Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Gaming Computer lagging severely, disk is at 100% in task manager


  • Please log in to reply

#1
FordTaurus00

FordTaurus00

    New Member

  • Member
  • Pip
  • 4 posts

Found you guys via google and hope you can help,

 

Computer used to be really fast.   within the past several months its been getting slower and sounds like its constantly accessing the disk.   sometimes checking task manager shows disk listed at 100%   ran FRST and logs are pasted below

 

 Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-10-2023

Ran by Justin (administrator) on DESKTOP-NLGCM7D (Micro-Star International Co., Ltd. MS-7B22) (14-10-2023 10:10:27)
Running from C:\Users\Justin\Desktop\FRST64.exe
Loaded Profiles: Justin
Platform: Microsoft Windows 10 Pro Version 22H2 19045.3448 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_agent.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <15>
(explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\schtasks.exe
(services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21624.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21624.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.7272.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Micro-Star International CO., LTD. -> ) C:\Program Files\GamingOSD\mysticlight\MysticLightController.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Toast Server\MSIToastServer.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Windows\SysWOW64\muachost.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_550508a90a3c9a47\RtkAudUService64.exe [1618320 2022-11-16] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1028280 2017-11-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
HKLM-x32\...\Run: [APP Manager] => C:\Program Files (x86)\MSI\APP Manager\AppManager.exe [3705520 2019-05-20] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [759120 2015-04-22] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [835760 2019-04-30] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
HKLM-x32\...\Run: [X_Boost] => C:\Program Files (x86)\MSI\MSI X Boost\X_Boost.exe [4260000 2018-08-28] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
HKLM-x32\...\Run: [MSI Gaming Lan Manager] => C:\MSI\MSI Gaming Lan Manager\MSI_Gaming_Lan_Manager.exe [4705952 2018-12-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [26290352 2019-11-12] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1310720 2020-02-10] (Seiko Epson Corporation) [File not signed]
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\82.0.1.0\GoogleDriveFS.exe [55189280 2023-10-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\82.0.1.0\GoogleDriveFS.exe [55189280 2023-10-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4375912 2023-09-29] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [371304 2019-12-16] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIRBE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIWDE.EXE [418736 2019-08-22] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\82.0.1.0\GoogleDriveFS.exe [55189280 2023-10-09] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\Run: [SIMDashboardServer] => C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe [7606248 2023-06-12] (Christian Hausmann -> stryder-it)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\Run: [LGHUB] => C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe [45891840 2023-10-10] (Logitech Inc -> Logitech, Inc.)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\RunOnce: [Application Restart #8] => C:\Windows\SysWOW64\muachost.exe [1692840 2015-08-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Justin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Justin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" [64799664 2023-10-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\RunOnce: [Uninstall 23.194.0917.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Justin\AppData\Local\Microsoft\OneDrive\23.194.0917.0001" [0 2023-10-14] () <==== ATTENTION [zero byte File/Folder]
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [154624 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\82.0.1.0\GoogleDriveFS.exe [55189280 2023-10-09] (Google LLC -> Google, Inc.)
HKLM\...\Print\Monitors\EPSON XP-340 Series 64MonitorBE: C:\WINDOWS\system32\E_YLMBRBE.DLL [182784 2015-12-09] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
HKLM\...\Print\Monitors\EPSON XP-4100 Series 64MonitorBE: C:\WINDOWS\system32\E_YLMBWDE.DLL [187392 2018-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Seiko Epson Corporation)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\WINDOWS\system32\enppmon.dll [500736 2016-09-14] (SEIKO EPSON CORPORATION) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\117.0.5938.152\Installer\chrmstp.exe [2023-10-14] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {5734FAC2-5C5F-47CB-A7E7-3A51C40FF4E1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1566200 2023-08-02] (Adobe Inc. -> Adobe Inc.)
Task: {3F93CF44-832B-4FEE-91FA-6164B91C633C} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [506880 2019-12-04] (Advanced Micro Devices, Inc.) [File not signed]
Task: {BF7D0C0E-F498-42EC-9C13-6B156831497B} - System32\Tasks\EPSON XP-340 Series Update {103F1E32-CDC2-4856-AD44-BBB597C2DB07} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSRBE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Task: {FE725D3E-8526-42EA-8FD4-A06855ADCABA} - System32\Tasks\EPSON XP-4100 Series Update {BFD293AF-FFA6-498C-BE06-A6071F75EBC4} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSWDE.EXE [680440 2017-06-07] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Task: {44B601B2-F32C-4FE5-8D06-AC23C3E425E0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-11-25] (Google Inc -> Google Inc.)
Task: {0288F21C-BF70-46FD-BBE5-BE9D295BFF80} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-11-25] (Google Inc -> Google Inc.)
Task: {4B453DE0-5CC6-43A9-B0E4-1BE35AABBF1F} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe [818008 2021-09-15] (Intel Corporation -> Intel® Corporation)
Task: {1AD9E188-5C67-48EA-8E7D-35F27EC4BAE3} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [1625400 2018-06-29] (Intel® Software -> Intel Corporation)
Task: {2897278A-57EF-48DF-BAAE-B861754AA222} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-09-28] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {15A3A4C9-B124-4F06-8DBA-4368BFBFE83A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-09-28] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BC7FF2EE-BC78-494C-8103-A88301E242EA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-09-28] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F22FAD66-CBCA-4067-9A14-AEE32A076339} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-09-28] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {691349F3-7743-4DFF-B72D-85D9E91913B3} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [506880 2019-12-04] (Advanced Micro Devices, Inc.) [File not signed]
Task: {35552BF4-561D-4B0B-8E18-2C7343788CB6} - System32\Tasks\MonitorMysticLight => C:\Program Files\GamingOSD\MysticLight\MysticLightController.exe [31224 2018-11-09] (Micro-Star International CO., LTD. -> )
Task: {DC2071F1-9CB6-4E4C-BC98-28BFEC28D2AE} - System32\Tasks\MSI_Toast_Server => C:\Program Files (x86)\MSI\MSI Toast Server\MSIToastServer.exe [31904 2019-03-05] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
Task: {FA8E0775-3CC5-4F24-8AD2-9CC03D0FBF1D} - System32\Tasks\MSIGH_Host => C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey.exe [3354296 2019-01-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
Task: {3A09A61F-08DD-4524-882C-F0B87786AFEA} - System32\Tasks\MSILEDKeeper_Host => C:\Program Files (x86)\MSI\MysticLight\LEDKeeper.exe [1049744 2019-06-05] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
Task: {0E93192D-8631-464A-B509-7732C16DC686} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [1692840 2015-08-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
Task: {399A79B2-36E4-499F-B75D-40A908D6D797} - System32\Tasks\SIMDB_75b6e096fc79c825286efd6614b8d0f4 => C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe [7606248 2023-06-12] (Christian Hausmann -> stryder-it)
Task: {ADEAA972-638C-4B5E-BA7A-103782CF5286} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61624 2019-12-05] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {C4BCA1FB-39AD-4CC9-9793-9C8AD425BC66} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [69304 2019-12-05] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\EPSON XP-340 Series Update {103F1E32-CDC2-4856-AD44-BBB597C2DB07}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSRBE.EXE:/EXE:{103F1E32-CDC2-4856-AD44-BBB597C2DB07} /F:UpdateWORKGROUP\DESKTOP-NLGCM7D$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\EPSON XP-4100 Series Update {BFD293AF-FFA6-498C-BE06-A6071F75EBC4}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSWDE.EXE:/EXE:{BFD293AF-FFA6-498C-BE06-A6071F75EBC4} /F:UpdateWORKGROUP\DESKTOP-NLGCM7D$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\MSILEDKeeper_Host.job => C:\Program Files (x86)\MSI\MysticLight\LEDKeeper.exe
Task: C:\WINDOWS\Tasks\MSISW_Host.job => C:\WINDOWS\SysWOW64\muachost.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{6cec44a2-fa1b-42ba-b0b9-ba138a802357}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Edge: 
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\Justin\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-27]
 
FireFox:
========
FF DefaultProfile: ygbukk4o.default
FF ProfilePath: C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\ygbukk4o.default [2020-12-20]
FF ProfilePath: C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\0ryq3nzy.default-release [2020-12-20]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2023-09-06] (Adobe Inc. -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\Justin\AppData\Local\Google\Chrome\User Data\Default [2023-10-14]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Justin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2023-10-10]
CHR Extension: (Google Docs Offline) - C:\Users\Justin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-09-18]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\Justin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-09-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Justin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-31]
CHR HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-08-02] (Adobe Inc. -> Adobe Inc.)
S4 cFosSpeedS; C:\Program Files\cFosSpeed\spd.exe [605528 2018-08-14] (cFos Software GmbH -> cFos Software GmbH)
S4 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4452456 2019-12-16] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S4 Dynamsoft WebTWAIN Service; C:\Windows\SysWOW64\Dynamsoft\DynamicWebTwain\ForChrome\WebTWAINService.exe [1347088 2015-08-31] (DynamSoft Corporation -> Dynamsoft Corporation)
S4 Epson PMAService A; C:\Program Files (x86)\Epson Software\PMA_A\PMAService.exe [113144 2017-03-28] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S4 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [678328 2018-06-11] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
S4 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [145224 2016-11-08] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S4 GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [46776 2018-09-06] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
S4 GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2027192 2019-01-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [10688256 2023-10-10] (Logitech Inc -> Logitech, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9287968 2023-10-08] (Malwarebytes Inc. -> Malwarebytes)
S4 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService_x64.exe [2669240 2018-01-12] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S4 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2343608 2018-11-19] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S4 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService_x64.exe [2725048 2017-12-22] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S4 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [2255544 2018-11-19] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S4 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2507952 2019-05-08] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S4 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2136248 2018-03-29] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S4 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [2742968 2018-08-23] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S4 MSI_ActiveX_Service; C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [86688 2018-07-25] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
S4 MSI_AppManager_Service; C:\Program Files (x86)\MSI\APP Manager\AppManager_Service.exe [2055352 2019-01-04] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S4 MSI_DPCLTSERVICE; C:\Program Files (x86)\MSI\DPC Latency Tuner\DPCLT_Service.exe [2167440 2019-04-19] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
S4 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [113336 2017-12-21] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S4 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2323632 2019-11-07] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
S4 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [183480 2019-02-14] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S4 MysticLight2_Service; C:\Program Files (x86)\MSI\MysticLight\MysticLight2_Service.exe [34976 2018-12-20] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
S4 NahimicService; C:\WINDOWS\system32\NahimicService.exe [1888424 2021-10-08] (A-Volute SAS -> Nahimic)
S4 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1934744 2021-06-27] (Rockstar Games, Inc. -> Rockstar Games)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402264 2023-09-12] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe [3116904 2023-09-28] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe [133584 2023-09-28] (Microsoft Windows Publisher -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [54720 2022-10-21] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\amdkmdag.sys [94467928 2023-04-06] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 BlueStacksDrv_msi2; C:\Program Files\BlueStacks_msi2\BstkDrv.sys [303712 2019-01-23] (Bluestack Systems, Inc. -> Bluestack System Inc.)
R1 cFosSpeed; C:\WINDOWS\system32\DRIVERS\cfosspeed6.sys [1570232 2018-08-13] (cFos Software GmbH -> cFos Software GmbH)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2019-12-16] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2019-12-16] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R1 EneIo; C:\Windows\system32\drivers\ene.sys [16320 2018-03-20] (Ptolemy Tech Co., Ltd -> )
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2022-12-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R1 googledrivefs31092; C:\WINDOWS\System32\DRIVERS\googledrivefs31092.sys [384600 2023-02-06] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 I2cHkBurn; C:\WINDOWS\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (Feature Integration Technology -> FINTEK Corp.)
R3 logi_generic_hid_filter; C:\WINDOWS\system32\drivers\logi_generic_hid_filter.sys [62288 2023-06-28] (Logitech Inc -> Logitech)
R3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [44880 2023-08-05] (Logitech Inc -> Logitech)
R3 logi_joy_hid_filter; C:\WINDOWS\system32\drivers\logi_joy_hid_filter.sys [63824 2023-06-28] (Logitech Inc -> Logitech)
R3 logi_joy_hid_lo; C:\WINDOWS\system32\drivers\logi_joy_hid_lo.sys [51536 2023-06-28] (Logitech Inc -> Logitech)
R3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [32080 2023-06-28] (Logitech Inc -> Logitech)
R3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [73040 2023-08-05] (Logitech Inc -> Logitech)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [222272 2023-10-10] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2022-10-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [200104 2023-10-14] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2022-12-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [181984 2023-10-14] (Malwarebytes Inc. -> Malwarebytes)
R3 MpKslcb6d747a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{00A3B998-FE01-4329-AEB2-7BC56380F4DD}\MpKslDrv.sys [263560 2023-10-14] (Microsoft Windows -> Microsoft Corporation)
R3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [85616 2021-08-13] (A-Volute -> Windows ® Win 7 DDK provider)
S3 NTIOLib_DPC; C:\Program Files (x86)\MSI\DPC Latency Tuner\NTIOLib_X64.sys [14288 2017-03-29] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [14288 2017-03-29] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S3 NTIOLib_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [14288 2017-03-15] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55856 2023-09-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [572712 2023-09-28] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105872 2023-09-28] (Microsoft Windows -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2023-10-14 10:10 - 2023-10-14 10:12 - 000028180 _____ C:\Users\Justin\Desktop\FRST.txt
2023-10-14 10:10 - 2023-10-14 10:10 - 000000000 ____D C:\Users\Justin\Desktop\FRST-OlderVersion
2023-10-14 10:09 - 2023-10-14 10:11 - 000000000 ____D C:\FRST
2023-10-14 10:08 - 2023-10-14 10:10 - 002383360 _____ (Farbar) C:\Users\Justin\Desktop\FRST64.exe
2023-10-14 08:03 - 2023-10-14 08:09 - 000000000 ___HD C:\$WinREAgent
2023-10-14 07:52 - 2023-10-14 07:52 - 000181984 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2023-10-10 19:47 - 2023-10-10 19:47 - 000000000 ____D C:\Users\Justin\AppData\Local\LGHUB
2023-10-10 19:46 - 2023-10-10 19:48 - 000000000 ____D C:\Users\Justin\AppData\Roaming\lghub
2023-10-10 19:46 - 2023-10-10 19:46 - 000000932 _____ C:\Users\Public\Desktop\Logitech G HUB.lnk
2023-10-10 19:46 - 2023-10-10 19:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi
2023-10-10 19:45 - 2023-10-10 19:46 - 000000000 ____D C:\ProgramData\LGHUB
2023-09-18 17:35 - 2023-10-10 19:48 - 000000000 ____D C:\Users\Justin\AppData\Roaming\G HUB
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2023-10-14 10:10 - 2021-12-15 18:36 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-10-14 10:10 - 2019-11-25 12:41 - 000000000 ____D C:\Program Files (x86)\Google
2023-10-14 10:05 - 2021-05-10 20:59 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-10-14 09:35 - 2019-11-25 12:41 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-10-14 09:35 - 2019-11-25 12:41 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-10-14 09:29 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-10-14 09:24 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-10-14 08:22 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2023-10-14 08:22 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-10-14 08:10 - 2021-12-15 08:06 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3020459029-3775271098-2569446579-1002
2023-10-14 08:10 - 2021-05-10 21:20 - 000003382 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3020459029-3775271098-2569446579-1002
2023-10-14 08:10 - 2021-05-10 14:51 - 000002431 _____ C:\Users\Justin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-10-14 08:01 - 2023-04-27 07:14 - 000000000 ____D C:\Users\Justin\AppData\Local\Malwarebytes
2023-10-14 07:50 - 2021-10-27 13:05 - 000003128 _____ C:\WINDOWS\system32\Tasks\AMDInstallLauncher
2023-10-14 07:49 - 2021-05-10 14:51 - 000000000 ____D C:\Users\Justin
2023-10-14 07:47 - 2021-05-10 21:20 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-10-14 07:47 - 2021-05-10 20:58 - 000008192 ___SH C:\DumpStack.log.tmp
2023-10-10 20:43 - 2019-11-25 14:01 - 000000000 ____D C:\Program Files (x86)\Steam
2023-10-10 19:48 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2023-10-10 19:46 - 2023-06-28 10:31 - 000000000 ____D C:\Program Files\LGHUB
2023-10-10 19:37 - 2021-05-03 13:45 - 000000000 ____D C:\Users\Justin\AppData\Local\BeamNG.drive
2023-10-10 19:33 - 2019-12-15 10:45 - 000000000 ____D C:\Users\Justin\AppData\Local\D3DSCache
2023-10-10 19:32 - 2019-11-25 14:02 - 000000000 ____D C:\Users\Justin\AppData\Local\Steam
2023-10-10 17:52 - 2023-07-16 09:30 - 000003068 _____ C:\WINDOWS\system32\Tasks\SIMDB_75b6e096fc79c825286efd6614b8d0f4
2023-10-10 17:06 - 2019-11-25 14:00 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-10-10 17:01 - 2019-11-25 14:00 - 181553176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-10-09 16:12 - 2021-09-23 09:03 - 000002166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2023-10-09 16:12 - 2021-09-23 09:03 - 000002084 _____ C:\Users\Justin\Desktop\Google Slides.lnk
2023-10-09 16:12 - 2021-09-23 09:03 - 000002084 _____ C:\Users\Justin\Desktop\Google Sheets.lnk
2023-10-09 16:12 - 2021-09-23 09:03 - 000002072 _____ C:\Users\Justin\Desktop\Google Docs.lnk
2023-10-09 16:12 - 2021-09-23 09:03 - 000002048 _____ C:\Users\Justin\Desktop\Google Drive.lnk
2023-10-07 20:17 - 2021-04-15 00:43 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-10-07 20:17 - 2021-04-15 00:43 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-10-05 02:04 - 2022-02-18 19:40 - 000000000 ____D C:\Program Files\RUXIM
2023-09-28 01:59 - 2019-07-18 17:07 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2023-09-26 14:50 - 2019-07-18 17:10 - 000000000 ____D C:\ProgramData\Packages
2023-09-18 15:05 - 2021-05-10 21:20 - 000003714 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2023-09-18 15:05 - 2021-05-10 21:20 - 000003590 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-10-2023
Ran by Justin (14-10-2023 10:17:08)
Running from C:\Users\Justin\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.3448 (X64) (2021-05-11 01:21:22)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-3020459029-3775271098-2569446579-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3020459029-3775271098-2569446579-503 - Limited - Disabled)
Guest (S-1-5-21-3020459029-3775271098-2569446579-501 - Limited - Enabled)
Justin (S-1-5-21-3020459029-3775271098-2569446579-1002 - Administrator - Enabled) => C:\Users\Justin
WDAGUtilityAccount (S-1-5-21-3020459029-3775271098-2569446579-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Disabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 23.006.20320 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601052}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 19.12.2 - Advanced Micro Devices, Inc.)
Back to the Future - The Game (HKLM-x32\...\1207659097_is1) (Version: 2.1.0.5 - GOG.com)
Big Fish: Game Manager (HKLM-x32\...\BFGC) (Version: 3.3.0.2 - )
cFosSpeed v10.27 (HKLM\...\cFosSpeed) (Version: 10.27 - cFos Software GmbH, Bonn)
Community Modpack for Mafia: The City of Lost Heaven (HKLM-x32\...\Community Modpack for Mafia: The City of Lost Heaven_is1) (Version:  - Rimsky)
Core Temp 1.15.1 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.15.1 - ALCPU)
CPUID CPU-Z MSI 1.88 (HKLM\...\CPUID CPU-Z MSI_is1) (Version: 1.88 - CPUID, Inc.)
CPUID HWMonitor 1.41 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.41 - CPUID, Inc.)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.11.0.1001 - Disc Soft Ltd)
DVD Flick 1.3.0.7 (HKLM-x32\...\DVD Flick_is1) (Version: 1.3.0.7 - Dennis Meuwissen)
Dynamic Web TWAIN HTML5 Edition (HKLM-x32\...\{B4D31736-4D13-4BCD-B050-7DD3E45C1650}) (Version: 11.1.831 - Dynamsoft)
Easy Photo Scan (HKLM-x32\...\{9E3F2EC3-7E4F-4F20-A56F-7A24D6E3D39B}) (Version: 1.00.0017 - Seiko Epson Corporation)
ENE RGB HAL (HKLM\...\{095C8467-BF29-4384-B727-1C36ED8BC704}) (Version: 1.00.08 - Ene Tech.) Hidden
ENE RGB HAL (HKLM-x32\...\{164b6011-4720-403c-8ee0-dae7640cce9f}) (Version: 1.00.08 - Ene Tech.) Hidden
Epson Customer Research Participation (HKLM\...\{B26449A6-6007-4460-B4FE-C4776115BCEA}) (Version: 1.83.0000 - Seiko Epson Corporation)
Epson Event Manager (HKLM-x32\...\{DBC38C08-9FB5-43A5-B6BA-EB10AC7DA570}) (Version: 3.11.0053 - Seiko Epson Corporation)
Epson ReadyInk Agent (A) (HKLM-x32\...\{A9B4584F-A29E-4880-97E6-1744B4AF2AF8}) (Version: 1.0.2.0 - Seiko Epson Corporation)
Epson Scan 2 (HKLM-x32\...\Epson Scan 2) (Version:  - Seiko Epson Corporation)
EPSON Scan OCR Component (HKLM-x32\...\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}) (Version: 3.00.04 - SEIKO EPSON Corp.)
Epson Software Updater (HKLM-x32\...\{D2D9559D-359A-4C61-B93A-FE01AE2BFB75}) (Version: 4.5.4 - Seiko Epson Corporation)
EPSON XP-340 Series Printer Uninstall (HKLM\...\EPSON XP-340 Series) (Version:  - Seiko Epson Corporation)
EPSON XP-4100 Series Printer Uninstall (HKLM\...\EPSON XP-4100 Series) (Version:  - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
GamingOSD(x64) (HKLM\...\{11E14722-1213-4021-AD72-32252315CB8B}) (Version: 0.0.2.3 - MICRO-STAR INT'L,.LTD.) Hidden
GamingOSD(x64) (HKLM-x32\...\Installshield_{11E14722-1213-4021-AD72-32252315CB8B}) (Version: 0.0.2.3 - MICRO-STAR INT'L,.LTD.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 117.0.5938.152 - Google LLC)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 82.0.1.0 - Google LLC)
Google Drive (HKLM-x32\...\{459CE109-4E46-4340-92BC-054642BC3BC2}) (Version: 1.31.2873.2758 - Google, Inc.)
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
HandBrake 1.3.3 (HKLM-x32\...\HandBrake) (Version: 1.3.3 - )
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
Intel® Chipset Device Software (HKLM\...\{97B7DB53-C2AD-46EF-8310-20F8CE5AEFE1}) (Version: 10.1.17968.8131 - Intel Corporation) Hidden
Intel® Chipset Device Software (HKLM-x32\...\{ffddf9dd-c47f-453a-92f5-ac6c98af8b5b}) (Version: 10.1.17968.8131 - Intel® Corporation)
Intel® Extreme Tuning Utility (HKLM-x32\...\{78de1723-f95d-4e02-b94d-f748c484863a}) (Version: 6.5.0.83 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 1912.12.0.1246 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{38FF9297-58C2-414F-BD49-355872F8418D}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{7AA30DD8-C2AC-4523-AA73-BBAA60B6EF00}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Driver (HKLM\...\{05622855-82CE-4EF6-B20B-6BCCAAA1DA09}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Network Connections 23.5.0.0 (HKLM\...\{967E7483-38D0-40E3-A44C-BAC69E0DC853}) (Version: 23.5.0.0 - Intel) Hidden
Intel® Network Connections 23.5.0.0 (HKLM\...\PROSetDX) (Version: 23.5.0.0 - Intel)
Intel® Trusted Connect Service Client x64 (HKLM\...\{C9552825-7BF2-4344-BA91-D3CD46F4C442}) (Version: 1.52.230.1 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.52.230.1 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (HKLM-x32\...\{c6de84fd-ece7-4c2a-9f06-8cabe7ab79a0}) (Version: 1.52.230.1 - Intel Corporation) Hidden
Logitech G HUB (HKLM\...\{521c89be-637f-4274-a840-baaf7460c2b2}) (Version: 2023.8.459147 - Logitech)
Mafia III (HKLM-x32\...\Mafia III_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, markfiter)
Malwarebytes version 4.6.3.282 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.3.282 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 117.0.2045.60 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 117.0.2045.60 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\OneDriveSetup.exe) (Version: 23.199.0924.0001 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU CTP1 (HKLM\...\{FAF57A91-58B3-490C-9D0C-66337DAD3F11}) (Version: 4.0.8854.1 - Microsoft Corporation) Hidden
Microsoft Update Health Tools (HKLM\...\{2953E19B-9F91-4A49-A23B-7E25970A1951}) (Version: 3.73.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{A62CB02D-E417-4243-8A6B-50E22F75AB9F}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{D96BF0A6-7612-41CB-9E7D-2386AF6F8E42}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29334 (HKLM-x32\...\{b2d0f752-adc5-496e-8f70-8669de01f746}) (Version: 14.28.29334.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.34.31931 (HKLM-x32\...\{d4cecf3b-b68f-4995-8840-52ea0fab646e}) (Version: 14.34.31931.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29334 (HKLM-x32\...\{14C49FC8-3E9B-4F29-8526-26629B5CF30B}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29334 (HKLM-x32\...\{0D01A812-82A1-481F-8546-8E28E976F8DF}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.34.31931 (HKLM\...\{EAE242B1-0A26-485A-BFEB-0292EE9F03CB}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.34.31931 (HKLM\...\{CF4C347D-954E-4543-88D2-EC17F07F466F}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Midnight in Salem 1.0 CL_11638 (HKLM-x32\...\{6460A41D-13B4-4A1F-90AC-D257DCD61DA0}_is1) (Version: 1.0 - HeR Interactive)
Midnight Mysteries Devil on the Mississippi (HKLM-x32\...\Midnight Mysteries Devil on the Mississippi) (Version: 1.1.0.0 - MumboJumbo)
Midnight Mysteries Haunted Houdini (HKLM-x32\...\Midnight Mysteries Haunted Houdini) (Version: 1.1.0.0 - MumboJumbo)
Midnight Mysteries Salem Witch Trials (HKLM-x32\...\Midnight Mysteries Salem Witch Trials) (Version: 1.1.0.0 - MumboJumbo)
Midnight Mysteries the Edgar Allan Poe Conspiracy (HKLM-x32\...\Midnight Mysteries the Edgar Allan Poe Conspiracy) (Version: 1.1.0.0 - MumboJumbo)
MSI APP Manager (HKLM-x32\...\{00F47104-12BA-4E58-A7E6-F456C1BA338E}}_is1) (Version: 1.0.0.32 - MSI)
MSI App Player (HKLM\...\BlueStacks_msi2) (Version: 4.31.59.3005 - BlueStack Systems, Inc.)
MSI Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 3.0.0.94 - MSI)
MSI Display Kit(x64) (HKLM\...\{5A8E3E72-D260-4DB3-BCE3-AF47C364F275}) (Version: 0.0.1.1 - MSI) Hidden
MSI Display Kit(x64) (HKLM-x32\...\Installshield_{5A8E3E72-D260-4DB3-BCE3-AF47C364F275}) (Version: 0.0.1.1 - MICRO-STAR INT'L,.LTD.)
MSI DPC Latency Tuner (HKLM-x32\...\{1AAC56F3-3F60-47DB-BE6B-088F36ADFDC5}_is1) (Version: 1.0.0.38 - MSI)
MSI Fast Boot (HKLM-x32\...\{0F212E7A-65EB-4668-A8D7-749026A64F8E}_is1) (Version: 1.0.1.15 - MSI)
MSI Gaming APP (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 6.2.0.88 - MSI)
MSI Gaming Lan Manager (HKLM-x32\...\{3318282C-D4D6-4B29-BBD5-95FC34B54FF0}_is1) (Version: 2.0.0.13 - MSI)
MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.2.0.63 - MSI)
MSI MysticLight (HKLM-x32\...\{93874B70-6C5E-446A-AF4D-E5AC776A0386}}_is1) (Version: 3.0.0.56 - MSI)
MSI Smart Tool (HKLM-x32\...\{DDCCA038-DAB1-4D09-B85C-848020AA75D6}}_is1) (Version: 1.0.0.41 - MSI)
MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.3.0.28 - MSI)
MSI X Boost (HKLM-x32\...\{515143BB-7A11-4D85-B941-D520AAAA099C}_is1) (Version: 1.0.0.46 - MSI)
Nancy Drew The Silent Spy 1.00 (HKLM-x32\...\Nancy Drew The Silent Spy 1.00) (Version: 1.00 - Games)
Nancy Drew: Labyrinth of Lies (HKLM-x32\...\BFG-Nancy Drew - Labyrinth of Lies) (Version:  - )
Nancy Drew: The Deadly Device (HKLM-x32\...\{CC7341D8-5CBC-4A2B-8442-6846027A7A79}) (Version: 1.00 - Her Interactive)
Nancy Drew: The Shattered Medallion (HKLM-x32\...\BFG-Nancy Drew - The Shattered Medallion) (Version:  - )
Nancy Drew: Tomb of the Lost Queen (HKLM-x32\...\{56CCBC54-8CEE-479F-9302-E0651BCBA13D}) (Version: 1.00 - Her Interactive)
Naviextras Toolbox (HKLM-x32\...\Naviextras Toolbox) (Version: 3.9.0.18087 - NNG Llc.)
Naviextras Toolbox Prerequesities (HKLM-x32\...\{537575D6-3B96-474C-BD8F-DFF667363DBD}) (Version: 1.0.0 - NNG Llc.)
Need for Speed Underground 2 (HKLM-x32\...\Need for Speed Underground 2) (Version:  - )
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OBS Multiplatform (HKLM-x32\...\OBS Multiplatform) (Version: 0.10.2 - OBS Project)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8858.1 - Realtek Semiconductor Corp.)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.42.369 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.8.5 - Rockstar Games)
SIMDashboardServer (HKLM-x32\...\{037C1DB1-CC56-4A0C-98CB-4A7F03CCCE3F}) (Version: 3.14.0.0 - stryder-it)
SnowRunner (HKLM-x32\...\SnowRunner_is1) (Version:  - )
Spintires MudRunner American Wilds (HKLM-x32\...\Spintires MudRunner American Wilds_is1) (Version:  - )
Spotify (HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\Spotify) (Version: 1.1.34.694.gac68a2b3 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TANE (HKLM-x32\...\TANE_sp4-com.n3vgames.tane-windows-4e2b8aa58576c14cb85a1b169cd64f66) (Version:  - N3V Games)
TurboTax 2018 (HKLM-x32\...\TurboTax 2018) (Version: 2018.0 - Intuit, Inc)
TurboTax 2018 WinPerFedFormset (HKLM-x32\...\{4F5D754A-4CF7-489E-9FC7-DCF124A9C13B}) (Version: 018.000.3420 - Intuit Inc.) Hidden
TurboTax 2018 WinPerReleaseEngine (HKLM-x32\...\{3B81DEB0-2307-4542-A370-47D7B15B4EE5}) (Version: 018.000.0674 - Intuit Inc.) Hidden
TurboTax 2018 WinPerTaxSupport (HKLM-x32\...\{E9FCBA33-DB82-4992-A4FE-3A2D4C974DD7}) (Version: 018.000.0130 - Intuit Inc.) Hidden
TurboTax 2018 wpaiper (HKLM-x32\...\{E0988D30-4BF7-45B3-8547-CE76CF6AD089}) (Version: 018.000.1338 - Intuit Inc.) Hidden
TurboTax 2018 wrapper (HKLM-x32\...\{B29215FE-D5C4-4C2D-BDA1-11EBF3638653}) (Version: 018.000.0109 - Intuit Inc.) Hidden
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{7B63012A-4AC6-40C6-B6AF-B24A84359DD5}) (Version: 8.93.0.0 - Microsoft Corporation)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
WinRAR 5.80 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.80.0 - win.rar GmbH)
 
Packages:
=========
Any DVD -> C:\Program Files\WindowsApps\15191PeakPlayer.50533F9B98293_3.2.34.0_x64__y5c4dfz5b21fm [2023-10-03] (Any DVD &amp; Office App)
Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe [2023-08-12] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-05-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-05-10] (Microsoft Corporation) [MS Ad]
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-12-01] (Microsoft Corporation)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.38.277.0_x64__dt26b99r8h8gj [2023-03-28] (Realtek Semiconductor Corp)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.17.10050.0_x64__8wekyb3d8bbwe [2023-10-09] (Microsoft Studios) [MS Ad]
Windows Package Manager Source (winget) -> C:\Program Files\WindowsApps\Microsoft.Winget.Source_2023.928.2303.555_neutral__8wekyb3d8bbwe [2023-09-28] (Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3020459029-3775271098-2569446579-1002_Classes\CLSID\{80172dde-4e20-4df0-81a2-0a48553e80bb}\localserver32 -> C:\Users\Justin\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe (A-Volute SAS -> A-Volute)
CustomCLSID: HKU\S-1-5-21-3020459029-3775271098-2569446579-1002_Classes\CLSID\{BFBE0943-74C5-40E0-9E80-0B808109E95D}\InprocServer32 -> C:\Users\Justin\AppData\Local\Microsoft\EdgeUpdate\1.3.163.19\psuser_64.dll => No File
ShellIconOverlayIdentifiers: [    GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [    GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [    GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [    GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google Inc -> Google)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-19] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2016-07-29] (Google Inc -> Google)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2019-12-16] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2019-12-16] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-03-04] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-19] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2016-07-29] (Google Inc -> Google)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll -> No File
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-03-04] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\Justin\Desktop\Google Drive.lnk -> C:\Program Files\Google\Drive File Stream\launch.bat ()
ShortcutWithArgument: C:\Users\Justin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\d249d9ddd424b688\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default
 
==================== Loaded Modules (Whitelisted) =============
 
2019-07-18 14:33 - 2019-07-18 14:33 - 000017920 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libEGL.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 003567616 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2018-04-11 18:28 - 2018-04-11 18:28 - 006160384 _____ () [File not signed] C:\Program Files\GamingOSD\MysticLight\Library\MSIMysticDll.dll
2019-12-05 00:14 - 2019-12-05 00:14 - 001516544 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\AMD\WVR\OpenVR\bin\win64\driver_amdwvr.dll
2010-11-19 01:08 - 2010-11-19 01:08 - 000086016 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2016-09-14 17:31 - 2016-09-14 17:31 - 000500736 ____S (SEIKO EPSON CORPORATION) [File not signed] C:\WINDOWS\System32\enppmon.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000031744 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qgif.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000039424 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qicns.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000031744 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qico.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000413696 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qjpeg.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000025088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qsvg.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000025088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qtga.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000023552 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwbmp.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000519168 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwebp.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 001431040 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\platforms\qwindows.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 001180672 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\sqldrivers\qsqlite.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000135680 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\styles\qwindowsvistastyle.dll
2019-12-05 00:23 - 2019-12-05 00:23 - 006010880 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 006345216 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 001078272 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000313856 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Positioning.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 004000256 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 003802624 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000171008 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5QuickControls2.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 001083904 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5QuickTemplates2.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000205312 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Sql.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000329728 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Svg.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000113152 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebChannel.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000376320 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebEngine.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 092323328 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebEngineCore.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 005560832 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000463360 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000188416 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 002888704 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5XmlPatterns.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000053760 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000059392 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000017408 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000287232 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls.2\qtquickcontrols2plugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000329216 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000136192 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000089088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000312320 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Templates.2\qtquicktemplates2plugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000017920 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2019-12-05 00:23 - 2019-12-05 00:23 - 000085504 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtWebEngine\qtwebengineplugin.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F [270]
AlternateDataStreams: C:\ProgramData\TEMP:CFBF7F81 [255]
AlternateDataStreams: C:\ProgramData\TEMP:DBF60C66 [244]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2019-03-19 00:49 - 2019-03-19 00:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\DAL
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\MSI\GAMING PLUS.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1)
Windows Firewall is enabled.
 
Network Binding:
=============
Ethernet: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled) 
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AMD Crash Defender Service => 2
MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: cFosSpeedS => 2
MSCONFIG\Services: Disc Soft Lite Bus Service => 3
MSCONFIG\Services: Dynamsoft WebTWAIN Service => 2
MSCONFIG\Services: Epson PMAService A => 2
MSCONFIG\Services: EpsonCustomerResearchParticipation => 2
MSCONFIG\Services: EpsonScanSvc => 2
MSCONFIG\Services: GamingApp_Service => 2
MSCONFIG\Services: GamingHotkey_Service => 2
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: Intel® Capability Licensing Service TCP IP Interface => 3
MSCONFIG\Services: Intel® PROSet Monitoring Service => 2
MSCONFIG\Services: Intel® TPM Provisioning Service => 2
MSCONFIG\Services: IntuitUpdateServiceV4 => 2
MSCONFIG\Services: jhi_service => 2
MSCONFIG\Services: LGHUBUpdaterService => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MSIClock_CC => 3
MSCONFIG\Services: MSICOMM_CC => 3
MSCONFIG\Services: MSICPU_CC => 3
MSCONFIG\Services: MSICTL_CC => 2
MSCONFIG\Services: MSIDDR_CC => 3
MSCONFIG\Services: MSISMB_CC => 3
MSCONFIG\Services: MSISuperIO_CC => 3
MSCONFIG\Services: MSI_ActiveX_Service => 2
MSCONFIG\Services: MSI_AppManager_Service => 2
MSCONFIG\Services: MSI_DPCLTSERVICE => 2
MSCONFIG\Services: MSI_FastBoot => 2
MSCONFIG\Services: MSI_LiveUpdate_Service => 2
MSCONFIG\Services: MSI_SuperCharger => 2
MSCONFIG\Services: MysticLight2_Service => 2
MSCONFIG\Services: NahimicService => 2
MSCONFIG\Services: Rockstar Service => 3
MSCONFIG\Services: RtkAudioUniversalService => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: XTU3SERVICE => 2
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKLM\...\StartupApproved\Run32: => "X_Boost"
HKLM\...\StartupApproved\Run32: => "EEventManager"
HKLM\...\StartupApproved\Run32: => "Super Charger"
HKLM\...\StartupApproved\Run32: => "Fast Boot"
HKLM\...\StartupApproved\Run32: => "Command Center"
HKLM\...\StartupApproved\Run32: => "MSI Gaming Lan Manager"
HKLM\...\StartupApproved\Run32: => "Live Update"
HKLM\...\StartupApproved\Run32: => "APP Manager"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "EPLTarget\P0000000000000000"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "EPLTarget\P0000000000000001"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "GoogleDriveFS"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "ut"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "SIMDashboardServer"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "utweb"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{7A77FB92-29EE-4EED-8C0D-DAF8BC456376}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BeamNG.drive\BeamNG.drive.exe (BeamNG GmbH -> BeamNG GmbH)
FirewallRules: [{27373D4E-8F64-4EDD-AD67-EF46995BB6F2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BeamNG.drive\BeamNG.drive.exe (BeamNG GmbH -> BeamNG GmbH)
FirewallRules: [{D5573D42-7855-45B5-ADF7-A6B524B74332}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021 Demo\Car Mechanic Simulator 2021 Demo.exe => No File
FirewallRules: [{02BFF45C-2C2A-4C52-8A4F-1F8DF7462EE2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021 Demo\Car Mechanic Simulator 2021 Demo.exe => No File
FirewallRules: [{E5277D3C-00FE-49EE-9E38-7EF6EACCE4D9}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe => No File
FirewallRules: [{7B2F66BB-6732-45BC-A503-61316C41ED13}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe => No File
FirewallRules: [{9BF5FB73-B5F8-4D46-A46A-BE3A058F1179}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [{FD5184E1-6FEF-4C84-BAE3-3876C663F3F3}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [{31BCD554-FCEA-4A70-A9E1-583AC162BAC7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe => No File
FirewallRules: [{D7BC18F7-4E02-4AB6-82B9-CA271EAC1671}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\launcher.exe => No File
FirewallRules: [{4A64961F-D4EC-4641-98FE-9139FDF6E12E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\launcher.exe => No File
FirewallRules: [UDP Query User{517666D0-9441-4717-A531-E750AA56A064}C:\users\justin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\justin\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{E4EBDE48-BE47-426A-A73A-8B109AF2ED80}C:\users\justin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\justin\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A97AF0AB-2259-401F-BBC6-8AFF72DF088B}] => (Allow) C:\Users\Justin\AppData\Local\Temp\XP-340\Network\EpsonNetSetup\ENEasyApp.exe => No File
FirewallRules: [{BC7FD00E-64AD-43CF-9931-38936160E595}] => (Allow) C:\Users\Justin\AppData\Local\Temp\XP-340\Network\EpsonNetSetup\ENEasyApp.exe => No File
FirewallRules: [{824E20D3-32AC-4363-9EB9-34F70C30B4C1}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [{4A2387B6-778C-4CEB-82F5-BA93947522E4}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [UDP Query User{FEAFA2C0-DE0D-4C4B-8BB0-5CE07F9914BB}C:\users\justin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\justin\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{03B0D85B-D716-44E5-883B-A84A5A337AC9}C:\users\justin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\justin\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{83187A5E-819A-4142-A0D4-2E0320C4DBE2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II Definitive Edition\pc\Mafia2Launcher\Launcher.exe => No File
FirewallRules: [{D3FABB4D-62B7-4A5A-8532-4D46899595C8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II Definitive Edition\pc\Mafia2Launcher\Launcher.exe => No File
FirewallRules: [UDP Query User{1081D3FE-36E3-4C43-99C8-4BD6B40162C6}C:\users\justin\appdata\local\temp\ign4699.tmp\lmiignition.exe] => (Allow) C:\users\justin\appdata\local\temp\ign4699.tmp\lmiignition.exe => No File
FirewallRules: [TCP Query User{1AF96D7A-6365-4523-BA1E-299D2475E399}C:\users\justin\appdata\local\temp\ign4699.tmp\lmiignition.exe] => (Allow) C:\users\justin\appdata\local\temp\ign4699.tmp\lmiignition.exe => No File
FirewallRules: [UDP Query User{03DCBC42-16D2-4F77-B2B2-9AB860EE7E03}C:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) C:\program files\rockstar games\grand theft auto v\gta5.exe => No File
FirewallRules: [TCP Query User{E2C315EC-4628-46C6-A0F1-4871DCCF8311}C:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) C:\program files\rockstar games\grand theft auto v\gta5.exe => No File
FirewallRules: [{A0A4147B-52B8-4BDA-835D-AA151CB22654}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{18F12D1B-2FD0-4485-80E7-4AB60DF6596B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{0D723A75-54F6-456E-A3C2-D6E5CA938541}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{7496C7DF-A2A1-404A-A1C7-35974731F314}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{5D10FCA1-6D2C-4630-9156-6379E190BC83}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{E2E9FBFB-5BE5-4EB2-B3B0-ED6ACA28CAC1}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [UDP Query User{4D278354-9384-406C-B0CB-5C3AA9B903F1}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe] => (Allow) C:\program files\rockstar games\grand theft auto iv\gtaiv.exe => No File
FirewallRules: [TCP Query User{AEB612CC-1CA7-4BB5-A117-60636B214E60}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe] => (Allow) C:\program files\rockstar games\grand theft auto iv\gtaiv.exe => No File
FirewallRules: [{4494513B-30BF-4127-B411-8E2A697C69F8}] => (Allow) C:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe => No File
FirewallRules: [{56F97522-9336-4F4E-AAFF-4BDDF3953817}] => (Allow) C:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe => No File
FirewallRules: [{B3F666BB-FAB3-4AF7-9955-3103E1D5FE5D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia III\launcher.exe => No File
FirewallRules: [{011D2C6B-24C8-4831-BE42-5FFDD2B08832}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia III\launcher.exe => No File
FirewallRules: [{77DE1CE8-87FC-41B4-8B1E-B8328760A185}] => (Allow) C:\Program Files (x86)\Need For Speed Payback\NeedForSpeedPayback.exe => No File
FirewallRules: [{248E9571-C403-440A-B7E3-DD16E5E3142E}] => (Allow) C:\Program Files (x86)\Need For Speed Payback\NeedForSpeedPayback.exe => No File
FirewallRules: [{9A3637FA-BAC5-4EAA-AE92-034C4D42DED2}] => (Allow) C:\Program Files (x86)\Need For Speed Payback\NeedForSpeedPaybackTrial.exe => No File
FirewallRules: [{88117287-F9B3-4567-B60B-A9AD0D226464}] => (Allow) C:\Program Files (x86)\Need For Speed Payback\NeedForSpeedPaybackTrial.exe => No File
FirewallRules: [UDP Query User{90A282DF-2A30-4FAC-88CB-D56CB1B40B03}C:\program files (x86)\mafia iii\launcher.exe] => (Allow) C:\program files (x86)\mafia iii\launcher.exe => No File
FirewallRules: [TCP Query User{F2C0FFB9-7556-40B7-8B7F-1BE2E8534E76}C:\program files (x86)\mafia iii\launcher.exe] => (Allow) C:\program files (x86)\mafia iii\launcher.exe => No File
FirewallRules: [{F0A10025-3A56-4149-A701-8EDB6E1053DA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{AFBF8DFD-16C4-4856-9E23-08B3B63F7A61}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{9F9D0CFF-32AA-401E-A55A-71239E1202ED}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{E94AEC73-2ACC-4A8D-BB70-F980DC28D615}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [UDP Query User{826A45F3-8F81-4DA8-A834-D7B3B39BA09E}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [TCP Query User{308843FA-331A-4F5F-896D-8E12E6D8E89C}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [UDP Query User{A5857991-3541-4714-AD62-7A7160D85A35}C:\games\mafia iii\mafia3.exe] => (Block) C:\games\mafia iii\mafia3.exe => No File
FirewallRules: [TCP Query User{78C09911-8D76-4D6C-8F2F-C941B08F0402}C:\games\mafia iii\mafia3.exe] => (Block) C:\games\mafia iii\mafia3.exe => No File
FirewallRules: [UDP Query User{77E7A918-6AE5-4439-994B-6C92286690B1}C:\games\mafia iii\launcher.exe] => (Block) C:\games\mafia iii\launcher.exe => No File
FirewallRules: [TCP Query User{76FD4E18-D58A-495A-B024-16CCB53A9BC5}C:\games\mafia iii\launcher.exe] => (Block) C:\games\mafia iii\launcher.exe => No File
FirewallRules: [UDP Query User{578EA09F-1765-4D0C-B353-99ECA4FF55E6}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{58C6386A-F577-4620-93BD-8196DD133FF2}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{0A3791A0-F15E-404B-B7D1-28EDBC508F63}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia III\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{B9DB7181-0ED4-4C38-885B-55F1901B1454}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia III\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{AAFF1B42-FE0D-43F1-A920-502A8D71AB5B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{AF585D32-3C25-4690-BD13-7555D0E3F693}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{4670EDFC-6362-4E23-BC99-6FFAC512586A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator Demo\bin\win_x64\amtrucks.exe => No File
FirewallRules: [{83479E98-3DDD-4613-8890-3AF92142CC08}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator Demo\bin\win_x64\amtrucks.exe => No File
FirewallRules: [{7BEC1B97-2798-4617-ADF0-AE4322DA7264}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021 Demo\playway-launcher-win32-ia32\playway-launcher.exe => No File
FirewallRules: [{D5C3DFEA-7E14-4108-8FF0-CCD370295CF4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021 Demo\playway-launcher-win32-ia32\playway-launcher.exe => No File
FirewallRules: [{F6D7185F-D223-4B33-98B2-D6657D551C72}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021\Car Mechanic Simulator 2021.exe (Unity Technologies ApS) [File not signed]
FirewallRules: [{FC587F5D-6F6B-4621-9BA1-68398F72145F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021\Car Mechanic Simulator 2021.exe (Unity Technologies ApS) [File not signed]
FirewallRules: [{2A25A2AA-8920-46E1-9422-5F0168251BAA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Police Shootout Demo\playway-launcher-win32-ia32\playway-launcher.exe (Pway Sp. z o.o. (Piotr "Xeno" Adamczyk)) [File not signed]
FirewallRules: [{BC2AE557-BBEC-492E-BAA2-F487DF494CEA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Police Shootout Demo\playway-launcher-win32-ia32\playway-launcher.exe (Pway Sp. z o.o. (Piotr "Xeno" Adamczyk)) [File not signed]
FirewallRules: [{4AB7CBC3-B3D5-4136-A738-2A6E2E74B78A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{CDFF6005-1A1A-4F7F-BFBD-619061E6F1C1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{68E0F4FA-2563-4E4F-AD0E-8D01CB9B1530}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{84899661-3EC5-4A41-8E9D-F64C547F1618}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{C8BBBFCB-2CEB-4C9B-B26A-66FE4AAFE2C0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PC Building Simulator\PCBS.exe () [File not signed]
FirewallRules: [{13BE5EC5-4986-41D1-93F4-67FC5E15B523}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PC Building Simulator\PCBS.exe () [File not signed]
FirewallRules: [{C1E0FA98-B749-48D5-8786-5F812D6FCE46}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{AA53364B-92D6-4546-BBBC-EE83AC5799B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{50667B92-9CE1-4FD2-9E84-511776F5967F}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [{7BB8C4F5-277B-47B2-8BFD-FD31E32B0496}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [{13001E03-8E5B-4320-8275-E04892B32167}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{04F548EA-4EF0-49F6-A4C9-0E6D5028DD50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [TCP Query User{DF8A630B-B8C2-4E84-B501-55285714E4EF}C:\users\justin\downloads\microsoft flight simulator 2020 premium deluxe\flightsimulator.exe] => (Block) C:\users\justin\downloads\microsoft flight simulator 2020 premium deluxe\flightsimulator.exe => No File
FirewallRules: [UDP Query User{ECA6FD43-7738-4130-9BBB-F3D83F3B616C}C:\users\justin\downloads\microsoft flight simulator 2020 premium deluxe\flightsimulator.exe] => (Block) C:\users\justin\downloads\microsoft flight simulator 2020 premium deluxe\flightsimulator.exe => No File
FirewallRules: [{B37994BF-DE13-4150-B6C3-DE2C838BBC45}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SnowRunner\Sources\Bin\SnowRunner.exe (Focus Entertainment SA -> Focus Home Interactive)
FirewallRules: [{EA98986A-1730-48C7-A3CF-78CCA412FDE7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SnowRunner\Sources\Bin\SnowRunner.exe (Focus Entertainment SA -> Focus Home Interactive)
FirewallRules: [TCP Query User{41C174A8-CD35-4A45-A59C-5CD4F467BC43}C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe (BeamNG GmbH -> BeamNG GmbH)
FirewallRules: [UDP Query User{16FA8D04-454A-48D5-9618-DFF93E3F138A}C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe (BeamNG GmbH -> BeamNG GmbH)
FirewallRules: [{2A5DE77C-54E3-4392-A19F-D15F2688BEAB}] => (Allow) C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe (Christian Hausmann -> stryder-it)
FirewallRules: [{42529C6B-3331-4076-A14D-A90578B30F48}] => (Allow) C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe (Christian Hausmann -> stryder-it)
FirewallRules: [{8C3186FF-6897-4409-B270-1814F89054AF}] => (Allow) C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe (Christian Hausmann -> stryder-it)
FirewallRules: [{CF800C8B-6EA6-4A15-A144-3D6BADAF3E2A}] => (Allow) C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe (Christian Hausmann -> stryder-it)
FirewallRules: [{D6F33659-366A-4AD2-81EB-9422ABF50E71}] => (Allow) C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe (Christian Hausmann -> stryder-it)
FirewallRules: [{6BDB2120-416D-4E55-B76B-E331E16EC4AE}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.60\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A8555528-2151-42F9-A28D-741438EEBC0D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.105.3214.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{AC2E25BD-C9FB-4665-9D19-8C0FC9D275B0}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.105.3214.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{49F45B36-426D-4C00-B1FB-E35C2FB543AB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.105.3214.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{271DB596-08AF-4AF0-9DC1-C64289865B8C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.105.3214.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{BBD0D66E-C4C8-43BD-8546-0C5F22C7052A}] => (Allow) LPort=26820
FirewallRules: [{AEDF04EE-E669-4A1E-A8FA-E94BBCBBA16A}] => (Allow) LPort=26822
FirewallRules: [{7FE92B83-1C3C-4893-941F-2ABB8B2AC126}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
08-10-2023 21:27:43 Scheduled Checkpoint
10-10-2023 17:06:11 Windows Modules Installer
14-10-2023 08:09:47 Windows Modules Installer
 
==================== Faulty Device Manager Devices ============
 
Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: Microsoft PS/2 Mouse
Description: Microsoft PS/2 Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (10/14/2023 07:59:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MBAMService.exe, version: 3.2.0.1239, time stamp: 0x64fa28c3
Faulting module name: ntdll.dll, version: 10.0.19041.3393, time stamp: 0xfeef31d3
Exception code: 0xc0000005
Fault offset: 0x00000000000634f6
Faulting process id: 0xda8
Faulting application start time: 0x01d9fe9447f76b23
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 493c5c19-3499-486c-964e-a7cc4de7476b
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (10/05/2023 02:24:21 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on (C:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
Error: (09/30/2023 06:17:42 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program PhoneExperienceHost.exe version 1.23082.126.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 219c
 
Start Time: 01d9ee42c1ed941f
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\Microsoft.YourPhone_1.23082.126.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
 
Report Id: 1b6a30c8-ca42-4706-882c-dfe4c8056b70
 
Faulting package full name: Microsoft.YourPhone_1.23082.126.0_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: App
 
Hang type: Quiesce
 
Error: (09/28/2023 02:37:04 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on (C:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
Error: (09/21/2023 02:50:34 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on (C:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
Error: (09/14/2023 04:42:03 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on (C:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
Error: (09/07/2023 03:28:58 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on (C:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
Error: (09/01/2023 05:19:06 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Program Files (x86)\Microsoft\EdgeCore\116.0.1938.62\WidevineCdm\_platform_specific\win_x64\widevinecdm.dll for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Microsoft Edge Installer because of this error.
 
Program: Microsoft Edge Installer
File: C:\Program Files (x86)\Microsoft\EdgeCore\116.0.1938.62\WidevineCdm\_platform_specific\win_x64\widevinecdm.dll
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
 
Additional Data
Error value: C000009C
Disk type: 3
 
 
System errors:
=============
Error: (10/14/2023 09:44:59 AM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (10/14/2023 09:44:56 AM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (10/14/2023 09:32:12 AM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (10/14/2023 09:32:09 AM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (10/14/2023 09:32:04 AM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (10/14/2023 09:31:58 AM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (10/14/2023 09:31:54 AM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (10/14/2023 09:31:51 AM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
 
Windows Defender:
================
Date: 2023-10-10 02:13:25
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-10-09 02:13:46
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-10-08 21:24:10
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-10-07 02:13:45
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-10-05 02:13:39
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]:
 
Date: 2023-10-14 08:23:49
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.399.384.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.23090.2007
Error code: 0x80070020
Error description: The process cannot access the file because it is being used by another process. 
 
Date: 2023-10-14 08:23:49
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.399.384.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.23090.2007
Error code: 0x80070020
Error description: The process cannot access the file because it is being used by another process. 
 
Date: 2023-10-14 08:23:49
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.399.384.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.23090.2007
Error code: 0x80070020
Error description: The process cannot access the file because it is being used by another process. 
 
Date: 2023-08-05 18:56:48
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.393.2046.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.23070.1005
Error code: 0x80070102
Error description: The wait operation timed out. 
 
Date: 2023-07-18 21:04:20
Description: 
Microsoft Defender Antivirus engine has been terminated due to an unexpected error.
Failure Type: Crash
Exception code: 0xc0000006
Resource: file:C:\Users\Justin\AppData\Local\Steam\htmlcache\e194da99-ca5d-414b-8248-c5e9fbfb4c50.tmp
Engine Code: 16445
 
CodeIntegrity:
===============
Date: 2023-10-14 10:17:37
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. 2.70 03/22/2019
Motherboard: Micro-Star International Co., Ltd. B360 GAMING PLUS (MS-7B22)
Processor: Intel® Core™ i3-9100F CPU @ 3.60GHz
Percentage of memory in use: 37%
Total physical RAM: 16319.6 MB
Available physical RAM: 10152.3 MB
Total Virtual: 18751.6 MB
Available Virtual: 9747.35 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:697.57 GB) (Free:75 GB) (Model: ST3750528AS) NTFS
Drive e: () (CDROM) (Total:0 GB) (Free:0 GB) 
 
\\?\Volume{39923072-ba16-47a3-b19d-a299cd26f23d}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS
\\?\Volume{3b745328-203b-40fa-855d-8bf1e31b3e69}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS
\\?\Volume{3053251c-f081-4410-9b43-c0be99bb253f}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 1E260D63)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

 


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Error: (10/14/2023 09:44:59 AM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

 

 

Might be that problem.  Search for:

CMD

 

It will find Command Prompt

Right click on Command Prompt and Run As Admin.

 

Type:

chkdsk C: /r

Hit Enter.  It will will say:

 
The type of the file system is NTFS.
Cannot lock current drive.
 
Chkdsk cannot run because the volume is in use by another
process.  Would you like to schedule this volume to be
checked the next time the system restarts? (Y/N)

 

Answer with a Y.  Reboot.  The drive test should run and may take an hour or more to finish.  It will reboot into Windows when done.

 

Rerun FRST but I only need the Addition.txt file to see if it worked.

 

Also if you go into Task Manager then Performance then Open Resource Monitor you can see Disk Activity in the middle section.  (Make sure the window is full screen - click on the box in the upper right).

 

There is a down arrow on the right which you may need to click to open up the Disk Activity section.  Find the column header for "Total (B/sec)" and click on it once or twice until the largest numbers are at the top.  This will show you what processes are using the drive.  Take a screenshot .

https://www.cnet.com...dows-10-and-11/

 

and save it where you can find it as a jpg.  Attach the file to a post:

 
First click on More Reply Options
Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.
 

 

 

Check your drive health with CrystalDiskInfo:

 
 
 
 
Scroll down a bit and you will see a picture of a black window with Samsung SSD in it.  Underneath the black window 
is a button that says Vista+.  That's the button you need to use to download the installer.  
Save the file then go to the download folder and right click on the file and run as admin.  
The program will install and then start up.   Once it reads the drives you just hit File then Save Text.  
Save the file to your desktop and then attach it or open it then copy and paste the text to a reply.  
 
Get Process Explorer
 
 
Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  
View and check Show Processes From All Users 
 
View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures
 
 
Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  
 
Wait a full minute then:
 
File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.
 

  • 0

#3
FordTaurus00

FordTaurus00

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts

sorry,  was out of town for the weekend.  heres the new addition.txt and the screenshot is attached,  rest requested in next reply

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-10-2023
Ran by Justin (16-10-2023 21:11:32)
Running from C:\Users\Justin\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.3570 (X64) (2021-05-11 01:21:22)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-3020459029-3775271098-2569446579-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3020459029-3775271098-2569446579-503 - Limited - Disabled)
Guest (S-1-5-21-3020459029-3775271098-2569446579-501 - Limited - Enabled)
Justin (S-1-5-21-3020459029-3775271098-2569446579-1002 - Administrator - Enabled) => C:\Users\Justin
WDAGUtilityAccount (S-1-5-21-3020459029-3775271098-2569446579-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Disabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 23.006.20320 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601052}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 19.12.2 - Advanced Micro Devices, Inc.)
Back to the Future - The Game (HKLM-x32\...\1207659097_is1) (Version: 2.1.0.5 - GOG.com)
Big Fish: Game Manager (HKLM-x32\...\BFGC) (Version: 3.3.0.2 - )
cFosSpeed v10.27 (HKLM\...\cFosSpeed) (Version: 10.27 - cFos Software GmbH, Bonn)
Community Modpack for Mafia: The City of Lost Heaven (HKLM-x32\...\Community Modpack for Mafia: The City of Lost Heaven_is1) (Version:  - Rimsky)
Core Temp 1.15.1 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.15.1 - ALCPU)
CPUID CPU-Z MSI 1.88 (HKLM\...\CPUID CPU-Z MSI_is1) (Version: 1.88 - CPUID, Inc.)
CPUID HWMonitor 1.41 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.41 - CPUID, Inc.)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.11.0.1001 - Disc Soft Ltd)
DVD Flick 1.3.0.7 (HKLM-x32\...\DVD Flick_is1) (Version: 1.3.0.7 - Dennis Meuwissen)
Dynamic Web TWAIN HTML5 Edition (HKLM-x32\...\{B4D31736-4D13-4BCD-B050-7DD3E45C1650}) (Version: 11.1.831 - Dynamsoft)
Easy Photo Scan (HKLM-x32\...\{9E3F2EC3-7E4F-4F20-A56F-7A24D6E3D39B}) (Version: 1.00.0017 - Seiko Epson Corporation)
ENE RGB HAL (HKLM\...\{095C8467-BF29-4384-B727-1C36ED8BC704}) (Version: 1.00.08 - Ene Tech.) Hidden
ENE RGB HAL (HKLM-x32\...\{164b6011-4720-403c-8ee0-dae7640cce9f}) (Version: 1.00.08 - Ene Tech.) Hidden
Epson Customer Research Participation (HKLM\...\{B26449A6-6007-4460-B4FE-C4776115BCEA}) (Version: 1.83.0000 - Seiko Epson Corporation)
Epson Event Manager (HKLM-x32\...\{DBC38C08-9FB5-43A5-B6BA-EB10AC7DA570}) (Version: 3.11.0053 - Seiko Epson Corporation)
Epson ReadyInk Agent (A) (HKLM-x32\...\{A9B4584F-A29E-4880-97E6-1744B4AF2AF8}) (Version: 1.0.2.0 - Seiko Epson Corporation)
Epson Scan 2 (HKLM-x32\...\Epson Scan 2) (Version:  - Seiko Epson Corporation)
EPSON Scan OCR Component (HKLM-x32\...\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}) (Version: 3.00.04 - SEIKO EPSON Corp.)
Epson Software Updater (HKLM-x32\...\{D2D9559D-359A-4C61-B93A-FE01AE2BFB75}) (Version: 4.5.4 - Seiko Epson Corporation)
EPSON XP-340 Series Printer Uninstall (HKLM\...\EPSON XP-340 Series) (Version:  - Seiko Epson Corporation)
EPSON XP-4100 Series Printer Uninstall (HKLM\...\EPSON XP-4100 Series) (Version:  - Seiko Epson Corporation)
EpsonNet Print (HKLM\...\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
GamingOSD(x64) (HKLM\...\{11E14722-1213-4021-AD72-32252315CB8B}) (Version: 0.0.2.3 - MICRO-STAR INT'L,.LTD.) Hidden
GamingOSD(x64) (HKLM-x32\...\Installshield_{11E14722-1213-4021-AD72-32252315CB8B}) (Version: 0.0.2.3 - MICRO-STAR INT'L,.LTD.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 117.0.5938.152 - Google LLC)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 82.0.1.0 - Google LLC)
Google Drive (HKLM-x32\...\{459CE109-4E46-4340-92BC-054642BC3BC2}) (Version: 1.31.2873.2758 - Google, Inc.)
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
HandBrake 1.3.3 (HKLM-x32\...\HandBrake) (Version: 1.3.3 - )
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
Intel® Chipset Device Software (HKLM\...\{97B7DB53-C2AD-46EF-8310-20F8CE5AEFE1}) (Version: 10.1.17968.8131 - Intel Corporation) Hidden
Intel® Chipset Device Software (HKLM-x32\...\{ffddf9dd-c47f-453a-92f5-ac6c98af8b5b}) (Version: 10.1.17968.8131 - Intel® Corporation)
Intel® Extreme Tuning Utility (HKLM-x32\...\{78de1723-f95d-4e02-b94d-f748c484863a}) (Version: 6.5.0.83 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 1912.12.0.1246 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{38FF9297-58C2-414F-BD49-355872F8418D}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{7AA30DD8-C2AC-4523-AA73-BBAA60B6EF00}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Management Engine Driver (HKLM\...\{05622855-82CE-4EF6-B20B-6BCCAAA1DA09}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel® Network Connections 23.5.0.0 (HKLM\...\{967E7483-38D0-40E3-A44C-BAC69E0DC853}) (Version: 23.5.0.0 - Intel) Hidden
Intel® Network Connections 23.5.0.0 (HKLM\...\PROSetDX) (Version: 23.5.0.0 - Intel)
Intel® Trusted Connect Service Client x64 (HKLM\...\{C9552825-7BF2-4344-BA91-D3CD46F4C442}) (Version: 1.52.230.1 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.52.230.1 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (HKLM-x32\...\{c6de84fd-ece7-4c2a-9f06-8cabe7ab79a0}) (Version: 1.52.230.1 - Intel Corporation) Hidden
Logitech G HUB (HKLM\...\{521c89be-637f-4274-a840-baaf7460c2b2}) (Version: 2023.8.459147 - Logitech)
Mafia III (HKLM-x32\...\Mafia III_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, markfiter)
Malwarebytes version 4.6.3.282 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.3.282 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 117.0.2045.60 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 117.0.2045.60 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\OneDriveSetup.exe) (Version: 23.199.0924.0001 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU CTP1 (HKLM\...\{FAF57A91-58B3-490C-9D0C-66337DAD3F11}) (Version: 4.0.8854.1 - Microsoft Corporation) Hidden
Microsoft Update Health Tools (HKLM\...\{2953E19B-9F91-4A49-A23B-7E25970A1951}) (Version: 3.73.0.0 - Microsoft Corporation)
Microsoft VC++ redistributables repacked. (HKLM\...\{A62CB02D-E417-4243-8A6B-50E22F75AB9F}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft VC++ redistributables repacked. (HKLM-x32\...\{D96BF0A6-7612-41CB-9E7D-2386AF6F8E42}) (Version: 12.0.0.0 - Intel Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29334 (HKLM-x32\...\{b2d0f752-adc5-496e-8f70-8669de01f746}) (Version: 14.28.29334.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.34.31931 (HKLM-x32\...\{d4cecf3b-b68f-4995-8840-52ea0fab646e}) (Version: 14.34.31931.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.28.29334 (HKLM-x32\...\{14C49FC8-3E9B-4F29-8526-26629B5CF30B}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.28.29334 (HKLM-x32\...\{0D01A812-82A1-481F-8546-8E28E976F8DF}) (Version: 14.28.29334 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.34.31931 (HKLM\...\{EAE242B1-0A26-485A-BFEB-0292EE9F03CB}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.34.31931 (HKLM\...\{CF4C347D-954E-4543-88D2-EC17F07F466F}) (Version: 14.34.31931 - Microsoft Corporation) Hidden
Midnight in Salem 1.0 CL_11638 (HKLM-x32\...\{6460A41D-13B4-4A1F-90AC-D257DCD61DA0}_is1) (Version: 1.0 - HeR Interactive)
Midnight Mysteries Devil on the Mississippi (HKLM-x32\...\Midnight Mysteries Devil on the Mississippi) (Version: 1.1.0.0 - MumboJumbo)
Midnight Mysteries Haunted Houdini (HKLM-x32\...\Midnight Mysteries Haunted Houdini) (Version: 1.1.0.0 - MumboJumbo)
Midnight Mysteries Salem Witch Trials (HKLM-x32\...\Midnight Mysteries Salem Witch Trials) (Version: 1.1.0.0 - MumboJumbo)
Midnight Mysteries the Edgar Allan Poe Conspiracy (HKLM-x32\...\Midnight Mysteries the Edgar Allan Poe Conspiracy) (Version: 1.1.0.0 - MumboJumbo)
MSI APP Manager (HKLM-x32\...\{00F47104-12BA-4E58-A7E6-F456C1BA338E}}_is1) (Version: 1.0.0.32 - MSI)
MSI App Player (HKLM\...\BlueStacks_msi2) (Version: 4.31.59.3005 - BlueStack Systems, Inc.)
MSI Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 3.0.0.94 - MSI)
MSI Display Kit(x64) (HKLM\...\{5A8E3E72-D260-4DB3-BCE3-AF47C364F275}) (Version: 0.0.1.1 - MSI) Hidden
MSI Display Kit(x64) (HKLM-x32\...\Installshield_{5A8E3E72-D260-4DB3-BCE3-AF47C364F275}) (Version: 0.0.1.1 - MICRO-STAR INT'L,.LTD.)
MSI DPC Latency Tuner (HKLM-x32\...\{1AAC56F3-3F60-47DB-BE6B-088F36ADFDC5}_is1) (Version: 1.0.0.38 - MSI)
MSI Fast Boot (HKLM-x32\...\{0F212E7A-65EB-4668-A8D7-749026A64F8E}_is1) (Version: 1.0.1.15 - MSI)
MSI Gaming APP (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 6.2.0.88 - MSI)
MSI Gaming Lan Manager (HKLM-x32\...\{3318282C-D4D6-4B29-BBD5-95FC34B54FF0}_is1) (Version: 2.0.0.13 - MSI)
MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.2.0.63 - MSI)
MSI MysticLight (HKLM-x32\...\{93874B70-6C5E-446A-AF4D-E5AC776A0386}}_is1) (Version: 3.0.0.56 - MSI)
MSI Smart Tool (HKLM-x32\...\{DDCCA038-DAB1-4D09-B85C-848020AA75D6}}_is1) (Version: 1.0.0.41 - MSI)
MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.3.0.28 - MSI)
MSI X Boost (HKLM-x32\...\{515143BB-7A11-4D85-B941-D520AAAA099C}_is1) (Version: 1.0.0.46 - MSI)
Nancy Drew The Silent Spy 1.00 (HKLM-x32\...\Nancy Drew The Silent Spy 1.00) (Version: 1.00 - Games)
Nancy Drew: Labyrinth of Lies (HKLM-x32\...\BFG-Nancy Drew - Labyrinth of Lies) (Version:  - )
Nancy Drew: The Deadly Device (HKLM-x32\...\{CC7341D8-5CBC-4A2B-8442-6846027A7A79}) (Version: 1.00 - Her Interactive)
Nancy Drew: The Shattered Medallion (HKLM-x32\...\BFG-Nancy Drew - The Shattered Medallion) (Version:  - )
Nancy Drew: Tomb of the Lost Queen (HKLM-x32\...\{56CCBC54-8CEE-479F-9302-E0651BCBA13D}) (Version: 1.00 - Her Interactive)
Naviextras Toolbox (HKLM-x32\...\Naviextras Toolbox) (Version: 3.9.0.18087 - NNG Llc.)
Naviextras Toolbox Prerequesities (HKLM-x32\...\{537575D6-3B96-474C-BD8F-DFF667363DBD}) (Version: 1.0.0 - NNG Llc.)
Need for Speed Underground 2 (HKLM-x32\...\Need for Speed Underground 2) (Version:  - )
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OBS Multiplatform (HKLM-x32\...\OBS Multiplatform) (Version: 0.10.2 - OBS Project)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8858.1 - Realtek Semiconductor Corp.)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.42.369 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.8.5 - Rockstar Games)
SIMDashboardServer (HKLM-x32\...\{037C1DB1-CC56-4A0C-98CB-4A7F03CCCE3F}) (Version: 3.14.0.0 - stryder-it)
SnowRunner (HKLM-x32\...\SnowRunner_is1) (Version:  - )
Spintires MudRunner American Wilds (HKLM-x32\...\Spintires MudRunner American Wilds_is1) (Version:  - )
Spotify (HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\Spotify) (Version: 1.1.34.694.gac68a2b3 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TANE (HKLM-x32\...\TANE_sp4-com.n3vgames.tane-windows-4e2b8aa58576c14cb85a1b169cd64f66) (Version:  - N3V Games)
TurboTax 2018 (HKLM-x32\...\TurboTax 2018) (Version: 2018.0 - Intuit, Inc)
TurboTax 2018 WinPerFedFormset (HKLM-x32\...\{4F5D754A-4CF7-489E-9FC7-DCF124A9C13B}) (Version: 018.000.3420 - Intuit Inc.) Hidden
TurboTax 2018 WinPerReleaseEngine (HKLM-x32\...\{3B81DEB0-2307-4542-A370-47D7B15B4EE5}) (Version: 018.000.0674 - Intuit Inc.) Hidden
TurboTax 2018 WinPerTaxSupport (HKLM-x32\...\{E9FCBA33-DB82-4992-A4FE-3A2D4C974DD7}) (Version: 018.000.0130 - Intuit Inc.) Hidden
TurboTax 2018 wpaiper (HKLM-x32\...\{E0988D30-4BF7-45B3-8547-CE76CF6AD089}) (Version: 018.000.1338 - Intuit Inc.) Hidden
TurboTax 2018 wrapper (HKLM-x32\...\{B29215FE-D5C4-4C2D-BDA1-11EBF3638653}) (Version: 018.000.0109 - Intuit Inc.) Hidden
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{7B63012A-4AC6-40C6-B6AF-B24A84359DD5}) (Version: 8.93.0.0 - Microsoft Corporation)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
WinRAR 5.80 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.80.0 - win.rar GmbH)
 
Packages:
=========
Any DVD -> C:\Program Files\WindowsApps\15191PeakPlayer.50533F9B98293_3.2.34.0_x64__y5c4dfz5b21fm [2023-10-03] (Any DVD &amp; Office App)
Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2308.1005.0_x64__8wekyb3d8bbwe [2023-08-12] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-05-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-05-10] (Microsoft Corporation) [MS Ad]
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-12-01] (Microsoft Corporation)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.38.277.0_x64__dt26b99r8h8gj [2023-03-28] (Realtek Semiconductor Corp)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.17.10050.0_x64__8wekyb3d8bbwe [2023-10-09] (Microsoft Studios) [MS Ad]
Windows Package Manager Source (winget) -> C:\Program Files\WindowsApps\Microsoft.Winget.Source_2023.928.2303.555_neutral__8wekyb3d8bbwe [2023-09-28] (Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3020459029-3775271098-2569446579-1002_Classes\CLSID\{80172dde-4e20-4df0-81a2-0a48553e80bb}\localserver32 -> C:\Users\Justin\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe (A-Volute SAS -> A-Volute)
CustomCLSID: HKU\S-1-5-21-3020459029-3775271098-2569446579-1002_Classes\CLSID\{BFBE0943-74C5-40E0-9E80-0B808109E95D}\InprocServer32 -> C:\Users\Justin\AppData\Local\Microsoft\EdgeUpdate\1.3.163.19\psuser_64.dll => No File
ShellIconOverlayIdentifiers: [    GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [    GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [    GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [    GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google Inc -> Google)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-19] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2016-07-29] (Google Inc -> Google)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2019-12-16] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2019-12-16] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-03-04] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-19] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2016-07-29] (Google Inc -> Google)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll -> No File
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\82.0.1.0\drivefsext.dll [2023-10-09] (Google LLC -> Google, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-03-04] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\Justin\Desktop\Google Drive.lnk -> C:\Program Files\Google\Drive File Stream\launch.bat ()
ShortcutWithArgument: C:\Users\Justin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\d249d9ddd424b688\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default
 
==================== Loaded Modules (Whitelisted) =============
 
2019-07-18 14:33 - 2019-07-18 14:33 - 000017920 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libEGL.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 003567616 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2018-04-11 18:28 - 2018-04-11 18:28 - 006160384 _____ () [File not signed] C:\Program Files\GamingOSD\MysticLight\Library\MSIMysticDll.dll
2019-12-05 00:14 - 2019-12-05 00:14 - 001516544 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\AMD\WVR\OpenVR\bin\win64\driver_amdwvr.dll
2010-11-19 01:08 - 2010-11-19 01:08 - 000086016 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2016-09-14 17:31 - 2016-09-14 17:31 - 000500736 ____S (SEIKO EPSON CORPORATION) [File not signed] C:\WINDOWS\System32\enppmon.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000031744 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qgif.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000039424 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qicns.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000031744 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qico.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000413696 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qjpeg.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000025088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qsvg.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000025088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qtga.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000023552 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwbmp.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000519168 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\qwebp.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 001431040 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\platforms\qwindows.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 001180672 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\sqldrivers\qsqlite.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000135680 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\plugins\styles\qwindowsvistastyle.dll
2019-12-05 00:23 - 2019-12-05 00:23 - 006010880 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 006345216 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 001078272 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000313856 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Positioning.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 004000256 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 003802624 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000171008 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5QuickControls2.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 001083904 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5QuickTemplates2.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000205312 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Sql.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000329728 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Svg.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000113152 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebChannel.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000376320 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebEngine.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 092323328 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WebEngineCore.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 005560832 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000463360 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000188416 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 002888704 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5XmlPatterns.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000053760 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000059392 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000017408 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000287232 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls.2\qtquickcontrols2plugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000329216 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000136192 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000089088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000312320 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Templates.2\qtquicktemplates2plugin.dll
2019-07-18 14:33 - 2019-07-18 14:33 - 000017920 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2019-12-05 00:23 - 2019-12-05 00:23 - 000085504 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\AMD\CNext\CNext\QtWebEngine\qtwebengineplugin.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F [270]
AlternateDataStreams: C:\ProgramData\TEMP:CFBF7F81 [255]
AlternateDataStreams: C:\ProgramData\TEMP:DBF60C66 [244]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2019-03-19 00:49 - 2019-03-19 00:49 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\DAL
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\MSI\GAMING PLUS.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1)
Windows Firewall is enabled.
 
Network Binding:
=============
Ethernet: cFosSpeed for faster Internet connections (NDIS 6) -> cfosspeed (enabled) 
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AMD Crash Defender Service => 2
MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: cFosSpeedS => 2
MSCONFIG\Services: Disc Soft Lite Bus Service => 3
MSCONFIG\Services: Dynamsoft WebTWAIN Service => 2
MSCONFIG\Services: Epson PMAService A => 2
MSCONFIG\Services: EpsonCustomerResearchParticipation => 2
MSCONFIG\Services: EpsonScanSvc => 2
MSCONFIG\Services: GamingApp_Service => 2
MSCONFIG\Services: GamingHotkey_Service => 2
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: Intel® Capability Licensing Service TCP IP Interface => 3
MSCONFIG\Services: Intel® PROSet Monitoring Service => 2
MSCONFIG\Services: Intel® TPM Provisioning Service => 2
MSCONFIG\Services: IntuitUpdateServiceV4 => 2
MSCONFIG\Services: jhi_service => 2
MSCONFIG\Services: LGHUBUpdaterService => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MSIClock_CC => 3
MSCONFIG\Services: MSICOMM_CC => 3
MSCONFIG\Services: MSICPU_CC => 3
MSCONFIG\Services: MSICTL_CC => 2
MSCONFIG\Services: MSIDDR_CC => 3
MSCONFIG\Services: MSISMB_CC => 3
MSCONFIG\Services: MSISuperIO_CC => 3
MSCONFIG\Services: MSI_ActiveX_Service => 2
MSCONFIG\Services: MSI_AppManager_Service => 2
MSCONFIG\Services: MSI_DPCLTSERVICE => 2
MSCONFIG\Services: MSI_FastBoot => 2
MSCONFIG\Services: MSI_LiveUpdate_Service => 2
MSCONFIG\Services: MSI_SuperCharger => 2
MSCONFIG\Services: MysticLight2_Service => 2
MSCONFIG\Services: NahimicService => 2
MSCONFIG\Services: Rockstar Service => 3
MSCONFIG\Services: RtkAudioUniversalService => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: XTU3SERVICE => 2
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKLM\...\StartupApproved\Run32: => "X_Boost"
HKLM\...\StartupApproved\Run32: => "EEventManager"
HKLM\...\StartupApproved\Run32: => "Super Charger"
HKLM\...\StartupApproved\Run32: => "Fast Boot"
HKLM\...\StartupApproved\Run32: => "Command Center"
HKLM\...\StartupApproved\Run32: => "MSI Gaming Lan Manager"
HKLM\...\StartupApproved\Run32: => "Live Update"
HKLM\...\StartupApproved\Run32: => "APP Manager"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "EPLTarget\P0000000000000000"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "EPLTarget\P0000000000000001"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "GoogleDriveFS"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "ut"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "SIMDashboardServer"
HKU\S-1-5-21-3020459029-3775271098-2569446579-1002\...\StartupApproved\Run: => "utweb"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{7A77FB92-29EE-4EED-8C0D-DAF8BC456376}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BeamNG.drive\BeamNG.drive.exe (BeamNG GmbH -> BeamNG GmbH)
FirewallRules: [{27373D4E-8F64-4EDD-AD67-EF46995BB6F2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BeamNG.drive\BeamNG.drive.exe (BeamNG GmbH -> BeamNG GmbH)
FirewallRules: [{D5573D42-7855-45B5-ADF7-A6B524B74332}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021 Demo\Car Mechanic Simulator 2021 Demo.exe => No File
FirewallRules: [{02BFF45C-2C2A-4C52-8A4F-1F8DF7462EE2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021 Demo\Car Mechanic Simulator 2021 Demo.exe => No File
FirewallRules: [{E5277D3C-00FE-49EE-9E38-7EF6EACCE4D9}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe => No File
FirewallRules: [{7B2F66BB-6732-45BC-A503-61316C41ED13}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe => No File
FirewallRules: [{9BF5FB73-B5F8-4D46-A46A-BE3A058F1179}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [{FD5184E1-6FEF-4C84-BAE3-3876C663F3F3}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [{31BCD554-FCEA-4A70-A9E1-583AC162BAC7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe => No File
FirewallRules: [{D7BC18F7-4E02-4AB6-82B9-CA271EAC1671}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\launcher.exe => No File
FirewallRules: [{4A64961F-D4EC-4641-98FE-9139FDF6E12E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\launcher.exe => No File
FirewallRules: [UDP Query User{517666D0-9441-4717-A531-E750AA56A064}C:\users\justin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\justin\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{E4EBDE48-BE47-426A-A73A-8B109AF2ED80}C:\users\justin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\justin\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A97AF0AB-2259-401F-BBC6-8AFF72DF088B}] => (Allow) C:\Users\Justin\AppData\Local\Temp\XP-340\Network\EpsonNetSetup\ENEasyApp.exe => No File
FirewallRules: [{BC7FD00E-64AD-43CF-9931-38936160E595}] => (Allow) C:\Users\Justin\AppData\Local\Temp\XP-340\Network\EpsonNetSetup\ENEasyApp.exe => No File
FirewallRules: [{824E20D3-32AC-4363-9EB9-34F70C30B4C1}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [{4A2387B6-778C-4CEB-82F5-BA93947522E4}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [UDP Query User{FEAFA2C0-DE0D-4C4B-8BB0-5CE07F9914BB}C:\users\justin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\justin\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{03B0D85B-D716-44E5-883B-A84A5A337AC9}C:\users\justin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\justin\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{83187A5E-819A-4142-A0D4-2E0320C4DBE2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II Definitive Edition\pc\Mafia2Launcher\Launcher.exe => No File
FirewallRules: [{D3FABB4D-62B7-4A5A-8532-4D46899595C8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II Definitive Edition\pc\Mafia2Launcher\Launcher.exe => No File
FirewallRules: [UDP Query User{1081D3FE-36E3-4C43-99C8-4BD6B40162C6}C:\users\justin\appdata\local\temp\ign4699.tmp\lmiignition.exe] => (Allow) C:\users\justin\appdata\local\temp\ign4699.tmp\lmiignition.exe => No File
FirewallRules: [TCP Query User{1AF96D7A-6365-4523-BA1E-299D2475E399}C:\users\justin\appdata\local\temp\ign4699.tmp\lmiignition.exe] => (Allow) C:\users\justin\appdata\local\temp\ign4699.tmp\lmiignition.exe => No File
FirewallRules: [UDP Query User{03DCBC42-16D2-4F77-B2B2-9AB860EE7E03}C:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) C:\program files\rockstar games\grand theft auto v\gta5.exe => No File
FirewallRules: [TCP Query User{E2C315EC-4628-46C6-A0F1-4871DCCF8311}C:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) C:\program files\rockstar games\grand theft auto v\gta5.exe => No File
FirewallRules: [{A0A4147B-52B8-4BDA-835D-AA151CB22654}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{18F12D1B-2FD0-4485-80E7-4AB60DF6596B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{0D723A75-54F6-456E-A3C2-D6E5CA938541}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{7496C7DF-A2A1-404A-A1C7-35974731F314}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{5D10FCA1-6D2C-4630-9156-6379E190BC83}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{E2E9FBFB-5BE5-4EB2-B3B0-ED6ACA28CAC1}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [UDP Query User{4D278354-9384-406C-B0CB-5C3AA9B903F1}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe] => (Allow) C:\program files\rockstar games\grand theft auto iv\gtaiv.exe => No File
FirewallRules: [TCP Query User{AEB612CC-1CA7-4BB5-A117-60636B214E60}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe] => (Allow) C:\program files\rockstar games\grand theft auto iv\gtaiv.exe => No File
FirewallRules: [{4494513B-30BF-4127-B411-8E2A697C69F8}] => (Allow) C:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe => No File
FirewallRules: [{56F97522-9336-4F4E-AAFF-4BDDF3953817}] => (Allow) C:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe => No File
FirewallRules: [{B3F666BB-FAB3-4AF7-9955-3103E1D5FE5D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia III\launcher.exe => No File
FirewallRules: [{011D2C6B-24C8-4831-BE42-5FFDD2B08832}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia III\launcher.exe => No File
FirewallRules: [{77DE1CE8-87FC-41B4-8B1E-B8328760A185}] => (Allow) C:\Program Files (x86)\Need For Speed Payback\NeedForSpeedPayback.exe => No File
FirewallRules: [{248E9571-C403-440A-B7E3-DD16E5E3142E}] => (Allow) C:\Program Files (x86)\Need For Speed Payback\NeedForSpeedPayback.exe => No File
FirewallRules: [{9A3637FA-BAC5-4EAA-AE92-034C4D42DED2}] => (Allow) C:\Program Files (x86)\Need For Speed Payback\NeedForSpeedPaybackTrial.exe => No File
FirewallRules: [{88117287-F9B3-4567-B60B-A9AD0D226464}] => (Allow) C:\Program Files (x86)\Need For Speed Payback\NeedForSpeedPaybackTrial.exe => No File
FirewallRules: [UDP Query User{90A282DF-2A30-4FAC-88CB-D56CB1B40B03}C:\program files (x86)\mafia iii\launcher.exe] => (Allow) C:\program files (x86)\mafia iii\launcher.exe => No File
FirewallRules: [TCP Query User{F2C0FFB9-7556-40B7-8B7F-1BE2E8534E76}C:\program files (x86)\mafia iii\launcher.exe] => (Allow) C:\program files (x86)\mafia iii\launcher.exe => No File
FirewallRules: [{F0A10025-3A56-4149-A701-8EDB6E1053DA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{AFBF8DFD-16C4-4856-9E23-08B3B63F7A61}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{9F9D0CFF-32AA-401E-A55A-71239E1202ED}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{E94AEC73-2ACC-4A8D-BB70-F980DC28D615}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [UDP Query User{826A45F3-8F81-4DA8-A834-D7B3B39BA09E}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [TCP Query User{308843FA-331A-4F5F-896D-8E12E6D8E89C}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [UDP Query User{A5857991-3541-4714-AD62-7A7160D85A35}C:\games\mafia iii\mafia3.exe] => (Block) C:\games\mafia iii\mafia3.exe => No File
FirewallRules: [TCP Query User{78C09911-8D76-4D6C-8F2F-C941B08F0402}C:\games\mafia iii\mafia3.exe] => (Block) C:\games\mafia iii\mafia3.exe => No File
FirewallRules: [UDP Query User{77E7A918-6AE5-4439-994B-6C92286690B1}C:\games\mafia iii\launcher.exe] => (Block) C:\games\mafia iii\launcher.exe => No File
FirewallRules: [TCP Query User{76FD4E18-D58A-495A-B024-16CCB53A9BC5}C:\games\mafia iii\launcher.exe] => (Block) C:\games\mafia iii\launcher.exe => No File
FirewallRules: [UDP Query User{578EA09F-1765-4D0C-B353-99ECA4FF55E6}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{58C6386A-F577-4620-93BD-8196DD133FF2}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{0A3791A0-F15E-404B-B7D1-28EDBC508F63}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia III\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{B9DB7181-0ED4-4C38-885B-55F1901B1454}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia III\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{AAFF1B42-FE0D-43F1-A920-502A8D71AB5B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{AF585D32-3C25-4690-BD13-7555D0E3F693}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{4670EDFC-6362-4E23-BC99-6FFAC512586A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator Demo\bin\win_x64\amtrucks.exe => No File
FirewallRules: [{83479E98-3DDD-4613-8890-3AF92142CC08}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator Demo\bin\win_x64\amtrucks.exe => No File
FirewallRules: [{7BEC1B97-2798-4617-ADF0-AE4322DA7264}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021 Demo\playway-launcher-win32-ia32\playway-launcher.exe => No File
FirewallRules: [{D5C3DFEA-7E14-4108-8FF0-CCD370295CF4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021 Demo\playway-launcher-win32-ia32\playway-launcher.exe => No File
FirewallRules: [{F6D7185F-D223-4B33-98B2-D6657D551C72}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021\Car Mechanic Simulator 2021.exe (Unity Technologies ApS) [File not signed]
FirewallRules: [{FC587F5D-6F6B-4621-9BA1-68398F72145F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Car Mechanic Simulator 2021\Car Mechanic Simulator 2021.exe (Unity Technologies ApS) [File not signed]
FirewallRules: [{2A25A2AA-8920-46E1-9422-5F0168251BAA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Police Shootout Demo\playway-launcher-win32-ia32\playway-launcher.exe (Pway Sp. z o.o. (Piotr "Xeno" Adamczyk)) [File not signed]
FirewallRules: [{BC2AE557-BBEC-492E-BAA2-F487DF494CEA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Police Shootout Demo\playway-launcher-win32-ia32\playway-launcher.exe (Pway Sp. z o.o. (Piotr "Xeno" Adamczyk)) [File not signed]
FirewallRules: [{4AB7CBC3-B3D5-4136-A738-2A6E2E74B78A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{CDFF6005-1A1A-4F7F-BFBD-619061E6F1C1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{68E0F4FA-2563-4E4F-AD0E-8D01CB9B1530}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{84899661-3EC5-4A41-8E9D-F64C547F1618}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{C8BBBFCB-2CEB-4C9B-B26A-66FE4AAFE2C0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PC Building Simulator\PCBS.exe () [File not signed]
FirewallRules: [{13BE5EC5-4986-41D1-93F4-67FC5E15B523}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PC Building Simulator\PCBS.exe () [File not signed]
FirewallRules: [{C1E0FA98-B749-48D5-8786-5F812D6FCE46}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{AA53364B-92D6-4546-BBBC-EE83AC5799B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia Definitive Edition\2KLauncher\LauncherPatcher.exe => No File
FirewallRules: [{50667B92-9CE1-4FD2-9E84-511776F5967F}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [{7BB8C4F5-277B-47B2-8BFD-FD31E32B0496}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (Seiko Epson Corporation) [File not signed]
FirewallRules: [{13001E03-8E5B-4320-8275-E04892B32167}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{04F548EA-4EF0-49F6-A4C9-0E6D5028DD50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\American Truck Simulator\bin\win_x64\amtrucks.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [TCP Query User{DF8A630B-B8C2-4E84-B501-55285714E4EF}C:\users\justin\downloads\microsoft flight simulator 2020 premium deluxe\flightsimulator.exe] => (Block) C:\users\justin\downloads\microsoft flight simulator 2020 premium deluxe\flightsimulator.exe => No File
FirewallRules: [UDP Query User{ECA6FD43-7738-4130-9BBB-F3D83F3B616C}C:\users\justin\downloads\microsoft flight simulator 2020 premium deluxe\flightsimulator.exe] => (Block) C:\users\justin\downloads\microsoft flight simulator 2020 premium deluxe\flightsimulator.exe => No File
FirewallRules: [{B37994BF-DE13-4150-B6C3-DE2C838BBC45}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SnowRunner\Sources\Bin\SnowRunner.exe (Focus Entertainment SA -> Focus Home Interactive)
FirewallRules: [{EA98986A-1730-48C7-A3CF-78CCA412FDE7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SnowRunner\Sources\Bin\SnowRunner.exe (Focus Entertainment SA -> Focus Home Interactive)
FirewallRules: [TCP Query User{41C174A8-CD35-4A45-A59C-5CD4F467BC43}C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe (BeamNG GmbH -> BeamNG GmbH)
FirewallRules: [UDP Query User{16FA8D04-454A-48D5-9618-DFF93E3F138A}C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\beamng.drive\bin64\beamng.drive.x64.exe (BeamNG GmbH -> BeamNG GmbH)
FirewallRules: [{2A5DE77C-54E3-4392-A19F-D15F2688BEAB}] => (Allow) C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe (Christian Hausmann -> stryder-it)
FirewallRules: [{42529C6B-3331-4076-A14D-A90578B30F48}] => (Allow) C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe (Christian Hausmann -> stryder-it)
FirewallRules: [{8C3186FF-6897-4409-B270-1814F89054AF}] => (Allow) C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe (Christian Hausmann -> stryder-it)
FirewallRules: [{CF800C8B-6EA6-4A15-A144-3D6BADAF3E2A}] => (Allow) C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe (Christian Hausmann -> stryder-it)
FirewallRules: [{D6F33659-366A-4AD2-81EB-9422ABF50E71}] => (Allow) C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe (Christian Hausmann -> stryder-it)
FirewallRules: [{6BDB2120-416D-4E55-B76B-E331E16EC4AE}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.60\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BBD0D66E-C4C8-43BD-8546-0C5F22C7052A}] => (Allow) LPort=26820
FirewallRules: [{AEDF04EE-E669-4A1E-A8FA-E94BBCBBA16A}] => (Allow) LPort=26822
FirewallRules: [{7FE92B83-1C3C-4893-941F-2ABB8B2AC126}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{47304018-EA99-4B88-9974-7F2B242323F2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.106.3210.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{48929A13-9540-4DBF-AABC-4A19B5CF3B89}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.106.3210.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{26E49BBB-6A58-4648-A011-4CBBDF4197CE}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.106.3210.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{CB82FB06-F114-4046-99E1-9C47097ADC3E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.106.3210.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
 
==================== Restore Points =========================
 
08-10-2023 21:27:43 Scheduled Checkpoint
10-10-2023 17:06:11 Windows Modules Installer
14-10-2023 08:09:47 Windows Modules Installer
 
==================== Faulty Device Manager Devices ============
 
Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: Microsoft PS/2 Mouse
Description: Microsoft PS/2 Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (10/16/2023 05:30:34 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SearchApp.exe version 10.0.19041.3570 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1ea4
 
Start Time: 01da007775cd3437
 
Termination Time: 4294967295
 
Application Path: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
 
Report Id: d944b807-a658-4fa7-9d2a-ee0368952fa4
 
Faulting package full name: Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy
 
Faulting package-relative application ID: CortanaUI
 
Hang type: Quiesce
 
Error: (10/16/2023 05:14:46 PM) (Source: Microsoft-Windows-WMI) (EventID: 5601) (User: NT AUTHORITY)
Description: The Windows Management Instrumentation Service failed to load the repository files under the directory %windir%\system32\wbem\repository.  This can be caused by a corruption in the repository files, security settings on this directory, lack of disk space, or other system resource issues like lack of memory.  If this error happens every time the machine is rebooted then the administrator on this machine may need to stop WMI Service, review the security setting on this folder and files under this folder, and run WMIDiag to validate the health of Windows Management Instrumentation
 
Error: (10/16/2023 05:14:30 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress.
.
 
Error: (10/16/2023 05:14:30 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
 
Error: (10/16/2023 05:14:30 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress.
.
 
Error: (10/16/2023 05:14:29 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
 
Error: (10/14/2023 12:26:17 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on (C:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
 
Error: (10/14/2023 07:59:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MBAMService.exe, version: 3.2.0.1239, time stamp: 0x64fa28c3
Faulting module name: ntdll.dll, version: 10.0.19041.3393, time stamp: 0xfeef31d3
Exception code: 0xc0000005
Fault offset: 0x00000000000634f6
Faulting process id: 0xda8
Faulting application start time: 0x01d9fe9447f76b23
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 493c5c19-3499-486c-964e-a7cc4de7476b
Faulting package full name: 
Faulting package-relative application ID:
 
 
System errors:
=============
Error: (10/16/2023 05:30:58 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Sync Host_31fec3 service terminated with the following error: 
Access is denied.
 
Error: (10/16/2023 05:30:52 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024001e: Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.399.774.0).
 
Error: (10/16/2023 05:30:41 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-NLGCM7D)
Description: The server Microsoft.AAD.BrokerPlugin_1000.19041.3570.0_neutral_neutral_cw5n1h2txyewy!Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider did not register with DCOM within the required timeout.
 
Error: (10/16/2023 05:14:07 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16392) (User: NT AUTHORITY)
Description: The BITS service failed to start.  Error 2147549186.
 
Error: (10/16/2023 05:13:52 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 1:47:48 PM on ‎10/‎14/‎2023 was unexpected.
 
Error: (10/14/2023 12:26:07 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (10/14/2023 12:26:04 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (10/14/2023 12:26:01 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
 
Windows Defender:
================
Date: 2023-10-10 02:13:25
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-10-09 02:13:46
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-10-08 21:24:10
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-10-07 02:13:45
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2023-10-05 02:13:39
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]:
 
Date: 2023-10-16 17:31:04
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.399.774.0
Previous security intelligence Version: 1.399.604.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.23090.2007
Previous Engine Version: 1.1.23090.2007
Error code: 0x80509004
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. 
 
Date: 2023-10-16 17:31:04
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.399.774.0
Previous security intelligence Version: 1.399.604.0
Update Source: User
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 1.1.23090.2007
Previous Engine Version: 1.1.23090.2007
Error code: 0x80509004
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. 
 
Date: 2023-10-16 17:30:52
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.399.604.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.23090.2007
Error code: 0x80240022
Error description: The program can't check for definition updates. 
 
Date: 2023-10-14 08:23:49
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.399.384.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.23090.2007
Error code: 0x80070020
Error description: The process cannot access the file because it is being used by another process. 
 
Date: 2023-10-14 08:23:49
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.399.384.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.23090.2007
Error code: 0x80070020
Error description: The process cannot access the file because it is being used by another process. 
 
CodeIntegrity:
===============
Date: 2023-10-16 21:12:37
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. 2.70 03/22/2019
Motherboard: Micro-Star International Co., Ltd. B360 GAMING PLUS (MS-7B22)
Processor: Intel® Core™ i3-9100F CPU @ 3.60GHz
Percentage of memory in use: 26%
Total physical RAM: 16319.6 MB
Available physical RAM: 11999.61 MB
Total Virtual: 18751.6 MB
Available Virtual: 11819.44 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:697.57 GB) (Free:68.09 GB) (Model: ST3750528AS) NTFS
Drive e: () (CDROM) (Total:0 GB) (Free:0 GB) 
 
\\?\Volume{39923072-ba16-47a3-b19d-a299cd26f23d}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS
\\?\Volume{3b745328-203b-40fa-855d-8bf1e31b3e69}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS
\\?\Volume{3053251c-f081-4410-9b43-c0be99bb253f}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 1E260D63)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

Attached Thumbnails

  • resource.jpg

  • 0

#4
FordTaurus00

FordTaurus00

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts

attached is the crystal log,  the other log is below.   its definitely better since the disc check.  still showing 100% disc in task manager  :(

Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
System Idle Process 97.85 60 K 8 K 0
procexp64.exe 0.76 36,932 K 77,364 K 7768 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
MsMpEng.exe 0.38 301,080 K 249,480 K 3228
ctfmon.exe 0.38 4,508 K 22,376 K 5960 CTF Loader Microsoft Corporation (Verified) Microsoft Windows
dwm.exe < 0.01 84,656 K 69,472 K 1232 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
Interrupts < 0.01 0 K 0 K n/a Hardware Interrupts and DPCs
csrss.exe < 0.01 6,788 K 5,860 K 844
System < 0.01 288 K 46,836 K 4
explorer.exe < 0.01 134,984 K 181,952 K 7144 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows
GamingHotkey.exe < 0.01 51,740 K 16,240 K 5800 Gaming Hotkey Micro-Star INT'L CO., LTD. (Verified) MICRO-STAR INTERNATIONAL CO., LTD.
chrome.exe < 0.01 146,960 K 252,328 K 8396 Google Chrome Google LLC (Verified) Google LLC
SgrmBroker.exe < 0.01 4,940 K 7,956 K 6800
TextInputHost.exe < 0.01 15,936 K 45,904 K 10596 Microsoft Corporation (Verified) Microsoft Windows
MBAMService.exe < 0.01 78,880 K 126,988 K 3148
lghub_system_tray.exe < 0.01 26,536 K 55,288 K 8404 G HUB Logitech, Inc. (Verified) Logitech Inc
chrome.exe < 0.01 31,720 K 54,852 K 9468 Google Chrome Google LLC (Verified) Google LLC
RadeonSoftware.exe < 0.01 142,552 K 54,204 K 7372 Radeon Software: Host Application Advanced Micro Devices, Inc. (Verified) Advanced Micro Devices, Inc.
lghub_agent.exe < 0.01 103,384 K 61,524 K 4952 LGHUB Agent Logitech, Inc. (Verified) Logitech Inc
svchost.exe < 0.01 3,116 K 8,976 K 2356 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
chrome.exe < 0.01 196,888 K 163,468 K 8672 Google Chrome Google LLC (Verified) Google LLC
AMDRSServ.exe < 0.01 246,700 K 217,836 K 8348 Radeon Settings: Host Service Advanced Micro Devices, Inc. (Verified) Advanced Micro Devices, Inc.
chrome.exe < 0.01 55,096 K 105,272 K 2460 Google Chrome Google LLC (Verified) Google LLC
svchost.exe < 0.01 16,072 K 26,756 K 3104 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
MSIToastServer.exe < 0.01 30,020 K 4,588 K 5772 MSIToastServer Micro-Star INT'L CO., LTD. (Verified) MICRO-STAR INTERNATIONAL CO., LTD.
svchost.exe < 0.01 6,156 K 18,396 K 2372
svchost.exe < 0.01 4,000 K 22,224 K 2396 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
lsass.exe < 0.01 8,220 K 22,696 K 992 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 11,560 K 21,808 K 3056 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 7,884 K 15,892 K 1112 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
mbamtray.exe < 0.01 30,272 K 50,336 K 6980 Malwarebytes Tray Application Malwarebytes (Verified) Malwarebytes Inc.
svchost.exe < 0.01 1,456 K 6,324 K 2108 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 4,232 K 15,000 K 3116 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 4,968 K 18,392 K 6548 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
chrome.exe < 0.01 38,260 K 62,476 K 7036 Google Chrome Google LLC (Verified) Google LLC
svchost.exe < 0.01 2,836 K 9,932 K 2312 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
taskhostw.exe < 0.01 10,504 K 21,204 K 5636 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
unsecapp.exe < 0.01 2,128 K 8,968 K 9388 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation (Verified) Microsoft Windows
svchost.exe < 0.01 127,484 K 138,160 K 1660 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
chrome.exe < 0.01 20,736 K 46,404 K 8216 Google Chrome Google LLC (Verified) Google LLC
chrome.exe < 0.01 21,372 K 51,344 K 11116 Google Chrome Google LLC (Verified) Google LLC
csrss.exe < 0.01 2,180 K 5,796 K 732
WmiPrvSE.exe 21,056 K 39,976 K 7056 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe 2,120 K 9,696 K 9340 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
winlogon.exe 2,416 K 12,260 K 960 Windows Logon Application Microsoft Corporation (Verified) Microsoft Windows
wininit.exe 1,412 K 7,312 K 868
Video.UI.exe Suspended 19,376 K 35,800 K 9376 (Verified) Microsoft Corporation
UserOOBEBroker.exe 1,992 K 9,808 K 2000 User OOBE Broker Microsoft Corporation (Verified) Microsoft Windows
SystemSettings.exe Suspended 25,520 K 31,688 K 828 Settings Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 7,592 K 16,656 K 3020 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 11,252 K 30,536 K 688 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,984 K 8,380 K 656 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,344 K 9,444 K 3800 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,372 K 8,084 K 1168 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 9,524 K 28,800 K 5528 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,480 K 12,284 K 7104
svchost.exe 2,780 K 11,376 K 1920 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 6,288 K 16,004 K 1796 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,516 K 12,808 K 1496 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 15,824 K 19,392 K 1588 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,088 K 7,896 K 4828 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,864 K 7,908 K 1684 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 13,264 K 22,732 K 2776 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,572 K 11,316 K 7112 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,400 K 20,376 K 3292 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 35,320 K 55,496 K 2364 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,104 K 7,916 K 2016 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,788 K 11,784 K 5096 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 29,620 K 34,576 K 4440
svchost.exe 3,364 K 11,392 K 5888 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,388 K 14,480 K 2188 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 16,112 K 33,756 K 3136 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4,816 K 9,144 K 1820 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,596 K 17,140 K 7632 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,732 K 10,988 K 3084 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,276 K 5,964 K 3284 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,956 K 7,764 K 2828 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,336 K 9,808 K 2476 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,556 K 6,624 K 2484 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 5,908 K 24,676 K 7648 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 6,436 K 23,312 K 6828 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,796 K 8,284 K 1928 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,612 K 7,520 K 9364 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,404 K 14,236 K 1652 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,052 K 8,680 K 6428 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,192 K 12,384 K 1504 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,684 K 7,576 K 5468
svchost.exe 4,504 K 20,992 K 6080 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,312 K 6,724 K 3252 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,176 K 14,048 K 2420 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,408 K 6,036 K 2120 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 10,044 K 40,612 K 5552 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,296 K 6,056 K 1668 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,240 K 5,688 K 3576 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,748 K 12,464 K 3276 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,884 K 8,152 K 1976 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,464 K 8,908 K 1968 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,416 K 11,976 K 1696 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,296 K 10,280 K 1344 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,672 K 6,756 K 1424 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,236 K 5,604 K 1500 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,244 K 13,084 K 2568 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,848 K 8,640 K 2436 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,520 K 7,496 K 2532 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,640 K 7,348 K 3092 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,572 K 6,984 K 3256 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,400 K 7,412 K 3532 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3,476 K 13,296 K 3968 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,728 K 10,056 K 3040 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,048 K 7,760 K 4492 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,780 K 8,268 K 5824 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1,548 K 11,492 K 6792 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2,580 K 13,420 K 5524 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows Publisher
StartMenuExperienceHost.exe 31,124 K 84,636 K 1420 (Verified) Microsoft Windows
spoolsv.exe 5,964 K 18,076 K 2876 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
smss.exe 1,076 K 1,232 K 460
smartscreen.exe 10,328 K 28,508 K 5944 Windows Defender SmartScreen Microsoft Corporation (Verified) Microsoft Windows
sihost.exe 6,716 K 29,036 K 5484 Shell Infrastructure Host Microsoft Corporation (Verified) Microsoft Windows
ShellExperienceHost.exe Suspended 18,320 K 57,712 K 8208 Windows Shell Experience Host Microsoft Corporation (Verified) Microsoft Windows
services.exe 5,152 K 10,616 K 916
SecurityHealthService.exe 3,252 K 13,100 K 9336
SearchIndexer.exe 31,984 K 42,968 K 7476 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
SearchApp.exe Suspended 158,028 K 246,572 K 7560 Search application Microsoft Corporation (Verified) Microsoft Windows
schtasks.exe 1,212 K 6,052 K 3308 Task Scheduler Configuration Tool Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 12,720 K 40,792 K 7996 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 7,024 K 26,308 K 5448 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 2,996 K 17,924 K 9832 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 6,384 K 26,820 K 7308 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 2,100 K 9,852 K 8820 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
Registry 11,016 K 83,988 K 108
procexp.exe 4,340 K 12,580 K 10752 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
PhoneExperienceHost.exe 48,140 K 141,320 K 6808 Microsoft Phone Link Microsoft Corporation (Verified) Microsoft Corporation
notepad.exe 3,032 K 18,112 K 8676 Notepad Microsoft Corporation (Verified) Microsoft Windows
NisSrv.exe 4,324 K 11,972 K 3644
MysticLightController.exe 21,612 K 26,476 K 5744 MysticLightController (Verified) Micro-Star International CO., LTD.
muachost.exe 1,816 K 2,156 K 5728 Windows Host Process MSI (Verified) MICRO-STAR INTERNATIONAL CO., LTD.
MicrosoftEdgeUpdate.exe 1,904 K 680 K 5916 Microsoft Edge Update Microsoft Corporation (Verified) Microsoft Corporation
Memory Compression 68 K 140 K 1848
lghub_updater.exe 12,580 K 21,912 K 3236 LGHUB Updater Logitech, Inc. (Verified) Logitech Inc
GoogleUpdate.exe 2,480 K 816 K 5736 Google Installer Google Inc. (Verified) Google Inc
fontdrvhost.exe 5,156 K 9,760 K 1012 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
fontdrvhost.exe 1,308 K 3,524 K 1032 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
DTShellHlp.exe 6,448 K 17,264 K 9780 DAEMON Tools Shell Extensions Helper Disc Soft Ltd (Verified) AVB Disc Soft, SIA
dllhost.exe 3,540 K 12,748 K 10244 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
DiskInfo64.exe 12,236 K 48,464 K 8240 CrystalDiskInfo Crystal Dew World (Verified) Open Source Developer, Noriyuki Miyazaki
dasHost.exe 4,736 K 15,956 K 3696 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
dasHost.exe 1,080 K 5,232 K 4556 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
conhost.exe 6,308 K 10,444 K 1276 Console Window Host Microsoft Corporation (Verified) Microsoft Windows
CompPkgSrv.exe 1,532 K 8,964 K 10676 Component Package Support Server Microsoft Corporation (Verified) Microsoft Windows
chrome.exe 16,004 K 25,612 K 2808 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 24,352 K 52,264 K 10484 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 27,560 K 44,564 K 10812 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 26,528 K 53,628 K 8092 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 26,676 K 55,652 K 2852 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 22,908 K 49,792 K 7732 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 29,620 K 57,908 K 4372 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 22,184 K 45,792 K 9356 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 96,248 K 158,488 K 7368 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 6,864 K 10,016 K 8884 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 63,716 K 114,248 K 4376 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 17,680 K 28,840 K 4928 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 29,436 K 61,820 K 2044 Google Chrome Google LLC (Verified) Google LLC
audiodg.exe 6,584 K 12,064 K 11212 Windows Audio Device Graph Isolation Microsoft Corporation (Verified) Microsoft Windows
ApplicationFrameHost.exe 8,252 K 28,268 K 7968 Application Frame Host Microsoft Corporation (Verified) Microsoft Windows
amdow.exe 2,156 K 1,752 K 1776 Radeon Settings: Desktop Overlay Advanced Micro Devices, Inc. (Verified) Advanced Micro Devices, Inc.

Attached Files


Edited by FordTaurus00, 16 October 2023 - 07:45 PM.

  • 0

#5
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Hard drive is getting old.  Lots of errors and bad sectors per the Crystal report.  Would be wise to clone it while it still works.  You can get a SAMSUNG 870 EVO SATA III SSD 1TB 2.5” on Amazon for $49.99.  This is about the same price as a replacement drive.  This will speed up your system a lot too.  Samsung has Data Migration Software which you can download for free from their site

https://semiconducto.../support/tools/

which will move your data and operating system to the new drive quite easily.  With a desktop the quick way is to temporarily move the CD drive's cable to the SSD.  Once you run the program it will shut down and you can move the old drive's cables to the SSD and reconnect the CD drive. They make adapters to fit in the same of a 3.5" drive but I just tie wrap the SSD to the drive frame.

 

The disk check fixed the bad block errors but that means that a section of the drive was bad and it now knows to skip that section.  Any data that was in the bad section was probably lost so it's a good idea to run the following fix list which will check to make sure that all system files are OK.

 

 
Download the attached fixlist.txt to the same location as FRST
 
Attached File  fixlist.txt   414bytes   76 downloads
 
Run FRST and press Fix.  This usually take about 30 minutes but can timeout after an hour on a slow system.
 
A fix log will be generated (if it doesn't time out) please post that 
 
It will reboot when done.
 
Run FRST again but this time make sure Addition.txt is checked and hit Scan.  Post both logs.
 
Process Explorer doesn't show anything hogging the CPU.
 
You didn't get the right display on the Task Manager.  That's the Overview page.  Click on the Disk tab.
 
 
 
 

  • 0

#6
FordTaurus00

FordTaurus00

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts

fixlist just keeps timing out.  but i took a screenshot of the disk tab and attached it

Attached Thumbnails

  • disk image.jpg

  • 0

#7
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Let's try it manually in reverse order.  Normally I let it run DISM first.  So let's run SFC first.

 

Search for:

cmd

It will find Command Prompt.  Right click on it and Run As Admin.  That will bring up a black window.

 

Type:

SFC  /scannow
Hit Enter
 
This usually takes about 10 minutes.  
 
When it finishes it will say one of the following:
 
Windows did not find any integrity violations (a good thing)
Windows Resource Protection found corrupt files and repaired them (a good thing)
Windows Resource Protection found corrupt files but was unable to fix some (or all) of them (not a good thing)
 
If you get the last result then type:
findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log  >  %UserProfile%\desktop\junk.txt 
 
 
Hit Enter.  Then type::
 
 
notepad %UserProfile%\desktop\junk.txt 
 
Hit Enter. 
 
 Copy the text from notepad and paste it into a reply.
 
 
After you finish SFC, regardless of the result:
 
Reboot then:
 
1. Please download the Event Viewer Tool by Vino Rosso
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:
 
* System
 
* Application
4. Under 'Select type to list', select:
* Error
* Warning
 
 
Then use the 'Number of events' as follows:
 
 
1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button and wait.
Notepad will open with the output log.
 
 
Please copy and paste the Output log into your next reply 
 
 
Open an Admin Command Prompt as before and type:
 
DISM  /Online  /Cleanup-Image  /RestoreHealth

Hit Enter.  This is probably the one that is timing out so will probably take longer than the usual 20 minutes.  May take as kong as two hours.  Be patient.

 

Reboot when done and rerun VEW as before.

 

We can look at the response of the hard drive.

HD Tune
 
 
 
Actual download is at:
 
 
 
 
Download, Save, right click and Run As Admin.  Run the Benchmark test and report your min, max & average transfer times.  Ideally the graph would be flat or slightly tilted to the right.  On a bad drive you will see sharp drops.  The fewer programs running at the same time the better.  Pause your anti-virus.
 
Also Seagate makes a drive test program:
 
 
Look for the one called:  
 
SeaTools 5
 
Windows version.
 
I haven't run it in a while as I only use Western Digital drives (and Samsung SSDs) but there are two tests.  The short one and the extended test.  Neither test should hurt your data.  if it fails either test it needs to be replaced.  
 
The screenshot is not sorted with the biggest entries in the Total column so not much use.  I do wonder what is going on with the top entry in the second section.  Is it trying to burn a CD or DVD?
 
 

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP