#1
Hcanpos07
-
- Members
- 20 posts
- OFFLINE
Posted 31 July 2026 - 05:47 PM
I'm running Windows 11 Home Insider Preview 25H2 on an ASUS desktop, using Google Chrome as my default browser. About a week ago I noticed my search engine kept getting hijacked to ssic.safe-search.net, showing up as a "Site search" shortcut entry in Chrome settings with a garbled search URL string containing placeholders like {google:baseURL}. I was actually watching my screen once when it changed on its own.
Steps I've already tried, all of which the hijacker survived:
- Deleted Chrome's Preferences and Secure Preferences files
- Full Chrome reset via chrome://settings/reset
- Removed the ssic.safe-search.net entry manually from chrome://settings/searchEngines (it came back)
- Ran a Malwarebytes free scan, came back clean
- Ran additional Malwarebytes scans since, along with ESET Online Scanner
- Checked HKCU\SOFTWARE\Policies\Google\Chrome, no Google folder present there
- Checked chrome://policy, only shows a legitimate LocalNetworkAccessAllowedForUrls entry tied to my employer's SharePoint
- Checked Chrome extensions list, everything installed looks legitimate
- Checked the Chrome shortcut Target field, ends cleanly in chrome.exe with nothing appended
- Checked chrome://settings/onStartup, nothing suspicious set
- Investigated Task Scheduler folders GoogleUserPEH and SoftLanding, initially suspected these but confirmed through research they're actually known legitimate/benign Windows and Chrome components, not the hijacker
I ran FRST and I'm attaching the full FRST.txt log. The thing that stood out most to me in the results is this, near the bottom of the Registry section:
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
Those keys show as permission restricted, which I understand means something has locked them down even from admin access, and includes Windows Update and Microsoft's Malicious Software Removal Tool being restricted too. This seems like the actual root cause but I don't want to touch registry permissions myself without guidance given how sensitive that is.
I'm attaching FRST.txt now and will attach Addition.txt as well. Any help pinning down and safely removing this would be appreciated.
ill be closed. The file will not be moved.)
(Anthropic, PBC -> Anthropic) C:\Program Files\WindowsApps\Claude_1.24012.9.0_x64__pzs8sxrjxfjjc\app\claude.exe <7>
(ASUSTeK COMPUTER INC. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe
(ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSOptimization\AsusOSD.exe
(C:\Program Files (x86)\LightingService\LightingService.exe ->) (ASUSTeK COMPUTER INC. -> ) C:\Program Files\ASUS\AacAmbientHal\AacAmbientLighting.exe
(C:\Program Files\ASUS\Armoury Crate Service\ArmouryCrate.Service.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\Armoury Crate Service\ArmouryCrate.UserSessionHelper.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\ShadowPlay\nvsphelper64.exe
(C:\Program Files\Oculus\Support\oculus-remote-desktop\RemoteDesktopCompanion.exe ->) () [File not signed] C:\Program Files\Oculus\Support\oculus-remote-desktop\MQRDCrashpadHandler.exe
(C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe ->) (Meta Platforms, Inc. -> Meta Platforms Technologies LLC) C:\Program Files\Oculus\Support\oculus-remote-desktop\RemoteDesktopCompanion.exe
(C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Meta Platforms, Inc. -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe
(C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Meta Platforms, Inc. -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe
(C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2628.101.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\151.0.4129.54\msedgewebview2.exe
(C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_526.19501.0.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\151.0.4129.54\msedgewebview2.exe
(C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.294.583.0_x64__zpdnekdrzrea0\SpotifyWidgetProvider.exe ->) (Spotify AB -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.294.583.0_x64__zpdnekdrzrea0\crashpad_handler.exe
(DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSOptimization\AsusOptimization.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSOptimization\AsusOptimizationStartupTask.exe
(DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSoftwareManager\AsusSoftwareManager.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSoftwareManager\AsusSoftwareManagerAgent.exe
(ESET, spol. s r.o. -> ESET) C:\Users\hecto\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner_nt64.exe
(explorer.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2628.101.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(explorer.exe ->) (Anthropic, PBC -> Anthropic) C:\Program Files\WindowsApps\Claude_1.24012.9.0_x64__pzs8sxrjxfjjc\app\claude.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.ScreenSketch_11.2602.49.0_x64__8wekyb3d8bbwe\SnippingTool\SnippingTool.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\regedit.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <39>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\151.0.4129.54\msedgewebview2.exe <16>
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\GameInputSvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe <4>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_f4c7a2fd13e0f763\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (Anthropic, PBC -> ) C:\Program Files\WindowsApps\Claude_1.24012.9.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> Asustek Computer Inc.) C:\Program Files (x86)\ASUS\AsusCertService\1.2.36\AsusCertService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\2.03.43\AsusFanControlService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.03.12\atkexComSvc.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files (x86)\LightingService\LightingService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\Armoury Crate Service\ArmouryCrate.Service.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\AsusAppService\AsusAppService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSOptimization\AsusOptimization.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSoftwareManager\AsusSoftwareManager.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSwitch\AsusSwitch.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSystemAnalysis\AsusSystemAnalysis.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSystemDiagnosis\AsusSystemDiagnosis.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Meta Platforms, Inc. -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\GameInputSvc.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_f4c7a2fd13e0f763\Display.NvContainer\NVDisplay.Container.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e8d71250669d562e\RtkAudUService64.exe
(svchost.exe ->) (38BC0208-0916-4E44-909B-E6832F47CDE7 -> ASUSTek COMPUTER INC.) C:\Program Files\WindowsApps\B9ECED6F.ArmouryCrate_6.5.7.0_x64__qmba6cd70vzyy\ArmouryCrate.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ) C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x64.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ) C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x86.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Compputer Inc.) C:\Program Files\ASUS\AacMB\Aac3572MbHal_x86.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\AacExtCard\extensionCardHal_x86.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS_Aac_DRAM\Aac3572DramHal_x86.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.StorePurchaseApp_22606.1401.2.0_x64__8wekyb3d8bbwe\StoreExperienceHost.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot_proxy.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Spotify AB -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.294.583.0_x64__zpdnekdrzrea0\SpotifyWidgetProvider.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e8d71250669d562e\RtkAudUService64.exe [1350240 2023-08-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-31] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM\...\Run: [Logi Download Assistant] => C:\Program Files\LogiDownloadAssistant\bin\logi_download_assistant.exe [18838016 2025-05-15] (Logitech, Inc.) [File not signed]
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [142222176 2023-04-21] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2023-08-15] (Adobe Inc. -> )
HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\GamingMouse\Monitor.exe [757760 2017-08-14] () [File not signed]
HKLM-x32\...\Run: [Syber Mouse] => C:\Program Files (x86)\Syber Mouse\Monitor.exe [1909760 2019-06-01] () [File not signed]
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [1131488 2023-12-18] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2024-09-29] (Wondershare Technology Co.,Ltd -> Wondershare)
HKLM\...\Policies\Explorer: [NoViewOnDrive] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0
HKLM\...\Policies\Explorer: [NoShellSearchButton] 0
HKLM\...\Policies\Explorer: [NoFind] 0
HKLM\...\Policies\Explorer: [NoFile] 0
HKLM\...\Policies\Explorer: [HideClock] 0
HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\...\Policies\Explorer: [NoSetFolders] 0
HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\...\Policies\Explorer: [NoSetTaskbar] 0
HKLM\...\Policies\Explorer: [NoDeletePrinter] 0
HKLM\...\Policies\Explorer: [NoDFSTab] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\...\Policies\Explorer: [NoLogoff] 0
HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 0
HKLM\...\Policies\Explorer: [NoSaveSettings] 0
HKLM\...\Policies\Explorer: [NoHardwareTab] 0
HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4752784 2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3702432 2025-08-15] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [5775000 2026-06-01] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [Microsoft.Lists] => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\OneDrive.Sync.Service.exe [962920 2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [51763128 2026-06-04] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [GoogleChromeAutoLaunch_F93D88D83F5291D09140A23D6B4E67C9] => "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [4057240 2026-07-29] (Google LLC -> Google LLC)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [Discord] => C:\Users\hecto\AppData\Local\Discord\Update.exe [1596344 2025-08-04] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [com.squirrel.WisprFlow.WisprFlow] => C:\Users\hecto\AppData\Local\WisprFlow\Wispr Flow.exe [580096 2026-01-09] (Wispr AI) [File not signed]
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [CiscoMeetingDaemon] => C:\Users\hecto\AppData\Local\WebEx\WebexHost.exe [7297248 2025-10-30] (Cisco WebEx LLC -> Cisco Webex LLC)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [MicrosoftEdgeAutoLaunch_DF1BBEBB8B9DFD0C6D749DA0C6C6E0A9] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start [5024072 2026-07-29] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [45052888 2026-06-24] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Run: [MicrosoftCopilotAutoLaunch_000F0D3998EF571409DE93C2262170FD] => C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe [4589384 2026-07-26] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [565248 2026-07-21] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [203936 2023-08-19] (Adobe Inc. -> Adobe Systems Inc)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\151.0.7922.72\Installer\chrmstp.exe [7593112 2026-07-31] (Google LLC -> Google LLC)
Startup: C:\Users\hecto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2025-08-02]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"C:\Windows\System32\Tasks\Microsoft\Windows\Security\Pwdless\IntelligentPwdlessTask" Access Denied. <==== ATTENTION
Task: {DEA1F398-432F-48CE-B57F-D23721E24232} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {E5BDB53A-88CB-490C-A4F5-87F76F63B302} - System32\Tasks\ASUS Optimization 36D18D69AFC3 => C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSOptimization\AsusHotkey.exe [365104 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
Task: {A817703E-E69C-4CF8-BD88-D589BEBA6ABA} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [398688 2025-05-27] (ASUSTeK COMPUTER INC. -> ASUS)
Task: {F3466CBF-A2DA-4304-B688-D3D61CCE02AF} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\TaskSchedulerTool_ArmourySocketServer.exe [120672 2025-05-27] (ASUSTeK COMPUTER INC. -> TODO: <公司名稱>)
Task: {70362004-4D49-45A4-BAD5-3A3786AFEDAC} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d9c7be32379f93 => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-08-05] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
Task: {2FFD9E95-AE7C-4EB9-B78C-529CBC6284C3} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-08-05] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
Task: {61697F33-D739-44E4-BED8-F222BBA734E0} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\TaskSchedulerTool_asus_framework.exe [120664 2025-06-27] (ASUSTeK COMPUTER INC. -> TODO: <公司名稱>)
Task: {381EE4C4-DEB9-459D-8337-322D1E5D3121} - System32\Tasks\ASUS\NoiseCancelingEngine => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe [1261928 2024-04-09] (ASUSTeK COMPUTER INC. -> ASUS)
Task: {1A225272-3091-43E3-B2D7-EE7814A9611B} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {8776E964-A24E-4112-B498-E5FBEFC65140} - System32\Tasks\AsusSystemAnalysis_754F3273-0563-4F20-B12F-826510B07474 => C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSystemAnalysis\AsusSystemAnalysis.exe [6498352 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
Task: {B8633BC8-2B64-49AA-A20E-E5767023618E} - System32\Tasks\AsusSystemDiagnosis_DriverQuality => C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSystemDiagnosis\AsusSystemDiagnosis.exe [1514544 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
Task: {ABE17873-F4C4-4DEB-BC74-6B61AB7FDECB} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem152.0.7933.0{F29FB85E-D409-445D-B046-351252AE65AE} => C:\Program Files (x86)\Google\GoogleUpdater\152.0.7933.0\updater.exe [9512088 2026-07-05] (Google LLC -> Google LLC)
Task: {4486CC51-B360-48FE-AB6C-F55DB2E71725} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [95752 2026-06-29] (HP Inc. -> HP Inc.)
Task: {9F3B767A-7E75-4138-8E52-9EB1AF87C3D1} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [95752 2026-06-29] (HP Inc. -> HP Inc.)
Task: {3836B46E-14B4-432F-9E64-627388469792} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe [16780592 2026-07-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {BF7A258C-B0AA-4F2A-A2BA-1A895EF3A212} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28726080 2026-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {980D43FD-9AB0-4E0D-8394-CCF368864465} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\opushutil.exe [74080 2026-07-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {27439B9B-2ABA-4E2E-BBEE-1C747DC2C161} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28726080 2026-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {D9335146-012E-4D87-92CF-62BBD7385F20} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [441632 2026-07-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {C3F1BBD7-66EC-4E41-A058-901EF9F2033C} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [441632 2026-07-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {A4013D12-8119-4DF8-A0CE-D112C1143378} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [1370480 2026-07-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {52C64779-DDBA-46EB-9F40-1E7DFF7F4687} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [3690016 2026-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {8A8E6C11-9CF0-4244-AF90-6102758F9282} - System32\Tasks\Microsoft\Office\Office Startup Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe [16780592 2026-07-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {80B74007-0C0F-4D56-A445-1520EC16B9BD} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\0DAD22BF-3910-4A5F-A7CA-BDA78B597C1F\Refresh schedule created by Declared Configuration to refresh any settings changed on the device => C:\WINDOWS\system32\deviceenroller.exe [573440 2026-07-21] (Microsoft Windows -> Microsoft Corporation)
Task: {7B85FA79-AF98-4F34-B4B4-4E8478ECC865} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\SessionRetry\0DAD22BF-3910-4A5F-A7CA-BDA78B597C1F\Retry Schedule created for incomplete session {D39F656F-45DC-403C-AC39-9AD2C789615A} => C:\WINDOWS\system32\deviceenroller.exe [573440 2026-07-21] (Microsoft Windows -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {6E70A08B-CB4D-4CA5-BF99-B69C698EB287} - System32\Tasks\Microsoft\Windows\Shell\UndockedFlightingUpdate => C:\WINDOWS\system32\UndockedFlightingUpdateTask.exe [81920 2025-08-02] (Microsoft Corporation) [File not signed]
Task: {87555B29-C0C2-44E3-87F3-A0BD06278F9E} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => %windir%\System32\UNP\UpdateNotificationMgr.exe (No File)
Task: {01AC22E7-D47D-4EA6-999D-49CF1DB9BF12} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {B6713205-46FA-492E-85D0-74463AF61782} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D9E52738-317B-447E-94EC-01562B2BA5E1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6B89B790-E9B0-4F8B-AB02-AD47B65B6F53} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {EAAF8508-3568-4E9B-9491-C15504B87674} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7F180296-6636-41D0-986B-8E89B23A1209} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3324528 2025-10-15] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {59249506-3D6F-46E4-A03F-265DF4B0A8FC} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407656 2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {85573B2E-6610-455C-AFA8-843F26D049B6} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1708692506-2486377805-3190084330-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407656 2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {C56480DF-0AEF-4B12-8FED-A1EA7933B14D} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1708692506-2486377805-3190084330-1001 => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\OneDriveLauncher.exe [852328 2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {BF49A34D-042C-468A-A5C8-84BDAC0A6689} - System32\Tasks\Ubisoft\Ubisoft Connect Background Update => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe [17835000 2026-06-07] (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
Task: {DD05AF63-9F3F-4616-BF1C-8AEC8BAE0472} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-1708692506-2486377805-3190084330-1001 => C:\Users\hecto\AppData\Roaming\Zoom\bin\Zoom.exe [511872 2026-06-29] (Zoom Communications, Inc. -> Zoom Communications, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{62373adc-dbfd-4690-9f0a-0c3820eca432}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{c4579a23-9022-4cbd-8720-ceb646480b50}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{c985b092-c5e4-45f7-9d29-e8ae8db4e5f2}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{d50616f2-f447-40b0-8477-b0fcd59c0d88}: [DhcpNameServer] 75.75.75.75 75.75.76.76
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-06-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-06-24] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2023-12-18] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2026-06-30] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2023-12-18] (Adobe Inc. -> Adobe Systems)
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default [0]
Edge Notifications: Default -> hxxps://app.zoom.us; hxxps://www.nvidia.com; hxxps://www.youtube.com
Edge HomePage: Default -> hxxp://www.google.com/
Edge DefaultSearchURL: Default -> hxxps://searchsafe.norton.com/search?omnisearch=yes&q={searchTerms}
Edge DefaultSearchKeyword: Default -> nortonsafe
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [0]
Edge Extension: (Calendly: Meeting Scheduling Software) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cbhilkcodigmigfbnphipnnmamjfkipp [0]
Edge Extension: (Seamless.AI) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dbepenphjfofmnjmlacfcdehikakmaap [0]
Edge Extension: (cast player) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dionggdmdobjjolppiiejleechniphok [0]
Edge Extension: (Google Docs Offline) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [0]
Edge Extension: (Dark Mode - Night Eye) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gijhmcgnnbcpigflkfoimbnfjnbcphah [0]
Edge Extension: (Cisco Webex Extension) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ikdddppdhmjcdfgilpnbkdeggoiicjgo [0]
Edge Extension: (Edge relevant text changes) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [0]
Edge Extension: (Capital One Shopping: Save Now) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kiiaghlmeikbpmeabhilfphikfcefljn [0]
Edge Extension: (OneLogin for Edge) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mpnjdddkcbccdhgahjdcjppglaecajdj [0]
Edge Extension: (Norton Safe) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mpnlkmlkncncpgnnkmkgoobfpnjmblnk [0]
Edge Extension: (AdBlock — block ads across the web) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [0]
Edge Extension: (Lightning Autofill) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nlmmgnhgdeffjkdckmikfpnddkbbfkkk [0]
Edge Extension: (HubSpot Sales) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\oiiaigjnkhngdbnoookogelabohpglmd [0]
Edge Extension: (OneNote Web Clipper) - C:\Users\hecto\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\oogbnpmeihfgnccdnmmlgicknopghhma [0]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default [0]
CHR HomePage: Default -> hxxps://airtable.com/
CHR StartupUrls: Default -> "hxxp://www.drudgereport.com/","hxxp://www.google.com","hxxp://xfinity.comcast.net/?cid=insDate11202013","hxxp://www.google.com/"
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [0]
CHR Extension: (Claude) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcoeoabgfenejglbffodgkkbkcdhcgfn [0]
CHR Extension: (Google Docs Offline) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [0]
CHR Extension: (OneNote Web Clipper) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default\Extensions\gojbdfnpnhogfdgjbigejoaolejmgdhk [0]
CHR Extension: (Fetch) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgpkkikfhmllgfnclpfiklpcpehelhda [0]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [0]
CHR Extension: (OneLogin for Google Chrome) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioalpmibngobedobkmbhgmadaphocjdn [0]
CHR Extension: (Gmail reverse conversation) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfgepjmmgamniaefbjlbacahkjjnjoaa [0]
CHR Extension: (Privacy Guard for Chrome) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default\Extensions\laeijbcenliojmganbdmejdbljojcnnp [0]
CHR Extension: (Chrome Web Store Payments) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [0]
CHR Extension: (WASM TTS Engine) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\WasmTtsEngine\20260723.1 [0] [UpdateUrl:0] <==== ATTENTION
CHR Profile: C:\Users\hecto\AppData\Local\Google\Chrome\User Data\System Profile [0]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
S2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [944096 2023-12-18] (Adobe Inc. -> Adobe Inc.)
R2 ArmouryCrateService; C:\Program Files\ASUS\Armoury Crate Service\ArmouryCrate.Service.exe [431144 2025-07-31] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.03.12\atkexComSvc.exe [908648 2024-12-12] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-08-05] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
R2 AsusAppService; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\AsusAppService\AsusAppService.exe [1167408 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\1.2.36\AsusCertService.exe [485720 2025-04-17] (ASUSTeK COMPUTER INC. -> Asustek Computer Inc.)
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\2.03.43\AsusFanControlService.exe [1854312 2025-07-31] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-08-05] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
R2 ASUSOptimization; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSOptimization\AsusOptimization.exe [661552 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
S2 AsusROGLSLService; C:\Program Files (x86)\ASUS\AsusROGLSLService\AsusROGLSLService.exe [681832 2023-12-21] (ASUSTeK COMPUTER INC. -> ASUS)
R2 ASUSSoftwareManager; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSoftwareManager\AsusSoftwareManager.exe [1444912 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSSwitch; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSwitch\AsusSwitch.exe [653872 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSSystemAnalysis; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSystemAnalysis\AsusSystemAnalysis.exe [6498352 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 ASUSSystemDiagnosis; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSystemDiagnosis\AsusSystemDiagnosis.exe [1514544 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
S2 AsusUpdateCheck; C:\WINDOWS\System32\AsusUpdateCheck.exe [845256 2026-07-31] (ASUSTeK Computer Inc. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13546304 2026-07-22] (Microsoft Corporation -> Microsoft Corporation)
S4 CorsairCpuIdService; C:\Program Files\Corsair\Corsair iCUE5 Software\CorsairCpuIdService.exe [303656 2024-07-24] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
S4 CorsairDeviceListerService; C:\Program Files\Corsair\Corsair iCUE5 Software\CorsairDeviceListerService.exe [177192 2024-07-24] (Corsair Memory, Inc. -> )
R2 CoworkVMService; C:\Program Files\WindowsApps\Claude_1.24012.9.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe [12683088 2026-07-24] (Anthropic, PBC -> )
S2 DTSAPO3Service; C:\WINDOWS\System32\DTS\PC\APO3x\DTSAPO3Service.exe [222104 2023-08-06] (DTS, Inc. -> )
S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [19122848 2025-08-15] (Electronic Arts, Inc. -> Electronic Arts)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811496 2024-01-09] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [943528 2024-06-01] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicGamesUpdater; C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesUpdater.exe [3407800 2026-06-04] (Epic Games Inc. -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [2606008 2026-06-01] (Epic Games Inc. -> Epic Games, Inc.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncHelper.exe [3656552 2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [345904 2024-11-22] (Underwriters Laboratories Inc. -> Futuremark)
S2 GameInputRedistService; C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe [401792 2026-05-15] (Microsoft Corporation -> Windows ® Win 7 DDK provider)
S2 GameSDK Service; C:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe [397544 2022-05-31] (ASUSTeK COMPUTER INC. -> ASUS Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [244232 2026-06-29] (HP Inc. -> HP Inc.)
S4 iCUEUpdateService; C:\Program Files\Corsair\Corsair iCUE5 Software\iCUEUpdateService.exe [455720 2024-07-24] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
S3 IsolationSession; C:\WINDOWS\System32\IsoSessionServer.dll [995328 2026-07-21] (Microsoft Windows -> Microsoft Corporation)
R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [5094240 2025-05-26] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11529224 2026-07-28] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-06-13] (Malwarebytes Inc -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe [2100520 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_f4c7a2fd13e0f763\Display.NvContainer\NVDisplay.Container.exe [1275624 2026-02-18] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.134.0713.0003\OneDriveUpdaterService.exe [4039528 2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
S3 OVRLibraryService; C:\Program Files\Oculus\Support\oculus-librarian\OVRLibraryService.exe [127232 2026-07-16] (Meta Platforms, Inc. -> Facebook Technologies, LLC)
R2 OVRService; C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe [508664 2026-07-16] (Meta Platforms, Inc. -> Facebook Technologies, LLC)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [6291440 2024-04-12] (Rockstar Games, Inc. -> Rockstar Games)
R2 ROG Live Service; C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe [2769512 2026-01-15] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
S3 UpcElevationService; C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher Core\UpcElevationService.exe [356344 2026-06-07] (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe [4769792 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe [290704 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [54784 2023-02-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [27920 2024-03-27] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R1 Asusgio3; C:\Windows\system32\drivers\AsIO3.sys [59936 2025-04-17] (ASUSTeK COMPUTER INC. -> Asustek Computer Inc.)
R3 AsusSAIO; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSSystemAnalysis\AsusSAIO.sys [51296 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R1 ATKWMIACPIIO; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_3642f6b2eb6cd5d1\ASUSOptimization\AsusWmiAcpi.sys [50952 2026-06-18] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [47032 2024-07-24] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [22968 2024-07-24] (Microsoft Windows Hardware Compatibility Publisher -> Corsair)
R1 CTIAIO; C:\Windows\system32\drivers\CtiAIo64.sys [34920 2024-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
S3 HarmanAudioService; C:\WINDOWS\System32\DriverStore\FileRepository\quantumusbaudio.inf_amd64_80046965b4a18403\HarmanFilter.sys [50688 2024-06-02] (Harman International Industries, Inc -> Harman International)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [55416 2024-12-02] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-20] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [235624 2026-07-31] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2026-05-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [246376 2026-07-10] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 mshield; C:\WINDOWS\System32\DRIVERS\mshield.sys [43112 2024-09-17] (nordvpn s.a. -> Nordvpn S.A.)
R1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [19672 2023-12-11] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R3 MTKBTFilterX64; C:\WINDOWS\System32\DriverStore\FileRepository\mtkbtfilter.inf_amd64_cde37df5add40ae6\mtkbtfilterx.sys [539608 2024-12-12] (Microsoft Windows Hardware Compatibility Publisher -> MediaTek Inc.)
R3 mtkwlex; C:\WINDOWS\System32\drivers\mtkwl6ex.sys [1696416 2023-11-03] (Microsoft Windows Hardware Compatibility Publisher -> MediaTek Inc.)
R3 oculusvad_oculusvad; C:\WINDOWS\System32\drivers\oculusvad.sys [73400 2024-11-09] (Microsoft Windows Hardware Compatibility Publisher -> Windows ® Win 7 DDK provider)
R3 Oculus_ViGEmBus; C:\WINDOWS\System32\drivers\Oculus_ViGEmBus.sys [32856 2024-01-11] (Oculus VR, LLC -> Facebook Inc.)
S3 ovpn-dco; C:\WINDOWS\System32\drivers\ovpn-dco.sys [92664 2024-06-05] (WDKTestCert lev,133391533294737317 -> OpenVPN, Inc)
R3 rt25cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt25cx21x64.inf_amd64_7a47c3c01d4b9cab\rt25cx21x64.sys [897472 2024-12-12] (Realtek Semiconductor Corp. -> Realtek)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
S3 RtNdPt640; C:\WINDOWS\system32\DRIVERS\RtNdPt640.sys [52632 2023-06-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
S3 RTTEAMPT640; C:\WINDOWS\system32\DRIVERS\RtTeam640.sys [74112 2023-06-13] (Realtek Semiconductor Corp. -> Realtek Corporation)
S3 RTVLANPT640; C:\WINDOWS\system32\DRIVERS\RtVlan640.sys [55904 2020-12-29] (Realtek Semiconductor Corp. -> Realtek Corporation)
S3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [48800 2022-02-24] (SteelSeries ApS -> SteelSeries ApS)
S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [50568 2026-07-08] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21928 2026-07-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [616880 2026-07-08] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [110984 2026-07-08] (Microsoft Windows -> Microsoft Corporation)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2024-07-11] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_8fef709a33c4f183\WSDPrint.sys [57344 2026-02-27] (Microsoft Windows -> Microsoft Corporation)
S3 WSDScan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_be13574fd193cc50\WSDScan.sys [61440 2026-07-21] (Microsoft Windows -> Microsoft Corporation)
S3 EAAntiCheat; system32\drivers\eaanticheat.sys (No File)
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-07-31 18:28 - 2026-07-31 18:29 - 000051513 _____ C:\Users\hecto\Downloads\FRST.txt
2026-07-31 18:28 - 2026-07-31 18:28 - 002448896 _____ (Farbar) C:\Users\hecto\Downloads\FRST64 (1).exe
2026-07-31 18:28 - 2026-07-31 18:28 - 000000000 ____D C:\FRST
2026-07-31 18:26 - 2026-07-31 18:26 - 002448896 _____ (Farbar) C:\Users\hecto\Downloads\FRST64.exe
2026-07-31 17:16 - 2026-07-31 17:16 - 014292512 _____ (Sophos B.V.) C:\Users\hecto\Downloads\HitmanPro_x64 (1).exe
2026-07-31 17:14 - 2026-07-31 17:20 - 000000000 ____D C:\ProgramData\HitmanPro
2026-07-31 17:14 - 2026-07-31 17:14 - 011331520 _____ (SurfRight B.V.) C:\Users\hecto\Downloads\HitmanPro_x64.exe
2026-07-31 17:09 - 2026-07-31 17:09 - 002886560 _____ (Malwarebytes) C:\Users\hecto\Downloads\MBSetup-3.3.exe
2026-07-31 13:17 - 2026-07-31 13:17 - 000007444 _____ C:\Users\hecto\OneDrive\Desktop\Rkill.txt
2026-07-31 13:16 - 2026-07-31 13:16 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\hecto\Downloads\iExplore.exe
2026-07-31 12:53 - 2026-07-31 17:05 - 000001468 _____ C:\Users\hecto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2026-07-31 12:53 - 2026-07-31 17:05 - 000001368 _____ C:\Users\hecto\OneDrive\Desktop\ESET Online Scanner.lnk
2026-07-31 12:53 - 2026-07-31 12:53 - 008423856 _____ (ESET) C:\Users\hecto\Downloads\esetonlinescanner.exe
2026-07-31 12:53 - 2026-07-31 12:53 - 000000000 ____D C:\Users\hecto\AppData\Local\ESET
2026-07-31 12:48 - 2026-07-31 12:48 - 000000000 ____D C:\Users\hecto\AppData\Local\Claude
2026-07-31 12:47 - 2026-07-31 12:47 - 000000000 ____D C:\AdwCleaner
2026-07-31 12:35 - 2026-07-31 12:35 - 009630992 _____ (Malwarebytes) C:\Users\hecto\Downloads\adwcleaner.exe
2026-07-31 12:21 - 2026-07-31 12:27 - 000000000 ____D C:\Users\hecto\Downloads\Autoruns
2026-07-31 12:17 - 2026-07-31 12:17 - 003183752 _____ C:\Users\hecto\Downloads\Autoruns.zip
2026-07-31 12:05 - 2026-07-31 12:05 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleUserPEH
2026-07-31 12:04 - 2026-07-31 12:04 - 000000000 ____D C:\WINDOWS\system32\Tasks\SoftLanding
2026-07-31 11:08 - 2026-07-31 11:08 - 000714145 _____ C:\Users\hecto\Downloads\651caca6-46cc-475d-92ab-afca1c3426b7.jpg.jpeg
2026-07-31 10:02 - 2026-07-31 10:02 - 000015718 _____ C:\Users\hecto\Downloads\DSC_0474 (2).jpeg
2026-07-31 09:59 - 2026-07-31 09:59 - 001406314 _____ C:\Users\hecto\Downloads\20260401_170856.jpg.jpeg
2026-07-30 01:57 - 2026-07-31 14:05 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-07-28 14:33 - 2026-07-28 14:33 - 003764026 _____ C:\Users\hecto\Downloads\IMG_0464.heic
2026-07-28 14:33 - 2026-07-28 14:33 - 000071916 _____ C:\Users\hecto\Downloads\IMG_0333.heic
2026-07-28 14:28 - 2026-07-28 14:28 - 003565534 _____ C:\Users\hecto\Downloads\IMG_6012.heic
2026-07-28 14:06 - 2026-07-28 14:06 - 000427628 _____ C:\Users\hecto\Downloads\DSC_0474_full_enh.jpeg
2026-07-28 14:00 - 2026-07-28 14:00 - 000018431 _____ C:\Users\hecto\Downloads\DSC_0474 (1).jpeg
2026-07-28 13:57 - 2026-07-28 13:57 - 000016856 _____ C:\Users\hecto\Downloads\DSC_0486 (2).jpeg
2026-07-28 13:56 - 2026-07-28 13:56 - 000047216 _____ C:\Users\hecto\Downloads\DSC_0486 (1).jpeg
2026-07-28 13:54 - 2026-07-28 13:54 - 000128322 _____ C:\Users\hecto\Downloads\DSC_0489_enh.jpeg
2026-07-28 13:12 - 2026-07-28 13:12 - 000080183 _____ C:\Users\hecto\Downloads\DSC_0474.jpeg
2026-07-28 13:12 - 2026-07-28 13:12 - 000079525 _____ C:\Users\hecto\Downloads\DSC_0486.jpeg
2026-07-28 13:12 - 2026-07-28 13:12 - 000073166 _____ C:\Users\hecto\Downloads\DSC_0489.jpeg
2026-07-28 12:12 - 2026-07-28 12:12 - 000087390 _____ C:\Users\hecto\Downloads\DSC_0182.jpeg
2026-07-24 13:24 - 2026-07-24 13:24 - 000682390 _____ C:\Users\hecto\Downloads\Indiv Senior Tribute Examples.pdf
2026-07-24 13:07 - 2026-07-24 13:07 - 005329555 _____ C:\Users\hecto\Downloads\IMG_1744.HEIC
2026-07-24 11:55 - 2026-07-24 11:55 - 000182600 _____ C:\Users\hecto\Downloads\KEY DATES 2026-2027[52].pdf
2026-07-24 11:47 - 2026-07-24 11:47 - 005957384 _____ C:\Users\hecto\Downloads\IMG_0359.jpeg
2026-07-15 11:42 - 2026-07-15 11:42 - 001972636 _____ C:\Users\hecto\Downloads\360DS_MicroDrama_Podcast_Intro_Deck_2026_V4.pdf
2026-07-13 17:09 - 2026-07-13 17:09 - 000513606 _____ C:\Users\hecto\Downloads\clinical notes April 15 2026.pdf
2026-07-13 17:07 - 2026-07-13 17:07 - 000209847 _____ C:\Users\hecto\Downloads\After Visit Summary Apr 15, 2026.PDF
2026-07-13 16:48 - 2026-07-13 16:48 - 000920505 _____ C:\Users\hecto\Downloads\CAMPOS IE NOTE04022026164457.pdf
2026-07-10 09:27 - 2026-07-10 09:27 - 000208840 _____ (Zoom Communications, Inc.) C:\Users\hecto\Downloads\Zoom_cm_fo42anktZ9vvrZo4_mfByn1VunjQniB9Gr6A3tqw3TStE7-FeYQkzQ@6SXIuwx5e4aRbzmw_k2d926e5c532106e7_.exe
2026-07-09 09:06 - 2026-07-09 09:06 - 000247998 _____ C:\Users\hecto\Downloads\266796.jpeg
2026-07-09 09:00 - 2026-07-09 09:00 - 000521627 _____ C:\Users\hecto\Downloads\266798.jpeg
2026-07-08 10:26 - 2026-07-08 10:26 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2026-07-01 10:50 - 2026-07-01 10:50 - 000067693 _____ C:\Users\hecto\Downloads\HC-Q-2026-01 Invoice (updated) - Google Docs.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-07-31 18:28 - 2025-09-10 02:34 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-07-31 18:25 - 2026-05-26 12:37 - 000000000 ____D C:\Users\hecto\AppData\Local\Malwarebytes
2026-07-31 18:15 - 2026-03-01 01:09 - 000004160 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{A66635BD-E9FB-4359-A4B6-F3001AD89217}
2026-07-31 17:17 - 2025-09-10 02:34 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-07-31 17:10 - 2026-05-26 12:37 - 000002141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-07-31 17:10 - 2025-09-10 02:33 - 000000000 ____D C:\WINDOWS\INF
2026-07-31 17:09 - 2026-05-26 12:37 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-07-31 17:09 - 2026-05-26 12:37 - 000000000 ____D C:\Program Files\Malwarebytes
2026-07-31 17:04 - 2026-03-01 01:05 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-07-31 12:59 - 2026-03-01 01:09 - 000003752 _____ C:\WINDOWS\system32\Tasks\AsusSystemAnalysis_754F3273-0563-4F20-B12F-826510B07474
2026-07-31 12:57 - 2026-06-29 09:40 - 000003822 _____ C:\WINDOWS\system32\Tasks\AsusSystemDiagnosis_DriverQuality
2026-07-31 12:52 - 2024-11-18 18:25 - 000000000 ____D C:\Users\hecto\AppData\Roaming\Oculus Remote Desktop
2026-07-31 12:52 - 2024-01-11 16:21 - 000000000 ____D C:\Users\hecto\AppData\Local\Oculus
2026-07-31 12:52 - 2023-08-05 13:17 - 000000000 ____D C:\Users\hecto\AppData\Roaming\asus_framework
2026-07-31 12:52 - 2023-08-05 12:43 - 000000000 ____D C:\ProgramData\NVIDIA
2026-07-31 12:15 - 2026-03-01 01:09 - 000004254 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-1708692506-2486377805-3190084330-1001
2026-07-31 12:15 - 2025-09-10 02:34 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2026-07-31 12:11 - 2026-03-01 01:14 - 000836658 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-07-31 12:05 - 2025-09-10 02:34 - 000000000 ___HD C:\Program Files\WindowsApps
2026-07-31 12:05 - 2025-09-10 02:34 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-07-31 12:05 - 2024-12-12 08:20 - 000030222 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-07-31 12:05 - 2023-08-05 12:48 - 000000000 ___RD C:\Users\hecto\OneDrive
2026-07-31 12:04 - 2026-03-01 01:09 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-07-31 12:04 - 2026-02-27 17:09 - 000000000 ____D C:\Users\hecto
2026-07-31 12:04 - 2025-09-10 02:34 - 000000000 ____D C:\WINDOWS\ServiceState
2026-07-31 12:04 - 2025-09-10 02:31 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2026-07-31 12:04 - 2023-08-05 14:56 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2026-07-31 12:04 - 2023-08-04 17:30 - 000901328 _____ () C:\WINDOWS\system32\wpbbin.exe
2026-07-31 12:04 - 2023-08-04 17:30 - 000845256 _____ C:\WINDOWS\system32\AsusUpdateCheck.exe
2026-07-31 12:04 - 2023-08-04 17:30 - 000012288 ___SH C:\DumpStack.log.tmp
2026-07-31 10:41 - 2023-08-05 14:41 - 000002295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-07-31 10:17 - 2025-07-31 15:03 - 000000000 ____D C:\ProgramData\Whesvc
2026-07-31 10:01 - 2023-08-05 12:47 - 000000000 ____D C:\Users\hecto\AppData\Local\D3DSCache
2026-07-30 20:53 - 2023-12-17 10:02 - 000000000 ____D C:\Users\hecto\AppData\Local\Ubisoft Game Launcher
2026-07-30 10:05 - 2026-03-15 11:55 - 000001857 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive Photos.lnk
2026-07-30 10:05 - 2026-03-01 01:09 - 000003596 _____ C:\WINDO
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-07-2026 01
Ran by hecto (31-07-2026 18:30:02)
Running from C:\Users\hecto\Downloads
Microsoft Windows 11 Home Insider Preview Version 25H2 26220.8925 (X64) (2026-03-01 05:09:12)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-1708692506-2486377805-3190084330-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-1708692506-2486377805-3190084330-503 - Limited - Disabled)
Guest (S-1-5-21-1708692506-2486377805-3190084330-501 - Limited - Disabled)
hecto (DisplayName: H***** *****s) (S-1-5-21-1708692506-2486377805-3190084330-1001 - Administrators - Enabled) [MS Account] => C:\Users\hecto
WDAGUtilityAccount (S-1-5-21-1708692506-2486377805-3190084330-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Webroot SecureAnywhere (Enabled - Up to date) {27386327-997E-DE34-2AEF-2B42B2EC1491}
AV: Webroot SecureAnywhere (Enabled - Up to date) {2936F8B3-571B-7336-8577-2471F5CC8C22}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Webroot SecureAnywhere (Enabled - Up to date) {3DAE9632-D5AA-E6D1-8EA5-EB60454F4935}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-FFFF-7760-BC15014EA700}) (Version: 26.001.21691 - Adobe)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 6.1.0.587 - Adobe Inc.)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 6.05.16.221 - Advanced Micro Devices, Inc.)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.133 - Advanced Micro Devices, Inc.) Hidden
AMD I2C Driver (HKLM-x32\...\{B31D92D9-2914-46B0-9738-F668A563DE73}) (Version: 1.2.0.124 - Advanced Micro Devices, Inc.) Hidden
AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.90 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.27.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 8.0.0.13 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.44 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\{1ee7f179-da35-4723-a064-99a2a93c80be}) (Version: 6.05.16.221 - Advanced Micro Devices, Inc.) Hidden
AniMe Matrix MB EN (HKLM\...\{399B6DA7-B609-426E-95F8-B9A83FB7D06E}) (Version: 1.0.1 - ASUS)
Armoury Crate Service (HKLM\...\Armoury Crate Service) (Version: 6.2.11 - ASUSTeK COMPUTER INC.)
ASUS AIOFan HAL (HKLM\...\{EAE80DED-1A39-41C5-9F60-87CC947F6454}) (Version: 1.4.6.0 - ASUSTeK COMPUTER INC.) Hidden
ASUS AIOFan HAL (HKLM-x32\...\{ec89ca82-ee79-4e81-b2de-dc9328a482f2}) (Version: 1.4.6.0 - ASUSTeK COMPUTER INC.) Hidden
ASUS Ambient HAL (HKLM\...\{BC4DB8AE-8E55-4B06-8656-FB1E4A035A11}) (Version: 6.5.0.0 - ASUSTeK COMPUTER INC.) Hidden
ASUS Ambient HAL (HKLM-x32\...\{f9a8e352-4536-4d05-a61c-6586b177bc28}) (Version: 6.5.0.0 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Extension Card HAL (HKLM\...\{237E1CAC-1708-4940-AC34-DF15C079AB70}) (Version: 1.1.0.20 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Extension Card HAL (HKLM-x32\...\{49c4358d-054e-4cf1-9ec1-dca3487f304a}) (Version: 1.1.0.20 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Motherboard HAL (HKLM\...\{359B9A9D-A289-4962-BCE2-13EBFD50D532}) (Version: 1.5.0.2 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Motherboard HAL (HKLM-x32\...\{00aac91e-7198-484b-b29d-1c9990d843ae}) (Version: 1.5.0.2 - ASUSTeK COMPUTER INC.) Hidden
ASUS Aura SDK (HKLM\...\{CF8E6E00-9C03-4440-81C0-21FACB921A6B}) (Version: 3.05.10 - ASUSTeK COMPUTER INC.) Hidden
ASUS Framework Service (HKLM-x32\...\{339A6383-7862-46DA-8A9D-E84180EF9424}) (Version: 4.2.4.4 - ASUSTeK Computer Inc.)
ASUS Motherboard (HKLM-x32\...\{93795eb8-bd86-4d4d-ab27-ff80f9467b37}) (Version: 4.05.06 - ASUSTek Computer Inc.)
ASUS Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.107.159 - ASUSTeK Computer Inc.) Hidden
AURA DRAM Component (HKLM\...\{B6B3BA9B-2FA3-4B3A-9C3A-0945B89E725C}) (Version: 1.1.27 - ASUS) Hidden
AURA DRAM Component (HKLM-x32\...\{9983b059-3dd9-449a-80e6-bcb45c840bdf}) (Version: 1.1.27 - ASUS) Hidden
AURA lighting effect add-on (HKLM-x32\...\{1E2EA04B-FCA7-457E-B6F4-F33E1858E859}) (Version: 0.0.49 - ASUSTek COMPUTER INC.)
AURA lighting effect add-on x64 (HKLM\...\{C5A4A164-4428-4931-B728-96EEF0FA3C44}) (Version: 0.0.49 - ASUSTek COMPUTER INC.)
AURA Service (HKLM-x32\...\{56EEEF7D-0AE3-401A-898B-581719D005AE}) (Version: 3.08.52 - ASUSTeK COMPUTER INC.) Hidden
AURA Service (HKLM-x32\...\{bb9ee5ec-749d-429a-ad53-7c1a8d164e04}) (Version: 3.08.52 - ASUSTeK COMPUTER INC.)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 151.0.4129.49 - Microsoft Corporation)
Discord (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\Discord) (Version: 1.0.9240 - Discord Inc.)
Documentation Manager (HKLM\...\{9D3BCA38-52D5-4491-9530-05241EB11029}) (Version: 22.200.2.1 - Intel Corporation) Hidden
EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.531.2.6045 - Electronic Arts) Hidden
EA app (HKLM-x32\...\{847fe226-69b4-49a2-bb04-eab831e8d2a7}) (Version: 13.531.2.6045 - Electronic Arts)
EA SPORTS FC 25 (HKLM-x32\...\{E06B70DD-D5C9-458A-9518-2AE2C4C1AF34}) (Version: 1.0.120.62184 - Electronic Arts)
ENE RGB HAL (HKLM\...\{E050E98C-5524-4AFB-9E53-97700BEF2C02}) (Version: 1.1.53.0 - Ene Tech.) Hidden
ENE RGB HAL (HKLM-x32\...\{34c42fa7-d8b5-4396-b5d0-5e377ca5c3ad}) (Version: 1.1.53.0 - Ene Tech.) Hidden
ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.13.0 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM-x32\...\{0d380ad9-daa5-4680-ada2-dc3ed9207e16}) (Version: 1.0.13.0 - ENE TECHNOLOGY INC.) Hidden
Epic Games Launcher (HKLM-x32\...\{4F5818BB-3B93-45DD-9290-325F0EF4A0A6}) (Version: 1.3.142.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epic Online Services (HKLM-x32\...\{6730F587-C259-4C4C-A527-F7FF31D970F8}) (Version: 4.2.1 - Epic Games, Inc.)
Far Cry 6 Trial (HKLM-x32\...\Uplay Install 61402) (Version: - Ubisoft)
Futuremark SystemInfo (HKLM-x32\...\{9BD32ADA-36E6-4878-96BD-7AC4D9F53DC6}) (Version: 5.76.1304.0 - Futuremark)
GameSDK Service (HKLM-x32\...\{021d69c3-d686-4a94-8fb5-fd1ee782fb14}) (Version: 1.0.5.0 - ASUSTek COMPUTER INC.)
GameSDK Service (HKLM-x32\...\{7160DA8D-3F25-4F6E-ABC8-F693551D82FA}) (Version: 1.0.5.0 - ASUSTek COMPUTER INC.) Hidden
GamingMouse (HKLM-x32\...\{6D3E26A5-BA44-4EEB-A2D2-8F8E8D8CD007}) (Version: 1.0 - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 151.0.7922.72 - Google LLC)
Intel® Software Installer (HKLM-x32\...\{f4904fe5-b7ba-401f-aba7-76a196f47b73}) (Version: 22.200.2.1 - Intel Corporation) Hidden
Kingston AURA DRAM Component (HKLM\...\{965CDF5F-901C-476F-B3A8-7396701B1129}) (Version: 1.1.36 - KINGSTON COMPONENTS INC.) Hidden
Kingston AURA DRAM Component (HKLM-x32\...\{afab10dc-c1d5-45c1-ad91-fe33af8ac488}) (Version: 1.1.36 - KINGSTON COMPONENTS INC.) Hidden
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Logi Download Assistant (HKLM-x32\...\LogiDownloadAssistant) (Version: 2.0.529 - Logitech)
Malwarebytes version 5.6.3.284 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.6.3.284 - Malwarebytes)
Microsoft .NET Host - 6.0.16 (x64) (HKLM\...\{1D0AC7F1-2B34-44AF-91F6-88757D768DA7}) (Version: 48.67.58427 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.13 (x64) (HKLM\...\{6CD2C0A9-55E7-4133-BC19-205CCF2B64C9}) (Version: 64.52.27977 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.16 (x64) (HKLM\...\{B8537ACA-B210-4DF5-B928-E41CEB76723D}) (Version: 48.67.58427 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.13 (x64) (HKLM\...\{BB5AC4BC-A263-43DA-A530-9CB56342D6B8}) (Version: 64.52.27977 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.8 (x64) (HKLM\...\{7FE24458-0796-4428-99C2-9A0F8DAB93CC}) (Version: 64.32.18380 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.16 (x64) (HKLM\...\{C71E93D2-B8B4-4858-B2A1-4C967DBC1C5F}) (Version: 48.67.58427 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.16 (x64) (HKLM-x32\...\{2a8d0f2b-911b-4b58-8252-46b29e7a4590}) (Version: 6.0.16.32323 - Microsoft Corporation)
Microsoft .NET Runtime - 8.0.13 (x64) (HKLM\...\{C7FB4EEE-D481-4AC1-B113-120A9124FE50}) (Version: 64.52.27977 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.13 (x64) (HKLM-x32\...\{8def024a-2c3c-4c48-a40d-05682ee1ec65}) (Version: 8.0.13.34516 - Microsoft Corporation)
Microsoft .NET Runtime - 8.0.8 (x64) (HKLM\...\{9ACB23DB-4D32-49ED-A5E3-F4E2F8D9D2AA}) (Version: 64.32.18380 - Microsoft Corporation) Hidden
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.20228.20110 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 151.0.4129.54 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 151.0.4129.54 - Microsoft Corporation) Hidden
Microsoft GameInput (HKLM\...\{14EDF950-06B9-415F-862C-1D5DEC321AE6}) (Version: 3.3.221.0 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 26.134.0713.0003 - Microsoft Corporation)
Microsoft Power BI Desktop (x64) (HKLM\...\{1f201073-f25d-4638-97a6-4018c76f71f2}) (Version: 2.149.1429.0 - Microsoft Corporation) Hidden
Microsoft PowerBI Desktop (x64) (HKLM-x32\...\{c97329b0-d06b-4527-9dd5-a5d353e5541a}) (Version: 2.149.1429.0 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.25.28902 - Microsoft)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.8 (x64) (HKLM\...\{663E7053-3B36-4AE5-8223-234867FAEAE6}) (Version: 64.32.18376 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.8 (x64) (HKLM-x32\...\{33832ff3-5583-4b81-b270-d9fd42760e1a}) (Version: 8.0.8.33916 - Microsoft Corporation)
MSI Afterburner 4.6.5 (HKLM-x32\...\Afterburner) (Version: 4.6.5 - MSI Co., LTD)
NVIDIA App 11.0.5.420 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.5.420 - NVIDIA Corporation)
NVIDIA FrameView SDK 1.5.11504.36206172 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.5.11504.36206172 - NVIDIA Corporation)
NVIDIA Graphics Driver 580.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 580.88 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.4.5.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.5.0 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
Oculus (HKLM\...\Oculus) (Version: <3 - Facebook Technologies, LLC)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.20131.20112 - Microsoft Corporation) Hidden
Patriot Viper DRAM RGB (HKLM\...\{1F9C282E-CCB4-4D8E-A5CB-7B74DFCD8C95}) (Version: 1.0.9.8 - Patriot Memory) Hidden
Patriot Viper DRAM RGB (HKLM-x32\...\{55993b50-5bec-47c8-8b2b-1aecad927e48}) (Version: 1.0.9.8 - Patriot Memory) Hidden
Patriot Viper M2 SSD RGB (HKLM\...\{8B4C0A3D-C135-4E1F-98D8-3926494B4D61}) (Version: 1.1.0.3 - Patriot Memory) Hidden
Patriot Viper M2 SSD RGB (HKLM-x32\...\{6e0eff60-c502-43bb-8f56-360ca07e73d9}) (Version: 1.1.0.3 - Patriot Memory) Hidden
PHISON HAL (HKLM\...\{966E33F0-6786-4B38-AA29-C1B3F6C1955D}) (Version: 1.0.9.0 - PHISON Electronics Corp.) Hidden
PHISON HAL (HKLM-x32\...\{549da357-1b81-456b-83f2-dcc47c41dfff}) (Version: 1.0.9.0 - PHISON Electronics Corp.) Hidden
Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 3.0.1.0 - Advanced Micro Devices, Inc.) Hidden
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9238.1 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1125.21.903.2024 - Realtek)
Realtek Ethernet Diagnostic Utility (HKLM-x32\...\{DADC7AB0-E554-4705-9F6A-83EA82ED708E}) (Version: 2.0.8.1 - Realtek)
RivaTuner Statistics Server 7.3.4 (HKLM-x32\...\RTSS) (Version: 7.3.4 - Unwinder)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.87.1898 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.3.0.2 - Rockstar Games)
ROG Live Service (HKLM\...\{2D87BFB6-C184-4A59-9BBE-3E20CE797631}) (Version: 3.4.12.0 - ASUSTek COMPUTER INC.)
ROGFontInstaller (HKLM\...\{605108C1-153E-43D8-8A67-7CE326B00ECA}) (Version: 1.0.0 - ASUS)
Star Wars Outlaws Demo (HKLM-x32\...\Uplay Install 65601) (Version: - Ubisoft)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Syber Mouse (HKLM-x32\...\{586BD210-8F54-4122-B957-F141E38FB37F}_is1) (Version: 1.1.0 - )
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.6.0.11166 - Microsoft Corporation)
TP-Link Archer T6E Driver (HKLM-x32\...\{F2CF3250-3769-431E-A808-056BFA917849}) (Version: 2.1.0 - TP-Link)
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 159.2.11504 - Ubisoft)
Universal Holtek RGB DRAM (HKLM\...\{826388E4-E31F-4514-948B-3BB954FB3EAF}) (Version: 1.0.0.7 - PD) Hidden
Universal Holtek RGB DRAM (HKLM-x32\...\{9a732423-e2f4-47d0-87ab-ef745c7dba69}) (Version: 1.0.0.7 - PD) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WD_BLACK AN1500 (HKLM\...\{085E2365-0A70-4230-B664-02D5E4FE7E9C}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
WD_BLACK AN1500 (HKLM-x32\...\{e42c5874-37b0-4977-9e8d-70bf006e1f76}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
Webex (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\CiscoWebex) (Version: 45.10.0.33234 - Cisco Systems, Inc)
Wispr Flow (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\WisprFlow) (Version: 1.4.171 - Wispr Flow)
Wondershare Helper Compact 2.6.0 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.6.0 - Wondershare)
Zoom Workplace (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\ZoomUMX) (Version: 7.0.5 (38856) - Zoom Communications, Inc.)
Chrome apps:
============
Calendar (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\8755160b8a036a98f77f60f83cc3249d) (Version: 1.0 - Google\Chrome)
Docs (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\b6837776032ca378e83be83262725d7e) (Version: 1.0 - Google\Chrome)
Gmail (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\7dd1552c194921bab2a417c56a442212) (Version: 1.0 - Google\Chrome)
Google AI Studio (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\a299355e0dab1bbc56141dc56a14fbe6) (Version: 1.0 - Google\Chrome)
Google Drive (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\748232f862c68c134289b86b349534e1) (Version: 1.0 - Google\Chrome)
Google Meet (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\22a8567dedb1d855f8b76ca474d69db3) (Version: 1.0 - Google\Chrome)
Messages (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\50be753bfe433ffccc8b0d9d2c1d689a) (Version: 1.0 - Google\Chrome)
Sheets (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\cc67e3913870164818b1705bad0fe7d7) (Version: 1.0 - Google\Chrome)
Slides (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\6a0862815e2ace20242340a287f4112b) (Version: 1.0 - Google\Chrome)
YouTube (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\05bf99c9dc338af0882727cdcf268a72) (Version: 1.0 - Google\Chrome)
YouTube Music (HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\...\f082dc848ab11ba092333bba5436c9f5) (Version: 1.0 - Google\Chrome)
Packages:
=========
A Plague Tale: Requiem - Windows -> C:\Program Files\WindowsApps\FocusHomeInteractiveSA.APlagueTaleRequiem-Windows_1.6.0.0_x64__4hny5m903y3g0 [0] ()
Acrobat Notification Client -> C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2023-09-07] (Adobe Systems Incorporated)
Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC [0] ()
Adobe Notification Client -> C:\Program Files\WindowsApps\AdobeNotificationClient_3.0.1.1_x86__enpm4xejd91yc [2023-08-15] (Adobe Systems Incorporated)
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2024-11-08] (INTEL CORP) [Startup Task]
Armoury Crate -> C:\Program Files\ASUS\AacAmbientHal [0] (Sparse Package)
Armoury Crate -> C:\Program Files\WindowsApps\B9ECED6F.ArmouryCrate_6.5.7.0_x64__qmba6cd70vzyy [2026-05-20] (ASUSTeK COMPUTER INC.)
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2024-07-11] (Autodesk Inc.)
ChatGPT Classic -> C:\Program Files\WindowsApps\OpenAI.ChatGPT-Desktop_1.2026.190.0_x64__2p2nqsd0c76g0 [2026-07-10] (OpenAI) [Startup Task]
Cinebench -> C:\Program Files\WindowsApps\MAXONComputerGmbH.Cinebench_2026.1.3.0_x64__rsne5bsk8s7tj [2026-07-05] (MAXON Computer GmbH)
Claude -> C:\Program Files\WindowsApps\Claude_1.24012.9.0_x64__pzs8sxrjxfjjc [2026-07-24] (Anthropic, PBC) [Startup Task]
Dell Shop -> C:\Program Files\WindowsApps\DellInc.DellShop_2.2.1.0_neutral__htrsf667h5kn2 [2024-07-11] (Dell Inc)
DOOM: The Dark Ages -> C:\Program Files\WindowsApps\BethesdaSoftworks.ProjectTitan_1.12.58.0_x64_WW_3275kfvn8vcwc [2026-07-27] (Bethesda Softworks)
DTS Custom for Asus -> C:\Program Files\WindowsApps\DTSInc.DTSCustomforAsus_2.1.1.0_x64__t5j2fzbtdg37r [2023-08-06] (DTS, Inc.)
Galaxy Buds -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.GalaxyBuds_6.9.8.0_x64__3c1yjt4zspk6g [2026-02-24] (Samsung Electronics Co. Ltd.) [Startup Task]
GoPro Player -> C:\Program Files\WindowsApps\GoPro.GoProPlayer_3.2.2.0_x64__1h9vz9xjm6b8c [2026-05-03] (GoPro)
Greeting Cards Studio -> C:\Program Files\WindowsApps\2189hi-score.GreetingCardsStudio_4.9.0.0_neutral__sqtpx88dh7gfw [2023-08-06] (hi-score)
GroupMe -> C:\Program Files\WindowsApps\MICROSOFT.GROUPME10_7.9.13.0_neutral__kzf8qxf38zg5c [2024-05-09] (Skype)
HP Print Support Application -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterDriver_2604.1.4520.0_x64__v10z8vjag6ke6 [2026-07-07] (HP Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_165.4.1108.0_x64__v10z8vjag6ke6 [2026-07-13] (HP Inc.)
Ink.Handwriting.en-US.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.en-US.1.0_0.1248.2215.0_x64__8wekyb3d8bbwe [2026-06-04] (Microsoft Corporation)
Ink.Handwriting.en-US.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.en-US.1.0_0.1248.2215.0_x86__8wekyb3d8bbwe [2026-06-04] (Microsoft Corporation)
Ink.Handwriting.Main.en-US.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.Main.en-US.1.0.1_0.1248.2215.0_x64__8wekyb3d8bbwe [2026-06-04] (Microsoft Corporation)
Local AI Manager for Microsoft 365 -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\AI [0] ()
Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [0] ()
Microsoft 365 companion apps -> C:\Program Files\WindowsApps\Microsoft.M365Companions_2.2510.22000.0_x64__8wekyb3d8bbwe [2025-11-05] (Microsoft Corporation)
Microsoft Defender -> C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2504.16004.0_x64__8wekyb3d8bbwe [2026-06-04] (Microsoft Corporation) [Startup Task]
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2023-09-15] (Microsoft Corp.)
Microsoft Loop -> C:\Program Files\WindowsApps\Microsoft.MicrosoftLoop_1.0.1.0_neutral__8wekyb3d8bbwe [2024-02-13] (Microsoft Corporation)
Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_56.20201.588.0_x64__8wekyb3d8bbwe [2026-02-07] (Microsoft Corporation)
Microsoft.Office.ActionsServer -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\ActionsServer [0] ()
Mountain Dwellings -> C:\Program Files\WindowsApps\Microsoft.MountainDwellings_1.0.0.0_neutral__8wekyb3d8bbwe [2023-08-05] (Microsoft Corporation)
MyASUS -> C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_4.0.71.0_x64__qmba6cd70vzyy [2026-07-03] (ASUSTeK COMPUTER INC.) [Startup Task]
NetGuard -> C:\Program Files\WindowsApps\NetGuard.NetGuard_1.24.90.0_x64__7jfvxrxvj6v90 [2025-10-22] (NetGuard) [Startup Task]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2025-11-07] (NVIDIA Corp.)
OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [0] ()
OneNote Virtual Printer -> C:\Program Files\WindowsApps\Microsoft.Office.OneNoteVirtualPrinter_1.0.0.0_x64__8wekyb3d8bbwe [2025-04-01] (Microsoft Corporation)
PhotoScape X -> C:\Program Files\WindowsApps\MooiiTech.PhotoScapeX_4.2.1.0_x64__f5eddttrpssna [2024-07-11] (Mooii Tech)
Planet of Lana -> C:\Program Files\WindowsApps\Thunderful.PlanetofLana_1.1.0.0_x64__8j53pwgd019sy [2024-06-14] (Thunderful Publishing AB)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.29.256.0_x64__dt26b99r8h8gj [2023-08-06] (Realtek Semiconductor Corp)
Speech Pack - English (United States) -> C:\Program Files\WindowsApps\MicrosoftWindows.Speech.en-US.1_1.0.29.0_x64__cw5n1h2txyewy [2026-05-21] (Microsoft Windows)
Speedtest by Ookla -> C:\Program Files\WindowsApps\Ookla.SpeedtestbyOokla_1.27.200.0_x64__43tkc6nmykmb6 [2026-05-03] (Ookla)
SpotifyAB.SpotifyMusic -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.294.583.0_x64__zpdnekdrzrea0 [2026-07-16] (Spotify AB) [Startup Task]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.TWITTER_7.0.1.0_neutral__wgeqdkkx372wm [2024-07-11] (Twitter Inc.)
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2628.101.0_x64__cv1g1gvanyjgm [2026-07-31] (WhatsApp Inc.) [Startup Task]
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_8002.3.0.0_x64__8wekyb3d8bbwe [2026-07-16] (Microsoft Corp.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{04271989-4A69-28E0-A52C-F629F5AAEAF1} -> [OneDrive - Maggard Information Associates, LLC] => C:\Users\hecto\OneDrive - Maggard Information Associates, LLC [2025-12-08 14:36]
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{04271989-4A69-32A6-D5EF-3F1E3069CDF8} -> [Maggard Information Associates, LLC] => C:\Users\hecto\Maggard Information Associates, LLC [2025-12-30 10:46]
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{04271989-C4D2-8889-85D6-23CE2F94A18E} -> [OneDrive - UP Entertainment] => C:\Users\hecto\OneDrive - UP Entertainment [2023-08-05 12:43]
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{14100442-9664-1407-2647-000000000000}\localserver32 -> "C:\Users\hecto\AppData\Local\Wondershare\Wondershare NativePush\WsToastNotification.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{23A5B06E-20BB-4E7E-A0AC-6982ED6A6041}\localserver32 -> C:\Users\hecto\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner_nt64.exe (ESET, spol. s r.o. -> ESET)
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{2F81B25E-7507-4844-BFF2-77D2CC24CED4}\localserver32 -> C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Inc. -> Adobe Inc.)
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{4e6f7264-5650-4e00-0000-000000000000}\localserver32 -> "C:\Program Files\NordVPN\NordVPN.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> "C:\Users\hecto\AppData\Local\Microsoft\Teams\current\Teams.exe" --toast => No File
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems)
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{EABAE40C-B27C-455A-B672-F234DD780948}\InprocServer32 -> C:\Users\hecto\AppData\Local\Microsoft\TeamsMeetingAdd-in\1.25.28902\x64\Microsoft.Teams.MeetingAddin.DLL (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-30] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-30] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-30] (Adobe Inc. -> )
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-30] (Adobe Inc. -> )
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2026-06-09] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-06-06] (Malwarebytes Inc -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.134.0713.0003\FileSyncShell64.dll [2026-07-30] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_f4c7a2fd13e0f763\nvshext.dll [2026-02-18] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2023-11-30] (Adobe Inc. -> )
ContextMen
Edited by buddy215, 31 July 2026 - 06:40 PM.
BC AdBot (Login to Remove)

- BleepingComputer.com
- Register to remove ads
#2
icotonev
icotonev
-
- Malware Response Team
- 720 posts
- OFFLINE
Malware Hunter
- Gender:Male
- Location:Bulgaria
- Local time:02:50 AM
Posted 02 August 2026 - 11:03 AM
Hello..! Welcome to the virus removal section, тrojan, spyware and malware..!
My name is icotonev and I'm here to help you remove malware ..!
Please give me some time to examine your logs.... Dependant on how much I need to research, this may (or may not) take some time. I'll be back as soon as I've finished..!
Until then, please perform the following scan:
Farbar Service Scanner
- Download Farbar Service Scanner and save the file taking note of where the file is saved (Desktop, Downloads folder, etc.)
- Make sure the following options are checked:
- Internet Services
- Windows Firewall
- System Restore
- Security Center/Action Center
- Windows Update
- Windows Defender
- Other Services
- Press Scan
- Please copy and paste the contents of the FSS.txt report in your reply.
Scan with SecurityCheck by glax24
- Temporarily disable Microsoft SmartScreen only if it blocks the download of the software. The program is safe
- Download SecurityCheck by glax24 from here
- If SmartScreen blocks the file from running click on More info and Run anyway
- This tool is safe. Smartscreen is overly sensitive. You can check the VirusTotal scan of the tool from here
- Right-click with your mouse on the Securitycheck.exe and select "Run as administrator" and reply YES to allow it to run
- Wait for the scan to finish. It will open a text file named SecurityCheck.txt Close the file. Attach it with your next reply.
- You can find this file in a folder called SecurityCheck, C:\SecurityCheck\SecurityCheck.tx
In your next reply, please include:
- SecurityCheck.txt
- FSS.txt
#3
Hcanpos07
Hcanpos07
- Topic Starter
-
- Members
- 20 posts
- OFFLINE
#4
icotonev
icotonev
-
- Malware Response Team
- 720 posts
- OFFLINE
Malware Hunter
- Gender:Male
- Location:Bulgaria
- Local time:02:50 AM
Posted 02 August 2026 - 12:31 PM
Uninstalling Programs Using Revo Uninstaller Free Portable
- Download Revo Uninstaller Free Portable and save it to your Desktop
- Right click on the folder and select Extract All..., then click Extract
- Double click on the RevoUninstaller-Portable folder
- Right click on RevoUPort and select Run as administrator
- Click OK on the License Agreement
- From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
Wondershare Helper Compact
- If the program's uninstaller appears work through the steps to remove the program(s)
- Be sure the Advanced option is selected then click Scan
- For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
- Once done click Finish
- Reboot your computer
Multiple enabled antivirus products detected
Multiple AV products are enabled at the same time. Running multiple real-time AV engines can cause conflicts and performance issues.Detected enabled AV entries: 4
AV: Webroot SecureAnywhere (Enabled - Up to date) {27386327-997E-DE34-2AEF-2B42B2EC1491}
AV: Webroot SecureAnywhere (Enabled - Up to date) {2936F8B3-571B-7336-8577-2471F5CC8C22}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Webroot SecureAnywhere (Enabled - Up to date) {3DAE9632-D5AA-E6D1-8EA5-EB60454F4935}
Webroot SecureAnywhere remains registered in Windows Security Center/WMI as an antivirus, but no matching installed product, running process, active service, driver, or scheduled task was found. In the next fix, we will only remove the entry in the “Security Center”; this does not uninstall Webroot SecureAnywhere or delete its files.
Farbar Recovery Scan Tool Fix
- Right click on the FRST64 icon and select Run as administrator
- Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
- There is no need to paste the information anywhere, FRST64 will do it for you
Start::
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
"C:\Windows\System32\Tasks\Microsoft\Windows\Security\Pwdless\IntelligentPwdlessTask" Access Denied. <==== ATTENTION
Task: {1A225272-3091-43E3-B2D7-EE7814A9611B} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {87555B29-C0C2-44E3-87F3-A0BD06278F9E} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => %windir%\System32\UNP\UpdateNotificationMgr.exe (No File)
Task: {01AC22E7-D47D-4EA6-999D-49CF1DB9BF12} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
CHR Extension: (WASM TTS Engine) - C:\Users\hecto\AppData\Local\Google\Chrome\User Data\WasmTtsEngine\20260723.1 [0] [UpdateUrl:0] <==== ATTENTION
S3 EAAntiCheat; system32\drivers\eaanticheat.sys (No File)
2024-06-04 16:53 - 2024-06-04 16:53 - 000004334 _____ () C:\Users\hecto\AppData\Local\885259240
2025-07-14 19:11 - 2025-07-14 19:11 - 000005279 _____ () C:\Users\hecto\AppData\Local\94097465662
AV: Webroot SecureAnywhere (Enabled - Up to date) {27386327-997E-DE34-2AEF-2B42B2EC1491}
AV: Webroot SecureAnywhere (Enabled - Up to date) {2936F8B3-571B-7336-8577-2471F5CC8C22}
AV: Webroot SecureAnywhere (Enabled - Up to date) {3DAE9632-D5AA-E6D1-8EA5-EB60454F4935}
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{14100442-9664-1407-2647-000000000000}\localserver32 -> "C:\Users\hecto\AppData\Local\Wondershare\Wondershare NativePush\WsToastNotification.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{4e6f7264-5650-4e00-0000-000000000000}\localserver32 -> "C:\Program Files\NordVPN\NordVPN.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> "C:\Users\hecto\AppData\Local\Microsoft\Teams\current\Teams.exe" --toast => No File
AlternateDataStreams: C:\Users\hecto\Downloads\01 (1).jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1488]
AlternateDataStreams: C:\Users\hecto\Downloads\01.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1488]
AlternateDataStreams: C:\Users\hecto\Downloads\11-2-24_gamecard.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1292]
AlternateDataStreams: C:\Users\hecto\Downloads\16 year old birthday card for Gobi, blonde hair and blue eye, baseball pitcher, computer gamer, world traveler, comic book illustration.png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [66]
AlternateDataStreams: C:\Users\hecto\Downloads\16 year old birthday card with driving a car, pitching baseball, computer gamer, traveler, and the name Gobi.png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [66]
AlternateDataStreams: C:\Users\hecto\Downloads\1725368752-103358-31947-1219-1.eml:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [226]
AlternateDataStreams: C:\Users\hecto\Downloads\195752924059.JPEG:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [418]
AlternateDataStreams: C:\Users\hecto\Downloads\2.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1486]
AlternateDataStreams: C:\Users\hecto\Downloads\20-236-879-03.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [167]
AlternateDataStreams: C:\Users\hecto\Downloads\20231112_103250~3.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [90]
AlternateDataStreams: C:\Users\hecto\Downloads\2024 UP and UPFF OPP 5.15.24.xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1613]
AlternateDataStreams: C:\Users\hecto\Downloads\2024-11-24 - Magic Kingdom Park - Pirates of the caribbean.jpeg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [622]
AlternateDataStreams: C:\Users\hecto\Downloads\20240120_133410.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [90]
AlternateDataStreams: C:\Users\hecto\Downloads\20240616_170322.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [202]
AlternateDataStreams: C:\Users\hecto\Downloads\20240810_193302.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [202]
AlternateDataStreams: C:\Users\hecto\Downloads\20240810_193302.jpg:shield [205]
AlternateDataStreams: C:\Users\hecto\Downloads\20240822_125457.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1271]
AlternateDataStreams: C:\Users\hecto\Downloads\20240822_125506.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1271]
AlternateDataStreams: C:\Users\hecto\Downloads\20240914_100032.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [202]
AlternateDataStreams: C:\Users\hecto\Downloads\20241203_112159[1].jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1278]
AlternateDataStreams: C:\Users\hecto\Downloads\20241221_100352.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [202]
AlternateDataStreams: C:\Users\hecto\Downloads\20241221_100400.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [202]
AlternateDataStreams: C:\Users\hecto\Downloads\20241225_095817.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [202]
AlternateDataStreams: C:\Users\hecto\Downloads\20241225_120359.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [202]
AlternateDataStreams: C:\Users\hecto\Downloads\20241229_162032[1].jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1277]
AlternateDataStreams: C:\Users\hecto\Downloads\2024GA500-2-8-7_36.html:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [60]
AlternateDataStreams: C:\Users\hecto\Downloads\2024GA500-2-8-7_51.html:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [60]
AlternateDataStreams: C:\Users\hecto\Downloads\24_1040.xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [184]
AlternateDataStreams: C:\Users\hecto\Downloads\24_25_Medical_Form (1).docx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [127]
AlternateDataStreams: C:\Users\hecto\Downloads\24_25_Medical_Form (1).docx:shield [178]
AlternateDataStreams: C:\Users\hecto\Downloads\24_25_Medical_Form.docx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [127]
AlternateDataStreams: C:\Users\hecto\Downloads\24_25_Medical_Form.docx:shield [174]
AlternateDataStreams: C:\Users\hecto\Downloads\468f0d04-a6d5-4ef5-9730-c41c90371bf1.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [182]
AlternateDataStreams: C:\Users\hecto\Downloads\5A78416B-E9E3-45F1-A373-5A57662EA9F1.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [474]
AlternateDataStreams: C:\Users\hecto\Downloads\71NulLwsRmL._AC_SX679_.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [135]
AlternateDataStreams: C:\Users\hecto\Downloads\7D78v1H1.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [120]
AlternateDataStreams: C:\Users\hecto\Downloads\7d96b0be-091b-4847-9f39-7bf47ddb38ee.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [182]
AlternateDataStreams: C:\Users\hecto\Downloads\7E12v1G.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [118]
AlternateDataStreams: C:\Users\hecto\Downloads\A beach image (1).png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [66]
AlternateDataStreams: C:\Users\hecto\Downloads\A beach image.png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [66]
AlternateDataStreams: C:\Users\hecto\Downloads\activity (1).xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [400]
AlternateDataStreams: C:\Users\hecto\Downloads\activity (2).xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [399]
AlternateDataStreams: C:\Users\hecto\Downloads\activity (3).xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [399]
AlternateDataStreams: C:\Users\hecto\Downloads\activity (4).xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [399]
AlternateDataStreams: C:\Users\hecto\Downloads\Allrites - Chief Content Officer.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [294]
AlternateDataStreams: C:\Users\hecto\Downloads\amd-software-adrenalin-edition-24.10.1-minimalsetup-241031_web.exe:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [189]
AlternateDataStreams: C:\Users\hecto\Downloads\amd_bt_driver.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [124]
AlternateDataStreams: C:\Users\hecto\Downloads\amd_chipset_drivers_am4_am5.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [139]
AlternateDataStreams: C:\Users\hecto\Downloads\amd_vga_driver_am5.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [130]
AlternateDataStreams: C:\Users\hecto\Downloads\amd_wifi_driver.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [126]
AlternateDataStreams: C:\Users\hecto\Downloads\An elaborate front porch Christmas card.png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [66]
AlternateDataStreams: C:\Users\hecto\Downloads\AnnualInitiativePerformance.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [486]
AlternateDataStreams: C:\Users\hecto\Downloads\batting-cages-inc-batting-cage-freestanding-trapezoid-premium-batting-cage-package-deal-33926167887925.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [305]
AlternateDataStreams: C:\Users\hecto\Downloads\batting-cages-inc-batting-cage-freestanding-trapezoid-premium-batting-cage-package-deal-33926167887925.jpg:shield [342]
AlternateDataStreams: C:\Users\hecto\Downloads\Bobbie-Goods-Coloring-Pages-139 (1).webp:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1271]
AlternateDataStreams: C:\Users\hecto\Downloads\Bobbie-Goods-Coloring-Pages-139.webp:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1292]
AlternateDataStreams: C:\Users\hecto\Downloads\Checking1.csv:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [74]
AlternateDataStreams: C:\Users\hecto\Downloads\Checking2.csv:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [74]
AlternateDataStreams: C:\Users\hecto\Downloads\Christmas Card with a front porch.png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [66]
AlternateDataStreams: C:\Users\hecto\Downloads\Christmas card with images of the mountains and beach.png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [66]
AlternateDataStreams: C:\Users\hecto\Downloads\Christmas card with mountains and beaches.png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [66]
AlternateDataStreams: C:\Users\hecto\Downloads\Claude Setup.exe:MBAM.Zone.Identifier [362]
AlternateDataStreams: C:\Users\hecto\Downloads\contacts (6).csv:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [50]
AlternateDataStreams: C:\Users\hecto\Downloads\contacts (7).csv:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [50]
AlternateDataStreams: C:\Users\hecto\Downloads\Content Strategy Assistant Job Description - 2023-HGC.docx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [104]
AlternateDataStreams: C:\Users\hecto\Downloads\Copy of Ovation Acquisition Summary 9.11.24 (1).xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1144]
AlternateDataStreams: C:\Users\hecto\Downloads\Copy of Ovation Acquisition Summary 9.11.24.xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1105]
AlternateDataStreams: C:\Users\hecto\Downloads\Delivery Specs.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [88]
AlternateDataStreams: C:\Users\hecto\Downloads\Dell 3650.avif:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [376]
AlternateDataStreams: C:\Users\hecto\Downloads\Diagnostic_v2.0.8.1_1.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [332]
AlternateDataStreams: C:\Users\hecto\Downloads\Drawing - Copy (1).pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [74]
AlternateDataStreams: C:\Users\hecto\Downloads\Drawing - Copy.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [74]
AlternateDataStreams: C:\Users\hecto\Downloads\DRV_Chipset_AMD_AM5_SZ-TSD_W11_64_V60516221_20240617R (1).zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [202]
AlternateDataStreams: C:\Users\hecto\Downloads\Electric Deal 8.5.24.xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1119]
AlternateDataStreams: C:\Users\hecto\Downloads\Euro Arts and Evergreen Rollouts Across Platforms 7.24.24CM.xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1144]
AlternateDataStreams: C:\Users\hecto\Downloads\Euro Arts and Evergreen Rollouts Across Platforms 7.24.24CM.xlsx:shield [275]
AlternateDataStreams: C:\Users\hecto\Downloads\fb748959-3fda-41d7-8bed-ad087406dc01.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [182]
AlternateDataStreams: C:\Users\hecto\Downloads\gkgproductions_discussion-for-8-27-projects_2024-08-27_0200.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [543]
AlternateDataStreams: C:\Users\hecto\Downloads\GOG_Galaxy_2.0.exe:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1616]
AlternateDataStreams: C:\Users\hecto\Downloads\HPPSdr.exe:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [192]
AlternateDataStreams: C:\Users\hecto\Downloads\ID Card_02_12_2025.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [70]
AlternateDataStreams: C:\Users\hecto\Downloads\ID Card_08_30_2024.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [50]
AlternateDataStreams: C:\Users\hecto\Downloads\IMG_5690.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1307]
AlternateDataStreams: C:\Users\hecto\Downloads\IMG_5691.jpg:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1274]
AlternateDataStreams: C:\Users\hecto\Downloads\Inkbird Meat Thermometer.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [88]
AlternateDataStreams: C:\Users\hecto\Downloads\Insperity Payroll ORK Ded_Form 2023-HGC.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [95]
AlternateDataStreams: C:\Users\hecto\Downloads\Insperity Payroll ORK Ded_Form 2023.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [900]
AlternateDataStreams: C:\Users\hecto\Downloads\Install_PCIE_Win11_11021_11222024.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [364]
AlternateDataStreams: C:\Users\hecto\Downloads\Interpretive Essay 3.docx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [725]
AlternateDataStreams: C:\Users\hecto\Downloads\Lexus Title-Back.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [95]
AlternateDataStreams: C:\Users\hecto\Downloads\Lexus Title.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [95]
AlternateDataStreams: C:\Users\hecto\Downloads\Maggie Braswell.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [88]
AlternateDataStreams: C:\Users\hecto\Downloads\MarketRate3.csv:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [74]
AlternateDataStreams: C:\Users\hecto\Downloads\mediacreationtool.exe:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [194]
AlternateDataStreams: C:\Users\hecto\Downloads\MIPCOM (1).ics:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [59]
AlternateDataStreams: C:\Users\hecto\Downloads\mountains.png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [66]
AlternateDataStreams: C:\Users\hecto\Downloads\MSTeamsSetup (1).exe:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [160]
AlternateDataStreams: C:\Users\hecto\Downloads\MSTeamsSetup.exe:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [160]
AlternateDataStreams: C:\Users\hecto\Downloads\MV-16_0 (1).pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1317]
AlternateDataStreams: C:\Users\hecto\Downloads\MV-16_0.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [227]
AlternateDataStreams: C:\Users\hecto\Downloads\NordVPNSetup (1).exe:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [161]
AlternateDataStreams: C:\Users\hecto\Downloads\NordVPNSetup (1).exe:shield [164]
AlternateDataStreams: C:\Users\hecto\Downloads\NordVPNSetup.exe:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [154]
AlternateDataStreams: C:\Users\hecto\Downloads\Org Chart2.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1484]
AlternateDataStreams: C:\Users\hecto\Downloads\Ovation FAST Channels Coordinator Draft JD.docx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [259]
AlternateDataStreams: C:\Users\hecto\Downloads\Photos-001 (1).zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [691]
AlternateDataStreams: C:\Users\hecto\Downloads\Photos-001 (2).zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [691]
AlternateDataStreams: C:\Users\hecto\Downloads\Photos-001 (2).zip:shield [693]
AlternateDataStreams: C:\Users\hecto\Downloads\Policy document_02_13_2025.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [70]
AlternateDataStreams: C:\Users\hecto\Downloads\P_setting_xxx_0_90_end_500.png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [221]
AlternateDataStreams: C:\Users\hecto\Downloads\Quiver-UP Entertainment - Select Availabilities.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [104]
AlternateDataStreams: C:\Users\hecto\Downloads\realtek_pcielan_w11 (1).zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [130]
AlternateDataStreams: C:\Users\hecto\Downloads\realtek_pcielan_w11.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [131]
AlternateDataStreams: C:\Users\hecto\Downloads\receipt_599218f1-1b1a-4016-83b3-593b6cd19034.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [58]
AlternateDataStreams: C:\Users\hecto\Downloads\receipt_f63617e2-a344-4a53-907a-25cf73fed5de.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [58]
AlternateDataStreams: C:\Users\hecto\Downloads\ROG-STRIX-X870E-E-GAMING-WIFI-ASUS-1001.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [201]
AlternateDataStreams: C:\Users\hecto\Downloads\SC_Teacher_Certification_Guide_0.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [482]
AlternateDataStreams: C:\Users\hecto\Downloads\Steer Clear- Signed.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [95]
AlternateDataStreams: C:\Users\hecto\Downloads\Steer Clear.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1274]
AlternateDataStreams: C:\Users\hecto\Downloads\Team Swift Spring 2024 Schedule.docx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1292]
AlternateDataStreams: C:\Users\hecto\Downloads\Tennis Mixed 4.0 Drill.ics:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [287]
AlternateDataStreams: C:\Users\hecto\Downloads\Tophat1.png:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [156]
AlternateDataStreams: C:\Users\hecto\Downloads\Trade-In Instructions - SA030429562.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [615]
AlternateDataStreams: C:\Users\hecto\Downloads\Trade-In Instructions - SA060816157.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [615]
AlternateDataStreams: C:\Users\hecto\Downloads\Trade-In Instructions - SA060816157.pdf:shield [640]
AlternateDataStreams: C:\Users\hecto\Downloads\UP Entertainment Content Budgets 2024 - Final.xlsx:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [104]
AlternateDataStreams: C:\Users\hecto\Downloads\UP Entertainment Multiplatform Delivery Requirements 2023.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [1485]
AlternateDataStreams: C:\Users\hecto\Downloads\Upcoming Appointment (1).ics:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [365]
AlternateDataStreams: C:\Users\hecto\Downloads\Upcoming Appointment (1).ics:shield [260]
AlternateDataStreams: C:\Users\hecto\Downloads\Upcoming Appointment (2).ics:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [383]
AlternateDataStreams: C:\Users\hecto\Downloads\Upcoming Appointment.ics:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [365]
AlternateDataStreams: C:\Users\hecto\Downloads\Upcoming Appointment.ics:shield [256]
AlternateDataStreams: C:\Users\hecto\Downloads\Vengeance_RGB_Pro_PDP_Black_04.avif:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [201]
AlternateDataStreams: C:\Users\hecto\Downloads\Waiver.pdf:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [88]
AlternateDataStreams: C:\Users\hecto\Downloads\wip10year-dark.zip:C7140AA6-7976-4D71-9C3A-F8BD5BCEF8DD [104]
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Classes\exefile: "%1" %* <==== ATTENTION
HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Classes\.exe: exefile => "%1" %* <==== ATTENTION
FirewallRules: [{7D48AADB-1BB6-485F-9AB1-E4B2E71CE7E2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe => No File
FirewallRules: [{4715D5C4-EB46-4198-9AB0-85E4A6FED818}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe => No File
FirewallRules: [{AFD2B650-F966-4815-82B7-87B45394BA0E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe => No File
FirewallRules: [{7ADCE27F-2B03-4473-AF10-96E11201FD98}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{97296557-E126-42FA-BEB5-F5190EE37C9B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{66766DD4-79C2-4301-8C46-1FD3165205A2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{23B64B20-002F-4025-8FC6-57A90D1DEDA4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{134DDE44-5C8B-4FD4-AB18-E496763F55F2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{A34A6746-A595-41B6-83C5-8CC436B00A46}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{886FEDB0-0D5E-448D-88FA-0F40A0838B24}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{DE4A5C3C-7A0C-4304-9A7E-7E1B278B974E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{EBA642D9-6C6A-4F21-ACEC-C8C48184B21C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [{014BFC7E-4995-447B-87EC-FC0779C252B0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.283.461.0_x64__zpdnekdrzrea0\Spotify.exe => No File
FirewallRules: [UDP Query User{2107F8A0-FC72-418C-89FF-F19003A67228}C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.328.0_x64__2p2nqsd0c76g0\app\chatgpt.exe] => (Block) C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.328.0_x64__2p2nqsd0c76g0\app\chatgpt.exe => No File
FirewallRules: [TCP Query User{1E672D45-08F3-42D0-93F1-16E43CB22B08}C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.328.0_x64__2p2nqsd0c76g0\app\chatgpt.exe] => (Block) C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.328.0_x64__2p2nqsd0c76g0\app\chatgpt.exe => No File
FirewallRules: [UDP Query User{3723AEF4-24E5-4D07-990E-C7B689FD935B}C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.224.0_x64__2p2nqsd0c76g0\app\chatgpt.exe] => (Allow) C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.224.0_x64__2p2nqsd0c76g0\app\chatgpt.exe => No File
FirewallRules: [TCP Query User{D3608CFB-70CF-4F0A-A9F3-7337F76DBD75}C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.224.0_x64__2p2nqsd0c76g0\app\chatgpt.exe] => (Allow) C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.224.0_x64__2p2nqsd0c76g0\app\chatgpt.exe => No File
FirewallRules: [{E61D2454-BB6F-4A5C-960D-579E5F3ABFDE}] => (Allow) G:\program files\asus\aacambienthal\aacambientlighting.exe => No File
FirewallRules: [{B901E3CA-2C7B-46A9-B6CA-9B787C596188}] => (Allow) C:\Users\hecto\AppData\Local\Temp\ACFL20250731144706\ACSetup\ACSetup.exe => No File
FirewallRules: [{58DC8749-3FD6-4138-AC2C-A979F0A7E9AF}] => (Allow) C:\Users\hecto\AppData\Local\Temp\ACFL20250731144706\ACSetup\ACSetup.exe => No File
FirewallRules: [{E1B599B4-DEE4-4DBB-B7B5-B8CFB3EEC9E8}] => (Allow) C:\Users\hecto\AppData\Local\Wondershare\Wondershare NativePush\WsToastNotification.exe => No File
FirewallRules: [{3C70FC3C-92A9-4197-A4A5-71AAD428CC05}] => (Allow) C:\Users\hecto\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe => No File
FirewallRules: [{2ECAE487-4F91-4378-BAD0-25C5A079063E}] => (Allow) C:\Users\hecto\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe => No File
FirewallRules: [UDP Query User{D05DBC42-D434-4151-8ADE-88D91DAFD9F1}C:\xboxgames\call of duty\content\sp24\sp24-cod.exe] => (Allow) C:\xboxgames\call of duty\content\sp24\sp24-cod.exe => No File
FirewallRules: [TCP Query User{C44ECE04-5313-4D36-9488-771BB165E499}C:\xboxgames\call of duty\content\sp24\sp24-cod.exe] => (Allow) C:\xboxgames\call of duty\content\sp24\sp24-cod.exe => No File
FirewallRules: [UDP Query User{17EA4777-6455-4A79-921C-B7E95B465AC5}C:\xboxgames\call of duty\content\cod.exe] => (Allow) C:\xboxgames\call of duty\content\cod.exe => No File
FirewallRules: [TCP Query User{14419224-F010-480F-98ED-456A379CB931}C:\xboxgames\call of duty\content\cod.exe] => (Allow) C:\xboxgames\call of duty\content\cod.exe => No File
FirewallRules: [UDP Query User{A30FF252-DAAB-49FE-ACF4-F131E545E578}G:\games\s.t.a.l.k.e.r. 2\content\stalker2\binaries\wingdk\stalker2-wingdk-shipping.exe] => (Allow) G:\games\s.t.a.l.k.e.r. 2\content\stalker2\binaries\wingdk\stalker2-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{EB303A57-77AC-4936-9B99-F9EFBAFCF3EC}G:\games\s.t.a.l.k.e.r. 2\content\stalker2\binaries\wingdk\stalker2-wingdk-shipping.exe] => (Allow) G:\games\s.t.a.l.k.e.r. 2\content\stalker2\binaries\wingdk\stalker2-wingdk-shipping.exe => No File
FirewallRules: [UDP Query User{552D3C00-EEA1-416F-A03B-D40D690245FD}G:\games\mechwarrior 5- clans\content\mw5clans\binaries\wingdk\mechwarrior-wingdk-shipping.exe] => (Allow) G:\games\mechwarrior 5- clans\content\mw5clans\binaries\wingdk\mechwarrior-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{5C7C176F-94DA-4374-870C-8D4C21FC1D85}G:\games\mechwarrior 5- clans\content\mw5clans\binaries\wingdk\mechwarrior-wingdk-shipping.exe] => (Allow) G:\games\mechwarrior 5- clans\content\mw5clans\binaries\wingdk\mechwarrior-wingdk-shipping.exe => No File
FirewallRules: [UDP Query User{BD5FCBE7-4152-4DED-A6F0-56EC59F44485}G:\games\call of duty\content\sp24\sp24-cod.exe] => (Allow) G:\games\call of duty\content\sp24\sp24-cod.exe => No File
FirewallRules: [TCP Query User{6F7B3178-2624-429D-B9F0-28A24A73A89E}G:\games\call of duty\content\sp24\sp24-cod.exe] => (Allow) G:\games\call of duty\content\sp24\sp24-cod.exe => No File
FirewallRules: [UDP Query User{81EE5511-69BB-4D0C-BAD4-CF491F6F33B7}G:\games\resident evil 2\content\re2.exe] => (Allow) G:\games\resident evil 2\content\re2.exe => No File
FirewallRules: [TCP Query User{423944F4-F071-4C1A-A43B-F759E8023DB4}G:\games\resident evil 2\content\re2.exe] => (Allow) G:\games\resident evil 2\content\re2.exe => No File
FirewallRules: [UDP Query User{DFCFDF05-29DE-4B3F-B8CD-419EBF4B5230}G:\games\still wakes the deep\content\habitat\binaries\wingdk\habitat-wingdk-shipping.exe] => (Allow) G:\games\still wakes the deep\content\habitat\binaries\wingdk\habitat-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{88FE32B9-8504-4ABB-B6E1-DABE8DF34F45}G:\games\still wakes the deep\content\habitat\binaries\wingdk\habitat-wingdk-shipping.exe] => (Allow) G:\games\still wakes the deep\content\habitat\binaries\wingdk\habitat-wingdk-shipping.exe => No File
FirewallRules: [UDP Query User{D905E0B1-6737-4337-B0A0-978F6B0F1EDD}G:\games\call of duty\content\sp23\sp23-cod.exe] => (Allow) G:\games\call of duty\content\sp23\sp23-cod.exe => No File
FirewallRules: [TCP Query User{AA9B6189-9338-4FAE-8717-683F32E99C12}G:\games\call of duty\content\sp23\sp23-cod.exe] => (Allow) G:\games\call of duty\content\sp23\sp23-cod.exe => No File
FirewallRules: [UDP Query User{527B50CC-F3F9-4D05-A718-B59EECE442D7}G:\games\call of duty\content\cod.exe] => (Allow) G:\games\call of duty\content\cod.exe => No File
FirewallRules: [TCP Query User{4D44E104-D980-4037-BB02-B4401AC35347}G:\games\call of duty\content\cod.exe] => (Allow) G:\games\call of duty\content\cod.exe => No File
FirewallRules: [UDP Query User{C38C3631-B811-4233-90D6-9111A8378F9E}G:\games\hellblade- senua's sacrifice\content\hellbladegame\binaries\wingdk\hellbladegame-wingdk-shipping.exe] => (Allow) G:\games\hellblade- senua's sacrifice\content\hellbladegame\binaries\wingdk\hellbladegame-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{4DA44F8E-1C34-46D2-9B69-62BC87D3679D}G:\games\hellblade- senua's sacrifice\content\hellbladegame\binaries\wingdk\hellbladegame-wingdk-shipping.exe] => (Allow) G:\games\hellblade- senua's sacrifice\content\hellbladegame\binaries\wingdk\hellbladegame-wingdk-shipping.exe => No File
FirewallRules: [UDP Query User{69633F94-3820-4E66-8BA4-B27922234DCC}G:\games\the callisto protocol\content\thecallistoprotocol\binaries\wingdk\thecallistoprotocol-wingdk-shipping.exe] => (Allow) G:\games\the callisto protocol\content\thecallistoprotocol\binaries\wingdk\thecallistoprotocol-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{7B86E3B5-4C66-43EA-9D7C-8D2967A1A5BE}G:\games\the callisto protocol\content\thecallistoprotocol\binaries\wingdk\thecallistoprotocol-wingdk-shipping.exe] => (Allow) G:\games\the callisto protocol\content\thecallistoprotocol\binaries\wingdk\thecallistoprotocol-wingdk-shipping.exe => No File
FirewallRules: [{DA453E40-D961-41B1-8A0A-7FB85BB5308A}] => (Allow) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_4fc38a913e0f2ea5\ASUSLinkRemote\AsusLinkRemoteAgent.exe => No File
FirewallRules: [{CFDDE2C2-FB3C-435D-AA43-57A4975464A3}] => (Allow) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_4fc38a913e0f2ea5\ASUSLinkRemote\AsusLinkRemoteAgent.exe => No File
FirewallRules: [{403330C3-AE5C-4F61-A004-062CBC526EC0}] => (Allow) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_4fc38a913e0f2ea5\ASUSLinkNear\AsusLinkNear.exe => No File
FirewallRules: [{88C763D0-B4B7-4E80-8603-881EEA652C48}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\bin\win32\vrstartup.exe => No File
FirewallRules: [{9B6CD0C6-AEB3-4878-8C0C-4097EBF12A0B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\bin\win32\vrstartup.exe => No File
FirewallRules: [UDP Query User{D23EB973-FC1F-4106-97A5-E43E51009A50}C:\xboxgames\hell let loose\content\hll\binaries\win64\hll-win64-shipping.exe] => (Allow) C:\xboxgames\hell let loose\content\hll\binaries\win64\hll-win64-shipping.exe => No File
FirewallRules: [TCP Query User{1C3901E5-AF7F-49EC-A88A-2AEA33B23B0B}C:\xboxgames\hell let loose\content\hll\binaries\win64\hll-win64-shipping.exe] => (Allow) C:\xboxgames\hell let loose\content\hll\binaries\win64\hll-win64-shipping.exe => No File
FirewallRules: [UDP Query User{251A3903-EC72-4C8D-A2A5-796589D641B5}C:\xboxgames\remnant 2\content\remnant2\binaries\wingdk\remnant2-wingdk-shipping.exe] => (Allow) C:\xboxgames\remnant 2\content\remnant2\binaries\wingdk\remnant2-wingdk-shipping.exe => No File
FirewallRules: [TCP Query User{A0436C34-0F2D-494D-AC4E-5126D7873C84}C:\xboxgames\remnant 2\content\remnant2\binaries\wingdk\remnant2-wingdk-shipping.exe] => (Allow) C:\xboxgames\remnant 2\content\remnant2\binaries\wingdk\remnant2-wingdk-shipping.exe => No File
FirewallRules: [{F9E1ABD9-9D9C-4A72-AED8-EB0E957C9045}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life 2\hl2.exe => No File
FirewallRules: [{5A8D7A61-1737-4C75-B05D-5B4901421CF9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life 2\hl2.exe => No File
FirewallRules: [UDP Query User{9C1A5D7B-BAEA-4795-A35E-DB8E346C5310}C:\program files\ea games\ea sports fc 24\fc24.exe] => (Allow) C:\program files\ea games\ea sports fc 24\fc24.exe => No File
FirewallRules: [TCP Query User{A4D5A5E0-CF11-449C-AD0C-D336822A93C1}C:\program files\ea games\ea sports fc 24\fc24.exe] => (Allow) C:\program files\ea games\ea sports fc 24\fc24.exe => No File
FirewallRules: [UDP Query User{480D32C7-FAC1-4DAD-A8EE-B54D0CCCB4A6}C:\xboxgames\halo infinite\content\subgames\campaigns1\haloinfinite.exe] => (Allow) C:\xboxgames\halo infinite\content\subgames\campaigns1\haloinfinite.exe => No File
FirewallRules: [TCP Query User{E01A020F-6DD0-4BDF-8020-6D824BA8EA2E}C:\xboxgames\halo infinite\content\subgames\campaigns1\haloinfinite.exe] => (Allow) C:\xboxgames\halo infinite\content\subgames\campaigns1\haloinfinite.exe => No File
FirewallRules: [UDP Query User{6915E65A-A58E-438D-906E-86EDCB5510C8}C:\xboxgames\halo infinite\content\game\haloinfinite.exe] => (Allow) C:\xboxgames\halo infinite\content\game\haloinfinite.exe => No File
FirewallRules: [TCP Query User{DB631949-53EE-4F87-8E31-7CB4EA90596C}C:\xboxgames\halo infinite\content\game\haloinfinite.exe] => (Allow) C:\xboxgames\halo infinite\content\game\haloinfinite.exe => No File
FirewallRules: [UDP Query User{DE6E1356-5011-4F13-BCEF-1675F4B069B4}C:\users\hecto\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\hecto\appdata\local\microsoft\teams\current\teams.exe => No File
FirewallRules: [TCP Query User{2186028A-B90C-4D56-9A06-A11734A95F54}C:\users\hecto\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\hecto\appdata\local\microsoft\teams\current\teams.exe => No File
FirewallRules: [TCP Query User{9221BCB4-D305-4C19-A14D-F38DF484DF42}G:\games\borderlands 3 windows pc\content\oakgame\binaries\gdk\oakgame-gdk-shipping.exe] => (Allow) G:\games\borderlands 3 windows pc\content\oakgame\binaries\gdk\oakgame-gdk-shipping.exe => No File
FirewallRules: [UDP Query User{1269C74C-5282-4033-8D2F-F7408A01BDC4}G:\games\borderlands 3 windows pc\content\oakgame\binaries\gdk\oakgame-gdk-shipping.exe] => (Allow) G:\games\borderlands 3 windows pc\content\oakgame\binaries\gdk\oakgame-gdk-shipping.exe => No File
FirewallRules: [TCP Query User{6FA13D6C-CFF0-4145-B57F-8A0C72A8675E}G:\far cry 5\bin_plus\farcry5.exe] => (Allow) G:\far cry 5\bin_plus\farcry5.exe => No File
FirewallRules: [UDP Query User{B297B8D1-746B-40F0-A451-CE397A369B37}G:\far cry 5\bin_plus\farcry5.exe] => (Allow) G:\far cry 5\bin_plus\farcry5.exe => No File
FirewallRules: [TCP Query User{0B337A5F-2701-44B6-87E8-2DAF3740BA8C}C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.258.0_x64__2p2nqsd0c76g0\app\chatgpt.exe] => (Allow) C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.258.0_x64__2p2nqsd0c76g0\app\chatgpt.exe => No File
FirewallRules: [UDP Query User{4FB7084E-85FA-440D-9D3C-A7F3E8875829}C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.258.0_x64__2p2nqsd0c76g0\app\chatgpt.exe] => (Allow) C:\program files\windowsapps\openai.chatgpt-desktop_1.2025.258.0_x64__2p2nqsd0c76g0\app\chatgpt.exe => No File
cmd: netsh winsock reset catalog
cmd: netsh int ip reset resetlog.txt
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: bitsadmin /reset /allusers
cmd: ipconfig /flushdns
Removeproxy:
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-Image /CheckHealth
EmptyTemp:
End::
- Click Fix
- Note: The Emptytemp: command will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
- When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
In your next reply, please include:
- Fixlog.txt
#5
Hcanpos07
Hcanpos07
- Topic Starter
-
- Members
- 20 posts
- OFFLINE
Posted 02 August 2026 - 12:55 PM
Farbar is currently scanning. Will it become clear when I copy and or paste the information and when do i click fix
#6
Hcanpos07
Hcanpos07
- Topic Starter
-
- Members
- 20 posts
- OFFLINE
#7
icotonev
icotonev
-
- Malware Response Team
- 720 posts
- OFFLINE
Malware Hunter
- Gender:Male
- Location:Bulgaria
- Local time:02:50 AM
Posted 02 August 2026 - 01:19 PM
Thank you..!
Fresh FRST logs
Please run FRST tool once more, and attach for me fresh logs:
- Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
- Press Scan button and wait for a while.
- The scanner will produce two logs on your Desktop: FRST.txt and Addition.txt.
- Please attach these two logs in your next reply.
In your next reply, please include:
- FRST.txt
- Addition.txt
#8
Hcanpos07
Hcanpos07
- Topic Starter
-
- Members
- 20 posts
- OFFLINE
#9
icotonev
icotonev
-
- Malware Response Team
- 720 posts
- OFFLINE
Malware Hunter
- Gender:Male
- Location:Bulgaria
- Local time:02:50 AM
Posted 02 August 2026 - 02:06 PM
We still need to fix the issues related to Windows security and system policies. In the next update, we will remove the unwanted policy settings and restore the affected Windows settings..! In addition, I see that there isn't enough free space on the system drive: approximately 85.9 GB of free space out of a total of 930.4 GB. Creating restore points, Windows Update, and Windows maintenance may fail or not work properly until more space is freed up.
Farbar Recovery Scan Tool Fix
- Right click on the FRST64 icon and select Run as administrator
- Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
- There is no need to paste the information anywhere, FRST64 will do it for you
Start::
CreateRestorePoint:
CloseProcesses:
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl]
"AutoReboot"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate"=-
EndRegedit:
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoViewOnDrive
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|DisableLocalMachineRun
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|DisableLocalMachineRunOnce
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|DisableCurrentUserRun
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|DisableCurrentUserRunOnce
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoViewContextMenu
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoShellSearchButton
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoFind
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoFile
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|HideClock
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoTrayContextMenu
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoTrayItemsDisplay
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoSetFolders
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoDevMgrUpdate
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoSetTaskbar
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoDeletePrinter
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoDFSTab
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoChangeStartMenu
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoLogoff
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoWindowsUpdate
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoEncryptOnMove
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoRunasInstallPrompt
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoResolveSearch
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoSaveSettings
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoHardwareTab
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoStartMenuSubFolders
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoViewOnDrive
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|DisableLocalMachineRun
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|DisableLocalMachineRunOnce
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|DisableCurrentUserRun
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|DisableCurrentUserRunOnce
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoViewContextMenu
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoShellSearchButton
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoFind
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoFile
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|HideClock
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoTrayContextMenu
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoTrayItemsDisplay
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoSetFolders
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoDevMgrUpdate
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoSetTaskbar
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoDeletePrinter
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoDFSTab
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoChangeStartMenu
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoLogoff
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoWindowsUpdate
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoEncryptOnMove
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoRunasInstallPrompt
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoResolveSearch
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoSaveSettings
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoHardwareTab
DeleteValue: HKU\S-1-5-21-1708692506-2486377805-3190084330-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoStartMenuSubFolders
Task: {8056CB22-49E5-4DEB-AECE-38BBCE8A1690} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker -> No File <==== ATTENTION
"C:\Windows\System32\Tasks\Microsoft\Windows\Security\Pwdless\IntelligentPwdlessTask" Access Denied. <==== ATTENTION
EmptyTemp:
End::
- Click Fix
- Note: The Emptytemp: command will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
- When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
In your next reply, please include:
- Fixlog.txt
#10
Hcanpos07
Hcanpos07
- Topic Starter
-
- Members
- 20 posts
- OFFLINE
Posted 02 August 2026 - 03:57 PM
Here you go! On a side note, I got a message from my xfinity router/app that SSIC.safe-search.net was blocked from my son's phone.
#11
Hcanpos07
Hcanpos07
- Topic Starter
-
- Members
- 20 posts
- OFFLINE
Posted 02 August 2026 - 05:28 PM
I also cleaned up some games I had on the compuer, so now i have 239gb of free space. I did that after I did the changes.
#12
Hcanpos07
Hcanpos07
- Topic Starter
-
- Members
- 20 posts
- OFFLINE
Posted 02 August 2026 - 05:59 PM
I just went to go search something on my computer and the malware had gone ahead and switched out my search again. I'm not sure anyting we have done worked.
#13
icotonev
icotonev
-
- Malware Response Team
- 720 posts
- OFFLINE
Malware Hunter
- Gender:Male
- Location:Bulgaria
- Local time:02:50 AM
Posted 02 August 2026 - 09:17 PM
He is persistent..!
Removing Chrome Notifications and Resetting Chrome Sync
- Launch Chrome web browser
- Type chrome://settings/syncSetup in the address bar and hit Enter
- Next to your user name select Turn off and confirm the action (If it indicates Sign into Chrome stop and let me know)
- Click on https://chrome.google.com/sync
- If necessary sign into Google account login screen
- Under Chrome and ChromeOS data in your account select Delete data then Delete to confirm the action
- In a new Chrome tab type chrome://settings/syncSetup in the address bar and hit Enter
- Click Turn on sync...
- Select Yes, I'm in
- Once the Sync has completed check your browser performance
- Note: This process will have to be repeated on any other device syncing to Google Chrome
Next..:
Set default search engine and site search shortcuts
https://support.google.com/chrome/answer/95426?hl=en&co=GENIE.Platform=Desktop
Set your homepage and startup page
https://support.google.com/chrome/answer/95314?hl=en&co=GENIE.Platform=Desktop
Next..:
Fresh FRST logs
Please run FRST tool once more, and attach for me fresh logs:
- Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
- Press Scan button and wait for a while.
- The scanner will produce two logs on your Desktop: FRST.txt and Addition.txt.
- Please attach these two logs in your next reply.
In your next reply, please include:
- FRST.txt
- Addition.txt
Edited by icotonev, 02 August 2026 - 09:18 PM.
#14
Hcanpos07
Hcanpos07
- Topic Starter
-
- Members
- 20 posts
- OFFLINE
Posted 03 August 2026 - 07:45 AM
I wanted to let you know that in the first step when I typed in chrome://settings/syncSetup It took me to a screen and when I clicked on my name there wasn't a single toggle (I've included a screenshot). It listed a toggle for many different things. I toggled all of them off. Then did the same thing to toggle them all back on, but I didn't get a message Yes, I'm in. Also, I wanted to let you know that while I selected Google as my search engine, I didn't delete/disable the "Safe" search engine that is still listed as an optional search engine.
#15
icotonev
icotonev
-
- Malware Response Team
- 720 posts
- OFFLINE
Malware Hunter
- Gender:Male
- Location:Bulgaria
- Local time:02:50 AM
Posted 03 August 2026 - 10:42 AM
Turn off Chrome Sync
- Launch Chrome web browser
- Type chrome://settings/syncSetup in the address bar and hit Enter
- If Sync is enabled click Turn off
Microsoft Edge
- Click on the small three dots on the upper right corner of the page.
- Click on Settings.
- By default you're on profile tab.
- Click on Sync.
- Click Turn Off Sync.
Farbar Recovery Scan Tool SearchAll
- Right click on FRST and select Run as administrator
- Copy/paste the following in the Search: box
SearchAll: WasmTtsEngine;20260723.1
- Click Search Files
- When completed click OK and a Search.txt document will open on your desktop
- Please copy and paste the contents of the file in your reply.
Malwarebytes AdwCleaner
- Please download AdwCleaner and save it to your Desktop
- Close all open programs and browsers
- Right click on the icon and select Run as administrator
- Click Scan now
- Uncheck any detected items you would to keep then click Next
- If a Preinstalled software was found! screen appears review it if you'd like then click OK
- Review the list of Preinstalled software and place a check mark in those you do not wish to keep. I would recommend removing all pre-installed software
- Click Quarantine, then Continue
- When completed click View Log File
- Copy and paste the contents in your reply
- Close the AdwCleaner window
In your next reply, please include:
- Search report
- AdwCleaner report
Edited by icotonev, 03 August 2026 - 10:43 AM.

Back to top
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.