Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Pop Up for Quickbooks Support saying to call number because my QB is c

Quickbooks Scam

  • Please log in to reply

#1
CCWTech

CCWTech

    Member

  • Member
  • PipPipPip
  • 191 posts

Hi, I keep getting a pop up saying QB found some problems with your data file... Then it gives a number to call. QB (Intuit) says this is a scam. Trying to figure out how to remove this virus/spyware please.

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-12-2022
Ran by Sue (administrator) on DESKTOP-E2I7FB8 (LENOVO 11JN0072US) (19-12-2022 17:55:15)
Running from C:\Users\Sue\Desktop
Loaded Profiles: Sue
Platform: Microsoft Windows 10 Pro Version 22H2 19045.2364 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(\\TTVC-SVR\AVImark\AVImark.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCopyAccelerator.exe
(explorer.exe ->) (McAllister Software Systems LLC. -> McAllister Software Systems Inc.) \\TTVC-SVR\AVImark\AVImark.exe
(Intuit, Inc. -> SAP SE or an SAP affiliate company) C:\Program Files\Intuit\QuickBooks 2023\QBDBMgr.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <19>
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\System32\drivers\lenovo\UDC\Service\UDClientService.exe
(services.exe ->) (mc.ntg.co-8edb73 -> ) [File not signed] C:\Program Files\Mesh Agent\MeshAgent.exe <3>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e80fb7173daab733\RtkAudUService64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (Intuit, Inc. -> Intuit Inc.) C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21238.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21238.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22092.214.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Solanki Piyushkumar -> ) C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e80fb7173daab733\RtkAudUService64.exe [3496296 2022-07-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1318024 2021-04-15] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM-x32\...\Run: [Immunet Protect Iptray] => "C:\Program Files\Immunet\7.5.8.21178\iptray.exe" (No File)
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" (No File)
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626448 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [MicrosoftEdgeAutoLaunch_48FDC4BBB2BFB3180449326C7B7EF46E] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3879848 2022-12-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIS3E.EXE [416896 2017-09-21] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [QuickBooks for Windows] => C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe [95080 2022-09-24] (Solanki Piyushkumar -> )
HKLM\...\Print\Monitors\EPSON ET-2760 Series 64MonitorBE: C:\Windows\system32\E_YLMBS3E.DLL [187392 2018-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\Windows\system32\enppmon.dll [500736 2016-09-14] (SEIKO EPSON CORPORATION) [File not signed]
HKLM\...\Print\Monitors\HP Standard TCP/IP Port: C:\Windows\system32\HpTcpMon.dll [331264 2009-09-16] (Hewlett Packard) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\108.0.5359.125\Installer\chrmstp.exe [2022-12-15] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk [2022-11-22]
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit, Inc. -> Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\IntuitDownloadManager.lnk [2022-11-21]
ShortcutTarget: IntuitDownloadManager.lnk -> C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe (Solanki Piyushkumar -> )
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk [2022-11-22]
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files\Intuit\QuickBooks 2023\QBW.EXE (Intuit, Inc. -> Intuit Inc.)
BootExecute: autocheck autochk * bootdelete
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0EB2FD9D-A4AF-4F07-A043-656EF3843AA6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-27] (Adobe Inc. -> Adobe Inc.)
Task: {139615F1-B783-4CAF-AF94-3AA2334EDAFB} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin => C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\ScheduleEventAction.exe [27480 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
Task: {1CAB845A-EFB0-45A2-8DE1-3F65EFFF3F5A} - System32\Tasks\MicrosoftEdgeShadowStackRollbackTask => C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.54\Installer\setup.exe [3367848 2022-12-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {216A41D9-449D-40CD-9B91-6363FDB405B6} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3259427507-1055586877-3198061443-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189072 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {309C78F5-DFCA-45BE-8FAF-EF9ADB6547E7} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoCompanionAppAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\ScheduleEventAction.exe [27480 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
Task: {3939AB69-A43B-4561-9C6A-54A431D17C1A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {3A6C6083-5B8D-4A0F-95EF-8AB6A60CC0CB} - System32\Tasks\Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance => %systemroot%\system32\sc.exe start LenovoVantageService
Task: {3ABBB444-6BCB-448F-9772-8232965A2E85} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION
Task: {5AF9E179-DCF7-4B52-BFAF-58D538B3A142} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {5D5D2BAA-F528-4590-A803-A5A97DA5F42F} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189072 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {81E1AB3E-DC23-4A44-AD8E-E13D982CFFF3} - System32\Tasks\Lenovo\UDC\Lenovo UDC Monitor => C:\Windows\system32\drivers\lenovo\udc\data\InfBackup\UdcInfInstaller.exe [184656 2022-05-23] (Lenovo -> Lenovo Group Ltd.)
Task: {8E12C014-148F-4780-B94E-9019E0B9662D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {901A3E09-DD28-4C4E-8801-C8824C51B691} - \Lenovo\ImController\TimeBasedEvents\10a8f074-22a1-4370-bb82-5ecf54dbf8e3 -> No File <==== ATTENTION
Task: {9429409C-F658-481F-82D4-73CE86F835F6} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION
Task: {98015232-CD73-4C11-9D9E-47E4A8926F7D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {9F8516B3-965D-4CB4-84C8-3BA797197D41} - System32\Tasks\GoogleUpdateTaskMachineUA{7502EB32-9AA7-4409-A70A-5A0A783A8CB9} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [171480 2022-11-10] (Google LLC -> Google LLC)
Task: {A0D16F44-B686-46CA-A6A1-7F0CDC72B3EC} - \Lenovo\ImController\TimeBasedEvents\196a1ff6-3590-426e-8989-7fe35d618f54 -> No File <==== ATTENTION
Task: {A30D4232-8B51-4E53-A352-775421CFC9FD} - System32\Tasks\EPSON ET-2760 Series Update {7804B21A-373A-468A-A7B1-6F428643C8AB} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSS3E.EXE [680440 2017-06-06] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Task: {AAA6E0C5-BBE9-449F-88ED-BF7E02C56709} - \Lenovo\ImController\TimeBasedEvents\46ca8c6b-2524-462b-866f-89d8b584add8 -> No File <==== ATTENTION
Task: {B7132DD9-FFA7-41BB-988F-5FC331B9ECF9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B8D79FD1-0201-43C5-B4D0-0F22A5EFBD98} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION
Task: {BA16315F-9972-4FB7-BD4A-CE05647C3C37} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {BB757E02-9F4B-4F18-8E3D-EEEADB5E35B4} - System32\Tasks\Lenovo\UDC\Lenovo UDC Idle Monitor => C:\windows\system32\drivers\Lenovo\udc\Service\UDCUserAgent.exe [89408 2022-05-23] (Lenovo -> Lenovo Group Ltd.)
Task: {BBDB025B-950A-4C54-A6AC-9D087FAF158F} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoSystemUpdateAddin_WeeklyTask => C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\ScheduleEventAction.exe [27480 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
Task: {C4029849-3F83-4719-8545-B464C0A68920} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DA835E9F-8961-416B-819A-392E76426410} - System32\Tasks\GoogleUpdateTaskMachineCore{6A2DD8C7-7DB0-46A7-AC32-0FD8EC7C636A} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [171480 2022-11-10] (Google LLC -> Google LLC)
Task: {E633E663-F2CB-4D3F-A86B-A1E0FA3DA379} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [146816 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {FD787C0A-F968-4283-A769-D9319DE7F622} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\EPSON ET-2760 Series Update {7804B21A-373A-468A-A7B1-6F428643C8AB}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSS3E.EXE:/EXE:{7804B21A-373A-468A-A7B1-6F428643C8AB} /F:UpdateWORKGROUP\DESKTOP-E2I7FB8$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ac8a25b1-8e84-445b-8d31-2b270eb6de82}: [DhcpNameServer] 192.168.1.1
 
Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Sue\AppData\Local\Microsoft\Edge\User Data\Default [2022-12-19]
Edge HomePage: Default -> hxxp://www.msn.com/?pc=DCTE
Edge Extension: (URL Safety) - C:\Users\Sue\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\plkaklmpcfkechocmkmhjheonopjbnpo [2022-11-10]
 
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-16] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-10-16] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-16] (Microsoft Corporation -> Microsoft Corporation)
 
Chrome: 
=======
CHR Profile: C:\Users\Sue\AppData\Local\Google\Chrome\User Data\Default [2022-12-19]
CHR Extension: (Google Docs Offline) - C:\Users\Sue\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-12-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Sue\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-11-10]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-27] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12540928 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
S2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [206304 2020-10-02] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncHelper.exe [3478928 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
S2 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantageService.exe [31072 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
R2 Mesh Agent; C:\Program Files\Mesh Agent\MeshAgent.exe [3457112 2022-11-10] (mc.ntg.co-8edb73 -> ) [File not signed]
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.238.1114.0002\OneDriveUpdaterService.exe [3845008 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
S3 QBFCService; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [65536 2022-10-19] (Intuit Inc.) [File not signed]
S2 QBVSS; C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe [1570816 2022-10-08] (Intuit Inc.) [File not signed]
S2 QBWCMonitor; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBWebConnector3.0\Intuit.QBDT.Webconnector.QBWCMonitor.exe [47384 2022-12-02] (Intuit, Inc. -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [224184 2022-11-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [16196920 2022-11-09] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 UDCService; C:\Windows\System32\drivers\Lenovo\udc\Service\UDClientService.exe [71504 2022-05-23] (Lenovo -> Lenovo Group Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe [3191264 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe [133592 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 EpsonCustomerResearchParticipation; "C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe" [X]
S2 HitmanPro38CrusaderBoot; "C:\Users\Sue\Downloads\HitmanPro_x64.exe" /crusader:boot [X]
S2 ImControllerService; %SystemRoot%\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [X]
S3 MicrosoftEdgeElevationService; "C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\elevation_service.exe" [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [33216 2021-12-02] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0374729.inf_amd64_acb1e75867156c4f\B374580\amdkmdag.sys [82880872 2021-12-09] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R4 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [42000 2022-12-15] (Microsoft Windows Hardware Compatibility Publisher -> )
R0 rtvdevw10; C:\Windows\System32\drivers\rtvdevw10x64.sys [50128 2022-08-18] (Realtek Semiconductor Corp. -> Realtek)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [49568 2022-12-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [473376 2022-12-08] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [99616 2022-12-08] (Microsoft Windows -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-12-19 17:55 - 2022-12-19 17:55 - 000019912 _____ C:\Users\Sue\Desktop\FRST.txt
2022-12-19 17:54 - 2022-12-19 17:55 - 000000000 ____D C:\FRST
2022-12-19 17:53 - 2022-12-19 17:53 - 002375680 _____ (Farbar) C:\Users\Sue\Desktop\FRST64.exe
2022-12-19 15:03 - 2022-12-19 15:03 - 001494555 _____ C:\Users\Sue\Downloads\CA Weekly Promo_12.19-23_V3_Writable.pdf
2022-12-17 16:38 - 2022-12-17 16:38 - 012166202 _____ C:\Users\Sue\Downloads\2023 Zoetis Petcare Price List.pdf
2022-12-17 16:38 - 2022-12-17 16:38 - 012166202 _____ C:\Users\Sue\Downloads\2023 Zoetis Petcare Price List (1).pdf
2022-12-17 16:37 - 2022-12-17 16:37 - 000046545 _____ C:\Users\Sue\Downloads\Zoetis 2002 End of Year Shipping.pdf
2022-12-17 13:01 - 2022-12-17 13:01 - 000000000 ____D C:\Program Files (x86)\ScreenConnect Client (61e735463d3bf1de)
2022-12-15 16:08 - 2022-12-15 16:08 - 000012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2022-12-15 16:08 - 2022-12-15 16:08 - 000000304 _____ C:\Windows\system32\.crusader
2022-12-15 16:08 - 2022-12-15 16:08 - 000000254 _____ C:\Windows\system32\bootdelete.lst
2022-12-15 16:07 - 2022-12-15 16:07 - 000042000 _____ C:\Windows\system32\Drivers\hitmanpro37.sys
2022-12-15 16:06 - 2022-12-15 16:08 - 000000000 ____D C:\ProgramData\HitmanPro
2022-12-15 16:03 - 2022-12-15 16:04 - 000000000 ____D C:\AdwCleaner
2022-12-14 19:10 - 2022-12-14 19:20 - 000000000 ____D C:\Program Files\Immunet
2022-12-14 19:10 - 2022-12-14 19:10 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ImmunetNetworkMonitor_01009.Wdf
2022-12-14 19:10 - 2022-12-14 19:10 - 000000000 ____D C:\ProgramData\Immunet
2022-12-14 18:40 - 2022-12-14 18:40 - 000000000 ____D C:\Users\Sue\AppData\Local\mbam
2022-12-14 18:39 - 2022-12-15 15:54 - 000000000 ____D C:\Program Files\Malwarebytes
2022-12-14 15:41 - 2022-12-15 17:08 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2022-12-14 15:40 - 2022-12-14 15:41 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2022-12-14 15:40 - 2022-12-14 15:41 - 000002139 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-12-14 15:40 - 2022-12-14 15:41 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive
2022-12-14 15:40 - 2022-12-14 15:40 - 000000000 ___RD C:\Users\Default\OneDrive
2022-12-14 06:46 - 2022-12-14 06:46 - 000012367 _____ C:\Windows\system32\DrtmAuthTxt.wim
2022-12-14 06:42 - 2022-12-14 06:43 - 000000000 ___HD C:\$WinREAgent
2022-12-13 12:50 - 2022-12-13 12:50 - 067756032 _____ C:\Users\Sue\Documents\Nov22 Tender Touch Veterinary Care (Backup Dec 13,2022  12 49 PM).QBB
2022-12-13 10:57 - 2022-12-14 15:40 - 000000000 ____D C:\Program Files (x86)\LogMeIn Rescue Applet
2022-12-13 10:56 - 2022-12-13 11:37 - 000000000 ____D C:\Users\Sue\AppData\Local\LogMeIn Rescue Applet
2022-12-13 10:56 - 2022-12-13 10:56 - 000002321 _____ C:\Users\Sue\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HelpDesk.lnk
2022-12-11 15:45 - 2022-12-11 15:45 - 000067703 _____ C:\Users\Sue\Downloads\TaxJurisdictionMonthly-en-us-4023877 (1).pdf
2022-12-11 13:22 - 2022-12-11 13:22 - 000000131 _____ C:\Users\Sue\Downloads\Reimbursements (1).csv
2022-12-11 13:01 - 2022-12-11 13:01 - 000000000 ____D C:\Users\Sue\AppData\LocalLow\Temp
2022-12-11 12:43 - 2022-12-11 12:43 - 000029683 _____ C:\Users\Sue\Downloads\Clinic - 4868_08-01-2022_12-15-2022.csv
2022-12-07 14:56 - 2022-12-07 14:56 - 000178749 _____ C:\Users\Sue\Downloads\Document (3).pdf
2022-12-07 14:56 - 2022-12-07 14:56 - 000178749 _____ C:\Users\Sue\Downloads\Document (2).pdf
2022-12-07 10:51 - 2022-12-07 10:51 - 000178749 _____ C:\Users\Sue\Downloads\Document.pdf
2022-12-07 10:51 - 2022-12-07 10:51 - 000178749 _____ C:\Users\Sue\Downloads\Document (1).pdf
2022-12-07 10:41 - 2022-12-07 10:41 - 000131708 _____ C:\Users\Sue\Downloads\ModelInfectionControlPlan (1).pdf
2022-12-07 10:41 - 2022-12-07 10:41 - 000131708 _____ C:\Users\Sue\Downloads\ModelInfectionControlPlan (1) (1).pdf
2022-12-06 11:46 - 2022-12-06 11:46 - 000431305 _____ C:\Users\Sue\Downloads\INVOICE#716A131.html
2022-12-05 16:33 - 2022-12-05 16:33 - 000034927 _____ C:\Users\Sue\Downloads\Statement.pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041630 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (5).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041630 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (4).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041630 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (3).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041623 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (1).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000025117 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632.pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000025117 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (2).pdf
2022-12-04 14:29 - 2022-12-04 14:29 - 000000000 ____D C:\Users\Sue\Downloads\JAN22_files
2022-12-04 14:28 - 2022-12-04 14:29 - 000431599 _____ C:\Users\Sue\Downloads\JAN22.html
2022-12-04 14:27 - 2022-12-04 14:27 - 000039823 _____ C:\Users\Sue\Downloads\2022-02-28 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000048846 _____ C:\Users\Sue\Downloads\2022-11-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000044339 _____ C:\Users\Sue\Downloads\2022-10-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000041717 _____ C:\Users\Sue\Downloads\2022-03-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000039800 _____ C:\Users\Sue\Downloads\2022-06-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000039458 _____ C:\Users\Sue\Downloads\2022-07-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000039214 _____ C:\Users\Sue\Downloads\2022-09-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000037923 _____ C:\Users\Sue\Downloads\2022-04-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000036161 _____ C:\Users\Sue\Downloads\2022-05-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000020207 _____ C:\Users\Sue\Downloads\2022-08-31 Statement - USB Savings 2632.pdf
2022-12-04 14:03 - 2022-12-04 14:03 - 000002031 _____ C:\Users\Sue\Downloads\Savings - 2632_01-04-2022_12-08-2022.csv
2022-12-04 14:01 - 2022-12-04 14:01 - 000002568 _____ C:\Users\Sue\Downloads\building - 9319_01-01-2022_12-08-2022.csv
2022-12-03 15:21 - 2022-12-03 15:21 - 000119808 _____ C:\Users\Sue\Downloads\100991537_US_ah_2022_12.pdf
2022-12-03 15:20 - 2022-12-03 15:20 - 000068608 _____ C:\Users\Sue\Downloads\Invoice-6100988911.pdf
2022-12-03 15:09 - 2022-12-03 15:09 - 000106591 _____ C:\Users\Sue\Downloads\1c370d69-4218-47f1-8a1d-f5f90d378eb2.pdf
2022-12-02 10:36 - 2022-12-02 10:36 - 000084136 _____ C:\Users\Sue\Downloads\MVS Exclusive Promo DechraNutramax Nov 17-30.pdf
2022-11-30 10:42 - 2022-11-30 10:42 - 001679221 _____ C:\Users\Sue\Downloads\CA Weekly Promo_11.28-12.2_writable.pdf
2022-11-25 14:55 - 2022-11-25 14:55 - 001037515 _____ C:\Users\Sue\Downloads\Video.mov
2022-11-25 10:06 - 2022-11-25 10:06 - 000213027 _____ C:\Users\Sue\Downloads\976468ef-e02f-42ea-9f58-0ee93aa7eb40.pdf
2022-11-23 12:07 - 2022-11-23 12:07 - 000000410 _____ C:\Users\Sue\Downloads\Sue Vet license 2023.htm
2022-11-23 12:07 - 2022-11-23 12:07 - 000000000 ____D C:\Users\Sue\Downloads\Sue Vet license 2023_files
2022-11-23 09:48 - 2022-11-23 09:48 - 014486872 _____ (Glance Networks, Inc.) C:\Users\Sue\Downloads\GlanceGuestSetup_4.17.1 (1).exe
2022-11-23 09:48 - 2022-11-23 09:48 - 000000000 ____D C:\Users\Sue\AppData\Local\Glance
2022-11-23 09:47 - 2022-11-23 09:47 - 014486872 _____ (Glance Networks, Inc.) C:\Users\Sue\Downloads\GlanceGuestSetup_4.17.1.exe
2022-11-22 09:50 - 2022-11-22 09:50 - 000002196 _____ C:\Users\Public\Desktop\QuickBooks Premier Plus Edition 2023.lnk
2022-11-22 09:45 - 2022-11-22 09:47 - 1091567600 _____ (Intuit, Inc. ) C:\Users\Sue\AppData\Roaming\QuickBooksPremierSub2023.exe
2022-11-22 09:42 - 2022-11-22 09:42 - 071151810 _____ (Intuit, Inc. ) C:\Users\Sue\AppData\Roaming\QuickBooksPro2019.exe
2022-11-22 09:42 - 2022-11-22 09:42 - 001620600 _____ () C:\Users\Sue\Downloads\QuickBooks desktop manager (2).exe
2022-11-22 09:39 - 2022-11-22 09:39 - 001620600 _____ () C:\Users\Sue\Downloads\QuickBooks desktop manager (1).exe
2022-11-22 09:38 - 2022-11-22 09:38 - 001620600 _____ () C:\Users\Sue\Downloads\QuickBooks desktop manager.exe
2022-11-21 15:05 - 2022-11-24 01:03 - 000000000 ____D C:\ProgramData\SQL Anywhere 17
2022-11-21 15:03 - 2022-11-21 15:04 - 000000000 ____D C:\quickbooks2022
2022-11-21 14:48 - 2022-11-23 09:45 - 000000000 ____D C:\Users\Sue\AppData\Local\Intuit
2022-11-21 14:48 - 2022-11-22 09:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickBooks
2022-11-21 14:48 - 2022-11-21 14:48 - 000000000 ____D C:\Windows\SysWOW64\spool
2022-11-21 14:48 - 2022-11-21 14:48 - 000000000 ____D C:\Users\Sue\AppData\Roaming\SQL Anywhere 17
2022-11-21 14:48 - 2012-08-15 01:15 - 006525440 _____ (Amyuni Technologies hxxp://www.amyuni.com) C:\Windows\system32\cdintf450_64.dll
2022-11-21 14:48 - 2012-08-15 01:11 - 004809728 _____ (Amyuni Technologies hxxp://www.amyuni.com) C:\Windows\SysWOW64\cdintf450.dll
2022-11-21 14:46 - 2022-12-13 10:58 - 000000000 ____D C:\ProgramData\Intuit
2022-11-21 14:46 - 2022-11-22 09:48 - 000000095 _____ C:\Windows\QBChanUtil_Trigger.ini
2022-11-21 14:46 - 2022-11-22 09:47 - 000000000 ____D C:\ProgramData\Package Cache
2022-11-21 14:46 - 2022-11-22 09:47 - 000000000 ____D C:\Program Files\Intuit
2022-11-21 14:46 - 2022-11-22 09:47 - 000000000 ____D C:\Program Files\Common Files\Intuit
2022-11-21 14:46 - 2022-11-22 09:47 - 000000000 ____D C:\Program Files (x86)\Intuit
2022-11-21 14:43 - 2022-11-21 14:44 - 908359728 _____ (Intuit, Inc. ) C:\Users\Sue\Downloads\QuickBooksPremierSub2022.exe
2022-11-21 14:40 - 2022-12-07 10:50 - 000000000 ___HD C:\Users\Public\Documents\Windows
2022-11-21 14:40 - 2022-11-21 14:40 - 002672640 _____ C:\Users\Sue\Downloads\QuickBooks Setup.msi
2022-11-21 14:39 - 2022-11-22 09:48 - 000000000 ____D C:\Windows\Intuit
2022-11-21 14:36 - 2022-11-21 14:38 - 908359728 _____ (Intuit, Inc. ) C:\Users\Sue\Downloads\Setup_QuickBooksPremierSub2022.exe
2022-11-21 13:47 - 2022-11-22 09:47 - 000000000 ____D C:\Users\Public\Documents\Intuit
2022-11-21 13:44 - 2020-11-26 15:46 - 000002308 _____ C:\Users\Sue\Desktop\Server.rdp
2022-11-21 13:44 - 2019-05-19 13:31 - 731665752 _____ (Intuit, Inc. ) C:\Users\Sue\Desktop\QuickBooksPro2019.exe
2022-11-21 13:44 - 2016-05-26 16:37 - 637513640 _____ (Intuit, Inc. ) C:\Users\Sue\Desktop\QuickBooksPro2016.exe
2022-11-21 13:43 - 2022-11-21 13:43 - 000000000 ____D C:\Users\Sue\Downloads\sensor 1_files
2022-11-21 13:43 - 2022-11-21 13:43 - 000000000 ____D C:\Users\Sue\Downloads\MVSO New Launch Social Media Graphic_09.29_v2.jpg_files
2022-11-21 13:43 - 2022-11-21 13:43 - 000000000 ____D C:\Users\Sue\Downloads\BONIL_files
2022-11-21 13:43 - 2022-11-21 13:43 - 000000000 ____D C:\Users\Sue\Downloads\bank_files
2022-11-21 13:43 - 2022-11-21 13:43 - 000000000 ____D C:\Users\Sue\Downloads\Approval Requests - 7009284_files
2022-11-21 13:43 - 2022-09-17 11:08 - 000000116 _____ C:\Users\Sue\Downloads\payments.csv.crdownload
2022-11-21 13:43 - 2022-08-16 16:38 - 000023028 _____ C:\Users\Sue\Downloads\controlled1.html
2022-11-21 13:43 - 2022-01-15 15:22 - 000597859 _____ C:\Users\Sue\Downloads\w2 2021.pdf
2022-11-21 13:43 - 2021-04-29 11:18 - 002021327 _____ C:\Users\Sue\Downloads\first-aid-checklist (3).pdf
2022-11-21 13:43 - 2021-04-29 11:15 - 002021327 _____ C:\Users\Sue\Downloads\first-aid-checklist (2).pdf
2022-11-21 13:43 - 2021-04-28 11:34 - 002021327 _____ C:\Users\Sue\Downloads\first-aid-checklist (1).pdf
2022-11-21 13:43 - 2021-04-28 11:32 - 002021327 _____ C:\Users\Sue\Downloads\first-aid-checklist.pdf
2022-11-21 13:43 - 2021-04-11 13:01 - 000076440 _____ C:\Users\Sue\Downloads\INWKS941_210411_135949.pdf
2022-11-21 13:43 - 2021-03-24 07:53 - 000358990 _____ C:\Users\Sue\Downloads\bank.html
2022-11-21 13:43 - 2021-02-13 15:55 - 000051325 _____ C:\Users\Sue\Downloads\December 31, 2020 (3).pdf
2022-11-21 13:43 - 2021-02-13 15:44 - 000047031 _____ C:\Users\Sue\Downloads\January 31, 2020 (1).pdf
2022-11-21 13:43 - 2021-02-13 15:44 - 000042706 _____ C:\Users\Sue\Downloads\February 29, 2020 (1).pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000058815 _____ C:\Users\Sue\Downloads\March 31, 2020 (1).pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000051325 _____ C:\Users\Sue\Downloads\December 31, 2020 (1).pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000050666 _____ C:\Users\Sue\Downloads\January 31, 2021.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000046597 _____ C:\Users\Sue\Downloads\November 30, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000045178 _____ C:\Users\Sue\Downloads\October 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000045173 _____ C:\Users\Sue\Downloads\September 30, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000044267 _____ C:\Users\Sue\Downloads\April 30, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000043943 _____ C:\Users\Sue\Downloads\August 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000042571 _____ C:\Users\Sue\Downloads\July 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000042564 _____ C:\Users\Sue\Downloads\June 30, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000037135 _____ C:\Users\Sue\Downloads\May 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:30 - 000051325 _____ C:\Users\Sue\Downloads\December 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:29 - 000058815 _____ C:\Users\Sue\Downloads\March 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:29 - 000042706 _____ C:\Users\Sue\Downloads\February 29, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:28 - 000047031 _____ C:\Users\Sue\Downloads\January 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:27 - 000053252 _____ C:\Users\Sue\Downloads\December 31, 2019.pdf
2022-11-21 13:43 - 2021-02-13 15:27 - 000042289 _____ C:\Users\Sue\Downloads\November 30, 2019.pdf
2022-11-21 13:43 - 2021-02-13 15:26 - 000045129 _____ C:\Users\Sue\Downloads\October 31, 2019.pdf
2022-11-21 13:43 - 2021-02-13 15:25 - 000044820 _____ C:\Users\Sue\Downloads\September 30, 2019.pdf
2022-11-21 13:43 - 2021-02-13 15:25 - 000040046 _____ C:\Users\Sue\Downloads\August 31, 2019 (1).pdf
2022-11-21 13:43 - 2021-02-13 15:24 - 000040046 _____ C:\Users\Sue\Downloads\August 31, 2019.pdf
2022-11-21 13:43 - 2021-02-10 13:55 - 000288465 _____ C:\Users\Sue\Downloads\iris-pocket-guide-2.pdf
2022-11-21 13:43 - 2021-02-08 10:56 - 000029431 _____ C:\Users\Sue\Downloads\TaxJurisdictionAnnually-en-us-4023877.mht
2022-11-21 13:43 - 2021-02-08 10:51 - 000084450 _____ C:\Users\Sue\Downloads\SVM00813-PBV00887.pdf
2022-11-21 13:43 - 2021-02-08 10:51 - 000084450 _____ C:\Users\Sue\Downloads\SVM00813-PBV00887 (1).pdf
2022-11-21 13:43 - 2021-02-05 16:55 - 000030393 _____ C:\Users\Sue\Downloads\14575.pdf
2022-11-21 13:43 - 2021-02-05 16:54 - 000067789 _____ C:\Users\Sue\Downloads\Inv_4816_from_Klings_Lawn__Landscape_LLC._5392.pdf
2022-11-21 13:43 - 2021-01-18 14:35 - 000000082 _____ C:\Users\Sue\Downloads\GlCodeSummaryReport_284360_001_20210118_153329 (2).csv
2022-11-21 13:43 - 2021-01-18 14:34 - 000020463 _____ C:\Users\Sue\Downloads\GlCodeDetailReport_284360_001_20210118_153329.csv
2022-11-21 13:43 - 2021-01-18 14:33 - 000000082 _____ C:\Users\Sue\Downloads\GlCodeSummaryReport_284360_001_20210118_153329.csv
2022-11-21 13:43 - 2021-01-18 14:33 - 000000082 _____ C:\Users\Sue\Downloads\GlCodeSummaryReport_284360_001_20210118_153329 (1).csv
2022-11-21 13:43 - 2021-01-10 15:46 - 000153983 _____ C:\Users\Sue\Downloads\11975871.pdf
2022-11-21 13:43 - 2021-01-10 15:46 - 000153983 _____ C:\Users\Sue\Downloads\11975871 (1).pdf
2022-11-21 13:43 - 2021-01-10 13:05 - 000067405 _____ C:\Users\Sue\Downloads\Inv_4783_from_Klings_Lawn__Landscape_LLC._1664.pdf
2022-11-21 13:43 - 2021-01-10 13:05 - 000067405 _____ C:\Users\Sue\Downloads\Inv_4783_from_Klings_Lawn__Landscape_LLC._1664 (1).pdf
2022-11-21 13:43 - 2020-12-06 16:30 - 000083963 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-11.pdf
2022-11-21 13:43 - 2020-12-06 16:28 - 000142603 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011987634.pdf
2022-11-21 13:43 - 2020-12-06 16:28 - 000083109 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011874619.pdf
2022-11-21 13:43 - 2020-12-06 16:28 - 000083109 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011874619 (1).pdf
2022-11-21 13:43 - 2020-12-06 16:28 - 000083087 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011874647.pdf
2022-11-21 13:43 - 2020-12-04 14:18 - 000042842 _____ C:\Users\Sue\Downloads\M234427803.PDF
2022-11-21 13:43 - 2020-12-04 14:17 - 000040366 _____ C:\Users\Sue\Downloads\M074018230.PDF
2022-11-21 13:43 - 2020-12-04 14:17 - 000040366 _____ C:\Users\Sue\Downloads\M074018230 (1).PDF
2022-11-21 13:43 - 2020-11-14 14:44 - 000301438 _____ C:\Users\Sue\Downloads\October 30, 2020.pdf
2022-11-21 13:43 - 2020-11-14 14:44 - 000301438 _____ C:\Users\Sue\Downloads\October 30, 2020 (1).pdf
2022-11-21 13:43 - 2020-11-14 12:06 - 000078641 _____ C:\Users\Sue\Downloads\October 23, 2020.pdf
2022-11-21 13:43 - 2020-11-10 10:14 - 001096493 _____ C:\Users\Sue\Downloads\Client information packet.zip
2022-11-21 13:43 - 2020-11-10 10:14 - 001096493 _____ C:\Users\Sue\Downloads\Client information packet (1).zip
2022-11-21 13:43 - 2020-11-07 15:42 - 000046479 _____ C:\Users\Sue\Downloads\midwestvet_4023877_20201101_8252840_2539518666 (1).pdf
2022-11-21 13:43 - 2020-11-07 15:39 - 000046479 _____ C:\Users\Sue\Downloads\midwestvet_4023877_20201101_8252840_2539518666.pdf
2022-11-21 13:43 - 2020-11-07 15:32 - 000153969 _____ C:\Users\Sue\Downloads\11543996.pdf
2022-11-21 13:43 - 2020-10-26 07:12 - 000153947 _____ C:\Users\Sue\Downloads\11679460.pdf
2022-11-21 13:43 - 2020-10-26 07:12 - 000153947 _____ C:\Users\Sue\Downloads\11679460 (1).pdf
2022-11-21 13:43 - 2020-10-19 14:07 - 001488986 _____ C:\Users\Sue\Downloads\05a Vetwatch Commentary-Week 40.pdf
2022-11-21 13:43 - 2020-10-15 13:55 - 001914679 _____ C:\Users\Sue\Downloads\VS.VEHCS Flier July 2020.pdf
2022-11-21 13:43 - 2020-10-15 13:55 - 000252928 _____ C:\Users\Sue\Downloads\Q3 NVAP Newsletter - supplemental export newsletter for SC  Madison (3).pub
2022-11-21 13:43 - 2020-10-15 13:54 - 000252928 _____ C:\Users\Sue\Downloads\Q3 NVAP Newsletter - supplemental export newsletter for SC  Madison.pub
2022-11-21 13:43 - 2020-10-15 13:54 - 000252928 _____ C:\Users\Sue\Downloads\Q3 NVAP Newsletter - supplemental export newsletter for SC  Madison (2).pub
2022-11-21 13:43 - 2020-10-15 13:54 - 000252928 _____ C:\Users\Sue\Downloads\Q3 NVAP Newsletter - supplemental export newsletter for SC  Madison (1).pub
2022-11-21 13:43 - 2020-10-15 13:27 - 000138734 _____ C:\Users\Sue\Downloads\Approval Requests - 7009284.html
2022-11-21 13:43 - 2020-10-06 12:52 - 000088977 _____ C:\Users\Sue\Downloads\ResumeAshleyToledo.pdf
2022-11-21 13:43 - 2020-10-05 07:13 - 000530604 _____ C:\Users\Sue\Downloads\MVSO New Launch Social Media Graphic_09.29_v2.jpg.html
2022-11-21 13:43 - 2020-09-20 12:06 - 000084698 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-04.pdf
2022-11-21 13:43 - 2020-09-20 12:06 - 000084698 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-04 (1).pdf
2022-11-21 13:43 - 2020-09-20 12:06 - 000084489 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-03.pdf
2022-11-21 13:43 - 2020-09-20 12:06 - 000084489 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-03 (1).pdf
2022-11-21 13:43 - 2020-09-20 12:06 - 000084272 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-01.pdf
2022-11-21 13:43 - 2020-09-20 12:06 - 000084272 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-01 (1).pdf
2022-11-21 13:43 - 2020-09-20 12:05 - 000084469 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-07.pdf
2022-11-21 13:43 - 2020-09-20 12:05 - 000084335 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-08.pdf
2022-11-21 13:43 - 2020-09-19 17:18 - 000001711 _____ C:\Users\Sue\Downloads\ph_wFQCA3.CSV
2022-11-21 13:43 - 2020-09-19 17:16 - 000164526 _____ C:\Users\Sue\Downloads\dnld20200919191635.pdf
2022-11-21 13:43 - 2020-09-19 17:15 - 001693563 _____ C:\Users\Sue\Downloads\dnld20200919191540.pdf
2022-11-21 13:43 - 2020-09-19 17:03 - 000110673 _____ C:\Users\Sue\Downloads\dnld20200919190346.pdf
2022-11-21 13:43 - 2020-09-19 16:47 - 000305087 _____ C:\Users\Sue\Downloads\dnld20200919184746.pdf
2022-11-21 13:43 - 2020-09-19 16:47 - 000305087 _____ C:\Users\Sue\Downloads\dnld20200919184744.pdf
2022-11-21 13:43 - 2020-09-19 16:41 - 000083069 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011319753.pdf
2022-11-21 13:43 - 2020-09-19 16:40 - 000082873 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011072887.pdf
2022-11-21 13:43 - 2020-08-16 13:45 - 000048336 _____ C:\Users\Sue\Downloads\Credit Card Agreement Form.pdf
2022-11-21 13:43 - 2020-08-15 17:39 - 000078513 _____ C:\Users\Sue\Downloads\July 23, 2020.pdf
2022-11-21 13:43 - 2020-08-14 12:36 - 000037544 _____ C:\Users\Sue\Downloads\ResumeDanielleJohnson.pdf
2022-11-21 13:43 - 2020-08-14 12:36 - 000036951 _____ C:\Users\Sue\Downloads\ResumeMariaPrzislicki.pdf
2022-11-21 13:43 - 2020-08-11 08:00 - 000131640 _____ C:\Users\Sue\Downloads\boni lacross Rabies certficate (1).pdf
2022-11-21 13:43 - 2020-08-11 07:57 - 000131640 _____ C:\Users\Sue\Downloads\boni lacross Rabies certficate.pdf
2022-11-21 13:43 - 2020-08-11 07:51 - 000789989 _____ C:\Users\Sue\Downloads\Boni Lacross paperwork for travel 2.pdf
2022-11-21 13:43 - 2020-08-10 16:04 - 000458831 _____ C:\Users\Sue\Downloads\Boni Lacross paperwork of travel.pdf
2022-11-21 13:43 - 2020-08-10 15:52 - 002359472 _____ C:\Users\Sue\Downloads\Boni Lacross.pdf
2022-11-21 13:43 - 2020-08-10 15:52 - 002359472 _____ C:\Users\Sue\Downloads\Boni Lacross (1).pdf
2022-11-21 13:43 - 2020-08-10 11:31 - 000063040 _____ C:\Users\Sue\Downloads\BONIL.html
2022-11-21 13:43 - 2020-08-01 09:19 - 000082926 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9010929400.pdf
2022-11-21 13:43 - 2020-07-31 15:20 - 000045292 _____ C:\Users\Sue\Downloads\Sue20200731_13321631.pdf
2022-11-21 13:43 - 2020-07-31 15:20 - 000045292 _____ C:\Users\Sue\Downloads\Sue20200731_13321631 (2).pdf
2022-11-21 13:43 - 2020-07-31 15:20 - 000045292 _____ C:\Users\Sue\Downloads\Sue20200731_13321631 (1).pdf
2022-11-21 13:43 - 2020-07-28 10:14 - 000030738 _____ C:\Users\Sue\Downloads\CPV2 CDV Results C Klamert Webster  July 2020.pdf
2022-11-21 13:43 - 2020-07-28 09:19 - 000042060 _____ C:\Users\Sue\Downloads\ResumeLoriBierman.pdf
2022-11-21 13:43 - 2020-07-28 09:19 - 000042060 _____ C:\Users\Sue\Downloads\ResumeLoriBierman (1).pdf
2022-11-21 13:43 - 2020-07-27 07:49 - 000035963 _____ C:\Users\Sue\Downloads\ResumeCourtneyThistle.pdf
2022-11-21 13:43 - 2020-07-27 07:49 - 000035963 _____ C:\Users\Sue\Downloads\ResumeCourtneyThistle (1).pdf
2022-11-21 13:43 - 2020-07-25 11:53 - 000094387 _____ C:\Users\Sue\Downloads\sensor 1.pdf
2022-11-21 13:43 - 2020-07-25 11:35 - 000090787 _____ C:\Users\Sue\Downloads\VEHCS flyer_MARCH 2017 (1).pdf
2022-11-21 13:43 - 2020-07-25 11:29 - 000341449 _____ C:\Users\Sue\Downloads\AVMA Poster VEHCS.PDF
2022-11-21 13:43 - 2020-07-25 11:27 - 000090787 _____ C:\Users\Sue\Downloads\VEHCS flyer_MARCH 2017.pdf
2022-11-21 13:43 - 2020-07-25 11:24 - 000041290 _____ C:\Users\Sue\Downloads\M011214551.PDF
2022-11-21 13:43 - 2020-07-25 11:24 - 000041290 _____ C:\Users\Sue\Downloads\M011214551 (1).PDF
2022-11-21 13:43 - 2020-07-23 12:40 - 000127688 _____ C:\Users\Sue\Downloads\CBS August 2020.pptx
2022-11-21 13:43 - 2020-07-23 12:40 - 000127688 _____ C:\Users\Sue\Downloads\CBS August 2020 (1).pptx
2022-11-21 13:43 - 2020-07-17 15:37 - 000605107 _____ C:\Users\Sue\Downloads\image1.jpeg
2022-11-21 13:43 - 2020-07-17 15:36 - 000666325 _____ C:\Users\Sue\Downloads\image0 (2).jpeg
2022-11-21 13:43 - 2020-07-17 15:36 - 000659535 _____ C:\Users\Sue\Downloads\image0 (1).jpeg
2022-11-21 13:43 - 2020-07-17 15:32 - 000659535 _____ C:\Users\Sue\Downloads\image0.jpeg
2022-11-21 13:43 - 2020-07-17 13:15 - 000132110 _____ C:\Users\Sue\Downloads\REPORT_ Sammy Name_ Beringer^Sammy^^^ Species_ CANINE At Tender Touch Veterinary Care.pdf
2022-11-21 13:43 - 2020-07-15 17:50 - 000583246 _____ C:\Users\Sue\Downloads\sensor 1.html
2022-11-21 13:43 - 2020-04-18 09:07 - 002238453 _____ C:\Users\Sue\Downloads\PPP1.pdf
2022-11-21 13:43 - 2020-04-18 09:07 - 000111748 _____ C:\Users\Sue\Downloads\ppp2.pdf
2022-11-21 13:43 - 2020-04-07 15:10 - 003713997 _____ C:\Users\Sue\Downloads\Gravity_Documents_for_Tender_Touch_Veterinary.pdf
2022-11-21 13:43 - 2020-04-02 10:22 - 000044185 _____ C:\Users\Sue\Downloads\ResumeCharityNelson.pdf
2022-11-21 13:43 - 2020-03-31 17:04 - 000068646 _____ C:\Users\Sue\Downloads\magnet.pdf
2022-11-21 13:43 - 2020-02-14 14:57 - 000036657 _____ C:\Users\Sue\Downloads\mortgage 2020 part 2.pdf
2022-11-21 13:43 - 2020-02-14 14:56 - 000113023 _____ C:\Users\Sue\Downloads\Tender Touch Renewal2020 mortgage.pdf
2022-11-21 13:43 - 2019-10-08 14:07 - 000085272 _____ C:\Users\Sue\Downloads\ConnectWiseControl.Client (2).exe
2022-11-21 13:43 - 2019-10-01 12:20 - 000630331 _____ C:\Users\Sue\Downloads\6291FD2D-3380-4574-913C-97C80B8AE5A2.pdf
2022-11-21 13:43 - 2019-09-03 15:21 - 000075853 _____ C:\Users\Sue\Downloads\aero.txt
2022-11-21 13:43 - 2019-01-11 11:44 - 000054561 _____ C:\Users\Sue\Downloads\February 28, 2018 (1).pdf
2022-11-21 13:43 - 2019-01-11 11:43 - 000042175 _____ C:\Users\Sue\Downloads\April 30, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:43 - 000040277 _____ C:\Users\Sue\Downloads\January 31, 2018 (2).pdf
2022-11-21 13:43 - 2019-01-11 11:43 - 000037068 _____ C:\Users\Sue\Downloads\March 31, 2018 (1).pdf
2022-11-21 13:43 - 2019-01-11 11:42 - 000042147 _____ C:\Users\Sue\Downloads\May 31, 2018 (1).pdf
2022-11-21 13:43 - 2019-01-11 11:42 - 000037085 _____ C:\Users\Sue\Downloads\June 30, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:41 - 000042283 _____ C:\Users\Sue\Downloads\July 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:38 - 000041815 _____ C:\Users\Sue\Downloads\October 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000054561 _____ C:\Users\Sue\Downloads\February 28, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000043434 _____ C:\Users\Sue\Downloads\September 30, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000042158 _____ C:\Users\Sue\Downloads\December 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000042158 _____ C:\Users\Sue\Downloads\December 31, 2018 (1).pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000042155 _____ C:\Users\Sue\Downloads\August 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000042147 _____ C:\Users\Sue\Downloads\May 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000040519 _____ C:\Users\Sue\Downloads\November 30, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000037068 _____ C:\Users\Sue\Downloads\March 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:36 - 000040277 _____ C:\Users\Sue\Downloads\January 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:36 - 000040277 _____ C:\Users\Sue\Downloads\January 31, 2018 (1).pdf
2022-11-21 13:43 - 2019-01-11 11:30 - 000414497 _____ C:\Users\Sue\Downloads\Amortization_Schedule (4).pdf
2022-11-21 13:43 - 2019-01-11 11:28 - 000414442 _____ C:\Users\Sue\Downloads\Amortization_Schedule (3).pdf
2022-11-21 13:43 - 2019-01-08 12:03 - 000186549 _____ C:\Users\Sue\Downloads\Vet License.pdf
2022-11-21 13:43 - 2019-01-01 14:01 - 002491413 _____ C:\Users\Sue\Downloads\AVImark-End-of-the-Year-FAQs.pdf
2022-11-21 13:43 - 2018-12-04 13:39 - 000417558 _____ C:\Users\Sue\Downloads\Amortization_Schedule (2).pdf
2022-11-21 13:43 - 2018-11-15 17:21 - 000027476 _____ C:\Users\Sue\Downloads\export 1.csv
2022-11-21 13:43 - 2018-08-19 12:45 - 000034657 _____ C:\Users\Sue\Downloads\July 23, 2018.pdf
2022-11-21 13:43 - 2018-08-19 12:45 - 000034657 _____ C:\Users\Sue\Downloads\July 23, 2018 (1).pdf
2022-11-21 13:43 - 2018-04-22 07:04 - 000439287 _____ C:\Users\Sue\Downloads\Amortization_Schedule (1).pdf
2022-11-21 13:43 - 2018-03-25 09:24 - 000443812 _____ C:\Users\Sue\Downloads\Amortization_Schedule.pdf
2022-11-21 13:43 - 2018-02-15 16:48 - 000841268 _____ C:\Users\Sue\Downloads\Royal 2018.pdf
2022-11-21 13:43 - 2017-12-26 18:02 - 000347897 _____ C:\Users\Sue\Downloads\international cert Shilio.pdf
2022-11-21 13:43 - 2017-10-25 14:27 - 000381821 _____ C:\Users\Sue\Downloads\Ann Gutting 2018 COI plit.pdf
2022-11-21 13:43 - 2017-10-25 14:25 - 000187137 _____ C:\Users\Sue\Downloads\Gutting 2019 wi license.pdf
2022-11-21 13:43 - 2017-09-19 13:26 - 445123208 _____ (Intuit Inc.) C:\Users\Sue\Downloads\qbwebpatch.exe
2022-11-21 13:43 - 2017-06-07 11:10 - 002833655 _____ C:\Users\Sue\Downloads\[Untitled] (2).pdf
2022-11-21 13:43 - 2017-06-07 10:57 - 000154944 _____ C:\Users\Sue\Downloads\[Untitled] (1).pdf
2022-11-21 13:43 - 2017-05-30 08:23 - 000684067 _____ C:\Users\Sue\Downloads\VGP Overview Sheet.pdf
2022-11-21 13:43 - 2017-05-30 08:19 - 000726779 _____ C:\Users\Sue\Downloads\VGP 2017 June Pathway Planning Workshop Flyer_Chicago_Rd03.pdf
2022-11-21 13:43 - 2017-05-24 16:21 - 006262463 _____ C:\Users\Sue\Downloads\MER-17022_Summer_Sell-in_Promotion_detailer_Scroll indd.pdf
2022-11-21 13:43 - 2017-05-24 16:19 - 000102364 _____ C:\Users\Sue\Downloads\Suggested Order for TENDER TOUCH__ VET CARE-TENDER TOUCH VET CARE - 051917....pdf
2022-11-21 13:43 - 2017-05-21 09:30 - 000003554 _____ C:\Users\Sue\Downloads\sigimg0
2022-11-21 13:43 - 2017-05-21 09:30 - 000003503 _____ C:\Users\Sue\Downloads\sigimg1
2022-11-21 13:43 - 2017-05-10 10:21 - 000332456 _____ C:\Users\Sue\Downloads\Customizing Treatment Options (3).pdf
2022-11-21 13:43 - 2017-05-10 08:17 - 000625606 _____ C:\Users\Sue\Downloads\CYT  Recommended Order Sell Sheet.pdf
2022-11-21 13:43 - 2017-05-10 08:15 - 000765038 _____ C:\Users\Sue\Downloads\CYT Dosing Cling .pdf
2022-11-21 13:43 - 2017-05-10 08:12 - 000332456 _____ C:\Users\Sue\Downloads\Customizing Treatment Options.pdf
2022-11-21 13:43 - 2017-05-10 08:12 - 000332456 _____ C:\Users\Sue\Downloads\Customizing Treatment Options (2).pdf
2022-11-21 13:43 - 2017-05-10 08:12 - 000332456 _____ C:\Users\Sue\Downloads\Customizing Treatment Options (1).pdf
2022-11-21 13:43 - 2017-05-10 08:11 - 001244205 _____ C:\Users\Sue\Downloads\CYT Now Available Flyer  (Color) -.pdf
2022-11-21 13:43 - 2017-05-02 16:44 - 000142364 _____ C:\Users\Sue\Downloads\[Untitled].pdf
2022-11-21 13:43 - 2017-04-26 16:06 - 000774086 _____ C:\Users\Sue\Downloads\CatFoodProteinFatCarbPhosphorusChart.pdf
2022-11-21 13:43 - 2017-04-21 15:49 - 001364249 _____ C:\Users\Sue\Downloads\Tender Touch Veterinary Care - IT Support Plans and Estimate.pdf
2022-11-21 13:43 - 2017-04-10 09:40 - 000107100 _____ C:\Users\Sue\Downloads\20003110 Tender Touch Vet Care - Bladview 4343R CSI (1).pdf
2022-11-21 13:43 - 2017-04-10 09:20 - 000107100 _____ C:\Users\Sue\Downloads\20003110 Tender Touch Vet Care - Bladview 4343R CSI.pdf
2022-11-21 13:43 - 2017-03-24 12:42 - 000128358 _____ C:\Users\Sue\Downloads\Tender Touch Veterinary Care 03-24-17_v1.pdf
2022-11-21 13:43 - 2017-03-24 12:41 - 000437797 _____ C:\Users\Sue\Downloads\Computers Supplied by VetRay Technologies.pdf
2022-11-21 13:43 - 2017-03-24 08:14 - 000015147 _____ C:\Users\Sue\Downloads\Vet exposure chart_V20170321.xlsx
2022-11-21 13:43 - 2017-03-22 09:03 - 000952320 _____ C:\Users\Sue\Downloads\20003110 Tender Touch Vet Care - Bladview 4343R CSI (EVB).xls
2022-11-21 13:43 - 2017-03-15 13:47 - 000333594 _____ C:\Users\Sue\Downloads\1 Brochure Precision DR C 1417 Low 1500L C.pdf
2022-11-21 13:43 - 2017-03-15 13:47 - 000333594 _____ C:\Users\Sue\Downloads\1 Brochure Precision DR C 1417 Low 1500L C (2).pdf
2022-11-21 13:43 - 2017-03-15 13:47 - 000333594 _____ C:\Users\Sue\Downloads\1 Brochure Precision DR C 1417 Low 1500L C (1).pdf
2022-11-21 13:43 - 2017-03-06 10:53 - 000115396 _____ C:\Users\Sue\Downloads\2016-09-29_Education Coordinator.pdf
2022-11-21 13:43 - 2017-02-27 13:56 - 000430284 _____ C:\Users\Sue\Downloads\fluhr 2-26.pdf
2022-11-21 13:43 - 2017-02-21 12:31 - 000144714 _____ C:\Users\Sue\Downloads\Invoice INV211128487.pdf
2022-11-21 13:43 - 2017-02-07 15:28 - 000026241 _____ C:\Users\Sue\Downloads\ResumeJudiMihas.pdf
2022-11-21 13:43 - 2017-02-05 12:23 - 000008470 _____ C:\Users\Sue\Downloads\ResumeEmilyOgnenoff.pdf
2022-11-21 13:43 - 2017-02-05 12:20 - 000014677 _____ C:\Users\Sue\Downloads\ResumeSamanthaMiller.pdf
2022-11-21 13:43 - 2017-02-05 12:14 - 000188316 _____ C:\Users\Sue\Downloads\7152218001_20170204_191532.wav
2022-11-21 13:43 - 2017-02-05 12:14 - 000101286 _____ C:\Users\Sue\Downloads\6082890689_20170205_075711.wav
2022-11-21 13:43 - 2017-02-05 12:14 - 000098935 _____ C:\Users\Sue\Downloads\2622241144_20170204_182321.wav
2022-11-21 13:43 - 2017-02-05 12:13 - 000096663 _____ C:\Users\Sue\Downloads\8003090524_20170205_115430.wav
2022-11-21 13:43 - 2017-02-05 12:13 - 000096663 _____ C:\Users\Sue\Downloads\8003090524_20170205_115430 (1).wav
2022-11-21 13:43 - 2017-01-25 16:44 - 000166335 _____ C:\Users\Sue\Downloads\2629394965_20170125_162055.wav
2022-11-21 13:43 - 2017-01-18 15:30 - 000103652 _____ C:\Users\Sue\Downloads\Statement 305310.pdf
2022-11-21 13:43 - 2017-01-09 10:29 - 000221798 _____ C:\Users\Sue\Downloads\sales and use 2015.pdf
2022-11-21 13:43 - 2017-01-06 13:09 - 000034603 _____ C:\Users\Sue\Downloads\Invoice-000114-01_05_2017.pdf
2022-11-21 13:43 - 2017-01-02 08:50 - 000038442 _____ C:\Users\Sue\Downloads\Invoice-000111-12_31_2016.pdf
2022-11-21 13:43 - 2016-12-07 14:48 - 000004143 _____ C:\Users\Sue\Downloads\Invoice- Beth.pdf
2022-11-21 13:43 - 2016-11-30 12:34 - 000137380 _____ C:\Users\Sue\Downloads\2626896424_20161130_122602.wav
2022-11-21 13:43 - 2016-11-25 17:12 - 000035830 _____ C:\Users\Sue\Downloads\Invoice-000108-11_22_2016.pdf
2022-11-21 13:43 - 2016-11-11 16:02 - 000109107 _____ C:\Users\Sue\Downloads\Suggested Order for TENDER TOUCH__ VET CARE-2016 Winter Sell-In PromotionTrue.pdf
2022-11-21 13:43 - 2016-11-07 17:25 - 000091023 _____ C:\Users\Sue\Downloads\M16-27013_F_20161107113339 (2).PDF
2022-11-21 13:43 - 2016-11-07 17:24 - 000091279 _____ C:\Users\Sue\Downloads\M16-27013_P_20161006180202.PDF
2022-11-21 13:43 - 2016-11-07 16:58 - 000091023 _____ C:\Users\Sue\Downloads\M16-27013_F_20161107113339 (1).PDF
2022-11-21 13:43 - 2016-11-07 16:56 - 000091023 _____ C:\Users\Sue\Downloads\M16-27013_F_20161107113339.PDF
2022-11-21 13:43 - 2016-10-31 12:42 - 000042114 _____ C:\Users\Sue\Downloads\Invoice-000107-10_28_2016.pdf
2022-11-21 13:43 - 2016-10-05 16:09 - 000126392 _____ C:\Users\Sue\Downloads\RptAccPrint.pdf
2022-11-21 13:43 - 2016-10-02 11:03 - 000035717 _____ C:\Users\Sue\Downloads\Invoice-000097-09_30_2016.pdf
2022-11-21 13:43 - 2016-09-23 14:25 - 000385460 _____ C:\Users\Sue\Downloads\F1683216.pdf
2022-11-21 13:43 - 2016-08-31 10:42 - 000034924 _____ C:\Users\Sue\Downloads\Invoice-000095-08_30_2016.pdf
2022-11-21 13:43 - 2016-08-05 09:26 - 000385792 _____ C:\Users\Sue\Downloads\F1667213.pdf
2022-11-21 13:43 - 2016-07-27 13:38 - 000063603 _____ C:\Users\Sue\Downloads\Lab Report - 094-026472-A01.pdf
2022-11-21 13:43 - 2016-07-27 13:38 - 000063603 _____ C:\Users\Sue\Downloads\Lab Report - 094-026472-A01 (1).pdf
2022-11-21 13:43 - 2016-07-25 12:00 - 000246416 _____ C:\Users\Sue\Downloads\7.4.27 - Public Relations Coordinator.pdf
2022-11-21 13:43 - 2016-07-18 13:19 - 000209516 _____ C:\Users\Sue\Downloads\Grrow,Elsa-paper file bldwork.pdf
2022-11-21 13:43 - 2016-07-14 13:19 - 000344268 _____ C:\Users\Sue\Downloads\bugatti gundrum international certificate (2).pdf
2022-11-21 13:43 - 2016-07-14 13:08 - 000342933 _____ C:\Users\Sue\Downloads\bugatti gundrum international certificate (1).pdf
2022-11-21 13:43 - 2016-07-14 13:07 - 000342933 _____ C:\Users\Sue\Downloads\bugatti gundrum international certificate.pdf
2022-11-21 13:43 - 2016-07-13 08:47 - 001600002 _____ C:\Users\Sue\Downloads\mod09_web_completion_certificate (1).pdf
2022-11-21 13:43 - 2016-07-13 08:38 - 001600002 _____ C:\Users\Sue\Downloads\mod09_web_completion_certificate.pdf
2022-11-21 13:43 - 2016-07-13 08:38 - 001583676 _____ C:\Users\Sue\Downloads\mod07_web_completion_certificate.pdf
2022-11-21 13:43 - 2016-07-13 08:38 - 001583676 _____ C:\Users\Sue\Downloads\mod07_web_completion_certificate (1).pdf
2022-11-21 13:43 - 2016-07-13 08:37 - 000904469 _____ C:\Users\Sue\Downloads\mod10_web_completion_certificate.pdf
2022-11-21 13:43 - 2016-06-27 10:51 - 000445248 _____ C:\Users\Sue\Downloads\document-0.pdf
2022-11-21 13:43 - 2016-06-06 12:59 - 166179864 _____ (Kaspersky Lab) C:\Users\Sue\Downloads\kts16.0.1.445abcen_10308 (1).exe
2022-11-21 13:43 - 2016-06-06 10:53 - 166179864 _____ (Kaspersky Lab) C:\Users\Sue\Downloads\kts16.0.1.445abcen_10308.exe
2022-11-21 13:43 - 2016-05-31 09:59 - 000035981 _____ C:\Users\Sue\Downloads\Invoice-000082-05_27_2016.pdf
2022-11-21 13:43 - 2016-05-26 16:30 - 000537328 _____ C:\Users\Sue\Downloads\Setup_QuickBooksPro2016.exe
2022-11-21 13:43 - 2016-05-26 16:26 - 001838632 _____ (LogMeIn, Inc.) C:\Users\Sue\Downloads\Support-LogMeInRescue.exe
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\winnie_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\U.S. Bank - My Loan2-20-22_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\RenderReport_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\Online Return Center_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\lock box_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\license 2023_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\licence 2023_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\Custom Office Templates
2022-11-21 13:41 - 2022-08-19 14:03 - 000303653 _____ C:\Users\Sue\Documents\AFASTIntroductiontoItsTargetOrganApproachandFluidScoringSystems (1).pdf
2022-11-21 13:41 - 2022-08-19 14:01 - 000303653 _____ C:\Users\Sue\Documents\AFASTIntroductiontoItsTargetOrganApproachandFluidScoringSystems.pdf
2022-11-21 13:41 - 2022-07-27 15:29 - 000000084 _____ C:\Users\Sue\Documents\payments.csv
2022-11-21 13:41 - 2022-07-11 12:54 - 000024251 _____ C:\Users\Sue\Documents\iris reciept.pdf
2022-11-21 13:41 - 2022-07-10 12:13 - 000425521 _____ C:\Users\Sue\Documents\Online Return Center.html
2022-11-21 13:41 - 2022-06-28 10:34 - 000675159 _____ C:\Users\Sue\Documents\2021 Fluhr, Suzanne Individual Client Copy personal taxes.pdf
2022-11-21 13:41 - 2022-06-25 13:41 - 000479981 _____ C:\Users\Sue\Documents\TENDER TOUCH VETERINARY CARE INC_2021_1120S_Tax Returns.pdf
2022-11-21 13:41 - 2022-06-25 13:31 - 000874920 _____ C:\Users\Sue\Documents\TENDER TOUCH VETERINARY CARE INC_2021_1120S_Tax Returns (7).zip
2022-11-21 13:41 - 2022-06-25 13:23 - 000771014 _____ C:\Users\Sue\Documents\TENDER TOUCH VETERINARY CARE INC_2021_1120S_Tax Returns (5).zip
2022-11-21 13:41 - 2022-06-01 13:17 - 009204132 _____ C:\Users\Sue\Documents\lock box.html
2022-11-21 13:41 - 2022-05-29 13:27 - 000025725 _____ C:\Users\Sue\Documents\Dr Sue License.pdf
2022-11-21 13:41 - 2022-05-24 11:00 - 000274268 _____ C:\Users\Sue\Documents\winnie.html
2022-11-21 13:41 - 2022-03-23 14:17 - 000108754 _____ C:\Users\Sue\Documents\Insurance Census 2022.pdf
2022-11-21 13:41 - 2022-03-11 17:26 - 000141974 _____ C:\Users\Sue\Documents\MYS.jpeg
2022-11-21 13:41 - 2022-02-22 14:01 - 009160564 _____ C:\Users\Sue\Documents\-vs2-operator_s-manual-no-crops.pdf
2022-11-21 13:41 - 2022-02-19 14:25 - 000394929 _____ C:\Users\Sue\Documents\U.S. Bank - My Loan2-20-22.html
2022-11-21 13:41 - 2022-02-13 14:28 - 000213687 _____ C:\Users\Sue\Documents\jan 22 sales tax.pdf
2022-11-21 13:41 - 2022-02-09 17:26 - 000068071 _____ C:\Users\Sue\Documents\TaxJurisdictionMonthly-en-us-4023877 (1) jan 2022.pdf
2022-11-21 13:41 - 2022-02-09 17:24 - 000051557 _____ C:\Users\Sue\Documents\TaxSummaryMonthly-en-us-4023877Jan 2021.pdf
2022-11-21 13:41 - 2022-01-28 16:57 - 000100656 _____ C:\Users\Sue\Documents\2021 Updated Employee W-2s.pdf
2022-11-21 13:41 - 2022-01-21 09:31 - 001160720 _____ C:\Users\Sue\Documents\ColdWeatherSafety.pdf
2022-11-21 13:41 - 2022-01-16 14:31 - 000042428 _____ C:\Users\Sue\Documents\2021-01-27 Statement - USB Sue Savings 3473.pdf
2022-11-21 13:41 - 2022-01-15 13:41 - 000051110 _____ C:\Users\Sue\Documents\MYS Dec 21 Tax.pdf
2022-11-21 13:41 - 2022-01-01 13:03 - 009434929 _____ C:\Users\Sue\Documents\contract signed.pdf
2022-11-21 13:41 - 2022-01-01 13:01 - 001185532 _____ C:\Users\Sue\Documents\document.pdf
2022-11-21 13:41 - 2022-01-01 13:01 - 000187956 _____ C:\Users\Sue\Documents\VEBLegalCertificateAllison.pdf
2022-11-21 13:41 - 2022-01-01 12:57 - 000000082 _____ C:\Users\Sue\Documents\GlCodeSummaryReport_284360_001_20220101_135733.csv
2022-11-21 13:41 - 2022-01-01 12:42 - 000806662 _____ C:\Users\Sue\Documents\AVImark-Year-End-Processes_12092021.pdf
2022-11-21 13:41 - 2022-01-01 11:57 - 000029370 _____ C:\Users\Sue\Documents\Amortization schedule1-1-22.pdf
2022-11-21 13:41 - 2022-01-01 10:36 - 000050838 _____ C:\Users\Sue\Documents\TaxSummaryMonthly-en-us-4023877.pdf
2022-11-21 13:41 - 2021-12-29 12:38 - 000000400 _____ C:\Users\Sue\Documents\licence 2023.htm
2022-11-21 13:41 - 2021-12-29 12:37 - 000000400 _____ C:\Users\Sue\Documents\RenderReport.htm
2022-11-21 13:41 - 2021-12-26 16:00 - 000000400 _____ C:\Users\Sue\Documents\license 2023.htm
2022-11-21 13:41 - 2021-12-25 17:23 - 000000000 ____D C:\Users\Sue\Documents\FeedbackHub
2022-11-21 13:41 - 2021-12-22 18:46 - 000188529 _____ C:\Users\Sue\Documents\VEBLegalCertificatelicense 2023.pdf
2022-11-21 13:41 - 2021-12-14 16:16 - 003900274 _____ C:\Users\Sue\Documents\VINFoundation_ModelEmploymentAgreement_042018.pdf
2022-11-21 13:41 - 2021-10-02 16:25 - 000067863 _____ C:\Users\Sue\Documents\TaxJurisdictionMonthly-en-us-4023877.pdf
2022-11-21 13:41 - 2021-09-30 14:43 - 000020970 _____ C:\Users\Sue\Documents\DEA2021.pdf
2022-11-21 13:41 - 2021-05-16 13:56 - 000924264 _____ C:\Users\Sue\Documents\fte.pdf
2022-11-21 13:41 - 2021-05-16 13:43 - 001300599 _____ C:\Users\Sue\Documents\222.pdf
2022-11-21 13:41 - 2021-05-16 13:42 - 001513069 _____ C:\Users\Sue\Documents\sum.pdf
2022-11-21 13:41 - 2021-05-16 13:39 - 003213569 _____ C:\Users\Sue\Documents\nov2.pdf
2022-11-21 13:41 - 2021-05-16 13:38 - 003053350 _____ C:\Users\Sue\Documents\nov1.pdf
2022-11-21 13:41 - 2021-05-16 13:34 - 009751493 _____ C:\Users\Sue\Documents\sobs.pdf
2022-11-21 13:41 - 2021-05-16 13:25 - 009910722 _____ C:\Users\Sue\Documents\jsbs.pdf
2022-11-21 13:41 - 2021-05-16 13:18 - 009165865 _____ C:\Users\Sue\Documents\bsmj.pdf
2022-11-21 13:41 - 2021-05-16 13:13 - 006799728 _____ C:\Users\Sue\Documents\Scan.pdf
2022-11-21 13:41 - 2021-05-16 12:59 - 006857725 _____ C:\Users\Sue\Documents\941 for PPP.pdf
2022-11-21 13:41 - 2021-05-12 07:58 - 001302991 _____ C:\Users\Sue\Documents\Scan 222.pdf
2022-11-21 13:41 - 2021-03-13 11:31 - 000137444 _____ C:\Users\Sue\Documents\tax feb.oxps
2022-11-21 13:41 - 2021-01-13 15:22 - 000143715 _____ C:\Users\Sue\Documents\[email protected]
2022-11-21 13:41 - 2020-11-21 14:19 - 000071457 _____ C:\Users\Sue\Documents\20200331_INWKS941.pdf
2022-11-21 13:41 - 2020-11-21 14:10 - 000176205 _____ C:\Users\Sue\Documents\20200930_INWKS941.pdf
2022-11-21 13:41 - 2020-11-21 14:07 - 000537581 _____ C:\Users\Sue\Documents\20200630_INWKS941.pdf
2022-11-21 13:41 - 2020-11-21 14:05 - 000005809 _____ C:\Users\Sue\Documents\20200930_WIUCT101.pdf
2022-11-21 13:41 - 2020-11-21 13:58 - 000005808 _____ C:\Users\Sue\Documents\20200630_WIUCT101.pdf
2022-11-21 13:41 - 2020-08-11 08:00 - 000131640 _____ C:\Users\Sue\Documents\bonilacrossR.pdf
2022-11-21 13:41 - 2020-08-11 07:58 - 000131640 _____ C:\Users\Sue\Documents\Rabie Boni.pdf
2022-11-21 13:41 - 2020-08-11 07:52 - 000789989 _____ C:\Users\Sue\Documents\BoniLacrosstravel2.pdf
2022-11-21 13:41 - 2020-08-10 16:08 - 000458831 _____ C:\Users\Sue\Documents\Bonilacross.pdf
2022-11-21 13:41 - 2020-08-10 16:07 - 000458831 _____ C:\Users\Sue\Documents\Boni Lacross 1.pdf
2022-11-21 13:41 - 2020-08-10 16:04 - 000458831 _____ C:\Users\Sue\Documents\Boni Lacross paperwork of travel.pdf
2022-11-21 13:41 - 2020-08-10 11:29 - 000272498 _____ C:\Users\Sue\Documents\BONI.pdf
2022-11-21 13:41 - 2020-08-10 11:24 - 000272029 _____ C:\Users\Sue\Documents\Boni Lacross.pdf
2022-11-21 13:41 - 2020-06-11 11:09 - 000000000 ____D C:\Users\Sue\Documents\Zoom
2022-11-21 13:41 - 2020-03-29 14:06 - 001996755 _____ C:\Users\Sue\Documents\TenderTouch (1).pdf
2022-11-21 13:41 - 2020-02-19 16:16 - 000207178 _____ C:\Users\Sue\Documents\Max 2020.oxps
2022-11-21 13:41 - 2018-02-25 10:44 - 000004704 _____ C:\Users\Sue\Documents\payment-confirmation-2-24-18.pdf
2022-11-21 13:41 - 2016-11-06 14:01 - 000164751 _____ C:\Users\Sue\Documents\Book2.xlsx
2022-11-21 13:36 - 2022-11-21 13:36 - 000000000 ___HD C:\OneDriveTemp
2022-11-21 13:34 - 2022-11-21 13:36 - 000000000 ____D C:\Users\Sue\AppData\Local\Notepad
2022-11-21 13:32 - 2022-11-21 13:32 - 000297472 _____ C:\Windows\system32\Windows.Management.InprocObjects.dll
2022-11-21 13:20 - 2022-11-21 13:20 - 000000625 _____ C:\Users\Sue\Desktop\SharedDocuments (TTVC-SVRData) (S) - Shortcut.lnk
2022-11-21 13:01 - 2022-11-21 15:02 - 000000000 ____D C:\Backup
2022-11-21 12:26 - 2022-11-21 12:33 - 000000000 ____D C:\ProgramData\scre..tion_b15b0581876c57b7_0015.000d_86ab3ae43306d26a
2022-11-21 12:26 - 2022-11-21 12:26 - 000086688 _____ C:\Users\Sue\Downloads\ConnectWiseControl.Client (1).exe
2022-11-19 16:09 - 2022-11-19 16:11 - 037942757 _____ C:\Users\Sue\Downloads\Protect Every Pet Clinic Toolkit.zip
2022-11-19 15:57 - 2022-11-19 15:57 - 000067704 _____ C:\Users\Sue\Downloads\TaxJurisdictionMonthly-en-us-4023877.pdf
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-12-19 17:51 - 2021-10-27 11:15 - 000000000 ____D C:\Windows\system32\SleepStudy
2022-12-19 17:28 - 2022-11-10 21:23 - 000000000 ____D C:\Program Files (x86)\Google
2022-12-19 17:16 - 2019-12-07 03:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-12-19 14:07 - 2019-12-07 03:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-12-19 14:07 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\AppReadiness
2022-12-17 12:14 - 2022-11-10 17:12 - 000000000 ____D C:\ProgramData\ScreenConnect Client (61e735463d3bf1de)
2022-12-17 11:04 - 2022-11-11 09:00 - 000004784 _____ C:\Windows\system32\Tasks\MicrosoftEdgeShadowStackRollbackTask
2022-12-17 11:04 - 2021-10-27 11:15 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-12-16 11:19 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\D3DSCache
2022-12-15 16:04 - 2022-11-11 10:37 - 000000000 ____D C:\ProgramData\EPSON
2022-12-15 16:04 - 2022-11-11 10:37 - 000000000 ____D C:\Program Files\epson
2022-12-15 16:04 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\Lenovo
2022-12-15 16:04 - 2022-06-20 22:51 - 000000000 ____D C:\ProgramData\Lenovo
2022-12-15 16:04 - 2022-06-20 22:00 - 000000000 ____D C:\Windows\system32\Tasks\Lenovo
2022-12-15 16:04 - 2022-06-20 22:00 - 000000000 ____D C:\Windows\Lenovo
2022-12-15 15:58 - 2019-12-07 03:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2022-12-15 15:29 - 2022-11-10 21:24 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-12-15 15:29 - 2022-11-10 21:24 - 000002213 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-12-14 15:56 - 2019-12-07 03:13 - 000000000 ____D C:\Windows\INF
2022-12-14 15:47 - 2022-09-21 18:43 - 000795738 _____ C:\Windows\system32\PerfStringBackup.INI
2022-12-14 15:42 - 2022-11-10 17:15 - 000000000 ___RD C:\Users\Sue\OneDrive
2022-12-14 15:41 - 2022-11-10 21:23 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3259427507-1055586877-3198061443-1001
2022-12-14 15:41 - 2022-11-10 16:03 - 000000000 ____D C:\Program Files\Mesh Agent
2022-12-14 15:40 - 2022-11-10 15:57 - 000000000 ____D C:\Program Files\TeamViewer
2022-12-14 15:40 - 2022-06-20 22:01 - 000000000 ____D C:\Program Files\Microsoft Office
2022-12-14 15:40 - 2021-10-27 11:15 - 000454824 _____ C:\Windows\system32\FNTCACHE.DAT
2022-12-14 15:40 - 2021-10-27 11:15 - 000008192 ___SH C:\DumpStack.log.tmp
2022-12-14 15:40 - 2021-10-27 11:15 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-12-14 15:40 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\ServiceState
2022-12-14 15:40 - 2019-12-07 03:03 - 000524288 _____ C:\Windows\system32\config\BBI
2022-12-14 15:39 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\bcastdvr
2022-12-14 15:39 - 2019-12-07 03:14 - 000000000 ____D C:\Program Files\Common Files\System
2022-12-14 15:37 - 2022-11-10 17:12 - 000000000 ____D C:\Users\Sue
2022-12-14 15:37 - 2019-12-07 03:03 - 000000000 ____D C:\Windows\CbsTemp
2022-12-14 06:41 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2022-12-14 06:40 - 2022-11-10 15:38 - 000000000 ____D C:\Windows\system32\MRT
2022-12-14 06:39 - 2022-11-10 15:38 - 148633544 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2022-12-13 14:04 - 2022-11-10 21:12 - 000002208 _____ C:\Users\Sue\Desktop\AVImark - Shortcut.lnk
2022-12-08 16:47 - 2021-10-27 11:15 - 000000000 ____D C:\Windows\system32\Drivers\wd
2022-12-06 17:03 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\Packages
2022-11-21 15:05 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\AMD
2022-11-21 14:58 - 2022-06-20 22:56 - 000000000 ____D C:\Windows\SystemTemp
2022-11-21 13:35 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\ConnectedDevicesPlatform
2022-11-21 13:35 - 2022-06-20 22:51 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ___SD C:\Windows\system32\UNP
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\es-MX
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SystemResources
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SystemApps
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\lv-LV
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\lt-LT
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\et-EE
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\es-MX
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\Dism
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\Provisioning
2022-11-21 13:32 - 2021-10-27 11:17 - 003014656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2022-11-21 12:26 - 2022-11-10 15:54 - 000000000 ____D C:\Users\Sue\AppData\Local\Deployment
 
==================== Files in the root of some directories ========
 
2022-10-19 14:00 - 2022-10-19 14:00 - 000513168 _____ (Intuit Inc.) C:\Program Files\Common Files\GraphSeriesCol.dll
2022-11-22 09:45 - 2022-11-22 09:47 - 1091567600 _____ (Intuit, Inc.                                                ) C:\Users\Sue\AppData\Roaming\QuickBooksPremierSub2023.exe
2022-11-22 09:42 - 2022-11-22 09:42 - 071151810 _____ (Intuit, Inc.                                                ) C:\Users\Sue\AppData\Roaming\QuickBooksPro2019.exe
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-12-2022
Ran by Sue (19-12-2022 17:56:00)
Running from C:\Users\Sue\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.2364 (X64) (2022-11-10 22:45:14)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-3259427507-1055586877-3198061443-500 - Administrator - Disabled)
ccwadmin (S-1-5-21-3259427507-1055586877-3198061443-1002 - Administrator - Enabled)
DefaultAccount (S-1-5-21-3259427507-1055586877-3198061443-503 - Limited - Disabled)
Guest (S-1-5-21-3259427507-1055586877-3198061443-501 - Limited - Enabled)
Sue (S-1-5-21-3259427507-1055586877-3198061443-1001 - Administrator - Enabled) => C:\Users\Sue
WDAGUtilityAccount (S-1-5-21-3259427507-1055586877-3198061443-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
ABS PDF Install (HKLM-x32\...\{C42DD564-7DCD-4555-A7F3-15C0F46221D0}) (Version: 4.6.0 - Atlas Business Solutions, Inc.)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-1033-7760-BC15014EA700}) (Version: 22.003.20263 - Adobe)
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 2.14.04.018 - Advanced Micro Devices, Inc.)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.130 - Advanced Micro Devices, Inc.) Hidden
AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.82 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 4.13.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 6.0.0.9 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver Alpha (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\{71990c55-cd9c-43d0-9271-e2d3941f3ca8}) (Version: 2.14.04.018 - Advanced Micro Devices, Inc.) Hidden
EPSON ET-2760 Series Printer Uninstall (HKLM\...\EPSON ET-2760 Series) (Version:  - Seiko Epson Corporation)
Epson ET-2760 User’s Guide (HKLM-x32\...\UsersGuideEpson ET-2760 User’s Guide_is1) (Version: 1.0 - Epson America, Inc.)
Epson Event Manager (HKLM-x32\...\{3ACC34BD-4B01-49CA-9859-0FDD746BB36E}) (Version: 3.11.0058 - Seiko Epson Corporation)
Epson Scan 2 (HKLM-x32\...\Epson Scan 2) (Version:  - Seiko Epson Corporation)
EPSON Scan OCR Component (HKLM-x32\...\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}) (Version: 3.00.04 - SEIKO EPSON Corp.)
Epson Software Updater (HKLM-x32\...\{26A9B753-4B5D-46D8-A329-5CEF96FC22D2}) (Version: 4.6.5 - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 108.0.5359.125 - Google LLC)
HP Unified IO (HKLM\...\{5C76ED0D-0F6F-4985-8B34-F9AE7834848F}) (Version: 2.0.0.434 - HP) Hidden
HP Unified IO (HKLM-x32\...\{F1390872-2500-4408-A46C-CD16C960C661}) (Version: 2.0.0.434 - HP) Hidden
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 3.13.14.0 - Lenovo Group Ltd.)
Mesh Agent (HKLM\...\Mesh Agent) (Version: 2022-08-25 00:17:18.000-07:00 - )
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 108.0.1462.54 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 108.0.1462.54 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 22.238.1114.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{80F1AF52-7AC0-42A3-9AF0-689BFB271D1D}) (Version: 3.68.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23026 (HKLM-x32\...\{BE960C1C-7BAD-3DE6-8B1A-2616FE532845}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23026 (HKLM-x32\...\{A2563E55-3BEC-3828-8D67-E5E8B9E8B675}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.30.30704 (HKLM-x32\...\{57a73df6-4ba9-4c1d-bbbb-517289ff6c13}) (Version: 14.30.30704.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.30.30704 (HKLM\...\{6DB765A8-05AF-49A1-A71D-6F645EE3CE41}) (Version: 14.30.30704 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.30.30704 (HKLM\...\{662A0088-6FCD-45DD-9EA7-68674058AED5}) (Version: 14.30.30704 - Microsoft Corporation) Hidden
Microsoft Word 2021 - en-us (HKLM\...\Word2021Retail - en-us) (Version: 16.0.15831.20208 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.15726.20202 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.15831.20184 - Microsoft Corporation) Hidden
QuickBooks (HKLM\...\{3F034BE4-4FD8-4B4C-B9A7-BE9BF17C3CA4}) (Version: 33.0.4003.3302 - Intuit Inc.) Hidden
QuickBooks (HKLM\...\{A8FB867A-1595-43B2-8F8C-B6112C77CB8D}) (Version: 32.0.4006.3201 - Intuit Inc.) Hidden
QuickBooks Premier Edition 2022 (HKLM\...\{C32D73A9-B060-4D84-BEBB-5B595944E9E3}) (Version: 32.0.4006.3201 - Intuit Inc.)
QuickBooks Premier Edition 2023 (HKLM\...\{A9C6041A-3497-4CA5-86D1-F8759DD1BE58}) (Version: 33.0.4003.3302 - Intuit Inc.)
QuickBooks Runtime Redistributable (HKLM\...\{F2A4F809-2DE6-4D27-888B-4D2BB8DAF20E}) (Version: 1.00.0000 - Intuit Inc.)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9098.1 - Realtek Semiconductor Corp.)
ScreenConnect Client (61e735463d3bf1de) (HKLM-x32\...\{59AE0A72-DD3C-442C-AA9A-4529DA385797}) (Version: 21.13.4914.7937 - ScreenConnect Software)
TeamViewer (HKLM\...\TeamViewer) (Version: 15.35.9 - TeamViewer)
 
Packages:
=========
AMD Radeon Software -> C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.21.40031.0_x64__0a9344xs7nr4m [2022-11-10] (Advanced Micro Devices Inc.) [Startup Task]
AV1 Video Extension -> C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.1.52851.0_x64__8wekyb3d8bbwe [2022-12-08] (Microsoft Corporation)
Lenovo Commercial Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoSettingsforEnterprise_10.2210.33.0_x64__k1h2ywk1493x8 [2022-11-12] (LENOVO INC.)
MPEG-2 Video Extension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.50901.0_x64__8wekyb3d8bbwe [2022-11-12] (Microsoft Corporation)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.36.273.0_x64__dt26b99r8h8gj [2022-11-12] (Realtek Semiconductor Corp)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.15.12020.0_x64__8wekyb3d8bbwe [2022-12-08] (Microsoft Studios) [MS Ad]
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{05EC5C13-D255-4592-9CCB-98615172F0D6}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{0ADF9C35-0D5E-4B75-88DD-B64868907E17}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{123FAF7F-3FB1-4B8F-AD18-0047401D436A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{1B3210AF-E236-46D4-83EF-6421F2FF543C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBDTVIEW.OCx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{1E78DD72-771E-42BF-8B4B-363CEB18E07B}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBDTVIEW.OCx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{22664BE2-0806-4BA4-8643-DE40C9149176}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{2A9EBDB5-0600-4E8C-B910-4001BEB2DD8C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{349D777D-F7A2-4AAE-967F-A54F05A7FF3B}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBFinder.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{37A2FC00-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{37A2FC02-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58721-5F93-11D5-9F94-0008C7AA5BD9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\COMObjectFactory.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58742-5F93-11D5-9F94-0008C7AA5BD9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSrcColumns.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58743-5F93-11D5-9F94-0008C7AA5BD9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSrcColumns.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58744-5F93-11D5-9F94-0008C7AA5BD9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSrcColumns.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{4716D3CE-55DB-4D2A-818C-87D912895890}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{4844F3F7-2161-4AC4-B219-B3B4311782AA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{4E5E74B5-8EB5-4859-A335-837EED412620}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{5249684A-D7A2-4DBE-94F4-B90923A7BC64}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{547C8F00-5567-4AE3-8BB0-CC3CE2AB9070}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{57D590F1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{596801D8-2C9D-4627-9C67-195CB81B655A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{61B76A32-6422-11D5-A590-0050DABD6B8C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{61B76A34-6422-11D5-A590-0050DABD6B8C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{63B5B272-1760-4A4F-922B-57F274900044}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{70478C56-E77F-4134-B3E3-3B18EE036D71}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBDTRatios.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{7DBF8260-30AD-4D1B-876A-8032B87B809F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{828E5386-74CF-4019-B356-C857CD028A7D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{82CC31B3-53B4-4161-A4E9-6B4F1290A6C8}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{8572570D-12D9-4F2C-8BB8-EB8848178B94}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{8E590317-1329-11D1-B70B-00805F29CD16}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2023\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F2-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F3-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F4-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F5-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F6-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F7-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A14A674B-E0BE-48C1-BAB2-6ACBA33CA8CF}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\qfill.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A58C4EAB-2DB8-445E-9CAE-2AE197A5C708}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A63E42D0-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A63E42D2-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{AF5E0A13-CEAB-47CE-991D-77E82CD1BF3F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{B10BFAC3-EFF1-40D9-ADA0-BEBE037C24CA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{B66F2BF1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{b775f163-bef1-433e-aaab-c4344a51c94c}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2023\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{BCD594EA-15C3-4FD8-B92B-114BB9694537}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBCtrIPMDS2.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{CBEF1FB5-78FF-4B14-9B0F-275493FB589C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{CE18240D-F3F8-43AE-9EA0-A0DC85A95375}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBDTRatios.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D14FD6B3-6A9F-4537-9460-07B836707127}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D4A12AAF-E15E-470B-A6B6-63032186F91F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9B9C060-0954-11D3-9E07-00104BD2BE34}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSource.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6F81-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6F84-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6F87-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA1-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA3-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA5-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA6-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FB2-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\StorageClasses.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FC1-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSrcColumns.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{DCB2B478-EFF6-48F6-B718-13E98876854E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{DFD0AF10-B86C-4AF3-B609-1348D513E565}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E1A173E1-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E1A173E3-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{e64977bd-9e0b-498d-843e-1776102710aa}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2022\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E6E4DF8B-17CE-43ED-B2C7-2CE10457552D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E7D2D0F6-B754-438D-B5C9-BF848D311A0F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBDTRatios.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{EADA914E-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{EAEF733D-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{F9EF917A-E55E-4242-B205-E778395AC313}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{FAC93D42-FFC2-11d1-9DEB-0008C7A08EBA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2023\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{FB17915F-06D1-4214-A902-CC5EE05186E9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{FB359C2A-6927-4AD7-8F1B-B6472CA7CDE7}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Windows\System32\atiacm64.dll [2021-12-09] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
2009-09-16 20:44 - 2009-09-16 20:44 - 000153088 _____ (Hewlett Packard) [File not signed] C:\Windows\System32\hptcpmib.dll
2009-09-16 20:45 - 2009-09-16 20:45 - 000331264 _____ (Hewlett Packard) [File not signed] C:\Windows\System32\HpTcpMon.dll
2009-09-16 13:44 - 2009-09-16 13:44 - 000132096 _____ (Hewlett Packard) [File not signed] C:\Windows\System32\hpzjrd01.dll
2022-10-19 12:12 - 2022-10-19 12:12 - 005182464 _____ (Intuit Inc.) [File not signed] C:\Windows\SYSTEM32\InetClnt.dll
2022-08-26 03:12 - 2022-08-26 03:12 - 000944128 _____ (Intuit, Inc.) [File not signed] C:\Program Files\Common Files\Intuit\Entitlement Client\v8\Client\EntitlementClientBootstrap.dll
2009-09-16 20:45 - 2009-09-16 20:45 - 000317440 _____ (Microsoft Corporation) [File not signed] C:\Windows\System32\HPTcpMUI.dll
2022-06-20 22:01 - 2022-06-20 22:01 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\Root\Office16\AppVIsvSubsystems64.dll
2022-06-20 22:01 - 2022-06-20 22:01 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\Root\Office16\c2r64.dll
2016-09-14 16:31 - 2016-09-14 16:31 - 000500736 ____S (SEIKO EPSON CORPORATION) [File not signed] C:\Windows\System32\enppmon.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Mesh Agent => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ScreenConnect Client (61e735463d3bf1de) => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2022-11-16] (Microsoft Corporation -> Microsoft Corporation)
Handler: intu-help-qb15 - {0EEC9CBF-4C3D-45B3-9384-3C3CA3034A8B} - C:\Program Files\Intuit\QuickBooks 2022\HelpAsyncPluggableProtocol.dll [2022-10-19] (Intuit, Inc. -> Intuit, Inc.)
Handler: intu-help-qb16 - {6995859E-9BFA-4D54-9059-180AA18A20CF} - C:\Program Files\Intuit\QuickBooks 2023\HelpAsyncPluggableProtocol.dll [2022-10-08] (Intuit, Inc. -> Intuit, Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2019-12-07 03:14 - 2019-12-07 03:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Sue\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{3A41CBAC-D63D-45B0-BCDD-CE593C6EB293}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{53A494BB-440B-43BB-B888-4E5C7905CBA8}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{947D4551-4AEB-464F-B053-BC1819DB6DE9}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{E531F30C-28D8-49F5-9C51-F22377CC989E}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0EAF02BE-2725-4A97-849D-3AF2C042552E}] => (Allow) C:\Program Files\Mesh Agent\MeshAgent.exe (mc.ntg.co-8edb73 -> ) [File not signed]
FirewallRules: [{EF13EEE1-2B37-4589-9615-0DB450A3A347}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [{6926B347-FC06-4364-AB7C-3791D62D4A3E}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [TCP Query User{E70C39EE-C537-4B53-8CAD-0CD0D6D5DC62}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [UDP Query User{7273A62E-C192-4FBE-B0A7-2749E19437B7}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [{9A6F0C91-EDAC-4E0A-835D-DCF6AD8E3745}] => (Allow) C:\Users\Public\Documents\Windows\QuickBooksDownloder.exe (Solanki Piyushkumar -> )
FirewallRules: [{25640E72-63CB-41AA-AAB7-3E771EA5461B}] => (Allow) C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe (Solanki Piyushkumar -> )
FirewallRules: [{7D6F1BBE-49E3-4419-A620-F54CD2574AA4}] => (Allow) C:\Users\Public\Documents\Windows\QuickBooksDownloder.exe (Solanki Piyushkumar -> )
FirewallRules: [{82331809-63A0-49F2-9DCF-4F5D31D6030E}] => (Allow) C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe (Solanki Piyushkumar -> )
FirewallRules: [{D40BCBB0-E85A-488E-A5AE-7683650A60AB}] => (Allow) C:\Program Files\Intuit\QuickBooks 2022\CefSharp.BrowserSubprocess.exe (The CefSharp Authors) [File not signed]
FirewallRules: [{F7DD5539-4D4E-4F60-87EA-6D7503C0D851}] => (Allow) C:\Program Files\Intuit\QuickBooks 2023\CefSharp.BrowserSubprocess.exe (The CefSharp Authors) [File not signed]
FirewallRules: [{982F8AF2-2C81-4C00-AB06-E0117B5BC8EE}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\108.0.1462.46\msedgewebview2.exe => No File
FirewallRules: [{F40FD09B-2DA9-4AB3-A3D4-CE738AB00963}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C7CEA418-93BB-4E28-B30E-F2DFDFAFBA67}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{554174AB-D730-4FD4-B458-2AD13248F766}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{87A45F36-2111-4C45-80A0-D51577AAC7E1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{9524BB9E-4F42-4C9C-B737-D27F2115ED93}C:\users\sue\appdata\local\logmein rescue applet\lmir099f3001.tmp\lmi_rescue_srv.exe] => (Allow) C:\users\sue\appdata\local\logmein rescue applet\lmir099f3001.tmp\lmi_rescue_srv.exe => No File
FirewallRules: [UDP Query User{2CF7B6A6-F56A-4519-A9BC-8A88C6007279}C:\users\sue\appdata\local\logmein rescue applet\lmir099f3001.tmp\lmi_rescue_srv.exe] => (Allow) C:\users\sue\appdata\local\logmein rescue applet\lmir099f3001.tmp\lmi_rescue_srv.exe => No File
FirewallRules: [{6C683A2E-759E-4388-BBDB-33639BC666D4}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (12/19/2022 05:55:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000038c,SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5},0,REG_BINARY,0000008F9FB7E080.72).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (12/19/2022 05:55:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000038c,SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5},0,REG_BINARY,0000008F9FB7E080.72).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (12/19/2022 05:55:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000038c,SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5},0,REG_BINARY,0000008F9FB7E080.72).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (12/19/2022 05:55:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000038c,SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5},0,REG_BINARY,0000008F9FB7E080.72).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (12/19/2022 05:55:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000038c,SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5},0,REG_BINARY,0000008F9FB7E120.72).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (12/19/2022 05:55:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000038c,SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5},0,REG_BINARY,0000008F9FB7E120.72).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (12/19/2022 05:55:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000038c,SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5},0,REG_BINARY,00000278DF1203B0.72).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (12/19/2022 05:55:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000370,SYSTEM\CurrentControlSet\Services\VSS\Diag\Lovelace,0,REG_BINARY,0000008F9FB7DC10.72).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
 
System errors:
=============
Error: (12/19/2022 05:54:52 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error: 
Access is denied.
 
Error: (12/19/2022 04:34:44 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error: 
Access is denied.
 
Error: (12/19/2022 04:09:07 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
Access is denied.
 
Error: (12/19/2022 04:09:07 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Security with the following error: 
Access is denied.
 
Error: (12/19/2022 04:08:34 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Security with the following error: 
Access is denied.
 
Error: (12/19/2022 03:22:08 PM) (Source: DCOM) (EventID: 10000) (User: DESKTOP-E2I7FB8)
Description: Unable to start a DCOM Server: {628ACE20-B77A-456F-A88D-547DB6CEEDD5}. The error:
"2147942402"
Happened while starting this command:
"C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.54\notification_helper.exe" -Embedding
 
Error: (12/19/2022 03:21:48 PM) (Source: DCOM) (EventID: 10000) (User: DESKTOP-E2I7FB8)
Description: Unable to start a DCOM Server: {628ACE20-B77A-456F-A88D-547DB6CEEDD5}. The error:
"2147942402"
Happened while starting this command:
"C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.54\notification_helper.exe" -Embedding
 
Error: (12/19/2022 02:52:07 PM) (Source: DCOM) (EventID: 10001) (User: DESKTOP-E2I7FB8)
Description: Unable to start a DCOM Server: Microsoft.WindowsAlarms_11.2210.7.0_x64__8wekyb3d8bbwe!App.AppXwzrz54cs8gbnfgve6ctx6ht4bjw97w0y.mca as Unavailable/Unavailable. The error:
"2147942402"
Happened while starting this command:
"C:\Windows\system32\backgroundTaskHost.exe" -ServerName:App.AppX4325622ft6437f3xfywcfxgbedfvpn0x.mca
 
 
Windows Defender:
================
Date: 2022-12-19 16:09:07
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2022-12-18 17:40:37
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2022-12-17 17:02:55
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2022-12-16 16:43:37
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2022-12-15 16:04:27
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Full Scan

CodeIntegrity:
===============
Date: 2022-12-15 16:35:23
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2022-12-15 15:54:37
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.
 
Date: 2022-12-14 19:18:50
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume3\Program Files\Immunet\scriptid\damsicom64.dll that did not meet the Microsoft signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: LENOVO M47KT21A 06/29/2022
Motherboard: LENOVO 32E4
Processor: AMD Ryzen 7 PRO 5750GE with Radeon Graphics 
Percentage of memory in use: 40%
Total physical RAM: 15751.31 MB
Available physical RAM: 9402.95 MB
Total Virtual: 18183.31 MB
Available Virtual: 10388.86 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:474.72 GB) (Free:390.25 GB) (Model: SAMSUNG MZVLB512HBJQ-000L7) NTFS
Drive s: () (Network) (Total:699.46 GB) (Free:655.23 GB) (Model: SAMSUNG MZVLB512HBJQ-000L7) NTFS
 
\\?\Volume{4574aa8f-2317-4bcf-9c02-c733a72f1cac}\ (WinRE_DRV) (Fixed) (Total:1.95 GB) (Free:1.31 GB) NTFS
\\?\Volume{d874ff2f-a813-487a-ae1a-1cc02c2d1c6b}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: 4B8FB9AB)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

 


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
I'm pretty sure your pop ups are coming from:

(svchost.exe ->) (Solanki Piyushkumar -> ) C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe
 

 

 

As you can see it claims to be an Intuit process but is owned by somebody with a strange name.  Also it is running from the Documents folder which no legit program would do.

 

We can remove it and some dead wood with a fixlist.  The fixlist will also check that none of your system files have been tampered with so will probably take about 25 minutes to complete.  Be patient.  It will reboot your PC when done.  

 

Download the attached fixlist.txt to the same location as FRST

 
Attached File  fixlist.txt   18.17KB   98 downloads
 
Run FRST and press Fix
A fixlog.txt (located in the same folder as FRST) will be generated please post that 
 
Reboot if the fix doesn't reboot it for you
 
Run FRST again but this time make sure Addition.txt is checked and hit Scan.  Post both logs.
 
 
Did that get rid of the popups?
 
I see both TeamViewer and Mesh Agent were installed at about the same time and Logmein was installed the day before.
 
 
2022-12-14 15:41 - 2022-11-10 16:03 - 000000000 ____D C:\Program Files\Mesh Agent
2022-12-14 15:40 - 2022-11-10 15:57 - 000000000 ____D C:\Program Files\TeamViewer
 
2022-12-13 10:57 - 2022-12-14 15:40 - 000000000 ____D C:\Program Files (x86)\LogMeIn Rescue Applet

 

 
These are remote control apps that allow access from another computer which are often installed by phony support services.  Did you install them?  If not they should be uninstalled and you should change all of your passwords immediately!  If you did install them do you really need all three?  They will slow your PC down and are possible infection vectors.
 
You have also run HitmanPro.  This program is not recommended as it is very difficult to uninstall completely and sometimes leaves a system unbootable.  I thought about removing it with the fixlist but decided not to risk it.
 
 
 
 
 
 
 
 
 
 

  • 0

#3
CCWTech

CCWTech

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 191 posts

Hi, yes, I did install the remote access apps. 

I can uninstall HitMan Pro if you suggest. I don't want to make any changes however without checking with you first.

Here are all three logs requested. Thank you very much. I will monitor to see if the pop-ups are gone.

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 16-12-2022
Ran by Sue (20-12-2022 08:43:49) Run:1
Running from C:\Users\Sue\Desktop
Loaded Profiles: Sue
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
(svchost.exe ->) (Solanki Piyushkumar -> ) C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe
Unlock: C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe
C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe
CreateDummy: C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe
HKLM-x32\...\Run: [Immunet Protect Iptray] => "C:\Program Files\Immunet\7.5.8.21178\iptray.exe" (No File)
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" (No File)
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [QuickBooks for Windows] => C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe [95080 2022-09-24] (Solanki Piyushkumar -> )
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\IntuitDownloadManager.lnk [2022-11-21]
ShortcutTarget: IntuitDownloadManager.lnk -> C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe (Solanki Piyushkumar -> )
Task: {3ABBB444-6BCB-448F-9772-8232965A2E85} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION
Task: {901A3E09-DD28-4C4E-8801-C8824C51B691} - \Lenovo\ImController\TimeBasedEvents\10a8f074-22a1-4370-bb82-5ecf54dbf8e3 -> No File <==== ATTENTION
Task: {9429409C-F658-481F-82D4-73CE86F835F6} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION
Task: {A0D16F44-B686-46CA-A6A1-7F0CDC72B3EC} - \Lenovo\ImController\TimeBasedEvents\196a1ff6-3590-426e-8989-7fe35d618f54 -> No File <==== ATTENTION
Task: {AAA6E0C5-BBE9-449F-88ED-BF7E02C56709} - \Lenovo\ImController\TimeBasedEvents\46ca8c6b-2524-462b-866f-89d8b584add8 -> No File <==== ATTENTION
Task: {B8D79FD1-0201-43C5-B4D0-0F22A5EFBD98} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION
Task: C:\Windows\Tasks\EPSON ET-2760 Series Update {7804B21A-373A-468A-A7B1-6F428643C8AB}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSS3E.EXE:/EXE:{7804B21A-373A-468A-A7B1-6F428643C8AB} /F:UpdateWORKGROUP\DESKTOP-E2I7FB8$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Edge Extension: (URL Safety) - C:\Users\Sue\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\plkaklmpcfkechocmkmhjheonopjbnpo [2022-11-10]
S2 EpsonCustomerResearchParticipation; "C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe" [X]
S2 ImControllerService; %SystemRoot%\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [X]
S3 MicrosoftEdgeElevationService; "C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.46\elevation_service.exe" [X]
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{1B3210AF-E236-46D4-83EF-6421F2FF543C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBDTVIEW.OCx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{1E78DD72-771E-42BF-8B4B-363CEB18E07B}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBDTVIEW.OCx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{22664BE2-0806-4BA4-8643-DE40C9149176}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{2A9EBDB5-0600-4E8C-B910-4001BEB2DD8C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{349D777D-F7A2-4AAE-967F-A54F05A7FF3B}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBFinder.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58721-5F93-11D5-9F94-0008C7AA5BD9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\COMObjectFactory.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58742-5F93-11D5-9F94-0008C7AA5BD9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSrcColumns.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58743-5F93-11D5-9F94-0008C7AA5BD9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSrcColumns.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58744-5F93-11D5-9F94-0008C7AA5BD9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSrcColumns.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{5249684A-D7A2-4DBE-94F4-B90923A7BC64}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{61B76A32-6422-11D5-A590-0050DABD6B8C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{61B76A34-6422-11D5-A590-0050DABD6B8C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{70478C56-E77F-4134-B3E3-3B18EE036D71}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBDTRatios.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A14A674B-E0BE-48C1-BAB2-6ACBA33CA8CF}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\qfill.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A58C4EAB-2DB8-445E-9CAE-2AE197A5C708}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{BCD594EA-15C3-4FD8-B92B-114BB9694537}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBCtrIPMDS2.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{CE18240D-F3F8-43AE-9EA0-A0DC85A95375}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBDTRatios.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA1-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA3-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA5-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA6-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FC1-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSrcColumns.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E6E4DF8B-17CE-43ED-B2C7-2CE10457552D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E7D2D0F6-B754-438D-B5C9-BF848D311A0F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBDTRatios.dll => No File
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{F9EF917A-E55E-4242-B205-E778395AC313}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\BbfDepCalc.ocx => No File
FirewallRules: [{82331809-63A0-49F2-9DCF-4F5D31D6030E}] => (Allow) C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe (Solanki Piyushkumar -> )
FirewallRules: [{982F8AF2-2C81-4C00-AB06-E0117B5BC8EE}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\108.0.1462.46\msedgewebview2.exe => No File 
FirewallRules: [TCP Query User{9524BB9E-4F42-4C9C-B737-D27F2115ED93}C:\users\sue\appdata\local\logmein rescue applet\lmir099f3001.tmp\lmi_rescue_srv.exe] => (Allow) C:\users\sue\appdata\local\logmein rescue applet\lmir099f3001.tmp\lmi_rescue_srv.exe => No File
FirewallRules: [UDP Query User{2CF7B6A6-F56A-4519-A9BC-8A88C6007279}C:\users\sue\appdata\local\logmein rescue applet\lmir099f3001.tmp\lmi_rescue_srv.exe] => (Allow) C:\users\sue\appdata\local\logmein rescue applet\lmir099f3001.tmp\lmi_rescue_srv.exe => No File
CMD: DISM /Online /Cleanup-Image /RestoreHealth
CMD: SFC /scannow
CMD: findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
Reboot:
 
 
*****************
 
[16656] C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe => process closed successfully.
"C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe" => was unlocked
C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe => moved successfully
C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe => Dummy created successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Immunet Protect Iptray" => removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Update Binary" => removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Standalone Update Binary" => removed successfully
"HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\Software\Microsoft\Windows\CurrentVersion\Run\\QuickBooks for Windows" => removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\IntuitDownloadManager.lnk => moved successfully
Could not move "C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe" => Scheduled to move on reboot.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3ABBB444-6BCB-448F-9772-8232965A2E85}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3ABBB444-6BCB-448F-9772-8232965A2E85}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{901A3E09-DD28-4C4E-8801-C8824C51B691}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{901A3E09-DD28-4C4E-8801-C8824C51B691}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\10a8f074-22a1-4370-bb82-5ecf54dbf8e3" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9429409C-F658-481F-82D4-73CE86F835F6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9429409C-F658-481F-82D4-73CE86F835F6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Monitor" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A0D16F44-B686-46CA-A6A1-7F0CDC72B3EC}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0D16F44-B686-46CA-A6A1-7F0CDC72B3EC}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\196a1ff6-3590-426e-8989-7fe35d618f54" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AAA6E0C5-BBE9-449F-88ED-BF7E02C56709}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AAA6E0C5-BBE9-449F-88ED-BF7E02C56709}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\46ca8c6b-2524-462b-866f-89d8b584add8" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B8D79FD1-0201-43C5-B4D0-0F22A5EFBD98}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B8D79FD1-0201-43C5-B4D0-0F22A5EFBD98}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask" => removed successfully
C:\Windows\Tasks\EPSON ET-2760 Series Update {7804B21A-373A-468A-A7B1-6F428643C8AB}.job => moved successfully
Edge Extension: (URL Safety) - C:\Users\Sue\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\plkaklmpcfkechocmkmhjheonopjbnpo [2022-11-10] => Error: No automatic fix found for this entry.
HKLM\System\CurrentControlSet\Services\EpsonCustomerResearchParticipation => removed successfully
EpsonCustomerResearchParticipation => service removed successfully
HKLM\System\CurrentControlSet\Services\ImControllerService => removed successfully
ImControllerService => service removed successfully
HKLM\System\CurrentControlSet\Services\MicrosoftEdgeElevationService => removed successfully
MicrosoftEdgeElevationService => service removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{1B3210AF-E236-46D4-83EF-6421F2FF543C} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{1E78DD72-771E-42BF-8B4B-363CEB18E07B} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{22664BE2-0806-4BA4-8643-DE40C9149176} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{2A9EBDB5-0600-4E8C-B910-4001BEB2DD8C} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{349D777D-F7A2-4AAE-967F-A54F05A7FF3B} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58721-5F93-11D5-9F94-0008C7AA5BD9} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58742-5F93-11D5-9F94-0008C7AA5BD9} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58743-5F93-11D5-9F94-0008C7AA5BD9} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{38F58744-5F93-11D5-9F94-0008C7AA5BD9} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{5249684A-D7A2-4DBE-94F4-B90923A7BC64} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{61B76A32-6422-11D5-A590-0050DABD6B8C} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{61B76A34-6422-11D5-A590-0050DABD6B8C} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{70478C56-E77F-4134-B3E3-3B18EE036D71} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A14A674B-E0BE-48C1-BAB2-6ACBA33CA8CF} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A58C4EAB-2DB8-445E-9CAE-2AE197A5C708} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{BCD594EA-15C3-4FD8-B92B-114BB9694537} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{CE18240D-F3F8-43AE-9EA0-A0DC85A95375} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA1-A54B-11D4-A516-0050DA68678D} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA3-A54B-11D4-A516-0050DA68678D} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA5-A54B-11D4-A516-0050DA68678D} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FA6-A54B-11D4-A516-0050DA68678D} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FC1-A54B-11D4-A516-0050DA68678D} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E6E4DF8B-17CE-43ED-B2C7-2CE10457552D} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E7D2D0F6-B754-438D-B5C9-BF848D311A0F} => removed successfully
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{F9EF917A-E55E-4242-B205-E778395AC313} => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{82331809-63A0-49F2-9DCF-4F5D31D6030E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{982F8AF2-2C81-4C00-AB06-E0117B5BC8EE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{9524BB9E-4F42-4C9C-B737-D27F2115ED93}C:\users\sue\appdata\local\logmein rescue applet\lmir099f3001.tmp\lmi_rescue_srv.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2CF7B6A6-F56A-4519-A9BC-8A88C6007279}C:\users\sue\appdata\local\logmein rescue applet\lmir099f3001.tmp\lmi_rescue_srv.exe" => removed successfully
 
========= DISM /Online /Cleanup-Image /RestoreHealth =========
 
 
Deployment Image Servicing and Management tool
Version: 10.0.19041.844
 
Image Version: 10.0.19045.2364
 
 
[==                         3.8%                           ] 
 
[==                         4.8%                           ] 
 
[===                        5.7%                           ] 
 
[===                        6.7%                           ] 
 
[====                       7.7%                           ] 
 
[=====                      8.7%                           ] 
 
[=====                      9.7%                           ] 
 
[======                     10.6%                          ] 
 
[======                     11.6%                          ] 
 
[=======                    12.6%                          ] 
 
[=======                    13.6%                          ] 
 
[========                   14.6%                          ] 
 
[=========                  15.5%                          ] 
 
[=========                  16.5%                          ] 
 
[==========                 17.5%                          ] 
 
[==========                 18.5%                          ] 
 
[===========                19.5%                          ] 
 
[===========                20.5%                          ] 
 
[============               21.1%                          ] 
 
[============               22.0%                          ] 
 
[============               22.3%                          ] 
 
[=============              23.2%                          ] 
 
[==============             24.2%                          ] 
 
[==============             25.2%                          ] 
 
[===============            26.2%                          ] 
 
[===============            27.2%                          ] 
 
[================           28.2%                          ] 
 
[================           29.1%                          ] 
 
[=================          30.1%                          ] 
 
[==================         31.1%                          ] 
 
[==================         32.1%                          ] 
 
[===================        33.1%                          ] 
 
[===================        34.0%                          ] 
 
[====================       34.8%                          ] 
 
[====================       35.2%                          ] 
 
[====================       35.8%                          ] 
 
[=====================      36.8%                          ] 
 
[=====================      37.7%                          ] 
 
[======================     38.6%                          ] 
 
[======================     39.3%                          ] 
 
[======================     39.5%                          ] 
 
[=======================    40.5%                          ] 
 
[========================   41.5%                          ] 
 
[========================   42.2%                          ] 
 
[========================   43.1%                          ] 
 
[=========================  44.1%                          ] 
 
[========================== 45.1%                          ] 
 
[========================== 46.0%                          ] 
 
[===========================47.0%                          ] 
 
[===========================48.0%                          ] 
 
[===========================49.0%                          ] 
 
[===========================50.0%                          ] 
 
[===========================50.9%                          ] 
 
[===========================51.9%                          ] 
 
[===========================52.0%                          ] 
 
[===========================52.3%                          ] 
 
[===========================52.4%                          ] 
 
[===========================52.5%                          ] 
 
[===========================52.5%                          ] 
 
[===========================52.7%                          ] 
 
[===========================52.8%                          ] 
 
[===========================53.0%                          ] 
 
[===========================53.1%                          ] 
 
[===========================53.3%                          ] 
 
[===========================53.5%                          ] 
 
[===========================53.7%                          ] 
 
[===========================53.7%                          ] 
 
[===========================53.8%                          ] 
 
[===========================54.0%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.3%                          ] 
 
[===========================54.4%                          ] 
 
[===========================54.5%                          ] 
 
[===========================54.6%                          ] 
 
[===========================54.7%                          ] 
 
[===========================54.8%                          ] 
 
[===========================54.9%                          ] 
 
[===========================55.0%                          ] 
 
[===========================55.2%                          ] 
 
[===========================55.3%                          ] 
 
[===========================55.7%                          ] 
 
[===========================55.9%                          ] 
 
[===========================56.1%                          ] 
 
[===========================56.2%                          ] 
 
[===========================56.5%                          ] 
 
[===========================56.6%                          ] 
 
[===========================57.2%=                         ] 
 
[===========================58.2%=                         ] 
 
[===========================59.2%==                        ] 
 
[===========================60.2%==                        ] 
 
[===========================62.3%====                      ] 
 
[===========================84.9%=================         ] 
 
[==========================100.0%==========================] 
The restore operation completed successfully.
The operation completed successfully.
 
========= End of CMD: =========
 
 
========= SFC /scannow =========
 
 
 
Beginning system scan.  This process will take some time.
 
 
 
Beginning verification phase of system scan.
 
 
Verification 0% complete.
Verification 1% complete.
Verification 1% complete.
Verification 2% complete.
Verification 3% complete.
Verification 3% complete.
Verification 4% complete.
Verification 5% complete.
Verification 5% complete.
Verification 6% complete.
Verification 7% complete.
Verification 7% complete.
Verification 8% complete.
Verification 9% complete.
Verification 9% complete.
Verification 10% complete.
Verification 11% complete.
Verification 11% complete.
Verification 12% complete.
Verification 13% complete.
Verification 13% complete.
Verification 14% complete.
Verification 14% complete.
Verification 15% complete.
Verification 16% complete.
Verification 16% complete.
Verification 17% complete.
Verification 18% complete.
Verification 18% complete.
Verification 19% complete.
Verification 20% complete.
Verification 20% complete.
Verification 21% complete.
Verification 22% complete.
Verification 22% complete.
Verification 23% complete.
Verification 24% complete.
Verification 24% complete.
Verification 25% complete.
Verification 26% complete.
Verification 26% complete.
Verification 27% complete.
Verification 27% complete.
Verification 28% complete.
Verification 29% complete.
Verification 29% complete.
Verification 30% complete.
Verification 31% complete.
Verification 31% complete.
Verification 32% complete.
Verification 33% complete.
Verification 33% complete.
Verification 34% complete.
Verification 35% complete.
Verification 35% complete.
Verification 36% complete.
Verification 37% complete.
Verification 37% complete.
Verification 38% complete.
Verification 39% complete.
Verification 39% complete.
Verification 40% complete.
Verification 40% complete.
Verification 41% complete.
Verification 42% complete.
Verification 42% complete.
Verification 43% complete.
Verification 44% complete.
Verification 44% complete.
Verification 45% complete.
Verification 46% complete.
Verification 46% complete.
Verification 47% complete.
Verification 48% complete.
Verification 48% complete.
Verification 49% complete.
Verification 50% complete.
Verification 50% complete.
Verification 51% complete.
Verification 52% complete.
Verification 52% complete.
Verification 53% complete.
Verification 53% complete.
Verification 54% complete.
Verification 55% complete.
Verification 55% complete.
Verification 56% complete.
Verification 57% complete.
Verification 57% complete.
Verification 58% complete.
Verification 59% complete.
Verification 59% complete.
Verification 60% complete.
Verification 61% complete.
Verification 61% complete.
Verification 62% complete.
Verification 63% complete.
Verification 63% complete.
Verification 64% complete.
Verification 65% complete.
Verification 65% complete.
Verification 66% complete.
Verification 67% complete.
Verification 67% complete.
Verification 68% complete.
Verification 68% complete.
Verification 69% complete.
Verification 70% complete.
Verification 70% complete.
Verification 71% complete.
Verification 72% complete.
Verification 72% complete.
Verification 73% complete.
Verification 74% complete.
Verification 74% complete.
Verification 75% complete.
Verification 76% complete.
Verification 76% complete.
Verification 77% complete.
Verification 78% complete.
Verification 78% complete.
Verification 79% complete.
Verification 80% complete.
Verification 80% complete.
Verification 81% complete.
Verification 81% complete.
Verification 82% complete.
Verification 83% complete.
Verification 83% complete.
Verification 84% complete.
Verification 85% complete.
Verification 85% complete.
Verification 86% complete.
Verification 87% complete.
Verification 87% complete.
Verification 88% complete.
Verification 89% complete.
Verification 89% complete.
Verification 90% complete.
Verification 91% complete.
Verification 91% complete.
Verification 92% complete.
Verification 93% complete.
Verification 93% complete.
Verification 94% complete.
Verification 94% complete.
Verification 95% complete.
Verification 96% complete.
Verification 96% complete.
Verification 97% complete.
Verification 98% complete.
Verification 98% complete.
Verification 99% complete.
Verification 100% complete.
 
 
Windows Resource Protection found corrupt files and successfully repaired them.
 
For online repairs, details are included in the CBS log file located at
 
windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline
 
repairs, details are included in the log file provided by the /OFFLOGFILE flag.
 
 
========= End of CMD: =========
 
 
========= findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log =========
 
2022-12-19 21:40:33, Info                  CSI    00000006 [SR] Verifying 1 components
2022-12-19 21:40:33, Info                  CSI    00000007 [SR] Beginning Verify and Repair transaction
2022-12-19 21:40:33, Info                  CSI    00000008 [SR] Verify complete
2022-12-19 21:40:33, Info                  CSI    00000009 [SR] Verifying 1 components
2022-12-19 21:40:33, Info                  CSI    0000000a [SR] Beginning Verify and Repair transaction
2022-12-19 21:40:33, Info                  CSI    0000000b [SR] Verify complete
2022-12-19 21:40:33, Info                  CSI    0000000c [SR] Verifying 1 components
2022-12-19 21:40:33, Info                  CSI    0000000d [SR] Beginning Verify and Repair transaction
2022-12-19 21:40:33, Info                  CSI    0000000e [SR] Verify complete
2022-12-19 21:40:33, Info                  CSI    0000000f [SR] Verifying 1 components
2022-12-19 21:40:33, Info                  CSI    00000010 [SR] Beginning Verify and Repair transaction
2022-12-19 21:40:33, Info                  CSI    00000011 [SR] Verify complete
2022-12-19 21:40:33, Info                  CSI    00000012 [SR] Verifying 1 components
2022-12-19 21:40:33, Info                  CSI    00000013 [SR] Beginning Verify and Repair transaction
2022-12-19 21:40:33, Info                  CSI    00000014 [SR] Verify complete
2022-12-19 21:40:33, Info                  CSI    00000015 [SR] Verifying 1 components
2022-12-19 21:40:33, Info                  CSI    00000016 [SR] Beginning Verify and Repair transaction
2022-12-19 21:40:33, Info                  CSI    00000017 [SR] Verify complete
2022-12-20 08:45:11, Info                  CSI    00000011 [SR] Verifying 100 components
2022-12-20 08:45:11, Info                  CSI    00000012 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:11, Info                  CSI    00000013 [SR] Verify complete
2022-12-20 08:45:11, Info                  CSI    00000014 [SR] Verifying 100 components
2022-12-20 08:45:11, Info                  CSI    00000015 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:11, Info                  CSI    00000016 [SR] Verify complete
2022-12-20 08:45:11, Info                  CSI    00000017 [SR] Verifying 100 components
2022-12-20 08:45:11, Info                  CSI    00000018 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:12, Info                  CSI    00000019 [SR] Verify complete
2022-12-20 08:45:12, Info                  CSI    0000001a [SR] Verifying 100 components
2022-12-20 08:45:12, Info                  CSI    0000001b [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:12, Info                  CSI    0000001c [SR] Verify complete
2022-12-20 08:45:12, Info                  CSI    0000001d [SR] Verifying 100 components
2022-12-20 08:45:12, Info                  CSI    0000001e [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:12, Info                  CSI    0000001f [SR] Verify complete
2022-12-20 08:45:12, Info                  CSI    00000020 [SR] Verifying 100 components
2022-12-20 08:45:12, Info                  CSI    00000021 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:13, Info                  CSI    00000022 [SR] Verify complete
2022-12-20 08:45:13, Info                  CSI    00000023 [SR] Verifying 100 components
2022-12-20 08:45:13, Info                  CSI    00000024 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:14, Info                  CSI    00000025 [SR] Verify complete
2022-12-20 08:45:14, Info                  CSI    00000026 [SR] Verifying 100 components
2022-12-20 08:45:14, Info                  CSI    00000027 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:15, Info                  CSI    00000028 [SR] Verify complete
2022-12-20 08:45:15, Info                  CSI    00000029 [SR] Verifying 100 components
2022-12-20 08:45:15, Info                  CSI    0000002a [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:19, Info                  CSI    0000002b [SR] Verify complete
2022-12-20 08:45:19, Info                  CSI    0000002c [SR] Verifying 100 components
2022-12-20 08:45:19, Info                  CSI    0000002d [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:19, Info                  CSI    0000002e [SR] Verify complete
2022-12-20 08:45:19, Info                  CSI    0000002f [SR] Verifying 100 components
2022-12-20 08:45:19, Info                  CSI    00000030 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:19, Info                  CSI    00000031 [SR] Verify complete
2022-12-20 08:45:19, Info                  CSI    00000032 [SR] Verifying 100 components
2022-12-20 08:45:19, Info                  CSI    00000033 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:20, Info                  CSI    00000034 [SR] Verify complete
2022-12-20 08:45:20, Info                  CSI    00000035 [SR] Verifying 100 components
2022-12-20 08:45:20, Info                  CSI    00000036 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:20, Info                  CSI    00000037 [SR] Verify complete
2022-12-20 08:45:20, Info                  CSI    00000038 [SR] Verifying 100 components
2022-12-20 08:45:20, Info                  CSI    00000039 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:20, Info                  CSI    0000003a [SR] Verify complete
2022-12-20 08:45:20, Info                  CSI    0000003b [SR] Verifying 100 components
2022-12-20 08:45:20, Info                  CSI    0000003c [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:20, Info                  CSI    0000003d [SR] Verify complete
2022-12-20 08:45:21, Info                  CSI    0000003e [SR] Verifying 100 components
2022-12-20 08:45:21, Info                  CSI    0000003f [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:21, Info                  CSI    00000040 [SR] Verify complete
2022-12-20 08:45:21, Info                  CSI    00000041 [SR] Verifying 100 components
2022-12-20 08:45:21, Info                  CSI    00000042 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:21, Info                  CSI    00000043 [SR] Verify complete
2022-12-20 08:45:21, Info                  CSI    00000044 [SR] Verifying 100 components
2022-12-20 08:45:21, Info                  CSI    00000045 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:21, Info                  CSI    00000046 [SR] Verify complete
2022-12-20 08:45:21, Info                  CSI    00000047 [SR] Verifying 100 components
2022-12-20 08:45:21, Info                  CSI    00000048 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:22, Info                  CSI    00000049 [SR] Verify complete
2022-12-20 08:45:22, Info                  CSI    0000004a [SR] Verifying 100 components
2022-12-20 08:45:22, Info                  CSI    0000004b [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:22, Info                  CSI    0000004c [SR] Verify complete
2022-12-20 08:45:22, Info                  CSI    0000004d [SR] Verifying 100 components
2022-12-20 08:45:22, Info                  CSI    0000004e [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:22, Info                  CSI    0000004f [SR] Verify complete
2022-12-20 08:45:22, Info                  CSI    00000050 [SR] Verifying 100 components
2022-12-20 08:45:22, Info                  CSI    00000051 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:23, Info                  CSI    00000052 [SR] Verify complete
2022-12-20 08:45:23, Info                  CSI    00000053 [SR] Verifying 100 components
2022-12-20 08:45:23, Info                  CSI    00000054 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:23, Info                  CSI    00000055 [SR] Verify complete
2022-12-20 08:45:23, Info                  CSI    00000056 [SR] Verifying 100 components
2022-12-20 08:45:23, Info                  CSI    00000057 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:23, Info                  CSI    00000058 [SR] Verify complete
2022-12-20 08:45:24, Info                  CSI    00000059 [SR] Verifying 100 components
2022-12-20 08:45:24, Info                  CSI    0000005a [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:24, Info                  CSI    0000005b [SR] Verify complete
2022-12-20 08:45:24, Info                  CSI    0000005c [SR] Verifying 100 components
2022-12-20 08:45:24, Info                  CSI    0000005d [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:24, Info                  CSI    0000005e [SR] Verify complete
2022-12-20 08:45:24, Info                  CSI    0000005f [SR] Verifying 100 components
2022-12-20 08:45:24, Info                  CSI    00000060 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:24, Info                  CSI    00000061 [SR] Verify complete
2022-12-20 08:45:24, Info                  CSI    00000062 [SR] Verifying 100 components
2022-12-20 08:45:24, Info                  CSI    00000063 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:25, Info                  CSI    00000064 [SR] Verify complete
2022-12-20 08:45:25, Info                  CSI    00000065 [SR] Verifying 100 components
2022-12-20 08:45:25, Info                  CSI    00000066 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:25, Info                  CSI    00000067 [SR] Verify complete
2022-12-20 08:45:25, Info                  CSI    00000068 [SR] Verifying 100 components
2022-12-20 08:45:25, Info                  CSI    00000069 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:25, Info                  CSI    0000006a [SR] Verify complete
2022-12-20 08:45:25, Info                  CSI    0000006b [SR] Verifying 100 components
2022-12-20 08:45:25, Info                  CSI    0000006c [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:25, Info                  CSI    0000006d [SR] Verify complete
2022-12-20 08:45:25, Info                  CSI    0000006e [SR] Verifying 100 components
2022-12-20 08:45:25, Info                  CSI    0000006f [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:26, Info                  CSI    00000070 [SR] Verify complete
2022-12-20 08:45:26, Info                  CSI    00000071 [SR] Verifying 100 components
2022-12-20 08:45:26, Info                  CSI    00000072 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:26, Info                  CSI    00000073 [SR] Verify complete
2022-12-20 08:45:26, Info                  CSI    00000074 [SR] Verifying 100 components
2022-12-20 08:45:26, Info                  CSI    00000075 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:26, Info                  CSI    00000076 [SR] Verify complete
2022-12-20 08:45:26, Info                  CSI    00000077 [SR] Verifying 100 components
2022-12-20 08:45:26, Info                  CSI    00000078 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:26, Info                  CSI    00000079 [SR] Verify complete
2022-12-20 08:45:26, Info                  CSI    0000007a [SR] Verifying 100 components
2022-12-20 08:45:26, Info                  CSI    0000007b [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:27, Info                  CSI    0000007c [SR] Verify complete
2022-12-20 08:45:27, Info                  CSI    0000007d [SR] Verifying 100 components
2022-12-20 08:45:27, Info                  CSI    0000007e [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:27, Info                  CSI    0000007f [SR] Verify complete
2022-12-20 08:45:27, Info                  CSI    00000080 [SR] Verifying 100 components
2022-12-20 08:45:27, Info                  CSI    00000081 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:27, Info                  CSI    00000082 [SR] Verify complete
2022-12-20 08:45:27, Info                  CSI    00000083 [SR] Verifying 100 components
2022-12-20 08:45:27, Info                  CSI    00000084 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:28, Info                  CSI    00000088 [SR] Verify complete
2022-12-20 08:45:28, Info                  CSI    00000089 [SR] Verifying 100 components
2022-12-20 08:45:28, Info                  CSI    0000008a [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:28, Info                  CSI    0000008b [SR] Verify complete
2022-12-20 08:45:28, Info                  CSI    0000008c [SR] Verifying 100 components
2022-12-20 08:45:28, Info                  CSI    0000008d [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:29, Info                  CSI    0000008e [SR] Verify complete
2022-12-20 08:45:29, Info                  CSI    0000008f [SR] Verifying 100 components
2022-12-20 08:45:29, Info                  CSI    00000090 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:29, Info                  CSI    00000091 [SR] Verify complete
2022-12-20 08:45:29, Info                  CSI    00000092 [SR] Verifying 100 components
2022-12-20 08:45:29, Info                  CSI    00000093 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:29, Info                  CSI    00000094 [SR] Verify complete
2022-12-20 08:45:30, Info                  CSI    00000095 [SR] Verifying 100 components
2022-12-20 08:45:30, Info                  CSI    00000096 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:30, Info                  CSI    00000097 [SR] Verify complete
2022-12-20 08:45:30, Info                  CSI    00000098 [SR] Verifying 100 components
2022-12-20 08:45:30, Info                  CSI    00000099 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:30, Info                  CSI    0000009a [SR] Verify complete
2022-12-20 08:45:30, Info                  CSI    0000009b [SR] Verifying 100 components
2022-12-20 08:45:30, Info                  CSI    0000009c [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:30, Info                  CSI    0000009d [SR] Verify complete
2022-12-20 08:45:30, Info                  CSI    0000009e [SR] Verifying 100 components
2022-12-20 08:45:30, Info                  CSI    0000009f [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:30, Info                  CSI    000000a0 [SR] Verify complete
2022-12-20 08:45:31, Info                  CSI    000000a1 [SR] Verifying 100 components
2022-12-20 08:45:31, Info                  CSI    000000a2 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:31, Info                  CSI    000000a3 [SR] Verify complete
2022-12-20 08:45:31, Info                  CSI    000000a4 [SR] Verifying 100 components
2022-12-20 08:45:31, Info                  CSI    000000a5 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:31, Info                  CSI    000000a6 [SR] Verify complete
2022-12-20 08:45:32, Info                  CSI    000000a7 [SR] Verifying 100 components
2022-12-20 08:45:32, Info                  CSI    000000a8 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:32, Info                  CSI    000000a9 [SR] Verify complete
2022-12-20 08:45:32, Info                  CSI    000000aa [SR] Verifying 100 components
2022-12-20 08:45:32, Info                  CSI    000000ab [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:32, Info                  CSI    000000ac [SR] Verify complete
2022-12-20 08:45:32, Info                  CSI    000000ad [SR] Verifying 100 components
2022-12-20 08:45:32, Info                  CSI    000000ae [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:32, Info                  CSI    000000af [SR] Verify complete
2022-12-20 08:45:32, Info                  CSI    000000b0 [SR] Verifying 100 components
2022-12-20 08:45:32, Info                  CSI    000000b1 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:33, Info                  CSI    000000b2 [SR] Verify complete
2022-12-20 08:45:33, Info                  CSI    000000b3 [SR] Verifying 100 components
2022-12-20 08:45:33, Info                  CSI    000000b4 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:33, Info                  CSI    000000b5 [SR] Verify complete
2022-12-20 08:45:33, Info                  CSI    000000b6 [SR] Verifying 100 components
2022-12-20 08:45:33, Info                  CSI    000000b7 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:33, Info                  CSI    000000b8 [SR] Verify complete
2022-12-20 08:45:33, Info                  CSI    000000b9 [SR] Verifying 100 components
2022-12-20 08:45:33, Info                  CSI    000000ba [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:34, Info                  CSI    000000bb [SR] Verify complete
2022-12-20 08:45:34, Info                  CSI    000000bc [SR] Verifying 100 components
2022-12-20 08:45:34, Info                  CSI    000000bd [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:34, Info                  CSI    000000be [SR] Verify complete
2022-12-20 08:45:34, Info                  CSI    000000bf [SR] Verifying 100 components
2022-12-20 08:45:34, Info                  CSI    000000c0 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:34, Info                  CSI    000000c1 [SR] Verify complete
2022-12-20 08:45:34, Info                  CSI    000000c2 [SR] Verifying 100 components
2022-12-20 08:45:34, Info                  CSI    000000c3 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:35, Info                  CSI    000000c4 [SR] Verify complete
2022-12-20 08:45:35, Info                  CSI    000000c5 [SR] Verifying 100 components
2022-12-20 08:45:35, Info                  CSI    000000c6 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:35, Info                  CSI    000000c7 [SR] Verify complete
2022-12-20 08:45:35, Info                  CSI    000000c8 [SR] Verifying 100 components
2022-12-20 08:45:35, Info                  CSI    000000c9 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:35, Info                  CSI    000000ca [SR] Verify complete
2022-12-20 08:45:35, Info                  CSI    000000cb [SR] Verifying 100 components
2022-12-20 08:45:35, Info                  CSI    000000cc [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:36, Info                  CSI    000000cd [SR] Verify complete
2022-12-20 08:45:36, Info                  CSI    000000ce [SR] Verifying 100 components
2022-12-20 08:45:36, Info                  CSI    000000cf [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:36, Info                  CSI    000000d0 [SR] Verify complete
2022-12-20 08:45:36, Info                  CSI    000000d1 [SR] Verifying 100 components
2022-12-20 08:45:36, Info                  CSI    000000d2 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:36, Info                  CSI    000000d3 [SR] Verify complete
2022-12-20 08:45:36, Info                  CSI    000000d4 [SR] Verifying 100 components
2022-12-20 08:45:36, Info                  CSI    000000d5 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:37, Info                  CSI    000000d6 [SR] Verify complete
2022-12-20 08:45:37, Info                  CSI    000000d7 [SR] Verifying 100 components
2022-12-20 08:45:37, Info                  CSI    000000d8 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:37, Info                  CSI    000000d9 [SR] Verify complete
2022-12-20 08:45:37, Info                  CSI    000000da [SR] Verifying 100 components
2022-12-20 08:45:37, Info                  CSI    000000db [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:37, Info                  CSI    000000dc [SR] Verify complete
2022-12-20 08:45:37, Info                  CSI    000000dd [SR] Verifying 100 components
2022-12-20 08:45:37, Info                  CSI    000000de [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:37, Info                  CSI    000000df [SR] Verify complete
2022-12-20 08:45:38, Info                  CSI    000000e0 [SR] Verifying 100 components
2022-12-20 08:45:38, Info                  CSI    000000e1 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:38, Info                  CSI    000000e2 [SR] Verify complete
2022-12-20 08:45:38, Info                  CSI    000000e3 [SR] Verifying 100 components
2022-12-20 08:45:38, Info                  CSI    000000e4 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:38, Info                  CSI    000000e5 [SR] Verify complete
2022-12-20 08:45:38, Info                  CSI    000000e6 [SR] Verifying 100 components
2022-12-20 08:45:38, Info                  CSI    000000e7 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:38, Info                  CSI    000000e8 [SR] Verify complete
2022-12-20 08:45:38, Info                  CSI    000000e9 [SR] Verifying 100 components
2022-12-20 08:45:38, Info                  CSI    000000ea [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:39, Info                  CSI    000000eb [SR] Verify complete
2022-12-20 08:45:39, Info                  CSI    000000ec [SR] Verifying 100 components
2022-12-20 08:45:39, Info                  CSI    000000ed [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:39, Info                  CSI    000000ee [SR] Verify complete
2022-12-20 08:45:39, Info                  CSI    000000ef [SR] Verifying 100 components
2022-12-20 08:45:39, Info                  CSI    000000f0 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:39, Info                  CSI    000000f1 [SR] Verify complete
2022-12-20 08:45:39, Info                  CSI    000000f2 [SR] Verifying 100 components
2022-12-20 08:45:39, Info                  CSI    000000f3 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:39, Info                  CSI    000000f4 [SR] Verify complete
2022-12-20 08:45:39, Info                  CSI    000000f5 [SR] Verifying 100 components
2022-12-20 08:45:39, Info                  CSI    000000f6 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:40, Info                  CSI    000000f7 [SR] Verify complete
2022-12-20 08:45:40, Info                  CSI    000000f8 [SR] Verifying 100 components
2022-12-20 08:45:40, Info                  CSI    000000f9 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:40, Info                  CSI    000000fa [SR] Verify complete
2022-12-20 08:45:40, Info                  CSI    000000fb [SR] Verifying 100 components
2022-12-20 08:45:40, Info                  CSI    000000fc [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:40, Info                  CSI    000000fd [SR] Verify complete
2022-12-20 08:45:40, Info                  CSI    000000fe [SR] Verifying 100 components
2022-12-20 08:45:40, Info                  CSI    000000ff [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:41, Info                  CSI    00000100 [SR] Verify complete
2022-12-20 08:45:41, Info                  CSI    00000101 [SR] Verifying 100 components
2022-12-20 08:45:41, Info                  CSI    00000102 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:41, Info                  CSI    00000106 [SR] Verify complete
2022-12-20 08:45:41, Info                  CSI    00000107 [SR] Verifying 100 components
2022-12-20 08:45:41, Info                  CSI    00000108 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:42, Info                  CSI    00000109 [SR] Verify complete
2022-12-20 08:45:42, Info                  CSI    0000010a [SR] Verifying 100 components
2022-12-20 08:45:42, Info                  CSI    0000010b [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:42, Info                  CSI    0000010c [SR] Verify complete
2022-12-20 08:45:42, Info                  CSI    0000010d [SR] Verifying 100 components
2022-12-20 08:45:42, Info                  CSI    0000010e [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:42, Info                  CSI    0000010f [SR] Verify complete
2022-12-20 08:45:42, Info                  CSI    00000110 [SR] Verifying 100 components
2022-12-20 08:45:42, Info                  CSI    00000111 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:43, Info                  CSI    00000112 [SR] Verify complete
2022-12-20 08:45:43, Info                  CSI    00000113 [SR] Verifying 100 components
2022-12-20 08:45:43, Info                  CSI    00000114 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:43, Info                  CSI    00000115 [SR] Verify complete
2022-12-20 08:45:43, Info                  CSI    00000116 [SR] Verifying 100 components
2022-12-20 08:45:43, Info                  CSI    00000117 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:43, Info                  CSI    00000118 [SR] Verify complete
2022-12-20 08:45:43, Info                  CSI    00000119 [SR] Verifying 100 components
2022-12-20 08:45:43, Info                  CSI    0000011a [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:44, Info                  CSI    0000011b [SR] Verify complete
2022-12-20 08:45:44, Info                  CSI    0000011c [SR] Verifying 100 components
2022-12-20 08:45:44, Info                  CSI    0000011d [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:44, Info                  CSI    0000011e [SR] Verify complete
2022-12-20 08:45:44, Info                  CSI    0000011f [SR] Verifying 100 components
2022-12-20 08:45:44, Info                  CSI    00000120 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:44, Info                  CSI    00000121 [SR] Verify complete
2022-12-20 08:45:45, Info                  CSI    00000122 [SR] Verifying 100 components
2022-12-20 08:45:45, Info                  CSI    00000123 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:45, Info                  CSI    00000124 [SR] Verify complete
2022-12-20 08:45:45, Info                  CSI    00000125 [SR] Verifying 100 components
2022-12-20 08:45:45, Info                  CSI    00000126 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:45, Info                  CSI    00000127 [SR] Verify complete
2022-12-20 08:45:45, Info                  CSI    00000128 [SR] Verifying 100 components
2022-12-20 08:45:45, Info                  CSI    00000129 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:45, Info                  CSI    0000012a [SR] Verify complete
2022-12-20 08:45:45, Info                  CSI    0000012b [SR] Verifying 100 components
2022-12-20 08:45:45, Info                  CSI    0000012c [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:46, Info                  CSI    0000012d [SR] Verify complete
2022-12-20 08:45:46, Info                  CSI    0000012e [SR] Verifying 100 components
2022-12-20 08:45:46, Info                  CSI    0000012f [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:46, Info                  CSI    00000130 [SR] Verify complete
2022-12-20 08:45:46, Info                  CSI    00000131 [SR] Verifying 100 components
2022-12-20 08:45:46, Info                  CSI    00000132 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:46, Info                  CSI    00000133 [SR] Verify complete
2022-12-20 08:45:46, Info                  CSI    00000134 [SR] Verifying 100 components
2022-12-20 08:45:46, Info                  CSI    00000135 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:47, Info                  CSI    00000136 [SR] Verify complete
2022-12-20 08:45:47, Info                  CSI    00000137 [SR] Verifying 100 components
2022-12-20 08:45:47, Info                  CSI    00000138 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:47, Info                  CSI    00000139 [SR] Verify complete
2022-12-20 08:45:47, Info                  CSI    0000013a [SR] Verifying 100 components
2022-12-20 08:45:47, Info                  CSI    0000013b [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:47, Info                  CSI    0000013c [SR] Verify complete
2022-12-20 08:45:47, Info                  CSI    0000013d [SR] Verifying 100 components
2022-12-20 08:45:47, Info                  CSI    0000013e [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:47, Info                  CSI    0000013f [SR] Verify complete
2022-12-20 08:45:47, Info                  CSI    00000140 [SR] Verifying 100 components
2022-12-20 08:45:47, Info                  CSI    00000141 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:48, Info                  CSI    00000142 [SR] Verify complete
2022-12-20 08:45:48, Info                  CSI    00000143 [SR] Verifying 100 components
2022-12-20 08:45:48, Info                  CSI    00000144 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:48, Info                  CSI    00000145 [SR] Verify complete
2022-12-20 08:45:48, Info                  CSI    00000146 [SR] Verifying 100 components
2022-12-20 08:45:48, Info                  CSI    00000147 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:48, Info                  CSI    00000148 [SR] Verify complete
2022-12-20 08:45:48, Info                  CSI    00000149 [SR] Verifying 100 components
2022-12-20 08:45:48, Info                  CSI    0000014a [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:49, Info                  CSI    0000014b [SR] Verify complete
2022-12-20 08:45:49, Info                  CSI    0000014c [SR] Verifying 100 components
2022-12-20 08:45:49, Info                  CSI    0000014d [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:49, Info                  CSI    0000014e [SR] Verify complete
2022-12-20 08:45:49, Info                  CSI    0000014f [SR] Verifying 100 components
2022-12-20 08:45:49, Info                  CSI    00000150 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:49, Info                  CSI    00000151 [SR] Verify complete
2022-12-20 08:45:49, Info                  CSI    00000152 [SR] Verifying 100 components
2022-12-20 08:45:49, Info                  CSI    00000153 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:49, Info                  CSI    00000154 [SR] Verify complete
2022-12-20 08:45:49, Info                  CSI    00000155 [SR] Verifying 100 components
2022-12-20 08:45:49, Info                  CSI    00000156 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:50, Info                  CSI    00000157 [SR] Verify complete
2022-12-20 08:45:50, Info                  CSI    00000158 [SR] Verifying 100 components
2022-12-20 08:45:50, Info                  CSI    00000159 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:50, Info                  CSI    0000015a [SR] Verify complete
2022-12-20 08:45:50, Info                  CSI    0000015b [SR] Verifying 100 components
2022-12-20 08:45:50, Info                  CSI    0000015c [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:50, Info                  CSI    0000015d [SR] Verify complete
2022-12-20 08:45:50, Info                  CSI    0000015e [SR] Verifying 100 components
2022-12-20 08:45:50, Info                  CSI    0000015f [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:51, Info                  CSI    00000160 [SR] Verify complete
2022-12-20 08:45:51, Info                  CSI    00000161 [SR] Verifying 100 components
2022-12-20 08:45:51, Info                  CSI    00000162 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:51, Info                  CSI    00000163 [SR] Verify complete
2022-12-20 08:45:51, Info                  CSI    00000164 [SR] Verifying 100 components
2022-12-20 08:45:51, Info                  CSI    00000165 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:51, Info                  CSI    00000166 [SR] Verify complete
2022-12-20 08:45:51, Info                  CSI    00000167 [SR] Verifying 100 components
2022-12-20 08:45:51, Info                  CSI    00000168 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:51, Info                  CSI    00000169 [SR] Verify complete
2022-12-20 08:45:52, Info                  CSI    0000016a [SR] Verifying 100 components
2022-12-20 08:45:52, Info                  CSI    0000016b [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:52, Info                  CSI    0000016c [SR] Verify complete
2022-12-20 08:45:52, Info                  CSI    0000016d [SR] Verifying 100 components
2022-12-20 08:45:52, Info                  CSI    0000016e [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:52, Info                  CSI    0000016f [SR] Verify complete
2022-12-20 08:45:52, Info                  CSI    00000170 [SR] Verifying 100 components
2022-12-20 08:45:52, Info                  CSI    00000171 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:52, Info                  CSI    00000172 [SR] Verify complete
2022-12-20 08:45:52, Info                  CSI    00000173 [SR] Verifying 100 components
2022-12-20 08:45:52, Info                  CSI    00000174 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:53, Info                  CSI    00000175 [SR] Verify complete
2022-12-20 08:45:53, Info                  CSI    00000176 [SR] Verifying 100 components
2022-12-20 08:45:53, Info                  CSI    00000177 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:53, Info                  CSI    00000178 [SR] Verify complete
2022-12-20 08:45:53, Info                  CSI    00000179 [SR] Verifying 100 components
2022-12-20 08:45:53, Info                  CSI    0000017a [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:53, Info                  CSI    0000017b [SR] Verify complete
2022-12-20 08:45:53, Info                  CSI    0000017c [SR] Verifying 100 components
2022-12-20 08:45:53, Info                  CSI    0000017d [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:53, Info                  CSI    0000017e [SR] Verify complete
2022-12-20 08:45:54, Info                  CSI    0000017f [SR] Verifying 100 components
2022-12-20 08:45:54, Info                  CSI    00000180 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:54, Info                  CSI    00000184 [SR] Verify complete
2022-12-20 08:45:54, Info                  CSI    00000185 [SR] Verifying 100 components
2022-12-20 08:45:54, Info                  CSI    00000186 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:54, Info                  CSI    00000187 [SR] Verify complete
2022-12-20 08:45:54, Info                  CSI    00000188 [SR] Verifying 100 components
2022-12-20 08:45:54, Info                  CSI    00000189 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:54, Info                  CSI    0000018a [SR] Verify complete
2022-12-20 08:45:54, Info                  CSI    0000018b [SR] Verifying 100 components
2022-12-20 08:45:54, Info                  CSI    0000018c [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:54, Info                  CSI    0000018d [SR] Verify complete
2022-12-20 08:45:54, Info                  CSI    0000018e [SR] Verifying 100 components
2022-12-20 08:45:54, Info                  CSI    0000018f [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:55, Info                  CSI    00000190 [SR] Verify complete
2022-12-20 08:45:55, Info                  CSI    00000191 [SR] Verifying 100 components
2022-12-20 08:45:55, Info                  CSI    00000192 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:55, Info                  CSI    00000193 [SR] Verify complete
2022-12-20 08:45:55, Info                  CSI    00000194 [SR] Verifying 100 components
2022-12-20 08:45:55, Info                  CSI    00000195 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:55, Info                  CSI    00000196 [SR] Verify complete
2022-12-20 08:45:55, Info                  CSI    00000197 [SR] Verifying 100 components
2022-12-20 08:45:55, Info                  CSI    00000198 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:56, Info                  CSI    00000199 [SR] Verify complete
2022-12-20 08:45:56, Info                  CSI    0000019a [SR] Verifying 100 components
2022-12-20 08:45:56, Info                  CSI    0000019b [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:56, Info                  CSI    0000019c [SR] Verify complete
2022-12-20 08:45:56, Info                  CSI    0000019d [SR] Verifying 100 components
2022-12-20 08:45:56, Info                  CSI    0000019e [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:56, Info                  CSI    0000019f [SR] Verify complete
2022-12-20 08:45:56, Info                  CSI    000001a0 [SR] Verifying 100 components
2022-12-20 08:45:56, Info                  CSI    000001a1 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:57, Info                  CSI    000001a2 [SR] Verify complete
2022-12-20 08:45:57, Info                  CSI    000001a3 [SR] Verifying 100 components
2022-12-20 08:45:57, Info                  CSI    000001a4 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:57, Info                  CSI    000001a5 [SR] Repairing file \??\C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\OneDrive.lnk from store
2022-12-20 08:45:57, Info                  CSI    000001a6 [SR] Verify complete
2022-12-20 08:45:57, Info                  CSI    000001a7 [SR] Verifying 100 components
2022-12-20 08:45:57, Info                  CSI    000001a8 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:57, Info                  CSI    000001a9 [SR] Verify complete
2022-12-20 08:45:57, Info                  CSI    000001aa [SR] Verifying 100 components
2022-12-20 08:45:57, Info                  CSI    000001ab [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:58, Info                  CSI    000001ac [SR] Verify complete
2022-12-20 08:45:58, Info                  CSI    000001ad [SR] Verifying 100 components
2022-12-20 08:45:58, Info                  CSI    000001ae [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:58, Info                  CSI    000001af [SR] Verify complete
2022-12-20 08:45:58, Info                  CSI    000001b0 [SR] Verifying 100 components
2022-12-20 08:45:58, Info                  CSI    000001b1 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:58, Info                  CSI    000001b2 [SR] Verify complete
2022-12-20 08:45:58, Info                  CSI    000001b3 [SR] Verifying 100 components
2022-12-20 08:45:58, Info                  CSI    000001b4 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:59, Info                  CSI    000001b9 [SR] Verify complete
2022-12-20 08:45:59, Info                  CSI    000001ba [SR] Verifying 100 components
2022-12-20 08:45:59, Info                  CSI    000001bb [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:59, Info                  CSI    000001bc [SR] Verify complete
2022-12-20 08:45:59, Info                  CSI    000001bd [SR] Verifying 100 components
2022-12-20 08:45:59, Info                  CSI    000001be [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:59, Info                  CSI    000001bf [SR] Verify complete
2022-12-20 08:45:59, Info                  CSI    000001c0 [SR] Verifying 100 components
2022-12-20 08:45:59, Info                  CSI    000001c1 [SR] Beginning Verify and Repair transaction
2022-12-20 08:45:59, Info                  CSI    000001c2 [SR] Verify complete
2022-12-20 08:45:59, Info                  CSI    000001c3 [SR] Verifying 100 components
2022-12-20 08:45:59, Info                  CSI    000001c4 [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:00, Info                  CSI    000001c5 [SR] Verify complete
2022-12-20 08:46:00, Info                  CSI    000001c6 [SR] Verifying 100 components
2022-12-20 08:46:00, Info                  CSI    000001c7 [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:00, Info                  CSI    000001c8 [SR] Verify complete
2022-12-20 08:46:00, Info                  CSI    000001c9 [SR] Verifying 100 components
2022-12-20 08:46:00, Info                  CSI    000001ca [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:00, Info                  CSI    000001cb [SR] Verify complete
2022-12-20 08:46:00, Info                  CSI    000001cc [SR] Verifying 100 components
2022-12-20 08:46:00, Info                  CSI    000001cd [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:01, Info                  CSI    000001ce [SR] Verify complete
2022-12-20 08:46:01, Info                  CSI    000001cf [SR] Verifying 100 components
2022-12-20 08:46:01, Info                  CSI    000001d0 [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:01, Info                  CSI    000001d1 [SR] Verify complete
2022-12-20 08:46:01, Info                  CSI    000001d2 [SR] Verifying 100 components
2022-12-20 08:46:01, Info                  CSI    000001d3 [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:01, Info                  CSI    000001d4 [SR] Verify complete
2022-12-20 08:46:02, Info                  CSI    000001d5 [SR] Verifying 100 components
2022-12-20 08:46:02, Info                  CSI    000001d6 [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:02, Info                  CSI    000001d7 [SR] Verify complete
2022-12-20 08:46:02, Info                  CSI    000001d8 [SR] Verifying 100 components
2022-12-20 08:46:02, Info                  CSI    000001d9 [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:02, Info                  CSI    000001da [SR] Verify complete
2022-12-20 08:46:02, Info                  CSI    000001db [SR] Verifying 100 components
2022-12-20 08:46:02, Info                  CSI    000001dc [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:02, Info                  CSI    000001dd [SR] Verify complete
2022-12-20 08:46:02, Info                  CSI    000001de [SR] Verifying 100 components
2022-12-20 08:46:02, Info                  CSI    000001df [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:03, Info                  CSI    000001e0 [SR] Verify complete
2022-12-20 08:46:03, Info                  CSI    000001e1 [SR] Verifying 100 components
2022-12-20 08:46:03, Info                  CSI    000001e2 [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:03, Info                  CSI    000001e3 [SR] Verify complete
2022-12-20 08:46:03, Info                  CSI    000001e4 [SR] Verifying 100 components
2022-12-20 08:46:03, Info                  CSI    000001e5 [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:03, Info                  CSI    000001e6 [SR] Verify complete
2022-12-20 08:46:03, Info                  CSI    000001e7 [SR] Verifying 100 components
2022-12-20 08:46:03, Info                  CSI    000001e8 [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:04, Info                  CSI    000001e9 [SR] Verify complete
2022-12-20 08:46:04, Info                  CSI    000001ea [SR] Verifying 73 components
2022-12-20 08:46:04, Info                  CSI    000001eb [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:04, Info                  CSI    000001ec [SR] Verify complete
2022-12-20 08:46:04, Info                  CSI    000001ed [SR] Repairing 1 components
2022-12-20 08:46:04, Info                  CSI    000001ee [SR] Beginning Verify and Repair transaction
2022-12-20 08:46:04, Info                  CSI    000001ef [SR] Repairing file \??\C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\OneDrive.lnk from store
2022-12-20 08:46:04, Info                  CSI    000001f0 [SR] Repair complete
2022-12-20 08:46:04, Info                  CSI    000001f1 [SR] Committing transaction
2022-12-20 08:46:04, Info                  CSI    000001f8 [SR] Verify and Repair Transaction completed. All files and registry keys listed in this transaction  have been successfully repaired
 
========= End of CMD: =========
 
 
========= FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" =========
 
 
C:\Users\Sue\Desktop>wevtutil cl "AMSI/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "AirSpaceChannel" 
 
C:\Users\Sue\Desktop>wevtutil cl "Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Application" 
 
C:\Users\Sue\Desktop>wevtutil cl "DirectShowFilterGraph" 
 
C:\Users\Sue\Desktop>wevtutil cl "DirectShowPluginControl" 
 
C:\Users\Sue\Desktop>wevtutil cl "Els_Hyphenation/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "EndpointMapper" 
 
C:\Users\Sue\Desktop>wevtutil cl "FirstUXPerf-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "ForwardedEvents" 
 
C:\Users\Sue\Desktop>wevtutil cl "General Logging" 
 
C:\Users\Sue\Desktop>wevtutil cl "HardwareEvents" 
 
C:\Users\Sue\Desktop>wevtutil cl "IHM_DebugChannel" 
 
C:\Users\Sue\Desktop>wevtutil cl "Intel-iaLPSS-GPIO/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Intel-iaLPSS-I2C/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Intel-iaLPSS2-GPIO2/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Intel-iaLPSS2-GPIO2/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Intel-iaLPSS2-I2C/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Intel-iaLPSS2-I2C/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Internet Explorer" 
 
C:\Users\Sue\Desktop>wevtutil cl "Key Management Service" 
 
C:\Users\Sue\Desktop>wevtutil cl "Lenovo-Sif-Companion/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Lenovo-Sif-Core/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Lenovo-Sif-Device/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Lenovo-Sif-Settings/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "MF_MediaFoundationDeviceMFT" 
 
C:\Users\Sue\Desktop>wevtutil cl "MF_MediaFoundationDeviceProxy" 
 
C:\Users\Sue\Desktop>wevtutil cl "MF_MediaFoundationFrameServer" 
 
C:\Users\Sue\Desktop>wevtutil cl "MedaFoundationVideoProc" 
 
C:\Users\Sue\Desktop>wevtutil cl "MedaFoundationVideoProcD3D" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationAsyncWrapper" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationContentProtection" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationDS" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationDeviceProxy" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationMP4" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationMediaEngine" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationPerformance" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationPerformanceCore" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationPipeline" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationPlatform" 
 
C:\Users\Sue\Desktop>wevtutil cl "MediaFoundationSrcPrefetch" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-AppV-Client-Streamingux/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-AppV-Client/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-AppV-Client/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-AppV-Client/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-AppV-Client/Virtual Applications" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-AppV-SharedPerformance/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Client-License-Flexible-Platform/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Client-License-Flexible-Platform/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Client-License-Flexible-Platform/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Client-Licensing-Platform/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Client-Licensing-Platform/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Client-Licensing-Platform/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-IE/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-IEFRAME/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-JSDumpHeap/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-OneCore-Setup/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-PerfTrack-IEFRAME/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-PerfTrack-MSHTML/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-User Experience Virtualization-Admin/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-User Experience Virtualization-Agent Driver/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-User Experience Virtualization-Agent Driver/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-User Experience Virtualization-App Agent/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-User Experience Virtualization-App Agent/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-User Experience Virtualization-App Agent/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-User Experience Virtualization-IPC/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-User Experience Virtualization-SQM Uploader/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-User Experience Virtualization-SQM Uploader/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-User Experience Virtualization-SQM Uploader/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AAD/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AAD/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ADSI/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ASN1/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ATAPort/General" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ATAPort/SATA-LPM" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ActionQueue/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-All-User-Install-Agent/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AllJoyn/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AllJoyn/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppHost/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppHost/ApplicationTracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppHost/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppHost/Internal" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppID/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppLocker/EXE and DLL" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppLocker/MSI and Script" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppLocker/Packaged app-Deployment" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppLocker/Packaged app-Execution" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppModel-Runtime/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppModel-Runtime/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppModel-Runtime/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppModel-Runtime/Diagnostics" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppModel-State/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppModel-State/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppReadiness/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppReadiness/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppReadiness/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppSruProv" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppXDeployment/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppXDeployment/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppXDeploymentServer/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppXDeploymentServer/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppXDeploymentServer/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppXDeploymentServer/Restricted" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ApplicabilityEngine/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ApplicabilityEngine/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application Server-Applications/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application Server-Applications/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application Server-Applications/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application Server-Applications/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application-Experience/Compatibility-Infrastructure-Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application-Experience/Program-Compatibility-Assistant" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application-Experience/Program-Compatibility-Assistant/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application-Experience/Program-Compatibility-Assistant/Trace" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application-Experience/Program-Compatibility-Troubleshooter" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application-Experience/Program-Inventory" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application-Experience/Program-Telemetry" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Application-Experience/Steps-Recorder" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppxPackaging/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppxPackaging/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AppxPackaging/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AssignedAccess/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AssignedAccess/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AssignedAccessBroker/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AssignedAccessBroker/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AsynchronousCausality/Causality" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Audio/CaptureMonitor" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Audio/GlitchDetection" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Audio/Informational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Audio/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Audio/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Audio/PlaybackManager" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Audit/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Authentication User Interface/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Authentication/AuthenticationPolicyFailures-DomainController" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Authentication/ProtectedUser-Client" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Authentication/ProtectedUserFailures-DomainController" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Authentication/ProtectedUserSuccesses-DomainController" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-AxInstallService/Log" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BTH-BTHPORT/HCI" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BTH-BTHPORT/L2CAP" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BTH-BTHUSB/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BTH-BTHUSB/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BackgroundTaskInfrastructure/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BackgroundTaskInfrastructure/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BackgroundTransfer-ContentPrefetcher/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Backup" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Base-Filtering-Engine-Connections/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Base-Filtering-Engine-Resource-Flows/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Battery/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Biometrics/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Biometrics/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BitLocker-DrivePreparationTool/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BitLocker-DrivePreparationTool/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BitLocker-Driver-Performance/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BitLocker/BitLocker Management" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BitLocker/BitLocker Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BitLocker/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Bits-Client/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Bits-Client/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Bluetooth-BthLEPrepairing/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Bluetooth-Bthmini/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Bluetooth-MTPEnum/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Bluetooth-Policy/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BranchCache/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BranchCacheClientEventProvider/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BranchCacheEventProvider/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BranchCacheMonitoring/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BranchCacheSMB/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-BranchCacheSMB/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CAPI2/Catalog Database Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CAPI2/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CDROM/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COM/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COM/ApartmentInitialize" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COM/ApartmentUninitialize" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COM/Call" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COM/CreateInstance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COM/ExtensionCatalog" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COM/FreeUnusedLibrary" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COM/RundownInstrumentation" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COMRuntime/Activations" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COMRuntime/MessageProcessing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-COMRuntime/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CertPoleEng/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CertificateServicesClient-CredentialRoaming/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Cleanmgr/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ClearTypeTextTuner/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CloudStore/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CloudStore/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CmiSetup/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CodeIntegrity/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CodeIntegrity/Verbose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ComDlg32/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ComDlg32/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Compat-Appraiser/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Compat-Appraiser/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Containers-BindFlt/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Containers-BindFlt/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Containers-Wcifs/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Containers-Wcifs/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Containers-Wcnfs/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Containers-Wcnfs/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CoreApplication/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CoreApplication/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CoreApplication/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CoreSystem-SmsRouter-Events/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CoreSystem-SmsRouter-Events/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CoreWindow/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CoreWindow/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CorruptedFileRecovery-Client/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CorruptedFileRecovery-Server/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Crashdump/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-CredUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Crypto-BCRYPT/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Crypto-CNG/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Crypto-DPAPI/BackUpKeySvc" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Crypto-DPAPI/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Crypto-DPAPI/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Crypto-DSSEnh/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Crypto-NCrypt/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Crypto-RNG/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Crypto-RSAEnh/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-D3D10Level9/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-D3D10Level9/PerfTiming" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DAL-Provider/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DAL-Provider/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DAMM/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DCLocator/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DDisplay/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DDisplay/Logging" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DLNA-Namespace/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DNS-Client/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DSC/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DSC/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DSC/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DSC/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DUSER/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DXGI/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DXGI/Logging" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DXP/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Data-Pdf/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DataIntegrityScan/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DataIntegrityScan/CrashRecovery" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DateTimeControlPanel/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DateTimeControlPanel/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DateTimeControlPanel/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Deduplication/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Deduplication/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Deduplication/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Deduplication/Scrubbing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Defrag-Core/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Deplorch/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DesktopActivityModerator/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DesktopWindowManager-Diag/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceAssociationService/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceConfidence/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceGuard/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceGuard/Verbose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceSetupManager/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceSetupManager/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceSetupManager/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceSetupManager/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceSync/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceSync/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceUpdateAgent/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceUx/Informational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DeviceUx/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Devices-Background/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dhcp-Client/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dhcp-Client/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dhcpv6-Client/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dhcpv6-Client/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DiagCpl/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-AdvancedTaskManager/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-DPS/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-DPS/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-DPS/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-MSDE/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-PCW/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-PCW/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-PCW/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-PLA/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-PLA/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-Perfhost/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-Scheduled/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-Scripted/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-Scripted/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-Scripted/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-Scripted/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-WDC/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnosis-WDI/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnostics-Networking/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnostics-Networking/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnostics-PerfTrack-Counters/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnostics-PerfTrack/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnostics-Performance/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnostics-Performance/Diagnostic/Loopback" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Diagnostics-Performance/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Direct3D10/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Direct3D10_1/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Direct3D11/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Direct3D11/Logging" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Direct3D11/PerfTiming" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Direct3D12/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Direct3D12/Logging" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Direct3D12/PerfTiming" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Direct3D9/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Direct3DShaderCache/Default" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DirectComposition/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DirectManipulation/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DirectShow-KernelSupport/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DirectSound/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Disk/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DiskDiagnostic/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DiskDiagnosticDataCollector/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DiskDiagnosticResolver/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dism-Api/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dism-Api/ExternalAnalytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dism-Api/InternalAnalytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dism-Cli/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DisplayColorCalibration/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DisplayColorCalibration/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DisplaySwitch/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Documents/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dot3MM/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DriverFrameworks-UserMode/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DucUpdateAgent/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dwm-API/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dwm-Core/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dwm-Dwm/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dwm-Redir/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Dwm-Udwm/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DxgKrnl-Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DxgKrnl-Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DxgKrnl/Contention" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DxgKrnl/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DxgKrnl/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DxgKrnl/Power" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-DxpTaskSyncProvider/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EDP-Application-Learning/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EDP-Audit-Regular/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EDP-Audit-TCB/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EFS/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ESE/IODiagnose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ESE/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EapHost/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EapHost/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EapHost/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EapMethods-RasChap/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EapMethods-RasTls/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EapMethods-Sim/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EapMethods-Ttls/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EaseOfAccess/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Energy-Estimation-Engine/EventLog" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Energy-Estimation-Engine/Trace" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EnhancedStorage-EhStorTcgDrv/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EventCollector/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EventCollector/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EventLog-WMIProvider/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EventLog/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-EventLog/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FMS/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FMS/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FMS/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FailoverClustering-Client/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Fault-Tolerant-Heap/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FeatureConfiguration/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FeatureConfiguration/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-Catalog/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-Catalog/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-ConfigManager/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-ConfigManager/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-Core/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-Core/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-Core/WHC" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-Engine/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-Engine/BackupLog" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-Engine/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-EventListener/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-EventListener/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-Service/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-Service/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-UI-Events/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileHistory-UI-Events/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-FileInfoMinifilter/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Firewall-CPL/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Folder Redirection/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Forwarding/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Forwarding/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-GPIO-ClassExtension/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-GenericRoaming/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-GroupPolicy/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HAL/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HealthCenter/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HealthCenter/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HealthCenterCPL/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HelloForBusiness/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Help/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HomeGroup Control Panel Performance/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HomeGroup Control Panel/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HomeGroup Listener Service/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HomeGroup Provider Service Performance/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HomeGroup Provider Service/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HomeGroup-ListenerService" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HotspotAuth/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HotspotAuth/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HttpService/Log" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-HttpService/Trace" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-Guest-Drivers/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-Guest-Drivers/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-Guest-Drivers/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-Guest-Drivers/Diagnose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-Guest-Drivers/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-Hypervisor-Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-Hypervisor-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-Hypervisor-Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-NETVSC/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-VID-Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Hyper-V-VID-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IE-SmartScreen" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IKE/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IKEDBG/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-Broker/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-CandidateUI/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-CustomerFeedbackManager/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-CustomerFeedbackManagerUI/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-JPAPI/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-JPLMP/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-JPPRED/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-JPSetting/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-JPTIP/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-KRAPI/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-KRTIP/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-OEDCompiler/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-TCCORE/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-TCTIP/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IME-TIP/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IPNAT/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IPSEC-SRV/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IPxlatCfg/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IPxlatCfg/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IdCtrls/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IdCtrls/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-IndirectDisplays-ClassExtension-Events/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Input-HIDCLASS-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-InputSwitch/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-International-RegionalOptionsControlPanel/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Iphlpsvc/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Iphlpsvc/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Iphlpsvc/Trace" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-KdsSvc/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kerberos/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Acpi/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-AppCompat/General" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-AppCompat/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-ApphelpCache/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-ApphelpCache/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-ApphelpCache/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Boot/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Boot/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-BootDiagnostics/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Disk/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-EventTracing/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-EventTracing/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-File/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-IO/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Interrupt-Steering/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-IoTrace/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-LiveDump/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-LiveDump/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Memory/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Network/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Pdc/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Pep/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-PnP/Boot Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-PnP/Configuration" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-PnP/Configuration Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-PnP/Driver Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-PnP/Driver Watchdog" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Power/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Power/Thermal-Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Power/Thermal-Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Prefetch/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Process/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Processor-Power/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Registry/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-Registry/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-ShimEngine/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-ShimEngine/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-ShimEngine/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-StoreMgr/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-StoreMgr/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-WDI/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-WDI/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-WDI/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-WHEA/Errors" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-WHEA/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Kernel-XDV/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-KeyboardFilter/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-KeyboardFilter/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-KeyboardFilter/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Known Folders API Service" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-L2NA/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LDAP-Client/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LSA/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LSA/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LSA/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LUA-ConsentUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LanguagePackSetup/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LanguagePackSetup/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LanguagePackSetup/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LimitsManagement/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LinkLayerDiscoveryProtocol/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LinkLayerDiscoveryProtocol/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LiveId/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-LiveId/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MPEG2-Video-Encoder-MFT_Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MPS-CLNT/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MPS-DRV/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MPS-SRV/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MSFTEDIT/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MSPaint/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MSPaint/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MSPaint/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MUI/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MUI/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MUI/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MUI/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Media-Streaming/DMC" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Media-Streaming/DMR" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Media-Streaming/MDE" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MediaFoundation-MFCaptureEngine/MFCaptureEngine" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MediaFoundation-MFReadWrite/SinkWriter" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MediaFoundation-MFReadWrite/SourceReader" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MediaFoundation-MFReadWrite/Transform" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MediaFoundation-Performance/SARStreamResource" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MediaFoundation-PlayAPI/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MemoryDiagnostics-Results/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Minstore/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Minstore/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Mobile-Broadband-Experience-Api-Internal/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Mobile-Broadband-Experience-Api/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Mobile-Broadband-Experience-Parser-Task/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Mobile-Broadband-Experience-Parser-Task/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Mobile-Broadband-Experience-SmsApi/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-MobilityCenter/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Diagnostics" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Mprddm/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NCSI/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NCSI/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NDF-HelperClassDiscovery/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NDIS-PacketCapture/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NDIS/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NDIS/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NTLM/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NWiFi/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Narrator/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Ncasvc/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NcdAutoSetup/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NcdAutoSetup/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NdisImPlatform/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Ndu/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NetShell/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Network-Connection-Broker" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Network-DataUsage/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Network-Setup/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Network-and-Sharing-Center/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NetworkBridge/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NetworkLocationWizard/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NetworkProfile/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NetworkProfile/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NetworkProvider/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NetworkProvisioning/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NetworkProvisioning/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NetworkSecurity/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NetworkStatus/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Networking-Correlation/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Networking-RealTimeCommunication/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NlaSvc/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-NlaSvc/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Ntfs/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Ntfs/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Ntfs/WHC" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OLE/Clipboard-Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OLEACC/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OLEACC/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OOBE-FirstLogonAnim/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OOBE-Machine-Core/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OOBE-Machine-DUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OOBE-Machine-DUI/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OOBE-Machine-Plugins-Wireless/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OcpUpdateAgent/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OfflineFiles/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OfflineFiles/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OfflineFiles/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OfflineFiles/SyncLog" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OneBackup/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OneX/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OneX/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OobeLdr/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-OtpCredentialProvider/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PCI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PackageStateRoaming/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PackageStateRoaming/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PackageStateRoaming/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ParentalControls/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Partition/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Partition/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PeerToPeerDrtEventProvider/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PerceptionRuntime/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PerceptionSensorDataService/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PersistentMemory-Nvdimm/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PersistentMemory-Nvdimm/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PersistentMemory-Nvdimm/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PersistentMemory-PmemDisk/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PersistentMemory-PmemDisk/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PersistentMemory-PmemDisk/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PersistentMemory-ScmBus/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PersistentMemory-ScmBus/Certification" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PersistentMemory-ScmBus/Diagnose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PersistentMemory-ScmBus/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PhotoAcq/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PlayToManager/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Policy/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Policy/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PortableDeviceStatusProvider/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PortableDeviceSyncProvider/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Power-Meter-Polling/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PowerCfg/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PowerCpl/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PowerEfficiencyDiagnostics/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PowerShell-DesiredStateConfiguration-FileDownloadManager/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PowerShell-DesiredStateConfiguration-FileDownloadManager/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PowerShell-DesiredStateConfiguration-FileDownloadManager/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PowerShell/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PowerShell/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PowerShell/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PowerShell/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PrimaryNetworkIcon/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PrintBRM/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PrintService-USBMon/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PrintService/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PrintService/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PrintService/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Privacy-Auditing/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ProcessStateManager/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Program-Compatibility-Assistant/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Program-Compatibility-Assistant/CompatAfterUpgrade" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Provisioning-Diagnostics-Provider/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Provisioning-Diagnostics-Provider/AutoPilot" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Provisioning-Diagnostics-Provider/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Provisioning-Diagnostics-Provider/ManagementService" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Proximity-Common/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Proximity-Common/Informational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Proximity-Common/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PushNotification-Developer/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PushNotification-InProc/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PushNotification-Platform/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PushNotification-Platform/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-PushNotification-Platform/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-QoS-Pacer/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-QoS-qWAVE/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RPC-Proxy/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RPC/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RPC/EEInfo" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RRAS/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RRAS/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RadioManager/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Ras-NdisWanPacketCapture/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RasAgileVpn/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RasAgileVpn/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ReFS/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ReadyBoost/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ReadyBoost/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ReadyBoostDriver/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ReadyBoostDriver/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Regsvr32/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteApp and Desktop Connections/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteApp and Desktop Connections/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteAssistance/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteAssistance/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteAssistance/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteDesktopServices-RemoteFX-Synth3dvsc/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteDesktopServices-RemoteFX-VM-Kernel-Mode-Transport/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteDesktopServices-RemoteFX-VM-User-Mode-Transport/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RemoteDesktopServices-SessionServices/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Remotefs-Rdbss/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Remotefs-Rdbss/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ResetEng-Trace/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Resource-Exhaustion-Detector/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Resource-Exhaustion-Resolver/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ResourcePublication/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RestartManager/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RetailDemo/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-RetailDemo/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime-Graphics/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime-Networking-BackgroundTransfer/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime-Networking/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime-Web-Http/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime-WebAPI/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime-Windows-Media/WinRTAdaptiveMediaSource" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime-Windows-Media/WinRTCaptureEngine" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime-Windows-Media/WinRTMediaStreamSource" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime-Windows-Media/WinRTTranscode" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime/CreateInstance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Runtime/Error" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SENSE/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBClient/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBClient/HelperClassDiagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBClient/ObjectStateDiagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBClient/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBDirect/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBDirect/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBDirect/Netmon" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBServer/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBServer/Audit" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBServer/Connectivity" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBServer/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBServer/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBServer/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBServer/Security" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBWitnessClient/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SMBWitnessClient/Informational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SPB-ClassExtension/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SPB-HIDI2C/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Schannel-Events/Perf" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Sdbus/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Sdbus/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Sdstor/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Search-Core/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Search-ProtocolHandlers/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SearchUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SearchUI/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SecureAssessment/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-Adminless/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-Audit-Configuration-Client/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-Audit-Configuration-Client/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-EnterpriseData-FileRevocationManager/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-ExchangeActiveSyncProvisioning/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-ExchangeActiveSyncProvisioning/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-IdentityListener/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-IdentityStore/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-LessPrivilegedAppContainer/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-Mitigations/KernelMode" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-Mitigations/UserMode" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-Netlogon/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-SPP-UX-GC/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-SPP-UX-GenuineCenter-Logging/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-SPP-UX-Notifications/ActionCenter" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-SPP-UX/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-SPP/Perf" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-UserConsentVerifier/Audit" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Security-Vault/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SecurityMitigationsBroker/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SecurityMitigationsBroker/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SecurityMitigationsBroker/Perf" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SendTo/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Sens/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SenseIR/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Sensors/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Sensors/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Serial-ClassExtension-V2/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Serial-ClassExtension/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ServiceReportingApi/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Services-Svchost/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Services/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Servicing/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SettingSync-Azure/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SettingSync-Azure/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SettingSync-OneDrive/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SettingSync-OneDrive/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SettingSync-OneDrive/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SettingSync/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SettingSync/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SettingSync/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SettingSync/VerboseDebug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Setup/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SetupCl/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SetupPlatform/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SetupQueue/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SetupUGC/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ShareMedia-ControlPanel/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-AppWizCpl/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-AuthUI-BootAnim/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-AuthUI-Common/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-AuthUI-CredUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-AuthUI-CredentialProviderUser/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-AuthUI-Logon/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-AuthUI-LogonUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-AuthUI-Shutdown/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-ConnectedAccountState/ActionCenter" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-Core/ActionCenter" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-Core/AppDefaults" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-Core/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-Core/LogonTasksChannel" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-Core/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-DefaultPrograms/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-LockScreenContent/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-OpenWith/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-Shwebsvc" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shell-ZipFolder/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ShellCommon-StartLayoutPopulation/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Shsvcs/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SleepStudy/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SmartCard-Audit/Authentication" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SmartCard-DeviceEnum/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SmartCard-TPM-VCard-Module/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SmartCard-TPM-VCard-Module/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SmartScreen/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SmbClient/Audit" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SmbClient/Connectivity" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SmbClient/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SmbClient/Security" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Speech-UserExperience/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Spell-Checking/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SpellChecker/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Spellchecking-Host/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SruMon/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SrumTelemetry" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StateRepository/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StateRepository/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StateRepository/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StateRepository/Restricted" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorDiag/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorPort/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-ATAPort/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-ATAPort/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-ATAPort/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-ATAPort/Diagnose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-ATAPort/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-ClassPnP/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-ClassPnP/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-ClassPnP/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-ClassPnP/Diagnose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-ClassPnP/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Disk/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Disk/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Disk/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Disk/Diagnose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Disk/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Storport/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Storport/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Storport/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Storport/Diagnose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Storport/Health" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Storport/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Tiering-IoHeat/Heat" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storage-Tiering/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorageManagement/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorageManagement/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorageSettings/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorageSpaces-Driver/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorageSpaces-Driver/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorageSpaces-Driver/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorageSpaces-ManagementAgent/WHC" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorageSpaces-SpaceManager/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-StorageSpaces-SpaceManager/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Store/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Storsvc/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Subsys-Csr/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Subsys-SMSS/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Superfetch/Main" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Superfetch/PfApLog" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Superfetch/StoreLog" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Sysprep/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-System-Profile-HardwareId/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SystemSettingsHandlers/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SystemSettingsThreshold/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SystemSettingsThreshold/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-SystemSettingsThreshold/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TCPIP/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TCPIP/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TSF-msctf/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TSF-msctf/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TSF-msutb/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TSF-msutb/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TTS/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TWinAPI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TWinUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TWinUI/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TZSync/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TZSync/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TZUtil/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TaskScheduler/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TaskScheduler/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TaskScheduler/Maintenance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TaskScheduler/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TaskbarCPL/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TenantRestrictions/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-ClientUSBDevices/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-ClientUSBDevices/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-ClientUSBDevices/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-ClientUSBDevices/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-LocalSessionManager/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-LocalSessionManager/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-LocalSessionManager/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-MediaRedirection/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-PnPDevices/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-PnPDevices/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-PnPDevices/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-PnPDevices/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-Printers/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-Printers/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-Printers/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-Printers/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-RDPClient/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-RDPClient/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-RDPClient/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-RdpSoundDriver/Capture" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-RdpSoundDriver/Playback" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-ServerUSBDevices/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-ServerUSBDevices/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-ServerUSBDevices/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TerminalServices-ServerUSBDevices/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Tethering-Manager/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Tethering-Station/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ThemeCPL/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ThemeUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Threat-Intelligence/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Time-Service-PTP-Provider/PTP-Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Time-Service/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Troubleshooting-Recommended/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Troubleshooting-Recommended/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-TunnelDriver" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UAC-FileVirtualization/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UAC/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UI-Shell/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UIAnimation/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UIAutomationCore/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UIAutomationCore/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UIAutomationCore/Perf" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UIRibbon/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-USB-MAUSBHOST-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-USB-UCX-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-USB-USBHUB/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-USB-USBHUB3-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-USB-USBPORT/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-USB-USBXHCI-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-USB-USBXHCI-Trustlet-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UniversalTelemetryClient/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-User Control Panel Performance/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-User Control Panel Usage/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-User Control Panel/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-User Control Panel/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-User Device Registration/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-User Device Registration/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-User Profile Service/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-User Profile Service/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-User-Loader/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-User-Loader/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UserAccountControl/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UserModePowerService/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UserPnp/ActionCenter" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UserPnp/DeviceInstall" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UserPnp/DeviceMetadata/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UserPnp/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UserPnp/SchedulerOperations" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UxInit/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-UxTheme/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VAN/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VDRVROOT/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VHDMP-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VHDMP-Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VIRTDISK-Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VPN-Client/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VPN/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VWiFi/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VerifyHardwareSecurity/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VerifyHardwareSecurity/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Volume/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VolumeControl/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VolumeSnapshot-Driver/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-VolumeSnapshot-Driver/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WABSyncProvider/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WCN-Config-Registrar/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WCNWiz/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WDAG-PolicyEvaluator-CSP/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WDAG-PolicyEvaluator-GP/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WEPHOSTSVC/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WER-PayloadHealth/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WFP/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WFP/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WLAN-AutoConfig/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WLAN-Autoconfig/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WLAN-Driver/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WLAN-MediaManager/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WLANConnectionFlow/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WMI-Activity/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WMI-Activity/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WMI-Activity/Trace" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WMPDMCUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WMPNSS-PublicAPI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WMPNSS-Service/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WMPNSS-Service/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WMPNSSUI/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WPD-API/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WPD-ClassInstaller/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WPD-ClassInstaller/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WPD-CompositeClassDriver/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WPD-CompositeClassDriver/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WPD-MTPBT/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WPD-MTPClassDriver/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WPD-MTPClassDriver/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WPD-MTPIP/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WPD-MTPUS/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WSC-SRV/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WUSA/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WWAN-CFE/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WWAN-MM-Events/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WWAN-MediaManager/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WWAN-NDISUIO-EVENTS/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WWAN-SVC-Events/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WWAN-SVC-Events/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Wcmsvc/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Wcmsvc/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WebAuth/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WebAuthN/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WebIO-NDF/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WebIO/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WebPlatStorage-Server" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WebServices/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WebcamProvider/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Websocket-Protocol-Component/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WiFiDisplay/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Win32k/Concurrency" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Win32k/Contention" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Win32k/Messages" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Win32k/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Win32k/Power" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Win32k/Render" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Win32k/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Win32k/UIPI" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinHTTP-NDF/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinHttp-Pca" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinHttp/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinHttp/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinINet-Capture/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinINet-Config/ProxyConfigChanged" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinINet/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinINet/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinINet/Pca" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinINet/UsageLog" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinINet/WebSocket" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinMDE/MDE" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinML/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinNat/Oper" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinNat/Trace" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinRM/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinRM/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinRM/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WinURLMon/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Windeploy/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Windows Defender/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Windows Defender/WHC" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurity" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurityVerbose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Windows Firewall With Advanced Security/FirewallDiagnostics" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Windows Firewall With Advanced Security/FirewallVerbose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WindowsBackup/ActionCenter" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WindowsColorSystem/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WindowsColorSystem/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WindowsSystemAssessmentTool/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WindowsSystemAssessmentTool/Tracing" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WindowsUIImmersive/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WindowsUIImmersive/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WindowsUpdateClient/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WindowsUpdateClient/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Wininit/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Winlogon/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Winlogon/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Winsock-AFD/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Winsock-NameResolution/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Winsock-WS2HELP/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Winsrv/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Wired-AutoConfig/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Wired-AutoConfig/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WlanDlg/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Wordpad/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Wordpad/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Wordpad/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WorkFolders/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WorkFolders/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WorkFolders/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-WorkFolders/WHC" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-Workplace Join/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-XAML-Diagnostics/Default" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-XAML/Default" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-XAudio2/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-XAudio2/Performance" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-glcnd/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-glcnd/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-glcnd/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-mobsync/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ntshrui" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-ntshrui-perf" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-osk/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-stobject/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-wmbclass/Analytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-Windows-wmbclass/Trace" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-WindowsPhone-Connectivity-WiFiConnSvc-Channel" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-WindowsPhone-LocationServiceProvider/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-WindowsPhone-Net-Cellcore-CellManager/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "Microsoft-WindowsPhone-Net-Cellcore-CellularAPI/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "NIS-Driver-WFP/Diagnostic" 
 
C:\Users\Sue\Desktop>wevtutil cl "Navigator" 
 
C:\Users\Sue\Desktop>wevtutil cl "Network Isolation Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "OAlerts" 
 
C:\Users\Sue\Desktop>wevtutil cl "OSK_SoftKeyboard_Channel" 
 
C:\Users\Sue\Desktop>wevtutil cl "OfficeChannel" 
 
C:\Users\Sue\Desktop>wevtutil cl "OfficeDebugChannel" 
 
C:\Users\Sue\Desktop>wevtutil cl "OpenSSH/Admin" 
 
C:\Users\Sue\Desktop>wevtutil cl "OpenSSH/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "OpenSSH/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Physical_Keyboard_Manager_Channel" 
 
C:\Users\Sue\Desktop>wevtutil cl "PlayReadyPerformanceChannel" 
 
C:\Users\Sue\Desktop>wevtutil cl "RTWorkQueueExtended" 
 
C:\Users\Sue\Desktop>wevtutil cl "RTWorkQueueTheading" 
 
C:\Users\Sue\Desktop>wevtutil cl "SMSApi" 
 
C:\Users\Sue\Desktop>wevtutil cl "Security" 
 
C:\Users\Sue\Desktop>wevtutil cl "Setup" 
 
C:\Users\Sue\Desktop>wevtutil cl "SmbWmiAnalytic" 
 
C:\Users\Sue\Desktop>wevtutil cl "System" 
 
C:\Users\Sue\Desktop>wevtutil cl "SystemEventsBroker" 
 
C:\Users\Sue\Desktop>wevtutil cl "TabletPC_InputPanel_Channel" 
 
C:\Users\Sue\Desktop>wevtutil cl "TabletPC_InputPanel_Channel/IHM" 
 
C:\Users\Sue\Desktop>wevtutil cl "TimeBroker" 
 
C:\Users\Sue\Desktop>wevtutil cl "UIManager_Channel" 
 
C:\Users\Sue\Desktop>wevtutil cl "Uac/Debug" 
 
C:\Users\Sue\Desktop>wevtutil cl "WINDOWS_KS_CHANNEL" 
 
C:\Users\Sue\Desktop>wevtutil cl "WINDOWS_MFH264Enc_CHANNEL" 
 
C:\Users\Sue\Desktop>wevtutil cl "WINDOWS_MP4SDECD_CHANNEL" 
 
C:\Users\Sue\Desktop>wevtutil cl "WINDOWS_MSMPEG2ADEC_CHANNEL" 
 
C:\Users\Sue\Desktop>wevtutil cl "WINDOWS_MSMPEG2VDEC_CHANNEL" 
 
C:\Users\Sue\Desktop>wevtutil cl "WINDOWS_VC1ENC_CHANNEL" 
 
C:\Users\Sue\Desktop>wevtutil cl "WINDOWS_WMPHOTO_CHANNEL" 
 
C:\Users\Sue\Desktop>wevtutil cl "WINDOWS_wmvdecod_CHANNEL" 
 
C:\Users\Sue\Desktop>wevtutil cl "WMPSetup" 
 
C:\Users\Sue\Desktop>wevtutil cl "WMPSyncEngine" 
 
C:\Users\Sue\Desktop>wevtutil cl "Windows Networking Vpn Plugin Platform/Operational" 
 
C:\Users\Sue\Desktop>wevtutil cl "Windows Networking Vpn Plugin Platform/OperationalVerbose" 
 
C:\Users\Sue\Desktop>wevtutil cl "Windows PowerShell" 
 
C:\Users\Sue\Desktop>wevtutil cl "WordChannel" 
 
C:\Users\Sue\Desktop>wevtutil cl "muxencode" 
 
========= End of CMD: =========
 
 
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 20-12-2022 08:50:45)
 
C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe => Is moved successfully
 
==== End of Fixlog 08:50:45 ====
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-12-2022
Ran by Sue (20-12-2022 08:52:13)
Running from C:\Users\Sue\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.2364 (X64) (2022-11-10 22:45:14)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-3259427507-1055586877-3198061443-500 - Administrator - Disabled)
ccwadmin (S-1-5-21-3259427507-1055586877-3198061443-1002 - Administrator - Enabled)
DefaultAccount (S-1-5-21-3259427507-1055586877-3198061443-503 - Limited - Disabled)
Guest (S-1-5-21-3259427507-1055586877-3198061443-501 - Limited - Enabled)
Sue (S-1-5-21-3259427507-1055586877-3198061443-1001 - Administrator - Enabled) => C:\Users\Sue
WDAGUtilityAccount (S-1-5-21-3259427507-1055586877-3198061443-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
ABS PDF Install (HKLM-x32\...\{C42DD564-7DCD-4555-A7F3-15C0F46221D0}) (Version: 4.6.0 - Atlas Business Solutions, Inc.)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-1033-7760-BC15014EA700}) (Version: 22.003.20263 - Adobe)
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 2.14.04.018 - Advanced Micro Devices, Inc.)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.130 - Advanced Micro Devices, Inc.) Hidden
AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.82 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 4.13.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 6.0.0.9 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver Alpha (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\{71990c55-cd9c-43d0-9271-e2d3941f3ca8}) (Version: 2.14.04.018 - Advanced Micro Devices, Inc.) Hidden
EPSON ET-2760 Series Printer Uninstall (HKLM\...\EPSON ET-2760 Series) (Version:  - Seiko Epson Corporation)
Epson ET-2760 User’s Guide (HKLM-x32\...\UsersGuideEpson ET-2760 User’s Guide_is1) (Version: 1.0 - Epson America, Inc.)
Epson Event Manager (HKLM-x32\...\{3ACC34BD-4B01-49CA-9859-0FDD746BB36E}) (Version: 3.11.0058 - Seiko Epson Corporation)
Epson Scan 2 (HKLM-x32\...\Epson Scan 2) (Version:  - Seiko Epson Corporation)
EPSON Scan OCR Component (HKLM-x32\...\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}) (Version: 3.00.04 - SEIKO EPSON Corp.)
Epson Software Updater (HKLM-x32\...\{26A9B753-4B5D-46D8-A329-5CEF96FC22D2}) (Version: 4.6.5 - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 108.0.5359.125 - Google LLC)
HP Unified IO (HKLM\...\{5C76ED0D-0F6F-4985-8B34-F9AE7834848F}) (Version: 2.0.0.434 - HP) Hidden
HP Unified IO (HKLM-x32\...\{F1390872-2500-4408-A46C-CD16C960C661}) (Version: 2.0.0.434 - HP) Hidden
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 3.13.14.0 - Lenovo Group Ltd.)
Mesh Agent (HKLM\...\Mesh Agent) (Version: 2022-08-25 00:17:18.000-07:00 - )
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 108.0.1462.54 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 108.0.1462.54 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 22.238.1114.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{80F1AF52-7AC0-42A3-9AF0-689BFB271D1D}) (Version: 3.68.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23026 (HKLM-x32\...\{BE960C1C-7BAD-3DE6-8B1A-2616FE532845}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23026 (HKLM-x32\...\{A2563E55-3BEC-3828-8D67-E5E8B9E8B675}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.30.30704 (HKLM-x32\...\{57a73df6-4ba9-4c1d-bbbb-517289ff6c13}) (Version: 14.30.30704.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.30.30704 (HKLM\...\{6DB765A8-05AF-49A1-A71D-6F645EE3CE41}) (Version: 14.30.30704 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.30.30704 (HKLM\...\{662A0088-6FCD-45DD-9EA7-68674058AED5}) (Version: 14.30.30704 - Microsoft Corporation) Hidden
Microsoft Word 2021 - en-us (HKLM\...\Word2021Retail - en-us) (Version: 16.0.15831.20208 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.15726.20202 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.15831.20184 - Microsoft Corporation) Hidden
QuickBooks (HKLM\...\{3F034BE4-4FD8-4B4C-B9A7-BE9BF17C3CA4}) (Version: 33.0.4003.3302 - Intuit Inc.) Hidden
QuickBooks (HKLM\...\{A8FB867A-1595-43B2-8F8C-B6112C77CB8D}) (Version: 32.0.4006.3201 - Intuit Inc.) Hidden
QuickBooks Premier Edition 2022 (HKLM\...\{C32D73A9-B060-4D84-BEBB-5B595944E9E3}) (Version: 32.0.4006.3201 - Intuit Inc.)
QuickBooks Premier Edition 2023 (HKLM\...\{A9C6041A-3497-4CA5-86D1-F8759DD1BE58}) (Version: 33.0.4003.3302 - Intuit Inc.)
QuickBooks Runtime Redistributable (HKLM\...\{F2A4F809-2DE6-4D27-888B-4D2BB8DAF20E}) (Version: 1.00.0000 - Intuit Inc.)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9098.1 - Realtek Semiconductor Corp.)
ScreenConnect Client (61e735463d3bf1de) (HKLM-x32\...\{59AE0A72-DD3C-442C-AA9A-4529DA385797}) (Version: 21.13.4914.7937 - ScreenConnect Software)
TeamViewer (HKLM\...\TeamViewer) (Version: 15.35.9 - TeamViewer)
 
Packages:
=========
AMD Radeon Software -> C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.21.40031.0_x64__0a9344xs7nr4m [2022-11-10] (Advanced Micro Devices Inc.) [Startup Task]
AV1 Video Extension -> C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.1.52851.0_x64__8wekyb3d8bbwe [2022-12-08] (Microsoft Corporation)
Lenovo Commercial Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoSettingsforEnterprise_10.2210.33.0_x64__k1h2ywk1493x8 [2022-11-12] (LENOVO INC.)
MPEG-2 Video Extension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.50901.0_x64__8wekyb3d8bbwe [2022-11-12] (Microsoft Corporation)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.36.273.0_x64__dt26b99r8h8gj [2022-11-12] (Realtek Semiconductor Corp)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.15.12020.0_x64__8wekyb3d8bbwe [2022-12-08] (Microsoft Studios) [MS Ad]
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{05EC5C13-D255-4592-9CCB-98615172F0D6}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{0ADF9C35-0D5E-4B75-88DD-B64868907E17}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{123FAF7F-3FB1-4B8F-AD18-0047401D436A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{37A2FC00-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{37A2FC02-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{4716D3CE-55DB-4D2A-818C-87D912895890}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{4844F3F7-2161-4AC4-B219-B3B4311782AA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{4E5E74B5-8EB5-4859-A335-837EED412620}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{547C8F00-5567-4AE3-8BB0-CC3CE2AB9070}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{57D590F1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{596801D8-2C9D-4627-9C67-195CB81B655A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{63B5B272-1760-4A4F-922B-57F274900044}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{7DBF8260-30AD-4D1B-876A-8032B87B809F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{828E5386-74CF-4019-B356-C857CD028A7D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{82CC31B3-53B4-4161-A4E9-6B4F1290A6C8}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{8572570D-12D9-4F2C-8BB8-EB8848178B94}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{8E590317-1329-11D1-B70B-00805F29CD16}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2023\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F2-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F3-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F4-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F5-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F6-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F7-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A63E42D0-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A63E42D2-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{AF5E0A13-CEAB-47CE-991D-77E82CD1BF3F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{B10BFAC3-EFF1-40D9-ADA0-BEBE037C24CA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{B66F2BF1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{b775f163-bef1-433e-aaab-c4344a51c94c}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2023\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{CBEF1FB5-78FF-4B14-9B0F-275493FB589C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D14FD6B3-6A9F-4537-9460-07B836707127}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D4A12AAF-E15E-470B-A6B6-63032186F91F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9B9C060-0954-11D3-9E07-00104BD2BE34}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSource.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6F81-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6F84-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6F87-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FB2-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\StorageClasses.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{DCB2B478-EFF6-48F6-B718-13E98876854E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{DFD0AF10-B86C-4AF3-B609-1348D513E565}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E1A173E1-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E1A173E3-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{e64977bd-9e0b-498d-843e-1776102710aa}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2022\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{EADA914E-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{EAEF733D-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{FAC93D42-FFC2-11d1-9DEB-0008C7A08EBA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2023\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{FB17915F-06D1-4214-A902-CC5EE05186E9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{FB359C2A-6927-4AD7-8F1B-B6472CA7CDE7}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Windows\System32\atiacm64.dll [2021-12-09] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
2009-09-16 20:44 - 2009-09-16 20:44 - 000153088 _____ (Hewlett Packard) [File not signed] C:\Windows\System32\hptcpmib.dll
2009-09-16 20:45 - 2009-09-16 20:45 - 000331264 _____ (Hewlett Packard) [File not signed] C:\Windows\System32\HpTcpMon.dll
2009-09-16 13:44 - 2009-09-16 13:44 - 000132096 _____ (Hewlett Packard) [File not signed] C:\Windows\System32\hpzjrd01.dll
2009-09-16 20:45 - 2009-09-16 20:45 - 000317440 _____ (Microsoft Corporation) [File not signed] C:\Windows\System32\HPTcpMUI.dll
2020-07-10 13:23 - 2020-07-10 13:23 - 000132096 _____ (Seiko Epson Corporation) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\epnsm.dll
2020-05-26 21:20 - 2020-05-26 21:20 - 000291328 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\LcMgr.dll
2016-09-14 16:31 - 2016-09-14 16:31 - 000500736 ____S (SEIKO EPSON CORPORATION) [File not signed] C:\Windows\System32\enppmon.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Mesh Agent => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ScreenConnect Client (61e735463d3bf1de) => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2022-11-16] (Microsoft Corporation -> Microsoft Corporation)
Handler: intu-help-qb15 - {0EEC9CBF-4C3D-45B3-9384-3C3CA3034A8B} - C:\Program Files\Intuit\QuickBooks 2022\HelpAsyncPluggableProtocol.dll [2022-10-19] (Intuit, Inc. -> Intuit, Inc.)
Handler: intu-help-qb16 - {6995859E-9BFA-4D54-9059-180AA18A20CF} - C:\Program Files\Intuit\QuickBooks 2023\HelpAsyncPluggableProtocol.dll [2022-10-08] (Intuit, Inc. -> Intuit, Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2019-12-07 03:14 - 2019-12-07 03:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Sue\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{3A41CBAC-D63D-45B0-BCDD-CE593C6EB293}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{53A494BB-440B-43BB-B888-4E5C7905CBA8}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{947D4551-4AEB-464F-B053-BC1819DB6DE9}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{E531F30C-28D8-49F5-9C51-F22377CC989E}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0EAF02BE-2725-4A97-849D-3AF2C042552E}] => (Allow) C:\Program Files\Mesh Agent\MeshAgent.exe (mc.ntg.co-8edb73 -> ) [File not signed]
FirewallRules: [{EF13EEE1-2B37-4589-9615-0DB450A3A347}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [{6926B347-FC06-4364-AB7C-3791D62D4A3E}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [TCP Query User{E70C39EE-C537-4B53-8CAD-0CD0D6D5DC62}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [UDP Query User{7273A62E-C192-4FBE-B0A7-2749E19437B7}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [{9A6F0C91-EDAC-4E0A-835D-DCF6AD8E3745}] => (Allow) C:\Users\Public\Documents\Windows\QuickBooksDownloder.exe (Solanki Piyushkumar -> )
FirewallRules: [{25640E72-63CB-41AA-AAB7-3E771EA5461B}] => (Allow) C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe => No File
FirewallRules: [{7D6F1BBE-49E3-4419-A620-F54CD2574AA4}] => (Allow) C:\Users\Public\Documents\Windows\QuickBooksDownloder.exe (Solanki Piyushkumar -> )
FirewallRules: [{D40BCBB0-E85A-488E-A5AE-7683650A60AB}] => (Allow) C:\Program Files\Intuit\QuickBooks 2022\CefSharp.BrowserSubprocess.exe (The CefSharp Authors) [File not signed]
FirewallRules: [{F7DD5539-4D4E-4F60-87EA-6D7503C0D851}] => (Allow) C:\Program Files\Intuit\QuickBooks 2023\CefSharp.BrowserSubprocess.exe (The CefSharp Authors) [File not signed]
FirewallRules: [{F40FD09B-2DA9-4AB3-A3D4-CE738AB00963}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C7CEA418-93BB-4E28-B30E-F2DFDFAFBA67}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{554174AB-D730-4FD4-B458-2AD13248F766}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{87A45F36-2111-4C45-80A0-D51577AAC7E1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{6C683A2E-759E-4388-BBDB-33639BC666D4}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
15-12-2022 16:01:15 Removed Windows PC Health Check
15-12-2022 16:04:21 AdwCleaner_BeforeCleaning_15/12/2022_16:04:21
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (12/20/2022 08:47:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_stisvc, version: 10.0.19041.1806, time stamp: 0x7dcad237
Faulting module name: esxw2u2.dll, version: 1.2.2.0, time stamp: 0x599d2610
Exception code: 0xc0000005
Fault offset: 0x000000000003e86b
Faulting process id: 0x8e0
Faulting application start time: 0x01d91481ea882f84
Faulting application path: C:\Windows\system32\svchost.exe
Faulting module path: C:\Windows\system32\esxw2u2.dll
Report Id: 29a511bd-b004-4bf1-b4ee-1b31037d76c1
Faulting package full name: 
Faulting package-relative application ID:
 
 
System errors:
=============
Error: (12/20/2022 08:47:02 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Image Acquisition (WIA) service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (12/20/2022 08:47:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HitmanPro38CrusaderBoot service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (12/20/2022 08:46:25 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\system32\IntelIHVRouter08.dll
 
Error: (12/20/2022 08:46:25 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\system32\IntelIHVRouter08.dll
 
Error: (12/20/2022 08:46:24 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\system32\IntelIHVRouter08.dll
 
Error: (12/20/2022 08:46:22 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error: 
Access is denied.
 
Error: (12/20/2022 08:46:22 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-E2I7FB8)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
 
Error: (12/20/2022 08:46:21 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error: 
Access is denied.
 
 
==================== Memory info =========================== 
 
BIOS: LENOVO M47KT21A 06/29/2022
Motherboard: LENOVO 32E4
Processor: AMD Ryzen 7 PRO 5750GE with Radeon Graphics 
Percentage of memory in use: 26%
Total physical RAM: 15751.31 MB
Available physical RAM: 11573.89 MB
Total Virtual: 18183.31 MB
Available Virtual: 13649.48 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:474.72 GB) (Free:389.53 GB) (Model: SAMSUNG MZVLB512HBJQ-000L7) NTFS
 
\\?\Volume{4574aa8f-2317-4bcf-9c02-c733a72f1cac}\ (WinRE_DRV) (Fixed) (Total:1.95 GB) (Free:1.31 GB) NTFS
\\?\Volume{d874ff2f-a813-487a-ae1a-1cc02c2d1c6b}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: 4B8FB9AB)
 
Partition: GPT.
 
==================== End of Addition.txt =======================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-12-2022
Ran by Sue (administrator) on DESKTOP-E2I7FB8 (LENOVO 11JN0072US) (20-12-2022 08:51:28)
Running from C:\Users\Sue\Desktop
Loaded Profiles: Sue
Platform: Microsoft Windows 10 Pro Version 22H2 19045.2364 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBWebConnector3.0\Intuit.QBDT.Webconnector.QBWCMonitor.exe ->) (Intuit, Inc. -> ) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBWebConnector3.0\Intuit.QBDT.Webconnector.Application.exe
(C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantage-(SmartInteractAddin).exe
(C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantage-(VantageCoreAddin).exe
(C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe ->) (Intuit, Inc. -> ) C:\Program Files\Common Files\Intuit\DataProtect\IBuEngHost.exe
(DriverStore\FileRepositoryʹ729.inf_amd64_acb1e75867156c4f\B374580\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepositoryʹ729.inf_amd64_acb1e75867156c4f\B374580\atieclxx.exe
(explorer.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\spool\drivers\x64\3\E_YATIS3E.EXE
(Intuit, Inc. -> Intuit Inc.) C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepositoryʹ729.inf_amd64_acb1e75867156c4f\B374580\atiesrxx.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\piecomponent.inf_amd64_a751a85f0845cf98\Intel_PIE_Service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Intuit Inc.) [File not signed] C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
(services.exe ->) (Intuit, Inc. -> ) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBWebConnector3.0\Intuit.QBDT.Webconnector.QBWCMonitor.exe
(services.exe ->) (Intuit, Inc. -> Intuit Inc.) C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantageService.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\System32\drivers\lenovo\UDC\Service\UDClientService.exe
(services.exe ->) (mc.ntg.co-8edb73 -> ) [File not signed] C:\Program Files\Mesh Agent\MeshAgent.exe <3>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e80fb7173daab733\RtkAudUService64.exe <2>
(services.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21238.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21238.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22102.229.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e80fb7173daab733\RtkAudUService64.exe [3496296 2022-07-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1318024 2021-04-15] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626448 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [MicrosoftEdgeAutoLaunch_48FDC4BBB2BFB3180449326C7B7EF46E] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3879848 2022-12-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIS3E.EXE [416896 2017-09-21] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EPSON ET-2760 Series 64MonitorBE: C:\Windows\system32\E_YLMBS3E.DLL [187392 2018-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\Windows\system32\enppmon.dll [500736 2016-09-14] (SEIKO EPSON CORPORATION) [File not signed]
HKLM\...\Print\Monitors\HP Standard TCP/IP Port: C:\Windows\system32\HpTcpMon.dll [331264 2009-09-16] (Hewlett Packard) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\108.0.5359.125\Installer\chrmstp.exe [2022-12-15] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk [2022-11-22]
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit, Inc. -> Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk [2022-11-22]
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files\Intuit\QuickBooks 2023\QBW.EXE (Intuit, Inc. -> Intuit Inc.)
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0EB2FD9D-A4AF-4F07-A043-656EF3843AA6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-27] (Adobe Inc. -> Adobe Inc.)
Task: {139615F1-B783-4CAF-AF94-3AA2334EDAFB} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin => C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\ScheduleEventAction.exe [27480 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
Task: {1CAB845A-EFB0-45A2-8DE1-3F65EFFF3F5A} - System32\Tasks\MicrosoftEdgeShadowStackRollbackTask => C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.54\Installer\setup.exe [3367848 2022-12-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {216A41D9-449D-40CD-9B91-6363FDB405B6} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3259427507-1055586877-3198061443-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189072 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {309C78F5-DFCA-45BE-8FAF-EF9ADB6547E7} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoCompanionAppAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\ScheduleEventAction.exe [27480 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
Task: {3939AB69-A43B-4561-9C6A-54A431D17C1A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {3A6C6083-5B8D-4A0F-95EF-8AB6A60CC0CB} - System32\Tasks\Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance => %systemroot%\system32\sc.exe start LenovoVantageService
Task: {5AF9E179-DCF7-4B52-BFAF-58D538B3A142} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {5D5D2BAA-F528-4590-A803-A5A97DA5F42F} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189072 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {81E1AB3E-DC23-4A44-AD8E-E13D982CFFF3} - System32\Tasks\Lenovo\UDC\Lenovo UDC Monitor => C:\Windows\system32\drivers\lenovo\udc\data\InfBackup\UdcInfInstaller.exe [184656 2022-05-23] (Lenovo -> Lenovo Group Ltd.)
Task: {8E12C014-148F-4780-B94E-9019E0B9662D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {98015232-CD73-4C11-9D9E-47E4A8926F7D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {9F8516B3-965D-4CB4-84C8-3BA797197D41} - System32\Tasks\GoogleUpdateTaskMachineUA{7502EB32-9AA7-4409-A70A-5A0A783A8CB9} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [171480 2022-11-10] (Google LLC -> Google LLC)
Task: {B7132DD9-FFA7-41BB-988F-5FC331B9ECF9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BA16315F-9972-4FB7-BD4A-CE05647C3C37} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {BB757E02-9F4B-4F18-8E3D-EEEADB5E35B4} - System32\Tasks\Lenovo\UDC\Lenovo UDC Idle Monitor => C:\windows\system32\drivers\Lenovo\udc\Service\UDCUserAgent.exe [89408 2022-05-23] (Lenovo -> Lenovo Group Ltd.)
Task: {BBDB025B-950A-4C54-A6AC-9D087FAF158F} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoSystemUpdateAddin_WeeklyTask => C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\ScheduleEventAction.exe [27480 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
Task: {C4029849-3F83-4719-8545-B464C0A68920} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DA835E9F-8961-416B-819A-392E76426410} - System32\Tasks\GoogleUpdateTaskMachineCore{6A2DD8C7-7DB0-46A7-AC32-0FD8EC7C636A} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [171480 2022-11-10] (Google LLC -> Google LLC)
Task: {E633E663-F2CB-4D3F-A86B-A1E0FA3DA379} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [146816 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {FD787C0A-F968-4283-A769-D9319DE7F622} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ac8a25b1-8e84-445b-8d31-2b270eb6de82}: [DhcpNameServer] 192.168.1.1
 
Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Sue\AppData\Local\Microsoft\Edge\User Data\Default [2022-12-20]
Edge HomePage: Default -> hxxp://www.msn.com/?pc=DCTE
Edge Extension: (URL Safety) - C:\Users\Sue\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\plkaklmpcfkechocmkmhjheonopjbnpo [2022-11-10]
 
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-16] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-10-16] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-16] (Microsoft Corporation -> Microsoft Corporation)
 
Chrome: 
=======
CHR Profile: C:\Users\Sue\AppData\Local\Google\Chrome\User Data\Default [2022-12-19]
CHR Extension: (Google Docs Offline) - C:\Users\Sue\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-12-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Sue\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-11-10]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-27] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12540928 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [206304 2020-10-02] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncHelper.exe [3478928 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
R2 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantageService.exe [31072 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
R2 Mesh Agent; C:\Program Files\Mesh Agent\MeshAgent.exe [3457112 2022-11-10] (mc.ntg.co-8edb73 -> ) [File not signed]
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.238.1114.0002\OneDriveUpdaterService.exe [3845008 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
S3 QBFCService; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [65536 2022-10-19] (Intuit Inc.) [File not signed]
R2 QBVSS; C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe [1570816 2022-10-08] (Intuit Inc.) [File not signed]
R2 QBWCMonitor; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBWebConnector3.0\Intuit.QBDT.Webconnector.QBWCMonitor.exe [47384 2022-12-02] (Intuit, Inc. -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [224184 2022-11-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [16196920 2022-11-09] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 UDCService; C:\Windows\System32\drivers\Lenovo\udc\Service\UDClientService.exe [71504 2022-05-23] (Lenovo -> Lenovo Group Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe [3191264 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe [133592 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 HitmanPro38CrusaderBoot; "C:\Users\Sue\Downloads\HitmanPro_x64.exe" /crusader:boot [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [33216 2021-12-02] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepositoryʹ729.inf_amd64_acb1e75867156c4f\B374580\amdkmdag.sys [82880872 2021-12-09] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R0 rtvdevw10; C:\Windows\System32\drivers\rtvdevw10x64.sys [50128 2022-08-18] (Realtek Semiconductor Corp. -> Realtek)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [49568 2022-12-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [473376 2022-12-08] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [99616 2022-12-08] (Microsoft Windows -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-12-20 08:43 - 2022-12-20 08:50 - 000170530 _____ C:\Users\Sue\Desktop\Fixlog.txt
2022-12-19 18:08 - 2022-12-19 18:08 - 302314336 _____ (Malwarebytes) C:\Users\Sue\Downloads\mb4-setup-consumer-4.5.19.229-1.0.1860-1.0.63451.exe
2022-12-19 18:07 - 2022-12-19 18:07 - 002542312 _____ (Malwarebytes) C:\Users\Sue\Downloads\MBSetup-C14E4470.exe
2022-12-19 17:56 - 2022-12-19 17:56 - 000048409 _____ C:\Users\Sue\Desktop\Addition.txt
2022-12-19 17:55 - 2022-12-20 08:51 - 000019096 _____ C:\Users\Sue\Desktop\FRST.txt
2022-12-19 17:54 - 2022-12-20 08:51 - 000000000 ____D C:\FRST
2022-12-19 17:53 - 2022-12-19 17:53 - 002375680 _____ (Farbar) C:\Users\Sue\Desktop\FRST64.exe
2022-12-19 15:03 - 2022-12-19 15:03 - 001494555 _____ C:\Users\Sue\Downloads\CA Weekly Promo_12.19-23_V3_Writable.pdf
2022-12-17 16:38 - 2022-12-17 16:38 - 012166202 _____ C:\Users\Sue\Downloads\2023 Zoetis Petcare Price List.pdf
2022-12-17 16:38 - 2022-12-17 16:38 - 012166202 _____ C:\Users\Sue\Downloads\2023 Zoetis Petcare Price List (1).pdf
2022-12-17 16:37 - 2022-12-17 16:37 - 000046545 _____ C:\Users\Sue\Downloads\Zoetis 2002 End of Year Shipping.pdf
2022-12-17 13:01 - 2022-12-17 13:01 - 000000000 ____D C:\Program Files (x86)\ScreenConnect Client (61e735463d3bf1de)
2022-12-15 16:08 - 2022-12-15 16:08 - 000012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2022-12-15 16:08 - 2022-12-15 16:08 - 000000304 _____ C:\Windows\system32\.crusader
2022-12-15 16:07 - 2022-12-15 16:07 - 000042000 _____ C:\Windows\system32\Drivers\hitmanpro37.sys
2022-12-15 16:06 - 2022-12-15 16:08 - 000000000 ____D C:\ProgramData\HitmanPro
2022-12-15 16:03 - 2022-12-15 16:04 - 000000000 ____D C:\AdwCleaner
2022-12-14 19:10 - 2022-12-14 19:20 - 000000000 ____D C:\Program Files\Immunet
2022-12-14 19:10 - 2022-12-14 19:10 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ImmunetNetworkMonitor_01009.Wdf
2022-12-14 19:10 - 2022-12-14 19:10 - 000000000 ____D C:\ProgramData\Immunet
2022-12-14 18:40 - 2022-12-14 18:40 - 000000000 ____D C:\Users\Sue\AppData\Local\mbam
2022-12-14 18:39 - 2022-12-15 15:54 - 000000000 ____D C:\Program Files\Malwarebytes
2022-12-14 15:41 - 2022-12-15 17:08 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2022-12-14 15:40 - 2022-12-14 15:41 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2022-12-14 15:40 - 2022-12-14 15:41 - 000002139 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-12-14 15:40 - 2022-12-14 15:40 - 000000000 ___RD C:\Users\Default\OneDrive
2022-12-14 06:46 - 2022-12-14 06:46 - 000012367 _____ C:\Windows\system32\DrtmAuthTxt.wim
2022-12-14 06:42 - 2022-12-14 06:43 - 000000000 ___HD C:\$WinREAgent
2022-12-13 12:50 - 2022-12-13 12:50 - 067756032 _____ C:\Users\Sue\Documents\Nov22 Tender Touch Veterinary Care (Backup Dec 13,2022  12 49 PM).QBB
2022-12-13 10:57 - 2022-12-14 15:40 - 000000000 ____D C:\Program Files (x86)\LogMeIn Rescue Applet
2022-12-13 10:56 - 2022-12-13 11:37 - 000000000 ____D C:\Users\Sue\AppData\Local\LogMeIn Rescue Applet
2022-12-13 10:56 - 2022-12-13 10:56 - 000002321 _____ C:\Users\Sue\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HelpDesk.lnk
2022-12-11 15:45 - 2022-12-11 15:45 - 000067703 _____ C:\Users\Sue\Downloads\TaxJurisdictionMonthly-en-us-4023877 (1).pdf
2022-12-11 13:22 - 2022-12-11 13:22 - 000000131 _____ C:\Users\Sue\Downloads\Reimbursements (1).csv
2022-12-11 13:01 - 2022-12-11 13:01 - 000000000 ____D C:\Users\Sue\AppData\LocalLow\Temp
2022-12-11 12:43 - 2022-12-11 12:43 - 000029683 _____ C:\Users\Sue\Downloads\Clinic - 4868_08-01-2022_12-15-2022.csv
2022-12-07 14:56 - 2022-12-07 14:56 - 000178749 _____ C:\Users\Sue\Downloads\Document (3).pdf
2022-12-07 14:56 - 2022-12-07 14:56 - 000178749 _____ C:\Users\Sue\Downloads\Document (2).pdf
2022-12-07 10:51 - 2022-12-07 10:51 - 000178749 _____ C:\Users\Sue\Downloads\Document.pdf
2022-12-07 10:51 - 2022-12-07 10:51 - 000178749 _____ C:\Users\Sue\Downloads\Document (1).pdf
2022-12-07 10:41 - 2022-12-07 10:41 - 000131708 _____ C:\Users\Sue\Downloads\ModelInfectionControlPlan (1).pdf
2022-12-07 10:41 - 2022-12-07 10:41 - 000131708 _____ C:\Users\Sue\Downloads\ModelInfectionControlPlan (1) (1).pdf
2022-12-06 11:46 - 2022-12-06 11:46 - 000431305 _____ C:\Users\Sue\Downloads\INVOICE#716A131.html
2022-12-05 16:33 - 2022-12-05 16:33 - 000034927 _____ C:\Users\Sue\Downloads\Statement.pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041630 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (5).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041630 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (4).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041630 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (3).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041623 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (1).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000025117 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632.pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000025117 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (2).pdf
2022-12-04 14:29 - 2022-12-04 14:29 - 000000000 ____D C:\Users\Sue\Downloads\JAN22_files
2022-12-04 14:28 - 2022-12-04 14:29 - 000431599 _____ C:\Users\Sue\Downloads\JAN22.html
2022-12-04 14:27 - 2022-12-04 14:27 - 000039823 _____ C:\Users\Sue\Downloads\2022-02-28 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000048846 _____ C:\Users\Sue\Downloads\2022-11-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000044339 _____ C:\Users\Sue\Downloads\2022-10-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000041717 _____ C:\Users\Sue\Downloads\2022-03-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000039800 _____ C:\Users\Sue\Downloads\2022-06-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000039458 _____ C:\Users\Sue\Downloads\2022-07-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000039214 _____ C:\Users\Sue\Downloads\2022-09-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000037923 _____ C:\Users\Sue\Downloads\2022-04-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000036161 _____ C:\Users\Sue\Downloads\2022-05-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000020207 _____ C:\Users\Sue\Downloads\2022-08-31 Statement - USB Savings 2632.pdf
2022-12-04 14:03 - 2022-12-04 14:03 - 000002031 _____ C:\Users\Sue\Downloads\Savings - 2632_01-04-2022_12-08-2022.csv
2022-12-04 14:01 - 2022-12-04 14:01 - 000002568 _____ C:\Users\Sue\Downloads\building - 9319_01-01-2022_12-08-2022.csv
2022-12-03 15:21 - 2022-12-03 15:21 - 000119808 _____ C:\Users\Sue\Downloads\100991537_US_ah_2022_12.pdf
2022-12-03 15:20 - 2022-12-03 15:20 - 000068608 _____ C:\Users\Sue\Downloads\Invoice-6100988911.pdf
2022-12-03 15:09 - 2022-12-03 15:09 - 000106591 _____ C:\Users\Sue\Downloads\1c370d69-4218-47f1-8a1d-f5f90d378eb2.pdf
2022-12-02 10:36 - 2022-12-02 10:36 - 000084136 _____ C:\Users\Sue\Downloads\MVS Exclusive Promo DechraNutramax Nov 17-30.pdf
2022-11-30 10:42 - 2022-11-30 10:42 - 001679221 _____ C:\Users\Sue\Downloads\CA Weekly Promo_11.28-12.2_writable.pdf
2022-11-25 14:55 - 2022-11-25 14:55 - 001037515 _____ C:\Users\Sue\Downloads\Video.mov
2022-11-25 10:06 - 2022-11-25 10:06 - 000213027 _____ C:\Users\Sue\Downloads\976468ef-e02f-42ea-9f58-0ee93aa7eb40.pdf
2022-11-23 12:07 - 2022-11-23 12:07 - 000000410 _____ C:\Users\Sue\Downloads\Sue Vet license 2023.htm
2022-11-23 12:07 - 2022-11-23 12:07 - 000000000 ____D C:\Users\Sue\Downloads\Sue Vet license 2023_files
2022-11-23 09:48 - 2022-11-23 09:48 - 014486872 _____ (Glance Networks, Inc.) C:\Users\Sue\Downloads\GlanceGuestSetup_4.17.1 (1).exe
2022-11-23 09:48 - 2022-11-23 09:48 - 000000000 ____D C:\Users\Sue\AppData\Local\Glance
2022-11-23 09:47 - 2022-11-23 09:47 - 014486872 _____ (Glance Networks, Inc.) C:\Users\Sue\Downloads\GlanceGuestSetup_4.17.1.exe
2022-11-22 09:50 - 2022-11-22 09:50 - 000002196 _____ C:\Users\Public\Desktop\QuickBooks Premier Plus Edition 2023.lnk
2022-11-22 09:45 - 2022-11-22 09:47 - 1091567600 _____ (Intuit, Inc. ) C:\Users\Sue\AppData\Roaming\QuickBooksPremierSub2023.exe
2022-11-22 09:42 - 2022-11-22 09:42 - 071151810 _____ (Intuit, Inc. ) C:\Users\Sue\AppData\Roaming\QuickBooksPro2019.exe
2022-11-22 09:42 - 2022-11-22 09:42 - 001620600 _____ () C:\Users\Sue\Downloads\QuickBooks desktop manager (2).exe
2022-11-22 09:39 - 2022-11-22 09:39 - 001620600 _____ () C:\Users\Sue\Downloads\QuickBooks desktop manager (1).exe
2022-11-22 09:38 - 2022-11-22 09:38 - 001620600 _____ () C:\Users\Sue\Downloads\QuickBooks desktop manager.exe
2022-11-21 15:05 - 2022-11-24 01:03 - 000000000 ____D C:\ProgramData\SQL Anywhere 17
2022-11-21 15:03 - 2022-11-21 15:04 - 000000000 ____D C:\quickbooks2022
2022-11-21 14:48 - 2022-11-23 09:45 - 000000000 ____D C:\Users\Sue\AppData\Local\Intuit
2022-11-21 14:48 - 2022-11-22 09:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickBooks
2022-11-21 14:48 - 2022-11-21 14:48 - 000000000 ____D C:\Windows\SysWOW64\spool
2022-11-21 14:48 - 2022-11-21 14:48 - 000000000 ____D C:\Users\Sue\AppData\Roaming\SQL Anywhere 17
2022-11-21 14:48 - 2012-08-15 01:15 - 006525440 _____ (Amyuni Technologies hxxp://www.amyuni.com) C:\Windows\system32\cdintf450_64.dll
2022-11-21 14:48 - 2012-08-15 01:11 - 004809728 _____ (Amyuni Technologies hxxp://www.amyuni.com) C:\Windows\SysWOW64\cdintf450.dll
2022-11-21 14:46 - 2022-12-13 10:58 - 000000000 ____D C:\ProgramData\Intuit
2022-11-21 14:46 - 2022-11-22 09:48 - 000000095 _____ C:\Windows\QBChanUtil_Trigger.ini
2022-11-21 14:46 - 2022-11-22 09:47 - 000000000 ____D C:\ProgramData\Package Cache
2022-11-21 14:46 - 2022-11-22 09:47 - 000000000 ____D C:\Program Files\Intuit
2022-11-21 14:46 - 2022-11-22 09:47 - 000000000 ____D C:\Program Files\Common Files\Intuit
2022-11-21 14:46 - 2022-11-22 09:47 - 000000000 ____D C:\Program Files (x86)\Intuit
2022-11-21 14:43 - 2022-11-21 14:44 - 908359728 _____ (Intuit, Inc. ) C:\Users\Sue\Downloads\QuickBooksPremierSub2022.exe
2022-11-21 14:40 - 2022-12-20 08:46 - 000000000 ___HD C:\Users\Public\Documents\Windows
2022-11-21 14:40 - 2022-11-21 14:40 - 002672640 _____ C:\Users\Sue\Downloads\QuickBooks Setup.msi
2022-11-21 14:39 - 2022-11-22 09:48 - 000000000 ____D C:\Windows\Intuit
2022-11-21 14:36 - 2022-11-21 14:38 - 908359728 _____ (Intuit, Inc. ) C:\Users\Sue\Downloads\Setup_QuickBooksPremierSub2022.exe
2022-11-21 13:47 - 2022-11-22 09:47 - 000000000 ____D C:\Users\Public\Documents\Intuit
2022-11-21 13:44 - 2020-11-26 15:46 - 000002308 _____ C:\Users\Sue\Desktop\Server.rdp
2022-11-21 13:44 - 2019-05-19 13:31 - 731665752 _____ (Intuit, Inc. ) C:\Users\Sue\Desktop\QuickBooksPro2019.exe
2022-11-21 13:44 - 2016-05-26 16:37 - 637513640 _____ (Intuit, Inc. ) C:\Users\Sue\Desktop\QuickBooksPro2016.exe
2022-11-21 13:43 - 2022-11-21 13:43 - 000000000 ____D C:\Users\Sue\Downloads\sensor 1_files
2022-11-21 13:43 - 2022-11-21 13:43 - 000000000 ____D C:\Users\Sue\Downloads\MVSO New Launch Social Media Graphic_09.29_v2.jpg_files
2022-11-21 13:43 - 2022-11-21 13:43 - 000000000 ____D C:\Users\Sue\Downloads\BONIL_files
2022-11-21 13:43 - 2022-11-21 13:43 - 000000000 ____D C:\Users\Sue\Downloads\bank_files
2022-11-21 13:43 - 2022-11-21 13:43 - 000000000 ____D C:\Users\Sue\Downloads\Approval Requests - 7009284_files
2022-11-21 13:43 - 2022-09-17 11:08 - 000000116 _____ C:\Users\Sue\Downloads\payments.csv.crdownload
2022-11-21 13:43 - 2022-08-16 16:38 - 000023028 _____ C:\Users\Sue\Downloads\controlled1.html
2022-11-21 13:43 - 2022-01-15 15:22 - 000597859 _____ C:\Users\Sue\Downloads\w2 2021.pdf
2022-11-21 13:43 - 2021-04-29 11:18 - 002021327 _____ C:\Users\Sue\Downloads\first-aid-checklist (3).pdf
2022-11-21 13:43 - 2021-04-29 11:15 - 002021327 _____ C:\Users\Sue\Downloads\first-aid-checklist (2).pdf
2022-11-21 13:43 - 2021-04-28 11:34 - 002021327 _____ C:\Users\Sue\Downloads\first-aid-checklist (1).pdf
2022-11-21 13:43 - 2021-04-28 11:32 - 002021327 _____ C:\Users\Sue\Downloads\first-aid-checklist.pdf
2022-11-21 13:43 - 2021-04-11 13:01 - 000076440 _____ C:\Users\Sue\Downloads\INWKS941_210411_135949.pdf
2022-11-21 13:43 - 2021-03-24 07:53 - 000358990 _____ C:\Users\Sue\Downloads\bank.html
2022-11-21 13:43 - 2021-02-13 15:55 - 000051325 _____ C:\Users\Sue\Downloads\December 31, 2020 (3).pdf
2022-11-21 13:43 - 2021-02-13 15:44 - 000047031 _____ C:\Users\Sue\Downloads\January 31, 2020 (1).pdf
2022-11-21 13:43 - 2021-02-13 15:44 - 000042706 _____ C:\Users\Sue\Downloads\February 29, 2020 (1).pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000058815 _____ C:\Users\Sue\Downloads\March 31, 2020 (1).pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000051325 _____ C:\Users\Sue\Downloads\December 31, 2020 (1).pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000050666 _____ C:\Users\Sue\Downloads\January 31, 2021.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000046597 _____ C:\Users\Sue\Downloads\November 30, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000045178 _____ C:\Users\Sue\Downloads\October 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000045173 _____ C:\Users\Sue\Downloads\September 30, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000044267 _____ C:\Users\Sue\Downloads\April 30, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000043943 _____ C:\Users\Sue\Downloads\August 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000042571 _____ C:\Users\Sue\Downloads\July 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000042564 _____ C:\Users\Sue\Downloads\June 30, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:43 - 000037135 _____ C:\Users\Sue\Downloads\May 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:30 - 000051325 _____ C:\Users\Sue\Downloads\December 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:29 - 000058815 _____ C:\Users\Sue\Downloads\March 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:29 - 000042706 _____ C:\Users\Sue\Downloads\February 29, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:28 - 000047031 _____ C:\Users\Sue\Downloads\January 31, 2020.pdf
2022-11-21 13:43 - 2021-02-13 15:27 - 000053252 _____ C:\Users\Sue\Downloads\December 31, 2019.pdf
2022-11-21 13:43 - 2021-02-13 15:27 - 000042289 _____ C:\Users\Sue\Downloads\November 30, 2019.pdf
2022-11-21 13:43 - 2021-02-13 15:26 - 000045129 _____ C:\Users\Sue\Downloads\October 31, 2019.pdf
2022-11-21 13:43 - 2021-02-13 15:25 - 000044820 _____ C:\Users\Sue\Downloads\September 30, 2019.pdf
2022-11-21 13:43 - 2021-02-13 15:25 - 000040046 _____ C:\Users\Sue\Downloads\August 31, 2019 (1).pdf
2022-11-21 13:43 - 2021-02-13 15:24 - 000040046 _____ C:\Users\Sue\Downloads\August 31, 2019.pdf
2022-11-21 13:43 - 2021-02-10 13:55 - 000288465 _____ C:\Users\Sue\Downloads\iris-pocket-guide-2.pdf
2022-11-21 13:43 - 2021-02-08 10:56 - 000029431 _____ C:\Users\Sue\Downloads\TaxJurisdictionAnnually-en-us-4023877.mht
2022-11-21 13:43 - 2021-02-08 10:51 - 000084450 _____ C:\Users\Sue\Downloads\SVM00813-PBV00887.pdf
2022-11-21 13:43 - 2021-02-08 10:51 - 000084450 _____ C:\Users\Sue\Downloads\SVM00813-PBV00887 (1).pdf
2022-11-21 13:43 - 2021-02-05 16:55 - 000030393 _____ C:\Users\Sue\Downloads\14575.pdf
2022-11-21 13:43 - 2021-02-05 16:54 - 000067789 _____ C:\Users\Sue\Downloads\Inv_4816_from_Klings_Lawn__Landscape_LLC._5392.pdf
2022-11-21 13:43 - 2021-01-18 14:35 - 000000082 _____ C:\Users\Sue\Downloads\GlCodeSummaryReport_284360_001_20210118_153329 (2).csv
2022-11-21 13:43 - 2021-01-18 14:34 - 000020463 _____ C:\Users\Sue\Downloads\GlCodeDetailReport_284360_001_20210118_153329.csv
2022-11-21 13:43 - 2021-01-18 14:33 - 000000082 _____ C:\Users\Sue\Downloads\GlCodeSummaryReport_284360_001_20210118_153329.csv
2022-11-21 13:43 - 2021-01-18 14:33 - 000000082 _____ C:\Users\Sue\Downloads\GlCodeSummaryReport_284360_001_20210118_153329 (1).csv
2022-11-21 13:43 - 2021-01-10 15:46 - 000153983 _____ C:\Users\Sue\Downloads\11975871.pdf
2022-11-21 13:43 - 2021-01-10 15:46 - 000153983 _____ C:\Users\Sue\Downloads\11975871 (1).pdf
2022-11-21 13:43 - 2021-01-10 13:05 - 000067405 _____ C:\Users\Sue\Downloads\Inv_4783_from_Klings_Lawn__Landscape_LLC._1664.pdf
2022-11-21 13:43 - 2021-01-10 13:05 - 000067405 _____ C:\Users\Sue\Downloads\Inv_4783_from_Klings_Lawn__Landscape_LLC._1664 (1).pdf
2022-11-21 13:43 - 2020-12-06 16:30 - 000083963 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-11.pdf
2022-11-21 13:43 - 2020-12-06 16:28 - 000142603 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011987634.pdf
2022-11-21 13:43 - 2020-12-06 16:28 - 000083109 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011874619.pdf
2022-11-21 13:43 - 2020-12-06 16:28 - 000083109 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011874619 (1).pdf
2022-11-21 13:43 - 2020-12-06 16:28 - 000083087 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011874647.pdf
2022-11-21 13:43 - 2020-12-04 14:18 - 000042842 _____ C:\Users\Sue\Downloads\M234427803.PDF
2022-11-21 13:43 - 2020-12-04 14:17 - 000040366 _____ C:\Users\Sue\Downloads\M074018230.PDF
2022-11-21 13:43 - 2020-12-04 14:17 - 000040366 _____ C:\Users\Sue\Downloads\M074018230 (1).PDF
2022-11-21 13:43 - 2020-11-14 14:44 - 000301438 _____ C:\Users\Sue\Downloads\October 30, 2020.pdf
2022-11-21 13:43 - 2020-11-14 14:44 - 000301438 _____ C:\Users\Sue\Downloads\October 30, 2020 (1).pdf
2022-11-21 13:43 - 2020-11-14 12:06 - 000078641 _____ C:\Users\Sue\Downloads\October 23, 2020.pdf
2022-11-21 13:43 - 2020-11-10 10:14 - 001096493 _____ C:\Users\Sue\Downloads\Client information packet.zip
2022-11-21 13:43 - 2020-11-10 10:14 - 001096493 _____ C:\Users\Sue\Downloads\Client information packet (1).zip
2022-11-21 13:43 - 2020-11-07 15:42 - 000046479 _____ C:\Users\Sue\Downloads\midwestvet_4023877_20201101_8252840_2539518666 (1).pdf
2022-11-21 13:43 - 2020-11-07 15:39 - 000046479 _____ C:\Users\Sue\Downloads\midwestvet_4023877_20201101_8252840_2539518666.pdf
2022-11-21 13:43 - 2020-11-07 15:32 - 000153969 _____ C:\Users\Sue\Downloads\11543996.pdf
2022-11-21 13:43 - 2020-10-26 07:12 - 000153947 _____ C:\Users\Sue\Downloads\11679460.pdf
2022-11-21 13:43 - 2020-10-26 07:12 - 000153947 _____ C:\Users\Sue\Downloads\11679460 (1).pdf
2022-11-21 13:43 - 2020-10-19 14:07 - 001488986 _____ C:\Users\Sue\Downloads\05a Vetwatch Commentary-Week 40.pdf
2022-11-21 13:43 - 2020-10-15 13:55 - 001914679 _____ C:\Users\Sue\Downloads\VS.VEHCS Flier July 2020.pdf
2022-11-21 13:43 - 2020-10-15 13:55 - 000252928 _____ C:\Users\Sue\Downloads\Q3 NVAP Newsletter - supplemental export newsletter for SC  Madison (3).pub
2022-11-21 13:43 - 2020-10-15 13:54 - 000252928 _____ C:\Users\Sue\Downloads\Q3 NVAP Newsletter - supplemental export newsletter for SC  Madison.pub
2022-11-21 13:43 - 2020-10-15 13:54 - 000252928 _____ C:\Users\Sue\Downloads\Q3 NVAP Newsletter - supplemental export newsletter for SC  Madison (2).pub
2022-11-21 13:43 - 2020-10-15 13:54 - 000252928 _____ C:\Users\Sue\Downloads\Q3 NVAP Newsletter - supplemental export newsletter for SC  Madison (1).pub
2022-11-21 13:43 - 2020-10-15 13:27 - 000138734 _____ C:\Users\Sue\Downloads\Approval Requests - 7009284.html
2022-11-21 13:43 - 2020-10-06 12:52 - 000088977 _____ C:\Users\Sue\Downloads\ResumeAshleyToledo.pdf
2022-11-21 13:43 - 2020-10-05 07:13 - 000530604 _____ C:\Users\Sue\Downloads\MVSO New Launch Social Media Graphic_09.29_v2.jpg.html
2022-11-21 13:43 - 2020-09-20 12:06 - 000084698 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-04.pdf
2022-11-21 13:43 - 2020-09-20 12:06 - 000084698 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-04 (1).pdf
2022-11-21 13:43 - 2020-09-20 12:06 - 000084489 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-03.pdf
2022-11-21 13:43 - 2020-09-20 12:06 - 000084489 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-03 (1).pdf
2022-11-21 13:43 - 2020-09-20 12:06 - 000084272 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-01.pdf
2022-11-21 13:43 - 2020-09-20 12:06 - 000084272 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-01 (1).pdf
2022-11-21 13:43 - 2020-09-20 12:05 - 000084469 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-07.pdf
2022-11-21 13:43 - 2020-09-20 12:05 - 000084335 _____ C:\Users\Sue\Downloads\Zoetis-statement-2020-08.pdf
2022-11-21 13:43 - 2020-09-19 17:18 - 000001711 _____ C:\Users\Sue\Downloads\ph_wFQCA3.CSV
2022-11-21 13:43 - 2020-09-19 17:16 - 000164526 _____ C:\Users\Sue\Downloads\dnld20200919191635.pdf
2022-11-21 13:43 - 2020-09-19 17:15 - 001693563 _____ C:\Users\Sue\Downloads\dnld20200919191540.pdf
2022-11-21 13:43 - 2020-09-19 17:03 - 000110673 _____ C:\Users\Sue\Downloads\dnld20200919190346.pdf
2022-11-21 13:43 - 2020-09-19 16:47 - 000305087 _____ C:\Users\Sue\Downloads\dnld20200919184746.pdf
2022-11-21 13:43 - 2020-09-19 16:47 - 000305087 _____ C:\Users\Sue\Downloads\dnld20200919184744.pdf
2022-11-21 13:43 - 2020-09-19 16:41 - 000083069 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011319753.pdf
2022-11-21 13:43 - 2020-09-19 16:40 - 000082873 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9011072887.pdf
2022-11-21 13:43 - 2020-08-16 13:45 - 000048336 _____ C:\Users\Sue\Downloads\Credit Card Agreement Form.pdf
2022-11-21 13:43 - 2020-08-15 17:39 - 000078513 _____ C:\Users\Sue\Downloads\July 23, 2020.pdf
2022-11-21 13:43 - 2020-08-14 12:36 - 000037544 _____ C:\Users\Sue\Downloads\ResumeDanielleJohnson.pdf
2022-11-21 13:43 - 2020-08-14 12:36 - 000036951 _____ C:\Users\Sue\Downloads\ResumeMariaPrzislicki.pdf
2022-11-21 13:43 - 2020-08-11 08:00 - 000131640 _____ C:\Users\Sue\Downloads\boni lacross Rabies certficate (1).pdf
2022-11-21 13:43 - 2020-08-11 07:57 - 000131640 _____ C:\Users\Sue\Downloads\boni lacross Rabies certficate.pdf
2022-11-21 13:43 - 2020-08-11 07:51 - 000789989 _____ C:\Users\Sue\Downloads\Boni Lacross paperwork for travel 2.pdf
2022-11-21 13:43 - 2020-08-10 16:04 - 000458831 _____ C:\Users\Sue\Downloads\Boni Lacross paperwork of travel.pdf
2022-11-21 13:43 - 2020-08-10 15:52 - 002359472 _____ C:\Users\Sue\Downloads\Boni Lacross.pdf
2022-11-21 13:43 - 2020-08-10 15:52 - 002359472 _____ C:\Users\Sue\Downloads\Boni Lacross (1).pdf
2022-11-21 13:43 - 2020-08-10 11:31 - 000063040 _____ C:\Users\Sue\Downloads\BONIL.html
2022-11-21 13:43 - 2020-08-01 09:19 - 000082926 _____ C:\Users\Sue\Downloads\Zoetis-invoice-9010929400.pdf
2022-11-21 13:43 - 2020-07-31 15:20 - 000045292 _____ C:\Users\Sue\Downloads\Sue20200731_13321631.pdf
2022-11-21 13:43 - 2020-07-31 15:20 - 000045292 _____ C:\Users\Sue\Downloads\Sue20200731_13321631 (2).pdf
2022-11-21 13:43 - 2020-07-31 15:20 - 000045292 _____ C:\Users\Sue\Downloads\Sue20200731_13321631 (1).pdf
2022-11-21 13:43 - 2020-07-28 10:14 - 000030738 _____ C:\Users\Sue\Downloads\CPV2 CDV Results C Klamert Webster  July 2020.pdf
2022-11-21 13:43 - 2020-07-28 09:19 - 000042060 _____ C:\Users\Sue\Downloads\ResumeLoriBierman.pdf
2022-11-21 13:43 - 2020-07-28 09:19 - 000042060 _____ C:\Users\Sue\Downloads\ResumeLoriBierman (1).pdf
2022-11-21 13:43 - 2020-07-27 07:49 - 000035963 _____ C:\Users\Sue\Downloads\ResumeCourtneyThistle.pdf
2022-11-21 13:43 - 2020-07-27 07:49 - 000035963 _____ C:\Users\Sue\Downloads\ResumeCourtneyThistle (1).pdf
2022-11-21 13:43 - 2020-07-25 11:53 - 000094387 _____ C:\Users\Sue\Downloads\sensor 1.pdf
2022-11-21 13:43 - 2020-07-25 11:35 - 000090787 _____ C:\Users\Sue\Downloads\VEHCS flyer_MARCH 2017 (1).pdf
2022-11-21 13:43 - 2020-07-25 11:29 - 000341449 _____ C:\Users\Sue\Downloads\AVMA Poster VEHCS.PDF
2022-11-21 13:43 - 2020-07-25 11:27 - 000090787 _____ C:\Users\Sue\Downloads\VEHCS flyer_MARCH 2017.pdf
2022-11-21 13:43 - 2020-07-25 11:24 - 000041290 _____ C:\Users\Sue\Downloads\M011214551.PDF
2022-11-21 13:43 - 2020-07-25 11:24 - 000041290 _____ C:\Users\Sue\Downloads\M011214551 (1).PDF
2022-11-21 13:43 - 2020-07-23 12:40 - 000127688 _____ C:\Users\Sue\Downloads\CBS August 2020.pptx
2022-11-21 13:43 - 2020-07-23 12:40 - 000127688 _____ C:\Users\Sue\Downloads\CBS August 2020 (1).pptx
2022-11-21 13:43 - 2020-07-17 15:37 - 000605107 _____ C:\Users\Sue\Downloads\image1.jpeg
2022-11-21 13:43 - 2020-07-17 15:36 - 000666325 _____ C:\Users\Sue\Downloads\image0 (2).jpeg
2022-11-21 13:43 - 2020-07-17 15:36 - 000659535 _____ C:\Users\Sue\Downloads\image0 (1).jpeg
2022-11-21 13:43 - 2020-07-17 15:32 - 000659535 _____ C:\Users\Sue\Downloads\image0.jpeg
2022-11-21 13:43 - 2020-07-17 13:15 - 000132110 _____ C:\Users\Sue\Downloads\REPORT_ Sammy Name_ Beringer^Sammy^^^ Species_ CANINE At Tender Touch Veterinary Care.pdf
2022-11-21 13:43 - 2020-07-15 17:50 - 000583246 _____ C:\Users\Sue\Downloads\sensor 1.html
2022-11-21 13:43 - 2020-04-18 09:07 - 002238453 _____ C:\Users\Sue\Downloads\PPP1.pdf
2022-11-21 13:43 - 2020-04-18 09:07 - 000111748 _____ C:\Users\Sue\Downloads\ppp2.pdf
2022-11-21 13:43 - 2020-04-07 15:10 - 003713997 _____ C:\Users\Sue\Downloads\Gravity_Documents_for_Tender_Touch_Veterinary.pdf
2022-11-21 13:43 - 2020-04-02 10:22 - 000044185 _____ C:\Users\Sue\Downloads\ResumeCharityNelson.pdf
2022-11-21 13:43 - 2020-03-31 17:04 - 000068646 _____ C:\Users\Sue\Downloads\magnet.pdf
2022-11-21 13:43 - 2020-02-14 14:57 - 000036657 _____ C:\Users\Sue\Downloads\mortgage 2020 part 2.pdf
2022-11-21 13:43 - 2020-02-14 14:56 - 000113023 _____ C:\Users\Sue\Downloads\Tender Touch Renewal2020 mortgage.pdf
2022-11-21 13:43 - 2019-10-08 14:07 - 000085272 _____ C:\Users\Sue\Downloads\ConnectWiseControl.Client (2).exe
2022-11-21 13:43 - 2019-10-01 12:20 - 000630331 _____ C:\Users\Sue\Downloads\6291FD2D-3380-4574-913C-97C80B8AE5A2.pdf
2022-11-21 13:43 - 2019-09-03 15:21 - 000075853 _____ C:\Users\Sue\Downloads\aero.txt
2022-11-21 13:43 - 2019-01-11 11:44 - 000054561 _____ C:\Users\Sue\Downloads\February 28, 2018 (1).pdf
2022-11-21 13:43 - 2019-01-11 11:43 - 000042175 _____ C:\Users\Sue\Downloads\April 30, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:43 - 000040277 _____ C:\Users\Sue\Downloads\January 31, 2018 (2).pdf
2022-11-21 13:43 - 2019-01-11 11:43 - 000037068 _____ C:\Users\Sue\Downloads\March 31, 2018 (1).pdf
2022-11-21 13:43 - 2019-01-11 11:42 - 000042147 _____ C:\Users\Sue\Downloads\May 31, 2018 (1).pdf
2022-11-21 13:43 - 2019-01-11 11:42 - 000037085 _____ C:\Users\Sue\Downloads\June 30, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:41 - 000042283 _____ C:\Users\Sue\Downloads\July 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:38 - 000041815 _____ C:\Users\Sue\Downloads\October 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000054561 _____ C:\Users\Sue\Downloads\February 28, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000043434 _____ C:\Users\Sue\Downloads\September 30, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000042158 _____ C:\Users\Sue\Downloads\December 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000042158 _____ C:\Users\Sue\Downloads\December 31, 2018 (1).pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000042155 _____ C:\Users\Sue\Downloads\August 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000042147 _____ C:\Users\Sue\Downloads\May 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000040519 _____ C:\Users\Sue\Downloads\November 30, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:37 - 000037068 _____ C:\Users\Sue\Downloads\March 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:36 - 000040277 _____ C:\Users\Sue\Downloads\January 31, 2018.pdf
2022-11-21 13:43 - 2019-01-11 11:36 - 000040277 _____ C:\Users\Sue\Downloads\January 31, 2018 (1).pdf
2022-11-21 13:43 - 2019-01-11 11:30 - 000414497 _____ C:\Users\Sue\Downloads\Amortization_Schedule (4).pdf
2022-11-21 13:43 - 2019-01-11 11:28 - 000414442 _____ C:\Users\Sue\Downloads\Amortization_Schedule (3).pdf
2022-11-21 13:43 - 2019-01-08 12:03 - 000186549 _____ C:\Users\Sue\Downloads\Vet License.pdf
2022-11-21 13:43 - 2019-01-01 14:01 - 002491413 _____ C:\Users\Sue\Downloads\AVImark-End-of-the-Year-FAQs.pdf
2022-11-21 13:43 - 2018-12-04 13:39 - 000417558 _____ C:\Users\Sue\Downloads\Amortization_Schedule (2).pdf
2022-11-21 13:43 - 2018-11-15 17:21 - 000027476 _____ C:\Users\Sue\Downloads\export 1.csv
2022-11-21 13:43 - 2018-08-19 12:45 - 000034657 _____ C:\Users\Sue\Downloads\July 23, 2018.pdf
2022-11-21 13:43 - 2018-08-19 12:45 - 000034657 _____ C:\Users\Sue\Downloads\July 23, 2018 (1).pdf
2022-11-21 13:43 - 2018-04-22 07:04 - 000439287 _____ C:\Users\Sue\Downloads\Amortization_Schedule (1).pdf
2022-11-21 13:43 - 2018-03-25 09:24 - 000443812 _____ C:\Users\Sue\Downloads\Amortization_Schedule.pdf
2022-11-21 13:43 - 2018-02-15 16:48 - 000841268 _____ C:\Users\Sue\Downloads\Royal 2018.pdf
2022-11-21 13:43 - 2017-12-26 18:02 - 000347897 _____ C:\Users\Sue\Downloads\international cert Shilio.pdf
2022-11-21 13:43 - 2017-10-25 14:27 - 000381821 _____ C:\Users\Sue\Downloads\Ann Gutting 2018 COI plit.pdf
2022-11-21 13:43 - 2017-10-25 14:25 - 000187137 _____ C:\Users\Sue\Downloads\Gutting 2019 wi license.pdf
2022-11-21 13:43 - 2017-09-19 13:26 - 445123208 _____ (Intuit Inc.) C:\Users\Sue\Downloads\qbwebpatch.exe
2022-11-21 13:43 - 2017-06-07 11:10 - 002833655 _____ C:\Users\Sue\Downloads\[Untitled] (2).pdf
2022-11-21 13:43 - 2017-06-07 10:57 - 000154944 _____ C:\Users\Sue\Downloads\[Untitled] (1).pdf
2022-11-21 13:43 - 2017-05-30 08:23 - 000684067 _____ C:\Users\Sue\Downloads\VGP Overview Sheet.pdf
2022-11-21 13:43 - 2017-05-30 08:19 - 000726779 _____ C:\Users\Sue\Downloads\VGP 2017 June Pathway Planning Workshop Flyer_Chicago_Rd03.pdf
2022-11-21 13:43 - 2017-05-24 16:21 - 006262463 _____ C:\Users\Sue\Downloads\MER-17022_Summer_Sell-in_Promotion_detailer_Scroll indd.pdf
2022-11-21 13:43 - 2017-05-24 16:19 - 000102364 _____ C:\Users\Sue\Downloads\Suggested Order for TENDER TOUCH__ VET CARE-TENDER TOUCH VET CARE - 051917....pdf
2022-11-21 13:43 - 2017-05-21 09:30 - 000003554 _____ C:\Users\Sue\Downloads\sigimg0
2022-11-21 13:43 - 2017-05-21 09:30 - 000003503 _____ C:\Users\Sue\Downloads\sigimg1
2022-11-21 13:43 - 2017-05-10 10:21 - 000332456 _____ C:\Users\Sue\Downloads\Customizing Treatment Options (3).pdf
2022-11-21 13:43 - 2017-05-10 08:17 - 000625606 _____ C:\Users\Sue\Downloads\CYT  Recommended Order Sell Sheet.pdf
2022-11-21 13:43 - 2017-05-10 08:15 - 000765038 _____ C:\Users\Sue\Downloads\CYT Dosing Cling .pdf
2022-11-21 13:43 - 2017-05-10 08:12 - 000332456 _____ C:\Users\Sue\Downloads\Customizing Treatment Options.pdf
2022-11-21 13:43 - 2017-05-10 08:12 - 000332456 _____ C:\Users\Sue\Downloads\Customizing Treatment Options (2).pdf
2022-11-21 13:43 - 2017-05-10 08:12 - 000332456 _____ C:\Users\Sue\Downloads\Customizing Treatment Options (1).pdf
2022-11-21 13:43 - 2017-05-10 08:11 - 001244205 _____ C:\Users\Sue\Downloads\CYT Now Available Flyer  (Color) -.pdf
2022-11-21 13:43 - 2017-05-02 16:44 - 000142364 _____ C:\Users\Sue\Downloads\[Untitled].pdf
2022-11-21 13:43 - 2017-04-26 16:06 - 000774086 _____ C:\Users\Sue\Downloads\CatFoodProteinFatCarbPhosphorusChart.pdf
2022-11-21 13:43 - 2017-04-21 15:49 - 001364249 _____ C:\Users\Sue\Downloads\Tender Touch Veterinary Care - IT Support Plans and Estimate.pdf
2022-11-21 13:43 - 2017-04-10 09:40 - 000107100 _____ C:\Users\Sue\Downloads\20003110 Tender Touch Vet Care - Bladview 4343R CSI (1).pdf
2022-11-21 13:43 - 2017-04-10 09:20 - 000107100 _____ C:\Users\Sue\Downloads\20003110 Tender Touch Vet Care - Bladview 4343R CSI.pdf
2022-11-21 13:43 - 2017-03-24 12:42 - 000128358 _____ C:\Users\Sue\Downloads\Tender Touch Veterinary Care 03-24-17_v1.pdf
2022-11-21 13:43 - 2017-03-24 12:41 - 000437797 _____ C:\Users\Sue\Downloads\Computers Supplied by VetRay Technologies.pdf
2022-11-21 13:43 - 2017-03-24 08:14 - 000015147 _____ C:\Users\Sue\Downloads\Vet exposure chart_V20170321.xlsx
2022-11-21 13:43 - 2017-03-22 09:03 - 000952320 _____ C:\Users\Sue\Downloads\20003110 Tender Touch Vet Care - Bladview 4343R CSI (EVB).xls
2022-11-21 13:43 - 2017-03-15 13:47 - 000333594 _____ C:\Users\Sue\Downloads\1 Brochure Precision DR C 1417 Low 1500L C.pdf
2022-11-21 13:43 - 2017-03-15 13:47 - 000333594 _____ C:\Users\Sue\Downloads\1 Brochure Precision DR C 1417 Low 1500L C (2).pdf
2022-11-21 13:43 - 2017-03-15 13:47 - 000333594 _____ C:\Users\Sue\Downloads\1 Brochure Precision DR C 1417 Low 1500L C (1).pdf
2022-11-21 13:43 - 2017-03-06 10:53 - 000115396 _____ C:\Users\Sue\Downloads\2016-09-29_Education Coordinator.pdf
2022-11-21 13:43 - 2017-02-27 13:56 - 000430284 _____ C:\Users\Sue\Downloads\fluhr 2-26.pdf
2022-11-21 13:43 - 2017-02-21 12:31 - 000144714 _____ C:\Users\Sue\Downloads\Invoice INV211128487.pdf
2022-11-21 13:43 - 2017-02-07 15:28 - 000026241 _____ C:\Users\Sue\Downloads\ResumeJudiMihas.pdf
2022-11-21 13:43 - 2017-02-05 12:23 - 000008470 _____ C:\Users\Sue\Downloads\ResumeEmilyOgnenoff.pdf
2022-11-21 13:43 - 2017-02-05 12:20 - 000014677 _____ C:\Users\Sue\Downloads\ResumeSamanthaMiller.pdf
2022-11-21 13:43 - 2017-02-05 12:14 - 000188316 _____ C:\Users\Sue\Downloads\7152218001_20170204_191532.wav
2022-11-21 13:43 - 2017-02-05 12:14 - 000101286 _____ C:\Users\Sue\Downloads\6082890689_20170205_075711.wav
2022-11-21 13:43 - 2017-02-05 12:14 - 000098935 _____ C:\Users\Sue\Downloads\2622241144_20170204_182321.wav
2022-11-21 13:43 - 2017-02-05 12:13 - 000096663 _____ C:\Users\Sue\Downloads\8003090524_20170205_115430.wav
2022-11-21 13:43 - 2017-02-05 12:13 - 000096663 _____ C:\Users\Sue\Downloads\8003090524_20170205_115430 (1).wav
2022-11-21 13:43 - 2017-01-25 16:44 - 000166335 _____ C:\Users\Sue\Downloads\2629394965_20170125_162055.wav
2022-11-21 13:43 - 2017-01-18 15:30 - 000103652 _____ C:\Users\Sue\Downloads\Statement 305310.pdf
2022-11-21 13:43 - 2017-01-09 10:29 - 000221798 _____ C:\Users\Sue\Downloads\sales and use 2015.pdf
2022-11-21 13:43 - 2017-01-06 13:09 - 000034603 _____ C:\Users\Sue\Downloads\Invoice-000114-01_05_2017.pdf
2022-11-21 13:43 - 2017-01-02 08:50 - 000038442 _____ C:\Users\Sue\Downloads\Invoice-000111-12_31_2016.pdf
2022-11-21 13:43 - 2016-12-07 14:48 - 000004143 _____ C:\Users\Sue\Downloads\Invoice- Beth.pdf
2022-11-21 13:43 - 2016-11-30 12:34 - 000137380 _____ C:\Users\Sue\Downloads\2626896424_20161130_122602.wav
2022-11-21 13:43 - 2016-11-25 17:12 - 000035830 _____ C:\Users\Sue\Downloads\Invoice-000108-11_22_2016.pdf
2022-11-21 13:43 - 2016-11-11 16:02 - 000109107 _____ C:\Users\Sue\Downloads\Suggested Order for TENDER TOUCH__ VET CARE-2016 Winter Sell-In PromotionTrue.pdf
2022-11-21 13:43 - 2016-11-07 17:25 - 000091023 _____ C:\Users\Sue\Downloads\M16-27013_F_20161107113339 (2).PDF
2022-11-21 13:43 - 2016-11-07 17:24 - 000091279 _____ C:\Users\Sue\Downloads\M16-27013_P_20161006180202.PDF
2022-11-21 13:43 - 2016-11-07 16:58 - 000091023 _____ C:\Users\Sue\Downloads\M16-27013_F_20161107113339 (1).PDF
2022-11-21 13:43 - 2016-11-07 16:56 - 000091023 _____ C:\Users\Sue\Downloads\M16-27013_F_20161107113339.PDF
2022-11-21 13:43 - 2016-10-31 12:42 - 000042114 _____ C:\Users\Sue\Downloads\Invoice-000107-10_28_2016.pdf
2022-11-21 13:43 - 2016-10-05 16:09 - 000126392 _____ C:\Users\Sue\Downloads\RptAccPrint.pdf
2022-11-21 13:43 - 2016-10-02 11:03 - 000035717 _____ C:\Users\Sue\Downloads\Invoice-000097-09_30_2016.pdf
2022-11-21 13:43 - 2016-09-23 14:25 - 000385460 _____ C:\Users\Sue\Downloads\F1683216.pdf
2022-11-21 13:43 - 2016-08-31 10:42 - 000034924 _____ C:\Users\Sue\Downloads\Invoice-000095-08_30_2016.pdf
2022-11-21 13:43 - 2016-08-05 09:26 - 000385792 _____ C:\Users\Sue\Downloads\F1667213.pdf
2022-11-21 13:43 - 2016-07-27 13:38 - 000063603 _____ C:\Users\Sue\Downloads\Lab Report - 094-026472-A01.pdf
2022-11-21 13:43 - 2016-07-27 13:38 - 000063603 _____ C:\Users\Sue\Downloads\Lab Report - 094-026472-A01 (1).pdf
2022-11-21 13:43 - 2016-07-25 12:00 - 000246416 _____ C:\Users\Sue\Downloads\7.4.27 - Public Relations Coordinator.pdf
2022-11-21 13:43 - 2016-07-18 13:19 - 000209516 _____ C:\Users\Sue\Downloads\Grrow,Elsa-paper file bldwork.pdf
2022-11-21 13:43 - 2016-07-14 13:19 - 000344268 _____ C:\Users\Sue\Downloads\bugatti gundrum international certificate (2).pdf
2022-11-21 13:43 - 2016-07-14 13:08 - 000342933 _____ C:\Users\Sue\Downloads\bugatti gundrum international certificate (1).pdf
2022-11-21 13:43 - 2016-07-14 13:07 - 000342933 _____ C:\Users\Sue\Downloads\bugatti gundrum international certificate.pdf
2022-11-21 13:43 - 2016-07-13 08:47 - 001600002 _____ C:\Users\Sue\Downloads\mod09_web_completion_certificate (1).pdf
2022-11-21 13:43 - 2016-07-13 08:38 - 001600002 _____ C:\Users\Sue\Downloads\mod09_web_completion_certificate.pdf
2022-11-21 13:43 - 2016-07-13 08:38 - 001583676 _____ C:\Users\Sue\Downloads\mod07_web_completion_certificate.pdf
2022-11-21 13:43 - 2016-07-13 08:38 - 001583676 _____ C:\Users\Sue\Downloads\mod07_web_completion_certificate (1).pdf
2022-11-21 13:43 - 2016-07-13 08:37 - 000904469 _____ C:\Users\Sue\Downloads\mod10_web_completion_certificate.pdf
2022-11-21 13:43 - 2016-06-27 10:51 - 000445248 _____ C:\Users\Sue\Downloads\document-0.pdf
2022-11-21 13:43 - 2016-06-06 12:59 - 166179864 _____ (Kaspersky Lab) C:\Users\Sue\Downloads\kts16.0.1.445abcen_10308 (1).exe
2022-11-21 13:43 - 2016-06-06 10:53 - 166179864 _____ (Kaspersky Lab) C:\Users\Sue\Downloads\kts16.0.1.445abcen_10308.exe
2022-11-21 13:43 - 2016-05-31 09:59 - 000035981 _____ C:\Users\Sue\Downloads\Invoice-000082-05_27_2016.pdf
2022-11-21 13:43 - 2016-05-26 16:30 - 000537328 _____ C:\Users\Sue\Downloads\Setup_QuickBooksPro2016.exe
2022-11-21 13:43 - 2016-05-26 16:26 - 001838632 _____ (LogMeIn, Inc.) C:\Users\Sue\Downloads\Support-LogMeInRescue.exe
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\winnie_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\U.S. Bank - My Loan2-20-22_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\RenderReport_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\Online Return Center_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\lock box_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\license 2023_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\licence 2023_files
2022-11-21 13:41 - 2022-11-21 13:41 - 000000000 ____D C:\Users\Sue\Documents\Custom Office Templates
2022-11-21 13:41 - 2022-08-19 14:03 - 000303653 _____ C:\Users\Sue\Documents\AFASTIntroductiontoItsTargetOrganApproachandFluidScoringSystems (1).pdf
2022-11-21 13:41 - 2022-08-19 14:01 - 000303653 _____ C:\Users\Sue\Documents\AFASTIntroductiontoItsTargetOrganApproachandFluidScoringSystems.pdf
2022-11-21 13:41 - 2022-07-27 15:29 - 000000084 _____ C:\Users\Sue\Documents\payments.csv
2022-11-21 13:41 - 2022-07-11 12:54 - 000024251 _____ C:\Users\Sue\Documents\iris reciept.pdf
2022-11-21 13:41 - 2022-07-10 12:13 - 000425521 _____ C:\Users\Sue\Documents\Online Return Center.html
2022-11-21 13:41 - 2022-06-28 10:34 - 000675159 _____ C:\Users\Sue\Documents\2021 Fluhr, Suzanne Individual Client Copy personal taxes.pdf
2022-11-21 13:41 - 2022-06-25 13:41 - 000479981 _____ C:\Users\Sue\Documents\TENDER TOUCH VETERINARY CARE INC_2021_1120S_Tax Returns.pdf
2022-11-21 13:41 - 2022-06-25 13:31 - 000874920 _____ C:\Users\Sue\Documents\TENDER TOUCH VETERINARY CARE INC_2021_1120S_Tax Returns (7).zip
2022-11-21 13:41 - 2022-06-25 13:23 - 000771014 _____ C:\Users\Sue\Documents\TENDER TOUCH VETERINARY CARE INC_2021_1120S_Tax Returns (5).zip
2022-11-21 13:41 - 2022-06-01 13:17 - 009204132 _____ C:\Users\Sue\Documents\lock box.html
2022-11-21 13:41 - 2022-05-29 13:27 - 000025725 _____ C:\Users\Sue\Documents\Dr Sue License.pdf
2022-11-21 13:41 - 2022-05-24 11:00 - 000274268 _____ C:\Users\Sue\Documents\winnie.html
2022-11-21 13:41 - 2022-03-23 14:17 - 000108754 _____ C:\Users\Sue\Documents\Insurance Census 2022.pdf
2022-11-21 13:41 - 2022-03-11 17:26 - 000141974 _____ C:\Users\Sue\Documents\MYS.jpeg
2022-11-21 13:41 - 2022-02-22 14:01 - 009160564 _____ C:\Users\Sue\Documents\-vs2-operator_s-manual-no-crops.pdf
2022-11-21 13:41 - 2022-02-19 14:25 - 000394929 _____ C:\Users\Sue\Documents\U.S. Bank - My Loan2-20-22.html
2022-11-21 13:41 - 2022-02-13 14:28 - 000213687 _____ C:\Users\Sue\Documents\jan 22 sales tax.pdf
2022-11-21 13:41 - 2022-02-09 17:26 - 000068071 _____ C:\Users\Sue\Documents\TaxJurisdictionMonthly-en-us-4023877 (1) jan 2022.pdf
2022-11-21 13:41 - 2022-02-09 17:24 - 000051557 _____ C:\Users\Sue\Documents\TaxSummaryMonthly-en-us-4023877Jan 2021.pdf
2022-11-21 13:41 - 2022-01-28 16:57 - 000100656 _____ C:\Users\Sue\Documents\2021 Updated Employee W-2s.pdf
2022-11-21 13:41 - 2022-01-21 09:31 - 001160720 _____ C:\Users\Sue\Documents\ColdWeatherSafety.pdf
2022-11-21 13:41 - 2022-01-16 14:31 - 000042428 _____ C:\Users\Sue\Documents\2021-01-27 Statement - USB Sue Savings 3473.pdf
2022-11-21 13:41 - 2022-01-15 13:41 - 000051110 _____ C:\Users\Sue\Documents\MYS Dec 21 Tax.pdf
2022-11-21 13:41 - 2022-01-01 13:03 - 009434929 _____ C:\Users\Sue\Documents\contract signed.pdf
2022-11-21 13:41 - 2022-01-01 13:01 - 001185532 _____ C:\Users\Sue\Documents\document.pdf
2022-11-21 13:41 - 2022-01-01 13:01 - 000187956 _____ C:\Users\Sue\Documents\VEBLegalCertificateAllison.pdf
2022-11-21 13:41 - 2022-01-01 12:57 - 000000082 _____ C:\Users\Sue\Documents\GlCodeSummaryReport_284360_001_20220101_135733.csv
2022-11-21 13:41 - 2022-01-01 12:42 - 000806662 _____ C:\Users\Sue\Documents\AVImark-Year-End-Processes_12092021.pdf
2022-11-21 13:41 - 2022-01-01 11:57 - 000029370 _____ C:\Users\Sue\Documents\Amortization schedule1-1-22.pdf
2022-11-21 13:41 - 2022-01-01 10:36 - 000050838 _____ C:\Users\Sue\Documents\TaxSummaryMonthly-en-us-4023877.pdf
2022-11-21 13:41 - 2021-12-29 12:38 - 000000400 _____ C:\Users\Sue\Documents\licence 2023.htm
2022-11-21 13:41 - 2021-12-29 12:37 - 000000400 _____ C:\Users\Sue\Documents\RenderReport.htm
2022-11-21 13:41 - 2021-12-26 16:00 - 000000400 _____ C:\Users\Sue\Documents\license 2023.htm
2022-11-21 13:41 - 2021-12-25 17:23 - 000000000 ____D C:\Users\Sue\Documents\FeedbackHub
2022-11-21 13:41 - 2021-12-22 18:46 - 000188529 _____ C:\Users\Sue\Documents\VEBLegalCertificatelicense 2023.pdf
2022-11-21 13:41 - 2021-12-14 16:16 - 003900274 _____ C:\Users\Sue\Documents\VINFoundation_ModelEmploymentAgreement_042018.pdf
2022-11-21 13:41 - 2021-10-02 16:25 - 000067863 _____ C:\Users\Sue\Documents\TaxJurisdictionMonthly-en-us-4023877.pdf
2022-11-21 13:41 - 2021-09-30 14:43 - 000020970 _____ C:\Users\Sue\Documents\DEA2021.pdf
2022-11-21 13:41 - 2021-05-16 13:56 - 000924264 _____ C:\Users\Sue\Documents\fte.pdf
2022-11-21 13:41 - 2021-05-16 13:43 - 001300599 _____ C:\Users\Sue\Documents\222.pdf
2022-11-21 13:41 - 2021-05-16 13:42 - 001513069 _____ C:\Users\Sue\Documents\sum.pdf
2022-11-21 13:41 - 2021-05-16 13:39 - 003213569 _____ C:\Users\Sue\Documents\nov2.pdf
2022-11-21 13:41 - 2021-05-16 13:38 - 003053350 _____ C:\Users\Sue\Documents\nov1.pdf
2022-11-21 13:41 - 2021-05-16 13:34 - 009751493 _____ C:\Users\Sue\Documents\sobs.pdf
2022-11-21 13:41 - 2021-05-16 13:25 - 009910722 _____ C:\Users\Sue\Documents\jsbs.pdf
2022-11-21 13:41 - 2021-05-16 13:18 - 009165865 _____ C:\Users\Sue\Documents\bsmj.pdf
2022-11-21 13:41 - 2021-05-16 13:13 - 006799728 _____ C:\Users\Sue\Documents\Scan.pdf
2022-11-21 13:41 - 2021-05-16 12:59 - 006857725 _____ C:\Users\Sue\Documents\941 for PPP.pdf
2022-11-21 13:41 - 2021-05-12 07:58 - 001302991 _____ C:\Users\Sue\Documents\Scan 222.pdf
2022-11-21 13:41 - 2021-03-13 11:31 - 000137444 _____ C:\Users\Sue\Documents\tax feb.oxps
2022-11-21 13:41 - 2021-01-13 15:22 - 000143715 _____ C:\Users\Sue\Documents\[email protected]
2022-11-21 13:41 - 2020-11-21 14:19 - 000071457 _____ C:\Users\Sue\Documents\20200331_INWKS941.pdf
2022-11-21 13:41 - 2020-11-21 14:10 - 000176205 _____ C:\Users\Sue\Documents\20200930_INWKS941.pdf
2022-11-21 13:41 - 2020-11-21 14:07 - 000537581 _____ C:\Users\Sue\Documents\20200630_INWKS941.pdf
2022-11-21 13:41 - 2020-11-21 14:05 - 000005809 _____ C:\Users\Sue\Documents\20200930_WIUCT101.pdf
2022-11-21 13:41 - 2020-11-21 13:58 - 000005808 _____ C:\Users\Sue\Documents\20200630_WIUCT101.pdf
2022-11-21 13:41 - 2020-08-11 08:00 - 000131640 _____ C:\Users\Sue\Documents\bonilacrossR.pdf
2022-11-21 13:41 - 2020-08-11 07:58 - 000131640 _____ C:\Users\Sue\Documents\Rabie Boni.pdf
2022-11-21 13:41 - 2020-08-11 07:52 - 000789989 _____ C:\Users\Sue\Documents\BoniLacrosstravel2.pdf
2022-11-21 13:41 - 2020-08-10 16:08 - 000458831 _____ C:\Users\Sue\Documents\Bonilacross.pdf
2022-11-21 13:41 - 2020-08-10 16:07 - 000458831 _____ C:\Users\Sue\Documents\Boni Lacross 1.pdf
2022-11-21 13:41 - 2020-08-10 16:04 - 000458831 _____ C:\Users\Sue\Documents\Boni Lacross paperwork of travel.pdf
2022-11-21 13:41 - 2020-08-10 11:29 - 000272498 _____ C:\Users\Sue\Documents\BONI.pdf
2022-11-21 13:41 - 2020-08-10 11:24 - 000272029 _____ C:\Users\Sue\Documents\Boni Lacross.pdf
2022-11-21 13:41 - 2020-06-11 11:09 - 000000000 ____D C:\Users\Sue\Documents\Zoom
2022-11-21 13:41 - 2020-03-29 14:06 - 001996755 _____ C:\Users\Sue\Documents\TenderTouch (1).pdf
2022-11-21 13:41 - 2020-02-19 16:16 - 000207178 _____ C:\Users\Sue\Documents\Max 2020.oxps
2022-11-21 13:41 - 2018-02-25 10:44 - 000004704 _____ C:\Users\Sue\Documents\payment-confirmation-2-24-18.pdf
2022-11-21 13:41 - 2016-11-06 14:01 - 000164751 _____ C:\Users\Sue\Documents\Book2.xlsx
2022-11-21 13:36 - 2022-11-21 13:36 - 000000000 ___HD C:\OneDriveTemp
2022-11-21 13:34 - 2022-11-21 13:36 - 000000000 ____D C:\Users\Sue\AppData\Local\Notepad
2022-11-21 13:32 - 2022-11-21 13:32 - 000297472 _____ C:\Windows\system32\Windows.Management.InprocObjects.dll
2022-11-21 13:20 - 2022-11-21 13:20 - 000000625 _____ C:\Users\Sue\Desktop\SharedDocuments (TTVC-SVRData) (S) - Shortcut.lnk
2022-11-21 13:01 - 2022-11-21 15:02 - 000000000 ____D C:\Backup
2022-11-21 12:26 - 2022-11-21 12:33 - 000000000 ____D C:\ProgramData\scre..tion_b15b0581876c57b7_0015.000d_86ab3ae43306d26a
2022-11-21 12:26 - 2022-11-21 12:26 - 000086688 _____ C:\Users\Sue\Downloads\ConnectWiseControl.Client (1).exe
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-12-20 08:52 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\Lenovo
2022-12-20 08:50 - 2022-09-21 18:43 - 000795738 _____ C:\Windows\system32\PerfStringBackup.INI
2022-12-20 08:50 - 2019-12-07 03:13 - 000000000 ____D C:\Windows\INF
2022-12-20 08:49 - 2022-11-10 21:23 - 000000000 ____D C:\Program Files (x86)\Google
2022-12-20 08:47 - 2022-11-10 17:15 - 000000000 ___RD C:\Users\Sue\OneDrive
2022-12-20 08:47 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\D3DSCache
2022-12-20 08:47 - 2022-11-10 15:57 - 000000000 ____D C:\Program Files\TeamViewer
2022-12-20 08:47 - 2021-10-27 11:15 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-12-20 08:47 - 2019-12-07 03:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-12-20 08:47 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\ServiceState
2022-12-20 08:47 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\AppReadiness
2022-12-20 08:47 - 2019-12-07 03:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-12-20 08:46 - 2021-10-27 11:15 - 000008192 ___SH C:\DumpStack.log.tmp
2022-12-20 08:46 - 2019-12-07 03:03 - 000524288 _____ C:\Windows\system32\config\BBI
2022-12-20 08:45 - 2019-12-07 03:03 - 000000000 ____D C:\Windows\CbsTemp
2022-12-20 08:41 - 2021-10-27 11:15 - 000000000 ____D C:\Windows\system32\SleepStudy
2022-12-17 12:14 - 2022-11-10 17:12 - 000000000 ____D C:\ProgramData\ScreenConnect Client (61e735463d3bf1de)
2022-12-17 11:04 - 2022-11-11 09:00 - 000004784 _____ C:\Windows\system32\Tasks\MicrosoftEdgeShadowStackRollbackTask
2022-12-17 11:04 - 2021-10-27 11:15 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-12-15 16:04 - 2022-11-11 10:37 - 000000000 ____D C:\ProgramData\EPSON
2022-12-15 16:04 - 2022-11-11 10:37 - 000000000 ____D C:\Program Files\epson
2022-12-15 16:04 - 2022-06-20 22:51 - 000000000 ____D C:\ProgramData\Lenovo
2022-12-15 16:04 - 2022-06-20 22:00 - 000000000 ____D C:\Windows\system32\Tasks\Lenovo
2022-12-15 16:04 - 2022-06-20 22:00 - 000000000 ____D C:\Windows\Lenovo
2022-12-15 15:58 - 2019-12-07 03:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2022-12-15 15:29 - 2022-11-10 21:24 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-12-15 15:29 - 2022-11-10 21:24 - 000002213 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-12-14 15:41 - 2022-11-10 21:23 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3259427507-1055586877-3198061443-1001
2022-12-14 15:41 - 2022-11-10 16:03 - 000000000 ____D C:\Program Files\Mesh Agent
2022-12-14 15:40 - 2022-06-20 22:01 - 000000000 ____D C:\Program Files\Microsoft Office
2022-12-14 15:40 - 2021-10-27 11:15 - 000454824 _____ C:\Windows\system32\FNTCACHE.DAT
2022-12-14 15:39 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\bcastdvr
2022-12-14 15:39 - 2019-12-07 03:14 - 000000000 ____D C:\Program Files\Common Files\System
2022-12-14 15:37 - 2022-11-10 17:12 - 000000000 ____D C:\Users\Sue
2022-12-14 06:41 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2022-12-14 06:40 - 2022-11-10 15:38 - 000000000 ____D C:\Windows\system32\MRT
2022-12-14 06:39 - 2022-11-10 15:38 - 148633544 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2022-12-13 14:04 - 2022-11-10 21:12 - 000002208 _____ C:\Users\Sue\Desktop\AVImark - Shortcut.lnk
2022-12-08 16:47 - 2021-10-27 11:15 - 000000000 ____D C:\Windows\system32\Drivers\wd
2022-12-06 17:03 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\Packages
2022-11-21 15:05 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\AMD
2022-11-21 14:58 - 2022-06-20 22:56 - 000000000 ____D C:\Windows\SystemTemp
2022-11-21 13:35 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\ConnectedDevicesPlatform
2022-11-21 13:35 - 2022-06-20 22:51 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ___SD C:\Windows\system32\UNP
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\es-MX
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SystemResources
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\SystemApps
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\lv-LV
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\lt-LT
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\et-EE
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\es-MX
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\Dism
2022-11-21 13:35 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\Provisioning
2022-11-21 13:32 - 2021-10-27 11:17 - 003014656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2022-11-21 12:26 - 2022-11-10 15:54 - 000000000 ____D C:\Users\Sue\AppData\Local\Deployment
 
==================== Files in the root of some directories ========
 
2022-10-19 14:00 - 2022-10-19 14:00 - 000513168 _____ (Intuit Inc.) C:\Program Files\Common Files\GraphSeriesCol.dll
2022-11-22 09:45 - 2022-11-22 09:47 - 1091567600 _____ (Intuit, Inc.                                                ) C:\Users\Sue\AppData\Roaming\QuickBooksPremierSub2023.exe
2022-11-22 09:42 - 2022-11-22 09:42 - 071151810 _____ (Intuit, Inc.                                                ) C:\Users\Sue\AppData\Roaming\QuickBooksPro2019.exe
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================

  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Go ahead and uninstall Hitmanpro.  It's causing errors anyway.  Reboot and then do another FRST scan and post both logs.


  • 0

#5
CCWTech

CCWTech

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 191 posts

It's no longer in add/remove programs for some reason.


  • 0

#6
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Try method 4 on: https://www.revounin...pname=HitmanPro

 

You can also try method 1 if you don't mind temporarily installing revo


  • 0

#7
CCWTech

CCWTech

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 191 posts

I will try that and report back. Thank you.


  • 0

#8
CCWTech

CCWTech

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 191 posts

Sorry for the delay. I hope you had a great Christmas. Here you go:
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-12-2022
Ran by Sue (administrator) on DRSUENEWPC (LENOVO 11JN0072US) (26-12-2022 16:43:50)
Running from C:\Users\Sue\Desktop
Loaded Profiles: Sue
Platform: Microsoft Windows 10 Pro Version 22H2 19045.2364 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBWebConnector3.0\Intuit.QBDT.Webconnector.QBWCMonitor.exe ->) (Intuit, Inc. -> ) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBWebConnector3.0\Intuit.QBDT.Webconnector.Application.exe
(C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantage-(LenovoCompanionAppAddin).exe
(C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantage-(VantageCoreAddin).exe
(C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe ->) (Intuit, Inc. -> ) C:\Program Files\Common Files\Intuit\DataProtect\IBuEngHost.exe
(DriverStore\FileRepositoryʹ729.inf_amd64_acb1e75867156c4f\B374580\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepositoryʹ729.inf_amd64_acb1e75867156c4f\B374580\atieclxx.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(explorer.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\spool\drivers\x64\3\E_YATIS3E.EXE
(Intuit, Inc. -> Intuit Inc.) C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepositoryʹ729.inf_amd64_acb1e75867156c4f\B374580\atiesrxx.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\piecomponent.inf_amd64_a751a85f0845cf98\Intel_PIE_Service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Intuit Inc.) [File not signed] C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
(services.exe ->) (Intuit, Inc. -> ) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBWebConnector3.0\Intuit.QBDT.Webconnector.QBWCMonitor.exe
(services.exe ->) (Intuit, Inc. -> Intuit Inc.) C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantageService.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\System32\drivers\lenovo\UDC\Service\UDClientService.exe
(services.exe ->) (mc.ntg.co-8edb73 -> ) [File not signed] C:\Program Files\Mesh Agent\MeshAgent.exe <3>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e80fb7173daab733\RtkAudUService64.exe <2>
(services.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsAlarms_11.2210.7.0_x64__8wekyb3d8bbwe\Time.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21238.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21238.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22102.229.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2300_none_7e14edbc7c88b7d5\TiWorker.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_e80fb7173daab733\RtkAudUService64.exe [3496296 2022-07-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1318024 2021-04-15] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626448 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [MicrosoftEdgeAutoLaunch_48FDC4BBB2BFB3180449326C7B7EF46E] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3879848 2022-12-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIS3E.EXE [416896 2017-09-21] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EPSON ET-2760 Series 64MonitorBE: C:\Windows\system32\E_YLMBS3E.DLL [187392 2018-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\Windows\system32\enppmon.dll [500736 2016-09-14] (SEIKO EPSON CORPORATION) [File not signed]
HKLM\...\Print\Monitors\HP Standard TCP/IP Port: C:\Windows\system32\HpTcpMon.dll [331264 2009-09-16] (Hewlett Packard) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\108.0.5359.125\Installer\chrmstp.exe [2022-12-15] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk [2022-11-22]
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit, Inc. -> Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk [2022-11-22]
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files\Intuit\QuickBooks 2023\QBW.EXE (Intuit, Inc. -> Intuit Inc.)
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0EB2FD9D-A4AF-4F07-A043-656EF3843AA6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-27] (Adobe Inc. -> Adobe Inc.)
Task: {139615F1-B783-4CAF-AF94-3AA2334EDAFB} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin => C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\ScheduleEventAction.exe [27480 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
Task: {1CAB845A-EFB0-45A2-8DE1-3F65EFFF3F5A} - System32\Tasks\MicrosoftEdgeShadowStackRollbackTask => C:\Program Files (x86)\Microsoft\Edge\Application\108.0.1462.54\Installer\setup.exe [3367848 2022-12-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {216A41D9-449D-40CD-9B91-6363FDB405B6} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3259427507-1055586877-3198061443-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189072 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {309C78F5-DFCA-45BE-8FAF-EF9ADB6547E7} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoCompanionAppAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\ScheduleEventAction.exe [27480 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
Task: {3939AB69-A43B-4561-9C6A-54A431D17C1A} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {3A6C6083-5B8D-4A0F-95EF-8AB6A60CC0CB} - System32\Tasks\Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance => %systemroot%\system32\sc.exe start LenovoVantageService
Task: {5AF9E179-DCF7-4B52-BFAF-58D538B3A142} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {5D5D2BAA-F528-4590-A803-A5A97DA5F42F} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189072 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {81E1AB3E-DC23-4A44-AD8E-E13D982CFFF3} - System32\Tasks\Lenovo\UDC\Lenovo UDC Monitor => C:\Windows\system32\drivers\lenovo\udc\data\InfBackup\UdcInfInstaller.exe [184656 2022-05-23] (Lenovo -> Lenovo Group Ltd.)
Task: {8E12C014-148F-4780-B94E-9019E0B9662D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {98015232-CD73-4C11-9D9E-47E4A8926F7D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {9F8516B3-965D-4CB4-84C8-3BA797197D41} - System32\Tasks\GoogleUpdateTaskMachineUA{7502EB32-9AA7-4409-A70A-5A0A783A8CB9} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [171480 2022-11-10] (Google LLC -> Google LLC)
Task: {B7132DD9-FFA7-41BB-988F-5FC331B9ECF9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BA16315F-9972-4FB7-BD4A-CE05647C3C37} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {BB757E02-9F4B-4F18-8E3D-EEEADB5E35B4} - System32\Tasks\Lenovo\UDC\Lenovo UDC Idle Monitor => C:\windows\system32\drivers\Lenovo\udc\Service\UDCUserAgent.exe [89408 2022-05-23] (Lenovo -> Lenovo Group Ltd.)
Task: {BBDB025B-950A-4C54-A6AC-9D087FAF158F} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoSystemUpdateAddin_WeeklyTask => C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\ScheduleEventAction.exe [27480 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
Task: {C4029849-3F83-4719-8545-B464C0A68920} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DA835E9F-8961-416B-819A-392E76426410} - System32\Tasks\GoogleUpdateTaskMachineCore{6A2DD8C7-7DB0-46A7-AC32-0FD8EC7C636A} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [171480 2022-11-10] (Google LLC -> Google LLC)
Task: {E633E663-F2CB-4D3F-A86B-A1E0FA3DA379} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [146816 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {FD787C0A-F968-4283-A769-D9319DE7F622} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ac8a25b1-8e84-445b-8d31-2b270eb6de82}: [DhcpNameServer] 192.168.1.1
 
Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Sue\AppData\Local\Microsoft\Edge\User Data\Default [2022-12-26]
Edge HomePage: Default -> hxxp://www.msn.com/?pc=DCTE
Edge Extension: (URL Safety) - C:\Users\Sue\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\plkaklmpcfkechocmkmhjheonopjbnpo [2022-11-10]
 
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-16] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-10-16] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-16] (Microsoft Corporation -> Microsoft Corporation)
 
Chrome: 
=======
CHR Profile: C:\Users\Sue\AppData\Local\Google\Chrome\User Data\Default [2022-12-26]
CHR Extension: (Google Docs Offline) - C:\Users\Sue\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-12-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Sue\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-11-10]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-27] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12540928 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [206304 2020-10-02] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncHelper.exe [3478928 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
R2 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\3.13.14.0\LenovoVantageService.exe [31072 2022-05-24] (Lenovo -> Lenovo Group Ltd.)
R2 Mesh Agent; C:\Program Files\Mesh Agent\MeshAgent.exe [3457112 2022-11-10] (mc.ntg.co-8edb73 -> ) [File not signed]
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.238.1114.0002\OneDriveUpdaterService.exe [3845008 2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
S3 QBFCService; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [65536 2022-10-19] (Intuit Inc.) [File not signed]
R2 QBVSS; C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe [1570816 2022-10-08] (Intuit Inc.) [File not signed]
R2 QBWCMonitor; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBWebConnector3.0\Intuit.QBDT.Webconnector.QBWCMonitor.exe [47384 2022-12-02] (Intuit, Inc. -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [224184 2022-11-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [16196920 2022-11-09] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 UDCService; C:\Windows\System32\drivers\Lenovo\udc\Service\UDClientService.exe [71504 2022-05-23] (Lenovo -> Lenovo Group Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe [3191264 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe [133592 2022-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 HitmanPro38CrusaderBoot; "C:\Users\Sue\Downloads\HitmanPro_x64.exe" /crusader:boot [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [33216 2021-12-02] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepositoryʹ729.inf_amd64_acb1e75867156c4f\B374580\amdkmdag.sys [82880872 2021-12-09] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R0 rtvdevw10; C:\Windows\System32\drivers\rtvdevw10x64.sys [50128 2022-08-18] (Realtek Semiconductor Corp. -> Realtek)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [49568 2022-12-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [473376 2022-12-08] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [99616 2022-12-08] (Microsoft Windows -> Microsoft Corporation)
S3 MpKsl43cec76d; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{83FC0082-CFE3-4601-B5BA-01573A87E243}\MpKslDrv.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-12-26 16:43 - 2022-12-26 16:44 - 000019863 _____ C:\Users\Sue\Desktop\FRST.txt
2022-12-26 16:43 - 2022-12-26 16:43 - 000000000 ____D C:\Users\Sue\Desktop\FRST-OlderVersion
2022-12-26 16:41 - 2022-12-26 16:41 - 000000000 ____D C:\Users\Sue\Downloads\RevoUninstaller_Portable
2022-12-26 16:40 - 2022-12-26 16:40 - 009040984 _____ C:\Users\Sue\Downloads\RevoUninstaller_Portable.zip
2022-12-20 17:48 - 2022-12-20 17:49 - 067706880 _____ C:\Users\Sue\Documents\Nov22 Tender Touch Veterinary Care (Backup Dec 20,2022  05 48 PM).QBB
2022-12-20 08:43 - 2022-12-20 08:50 - 000170530 _____ C:\Users\Sue\Desktop\Fixlog.txt
2022-12-19 18:08 - 2022-12-19 18:08 - 302314336 _____ (Malwarebytes) C:\Users\Sue\Downloads\mb4-setup-consumer-4.5.19.229-1.0.1860-1.0.63451.exe
2022-12-19 18:07 - 2022-12-19 18:07 - 002542312 _____ (Malwarebytes) C:\Users\Sue\Downloads\MBSetup-C14E4470.exe
2022-12-19 17:54 - 2022-12-26 16:43 - 000000000 ____D C:\FRST
2022-12-19 17:53 - 2022-12-26 16:43 - 002375680 _____ (Farbar) C:\Users\Sue\Desktop\FRST64.exe
2022-12-19 15:03 - 2022-12-19 15:03 - 001494555 _____ C:\Users\Sue\Downloads\CA Weekly Promo_12.19-23_V3_Writable.pdf
2022-12-17 16:38 - 2022-12-17 16:38 - 012166202 _____ C:\Users\Sue\Downloads\2023 Zoetis Petcare Price List.pdf
2022-12-17 16:38 - 2022-12-17 16:38 - 012166202 _____ C:\Users\Sue\Downloads\2023 Zoetis Petcare Price List (1).pdf
2022-12-17 16:37 - 2022-12-17 16:37 - 000046545 _____ C:\Users\Sue\Downloads\Zoetis 2002 End of Year Shipping.pdf
2022-12-17 13:01 - 2022-12-17 13:01 - 000000000 ____D C:\Program Files (x86)\ScreenConnect Client (61e735463d3bf1de)
2022-12-15 16:08 - 2022-12-15 16:08 - 000012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2022-12-15 16:08 - 2022-12-15 16:08 - 000000304 _____ C:\Windows\system32\.crusader
2022-12-15 16:06 - 2022-12-15 16:08 - 000000000 ____D C:\ProgramData\HitmanPro
2022-12-15 16:03 - 2022-12-15 16:04 - 000000000 ____D C:\AdwCleaner
2022-12-14 19:10 - 2022-12-14 19:20 - 000000000 ____D C:\Program Files\Immunet
2022-12-14 19:10 - 2022-12-14 19:10 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ImmunetNetworkMonitor_01009.Wdf
2022-12-14 19:10 - 2022-12-14 19:10 - 000000000 ____D C:\ProgramData\Immunet
2022-12-14 18:40 - 2022-12-14 18:40 - 000000000 ____D C:\Users\Sue\AppData\Local\mbam
2022-12-14 18:39 - 2022-12-15 15:54 - 000000000 ____D C:\Program Files\Malwarebytes
2022-12-14 15:41 - 2022-12-15 17:08 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2022-12-14 15:40 - 2022-12-14 15:41 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2022-12-14 15:40 - 2022-12-14 15:41 - 000002139 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-12-14 15:40 - 2022-12-14 15:40 - 000000000 ___RD C:\Users\Default\OneDrive
2022-12-14 06:42 - 2022-12-14 06:43 - 000000000 ___HD C:\$WinREAgent
2022-12-13 12:50 - 2022-12-13 12:50 - 067756032 _____ C:\Users\Sue\Documents\Nov22 Tender Touch Veterinary Care (Backup Dec 13,2022  12 49 PM).QBB
2022-12-13 10:57 - 2022-12-14 15:40 - 000000000 ____D C:\Program Files (x86)\LogMeIn Rescue Applet
2022-12-13 10:56 - 2022-12-13 11:37 - 000000000 ____D C:\Users\Sue\AppData\Local\LogMeIn Rescue Applet
2022-12-13 10:56 - 2022-12-13 10:56 - 000002321 _____ C:\Users\Sue\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HelpDesk.lnk
2022-12-11 15:45 - 2022-12-11 15:45 - 000067703 _____ C:\Users\Sue\Downloads\TaxJurisdictionMonthly-en-us-4023877 (1).pdf
2022-12-11 13:22 - 2022-12-11 13:22 - 000000131 _____ C:\Users\Sue\Downloads\Reimbursements (1).csv
2022-12-11 13:01 - 2022-12-11 13:01 - 000000000 ____D C:\Users\Sue\AppData\LocalLow\Temp
2022-12-11 12:43 - 2022-12-11 12:43 - 000029683 _____ C:\Users\Sue\Downloads\Clinic - 4868_08-01-2022_12-15-2022.csv
2022-12-07 14:56 - 2022-12-07 14:56 - 000178749 _____ C:\Users\Sue\Downloads\Document (3).pdf
2022-12-07 14:56 - 2022-12-07 14:56 - 000178749 _____ C:\Users\Sue\Downloads\Document (2).pdf
2022-12-07 10:51 - 2022-12-07 10:51 - 000178749 _____ C:\Users\Sue\Downloads\Document.pdf
2022-12-07 10:51 - 2022-12-07 10:51 - 000178749 _____ C:\Users\Sue\Downloads\Document (1).pdf
2022-12-07 10:41 - 2022-12-07 10:41 - 000131708 _____ C:\Users\Sue\Downloads\ModelInfectionControlPlan (1).pdf
2022-12-07 10:41 - 2022-12-07 10:41 - 000131708 _____ C:\Users\Sue\Downloads\ModelInfectionControlPlan (1) (1).pdf
2022-12-06 11:46 - 2022-12-06 11:46 - 000431305 _____ C:\Users\Sue\Downloads\INVOICE#716A131.html
2022-12-05 16:33 - 2022-12-05 16:33 - 000034927 _____ C:\Users\Sue\Downloads\Statement.pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041630 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (5).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041630 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (4).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041630 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (3).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000041623 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (1).pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000025117 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632.pdf
2022-12-04 14:30 - 2022-12-04 14:30 - 000025117 _____ C:\Users\Sue\Downloads\2022-01-31 Statement - USB Savings 2632 (2).pdf
2022-12-04 14:29 - 2022-12-04 14:29 - 000000000 ____D C:\Users\Sue\Downloads\JAN22_files
2022-12-04 14:28 - 2022-12-04 14:29 - 000431599 _____ C:\Users\Sue\Downloads\JAN22.html
2022-12-04 14:27 - 2022-12-04 14:27 - 000039823 _____ C:\Users\Sue\Downloads\2022-02-28 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000048846 _____ C:\Users\Sue\Downloads\2022-11-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000044339 _____ C:\Users\Sue\Downloads\2022-10-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000041717 _____ C:\Users\Sue\Downloads\2022-03-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000039800 _____ C:\Users\Sue\Downloads\2022-06-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000039458 _____ C:\Users\Sue\Downloads\2022-07-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000039214 _____ C:\Users\Sue\Downloads\2022-09-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000037923 _____ C:\Users\Sue\Downloads\2022-04-30 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000036161 _____ C:\Users\Sue\Downloads\2022-05-31 Statement - USB Savings 2632.pdf
2022-12-04 14:26 - 2022-12-04 14:26 - 000020207 _____ C:\Users\Sue\Downloads\2022-08-31 Statement - USB Savings 2632.pdf
2022-12-04 14:03 - 2022-12-04 14:03 - 000002031 _____ C:\Users\Sue\Downloads\Savings - 2632_01-04-2022_12-08-2022.csv
2022-12-04 14:01 - 2022-12-04 14:01 - 000002568 _____ C:\Users\Sue\Downloads\building - 9319_01-01-2022_12-08-2022.csv
2022-12-03 15:21 - 2022-12-03 15:21 - 000119808 _____ C:\Users\Sue\Downloads\100991537_US_ah_2022_12.pdf
2022-12-03 15:20 - 2022-12-03 15:20 - 000068608 _____ C:\Users\Sue\Downloads\Invoice-6100988911.pdf
2022-12-03 15:09 - 2022-12-03 15:09 - 000106591 _____ C:\Users\Sue\Downloads\1c370d69-4218-47f1-8a1d-f5f90d378eb2.pdf
2022-12-02 10:36 - 2022-12-02 10:36 - 000084136 _____ C:\Users\Sue\Downloads\MVS Exclusive Promo DechraNutramax Nov 17-30.pdf
2022-11-30 10:42 - 2022-11-30 10:42 - 001679221 _____ C:\Users\Sue\Downloads\CA Weekly Promo_11.28-12.2_writable.pdf
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-12-26 16:34 - 2019-12-07 03:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-12-26 16:34 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\AppReadiness
2022-12-26 16:33 - 2022-11-10 21:23 - 000000000 ____D C:\Program Files (x86)\Google
2022-12-26 16:33 - 2019-12-07 03:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-12-26 16:31 - 2022-09-21 18:43 - 000795738 _____ C:\Windows\system32\PerfStringBackup.INI
2022-12-26 16:31 - 2019-12-07 03:13 - 000000000 ____D C:\Windows\INF
2022-12-26 16:28 - 2022-11-10 17:15 - 000000000 ___RD C:\Users\Sue\OneDrive
2022-12-26 16:27 - 2022-11-10 16:03 - 000000000 ____D C:\Program Files\Mesh Agent
2022-12-26 16:27 - 2022-11-10 15:57 - 000000000 ____D C:\Program Files\TeamViewer
2022-12-26 16:27 - 2021-10-27 11:15 - 000008192 ___SH C:\DumpStack.log.tmp
2022-12-26 16:27 - 2021-10-27 11:15 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-12-26 16:27 - 2021-10-27 11:15 - 000000000 ____D C:\Windows\system32\SleepStudy
2022-12-26 16:27 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\ServiceState
2022-12-20 11:44 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\D3DSCache
2022-12-20 08:52 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\Lenovo
2022-12-20 08:46 - 2022-11-21 14:40 - 000000000 ___HD C:\Users\Public\Documents\Windows
2022-12-20 08:46 - 2019-12-07 03:03 - 000524288 _____ C:\Windows\system32\config\BBI
2022-12-20 08:45 - 2019-12-07 03:03 - 000000000 ____D C:\Windows\CbsTemp
2022-12-17 12:14 - 2022-11-10 17:12 - 000000000 ____D C:\ProgramData\ScreenConnect Client (61e735463d3bf1de)
2022-12-17 11:04 - 2022-11-11 09:00 - 000004784 _____ C:\Windows\system32\Tasks\MicrosoftEdgeShadowStackRollbackTask
2022-12-17 11:04 - 2021-10-27 11:15 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-12-15 16:04 - 2022-11-11 10:37 - 000000000 ____D C:\ProgramData\EPSON
2022-12-15 16:04 - 2022-11-11 10:37 - 000000000 ____D C:\Program Files\epson
2022-12-15 16:04 - 2022-06-20 22:51 - 000000000 ____D C:\ProgramData\Lenovo
2022-12-15 16:04 - 2022-06-20 22:00 - 000000000 ____D C:\Windows\system32\Tasks\Lenovo
2022-12-15 16:04 - 2022-06-20 22:00 - 000000000 ____D C:\Windows\Lenovo
2022-12-15 15:58 - 2019-12-07 03:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2022-12-15 15:29 - 2022-11-10 21:24 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-12-15 15:29 - 2022-11-10 21:24 - 000002213 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-12-14 15:41 - 2022-11-10 21:23 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3259427507-1055586877-3198061443-1001
2022-12-14 15:40 - 2022-06-20 22:01 - 000000000 ____D C:\Program Files\Microsoft Office
2022-12-14 15:40 - 2021-10-27 11:15 - 000454824 _____ C:\Windows\system32\FNTCACHE.DAT
2022-12-14 15:39 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\bcastdvr
2022-12-14 15:39 - 2019-12-07 03:14 - 000000000 ____D C:\Program Files\Common Files\System
2022-12-14 15:37 - 2022-11-10 17:12 - 000000000 ____D C:\Users\Sue
2022-12-14 06:41 - 2019-12-07 03:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2022-12-14 06:40 - 2022-11-10 15:38 - 000000000 ____D C:\Windows\system32\MRT
2022-12-14 06:39 - 2022-11-10 15:38 - 148633544 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2022-12-13 14:04 - 2022-11-10 21:12 - 000002208 _____ C:\Users\Sue\Desktop\AVImark - Shortcut.lnk
2022-12-13 10:58 - 2022-11-21 14:46 - 000000000 ____D C:\ProgramData\Intuit
2022-12-08 16:47 - 2021-10-27 11:15 - 000000000 ____D C:\Windows\system32\Drivers\wd
2022-12-06 17:03 - 2022-11-10 17:13 - 000000000 ____D C:\Users\Sue\AppData\Local\Packages
 
==================== Files in the root of some directories ========
 
2022-10-19 14:00 - 2022-10-19 14:00 - 000513168 _____ (Intuit Inc.) C:\Program Files\Common Files\GraphSeriesCol.dll
2022-11-22 09:45 - 2022-11-22 09:47 - 1091567600 _____ (Intuit, Inc.                                                ) C:\Users\Sue\AppData\Roaming\QuickBooksPremierSub2023.exe
2022-11-22 09:42 - 2022-11-22 09:42 - 071151810 _____ (Intuit, Inc.                                                ) C:\Users\Sue\AppData\Roaming\QuickBooksPro2019.exe
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-12-2022
Ran by Sue (26-12-2022 16:44:29)
Running from C:\Users\Sue\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.2364 (X64) (2022-11-10 22:45:14)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-3259427507-1055586877-3198061443-500 - Administrator - Disabled)
ccwadmin (S-1-5-21-3259427507-1055586877-3198061443-1002 - Administrator - Enabled)
DefaultAccount (S-1-5-21-3259427507-1055586877-3198061443-503 - Limited - Disabled)
Guest (S-1-5-21-3259427507-1055586877-3198061443-501 - Limited - Enabled)
Sue (S-1-5-21-3259427507-1055586877-3198061443-1001 - Administrator - Enabled) => C:\Users\Sue
WDAGUtilityAccount (S-1-5-21-3259427507-1055586877-3198061443-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
ABS PDF Install (HKLM-x32\...\{C42DD564-7DCD-4555-A7F3-15C0F46221D0}) (Version: 4.6.0 - Atlas Business Solutions, Inc.)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-1033-7760-BC15014EA700}) (Version: 22.003.20263 - Adobe)
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 2.14.04.018 - Advanced Micro Devices, Inc.)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.130 - Advanced Micro Devices, Inc.) Hidden
AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.82 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 4.13.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 6.0.0.9 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver Alpha (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\{71990c55-cd9c-43d0-9271-e2d3941f3ca8}) (Version: 2.14.04.018 - Advanced Micro Devices, Inc.) Hidden
EPSON ET-2760 Series Printer Uninstall (HKLM\...\EPSON ET-2760 Series) (Version:  - Seiko Epson Corporation)
Epson ET-2760 User’s Guide (HKLM-x32\...\UsersGuideEpson ET-2760 User’s Guide_is1) (Version: 1.0 - Epson America, Inc.)
Epson Event Manager (HKLM-x32\...\{3ACC34BD-4B01-49CA-9859-0FDD746BB36E}) (Version: 3.11.0058 - Seiko Epson Corporation)
Epson Scan 2 (HKLM-x32\...\Epson Scan 2) (Version:  - Seiko Epson Corporation)
EPSON Scan OCR Component (HKLM-x32\...\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}) (Version: 3.00.04 - SEIKO EPSON Corp.)
Epson Software Updater (HKLM-x32\...\{26A9B753-4B5D-46D8-A329-5CEF96FC22D2}) (Version: 4.6.5 - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 108.0.5359.125 - Google LLC)
HP Unified IO (HKLM\...\{5C76ED0D-0F6F-4985-8B34-F9AE7834848F}) (Version: 2.0.0.434 - HP) Hidden
HP Unified IO (HKLM-x32\...\{F1390872-2500-4408-A46C-CD16C960C661}) (Version: 2.0.0.434 - HP) Hidden
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 3.13.14.0 - Lenovo Group Ltd.)
Mesh Agent (HKLM\...\Mesh Agent) (Version: 2022-08-25 00:17:18.000-07:00 - )
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 108.0.1462.54 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 108.0.1462.54 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 22.238.1114.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{80F1AF52-7AC0-42A3-9AF0-689BFB271D1D}) (Version: 3.68.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23026 (HKLM-x32\...\{BE960C1C-7BAD-3DE6-8B1A-2616FE532845}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23026 (HKLM-x32\...\{A2563E55-3BEC-3828-8D67-E5E8B9E8B675}) (Version: 14.0.23026 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.30.30704 (HKLM-x32\...\{57a73df6-4ba9-4c1d-bbbb-517289ff6c13}) (Version: 14.30.30704.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.30.30704 (HKLM\...\{6DB765A8-05AF-49A1-A71D-6F645EE3CE41}) (Version: 14.30.30704 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.30.30704 (HKLM\...\{662A0088-6FCD-45DD-9EA7-68674058AED5}) (Version: 14.30.30704 - Microsoft Corporation) Hidden
Microsoft Word 2021 - en-us (HKLM\...\Word2021Retail - en-us) (Version: 16.0.15831.20208 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.15726.20202 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.15831.20184 - Microsoft Corporation) Hidden
QuickBooks (HKLM\...\{3F034BE4-4FD8-4B4C-B9A7-BE9BF17C3CA4}) (Version: 33.0.4003.3302 - Intuit Inc.) Hidden
QuickBooks (HKLM\...\{A8FB867A-1595-43B2-8F8C-B6112C77CB8D}) (Version: 32.0.4006.3201 - Intuit Inc.) Hidden
QuickBooks Premier Edition 2022 (HKLM\...\{C32D73A9-B060-4D84-BEBB-5B595944E9E3}) (Version: 32.0.4006.3201 - Intuit Inc.)
QuickBooks Premier Edition 2023 (HKLM\...\{A9C6041A-3497-4CA5-86D1-F8759DD1BE58}) (Version: 33.0.4003.3302 - Intuit Inc.)
QuickBooks Runtime Redistributable (HKLM\...\{F2A4F809-2DE6-4D27-888B-4D2BB8DAF20E}) (Version: 1.00.0000 - Intuit Inc.)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9098.1 - Realtek Semiconductor Corp.)
ScreenConnect Client (61e735463d3bf1de) (HKLM-x32\...\{59AE0A72-DD3C-442C-AA9A-4529DA385797}) (Version: 21.13.4914.7937 - ScreenConnect Software)
TeamViewer (HKLM\...\TeamViewer) (Version: 15.35.9 - TeamViewer)
 
Packages:
=========
AMD Radeon Software -> C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.21.40031.0_x64__0a9344xs7nr4m [2022-11-10] (Advanced Micro Devices Inc.) [Startup Task]
AV1 Video Extension -> C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.1.52851.0_x64__8wekyb3d8bbwe [2022-12-08] (Microsoft Corporation)
Lenovo Commercial Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoSettingsforEnterprise_10.2210.33.0_x64__k1h2ywk1493x8 [2022-11-12] (LENOVO INC.)
MPEG-2 Video Extension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.50901.0_x64__8wekyb3d8bbwe [2022-11-12] (Microsoft Corporation)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.36.273.0_x64__dt26b99r8h8gj [2022-11-12] (Realtek Semiconductor Corp)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.15.12020.0_x64__8wekyb3d8bbwe [2022-12-08] (Microsoft Studios) [MS Ad]
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{05EC5C13-D255-4592-9CCB-98615172F0D6}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{0ADF9C35-0D5E-4B75-88DD-B64868907E17}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{123FAF7F-3FB1-4B8F-AD18-0047401D436A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{37A2FC00-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{37A2FC02-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{4716D3CE-55DB-4D2A-818C-87D912895890}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{4844F3F7-2161-4AC4-B219-B3B4311782AA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{4E5E74B5-8EB5-4859-A335-837EED412620}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{547C8F00-5567-4AE3-8BB0-CC3CE2AB9070}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{57D590F1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{596801D8-2C9D-4627-9C67-195CB81B655A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{63B5B272-1760-4A4F-922B-57F274900044}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{7DBF8260-30AD-4D1B-876A-8032B87B809F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{828E5386-74CF-4019-B356-C857CD028A7D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{82CC31B3-53B4-4161-A4E9-6B4F1290A6C8}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{8572570D-12D9-4F2C-8BB8-EB8848178B94}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{8E590317-1329-11D1-B70B-00805F29CD16}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2023\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F2-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F3-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F4-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F5-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F6-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{9D9B61F7-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A63E42D0-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{A63E42D2-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{AF5E0A13-CEAB-47CE-991D-77E82CD1BF3F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{B10BFAC3-EFF1-40D9-ADA0-BEBE037C24CA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{B66F2BF1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{b775f163-bef1-433e-aaab-c4344a51c94c}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2023\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{CBEF1FB5-78FF-4B14-9B0F-275493FB589C}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D14FD6B3-6A9F-4537-9460-07B836707127}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D4A12AAF-E15E-470B-A6B6-63032186F91F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9B9C060-0954-11D3-9E07-00104BD2BE34}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSource.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6F81-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6F84-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6F87-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll (Intuit, Inc. -> Intuit, Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{D9BC6FB2-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\StorageClasses.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{DCB2B478-EFF6-48F6-B718-13E98876854E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{DFD0AF10-B86C-4AF3-B609-1348D513E565}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E1A173E1-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{E1A173E3-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{e64977bd-9e0b-498d-843e-1776102710aa}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2022\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{EADA914E-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{EAEF733D-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{FAC93D42-FFC2-11d1-9DEB-0008C7A08EBA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2023\qbw.exe (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{FB17915F-06D1-4214-A902-CC5EE05186E9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-3259427507-1055586877-3198061443-1001_Classes\CLSID\{FB359C2A-6927-4AD7-8F1B-B6472CA7CDE7}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit, Inc. -> Intuit Inc.)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncShell64.dll [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Windows\System32\atiacm64.dll [2021-12-09] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
2009-09-16 20:44 - 2009-09-16 20:44 - 000153088 _____ (Hewlett Packard) [File not signed] C:\Windows\System32\hptcpmib.dll
2009-09-16 20:45 - 2009-09-16 20:45 - 000331264 _____ (Hewlett Packard) [File not signed] C:\Windows\System32\HpTcpMon.dll
2009-09-16 13:44 - 2009-09-16 13:44 - 000132096 _____ (Hewlett Packard) [File not signed] C:\Windows\System32\hpzjrd01.dll
2009-09-16 20:45 - 2009-09-16 20:45 - 000317440 _____ (Microsoft Corporation) [File not signed] C:\Windows\System32\HPTcpMUI.dll
2022-06-20 22:01 - 2022-06-20 22:01 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\Root\Office16\AppVIsvSubsystems64.dll
2022-06-20 22:01 - 2022-06-20 22:01 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\Root\Office16\c2r64.dll
2020-07-10 13:23 - 2020-07-10 13:23 - 000132096 _____ (Seiko Epson Corporation) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\epnsm.dll
2020-05-26 21:20 - 2020-05-26 21:20 - 000291328 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\LcMgr.dll
2016-09-14 16:31 - 2016-09-14 16:31 - 000500736 ____S (SEIKO EPSON CORPORATION) [File not signed] C:\Windows\System32\enppmon.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Mesh Agent => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ScreenConnect Client (61e735463d3bf1de) => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2022-11-16] (Microsoft Corporation -> Microsoft Corporation)
Handler: intu-help-qb15 - {0EEC9CBF-4C3D-45B3-9384-3C3CA3034A8B} - C:\Program Files\Intuit\QuickBooks 2022\HelpAsyncPluggableProtocol.dll [2022-10-19] (Intuit, Inc. -> Intuit, Inc.)
Handler: intu-help-qb16 - {6995859E-9BFA-4D54-9059-180AA18A20CF} - C:\Program Files\Intuit\QuickBooks 2023\HelpAsyncPluggableProtocol.dll [2022-10-08] (Intuit, Inc. -> Intuit, Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll [2019-12-07] (Microsoft Windows -> Microsoft Corporation)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2019-12-07 03:14 - 2019-12-07 03:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3259427507-1055586877-3198061443-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Sue\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{3A41CBAC-D63D-45B0-BCDD-CE593C6EB293}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{53A494BB-440B-43BB-B888-4E5C7905CBA8}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{947D4551-4AEB-464F-B053-BC1819DB6DE9}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{E531F30C-28D8-49F5-9C51-F22377CC989E}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{0EAF02BE-2725-4A97-849D-3AF2C042552E}] => (Allow) C:\Program Files\Mesh Agent\MeshAgent.exe (mc.ntg.co-8edb73 -> ) [File not signed]
FirewallRules: [{EF13EEE1-2B37-4589-9615-0DB450A3A347}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [{6926B347-FC06-4364-AB7C-3791D62D4A3E}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [TCP Query User{E70C39EE-C537-4B53-8CAD-0CD0D6D5DC62}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [UDP Query User{7273A62E-C192-4FBE-B0A7-2749E19437B7}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
FirewallRules: [{9A6F0C91-EDAC-4E0A-835D-DCF6AD8E3745}] => (Allow) C:\Users\Public\Documents\Windows\QuickBooksDownloder.exe (Solanki Piyushkumar -> )
FirewallRules: [{25640E72-63CB-41AA-AAB7-3E771EA5461B}] => (Allow) C:\Users\Public\Documents\Windows\IntuitDownloadManager.exe => No File
FirewallRules: [{7D6F1BBE-49E3-4419-A620-F54CD2574AA4}] => (Allow) C:\Users\Public\Documents\Windows\QuickBooksDownloder.exe (Solanki Piyushkumar -> )
FirewallRules: [{D40BCBB0-E85A-488E-A5AE-7683650A60AB}] => (Allow) C:\Program Files\Intuit\QuickBooks 2022\CefSharp.BrowserSubprocess.exe (The CefSharp Authors) [File not signed]
FirewallRules: [{F7DD5539-4D4E-4F60-87EA-6D7503C0D851}] => (Allow) C:\Program Files\Intuit\QuickBooks 2023\CefSharp.BrowserSubprocess.exe (The CefSharp Authors) [File not signed]
FirewallRules: [{F40FD09B-2DA9-4AB3-A3D4-CE738AB00963}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C7CEA418-93BB-4E28-B30E-F2DFDFAFBA67}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{554174AB-D730-4FD4-B458-2AD13248F766}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{87A45F36-2111-4C45-80A0-D51577AAC7E1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3204.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{6C683A2E-759E-4388-BBDB-33639BC666D4}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
15-12-2022 16:01:15 Removed Windows PC Health Check
15-12-2022 16:04:21 AdwCleaner_BeforeCleaning_15/12/2022_16:04:21
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (12/26/2022 04:27:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_stisvc, version: 10.0.19041.1806, time stamp: 0x7dcad237
Faulting module name: esxw2u2.dll, version: 1.2.2.0, time stamp: 0x599d2610
Exception code: 0xc0000005
Fault offset: 0x000000000003e86b
Faulting process id: 0x8c8
Faulting application start time: 0x01d919794616d1fa
Faulting application path: C:\Windows\system32\svchost.exe
Faulting module path: C:\Windows\system32\esxw2u2.dll
Report Id: a1d8cf99-90a0-4fa3-ae7b-da625fe62bf2
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (12/20/2022 09:41:22 AM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Premier Plus Edition 2023":
WPR: JOB_END_FAIL
 
Error: (12/20/2022 09:41:14 AM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Premier Plus Edition 2023":
WPR: calling  ABORT_CLOSE
 
Error: (12/20/2022 09:32:35 AM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Premier Plus Edition 2023":
DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'q:\source\QB\Platform\Data\DatabaseManager\src\connpool.cpp' at line 1043 from function:'DBMgr::DBConnPool::init'
 
Error: (12/20/2022 09:32:35 AM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Premier Plus Edition 2023":
Connection String:CON=QBConnectionPool-Probe-QB_data_engine_33; ;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Nov22 Tender Touch Veterinary Care.QBW;ENG=QB_data_engine_33;DBN=ae15c2cb227c426c9bd542946b1b0d89
 
Error: (12/20/2022 09:32:35 AM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Premier Plus Edition 2023":
Connection Error:Invalid user ID or password
 
Error: (12/20/2022 09:32:32 AM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Premier Plus Edition 2023":
DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'q:\source\QB\Platform\Data\DatabaseManager\src\connpool.cpp' at line 1043 from function:'DBMgr::DBConnPool::init'
 
Error: (12/20/2022 09:32:32 AM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Premier Plus Edition 2023":
Connection String:CON=QBConnectionPool-Probe-QB_data_engine_33; ;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Nov22 Tender Touch Veterinary Care.QBW;ENG=QB_data_engine_33;DBN=2348fd2e2e36487e9b7ce637fa94dac3
 
 
System errors:
=============
Error: (12/26/2022 04:40:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Mesh Agent service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
 
Error: (12/26/2022 04:27:45 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Image Acquisition (WIA) service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (12/26/2022 04:27:44 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HitmanPro38CrusaderBoot service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (12/26/2022 04:27:44 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:59:05 PM on ‎12/‎20/‎2022 was unexpected.
 
Error: (12/26/2022 04:27:38 PM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 3221225684A fatal error occurred processing the restoration data.
 
Error: (12/20/2022 08:47:02 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Image Acquisition (WIA) service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (12/20/2022 08:47:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HitmanPro38CrusaderBoot service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (12/20/2022 08:46:25 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\system32\IntelIHVRouter08.dll
 
 
CodeIntegrity:
===============
Date: 2022-12-20 16:22:47
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: LENOVO M47KT21A 06/29/2022
Motherboard: LENOVO 32E4
Processor: AMD Ryzen 7 PRO 5750GE with Radeon Graphics 
Percentage of memory in use: 27%
Total physical RAM: 15751.31 MB
Available physical RAM: 11477.66 MB
Total Virtual: 18183.31 MB
Available Virtual: 13678.93 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:474.72 GB) (Free:379.39 GB) (Model: SAMSUNG MZVLB512HBJQ-000L7) NTFS
 
\\?\Volume{4574aa8f-2317-4bcf-9c02-c733a72f1cac}\ (WinRE_DRV) (Fixed) (Total:1.95 GB) (Free:1.31 GB) NTFS
\\?\Volume{d874ff2f-a813-487a-ae1a-1cc02c2d1c6b}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: 4B8FB9AB)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP