AlucardSX
Contributor
- Sep 1, 2023
- 28
Hi,
as described in this thread over in the Windows 10 forum, I have a problem where Windows 10 all but goes into cardiac arrest every time I try to download after the system has been running for a couple of hours. So after trying a few solutions with no success, the mod helping me asked me to turn to you guys to see if the problem might be malware-related.
Here's the data from the FRST logs:
FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-08-2023
Ran by aluca (administrator) on DESKTOP-4F0VDIR (04-09-2023 21:47:22)
Running from C:\Users\aluca\Desktop\FRST64.exe
Loaded Profiles: aluca & _ashbackuppb_
Platform: Microsoft Windows 10 Home Version 22H2 19045.3324 (X64) Language: German (Germany) -> English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\backupService-abpb.exe ->) () [File not signed] C:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\oxHelper.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\AlwaysOnTop\PowerToys.AlwaysOnTop.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\Awake\PowerToys.Awake.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\ColorPicker\PowerToys.ColorPickerUI.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\FancyZones\PowerToys.FancyZones.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\KeyboardManager\KeyboardManagerEngine\PowerToys.KeyboardManagerEngine.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\launcher\PowerToys.PowerLauncher.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\PowerOCR\PowerToys.PowerOCR.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2309.1001.3.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(explorer.exe ->) (nordvpn s.a. -> TEFINCOM S.A.) C:\Program Files\NordVPN\NordVPN.exe
(explorer.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(explorer.exe ->) (Signal Messenger, LLC -> Signal Messenger, LLC) C:\Users\aluca\AppData\Local\Programs\signal-desktop\Signal.exe <4>
(explorer.exe ->) (Voyetra Turtle Beach, Inc. -> ROCCAT) C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\ROCCAT_Swarm_Monitor.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(MiniTool Software Limited -> ) C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe
(MosArt) [File not signed] C:\TECKNET wireless gaming mouse\TECKNET wireless gaming mouse.exe
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Ashampoo GmbH & Co. KG -> ) C:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\backupService-abpb.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
(services.exe ->) (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ICM\ICM-Service-NET.exe
(services.exe ->) (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) D:\Origin\OriginWebHelperService.exe
(services.exe ->) (Even Balance, Inc. -> ) C:\Windows\System32\PnkBstrA.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2>
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe
(services.exe ->) (MiniTool Software Limited -> ) C:\Program Files\MiniTool ShadowMaker\AgentService.exe
(services.exe ->) (MiniTool Software Limited -> ) C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe
(services.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordUpdater\NordUpdateService.exe
(services.exe ->) (nordvpn s.a. -> TEFINCOM S.A.) C:\Program Files\NordVPN\nordvpn-service.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_12a8d6d742c436e2\RtkAudUService64.exe
(services.exe ->) (Shanghai Microvirt Software Technology Co., Ltd. -> ) D:\Emulatoren\Android\MEmu\MemuService.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (GameplayCrush) [File not signed] C:\Users\aluca\Downloads\WindowedBorderlessGaming_2.1.0.1\WindowedBorderlessGaming.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.BingWeather_4.53.51922.0_x64__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2309.1001.3.0_x64__8wekyb3d8bbwe\XboxPcApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_4.6.2.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.OneNote_16001.14326.21452.0_x64__8wekyb3d8bbwe\onenoteim.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(svchost.exe ->) (Voyetra Turtle Beach, Inc. -> ROCCAT) C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\ROCCAT_dev_service.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [MTPW] => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [219616 2020-02-19] (MiniTool Software Limited -> )
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_12a8d6d742c436e2\RtkAudUService64.exe [1211184 2020-12-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [144696 2017-02-14] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [598200 2018-09-28] (Razer USA Ltd. -> Razer Inc.)
HKLM-x32\...\Run: [TECKNET wireless gaming mouse] => C:\TECKNET wireless gaming mouse\TECKNET wireless gaming mouse.exe [3845632 2018-06-25] (MosArt) [File not signed]
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [] => [X]
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [org.whispersystems.signal-desktop] => C:\Users\aluca\AppData\Local\Programs\signal-desktop\Signal.exe [163621088 2023-08-09] (Signal Messenger, LLC -> Signal Messenger, LLC)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [NordVPN] => C:\Program Files\NordVPN\NordVPN.exe [280952 2022-02-18] (nordvpn s.a. -> TEFINCOM S.A.)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [Humble Bundle] => C:\Users\aluca\AppData\Local\Programs\Humble App\Humble App.exe [151919352 2023-04-07] (Humble Bundle Inc. -> Humble Bundle)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [2637928 2023-08-28] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [ASRock A-Tuning] => [X]
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [GoogleChromeAutoLaunch_DC6ADF56C95D4F38FCEEDC413012C68B] => "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [3219744 2023-08-26] (Google LLC -> Google LLC)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\MountPoints2: {cbb4c2c2-e06f-11e6-8363-806e6f6e6963} - "I:\LaunchU3.exe" -a
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Winlogon: [Shell] C:\Windows\explorer.exe [5307536 2023-08-10] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Windows\System32\osk.exe [680448 2023-07-14] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\HP B111 Status Monitor: C:\Windows\system32\hpinkstsB111LM.dll [328552 2012-01-11] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\116.0.5845.141\Installer\chrmstp.exe [2023-09-01] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ROCCAT Swarm Monitor.lnk [2023-07-13]
ShortcutTarget: ROCCAT Swarm Monitor.lnk -> C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\ROCCAT_Swarm_Monitor.exe (Voyetra Turtle Beach, Inc. -> ROCCAT)
Startup: C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\QTTabBar Desktop Extension StartUp.QTTabGroup [2022-04-10] () [File not signed]
Startup: C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Razer Synapse.lnk [2019-01-20]
ShortcutTarget: Razer Synapse.lnk -> C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer USA Ltd. -> Razer Inc.)
GroupPolicy-Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {C83D7EEC-CF0F-496B-ADD1-8DDF6C8E4E70} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {CA01A975-9253-4F8F-B6E6-C87559BFC2E8} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564152 2023-04-03] (Adobe Inc. -> Adobe Inc.)
Task: {09F575CF-37C7-4F0C-996F-EA2BF7FF278D} - System32\Tasks\Avira_Antivirus_Systray => "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min (No File)
Task: {EC5E8D14-E52D-4004-A84B-20D546213EAE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-01-22] (Google Inc -> Google Inc.)
Task: {94C011EA-2384-4955-9D38-449068CC1792} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-01-22] (Google Inc -> Google Inc.)
Task: {689E3C95-59C0-4F8F-B6A3-F8D5DE2EC95C} - System32\Tasks\GSM_ao1jk-fcd33-67bde-vpwqd-s75md => D:\GameSave Manager\gs_mngr_3.exe [2696704 2021-09-29] (InsaneMatt) [File not signed]
Task: {685A4C3E-D289-46FB-BCA0-7C3BB9C2BFA5} - System32\Tasks\GSM_idnda-nwhy8-xbl73-7zqwz-ifk2j => F:\Game Save Manager\gs_mngr_3.exe [2719232 2022-10-05] (InsaneMatt) [File not signed]
Task: {F9E652F1-4BC0-4FE9-A5CD-A07B9C9E3191} - System32\Tasks\Microsoft\Windows\rempl\shell-usoscan => %ProgramFiles%\rempl\remsh.exe /RunUsoScanOnly (No File)
Task: {B2F3FA69-F65C-4FC7-8EF2-8DA67FA21947} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F3225AE4-7FBA-4F07-9DD7-BF8095F29DAD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DB213597-08DF-4CBA-8A39-E07585A422EF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {05FD2621-3B5D-4233-9ADE-EE705C48355C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {94B414E2-92D6-486D-993C-951E3FC571CA} - System32\Tasks\MiniToolPartitionWizard => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [219616 2020-02-19] (MiniTool Software Limited -> )
Task: {647CA575-AC0B-4C42-8168-CCEC90CD205D} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [815 2022-08-18] () [File not signed]
Task: {64D1A739-5CF7-42DD-B98B-2C3EB94E523C} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2023-03-17] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {B4C819D7-6FD8-468F-86A6-07364802F689} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-03-17] (Nvidia Corporation -> NVIDIA Corporation)
Task: {E4FA52EF-018E-4AF1-9A5F-3C03228E5967} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {732F2E43-AF41-415D-AFC9-5E92D723A69F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CDC679C3-63DF-42B1-AA46-C19E5B5290E4} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {29DEA42D-43EA-4840-934B-B0D2EE8CCBCB} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A9D30AEA-8B9F-46A3-899D-D88C4BECE4F8} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4CEB2DF4-2A77-49D7-88CE-6D7209135101} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3D3601D3-73F2-497C-A247-F3B611BDD81E} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5E27FF97-A730-42F5-BE88-127508A2D6DA} - System32\Tasks\PowerToys\Autorun for aluca => C:\Program Files\PowerToys\PowerToys.exe [1105344 2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {9E48E8A7-4F4F-48E2-A71D-14CD219A323B} - System32\Tasks\Private Internet Access Startup => C:\Program Files\pia_manager\pia_manager.exe [15732968 2018-06-18] (London Trust Media Inc -> ) [File not signed]
Task: {78C78A37-53AA-4E4D-A390-0276E7B15B5B} - System32\Tasks\ROCCAT DEVICE SERVICE => C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\ROCCAT_dev_service.exe [459672 2023-07-20] (Voyetra Turtle Beach, Inc. -> ROCCAT)
Task: {708B6639-2037-464B-98F7-CEA0868C16AC} - System32\Tasks\WindowedBorderlessGaming-aluca => C:\Users\aluca\Downloads\WindowedBorderlessGaming_2.1.0.1\WindowedBorderlessGaming.exe [893952 2015-03-17] (GameplayCrush) [File not signed]
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3: <==== ATTENTION (Restriction - Zones)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{43abba81-ac26-4732-bfde-521916648fe9}: [DhcpNameServer] 192.168.233.93
Tcpip\..\Interfaces\{a0d541e1-fa30-463e-92f7-238451da0013}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{fb2f4ab8-91e9-4b9d-93a1-3bca2dfa3a8c}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default [2023-09-04]
Edge HomePage: Default -> hxxps://www.google.at/webhp?hl=en
Edge StartupUrls: Default -> "chrome-extension://edacconmaakjimmfgnblocblbcdcpbko/main.html","hxxp://www.google.com/","hxxps://www.google.com/"
Edge Extension: (Google Translate) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-04-10]
Edge Extension: (PayPal Honey: Automatic Coupons & Cash Back) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\amnbcmdbanbkjhnfoeceemmmdiepnbpp [2023-09-04]
Edge Extension: (Google Voice Search Hotword (Beta)) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2022-03-23]
Edge Extension: (Avira Safe Shopping) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caiblelclndcckfafdaggpephhgfpoip [2022-10-31]
Edge Extension: (Pushbullet) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2023-04-08]
Edge Extension: (Search by Image (by Google)) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2022-03-23]
Edge Extension: (Checker Plus for Gmail™) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dkjkomkbjefdadfgbgdfgnpbmhmppiaa [2023-09-04]
Edge Extension: (Augmented Steam) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dnhpnfgdlenaccegplpojghhmaamnnfp [2023-07-14]
Edge Extension: (Avira Password Manager) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\emgfgdclgfeldebanedpihppahgngnle [2023-04-08]
Edge Extension: (Checker Plus for Google Calendar™) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fbongfbliechkeaegkjfehhimpenoani [2023-09-04]
Edge Extension: (Grammar Checker & Paraphraser – LanguageTool) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hfjadhjooeceemgojogkhlppanjkbobc [2023-09-02]
Edge Extension: (SteamDB) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hjknpdomhlodgaebegjopkmfafjpbblg [2023-09-04]
Edge Extension: (MyJDownloader Browser Extension) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ieapabanbplofifeaapjocpaogdhncdd [2022-03-23]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2023-09-02]
Edge Extension: (Chrome Remote Desktop) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2023-01-16]
Edge Extension: (Ask Historians Comment Helper) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jdkfbkogojpmdmpnkgjcgpngkkmhdfem [2022-03-23]
Edge Extension: (Reddit Enhancement Suite) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jlhgedjpndhblehblebhncfmkkpngiep [2023-04-08]
Edge Extension: (Edge relevant text changes) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-02]
Edge Extension: (Chrometana - Redirect Bing Somewhere Better) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kaicbfmipfpfpjmlbpejaoaflfdnabnc [2022-03-23]
Edge Extension: (Image Viewer) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kcljlcpbfbkapegpifkodjdmdllgdlmk [2022-03-23]
Edge Extension: (h264ify) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ldjamdlpbjpcfagnckgipdjiamhdcnbd [2022-03-23]
Edge Extension: (Chrometana Pro - Redirect Cortana and Bing) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\lllggmgeiphnciplalhefnbpddbadfdi [2023-01-16]
Edge Extension: (BeeLine Reader) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\lnhgohblpnbhabhglnlalchebkiegcii [2022-10-31]
Edge Extension: (Bing2Google) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mgoehlfmhfafaiepckjikpphoklijedl [2022-03-23]
Edge Extension: (Plugins) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mmcblfncjaclajmegihojiekebofjcen [2023-09-04]
Edge Extension: (Video Deck for YouTube™) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mpoakikepagdiphlmfaeifpojdmbnegj [2022-03-23]
Edge Extension: (Fakespot Fake Amazon Reviews and eBay Sellers) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nakplnnackehceedgkgkokbgbmfghain [2023-09-04]
Edge Extension: (AdBlock — best ad blocker) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2023-09-02]
Edge Extension: (Extensions Update Notifier) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nlldbplhbaopldicmcoogopmkonpebjm [2022-03-23]
Edge Extension: (Comic Updater) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pclklbdlpfhhbigalgggdfgiegbkipne [2022-03-23]
Edge Extension: (FFBE Sync) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pjcodgpdnfndnjegedmjnlamjfkigied [2023-03-14]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF DefaultProfile: piWQYoLX.default
FF ProfilePath: C:\Users\aluca\AppData\Roaming\Zotero\Zotero\Profiles\5hrqqoqw.default [2018-05-13]
FF Extension: (Zotero LibreOffice Integration) - C:\Program Files (x86)\Zotero Standalone\extensions\zoteroOpenOfficeIntegration@zotero.org [2018-05-12] [Legacy] [not signed]
FF Extension: (Zotero Word for Windows Integration) - C:\Program Files (x86)\Zotero Standalone\extensions\zoteroWinWordIntegration@zotero.org [2018-05-12] [Legacy] [not signed]
FF ProfilePath: C:\Users\aluca\AppData\Roaming\Mozilla\Firefox\Profiles\piWQYoLX.default [2022-09-29]
FF Extension: (Avira Browser Safety) - C:\Users\aluca\AppData\Roaming\Mozilla\Firefox\Profiles\piWQYoLX.default\Extensions\abs@avira.com.xpi [2018-12-09] [UpdateUrl:hxxps://download.avira.com/package/abs/firefox/update-webext.rdf]
FF Extension: (Video DownloadHelper) - C:\Users\aluca\AppData\Roaming\Mozilla\Firefox\Profiles\piWQYoLX.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-01-04]
FF Plugin: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-10-12] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-10-12] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> D:\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] (Apple Inc. -> )
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (Electronic Sports Network i Sverige AB -> ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) [File not signed]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2023-08-19] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3615177999-3261653453-3779512466-1001: ubisoft.com/uplaypc -> G:\Die Siedler 7\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll [2013-02-27] (Ubisoft Massive -> Ubisoft)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default [2023-09-04]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://loginstrom.com; hxxps://messages.google.com; hxxps://new.reddit.com; hxxps://web.whatsapp.com; hxxps://www.derstandard.at; hxxps://www.mydpd.at; hxxps://www.netflix.com; hxxps://www.reddit.com
CHR HomePage: Default -> hxxps://www.google.at/webhp?hl=en
CHR StartupUrls: Default -> "chrome-extension://edacconmaakjimmfgnblocblbcdcpbko/main.html","hxxp://www.google.com","hxxps://www.google.com/"
CHR DefaultSearchURL: Default -> hxxp://www.google.com/search?name=f&hl=en&q={searchTerms}
CHR DefaultSearchKeyword: Default -> google (no country redirect)
CHR Extension: (Google Übersetzer) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-03-23]
CHR Extension: (h264ify) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aleakchihdccplidncghkekgioiakgal [2019-09-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2017-05-23]
CHR Extension: (Honey: Automatische Coupons & Prämien) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2023-09-04]
CHR Extension: (History 2) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cahejgbbfgmlmjgdjlibphdjeldhagkp [2017-01-22]
CHR Extension: (Pushbullet) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2023-03-26]
CHR Extension: (uBlock Origin) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2023-07-30]
CHR Extension: (Search by Image (by Google)) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2017-01-22]
CHR Extension: (Augmented Steam) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnhpnfgdlenaccegplpojghhmaamnnfp [2023-07-08]
CHR Extension: (Reddit Masstagger) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebjdimopaogdkhiagbgmkjjhehmooheo [2019-11-17]
CHR Extension: (Session Buddy) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\edacconmaakjimmfgnblocblbcdcpbko [2023-07-26]
CHR Extension: (Adobe Acrobat: Werkzeuge zum Bearbeiten, Konvertieren und Signieren von PDF-Dateien) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2023-08-25]
CHR Extension: (MyJDownloader Browser Erweiterung) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbcohnmimjicjdomonkcbcpbpnhggkip [2021-06-28]
CHR Extension: (Avira Browserschutz) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2022-10-26]
CHR Extension: (Chrome Remote Desktop) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-18]
CHR Extension: (Google Docs Offline) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-08-25]
CHR Extension: (AdBlock – der beste Ad-Blocker) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2023-08-09]
CHR Extension: (TweetDeck by Twitter) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2017-01-22]
CHR Extension: (feedly) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipbfijinpcgfogaopmgehiegacbhmob [2017-01-22]
CHR Extension: (AirDroid) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkgndiocipalkpejnpafdbdlfdjihomd [2017-01-22]
CHR Extension: (Checker Plus for Google Calendar™) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkhggnncdpfibdhinjiegagmopldibha [2023-08-22]
CHR Extension: (BeeLine Reader) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifjafammaookpiajfbedmacfldaiamgg [2023-07-10]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2023-08-29]
CHR Extension: (Forecastfox) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihffmkcfkejomlfnilnmkokcpgclhfeg [2017-01-22]
CHR Extension: (Chrome Remote Desktop) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2022-12-08]
CHR Extension: (Ask Historians Comment Helper) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdkfbkogojpmdmpnkgjcgpngkkmhdfem [2019-10-16]
CHR Extension: (Chrometana - Redirect Bing Somewhere Better) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaicbfmipfpfpjmlbpejaoaflfdnabnc [2017-07-27]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2023-04-04]
CHR Extension: (Image Viewer) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcljlcpbfbkapegpifkodjdmdllgdlmk [2017-01-22]
CHR Extension: (SteamDB) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdbmhfkmnlmbkgbabkdealhhbfhlmmon [2023-08-24]
CHR Extension: (Chrometana Pro - Redirect Cortana and Bing) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\lllggmgeiphnciplalhefnbpddbadfdi [2022-12-07]
CHR Extension: (AirDroid Remote Control Plugin) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\macmgoeeggnlnmpiojbcniblabkdjphe [2019-11-19]
CHR Extension: (Bing2Google) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgoehlfmhfafaiepckjikpphoklijedl [2017-01-22]
CHR Extension: (Plugins) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcblfncjaclajmegihojiekebofjcen [2023-09-04]
CHR Extension: (Video Deck for YouTube™) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpoakikepagdiphlmfaeifpojdmbnegj [2017-04-08]
CHR Extension: (Fakespot Fake Amazon Reviews and eBay Sellers) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nakplnnackehceedgkgkokbgbmfghain [2023-08-24]
CHR Extension: (Keepa - Amazon Price Tracker) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\neebplgakaahbhdphmkckjjcegoiijjo [2023-08-11]
CHR Extension: (Extensions Update Notifier) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlldbplhbaopldicmcoogopmkonpebjm [2017-01-22]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Checker Plus for Gmail™) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2023-08-21]
CHR Extension: (Grammatik- und Rechtschreibprüfung – LanguageTool) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\oldceeleldhonbafppcapldpdifcinji [2023-07-03]
CHR Extension: (Youtube Playlist Load All) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbclhlmcclobinpephoflilgclodhnmf [2017-01-22]
CHR Extension: (Comic Updater) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pclklbdlpfhhbigalgggdfgiegbkipne [2017-12-10]
CHR Extension: (FFBE Sync) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjcodgpdnfndnjegedmjnlamjfkigied [2023-02-27]
CHR Extension: (Sci-Hub) - C:\Users\aluca\Downloads\Sci-Hub [2017-02-10] [UpdateUrl:hxxp://31.184.194.81/update] <==== ATTENTION
CHR Profile: C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Guest Profile [2022-02-16]
CHR Profile: C:\Users\aluca\AppData\Local\Google\Chrome\User Data\System Profile [2022-02-16]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32\...\Chrome\Extension: [hncafdhkllgldnimopgfkgnlcijmonah]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"MBAMChameleon" => service could not be unlocked. <==== ATTENTION
HKLM\SYSTEM\ControlSet001\Services\MBAMChameleon => \SystemRoot\System32\Drivers\MbamChameleon.sys <==== ATTENTION (Rootkit!/Locked Service)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-04-03] (Adobe Inc. -> Adobe Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-07-04] (ASUSTeK Computer Inc. -> )
R2 ashbackuppb; c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\backupService-abpb.exe [34184 2020-11-17] (Ashampoo GmbH & Co. KG -> )
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [9712432 2023-01-26] (BattlEye Innovations e.K. -> )
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [270336 2012-07-13] (Brother Industries, Ltd.) [File not signed]
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\116.0.5845.9\remoting_host.exe [74520 2023-06-26] (Google LLC -> Google LLC)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [10941544 2023-08-28] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2022-11-24] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [584680 2022-08-09] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2022-11-16] (Epic Games Inc. -> Epic Games, Inc.)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342456 2018-05-22] (FUTUREMARK INC -> Futuremark)
S3 GalaxyClientService; D:\GOG Galaxy\GalaxyClientService.exe [2346464 2023-07-20] (GOG sp. z o.o -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7178720 2023-07-20] (GOG sp. z o.o -> GOG.com)
S4 HiPatchService; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-07-11] (Hi-Rez Studios) [File not signed]
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [230352 2023-08-08] (HP Inc. -> HP Inc.)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [8929608 2021-11-17] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9283096 2023-08-27] (Malwarebytes Inc. -> Malwarebytes)
R2 MEmuSVC; D:\Emulatoren\Android\MEmu\MemuService.exe [85304 2019-07-02] (Shanghai Microvirt Software Technology Co., Ltd. -> )
R2 MTAgentService; C:\Program Files\MiniTool ShadowMaker\AgentService.exe [783728 2021-12-20] (MiniTool Software Limited -> )
R2 MTSchedulerService; C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe [228208 2021-12-20] (MiniTool Software Limited -> )
R2 NordUpdaterService; C:\Program Files\NordUpdater\NordUpdateService.exe [297848 2022-11-21] (nordvpn s.a. -> nordvpn S.A.)
R2 nordvpn-service; C:\Program Files\NordVPN\nordvpn-service.exe [281464 2022-02-18] (nordvpn s.a. -> TEFINCOM S.A.)
S3 Origin Client Service; D:\Origin\OriginClientService.exe [2575064 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; D:\Origin\OriginWebHelperService.exe [3494672 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2018-01-18] (Even Balance, Inc. -> )
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [16552248 2023-01-18] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [4076744 2017-02-14] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe [3121008 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe [133688 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ZA NET ICM Service; C:\Program Files (x86)\CheckPoint\ICM\ICM-Service-NET.exe [42208 2020-03-13] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S3 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [114936 2016-11-01] (Check Point Software Technologies Ltd. -> Check Point Software Technologies, Ltd.)
S2 ZoneAlarm ICM Service; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe [1037624 2017-02-14] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S2 AntivirProtectedService; "C:\Program Files (x86)\Avira\Antivirus\ProtectedService.exe" [X]
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
S3 SoundBoosterService; C:\Program Files (x86)\Letasoft Sound Booster\SoundBoosterService.exe [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-04] (ASUSTeK Computer Inc. -> )
S3 AsrDrv105; C:\WINDOWS\SysWOW64\Drivers\AsrDrv105.sys [40696 2023-08-28] (ASROCK INC. -> ASRock Incorporation)
S3 atvi-randgrid; C:\ProgramData\Battle.net_components\randgridauks\randgrid.sys [2986792 2023-09-01] (Activision Publishing Inc -> Activision Blizzard, Inc.)
S3 cpuz143; C:\Users\aluca\AppData\Local\Temp\cpuz143\cpuz143_x64.sys [48952 2023-09-02] (CPUID -> CPUID) <==== ATTENTION
S3 cpuz155; C:\Windows\temp\cpuz155\cpuz155_x64.sys [41480 2023-09-02] (Microsoft Windows Hardware Compatibility Publisher -> CPUID)
S3 DFX11_1; C:\Windows\system32\drivers\dfx11_1x64.sys [28008 2015-08-31] (Power Technology -> Windows (R) Win 7 DDK provider)
S3 DFX12; C:\Windows\system32\drivers\dfx12x64.sys [39048 2015-11-15] (Power Technology -> Windows (R) Win 7 DDK provider)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [21480 2022-06-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239544 2023-09-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R1 MEmuDrv; C:\Windows\system32\DRIVERS\MEmuDrv.sys [319448 2019-04-15] (Shanghai Microvirt Software Technology Co., Ltd. -> Maiwei Corporation)
R3 MpKsl68cd9a67; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DA88474F-78D1-4D98-878C-3FDD304493C4}\MpKslDrv.sys [222464 2023-09-04] (Microsoft Windows -> Microsoft Corporation)
S3 MpKsl97551fff; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DA88474F-78D1-4D98-878C-3FDD304493C4}\MpKslDrv.sys [222464 2023-09-04] (Microsoft Windows -> Microsoft Corporation)
R2 NDivert; C:\Program Files\NordVPN\6.48.19.0\Drivers\NDivert.sys [131456 2022-04-05] (nordvpn s.a. -> Nordvpn S.A.)
R1 nordlwf; C:\Windows\system32\DRIVERS\nordlwf.sys [44928 2022-02-22] (nordvpn s.a. -> TEFINCOM S.A.)
R1 npcap; C:\Windows\system32\DRIVERS\npcap.sys [77336 2022-08-19] (Insecure.Com LLC -> Insecure.Com LLC.)
R3 NvModuleTracker; C:\Windows\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2023-03-17] (Nvidia Corporation -> NVIDIA Corporation)
U5 PROCMON24; C:\Windows\System32\Drivers\PROCMON24.sys [80296 2023-08-31] (Microsoft Windows Hardware Compatibility Publisher -> Sysinternals - www.sysinternals.com)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] (MiniTool Solution Ltd -> )
S3 rspLLL; C:\Windows\System32\DRIVERS\rspLLL64.sys [26368 2020-08-21] (Daniel Terhell -> Resplendence Software Projects Sp.)
S3 rspWhySoSlow; C:\Windows\System32\DRIVERS\rspWhy64.sys [28928 2016-12-17] (Daniel Terhell -> Resplendence Software Projects Sp.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14024 2017-08-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [50392 2015-08-13] (Razer Inc. -> Razer Inc)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 tap0901; C:\Windows\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R3 tapnordvpn; C:\Windows\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
R3 USBPcap; C:\Windows\system32\DRIVERS\USBPcap.sys [52872 2020-05-22] (Tomasz Moń -> USBPcap)
R3 VirtualHID; C:\Windows\System32\drivers\VirtualHID.sys [26768 2022-08-15] (Voyetra Turtle Beach, Inc. -> TurtleBeach)
R1 Vsdatant; C:\Windows\system32\DRIVERS\vsdatant.sys [461240 2017-03-16] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [55872 2023-08-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [574872 2023-08-30] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105864 2023-08-30] (Microsoft Windows -> Microsoft Corporation)
S3 WIMMount; C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\amd64\DISM\wimmount.sys [42688 2016-07-16] (Microsoft Corporation -> Microsoft Corporation)
S3 WinRing0_1_2_0; C:\Users\aluca\Downloads\RealTemp_370\WinRing0x64.sys [14544 2008-07-26] (Noriyuki MIYAZAKI -> OpenLibSys.org)
S3 wintun; C:\Windows\System32\drivers\wintun.sys [29592 2022-04-10] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WofAdk; C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\amd64\DISM\wofadk.sys [221376 2016-07-16] (Microsoft Corporation -> Microsoft Corporation)
R1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [310536 2019-09-10] (Beijing Duodian Online Science and Technology Co.,Ltd -> BigNox Corporation)
S3 ALSysIO; \??\C:\Users\aluca\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 HWiNFO_174; \??\C:\Users\aluca\AppData\Local\Temp\HWiNFO64A_174.SYS [X] <==== ATTENTION
U3 iswSvc; no ImagePath
U4 npcap_wifi; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-09-04 21:47 - 2023-09-04 21:48 - 000049909 _____ C:\Users\aluca\Desktop\FRST.txt
2023-09-04 21:46 - 2023-09-04 20:21 - 002382336 _____ (Farbar) C:\Users\aluca\Desktop\FRST64.exe
2023-09-04 20:51 - 2023-09-04 20:57 - 000230480 _____ C:\Users\aluca\Downloads\Addition.txt
2023-09-04 20:49 - 2023-09-04 20:57 - 000072892 _____ C:\Users\aluca\Downloads\FRST.txt
2023-09-04 20:21 - 2023-09-04 21:47 - 000000000 ____D C:\FRST
2023-09-04 20:21 - 2023-09-04 20:21 - 002382336 _____ (Farbar) C:\Users\aluca\Downloads\FRST64.exe
2023-09-03 20:12 - 2023-09-03 20:12 - 000000000 ____D C:\Windows\LastGood.Tmp
2023-09-03 20:07 - 2023-08-16 12:15 - 000849088 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2023-09-03 20:07 - 2023-08-16 12:15 - 000849088 _____ C:\Windows\system32\vulkaninfo.exe
2023-09-03 20:07 - 2023-08-16 12:15 - 000713912 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2023-09-03 20:07 - 2023-08-16 12:15 - 000713912 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2023-09-03 20:07 - 2023-08-16 12:15 - 000653504 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2023-09-03 20:07 - 2023-08-16 12:15 - 000653504 _____ C:\Windows\system32\vulkan-1.dll
2023-09-03 20:07 - 2023-08-16 12:15 - 000637112 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2023-09-03 20:07 - 2023-08-16 12:15 - 000637112 _____ C:\Windows\SysWOW64\vulkan-1.dll
2023-09-03 20:07 - 2023-08-16 12:14 - 001487376 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2023-09-03 20:07 - 2023-08-16 12:14 - 001227296 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2023-09-03 20:07 - 2023-08-16 12:11 - 000669320 _____ C:\Windows\system32\nvofapi64.dll
2023-09-03 20:07 - 2023-08-16 12:10 - 001537544 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2023-09-03 20:07 - 2023-08-16 12:10 - 001195016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2023-09-03 20:07 - 2023-08-16 12:10 - 000938608 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2023-09-03 20:07 - 2023-08-16 12:10 - 000504456 _____ C:\Windows\SysWOW64\nvofapi.dll
2023-09-03 20:07 - 2023-08-16 12:09 - 002168456 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2023-09-03 20:07 - 2023-08-16 12:09 - 001622152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2023-09-03 20:07 - 2023-08-16 12:09 - 000992368 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2023-09-03 20:07 - 2023-08-16 12:09 - 000777760 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2023-09-03 20:07 - 2023-08-16 12:09 - 000768648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2023-09-03 20:07 - 2023-08-16 12:08 - 014520968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2023-09-03 20:07 - 2023-08-16 12:08 - 012066320 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2023-09-03 20:07 - 2023-08-16 12:08 - 003483168 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2023-09-03 20:07 - 2023-08-16 12:08 - 000459912 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2023-09-03 20:07 - 2023-08-16 12:07 - 006190088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2023-09-03 20:07 - 2023-08-16 12:07 - 005845640 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2023-09-03 20:07 - 2023-08-16 12:07 - 005550728 _____ (NVIDIA Corporation) C:\Windows\system32\nvcudadebugger.dll
2023-09-03 20:07 - 2023-08-16 12:07 - 000853104 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2023-09-03 20:07 - 2023-08-15 06:23 - 000108122 _____ C:\Windows\system32\nvinfo.pb
2023-09-03 20:05 - 2023-09-03 20:05 - 000000000 ____D C:\Users\aluca\AppData\Roaming\ArmoredCore6
2023-09-02 23:57 - 2023-09-02 23:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Armored Core 6 - Fires of Rubicon
2023-09-02 17:02 - 2023-09-02 17:02 - 001316932 _____ C:\Windows\Minidump\090223-21562-01.dmp
2023-09-02 15:57 - 2023-09-02 23:57 - 000000969 _____ C:\Users\Public\Desktop\Armored Core 6 - Bonus.lnk
2023-09-02 15:57 - 2023-09-02 23:57 - 000000793 _____ C:\Users\Public\Desktop\Armored Core 6 - Fires of Rubicon.lnk
2023-09-01 17:46 - 2023-09-01 17:46 - 017708338 _____ C:\Users\aluca\Documents\SysnativeFileCollectionApp.zip
2023-09-01 17:00 - 2023-09-01 17:00 - 035503819 _____ C:\Users\aluca\Desktop\trace.zip
2023-09-01 16:42 - 2023-09-01 16:55 - 161808384 _____ C:\Users\aluca\Desktop\trace.etl
2023-09-01 16:37 - 2023-09-01 16:55 - 152174592 _____ C:\kernel.etl
2023-08-31 23:15 - 2023-08-31 23:15 - 001975756 _____ C:\Windows\Minidump\083123-40046-01.dmp
2023-08-31 22:29 - 2023-08-31 22:40 - 000000000 ____D C:\Users\aluca\Documents\Latency Mon
2023-08-31 19:19 - 2023-08-31 19:19 - 000001465 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Procmon.lnk
2023-08-31 19:19 - 2023-08-31 19:19 - 000000000 ____D C:\Users\aluca\Downloads\ProcessMonitor
2023-08-31 19:17 - 2023-08-31 19:17 - 003456915 _____ C:\Users\aluca\Downloads\ProcessMonitor.zip
2023-08-31 19:17 - 2023-08-31 19:17 - 000001490 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DriverView.lnk
2023-08-31 15:44 - 2023-08-31 23:10 - 000000000 ____D C:\Users\aluca\Downloads\driverview-x64
2023-08-31 15:44 - 2023-08-31 15:44 - 000060809 _____ C:\Users\aluca\Downloads\driverview-x64.zip
2023-08-31 15:31 - 2023-08-31 15:31 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Wireshark
2023-08-31 15:25 - 2023-08-31 15:25 - 000001827 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark.lnk
2023-08-31 15:25 - 2023-08-31 15:25 - 000000000 ____D C:\Program Files\USBPcap
2023-08-31 15:24 - 2023-08-31 15:24 - 000003460 _____ C:\Windows\system32\Tasks\npcapwatchdog
2023-08-31 15:24 - 2023-08-31 15:24 - 000000000 ____D C:\Windows\SysWOW64\Npcap
2023-08-31 15:24 - 2023-08-31 15:24 - 000000000 ____D C:\Windows\system32\Npcap
2023-08-31 15:24 - 2023-08-31 15:24 - 000000000 ____D C:\Program Files\Npcap
2023-08-31 15:22 - 2023-08-31 15:25 - 000000000 ____D C:\Program Files\Wireshark
2023-08-31 15:20 - 2023-08-31 15:21 - 079164216 _____ (Wireshark development team) C:\Users\aluca\Downloads\Wireshark-win64-4.0.8.exe
2023-08-31 12:48 - 2023-08-31 20:17 - 000000000 ____D C:\Users\aluca\AppData\Local\DeadIsland
2023-08-31 12:48 - 2023-08-31 12:48 - 000000000 ____D C:\Users\Public\Documents\EMPRESS
2023-08-30 19:58 - 2023-08-30 20:25 - 000000000 ____D C:\ESD
2023-08-30 19:56 - 2023-08-30 20:04 - 000000000 ____D C:\Users\aluca\AppData\Roaming\U3
2023-08-30 19:54 - 2023-08-30 19:54 - 000000000 ___HD C:\$Windows.~WS
2023-08-30 19:54 - 2023-08-30 19:54 - 000000000 ____D C:\$WINDOWS.~BT
2023-08-29 21:12 - 2023-08-29 21:12 - 000000000 ____D C:\Program Files (x86)\Intel Driver
2023-08-29 21:10 - 2023-08-29 21:10 - 009822245 _____ C:\Users\aluca\Downloads\Realtek_LAN(v1125.1.714.2021).zip
2023-08-29 21:10 - 2023-08-29 21:10 - 001600291 _____ C:\Users\aluca\Downloads\Intel_LAN(v12.19.1.37b_v2).zip
2023-08-29 18:27 - 2023-08-29 18:27 - 000001519 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Speccy64.lnk
2023-08-29 18:26 - 2023-08-29 18:26 - 002781052 _____ C:\Users\aluca\Downloads\Speccy x64 portable.zip
2023-08-29 18:26 - 2023-08-29 18:26 - 000000000 ____D C:\Users\aluca\Downloads\Speccy x64 portable
2023-08-29 18:21 - 2023-09-01 17:45 - 000000000 ____D C:\Users\aluca\Documents\SysnativeFileCollectionApp
2023-08-29 18:20 - 2023-08-29 18:20 - 000175952 _____ (Sysnative) C:\Users\aluca\Downloads\SysnativeBSODCollectionApp.exe
2023-08-28 22:59 - 2023-08-28 22:59 - 002552364 _____ C:\Windows\Minidump\082823-12328-01.dmp
2023-08-28 22:50 - 2023-08-28 22:50 - 000000000 ____D C:\Program Files\Intel
2023-08-28 22:49 - 2023-08-28 22:49 - 003947286 _____ C:\Users\aluca\Downloads\INF(v10.1.18634.8254_Public).zip
2023-08-28 22:45 - 2023-08-29 21:18 - 000000000 ____D C:\Program Files (x86)\Realtek
2023-08-28 22:45 - 2023-08-28 22:51 - 000000000 ___HD C:\Program Files (x86)\Temp
2023-08-28 22:45 - 2020-12-09 18:06 - 005989992 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2023-08-28 22:45 - 2020-12-09 18:05 - 000276736 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTHDASIO64.dll
2023-08-28 22:45 - 2020-12-09 18:05 - 000231664 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RTHDASIO.dll
2023-08-28 22:45 - 2019-12-19 09:07 - 002877104 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
2023-08-28 22:44 - 2023-08-28 22:44 - 036578316 _____ C:\Users\aluca\Downloads\Realtek_Audio(v9079.1_UAD_WHQL_Nahimic).zip
2023-08-28 22:41 - 2023-08-28 22:41 - 000040696 _____ (ASRock Incorporation) C:\Windows\SysWOW64\Drivers\AsrDrv105.sys
2023-08-28 22:41 - 2023-08-28 22:41 - 000001344 _____ C:\Users\Public\Desktop\A-Tuning.lnk
2023-08-28 22:41 - 2023-08-28 22:41 - 000000000 ____D C:\Windows\ASRock
2023-08-28 22:41 - 2023-08-28 22:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility
2023-08-28 22:41 - 2023-08-28 22:41 - 000000000 ____D C:\Program Files (x86)\ASRock Utility
2023-08-28 22:40 - 2023-08-28 22:40 - 062145883 _____ C:\Users\aluca\Downloads\MotherboardUtility(v3.0.425).zip
2023-08-28 20:54 - 2023-08-28 20:54 - 000000000 ____D C:\SymCache
2023-08-28 20:53 - 2023-08-28 22:17 - 000000000 ____D C:\Users\aluca\Documents\WPR Files
2023-08-28 20:53 - 2023-08-28 22:17 - 000000000 ____D C:\Users\aluca\AppData\Local\Windows Performance Analyzer
2023-08-28 20:53 - 2023-08-28 20:53 - 000000000 ____D C:\Users\aluca\Documents\WPA Files
2023-08-28 20:29 - 2023-08-28 20:29 - 000000000 ____D C:\ProgramData\WindowsPerformanceRecorder
2023-08-28 19:52 - 2023-08-28 19:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2023-08-28 11:14 - 2023-08-28 11:14 - 002633636 _____ C:\Windows\Minidump\082823-15265-01.dmp
2023-08-26 15:24 - 2023-08-26 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dead Island 2
2023-08-23 11:05 - 2023-08-23 11:05 - 004653724 _____ C:\Windows\Minidump\082323-22625-01.dmp
2023-08-15 12:43 - 2023-08-22 14:39 - 000001326 _____ C:\Users\aluca\Desktop\Fire Toolbox V32.1.lnk
2023-08-14 11:04 - 2023-08-22 14:39 - 000001334 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fire Toolbox V32.1.lnk
2023-08-14 08:09 - 2023-08-15 11:14 - 000000000 ____D C:\Users\aluca\AppData\LocalLow\IGDump
2023-08-13 12:34 - 2023-08-16 12:05 - 006737504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2023-08-10 20:38 - 2023-08-10 20:38 - 000000000 ___HD C:\$WinREAgent
2023-08-09 16:02 - 2023-08-09 16:02 - 000315416 _____ C:\Users\aluca\Documents\Wien_Energie_Rechnung_005107849736.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-09-04 21:46 - 2021-04-08 14:04 - 000000000 ____D C:\Users\aluca\AppData\Local\Ashampoo Backup PB
2023-09-04 21:44 - 2021-12-17 01:26 - 000000000 ____D C:\Windows\SystemTemp
2023-09-04 21:44 - 2017-01-22 14:17 - 000000000 ____D C:\Program Files (x86)\Google
2023-09-04 21:43 - 2023-05-12 22:51 - 000000000 ____D C:\Users\aluca\AppData\Local\Malwarebytes
2023-09-04 21:43 - 2022-03-15 16:21 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Signal
2023-09-04 21:43 - 2017-05-13 17:16 - 000000000 ____D C:\ProgramData\NVIDIA
2023-09-04 21:43 - 2017-01-25 12:32 - 000000000 ____D C:\Users\aluca\Documents\Assassin's Creed Unity
2023-09-04 21:42 - 2022-11-08 13:23 - 000000000 ____D C:\Windows\system32\Tasks\PowerToys
2023-09-04 21:42 - 2022-07-09 12:39 - 000000000 ____D C:\Program Files\TeamViewer
2023-09-04 21:42 - 2021-03-15 17:21 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-09-04 21:42 - 2021-03-15 16:50 - 000008192 ___SH C:\DumpStack.log.tmp
2023-09-04 21:42 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-09-04 21:42 - 2019-12-07 11:03 - 000786432 _____ C:\Windows\system32\config\BBI
2023-09-04 21:40 - 2021-07-28 15:43 - 000239544 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2023-09-04 21:38 - 2018-07-10 14:13 - 000000000 ____D C:\Windows\pss
2023-09-04 21:38 - 2017-11-17 14:22 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2023-09-04 21:30 - 2017-01-22 20:55 - 000000000 ____D C:\Users\aluca\AppData\Local\CrashDumps
2023-09-04 21:25 - 2017-06-28 17:09 - 000000000 ____D C:\Users\aluca\AppData\Local\Battle.net
2023-09-04 21:03 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-09-04 21:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2023-09-04 21:02 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2023-09-04 12:34 - 2022-03-18 14:50 - 000000000 ____D C:\XboxGames
2023-09-04 12:34 - 2018-02-02 12:15 - 000000000 ____D C:\Users\aluca\AppData\Local\Packages
2023-09-04 12:32 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\Registration
2023-09-04 11:13 - 2021-03-15 16:51 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-09-04 00:32 - 2021-06-01 13:04 - 000004168 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{AB636331-6FD2-446F-9E32-00CA4DC5C76B}
2023-09-03 23:07 - 2021-03-15 17:04 - 002333492 _____ C:\Windows\system32\PerfStringBackup.INI
2023-09-03 23:07 - 2021-03-15 15:12 - 000477628 _____ C:\Windows\system32\perfh011.dat
2023-09-03 23:07 - 2021-03-15 15:12 - 000132506 _____ C:\Windows\system32\perfc011.dat
2023-09-03 23:07 - 2019-12-07 16:50 - 000743546 _____ C:\Windows\system32\perfh007.dat
2023-09-03 23:07 - 2019-12-07 16:50 - 000149968 _____ C:\Windows\system32\perfc007.dat
2023-09-03 22:58 - 2021-06-09 16:54 - 000000000 ____D C:\SteamLibrary
2023-09-03 22:38 - 2020-01-14 13:35 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Goldberg SteamEmu Saves
2023-09-03 20:12 - 2018-07-11 21:29 - 000000000 ____D C:\Users\aluca\AppData\Local\NVIDIA
2023-09-03 20:08 - 2017-05-13 17:16 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2023-09-03 20:05 - 2018-05-30 19:05 - 000000000 ____D C:\Users\aluca\AppData\Local\D3DSCache
2023-09-03 19:50 - 2017-01-23 21:26 - 000000000 ____D C:\Users\aluca\AppData\Roaming\XnViewMP
2023-09-02 23:50 - 2021-03-15 16:03 - 000000000 ____D C:\Users\aluca
2023-09-02 17:02 - 2022-03-18 14:53 - 000000000 ____D C:\Windows\Minidump
2023-09-02 17:02 - 2020-07-02 19:12 - 1833298942 _____ C:\Windows\MEMORY.DMP
2023-09-01 17:18 - 2020-06-07 20:36 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-09-01 17:18 - 2020-06-07 20:36 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-09-01 03:06 - 2022-02-16 15:06 - 000002239 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-09-01 03:06 - 2022-02-16 15:06 - 000002198 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-08-31 23:31 - 2022-10-21 21:03 - 000079360 _____ (Microsoft Corporation) C:\Windows\system32\xgamehelper.exe
2023-08-31 23:31 - 2022-10-21 21:03 - 000062976 _____ (Microsoft Corporation) C:\Windows\system32\xgamecontrol.exe
2023-08-31 23:31 - 2021-11-21 12:11 - 000169472 _____ (Microsoft Corporation) C:\Windows\system32\gamelaunchhelper.dll
2023-08-31 23:31 - 2020-05-01 10:54 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\gamingtcuihelpers.dll
2023-08-31 23:31 - 2019-12-13 12:23 - 000493056 _____ (Microsoft Corporation) C:\Windows\system32\gameplatformservices.dll
2023-08-31 23:31 - 2019-12-04 11:14 - 002807296 _____ (Microsoft Corporation) C:\Windows\system32\xgameruntime.dll
2023-08-31 23:31 - 2019-12-04 11:14 - 000247288 _____ (Microsoft Corporation) C:\Windows\system32\gamingservicesproxy.dll
2023-08-31 23:31 - 2019-12-04 11:14 - 000202240 _____ (Microsoft Corporation) C:\Windows\system32\gameconfighelper.dll
2023-08-31 22:48 - 2022-09-27 12:17 - 000000000 ____D C:\Users\aluca\AppData\Roaming\qBittorrent
2023-08-31 17:23 - 2017-01-26 22:24 - 000000000 ____D C:\Users\aluca\AppData\Local\JDownloader v2.0
2023-08-31 16:15 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2023-08-31 15:24 - 2017-01-22 17:37 - 000000000 ____D C:\ProgramData\Package Cache
2023-08-31 11:10 - 2021-12-11 12:53 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3615177999-3261653453-3779512466-1001
2023-08-31 11:10 - 2021-03-15 17:21 - 000003380 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3615177999-3261653453-3779512466-1001
2023-08-31 11:10 - 2021-03-15 16:03 - 000002383 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-08-30 23:14 - 2022-05-04 13:09 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Humble App
2023-08-30 20:25 - 2021-03-15 11:30 - 000000000 ___DC C:\Windows\Panther
2023-08-30 17:46 - 2019-12-07 11:14 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2023-08-30 17:26 - 2017-03-01 18:37 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Microsoft\Excel
2023-08-30 17:06 - 2017-01-22 20:21 - 000000000 ____D C:\ProgramData\Zoom Player
2023-08-30 16:58 - 2018-03-31 12:56 - 000000000 ____D C:\Windows\system32\Drivers\wd
2023-08-29 21:18 - 2017-08-13 16:16 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2023-08-29 16:34 - 2017-01-22 19:55 - 000000000 ____D C:\Program Files (x86)\Avira
2023-08-29 16:33 - 2021-04-16 11:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2023-08-29 16:33 - 2017-01-22 19:55 - 000000000 ____D C:\ProgramData\Avira
2023-08-29 16:32 - 2023-02-15 16:33 - 003893768 _____ C:\Windows\system32\rtp.db
2023-08-29 16:32 - 2022-06-06 12:10 - 000000000 ____D C:\Program Files\Avira
2023-08-29 16:32 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2023-08-29 15:17 - 2021-06-04 10:49 - 000000000 ____D C:\Games
2023-08-29 15:01 - 2018-02-16 12:03 - 000000000 ____D C:\Epic Games
2023-08-29 14:59 - 2018-02-16 12:03 - 000002135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
2023-08-29 14:59 - 2018-02-16 12:03 - 000002123 _____ C:\Users\Public\Desktop\Epic Games Launcher.lnk
2023-08-29 13:26 - 2017-01-23 20:03 - 000000000 ____D C:\Users\aluca\AppData\Local\Steam
2023-08-28 22:59 - 2021-03-15 16:51 - 000404152 _____ C:\Windows\system32\FNTCACHE.DAT
2023-08-28 11:18 - 2017-01-22 09:54 - 000918960 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2023-08-25 10:30 - 2022-04-10 19:24 - 000000000 ____D C:\Program Files\NordUpdater
2023-08-24 21:22 - 2022-10-13 18:33 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2023-08-23 00:32 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\LiveKernelReports
2023-08-22 14:39 - 2021-06-26 12:31 - 000001344 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Toolbox Updater.lnk
2023-08-22 14:39 - 2021-06-26 12:31 - 000001336 _____ C:\Users\aluca\Desktop\Toolbox Updater.lnk
2023-08-22 11:23 - 2020-03-22 19:44 - 000000000 ____D C:\Users\aluca\AppData\Local\Apps\2.0
2023-08-18 15:34 - 2018-09-13 16:10 - 000000347 _____ C:\Windows\BRRBCOM.INI
2023-08-16 12:06 - 2023-04-08 15:15 - 007858112 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2023-08-15 06:23 - 2023-04-08 15:15 - 000121880 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2023-08-13 12:35 - 2017-05-13 17:16 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\setup
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\migwiz
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\appraiser
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\appcompat
2023-08-10 20:44 - 2021-03-15 16:54 - 003015168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2023-08-10 20:38 - 2017-01-22 09:54 - 000000000 ____D C:\Windows\system32\MRT
2023-08-10 20:34 - 2017-01-22 09:53 - 175983240 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2023-08-10 10:34 - 2020-09-03 11:19 - 000000000 ____D C:\Users\Public\Security Sessions
2023-08-10 00:01 - 2017-09-29 16:49 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Microsoft\Word
2023-08-09 10:50 - 2022-11-08 13:22 - 000000000 ____D C:\Program Files\dotnet
2023-08-08 11:15 - 2021-05-12 13:21 - 000000000 ____D C:\Windows\system32\Tasks\HP
2023-08-08 11:15 - 2021-05-12 13:21 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
==================== Files in the root of some directories ========
2019-04-15 22:43 - 2019-04-16 23:46 - 000000002 _____ () C:\Users\aluca\AppData\Roaming\ceville_console_history.txt
2022-05-31 17:20 - 2022-05-31 17:20 - 000004870 _____ () C:\Users\aluca\AppData\Local\2758054585
2022-12-04 14:46 - 2022-12-04 14:46 - 000003998 _____ () C:\Users\aluca\AppData\Local\2830118318
2022-12-08 13:03 - 2022-12-25 13:08 - 000003998 _____ () C:\Users\aluca\AppData\Local\3206298627
2023-03-07 12:27 - 2023-03-07 12:27 - 000005358 _____ () C:\Users\aluca\AppData\Local\92443903807
2023-06-08 21:27 - 2023-06-08 21:27 - 000005990 _____ () C:\Users\aluca\AppData\Local\93205666527
2023-06-02 22:47 - 2023-06-02 22:47 - 000005990 _____ () C:\Users\aluca\AppData\Local\9618647855
2023-05-21 10:59 - 2023-05-21 10:59 - 000005990 _____ () C:\Users\aluca\AppData\Local\9980246772
2020-03-21 15:40 - 2023-05-15 20:09 - 000007601 _____ () C:\Users\aluca\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-08-2023
Ran by aluca (04-09-2023 21:49:15)
Running from C:\Users\aluca\Desktop
Microsoft Windows 10 Home Version 22H2 19045.3324 (X64) (2021-03-15 15:21:48)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-3615177999-3261653453-3779512466-500 - Administrator - Disabled)
aluca (S-1-5-21-3615177999-3261653453-3779512466-1001 - Administrator - Enabled) => C:\Users\aluca
DefaultAccount (S-1-5-21-3615177999-3261653453-3779512466-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-3615177999-3261653453-3779512466-1000 - Limited - Disabled) => C:\Users\defaultuser0
Gast (S-1-5-21-3615177999-3261653453-3779512466-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3615177999-3261653453-3779512466-504 - Limited - Disabled)
_ashbackuppb_ (S-1-5-21-3615177999-3261653453-3779512466-1002 - Administrator - Enabled) => C:\Users\_ashbackuppb_
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avira Security (Enabled - Up to date) {C622D33D-B035-6463-E471-9D92B9517CA1}
FW: Avira Security (Enabled) {BE55A40C-05CA-1096-36EB-CCA92DEAF539}
FW: ZoneAlarm Free Firewall Firewall (Disabled) {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
FW: Avira Security (Enabled) {877B141C-E73B-9A54-223E-108CC963426A}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
3DMark (HKLM\...\{1F3F2DD9-EE3C-4803-A287-49C9FFB0E7EB}) (Version: 2.5.5029.0 - UL) Hidden
3DMark (HKLM-x32\...\{21e80113-175b-4eb9-8f9e-49fdc5e68235}) (Version: 2.5.5029.0 - UL)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
Adobe Acrobat Reader (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 23.003.20284 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601047}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Amazon Games (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\{4DD10B06-78A4-4E6F-AA39-25E9C38FA568}) (Version: 2.3.8425.2 - Amazon.com Services, Inc.)
Amazon Kindle (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Amazon Kindle) (Version: 1.17.1.44183 - Amazon)
Anthem™ (HKLM-x32\...\{57b4eaa0-f1f5-407e-afbd-2db397381ad8}) (Version: 1.0.64.28115 - Electronic Arts)
Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{06A333EA-4E9D-4848-865F-FE5A1E12AB30}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Armored Core 6: Fires of Rubicon (HKLM-x32\...\Armored Core 6: Fires of Rubicon_is1) (Version: - )
Ashampoo Backup Pro 15 (HKLM\...\{DF972766-B348-CB30-5EB9-9171F37E9745}_is1) (Version: 15.03 - Ashampoo GmbH & Co. KG)
Assassin Creed Syndicate version 1.5 (HKLM-x32\...\Assassin Creed Syndicate_is1) (Version: 1.5 - KNIGHT)
Assassin's Creed Odyssey (HKLM-x32\...\Uplay Install 5059) (Version: - Ubisoft)
Assassins Creed Origins The Curse of the Pharaohs (HKLM-x32\...\Assassins Creed Origins The Curse of the Pharaohs_is1) (Version: - )
Assessments on Client (HKLM-x32\...\{F8288793-51B6-47EF-2F93-D37767663FC5}) (Version: 10.1.14393.0 - Microsoft) Hidden
Atelier: Dusk Trilogy (HKLM-x32\...\Atelier: Dusk Trilogy_is1) (Version: - )
A-Tuning v3.0.425 (HKLM-x32\...\A-Tuning_is1) (Version: 3.0.425 - ASRock Inc.)
AviSynth 2.6 (HKLM-x32\...\AviSynth) (Version: 2.6.0.6 - GPL Public release.)
AVStoDVD 2.8.6 (HKLM-x32\...\AVStoDVD) (Version: 2.8.6 - MrC)
Baldur's Gate: Enhanced Edition (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\AmazonGames/Baldur's Gate - Enhanced Edition) (Version: - Aspyr)
Bass Audio Decoder (remove only) (HKLM-x32\...\Bass Audio Decoder) (Version: - )
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.8.2.48475 - Electronic Arts)
Battlefield™ 2042 (HKLM-x32\...\{45e281f3-1414-47ea-bb64-4f50d50121f3}) (Version: 1.0.76.5661 - Electronic Arts)
Battlefield™ V (HKLM-x32\...\{e26b382f-e945-4f70-9318-121b683f1d61}) (Version: 1.0.60.9722 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB)
BCUninstaller (HKLM\...\{f4fef76c-1aa9-441c-af7e-d27f58d898d1}_is1) (Version: 5.1.0.0 - Marcin Szeniak)
Beholder 2 (HKLM-x32\...\Beholder 2_is1) (Version: - )
Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Blood and Wine (HKLM-x32\...\1441620909_is1) (Version: 1.32 - GOG.com)
Bloodstained: IGA's Back Pack (HKLM-x32\...\2089941670_is1) (Version: 1.05 - GOG.com)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
calibre (HKLM-x32\...\{25BA606B-AB60-4404-96DB-C839543BD535}) (Version: 3.2.1 - Kovid Goyal)
Call of Duty (HKLM-x32\...\Call of Duty) (Version: - Blizzard Entertainment)
Call of Duty Black Ops 4 (HKLM-x32\...\Call of Duty Black Ops 4) (Version: - Blizzard Entertainment)
Call of Duty Black Ops Cold War (HKLM-x32\...\Call of Duty Black Ops Cold War) (Version: - Blizzard Entertainment)
Call of Duty Modern Warfare (HKLM-x32\...\Call of Duty Modern Warfare) (Version: - Blizzard Entertainment)
Chrome Remote Desktop Host (HKLM-x32\...\{C17C2857-FF33-4EA0-8220-14A17DF82668}) (Version: 116.0.5845.9 - Google LLC)
Cloudpunk (HKLM-x32\...\Cloudpunk_is1) (Version: - )
CodeTwo QR Code Desktop Reader & Generator (HKLM-x32\...\{AF7E31D6-980C-4788-B80C-47F1837CF44C}) (Version: 1.1.2.4 - CodeTwo)
ComicRack v0.9.178 (HKLM\...\ComicRack) (Version: v0.9.178 - cYo Soft)
Core Temp 1.17.1 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.17.1 - ALCPU)
CPUID CPU-Z 2.03 (HKLM\...\CPUID CPU-Z_is1) (Version: 2.03 - CPUID, Inc.)
Crying Suns (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Humble App cryingsuns_windows) (Version: - )
Cuphead (HKLM-x32\...\1963513391_is1) (Version: hotfix_1.1.4 - GOG.com)
Cyberpunk 2077 (HKLM-x32\...\1423049311_is1) (Version: 1_61 - GOG.com)
Cyberpunk 2077 REDmod (HKLM-x32\...\1597316373_is1) (Version: 1_61 - GOG.com)
Dashboard (HKLM-x32\...\Western Digital SSD Dashboard) (Version: 3.2.2.9 - Western Digital Corporation)
DCoder Image Source (remove only) (HKLM-x32\...\DCoder Image Source) (Version: - )
Dead Island 2 (HKLM-x32\...\Dead Island 2_is1) (Version: 0.0.0 - DODI-Repacks)
Deadpool (HKLM-x32\...\Deadpool_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter)
Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform)
Devil May Cry 4 Special Edition (HKLM-x32\...\Devil May Cry 4 Special Edition_is1) (Version: - )
Die Siedler 7 (HKLM-x32\...\{63860309-DA8A-4BAE-9EAE-CE1D6D79340C}) (Version: 1.12.1396 - Ubisoft)
DirectVobSub (remove only) (HKLM-x32\...\DirectVobSub) (Version: - )
Disco Elysium (HKLM-x32\...\1771589310_is1) (Version: bbe2afa0 - GOG.com)
Discord (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Discord) (Version: 0.0.308 - Discord Inc.)
Disneyland Adventures (HKLM-x32\...\Disneyland Adventures_is1) (Version: - )
Divinity.Original.Sin.2.v3.0.151.229.REPACK-KaOs Uninstaller v3.0 (HKLM-x32\...\Divinity.Original.Sin.2.v3.0.151.229.REPACK-KaOs_is1) (Version: 3.0 - KaOsKrew)
Dragon Quest Builders 2 (HKLM-x32\...\Dragon Quest Builders 2_is1) (Version: - )
Dying Light (HKLM-x32\...\1448452156_is1) (Version: 1.16.0 - GOG.com)
Dying Light: Gun Psycho Bundle (HKLM-x32\...\1460996021_is1) (Version: 1.16.0 - GOG.com)
Dying Light: Harran Military Rifle (HKLM-x32\...\1182281905_is1) (Version: 1.16.0 - GOG.com)
Dying Light: Harran Ranger Bundle (HKLM-x32\...\1460996196_is1) (Version: 1.16.0 - GOG.com)
Dying Light: Volatile Hunter Bundle (HKLM-x32\...\1460996282_is1) (Version: 1.16.0 - GOG.com)
Dynasty Warriors 8 Xtreme Legends (HKLM-x32\...\Dynasty Warriors 8 Xtreme Legends_is1) (Version: - )
EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.8.0.5521 - Electronic Arts) Hidden
EA app (HKLM-x32\...\{547c1c17-118e-4cb9-bace-9bd738530ffc}) (Version: 13.8.0.5521 - Electronic Arts)
EasyBCD 2.4 (HKLM-x32\...\EasyBCD) (Version: 2.4 - NeoSmart Technologies)
EdgeDeflector (HKLM-x32\...\EdgeDeflector) (Version: - )
ENE_QSI_Loki_HAL (HKLM\...\{BDE43F26-5917-44F8-B86A-F1D9A6B80B32}) (Version: 1.0.3.0 - ENE TECHNOLOGY INC.) Hidden
ENE_QSI_Loki_HAL (HKLM-x32\...\{205ef3a8-937b-43cb-90fc-2f58f71408d8}) (Version: 1.0.3.0 - ENE TECHNOLOGY INC.) Hidden
Epic Games Launcher (HKLM-x32\...\{FE3CD7B8-14D4-46E9-A206-2C8F2C0E6F1F}) (Version: 1.1.139.0 - Epic Games, Inc.)
Epic Online Services (HKLM-x32\...\{A1EB595F-651D-4A04-99B0-A7065538B33C}) (Version: 2.0.38.0 - Epic Games, Inc.)
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
EVERSPACE - Encounters (HKLM-x32\...\1165094689_is1) (Version: 1.3.5.36556 - GOG.com)
EVERSPACE (HKLM-x32\...\1513949567_is1) (Version: 1.3.5.36556 - GOG.com)
Far Cry 3 Blood Dragon (HKLM-x32\...\Uplay Install 205) (Version: - Ubisoft)
Far Cry 5 (HKLM-x32\...\Far Cry 5_is1) (Version: - )
FFMPEG Core Files (remove only) (HKLM-x32\...\FFMPEG Core Files) (Version: - )
FIFA 21 (HKLM-x32\...\{A918ACE7-A83B-41F4-8746-AEF8DC821879}) (Version: 1.0.70.18952 - Electronic Arts)
Final Fantasy XII The Zodiac Age MULTi9 - ElAmigos version 1.0 (HKLM-x32\...\{87E52C4C-549B-4639-AFCB-78D3BC1B457F}_is1) (Version: 1.0 - Square Enix)
FINAL FANTASY XIV ONLINE (HKLM-x32\...\{2B41E132-07DF-4925-A3D3-F2D1765CCDFE}) (Version: 1.0.0000 - SQUARE ENIX CO., LTD.)
Fire Toolbox version (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\{879EB178-B5C2-4785-B5D4-704DBC011B2A}_is1) (Version: - Datastream33)
Folder Size Explorer (HKLM-x32\...\{CD453A88-D560-47A2-9D4D-414134F5A73D}) (Version: 2.0.0 - Bazwise)
Fraps (HKLM-x32\...\Fraps) (Version: - )
Free DLC program (16 DLC) (HKLM-x32\...\1430743168_is1) (Version: 1.32 - GOG.com)
FreeCommander XE (HKLM-x32\...\FreeCommander XE_is1) (Version: - Marek Jasinski)
Futuremark SystemInfo (HKLM-x32\...\{66E02F22-FA88-453D-9DE7-60F54E951FAF}) (Version: 5.10.676.0 - Futuremark)
Genshin Impact (HKLM\...\Genshin Impact) (Version: 2.8.4.0 - miHoYo Co.,Ltd)
Gods Trigger (HKLM-x32\...\Gods Trigger_is1) (Version: - )
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: 2.0.67.2 - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 116.0.5845.141 - Google LLC)
Google Earth Pro (HKLM\...\{F27DBA46-80E1-4858-9285-19198FFFBF3D}) (Version: 7.3.6.9345 - Google)
Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - )
Hearts of Iron IV Field Marshal Edition MULTi7 - ElAmigos version 1.5.2 (HKLM-x32\...\{9240BFB5-B3DE-4505-8351-5605EE8D4F84}_is1) (Version: 1.5.2 - Paradox Interactive)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
HL-3142CW (HKLM-x32\...\{C6580DE1-F539-4700-ADD2-3185121E51A8}) (Version: 1.0.1.0 - Brother Industries, Ltd.)
Humble App 1.1.8+411 (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\2f793df2-2969-529d-b0c0-7960ed40d70e) (Version: 1.1.8+411 - Humble Bundle)
HWiNFO64 Version 7.36 (HKLM\...\HWiNFO64_is1) (Version: 7.36 - Martin Malik - REALiX)
Imaging And Configuration Designer (HKLM-x32\...\{05935793-A34C-4272-3361-7AF9AEEE5649}) (Version: 10.1.14393.0 - Microsoft) Hidden
Imaging Designer (HKLM-x32\...\{FB54F620-9555-3A11-26CB-B027C4DDF260}) (Version: 10.1.14393.0 - Microsoft) Hidden
Imaging Tools Support (HKLM-x32\...\{C30A729A-E9BA-37F8-3C58-64AD9F1D4694}) (Version: 10.1.14393.0 - Microsoft) Hidden
Immortals Fenyx Rising (HKLM-x32\...\Uplay Install 5405) (Version: - Ubisoft)
Intel(R) Chipset Device Software (HKLM\...\{06D713D6-9845-436D-B857-5BF2596B4554}) (Version: 10.1.18634.8254 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{99926fb7-5da9-4101-b79f-eec3674ca64b}) (Version: 10.1.18634.8254 - Intel(R) Corporation)
Into the Breach (HKLM-x32\...\2004253604_is1) (Version: 1.0.20 - GOG.com)
iTunes (HKLM\...\{8A99C2B8-2B40-46B2-B900-621DC8E177CF}) (Version: 12.2.1.16 - Apple Inc.)
JA2 Stracciatella (HKLM-x32\...\JA2 Stracciatella) (Version: 0.19.1-git+6ad1b6f - Humanity)
Jagged Alliance 2 (HKLM-x32\...\1207658696_is1) (Version: 1.12 - GOG.com)
James Bond 007 Blood Stone MULTi8 - ElAmigos version 76654 (HKLM-x32\...\{54D77124-93E2-4D58-8E20-C1CFA218927A}_is1) (Version: 76654 - Activision Blizzard)
Java 8 Update 181 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
John Wick Hex (HKLM-x32\...\John Wick Hex_is1) (Version: - )
Kingdom Come Deliverance - Royal Ed. (HKLM\...\Kingdom Come Deliverance - Royal Ed.) (Version: - )
Kits Configuration Installer (HKLM-x32\...\{C661B45B-1D2A-AF7C-27D0-B4FFD670A4FE}) (Version: 10.1.14393.0 - Microsoft) Hidden
K-Lite Codec Pack 14.1.0 Standard (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.1.0 - KLCP)
Knockout City (HKLM-x32\...\{C75F8E76-29EF-44D0-9762-4F6D65BF0111}) (Version: 1.1.0.0 - Electronic Arts, Inc.)
LatencyMon 7.00 (HKLM\...\LatencyMon_is1) (Version: - Resplendence Software Projects Sp.)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LAV Filters 0.74.1 (HKLM-x32\...\lavfilters_is1) (Version: 0.74.1 - Hendrik Leppkes)
Layers of Fear - Inheritance (HKLM-x32\...\1256894029_is1) (Version: 2.2.0.5 - GOG.com)
Layers of Fear (HKLM-x32\...\1455107123_is1) (Version: 2.3.0.7 - GOG.com)
Letasoft Sound Booster 1.11.0.514 (HKLM-x32\...\{6C6CF38B-11DD-45C6-A15E-A3A0C4CE60F8}_is1) (Version: 1.11.0.514 - Letasoft LLC)
Macrium Reflect Free Edition (HKLM\...\{3323C7F6-9CAD-4203-A264-79B834D82C53}) (Version: 7.3.5854 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 7.3 - Paramount Software (UK) Ltd.)
MadVR (remove only) (HKLM-x32\...\MadVR) (Version: - )
Malwarebytes version 4.6.0.277 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.0.277 - Malwarebytes)
Marvels Avengers (HKLM-x32\...\Marvels Avengers_is1) (Version: 0.0.0 - DODI-Repacks)
Media Preview (HKLM\...\{52AFC3E1-0FAA-4C05-88FF-373911EA68F5}) (Version: 1.4.3.429 - BabelSoft)
MediathekView 13.9.1 (HKLM\...\1927-5045-2127-3394) (Version: 13.9.1 - MediathekView Team)
MEmu (HKLM-x32\...\MEmu) (Version: 6.2.7.0 - Microvirt)
Microsoft .NET Host - 6.0.21 (x64) (HKLM\...\{26FF35F7-ADBB-4C9F-97DA-79120DB80EC6}) (Version: 48.87.64667 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.21 (x64) (HKLM\...\{D937EF87-F11D-4778-973C-B71E178F95D0}) (Version: 48.87.64667 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.21 (x64) (HKLM\...\{8D2EC92E-5903-4B25-9406-182B8EFA834F}) (Version: 48.87.64667 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 116.0.1938.69 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 116.0.1938.69 - Microsoft Corporation)
Microsoft GameInput (HKLM-x32\...\{1F2B6AF3-C260-8666-5950-E3FEDBC851D6}) (Version: 10.1.22621.3036 - Microsoft Corporation)
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (HKLM-x32\...\{90140000-0015-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (HKLM-x32\...\{90140000-0016-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (HKLM\...\{90140000-002A-0000-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (HKLM-x32\...\{90140000-00A1-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (HKLM-x32\...\{90140000-001F-0410-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (HKLM-x32\...\{90140000-002C-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (HKLM-x32\...\{90140000-0019-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (HKLM\...\{90140000-002A-0407-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (HKLM-x32\...\{90140000-006E-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (HKLM-x32\...\{90140000-001B-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\OneDriveSetup.exe) (Version: 23.169.0813.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{BB052C53-34CB-42DE-AF41-66FDFCEEC868}) (Version: 3.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{577ff5ba-39aa-4d8c-a3a9-f95012763438}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660 (HKLM-x32\...\{7DAD0258-515C-3DD4-8964-BD714199E0F7}) (Version: 12.0.40660 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660 (HKLM-x32\...\{E30D8B21-D82D-3211-82CC-0F0A5D1495E8}) (Version: 12.0.40660 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 (HKLM-x32\...\{8bdfe669-9705-4184-9368-db9ce581e0e7}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.22.27821 (HKLM-x32\...\{3BDE80F7-7EC9-448E-8160-4ADA0CDA8879}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29334 (HKLM-x32\...\{14C49FC8-3E9B-4F29-8526-26629B5CF30B}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.22.27821 (HKLM-x32\...\{1E6FC929-567E-4D22-9206-C5B83F0A21B9}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29334 (HKLM-x32\...\{0D01A812-82A1-481F-8546-8E28E976F8DF}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532 (HKLM\...\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532 (HKLM\...\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}) (Version: 10.0.50908 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 2.11.63.5026 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 6.0.21 (x64) (HKLM\...\{AF6BF7DD-2B12-40C5-919C-2EC99054BBE1}) (Version: 48.87.64723 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.21 (x64) (HKLM-x32\...\{0f39db03-9030-48f3-82ef-5384bed81d85}) (Version: 6.0.21.32717 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
MiniTool Partition Wizard Free 12.6 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: 12.6 - MiniTool Software Limited)
MiniTool ShadowMaker PW Edition (HKLM-x32\...\MT-75D7C412-925B-4AD0-90DC-5E4FEE22EAE1_is1) (Version: 3.6 - MiniTool Software Limited)
Mirror's Edge™ Catalyst (HKLM-x32\...\{12228a0d-f6ad-4691-82af-d2c643424468}) (Version: 1.0.3.47248 - Electronic Arts)
Monster Hunter World: Iceborne (HKLM-x32\...\Monster Hunter World: Iceborne_is1) (Version: - )
Mozilla Firefox 72.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 72.0.2 (x64 en-US)) (Version: 72.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 57.0.2 - Mozilla)
MSI Afterburner 4.5.0 (HKLM-x32\...\Afterburner) (Version: 4.5.0 - MSI Co., LTD)
Mutant Year Zero - Road To Eden (HKLM-x32\...\{4DF4741F-8465-4AA8-9ABA-4B081F05FCAA}_is1) (Version: - The Bearded Ladies)
Need for Speed™ Heat (HKLM-x32\...\{8DA46384-7F54-4265-B90F-69BBC08DC3A1}) (Version: 1.0.60.7040 - Electronic Arts)
No Mans Sky (HKLM\...\No Mans Sky_is1) (Version: 3.05 - SE7EN Solutions)
NordUpdater (HKLM\...\{6E35DB82-3D19-4DD6-B8CB-F082815FDE18}_is1) (Version: 1.4.0.132 - Nord Security)
NordVPN (HKLM\...\{19465C24-3D5D-4327-B99F-3CC0A1D38151}_is1) (Version: 6.48.19.0 - Nord Security)
NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN)
Nox APP Player (HKLM-x32\...\Nox) (Version: 6.3.0.7 - Duodian Technology Co. Ltd.)
Npcap (HKLM-x32\...\NpcapInst) (Version: 1.71 - Nmap Project)
NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.27.0.112 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.27.0.112 - NVIDIA Corporation)
NVIDIA Graphics Driver 537.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 537.13 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.40.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.40.14 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
Observer (HKLM-x32\...\1449856523_is1) (Version: 1.0 - GOG.com)
One Piece Pirate Warriors 3: GOLD Edition (HKLM-x32\...\One Piece Pirate Warriors 3: GOLD Edition_is1) (Version: - )
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Ori and The Blind Forest - Definitive Edition (HKLM-x32\...\1384944984_is1) (Version: 2.0.0.2 - GOG.com)
Origin (HKLM-x32\...\Origin) (Version: 10.5.112.50486 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{af79dd32-90cb-4e63-ae56-a4d22f33921d}) (Version: latest - ppy Pty Ltd)
Overlay (HKLM-x32\...\1430742867_is1) (Version: 1.32 - GOG.com)
Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)
Owlboy (HKLM-x32\...\1159880091_is1) (Version: 1.3.6570.26602 - GOG.com)
Paradox Launcher v2 (HKLM\...\{A92DB5D9-A24D-4678-9F91-B4FA6D895718}) (Version: 2.0.4.0 - Paradox Interactive)
Photo Pos Pro 3 (HKLM\...\Photo Pos Pro 3) (Version: 3.30 - PowerOfSoftware Ltd.)
PlayStation Plus (HKLM-x32\...\{F86E19EB-C781-4A23-B764-6B397BC18BA1}) (Version: 12.2.0 - Sony Interactive Entertainment Inc.)
PowerToys (Preview) (HKLM\...\{06F18418-D1F4-4C41-A45A-DA86079A9823}) (Version: 0.64.0 - Microsoft Corporation) Hidden
PowerToys (Preview) x64 (HKLM-x32\...\{5aed9284-1ef0-4dbe-86f4-64b4731b508c}) (Version: 0.64.0 - Microsoft Corporation)
Private Internet Access v81 (HKLM-x32\...\{148169C2-5558-4C3E-B38A-7B1813A264CA}_is1) (Version: 81 - London Trust Media, Inc.)
Project Highrise MULTi6 - ElAmigos version 1.5.9.2 (HKLM-x32\...\{383D8816-459E-43F5-B788-98C32D3B99F4}_is1) (Version: 1.5.9.2 - Kasedo Games)
Project Hospital (HKLM-x32\...\1660194629_is1) (Version: 1.0.14224 RC4 - GOG.com)
PS Remote Play (HKLM-x32\...\{3A3A09F0-36EC-4CDD-BAA5-98BC05815E3C}) (Version: 5.5.0.08250 - Sony Interactive Entertainment Inc.)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
QTTabBar ver 2048 (HKLM\...\{13016E80-C7E5-4610-B149-FA8381CEE008}) (Version: 0.9.0 - Quizo)
Quantum Break (HKLM-x32\...\Quantum Break_is1) (Version: - )
Rayman Legends (HKLM-x32\...\Uplay Install 410) (Version: - Ubisoft)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.21.1 - Razer Inc.)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9079.1 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0037 - Realtek)
Rebel Galaxy Outlaw MULTi5 - ElAmigos version 1.17 (HKLM-x32\...\{E69E45AE-023B-4271-99D4-9EB93DA86644}_is1) (Version: 1.17 - Double Damage Games)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Regiments (HKLM-x32\...\Regiments_is1) (Version: - )
Resident Evil 2 (HKLM-x32\...\Resident Evil 2_is1) (Version: - )
RetroArch (HKLM-x32\...\RetroArch) (Version: 1.15.0.0 - Libretro)
ROCCAT SWARM (HKLM-x32\...\{E9CA669A-8FB1-4F3D-A771-2E0767D20F89}) (Version: 1.94.430 - ROCCAT GmbH) Hidden
ROCCAT SWARM (HKLM-x32\...\InstallShield_{E9CA669A-8FB1-4F3D-A771-2E0767D20F89}) (Version: 1.94.430 - ROCCAT GmbH)
ScummVM 2.0.0 (HKLM-x32\...\ScummVM_is1) (Version: 2.0.0 - The ScummVM Team)
Sekiro Shadows Die Twice MULTi13 - ElAmigos version 1.02 (HKLM-x32\...\{93A98F06-2B86-4F97-AAF2-A44AEB1E2C29}_is1) (Version: 1.02 - FromSoftware)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{8925227F-C7B5-4C95-AB58-4FCF2433DAEE}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{09A9DF49-DA06-4093-A2FD-F339211E39EA}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{ECC1D579-DC17-4B90-929C-B4A0BB35F7B3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{97099817-53F1-4CA1-ACEA-DA6D74371689}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{E4D76E88-C65F-4003-9C71-EC4306679D17}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{3B0FF7FF-0E85-4907-A511-3F8C27349FA4}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{996096F8-956B-41C9-A7E3-9BA1E801014F}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{D505EC85-885F-4BE3-8A89-3EFE4F855692}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Shadow Tactics (HKLM-x32\...\Shadow Tactics_is1) (Version: - )
Shantae Half Genie Hero Ultimate Edition (HKLM-x32\...\Shantae Half Genie Hero Ultimate Edition_is1) (Version: - )
Shovel Knight: Treasure Trove (HKLM-x32\...\1207664823_is1) (Version: 4.0A - GOG.com)
Signal 6.28.0 (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\7d96caee-06e6-597c-9f2f-c7bb2e0948b4) (Version: 6.28.0 - Signal Messenger, LLC)
Snake Pass MULTi5 - ElAmigos version 1.4 (HKLM-x32\...\{853FF7F2-9B65-4570-92E7-79386CB935B0}_is1) (Version: 1.4 - Sumo Digital)
SoundWire Server version 2.1.2 (HKLM-x32\...\{E15658BC-7742-4397-999F-98B1BD11B784}_is1) (Version: 2.1.2 - GeorgieLabs)
Star Control: Origins (HKLM-x32\...\1893867643_is1) (Version: 1.00.52584 - GOG.com)
STAR WARS Jedi - Fallen Order™ (HKLM-x32\...\{D00A89F1-2D8C-4589-B1D1-73A6544E3B1F}) (Version: 1.0.10.0 - Electronic Arts, Inc.)
STAR WARS™ Battlefront™ II (HKLM-x32\...\{8a882ce0-0c0b-4eb2-850c-28ebadab4f50}) (Version: 1.1.7.22040 - Electronic Arts)
StarCraft (HKLM-x32\...\StarCraft) (Version: - Blizzard Entertainment)
Stardew Valley - ElAmigos version 1.2.33 (HKLM-x32\...\{B798256B-8466-4DB5-A6A9-6A2C80B40D25}_is1) (Version: 1.2.33 - Chucklefish)
Starsector by Fractal Softworks LLC (HKLM-x32\...\Starsector) (Version: - )
Streets of Rage 4 (HKLM\...\Streets of Rage 4_is1) (Version: Build 10731343 - )
Summer in Mara (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Summer in Mara) (Version: - HOODLUM)
Sundered Eldritch Edition (HKLM-x32\...\Sundered Eldritch Edition_is1) (Version: - )
Sunset Overdrive (HKLM-x32\...\Sunset Overdrive_is1) (Version: - )
System Shock: Remake (HKLM-x32\...\System Shock: Remake_is1) (Version: - )
TeamViewer (HKLM\...\TeamViewer) (Version: 15.38.3 - TeamViewer)
TechPowerUp GPU-Z (HKLM-x32\...\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1) (Version: 2.52.0 - TechPowerUp)
TECKNET wireless gaming mouse version 1.0.0.7 (HKLM-x32\...\TECKNET wireless gaming mouse_is1) (Version: - )
The Binding of Isaac Rebirth MULTi3 - ElAmigos version 30.04.2018 (HKLM-x32\...\{16FA778B-E5D3-43A3-80A4-D043BCF67090}_is1) (Version: 30.04.2018 - Nicalis, Inc.)
The Crew 2 (HKLM-x32\...\Uplay Install 2855) (Version: - Ubisoft)
The Hong Kong Massacre (HKLM-x32\...\The Hong Kong Massacre_is1) (Version: - )
The Legend of Zelda: BotW (HKLM-x32\...\The Legend of Zelda: BotW_is1) (Version: - )
The Lord of the Rings Online™ v2305.0061.1867.4359 (HKLM-x32\...\12bbe590-c890-11d9-9669-0800200c9a66_is1) (Version: 2305.0061.1867.4359 - Standing Stone Games, LLC)
The Sims 4 (HKLM-x32\...\The Sims 4_is1) (Version: - )
The Ultimate DOOM (HKLM-x32\...\1435827232_is1) (Version: 2.0.0.3 - GOG.com)
The Witcher 3: Wild Hunt - Blood and Wine (HKLM-x32\...\Blood and Wine_is1) (Version: 1.24.0.0 - GOG.com)
The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.24.0.0 - GOG.com)
The Witcher 3: Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.32 - GOG.com)
Titanfall™ 2 (HKLM-x32\...\{4BD80373-FEE7-45B6-8249-6E8E98717405}) (Version: 1.0.1.3 - Electronic Arts, Inc.)
Tom Clancy Ghost Recon Wildlands (HKLM-x32\...\Tom Clancy Ghost Recon Wildlands_is1) (Version: 1.6.0 - THE KNIGHT)
Toolkit Documentation (HKLM-x32\...\{6143A694-5FE1-BDF6-F78E-4F7BF3E9419B}) (Version: 10.1.14393.0 - Microsoft) Hidden
Total War Three Kingdoms (HKLM-x32\...\Total War Three Kingdoms_is1) (Version: - )
Towerfall - Ascension - Dark World (HKLM-x32\...\1431078929_is1) (Version: 2.4.0.5 - GOG.com)
Towerfall - Ascension (HKLM-x32\...\1430924174_is1) (Version: 2.5.0.6 - GOG.com)
Trails from Zero (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\ED_ZERO) (Version: - )
Trilogy Save Editor version 2.2.1 (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\{6A0B979E-271B-4E50-A4C3-487C8E584070}_is1) (Version: 2.2.1 - Karlitos)
Two Point Hospital (HKLM-x32\...\Two Point Hospital_is1) (Version: - )
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 104.1 - Ubisoft)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
UE4 Prerequisites (x64) (HKLM\...\{36EAD5CF-44EF-4FCF-8BE1-D96C4835D7A4}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden
UE4 Prerequisites (x64) (HKLM-x32\...\{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden
UEV Tools on amd64 (HKLM\...\{1454FA4E-58BC-2EF1-9A19-147B0E499E03}) (Version: 10.1.14393.0 - Microsoft) Hidden
Unravel™ (HKLM-x32\...\{5105E605-9EE7-4050-9CC0-005093BBF89A}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{C270D21B-2327-49B8-85F7-395133A93C75}) (Version: 8.92.0.0 - Microsoft Corporation)
USBPcap 1.5.4.0 (HKLM\...\USBPcap) (Version: 1.5.4.0 - Tomasz Mon)
User State Migration Tool (HKLM-x32\...\{F7AADEDA-233A-1079-CD15-03AEB050F0C6}) (Version: 10.1.14393.0 - Microsoft) Hidden
VdhCoApp 1.2.4 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version: - DownloadHelper)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.16 - VideoLAN)
Vortex (HKLM\...\57979c68-f490-55b8-8fed-8b017a5af2fe) (Version: 1.8.5 - Black Tree Gaming Ltd.)
Warhammer 40000 Mechanicus (HKLM-x32\...\Warhammer 40000 Mechanicus_is1) (Version: - )
Watch Dogs 2 (HKLM-x32\...\Watch Dogs 2_is1) (Version: - )
WhoCrashed 7.00 (HKLM\...\WhoCrashed_is1) (Version: 7.00 - Resplendence Software Projects Sp.)
WhySoSlow 1.61 (HKLM\...\WhySoSlowHome_is1) (Version: - Resplendence Software Projects Sp.)
Windows Assessment and Deployment Kit - Windows 10 (HKLM-x32\...\{39ebb79f-797c-418f-b329-97cfdf92b7ab}) (Version: 10.1.14393.0 - Microsoft Corporation)
Windows Assessment Toolkit (AMD64 Architecture Specific) (HKLM-x32\...\{91361B2A-F741-E591-303B-4EF957F3BAF1}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows Assessment Toolkit (HKLM-x32\...\{F4EBF948-F00E-29EF-894C-D10A718F981D}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows Deployment Customizations (HKLM-x32\...\{9D550F66-5D52-29CA-28B5-EE0C2C0CDFBE}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows Deployment Tools (HKLM-x32\...\{52EA560E-E50F-DC8F-146D-1B631548BA29}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows PC Health Check (HKLM\...\{77ACFAF7-E5AB-410D-BA14-BBEBF89422DE}) (Version: 3.1.2109.29003 - Microsoft Corporation)
Windows PE x86 x64 (HKLM-x32\...\{230524D3-ADB4-69CC-2A78-96D879E3221B}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows PE x86 x64 wims (HKLM-x32\...\{47AEE104-BF96-E407-D3FE-80BBD42732F4}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows Phone Common Packaging and Test Tools (NT_x86_fre) (HKLM-x32\...\{4D989432-59D7-76A0-DD51-B96422F6FF7F}) (Version: 10.1.14393.0 - Microsoft Corporation) Hidden
Windows System Image Manager on amd64 (HKLM-x32\...\{363D76EC-B5B9-5D7B-0F59-C193FF6F03FC}) (Version: 10.1.14393.0 - Microsoft) Hidden
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
Wireshark 4.0.8 64-bit (HKLM-x32\...\Wireshark) (Version: 4.0.8 - The Wireshark developer community, hxxps://www.wireshark.org)
Wolfenstein: The Old Blood (HKLM-x32\...\Wolfenstein: The Old Blood_is1) (Version: - )
WORLD OF FINAL FANTASY MAXIMA (HKLM-x32\...\WORLD OF FINAL FANTASY MAXIMA_is1) (Version: - )
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
WPT Redistributables (HKLM-x32\...\{549DAD2D-2505-204C-EC58-59807FE6E037}) (Version: 10.1.14393.0 - Microsoft) Hidden
WPTx64 (HKLM-x32\...\{97B6FAD9-6F14-CC46-3165-F1785ECCE255}) (Version: 10.1.14393.0 - Microsoft) Hidden
XnViewMP 1.00.0 (HKLM\...\XnViewMP_is1) (Version: 1.00.0 - Gougelet Pierre-e)
ZeroLauncher (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\54166643f5cdc960) (Version: 1.0.1.0 - HP Inc.)
ZeroLauncher (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\d6b1847d788880db) (Version: 1.0.2.411 - Geofront)
ZoneAlarm Firewall (HKLM-x32\...\{F21C5C41-E759-472F-B5AE-501AC583B693}) (Version: 15.0.653.17211 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Free Firewall (HKLM-x32\...\ZoneAlarm Free Firewall) (Version: 15.0.653.17211 - Check Point)
ZoneAlarm Security (HKLM-x32\...\{06F804D0-A69C-423A-8F77-A158EA7DF295}) (Version: 15.0.653.17211 - Check Point Software Technologies Ltd.) Hidden
Zoom (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\ZoomUMX) (Version: 5.9.3 (3169) - Zoom Video Communications, Inc.)
Zoom Player (remove only) (HKLM-x32\...\ZoomPlayer) (Version: - )
Zotero Standalone 4.0.29.17 (x86 en-US) (HKLM-x32\...\Zotero Standalone 4.0.29.17 (x86 en-US)) (Version: 4.0.29.17 - Zotero)
Packages:
=========
Amazon Alexa -> C:\Program Files\WindowsApps\57540AMZNMobileLLC.AmazonAlexa_3.25.1177.0_x64__22t9g3sebte08 [2023-08-03] (AMZN Mobile LLC.) [Startup Task]
art of rally -> C:\Program Files\WindowsApps\Mutable\Funselektor.artofrally_1.0.11.0_x64__43tswnvjm2gzr [2023-01-16] (Funselektor Labs Inc.)
Atomic Heart -> C:\Program Files\WindowsApps\FocusHomeInteractiveSA.579645D26CFD_1.10.1.0_x64__4hny5m903y3g0 [2023-09-02] (Focus Home Interactive SA)
Audiobooks from Audible -> C:\Program Files\WindowsApps\AudibleInc.AudibleforWindowsPhone_10.5.67.0_x64__xns73kv1ymhp2 [2023-02-14] (Audible Inc)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.250.400.0_x64__kgqvnymyfvs32 [2023-08-25] (king.com)
Carrion -> C:\Program Files\WindowsApps\DevolverDigital.CarrionWin10_1.0.14.0_x64__6kzv4j18v0c96 [2021-10-27] (Devolver Digital)
Children of Morta -> C:\Program Files\WindowsApps\11bitstudios.12487E5DA4D9B_1.0.17.2_x64__gwy9gn5q9j1y6 [2021-10-08] (11 bit studios)
Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe [2023-08-10] (Microsoft Corporation)
Crusader Kings III -> C:\Program Files\WindowsApps\ParadoxInteractive.ProjectTitus_1.0.526.0_x64__zfnrdv2de78ny [2023-08-31] (Paradox Interactive)
Death's Door Win10 -> C:\Program Files\WindowsApps\DevolverDigital.DeathsDoorWin10_1.0.6.0_x64__6kzv4j18v0c96 [2022-01-25] (Devolver Digital)
Death's Gambit -> C:\Program Files\WindowsApps\CartoonInteractiveGroupIn.DeathsGambit_1.0.0.0_x64__6c1aaymwt3dwm [2020-02-15] (Cartoon Interactive Group Inc.)
DEMON'S TILT -> C:\Program Files\WindowsApps\FLARBLLC.57668A550983B_1.4.30.0_x64__hvfnz2ebz1aje [2020-10-25] (FLARB LLC)
Dishonored® Definitive Edition (PC) -> C:\Program Files\WindowsApps\BethesdaSoftworks.DishonoredDE-PC_1.10.0.0_x64__3275kfvn8vcwc [2022-11-06] (Bethesda Softworks)
Disney+ -> C:\Program Files\WindowsApps\Disney.37853FC22B2CE_1.57.3.0_x64__6rarf9sa4v8jt [2023-08-10] (Disney)
DJMAX RESPECT V -> C:\Program Files\WindowsApps\Neowiz.DJMAXRESPECTV_1.6872.2507.0_x64__r4z3116tdh636 [2023-06-22] (NEOWIZ)
Doom Eternal - PC -> C:\Program Files\WindowsApps\BethesdaSoftworks.DOOMEternal-PC_1.0.17.0_x64__3275kfvn8vcwc [2022-04-27] (Bethesda Softworks)
DOOM Eternal: Campaign -> C:\Program Files\WindowsApps\BethesdaSoftworks.DOOMEternalCampaignPC_1.0.1.0_x64__3275kfvn8vcwc [2020-12-08] (Bethesda Softworks)
Dropbox Lite -> C:\Program Files\WindowsApps\C27EB4BA.DROPBOX_23.4.20.0_x64__xbfy0k16fey96 [2023-09-02] (Dropbox Inc.)
Eiyuden Chronicle: Rising -> C:\Program Files\WindowsApps\505GAMESS.P.A.EiyudenChronicleRising_1.0.16.0_x64__tefn33qh9azfc [2022-06-21] (505 GAMES S.P.A.)
EVERSPACE™ 2 -> C:\Program Files\WindowsApps\ROCKFISHGames.EVERSPACE2_1.0.35328.0_x64__wm11qtfe9fmzj [2023-08-30] (ROCKFISH Games)
Exo One -> C:\Program Files\WindowsApps\FutureFriendsGames.ExoOne_1.2.1.0_x64__2whsqx9fyfsdj [2022-03-31] (Future Friends Games)
Forza Horizon 3 -> C:\Program Files\WindowsApps\Microsoft.OpusPG_1.0.125.2_x64__8wekyb3d8bbwe [2020-08-18] (Microsoft Studios)
Forza Horizon 4 -> C:\Program Files\WindowsApps\Microsoft.SunriseBaseGame_1.477.714.2_x64__8wekyb3d8bbwe [2023-04-10] (Microsoft Studios)
Forza Horizon 5 -> C:\Program Files\WindowsApps\Microsoft.624F8B84B80_3.607.493.0_x64__8wekyb3d8bbwe [2023-08-15] (Microsoft Studios)
Gears of War 4 -> C:\Program Files\WindowsApps\Microsoft.SpartaUWP_14.4.0.2_x64__8wekyb3d8bbwe [2019-07-11] (Microsoft Studios)
GUILTY GEAR STRIVE -> C:\Program Files\WindowsApps\asw-akiyama.GUILTYGEARSTRIVE_1.0.8.0_x64__krnzms20jbb38 [2023-09-04] (ARC SYSTEM WORKS)
Halo -> C:\Program Files\WindowsApps\Microsoft.Tomp_1.0.4723.0_x64__8wekyb3d8bbwe [2023-02-14] (Microsoft Studios)
Halo Infinite -> C:\Program Files\WindowsApps\Microsoft.254428597CFE2_1.3871.53028.0_x64__8wekyb3d8bbwe [2023-08-10] (Microsoft Studios)
Halo: Spartan Assault -> C:\Program Files\WindowsApps\Microsoft.HaloSpartanAssault_1.5.0.0_x86__8wekyb3d8bbwe [2019-12-29] (Microsoft Studios)
Halo: The Master Chief Collection -> C:\Program Files\WindowsApps\Mutable\Microsoft.Chelan_1.3251.0.0_x64__8wekyb3d8bbwe [2023-07-20] (Microsoft Studios)
Hardspace: Shipbreaker -> C:\Program Files\WindowsApps\FocusHomeInteractiveSA.HardspaceShipbreaker-PCVers_1.0.35.0_x64__4hny5m903y3g0 [2022-11-18] (Focus Home Interactive SA)
Hi-Fi RUSH -> C:\Program Files\WindowsApps\BethesdaSoftworks.Hibiki_1.6.0.0_x64__3275kfvn8vcwc [2023-07-05] (Bethesda Softworks)
Hollow Knight -> C:\Program Files\WindowsApps\TeamCherry.15373CD61C66B_5.80.11835.0_x64__y4jvztpgccj42 [2022-11-09] (Team Cherry)
HOT WHEELS UNLEASHED™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSUNLEASHED-WindowsEdition_1.0.6.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone s.r.l.)
HOT WHEELS™ - AcceleRacers Bassline™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC19_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - AcceleRacers Deora™ II -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC14_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - AcceleRacers Hollowback™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC44_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - AcceleRacers Power Rage™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC29_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Aston Martin DB5 1963 -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC08_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Barbie™ Dream Camper™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC22_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Batman Expansion -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC17_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Beefed Up Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC01_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Bone Shaker™ Unleashed Edition -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC03_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Booster Slam Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC28_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Classic Packard -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC64_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Corvette Stingray Convertible 2014 -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC35_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Cyberpunk Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC47_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Dinopult Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC21_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Gorilla Garage Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC34_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Haunted Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC40_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - He-Man™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC50_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Holiday Season Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC18_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Hot Rod Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC61_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Jumping Towers Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC49_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Looney Tunes Expansion -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC54_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - McLaren 720S -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC65_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - McLaren Senna -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC36_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Monster Trucks Expansion -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC39_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Outer Space Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC26_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Pink Fashion Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC11_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Retro Game Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC55_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Rolling Boulders Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC06_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Shark Jaws Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC42_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Skaters Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC32_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Skeletor™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC58_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Spinning Tire Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC20_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Sportscars Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC00_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Beasts™ Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC02_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Fighter Blanka -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC12_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Fighter Chun-Li -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC30_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Fighter M. Bison -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC05_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Fighter Ryu -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC41_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Fighter Vega -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC33_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Super Dealership Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC63_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Superman™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC07_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Swamp Thing™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC59_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - The Jetsons™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC62_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - The Mystery Machine™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC51_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - TMNT Donatello -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC48_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - TMNT Leonardo -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC15_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - TMNT Michelangelo -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC27_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - TMNT Raphael -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC43_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - TMNT Shredder -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC56_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Tropical Wave Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC04_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Wonder Woman™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC13_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Zero Gravity Checkpoint Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC57_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HP Scan and Capture -> C:\Program Files\WindowsApps\AD2F1837.HPScanandCapture_40.0.245.0_x64__v10z8vjag6ke6 [2023-01-17] (Hewlett-Packard Company)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_148.2.1069.0_x64__v10z8vjag6ke6 [2023-08-08] (HP Inc.)
Insurgency: Sandstorm - Windows -> C:\Program Files\WindowsApps\FocusHomeInteractiveSA.3806953BAE050_1.8.3.0_x64__4hny5m903y3g0 [2023-07-12] (Focus Home Interactive SA)
Kathy Rain -> C:\Program Files\WindowsApps\RawFury.1107399377650_1.0.9.0_x86__9s0pnehqffj7t [2020-09-24] (Raw Fury)
Lonely Mountains: Downhill -> C:\Program Files\WindowsApps\Thunderful.LonelyMontainsDownhill_1.5.2.0_x64__8j53pwgd019sy [2023-03-13] (Thunderful Publishing AB)
Metal: Hellsinger -> C:\Program Files\WindowsApps\FuncomOsloAS.ProjectHammerhead_1.6.8726.0_x64__pkaskhy6cdq4g [2023-06-21] (Funcom Oslo AS)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2021-03-15] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-03-15] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-03-15] (Microsoft Corporation) [MS Ad]
Microsoft Flight Simulator -> C:\Program Files\WindowsApps\Microsoft.FlightSimulator_1.33.8.0_x64__8wekyb3d8bbwe [2023-06-22] (Microsoft Studios)
Microsoft Flight Simulator Digital Ownership -> C:\Program Files\WindowsApps\Microsoft.DigitalOwnership_1.0.1.0_x64__8wekyb3d8bbwe [2021-06-01] (Microsoft Studios)
Microsoft Jigsaw -> C:\Program Files\WindowsApps\Microsoft.MicrosoftJigsaw_2.6.8211.0_x86__8wekyb3d8bbwe [2023-08-28] (Microsoft Studios)
Microsoft Minesweeper -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMinesweeper_4.4.7101.0_x64__8wekyb3d8bbwe [2023-07-26] (Microsoft Studios) [MS Ad]
Microsoft Sudoku -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSudoku_2.8.10203.0_x64__8wekyb3d8bbwe [2023-02-14] (Microsoft Studios) [MS Ad]
Microsoft Ultimate Word Games -> C:\Program Files\WindowsApps\Microsoft.Studios.Wordament_3.8.904.0_x64__8wekyb3d8bbwe [2023-02-14] (Microsoft Studios) [MS Ad]
Midnight Fight Express -> C:\Program Files\WindowsApps\HumbleBundle.MidnightFightExpress_1.1.1.0_x64__q2mcdwmzx4qja [2022-11-04] (Humble Bundle)
Mighty Goose -> C:\Program Files\WindowsApps\ActiveGamingMediaInc.MightyGoose_1.0.4.0_x64__4tj796bhrrsp0 [2021-10-02] (Active Gaming Media Inc.)
Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.20.1501.0_x64__8wekyb3d8bbwe [2023-08-17] (Microsoft Studios)
Mystery Manor: Hidden Objects -> C:\Program Files\WindowsApps\0EB8BD08.MysteryManorhiddenobjects_6.220.0.0_x86__erk4rrwmt7jyt [2023-08-30] (GAME INSIGHT UAB)
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-02-18] (Netflix, Inc.)
Night Call -> C:\Program Files\WindowsApps\RawFury.NightCallWIN10_1.3.6.0_x64__9s0pnehqffj7t [2021-08-26] (Raw Fury)
NORCO -> C:\Program Files\WindowsApps\RawFury.NORCO_1.4.7.0_x64__9s0pnehqffj7t [2023-02-23] (Raw Fury)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.964.0_x64__56jybvy8sckqj [2023-09-03] (NVIDIA Corp.)
ORF-TVthek -> C:\Program Files\WindowsApps\ORFsterreichischerRundfun.ORF-TVthek_3.5.0.0_x64__dzzx7e9x33sct [2023-02-14] (Österreichischer Rundfunk ORF)
PAC-MAN MUSEUM+ -> C:\Program Files\WindowsApps\NAMCOBANDAIGamesInc.PACMANMUSEUMPLUS_1.0.5.0_x64__gdy2aq6ez762w [2022-12-07] (BANDAI NAMCO Entertainment Inc.)
Penbook -> C:\Program Files\WindowsApps\36376UserCamp.Penbook_2.1.30.0_x64__t7afzrbtd67z0 [2023-02-14] (User Camp)
Pentiment -> C:\Program Files\WindowsApps\Microsoft.OE-Missouri_1.2.1713.0_x64__8wekyb3d8bbwe [2023-05-31] (Microsoft Studios)
Persona 5 Royal -> C:\Program Files\WindowsApps\SEGAofAmericaInc.F0cb6b3aer_1.10.27.0_x64_USEU_s751p9cej88mt [2023-01-12] (SEGA of America, Inc.)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation)
Prime Video for Windows -> C:\Program Files\WindowsApps\AmazonVideo.PrimeVideo_1.0.148.0_x64__pwbj9vvecjh7j [2023-09-03] (Amazon Development Centre (London) Ltd)
Project Wingman -> C:\Program Files\WindowsApps\HumbleBundle.ProjectWingman_0.6.12.0_x64__q2mcdwmzx4qja [2022-09-15] (Humble Bundle)
QUAKE -> C:\Program Files\WindowsApps\BethesdaSoftworks.ProjectSilver_1.0.5237.0_x64__3275kfvn8vcwc [2022-09-29] (Bethesda Softworks)
Quake 3 -> C:\Program Files\WindowsApps\Mutable\BethesdaSoftworks.Quake3_1.0.0.0_x86__3275kfvn8vcwc [2021-08-23] (Bethesda Softworks)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.20.238.0_x64__dt26b99r8h8gj [2023-08-28] (Realtek Semiconductor Corp)
River City Girls -> C:\Program Files\WindowsApps\6151WayForward.RiverCityGirlsPC_1.0.8.2_x64__38xd6w9je1dae [2023-02-14] (WayForward)
Royal Revolt 2 -> C:\Program Files\WindowsApps\flaregamesGmbH.RoyalRevolt2_9.2.2.0_x86__g0q0z3kw54rap [2023-08-10] (flaregames GmbH)
Ryza Roads -> C:\Program Files\WindowsApps\553FelipeFidelis.RyzaRoads_1.1.84.0_x64__4ganz59kg4aby [2023-02-14] (Felipe Godoy)
Serious Sam 4 -> C:\Program Files\WindowsApps\DevolverDigital.SeriousSam4Win10_1.0.8.0_x64__6kzv4j18v0c96 [2023-02-12] (Devolver Digital)
Solasta -> C:\Program Files\WindowsApps\TacticalAdventures.SolastaCOTM_1.5.94.0_x64__q0c2rn28zyrv4 [2023-07-18] (Tactical Adventures)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.17.8180.0_x64__8wekyb3d8bbwe [2023-09-03] (Microsoft Studios) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0 [2023-08-31] (Spotify AB) [Startup Task]
Teenage Mutant Ninja Turtles: Shredder's Revenge -> C:\Program Files\WindowsApps\DotEmu.TeenageMutantNinjaTurtlesShreddersRevenge_1.2307.27.0_x64__map6zyh9ym1xy [2023-09-02] (DotEmu)
Tetris® Effect: Connected -> C:\Program Files\WindowsApps\48710EnhanceIncorporated.TRIP2.0_2.0.20.0_x64__63vy8jfbpt4dt [2023-05-31] (Enhance Incorporated)
The Legend of Tianding -> C:\Program Files\WindowsApps\AnotherIndie.TheLegendofTianding_1.1.11.0_x64__zrgg4v79ydekg [2023-04-05] (Another Indie)
The Master Chief Collection: Halo 3 -> C:\Program Files\WindowsApps\Microsoft.MCCHalo3_1.12.0.0_x64__8wekyb3d8bbwe [2020-07-27] (Microsoft Studios)
The Master Chief Collection: Halo CE -> C:\Program Files\WindowsApps\Microsoft.HaloCombatEvolved_1.1367.0.0_x64__8wekyb3d8bbwe [2020-03-03] (Microsoft Studios)
The Master Chief Collection: REACH -> C:\Program Files\WindowsApps\Microsoft.TheMasterChiefCollectionREACH_1.1.0.0_x64__8wekyb3d8bbwe [2019-12-04] (Microsoft Studios)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2021-06-14] (Twitter Inc.)
Windjammers 2 -> C:\Program Files\WindowsApps\DotEmu.Windjammers2_22.3.24.0_x64__map6zyh9ym1xy [2022-03-29] (DotEmu)
Wolfenstein: The Old Blood (PC) -> C:\Program Files\WindowsApps\BethesdaSoftworks.WolfensteinTOB-PC_1.19.2.0_x64__3275kfvn8vcwc [2022-05-14] (Bethesda Softworks)
WWE Network -> C:\Program Files\WindowsApps\6FA0E4A0.WWENetwork_4.42.43.0_x64__46xvzjh8v0pjy [2020-05-13] (World Wrestling Entertainment Inc.)
Xbox Accessories -> C:\Program Files\WindowsApps\Microsoft.XboxDevices_2209.2209.14005.0_x64__8wekyb3d8bbwe [2022-09-26] (Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{36B27788-A8BB-4698-A756-DF9F11F64F84}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.SvgThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{3f5d0051-61b8-0f45-6166-996cfb4f914f}\localserver32 -> C:\Program Files\PowerToys\modules\launcher\PowerToys.PowerLauncher.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{45769bcc-e8fd-42d0-947e-02beef77a1f5}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.MarkdownPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{8BC8AFC2-4E7C-4695-818E-8C1FFDCEA2AF}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.StlThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{afbd5a44-2520-4ae0-9224-6cfce8fe4400}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.MonacoPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{BFEE99B4-B74D-4348-BCA5-E757029647FF}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.GcodeThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{ddee2b8a-6807-48a6-bb20-2338174ff779}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.SvgPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{ec52dea8-7c9f-4130-a77b-1737d0418507}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.GcodePreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
ShellExecuteHooks: QTTabBarLib.ExplorerProcessCaptor - {D2BF470E-ED1C-487F-AAAA-2BD8835EB6CE} - C:\Windows\System32\mscoree.dll [383488 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
ShellExecuteHooks-x32: QTTabBarLib.ExplorerProcessCaptor - {D2BF470E-ED1C-487F-AAAA-2BD8835EB6CE} - C:\Windows\SysWOW64\mscoree.dll [314880 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
ContextMenuHandlers1-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2019-09-20] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [ContextMenu] -> {ee10d625-cc60-30a4-b3df-4b349785be6b} => C:\Program Files (x86)\Avira\Security\Antivirus.ContextMenu\Antivirus.ContextMenu.DLL -> No File
ContextMenuHandlers2: [FileLocksmithExt] -> {84D68575-E186-46AD-B0CB-BAEB45EE29C0} => C:\Program Files\PowerToys\modules\FileLocksmith\PowerToys.FileLocksmithExt.dll [2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2019-09-20] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ContextMenuHandlers3: [ContextMenu] -> {ee10d625-cc60-30a4-b3df-4b349785be6b} => C:\Program Files (x86)\Avira\Security\Antivirus.ContextMenu\Antivirus.ContextMenu.DLL -> No File
ContextMenuHandlers3: [FileLocksmithExt] -> {84D68575-E186-46AD-B0CB-BAEB45EE29C0} => C:\Program Files\PowerToys\modules\FileLocksmith\PowerToys.FileLocksmithExt.dll [2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-03-03] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers3: [PowerRenameExt] -> {0440049F-D1DC-4E46-B27B-98393D79486B} => C:\Program Files\PowerToys\modules\PowerRename\PowerToys.PowerRenameExt.dll [2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers4: [ZPShellExt] -> {ABE00001-0123-ABED-1248-0248ADFA1909} => C:\Program Files (x86)\Zoom Player\zpshlext64.dll [2008-08-05] () [File not signed]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\nvshext.dll [2023-08-16] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-03-03] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\system32\frapsv64.dll [105984 2015-09-05] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\SysWOW64\ff_vfw.dll [112640 2014-02-09] () [File not signed]
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [94208 2015-09-05] (Beepa P/L) [File not signed]
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\aluca\Desktop\TikTok.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=nlalbmkafgmoifbeooblidblkmlhhpnc
ShortcutWithArgument: C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\TikTok.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=nlalbmkafgmoifbeooblidblkmlhhpnc
ShortcutWithArgument: C:\Users\aluca\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\ca79330482c36bc6\Checker Plus for Google Calendar™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hkhggnncdpfibdhinjiegagmopldibha
==================== Loaded Modules (Whitelisted) =============
2023-08-14 13:47 - 2023-08-09 01:46 - 004684288 _____ () [File not signed] \\?\C:\Users\aluca\AppData\Local\Programs\signal-desktop\resources\app.asar.unpacked\node_modules\@signalapp\better-sqlite3\build\Release\better_sqlite3.node
2023-08-14 13:47 - 2023-08-09 01:46 - 004961792 _____ () [File not signed] \\?\C:\Users\aluca\AppData\Local\Programs\signal-desktop\resources\app.asar.unpacked\node_modules\@signalapp\libsignal-client\prebuilds\win32-x64\node.napi.node
2023-08-14 13:47 - 2023-08-09 01:46 - 011730432 _____ () [File not signed] \\?\C:\Users\aluca\AppData\Local\Programs\signal-desktop\resources\app.asar.unpacked\node_modules\@signalapp\ringrtc\build\win32\libringrtc-x64.node
2017-05-13 17:14 - 2021-05-30 09:10 - 000027648 _____ () [File not signed] C:\Program Files (x86)\ASUS\AXSP\1.01.02\PEbiosinterface32.dll
2015-12-29 06:25 - 2015-12-29 00:25 - 000120334 _____ () [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\libgcc_s_dw2-1.dll
2015-12-29 06:25 - 2015-12-29 00:25 - 001540622 _____ () [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\libstdc++-6.dll
2022-08-30 19:45 - 2022-08-30 13:45 - 007523840 _____ () [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\resource.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000064512 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\ashinetutil.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000225792 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\jsoncpp.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000056320 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\lzma.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000111616 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\minizip.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000226816 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\party.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000678912 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\sqlite.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 001082368 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\webdave.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000082944 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\zdll.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000074240 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\ziputil.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000025088 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\zlibutil.dll
2015-12-29 06:25 - 2015-12-29 00:25 - 000079360 _____ (MingW-W64 Project. All rights reserved.) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\libwinpthread-1.dll
2023-08-30 17:34 - 2023-08-30 17:34 - 000143360 _____ (Quizo) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\QTPluginLib\530088c70427c7078963947151f0ff77\QTPluginLib.ni.dll
2023-08-30 17:34 - 2023-08-30 17:34 - 012233216 _____ (Quizo) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\QTTabBar\9aef4ed469f2184cd163dbd1b21a17be\QTTabBar.ni.dll
2021-04-08 12:59 - 2018-06-27 09:58 - 002135040 _____ (The curl library, hxxps://curl.haxx.se/) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\ash_libcurl.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000431616 _____ (The curl library, hxxps://curl.haxx.se/) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\libcurl.dll
2015-12-29 06:52 - 2015-12-29 00:52 - 002177536 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\LIBEAY32.dll
2015-12-29 06:52 - 2015-12-29 00:52 - 000462336 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\ssleay32.dll
2015-01-08 21:56 - 2020-12-15 12:04 - 001282048 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] D:\Origin\LIBEAY32.dll
2019-03-08 18:34 - 2020-12-15 12:04 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] D:\Origin\ssleay32.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 003423744 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\libcrypto-1_1-x64.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000684032 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\libssl-1_1-x64.dll
2016-06-11 02:15 - 2016-06-10 20:15 - 000058880 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qdds.dll
2016-06-10 15:32 - 2016-06-10 09:32 - 000033792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qgif.dll
2016-06-11 02:15 - 2016-06-10 20:15 - 000046592 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qicns.dll
2016-06-10 15:33 - 2016-06-10 09:33 - 000036352 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qico.dll
2016-06-10 15:32 - 2016-06-10 09:32 - 000258560 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qjpeg.dll
2016-06-11 01:51 - 2016-06-10 19:51 - 000028672 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qsvg.dll
2016-06-11 02:15 - 2016-06-10 20:15 - 000028672 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qtga.dll
2016-06-11 02:15 - 2016-06-10 20:15 - 000495616 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qtiff.dll
2016-06-11 02:15 - 2016-06-10 20:15 - 000027648 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qwbmp.dll
2016-06-11 02:16 - 2016-06-10 20:16 - 000416768 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qwebp.dll
2016-06-13 03:38 - 2016-06-12 21:38 - 000317440 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\mediaservice\dsengine.dll
2016-06-10 15:34 - 2016-06-10 09:34 - 001489920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\platforms\qwindows.dll
2020-01-13 09:29 - 2020-01-13 03:29 - 005384704 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Core.dll
2016-06-10 15:23 - 2016-06-10 09:23 - 005283840 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Gui.dll
2016-06-13 03:29 - 2016-06-12 21:29 - 000853504 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Multimedia.dll
2016-06-10 15:17 - 2016-06-10 09:17 - 001610240 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Network.dll
2016-06-11 01:51 - 2016-06-10 19:51 - 000348160 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Svg.dll
2016-06-13 03:27 - 2016-06-12 21:27 - 000188416 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5WebSockets.dll
2016-06-10 15:29 - 2016-06-10 09:29 - 006358528 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Widgets.dll
2022-06-15 11:48 - 2017-09-14 14:40 - 000884736 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\MiniTool ShadowMaker\sqldrivers\qsqlite.dll
2018-11-24 15:38 - 2020-12-15 12:04 - 001611264 _____ (The Qt Company Ltd) [File not signed] D:\Origin\platforms\qwindows.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 005487104 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5Core.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 005841920 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5Gui.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 001179136 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5Network.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 000146432 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5WebSockets.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 005089792 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5Widgets.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 000184832 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5Xml.dll
2022-08-15 17:23 - 2022-08-15 11:23 - 000110207 _____ (Un4seen Developments) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\BASS.dll
2022-08-15 17:23 - 2022-08-15 11:23 - 000012166 _____ (Un4seen Developments) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\BASSWASAPI.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000151552 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxbase310u_net_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 002172416 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxbase310u_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000165888 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxbase310u_xml_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 001376768 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxmsw310u_adv_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 004942336 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxmsw310u_core_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000642048 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxmsw310u_html_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000764416 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxmsw310u_xrc_vc_ox.dll
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\aluca\Anwendungsdaten:c7637b1ddf4ebe3cea300c7598738ba3 [394]
AlternateDataStreams: C:\Users\aluca\AppData\Roaming:c7637b1ddf4ebe3cea300c7598738ba3 [394]
AlternateDataStreams: C:\Users\Public\AppData:CSM [452]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [7586]
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Software\Classes\regfile: <==== ATTENTION
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Software\Classes\.reg: => <==== ATTENTION
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Software\Classes\.bat: => <==== ATTENTION
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Software\Classes\.cmd: => <==== ATTENTION
==================== Internet Explorer (Whitelisted) ==========
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_181\bin\ssv.dll [2018-10-12] (Oracle America, Inc. -> Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-10-12] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM - QT Command Bar - {d2bf470e-ed1c-487f-a666-2bd8835eb6ce} - C:\Windows\system32\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM - QT Command Bar 2 - {d2bf470e-ed1c-487f-a777-2bd8835eb6ce} - C:\Windows\system32\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM - QTTabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - C:\Windows\system32\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM - QT Base Toolbar - {d2bf470e-ed1c-487f-a300-2bd8835eb6ce} - C:\Windows\system32\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM-x32 - QT Command Bar - {d2bf470e-ed1c-487f-a666-2bd8835eb6ce} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM-x32 - QT Command Bar 2 - {d2bf470e-ed1c-487f-a777-2bd8835eb6ce} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM-x32 - QTTabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM-x32 - QT Base Toolbar - {d2bf470e-ed1c-487f-a300-2bd8835eb6ce} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2016-07-16 13:47 - 2018-07-21 12:58 - 000000872 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Calibre2\;C:\WINDOWS\System32\OpenSSH\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\dotnet\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\
HKU\S-1-5-21-3615177999-3261653453-3779512466-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\aluca\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\love_you_message_in_a_bottle-wallpaper-3840x2160.jpg
HKU\S-1-5-21-3615177999-3261653453-3779512466-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1)
Windows Firewall is disabled.
Network Binding:
=============
Ethernet 5: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)
Ethernet 5: NordVPN LightWeight Firewall -> NordLwf (enabled)
Ethernet 4: NordVPN LightWeight Firewall -> NordLwf (enabled)
Ethernet 4: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)
Ethernet 3: NordVPN LightWeight Firewall -> NordLwf (enabled)
Ethernet 3: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)
Bluetooth-Netzwerkverbindung 8: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run: => "Ashampoo Backup PB"
HKLM\...\StartupApproved\Run: => "MTPW"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\StartupApproved\StartupFolder: => "Razer Synapse.lnk"
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_DC6ADF56C95D4F38FCEEDC413012C68B"
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\StartupApproved\Run: => "Humble Bundle"
as described in this thread over in the Windows 10 forum, I have a problem where Windows 10 all but goes into cardiac arrest every time I try to download after the system has been running for a couple of hours. So after trying a few solutions with no success, the mod helping me asked me to turn to you guys to see if the problem might be malware-related.
Here's the data from the FRST logs:
FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-08-2023
Ran by aluca (administrator) on DESKTOP-4F0VDIR (04-09-2023 21:47:22)
Running from C:\Users\aluca\Desktop\FRST64.exe
Loaded Profiles: aluca & _ashbackuppb_
Platform: Microsoft Windows 10 Home Version 22H2 19045.3324 (X64) Language: German (Germany) -> English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\backupService-abpb.exe ->) () [File not signed] C:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\oxHelper.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\AlwaysOnTop\PowerToys.AlwaysOnTop.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\Awake\PowerToys.Awake.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\ColorPicker\PowerToys.ColorPickerUI.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\FancyZones\PowerToys.FancyZones.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\KeyboardManager\KeyboardManagerEngine\PowerToys.KeyboardManagerEngine.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\launcher\PowerToys.PowerLauncher.exe
(C:\Program Files\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\modules\PowerOCR\PowerToys.PowerOCR.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2309.1001.3.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(explorer.exe ->) (nordvpn s.a. -> TEFINCOM S.A.) C:\Program Files\NordVPN\NordVPN.exe
(explorer.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(explorer.exe ->) (Signal Messenger, LLC -> Signal Messenger, LLC) C:\Users\aluca\AppData\Local\Programs\signal-desktop\Signal.exe <4>
(explorer.exe ->) (Voyetra Turtle Beach, Inc. -> ROCCAT) C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\ROCCAT_Swarm_Monitor.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(MiniTool Software Limited -> ) C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe
(MosArt) [File not signed] C:\TECKNET wireless gaming mouse\TECKNET wireless gaming mouse.exe
(Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Ashampoo GmbH & Co. KG -> ) C:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\backupService-abpb.exe
(services.exe ->) (ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
(services.exe ->) (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ICM\ICM-Service-NET.exe
(services.exe ->) (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) D:\Origin\OriginWebHelperService.exe
(services.exe ->) (Even Balance, Inc. -> ) C:\Windows\System32\PnkBstrA.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2>
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe
(services.exe ->) (MiniTool Software Limited -> ) C:\Program Files\MiniTool ShadowMaker\AgentService.exe
(services.exe ->) (MiniTool Software Limited -> ) C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe
(services.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordUpdater\NordUpdateService.exe
(services.exe ->) (nordvpn s.a. -> TEFINCOM S.A.) C:\Program Files\NordVPN\nordvpn-service.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_12a8d6d742c436e2\RtkAudUService64.exe
(services.exe ->) (Shanghai Microvirt Software Technology Co., Ltd. -> ) D:\Emulatoren\Android\MEmu\MemuService.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (GameplayCrush) [File not signed] C:\Users\aluca\Downloads\WindowedBorderlessGaming_2.1.0.1\WindowedBorderlessGaming.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.BingWeather_4.53.51922.0_x64__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\PowerToys\PowerToys.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2309.1001.3.0_x64__8wekyb3d8bbwe\XboxPcApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_4.6.2.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.OneNote_16001.14326.21452.0_x64__8wekyb3d8bbwe\onenoteim.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(svchost.exe ->) (Voyetra Turtle Beach, Inc. -> ROCCAT) C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\ROCCAT_dev_service.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [MTPW] => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [219616 2020-02-19] (MiniTool Software Limited -> )
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_12a8d6d742c436e2\RtkAudUService64.exe [1211184 2020-12-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [144696 2017-02-14] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [598200 2018-09-28] (Razer USA Ltd. -> Razer Inc.)
HKLM-x32\...\Run: [TECKNET wireless gaming mouse] => C:\TECKNET wireless gaming mouse\TECKNET wireless gaming mouse.exe [3845632 2018-06-25] (MosArt) [File not signed]
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [] => [X]
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [org.whispersystems.signal-desktop] => C:\Users\aluca\AppData\Local\Programs\signal-desktop\Signal.exe [163621088 2023-08-09] (Signal Messenger, LLC -> Signal Messenger, LLC)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [NordVPN] => C:\Program Files\NordVPN\NordVPN.exe [280952 2022-02-18] (nordvpn s.a. -> TEFINCOM S.A.)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [Humble Bundle] => C:\Users\aluca\AppData\Local\Programs\Humble App\Humble App.exe [151919352 2023-04-07] (Humble Bundle Inc. -> Humble Bundle)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [2637928 2023-08-28] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [ASRock A-Tuning] => [X]
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Run: [GoogleChromeAutoLaunch_DC6ADF56C95D4F38FCEEDC413012C68B] => "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [3219744 2023-08-26] (Google LLC -> Google LLC)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\MountPoints2: {cbb4c2c2-e06f-11e6-8363-806e6f6e6963} - "I:\LaunchU3.exe" -a
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Winlogon: [Shell] C:\Windows\explorer.exe [5307536 2023-08-10] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Windows\System32\osk.exe [680448 2023-07-14] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\HP B111 Status Monitor: C:\Windows\system32\hpinkstsB111LM.dll [328552 2012-01-11] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\116.0.5845.141\Installer\chrmstp.exe [2023-09-01] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ROCCAT Swarm Monitor.lnk [2023-07-13]
ShortcutTarget: ROCCAT Swarm Monitor.lnk -> C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\ROCCAT_Swarm_Monitor.exe (Voyetra Turtle Beach, Inc. -> ROCCAT)
Startup: C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\QTTabBar Desktop Extension StartUp.QTTabGroup [2022-04-10] () [File not signed]
Startup: C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Razer Synapse.lnk [2019-01-20]
ShortcutTarget: Razer Synapse.lnk -> C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer USA Ltd. -> Razer Inc.)
GroupPolicy-Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {C83D7EEC-CF0F-496B-ADD1-8DDF6C8E4E70} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {CA01A975-9253-4F8F-B6E6-C87559BFC2E8} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564152 2023-04-03] (Adobe Inc. -> Adobe Inc.)
Task: {09F575CF-37C7-4F0C-996F-EA2BF7FF278D} - System32\Tasks\Avira_Antivirus_Systray => "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min (No File)
Task: {EC5E8D14-E52D-4004-A84B-20D546213EAE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-01-22] (Google Inc -> Google Inc.)
Task: {94C011EA-2384-4955-9D38-449068CC1792} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-01-22] (Google Inc -> Google Inc.)
Task: {689E3C95-59C0-4F8F-B6A3-F8D5DE2EC95C} - System32\Tasks\GSM_ao1jk-fcd33-67bde-vpwqd-s75md => D:\GameSave Manager\gs_mngr_3.exe [2696704 2021-09-29] (InsaneMatt) [File not signed]
Task: {685A4C3E-D289-46FB-BCA0-7C3BB9C2BFA5} - System32\Tasks\GSM_idnda-nwhy8-xbl73-7zqwz-ifk2j => F:\Game Save Manager\gs_mngr_3.exe [2719232 2022-10-05] (InsaneMatt) [File not signed]
Task: {F9E652F1-4BC0-4FE9-A5CD-A07B9C9E3191} - System32\Tasks\Microsoft\Windows\rempl\shell-usoscan => %ProgramFiles%\rempl\remsh.exe /RunUsoScanOnly (No File)
Task: {B2F3FA69-F65C-4FC7-8EF2-8DA67FA21947} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F3225AE4-7FBA-4F07-9DD7-BF8095F29DAD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DB213597-08DF-4CBA-8A39-E07585A422EF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {05FD2621-3B5D-4233-9ADE-EE705C48355C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {94B414E2-92D6-486D-993C-951E3FC571CA} - System32\Tasks\MiniToolPartitionWizard => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [219616 2020-02-19] (MiniTool Software Limited -> )
Task: {647CA575-AC0B-4C42-8168-CCEC90CD205D} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [815 2022-08-18] () [File not signed]
Task: {64D1A739-5CF7-42DD-B98B-2C3EB94E523C} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2023-03-17] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {B4C819D7-6FD8-468F-86A6-07364802F689} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-03-17] (Nvidia Corporation -> NVIDIA Corporation)
Task: {E4FA52EF-018E-4AF1-9A5F-3C03228E5967} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {732F2E43-AF41-415D-AFC9-5E92D723A69F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CDC679C3-63DF-42B1-AA46-C19E5B5290E4} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {29DEA42D-43EA-4840-934B-B0D2EE8CCBCB} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A9D30AEA-8B9F-46A3-899D-D88C4BECE4F8} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4CEB2DF4-2A77-49D7-88CE-6D7209135101} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3D3601D3-73F2-497C-A247-F3B611BDD81E} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5E27FF97-A730-42F5-BE88-127508A2D6DA} - System32\Tasks\PowerToys\Autorun for aluca => C:\Program Files\PowerToys\PowerToys.exe [1105344 2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {9E48E8A7-4F4F-48E2-A71D-14CD219A323B} - System32\Tasks\Private Internet Access Startup => C:\Program Files\pia_manager\pia_manager.exe [15732968 2018-06-18] (London Trust Media Inc -> ) [File not signed]
Task: {78C78A37-53AA-4E4D-A390-0276E7B15B5B} - System32\Tasks\ROCCAT DEVICE SERVICE => C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\ROCCAT_dev_service.exe [459672 2023-07-20] (Voyetra Turtle Beach, Inc. -> ROCCAT)
Task: {708B6639-2037-464B-98F7-CEA0868C16AC} - System32\Tasks\WindowedBorderlessGaming-aluca => C:\Users\aluca\Downloads\WindowedBorderlessGaming_2.1.0.1\WindowedBorderlessGaming.exe [893952 2015-03-17] (GameplayCrush) [File not signed]
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3: <==== ATTENTION (Restriction - Zones)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{43abba81-ac26-4732-bfde-521916648fe9}: [DhcpNameServer] 192.168.233.93
Tcpip\..\Interfaces\{a0d541e1-fa30-463e-92f7-238451da0013}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{fb2f4ab8-91e9-4b9d-93a1-3bca2dfa3a8c}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default [2023-09-04]
Edge HomePage: Default -> hxxps://www.google.at/webhp?hl=en
Edge StartupUrls: Default -> "chrome-extension://edacconmaakjimmfgnblocblbcdcpbko/main.html","hxxp://www.google.com/","hxxps://www.google.com/"
Edge Extension: (Google Translate) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-04-10]
Edge Extension: (PayPal Honey: Automatic Coupons & Cash Back) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\amnbcmdbanbkjhnfoeceemmmdiepnbpp [2023-09-04]
Edge Extension: (Google Voice Search Hotword (Beta)) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2022-03-23]
Edge Extension: (Avira Safe Shopping) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caiblelclndcckfafdaggpephhgfpoip [2022-10-31]
Edge Extension: (Pushbullet) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2023-04-08]
Edge Extension: (Search by Image (by Google)) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2022-03-23]
Edge Extension: (Checker Plus for Gmail™) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dkjkomkbjefdadfgbgdfgnpbmhmppiaa [2023-09-04]
Edge Extension: (Augmented Steam) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dnhpnfgdlenaccegplpojghhmaamnnfp [2023-07-14]
Edge Extension: (Avira Password Manager) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\emgfgdclgfeldebanedpihppahgngnle [2023-04-08]
Edge Extension: (Checker Plus for Google Calendar™) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fbongfbliechkeaegkjfehhimpenoani [2023-09-04]
Edge Extension: (Grammar Checker & Paraphraser – LanguageTool) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hfjadhjooeceemgojogkhlppanjkbobc [2023-09-02]
Edge Extension: (SteamDB) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hjknpdomhlodgaebegjopkmfafjpbblg [2023-09-04]
Edge Extension: (MyJDownloader Browser Extension) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ieapabanbplofifeaapjocpaogdhncdd [2022-03-23]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2023-09-02]
Edge Extension: (Chrome Remote Desktop) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2023-01-16]
Edge Extension: (Ask Historians Comment Helper) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jdkfbkogojpmdmpnkgjcgpngkkmhdfem [2022-03-23]
Edge Extension: (Reddit Enhancement Suite) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jlhgedjpndhblehblebhncfmkkpngiep [2023-04-08]
Edge Extension: (Edge relevant text changes) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-02]
Edge Extension: (Chrometana - Redirect Bing Somewhere Better) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kaicbfmipfpfpjmlbpejaoaflfdnabnc [2022-03-23]
Edge Extension: (Image Viewer) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kcljlcpbfbkapegpifkodjdmdllgdlmk [2022-03-23]
Edge Extension: (h264ify) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ldjamdlpbjpcfagnckgipdjiamhdcnbd [2022-03-23]
Edge Extension: (Chrometana Pro - Redirect Cortana and Bing) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\lllggmgeiphnciplalhefnbpddbadfdi [2023-01-16]
Edge Extension: (BeeLine Reader) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\lnhgohblpnbhabhglnlalchebkiegcii [2022-10-31]
Edge Extension: (Bing2Google) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mgoehlfmhfafaiepckjikpphoklijedl [2022-03-23]
Edge Extension: (Plugins) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mmcblfncjaclajmegihojiekebofjcen [2023-09-04]
Edge Extension: (Video Deck for YouTube™) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mpoakikepagdiphlmfaeifpojdmbnegj [2022-03-23]
Edge Extension: (Fakespot Fake Amazon Reviews and eBay Sellers) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nakplnnackehceedgkgkokbgbmfghain [2023-09-04]
Edge Extension: (AdBlock — best ad blocker) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2023-09-02]
Edge Extension: (Extensions Update Notifier) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nlldbplhbaopldicmcoogopmkonpebjm [2022-03-23]
Edge Extension: (Comic Updater) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pclklbdlpfhhbigalgggdfgiegbkipne [2022-03-23]
Edge Extension: (FFBE Sync) - C:\Users\aluca\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pjcodgpdnfndnjegedmjnlamjfkigied [2023-03-14]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF DefaultProfile: piWQYoLX.default
FF ProfilePath: C:\Users\aluca\AppData\Roaming\Zotero\Zotero\Profiles\5hrqqoqw.default [2018-05-13]
FF Extension: (Zotero LibreOffice Integration) - C:\Program Files (x86)\Zotero Standalone\extensions\zoteroOpenOfficeIntegration@zotero.org [2018-05-12] [Legacy] [not signed]
FF Extension: (Zotero Word for Windows Integration) - C:\Program Files (x86)\Zotero Standalone\extensions\zoteroWinWordIntegration@zotero.org [2018-05-12] [Legacy] [not signed]
FF ProfilePath: C:\Users\aluca\AppData\Roaming\Mozilla\Firefox\Profiles\piWQYoLX.default [2022-09-29]
FF Extension: (Avira Browser Safety) - C:\Users\aluca\AppData\Roaming\Mozilla\Firefox\Profiles\piWQYoLX.default\Extensions\abs@avira.com.xpi [2018-12-09] [UpdateUrl:hxxps://download.avira.com/package/abs/firefox/update-webext.rdf]
FF Extension: (Video DownloadHelper) - C:\Users\aluca\AppData\Roaming\Mozilla\Firefox\Profiles\piWQYoLX.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-01-04]
FF Plugin: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-10-12] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-10-12] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> D:\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] (Apple Inc. -> )
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (Electronic Sports Network i Sverige AB -> ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) [File not signed]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2023-08-19] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3615177999-3261653453-3779512466-1001: ubisoft.com/uplaypc -> G:\Die Siedler 7\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll [2013-02-27] (Ubisoft Massive -> Ubisoft)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default [2023-09-04]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://loginstrom.com; hxxps://messages.google.com; hxxps://new.reddit.com; hxxps://web.whatsapp.com; hxxps://www.derstandard.at; hxxps://www.mydpd.at; hxxps://www.netflix.com; hxxps://www.reddit.com
CHR HomePage: Default -> hxxps://www.google.at/webhp?hl=en
CHR StartupUrls: Default -> "chrome-extension://edacconmaakjimmfgnblocblbcdcpbko/main.html","hxxp://www.google.com","hxxps://www.google.com/"
CHR DefaultSearchURL: Default -> hxxp://www.google.com/search?name=f&hl=en&q={searchTerms}
CHR DefaultSearchKeyword: Default -> google (no country redirect)
CHR Extension: (Google Übersetzer) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-03-23]
CHR Extension: (h264ify) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aleakchihdccplidncghkekgioiakgal [2019-09-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2017-05-23]
CHR Extension: (Honey: Automatische Coupons & Prämien) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2023-09-04]
CHR Extension: (History 2) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cahejgbbfgmlmjgdjlibphdjeldhagkp [2017-01-22]
CHR Extension: (Pushbullet) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2023-03-26]
CHR Extension: (uBlock Origin) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2023-07-30]
CHR Extension: (Search by Image (by Google)) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2017-01-22]
CHR Extension: (Augmented Steam) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnhpnfgdlenaccegplpojghhmaamnnfp [2023-07-08]
CHR Extension: (Reddit Masstagger) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebjdimopaogdkhiagbgmkjjhehmooheo [2019-11-17]
CHR Extension: (Session Buddy) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\edacconmaakjimmfgnblocblbcdcpbko [2023-07-26]
CHR Extension: (Adobe Acrobat: Werkzeuge zum Bearbeiten, Konvertieren und Signieren von PDF-Dateien) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2023-08-25]
CHR Extension: (MyJDownloader Browser Erweiterung) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbcohnmimjicjdomonkcbcpbpnhggkip [2021-06-28]
CHR Extension: (Avira Browserschutz) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2022-10-26]
CHR Extension: (Chrome Remote Desktop) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-18]
CHR Extension: (Google Docs Offline) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-08-25]
CHR Extension: (AdBlock – der beste Ad-Blocker) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2023-08-09]
CHR Extension: (TweetDeck by Twitter) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2017-01-22]
CHR Extension: (feedly) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipbfijinpcgfogaopmgehiegacbhmob [2017-01-22]
CHR Extension: (AirDroid) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkgndiocipalkpejnpafdbdlfdjihomd [2017-01-22]
CHR Extension: (Checker Plus for Google Calendar™) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkhggnncdpfibdhinjiegagmopldibha [2023-08-22]
CHR Extension: (BeeLine Reader) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifjafammaookpiajfbedmacfldaiamgg [2023-07-10]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2023-08-29]
CHR Extension: (Forecastfox) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihffmkcfkejomlfnilnmkokcpgclhfeg [2017-01-22]
CHR Extension: (Chrome Remote Desktop) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2022-12-08]
CHR Extension: (Ask Historians Comment Helper) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdkfbkogojpmdmpnkgjcgpngkkmhdfem [2019-10-16]
CHR Extension: (Chrometana - Redirect Bing Somewhere Better) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaicbfmipfpfpjmlbpejaoaflfdnabnc [2017-07-27]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2023-04-04]
CHR Extension: (Image Viewer) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcljlcpbfbkapegpifkodjdmdllgdlmk [2017-01-22]
CHR Extension: (SteamDB) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdbmhfkmnlmbkgbabkdealhhbfhlmmon [2023-08-24]
CHR Extension: (Chrometana Pro - Redirect Cortana and Bing) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\lllggmgeiphnciplalhefnbpddbadfdi [2022-12-07]
CHR Extension: (AirDroid Remote Control Plugin) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\macmgoeeggnlnmpiojbcniblabkdjphe [2019-11-19]
CHR Extension: (Bing2Google) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgoehlfmhfafaiepckjikpphoklijedl [2017-01-22]
CHR Extension: (Plugins) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcblfncjaclajmegihojiekebofjcen [2023-09-04]
CHR Extension: (Video Deck for YouTube™) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpoakikepagdiphlmfaeifpojdmbnegj [2017-04-08]
CHR Extension: (Fakespot Fake Amazon Reviews and eBay Sellers) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nakplnnackehceedgkgkokbgbmfghain [2023-08-24]
CHR Extension: (Keepa - Amazon Price Tracker) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\neebplgakaahbhdphmkckjjcegoiijjo [2023-08-11]
CHR Extension: (Extensions Update Notifier) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlldbplhbaopldicmcoogopmkonpebjm [2017-01-22]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Checker Plus for Gmail™) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2023-08-21]
CHR Extension: (Grammatik- und Rechtschreibprüfung – LanguageTool) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\oldceeleldhonbafppcapldpdifcinji [2023-07-03]
CHR Extension: (Youtube Playlist Load All) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbclhlmcclobinpephoflilgclodhnmf [2017-01-22]
CHR Extension: (Comic Updater) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pclklbdlpfhhbigalgggdfgiegbkipne [2017-12-10]
CHR Extension: (FFBE Sync) - C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjcodgpdnfndnjegedmjnlamjfkigied [2023-02-27]
CHR Extension: (Sci-Hub) - C:\Users\aluca\Downloads\Sci-Hub [2017-02-10] [UpdateUrl:hxxp://31.184.194.81/update] <==== ATTENTION
CHR Profile: C:\Users\aluca\AppData\Local\Google\Chrome\User Data\Guest Profile [2022-02-16]
CHR Profile: C:\Users\aluca\AppData\Local\Google\Chrome\User Data\System Profile [2022-02-16]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32\...\Chrome\Extension: [hncafdhkllgldnimopgfkgnlcijmonah]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"MBAMChameleon" => service could not be unlocked. <==== ATTENTION
HKLM\SYSTEM\ControlSet001\Services\MBAMChameleon => \SystemRoot\System32\Drivers\MbamChameleon.sys <==== ATTENTION (Rootkit!/Locked Service)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-04-03] (Adobe Inc. -> Adobe Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-07-04] (ASUSTeK Computer Inc. -> )
R2 ashbackuppb; c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\backupService-abpb.exe [34184 2020-11-17] (Ashampoo GmbH & Co. KG -> )
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [9712432 2023-01-26] (BattlEye Innovations e.K. -> )
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [270336 2012-07-13] (Brother Industries, Ltd.) [File not signed]
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\116.0.5845.9\remoting_host.exe [74520 2023-06-26] (Google LLC -> Google LLC)
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [10941544 2023-08-28] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2022-11-24] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [584680 2022-08-09] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2022-11-16] (Epic Games Inc. -> Epic Games, Inc.)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342456 2018-05-22] (FUTUREMARK INC -> Futuremark)
S3 GalaxyClientService; D:\GOG Galaxy\GalaxyClientService.exe [2346464 2023-07-20] (GOG sp. z o.o -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7178720 2023-07-20] (GOG sp. z o.o -> GOG.com)
S4 HiPatchService; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-07-11] (Hi-Rez Studios) [File not signed]
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [230352 2023-08-08] (HP Inc. -> HP Inc.)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [8929608 2021-11-17] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9283096 2023-08-27] (Malwarebytes Inc. -> Malwarebytes)
R2 MEmuSVC; D:\Emulatoren\Android\MEmu\MemuService.exe [85304 2019-07-02] (Shanghai Microvirt Software Technology Co., Ltd. -> )
R2 MTAgentService; C:\Program Files\MiniTool ShadowMaker\AgentService.exe [783728 2021-12-20] (MiniTool Software Limited -> )
R2 MTSchedulerService; C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe [228208 2021-12-20] (MiniTool Software Limited -> )
R2 NordUpdaterService; C:\Program Files\NordUpdater\NordUpdateService.exe [297848 2022-11-21] (nordvpn s.a. -> nordvpn S.A.)
R2 nordvpn-service; C:\Program Files\NordVPN\nordvpn-service.exe [281464 2022-02-18] (nordvpn s.a. -> TEFINCOM S.A.)
S3 Origin Client Service; D:\Origin\OriginClientService.exe [2575064 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; D:\Origin\OriginWebHelperService.exe [3494672 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2018-01-18] (Even Balance, Inc. -> )
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [16552248 2023-01-18] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [4076744 2017-02-14] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe [3121008 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe [133688 2023-08-30] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ZA NET ICM Service; C:\Program Files (x86)\CheckPoint\ICM\ICM-Service-NET.exe [42208 2020-03-13] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S3 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [114936 2016-11-01] (Check Point Software Technologies Ltd. -> Check Point Software Technologies, Ltd.)
S2 ZoneAlarm ICM Service; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe [1037624 2017-02-14] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S2 AntivirProtectedService; "C:\Program Files (x86)\Avira\Antivirus\ProtectedService.exe" [X]
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
S3 SoundBoosterService; C:\Program Files (x86)\Letasoft Sound Booster\SoundBoosterService.exe [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-04] (ASUSTeK Computer Inc. -> )
S3 AsrDrv105; C:\WINDOWS\SysWOW64\Drivers\AsrDrv105.sys [40696 2023-08-28] (ASROCK INC. -> ASRock Incorporation)
S3 atvi-randgrid; C:\ProgramData\Battle.net_components\randgridauks\randgrid.sys [2986792 2023-09-01] (Activision Publishing Inc -> Activision Blizzard, Inc.)
S3 cpuz143; C:\Users\aluca\AppData\Local\Temp\cpuz143\cpuz143_x64.sys [48952 2023-09-02] (CPUID -> CPUID) <==== ATTENTION
S3 cpuz155; C:\Windows\temp\cpuz155\cpuz155_x64.sys [41480 2023-09-02] (Microsoft Windows Hardware Compatibility Publisher -> CPUID)
S3 DFX11_1; C:\Windows\system32\drivers\dfx11_1x64.sys [28008 2015-08-31] (Power Technology -> Windows (R) Win 7 DDK provider)
S3 DFX12; C:\Windows\system32\drivers\dfx12x64.sys [39048 2015-11-15] (Power Technology -> Windows (R) Win 7 DDK provider)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [21480 2022-06-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239544 2023-09-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R1 MEmuDrv; C:\Windows\system32\DRIVERS\MEmuDrv.sys [319448 2019-04-15] (Shanghai Microvirt Software Technology Co., Ltd. -> Maiwei Corporation)
R3 MpKsl68cd9a67; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DA88474F-78D1-4D98-878C-3FDD304493C4}\MpKslDrv.sys [222464 2023-09-04] (Microsoft Windows -> Microsoft Corporation)
S3 MpKsl97551fff; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DA88474F-78D1-4D98-878C-3FDD304493C4}\MpKslDrv.sys [222464 2023-09-04] (Microsoft Windows -> Microsoft Corporation)
R2 NDivert; C:\Program Files\NordVPN\6.48.19.0\Drivers\NDivert.sys [131456 2022-04-05] (nordvpn s.a. -> Nordvpn S.A.)
R1 nordlwf; C:\Windows\system32\DRIVERS\nordlwf.sys [44928 2022-02-22] (nordvpn s.a. -> TEFINCOM S.A.)
R1 npcap; C:\Windows\system32\DRIVERS\npcap.sys [77336 2022-08-19] (Insecure.Com LLC -> Insecure.Com LLC.)
R3 NvModuleTracker; C:\Windows\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2023-03-17] (Nvidia Corporation -> NVIDIA Corporation)
U5 PROCMON24; C:\Windows\System32\Drivers\PROCMON24.sys [80296 2023-08-31] (Microsoft Windows Hardware Compatibility Publisher -> Sysinternals - www.sysinternals.com)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] (MiniTool Solution Ltd -> )
S3 rspLLL; C:\Windows\System32\DRIVERS\rspLLL64.sys [26368 2020-08-21] (Daniel Terhell -> Resplendence Software Projects Sp.)
S3 rspWhySoSlow; C:\Windows\System32\DRIVERS\rspWhy64.sys [28928 2016-12-17] (Daniel Terhell -> Resplendence Software Projects Sp.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14024 2017-08-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [50392 2015-08-13] (Razer Inc. -> Razer Inc)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 tap0901; C:\Windows\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R3 tapnordvpn; C:\Windows\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
R3 USBPcap; C:\Windows\system32\DRIVERS\USBPcap.sys [52872 2020-05-22] (Tomasz Moń -> USBPcap)
R3 VirtualHID; C:\Windows\System32\drivers\VirtualHID.sys [26768 2022-08-15] (Voyetra Turtle Beach, Inc. -> TurtleBeach)
R1 Vsdatant; C:\Windows\system32\DRIVERS\vsdatant.sys [461240 2017-03-16] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [55872 2023-08-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [574872 2023-08-30] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105864 2023-08-30] (Microsoft Windows -> Microsoft Corporation)
S3 WIMMount; C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\amd64\DISM\wimmount.sys [42688 2016-07-16] (Microsoft Corporation -> Microsoft Corporation)
S3 WinRing0_1_2_0; C:\Users\aluca\Downloads\RealTemp_370\WinRing0x64.sys [14544 2008-07-26] (Noriyuki MIYAZAKI -> OpenLibSys.org)
S3 wintun; C:\Windows\System32\drivers\wintun.sys [29592 2022-04-10] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WofAdk; C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\amd64\DISM\wofadk.sys [221376 2016-07-16] (Microsoft Corporation -> Microsoft Corporation)
R1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [310536 2019-09-10] (Beijing Duodian Online Science and Technology Co.,Ltd -> BigNox Corporation)
S3 ALSysIO; \??\C:\Users\aluca\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 HWiNFO_174; \??\C:\Users\aluca\AppData\Local\Temp\HWiNFO64A_174.SYS [X] <==== ATTENTION
U3 iswSvc; no ImagePath
U4 npcap_wifi; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-09-04 21:47 - 2023-09-04 21:48 - 000049909 _____ C:\Users\aluca\Desktop\FRST.txt
2023-09-04 21:46 - 2023-09-04 20:21 - 002382336 _____ (Farbar) C:\Users\aluca\Desktop\FRST64.exe
2023-09-04 20:51 - 2023-09-04 20:57 - 000230480 _____ C:\Users\aluca\Downloads\Addition.txt
2023-09-04 20:49 - 2023-09-04 20:57 - 000072892 _____ C:\Users\aluca\Downloads\FRST.txt
2023-09-04 20:21 - 2023-09-04 21:47 - 000000000 ____D C:\FRST
2023-09-04 20:21 - 2023-09-04 20:21 - 002382336 _____ (Farbar) C:\Users\aluca\Downloads\FRST64.exe
2023-09-03 20:12 - 2023-09-03 20:12 - 000000000 ____D C:\Windows\LastGood.Tmp
2023-09-03 20:07 - 2023-08-16 12:15 - 000849088 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2023-09-03 20:07 - 2023-08-16 12:15 - 000849088 _____ C:\Windows\system32\vulkaninfo.exe
2023-09-03 20:07 - 2023-08-16 12:15 - 000713912 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2023-09-03 20:07 - 2023-08-16 12:15 - 000713912 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2023-09-03 20:07 - 2023-08-16 12:15 - 000653504 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2023-09-03 20:07 - 2023-08-16 12:15 - 000653504 _____ C:\Windows\system32\vulkan-1.dll
2023-09-03 20:07 - 2023-08-16 12:15 - 000637112 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2023-09-03 20:07 - 2023-08-16 12:15 - 000637112 _____ C:\Windows\SysWOW64\vulkan-1.dll
2023-09-03 20:07 - 2023-08-16 12:14 - 001487376 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2023-09-03 20:07 - 2023-08-16 12:14 - 001227296 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2023-09-03 20:07 - 2023-08-16 12:11 - 000669320 _____ C:\Windows\system32\nvofapi64.dll
2023-09-03 20:07 - 2023-08-16 12:10 - 001537544 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2023-09-03 20:07 - 2023-08-16 12:10 - 001195016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2023-09-03 20:07 - 2023-08-16 12:10 - 000938608 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2023-09-03 20:07 - 2023-08-16 12:10 - 000504456 _____ C:\Windows\SysWOW64\nvofapi.dll
2023-09-03 20:07 - 2023-08-16 12:09 - 002168456 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2023-09-03 20:07 - 2023-08-16 12:09 - 001622152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2023-09-03 20:07 - 2023-08-16 12:09 - 000992368 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2023-09-03 20:07 - 2023-08-16 12:09 - 000777760 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2023-09-03 20:07 - 2023-08-16 12:09 - 000768648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2023-09-03 20:07 - 2023-08-16 12:08 - 014520968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2023-09-03 20:07 - 2023-08-16 12:08 - 012066320 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2023-09-03 20:07 - 2023-08-16 12:08 - 003483168 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2023-09-03 20:07 - 2023-08-16 12:08 - 000459912 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2023-09-03 20:07 - 2023-08-16 12:07 - 006190088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2023-09-03 20:07 - 2023-08-16 12:07 - 005845640 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2023-09-03 20:07 - 2023-08-16 12:07 - 005550728 _____ (NVIDIA Corporation) C:\Windows\system32\nvcudadebugger.dll
2023-09-03 20:07 - 2023-08-16 12:07 - 000853104 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2023-09-03 20:07 - 2023-08-15 06:23 - 000108122 _____ C:\Windows\system32\nvinfo.pb
2023-09-03 20:05 - 2023-09-03 20:05 - 000000000 ____D C:\Users\aluca\AppData\Roaming\ArmoredCore6
2023-09-02 23:57 - 2023-09-02 23:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Armored Core 6 - Fires of Rubicon
2023-09-02 17:02 - 2023-09-02 17:02 - 001316932 _____ C:\Windows\Minidump\090223-21562-01.dmp
2023-09-02 15:57 - 2023-09-02 23:57 - 000000969 _____ C:\Users\Public\Desktop\Armored Core 6 - Bonus.lnk
2023-09-02 15:57 - 2023-09-02 23:57 - 000000793 _____ C:\Users\Public\Desktop\Armored Core 6 - Fires of Rubicon.lnk
2023-09-01 17:46 - 2023-09-01 17:46 - 017708338 _____ C:\Users\aluca\Documents\SysnativeFileCollectionApp.zip
2023-09-01 17:00 - 2023-09-01 17:00 - 035503819 _____ C:\Users\aluca\Desktop\trace.zip
2023-09-01 16:42 - 2023-09-01 16:55 - 161808384 _____ C:\Users\aluca\Desktop\trace.etl
2023-09-01 16:37 - 2023-09-01 16:55 - 152174592 _____ C:\kernel.etl
2023-08-31 23:15 - 2023-08-31 23:15 - 001975756 _____ C:\Windows\Minidump\083123-40046-01.dmp
2023-08-31 22:29 - 2023-08-31 22:40 - 000000000 ____D C:\Users\aluca\Documents\Latency Mon
2023-08-31 19:19 - 2023-08-31 19:19 - 000001465 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Procmon.lnk
2023-08-31 19:19 - 2023-08-31 19:19 - 000000000 ____D C:\Users\aluca\Downloads\ProcessMonitor
2023-08-31 19:17 - 2023-08-31 19:17 - 003456915 _____ C:\Users\aluca\Downloads\ProcessMonitor.zip
2023-08-31 19:17 - 2023-08-31 19:17 - 000001490 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DriverView.lnk
2023-08-31 15:44 - 2023-08-31 23:10 - 000000000 ____D C:\Users\aluca\Downloads\driverview-x64
2023-08-31 15:44 - 2023-08-31 15:44 - 000060809 _____ C:\Users\aluca\Downloads\driverview-x64.zip
2023-08-31 15:31 - 2023-08-31 15:31 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Wireshark
2023-08-31 15:25 - 2023-08-31 15:25 - 000001827 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark.lnk
2023-08-31 15:25 - 2023-08-31 15:25 - 000000000 ____D C:\Program Files\USBPcap
2023-08-31 15:24 - 2023-08-31 15:24 - 000003460 _____ C:\Windows\system32\Tasks\npcapwatchdog
2023-08-31 15:24 - 2023-08-31 15:24 - 000000000 ____D C:\Windows\SysWOW64\Npcap
2023-08-31 15:24 - 2023-08-31 15:24 - 000000000 ____D C:\Windows\system32\Npcap
2023-08-31 15:24 - 2023-08-31 15:24 - 000000000 ____D C:\Program Files\Npcap
2023-08-31 15:22 - 2023-08-31 15:25 - 000000000 ____D C:\Program Files\Wireshark
2023-08-31 15:20 - 2023-08-31 15:21 - 079164216 _____ (Wireshark development team) C:\Users\aluca\Downloads\Wireshark-win64-4.0.8.exe
2023-08-31 12:48 - 2023-08-31 20:17 - 000000000 ____D C:\Users\aluca\AppData\Local\DeadIsland
2023-08-31 12:48 - 2023-08-31 12:48 - 000000000 ____D C:\Users\Public\Documents\EMPRESS
2023-08-30 19:58 - 2023-08-30 20:25 - 000000000 ____D C:\ESD
2023-08-30 19:56 - 2023-08-30 20:04 - 000000000 ____D C:\Users\aluca\AppData\Roaming\U3
2023-08-30 19:54 - 2023-08-30 19:54 - 000000000 ___HD C:\$Windows.~WS
2023-08-30 19:54 - 2023-08-30 19:54 - 000000000 ____D C:\$WINDOWS.~BT
2023-08-29 21:12 - 2023-08-29 21:12 - 000000000 ____D C:\Program Files (x86)\Intel Driver
2023-08-29 21:10 - 2023-08-29 21:10 - 009822245 _____ C:\Users\aluca\Downloads\Realtek_LAN(v1125.1.714.2021).zip
2023-08-29 21:10 - 2023-08-29 21:10 - 001600291 _____ C:\Users\aluca\Downloads\Intel_LAN(v12.19.1.37b_v2).zip
2023-08-29 18:27 - 2023-08-29 18:27 - 000001519 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Speccy64.lnk
2023-08-29 18:26 - 2023-08-29 18:26 - 002781052 _____ C:\Users\aluca\Downloads\Speccy x64 portable.zip
2023-08-29 18:26 - 2023-08-29 18:26 - 000000000 ____D C:\Users\aluca\Downloads\Speccy x64 portable
2023-08-29 18:21 - 2023-09-01 17:45 - 000000000 ____D C:\Users\aluca\Documents\SysnativeFileCollectionApp
2023-08-29 18:20 - 2023-08-29 18:20 - 000175952 _____ (Sysnative) C:\Users\aluca\Downloads\SysnativeBSODCollectionApp.exe
2023-08-28 22:59 - 2023-08-28 22:59 - 002552364 _____ C:\Windows\Minidump\082823-12328-01.dmp
2023-08-28 22:50 - 2023-08-28 22:50 - 000000000 ____D C:\Program Files\Intel
2023-08-28 22:49 - 2023-08-28 22:49 - 003947286 _____ C:\Users\aluca\Downloads\INF(v10.1.18634.8254_Public).zip
2023-08-28 22:45 - 2023-08-29 21:18 - 000000000 ____D C:\Program Files (x86)\Realtek
2023-08-28 22:45 - 2023-08-28 22:51 - 000000000 ___HD C:\Program Files (x86)\Temp
2023-08-28 22:45 - 2020-12-09 18:06 - 005989992 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2023-08-28 22:45 - 2020-12-09 18:05 - 000276736 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTHDASIO64.dll
2023-08-28 22:45 - 2020-12-09 18:05 - 000231664 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RTHDASIO.dll
2023-08-28 22:45 - 2019-12-19 09:07 - 002877104 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
2023-08-28 22:44 - 2023-08-28 22:44 - 036578316 _____ C:\Users\aluca\Downloads\Realtek_Audio(v9079.1_UAD_WHQL_Nahimic).zip
2023-08-28 22:41 - 2023-08-28 22:41 - 000040696 _____ (ASRock Incorporation) C:\Windows\SysWOW64\Drivers\AsrDrv105.sys
2023-08-28 22:41 - 2023-08-28 22:41 - 000001344 _____ C:\Users\Public\Desktop\A-Tuning.lnk
2023-08-28 22:41 - 2023-08-28 22:41 - 000000000 ____D C:\Windows\ASRock
2023-08-28 22:41 - 2023-08-28 22:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility
2023-08-28 22:41 - 2023-08-28 22:41 - 000000000 ____D C:\Program Files (x86)\ASRock Utility
2023-08-28 22:40 - 2023-08-28 22:40 - 062145883 _____ C:\Users\aluca\Downloads\MotherboardUtility(v3.0.425).zip
2023-08-28 20:54 - 2023-08-28 20:54 - 000000000 ____D C:\SymCache
2023-08-28 20:53 - 2023-08-28 22:17 - 000000000 ____D C:\Users\aluca\Documents\WPR Files
2023-08-28 20:53 - 2023-08-28 22:17 - 000000000 ____D C:\Users\aluca\AppData\Local\Windows Performance Analyzer
2023-08-28 20:53 - 2023-08-28 20:53 - 000000000 ____D C:\Users\aluca\Documents\WPA Files
2023-08-28 20:29 - 2023-08-28 20:29 - 000000000 ____D C:\ProgramData\WindowsPerformanceRecorder
2023-08-28 19:52 - 2023-08-28 19:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2023-08-28 11:14 - 2023-08-28 11:14 - 002633636 _____ C:\Windows\Minidump\082823-15265-01.dmp
2023-08-26 15:24 - 2023-08-26 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dead Island 2
2023-08-23 11:05 - 2023-08-23 11:05 - 004653724 _____ C:\Windows\Minidump\082323-22625-01.dmp
2023-08-15 12:43 - 2023-08-22 14:39 - 000001326 _____ C:\Users\aluca\Desktop\Fire Toolbox V32.1.lnk
2023-08-14 11:04 - 2023-08-22 14:39 - 000001334 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fire Toolbox V32.1.lnk
2023-08-14 08:09 - 2023-08-15 11:14 - 000000000 ____D C:\Users\aluca\AppData\LocalLow\IGDump
2023-08-13 12:34 - 2023-08-16 12:05 - 006737504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2023-08-10 20:38 - 2023-08-10 20:38 - 000000000 ___HD C:\$WinREAgent
2023-08-09 16:02 - 2023-08-09 16:02 - 000315416 _____ C:\Users\aluca\Documents\Wien_Energie_Rechnung_005107849736.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-09-04 21:46 - 2021-04-08 14:04 - 000000000 ____D C:\Users\aluca\AppData\Local\Ashampoo Backup PB
2023-09-04 21:44 - 2021-12-17 01:26 - 000000000 ____D C:\Windows\SystemTemp
2023-09-04 21:44 - 2017-01-22 14:17 - 000000000 ____D C:\Program Files (x86)\Google
2023-09-04 21:43 - 2023-05-12 22:51 - 000000000 ____D C:\Users\aluca\AppData\Local\Malwarebytes
2023-09-04 21:43 - 2022-03-15 16:21 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Signal
2023-09-04 21:43 - 2017-05-13 17:16 - 000000000 ____D C:\ProgramData\NVIDIA
2023-09-04 21:43 - 2017-01-25 12:32 - 000000000 ____D C:\Users\aluca\Documents\Assassin's Creed Unity
2023-09-04 21:42 - 2022-11-08 13:23 - 000000000 ____D C:\Windows\system32\Tasks\PowerToys
2023-09-04 21:42 - 2022-07-09 12:39 - 000000000 ____D C:\Program Files\TeamViewer
2023-09-04 21:42 - 2021-03-15 17:21 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-09-04 21:42 - 2021-03-15 16:50 - 000008192 ___SH C:\DumpStack.log.tmp
2023-09-04 21:42 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-09-04 21:42 - 2019-12-07 11:03 - 000786432 _____ C:\Windows\system32\config\BBI
2023-09-04 21:40 - 2021-07-28 15:43 - 000239544 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2023-09-04 21:38 - 2018-07-10 14:13 - 000000000 ____D C:\Windows\pss
2023-09-04 21:38 - 2017-11-17 14:22 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2023-09-04 21:30 - 2017-01-22 20:55 - 000000000 ____D C:\Users\aluca\AppData\Local\CrashDumps
2023-09-04 21:25 - 2017-06-28 17:09 - 000000000 ____D C:\Users\aluca\AppData\Local\Battle.net
2023-09-04 21:03 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-09-04 21:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2023-09-04 21:02 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2023-09-04 12:34 - 2022-03-18 14:50 - 000000000 ____D C:\XboxGames
2023-09-04 12:34 - 2018-02-02 12:15 - 000000000 ____D C:\Users\aluca\AppData\Local\Packages
2023-09-04 12:32 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\Registration
2023-09-04 11:13 - 2021-03-15 16:51 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-09-04 00:32 - 2021-06-01 13:04 - 000004168 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{AB636331-6FD2-446F-9E32-00CA4DC5C76B}
2023-09-03 23:07 - 2021-03-15 17:04 - 002333492 _____ C:\Windows\system32\PerfStringBackup.INI
2023-09-03 23:07 - 2021-03-15 15:12 - 000477628 _____ C:\Windows\system32\perfh011.dat
2023-09-03 23:07 - 2021-03-15 15:12 - 000132506 _____ C:\Windows\system32\perfc011.dat
2023-09-03 23:07 - 2019-12-07 16:50 - 000743546 _____ C:\Windows\system32\perfh007.dat
2023-09-03 23:07 - 2019-12-07 16:50 - 000149968 _____ C:\Windows\system32\perfc007.dat
2023-09-03 22:58 - 2021-06-09 16:54 - 000000000 ____D C:\SteamLibrary
2023-09-03 22:38 - 2020-01-14 13:35 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Goldberg SteamEmu Saves
2023-09-03 20:12 - 2018-07-11 21:29 - 000000000 ____D C:\Users\aluca\AppData\Local\NVIDIA
2023-09-03 20:08 - 2017-05-13 17:16 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2023-09-03 20:05 - 2018-05-30 19:05 - 000000000 ____D C:\Users\aluca\AppData\Local\D3DSCache
2023-09-03 19:50 - 2017-01-23 21:26 - 000000000 ____D C:\Users\aluca\AppData\Roaming\XnViewMP
2023-09-02 23:50 - 2021-03-15 16:03 - 000000000 ____D C:\Users\aluca
2023-09-02 17:02 - 2022-03-18 14:53 - 000000000 ____D C:\Windows\Minidump
2023-09-02 17:02 - 2020-07-02 19:12 - 1833298942 _____ C:\Windows\MEMORY.DMP
2023-09-01 17:18 - 2020-06-07 20:36 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-09-01 17:18 - 2020-06-07 20:36 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-09-01 03:06 - 2022-02-16 15:06 - 000002239 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-09-01 03:06 - 2022-02-16 15:06 - 000002198 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-08-31 23:31 - 2022-10-21 21:03 - 000079360 _____ (Microsoft Corporation) C:\Windows\system32\xgamehelper.exe
2023-08-31 23:31 - 2022-10-21 21:03 - 000062976 _____ (Microsoft Corporation) C:\Windows\system32\xgamecontrol.exe
2023-08-31 23:31 - 2021-11-21 12:11 - 000169472 _____ (Microsoft Corporation) C:\Windows\system32\gamelaunchhelper.dll
2023-08-31 23:31 - 2020-05-01 10:54 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\gamingtcuihelpers.dll
2023-08-31 23:31 - 2019-12-13 12:23 - 000493056 _____ (Microsoft Corporation) C:\Windows\system32\gameplatformservices.dll
2023-08-31 23:31 - 2019-12-04 11:14 - 002807296 _____ (Microsoft Corporation) C:\Windows\system32\xgameruntime.dll
2023-08-31 23:31 - 2019-12-04 11:14 - 000247288 _____ (Microsoft Corporation) C:\Windows\system32\gamingservicesproxy.dll
2023-08-31 23:31 - 2019-12-04 11:14 - 000202240 _____ (Microsoft Corporation) C:\Windows\system32\gameconfighelper.dll
2023-08-31 22:48 - 2022-09-27 12:17 - 000000000 ____D C:\Users\aluca\AppData\Roaming\qBittorrent
2023-08-31 17:23 - 2017-01-26 22:24 - 000000000 ____D C:\Users\aluca\AppData\Local\JDownloader v2.0
2023-08-31 16:15 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2023-08-31 15:24 - 2017-01-22 17:37 - 000000000 ____D C:\ProgramData\Package Cache
2023-08-31 11:10 - 2021-12-11 12:53 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3615177999-3261653453-3779512466-1001
2023-08-31 11:10 - 2021-03-15 17:21 - 000003380 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3615177999-3261653453-3779512466-1001
2023-08-31 11:10 - 2021-03-15 16:03 - 000002383 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-08-30 23:14 - 2022-05-04 13:09 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Humble App
2023-08-30 20:25 - 2021-03-15 11:30 - 000000000 ___DC C:\Windows\Panther
2023-08-30 17:46 - 2019-12-07 11:14 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2023-08-30 17:26 - 2017-03-01 18:37 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Microsoft\Excel
2023-08-30 17:06 - 2017-01-22 20:21 - 000000000 ____D C:\ProgramData\Zoom Player
2023-08-30 16:58 - 2018-03-31 12:56 - 000000000 ____D C:\Windows\system32\Drivers\wd
2023-08-29 21:18 - 2017-08-13 16:16 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2023-08-29 16:34 - 2017-01-22 19:55 - 000000000 ____D C:\Program Files (x86)\Avira
2023-08-29 16:33 - 2021-04-16 11:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2023-08-29 16:33 - 2017-01-22 19:55 - 000000000 ____D C:\ProgramData\Avira
2023-08-29 16:32 - 2023-02-15 16:33 - 003893768 _____ C:\Windows\system32\rtp.db
2023-08-29 16:32 - 2022-06-06 12:10 - 000000000 ____D C:\Program Files\Avira
2023-08-29 16:32 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2023-08-29 15:17 - 2021-06-04 10:49 - 000000000 ____D C:\Games
2023-08-29 15:01 - 2018-02-16 12:03 - 000000000 ____D C:\Epic Games
2023-08-29 14:59 - 2018-02-16 12:03 - 000002135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
2023-08-29 14:59 - 2018-02-16 12:03 - 000002123 _____ C:\Users\Public\Desktop\Epic Games Launcher.lnk
2023-08-29 13:26 - 2017-01-23 20:03 - 000000000 ____D C:\Users\aluca\AppData\Local\Steam
2023-08-28 22:59 - 2021-03-15 16:51 - 000404152 _____ C:\Windows\system32\FNTCACHE.DAT
2023-08-28 11:18 - 2017-01-22 09:54 - 000918960 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2023-08-25 10:30 - 2022-04-10 19:24 - 000000000 ____D C:\Program Files\NordUpdater
2023-08-24 21:22 - 2022-10-13 18:33 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2023-08-23 00:32 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\LiveKernelReports
2023-08-22 14:39 - 2021-06-26 12:31 - 000001344 _____ C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Toolbox Updater.lnk
2023-08-22 14:39 - 2021-06-26 12:31 - 000001336 _____ C:\Users\aluca\Desktop\Toolbox Updater.lnk
2023-08-22 11:23 - 2020-03-22 19:44 - 000000000 ____D C:\Users\aluca\AppData\Local\Apps\2.0
2023-08-18 15:34 - 2018-09-13 16:10 - 000000347 _____ C:\Windows\BRRBCOM.INI
2023-08-16 12:06 - 2023-04-08 15:15 - 007858112 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2023-08-15 06:23 - 2023-04-08 15:15 - 000121880 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2023-08-13 12:35 - 2017-05-13 17:16 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\setup
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\migwiz
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\appraiser
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2023-08-10 23:55 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\appcompat
2023-08-10 20:44 - 2021-03-15 16:54 - 003015168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2023-08-10 20:38 - 2017-01-22 09:54 - 000000000 ____D C:\Windows\system32\MRT
2023-08-10 20:34 - 2017-01-22 09:53 - 175983240 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2023-08-10 10:34 - 2020-09-03 11:19 - 000000000 ____D C:\Users\Public\Security Sessions
2023-08-10 00:01 - 2017-09-29 16:49 - 000000000 ____D C:\Users\aluca\AppData\Roaming\Microsoft\Word
2023-08-09 10:50 - 2022-11-08 13:22 - 000000000 ____D C:\Program Files\dotnet
2023-08-08 11:15 - 2021-05-12 13:21 - 000000000 ____D C:\Windows\system32\Tasks\HP
2023-08-08 11:15 - 2021-05-12 13:21 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
==================== Files in the root of some directories ========
2019-04-15 22:43 - 2019-04-16 23:46 - 000000002 _____ () C:\Users\aluca\AppData\Roaming\ceville_console_history.txt
2022-05-31 17:20 - 2022-05-31 17:20 - 000004870 _____ () C:\Users\aluca\AppData\Local\2758054585
2022-12-04 14:46 - 2022-12-04 14:46 - 000003998 _____ () C:\Users\aluca\AppData\Local\2830118318
2022-12-08 13:03 - 2022-12-25 13:08 - 000003998 _____ () C:\Users\aluca\AppData\Local\3206298627
2023-03-07 12:27 - 2023-03-07 12:27 - 000005358 _____ () C:\Users\aluca\AppData\Local\92443903807
2023-06-08 21:27 - 2023-06-08 21:27 - 000005990 _____ () C:\Users\aluca\AppData\Local\93205666527
2023-06-02 22:47 - 2023-06-02 22:47 - 000005990 _____ () C:\Users\aluca\AppData\Local\9618647855
2023-05-21 10:59 - 2023-05-21 10:59 - 000005990 _____ () C:\Users\aluca\AppData\Local\9980246772
2020-03-21 15:40 - 2023-05-15 20:09 - 000007601 _____ () C:\Users\aluca\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-08-2023
Ran by aluca (04-09-2023 21:49:15)
Running from C:\Users\aluca\Desktop
Microsoft Windows 10 Home Version 22H2 19045.3324 (X64) (2021-03-15 15:21:48)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-3615177999-3261653453-3779512466-500 - Administrator - Disabled)
aluca (S-1-5-21-3615177999-3261653453-3779512466-1001 - Administrator - Enabled) => C:\Users\aluca
DefaultAccount (S-1-5-21-3615177999-3261653453-3779512466-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-3615177999-3261653453-3779512466-1000 - Limited - Disabled) => C:\Users\defaultuser0
Gast (S-1-5-21-3615177999-3261653453-3779512466-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3615177999-3261653453-3779512466-504 - Limited - Disabled)
_ashbackuppb_ (S-1-5-21-3615177999-3261653453-3779512466-1002 - Administrator - Enabled) => C:\Users\_ashbackuppb_
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avira Security (Enabled - Up to date) {C622D33D-B035-6463-E471-9D92B9517CA1}
FW: Avira Security (Enabled) {BE55A40C-05CA-1096-36EB-CCA92DEAF539}
FW: ZoneAlarm Free Firewall Firewall (Disabled) {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
FW: Avira Security (Enabled) {877B141C-E73B-9A54-223E-108CC963426A}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
3DMark (HKLM\...\{1F3F2DD9-EE3C-4803-A287-49C9FFB0E7EB}) (Version: 2.5.5029.0 - UL) Hidden
3DMark (HKLM-x32\...\{21e80113-175b-4eb9-8f9e-49fdc5e68235}) (Version: 2.5.5029.0 - UL)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
Adobe Acrobat Reader (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 23.003.20284 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601047}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Amazon Games (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\{4DD10B06-78A4-4E6F-AA39-25E9C38FA568}) (Version: 2.3.8425.2 - Amazon.com Services, Inc.)
Amazon Kindle (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Amazon Kindle) (Version: 1.17.1.44183 - Amazon)
Anthem™ (HKLM-x32\...\{57b4eaa0-f1f5-407e-afbd-2db397381ad8}) (Version: 1.0.64.28115 - Electronic Arts)
Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{06A333EA-4E9D-4848-865F-FE5A1E12AB30}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Armored Core 6: Fires of Rubicon (HKLM-x32\...\Armored Core 6: Fires of Rubicon_is1) (Version: - )
Ashampoo Backup Pro 15 (HKLM\...\{DF972766-B348-CB30-5EB9-9171F37E9745}_is1) (Version: 15.03 - Ashampoo GmbH & Co. KG)
Assassin Creed Syndicate version 1.5 (HKLM-x32\...\Assassin Creed Syndicate_is1) (Version: 1.5 - KNIGHT)
Assassin's Creed Odyssey (HKLM-x32\...\Uplay Install 5059) (Version: - Ubisoft)
Assassins Creed Origins The Curse of the Pharaohs (HKLM-x32\...\Assassins Creed Origins The Curse of the Pharaohs_is1) (Version: - )
Assessments on Client (HKLM-x32\...\{F8288793-51B6-47EF-2F93-D37767663FC5}) (Version: 10.1.14393.0 - Microsoft) Hidden
Atelier: Dusk Trilogy (HKLM-x32\...\Atelier: Dusk Trilogy_is1) (Version: - )
A-Tuning v3.0.425 (HKLM-x32\...\A-Tuning_is1) (Version: 3.0.425 - ASRock Inc.)
AviSynth 2.6 (HKLM-x32\...\AviSynth) (Version: 2.6.0.6 - GPL Public release.)
AVStoDVD 2.8.6 (HKLM-x32\...\AVStoDVD) (Version: 2.8.6 - MrC)
Baldur's Gate: Enhanced Edition (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\AmazonGames/Baldur's Gate - Enhanced Edition) (Version: - Aspyr)
Bass Audio Decoder (remove only) (HKLM-x32\...\Bass Audio Decoder) (Version: - )
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.8.2.48475 - Electronic Arts)
Battlefield™ 2042 (HKLM-x32\...\{45e281f3-1414-47ea-bb64-4f50d50121f3}) (Version: 1.0.76.5661 - Electronic Arts)
Battlefield™ V (HKLM-x32\...\{e26b382f-e945-4f70-9318-121b683f1d61}) (Version: 1.0.60.9722 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB)
BCUninstaller (HKLM\...\{f4fef76c-1aa9-441c-af7e-d27f58d898d1}_is1) (Version: 5.1.0.0 - Marcin Szeniak)
Beholder 2 (HKLM-x32\...\Beholder 2_is1) (Version: - )
Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Blood and Wine (HKLM-x32\...\1441620909_is1) (Version: 1.32 - GOG.com)
Bloodstained: IGA's Back Pack (HKLM-x32\...\2089941670_is1) (Version: 1.05 - GOG.com)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
calibre (HKLM-x32\...\{25BA606B-AB60-4404-96DB-C839543BD535}) (Version: 3.2.1 - Kovid Goyal)
Call of Duty (HKLM-x32\...\Call of Duty) (Version: - Blizzard Entertainment)
Call of Duty Black Ops 4 (HKLM-x32\...\Call of Duty Black Ops 4) (Version: - Blizzard Entertainment)
Call of Duty Black Ops Cold War (HKLM-x32\...\Call of Duty Black Ops Cold War) (Version: - Blizzard Entertainment)
Call of Duty Modern Warfare (HKLM-x32\...\Call of Duty Modern Warfare) (Version: - Blizzard Entertainment)
Chrome Remote Desktop Host (HKLM-x32\...\{C17C2857-FF33-4EA0-8220-14A17DF82668}) (Version: 116.0.5845.9 - Google LLC)
Cloudpunk (HKLM-x32\...\Cloudpunk_is1) (Version: - )
CodeTwo QR Code Desktop Reader & Generator (HKLM-x32\...\{AF7E31D6-980C-4788-B80C-47F1837CF44C}) (Version: 1.1.2.4 - CodeTwo)
ComicRack v0.9.178 (HKLM\...\ComicRack) (Version: v0.9.178 - cYo Soft)
Core Temp 1.17.1 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.17.1 - ALCPU)
CPUID CPU-Z 2.03 (HKLM\...\CPUID CPU-Z_is1) (Version: 2.03 - CPUID, Inc.)
Crying Suns (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Humble App cryingsuns_windows) (Version: - )
Cuphead (HKLM-x32\...\1963513391_is1) (Version: hotfix_1.1.4 - GOG.com)
Cyberpunk 2077 (HKLM-x32\...\1423049311_is1) (Version: 1_61 - GOG.com)
Cyberpunk 2077 REDmod (HKLM-x32\...\1597316373_is1) (Version: 1_61 - GOG.com)
Dashboard (HKLM-x32\...\Western Digital SSD Dashboard) (Version: 3.2.2.9 - Western Digital Corporation)
DCoder Image Source (remove only) (HKLM-x32\...\DCoder Image Source) (Version: - )
Dead Island 2 (HKLM-x32\...\Dead Island 2_is1) (Version: 0.0.0 - DODI-Repacks)
Deadpool (HKLM-x32\...\Deadpool_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter)
Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform)
Devil May Cry 4 Special Edition (HKLM-x32\...\Devil May Cry 4 Special Edition_is1) (Version: - )
Die Siedler 7 (HKLM-x32\...\{63860309-DA8A-4BAE-9EAE-CE1D6D79340C}) (Version: 1.12.1396 - Ubisoft)
DirectVobSub (remove only) (HKLM-x32\...\DirectVobSub) (Version: - )
Disco Elysium (HKLM-x32\...\1771589310_is1) (Version: bbe2afa0 - GOG.com)
Discord (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Discord) (Version: 0.0.308 - Discord Inc.)
Disneyland Adventures (HKLM-x32\...\Disneyland Adventures_is1) (Version: - )
Divinity.Original.Sin.2.v3.0.151.229.REPACK-KaOs Uninstaller v3.0 (HKLM-x32\...\Divinity.Original.Sin.2.v3.0.151.229.REPACK-KaOs_is1) (Version: 3.0 - KaOsKrew)
Dragon Quest Builders 2 (HKLM-x32\...\Dragon Quest Builders 2_is1) (Version: - )
Dying Light (HKLM-x32\...\1448452156_is1) (Version: 1.16.0 - GOG.com)
Dying Light: Gun Psycho Bundle (HKLM-x32\...\1460996021_is1) (Version: 1.16.0 - GOG.com)
Dying Light: Harran Military Rifle (HKLM-x32\...\1182281905_is1) (Version: 1.16.0 - GOG.com)
Dying Light: Harran Ranger Bundle (HKLM-x32\...\1460996196_is1) (Version: 1.16.0 - GOG.com)
Dying Light: Volatile Hunter Bundle (HKLM-x32\...\1460996282_is1) (Version: 1.16.0 - GOG.com)
Dynasty Warriors 8 Xtreme Legends (HKLM-x32\...\Dynasty Warriors 8 Xtreme Legends_is1) (Version: - )
EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.8.0.5521 - Electronic Arts) Hidden
EA app (HKLM-x32\...\{547c1c17-118e-4cb9-bace-9bd738530ffc}) (Version: 13.8.0.5521 - Electronic Arts)
EasyBCD 2.4 (HKLM-x32\...\EasyBCD) (Version: 2.4 - NeoSmart Technologies)
EdgeDeflector (HKLM-x32\...\EdgeDeflector) (Version: - )
ENE_QSI_Loki_HAL (HKLM\...\{BDE43F26-5917-44F8-B86A-F1D9A6B80B32}) (Version: 1.0.3.0 - ENE TECHNOLOGY INC.) Hidden
ENE_QSI_Loki_HAL (HKLM-x32\...\{205ef3a8-937b-43cb-90fc-2f58f71408d8}) (Version: 1.0.3.0 - ENE TECHNOLOGY INC.) Hidden
Epic Games Launcher (HKLM-x32\...\{FE3CD7B8-14D4-46E9-A206-2C8F2C0E6F1F}) (Version: 1.1.139.0 - Epic Games, Inc.)
Epic Online Services (HKLM-x32\...\{A1EB595F-651D-4A04-99B0-A7065538B33C}) (Version: 2.0.38.0 - Epic Games, Inc.)
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
EVERSPACE - Encounters (HKLM-x32\...\1165094689_is1) (Version: 1.3.5.36556 - GOG.com)
EVERSPACE (HKLM-x32\...\1513949567_is1) (Version: 1.3.5.36556 - GOG.com)
Far Cry 3 Blood Dragon (HKLM-x32\...\Uplay Install 205) (Version: - Ubisoft)
Far Cry 5 (HKLM-x32\...\Far Cry 5_is1) (Version: - )
FFMPEG Core Files (remove only) (HKLM-x32\...\FFMPEG Core Files) (Version: - )
FIFA 21 (HKLM-x32\...\{A918ACE7-A83B-41F4-8746-AEF8DC821879}) (Version: 1.0.70.18952 - Electronic Arts)
Final Fantasy XII The Zodiac Age MULTi9 - ElAmigos version 1.0 (HKLM-x32\...\{87E52C4C-549B-4639-AFCB-78D3BC1B457F}_is1) (Version: 1.0 - Square Enix)
FINAL FANTASY XIV ONLINE (HKLM-x32\...\{2B41E132-07DF-4925-A3D3-F2D1765CCDFE}) (Version: 1.0.0000 - SQUARE ENIX CO., LTD.)
Fire Toolbox version (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\{879EB178-B5C2-4785-B5D4-704DBC011B2A}_is1) (Version: - Datastream33)
Folder Size Explorer (HKLM-x32\...\{CD453A88-D560-47A2-9D4D-414134F5A73D}) (Version: 2.0.0 - Bazwise)
Fraps (HKLM-x32\...\Fraps) (Version: - )
Free DLC program (16 DLC) (HKLM-x32\...\1430743168_is1) (Version: 1.32 - GOG.com)
FreeCommander XE (HKLM-x32\...\FreeCommander XE_is1) (Version: - Marek Jasinski)
Futuremark SystemInfo (HKLM-x32\...\{66E02F22-FA88-453D-9DE7-60F54E951FAF}) (Version: 5.10.676.0 - Futuremark)
Genshin Impact (HKLM\...\Genshin Impact) (Version: 2.8.4.0 - miHoYo Co.,Ltd)
Gods Trigger (HKLM-x32\...\Gods Trigger_is1) (Version: - )
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: 2.0.67.2 - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 116.0.5845.141 - Google LLC)
Google Earth Pro (HKLM\...\{F27DBA46-80E1-4858-9285-19198FFFBF3D}) (Version: 7.3.6.9345 - Google)
Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - )
Hearts of Iron IV Field Marshal Edition MULTi7 - ElAmigos version 1.5.2 (HKLM-x32\...\{9240BFB5-B3DE-4505-8351-5605EE8D4F84}_is1) (Version: 1.5.2 - Paradox Interactive)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
HL-3142CW (HKLM-x32\...\{C6580DE1-F539-4700-ADD2-3185121E51A8}) (Version: 1.0.1.0 - Brother Industries, Ltd.)
Humble App 1.1.8+411 (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\2f793df2-2969-529d-b0c0-7960ed40d70e) (Version: 1.1.8+411 - Humble Bundle)
HWiNFO64 Version 7.36 (HKLM\...\HWiNFO64_is1) (Version: 7.36 - Martin Malik - REALiX)
Imaging And Configuration Designer (HKLM-x32\...\{05935793-A34C-4272-3361-7AF9AEEE5649}) (Version: 10.1.14393.0 - Microsoft) Hidden
Imaging Designer (HKLM-x32\...\{FB54F620-9555-3A11-26CB-B027C4DDF260}) (Version: 10.1.14393.0 - Microsoft) Hidden
Imaging Tools Support (HKLM-x32\...\{C30A729A-E9BA-37F8-3C58-64AD9F1D4694}) (Version: 10.1.14393.0 - Microsoft) Hidden
Immortals Fenyx Rising (HKLM-x32\...\Uplay Install 5405) (Version: - Ubisoft)
Intel(R) Chipset Device Software (HKLM\...\{06D713D6-9845-436D-B857-5BF2596B4554}) (Version: 10.1.18634.8254 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{99926fb7-5da9-4101-b79f-eec3674ca64b}) (Version: 10.1.18634.8254 - Intel(R) Corporation)
Into the Breach (HKLM-x32\...\2004253604_is1) (Version: 1.0.20 - GOG.com)
iTunes (HKLM\...\{8A99C2B8-2B40-46B2-B900-621DC8E177CF}) (Version: 12.2.1.16 - Apple Inc.)
JA2 Stracciatella (HKLM-x32\...\JA2 Stracciatella) (Version: 0.19.1-git+6ad1b6f - Humanity)
Jagged Alliance 2 (HKLM-x32\...\1207658696_is1) (Version: 1.12 - GOG.com)
James Bond 007 Blood Stone MULTi8 - ElAmigos version 76654 (HKLM-x32\...\{54D77124-93E2-4D58-8E20-C1CFA218927A}_is1) (Version: 76654 - Activision Blizzard)
Java 8 Update 181 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
John Wick Hex (HKLM-x32\...\John Wick Hex_is1) (Version: - )
Kingdom Come Deliverance - Royal Ed. (HKLM\...\Kingdom Come Deliverance - Royal Ed.) (Version: - )
Kits Configuration Installer (HKLM-x32\...\{C661B45B-1D2A-AF7C-27D0-B4FFD670A4FE}) (Version: 10.1.14393.0 - Microsoft) Hidden
K-Lite Codec Pack 14.1.0 Standard (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.1.0 - KLCP)
Knockout City (HKLM-x32\...\{C75F8E76-29EF-44D0-9762-4F6D65BF0111}) (Version: 1.1.0.0 - Electronic Arts, Inc.)
LatencyMon 7.00 (HKLM\...\LatencyMon_is1) (Version: - Resplendence Software Projects Sp.)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LAV Filters 0.74.1 (HKLM-x32\...\lavfilters_is1) (Version: 0.74.1 - Hendrik Leppkes)
Layers of Fear - Inheritance (HKLM-x32\...\1256894029_is1) (Version: 2.2.0.5 - GOG.com)
Layers of Fear (HKLM-x32\...\1455107123_is1) (Version: 2.3.0.7 - GOG.com)
Letasoft Sound Booster 1.11.0.514 (HKLM-x32\...\{6C6CF38B-11DD-45C6-A15E-A3A0C4CE60F8}_is1) (Version: 1.11.0.514 - Letasoft LLC)
Macrium Reflect Free Edition (HKLM\...\{3323C7F6-9CAD-4203-A264-79B834D82C53}) (Version: 7.3.5854 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 7.3 - Paramount Software (UK) Ltd.)
MadVR (remove only) (HKLM-x32\...\MadVR) (Version: - )
Malwarebytes version 4.6.0.277 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.0.277 - Malwarebytes)
Marvels Avengers (HKLM-x32\...\Marvels Avengers_is1) (Version: 0.0.0 - DODI-Repacks)
Media Preview (HKLM\...\{52AFC3E1-0FAA-4C05-88FF-373911EA68F5}) (Version: 1.4.3.429 - BabelSoft)
MediathekView 13.9.1 (HKLM\...\1927-5045-2127-3394) (Version: 13.9.1 - MediathekView Team)
MEmu (HKLM-x32\...\MEmu) (Version: 6.2.7.0 - Microvirt)
Microsoft .NET Host - 6.0.21 (x64) (HKLM\...\{26FF35F7-ADBB-4C9F-97DA-79120DB80EC6}) (Version: 48.87.64667 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.21 (x64) (HKLM\...\{D937EF87-F11D-4778-973C-B71E178F95D0}) (Version: 48.87.64667 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.21 (x64) (HKLM\...\{8D2EC92E-5903-4B25-9406-182B8EFA834F}) (Version: 48.87.64667 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 116.0.1938.69 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 116.0.1938.69 - Microsoft Corporation)
Microsoft GameInput (HKLM-x32\...\{1F2B6AF3-C260-8666-5950-E3FEDBC851D6}) (Version: 10.1.22621.3036 - Microsoft Corporation)
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (HKLM-x32\...\{90140000-0015-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (HKLM-x32\...\{90140000-0016-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (HKLM\...\{90140000-002A-0000-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (HKLM-x32\...\{90140000-00A1-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (HKLM-x32\...\{90140000-001F-0410-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (HKLM-x32\...\{90140000-002C-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (HKLM-x32\...\{90140000-0019-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (HKLM\...\{90140000-002A-0407-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (HKLM-x32\...\{90140000-006E-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (HKLM-x32\...\{90140000-001B-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\OneDriveSetup.exe) (Version: 23.169.0813.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{BB052C53-34CB-42DE-AF41-66FDFCEEC868}) (Version: 3.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{577ff5ba-39aa-4d8c-a3a9-f95012763438}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660 (HKLM-x32\...\{7DAD0258-515C-3DD4-8964-BD714199E0F7}) (Version: 12.0.40660 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660 (HKLM-x32\...\{E30D8B21-D82D-3211-82CC-0F0A5D1495E8}) (Version: 12.0.40660 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 (HKLM-x32\...\{8bdfe669-9705-4184-9368-db9ce581e0e7}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.22.27821 (HKLM-x32\...\{3BDE80F7-7EC9-448E-8160-4ADA0CDA8879}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29334 (HKLM-x32\...\{14C49FC8-3E9B-4F29-8526-26629B5CF30B}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.22.27821 (HKLM-x32\...\{1E6FC929-567E-4D22-9206-C5B83F0A21B9}) (Version: 14.22.27821 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29334 (HKLM-x32\...\{0D01A812-82A1-481F-8546-8E28E976F8DF}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532 (HKLM\...\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532 (HKLM\...\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}) (Version: 10.0.50908 - Microsoft Corporation) Hidden
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 2.11.63.5026 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 6.0.21 (x64) (HKLM\...\{AF6BF7DD-2B12-40C5-919C-2EC99054BBE1}) (Version: 48.87.64723 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.21 (x64) (HKLM-x32\...\{0f39db03-9030-48f3-82ef-5384bed81d85}) (Version: 6.0.21.32717 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
MiniTool Partition Wizard Free 12.6 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: 12.6 - MiniTool Software Limited)
MiniTool ShadowMaker PW Edition (HKLM-x32\...\MT-75D7C412-925B-4AD0-90DC-5E4FEE22EAE1_is1) (Version: 3.6 - MiniTool Software Limited)
Mirror's Edge™ Catalyst (HKLM-x32\...\{12228a0d-f6ad-4691-82af-d2c643424468}) (Version: 1.0.3.47248 - Electronic Arts)
Monster Hunter World: Iceborne (HKLM-x32\...\Monster Hunter World: Iceborne_is1) (Version: - )
Mozilla Firefox 72.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 72.0.2 (x64 en-US)) (Version: 72.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 57.0.2 - Mozilla)
MSI Afterburner 4.5.0 (HKLM-x32\...\Afterburner) (Version: 4.5.0 - MSI Co., LTD)
Mutant Year Zero - Road To Eden (HKLM-x32\...\{4DF4741F-8465-4AA8-9ABA-4B081F05FCAA}_is1) (Version: - The Bearded Ladies)
Need for Speed™ Heat (HKLM-x32\...\{8DA46384-7F54-4265-B90F-69BBC08DC3A1}) (Version: 1.0.60.7040 - Electronic Arts)
No Mans Sky (HKLM\...\No Mans Sky_is1) (Version: 3.05 - SE7EN Solutions)
NordUpdater (HKLM\...\{6E35DB82-3D19-4DD6-B8CB-F082815FDE18}_is1) (Version: 1.4.0.132 - Nord Security)
NordVPN (HKLM\...\{19465C24-3D5D-4327-B99F-3CC0A1D38151}_is1) (Version: 6.48.19.0 - Nord Security)
NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN)
Nox APP Player (HKLM-x32\...\Nox) (Version: 6.3.0.7 - Duodian Technology Co. Ltd.)
Npcap (HKLM-x32\...\NpcapInst) (Version: 1.71 - Nmap Project)
NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.27.0.112 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.27.0.112 - NVIDIA Corporation)
NVIDIA Graphics Driver 537.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 537.13 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.40.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.40.14 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)
Observer (HKLM-x32\...\1449856523_is1) (Version: 1.0 - GOG.com)
One Piece Pirate Warriors 3: GOLD Edition (HKLM-x32\...\One Piece Pirate Warriors 3: GOLD Edition_is1) (Version: - )
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Ori and The Blind Forest - Definitive Edition (HKLM-x32\...\1384944984_is1) (Version: 2.0.0.2 - GOG.com)
Origin (HKLM-x32\...\Origin) (Version: 10.5.112.50486 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{af79dd32-90cb-4e63-ae56-a4d22f33921d}) (Version: latest - ppy Pty Ltd)
Overlay (HKLM-x32\...\1430742867_is1) (Version: 1.32 - GOG.com)
Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)
Owlboy (HKLM-x32\...\1159880091_is1) (Version: 1.3.6570.26602 - GOG.com)
Paradox Launcher v2 (HKLM\...\{A92DB5D9-A24D-4678-9F91-B4FA6D895718}) (Version: 2.0.4.0 - Paradox Interactive)
Photo Pos Pro 3 (HKLM\...\Photo Pos Pro 3) (Version: 3.30 - PowerOfSoftware Ltd.)
PlayStation Plus (HKLM-x32\...\{F86E19EB-C781-4A23-B764-6B397BC18BA1}) (Version: 12.2.0 - Sony Interactive Entertainment Inc.)
PowerToys (Preview) (HKLM\...\{06F18418-D1F4-4C41-A45A-DA86079A9823}) (Version: 0.64.0 - Microsoft Corporation) Hidden
PowerToys (Preview) x64 (HKLM-x32\...\{5aed9284-1ef0-4dbe-86f4-64b4731b508c}) (Version: 0.64.0 - Microsoft Corporation)
Private Internet Access v81 (HKLM-x32\...\{148169C2-5558-4C3E-B38A-7B1813A264CA}_is1) (Version: 81 - London Trust Media, Inc.)
Project Highrise MULTi6 - ElAmigos version 1.5.9.2 (HKLM-x32\...\{383D8816-459E-43F5-B788-98C32D3B99F4}_is1) (Version: 1.5.9.2 - Kasedo Games)
Project Hospital (HKLM-x32\...\1660194629_is1) (Version: 1.0.14224 RC4 - GOG.com)
PS Remote Play (HKLM-x32\...\{3A3A09F0-36EC-4CDD-BAA5-98BC05815E3C}) (Version: 5.5.0.08250 - Sony Interactive Entertainment Inc.)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
QTTabBar ver 2048 (HKLM\...\{13016E80-C7E5-4610-B149-FA8381CEE008}) (Version: 0.9.0 - Quizo)
Quantum Break (HKLM-x32\...\Quantum Break_is1) (Version: - )
Rayman Legends (HKLM-x32\...\Uplay Install 410) (Version: - Ubisoft)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.21.1 - Razer Inc.)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9079.1 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0037 - Realtek)
Rebel Galaxy Outlaw MULTi5 - ElAmigos version 1.17 (HKLM-x32\...\{E69E45AE-023B-4271-99D4-9EB93DA86644}_is1) (Version: 1.17 - Double Damage Games)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Regiments (HKLM-x32\...\Regiments_is1) (Version: - )
Resident Evil 2 (HKLM-x32\...\Resident Evil 2_is1) (Version: - )
RetroArch (HKLM-x32\...\RetroArch) (Version: 1.15.0.0 - Libretro)
ROCCAT SWARM (HKLM-x32\...\{E9CA669A-8FB1-4F3D-A771-2E0767D20F89}) (Version: 1.94.430 - ROCCAT GmbH) Hidden
ROCCAT SWARM (HKLM-x32\...\InstallShield_{E9CA669A-8FB1-4F3D-A771-2E0767D20F89}) (Version: 1.94.430 - ROCCAT GmbH)
ScummVM 2.0.0 (HKLM-x32\...\ScummVM_is1) (Version: 2.0.0 - The ScummVM Team)
Sekiro Shadows Die Twice MULTi13 - ElAmigos version 1.02 (HKLM-x32\...\{93A98F06-2B86-4F97-AAF2-A44AEB1E2C29}_is1) (Version: 1.02 - FromSoftware)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{8925227F-C7B5-4C95-AB58-4FCF2433DAEE}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{09A9DF49-DA06-4093-A2FD-F339211E39EA}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{ECC1D579-DC17-4B90-929C-B4A0BB35F7B3}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{97099817-53F1-4CA1-ACEA-DA6D74371689}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{E4D76E88-C65F-4003-9C71-EC4306679D17}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{3B0FF7FF-0E85-4907-A511-3F8C27349FA4}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{996096F8-956B-41C9-A7E3-9BA1E801014F}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{D505EC85-885F-4BE3-8A89-3EFE4F855692}) (Version: - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{6B42CFAF-AA3D-478E-9B2F-A03225709EE3}) (Version: - Microsoft) Hidden
Shadow Tactics (HKLM-x32\...\Shadow Tactics_is1) (Version: - )
Shantae Half Genie Hero Ultimate Edition (HKLM-x32\...\Shantae Half Genie Hero Ultimate Edition_is1) (Version: - )
Shovel Knight: Treasure Trove (HKLM-x32\...\1207664823_is1) (Version: 4.0A - GOG.com)
Signal 6.28.0 (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\7d96caee-06e6-597c-9f2f-c7bb2e0948b4) (Version: 6.28.0 - Signal Messenger, LLC)
Snake Pass MULTi5 - ElAmigos version 1.4 (HKLM-x32\...\{853FF7F2-9B65-4570-92E7-79386CB935B0}_is1) (Version: 1.4 - Sumo Digital)
SoundWire Server version 2.1.2 (HKLM-x32\...\{E15658BC-7742-4397-999F-98B1BD11B784}_is1) (Version: 2.1.2 - GeorgieLabs)
Star Control: Origins (HKLM-x32\...\1893867643_is1) (Version: 1.00.52584 - GOG.com)
STAR WARS Jedi - Fallen Order™ (HKLM-x32\...\{D00A89F1-2D8C-4589-B1D1-73A6544E3B1F}) (Version: 1.0.10.0 - Electronic Arts, Inc.)
STAR WARS™ Battlefront™ II (HKLM-x32\...\{8a882ce0-0c0b-4eb2-850c-28ebadab4f50}) (Version: 1.1.7.22040 - Electronic Arts)
StarCraft (HKLM-x32\...\StarCraft) (Version: - Blizzard Entertainment)
Stardew Valley - ElAmigos version 1.2.33 (HKLM-x32\...\{B798256B-8466-4DB5-A6A9-6A2C80B40D25}_is1) (Version: 1.2.33 - Chucklefish)
Starsector by Fractal Softworks LLC (HKLM-x32\...\Starsector) (Version: - )
Streets of Rage 4 (HKLM\...\Streets of Rage 4_is1) (Version: Build 10731343 - )
Summer in Mara (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\Summer in Mara) (Version: - HOODLUM)
Sundered Eldritch Edition (HKLM-x32\...\Sundered Eldritch Edition_is1) (Version: - )
Sunset Overdrive (HKLM-x32\...\Sunset Overdrive_is1) (Version: - )
System Shock: Remake (HKLM-x32\...\System Shock: Remake_is1) (Version: - )
TeamViewer (HKLM\...\TeamViewer) (Version: 15.38.3 - TeamViewer)
TechPowerUp GPU-Z (HKLM-x32\...\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1) (Version: 2.52.0 - TechPowerUp)
TECKNET wireless gaming mouse version 1.0.0.7 (HKLM-x32\...\TECKNET wireless gaming mouse_is1) (Version: - )
The Binding of Isaac Rebirth MULTi3 - ElAmigos version 30.04.2018 (HKLM-x32\...\{16FA778B-E5D3-43A3-80A4-D043BCF67090}_is1) (Version: 30.04.2018 - Nicalis, Inc.)
The Crew 2 (HKLM-x32\...\Uplay Install 2855) (Version: - Ubisoft)
The Hong Kong Massacre (HKLM-x32\...\The Hong Kong Massacre_is1) (Version: - )
The Legend of Zelda: BotW (HKLM-x32\...\The Legend of Zelda: BotW_is1) (Version: - )
The Lord of the Rings Online™ v2305.0061.1867.4359 (HKLM-x32\...\12bbe590-c890-11d9-9669-0800200c9a66_is1) (Version: 2305.0061.1867.4359 - Standing Stone Games, LLC)
The Sims 4 (HKLM-x32\...\The Sims 4_is1) (Version: - )
The Ultimate DOOM (HKLM-x32\...\1435827232_is1) (Version: 2.0.0.3 - GOG.com)
The Witcher 3: Wild Hunt - Blood and Wine (HKLM-x32\...\Blood and Wine_is1) (Version: 1.24.0.0 - GOG.com)
The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.24.0.0 - GOG.com)
The Witcher 3: Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.32 - GOG.com)
Titanfall™ 2 (HKLM-x32\...\{4BD80373-FEE7-45B6-8249-6E8E98717405}) (Version: 1.0.1.3 - Electronic Arts, Inc.)
Tom Clancy Ghost Recon Wildlands (HKLM-x32\...\Tom Clancy Ghost Recon Wildlands_is1) (Version: 1.6.0 - THE KNIGHT)
Toolkit Documentation (HKLM-x32\...\{6143A694-5FE1-BDF6-F78E-4F7BF3E9419B}) (Version: 10.1.14393.0 - Microsoft) Hidden
Total War Three Kingdoms (HKLM-x32\...\Total War Three Kingdoms_is1) (Version: - )
Towerfall - Ascension - Dark World (HKLM-x32\...\1431078929_is1) (Version: 2.4.0.5 - GOG.com)
Towerfall - Ascension (HKLM-x32\...\1430924174_is1) (Version: 2.5.0.6 - GOG.com)
Trails from Zero (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\ED_ZERO) (Version: - )
Trilogy Save Editor version 2.2.1 (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\{6A0B979E-271B-4E50-A4C3-487C8E584070}_is1) (Version: 2.2.1 - Karlitos)
Two Point Hospital (HKLM-x32\...\Two Point Hospital_is1) (Version: - )
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 104.1 - Ubisoft)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
UE4 Prerequisites (x64) (HKLM\...\{36EAD5CF-44EF-4FCF-8BE1-D96C4835D7A4}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden
UE4 Prerequisites (x64) (HKLM-x32\...\{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden
UEV Tools on amd64 (HKLM\...\{1454FA4E-58BC-2EF1-9A19-147B0E499E03}) (Version: 10.1.14393.0 - Microsoft) Hidden
Unravel™ (HKLM-x32\...\{5105E605-9EE7-4050-9CC0-005093BBF89A}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{C270D21B-2327-49B8-85F7-395133A93C75}) (Version: 8.92.0.0 - Microsoft Corporation)
USBPcap 1.5.4.0 (HKLM\...\USBPcap) (Version: 1.5.4.0 - Tomasz Mon)
User State Migration Tool (HKLM-x32\...\{F7AADEDA-233A-1079-CD15-03AEB050F0C6}) (Version: 10.1.14393.0 - Microsoft) Hidden
VdhCoApp 1.2.4 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version: - DownloadHelper)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.16 - VideoLAN)
Vortex (HKLM\...\57979c68-f490-55b8-8fed-8b017a5af2fe) (Version: 1.8.5 - Black Tree Gaming Ltd.)
Warhammer 40000 Mechanicus (HKLM-x32\...\Warhammer 40000 Mechanicus_is1) (Version: - )
Watch Dogs 2 (HKLM-x32\...\Watch Dogs 2_is1) (Version: - )
WhoCrashed 7.00 (HKLM\...\WhoCrashed_is1) (Version: 7.00 - Resplendence Software Projects Sp.)
WhySoSlow 1.61 (HKLM\...\WhySoSlowHome_is1) (Version: - Resplendence Software Projects Sp.)
Windows Assessment and Deployment Kit - Windows 10 (HKLM-x32\...\{39ebb79f-797c-418f-b329-97cfdf92b7ab}) (Version: 10.1.14393.0 - Microsoft Corporation)
Windows Assessment Toolkit (AMD64 Architecture Specific) (HKLM-x32\...\{91361B2A-F741-E591-303B-4EF957F3BAF1}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows Assessment Toolkit (HKLM-x32\...\{F4EBF948-F00E-29EF-894C-D10A718F981D}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows Deployment Customizations (HKLM-x32\...\{9D550F66-5D52-29CA-28B5-EE0C2C0CDFBE}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows Deployment Tools (HKLM-x32\...\{52EA560E-E50F-DC8F-146D-1B631548BA29}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows PC Health Check (HKLM\...\{77ACFAF7-E5AB-410D-BA14-BBEBF89422DE}) (Version: 3.1.2109.29003 - Microsoft Corporation)
Windows PE x86 x64 (HKLM-x32\...\{230524D3-ADB4-69CC-2A78-96D879E3221B}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows PE x86 x64 wims (HKLM-x32\...\{47AEE104-BF96-E407-D3FE-80BBD42732F4}) (Version: 10.1.14393.0 - Microsoft) Hidden
Windows Phone Common Packaging and Test Tools (NT_x86_fre) (HKLM-x32\...\{4D989432-59D7-76A0-DD51-B96422F6FF7F}) (Version: 10.1.14393.0 - Microsoft Corporation) Hidden
Windows System Image Manager on amd64 (HKLM-x32\...\{363D76EC-B5B9-5D7B-0F59-C193FF6F03FC}) (Version: 10.1.14393.0 - Microsoft) Hidden
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
Wireshark 4.0.8 64-bit (HKLM-x32\...\Wireshark) (Version: 4.0.8 - The Wireshark developer community, hxxps://www.wireshark.org)
Wolfenstein: The Old Blood (HKLM-x32\...\Wolfenstein: The Old Blood_is1) (Version: - )
WORLD OF FINAL FANTASY MAXIMA (HKLM-x32\...\WORLD OF FINAL FANTASY MAXIMA_is1) (Version: - )
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
WPT Redistributables (HKLM-x32\...\{549DAD2D-2505-204C-EC58-59807FE6E037}) (Version: 10.1.14393.0 - Microsoft) Hidden
WPTx64 (HKLM-x32\...\{97B6FAD9-6F14-CC46-3165-F1785ECCE255}) (Version: 10.1.14393.0 - Microsoft) Hidden
XnViewMP 1.00.0 (HKLM\...\XnViewMP_is1) (Version: 1.00.0 - Gougelet Pierre-e)
ZeroLauncher (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\54166643f5cdc960) (Version: 1.0.1.0 - HP Inc.)
ZeroLauncher (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\d6b1847d788880db) (Version: 1.0.2.411 - Geofront)
ZoneAlarm Firewall (HKLM-x32\...\{F21C5C41-E759-472F-B5AE-501AC583B693}) (Version: 15.0.653.17211 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Free Firewall (HKLM-x32\...\ZoneAlarm Free Firewall) (Version: 15.0.653.17211 - Check Point)
ZoneAlarm Security (HKLM-x32\...\{06F804D0-A69C-423A-8F77-A158EA7DF295}) (Version: 15.0.653.17211 - Check Point Software Technologies Ltd.) Hidden
Zoom (HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\ZoomUMX) (Version: 5.9.3 (3169) - Zoom Video Communications, Inc.)
Zoom Player (remove only) (HKLM-x32\...\ZoomPlayer) (Version: - )
Zotero Standalone 4.0.29.17 (x86 en-US) (HKLM-x32\...\Zotero Standalone 4.0.29.17 (x86 en-US)) (Version: 4.0.29.17 - Zotero)
Packages:
=========
Amazon Alexa -> C:\Program Files\WindowsApps\57540AMZNMobileLLC.AmazonAlexa_3.25.1177.0_x64__22t9g3sebte08 [2023-08-03] (AMZN Mobile LLC.) [Startup Task]
art of rally -> C:\Program Files\WindowsApps\Mutable\Funselektor.artofrally_1.0.11.0_x64__43tswnvjm2gzr [2023-01-16] (Funselektor Labs Inc.)
Atomic Heart -> C:\Program Files\WindowsApps\FocusHomeInteractiveSA.579645D26CFD_1.10.1.0_x64__4hny5m903y3g0 [2023-09-02] (Focus Home Interactive SA)
Audiobooks from Audible -> C:\Program Files\WindowsApps\AudibleInc.AudibleforWindowsPhone_10.5.67.0_x64__xns73kv1ymhp2 [2023-02-14] (Audible Inc)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.250.400.0_x64__kgqvnymyfvs32 [2023-08-25] (king.com)
Carrion -> C:\Program Files\WindowsApps\DevolverDigital.CarrionWin10_1.0.14.0_x64__6kzv4j18v0c96 [2021-10-27] (Devolver Digital)
Children of Morta -> C:\Program Files\WindowsApps\11bitstudios.12487E5DA4D9B_1.0.17.2_x64__gwy9gn5q9j1y6 [2021-10-08] (11 bit studios)
Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe [2023-08-10] (Microsoft Corporation)
Crusader Kings III -> C:\Program Files\WindowsApps\ParadoxInteractive.ProjectTitus_1.0.526.0_x64__zfnrdv2de78ny [2023-08-31] (Paradox Interactive)
Death's Door Win10 -> C:\Program Files\WindowsApps\DevolverDigital.DeathsDoorWin10_1.0.6.0_x64__6kzv4j18v0c96 [2022-01-25] (Devolver Digital)
Death's Gambit -> C:\Program Files\WindowsApps\CartoonInteractiveGroupIn.DeathsGambit_1.0.0.0_x64__6c1aaymwt3dwm [2020-02-15] (Cartoon Interactive Group Inc.)
DEMON'S TILT -> C:\Program Files\WindowsApps\FLARBLLC.57668A550983B_1.4.30.0_x64__hvfnz2ebz1aje [2020-10-25] (FLARB LLC)
Dishonored® Definitive Edition (PC) -> C:\Program Files\WindowsApps\BethesdaSoftworks.DishonoredDE-PC_1.10.0.0_x64__3275kfvn8vcwc [2022-11-06] (Bethesda Softworks)
Disney+ -> C:\Program Files\WindowsApps\Disney.37853FC22B2CE_1.57.3.0_x64__6rarf9sa4v8jt [2023-08-10] (Disney)
DJMAX RESPECT V -> C:\Program Files\WindowsApps\Neowiz.DJMAXRESPECTV_1.6872.2507.0_x64__r4z3116tdh636 [2023-06-22] (NEOWIZ)
Doom Eternal - PC -> C:\Program Files\WindowsApps\BethesdaSoftworks.DOOMEternal-PC_1.0.17.0_x64__3275kfvn8vcwc [2022-04-27] (Bethesda Softworks)
DOOM Eternal: Campaign -> C:\Program Files\WindowsApps\BethesdaSoftworks.DOOMEternalCampaignPC_1.0.1.0_x64__3275kfvn8vcwc [2020-12-08] (Bethesda Softworks)
Dropbox Lite -> C:\Program Files\WindowsApps\C27EB4BA.DROPBOX_23.4.20.0_x64__xbfy0k16fey96 [2023-09-02] (Dropbox Inc.)
Eiyuden Chronicle: Rising -> C:\Program Files\WindowsApps\505GAMESS.P.A.EiyudenChronicleRising_1.0.16.0_x64__tefn33qh9azfc [2022-06-21] (505 GAMES S.P.A.)
EVERSPACE™ 2 -> C:\Program Files\WindowsApps\ROCKFISHGames.EVERSPACE2_1.0.35328.0_x64__wm11qtfe9fmzj [2023-08-30] (ROCKFISH Games)
Exo One -> C:\Program Files\WindowsApps\FutureFriendsGames.ExoOne_1.2.1.0_x64__2whsqx9fyfsdj [2022-03-31] (Future Friends Games)
Forza Horizon 3 -> C:\Program Files\WindowsApps\Microsoft.OpusPG_1.0.125.2_x64__8wekyb3d8bbwe [2020-08-18] (Microsoft Studios)
Forza Horizon 4 -> C:\Program Files\WindowsApps\Microsoft.SunriseBaseGame_1.477.714.2_x64__8wekyb3d8bbwe [2023-04-10] (Microsoft Studios)
Forza Horizon 5 -> C:\Program Files\WindowsApps\Microsoft.624F8B84B80_3.607.493.0_x64__8wekyb3d8bbwe [2023-08-15] (Microsoft Studios)
Gears of War 4 -> C:\Program Files\WindowsApps\Microsoft.SpartaUWP_14.4.0.2_x64__8wekyb3d8bbwe [2019-07-11] (Microsoft Studios)
GUILTY GEAR STRIVE -> C:\Program Files\WindowsApps\asw-akiyama.GUILTYGEARSTRIVE_1.0.8.0_x64__krnzms20jbb38 [2023-09-04] (ARC SYSTEM WORKS)
Halo -> C:\Program Files\WindowsApps\Microsoft.Tomp_1.0.4723.0_x64__8wekyb3d8bbwe [2023-02-14] (Microsoft Studios)
Halo Infinite -> C:\Program Files\WindowsApps\Microsoft.254428597CFE2_1.3871.53028.0_x64__8wekyb3d8bbwe [2023-08-10] (Microsoft Studios)
Halo: Spartan Assault -> C:\Program Files\WindowsApps\Microsoft.HaloSpartanAssault_1.5.0.0_x86__8wekyb3d8bbwe [2019-12-29] (Microsoft Studios)
Halo: The Master Chief Collection -> C:\Program Files\WindowsApps\Mutable\Microsoft.Chelan_1.3251.0.0_x64__8wekyb3d8bbwe [2023-07-20] (Microsoft Studios)
Hardspace: Shipbreaker -> C:\Program Files\WindowsApps\FocusHomeInteractiveSA.HardspaceShipbreaker-PCVers_1.0.35.0_x64__4hny5m903y3g0 [2022-11-18] (Focus Home Interactive SA)
Hi-Fi RUSH -> C:\Program Files\WindowsApps\BethesdaSoftworks.Hibiki_1.6.0.0_x64__3275kfvn8vcwc [2023-07-05] (Bethesda Softworks)
Hollow Knight -> C:\Program Files\WindowsApps\TeamCherry.15373CD61C66B_5.80.11835.0_x64__y4jvztpgccj42 [2022-11-09] (Team Cherry)
HOT WHEELS UNLEASHED™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSUNLEASHED-WindowsEdition_1.0.6.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone s.r.l.)
HOT WHEELS™ - AcceleRacers Bassline™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC19_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - AcceleRacers Deora™ II -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC14_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - AcceleRacers Hollowback™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC44_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - AcceleRacers Power Rage™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC29_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Aston Martin DB5 1963 -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC08_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Barbie™ Dream Camper™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC22_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Batman Expansion -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC17_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Beefed Up Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC01_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Bone Shaker™ Unleashed Edition -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC03_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Booster Slam Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC28_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Classic Packard -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC64_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Corvette Stingray Convertible 2014 -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC35_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Cyberpunk Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC47_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Dinopult Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC21_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Gorilla Garage Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC34_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Haunted Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC40_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - He-Man™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC50_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Holiday Season Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC18_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Hot Rod Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC61_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Jumping Towers Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC49_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Looney Tunes Expansion -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC54_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - McLaren 720S -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC65_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - McLaren Senna -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC36_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Monster Trucks Expansion -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC39_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Outer Space Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC26_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Pink Fashion Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC11_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Retro Game Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC55_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Rolling Boulders Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC06_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Shark Jaws Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC42_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Skaters Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC32_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Skeletor™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC58_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Spinning Tire Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC20_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Sportscars Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC00_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Beasts™ Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC02_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Fighter Blanka -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC12_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Fighter Chun-Li -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC30_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Fighter M. Bison -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC05_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Fighter Ryu -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC41_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Street Fighter Vega -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC33_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Super Dealership Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC63_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Superman™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC07_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Swamp Thing™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC59_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - The Jetsons™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC62_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - The Mystery Machine™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC51_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - TMNT Donatello -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC48_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - TMNT Leonardo -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC15_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - TMNT Michelangelo -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC27_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - TMNT Raphael -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC43_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - TMNT Shredder -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC56_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Tropical Wave Customization Pack -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC04_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Wonder Woman™ -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC13_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HOT WHEELS™ - Zero Gravity Checkpoint Module -> C:\Program Files\WindowsApps\MilestoneS.r.l.HOTWHEELSGDK-DLC57_1.0.0.0_x64__h6vxh15j4wapt [2023-02-07] (Milestone S.r.l.)
HP Scan and Capture -> C:\Program Files\WindowsApps\AD2F1837.HPScanandCapture_40.0.245.0_x64__v10z8vjag6ke6 [2023-01-17] (Hewlett-Packard Company)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_148.2.1069.0_x64__v10z8vjag6ke6 [2023-08-08] (HP Inc.)
Insurgency: Sandstorm - Windows -> C:\Program Files\WindowsApps\FocusHomeInteractiveSA.3806953BAE050_1.8.3.0_x64__4hny5m903y3g0 [2023-07-12] (Focus Home Interactive SA)
Kathy Rain -> C:\Program Files\WindowsApps\RawFury.1107399377650_1.0.9.0_x86__9s0pnehqffj7t [2020-09-24] (Raw Fury)
Lonely Mountains: Downhill -> C:\Program Files\WindowsApps\Thunderful.LonelyMontainsDownhill_1.5.2.0_x64__8j53pwgd019sy [2023-03-13] (Thunderful Publishing AB)
Metal: Hellsinger -> C:\Program Files\WindowsApps\FuncomOsloAS.ProjectHammerhead_1.6.8726.0_x64__pkaskhy6cdq4g [2023-06-21] (Funcom Oslo AS)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2021-03-15] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-03-15] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-03-15] (Microsoft Corporation) [MS Ad]
Microsoft Flight Simulator -> C:\Program Files\WindowsApps\Microsoft.FlightSimulator_1.33.8.0_x64__8wekyb3d8bbwe [2023-06-22] (Microsoft Studios)
Microsoft Flight Simulator Digital Ownership -> C:\Program Files\WindowsApps\Microsoft.DigitalOwnership_1.0.1.0_x64__8wekyb3d8bbwe [2021-06-01] (Microsoft Studios)
Microsoft Jigsaw -> C:\Program Files\WindowsApps\Microsoft.MicrosoftJigsaw_2.6.8211.0_x86__8wekyb3d8bbwe [2023-08-28] (Microsoft Studios)
Microsoft Minesweeper -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMinesweeper_4.4.7101.0_x64__8wekyb3d8bbwe [2023-07-26] (Microsoft Studios) [MS Ad]
Microsoft Sudoku -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSudoku_2.8.10203.0_x64__8wekyb3d8bbwe [2023-02-14] (Microsoft Studios) [MS Ad]
Microsoft Ultimate Word Games -> C:\Program Files\WindowsApps\Microsoft.Studios.Wordament_3.8.904.0_x64__8wekyb3d8bbwe [2023-02-14] (Microsoft Studios) [MS Ad]
Midnight Fight Express -> C:\Program Files\WindowsApps\HumbleBundle.MidnightFightExpress_1.1.1.0_x64__q2mcdwmzx4qja [2022-11-04] (Humble Bundle)
Mighty Goose -> C:\Program Files\WindowsApps\ActiveGamingMediaInc.MightyGoose_1.0.4.0_x64__4tj796bhrrsp0 [2021-10-02] (Active Gaming Media Inc.)
Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.20.1501.0_x64__8wekyb3d8bbwe [2023-08-17] (Microsoft Studios)
Mystery Manor: Hidden Objects -> C:\Program Files\WindowsApps\0EB8BD08.MysteryManorhiddenobjects_6.220.0.0_x86__erk4rrwmt7jyt [2023-08-30] (GAME INSIGHT UAB)
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-02-18] (Netflix, Inc.)
Night Call -> C:\Program Files\WindowsApps\RawFury.NightCallWIN10_1.3.6.0_x64__9s0pnehqffj7t [2021-08-26] (Raw Fury)
NORCO -> C:\Program Files\WindowsApps\RawFury.NORCO_1.4.7.0_x64__9s0pnehqffj7t [2023-02-23] (Raw Fury)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.964.0_x64__56jybvy8sckqj [2023-09-03] (NVIDIA Corp.)
ORF-TVthek -> C:\Program Files\WindowsApps\ORFsterreichischerRundfun.ORF-TVthek_3.5.0.0_x64__dzzx7e9x33sct [2023-02-14] (Österreichischer Rundfunk ORF)
PAC-MAN MUSEUM+ -> C:\Program Files\WindowsApps\NAMCOBANDAIGamesInc.PACMANMUSEUMPLUS_1.0.5.0_x64__gdy2aq6ez762w [2022-12-07] (BANDAI NAMCO Entertainment Inc.)
Penbook -> C:\Program Files\WindowsApps\36376UserCamp.Penbook_2.1.30.0_x64__t7afzrbtd67z0 [2023-02-14] (User Camp)
Pentiment -> C:\Program Files\WindowsApps\Microsoft.OE-Missouri_1.2.1713.0_x64__8wekyb3d8bbwe [2023-05-31] (Microsoft Studios)
Persona 5 Royal -> C:\Program Files\WindowsApps\SEGAofAmericaInc.F0cb6b3aer_1.10.27.0_x64_USEU_s751p9cej88mt [2023-01-12] (SEGA of America, Inc.)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation)
Prime Video for Windows -> C:\Program Files\WindowsApps\AmazonVideo.PrimeVideo_1.0.148.0_x64__pwbj9vvecjh7j [2023-09-03] (Amazon Development Centre (London) Ltd)
Project Wingman -> C:\Program Files\WindowsApps\HumbleBundle.ProjectWingman_0.6.12.0_x64__q2mcdwmzx4qja [2022-09-15] (Humble Bundle)
QUAKE -> C:\Program Files\WindowsApps\BethesdaSoftworks.ProjectSilver_1.0.5237.0_x64__3275kfvn8vcwc [2022-09-29] (Bethesda Softworks)
Quake 3 -> C:\Program Files\WindowsApps\Mutable\BethesdaSoftworks.Quake3_1.0.0.0_x86__3275kfvn8vcwc [2021-08-23] (Bethesda Softworks)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.20.238.0_x64__dt26b99r8h8gj [2023-08-28] (Realtek Semiconductor Corp)
River City Girls -> C:\Program Files\WindowsApps\6151WayForward.RiverCityGirlsPC_1.0.8.2_x64__38xd6w9je1dae [2023-02-14] (WayForward)
Royal Revolt 2 -> C:\Program Files\WindowsApps\flaregamesGmbH.RoyalRevolt2_9.2.2.0_x86__g0q0z3kw54rap [2023-08-10] (flaregames GmbH)
Ryza Roads -> C:\Program Files\WindowsApps\553FelipeFidelis.RyzaRoads_1.1.84.0_x64__4ganz59kg4aby [2023-02-14] (Felipe Godoy)
Serious Sam 4 -> C:\Program Files\WindowsApps\DevolverDigital.SeriousSam4Win10_1.0.8.0_x64__6kzv4j18v0c96 [2023-02-12] (Devolver Digital)
Solasta -> C:\Program Files\WindowsApps\TacticalAdventures.SolastaCOTM_1.5.94.0_x64__q0c2rn28zyrv4 [2023-07-18] (Tactical Adventures)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.17.8180.0_x64__8wekyb3d8bbwe [2023-09-03] (Microsoft Studios) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.219.941.0_x64__zpdnekdrzrea0 [2023-08-31] (Spotify AB) [Startup Task]
Teenage Mutant Ninja Turtles: Shredder's Revenge -> C:\Program Files\WindowsApps\DotEmu.TeenageMutantNinjaTurtlesShreddersRevenge_1.2307.27.0_x64__map6zyh9ym1xy [2023-09-02] (DotEmu)
Tetris® Effect: Connected -> C:\Program Files\WindowsApps\48710EnhanceIncorporated.TRIP2.0_2.0.20.0_x64__63vy8jfbpt4dt [2023-05-31] (Enhance Incorporated)
The Legend of Tianding -> C:\Program Files\WindowsApps\AnotherIndie.TheLegendofTianding_1.1.11.0_x64__zrgg4v79ydekg [2023-04-05] (Another Indie)
The Master Chief Collection: Halo 3 -> C:\Program Files\WindowsApps\Microsoft.MCCHalo3_1.12.0.0_x64__8wekyb3d8bbwe [2020-07-27] (Microsoft Studios)
The Master Chief Collection: Halo CE -> C:\Program Files\WindowsApps\Microsoft.HaloCombatEvolved_1.1367.0.0_x64__8wekyb3d8bbwe [2020-03-03] (Microsoft Studios)
The Master Chief Collection: REACH -> C:\Program Files\WindowsApps\Microsoft.TheMasterChiefCollectionREACH_1.1.0.0_x64__8wekyb3d8bbwe [2019-12-04] (Microsoft Studios)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2021-06-14] (Twitter Inc.)
Windjammers 2 -> C:\Program Files\WindowsApps\DotEmu.Windjammers2_22.3.24.0_x64__map6zyh9ym1xy [2022-03-29] (DotEmu)
Wolfenstein: The Old Blood (PC) -> C:\Program Files\WindowsApps\BethesdaSoftworks.WolfensteinTOB-PC_1.19.2.0_x64__3275kfvn8vcwc [2022-05-14] (Bethesda Softworks)
WWE Network -> C:\Program Files\WindowsApps\6FA0E4A0.WWENetwork_4.42.43.0_x64__46xvzjh8v0pjy [2020-05-13] (World Wrestling Entertainment Inc.)
Xbox Accessories -> C:\Program Files\WindowsApps\Microsoft.XboxDevices_2209.2209.14005.0_x64__8wekyb3d8bbwe [2022-09-26] (Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{36B27788-A8BB-4698-A756-DF9F11F64F84}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.SvgThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{3f5d0051-61b8-0f45-6166-996cfb4f914f}\localserver32 -> C:\Program Files\PowerToys\modules\launcher\PowerToys.PowerLauncher.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{45769bcc-e8fd-42d0-947e-02beef77a1f5}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.MarkdownPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{8BC8AFC2-4E7C-4695-818E-8C1FFDCEA2AF}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.StlThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{afbd5a44-2520-4ae0-9224-6cfce8fe4400}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.MonacoPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{BFEE99B4-B74D-4348-BCA5-E757029647FF}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.GcodeThumbnailProvider.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{ddee2b8a-6807-48a6-bb20-2338174ff779}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.SvgPreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3615177999-3261653453-3779512466-1001_Classes\CLSID\{ec52dea8-7c9f-4130-a77b-1737d0418507}\InprocServer32 -> C:\Program Files\PowerToys\modules\FileExplorerPreview\PowerToys.GcodePreviewHandler.comhost.dll (Microsoft Corporation -> Microsoft Corporation)
ShellExecuteHooks: QTTabBarLib.ExplorerProcessCaptor - {D2BF470E-ED1C-487F-AAAA-2BD8835EB6CE} - C:\Windows\System32\mscoree.dll [383488 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
ShellExecuteHooks-x32: QTTabBarLib.ExplorerProcessCaptor - {D2BF470E-ED1C-487F-AAAA-2BD8835EB6CE} - C:\Windows\SysWOW64\mscoree.dll [314880 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
ContextMenuHandlers1-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2019-09-20] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [ContextMenu] -> {ee10d625-cc60-30a4-b3df-4b349785be6b} => C:\Program Files (x86)\Avira\Security\Antivirus.ContextMenu\Antivirus.ContextMenu.DLL -> No File
ContextMenuHandlers2: [FileLocksmithExt] -> {84D68575-E186-46AD-B0CB-BAEB45EE29C0} => C:\Program Files\PowerToys\modules\FileLocksmith\PowerToys.FileLocksmithExt.dll [2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2019-09-20] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ContextMenuHandlers3: [ContextMenu] -> {ee10d625-cc60-30a4-b3df-4b349785be6b} => C:\Program Files (x86)\Avira\Security\Antivirus.ContextMenu\Antivirus.ContextMenu.DLL -> No File
ContextMenuHandlers3: [FileLocksmithExt] -> {84D68575-E186-46AD-B0CB-BAEB45EE29C0} => C:\Program Files\PowerToys\modules\FileLocksmith\PowerToys.FileLocksmithExt.dll [2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-03-03] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers3: [PowerRenameExt] -> {0440049F-D1DC-4E46-B27B-98393D79486B} => C:\Program Files\PowerToys\modules\PowerRename\PowerToys.PowerRenameExt.dll [2022-11-02] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers4: [ZPShellExt] -> {ABE00001-0123-ABED-1248-0248ADFA1909} => C:\Program Files (x86)\Zoom Player\zpshlext64.dll [2008-08-05] () [File not signed]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3828c822366e497\nvshext.dll [2023-08-16] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-03-03] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\system32\frapsv64.dll [105984 2015-09-05] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\SysWOW64\ff_vfw.dll [112640 2014-02-09] () [File not signed]
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [94208 2015-09-05] (Beepa P/L) [File not signed]
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\aluca\Desktop\TikTok.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=nlalbmkafgmoifbeooblidblkmlhhpnc
ShortcutWithArgument: C:\Users\aluca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\TikTok.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=nlalbmkafgmoifbeooblidblkmlhhpnc
ShortcutWithArgument: C:\Users\aluca\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\ca79330482c36bc6\Checker Plus for Google Calendar™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hkhggnncdpfibdhinjiegagmopldibha
==================== Loaded Modules (Whitelisted) =============
2023-08-14 13:47 - 2023-08-09 01:46 - 004684288 _____ () [File not signed] \\?\C:\Users\aluca\AppData\Local\Programs\signal-desktop\resources\app.asar.unpacked\node_modules\@signalapp\better-sqlite3\build\Release\better_sqlite3.node
2023-08-14 13:47 - 2023-08-09 01:46 - 004961792 _____ () [File not signed] \\?\C:\Users\aluca\AppData\Local\Programs\signal-desktop\resources\app.asar.unpacked\node_modules\@signalapp\libsignal-client\prebuilds\win32-x64\node.napi.node
2023-08-14 13:47 - 2023-08-09 01:46 - 011730432 _____ () [File not signed] \\?\C:\Users\aluca\AppData\Local\Programs\signal-desktop\resources\app.asar.unpacked\node_modules\@signalapp\ringrtc\build\win32\libringrtc-x64.node
2017-05-13 17:14 - 2021-05-30 09:10 - 000027648 _____ () [File not signed] C:\Program Files (x86)\ASUS\AXSP\1.01.02\PEbiosinterface32.dll
2015-12-29 06:25 - 2015-12-29 00:25 - 000120334 _____ () [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\libgcc_s_dw2-1.dll
2015-12-29 06:25 - 2015-12-29 00:25 - 001540622 _____ () [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\libstdc++-6.dll
2022-08-30 19:45 - 2022-08-30 13:45 - 007523840 _____ () [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\resource.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000064512 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\ashinetutil.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000225792 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\jsoncpp.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000056320 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\lzma.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000111616 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\minizip.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000226816 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\party.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000678912 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\sqlite.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 001082368 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\webdave.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000082944 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\zdll.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000074240 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\ziputil.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000025088 _____ () [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\zlibutil.dll
2015-12-29 06:25 - 2015-12-29 00:25 - 000079360 _____ (MingW-W64 Project. All rights reserved.) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\libwinpthread-1.dll
2023-08-30 17:34 - 2023-08-30 17:34 - 000143360 _____ (Quizo) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\QTPluginLib\530088c70427c7078963947151f0ff77\QTPluginLib.ni.dll
2023-08-30 17:34 - 2023-08-30 17:34 - 012233216 _____ (Quizo) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\QTTabBar\9aef4ed469f2184cd163dbd1b21a17be\QTTabBar.ni.dll
2021-04-08 12:59 - 2018-06-27 09:58 - 002135040 _____ (The curl library, hxxps://curl.haxx.se/) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\ash_libcurl.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000431616 _____ (The curl library, hxxps://curl.haxx.se/) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\libcurl.dll
2015-12-29 06:52 - 2015-12-29 00:52 - 002177536 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\LIBEAY32.dll
2015-12-29 06:52 - 2015-12-29 00:52 - 000462336 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\ssleay32.dll
2015-01-08 21:56 - 2020-12-15 12:04 - 001282048 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] D:\Origin\LIBEAY32.dll
2019-03-08 18:34 - 2020-12-15 12:04 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] D:\Origin\ssleay32.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 003423744 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\libcrypto-1_1-x64.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000684032 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\libssl-1_1-x64.dll
2016-06-11 02:15 - 2016-06-10 20:15 - 000058880 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qdds.dll
2016-06-10 15:32 - 2016-06-10 09:32 - 000033792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qgif.dll
2016-06-11 02:15 - 2016-06-10 20:15 - 000046592 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qicns.dll
2016-06-10 15:33 - 2016-06-10 09:33 - 000036352 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qico.dll
2016-06-10 15:32 - 2016-06-10 09:32 - 000258560 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qjpeg.dll
2016-06-11 01:51 - 2016-06-10 19:51 - 000028672 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qsvg.dll
2016-06-11 02:15 - 2016-06-10 20:15 - 000028672 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qtga.dll
2016-06-11 02:15 - 2016-06-10 20:15 - 000495616 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qtiff.dll
2016-06-11 02:15 - 2016-06-10 20:15 - 000027648 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qwbmp.dll
2016-06-11 02:16 - 2016-06-10 20:16 - 000416768 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\imageformats\qwebp.dll
2016-06-13 03:38 - 2016-06-12 21:38 - 000317440 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\mediaservice\dsengine.dll
2016-06-10 15:34 - 2016-06-10 09:34 - 001489920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\platforms\qwindows.dll
2020-01-13 09:29 - 2020-01-13 03:29 - 005384704 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Core.dll
2016-06-10 15:23 - 2016-06-10 09:23 - 005283840 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Gui.dll
2016-06-13 03:29 - 2016-06-12 21:29 - 000853504 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Multimedia.dll
2016-06-10 15:17 - 2016-06-10 09:17 - 001610240 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Network.dll
2016-06-11 01:51 - 2016-06-10 19:51 - 000348160 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Svg.dll
2016-06-13 03:27 - 2016-06-12 21:27 - 000188416 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5WebSockets.dll
2016-06-10 15:29 - 2016-06-10 09:29 - 006358528 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\Qt5Widgets.dll
2022-06-15 11:48 - 2017-09-14 14:40 - 000884736 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\MiniTool ShadowMaker\sqldrivers\qsqlite.dll
2018-11-24 15:38 - 2020-12-15 12:04 - 001611264 _____ (The Qt Company Ltd) [File not signed] D:\Origin\platforms\qwindows.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 005487104 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5Core.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 005841920 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5Gui.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 001179136 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5Network.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 000146432 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5WebSockets.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 005089792 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5Widgets.dll
2022-04-20 15:57 - 2020-12-15 12:04 - 000184832 _____ (The Qt Company Ltd) [File not signed] D:\Origin\Qt5Xml.dll
2022-08-15 17:23 - 2022-08-15 11:23 - 000110207 _____ (Un4seen Developments) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\BASS.dll
2022-08-15 17:23 - 2022-08-15 11:23 - 000012166 _____ (Un4seen Developments) [File not signed] C:\Program Files (x86)\ROCCAT\ROCCAT SWARM\BASSWASAPI.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000151552 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxbase310u_net_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 002172416 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxbase310u_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000165888 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxbase310u_xml_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 001376768 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxmsw310u_adv_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 004942336 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxmsw310u_core_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000642048 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxmsw310u_html_vc_ox.dll
2021-04-08 12:59 - 2020-10-13 11:02 - 000764416 _____ (wxWidgets development team) [File not signed] c:\Program Files\Ashampoo\Ashampoo Backup Pro 15\bin\wxmsw310u_xrc_vc_ox.dll
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\aluca\Anwendungsdaten:c7637b1ddf4ebe3cea300c7598738ba3 [394]
AlternateDataStreams: C:\Users\aluca\AppData\Roaming:c7637b1ddf4ebe3cea300c7598738ba3 [394]
AlternateDataStreams: C:\Users\Public\AppData:CSM [452]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [7586]
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Software\Classes\regfile: <==== ATTENTION
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Software\Classes\.reg: => <==== ATTENTION
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Software\Classes\.bat: => <==== ATTENTION
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Software\Classes\.cmd: => <==== ATTENTION
==================== Internet Explorer (Whitelisted) ==========
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_181\bin\ssv.dll [2018-10-12] (Oracle America, Inc. -> Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-10-12] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM - QT Command Bar - {d2bf470e-ed1c-487f-a666-2bd8835eb6ce} - C:\Windows\system32\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM - QT Command Bar 2 - {d2bf470e-ed1c-487f-a777-2bd8835eb6ce} - C:\Windows\system32\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM - QTTabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - C:\Windows\system32\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM - QT Base Toolbar - {d2bf470e-ed1c-487f-a300-2bd8835eb6ce} - C:\Windows\system32\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM-x32 - QT Command Bar - {d2bf470e-ed1c-487f-a666-2bd8835eb6ce} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM-x32 - QT Command Bar 2 - {d2bf470e-ed1c-487f-a777-2bd8835eb6ce} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM-x32 - QTTabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Toolbar: HKLM-x32 - QT Base Toolbar - {d2bf470e-ed1c-487f-a300-2bd8835eb6ce} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2016-07-16 13:47 - 2018-07-21 12:58 - 000000872 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Calibre2\;C:\WINDOWS\System32\OpenSSH\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\dotnet\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\
HKU\S-1-5-21-3615177999-3261653453-3779512466-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\aluca\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\love_you_message_in_a_bottle-wallpaper-3840x2160.jpg
HKU\S-1-5-21-3615177999-3261653453-3779512466-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1)
Windows Firewall is disabled.
Network Binding:
=============
Ethernet 5: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)
Ethernet 5: NordVPN LightWeight Firewall -> NordLwf (enabled)
Ethernet 4: NordVPN LightWeight Firewall -> NordLwf (enabled)
Ethernet 4: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)
Ethernet 3: NordVPN LightWeight Firewall -> NordLwf (enabled)
Ethernet 3: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)
Bluetooth-Netzwerkverbindung 8: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run: => "Ashampoo Backup PB"
HKLM\...\StartupApproved\Run: => "MTPW"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\StartupApproved\StartupFolder: => "Razer Synapse.lnk"
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_DC6ADF56C95D4F38FCEEDC413012C68B"
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-3615177999-3261653453-3779512466-1001\...\StartupApproved\Run: => "Humble Bundle"