Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Windows 10 won't boot, restore etc - tried many things! help p


  • This topic is locked This topic is locked

#106
peterm

peterm

    Trusted Tech

  • Technician
  • 3,387 posts

Hi  iammykyl

This guy has reposted in another forum http://www.geekstogo...problems-again/

 

Cheers

Peterm


  • 0

Advertisements


#107
iammykyl

iammykyl

    Tech Staff

  • Technician
  • 7,659 posts

Thanks for that, It is unlikely there will be responses. 


  • 0

#108
peterm

peterm

    Trusted Tech

  • Technician
  • 3,387 posts

I was waiting to see how you got it to boot without easybcd.

I'm tooooo lazy to work it out for my machine :laughing:


  • 0

#109
netrate

netrate

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 197 posts

Thank for the responses.  I gave up after trying everything I could think of and just used Windows Custom Install.  I used the cmd line to copy the files from windows I wanted to keep and went on with the install. I am giving up on RESTORE POINTS because they don't seem to work and just using MR to backup from now on.


  • 0

#110
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts

Should we consider this case closed?


  • 0

#111
netrate

netrate

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 197 posts

Not quite - I am still having boot issues with checking the disks each time.  I have had to unplug each drive, depending on which drive I am booting too.


  • 0

#112
iammykyl

iammykyl

    Tech Staff

  • Technician
  • 7,659 posts

I still think you will need to run FRST64 as JSntgRvr instructed, to look for other errors.

 

In the meantime see if these instructions fix chkdsk running.

Connect only the W7 drive, > start and allow chkdsk to run completely. (note the drive letter of the disk being checked)

 

Open CMD as admin and run the following, (replacing g with the correct drive letter.)

 

fsutil dirty query G:

This command will query the drive, and more than likely it will tell you that it is dirty.

Next, execute the following command:

 

CHKNTFS /X G:

The X tells Windows to NOT check that particular drive (G) on the next reboot.

 

At this time, manually reboot your computer, it should not run Chkdsk now, but take you directly to Windows.

Once Windows has fully loaded, bring up another command prompt and execute the following command:

Chkdsk /f /r g:

This should take you through five stages of the scan and will unset that dirty bit. Finally, type the following and hit Enter:

fsutil dirty query g:

Windows will confirm that the dirty bit is not set on that drive.

 

Do not connect the W10 drive until JSntgRvr gets back. 


  • 0

#113
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts

Not quite - I am still having boot issues with checking the disks each time.  I have had to unplug each drive, depending on which drive I am booting too.

That must be a registry entry. Post FRST64 logs to check your registry. Lets deal with this one drive at a time.


  • 0

#114
iammykyl

iammykyl

    Tech Staff

  • Technician
  • 7,659 posts

Can't remember if you ran FRST64 before, 

Connect only the W7 drive.

 

Please download https://www.techspot...-scan-tool.html and save it to your Desktop.
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

  • 0

#115
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts

Hi 

This guy has reposted in another forum http://www.geekstogo...problems-again/

 

Cheers

Peterm

 

Closing this topic, please continue above.


  • 0

Advertisements


#116
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts

Opened at the request of the user.


  • 0

#117
netrate

netrate

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 197 posts

Recap - dual boot

1) Win 10 (samsung SSD 500) - partitioned for storage and win 10

2) Win 7 (Kingston 120gig SSD) - non partitioned drive

3) Mobo Gigabtyte - GA-970A-D3 v 1.4

4) Storage drive - 1TB WD (non-boot) - this drive is always connected.

 

Prior to an issue with win 10, I had no problems with my win 10/win 7 dual boot using EasyBCD.  I had sudden issues before Xmas with my win 10 which was fixed with a custom install.  Shortly after Xmas, I was again presented with the same issue of Win 10 not booting - again fixed with win custom install (windows.old) to get win 10 to boot.

 

http://www.geekstogo...help-pls/page-1

 

I am now at the point where I have pseudo dual boot - I disconnect each drive, depending on which I am using (just to be safe).  I don't like disconnecting each drive because sometimes I would forget.  I would rather have a dual boot without worry.

 

Situation : 

It makes no difference whether I boot to win 7 / win 10 (remembering that I disconnect one or the other), I am constantly getting "Disk Checking".

Attached Files


Edited by netrate, 30 January 2021 - 03:58 PM.

  • 0

#118
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-01-2021
Ran by davids home (administrator) on DAVIDSHOME-PC (Gigabyte Technology Co., Ltd. GA-970A-D3) (30-01-2021 15:09:45)
Running from D:\downloads\software\WINDOWS UTILITIES
Loaded Profiles: davids home
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Default browser: "C:\Users\davids home\AppData\Local\Brave\app-0.9.6\Brave.exe" -- "%1"
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files (x86)\Codebox\BitMeter3\BitMeter2.exe
() [File not signed] C:\Program Files (x86)\Everything\Everything.exe
() [File not signed] C:\Windows\SysWOW64\UTSCSI.EXE
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe <32>
(Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(CHENGDU YIWO Tech Development Co., Ltd. -> ) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
(CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
(CyberGhost SRL -> CyberGhost S.A.) C:\Program Files\CyberGhost 6\CyberGhost.Service.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <3>
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\114.4.426\QtWebEngineProcess.exe <3>
(Giga-Byte Technology -> ) C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe
(GlassWire -> SecureMix LLC) C:\Program Files (x86)\GlassWire\GlassWire.exe
(GlassWire -> SecureMix LLC) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
(GlassWire -> SecureMix LLC) C:\Program Files (x86)\GlassWire\GWIdlMon.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <31>
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
(Malwarebytes) [File not signed] C:\ProgramData\MB3Install\MBAMIService.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\vds.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(Open Source Developer, Robin Krom -> Greenshot) C:\Program Files\Greenshot\Greenshot.exe
(Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(SMART Technologies ULC -> SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\Office\SMARTInk-SBSDKProxy.exe
(SMART Technologies ULC -> SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe
(SOFTPERFECT PTY. LTD. -> SoftPerfect) D:\downloads\software\TRAFFIC MONITORING\Networx_Setup_and_Portable-1593\Networx_Setup_and_Portable-1593\64-bit\networx.exe
(SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(VIA Technologies Inc. -> VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [527792 2017-08-09] (Open Source Developer, Robin Krom -> Greenshot)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [NetWorx] => "E:\downloads\software\Networx_Setup_and_Portable-1593\Networx_Setup_and_Portable-1593\64-bit\networx.exe" /auto
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [7631800 2020-11-26] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [7992336 2021-01-25] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM\...\RunOnce: [removeTempFiles936614] => cmd /c "del C:\Users\DAVIDS~1\AppData\Local\Temp\934055\uninstall.exe C:\Users\DAVIDS~1\AppData\Local\Temp\934055\smooth.dll C:\Users\DAVIDS~1\AppData\Local\Temp\934055\libgcc.dll C:\Users\DAVIDS~1\Ap (the data entry has 90 more characters). <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Run: [] => [X]
HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Run: [GlassWire] => C:\Program Files (x86)\GlassWire\glasswire.exe [8331232 2020-08-14] (GlassWire -> SecureMix LLC)
HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\MountPoints2: {2aeb10cd-4a88-11e5-b839-000272a7b3e1} - N:\LaunchU3.exe -a
HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\MountPoints2: {39ff28a2-f793-11e5-8973-902b34ad6ffc} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\START_HERE.htm
HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\MountPoints2: {8a211a53-63ad-11e3-bf94-902b34ad6ffc} - F:\LaunchU3.exe -a
HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Winlogon: [Shell] C:\Windows\explorer.exe [3229696 2016-08-29] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-18\...\Run: [MP3 Skype Recorder] => C:\Program Files (x86)\MP3 Skype Recorder\MP3 Skype Recorder.exe [1975296 2011-11-17] (Alexander Nikiforov) [File not signed]
HKU\S-1-5-18\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [30885360 2020-01-29] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2016-04-04] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Windows x64\Print Processors\spe__PC: C:\Windows\System32\spool\prtprocs\x64\spe__pc.dll [41984 2013-06-18] (Windows ® Codename Longhorn DDK provider) [File not signed]
HKLM\...\Print\Monitors\Adobe PDF Port: C:\Windows\SYSTEM32\AdobePDF64.dll [35928 2007-03-23] (Adobe Systems, Incorporated -> Adobe Systems Incorporated.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3200 series: C:\Windows\SYSTEM32\CNMLMB8.DLL [389120 2012-03-26] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\Canon BJNP Port: C:\Windows\SYSTEM32\CNMN6PPM.DLL [359936 2012-06-14] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\CutePDF Writer Monitor: C:\Windows\SYSTEM32\cpwmon64.dll [87152 2012-10-04] (Acro Software Inc -> )
HKLM\...\Print\Monitors\HP 0053 Status Monitor: C:\Windows\SYSTEM32\hpinksts0053LM.dll [485048 2016-10-14] (Hewlett Packard -> HP Inc.)
HKLM\...\Print\Monitors\HP 0E53 Status Monitor: C:\Windows\SYSTEM32\hpinksts0E53LM.dll [467592 2017-03-20] (Hewlett Packard -> HP Inc.)
HKLM\...\Print\Monitors\HP C211 Status Monitor: C:\Windows\SYSTEM32\hpinkstsC211LM.dll [333496 2012-12-15] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\HP Discovery Port Monitor (HP DeskJet 2600 series): C:\Windows\SYSTEM32\HPDiscoPM0053.dll [983176 2018-04-17] (Hewlett Packard -> HP Inc.)
HKLM\...\Print\Monitors\SMART Local Port: C:\Windows\system32\smrtlocalmon.dll [37776 2010-07-12] (SMART Technologies ULC -> SMART Technologies ULC)
HKLM\...\Print\Monitors\spe__ Langmon: C:\Windows\SYSTEM32\spe__l.dll [34304 2011-04-11] () [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\88.0.4324.104\Installer\chrmstp.exe [2021-01-26] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\88.1.19.88\Installer\chrmstp.exe [2021-01-28] (Brave Software, Inc. -> Brave Software, Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\...\Authentication\Credential Providers: [{50968FF7-10C1-4fb3-98B0-CD654D6CB97E}] -> C:\Program Files\WIDCOMM\Bluetooth Software\\BtwCP.dll [2014-07-17] (Broadcom Corporation -> Broadcom Corporation.)
HKLM\Software\...\Authentication\Credential Providers: [{D28973E5-8630-41af-8831-50A15FEB396B}] -> C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll [2014-07-17] (Broadcom Corporation -> Broadcom Corporation.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bitmeter2.lnk [2020-06-13]
ShortcutTarget: Bitmeter2.lnk -> C:\Program Files (x86)\Codebox\BitMeter3\BitMeter2.exe () [File not signed]
Startup: C:\Users\davids home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\networx - Shortcut.lnk [2020-12-30]
ShortcutTarget: networx - Shortcut.lnk -> D:\downloads\software\TRAFFIC MONITORING\Networx_Setup_and_Portable-1593\Networx_Setup_and_Portable-1593\64-bit\networx.exe (SOFTPERFECT PTY. LTD. -> SoftPerfect)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {04ADF39B-6211-40E7-8F5E-1C566F0070B9} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [972176 2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {0660CF24-3D9B-4CED-9A06-4370D64908A3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [286088 2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {0E9BF5E3-02A1-401C-BF50-7B853E98114C} - System32\Tasks\{CFC5F543-FD0B-4061-8FF3-918BD11230FA} => "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/...?LastError=1638
Task: {110418DC-7B6F-4954-B5E8-C0FE5F860525} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [693456 2021-01-02] (Mozilla Corporation -> Mozilla Foundation)
Task: {1268FC59-5FD1-4EEA-B87C-E9FC7CA186A7} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe
Task: {12E62D88-AE9E-437A-B00F-20458DEFF6B7} - System32\Tasks\{782D9BD6-F960-4FEC-9AC1-F459102F49C9} => "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/...?LastError=1638
Task: {13D7B664-9777-4CC3-AA27-28C875A78BC8} - System32\Tasks\Opera scheduled Autoupdate 1421366381 => C:\Program Files (x86)\Opera\launcher.exe [1529880 2020-11-25] (Opera Software AS -> Opera Software)
Task: {15D88E18-5A1A-40E8-996F-421C680D9882} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {1698C592-4AB0-4A05-9FE4-3F891B9B9C21} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [7192192 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {1A4D7C99-BF75-46DF-B14D-FD5C102DD168} - System32\Tasks\{37EBCFE2-5C26-4CD1-9152-E90CFDD75064} => C:\Program Files (x86)\QtWeb\QtWeb.exe [7881016 2013-09-09] (LSoft Technologies Inc -> QtWeb.NET)
Task: {1C0633E3-2F48-47F4-9ABB-12111B4F6C36} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2019-11-13] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {23B95387-2B3D-447A-8369-1417C4B8855C} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2590DFDE-1604-44AF-BB65-4E26BDA9A0E3} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646456 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {26039274-0495-477F-9381-3E2CB017DAD6} - System32\Tasks\{F648BB99-2D35-4D82-A366-E8F9372A2526} => "c:\program files (x86)\mozilla firefox\firefox.exe" http://ui.skype.com/...all?page=tsBing
Task: {2A58CACE-D570-412F-A376-7E6FFBF22C6B} - System32\Tasks\{EED0DE2D-0F70-4256-809D-809D27DDDD0B} => C:\Windows\system32\pcalua.exe -a "C:\Users\davids home\Downloads\Shockwave_Installer_Slim(1).exe" -d "C:\Users\davids home\Downloads"
Task: {331A9D8E-4B23-4DD4-9962-54F25CA35953} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [286088 2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {38506CAE-B2A0-4C51-914C-7D2F64DCE5BB} - System32\Tasks\{4AB362AA-C2FB-4778-9B51-F1DB56B4155E} => "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/...?LastError=1638
Task: {3A842B26-E961-46B9-8340-E3C6FEABA24C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {45CF2C34-8748-4B4F-BA69-7FD33D15961D} - System32\Tasks\{5DFD277F-3F93-4563-A5DD-3DEFF4310556} => "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/...?LastError=1638
Task: {4659912D-9E2D-4776-821A-5426679402E0} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [40432 2020-01-29] (Garmin International, Inc. -> )
Task: {4961FD58-7DDB-482D-B588-89E01D3A178A} - \{2609CC50-DA76-4AFC-83C9-43A19C9B397F} -> No File <==== ATTENTION
Task: {4CD98919-1C88-476B-AE48-6EEA76D3819A} - System32\Tasks\{D60F915A-2D57-40C3-B049-E4970422BBEB} => "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/...?LastError=1638
Task: {500EF536-2308-4528-8F71-C0F7F4581CC5} - System32\Tasks\{D9F33E97-426F-4732-BDA2-A1337BAAAEDE} => C:\Windows\system32\pcalua.exe -a "C:\Users\davids home\Downloads\Pinger-release-51862.exe" -d "C:\Users\davids home\Downloads"
Task: {5A51B2D0-937A-4701-BE70-5F5DB3FA918C} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5B680DB2-F686-4546-8156-D926FDDDA0C7} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {61664B92-A765-4C22-8C89-EDCA7FB44AEC} - System32\Tasks\{64CA553F-FBD4-4D11-9BCF-FD03099EE7FD} => C:\Windows\system32\pcalua.exe -a "C:\Users\davids home\Downloads\soph.exe" -d "C:\Users\davids home\Downloads"
Task: {61BFBD1F-1881-48D4-BBFB-885B6B492B8F} - System32\Tasks\{1658666F-6AD7-482B-A2AC-FF2047CD4779} => C:\Windows\system32\pcalua.exe -a "C:\Users\davids home\Downloads\Firefox Setup Stub 22.0(1).exe" -d "C:\Users\davids home\Downloads"
Task: {61F14E18-9650-4BC6-98F9-B11B8FF0BEB2} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6447C14E-1258-4983-ABD2-9AE4C0530960} - System32\Tasks\{07A5538C-4BF3-42C9-ABD9-760D5C2F4465} => "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/...?LastError=1638
Task: {64E07A99-DD99-4004-A64C-36E038AFB777} - System32\Tasks\{F828C793-EFB0-4B5A-BA69-EEF23BCA0AE0} => "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/...?LastError=1638
Task: {655C76FA-4DF9-483B-96CB-9C42A5459936} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc -> Dropbox, Inc.)
Task: {66D9DA4C-3C91-43AB-BEB2-3C7864BE0FBB} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [7651984 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {68AD1E32-4F68-4185-8403-57FD0BE23770} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => C:\Program Files\Microsoft IntelliType Pro\IType.exe [2345848 2009-11-11] (Microsoft Corporation -> Microsoft Corporation)
Task: {6D249839-EEC6-4041-AD37-4CD380439444} - System32\Tasks\after fire => C:\Users\davids home\Desktop\kweyboard short  cuts.png [30392 2018-04-14] () [File not signed]
Task: {6F297FC2-1E71-42AD-B7BA-6BA247BEE2A8} - System32\Tasks\{258AC9D0-8C18-41CB-8142-FD1BC022128D} => C:\Windows\system32\pcalua.exe -a "C:\Users\davids home\AppData\Local\Temp\Temp1_CuteWriter.zip\converter.exe" <==== ATTENTION
Task: {793C3702-16F8-4AF5-9725-1C244484C809} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1349200 2020-11-03] (Adobe Inc. -> Adobe Inc.)
Task: {8098A694-F566-4027-8832-3D55183F3819} - System32\Tasks\{3A921326-38E2-49A6-B7A1-DA90C1C16BC8} => C:\Windows\system32\pcalua.exe -a "C:\Users\davids home\Downloads\Pinger-release-51862 (1).exe" -d "C:\Users\davids home\Downloads"
Task: {87BA2664-3BBA-4D45-8AD8-370657AEE7DA} - System32\Tasks\{EA3AC294-5071-4E6F-838C-93A5F37AA48A} => "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/...&LastError=1638
Task: {880B5F92-6BAD-4144-B70A-D70ED00EEB3D} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {91ACA594-B883-47D5-810D-A625BC63C574} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [4811032 2014-09-26] (Piriform Ltd -> Piriform Ltd)
Task: {948DBE7D-C0CA-40E1-A61C-07321C9405F9} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-10-17] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {9E87121A-B7B3-4AE8-9AC0-E65BC188BFB0} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1128424 2020-10-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9EFB8344-6479-445E-A79A-35416D9669BF} - System32\Tasks\fire => "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" http://www.weather.ca
Task: {A0460E8E-9149-4DB9-AC97-B5D56C845C65} - System32\Tasks\{29CC99BC-DFE0-4AEB-AAB8-86997C6B13C0} => C:\Windows\system32\pcalua.exe -a D:\downloads\software\710_b042_multilanguage.exe -d D:\downloads\software
Task: {A8728782-6686-48F4-9395-7956C24EF92D} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe
Task: {B18E9A5D-0413-4F02-98D4-A3A7D116D6A6} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2019-11-13] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {B4556B6E-FE31-4F09-87ED-E72BC25A6367} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [6944304 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {B6BC6465-0501-494D-B580-9CEEA7511655} - \movie -> No File <==== ATTENTION
Task: {BF36F7B0-8F30-4244-80B4-88007EBF4DA3} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3301176 2020-10-20] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C12D4DC6-21A8-471F-9221-B8F0A0A6DEB9} - System32\Tasks\{0C813B2C-B935-449A-BD7B-596449DA4318} => C:\Windows\system32\pcalua.exe -a "C:\Users\davids home\Downloads\Pinger-release-51862 (1).exe" -d "C:\Users\davids home\Downloads"
Task: {CEDF6FF4-5532-436D-8AB0-B95E9DDF90FA} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-10-17] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {D9E0BFEB-AC33-4D5C-AE51-04345DDCC8BF} - \{B7FFB674-1F32-4651-8661-D3A4BDF8B84E} -> No File <==== ATTENTION
Task: {DEA636CD-CFB4-4A2D-8C3F-ABBC2C8D33B4} - System32\Tasks\{83D90EEF-EDD4-4F45-9EB5-414F37BADAA4} => C:\Windows\system32\pcalua.exe -a "C:\Users\davids home\Downloads\tweakui\tweakui.cpl"
Task: {E80D96EE-C914-4EAE-BC8C-A07A42585655} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc -> Dropbox, Inc.)
Task: {EBD82F01-9081-4A66-BD2B-035E98B85AFB} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [972176 2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {F15888B0-BE02-4046-83B0-81A3B2B2008D} - System32\Tasks\pic => C:\Users\davids home\Desktop\forloops min.png
Task: {F1E7DE2B-2CC2-40C1-987F-E1A6194E13CB} - System32\Tasks\Opera scheduled assistant Autoupdate 1582759496 => C:\Program Files (x86)\Opera\launcher.exe [1529880 2020-11-25] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Program Files (x86)\Opera\assistant" $(Arg0)
Task: {F7DB4BD6-911E-420A-9615-5240216D5E1E} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 05 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 06 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 09 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 05 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 06 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 09 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{12C864D3-3F2F-47CB-9E56-3AE279D1B329}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{61C46E22-0184-4E47-958D-E8C07FC5CD5C}: [DhcpNameServer] 192.168.0.1
 
FireFox:
========
FF DefaultProfile: dz77nqau.default
FF ProfilePath: C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\g9lb5ptp.David new [2020-08-21]
FF ProfilePath: C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default [2021-01-30]
FF Notifications: Mozilla\Firefox\Profiles\dz77nqau.default -> hxxps://realpython.com
FF Extension: (Avira Browser Safety) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2020-10-19]
FF Extension: (Ant Video downloader) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2020-05-23]
FF Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2020-12-20]
FF Extension: (SoundCloud MP3 Downloader) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2020-12-20]
FF Extension: (download-helper) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2020-12-20]
FF Extension: (audio-prime) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2020-12-20]
FF Extension: (OpenVideo - ad-free streaming) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2020-01-11]
FF Extension: (Soundcloud Downloader Pro) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2019-02-02]
FF Extension: (Advance - Powered by Laserlike) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2018-08-12]
FF Extension: (1-Click YouTube Video Downloader) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2018-04-12]
FF Extension: (YouTube Video Downloader/YouTube HD Download) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\[email protected] [2020-06-06]
FF Extension: (Grab Any Media) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{09481d87-0d89-459e-8ea0-42945a7e2df6}.xpi [2019-05-06]
FF Extension: (Save Video As) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{63f3b52d-7581-42cd-9e82-fb1b2cdb0043}.xpi [2019-02-08]
FF Extension: (Open in VLC™ media player) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{6b954d17-d17c-4a19-8fe6-ee8052a562d6}.xpi [2019-10-13]
FF Extension: (Video & Audio Downloader) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{72013dc0-572a-46a6-93a7-07d8740c6dbe}.xpi [2020-06-06]
FF Extension: (NoScript) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2021-01-06]
FF Extension: (Flash and Video Download) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{adeadebb-fedc-4180-a7f4-cfdd87496551}.xpi [2020-06-10]
FF Extension: (Download Streamable Video) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{b4629e37-bbce-479a-8805-8235727e5abc}.xpi [2019-04-18]
FF Extension: (Private Video Downloader) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{b9a672d6-0a2c-470e-9bed-1ca2e2a900c5}.xpi [2017-11-19]
FF Extension: (Video DownloadHelper) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-12-20]
FF Extension: (1-Click Downloader (Video or Photo)) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{bdfd9428-8d65-4ff5-bc97-4a883c2aba9c}.xpi [2018-09-19]
FF Extension: (SoundCloud Downloader) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{c7a839e7-7086-4021-8176-1cfcb7f169ce}.xpi [2021-01-06]
FF Extension: (Easy Video Downloader) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{cd04e15e-6b23-4648-860d-0057602a5c2a}.xpi [2020-05-23]
FF Extension: (DownThemAll!) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2019-11-26]
FF Extension: (Diigo Web Collector - Capture and Annotate) - C:\Users\davids home\AppData\Roaming\Mozilla\Firefox\Profiles\dz77nqau.default\Extensions\{fc2b8f80-d9a5-4f51-8076-7c7ce3c67ee3}.xpi [2017-09-22]
FF Plugin: @java.com/DTPlugin,version=11.241.2 -> C:\Program Files\Java\jre1.8.0_241\bin\dtplugin\npDeployJava1.dll [2020-01-27] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.241.2 -> C:\Program Files\Java\jre1.8.0_241\bin\plugin2\npjp2.dll [2020-01-27] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLCnew\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll [2014-06-24] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc. -> Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-06-08] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-07-23] (Nullsoft, Inc.) [File not signed]
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2012-12-13] (Research In Motion -> )
FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=3 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2019-11-13] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=9 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2019-11-13] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-12-07] (Adobe Inc. -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 2
CHR Profile: C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default [2021-01-30]
CHR Extension: (YouTube™ No Buffer (Stop Auto-playing)) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\afgfpcfjdgakemlmlgadojdfnejkpegd [2020-11-27]
CHR Extension: (Google Drive) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-31]
CHR Extension: (DuckDuckGo) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2021-01-11]
CHR Extension: (Honey) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2021-01-11]
CHR Extension: (Avira Password Manager) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2021-01-30]
CHR Extension: (Time spend on Facebook) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbdiihnkhjaiokcaeiecemajlohbhefo [2017-07-12]
CHR Extension: (Avira Safe Shopping) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2021-01-30]
CHR Extension: (Finance Toolbar - Real Time Stock Tracker) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\cichbngoomgnobmmjpagmbkimbamigie [2020-03-26]
CHR Extension: (uBlock Origin) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2021-01-11]
CHR Extension: (Tampermonkey) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2020-11-27]
CHR Extension: (Firebug Lite for Google Chrome) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehemiojjcpldeipjhjkepfdaohajpbdo [2020-11-02]
CHR Extension: (Blur) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2021-01-30]
CHR Extension: (Avira Browser Safety) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2020-12-09]
CHR Extension: (IBA Opt-out (by Google)) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbiekjoijknlhijdjbaadobpkdhmoebb [2016-03-17]
CHR Extension: (Google Docs Offline) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-27]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-01-30]
CHR Extension: (Google Keep - Notes and Lists) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2021-01-30]
CHR Extension: (Read&Write for Google Chrome™) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\inoeonmfapjbbkmdafoankkfajkcphgd [2020-12-09]
CHR Extension: (StayFocusd) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2020-11-28]
CHR Extension: (Skype) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-01]
CHR Extension: (Video Downloader GetThemAll) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbkekaeindpfpcoldfckljplboolgkfm [2017-07-30]
CHR Extension: (Images ON/OFF) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfmlhilnjccdggifdbhnhkffmjgalbgg [2020-03-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Chrome Media Router) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-12-09]
CHR Profile: C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-06-14]
CHR Profile: C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1 [2020-12-23]
CHR DefaultSearchURL: Profile 1 -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
CHR DefaultSearchKeyword: Profile 1 -> Yahoo
CHR DefaultSuggestURL: Profile 1 -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Extension: (Docs) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-07]
CHR Extension: (Google Drive) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-02]
CHR Extension: (YouTube) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-02]
CHR Extension: (Avira Password Manager) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2020-09-07]
CHR Extension: (Avira Safe Shopping) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2020-09-07]
CHR Extension: (Google Search) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-02]
CHR Extension: (Tampermonkey) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2020-12-18]
CHR Extension: (Google Docs Offline) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-12-18]
CHR Extension: (Yahoo Partner) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kpdmjodecdegfglgaapafjleomjjlpnh [2019-06-24]
CHR Extension: (Skype) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2018-01-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-06-24]
CHR Extension: (Chrome Media Router) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-12-18]
CHR Profile: C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2 [2021-01-30]
CHR Notifications: Profile 2 -> hxxps://meet.google.com
CHR DefaultSearchURL: Profile 2 -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
CHR DefaultSearchKeyword: Profile 2 -> Yahoo
CHR DefaultSuggestURL: Profile 2 -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Session Restore: Profile 2 -> is enabled.
CHR Extension: (Slides) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-07-02]
CHR Extension: (Docs) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2019-07-02]
CHR Extension: (Google Drive) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-29]
CHR Extension: (YouTube) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-07-02]
CHR Extension: (Avira Password Manager) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2021-01-11]
CHR Extension: (Avira Safe Shopping) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2021-01-11]
CHR Extension: (Rakuten: Get Cash Back For Shopping) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\chhjbpecpncaggjpdakmflnfcopglcmi [2021-01-11]
CHR Extension: (Tampermonkey) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2020-11-27]
CHR Extension: (Sheets) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-07-02]
CHR Extension: (Avira Browser Safety) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2020-12-09]
CHR Extension: (Google Docs Offline) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-27]
CHR Extension: (Page Marker) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\jfiihjeimjpkpoaekpdpllpaeichkiod [2021-01-29]
CHR Extension: (Yahoo Partner) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\kpdmjodecdegfglgaapafjleomjjlpnh [2019-07-02]
CHR Extension: (Skype) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2019-07-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-29]
CHR Extension: (Chrome Media Router) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-12-09]
CHR Profile: C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3 [2020-12-20]
CHR DefaultSearchURL: Profile 3 -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
CHR DefaultSearchKeyword: Profile 3 -> Yahoo
CHR DefaultSuggestURL: Profile 3 -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Extension: (Slides) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-02-16]
CHR Extension: (Docs) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2020-02-16]
CHR Extension: (Google Drive) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-02-16]
CHR Extension: (YouTube) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-02-16]
CHR Extension: (Tampermonkey) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2020-02-16]
CHR Extension: (Sheets) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-02-16]
CHR Extension: (Avira Browser Safety) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2020-02-16]
CHR Extension: (Google Docs Offline) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-02-16]
CHR Extension: (Yahoo Partner) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\kpdmjodecdegfglgaapafjleomjjlpnh [2020-02-16]
CHR Extension: (Skype) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2020-02-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-02-16]
CHR Extension: (Gmail) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-02-16]
CHR Extension: (Chrome Media Router) - C:\Users\davids home\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-02-16]
CHR Profile: C:\Users\davids home\AppData\Local\Google\Chrome\User Data\System Profile [2020-12-20]
CHR HKU\S-1-5-21-3046525360-976882445-4112316675-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32\...\Chrome\Extension: [kpdmjodecdegfglgaapafjleomjjlpnh]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl]
 
Opera: 
=======
OPR Profile: C:\Users\davids home\AppData\Roaming\Opera Software\Opera Stable [2021-01-30]
OPR Notifications: Opera Stable -> hxxps://www.smithsonianmag.com
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\davids home\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2020-10-22]
 
Brave: 
=======
BRA DefaultProfile: Profile 1
BRA Profile: C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2021-01-25]
BRA DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
BRA DefaultSearchKeyword: Default -> Yahoo
BRA DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
BRA Extension: (Avira Password Manager) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2021-01-20]
BRA Extension: (Avira Safe Shopping) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2021-01-20]
BRA Extension: (Tampermonkey) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2020-11-23]
BRA Extension: (Avira Browser Safety) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2020-12-04]
BRA Extension: (Yahoo Partner) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\kpdmjodecdegfglgaapafjleomjjlpnh [2019-11-13]
BRA Extension: (Skype) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2019-11-13]
BRA Profile: C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Guest Profile [2020-07-21]
BRA Profile: C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 1 [2021-01-30]
BRA DefaultSearchURL: Profile 1 -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
BRA DefaultSearchKeyword: Profile 1 -> Yahoo
BRA DefaultSuggestURL: Profile 1 -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
BRA Extension: (Google Translate) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 1\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2020-04-15]
BRA Extension: (Avira Password Manager) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 1\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2021-01-27]
BRA Extension: (Avira Safe Shopping) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 1\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2021-01-28]
BRA Extension: (Tampermonkey) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 1\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2020-10-22]
BRA Extension: (Avira Browser Safety) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 1\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2020-12-02]
BRA Extension: (Steam Database) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 1\Extensions\kdbmhfkmnlmbkgbabkdealhhbfhlmmon [2020-12-24]
BRA Extension: (Yahoo Partner) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 1\Extensions\kpdmjodecdegfglgaapafjleomjjlpnh [2020-03-21]
BRA Extension: (Skype) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2020-03-21]
BRA Profile: C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 2 [2020-12-21]
BRA DefaultSearchURL: Profile 2 -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
BRA DefaultSearchKeyword: Profile 2 -> Yahoo
BRA DefaultSuggestURL: Profile 2 -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
BRA Extension: (Avira Password Manager) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 2\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2020-12-20]
BRA Extension: (Avira Safe Shopping) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 2\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2020-12-21]
BRA Extension: (Tampermonkey) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 2\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2020-12-20]
BRA Extension: (Avira Browser Safety) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 2\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2020-12-21]
BRA Extension: (Yahoo Partner) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 2\Extensions\kpdmjodecdegfglgaapafjleomjjlpnh [2020-03-28]
BRA Extension: (Skype) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 2\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2020-03-28]
BRA Profile: C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 3 [2020-09-07]
BRA DefaultSearchURL: Profile 3 -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
BRA DefaultSearchKeyword: Profile 3 -> Yahoo
BRA DefaultSuggestURL: Profile 3 -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
BRA Extension: (Avira Password Manager) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 3\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2020-09-07]
BRA Extension: (Avira Safe Shopping) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 3\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2020-09-07]
BRA Extension: (Tampermonkey) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 3\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2020-09-07]
BRA Extension: (Avira Browser Safety) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 3\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2020-05-07]
BRA Extension: (Yahoo Partner) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 3\Extensions\kpdmjodecdegfglgaapafjleomjjlpnh [2020-04-07]
BRA Extension: (Skype) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Profile 3\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2020-04-07]
BRA Profile: C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\System Profile [2020-04-07]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2021-01-28]
BRA Extension: (chromeAutofillStatesData) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\AutofillStates [2020-12-01]
BRA Extension: (Brave Ad Block Updater (Default)) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2021-01-30]
BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2020-07-14]
BRA Extension: (Crowd Deny) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\Crowd Deny [2020-12-01]
BRA Extension: (Brave User Model Installer) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\emgmepnebbddgnkhfmhdhmjifkglkamo [2021-01-30]
BRA Extension: (Brave NTP sponsored images) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\gccbbckogglekeggclmmekihdgdpdgoe [2021-01-30]
BRA Extension: (Brave SpeedReader Updater) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\jicbkmdloagakknpihibphagfckhjdih [2020-08-13]
BRA Extension: (Brave User Model Installer) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\kkjipiepeooghlclkedllogndmohhnhi [2021-01-30]
BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2021-01-26]
BRA Extension: (Origin Trials Updates) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\OriginTrials [2020-09-23]
BRA Extension: (safetyTips) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\SafetyTips [2020-12-06]
BRA Extension: (sslErrorAssistant) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\SSLErrorAssistant [2020-09-23]
BRA Extension: (legacyTLSDeprecation) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\TLSDeprecationConfig [2020-09-23]
BRA Extension: (zxcvbnData) - C:\Users\davids home\AppData\Local\BraveSoftware\Brave-Browser\User Data\ZxcvbnData [2020-12-01]
StartMenuInternet: Brave - C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-02-08] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [170056 2020-11-03] (Adobe Inc. -> Adobe Inc.)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] (Giga-Byte Technology -> )
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [636264 2020-05-08] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S3 Blackberry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [577536 2013-01-18] (Research In Motion Limited) [File not signed]
S2 BMService; C:\Program Files\SoftPerfect Bandwidth Manager\BMCore.exe [10075464 2016-11-28] (SOFTPERFECT PTY. LTD. -> SoftPerfect)
S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2019-11-13] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [157320 2019-11-13] (Brave Software, Inc. -> BraveSoftware Inc.)
R2 CG6Service; C:\Program Files\CyberGhost 6\CyberGhost.Service.exe [204880 2018-06-11] (CyberGhost SRL -> CyberGhost S.A.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3052944 2020-07-14] (Microsoft Corporation -> Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [44064 2021-01-25] (Dropbox, Inc -> Dropbox, Inc.)
R2 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [40016 2019-07-01] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
R2 ES lite Service; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [68136 2009-08-24] (Giga-Byte Technology -> )
R2 Everything; C:\Program Files (x86)\Everything\Everything.exe [1048576 2014-08-05] () [File not signed]
S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [81280 2019-12-25] (Mixbyte Inc -> Freemake)
R2 GlassWire; C:\Program Files (x86)\GlassWire\GWCtlSrv.exe [5422048 2020-08-14] (GlassWire -> SecureMix LLC)
S3 ICCS; C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [8967416 2020-11-26] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
R2 MBAMIService; C:\ProgramData\MB3Install\MBAMIService.exe [170496 2018-05-29] (Malwarebytes) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-13] (Malwarebytes Inc -> Malwarebytes)
R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4477576 2018-06-18] (Logitech Inc -> Logitech)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3892256 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [3943664 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233712 2018-02-06] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SMARTHelperService; C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe [538416 2014-02-12] (SMART Technologies ULC -> SMART Technologies)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 UTSCSI; C:\Windows\SysWOW64\UTSCSI.EXE [45056 2013-01-10] () [File not signed]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies Inc. -> VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292480 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AM10; C:\Windows\System32\DRIVERS\am10w7.sys [1101600 2010-03-23] (Ralink Technology Corporation -> Ralink Technology Corp.)
S3 AODDriver; C:\Program Files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [52280 2010-03-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] (Giga-Byte Technology -> )
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [120416 2016-01-08] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.(www.devguru.co.kr))
R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [54152 2019-07-01] (CHENGDU YIWO Tech Development Co., Ltd. -> )
R3 gdrv; C:\Windows\gdrv.sys [25640 2021-01-30] (Giga-Byte Technology -> Windows ® Server 2003 DDK provider)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-02-08] (GIGA-BYTE TECHNOLOGY CO., LTD -> )
R1 gwdrv; C:\Windows\System32\DRIVERS\gwdrv.sys [33248 2015-05-29] (GlassWire -> SecureMix LLC)
S3 LGBusEnum; C:\Windows\System32\drivers\LGBusEnum.sys [37408 2015-06-10] (Microsoft Windows Hardware Compatibility Publisher -> Logitech Inc.)
S3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [68384 2015-06-10] (Microsoft Windows Hardware Compatibility Publisher -> Logitech Inc.)
S3 LGVirHid; C:\Windows\System32\drivers\LGVirHid.sys [26912 2015-06-10] (Microsoft Windows Hardware Compatibility Publisher -> Logitech Inc.)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-06-11] (Malwarebytes Inc -> Malwarebytes)
R1 networx; C:\Windows\System32\drivers\networx.sys [96488 2020-03-13] (SoftPerfect Pty. Ltd. -> Windows ® Win 7 DDK provider)
S3 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 PCAMp50a64; C:\Windows\System32\Drivers\PCAMp50a64.sys [43328 2006-11-28] (PRINTING COMMUNICATIONS ASSOC., INC. -> Printing Communications Assoc., Inc. (PCAUSA))
S3 PCASp50a64; C:\Windows\System32\Drivers\PCASp50a64.sys [41280 2006-11-28] (PRINTING COMMUNICATIONS ASSOC., INC. -> Printing Communications Assoc., Inc. (PCAUSA))
S3 PSMounterEx; C:\Windows\system32\drivers\psmounterex.sys [179416 2019-02-15] (Paramount Software UK Ltd -> Windows ® Win 7 DDK provider)
S3 psvolacc; C:\Windows\system32\drivers\psvolacc.sys [34520 2018-12-06] (Paramount Software UK Ltd -> Windows ® Win 7 DDK provider)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [78336 2013-01-03] (Microsoft Windows Hardware Compatibility Publisher -> Research In Motion Limited)
R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Microsoft Windows Hardware Compatibility Publisher -> Research in Motion Ltd)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SMARTMouseFilterx64; C:\Windows\System32\DRIVERS\SMARTMouseFilterx64.sys [10240 2013-08-12] (Microsoft Windows Hardware Compatibility Publisher -> SMART Technologies)
R3 SMARTVHidMiniVistaAmd64; C:\Windows\System32\DRIVERS\SMARTVHidMiniVistaAmd64.sys [9216 2013-08-12] (Microsoft Windows Hardware Compatibility Publisher -> SMART Technologies)
S3 SMARTVTabletPCx64; C:\Windows\System32\DRIVERS\SMARTVTabletPCx64.sys [22184 2013-08-12] (smarttech.com(Test) -> SMART Technologies ULC)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [213088 2016-01-08] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.(www.devguru.co.kr))
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R3 USBPcap; C:\Windows\System32\DRIVERS\USBPcap.sys [48960 2019-08-11] (Tomasz Moń -> USBPcap)
R3 VBAudioVMVAIOMME; C:\Windows\System32\DRIVERS\vbaudio_vmvaio64_win7.sys [63936 2019-09-17] (Vincent Burel -> Windows ® Win 7 DDK provider)
S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam64_prewin8.sys [31920 2018-02-26] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies)
S3 ZSMC211; C:\Windows\System32\Drivers\ZS211.sys [1493120 2007-06-13] (ZSMC.Corporation) [File not signed]
S3 dbx; system32\DRIVERS\dbx.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
U4 npcap_wifi; no ImagePath
S3 PID_0928; system32\DRIVERS\LV561V64.SYS [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 WN111v2; system32\DRIVERS\WN111v2w7x.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2021-01-29 20:11 - 2021-01-29 20:11 - 000047737 _____ C:\Users\davids home\Downloads\Alcatel Bypass Google Verify - HardReset.info.apk
2021-01-29 16:05 - 2021-01-29 16:05 - 000086616 _____ C:\Users\davids home\Downloads\Final Project.py
2021-01-28 23:23 - 2021-01-28 23:38 - 006266942 _____ C:\Users\davids home\Desktop\jason.psd
2021-01-26 21:36 - 2021-01-26 21:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2021-01-25 11:12 - 2021-01-25 11:12 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2021-01-25 11:12 - 2021-01-25 11:12 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2021-01-25 11:12 - 2021-01-25 11:12 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2021-01-25 11:12 - 2021-01-25 11:12 - 000044064 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2021-01-22 15:11 - 2021-01-22 18:35 - 000000000 ____D C:\Program Files\DiskGenius
2021-01-22 15:11 - 2021-01-22 15:11 - 000000796 _____ C:\Users\Public\Desktop\DiskGenius.lnk
2021-01-22 15:11 - 2021-01-22 15:11 - 000000796 _____ C:\ProgramData\Desktop\DiskGenius.lnk
2021-01-22 15:11 - 2021-01-22 15:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskGenius
2021-01-22 14:51 - 2021-01-22 14:51 - 000000000 ____D C:\Users\davids home\AppData\Local\TempTaskUpdateDetection9C962C5B-8078-47EB-B527-545643EC8054
2021-01-22 11:01 - 2021-01-22 11:01 - 000001422 _____ C:\Users\Public\Desktop\Data Lifeguard Diagnostic for Windows.lnk
2021-01-22 11:01 - 2021-01-22 11:01 - 000001422 _____ C:\ProgramData\Desktop\Data Lifeguard Diagnostic for Windows.lnk
2021-01-22 11:01 - 2021-01-22 11:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital Corporation
2021-01-22 11:01 - 2021-01-22 11:01 - 000000000 ____D C:\Program Files (x86)\Western Digital Corporation
2021-01-20 02:54 - 2021-01-20 02:54 - 000000000 __SHD C:\found.001
2021-01-19 23:17 - 2021-01-19 23:47 - 001287832 _____ C:\Windows\ntbtlog.txt
2021-01-15 14:18 - 2021-01-15 14:18 - 000000511 _____ C:\Users\davids home\Downloads\about
2021-01-15 09:50 - 2021-01-15 09:50 - 016443786 _____ C:\Users\davids home\Downloads\[PROTOTYPE] One Night at Chocis (2).sb3
2021-01-14 14:16 - 2021-01-29 16:22 - 000000000 ____D C:\ICS3U
2021-01-14 09:34 - 2021-01-14 09:34 - 000060701 _____ C:\Users\davids home\Downloads\End of Semester 1 Calendar 2021 (1).pdf
2021-01-13 14:27 - 2021-01-13 14:27 - 000060701 _____ C:\Users\davids home\Downloads\End of Semester 1 Calendar 2021.pdf
2021-01-09 14:51 - 2021-01-09 14:51 - 000001360 _____ C:\Users\davids home\Documents\mousebutton down.py
2021-01-07 21:44 - 2021-01-07 21:44 - 000000000 ____D C:\Program Files (x86)\Audacity222
2021-01-07 13:29 - 2021-01-04 09:33 - 001855192 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2021-01-07 13:29 - 2021-01-04 09:33 - 001855192 _____ C:\Windows\system32\vulkaninfo.exe
2021-01-07 13:29 - 2021-01-04 09:33 - 001435864 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2021-01-07 13:29 - 2021-01-04 09:33 - 001435864 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2021-01-07 13:29 - 2021-01-04 09:33 - 001094880 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2021-01-07 13:29 - 2021-01-04 09:33 - 001094880 _____ C:\Windows\system32\vulkan-1.dll
2021-01-07 13:29 - 2021-01-04 09:33 - 000948952 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2021-01-07 13:29 - 2021-01-04 09:33 - 000948952 _____ C:\Windows\SysWOW64\vulkan-1.dll
2021-01-07 13:29 - 2021-01-04 09:32 - 062437272 _____ (NVIDIA Corporation) C:\Windows\system32\nvrtum64.dll
2021-01-07 13:29 - 2021-01-04 09:32 - 008388504 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler64.dll
2021-01-07 13:29 - 2021-01-04 09:32 - 007413656 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler32.dll
2021-01-07 13:29 - 2021-01-04 09:32 - 000523672 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2021-01-07 13:29 - 2021-01-04 09:32 - 000452504 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2021-01-07 13:29 - 2021-01-04 09:32 - 000450456 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2021-01-07 13:29 - 2021-01-04 09:32 - 000352152 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2021-01-07 13:29 - 2021-01-04 09:31 - 158398872 _____ (NVIDIA Corporation) C:\Windows\system32\nvoptix.dll
2021-01-07 13:29 - 2021-01-04 09:31 - 042945944 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2021-01-07 13:29 - 2021-01-04 09:31 - 032197016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2021-01-07 13:29 - 2021-01-04 09:31 - 018705304 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl64.dll
2021-01-07 13:29 - 2021-01-04 09:31 - 016246168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl32.dll
2021-01-07 13:29 - 2021-01-04 09:31 - 000431000 _____ C:\Windows\system32\nvofapi64.dll
2021-01-07 13:29 - 2021-01-04 09:31 - 000384920 _____ C:\Windows\SysWOW64\nvofapi.dll
2021-01-07 13:29 - 2021-01-04 09:31 - 000199576 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2021-01-07 13:29 - 2021-01-04 09:31 - 000168344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 038580120 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2021-01-07 13:29 - 2021-01-04 09:30 - 007848856 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 002104728 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 001733016 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6446109.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 001588632 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 001512856 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 001492376 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6446109.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 001165208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 000673688 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 000559000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 000545688 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 000474008 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 000220056 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2021-01-07 13:29 - 2021-01-04 09:30 - 000187800 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2021-01-07 13:29 - 2021-01-04 09:29 - 040704920 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler64.dll
2021-01-07 13:29 - 2021-01-04 09:29 - 035556248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler32.dll
2021-01-07 13:29 - 2021-01-04 09:29 - 022685080 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2021-01-07 13:29 - 2021-01-04 09:29 - 019800472 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2021-01-07 13:29 - 2021-01-04 09:29 - 007093144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2021-01-07 13:29 - 2021-01-04 09:29 - 000683928 _____ (NVIDIA Corporation) C:\Windows\system32\nvcbl64.dll
2021-01-07 13:29 - 2021-01-04 09:25 - 029605648 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2021-01-07 13:29 - 2021-01-04 09:25 - 024806376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2021-01-07 13:29 - 2021-01-04 09:25 - 006186376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2021-01-07 13:29 - 2020-12-31 08:49 - 000135592 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2021-01-07 13:29 - 2020-12-31 08:49 - 000038640 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2021-01-07 13:29 - 2020-12-31 08:49 - 000000671 _____ C:\Windows\SysWOW64\nv-vk32.json
2021-01-07 13:29 - 2020-12-31 08:49 - 000000671 _____ C:\Windows\system32\nv-vk64.json
2021-01-07 10:27 - 2021-01-07 10:27 - 000000000 ____D C:\Users\davids home\AppData\Roaming\Teams
2021-01-06 22:53 - 2021-01-06 22:53 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2021-01-04 15:02 - 2021-01-04 15:02 - 000339479 _____ C:\Users\davids home\Desktop\ICS2O1-01-ClassList (1).pdf
2021-01-03 20:45 - 2021-01-09 14:41 - 000001694 _____ C:\Users\davids home\Documents\particle.py
2021-01-02 19:18 - 2021-01-07 08:49 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2021-01-02 18:39 - 2021-01-09 15:28 - 000002181 _____ C:\Users\davids home\Documents\testing menu.py
2021-01-02 17:01 - 2021-01-02 17:25 - 000001125 _____ C:\Users\davids home\Documents\menu system test 1.py
2021-01-01 15:36 - 2021-01-02 19:38 - 000002393 _____ C:\Users\davids home\Documents\pygame testing function text.py
2021-01-01 14:54 - 2021-01-03 18:33 - 000002690 _____ C:\Users\davids home\Documents\menu system.py
2020-12-31 17:00 - 2020-12-31 17:14 - 000000000 ____D C:\Users\davids home\AppData\Local\gameName
2020-12-31 17:00 - 2020-12-31 17:00 - 000000222 _____ C:\Users\davids home\Desktop\This Book Is A Dungeon.url
2020-12-31 17:00 - 2020-12-31 17:00 - 000000000 ____D C:\Users\davids home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2021-01-30 15:10 - 2020-06-13 10:30 - 000000000 ____D C:\ProgramData\Bitmeter2
2021-01-30 15:10 - 2016-03-17 09:47 - 000000000 ____D C:\FRST
2021-01-30 14:36 - 2013-01-12 04:27 - 000000000 ____D C:\Users\davids home\AppData\Local\Deployment
2021-01-30 10:53 - 2009-07-13 23:45 - 000027808 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2021-01-30 10:53 - 2009-07-13 23:45 - 000027808 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2021-01-30 10:50 - 2009-07-14 00:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
2021-01-30 10:50 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2021-01-30 10:45 - 2014-07-23 16:41 - 000000000 ____D C:\ProgramData\Package Cache
2021-01-30 10:44 - 2013-09-22 17:34 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2021-01-30 10:44 - 2013-01-06 23:07 - 000000000 ____D C:\ProgramData\NVIDIA
2021-01-30 10:43 - 2013-02-09 10:40 - 000025640 _____ (Windows ® Server 2003 DDK provider) C:\Windows\gdrv.sys
2021-01-30 10:43 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-01-28 23:23 - 2013-02-03 11:15 - 000000000 ____D C:\Users\davids home\AppData\Roaming\Adobe
2021-01-28 19:55 - 2018-01-08 21:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2021-01-28 14:40 - 2019-11-13 20:09 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2021-01-26 21:36 - 2015-07-17 14:39 - 000000000 ____D C:\Program Files (x86)\Dropbox
2021-01-26 20:54 - 2013-01-12 04:28 - 000002184 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-01-26 15:11 - 2020-09-06 13:23 - 000000000 ____D C:\Users\davids home\Desktop\dads book
2021-01-26 09:27 - 2014-06-03 21:10 - 000000000 ____D C:\Users\davids home\AppData\Local\Greenshot
2021-01-24 18:03 - 2019-09-27 20:21 - 000000000 ____D C:\Users\davids home\AppData\Roaming\obs-studio
2021-01-24 18:02 - 2018-03-18 12:40 - 000000000 ____D C:\Users\davids home\Desktop\a thru i
2021-01-24 18:01 - 2013-04-09 20:55 - 000000000 ____D C:\Users\davids home\AppData\Roaming\vlc
2021-01-23 13:53 - 2020-09-29 12:46 - 000000000 ____D C:\Users\davids home\Desktop\python grade 11 school
2021-01-22 23:25 - 2015-07-17 14:39 - 000000918 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2021-01-22 23:25 - 2015-07-17 14:39 - 000000914 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2021-01-22 17:29 - 2013-07-03 17:18 - 000000000 ____D C:\Users\davids home\AppData\Local\CrashDumps
2021-01-22 16:09 - 2015-07-17 14:39 - 000003916 _____ C:\Windows\system32\Tasks\DropboxUpdateTaskMachineUA
2021-01-22 16:09 - 2015-07-17 14:39 - 000003664 _____ C:\Windows\system32\Tasks\DropboxUpdateTaskMachineCore
2021-01-22 14:47 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\system32\NDF
2021-01-22 11:48 - 2017-07-03 19:54 - 000000616 __RSH C:\ProgramData\ntuser.pol
2021-01-20 09:48 - 2014-06-08 14:09 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-01-20 09:48 - 2014-06-08 14:02 - 000000000 ____D C:\Program Files\Microsoft Office 15
2021-01-19 23:20 - 2020-08-19 22:40 - 000000000 ____D C:\ProgramData\AVG
2021-01-18 10:11 - 2020-09-06 14:43 - 000000000 ____D C:\Users\davids home\Desktop\SCHOOL 2020 COVID sept jan
2021-01-18 10:10 - 2020-09-06 13:09 - 000000000 ____D C:\Users\davids home\Desktop\instructables
2021-01-17 22:58 - 2020-12-30 13:38 - 000003162 _____ C:\Windows\system32\Tasks\{29CC99BC-DFE0-4AEB-AAB8-86997C6B13C0}
2021-01-17 22:58 - 2020-08-22 20:11 - 000000000 ____D C:\Windows\system32\Tasks\AVAST Software
2021-01-17 22:58 - 2013-01-12 04:27 - 000003332 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2021-01-17 22:58 - 2013-01-12 04:27 - 000003204 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2021-01-17 20:39 - 2020-02-03 23:31 - 000000000 ____D C:\Program Files (x86)\Steam
2021-01-15 17:06 - 2016-04-02 09:24 - 000000000 ____D C:\Users\davids home\AppData\Roaming\brave
2021-01-14 15:55 - 2019-11-12 20:13 - 000000000 ____D C:\Users\davids home\AppData\Roaming\Discord
2021-01-14 15:47 - 2019-11-12 20:13 - 000000000 ____D C:\Users\davids home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2021-01-14 15:47 - 2019-11-12 20:13 - 000000000 ____D C:\Users\davids home\AppData\Local\Discord
2021-01-10 19:18 - 2020-03-01 21:48 - 000000000 ____D C:\Users\davids home\.openshot_qt
2021-01-07 21:46 - 2013-11-04 19:14 - 000000000 ____D C:\Users\davids home\AppData\Roaming\Audacity
2021-01-07 21:44 - 2020-04-17 19:45 - 000000988 _____ C:\Users\Public\Desktop\Audacity.lnk
2021-01-07 21:44 - 2020-04-17 19:45 - 000000988 _____ C:\ProgramData\Desktop\Audacity.lnk
2021-01-07 21:44 - 2020-02-16 14:03 - 000001000 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2021-01-07 13:33 - 2020-08-11 20:14 - 000000000 ____D C:\NVIDIA
2021-01-07 13:31 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\Help
2021-01-07 13:30 - 2020-08-17 15:26 - 000000000 ____D C:\Users\davids home\AppData\Roaming\NVIDIA
2021-01-07 13:30 - 2013-01-06 23:05 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2021-01-07 13:29 - 2014-04-21 22:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2021-01-07 10:56 - 2019-02-12 15:17 - 000000000 ____D C:\ICS4U
2021-01-07 10:27 - 2020-03-30 09:26 - 000002279 _____ C:\Users\davids home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2021-01-07 08:49 - 2013-01-12 04:33 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-01-06 23:00 - 2016-11-15 20:04 - 000000000 ____D C:\Users\davids home\AppData\LocalLow\Mozilla
2021-01-06 22:56 - 2014-05-23 23:28 - 000000000 ____D C:\Users\davids home\dwhelper
2021-01-06 22:54 - 2013-01-12 04:33 - 000000000 ____D C:\ProgramData\Mozilla
2021-01-04 09:42 - 2019-03-09 13:57 - 000000000 ____D C:\Users\davids home\Desktop\writing
2021-01-04 09:25 - 2020-08-11 20:15 - 076855672 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2021-01-04 09:25 - 2020-08-11 20:15 - 037682688 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2021-01-04 09:25 - 2020-08-11 20:15 - 007312096 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2021-01-03 16:11 - 2013-01-06 22:47 - 000000000 ____D C:\Users\davids home
2020-12-31 08:49 - 2020-04-22 17:33 - 001682376 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2020-12-31 08:49 - 2020-04-22 17:33 - 000058605 _____ C:\Windows\system32\nvinfo.pb
2020-12-31 04:48 - 2020-04-22 17:35 - 005623272 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2020-12-31 04:48 - 2020-04-22 17:35 - 002637800 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2020-12-31 04:48 - 2020-04-22 17:35 - 001760232 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2020-12-31 04:48 - 2020-04-22 17:35 - 000992232 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2020-12-31 04:48 - 2020-04-22 17:35 - 000122344 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2020-12-31 04:48 - 2020-04-22 17:35 - 000084456 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
 
==================== Files in the root of some directories ========
 
2015-08-23 14:18 - 2020-12-21 20:57 - 000065588 _____ () C:\Users\davids home\AppData\Roaming\Camdata.ini
2015-08-23 14:18 - 2020-12-21 20:57 - 000000408 _____ () C:\Users\davids home\AppData\Roaming\CamLayout.ini
2015-08-23 14:18 - 2020-12-21 20:57 - 000000408 _____ () C:\Users\davids home\AppData\Roaming\CamShapes.ini
2015-08-23 14:18 - 2020-12-21 20:57 - 000004512 _____ () C:\Users\davids home\AppData\Roaming\CamStudio.cfg
2018-04-20 20:10 - 2018-04-20 20:10 - 000000128 ____H () C:\Users\davids home\AppData\Roaming\ecf00c38dc807e105d881c433a6b455dd2c606b6
2020-12-10 19:15 - 2020-12-11 15:37 - 000000069 _____ () C:\Users\davids home\AppData\Roaming\Mu.launch.pyw.log
2013-01-11 05:32 - 2013-01-11 05:32 - 000012358 _____ () C:\Users\davids home\AppData\Roaming\PFP120JCM.{PB
2013-01-11 05:32 - 2013-01-11 05:32 - 000061678 _____ () C:\Users\davids home\AppData\Roaming\PFP120JPR.{PB
2014-03-01 18:32 - 2019-09-16 21:37 - 000003696 _____ () C:\Users\davids home\AppData\Roaming\Rim.Desktop.Exception.log
2014-03-01 18:31 - 2014-03-01 18:31 - 000001153 _____ () C:\Users\davids home\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2014-03-01 18:32 - 2019-09-16 21:37 - 000003850 _____ () C:\Users\davids home\AppData\Roaming\Rim.DesktopHelper.Exception.log
2019-09-17 20:12 - 2019-09-17 20:56 - 000004651 _____ () C:\Users\davids home\AppData\Roaming\VoiceMeeterDefault.xml
2020-04-28 13:38 - 2020-04-28 13:38 - 000003584 _____ () C:\Users\davids home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-12-20 14:19 - 2020-12-20 14:19 - 000013790 _____ () C:\Users\davids home\AppData\Local\kdenlive-layoutsrc
2020-12-20 14:19 - 2020-12-20 14:19 - 000003711 _____ () C:\Users\davids home\AppData\Local\kdenliverc
2020-05-09 09:28 - 2020-05-18 08:51 - 000007618 _____ () C:\Users\davids home\AppData\Local\resmon.resmoncfg
2020-12-20 14:19 - 2020-12-20 14:19 - 000000533 _____ () C:\Users\davids home\AppData\Local\user-places.xbel
2020-12-20 14:19 - 2020-12-20 14:19 - 000000000 _____ () C:\Users\davids home\AppData\Local\user-places.xbel.tbcache
2020-06-13 14:54 - 2020-06-13 14:54 - 000000000 _____ () C:\Users\davids home\AppData\Local\{07A3E7C5-6BB5-45C7-BC7D-72A25B7743E5}
2020-06-09 11:19 - 2020-06-09 11:19 - 000000000 _____ () C:\Users\davids home\AppData\Local\{6103F7DE-BFD7-4F87-8192-D75C45C4EDC2}
2020-06-09 11:19 - 2020-06-09 11:19 - 000000000 _____ () C:\Users\davids home\AppData\Local\{80B02193-291F-4B93-A2B3-0F87E0E48943}
2020-06-13 14:50 - 2020-06-13 14:50 - 000000000 _____ () C:\Users\davids home\AppData\Local\{DBF76D3E-91E7-474F-A3F9-B80ECC155F0C}
2020-05-04 07:30 - 2020-05-04 07:30 - 000000000 _____ () C:\Users\davids home\AppData\Local\{F9CD4BF5-F6B5-4D49-B0B3-D506AD5FC872}
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
 
LastRegBack: 2021-01-22 18:53
==================== End of FRST.txt ========================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-01-2021
Ran by davids home (30-01-2021 15:10:58)
Running from D:\downloads\software\WINDOWS UTILITIES
Windows 7 Ultimate Service Pack 1 (X64) (2013-01-07 03:47:44)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3046525360-976882445-4112316675-500 - Administrator - Disabled)
davids home (S-1-5-21-3046525360-976882445-4112316675-1000 - Administrator - Enabled) => C:\Users\davids home
Guest (S-1-5-21-3046525360-976882445-4112316675-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Spybot - Search and Destroy (Enabled - Out of date) {4C1D9672-63FE-5C90-371E-8FDA591C5B75}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version:  - )
AC3Filter 1.63b (HKLM-x32\...\AC3Filter_is1) (Version: 1.63b - Alexander Vigovsky)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.013.20074 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.1.0.5790 - Adobe Systems Inc.)
Adobe Creative Suite 4 Web Standard (HKLM-x32\...\Adobe_74391d4c0f181c4d062cf4de6461d86) (Version: 4.0 - Adobe Systems Incorporated)
Adobe CSI CS4 x64 (HKLM\...\{8DAA31EB-6830-4006-A99F-4DF8AB24714F}) (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.3.153 - Adobe Systems, Inc.)
AdoptOpenJDK JDK with Hotspot 11.0.3.7 (x64) (HKLM\...\{99A47A76-3216-431D-A10A-7461CA95C97D}) (Version: 11.0.3.7 - AdoptOpenJDK)
AdoptOpenJDK JDK with Hotspot 8.0.212.04 (x64) (HKLM\...\{7F78F0D1-F82C-4BB2-8C4D-D554C60E99B6}) (Version: 8.0.212.04 - AdoptOpenJDK)
Akamai NetSession Interface (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Akamai) (Version:  - Akamai Technologies, Inc)
ANT Drivers Installer x64 (HKLM\...\{6AA82A23-ABAE-4E28-9476-4DF72E67EFE3}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.10 - Michael Tippach)
Audacity 2.4.2 (HKLM-x32\...\Audacity_is1) (Version: 2.4.2 - Audacity Team)
Avira (HKLM-x32\...\{8FB15125-F526-4632-8055-837D0083EA3B}) (Version: 1.2.126.28786 - Avira Operations GmbH & Co. KG) Hidden
AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version:  - )
BitMeter (HKLM-x32\...\BitMeter) (Version:  - )
BitTorrent (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\BitTorrent) (Version: 7.8.2.30265 - BitTorrent Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Brány Skeldalu pro Windows 1.2 (HKLM-x32\...\Brány Skeldalu_is1) (Version:  - Napoleon games)
Brave (HKLM-x32\...\BraveSoftware Brave-Browser) (Version: 88.1.19.88 - Brave Software Inc)
Brave (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Brave) (Version: 0.9.6 - Brave Software)
CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform)
Collab (HKLM-x32\...\Collab) (Version:  - Image-Line bvba)
COMODO Programs Manager (HKLM\...\{D968E920-3A49-48EB-BA1D-8964DCDF0CA9}) (Version: 1.3_build_30 - COMODO)
Connect (HKLM-x32\...\{B29AD377-CC12-490A-A480-1452337C618D}) (Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
CoreAAC Audio Decoder (remove only) (HKLM-x32\...\CoreAAC Audio Decoder) (Version:  - )
CrystalDiskInfo 8.8.9 (HKLM\...\CrystalDiskInfo_is1) (Version: 8.8.9 - Crystal Dew World)
CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version:  3.0 - CutePDF.com)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Data Lifeguard Diagnostic version 1.37 (HKLM-x32\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version:  - Western Digital Corporation)
DDPB (HKLM-x32\...\{748590DB-44CD-48D2-8585-2496BBFE919F}) (Version: 1.0.9 - DauDen.vn)
Discord (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Discord) (Version: 0.0.309 - Discord Inc.)
DiskGenius 5.4.0 (HKLM\...\{2661F2FA-56A7-415D-8196-C4CB3D3ACFFE}_is1) (Version:  - Eassos Co., Ltd.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 114.4.426 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.415.1 - Dropbox, Inc.) Hidden
Duplicate Cleaner Free 4.1.2 (HKLM-x32\...\Duplicate Cleaner Free) (Version: 4.1.2 - DigitalVolcano Software Ltd)
EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version:  - EaseUS)
EaseUS Todo Backup Free 11.5 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 11.5 - CHENGDU YIWO Tech Development Co., Ltd)
EasyBCD 2.4 (HKLM-x32\...\EasyBCD) (Version: 2.4 - NeoSmart Technologies)
EasyCleaner (HKLM-x32\...\{F5346614-B7C4-4E94-826A-E2363155233D}) (Version: 2.0.6.380 - ToniArts)
Elevated Installer (HKLM-x32\...\{880D2C38-2835-4328-A11C-32DB9EAE6EA1}) (Version: 6.20.0.0 - Garmin Ltd or its subsidiaries) Hidden
EOS Webcam Utility Beta (HKLM\...\{6A2053A2-6427-44AA-8FFA-46A184C47663}) (Version: 0.9.0 - Canon U.S.A., Inc.)
Epic Games Launcher (HKLM-x32\...\{FEF3A9BA-A962-4469-AD62-04839D4BB847}) (Version: 1.1.298.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Etron USB3.0 Host Controller (HKLM-x32\...\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.118 - Etron Technology) Hidden
Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.118 - Etron Technology)
Everything 1.3.4.686 (x86) (HKLM-x32\...\Everything) (Version:  - )
ffdshow [rev 3299] [2010-03-03] (HKLM-x32\...\ffdshow_is1) (Version: 1.0.0.3299 - )
FFmpeg (Windows) for Audacity version 2.2.2 (HKLM-x32\...\{9C7E31E3-017F-434C-AC40-24431A354A1E}_is1) (Version: 2.2.2 - )
FL Studio 10 (HKLM-x32\...\FL Studio 10) (Version:  - Image-Line)
Garmin Express (HKLM-x32\...\{052d79d0-16af-4138-9d84-9f1605c2a26b}) (Version: 6.20.0.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{7C71E35F-9E7D-4B53-909D-6505C3B6689C}) (Version: 6.20.0.0 - Garmin Ltd or its subsidiaries) Hidden
GlassWire 2.2 (remove only) (HKLM-x32\...\GlassWire 2.2) (Version: 2.2.241 - SecureMix LLC)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 88.0.4324.104 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.36.51 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.99.0 - Google Inc.) Hidden
Greenshot 1.2.10.6 (HKLM\...\Greenshot_is1) (Version: 1.2.10.6 - Greenshot)
Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version:  - )
HandBrake 1.0.7 (HKLM-x32\...\HandBrake) (Version: 1.0.7 - )
HP DeskJet 2600 series Basic Device Software (HKLM\...\{FB71D010-BD89-4624-B681-355F72DE4E58}) (Version: 43.3.2478.18107 - HP Inc.)
iFree Skype Recorder 8.0.19 (HKLM-x32\...\iFree Skype Recorder) (Version: 8.0.19 - iFree Skype Recorder)
IL Download Manager (HKLM-x32\...\IL Download Manager) (Version:  - Image-Line)
Intel® PROSet/Wireless Software (HKLM-x32\...\{43534734-7770-4dce-8eda-5d51cefd98e5}) (Version: 21.40.5 - Intel Corporation)
IrfanView 4.51 (32-bit) (HKLM-x32\...\IrfanView) (Version: 4.51 - Irfan Skiljan)
Java 8 Update 241 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180241F0}) (Version: 8.0.2410.7 - Oracle Corporation)
JetBrains PyCharm Community Edition 2018.1.4 (HKLM-x32\...\PyCharm Community Edition 2018.1.4) (Version: 181.5087.37 - JetBrains s.r.o.)
JetBrains PyCharm Community Edition 5.0.4 (HKLM-x32\...\PyCharm Community Edition 5.0.4) (Version: 143.1919.2 - JetBrains s.r.o.)
kdenlive (HKLM-x32\...\kdenlive) (Version: 20.08.0 - KDE e.V.)
kuler (HKLM-x32\...\{098727E1-775A-4450-B573-3F441F1CA243}) (Version: 2.0 - Adobe Systems Incorporated) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LiveWeb (HKLM-x32\...\{F0A7B33E-C872-42C8-B1A9-55450809DAFF}) (Version: 4.00 - Shyam Pillai)
LMMS 1.1.3 (HKLM-x32\...\LMMS) (Version: 1.1.3 - LMMS Developers)
Logitech Camera Settings (HKLM-x32\...\LogiUCDPP) (Version: 2.5.17.0 - Logitech Europe S.A.)
Macrium Reflect Free Edition (HKLM\...\{E10EA502-8814-4DA4-8989-A8B1B38600A5}) (Version: 7.3.5321 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 7.3 - Paramount Software (UK) Ltd.)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
MarkBook 2014 (HKLM-x32\...\{E6AB4990-4AFA-4DF0-94BA-54C494CBC5EE}) (Version: 10.16.0 - Asylum Software Inc)
MarkBook 2015 (HKLM-x32\...\{54BFE612-3028-4250-BFC1-09C842B26B13}) (Version: 12.0.0 - Asylum Software Inc)
MarkBook 2016 (HKLM-x32\...\{FFFCCC49-EE45-4E90-AF24-388970A3382C}) (Version: 12.5.1 - Asylum Software Inc)
MarkBook 2017 (HKLM-x32\...\{01485D51-02D6-464F-90B6-DA24DE81A352}) (Version: 12.5.5 - Asylum Software Inc)
MarkBook 2018 (HKLM-x32\...\{DB94FC53-4585-4D5D-B455-8D7A0F2B946E}) (Version: 12.5.8 - Asylum Software Inc)
MarkBook 2019 (HKLM-x32\...\MkBk2019) (Version:  - )
MediaInfo 19.09 (HKLM\...\MediaInfo) (Version: 19.09 - MediaArea.net)
Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft IntelliType Pro 7.1 (HKLM\...\{E6B7BD80-A921-4C72-A68B-44A9EB438BE4}) (Version: 7.10.344.0 - Microsoft)
Microsoft Network Monitor 3.4 (HKLM\...\{8C5B5A11-CBF8-451B-B201-77FAB0D0B77D}) (Version: 3.4.2350.0 - Microsoft Corporation)
Microsoft Network Monitor: NetworkMonitor Parsers 3.4 (HKLM\...\{963E5FEB-1367-46B9-851D-A957F1A3747F}) (Version: 3.4.2350.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 15.0.5311.1000 - Microsoft Corporation)
Microsoft Office Proofing (English) 2007 (HKLM-x32\...\{90120000-002C-0409-0000-0000000FF1CE}) (Version:  - )
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Teams) (Version: 1.3.00.28779 - Microsoft Corporation)
Microsoft Text-to-Speech Engine 4.0 (English) (HKLM-x32\...\MSTTS) (Version:  - )
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version:  - )
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.25.28508 (HKLM-x32\...\{6913e92a-b64e-41c9-a5e6-cef39207fe89}) (Version: 14.25.28508.3 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820 (HKLM-x32\...\{45231ab4-69fd-486a-859d-7a59fcd11013}) (Version: 14.23.27820.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio Code (User) (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\{771FD6B0-FA20-440A-A002-3B3BAC16DC50}_is1) (Version: 1.36.1 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 84.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 84.0.1 (x64 en-US)) (Version: 84.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 65.0 - Mozilla)
Mu (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Mu) (Version: 1.0.3 - Nicholas H.Tollervey)
NetWorx 6.2.8 (HKLM\...\NetWorx_is1) (Version:  - SoftPerfect Pty Ltd)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.27 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.20.5.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.5.70 - NVIDIA Corporation)
NVIDIA Graphics Driver 461.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 461.09 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.38.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.40 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
NvModuleTracker (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvModuleTracker.Driver) (Version: 6.14.24033.38719 - NVIDIA Corporation) Hidden
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 23.1.0 - OBS Project)
Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.5311.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.5311.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0409-0000-0000000FF1CE}) (Version: 15.0.5311.1000 - Microsoft Corporation) Hidden
OpenShot Video Editor version 2.5.0 (HKLM\...\{4BB0DCDC-BC24-49EC-8937-72956C33A470}_is1) (Version: 2.5.0 - OpenShot Studios, LLC)
Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
Opera Stable 72.0.3815.400 (HKLM-x32\...\Opera 72.0.3815.400) (Version: 72.0.3815.400 - Opera Software)
Photoshop Camera Raw (HKLM-x32\...\{CC75AB5C-2110-4A7F-AF52-708680D22FE8}) (Version: 5.0 - Adobe Systems Incorporated) Hidden
Pinger (HKLM-x32\...\{9B56B031-A6C0-4BB7-8F61-938548C1B759}) (Version: 1.4.0.0 - ) Hidden
Process Hacker 2.39 (r124) (HKLM\...\Process_Hacker2_is1) (Version: 2.39.0.124 - wj32)
Product Portal (HKLM-x32\...\Product Portal) (Version:  - iZotope, Inc.)
Progress Telerik Fiddler (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Fiddler2) (Version: 5.0.20202.18177 - Progress Software Corporation)
Python 3.2 pygame-1.9.2a0 (HKLM-x32\...\{265E2F1D-0025-45DF-B83B-8320466108A8}) (Version: 1.9.2 - Pete Shinners, Rene Dudfield, Marcus von Appen, Bob Pendleton, others...)
Python 3.2 pywin32-220 (HKLM\...\pywin32-py3.2) (Version:  - )
Python 3.2.5 (64-bit) (HKLM\...\{AE3AAD33-1790-415f-A3D0-63FC889FD49f}) (Version: 3.2.5150 - Python Software Foundation)
Python 3.3 pygame-1.9.2a0 (HKLM-x32\...\{A1B5F430-1B0D-4837-9A36-7E5E26FDB78D}) (Version: 1.9.2 - Pete Shinners, Rene Dudfield, Marcus von Appen, Bob Pendleton, others...)
Python 3.4 cx_Freeze-4.3.3 (HKLM\...\{F4322DF5-21EC-4BB4-BE5C-0A511B529A83}) (Version: 4.3.3 - Anthony Tuininga)
Python 3.6.5 (32-bit) (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\{3346977b-49da-4095-8f4d-f56f103e52e9}) (Version: 3.6.5150.0 - Python Software Foundation)
Python 3.6.5 Core Interpreter (32-bit) (HKLM-x32\...\{58E1C809-82C5-4EDF-B69B-188A6C81F21F}) (Version: 3.6.5150.0 - Python Software Foundation) Hidden
Python 3.6.5 Development Libraries (32-bit) (HKLM-x32\...\{21FD2EE0-8D55-49DC-A1B0-771696DDEE98}) (Version: 3.6.5150.0 - Python Software Foundation) Hidden
Python 3.6.5 Documentation (32-bit) (HKLM-x32\...\{5C613D87-0AED-48A9-A216-3A3783463D6C}) (Version: 3.6.5150.0 - Python Software Foundation) Hidden
Python 3.6.5 Executables (32-bit) (HKLM-x32\...\{9107CF1A-A09C-4035-B29E-E79B4098AB8C}) (Version: 3.6.5150.0 - Python Software Foundation) Hidden
Python 3.6.5 pip Bootstrap (32-bit) (HKLM-x32\...\{C024F06C-0E37-4529-945F-7920A9CFFD78}) (Version: 3.6.5150.0 - Python Software Foundation) Hidden
Python 3.6.5 Standard Library (32-bit) (HKLM-x32\...\{8C2E8A7D-95CC-491C-AB9C-DE785A137D00}) (Version: 3.6.5150.0 - Python Software Foundation) Hidden
Python 3.6.5 Tcl/Tk Support (32-bit) (HKLM-x32\...\{052FD2FB-034D-4CDD-864E-798DE45C742A}) (Version: 3.6.5150.0 - Python Software Foundation) Hidden
Python 3.6.5 Test Suite (32-bit) (HKLM-x32\...\{86533809-919A-4858-AFC4-4226B86C5291}) (Version: 3.6.5150.0 - Python Software Foundation) Hidden
Python 3.6.5 Utility Scripts (32-bit) (HKLM-x32\...\{5C0C82E9-B580-4EE4-894A-4451A23B0E2C}) (Version: 3.6.5150.0 - Python Software Foundation) Hidden
Python 3.7.3 (32-bit) (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\{24ac8299-2abd-4ddd-8be3-031debb6093c}) (Version: 3.7.3150.0 - Python Software Foundation)
Python 3.7.3 Core Interpreter (32-bit) (HKLM-x32\...\{33AB9CEA-621E-4064-9FB0-7048E79DB5B5}) (Version: 3.7.3150.0 - Python Software Foundation) Hidden
Python 3.7.3 Development Libraries (32-bit) (HKLM-x32\...\{52DDE5D8-B45C-4C1D-81DD-D72317DE8B08}) (Version: 3.7.3150.0 - Python Software Foundation) Hidden
Python 3.7.3 Documentation (32-bit) (HKLM-x32\...\{2BC067C0-B392-49C0-988B-C839C62D8B65}) (Version: 3.7.3150.0 - Python Software Foundation) Hidden
Python 3.7.3 Executables (32-bit) (HKLM-x32\...\{E3E61712-C062-45E7-8348-D7DBF66FACFD}) (Version: 3.7.3150.0 - Python Software Foundation) Hidden
Python 3.7.3 pip Bootstrap (32-bit) (HKLM-x32\...\{9846DC93-4A39-496F-8AE3-0E3AB4EF4385}) (Version: 3.7.3150.0 - Python Software Foundation) Hidden
Python 3.7.3 Standard Library (32-bit) (HKLM-x32\...\{DC6190E7-D05E-465A-9FB6-7418BC901991}) (Version: 3.7.3150.0 - Python Software Foundation) Hidden
Python 3.7.3 Tcl/Tk Support (32-bit) (HKLM-x32\...\{1341418F-C713-4943-ACB2-9F4D4743D193}) (Version: 3.7.3150.0 - Python Software Foundation) Hidden
Python 3.7.3 Test Suite (32-bit) (HKLM-x32\...\{FE5E4BF9-7487-4CE8-A2AC-F78C6B4BE487}) (Version: 3.7.3150.0 - Python Software Foundation) Hidden
Python 3.7.3 Utility Scripts (32-bit) (HKLM-x32\...\{AE9303AD-EBD0-4C85-A9D0-55B1BA972D11}) (Version: 3.7.3150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{A28C27E4-A725-482A-9C65-61EDC0E4D583}) (Version: 3.7.6657.0 - Python Software Foundation)
QtWeb Internet Browser 3.8.5 (HKLM-x32\...\{13C0E1F7-BB8A-4545-B25E-628D025A94AD}_is1) (Version:  - QtWeb.NET)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7106 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
Reflector 2 (HKLM\...\{5AD4DEFF-7C46-4125-B274-49AAC3B68CAD}) (Version: 2.7.1.0 - Squirrels)
Samsung Kies3 (HKLM-x32\...\{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 0.0.0.0 - SAMSUNG Electronics Co., Ltd.)
Shotcut (HKLM-x32\...\Shotcut) (Version: 20.04.12 - Meltytech, LLC)
Sketchpad (HKLM-x32\...\Sketchpad) (Version:  - )
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype version 8.68 (HKLM-x32\...\Skype_is1) (Version: 8.68 - Skype Technologies S.A.)
Sophocles Version 1.1   (Remove Only) (HKLM-x32\...\Sophocles) (Version:  - )
Spotify (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Spotify) (Version: 1.0.45.186.g3b5036d6 - Spotify AB)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.7.64.0 - Safer-Networking Ltd.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Suite Shared Configuration CS4 (HKLM-x32\...\{842B4B72-9E8F-4962-B3C1-1C422A5C4434}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1032 - SUPERAntiSpyware.com)
Switch Sound File Converter (HKLM-x32\...\Switch) (Version: 7.45 - NCH Software)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
SyncBackFree (HKLM-x32\...\SyncBackFree_is1) (Version: 8.5.97.0 - 2BrightSparks)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
Trelby (HKLM-x32\...\Trelby) (Version: 2.2.0.0 - Trelby.org)
Uninstall trueSpace7.6 (HKLM-x32\...\Caligari trueSpace7.6_is1) (Version: 7.6 - Caligari Corp.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
URL Snooper v2.42.01 (HKLM-x32\...\URLSnooper 2_is1) (Version:  - DonationCoder.com)
USBPcap 1.5.3.0 (HKLM\...\USBPcap) (Version: 1.5.3.0 - Tomasz Mon)
VdhCoApp 1.3.0 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version:  - DownloadHelper)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.8 - VideoLAN)
Voicemeeter, The Virtual Mixing Console (HKLM-x32\...\VB:Voicemeeter {17359A74-1236-5467}) (Version:  - VB-Audio Software)
VTI Graphing Calculator (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\VTI Graphing Calculator) (Version:  - )
WIDCOMM Bluetooth Software (HKLM\...\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.5800 - Broadcom Corporation)
Winamp Detector Plug-in (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
WinDirStat 1.1.2 (HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\WinDirStat) (Version:  - )
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinMorph™ 3.01 (HKLM-x32\...\WinMorph_is1) (Version:  - Satish Kumar)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.10 beta 3 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.3 - win.rar GmbH)
Xvid 1.2.2 final uninstall (HKLM-x32\...\Xvid_is1) (Version: 1.2 - Xvid team (Koepi))
ZAR X (HKLM\...\{85DA9B81-D7F9-4165-8E62-F776B57213F8}_is1) (Version:  - www.z-a-recovery.com)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\ChromeHTML: ->  <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-3046525360-976882445-4112316675-1000_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\davids home\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20244.4\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3046525360-976882445-4112316675-1000_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\davids home\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20244.4\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2217832 2009-02-26] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [2007-05-10] (Adobe Systems Inc.) [File not signed]
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2019-09-20] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2019-07-01] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-05-02] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-05-02] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2-x32: [QuickFinderMenu] -> {C0E10002-0028-0005-C0E1-C0E1C0E1C0E1} => C:\Program Files (x86)\WordPerfect Office 12\Programs\PFSE120.DLL [2004-06-24] (Corel Corporation) [File not signed]
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2019-09-20] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ContextMenuHandlers2: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2019-07-01] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers4-x32: [QuickFinderMenu] -> {C0E10002-0028-0005-C0E1-C0E1C0E1C0E1} => C:\Program Files (x86)\WordPerfect Office 12\Programs\PFSE120.DLL [2004-06-24] (Corel Corporation) [File not signed]
ContextMenuHandlers4: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2019-07-01] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2020-12-31] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [2007-05-10] (Adobe Systems Inc.) [File not signed]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-05-02] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-05-02] (win.rar GmbH -> Alexander Roshal)
FolderExtensions: [] -> {F6BF8414-962C-40FE-90F1-B80A7E72DB9A} => C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\keyiso.dll -> No File
FolderExtensions_S-1-5-21-3046525360-976882445-4112316675-1000: [] -> {F6BF8414-962C-40FE-90F1-B80A7E72DB9A} => C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\keyiso.dll -> No File
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [VIDC.I420] => C:\Windows\SYSTEM32\lvcod64.dll [398360 2009-04-30] (Logitech Inc -> Logitech Inc.)
HKLM\...\Drivers32: [msacm.ac3filter] => C:\Windows\SYSTEM32\ac3filter64.acm [580096 2009-08-11] () [File not signed]
HKLM\...\Drivers32-x32: [vidc.i420] => lvcodec2.dll
HKLM\...\Drivers32: [vidc.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [180224 2009-06-07] () [File not signed]
HKLM\...\Drivers32: [vidc.MPG4] => C:\Windows\SysWOW64\MPG4c32.dll [413760 2001-01-07] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.MP42] => C:\Windows\SysWOW64\MPG4c32.dll [413760 2001-01-07] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.MP43] => C:\Windows\SysWOW64\MPG4c32.dll [413760 2001-01-07] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [msacm.l3codec] => C:\Windows\SysWOW64\l3codecp.acm [220672 2009-07-13] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
HKLM\...\Drivers32: [vidc.tscc] => C:\Windows\SysWOW64\tsccvid.dll [110592 2003-02-14] (TechSmith Corporation) [File not signed]
HKLM\...\Drivers32: [msacm.ac3filter] => C:\Windows\SysWOW64\ac3filter.acm [497664 2009-08-11] () [File not signed]
HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\SysWOW64\ff_vfw.dll [85504 2010-03-03] () [File not signed]
HKLM\...\Drivers32: [msacm.vorbis] => C:\Windows\SysWOW64\vorbis.acm [1554944 2009-09-15] (HMS hxxp://hp.vector.co.jp/authors/VA012897/) [File not signed]
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\davids home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Image-Line website.lnk -> hxxp://www.image-line.com
Shortcut: C:\Users\davids home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Advanced\Diagnostic.lnk -> hxxp://www.image-line.com/diagnosti
Shortcut: C:\Users\davids home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Additional\Download Deckadance.lnk -> hxxp://www.deckadance.com
Shortcut: C:\Users\davids home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Additional\SynthMaker website.lnk -> hxxp://www.synthmaker.co.uk
ShortcutWithArgument: C:\Users\davids home\Desktop\DSBN - Brave.lnk -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc.) -> --profile-directory="Profile 3"
ShortcutWithArgument: C:\Users\davids home\Desktop\Person 1 - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\davids home\Desktop\program shortcuts\David (Person 2) - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\davids home\Desktop\program shortcuts\David (youtube channel) - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 3"
ShortcutWithArgument: C:\Users\davids home\Desktop\program shortcuts\fun - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\davids home\Desktop\program shortcuts\Profile 1 - Brave.lnk -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc.) -> --profile-directory="Default"
ShortcutWithArgument: C:\Users\davids home\Desktop\program shortcuts\testing sir - Brave.lnk -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc.) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\davids home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Keep - Notes and Lists.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki
ShortcutWithArgument: C:\Users\davids home\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\David (Person 2) - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 2" -DISABLE-BACKGROUND-NETWORKING
ShortcutWithArgument: C:\Users\davids home\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\fun - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\davids home\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\cf1969e670773ba9\Profile 2 - Brave.lnk -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc.) -> --profile-directory="Profile 1"
 
==================== Loaded Modules (Whitelisted) =============
 
2020-04-19 14:22 - 2020-04-19 14:22 - 000678912 _____ () [File not signed] C:\Program Files (x86)\Canon\EOS Webcam Utility Beta\x64\EDSDK.dll
2019-07-26 19:41 - 2019-06-28 10:09 - 001291264 _____ () [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\libxml2.dll
2019-07-26 19:41 - 2019-06-28 10:09 - 000055808 _____ () [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\zlib1.dll
2013-07-17 14:24 - 2011-04-11 00:26 - 000034304 _____ () [File not signed] C:\Windows\System32\spe__l.dll
2020-06-12 08:19 - 2016-10-17 05:16 - 000831488 _____ () [File not signed] D:\downloads\software\TRAFFIC MONITORING\Networx_Setup_and_Portable-1593\Networx_Setup_and_Portable-1593\64-bit\sqlite.dll
2007-05-10 22:18 - 2007-05-10 22:18 - 001560576 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu64.dll
2020-04-19 14:22 - 2020-04-19 14:22 - 000519168 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\EOS Webcam Utility Beta\x64\EdsImage.dll
2014-06-11 21:11 - 2012-03-26 04:00 - 000389120 _____ (CANON INC.) [File not signed] C:\Windows\System32\CNMLMB8.DLL
2014-06-11 21:11 - 2012-06-14 16:18 - 000359936 _____ (CANON INC.) [File not signed] C:\Windows\System32\CNMN6PPM.DLL
2019-07-26 19:41 - 2019-06-28 10:09 - 000892928 _____ (Free Software Foundation) [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\iconv.dll
2016-01-09 12:43 - 2015-12-31 09:15 - 000077312 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2018-03-26 12:58 - 2018-03-26 12:58 - 000112128 _____ (Microsoft Corporation) [File not signed] [File is in use] C:\Windows\Microsoft.Net\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
2013-08-22 14:35 - 2013-08-22 14:35 - 000185856 _____ (SMART Technologies) [File not signed] C:\Program Files (x86)\SMART Technologies\Education Software\Office\SBSDKComWrapper-wink.dll
2013-07-17 14:24 - 2013-06-18 23:23 - 000041984 _____ (Windows ® Codename Longhorn DDK provider) [File not signed] C:\Windows\system32\spool\PRTPROCS\x64\spe__pc.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData:iSpring Solutions [128]
AlternateDataStreams: C:\Users\All Users:iSpring Solutions [128]
AlternateDataStreams: C:\ProgramData\Application Data:iSpring Solutions [128]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
AlternateDataStreams: C:\Users\davids home\Application Data:iSpring Solutions [128]
AlternateDataStreams: C:\Users\davids home\Cookies:zy8Qj3GUfupn5oVfvajBV [2332]
AlternateDataStreams: C:\Users\davids home\AppData\Roaming:iSpring Solutions [128]
AlternateDataStreams: C:\Users\davids home\AppData\Local\Temporary Internet Files:urLyIdmw66pmGCeXdl3Fz9SnrM [2642]
AlternateDataStreams: C:\Users\davids home\AppData\Local\Temporary Internet Files:WKrGS1tLeTSnx6wwUHcWyvmQN [2166]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Version 11) (Whitelisted) ==========
 
HKU\S-1-5-21-3046525360-976882445-4112316675-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://ca.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {50579BD5-1E57-46AE-B42C-57986B435249} URL = 
SearchScopes: HKU\S-1-5-21-3046525360-976882445-4112316675-1000 -> {F05329FE-7BCF-47B7-9C9B-ACCECB15F6E9} URL = hxxps://ca.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_241\bin\ssv.dll [2020-01-27] (Oracle America, Inc. -> Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2020-06-09] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_241\bin\jp2ssv.dll [2020-01-27] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2020-03-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: SMART Notebook Download Utility -> {67BCF957-85FC-4036-8DC4-D4D80E00A77B} -> C:\Program Files (x86)\SMART Technologies\Education Software\NotebookPlugin.dll [2013-11-27] (SMART Technologies ULC -> SMART Technologies ULC.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2020-05-12] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2020-06-09] (Microsoft Corporation -> Microsoft Corporation)
DPF: HKLM-x32 {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} hxxp://download.gigabyte.com.tw/object/Dldrv.ocx
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-07-18] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\MP3 Skype Recorder\Skype4COM.dll [2011-09-07] (Skype Technologies SA -> Skype Technologies)
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com
 
There are 7947 more sites.
 
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-3046525360-976882445-4112316675-1000\...\123simsen.com -> www.123simsen.com
 
There are 7947 more sites.
 
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2021-01-07 11:29 - 000455017 ____R C:\Windows\system32\drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com
 
There are 15615 more lines.
 
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files\AdoptOpenJDK\jdk-8.0.212.04-hotspot\bin;C:\Program Files\AdoptOpenJDK\jdk-11.0.3.7-hotspot\bin;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\ProgramData\Oracle\Java\javapath;C:\Windows\SYSTEM32;C:\Windows;C:\Windows\SYSTEM32\WBEM;C:\Windows\SYSTEM32\WINDOWSPOWERSHELL\V1.0\;C:\PROGRAM FILES (X86)\QUICKTIME\QTSYSTEM\;C:\Program Files\WIDCOMM\Bluetooth Software\;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Microsoft Network Monitor 3\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Python36\Scripts;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
HKU\S-1-5-21-3046525360-976882445-4112316675-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\davids home\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
MSCONFIG\startupfolder: C:^Users^davids home^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP Deskjet 2540 series.lnk => C:\Windows\pss\Monitor Ink Alerts - HP Deskjet 2540 series.lnk.Startup
MSCONFIG\startupreg: AVGBrowserAutoLaunch_1C92ED8B1268CE7864F2D4D1ED1131DD => "C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe" --check-run=src=logon --auto-launch-at-startup --profile-directory="Default"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: com.squirrel.Teams.Teams => C:\Users\davids home\AppData\Local\Microsoft\Teams\Update.exe --processStart "Teams.exe" --process-start-args "--system-initiated"
MSCONFIG\startupreg: Discord => C:\Users\davids home\AppData\Local\Discord\app-0.0.306\Discord.exe
MSCONFIG\startupreg: EpicGamesLauncher => "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
MSCONFIG\startupreg: FreeMeter => "E:\downloads\software\FreeMeter_v1.6.3\FreeMeter_v1.6.3\FreeMeter.exe"
MSCONFIG\startupreg: NetMeter Evo => E:\downloads\software\NetMeterEvo 2.1.0\NetMeterEvo.exe
MSCONFIG\startupreg: NetTraffic => C:\Program Files (x86)\NetTraffic\NetTraffic.exe
MSCONFIG\startupreg: SolarWinds RBM => "C:\Program Files (x86)\SolarWinds\Real-Time Bandwidth Monitor\RealtimeBandwidthMonitor.exe"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{A0351049-50F2-46FF-8D33-D234B99F501D}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{6A0170DB-85B1-45CB-B3B4-1A21F00B702B}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{058B3D51-1150-4CA3-9F07-D0C08BB2E97E}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> )
FirewallRules: [{DC52D28C-8009-4759-9912-F5D6A3B20BAD}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> )
FirewallRules: [{A65F3B5D-16BB-4AD1-B12C-D928E0AF8D79}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe (GlassWire -> SecureMix LLC)
FirewallRules: [{0BBA3C6D-42EC-4C26-A109-00015C79A8D0}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe (GlassWire -> SecureMix LLC)
FirewallRules: [TCP Query User{6D0E41A1-84A2-4ACB-8A5F-E3928D737ACD}C:\program files (x86)\bravesoftware\brave-browser\application\brave.exe] => (Block) C:\program files (x86)\bravesoftware\brave-browser\application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)
FirewallRules: [UDP Query User{1282A2C6-620C-404A-9913-1E4DBA9993AC}C:\program files (x86)\bravesoftware\brave-browser\application\brave.exe] => (Block) C:\program files (x86)\bravesoftware\brave-browser\application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)
FirewallRules: [TCP Query User{1278358C-94A1-4624-A257-1AAD6337712F}C:\program files\jetbrains\pycharm community edition 2018.1.4\bin\pycharm64.exe] => (Block) C:\program files\jetbrains\pycharm community edition 2018.1.4\bin\pycharm64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [UDP Query User{A74316DF-5296-414F-8628-EA5A40C74390}C:\program files\jetbrains\pycharm community edition 2018.1.4\bin\pycharm64.exe] => (Block) C:\program files\jetbrains\pycharm community edition 2018.1.4\bin\pycharm64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [{0AFCD363-EEC8-4DE9-B3EB-62548CE66AFB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{1430BEEF-768B-449D-BE5A-BC14EA218AE6}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [{74A888AC-00EF-409C-B65C-70B189335C81}] => (Allow) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)
FirewallRules: [{D34B1356-65AB-4327-8F3C-5F45E8CC614A}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{BBCB7C62-60FF-43FB-A34A-7242C35B63AF}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service
 
==================== Restore Points =========================
 
30-01-2021 00:00:01 Scheduled Checkpoint
 
==================== Faulty Device Manager Devices ============
 
Name: Bluetooth L2CAP Interface
Description: Bluetooth L2CAP Interface
Class Guid: {c7c038ad-1f2d-44d4-b2fe-d912be20e6d5}
Manufacturer: Broadcom Corp.
Service: btwl2cap
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Bluetooth Hands-free Audio
Description: Bluetooth Hands-free Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Broadcom
Service: btwaudio
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: SMART Virtual TabletPC
Description: SMART Virtual TabletPC
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: SMART Technologies ULC
Service: SMARTVTabletPCx64
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Bluetooth Remote Control
Description: Bluetooth Remote Control
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: Broadcom
Service: btwrchid
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (01/30/2021 10:46:05 AM) (Source: BMService) (EventID: 1) (User: )
Description: Unexpected startup error occurred. Error message: Error loading network driver
 
Error: (01/30/2021 10:45:20 AM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe".Error in manifest or policy file "C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe.Config" on line 0.
Invalid Xml syntax.
 
Error: (01/30/2021 10:45:17 AM) (Source: MsiInstaller) (EventID: 11714) (User: NT AUTHORITY)
Description: Product: Avira -- Error 1714. The older version of Avira cannot be removed.  Contact your technical support group.  System Error 1612.
 
Error: (01/30/2021 10:43:57 AM) (Source: MBAMIService) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (01/30/2021 10:43:57 AM) (Source: MBAMIService) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (01/30/2021 10:43:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: FreemakeUtilsService.exe, version: 1.0.0.0, time stamp: 0x5e0346af
Faulting module name: KERNELBASE.dll, version: 6.1.7601.23915, time stamp: 0x59b94abb
Exception code: 0xe0434352
Fault offset: 0x0000c54f
Faulting process id: 0x86c
Faulting application start time: 0x01d6f71eae9fed20
Faulting application path: C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
Report Id: f57784cc-6311-11eb-9384-74d83e20980f
 
Error: (01/30/2021 10:43:40 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: FreemakeUtilsService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.FileNotFoundException
   at FreemakeUtilsService.Program.Main(System.String[])
 
Error: (01/29/2021 11:33:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 96564
 
 
System errors:
=============
Error: (01/30/2021 10:44:05 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
 
Error: (01/30/2021 10:43:56 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Freemake Improver service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (01/30/2021 10:43:56 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Freemake Improver service to connect.
 
Error: (01/29/2021 08:44:28 PM) (Source: volsnap) (EventID: 36) (User: )
Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
 
Error: (01/29/2021 10:10:23 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
 
Error: (01/29/2021 10:10:14 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Freemake Improver service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (01/29/2021 10:10:14 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Freemake Improver service to connect.
 
Error: (01/28/2021 11:21:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The SMART Helper Service service terminated unexpectedly.  It has done this 1 time(s).
 
 
CodeIntegrity:
===================================
 
Date: 2020-12-06 21:33:35.190
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\MediaFoundation.DefaultPerceptionProvider.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2020-12-06 21:33:34.912
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\MediaFoundation.DefaultPerceptionProvider.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2020-12-06 21:33:34.647
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\MediaFoundation.DefaultPerceptionProvider.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2020-12-06 21:33:34.403
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\MediaFoundation.DefaultPerceptionProvider.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2020-12-06 21:33:29.345
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-sensordataservice_31bf3856ad364e35_10.0.19041.1_none_b3f4f49ac9993d28\MediaFoundation.DefaultPerceptionProvider.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2020-12-06 21:33:29.051
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-sensordataservice_31bf3856ad364e35_10.0.19041.1_none_b3f4f49ac9993d28\MediaFoundation.DefaultPerceptionProvider.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2020-12-06 21:33:28.757
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-sensordataservice_31bf3856ad364e35_10.0.19041.1_none_b3f4f49ac9993d28\MediaFoundation.DefaultPerceptionProvider.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2020-12-06 21:33:28.511
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-sensordataservice_31bf3856ad364e35_10.0.19041.1_none_b3f4f49ac9993d28\MediaFoundation.DefaultPerceptionProvider.dll because the set of per-page image hashes could not be found on the system.
 
==================== Memory info =========================== 
 
BIOS: Award Software International, Inc. F11 10/18/2012
Motherboard: Gigabyte Technology Co., Ltd. GA-970A-D3
Processor: AMD FX™-6300 Six-Core Processor 
Percentage of memory in use: 70%
Total physical RAM: 12269.19 MB
Available physical RAM: 3648.26 MB
Total Virtual: 24536.57 MB
Available Virtual: 13922.62 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:111.69 GB) (Free:6.93 GB) NTFS
Drive d: (Faith) (Fixed) (Total:931.51 GB) (Free:184.22 GB) NTFS
 
\\?\Volume{cd9abd5b-589d-11e2-9deb-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 111.8 GB) (Disk ID: 0AC0E495)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS)
 
==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 862ABC76)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt =======================

  • 0

#119
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts

When you boot the computer, which OS loads as default?


  • 0

#120
netrate

netrate

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 197 posts

Since I have to disconnect, I always press F12 to select the drive and then I pick win 7, but I have never let it default to anything.  I always pick even when there is one drive attached.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP