}) (Version: 1.0.10.39591 - Electronic Arts) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Stellar Photo Recovery Professional (HKLM-x32\...\Stellar Photo Recovery Professional_is1) (Version: 9.0.0.0 - Stellar Information Technology Pvt Ltd.) Stopping Plex (HKLM-x32\...\{62D904BF-8577-433A-BF34-7F7F6E906E9E}) (Version: 1.18.2156 - Plex, Inc.) Hidden Subtitle Edit 3.5.8 (HKLM\...\SubtitleEdit_is1) (Version: 3.5.8.0 - Nikse) Subtitle Translation Wizard 4.9 (HKLM-x32\...\Subtitle Translation Wizard_is1) (Version: - upRedSun, Inc.) SubtitleCreator (HKLM-x32\...\SubtitleCreator) (Version: V2.3rc1 - Erik Vullings) Subtitles Translator version 2.0 (HKLM-x32\...\{D927261C-25B7-4E60-892E-A2D3D1F38C58}_is1) (Version: 2.0 - Mironto) SumatraPDF (HKLM-x32\...\SumatraPDF) (Version: 3.1.2 - Krzysztof Kowalczyk) Switch Sound File Converter (HKLM-x32\...\Switch) (Version: 8.18 - NCH Software) TDR Kotelnikov version 1.5.2 (HKLM\...\TDR Kotelnikov_is1) (Version: 1.5.2 - Tokyo Dawn Labs) TDR Nova version 2.0.2 (HKLM\...\TDR Nova_is1) (Version: 2.0.2 - Tokyo Dawn Labs) TDR VOS SlickEQ version 1.3.1 (HKLM\...\TDR VOS SlickEQ_is1) (Version: 1.3.1 - Tokyo Dawn Labs) TEAC ASIO USB DRIVER (HKLM\...\{AECF8D6E-C9D8-4F80-9C64-55AA6DAC4218}) (Version: 1.0.28.60 - TEAC) Telegram Desktop (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 3.5 - Telegram FZ-LLC) TeraCopy version 3.26 (HKLM\...\TeraCopy_is1) (Version: 3.26 - Code Sector) Text Editor Pro version 10.1.0 (HKLM-x32\...\{FC8AD371-A765-4E22-B25F-D5914D7193F1}}_is1) (Version: 10.1.0 - Lasse Markus Rautiainen) The Hong Kong Massacre (HKLM-x32\...\The Hong Kong Massacre_is1) (Version: - ) Thymesia (HKLM-x32\...\Thymesia_is1) (Version: - ) ToneBoosters Plugins (x64) (HKLM\...\{6089469C-6F2E-435C-9B04-3B17F21F2530}) (Version: 1.2.2.0 - ToneBoosters) Toolkit (HKLM-x32\...\Toolkit) (Version: 1.5.3.3 - Seagate) Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.4.6 - Tweaking.com) Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 112.3 - Ubisoft) UE4 Prerequisites (x64) (HKLM\...\{36EAD5CF-44EF-4FCF-8BE1-D96C4835D7A4}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (HKLM-x32\...\{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden UltData - Windows 7.3.5.8 (HKLM-x32\...\{UltData - Windows}_is1) (Version: 7.3.5.8 - Tenorshare, Inc.) UltimatePluginTool (HKLM-x32\...\UltimateOutsider_UltimatePluginTool) (Version: - UltimateOutsider) UnHackMe 13.50 (HKLM-x32\...\UnHackMe_is1) (Version: - Greatis Software) UpdateAssistant (HKLM\...\{EC4F72E8-52FE-454E-B70F-DBE5C0FA44C5}) (Version: 1.20.0.0 - Microsoft Corporation) Hidden UsbFix Anti-Malware Premium (HKLM-x32\...\Usbfix) (Version: 11.0.1.0 - SOSVirus (SOSVirus.Net)) USBHelperLauncher (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\USBHelperLauncher) (Version: 0.17b - FailedShack) USBPcap 1.5.4.0 (HKLM\...\USBPcap) (Version: 1.5.4.0 - Tomasz Mon) ValhallaDSP Full Bundle (HKLM\...\{1E84E45B-9956-48E0-9BD3-F7101FE17F08}) (Version: 2019 - Valhalla) VALORANT (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\Riot Game valorant.live) (Version: - Riot Games, Inc) VdhCoApp 1.6.3 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version: - DownloadHelper) VeraCrypt (HKLM-x32\...\VeraCrypt) (Version: 1.23-Hotfix-2 - IDRIX) ViGEm Bus Driver (HKLM\...\{4030BA52-E312-462E-B020-CCB5A2AC5497}) (Version: 1.16.116 - Nefarius Software Solutions e.U.) ViPER4Windows version 1.0.5 (HKLM\...\{1A0B530D-277E-4735-8A36-65DCF7E157CB}_is1) (Version: 1.0.5 - ViPERs Audio, Inc) VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.5.0.0 - Elaborate Bytes) VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.12 - VideoLAN) Voxengo Analogflux Suite 1.5.2 (HKLM-x32\...\Voxengo Analogflux Suite) (Version: - ) Voxengo bundle 2018.12 (HKLM\...\Voxengo bundle_is1) (Version: 2018.12 - Voxengo) Voxengo CurveEQ VST 2.6 (HKLM-x32\...\Voxengo CurveEQ VST) (Version: - ) VulkanSDK 1.1.106.0 (HKLM\...\VulkanSDK1.1.106.0) (Version: 1.1.106.0 - LunarG, Inc.) Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.7.6.0 - Azureus Software, Inc.) WeMod (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\WeMod) (Version: 7.1.19 - WeMod) WiinUPro version 0.9.7 (HKLM\...\{40F0DCB4-E81A-45CE-A596-F2D083E1D535}_is1) (Version: 0.9.7 - Justin Keys) WinDirStat 1.1.2 (HKU\S-1-5-21-266282535-48708807-158023499-1001\...\WinDirStat) (Version: - ) Windows Driver Package - Amanero Technologies (cmb38464) MEDIA (07/07/2017 1.0.62) (HKLM\...\5149B871135BAE648CA24646F92632E1054DB056) (Version: 07/07/2017 1.0.62 - Amanero Technologies) Windows Driver Package - GigaDevice (GDDFUDriver) USB (09/03/2019 7.54.5.81) (HKLM\...\E1C31C17E655A1667E552C504E68A8254134BC65) (Version: 09/03/2019 7.54.5.81 - GigaDevice) Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/27/2012 7.0.0000.00004) (HKLM\...\BE156A27AFEAEA39D6A7C9D25CFA8DAFAF91756B) (Version: 08/27/2012 7.0.0000.00004 - Google, Inc.) Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/27/2012 7.0.0000.00004) (HKLM\...\D43FD4059F47ACA9539247D6CF690AAEA503AF2D) (Version: 08/27/2012 7.0.0000.00004 - Google, Inc.) Windows Driver Package - SAMSUNG Electronics Co., Ltd. (dg_ssudbus) USB (12/02/2015 2.12.1.0) (HKLM\...\85A33267F12961AF9ED9AE799DEDA5E62BEA236F) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. ) Windows Driver Package - SAMSUNG Electronics Co., Ltd. (ssudmdm) Modem (12/02/2015 2.12.1.0) (HKLM\...\88ED314360B98E6E82E7CC3201FAEB4A9FD291B4) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. ) Windows Driver Package - SAMSUNG Electronics Co., Ltd. (WinUSB) AndroidUsbDeviceClass (12/02/2015 2.12.1.0) (HKLM\...\701281E8283E9E3681220099A9DA5013A5A437AF) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. ) Windows PC Health Check (HKLM\...\{77ACFAF7-E5AB-410D-BA14-BBEBF89422DE}) (Version: 3.1.2109.29003 - Microsoft Corporation) Windows PC Health Check (HKLM\...\{804A0628-543B-4984-896C-F58BF6A54832}) (Version: 3.7.2204.15001 - Microsoft Corporation) Wireshark 3.4.2 64-bit (HKLM-x32\...\Wireshark) (Version: 3.4.2 - The Wireshark developer community, hxxps://www.wireshark.org) Wise Force Deleter 1.5.2 (HKLM-x32\...\Wise Force Deleter_is1) (Version: 1.5.2 - WiseCleaner.com, Inc.) Wondershare Helper Compact 2.5.3 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.3 - Wondershare) Wondershare Recoverit(Build 10.0.7.3) (HKLM-x32\...\{829555DC-31E5-4FEA-B350-8FCF24CECD95}_is1) (Version: 10.0.7.3 - Wondershare Software Co.,Ltd.) Wondershare Video Converter Ultimate(Build 10.4.1.188) (HKLM-x32\...\Video Converter Ultimate_is1) (Version: 10.4.1.188 - Wondershare Software) XBCD Uninstaller (HKLM\...\{04054166-0801-48A9-89E0-BC4B53FE7A81}_is1) (Version: 0.2.7 - XBCD Project) Xilisoft Audio Converter Pro (HKLM-x32\...\Xilisoft Audio Converter Pro) (Version: 6.4.0.20120801 - Xilisoft) XLN Online Installer (HKLM\...\XLN Online Installer Inno Setup ID_is1) (Version: - ) XMOS USB Audio 2.0 Stereo Driver v4.13.0 (HKLM-x32\...\Software_XMOS_USBAudioStDriver_30C8_Setup) (Version: 4.13.0 - XMOS) Xpadder version 5.7 (HKLM-x32\...\{0DCE54A9-7256-4132-9D4E-1A64AE35E9B1}_is1) (Version: 5.7 - Xpadder, Inc.) Zone of the Enders 2nd Runner (HKLM-x32\...\Zone of the Enders 2nd Runner_is1) (Version: - ) Packages: ========= 9 zip -> C:\Program Files\WindowsApps\184MagikHub.9zip_3.3.75.0_x64__hvr7qkvwfhvx6 [2020-07-14] (Magik Hub) [MS Ad] AIDA64 -> C:\Program Files\WindowsApps\FinalWire.AIDA64_2.1.0.0_x64__a2fqy4btbmbvp [2022-01-30] (FinalWire) AMD Link -> C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDLink_10.22.20004.0_x64__0a9344xs7nr4m [2022-08-19] (Advanced Micro Devices Inc.) Audirvana -> C:\Program Files\WindowsApps\Audirvana.Audirvana-4118-9484-d80dbb7827cd_3.5.51.0_x64__q3nymrkmej12j [2023-01-10] (Audirvana) [Startup Task] Audirvāna Studio -> C:\Program Files\WindowsApps\Audirvana.Audirvana-4118-9684-d80dbb7827cd_2.2.2.0_x64__q3nymrkmej12j [2023-01-10] (Audirvana) [Startup Task] Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.) CUE Splitter -> C:\Program Files\WindowsApps\38812MedievalSoftware.CUESplitter_2.0.8.0_x64__qfb5004rcjhse [2018-12-26] (Medieval Software) Deezer Music -> C:\Program Files\WindowsApps\Deezer.62021768415AF_5.30.400.0_x86__q7m17pa7q8kj0 [2023-01-04] (Deezer SA) Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.0.2204.0_x64__rz1tebttyb220 [2019-11-15] (Dolby Laboratories) HEIC Image Viewer - Converter Supported -> C:\Program Files\WindowsApps\37309CoolLeGetInc.HEICImageViewer-ConverterSupport_2.2.44.0_neutral__g0y9d13zmhd68 [2022-09-01] (CoolLeGet Inc) IrfanView -> C:\Program Files\WindowsApps\30067IrfanSkiljanIrfanVie.IrfanView_4.6.2.0_x86__psgec73n2n7ne [2023-01-17] (Irfan Skiljan (IrfanView)) Media Player -> C:\Program Files\WindowsApps\YellowElephantProductions.MediaPlayerS_1.256.164.0_x64__p3e1zgp7z7szg [2022-11-22] (Yellow Elephant Productions) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-11] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-11] (Microsoft Corporation) [MS Ad] Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.18.3104.0_x64__8wekyb3d8bbwe [2022-04-28] (Microsoft Studios) Mp3tag -> C:\Program Files\WindowsApps\35795FlorianHeidenreich.Mp3tag_3.10.0.0_x86__rf0p6xgxmspcc [2021-10-15] (Florian Heidenreich) Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-02-16] (Netflix, Inc.) Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-10-23] (Microsoft Corporation) Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2018-11-30] (Plex) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.35.266.0_x64__dt26b99r8h8gj [2023-01-13] (Realtek Semiconductor Corp) RECOIL -> C:\Program Files\WindowsApps\9998PiotrFusik.RECOIL_6.3.2.0_x64__5dbjqw3zx3tpw [2022-12-11] (Piotr Fusik) Reddit -> C:\Program Files\WindowsApps\redditTV.Reddit_1.0.0.0_x86__99kbdge22ed1a [2022-01-10] (Reddit Inc.) Samsung Flow -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SamsungFlux_4.9.6.0_x64__wyx1vj98g3asy [2022-11-24] (Samsung Electronics Co, Ltd.) Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.15.12020.0_x64__8wekyb3d8bbwe [2022-12-08] (Microsoft Studios) [MS Ad] Speedtest by Ookla -> C:\Program Files\WindowsApps\Ookla.SpeedtestbyOokla_1.15.163.0_x64__43tkc6nmykmb6 [2022-01-10] (Ookla) VLC -> C:\Program Files\WindowsApps\VideoLAN.VLC_3.2.1.0_x64__paz6r1rewnh0a [2022-01-10] (VideoLAN) WiFi Analyzer -> C:\Program Files\WindowsApps\19965MATTHAFNER.WIFIANALYZER_2.6.0.0_x64__gs5k5vmxr2ste [2022-01-10] (Matt Hafner) WindowsAppRuntime.1.0 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.0_4.528.1755.0_x64__8wekyb3d8bbwe [2022-08-20] (Microsoft Corporation) WindowsAppRuntime.1.0 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.0_4.528.1755.0_x86__8wekyb3d8bbwe [2022-08-20] (Microsoft Corporation) WinZip Universal -> C:\Program Files\WindowsApps\WinZipComputing.WinZipUniversal_1.5.13516.0_x64__3ykzqggjzj4z0 [2019-05-31] (WinZip Computing) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-266282535-48708807-158023499-1001_Classes\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}\InprocServer32 -> C:\Users\Mark\AppData\Local\Microsoft\EdgeUpdate\1.3.171.39\psuser_64.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-266282535-48708807-158023499-1001_Classes\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32 -> C:\Users\Mark\AppData\Local\Microsoft\EdgeUpdate\1.3.171.39\psuser_64.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-266282535-48708807-158023499-1001_Classes\CLSID\{9B6D38F3-8EF4-48A5-AD30-FFFFFFFFFFFF}\InprocServer32 -> C:\Program Files\Honeyview\HVShell64.dll (Bandisoft -> Bandisoft.com) CustomCLSID: HKU\S-1-5-21-266282535-48708807-158023499-1001_Classes\CLSID\{A7F69DDF-0DDE-450E-AFBF-4E449E90E980}\localserver32 -> C:\Program Files\REAPER (x64)\reaper.exe (Cockos Incorporated -> Cockos Incorporated) [File not signed] CustomCLSID: HKU\S-1-5-21-266282535-48708807-158023499-1001_Classes\CLSID\{B29F5F83-90DF-479A-BDE7-8A9F4412E394}\InprocServer32 -> C:\Users\Mark\AppData\Local\Microsoft\EdgeUpdate\1.3.171.39\psuser_64.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-266282535-48708807-158023499-1001_Classes\CLSID\{D6169671-068B-42ED-B764-9A7AA7BA1CD3} -> [MEGAsync] => C:\Users\Mark\Documents\MEGAsync [2019-01-11 01:48] CustomCLSID: HKU\S-1-5-21-266282535-48708807-158023499-1001_Classes\CLSID\{FD848478-65F5-4F01-ACD9-69195EC3631F}\localserver32 -> C:\Program Files\cFosSpeed\cfosspeed.exe (cFos Software GmbH -> cFos Software GmbH) ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Mark\AppData\Local\MEGAsync\ShellExtX64.dll [2022-10-20] (Mega Limited -> ) ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Mark\AppData\Local\MEGAsync\ShellExtX64.dll [2022-10-20] (Mega Limited -> ) ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Mark\AppData\Local\MEGAsync\ShellExtX64.dll [2022-10-20] (Mega Limited -> ) ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\57.0.5.0\drivefsext.dll [2022-04-14] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\57.0.5.0\drivefsext.dll [2022-04-14] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\57.0.5.0\drivefsext.dll [2022-04-14] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\57.0.5.0\drivefsext.dll [2022-04-14] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed] ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Mark\AppData\Local\MEGAsync\ShellExtX64.dll [2022-10-20] (Mega Limited -> ) ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Mark\AppData\Local\MEGAsync\ShellExtX64.dll [2022-10-20] (Mega Limited -> ) ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Mark\AppData\Local\MEGAsync\ShellExtX64.dll [2022-10-20] (Mega Limited -> ) ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed] ContextMenuHandlers1: [0HVContext] -> {9B6D38F3-8EF4-48A5-AD30-FFFFFFFFFFFF} => C:\Program Files\Honeyview\HVShell64.dll [2021-05-24] (Bandisoft -> Bandisoft.com) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2022-06-15] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2022-10-22] (IP Izmaylov Artem Andreevich -> AIMP DevTeam) ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2020-12-31] (Notepad++ -> ) ContextMenuHandlers1: [axcrypt.File] -> {C3DFC144-30F8-4138-81F9-578DBEB9324A} => C:\Program Files\AxCrypt\AxCrypt\ShellExt.dll [2018-11-07] (AxCrypt AB -> AxCrypt AB) ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\57.0.5.0\drivefsext.dll [2022-04-14] (Google LLC -> Google, Inc.) ContextMenuHandlers1: [GpgEX] -> {CCD955E4-5C16-4A33-AFDA-A8947A94946B} => C:\Program Files (x86)\Gpg4win\bin_64\gpgex.dll [2018-11-13] (g10 Code GmbH) [File not signed] ContextMenuHandlers1: [IObitUninstaller] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2022-10-20] (IObit CO., LTD -> IObit) ContextMenuHandlers1: [LockHunterShellExt] -> {0BB27CDA-7029-4C0E-9C56-D922B229F0EB} => C:\Program Files\LockHunter\LHShellExt64.dll [2017-07-20] (Crystal Rich Ltd -> Crystal Rich Ltd) ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Mark\AppData\Local\MEGAsync\ShellExtX64.dll [2022-10-20] (Mega Limited -> ) ContextMenuHandlers1: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2018-10-22] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd) [File not signed] ContextMenuHandlers1: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-8C76A452CC54} => C:\WINDOWS\System32\IObitSmartDefragExtension.dll [2019-09-12] (IObit Information Technology -> IObit) ContextMenuHandlers1: [TeraCopy] -> {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} => C:\Program Files\TeraCopy\TeraCopyExt.dll [2016-12-07] (Code Sector -> ) ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG -> Elaborate Bytes AG) ContextMenuHandlers2: [LockHunterShellExt] -> {0BB27CDA-7029-4C0E-9C56-D922B229F0EB} => C:\Program Files\LockHunter\LHShellExt64.dll [2017-07-20] (Crystal Rich Ltd -> Crystal Rich Ltd) ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Mark\AppData\Local\MEGAsync\ShellExtX64.dll [2022-10-20] (Mega Limited -> ) ContextMenuHandlers2: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2018-10-22] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd) [File not signed] ContextMenuHandlers2: [TeraCopy] -> {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} => C:\Program Files\TeraCopy\TeraCopyExt.dll [2016-12-07] (Code Sector -> ) ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG -> Elaborate Bytes AG) ContextMenuHandlers3-x32: [FAExt] -> {05672D66-9736-42F5-8BEB-FA1DD3CA51C4} => C:\Program Files (x86)\FileASSASSIN\FileASSASSINExt.dll [2007-03-30] (Malwarebytes) [File not signed] ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-11-23] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Mark\AppData\Local\MEGAsync\ShellExtX64.dll [2022-10-20] (Mega Limited -> ) ContextMenuHandlers4: [0HVContext] -> {9B6D38F3-8EF4-48A5-AD30-FFFFFFFFFFFF} => C:\Program Files\Honeyview\HVShell64.dll [2021-05-24] (Bandisoft -> Bandisoft.com) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2022-06-15] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2022-10-22] (IP Izmaylov Artem Andreevich -> AIMP DevTeam) ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\57.0.5.0\drivefsext.dll [2022-04-14] (Google LLC -> Google, Inc.) ContextMenuHandlers4: [GpgEX] -> {CCD955E4-5C16-4A33-AFDA-A8947A94946B} => C:\Program Files (x86)\Gpg4win\bin_64\gpgex.dll [2018-11-13] (g10 Code GmbH) [File not signed] ContextMenuHandlers4: [IObitUninstaller] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2022-10-20] (IObit CO., LTD -> IObit) ContextMenuHandlers4: [LockHunterShellExt] -> {0BB27CDA-7029-4C0E-9C56-D922B229F0EB} => C:\Program Files\LockHunter\LHShellExt64.dll [2017-07-20] (Crystal Rich Ltd -> Crystal Rich Ltd) ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Mark\AppData\Local\MEGAsync\ShellExtX64.dll [2022-10-20] (Mega Limited -> ) ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2022-01-28] (Piriform Software Ltd -> Piriform Software Ltd) ContextMenuHandlers4: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2018-10-22] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd) [File not signed] ContextMenuHandlers4: [TeraCopy] -> {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} => C:\Program Files\TeraCopy\TeraCopyExt.dll [2016-12-07] (Code Sector -> ) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2022-11-30] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\57.0.5.0\drivefsext.dll [2022-04-14] (Google LLC -> Google, Inc.) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2022-06-15] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [axcrypt.File] -> {C3DFC144-30F8-4138-81F9-578DBEB9324A} => C:\Program Files\AxCrypt\AxCrypt\ShellExt.dll [2018-11-07] (AxCrypt AB -> AxCrypt AB) ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File ContextMenuHandlers6: [IObitUninstaller] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2022-10-20] (IObit CO., LTD -> IObit) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-11-23] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2022-01-28] (Piriform Software Ltd -> Piriform Software Ltd) ContextMenuHandlers6: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-8C76A452CC54} => C:\WINDOWS\System32\IObitSmartDefragExtension.dll [2019-09-12] (IObit Information Technology -> IObit) ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\System32\StartMenuHelper64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed] ContextMenuHandlers6: [TeraCopy] -> {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} => C:\Program Files\TeraCopy\TeraCopyExt.dll [2016-12-07] (Code Sector -> ) ContextMenuHandlers1_S-1-5-21-266282535-48708807-158023499-1001: [0HVContext] -> {9B6D38F3-8EF4-48A5-AD30-FFFFFFFFFFFF} => C:\Program Files\Honeyview\HVShell64.dll [2021-05-24] (Bandisoft -> Bandisoft.com) ContextMenuHandlers4_S-1-5-21-266282535-48708807-158023499-1001: [0HVContext] -> {9B6D38F3-8EF4-48A5-AD30-FFFFFFFFFFFF} => C:\Program Files\Honeyview\HVShell64.dll [2021-05-24] (Bandisoft -> Bandisoft.com) ContextMenuHandlers4_S-1-5-21-266282535-48708807-158023499-1001: [Fb2kShellExt] -> {511D48AF-9E45-4CB8-8F02-9C1BE4BC3CF8} => -> No File ==================== Codecs (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Drivers32: [vidc.i420] => C:\Windows\System32\lvcod64.dll [175392 2012-10-26] (Logitech, Inc. -> Logitech Inc.) HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\System32\x264vfw64.dll [3799552 2017-07-30] (x264vfw project) [File not signed] HKLM\...\Drivers32: [VIDC.HFYU] => C:\Windows\System32\huffyuv.dll [55296 2005-01-21] () [File not signed] HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\System32\lagarith.dll [148992 2011-12-07] () [File not signed] HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\System32\xvidvfw.dll [310784 2019-12-28] () [File not signed] HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\System32\ac3acm.acm [180736 2012-07-21] (fccHandler) [File not signed] HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech, Inc. -> Logitech Inc.) HKLM\...\Drivers32: [vidc.iv50] => C:\Program Files (x86)\SPlayer\ir50_32.dll [755200 2008-08-04] (Intel Corporation) [File not signed] HKLM\...\Drivers32: [vidc.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [284160 2019-12-28] () [File not signed] HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\SysWOW64\x264vfw.dll [3850240 2017-07-30] (x264vfw project) [File not signed] HKLM\...\Drivers32: [VIDC.HFYU] => C:\Windows\SysWOW64\huffyuv.dll [39936 2004-05-18] (Disappearing Inc.) [File not signed] HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-07] () [File not signed] HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\ac3acm.acm [122880 2012-07-21] (fccHandler) [File not signed] HKLM\...\Drivers32: [msacm.lameacm] => C:\Windows\SysWOW64\lameACM.acm [473088 2015-02-25] (hxxp://www.mp3dev.org/) [File not signed] HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\SysWOW64\ff_vfw.dll [112128 2015-10-24] () [File not signed] ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Mark\Desktop\Google Drive.lnk -> C:\Program Files\Google\Drive File Stream\launch.bat () ==================== Loaded Modules (Whitelisted) ============= 2017-03-06 04:23 - 2017-03-06 04:23 - 000119808 _____ () [File not signed] C:\Program Files (x86)\Deluge\_cffi_backend.pyd 2016-12-17 14:44 - 2016-12-17 14:44 - 000091648 _____ () [File not signed] C:\Program Files (x86)\Deluge\_ctypes.pyd 2016-12-17 14:46 - 2016-12-17 14:46 - 001016832 _____ () [File not signed] C:\Program Files (x86)\Deluge\_hashlib.pyd 2016-12-17 14:45 - 2016-12-17 14:45 - 000046592 _____ () [File not signed] C:\Program Files (x86)\Deluge\_socket.pyd 2016-12-17 14:45 - 2016-12-17 14:45 - 001410048 _____ () [File not signed] C:\Program Files (x86)\Deluge\_ssl.pyd 2011-04-09 02:03 - 2011-04-09 02:03 - 000208384 _____ () [File not signed] C:\Program Files (x86)\Deluge\atk.pyd 2016-12-17 14:44 - 2016-12-17 14:44 - 000071168 _____ () [File not signed] C:\Program Files (x86)\Deluge\bz2.pyd 2010-11-02 13:35 - 2010-11-02 13:35 - 000069632 _____ () [File not signed] C:\Program Files (x86)\Deluge\cairo._cairo.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 001828864 _____ () [File not signed] C:\Program Files (x86)\Deluge\cryptography.hazmat.bindings._openssl.pyd 2012-02-08 16:50 - 2012-02-08 16:50 - 000538324 _____ () [File not signed] C:\Program Files (x86)\Deluge\freetype6.dll 2011-04-09 01:59 - 2011-04-09 01:59 - 000263168 _____ () [File not signed] C:\Program Files (x86)\Deluge\gio._gio.pyd 2011-04-09 01:59 - 2011-04-09 01:59 - 000058368 _____ () [File not signed] C:\Program Files (x86)\Deluge\glib._glib.pyd 2011-04-09 01:59 - 2011-04-09 01:59 - 000113152 _____ () [File not signed] C:\Program Files (x86)\Deluge\gobject._gobject.pyd 2011-04-09 02:02 - 2011-04-09 02:02 - 001882624 _____ () [File not signed] C:\Program Files (x86)\Deluge\gtk._gtk.pyd 2011-04-09 02:03 - 2011-04-09 02:03 - 000018944 _____ () [File not signed] C:\Program Files (x86)\Deluge\gtk.glade.pyd 2017-05-12 14:30 - 2017-05-12 14:30 - 000156686 _____ () [File not signed] C:\Program Files (x86)\Deluge\lib\gtk-2.0\2.10.0\engines\libmurrine.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000062248 _____ () [File not signed] C:\Program Files (x86)\Deluge\lib\gtk-2.0\2.10.0\engines\libpixmap.dll 2012-02-08 16:50 - 2012-02-08 16:50 - 001294335 _____ () [File not signed] C:\Program Files (x86)\Deluge\libcairo-2.dll 2012-02-08 16:50 - 2012-02-08 16:50 - 000143096 _____ () [File not signed] C:\Program Files (x86)\Deluge\libexpat-1.dll 2012-02-08 16:50 - 2012-02-08 16:50 - 000279059 _____ () [File not signed] C:\Program Files (x86)\Deluge\libfontconfig-1.dll 2017-03-06 04:23 - 2017-03-06 04:23 - 000099840 _____ () [File not signed] C:\Program Files (x86)\Deluge\libgcc_s_sjlj-1.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000168833 _____ () [File not signed] C:\Program Files (x86)\Deluge\libglade-2.0-0.dll 2017-03-06 04:23 - 2017-03-06 04:23 - 000322560 _____ () [File not signed] C:\Program Files (x86)\Deluge\libmpg123-0.dll 2017-03-06 04:23 - 2017-03-06 04:23 - 000032768 _____ () [File not signed] C:\Program Files (x86)\Deluge\libogg-0.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000230529 _____ () [File not signed] C:\Program Files (x86)\Deluge\libpng14-14.dll 2017-02-19 09:11 - 2017-02-19 09:11 - 002596352 _____ () [File not signed] C:\Program Files (x86)\Deluge\libtorrent.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000174592 _____ () [File not signed] C:\Program Files (x86)\Deluge\libvorbis-0.dll 2017-03-06 04:23 - 2017-03-06 04:23 - 000040448 _____ () [File not signed] C:\Program Files (x86)\Deluge\libvorbisfile-3.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 001225225 _____ () [File not signed] C:\Program Files (x86)\Deluge\libxml2-2.dll 2014-10-04 10:10 - 2014-10-04 10:10 - 000008192 _____ () [File not signed] C:\Program Files (x86)\Deluge\markupsafe._speedups.pyd 2011-04-09 02:03 - 2011-04-09 02:03 - 000111616 _____ () [File not signed] C:\Program Files (x86)\Deluge\pango.pyd 2011-04-09 02:03 - 2011-04-09 02:03 - 000017920 _____ () [File not signed] C:\Program Files (x86)\Deluge\pangocairo.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000936960 _____ () [File not signed] C:\Program Files (x86)\Deluge\PIL._imaging.pyd 2016-12-17 14:44 - 2016-12-17 14:44 - 000136704 _____ () [File not signed] C:\Program Files (x86)\Deluge\pyexpat.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000022016 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.base.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000013824 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.bufferproxy.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000016384 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.cdrom.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000025088 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.color.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000014848 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.constants.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000021504 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.display.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000031744 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.draw.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000018944 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.event.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000012288 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.fastevent.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000021504 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.image.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000012800 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.joystick.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000009216 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.key.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000029184 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.mask.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000061440 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.math.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000027136 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.mixer.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000013824 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.mixer_music.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000010240 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.mouse.pyd 2012-02-02 13:16 - 2012-02-02 13:16 - 000015872 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.movie.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000008704 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.overlay.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000030720 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.pixelarray.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000018944 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.pixelcopy.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000023552 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.rect.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000011776 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.rwobject.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000012800 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.scrap.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000228864 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.surface.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000007680 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.surflock.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000011264 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.time.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000041472 _____ () [File not signed] C:\Program Files (x86)\Deluge\pygame.transform.pyd 2015-09-13 10:07 - 2015-09-13 10:07 - 000395776 _____ () [File not signed] C:\Program Files (x86)\Deluge\pythoncom27.dll 2015-09-13 10:07 - 2015-09-13 10:07 - 000109056 _____ () [File not signed] C:\Program Files (x86)\Deluge\pywintypes27.dll 2016-07-20 08:53 - 2016-07-20 08:53 - 000058368 _____ () [File not signed] C:\Program Files (x86)\Deluge\rencode._rencode.pyd 2017-03-06 04:23 - 2017-03-06 04:23 - 000388096 _____ () [File not signed] C:\Program Files (x86)\Deluge\SDL.dll 2017-03-06 04:23 - 2017-03-06 04:23 - 000644608 _____ () [File not signed] C:\Program Files (x86)\Deluge\SDL_mixer.dll 2016-12-17 14:44 - 2016-12-17 14:44 - 000010240 _____ () [File not signed] C:\Program Files (x86)\Deluge\select.pyd 2009-07-15 03:57 - 2009-07-15 03:57 - 000256512 _____ () [File not signed] C:\Program Files (x86)\Deluge\smpeg.dll 2016-12-17 14:44 - 2016-12-17 14:44 - 000687104 _____ () [File not signed] C:\Program Files (x86)\Deluge\unicodedata.pyd 2015-09-13 10:07 - 2015-09-13 10:07 - 000099328 _____ () [File not signed] C:\Program Files (x86)\Deluge\win32api.pyd 2015-09-13 10:07 - 2015-09-13 10:07 - 000360448 _____ () [File not signed] C:\Program Files (x86)\Deluge\win32com.shell.shell.pyd 2015-09-13 10:07 - 2015-09-13 10:07 - 000017408 _____ () [File not signed] C:\Program Files (x86)\Deluge\win32event.pyd 2015-09-13 10:07 - 2015-09-13 10:07 - 000118784 _____ () [File not signed] C:\Program Files (x86)\Deluge\win32file.pyd 2015-09-13 10:07 - 2015-09-13 10:07 - 000166912 _____ () [File not signed] C:\Program Files (x86)\Deluge\win32gui.pyd 2015-09-13 10:07 - 2015-09-13 10:07 - 000023040 _____ () [File not signed] C:\Program Files (x86)\Deluge\win32pipe.pyd 2015-09-13 10:07 - 2015-09-13 10:07 - 000035840 _____ () [File not signed] C:\Program Files (x86)\Deluge\win32process.pyd 2012-02-08 16:51 - 2012-02-08 16:51 - 000100352 _____ () [File not signed] C:\Program Files (x86)\Deluge\zlib1.dll 2017-03-06 04:23 - 2017-03-06 04:23 - 000019456 _____ () [File not signed] C:\Program Files (x86)\Deluge\zope.interface._zope_interface_coptimizations.pyd 2022-10-25 18:25 - 2022-10-25 18:25 - 001868800 _____ () [File not signed] C:\Program Files (x86)\GIGABYTE\AppCenter\BDR_info.dll 2023-01-18 10:01 - 2023-01-18 12:30 - 020100608 _____ () [File not signed] C:\Program Files\NordVPN\7.4.6.0\telio.dll 2019-04-21 00:56 - 2016-08-13 21:36 - 005217280 _____ (Artifex Software et al.) [File not signed] C:\Program Files (x86)\SumatraPDF\libmupdf.dll 2018-12-09 00:30 - 2018-10-22 14:11 - 000382608 _____ (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd) [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll 2019-05-01 15:24 - 2016-04-07 13:16 - 000562176 _____ (Creative Technology Ltd) [File not signed] C:\Program Files (x86)\Creative\SBAudigy5Rx\SB Audigy Control Panel\CTAudEp.dll 2019-05-01 15:24 - 2015-01-26 10:48 - 000239104 _____ (Creative Technology Ltd) [File not signed] C:\Program Files (x86)\Creative\SBAudigy5Rx\SB Audigy Control Panel\CTLoadRs.dll 2019-05-01 15:24 - 2014-11-20 08:23 - 000837120 _____ (Creative Technology Ltd) [File not signed] C:\Program Files (x86)\Creative\SBAudigy5Rx\SB Audigy Control Panel\HookWndU.DLL 2019-05-01 15:25 - 2008-08-07 13:20 - 000069632 _____ (Creative Technology Ltd) [File not signed] C:\Program Files (x86)\Creative\Shared Files\Module Loader\Audio Emulator\CTAudSeu.dll 2019-05-01 15:25 - 2006-06-07 15:23 - 000126976 _____ (Creative Technology Ltd) [File not signed] C:\Program Files (x86)\Creative\Shared Files\Module Loader\RC System\RCRx\RcHidUsb.dll 2019-04-29 19:00 - 2009-03-18 15:00 - 000151552 _____ (Creative Technology Ltd) [File not signed] C:\Program Files (x86)\Creative\ShareDLL\CADI\CTCadiEP.dll 2019-04-29 19:03 - 2015-12-18 17:18 - 000010240 _____ (Creative Technology Ltd) [File not signed] C:\WINDOWS\System32\CTDCRES.DLL 2019-05-01 15:25 - 2007-12-13 16:36 - 000077824 _____ (Creative Technology Ltd.) [File not signed] C:\Program Files (x86)\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll 2019-05-01 15:25 - 2007-05-04 14:27 - 000233472 _____ (Creative Technology Ltd.) [File not signed] C:\Program Files (x86)\Creative\Shared Files\Module Loader\OSD\PanelSvc.dll 2019-05-01 15:25 - 2009-03-16 13:55 - 000020480 _____ (Creative Technology Ltd.) [File not signed] C:\Program Files (x86)\Creative\Shared Files\Module Loader\RC System\AudSet.crl 2019-05-01 15:25 - 2009-12-21 14:14 - 000065536 _____ (Creative Technology Ltd.) [File not signed] C:\Program Files (x86)\Creative\Shared Files\Module Loader\RC System\EAXCADI.DLL 2019-05-01 15:25 - 2009-04-03 13:50 - 000036963 _____ (Creative Technology Ltd.) [File not signed] C:\Program Files (x86)\Creative\Shared Files\Module Loader\RC System\EAXMod.dll 2019-05-01 15:25 - 2006-06-07 15:23 - 000053248 _____ (Creative Technology Ltd.) [File not signed] C:\Program Files (x86)\Creative\Shared Files\Module Loader\RC System\RCRx\RCLDM.dll 2019-05-01 15:25 - 2009-09-16 16:59 - 000009728 _____ (Creative Technology Ltd.) [File not signed] C:\Program Files (x86)\Creative\Shared Files\Module Loader\RC System\RCSystem.CRL 2019-05-01 15:25 - 2009-12-16 09:24 - 000323584 _____ (Creative Technology Ltd.) [File not signed] C:\Program Files (x86)\Creative\Shared Files\Module Loader\RC System\RCSystem.dll 2012-02-08 16:50 - 2012-02-08 16:50 - 000152489 _____ (Free Software Foundation) [File not signed] C:\Program Files (x86)\Deluge\intl.dll 2018-11-13 02:24 - 2018-11-13 02:24 - 001040896 _____ (g10 Code GmbH) [File not signed] C:\Program Files (x86)\Gpg4win\bin_64\gpgex.dll 2022-08-24 11:45 - 2022-08-24 11:45 - 000242176 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) [File not signed] C:\Program Files (x86)\GIGABYTE\AppCenter\yccV3.dll 2021-11-05 17:07 - 2021-11-05 17:07 - 000236544 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) [File not signed] C:\Program Files (x86)\Gigabyte\EasyTuneEngineService\yccV3.dll 2022-11-10 15:39 - 2013-03-08 11:28 - 000187392 _____ (Gigabyte Technology CO., LTD.) [File not signed] C:\Program Files\Gigabyte\Smart Backup\RescuePlan.dll 2022-11-10 15:39 - 2018-10-19 10:44 - 000751616 _____ (Gigabyte Technology CO., LTD.) [File not signed] C:\Program Files\Gigabyte\Smart Backup\srpCore.dll 2022-06-15 17:00 - 2022-06-15 17:00 - 000094720 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll 2023-01-20 13:22 - 2021-03-17 15:33 - 001137152 _____ (Igor Pavlov) [File not signed] C:\Users\Mark\AppData\Local\Temp\mwbA3BB.tmp\7z.dll 2018-07-15 15:15 - 2018-07-15 15:15 - 003664696 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenuDLL.dll 2018-07-15 15:15 - 2018-07-15 15:15 - 000291128 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\WINDOWS\System32\StartMenuHelper64.dll 2016-12-17 14:43 - 2016-12-17 14:43 - 002639872 _____ (Python Software Foundation) [File not signed] C:\Program Files (x86)\Deluge\python27.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000333729 _____ (Red Hat Software) [File not signed] C:\Program Files (x86)\Deluge\libpango-1.0-0.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000104729 _____ (Red Hat Software) [File not signed] C:\Program Files (x86)\Deluge\libpangocairo-1.0-0.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000815421 _____ (Red Hat Software) [File not signed] C:\Program Files (x86)\Deluge\libpangoft2-1.0-0.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000108945 _____ (Red Hat Software) [File not signed] C:\Program Files (x86)\Deluge\libpangowin32-1.0-0.dll 2017-11-01 12:58 - 2017-11-01 12:58 - 001141248 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files (x86)\Adguard\SQLite.Interop.dll 2012-02-08 16:50 - 2012-02-08 16:50 - 000163476 _____ (Sun Microsystems Inc.) [File not signed] C:\Program Files (x86)\Deluge\libatk-1.0-0.dll 2022-11-14 08:40 - 2022-10-20 06:45 - 000817152 _____ (Tabibito Technology) [File not signed] C:\Program Files (x86)\K-Lite Codec Pack\Icaros\64-bit\IcarosPropertyHandler.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 001222182 _____ (The GLib developer community) [File not signed] C:\Program Files (x86)\Deluge\libgio-2.0-0.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 001242929 _____ (The GLib developer community) [File not signed] C:\Program Files (x86)\Deluge\libglib-2.0-0.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000036986 _____ (The GLib developer community) [File not signed] C:\Program Files (x86)\Deluge\libgmodule-2.0-0.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000341594 _____ (The GLib developer community) [File not signed] C:\Program Files (x86)\Deluge\libgobject-2.0-0.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000044287 _____ (The GLib developer community) [File not signed] C:\Program Files (x86)\Deluge\libgthread-2.0-0.dll 2012-02-08 16:50 - 2012-02-08 16:50 - 000285194 _____ (The GTK developer community) [File not signed] C:\Program Files (x86)\Deluge\libgdk_pixbuf-2.0-0.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 000932373 _____ (The GTK developer community) [File not signed] C:\Program Files (x86)\Deluge\libgdk-win32-2.0-0.dll 2012-02-08 16:51 - 2012-02-08 16:51 - 004939820 _____ (The GTK developer community) [File not signed] C:\Program Files (x86)\Deluge\libgtk-win32-2.0-0.dll 2016-07-15 08:36 - 2016-07-15 08:36 - 001265152 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Deluge\LIBEAY32.dll 2016-07-15 08:36 - 2016-07-15 08:36 - 000274432 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Deluge\SSLEAY32.dll 2015-10-14 01:15 - 2015-10-14 01:15 - 002042368 _____ (TODO: ) [File not signed] C:\Program Files (x86)\GIGABYTE\AppCenter\osvi.dll 2021-06-22 15:45 - 2021-06-22 15:45 - 009127424 _____ (TODO: ) [File not signed] C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\GbtNvGpuLib.dll 2021-10-14 03:35 - 2013-10-03 21:42 - 000844288 _____ (ViPERs Audio, Inc.) [File not signed] C:\Program Files\ViPER4Windows1\ViPER4Windows.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\logWSVCUUpdateHelper.log:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\RakhniDecryptor.1.21.26.1_07.04.2019_19.25.01_log.txt:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\RakhniDecryptor.1.21.26.1_09.04.2019_19.35.25_log.txt:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\RakhniDecryptor.1.21.26.1_12.12.2018_02.07.02_log.txt:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\WINDOWS\system32\atiapfxx.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\WINDOWS\system32\CmeauSPDIF2.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\WINDOWS\system32\fbnative.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\WINDOWS\system32\NetSetupMig.log:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\WINDOWS\Ctregrun.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\WINDOWS\regtlib.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\WINDOWS\Updreg.EXE:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\WINDOWS\SysWOW64\Eaolog.log:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\WINDOWS\SysWOW64\MC24.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [274] AlternateDataStreams: C:\Users\Mark\Desktop\BDGandCrabDecryptTool.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\Users\Mark\Downloads\Apollo_11_crew w Nixon _in_quarantine-GPN-2001-000007-EPUB-half.jpg:shield [301] AlternateDataStreams: C:\Users\Mark\Downloads\AudirvanaSetup_3.5.51.0_x64.appxbundle:shield [203] AlternateDataStreams: C:\Users\Mark\Downloads\AudirvanaStudioSetup_2.2.2.0_x64_StudioRelease.appxbundle:shield [267] AlternateDataStreams: C:\Users\Mark\Downloads\EmsisoftEmergencyKit (1).exe:shield [169] AlternateDataStreams: C:\Users\Mark\Downloads\EmsisoftEmergencyKit.exe:shield [131] AlternateDataStreams: C:\Users\Mark\Downloads\f0207-AS11-40-5872-aldrin-sulla-luna-EPUB-half.jpg:shield [269] AlternateDataStreams: C:\Users\Mark\Downloads\f0208-AS11-44-6643-LM-ritorno-crop-EPUB-half.jpg:shield [265] AlternateDataStreams: C:\Users\Mark\Downloads\f0209-Apollo 16 splashdown-S72-36293HR-ammaraggio-EPUB-half.jpg:shield [279] AlternateDataStreams: C:\Users\Mark\Downloads\f0303-AS11-40-5886 armstrong.jpg:shield [238] AlternateDataStreams: C:\Users\Mark\Downloads\f0303-AS11-40-5886_armstrong_crop-full-hires.jpg:shield [268] AlternateDataStreams: C:\Users\Mark\Downloads\Install-Anti-Malware-ti.exe:shield [117] AlternateDataStreams: C:\Users\Mark\Downloads\iobituninstaller (1).exe:shield [128] AlternateDataStreams: C:\Users\Mark\Downloads\iobituninstaller.exe:shield [124] AlternateDataStreams: C:\Users\Mark\Downloads\Lunar Module Apollo 11-ritorno-crop-EPUB-half.jpg:shield [266] AlternateDataStreams: C:\Users\Mark\Downloads\mb-support-1.8.7.918.exe:shield [132] AlternateDataStreams: C:\Users\Mark\Downloads\Moon Landing -aldrin-sulla-luna-EPUB-half.jpg:shield [264] AlternateDataStreams: C:\Users\Mark\Downloads\NZXT-CAM-Setup.exe:shield [121] AlternateDataStreams: C:\Users\Mark\Downloads\surprise-kill-vanish-by-annie-jacobsen_archive.torrent:shield [247] AlternateDataStreams: C:\Users\Mark\Downloads\the-pentagons-brain-an-uncensored-history-of-darpa-americas-top-secret-military_archive.torrent:shield [370] AlternateDataStreams: C:\Users\Mark\Downloads\tsp1995-02-28.flac16_archive.torrent:shield [193] AlternateDataStreams: C:\Users\Mark\Documents\My name in Japanese (Kanji and Eng).txt:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\Users\Mark\Documents\NiteMare Mkt mnemonic.txt:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\camsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dps => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lfsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\semgrsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\shellhwdetection => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TokenBroker => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\camsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dps => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lfsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\semgrsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\shellhwdetection => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TokenBroker => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2022-10-20] (IObit Information Technology -> IObit) DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://files.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\.DEFAULT\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\localhost -> localhost IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\0411dd.com -> 0411dd.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\0511zfhl.com -> 0511zfhl.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\0632qyw.com -> 0632qyw.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-266282535-48708807-158023499-1001\...\1001movie.com -> 1001movie.com There are 6091 more sites. ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2017-03-18 15:03 - 2023-01-06 21:59 - 000030250 _____ C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 telemetry.malwarebytes.com 0.0.0.0 0123movies.com 0.0.0.0 0sntp7dnrr.com 0.0.0.0 10gamestop.com 0.0.0.0 11bet.com 0.0.0.0 12kotov.ru 0.0.0.0 1406588359.rsc.cdn77.org 0.0.0.0 1dnscontrol.com 0.0.0.0 1redirb.com 0.0.0.0 360installer.com 0.0.0.0 4cj5qu70.top 0.0.0.0 77.mycfg.site 0.0.0.0 78325.alexsoff.com 0.0.0.0 88796.alexsoff.com 0.0.0.0 addons-chrome.com 0.0.0.0 adf.ly 0.0.0.0 adsrvr.org 0.0.0.0 adsymptotic.com 0.0.0.0 adturtle.biz 0.0.0.0 adult.yourblocksite.com 0.0.0.0 advertising.com 0.0.0.0 advmaker.su 0.0.0.0 agkn.com 0.0.0.0 akisho.ru 0.0.0.0 alexsoff.com 0.0.0.0 allowcontent.site 0.0.0.0 allsthe.net 0.0.0.0 alphashoppers.com 0.0.0.0 altocloudmedia.com 0.0.0.0 am15.net There are 1187 more lines. ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\VulkanSDK\1.1.106.0\Bin;C:\VulkanSDK\1.1.92.1\Bin;C:\Windows\System32;C:\Windows;C:\Windows\System32\wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\GnuPG\bin;C:\Windows\System32\OpenSSH\;C:\Program Files\Calibre2\;C:\Program Files (x86)\Smart Projects\IsoBuster;C:\Program Files\dotnet\ HKU\S-1-5-21-266282535-48708807-158023499-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Mark\AppData\Roaming\Honeyview\Wallpaper.bmp HKU\S-1-5-21-266282535-48708807-158023499-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Windows Firewall is enabled. Network Binding: ============= Npcap Loopback Adapter: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Npcap Loopback Adapter: Npcap Packet Driver (NPCAP) (Wi-Fi) -> INSECURE_NPCAP_WIFI (enabled) Npcap Loopback Adapter: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled) Npcap Loopback Adapter: NordVPN LightWeight Firewall -> NordLwf (enabled) Wi-Fi 2: Npcap Packet Driver (NPCAP) (Wi-Fi) -> INSECURE_NPCAP_WIFI (enabled) Wi-Fi 2: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Wi-Fi 2: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled) Wi-Fi 2: NordVPN LightWeight Firewall -> NordLwf (enabled) Ethernet: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled) Ethernet: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Ethernet: Npcap Packet Driver (NPCAP) (Wi-Fi) -> INSECURE_NPCAP_WIFI (enabled) Ethernet: NordVPN LightWeight Firewall -> NordLwf (enabled) NordLynx: Npcap Packet Driver (NPCAP) (Wi-Fi) -> INSECURE_NPCAP_WIFI (enabled) NordLynx: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Ethernet 2: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Ethernet 2: Npcap Packet Driver (NPCAP) (Wi-Fi) -> INSECURE_NPCAP_WIFI (enabled) Ethernet 2: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled) Ethernet 2: NordVPN LightWeight Firewall -> NordLwf (enabled) Ethernet 3: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Ethernet 3: Npcap Packet Driver (NPCAP) (Wi-Fi) -> INSECURE_NPCAP_WIFI (enabled) Ethernet 3: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled) Ethernet 3: NordVPN LightWeight Firewall -> NordLwf (enabled) ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) MSCONFIG\Services: AMD Crash Defender Service => 2 MSCONFIG\Services: AUEPLauncher => 2 MSCONFIG\Services: avast! Tools => 2 MSCONFIG\Services: BEService => 3 MSCONFIG\Services: cfbackd => 2 MSCONFIG\Services: Creative Dolby Digital Live Pack Licensing Service => 3 MSCONFIG\Services: Ds3Service => 2 MSCONFIG\Services: EaseUS Agent => 2 MSCONFIG\Services: EaseUS UPDATE SERVICE => 2 MSCONFIG\Services: EasyAntiCheat => 3 MSCONFIG\Services: ElevationService => 2 MSCONFIG\Services: GoogleChromeElevationService => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: IJPLMSVC => 2 MSCONFIG\Services: InputMapper Cerberus Whitelister => 2 MSCONFIG\Services: MaskVPNService => 2 MSCONFIG\Services: MBAMScheduler => 2 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: Media Center 25 Service => 3 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: MullvadVPN => 2 MSCONFIG\Services: MX5AudioDevMon => 2 MSCONFIG\Services: nebula => 2 MSCONFIG\Services: Origin Client Service => 3 MSCONFIG\Services: Origin Web Helper Service => 2 MSCONFIG\Services: PlexUpdateService => 2 MSCONFIG\Services: RealtekWlanU => 2 MSCONFIG\Services: reWASDService => 2 MSCONFIG\Services: RtkAudioUniversalService => 2 MSCONFIG\Services: RTLDHCPService => 2 MSCONFIG\Services: RunSwUSB => 2 MSCONFIG\Services: sshd => 3 MSCONFIG\Services: ss_conn_launcher_service => 3 MSCONFIG\Services: Steam Client Service => 3 MSCONFIG\Services: TeraCopyService => 2 MSCONFIG\Services: ViGEmBusUpdater => 3 MSCONFIG\Services: Wondershare InstallAssist => 2 MSCONFIG\Services: WsAppService => 2 MSCONFIG\Services: WsAppService3 => 2 MSCONFIG\Services: WsDrvInst => 2 HKLM\...\StartupApproved\StartupFolder: => "Shanling Audio Control Panel Autostart.lnk" HKLM\...\StartupApproved\StartupFolder: => "AudientAppLauncher Autostart.lnk" HKLM\...\StartupApproved\StartupFolder: => "WSAppHelper.lnk" HKLM\...\StartupApproved\StartupFolder: => "WSAndroidAppHelper.lnk" HKLM\...\StartupApproved\Run: => "Logitech Download Assistant" HKLM\...\StartupApproved\Run: => "XboxStat" HKLM\...\StartupApproved\Run32: => "VirtualCloneDrive" HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe" HKLM\...\StartupApproved\Run32: => "UpdReg" HKLM\...\StartupApproved\Run32: => "Everything" HKLM\...\StartupApproved\Run32: => "Adguard" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\StartupFolder: => "StartupManager.vbs" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\StartupFolder: => "name.vbsStartupManager.vbs" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\StartupFolder: => "name.vbsname.vbsStartupManager.vbs" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\StartupFolder: => "MEGAsync.lnk" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\StartupFolder: => "SoundGridStudioSilent.lnk" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\StartupFolder: => "PC Remote Controller.lnk" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\StartupFolder: => "essential.vbs" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "Toolkit" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "Plex Media Server" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "PeerBlock" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "Reference 4 Systemwide" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "Windows Shutdown Assistant" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "IDMan" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "Opera GX Stable" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "Opera GX Browser Assistant" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "reWASD Engine" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "WiinUPro" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "GoogleDriveFS" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "Settings" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "Battle.net" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "OSDownloader" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "OSDownloaderUpdate" HKU\S-1-5-21-266282535-48708807-158023499-1001\...\StartupApproved\Run: => "Pushbullet" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{490BF6FE-FABC-4B1E-8995-19E8CBC29F68}C:\program files (x86)\soulseekqt\soulseekqt.exe] => (Allow) C:\program files (x86)\soulseekqt\soulseekqt.exe () [File not signed] FirewallRules: [TCP Query User{59287EE1-53D7-4602-A386-75159997BD40}C:\program files (x86)\soulseekqt\soulseekqt.exe] => (Allow) C:\program files (x86)\soulseekqt\soulseekqt.exe () [File not signed] FirewallRules: [UDP Query User{7CFB0761-BE3C-4977-8E7A-CD7DF49B5468}C:\program files (x86)\deluge\deluge.exe] => (Allow) C:\program files (x86)\deluge\deluge.exe (Deluge Team) [File not signed] FirewallRules: [TCP Query User{2066E6DE-648E-49CD-83CE-4EBB42FFD19A}C:\program files (x86)\deluge\deluge.exe] => (Allow) C:\program files (x86)\deluge\deluge.exe (Deluge Team) [File not signed] FirewallRules: [{BC186E19-76DB-4A3D-B4F3-6D7C9ACF1A31}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] FirewallRules: [{F2CC7D89-3928-4EBE-899C-0AB12740BBA9}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] FirewallRules: [{014CBE0A-0783-4B8F-BABC-F9EA85663823}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{4AF131E9-C194-4A2F-8C87-B0A62714AF28}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [UDP Query User{6AAF4B4D-D915-4192-BCB5-067F3094DBE0}C:\program files\vuze\azureus.exe] => (Allow) C:\program files\vuze\azureus.exe (Azureus Software, Inc. -> Azureus Software, Inc) FirewallRules: [TCP Query User{0594BE87-5558-4AD5-B5D0-46E5728FE4AA}C:\program files\vuze\azureus.exe] => (Allow) C:\program files\vuze\azureus.exe (Azureus Software, Inc. -> Azureus Software, Inc) FirewallRules: [{4AA5EC74-BFFC-41BC-9FA5-C71E4C603AD5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{DFBF4FC6-A307-43FA-A70E-6C68395F0217}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{2EA2BFF5-9A2B-40E8-AB79-0B6774DE3220}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{EEE82B4C-5D08-4C2A-A88E-A3D901AB38F0}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [TCP Query User{8B0CE288-4EE9-4CE5-BA3F-C516EB122504}C:\program files (x86)\deluge\deluge.exe] => (Allow) C:\program files (x86)\deluge\deluge.exe (Deluge Team) [File not signed] FirewallRules: [UDP Query User{091EE747-EB26-473C-BC67-55600FE8CEDA}C:\program files (x86)\deluge\deluge.exe] => (Allow) C:\program files (x86)\deluge\deluge.exe (Deluge Team) [File not signed] FirewallRules: [{8B264F60-77C5-4BAD-9184-434D3039D9D0}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd) [File not signed] FirewallRules: [{4C47A084-2F46-4A54-9830-89F2B07B376C}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd) [File not signed] FirewallRules: [{542B853C-C9D6-4342-84D5-8056BE0DFE45}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd) [File not signed] FirewallRules: [{ABAC1B1A-44B2-47E1-BA5B-8193766E08DE}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd) [File not signed] FirewallRules: [{44745602-7C6F-428D-BA72-51C769199F75}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] FirewallRules: [{FB9091A2-17B0-46D6-A1C4-2295E7CF3620}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] FirewallRules: [{7CFB85B4-18A5-4170-B3AE-0352DE296DC1}] => (Allow) C:\Program Files\Vuze\Azureus.exe (Azureus Software, Inc. -> Azureus Software, Inc) FirewallRules: [{DDDE2674-C814-42A1-8115-119A57F61533}] => (Allow) C:\Program Files\Vuze\Azureus.exe (Azureus Software, Inc. -> Azureus Software, Inc) FirewallRules: [TCP Query User{D164E767-9CAE-4E0E-A0E6-15989E8B8898}C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe] => (Allow) C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU Yiwo Tech Development Co., Ltd.) [File not signed] FirewallRules: [UDP Query User{408861E4-E173-4AE1-87B6-4A81D58C2D60}C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe] => (Allow) C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU Yiwo Tech Development Co., Ltd.) [File not signed] FirewallRules: [TCP Query User{D57F49A7-88D3-4FAD-A248-D8DFA8850253}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [UDP Query User{09F151FE-F9F7-48CA-A2F0-1EB675BFB982}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [{CF579D66-6DF7-4353-89C4-B5E59EC1180E}] => (Allow) C:\VulkanSDK\1.1.106.0\Bin32\vktrace.exe () [File not signed] FirewallRules: [{A54918E1-FCBD-49E7-A268-D081573E9FB7}] => (Allow) C:\VulkanSDK\1.1.106.0\Bin32\vktrace.exe () [File not signed] FirewallRules: [{2E33E3BF-D880-46A2-9898-2323DC2AFAE2}] => (Allow) C:\VulkanSDK\1.1.106.0\Bin\vktrace.exe () [File not signed] FirewallRules: [{DD86EF2C-1038-44BE-A6C3-9033FCA38BD2}] => (Allow) C:\VulkanSDK\1.1.106.0\Bin\vktrace.exe () [File not signed] FirewallRules: [TCP Query User{10CD978F-A7C0-425E-B9A7-BB0E1E6709F4}C:\program files\plex\plex\plex.exe] => (Allow) C:\program files\plex\plex\plex.exe (Plex, Inc. -> ) FirewallRules: [UDP Query User{9819CCC0-8610-4E1D-AB9F-A25086FED236}C:\program files\plex\plex\plex.exe] => (Allow) C:\program files\plex\plex\plex.exe (Plex, Inc. -> ) FirewallRules: [TCP Query User{D13F1469-916D-49C6-89CE-1499F6844B80}C:\users\mark\appdata\local\apps\2.0\0v9jb9de.qxo\00tgxhgd.50j\audi..tion_44075894dcec301c_0001.0003_2389f461b6e44eb7\audirvanaplus.exe] => (Allow) C:\users\mark\appdata\local\apps\2.0\0v9jb9de.qxo\00tgxhgd.50j\audi..tion_44075894dcec301c_0001.0003_2389f461b6e44eb7\audirvanaplus.exe (Audirvana -> Audirvana) FirewallRules: [UDP Query User{C4F9C9A9-4493-4795-85DF-E94F3409AB38}C:\users\mark\appdata\local\apps\2.0\0v9jb9de.qxo\00tgxhgd.50j\audi..tion_44075894dcec301c_0001.0003_2389f461b6e44eb7\audirvanaplus.exe] => (Allow) C:\users\mark\appdata\local\apps\2.0\0v9jb9de.qxo\00tgxhgd.50j\audi..tion_44075894dcec301c_0001.0003_2389f461b6e44eb7\audirvanaplus.exe (Audirvana -> Audirvana) FirewallRules: [{FA656192-A197-4D82-A14D-E50DCCF23782}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc. -> Plex, Inc.) FirewallRules: [{887B98A8-659A-45DF-98CD-E42D8B5A121E}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Plex, Inc. -> Python Software Foundation) FirewallRules: [{8FCAEBE4-37A8-484A-8647-FC966CC59AA5}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe (Plex, Inc. -> Plex, Inc.) FirewallRules: [{983DC116-1A3B-43BE-9740-0D5704375F88}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe (Plex, Inc. -> ) FirewallRules: [DNS Server Forward Rule - TCP - 9C1B7501-5994-40CF-91D9-23B163C69745 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - 9C1B7501-5994-40CF-91D9-23B163C69745 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - 8BA68CF4-F15A-4DE0-B51D-208B6CD9EFD8 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - 8BA68CF4-F15A-4DE0-B51D-208B6CD9EFD8 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - 70D433A8-6256-48A0-AFB9-E7DF3B1FA9C9 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - 70D433A8-6256-48A0-AFB9-E7DF3B1FA9C9 - 0] => (Allow) LPort=53 FirewallRules: [TCP Query User{9330D3DD-C903-4A39-BE47-7B43A34F3795}C:\program files\core temp\core temp.exe] => (Allow) C:\program files\core temp\core temp.exe (ALCPU -> ALCPU) FirewallRules: [UDP Query User{091DCDAC-49D9-49CF-8DFB-FCE319BB6657}C:\program files\core temp\core temp.exe] => (Allow) C:\program files\core temp\core temp.exe (ALCPU -> ALCPU) FirewallRules: [TCP Query User{575C8ABE-9BA5-448E-803C-10B62D5DC81D}C:\users\mark\appdata\roaming\usbhelperlauncher\usbhelperlauncher.exe] => (Allow) C:\users\mark\appdata\roaming\usbhelperlauncher\usbhelperlauncher.exe () [File not signed] FirewallRules: [UDP Query User{8CDA9E45-C1A1-40CE-B8DF-DD6F269A4A8A}C:\users\mark\appdata\roaming\usbhelperlauncher\usbhelperlauncher.exe] => (Allow) C:\users\mark\appdata\roaming\usbhelperlauncher\usbhelperlauncher.exe () [File not signed] FirewallRules: [TCP Query User{D484CDFD-2505-4C05-B135-BD6CF518B376}C:\users\mark\appdata\roaming\usbhelperlauncher\wiiu_usb_helper_.exe] => (Allow) C:\users\mark\appdata\roaming\usbhelperlauncher\wiiu_usb_helper_.exe (Hikari06) [File not signed] FirewallRules: [UDP Query User{C43B6476-8C64-490D-9A6E-3EEF22DAE13B}C:\users\mark\appdata\roaming\usbhelperlauncher\wiiu_usb_helper_.exe] => (Allow) C:\users\mark\appdata\roaming\usbhelperlauncher\wiiu_usb_helper_.exe (Hikari06) [File not signed] FirewallRules: [{1E3EBAE7-7BF9-44C8-89BA-901528AC63DA}] => (Allow) C:\Program Files (x86)\Canon\IJ Network Device Setup Utility\cnwidadr.exe (Canon Inc. -> CANON INC.) FirewallRules: [{E4BBFFFD-A26E-4E8B-BBCC-271524548D3D}] => (Allow) C:\Program Files (x86)\Canon\IJ Network Device Setup Utility\cnwiddsu\cnwiddsu.exe (Canon Inc. -> CANON INC.) FirewallRules: [TCP Query User{240ACDD5-29FC-4C2C-8DA5-66F49A4E8F48}C:\program files\monero gui wallet\monero-wallet-gui.exe] => (Allow) C:\program files\monero gui wallet\monero-wallet-gui.exe => No File FirewallRules: [UDP Query User{CF84AD26-EAFB-438C-A3CD-D956242D7A02}C:\program files\monero gui wallet\monero-wallet-gui.exe] => (Allow) C:\program files\monero gui wallet\monero-wallet-gui.exe => No File FirewallRules: [{A1665D0F-4B75-4922-AB99-6B806B904760}] => (Allow) G:\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe (SQUARE ENIX CO., LTD. -> SQUARE ENIX CO., LTD.) FirewallRules: [{E4A24F53-722B-4BC8-ABA1-2D0390F585BF}] => (Allow) G:\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe (SQUARE ENIX CO., LTD. -> SQUARE ENIX CO., LTD.) FirewallRules: [{2F973FBB-5FF2-4985-B73B-18AEE1F84440}] => (Allow) G:\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivlauncher.exe (SQUARE ENIX CO., LTD. -> SQUARE ENIX CO., LTD.) FirewallRules: [{1160D6CE-3F0D-4BA7-B201-6E460B3BD85F}] => (Allow) G:\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivlauncher.exe (SQUARE ENIX CO., LTD. -> SQUARE ENIX CO., LTD.) FirewallRules: [{E7D7E0DC-18AD-4036-A80C-AB40AE9A4AE9}] => (Block) C:\Program Files (x86)\UltData - Windows\UltData - Windows.exe (Tenorshare Co.,Ltd. -> Tenorshare) FirewallRules: [{34D0E49A-C4B1-4353-8B4E-2ED458DDBB08}] => (Block) C:\Program Files (x86)\ReiBoot for Android\ReibootForAndroid.exe (Tenorshare Co.,Ltd. -> ) FirewallRules: [{5D76EEE5-9175-4AD0-86D0-D31CCE855BE6}] => (Allow) C:\Program Files (x86)\MaskVPN\mask_svc.exe => No File FirewallRules: [{631A4E8E-8B4B-448A-A64D-2693EADB3026}] => (Allow) C:\Program Files (x86)\MaskVPN\MaskVPN.exe => No File FirewallRules: [{5506D47E-CA19-4EF7-B09E-D56ACD5CEFDF}] => (Allow) C:\Program Files (x86)\MaskVPN\MaskVPNUpdate.exe => No File FirewallRules: [{D3BE5755-B143-4C56-AFCB-00D9049D26BC}] => (Allow) C:\Program Files (x86)\MaskVPN\tunnle.exe => No File FirewallRules: [TCP Query User{F9B7A6F6-BE11-429B-8C91-3961E200F4BD}C:\program files (x86)\audials\audials 2021\audials.exe] => (Allow) C:\program files (x86)\audials\audials 2021\audials.exe (Audials AG -> Audials AG) FirewallRules: [UDP Query User{CB0BAD3F-F4E7-4613-A05E-6938165C1E5C}C:\program files (x86)\audials\audials 2021\audials.exe] => (Allow) C:\program files (x86)\audials\audials 2021\audials.exe (Audials AG -> Audials AG) FirewallRules: [TCP Query User{1B249E21-8579-4AB2-A2DE-81D70421F511}C:\program files (x86)\audials\audials 2021\audials.exe] => (Allow) C:\program files (x86)\audials\audials 2021\audials.exe (Audials AG -> Audials AG) FirewallRules: [UDP Query User{9F3797D8-3D7E-4B96-B46E-1183F7796D70}C:\program files (x86)\audials\audials 2021\audials.exe] => (Allow) C:\program files (x86)\audials\audials 2021\audials.exe (Audials AG -> Audials AG) FirewallRules: [TCP Query User{4038FE75-9BA5-4017-88E1-D557FC06FB44}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [UDP Query User{400A96C9-CCFF-4AEE-9809-FFD4B7E37293}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{33844515-D429-4CBD-9ACF-8BC9A71D894C}] => (Allow) G:\SteamLibrary\steamapps\common\FuriousAngels\FuriousAngels.exe () [File not signed] FirewallRules: [{68481231-21DA-4AD2-9015-D930F663ACA2}] => (Allow) G:\SteamLibrary\steamapps\common\FuriousAngels\FuriousAngels.exe () [File not signed] FirewallRules: [TCP Query User{B5E3061E-3CE5-4999-9CD4-AF08E2B86713}C:\users\mark\desktop\programs\games\biomass - full game\biomass\biomass\biomass.exe] => (Allow) C:\users\mark\desktop\programs\games\biomass - full game\biomass\biomass\biomass.exe => No File FirewallRules: [UDP Query User{AEDA73E1-A4CE-4F49-9817-6117E7EDFE35}C:\users\mark\desktop\programs\games\biomass - full game\biomass\biomass\biomass.exe] => (Allow) C:\users\mark\desktop\programs\games\biomass - full game\biomass\biomass\biomass.exe => No File FirewallRules: [{A423B83F-4664-40AA-BA2B-7255EDDD78EA}] => (Allow) G:\SteamLibrary\steamapps\common\Amalthea\SpaceAdventure.ES.exe (RunServer) [File not signed] FirewallRules: [{F9D066C3-353B-4EB3-9407-5FA522D262A9}] => (Allow) G:\SteamLibrary\steamapps\common\Amalthea\SpaceAdventure.ES.exe (RunServer) [File not signed] FirewallRules: [{B2AF8A18-7A1C-44E6-8D8A-A73833FE8C85}] => (Allow) C:\WINDOWS\system32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [TCP Query User{F4A2B328-724D-4984-ADE8-67B8729FD9B0}G:\star wars jedi - fallen order\swgame\binaries\win64\starwarsjedifallenorder.exe] => (Allow) G:\star wars jedi - fallen order\swgame\binaries\win64\starwarsjedifallenorder.exe (Respawn Entertainment) [File not signed] FirewallRules: [UDP Query User{52C61451-F0C7-409C-95BA-BDBD19B8AD51}G:\star wars jedi - fallen order\swgame\binaries\win64\starwarsjedifallenorder.exe] => (Allow) G:\star wars jedi - fallen order\swgame\binaries\win64\starwarsjedifallenorder.exe (Respawn Entertainment) [File not signed] FirewallRules: [{C818E9C0-744A-4C98-A26C-5BF431DC1431}] => (Allow) C:\ProgramData\Waves Audio\MyMon\MyMonService.bundle\Contents\Win64\MyMonControlPanel.exe (Waves Inc -> ) FirewallRules: [TCP Query User{CEA082E6-190E-472F-9BD4-024EC8D62B54}C:\program files\windowsapps\audirvana.audirvana-4118-9684-d80dbb7827cd_1.3.0.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe] => (Allow) C:\program files\windowsapps\audirvana.audirvana-4118-9684-d80dbb7827cd_1.3.0.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe => No File FirewallRules: [UDP Query User{E5F40C2F-48E0-4E99-B61C-FCE97D039065}C:\program files\windowsapps\audirvana.audirvana-4118-9684-d80dbb7827cd_1.3.0.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe] => (Allow) C:\program files\windowsapps\audirvana.audirvana-4118-9684-d80dbb7827cd_1.3.0.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe => No File FirewallRules: [TCP Query User{83C34C3F-CE96-45CF-B812-242E1C6D98EC}C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.46.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe] => (Allow) C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.46.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe => No File FirewallRules: [UDP Query User{0D7F0947-5BFE-474F-ADD2-03002AAD1F40}C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.46.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe] => (Allow) C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.46.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe => No File FirewallRules: [TCP Query User{8E3121CA-4B8E-43F5-AB47-F0D894300386}C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.46.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe] => (Block) C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.46.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe => No File FirewallRules: [UDP Query User{9163E7B8-31B2-48D7-92D2-E85E5F6E4F0F}C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.46.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe] => (Block) C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.46.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe => No File FirewallRules: [TCP Query User{3CA5E796-C676-491B-AF4A-0765F58F0975}G:\star wars jedi - fallen order\swgame\binaries\win64\starwarsjedifallenorder.exe] => (Block) G:\star wars jedi - fallen order\swgame\binaries\win64\starwarsjedifallenorder.exe (Respawn Entertainment) [File not signed] FirewallRules: [UDP Query User{1E8E7C0E-80FB-4FE9-BA44-D2F18220E470}G:\star wars jedi - fallen order\swgame\binaries\win64\starwarsjedifallenorder.exe] => (Block) G:\star wars jedi - fallen order\swgame\binaries\win64\starwarsjedifallenorder.exe (Respawn Entertainment) [File not signed] FirewallRules: [TCP Query User{1A2EAE4A-A2AD-4A35-BE15-BB23D17CD7CA}C:\users\mark\desktop\programs\games\biomass - full game\biomass\biomass\biomass.exe] => (Allow) C:\users\mark\desktop\programs\games\biomass - full game\biomass\biomass\biomass.exe => No File FirewallRules: [UDP Query User{EA52E2DA-E871-4BCF-B818-9726BED8B134}C:\users\mark\desktop\programs\games\biomass - full game\biomass\biomass\biomass.exe] => (Allow) C:\users\mark\desktop\programs\games\biomass - full game\biomass\biomass\biomass.exe => No File FirewallRules: [{2268F812-A713-4980-A0AA-0C9E0E0A1A90}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) FirewallRules: [{4F336C0F-AD2E-4DAB-B4EB-6995752C2E2D}] => (Allow) LPort=1542 FirewallRules: [{8175DD7A-A367-46DF-9C36-B81703B46662}] => (Allow) LPort=1542 FirewallRules: [{FB988805-F452-46E6-BC20-45491AFB7102}] => (Allow) LPort=53 FirewallRules: [{5D4298E2-5177-4476-BDC8-D557E13982AA}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek) FirewallRules: [{7EF8ED55-9FCF-4544-BB50-29804CAA782B}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek) FirewallRules: [{2A0F68AB-2C3D-4865-B7D8-33D73904FED3}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek) FirewallRules: [{E63CA6D3-F5A6-4D65-9CBB-E3C4624B55FC}] => (Allow) LPort=53 FirewallRules: [{67908B87-3260-410B-B93F-4BCAAAF1E943}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek) FirewallRules: [{9640E045-1A6C-4BAF-BC0D-1CDA368A1E7A}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek) FirewallRules: [{1ED8C747-C68F-47E5-A2F5-EB1FFEB3D6C0}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek) FirewallRules: [{7277776E-0DA1-49FA-9E0C-E714DA357D7D}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe (Realtek Semiconductor Corp -> Realtek) FirewallRules: [TCP Query User{C1504CAD-0B5D-4742-A724-F670B51C810F}H:\resident evil village\re8.exe] => (Allow) H:\resident evil village\re8.exe => No File FirewallRules: [UDP Query User{AA9481B2-06F7-4BC9-A468-F8A3E2CE7105}H:\resident evil village\re8.exe] => (Allow) H:\resident evil village\re8.exe => No File FirewallRules: [TCP Query User{FCD58090-7ED3-4059-8ABC-DF75CFC40AB5}C:\program files\plitch\plitch.exe] => (Allow) C:\program files\plitch\plitch.exe (MegaDev GmbH -> MegaDev GmbH) FirewallRules: [UDP Query User{47045081-C9C4-4100-9C13-1AAA04A7BDD0}C:\program files\plitch\plitch.exe] => (Allow) C:\program files\plitch\plitch.exe (MegaDev GmbH -> MegaDev GmbH) FirewallRules: [TCP Query User{D2080CF2-7B05-4044-B85C-6C589FAFD6C9}C:\program files (x86)\aimp\aimp.exe] => (Allow) C:\program files (x86)\aimp\aimp.exe (IP Izmaylov Artem Andreevich -> AIMP DevTeam) FirewallRules: [UDP Query User{7574B2B7-55A1-4B7C-85FE-990284223C32}C:\program files (x86)\aimp\aimp.exe] => (Allow) C:\program files (x86)\aimp\aimp.exe (IP Izmaylov Artem Andreevich -> AIMP DevTeam) FirewallRules: [TCP Query User{EF1FC245-91E4-438D-B8B1-EB2FE726C97D}H:\resident evil village\re8.exe] => (Block) H:\resident evil village\re8.exe => No File FirewallRules: [UDP Query User{8B32DA69-947B-407B-963E-5DC9AFC3F4D6}H:\resident evil village\re8.exe] => (Block) H:\resident evil village\re8.exe => No File FirewallRules: [TCP Query User{BE845F3B-64E2-4661-A3A3-84E1CA75456B}C:\users\mark\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\mark\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software) FirewallRules: [UDP Query User{2D58DB63-767D-484F-863A-F56A07B2AC9A}C:\users\mark\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\mark\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software) FirewallRules: [TCP Query User{6994D420-6AF0-48DA-A5F6-B748027777AB}C:\users\mark\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\mark\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software) FirewallRules: [UDP Query User{80CE788E-A7EF-4C79-8548-0042DFFD06ED}C:\users\mark\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\mark\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software) FirewallRules: [{9FB02ECD-5FBC-4D79-9D7C-FEBA481FFBDB}] => (Allow) C:\Users\Mark\AppData\Roaming\RNStudio\PC Remote Controller\PC Remote Controller.exe (RNStudio) [File not signed] FirewallRules: [{6472EFC3-0ED8-43F9-867A-E760ADA1B5BC}] => (Allow) C:\Users\Mark\AppData\Roaming\RNStudio\PC Remote Controller\PC Remote Controller.exe (RNStudio) [File not signed] FirewallRules: [{D803687C-DDAC-44E8-80CA-1C9B03A9A9DB}] => (Allow) C:\Users\Mark\AppData\Roaming\RNStudio\PC Remote Controller\PC Remote Controller.exe (RNStudio) [File not signed] FirewallRules: [{EF51A5F2-9A79-42A7-A741-23DCF0664CFE}] => (Allow) C:\Users\Mark\AppData\Roaming\RNStudio\PC Remote Controller\PC Remote Controller.exe (RNStudio) [File not signed] FirewallRules: [{1A334550-5876-4167-87A9-27BD31E93284}] => (Allow) LPort=57209 FirewallRules: [{3957BB14-B76C-484F-9AC1-248435983B04}] => (Allow) LPort=57210 FirewallRules: [{3D6817F8-1EBB-4BE3-9AD2-2C2C318EDC87}] => (Allow) LPort=57211 FirewallRules: [{96A367CF-185B-48B2-A1EB-85AAD0FB3249}] => (Allow) LPort=57212 FirewallRules: [{64102B1A-C84F-4CBF-9024-7ADD553EFE19}] => (Allow) LPort=57213 FirewallRules: [{9B867FEB-4DFF-4ABC-BC24-FF12F5272820}] => (Allow) LPort=57214 FirewallRules: [{5845143E-C8F0-4249-8391-71F0DB2067CA}] => (Allow) LPort=57215 FirewallRules: [{810B11F1-639F-468F-B8A0-51E2AE6DC60E}] => (Allow) LPort=57216 FirewallRules: [{FF03DF8D-A0F5-4AF9-905B-C9CDEA46C49B}] => (Allow) LPort=57217 FirewallRules: [{329E2959-F08C-4F48-96CA-8DF23591F7AB}] => (Allow) LPort=57218 FirewallRules: [{AF4BBDEB-BEC3-4BBA-BB87-D65263CDFCC0}] => (Allow) LPort=57209 FirewallRules: [{D697F13B-DA0A-47D4-9B53-29F10927BC12}] => (Allow) LPort=57210 FirewallRules: [{308BC798-64BE-415A-9EAD-74439E37DFFF}] => (Allow) LPort=57211 FirewallRules: [{FB6F7F4A-A6F2-4830-9211-85CC36CB5421}] => (Allow) LPort=57212 FirewallRules: [{CC90290A-2644-414F-9DFD-6A8A94482562}] => (Allow) LPort=57213 FirewallRules: [{D4532B77-0464-4516-A1D3-AA034DC85F1E}] => (Allow) LPort=57214 FirewallRules: [{B0E024A3-9043-4A65-B458-67ECDB8CA6F2}] => (Allow) LPort=57215 FirewallRules: [{86CCB0FB-D63D-4D15-BEAA-BED58BCEFC5F}] => (Allow) LPort=57216 FirewallRules: [{EF639114-48C6-4880-A995-F8E03143CCFE}] => (Allow) LPort=57217 FirewallRules: [{F6EF77DF-9516-4F8B-8032-1C428299342A}] => (Allow) LPort=57218 FirewallRules: [{C9D158D1-6F92-468C-95D8-4DF808B464CA}] => (Allow) LPort=23007 FirewallRules: [{8AA01A63-4199-4F04-B1B8-C190A757E3DF}] => (Allow) LPort=23008 FirewallRules: [{D8258E9E-85F9-45D2-BF51-F2E0559B89AA}] => (Allow) LPort=33009 FirewallRules: [{B630793B-C48E-48F6-95EB-A3F0BF0D343C}] => (Allow) LPort=33010 FirewallRules: [{0EB1BC27-0314-461E-9238-E7F8CD93F237}] => (Allow) LPort=33011 FirewallRules: [{E476C803-BE4F-4EF9-BB82-A0E83F27DF96}] => (Allow) LPort=43012 FirewallRules: [{B6CDC61D-F974-4232-B3BE-7E4F064CBAF5}] => (Allow) LPort=43013 FirewallRules: [{25148352-AF1F-48F4-9311-E62E3E476E16}] => (Allow) LPort=53014 FirewallRules: [{61F818CE-B827-46E4-9E36-180B4E74E6BA}] => (Allow) LPort=53015 FirewallRules: [{2E96315C-28EE-4E83-9FBD-63A3C8EF6C32}] => (Allow) LPort=53016 FirewallRules: [{7B323336-D239-4930-9D9B-73D3FC1094EB}] => (Allow) LPort=23007 FirewallRules: [{64A67340-11E2-4973-84FF-0F2607150C8D}] => (Allow) LPort=23008 FirewallRules: [{375CDFD2-180A-4AFE-AF37-D51B45F2D2A4}] => (Allow) LPort=33009 FirewallRules: [{3676A4C0-932B-4C36-90E2-9B1F32AAB5AA}] => (Allow) LPort=33010 FirewallRules: [{EDDB783B-8383-4B71-81E0-9041EF2E34B2}] => (Allow) LPort=33011 FirewallRules: [{D4EFC800-00AE-411D-85B4-7FD8EF0DBE7A}] => (Allow) LPort=43012 FirewallRules: [{9525BF83-2D41-4224-B5A4-EB281F0A974A}] => (Allow) LPort=43013 FirewallRules: [{C366EB00-4754-4BB3-8CE4-BA47A3766548}] => (Allow) LPort=53014 FirewallRules: [{910929F8-965B-41DA-BFFF-9CA6FFFDA050}] => (Allow) LPort=53015 FirewallRules: [{49162100-77A8-4A3D-92D3-2FFD3A9B197F}] => (Allow) LPort=53016 FirewallRules: [{6E92887D-C8E2-43BC-82E6-03079FCBDC74}] => (Allow) LPort=50053 FirewallRules: [{D6946DAB-397D-4E32-BB66-27AC85D96E6A}] => (Allow) LPort=50053 FirewallRules: [TCP Query User{79089758-9040-4D2A-878D-43F980D14209}C:\program files\windowsapps\audirvana.audirvana-4118-9684-d80dbb7827cd_1.3.0.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe] => (Allow) C:\program files\windowsapps\audirvana.audirvana-4118-9684-d80dbb7827cd_1.3.0.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe => No File FirewallRules: [UDP Query User{037956F9-F32B-4787-A57F-71344527129B}C:\program files\windowsapps\audirvana.audirvana-4118-9684-d80dbb7827cd_1.3.0.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe] => (Allow) C:\program files\windowsapps\audirvana.audirvana-4118-9684-d80dbb7827cd_1.3.0.0_x64__fec4hfhj3emgj\audirvana\audirvana.exe => No File FirewallRules: [TCP Query User{B10C825F-FDD3-4271-A42F-14ACC2B60905}C:\program files (x86)\soulseekqt\soulseekqt.exe] => (Block) C:\program files (x86)\soulseekqt\soulseekqt.exe () [File not signed] FirewallRules: [UDP Query User{C383431E-A6AD-47C1-8FFB-B47C9E08B3A9}C:\program files (x86)\soulseekqt\soulseekqt.exe] => (Block) C:\program files (x86)\soulseekqt\soulseekqt.exe () [File not signed] FirewallRules: [{0AD572C0-AA38-47D2-BF4E-DB22EDC52881}] => (Allow) G:\SteamLibrary\steamapps\common\Steel Salvo\SteelSalvo.exe (Epic Games, Inc.) [File not signed] FirewallRules: [{16BD560E-26E2-47C8-9571-0F7073D28FF5}] => (Allow) G:\SteamLibrary\steamapps\common\Steel Salvo\SteelSalvo.exe (Epic Games, Inc.) [File not signed] FirewallRules: [TCP Query User{6F4B0A4B-9138-46F2-8618-D196B42EA921}C:\program files (x86)\aimp\aimp.exe] => (Allow) C:\program files (x86)\aimp\aimp.exe (IP Izmaylov Artem Andreevich -> AIMP DevTeam) FirewallRules: [UDP Query User{F15815AF-8B45-49EE-8190-37FD043CA001}C:\program files (x86)\aimp\aimp.exe] => (Allow) C:\program files (x86)\aimp\aimp.exe (IP Izmaylov Artem Andreevich -> AIMP DevTeam) FirewallRules: [TCP Query User{241EE1F9-432B-4FB9-B4CE-5E9C1B7E1340}C:\program files (x86)\image-line\minihost\minihostmodular.exe] => (Allow) C:\program files (x86)\image-line\minihost\minihostmodular.exe (Image Line -> Image-Line) [File not signed] FirewallRules: [UDP Query User{89FE1CDD-FA17-4C36-9577-4B8FBD74FBAC}C:\program files (x86)\image-line\minihost\minihostmodular.exe] => (Allow) C:\program files (x86)\image-line\minihost\minihostmodular.exe (Image Line -> Image-Line) [File not signed] FirewallRules: [TCP Query User{D9CE8607-FAE6-4AB5-B7F5-7D5924729EB9}I:\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Allow) I:\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File FirewallRules: [UDP Query User{20B14BFF-8F87-49D5-9AE4-568F14B910C0}I:\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Allow) I:\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File FirewallRules: [TCP Query User{8382B0FE-4B20-4B4B-BB0F-6EA4A5747B8A}I:\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Allow) I:\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File FirewallRules: [UDP Query User{51A40C3A-3304-4901-B863-1DF75C223F57}I:\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Allow) I:\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File FirewallRules: [TCP Query User{6C4CE97F-AC12-425F-BE74-E1CFEE843C67}C:\program files (x86)\image-line\minihost\minihostmodular.exe] => (Allow) C:\program files (x86)\image-line\minihost\minihostmodular.exe (Image Line -> Image-Line) [File not signed] FirewallRules: [UDP Query User{0064AA89-9CC3-48AD-8296-AED9C4FFE4B0}C:\program files (x86)\image-line\minihost\minihostmodular.exe] => (Allow) C:\program files (x86)\image-line\minihost\minihostmodular.exe (Image Line -> Image-Line) [File not signed] FirewallRules: [{BC84594C-4518-4180-B173-65BAAA1EBA9D}] => (Allow) C:\WINDOWS\System32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{37911995-9BE8-4DF0-A764-9EB01454BF42}] => (Allow) C:\WINDOWS\System32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{330E3F75-2681-4DD7-9B25-7385616FC475}] => (Allow) C:\Program Files (x86)\OSTotoSoft\DriverTalent\DriverTalent.exe => No File FirewallRules: [{640C6015-09BC-4CCE-A48B-AE3F5DE627D3}] => (Allow) C:\Program Files (x86)\OSTotoSoft\DriverTalent\LDrvSvc.dll => No File FirewallRules: [TCP Query User{E3E52D3D-B118-4628-B560-0B78F9D6D7AB}I:\deathloop\deathloop.exe] => (Allow) I:\deathloop\deathloop.exe => No File FirewallRules: [UDP Query User{427E1DFB-AF0F-4C8E-94D4-4D35DF281569}I:\deathloop\deathloop.exe] => (Allow) I:\deathloop\deathloop.exe => No File FirewallRules: [{F1400094-F004-4D94-909F-3E49D51E74E0}] => (Block) I:\deathloop\deathloop.exe => No File FirewallRules: [{9E6B831C-5597-4BA6-BC0C-61A82742F61B}] => (Block) I:\deathloop\deathloop.exe => No File FirewallRules: [{91BCE1D2-2EC9-4ADC-9E03-76AD55D4231D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Strike Suit Infinity\pc\main\Binary\SSZ.exe () [File not signed] FirewallRules: [{DB491448-D653-4478-8D65-08BAED68C748}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Strike Suit Infinity\pc\main\Binary\SSZ.exe () [File not signed] FirewallRules: [{85C9647B-B28D-45F4-9710-E5FA3EF80B96}] => (Allow) G:\Origin - Apex Legends\STAR WARS Squadrons\starwarssquadrons_launcher.exe (EasyAntiCheat Oy -> Epic Games, Inc) FirewallRules: [{74C862A8-74EA-4D9B-B8BD-828151C410E6}] => (Allow) G:\Origin - Apex Legends\STAR WARS Squadrons\starwarssquadrons_launcher.exe (EasyAntiCheat Oy -> Epic Games, Inc) FirewallRules: [TCP Query User{F53986AE-4515-4F34-A835-721476B5C540}G:\origin - apex legends\star wars squadrons\starwarssquadrons.exe] => (Allow) G:\origin - apex legends\star wars squadrons\starwarssquadrons.exe (Electronic Arts, Inc. -> Electronic Arts Inc.) FirewallRules: [UDP Query User{F40842F6-DCBB-40B3-8AC4-B119B484344B}G:\origin - apex legends\star wars squadrons\starwarssquadrons.exe] => (Allow) G:\origin - apex legends\star wars squadrons\starwarssquadrons.exe (Electronic Arts, Inc. -> Electronic Arts Inc.) FirewallRules: [{E3A4AC13-3CB0-41BA-B759-B697D4733EE6}] => (Allow) E:\Grand Theft Auto V\GTA5.exe => No File FirewallRules: [{7A472B7C-C852-49CA-A338-F723C4ADD016}] => (Allow) E:\Grand Theft Auto V\GTA5.exe => No File FirewallRules: [TCP Query User{90A0E9F9-E979-4C73-9314-5ADFD22907A4}E:\far cry 6\bin\farcry6.exe] => (Allow) E:\far cry 6\bin\farcry6.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment) [File not signed] FirewallRules: [UDP Query User{F21D20B3-6D42-43CD-81CC-F6C615B7E3AF}E:\far cry 6\bin\farcry6.exe] => (Allow) E:\far cry 6\bin\farcry6.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment) [File not signed] FirewallRules: [TCP Query User{A0229BCF-D3F3-49FA-9407-4DB5992F6B79}E:\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Allow) E:\cyberpunk 2077\bin\x64\cyberpunk2077.exe (CD PROJEKT SPÓŁKA AKCYJNA -> CD PROJEKT S.A.) FirewallRules: [UDP Query User{0EE85A64-8558-4884-AFD8-09CA2E47BB53}E:\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Allow) E:\cyberpunk 2077\bin\x64\cyberpunk2077.exe (CD PROJEKT SPÓŁKA AKCYJNA -> CD PROJEKT S.A.) FirewallRules: [TCP Query User{F99B4DAE-E79F-4068-B896-8FFAE187885C}E:\sd gundam battle alliance\sdgundamba\binaries\win64\sdgundamba-win64-shipping.exe] => (Block) E:\sd gundam battle alliance\sdgundamba\binaries\win64\sdgundamba-win64-shipping.exe (Epic Games, Inc.) [File not signed] FirewallRules: [UDP Query User{2C3C4407-9F2D-4D51-8A7B-F363B481BB3B}E:\sd gundam battle alliance\sdgundamba\binaries\win64\sdgundamba-win64-shipping.exe] => (Block) E:\sd gundam battle alliance\sdgundamba\binaries\win64\sdgundamba-win64-shipping.exe (Epic Games, Inc.) [File not signed] FirewallRules: [TCP Query User{664D09C5-5780-426B-9978-322439EA2D54}E:\rollerdrome\rollerdrome.exe] => (Allow) E:\rollerdrome\rollerdrome.exe () [File not signed] FirewallRules: [UDP Query User{EFA49394-87B2-436F-A6DF-835BE060554F}E:\rollerdrome\rollerdrome.exe] => (Allow) E:\rollerdrome\rollerdrome.exe () [File not signed] FirewallRules: [TCP Query User{3AABC4E4-8FF7-473F-8980-11014106BEF9}E:\v.rising.v0.5.41821.early.access\v rising\vrising_server\vrisingserver.exe] => (Allow) E:\v.rising.v0.5.41821.early.access\v rising\vrising_server\vrisingserver.exe => No File FirewallRules: [UDP Query User{FB753C7A-DA95-4DAB-9B99-EE8AA958B9C6}E:\v.rising.v0.5.41821.early.access\v rising\vrising_server\vrisingserver.exe] => (Allow) E:\v.rising.v0.5.41821.early.access\v rising\vrising_server\vrisingserver.exe => No File FirewallRules: [TCP Query User{5163B867-A7A7-4D3E-A6B7-CF5BDCFDDA46}E:\overwatch\_retail_\overwatch.exe] => (Allow) E:\overwatch\_retail_\overwatch.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment) FirewallRules: [UDP Query User{7D74E72A-CC70-4AEB-8E18-32B36B4EEA3B}E:\overwatch\_retail_\overwatch.exe] => (Allow) E:\overwatch\_retail_\overwatch.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment) FirewallRules: [{A81331CC-8FF5-41DB-BAD8-09425A2F7AEA}] => (Allow) C:\WINDOWS\winhlp32.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{F6954122-B882-4C9D-B339-C5C419A6B5B6}] => (Allow) C:\WINDOWS\winhlp32.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [TCP Query User{77447907-75EC-4764-9E37-CF6444601BA0}C:\windows\winhlp32.exe] => (Allow) C:\windows\winhlp32.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [UDP Query User{80EFD135-4146-43A8-91F0-17B54B2EB3BD}C:\windows\winhlp32.exe] => (Allow) C:\windows\winhlp32.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{65C1F4CC-088E-4DDA-83F2-10B6158941FD}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) FirewallRules: [{AC4EE05F-219C-474B-995C-A36EB0A8A8A6}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) FirewallRules: [{D0219ED7-D623-4208-B874-AC8F669A1B87}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) FirewallRules: [{1786F1C6-1C40-4D36-AF55-8652955545D4}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) FirewallRules: [TCP Query User{AA707452-CE59-4FDE-8F87-2FB75DF8A49B}E:\heavy rain\heavyrain.exe] => (Allow) E:\heavy rain\heavyrain.exe => No File FirewallRules: [UDP Query User{B6691454-5B21-4B45-B7E7-487E30C9458A}E:\heavy rain\heavyrain.exe] => (Allow) E:\heavy rain\heavyrain.exe => No File FirewallRules: [TCP Query User{27FADDC4-9512-45F2-8EF3-3C40999494A2}C:\program files (x86)\gigabyte\@bios\flashbios.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\flashbios.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) FirewallRules: [UDP Query User{AE1D6356-6200-49B1-BA3C-AE594D4B9AA8}C:\program files (x86)\gigabyte\@bios\flashbios.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\flashbios.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.) FirewallRules: [TCP Query User{BA2A6DE2-6DD6-4764-9436-904923489772}E:\haak v1.1.0\haak.exe] => (Allow) E:\haak v1.1.0\haak.exe => No File FirewallRules: [UDP Query User{BC6B3CF0-3C2C-465B-AE7A-E11CC70CF4FF}E:\haak v1.1.0\haak.exe] => (Allow) E:\haak v1.1.0\haak.exe => No File FirewallRules: [{9CE061A1-4EC0-4569-BBEB-63E0CD1C744F}] => (Allow) C:\Program Files\AMD\CNext\CNext\amddvr.exe => No File FirewallRules: [{EA9D336C-BB2E-44D8-9C38-F7A309C8E466}] => (Allow) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) FirewallRules: [{B02C87CC-B607-4593-8A46-A0AE6F52F83A}] => (Allow) C:\Program Files\AMD\CNext\CNext\Radeonsoftware.exe (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) FirewallRules: [{A909AED7-4543-4F30-ADEF-03F94EB3491B}] => (Allow) C:\Program Files\AMD\CNext\CNext\AMDLink.exe => No File FirewallRules: [TCP Query User{EC64059F-6364-456F-9958-2E461AC72B79}E:\malwarebytes anti-malware premium 4.2.0.82 incl license [crackingpatching]\license\licensemalwarebytes.exe] => (Allow) E:\malwarebytes anti-malware premium 4.2.0.82 incl license [crackingpatching]\license\licensemalwarebytes.exe => No File FirewallRules: [UDP Query User{1D1F1B96-4035-492B-BAEF-1325C407EFBC}E:\malwarebytes anti-malware premium 4.2.0.82 incl license [crackingpatching]\license\licensemalwarebytes.exe] => (Allow) E:\malwarebytes anti-malware premium 4.2.0.82 incl license [crackingpatching]\license\licensemalwarebytes.exe => No File FirewallRules: [{3B280644-2D7E-4F4B-8AED-F5EE3F0B5C7C}] => (Allow) C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SamsungFlux_4.9.6.0_x64__wyx1vj98g3asy\DesktopApp\SamsungFlowDesktop.exe (Samsung Electronics CO., LTD. -> ) FirewallRules: [{074AB59C-332A-44E7-8F08-EF5D38B46C19}] => (Allow) C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SamsungFlux_4.9.6.0_x64__wyx1vj98g3asy\DesktopApp\SamsungFlowDesktop.exe (Samsung Electronics CO., LTD. -> ) FirewallRules: [{8C77D043-D5EF-404C-8118-CD0FD066CAAE}] => (Allow) C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SamsungFlux_4.9.6.0_x64__wyx1vj98g3asy\DesktopApp\SamsungFlowDesktop.exe (Samsung Electronics CO., LTD. -> ) FirewallRules: [{CA531846-A4AA-4322-AF8E-CC5A3903ECDD}] => (Allow) C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SamsungFlux_4.9.6.0_x64__wyx1vj98g3asy\DesktopApp\SamsungFlowDesktop.exe (Samsung Electronics CO., LTD. -> ) FirewallRules: [TCP Query User{29BB2CCF-0172-462B-B19F-5D04B531BDDA}C:\users\mark\downloads\cultic.build.9970743\cultic.build.9970743\cultic.exe] => (Allow) C:\users\mark\downloads\cultic.build.9970743\cultic.build.9970743\cultic.exe => No File FirewallRules: [UDP Query User{B4C6D127-3195-4771-87CF-AF806D3C4880}C:\users\mark\downloads\cultic.build.9970743\cultic.build.9970743\cultic.exe] => (Allow) C:\users\mark\downloads\cultic.build.9970743\cultic.build.9970743\cultic.exe => No File FirewallRules: [TCP Query User{F20E3876-7458-4A65-8744-4A9E8D15DB27}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob) FirewallRules: [UDP Query User{6785FC18-143F-43DF-8147-67FFCA1739EC}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob) FirewallRules: [TCP Query User{CAC9C4CF-BD08-4EF2-9D09-ABCCF05777AC}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob) FirewallRules: [UDP Query User{94400C5B-1736-4ECA-9767-78EC6F9CFFB8}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe (Digiarty Software, Inc. -> DearMob) FirewallRules: [{70603A56-0D0F-485E-B6B7-19648AFC6876}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) FirewallRules: [{3B62D596-0AA4-4FB2-96AA-169DB9972B2B}] => (Allow) C:\Program Files (x86)\GIGABYTE\AppCenter\gcupd.exe (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) FirewallRules: [{C2F1E9A5-371B-46A8-A035-BDC534780A10}] => (Allow) C:\Program Files\reWASD\reWASDEngine.exe (SIA AVB Disc Soft -> Disc Soft Ltd) FirewallRules: [{4AE34AEB-ABBB-4AE3-8480-97EECC8C1EB2}] => (Allow) C:\Program Files\reWASD\reWASDEngine.exe (SIA AVB Disc Soft -> Disc Soft Ltd) FirewallRules: [{D443B886-F8E9-4831-99F5-3088B592A1DC}] => (Allow) C:\Program Files\reWASD\reWASD.exe (SIA AVB Disc Soft -> Disc Soft Ltd) FirewallRules: [{88FAFCCB-FC91-4904-A99A-47496E7E900E}] => (Allow) C:\Program Files\reWASD\reWASD.exe (SIA AVB Disc Soft -> Disc Soft Ltd) FirewallRules: [{40C7C491-2616-4EE0-840C-D0BC5D4D23FA}] => (Allow) LPort=35474 FirewallRules: [{FB8682FB-68DB-421D-A807-D3A957FFB60F}] => (Allow) LPort=35475 FirewallRules: [{711E531B-4F78-4067-AAEF-5DAA89881A0B}] => (Allow) LPort=35476 FirewallRules: [{0A033D93-7383-45E1-AE1E-9E3697697AF9}] => (Allow) LPort=36474 FirewallRules: [{8EE69E46-587C-4C93-94EB-ADF0AEACC467}] => (Allow) C:\Program Files\BIAS FX 2 Application (64bit)\BIAS FX 2_x64.exe => No File FirewallRules: [{AF1CE0F4-250A-4B62-8035-F911DFD0C365}] => (Allow) C:\Program Files\BIAS FX 2 Application (64bit)\BIAS FX 2_x64.exe => No File FirewallRules: [{58076EB3-67B2-4660-9D5A-BDFA852D03FF}] => (Allow) C:\Program Files\BIAS FX 2 Application (64bit)\BIAS FX 2_x64.exe => No File FirewallRules: [{417CBBCC-447E-4B39-A11D-9F5EF3DB047F}] => (Allow) C:\Program Files\BIAS FX 2 Application (64bit)\BIAS FX 2_x64.exe => No File FirewallRules: [{3C7EF239-8196-41B1-B070-1A9E24DC4921}] => (Allow) C:\Program Files (x86)\Adguard\AdguardSvc.exe (Adguard Software Limited -> Adguard Software Ltd) FirewallRules: [TCP Query User{7335128A-4451-4362-9EF8-99E86FCE04AC}C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.51.0_x64__q3nymrkmej12j\audirvana\audirvana.exe] => (Allow) C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.51.0_x64__q3nymrkmej12j\audirvana\audirvana.exe (Audirvana) [File not signed] FirewallRules: [UDP Query User{D7E03286-EAC7-4111-B8BE-94E1959EACD1}C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.51.0_x64__q3nymrkmej12j\audirvana\audirvana.exe] => (Allow) C:\program files\windowsapps\audirvana.audirvana-4118-9484-d80dbb7827cd_3.5.51.0_x64__q3nymrkmej12j\audirvana\audirvana.exe (Audirvana) [File not signed] FirewallRules: [TCP Query User{BF0ACE74-2FD4-46B6-8146-5F97697A64F3}C:\users\mark\desktop\programs\game save files & controller mapping software\biomass - full game\biomass\biomass\biomass.exe] => (Allow) C:\users\mark\desktop\programs\game save files & controller mapping software\biomass - full game\biomass\biomass\biomass.exe () [File not signed] FirewallRules: [UDP Query User{CE1C91BF-6749-49EA-8FEE-3F173F419FDC}C:\users\mark\desktop\programs\game save files & controller mapping software\biomass - full game\biomass\biomass\biomass.exe] => (Allow) C:\users\mark\desktop\programs\game save files & controller mapping software\biomass - full game\biomass\biomass\biomass.exe () [File not signed] ==================== Restore Points ========================= ==================== Faulty Device Manager Devices ============ Name: Npcap Loopback Adapter Description: Microsoft KM-TEST Loopback Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: kmloop Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ======================== Application errors: ================== Error: (01/20/2023 01:27:43 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: deluge.exe, version: 1.3.15.0, time stamp: 0x530bd002 Faulting module name: libtorrent.pyd, version: 0.0.0.0, time stamp: 0x58a9b5a3 Exception code: 0xc0000005 Fault offset: 0x0018a45c Faulting process id: 0x7dd0 Faulting application start time: 0x01d92c9b73f3b822 Faulting application path: C:\Program Files (x86)\Deluge\deluge.exe Faulting module path: C:\Program Files (x86)\Deluge\libtorrent.pyd Report Id: 4e092e36-ecc8-40c1-a198-88d3671c2542 Faulting package full name: Faulting package-relative application ID: Error: (01/20/2023 01:00:10 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program explorer.exe version 10.0.17763.1369 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 3564 Start Time: 01d92c9a92e95fe3 Termination Time: 18 Application Path: C:\WINDOWS\explorer.exe Report Id: 12ca1bd8-d1a4-46b3-9596-a321188bb8cc Faulting package full name: Faulting package-relative application ID: Hang type: Unknown Error: (01/20/2023 12:47:26 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid. . Operation: Executing Asynchronous Operation Context: Current State: DoSnapshotSet Error: (01/20/2023 12:46:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddCoreCsiFiles : GetNextFileMapContent() failed. System Error: The parameter is incorrect. . Error: (01/20/2023 12:46:32 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddCoreCsiFiles : GetNextFileMapContent() failed. System Error: The parameter is incorrect. . Error: (01/19/2023 10:40:39 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: WiinUPro.exe, version: 0.9.7.703, time stamp: 0x607a84c0 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x00007ffd71e7fcc9 Faulting process id: 0x9bfc Faulting application start time: 0x01d92c8957c66c2c Faulting application path: C:\Program Files\WiinUPro\WiinUPro.exe Faulting module path: unknown Report Id: 2f706b0c-ca78-443e-aa20-a980272f9298 Faulting package full name: Faulting package-relative application ID: Error: (01/19/2023 10:40:39 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: WiinUPro.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException at Shared.Globalization.SetSelectedLanguage(Int32) at WiinUPro.App.Application_Startup(System.Object, System.Windows.StartupEventArgs) at System.Windows.Application.OnStartup(System.Windows.StartupEventArgs) at System.Windows.Application.<.ctor>b__1_0(System.Object) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) at System.Windows.Threading.DispatcherOperation.InvokeImpl() at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object) at System.Windows.Threading.DispatcherOperation.Invoke() at System.Windows.Threading.Dispatcher.ProcessQueue() at System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) at MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) at MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) at System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) at MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) at MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) at System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) at System.Windows.Application.RunDispatcher(System.Object) at System.Windows.Application.RunInternal(System.Windows.Window) at WiinUPro.App.Main() Error: (01/19/2023 09:04:41 PM) (Source: ESENT) (EventID: 454) (User: ) Description: svchost (41588,U,98) DS_Token_DB: Database recovery/restore failed with unexpected error -1022. System errors: ============= Error: (01/20/2023 01:48:22 PM) (Source: DCOM) (EventID: 10010) (User: LEE) Description: The server {4BD3E4E1-7BD4-4A2B-9964-496400DE5193} did not register with DCOM within the required timeout. Error: (01/20/2023 01:46:22 PM) (Source: DCOM) (EventID: 10010) (User: LEE) Description: The server {4575438F-A6C8-4976-B0FE-2F26B80D959E} did not register with DCOM within the required timeout. Error: (01/20/2023 10:46:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Browser service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (01/20/2023 10:46:15 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (120000 milliseconds) while waiting for the Browser service to connect. Error: (01/20/2023 10:46:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Browser service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (01/20/2023 10:46:15 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (120000 milliseconds) while waiting for the Browser service to connect. Error: (01/20/2023 10:46:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Browser service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (01/20/2023 10:46:15 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (120000 milliseconds) while waiting for the Browser service to connect. Windows Defender: ================ Date: 2022-11-22 23:56:00.572 Description: N/A Date: 2022-11-22 23:55:56.612 Description: N/A Date: 2022-11-22 23:47:35.635 Description: N/A Date: 2022-11-22 20:17:10.566 Description: N/A Date: 2022-11-22 19:16:33.081 Description: N/A Event[0]: Date: 2022-12-07 14:16:28.405 Description: N/A Date: 2022-12-07 14:16:27.069 Description: N/A Date: 2022-11-23 03:04:50.491 Description: N/A ==================== Memory info =========================== BIOS: American Megatrends Inc. F22 03/15/2018 Motherboard: Gigabyte Technology Co., Ltd. AB350M-Gaming 3-CF Processor: AMD Ryzen 7 1800X Eight-Core Processor Percentage of memory in use: 44% Total physical RAM: 32718.32 MB Available physical RAM: 18313.3 MB Total Virtual: 64860.5 MB Available Virtual: 48300.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.54 GB) (Free:13.2 GB) (Model: WDC WD3200AAKS-61L9A0) NTFS Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.05 GB) (Model: WDC WD1002FAEX-00Z3A0) NTFS ==>[system with boot components (obtained from drive)] Drive e: () (Fixed) (Total:3726.02 GB) (Free:14.07 GB) (Model: ST4000DM004-2CV104) NTFS Drive f: () (Fixed) (Total:931.41 GB) (Free:15.91 GB) (Model: ST1000DM003-1CH162) NTFS ==>[system with boot components (obtained from drive)] Drive g: () (Fixed) (Total:931.41 GB) (Free:2.09 GB) (Model: WDC WD1002FAEX-00Z3A0) NTFS \\?\Volume{4d388c3c-1e53-4d8c-ae82-c06c1f1db914}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS \\?\Volume{52f40cbe-ed51-4390-a740-a63b1ed7cdd2}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 28746951) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS) ========================================================== Disk: 1 (Size: 298.1 GB) (Disk ID: 91D378D4) Partition: GPT. ========================================================== Disk: 2 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 16E7CD80) Partition 1: (Active) - (Size=931.4 GB) - (Type=07 NTFS) ========================================================== Disk: 3 (Size: 3726 GB) (Disk ID: 02D7F5AF) Partition: GPT. ==================== End of Addition.txt =======================