Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06.04.2024 01
Ran by david (administrator) on DESKTOP-OADEFFT (FUJITSU LIFEBOOK E734) (09-04-2024 05:55:59)
Running from C:\Users\david\Downloads\FRST64.exe
Loaded Profiles: david
Platform: Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Discord Inc. -> Discord Inc.) C:\Users\david\AppData\Local\Discord\app-1.0.9039\Discord.exe <6>
(explorer.exe ->) (Elan Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <18>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(explorer.exe ->) (Spotify AB -> Spotify Ltd) C:\Users\david\AppData\Roaming\Spotify\Spotify.exe <6>
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.363\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.363\GoogleCrashHandler64.exe
(Intel® pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wimserv.exe
(PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Intel® Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\NisSrv.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\david\AppData\Local\Microsoft\OneDrive\24.055.0317.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [FUJ02E3_BatteryChargingControlUpdate] => C:\Program Files (x86)\Fujitsu\FUJ02E3_BatteryChargingControlUpdate\CheckBatteryFW.exe [447808 2021-08-20] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU LIMITED)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2906608 2015-09-23] (Elan Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [FUJ02B1_Apps] => C:\Program Files (x86)\Fujitsu\FUJ02B1\CheckBatteryPack.exe [376128 2018-09-06] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16696840 2016-10-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1467400 2016-10-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS_SWVOL] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1467400 2016-10-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [FUJ02B1_Apps] => C:\Program Files (x86)\Fujitsu\FUJ02B1\CheckBatteryPack.exe [376128 2018-09-06] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU CLIENT COMPUTING LIMITED)
HKLM-x32\...\Run: [FUJ02E3_BatteryChargingControlUpdate] => C:\Program Files (x86)\Fujitsu\FUJ02E3_BatteryChargingControlUpdate\CheckBatteryFW.exe [447808 2021-08-20] (FUJITSU CLIENT COMPUTING LIMITED -> FUJITSU LIMITED)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Run: [Discord] => C:\Users\david\AppData\Local\Discord\Update.exe [1525024 2024-01-09] (Discord Inc. -> GitHub)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4384104 2024-03-06] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Run: [Spotify] => C:\Users\david\AppData\Roaming\Spotify\Spotify.exe [33526600 2024-03-25] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45285792 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Run: [MicrosoftEdgeAutoLaunch_30FCCE2722F4190AAE310221237BB02B] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4063784 2024-04-04] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\david\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\david\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" [67157520 2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\RunOnce: [Uninstall 24.050.0310.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\david\AppData\Local\Microsoft\OneDrive\24.050.0310.0001" [0 2024-04-09] () <==== ATTENTION [zero byte File/Folder]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\123.0.6312.106\Installer\chrmstp.exe [2024-04-08] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {760F5BDD-F686-46A7-9282-30BBBB73E45E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {F1798882-027A-41E7-A133-05510E2F3783} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5074848 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Gen Digital Inc. All rights reserved.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "e5347dbd-9e84-4a70-811b-ad1d555c6009" --version "6.22.10977" --silent
Task: {28BA7143-EF6C-4CA8-A7F6-DEA68DA0D6DC} - System32\Tasks\CCleanerSkipUAC - david => C:\Program Files\CCleaner\CCleaner.exe [39024544 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {BD8F8ADD-4F19-4C1B-A01F-33D89BD497A3} - System32\Tasks\GoogleUpdateTaskMachineCore{B18D7657-2F7F-498F-BC25-D473D4C5522C} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162080 2024-01-16] (Google LLC -> Google LLC)
Task: {D0BE20CC-D308-4069-B40A-9344A49C44F0} - System32\Tasks\GoogleUpdateTaskMachineUA{E11CFAF6-CB2C-428C-A1B5-B4B6EE3A58E8} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162080 2024-01-16] (Google LLC -> Google LLC)
Task: {8FA93DA7-FB8D-4BE7-9CEE-F5B566A1A97D} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [255056 2024-01-19] (Microsoft Corporation -> Microsoft)
Task: {CF926037-4077-4859-BD1E-9F74D961CCD1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1E20BE71-32C3-4EC9-807C-1E402F786889} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A112DC4F-53E6-4B7F-9D11-A8786FF2AA63} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {51E58255-EA4A-44E1-83AD-E74A6C9EE5BE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MpCmdRun.exe [1650024 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{930713eb-41ce-4d9f-ae20-b0cdcb7b71ae}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge Profile: C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default [2024-04-09]
Edge Extension: (RoPro - Enhance Your Roblox Experience) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\adbacgifemdbhdkfppmeilbgppmhaobf [2024-03-13]
Edge Extension: (Google Docs Offline) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-29]
Edge Extension: (BTRoblox - Making Roblox Better) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hbkpclpemjeibhioopcebchdmohaieln [2024-03-23]
Edge Extension: (Touch VPN - Secure and unlimited VPN proxy) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ighhnpmaabelnfcbbkijikgghajbiaml [2024-02-01]
Edge Extension: (Edge relevant text changes) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-27]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\Default [2024-04-09]
CHR Extension: (RoPro - Enhance Your Roblox Experience) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\adbacgifemdbhdkfppmeilbgppmhaobf [2024-03-13]
CHR Extension: (Just Black) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\aghfnjkcakhmadgdomlmlhhaocbkloab [2024-01-26]
CHR Extension: (Google Docs Offline) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-21]
CHR Extension: (Beyond 20) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnblbpbepfbfmoobegdogkglpbhcjofh [2024-02-24]
CHR Extension: (BTRoblox - Making Roblox Better) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbkpclpemjeibhioopcebchdmohaieln [2024-03-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-01-16]
CHR Extension: (hyde — hide the YouTube video player controls) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmkpddhfbiojipiehnejbjkgdgdpkdpb [2024-04-08]
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-03-28]
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-04-08]
CHR Extension: (Google Docs Offline) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-04-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-01-19]
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 2 [2024-03-28]
CHR Extension: (Google Docs Offline) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-01-26]
CHR Extension: (Chrome Web Store Payments) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-01-26]
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 3 [2024-03-28]
CHR Extension: (Just Black) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aghfnjkcakhmadgdomlmlhhaocbkloab [2024-01-26]
CHR Extension: (Google Docs Offline) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-01-26]
CHR Extension: (Chrome Web Store Payments) - C:\Users\david\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-01-26]
CHR Profile: C:\Users\david\AppData\Local\Google\Chrome\User Data\System Profile [2024-01-19]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1081248 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [935344 2023-10-13] (EasyAntiCheat Oy -> Epic Games, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9423680 2024-03-30] (Malwarebytes Inc. -> Malwarebytes)
S3 VSInstallerElevationService; C:\Program Files (x86)\Microsoft Visual Studio\Installer\VSInstallerElevationService.exe [41520 2024-01-19] (Microsoft Corporation -> Microsoft)
S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [142304 2022-06-01] (Microsoft Corporation -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\NisSrv.exe [3191272 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24020.7-0\MsMpEng.exe [133688 2024-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2020-12-23] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2020-12-23] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 ETDHIDUSB; C:\WINDOWS\System32\drivers\ETDHIDUSB.sys [233440 2015-09-23] (Elan Microelectronics Corporation -> ELAN Microelectronic Corp.)
R2 FBIOSDRV; C:\WINDOWS\System32\Drivers\FBIOSDRV.sys [48928 2016-01-28] (FUJITSU LIMITED -> FUJITSU LIMITED)
R3 FUJ02B1; C:\WINDOWS\System32\drivers\FUJ02B1.sys [68536 2018-09-06] (FUJITSU LIMITED -> FUJITSU LIMITED)
R3 fuj02e3; C:\WINDOWS\System32\drivers\fuj02e3.sys [182216 2021-08-20] (FUJITSU LIMITED -> FUJITSU LIMITED)
S3 GPIO; C:\WINDOWS\System32\drivers\iaiogpioe.sys [31232 2014-06-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
S3 iaioi2c; C:\WINDOWS\System32\drivers\iaioi2ce.sys [69632 2014-06-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223296 2024-03-30] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2024-02-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-02-08] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 parsecudeaudio; C:\WINDOWS\System32\drivers\parsecudeaudio.sys [163856 2023-05-24] (Microsoft Windows Hardware Compatibility Publisher -> Parsec)
S3 parsecvusba; C:\WINDOWS\System32\drivers\parsecvusba.sys [262712 2023-05-24] (Microsoft Windows Hardware Compatibility Publisher -> Parsec)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [76832 2022-09-30] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated)
R0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20928 2024-03-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [603416 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\System32\drivers\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105752 2024-03-13] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-04-09 05:55 - 2024-04-09 05:55 - 000000000 ___DC C:\Users\david\Downloads\FRST-OlderVersion
2024-04-09 05:42 - 2024-04-09 05:42 - 000000000 __HDC C:\OneDriveTemp
2024-04-08 04:40 - 2024-04-08 04:40 - 000000000 ___DC C:\Users\david\AppData\Roaming\Blender Foundation
2024-04-08 04:40 - 2024-04-08 04:40 - 000000000 ___DC C:\Users\david\AppData\Local\Blender Foundation
2024-04-08 04:40 - 2024-04-08 04:40 - 000000000 ___DC C:\Users\david\.thumbnails
2024-04-08 04:35 - 2024-04-08 04:35 - 000001314 ____C C:\Users\david\OneDrive\Desktop\Blender 4.1.lnk
2024-04-08 04:35 - 2024-04-08 04:35 - 000000000 ___DC C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\blender
2024-04-08 04:34 - 2024-04-08 04:34 - 000000000 ___DC C:\Program Files\Blender Foundation
2024-04-08 04:05 - 2024-04-08 04:10 - 343068672 ____C C:\Users\david\Downloads\blender-4.1.0-windows-x64.msi
2024-04-01 15:34 - 2024-04-01 15:35 - 000000000 __HDC C:\$WinREAgent
2024-03-19 09:00 - 2024-03-19 09:00 - 000137032 ____C (Zoom Video Communications, Inc.) C:\Users\david\Downloads\Zoom_cm_fo42lnktZ9vvrZo4_mOhRUBioIkX300FYal3iu4wJejON5PLhBzRoc@eBHqRsU8EY6fDT0q_k72deb81ba874761f_.exe
2024-03-19 08:41 - 2024-03-19 08:41 - 000000000 ___DC C:\ProgramData\Piriform
2024-03-19 08:41 - 2024-03-19 08:41 - 000000000 ___DC C:\ProgramData\Norton
2024-03-12 22:21 - 2024-03-12 22:21 - 000019530 ____C C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-03-12 22:21 - 2024-03-12 22:21 - 000019530 ____C C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-04-09 05:56 - 2024-01-19 12:37 - 000019758 ____C C:\Users\david\Downloads\FRST.txt
2024-04-09 05:56 - 2024-01-19 12:37 - 000000000 ___DC C:\FRST
2024-04-09 05:55 - 2024-01-19 12:35 - 002393600 ____C (Farbar) C:\Users\david\Downloads\FRST64.exe
2024-04-09 05:50 - 2024-01-21 11:17 - 000000000 ___DC C:\Program Files (x86)\Steam
2024-04-09 05:50 - 2024-01-15 18:50 - 000000000 ___DC C:\ProgramData\regid.1991-06.com.microsoft
2024-04-09 05:47 - 2024-01-16 08:49 - 000000000 ___DC C:\Program Files (x86)\Google
2024-04-09 05:47 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\SystemTemp
2024-04-09 05:42 - 2024-01-15 19:32 - 000000000 __RDC C:\Users\david\OneDrive
2024-04-09 05:41 - 2024-01-26 19:03 - 000000000 ___DC C:\Users\david\AppData\Local\Spotify
2024-04-09 05:41 - 2024-01-17 08:52 - 000003592 ____C C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1346671777-2945835254-3822528861-1001
2024-04-09 05:41 - 2024-01-15 19:32 - 000003380 ____C C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1346671777-2945835254-3822528861-1001
2024-04-09 05:41 - 2024-01-15 19:29 - 000002383 ____C C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-04-09 05:34 - 2024-02-08 02:30 - 000000000 ___DC C:\Users\david\AppData\Local\Malwarebytes
2024-04-09 05:34 - 2024-01-27 18:34 - 000000000 ___DC C:\Program Files\CCleaner
2024-04-09 05:34 - 2024-01-26 19:02 - 000000000 ___DC C:\Users\david\AppData\Roaming\Spotify
2024-04-09 05:34 - 2024-01-16 09:04 - 000002237 ____C C:\Users\david\OneDrive\Desktop\Discord.lnk
2024-04-09 05:34 - 2024-01-16 09:04 - 000000000 ___DC C:\Users\david\AppData\Roaming\discord
2024-04-09 05:34 - 2024-01-16 09:03 - 000000000 ___DC C:\Users\david\AppData\Local\Discord
2024-04-09 05:33 - 2024-01-16 05:04 - 000000180 ____C C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2024-04-09 05:33 - 2024-01-15 19:30 - 000000000 _SHDC C:\Users\david\IntelGraphicsProfiles
2024-04-08 08:16 - 2024-01-16 05:03 - 000000000 ___DC C:\WINDOWS\system32\SleepStudy
2024-04-08 08:16 - 2024-01-15 18:50 - 000000000 __HDC C:\Program Files\WindowsApps
2024-04-08 08:16 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\AppReadiness
2024-04-08 07:14 - 2024-01-16 10:16 - 000000000 ___DC C:\Users\david\AppData\Roaming\Telegram Desktop
2024-04-08 04:40 - 2024-01-15 19:29 - 000000000 ___DC C:\Users\david
2024-04-08 04:14 - 2024-01-16 05:04 - 000002438 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-04-08 04:08 - 2024-01-16 08:50 - 000002247 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-04-08 04:08 - 2024-01-16 05:04 - 000003536 ____C C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-04-08 04:08 - 2024-01-16 05:04 - 000003412 ____C C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-04-08 04:02 - 2024-01-19 11:42 - 000000000 ___DC C:\Program Files\Unity Hub
2024-04-08 03:45 - 2024-01-27 18:34 - 000004210 ____C C:\WINDOWS\system32\Tasks\CCleaner Update
2024-04-08 03:45 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\LiveKernelReports
2024-03-29 21:00 - 2024-01-16 05:12 - 001767980 ____C C:\WINDOWS\system32\PerfStringBackup.INI
2024-03-29 21:00 - 2024-01-15 18:52 - 000785394 ____C C:\WINDOWS\system32\perfh015.dat
2024-03-29 21:00 - 2024-01-15 18:52 - 000152280 ____C C:\WINDOWS\system32\perfc015.dat
2024-03-29 21:00 - 2024-01-15 18:48 - 000000000 ___DC C:\WINDOWS\INF
2024-03-29 20:52 - 2024-01-16 05:04 - 000000006 ___HC C:\WINDOWS\Tasks\SA.DAT
2024-03-29 20:52 - 2024-01-16 05:03 - 000008192 ___SH C:\DumpStack.log.tmp
2024-03-29 20:52 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\ServiceState
2024-03-29 20:52 - 2024-01-15 18:44 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2024-03-29 15:56 - 2024-01-24 13:12 - 000001401 ____C C:\Users\david\OneDrive\Desktop\Roblox Player.lnk
2024-03-29 15:56 - 2024-01-24 13:12 - 000001229 ____C C:\Users\david\OneDrive\Desktop\Roblox Studio.lnk
2024-03-29 15:56 - 2024-01-24 13:12 - 000000000 ___DC C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2024-03-29 14:42 - 2024-01-15 19:30 - 000000000 ___DC C:\Users\david\AppData\Local\Packages
2024-03-28 12:07 - 2024-02-11 07:49 - 000000000 ___DC C:\Users\david\AppData\Local\CrashDumps
2024-03-26 11:50 - 2024-01-16 08:53 - 000000000 ___DC C:\Users\david\AppData\Roaming\Zoom
2024-03-21 14:15 - 2024-01-27 18:34 - 000000666 ____C C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2024-03-21 14:14 - 2024-01-15 18:45 - 000000000 ___DC C:\WINDOWS\CbsTemp
2024-03-19 08:40 - 2024-01-27 18:34 - 000003382 ____C C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2024-03-15 21:28 - 2024-01-19 11:21 - 000000000 ___DC C:\Program Files\RUXIM
2024-03-14 14:32 - 2024-01-15 19:31 - 000000000 ___DC C:\ProgramData\Packages
2024-03-14 14:31 - 2024-01-15 19:32 - 000000000 ___DC C:\Users\david\AppData\Local\PlaceholderTileLogoFolder
2024-03-13 18:28 - 2024-01-16 05:03 - 000272072 ____C C:\WINDOWS\system32\FNTCACHE.DAT
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 __RDC C:\WINDOWS\ImmersiveControlPanel
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\SysWOW64\Dism
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\SystemResources
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\system32\oobe
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\system32\Dism
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\ShellExperiences
2024-03-13 18:28 - 2024-01-15 18:50 - 000000000 ___DC C:\WINDOWS\bcastdvr
2024-03-13 18:28 - 2024-01-15 18:44 - 000000000 ___DC C:\WINDOWS\servicing
2024-03-13 17:12 - 2024-01-16 05:04 - 000000000 ___DC C:\WINDOWS\system32\Drivers\wd
2024-03-12 22:21 - 2024-01-16 05:04 - 003017216 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2024-03-12 22:11 - 2024-01-19 11:21 - 000000000 ___DC C:\WINDOWS\system32\MRT
2024-03-12 22:09 - 2024-01-19 11:21 - 190470136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06.04.2024 01
Ran by david (09-04-2024 05:58:06)
Running from C:\Users\david\Downloads
Microsoft Windows 10 Home Version 22H2 19045.4170 (X64) (2024-01-16 02:08:05)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-1346671777-2945835254-3822528861-500 - Administrator - Disabled)
david (S-1-5-21-1346671777-2945835254-3822528861-1001 - Administrator - Enabled) => C:\Users\david
DefaultAccount (S-1-5-21-1346671777-2945835254-3822528861-503 - Limited - Disabled)
Guest (S-1-5-21-1346671777-2945835254-3822528861-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1346671777-2945835254-3822528861-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
blender (HKLM\...\{1589EDDA-7F97-49A7-A931-5646B819BC9E}) (Version: 4.1.0 - Blender Foundation)
CCleaner (HKLM\...\CCleaner) (Version: 6.22 - Piriform)
ClickOnce Bootstrapper Package for Microsoft .NET Framework (HKLM-x32\...\{22E13608-4DB0-4977-A267-3AAFA09CD54A}) (Version: 4.8.09037 - Microsoft Corporation) Hidden
DiagnosticsHub_CollectionService (HKLM\...\{FECAFEB5-8D0E-4AE4-8FA0-745BAA835C35}) (Version: 17.3.32601 - Microsoft Corporation) Hidden
Discord (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Discord) (Version: 1.0.9030 - Discord Inc.)
ELAN Touchpad 12.8.3.13_X64 (HKLM\...\Elantech) (Version: 12.8.3.13 - ELAN Microelectronic Corp.)
Entity Framework 6.2.0 Tools for Visual Studio 2022 (HKLM-x32\...\{3EDA2628-CE9D-4024-B0FC-669A477C3728}) (Version: 6.2.0.0 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 123.0.6312.106 - Google LLC)
Goose Goose Duck version 3.04.02 (HKLM-x32\...\{934B69A4-1E69-4309-9624-828F7982050D}_is1) (Version: 3.04.02 - Gaggle Studios Inc)
icecap_collection_neutral (HKLM-x32\...\{9DB8E966-047B-4FF5-B982-6FF32AD9EF02}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
icecap_collection_x64 (HKLM\...\{CFD78991-1C3B-4C91-9119-67A3C55D1F78}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
icecap_collectionresources (HKLM-x32\...\{62D8E076-72EB-44EB-99A6-6D7C22E6AAB8}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
icecap_collectionresourcesx64 (HKLM-x32\...\{6CE350F6-4B97-45A1-9B32-3B7925F2F25B}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
IntelliTraceProfilerProxy (HKLM\...\{F8B9E8C8-61E8-4E9E-879D-F3F498AD0230}) (Version: 15.0.21225.01 - Microsoft Corporation) Hidden
IntelliTraceProfilerProxy (HKLM-x32\...\{C8891AD2-C223-45CD-A9BE-617A68923B61}) (Version: 15.0.21225.01 - Microsoft Corporation) Hidden
Malwarebytes version 4.6.10.316 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.10.316 - Malwarebytes)
Microsoft .NET 8.0 Templates 8.0.101 (x64) (HKLM\...\{327FE233-6B6A-4AB4-89E1-746BC6FF8670}) (Version: 32.6.64801 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 8.0.1 (x64) (HKLM\...\{8F4A7EF6-D703-49BA-8CBF-25EACA80ACFE}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 8.0.1 (x64_arm64) (HKLM\...\{254DCD95-B644-4CA9-BC9D-6C8284624DC0}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET AppHost Pack - 8.0.1 (x64_x86) (HKLM\...\{6764BE50-AB13-4D6B-8893-F2FD8E801539}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.1 Doc Redirected Targeting Pack (ENU) (HKLM-x32\...\{8F5A2690-2EBD-4017-B995-C522C9204312}) (Version: 4.7.02558 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.1 Targeting Pack (HKLM-x32\...\{5686C5E9-A3B3-451E-A2EA-4C246CDE5CC9}) (Version: 4.7.02558 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 Targeting Pack (ENU) (HKLM-x32\...\{B517DBD3-B542-4FC8-9957-FFB2C3E65D1D}) (Version: 4.7.03062 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 Targeting Pack (HKLM-x32\...\{1784A8CD-F7FE-47E2-A87D-1F31E7242D0D}) (Version: 4.7.03062 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.8 SDK (HKLM-x32\...\{949C0535-171C-480F-9CF4-D25C9E60FE88}) (Version: 4.8.03928 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.8 Targeting Pack (ENU) (HKLM-x32\...\{A4EA9EE5-7CFF-4C5F-B159-B9B4E5D2BDE2}) (Version: 4.8.03761 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.8 Targeting Pack (HKLM-x32\...\{BAAF5851-0759-422D-A1E9-90061B597188}) (Version: 4.8.03761 - Microsoft Corporation) Hidden
Microsoft .NET Framework Cumulative Intellisense Pack for Visual Studio (ENU) (HKLM-x32\...\{1A9C3A1A-566B-4CFA-8B27-71FC623963BE}) (Version: 4.8.09037 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.1 (x64) (HKLM\...\{CF9AD294-8156-4084-A5CC-839970BA09FE}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Host - 8.0.1 (x86) (HKLM-x32\...\{41A5E673-39F9-4990-86C4-06132C5D4C90}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.1 (x64) (HKLM\...\{9B3DED90-F398-457A-9F6C-855A543FEC5C}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 8.0.1 (x86) (HKLM-x32\...\{69E249E3-4273-41A7-8955-510331DF4F32}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.1 (x64) (HKLM\...\{16FC6669-9194-4096-8BDA-68907224C20B}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 8.0.1 (x86) (HKLM-x32\...\{517088ED-4FE7-4A92-B833-6A72240B8933}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET SDK 8.0.101 (x64) from Visual Studio (HKLM\...\{24E9FB48-4983-4C9C-93D2-27307AE92B5E}) (Version: 8.1.123.58017 - Microsoft Corporation)
Microsoft .NET Standard Targeting Pack - 2.1.0 (x64) (HKLM\...\{A7036CFB-B403-4598-85FF-D397ABB88173}) (Version: 24.0.28113 - Microsoft Corporation) Hidden
Microsoft .NET Targeting Pack - 8.0.1 (x64) (HKLM\...\{227585DF-8EC9-4666-8A50-775D33FAE2D6}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Targeting Pack - 8.0.1 (x86) (HKLM-x32\...\{C0BC54F5-E755-4079-9A19-B015822DF58C}) (Version: 64.4.5793 - Microsoft Corporation) Hidden
Microsoft .NET Toolset 8.0.101 (x64) (HKLM\...\{9B8818C6-A34F-470C-B0FD-1765BB96A98A}) (Version: 32.6.64801 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.1 Shared Framework (x64) (HKLM\...\{093059CD-C51E-3BF3-95DA-E8269426A7F4}) (Version: 8.0.1.23580 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.1 Shared Framework (x86) (HKLM-x32\...\{8976E660-0FC8-3D45-95B9-72FEB340FD01}) (Version: 8.0.1.23580 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.1 Targeting Pack (x64) (HKLM\...\{031E4A07-D777-3102-B9ED-DD2A670186D9}) (Version: 8.0.1.23580 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 8.0.1 Targeting Pack (x86) (HKLM-x32\...\{D97FBF4B-A709-3D68-BC9E-7231ADAE1187}) (Version: 8.0.1.23580 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 123.0.2420.81 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 123.0.2420.81 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\OneDriveSetup.exe) (Version: 24.055.0317.0002 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2019 (HKLM\...\{5BC7E9EB-13E8-45DB-8A60-F2481FEB4595}) (Version: 15.0.2000.5 - Microsoft Corporation)
Microsoft TestPlatform SDK Local Feed (HKLM-x32\...\{839C2D45-DDF6-432C-A6A2-C6AF2EF281BF}) (Version: 17.0.0.5175695 - Microsoft) Hidden
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.38.33130 (HKLM-x32\...\{1de5e707-82da-4db6-b810-5d140cc4cbb3}) (Version: 14.38.33130.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.38.33130 (HKLM-x32\...\{2cfeba4a-21f8-4ea7-9927-c5a5c6f13cc9}) (Version: 14.38.33130.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.38.33130 (HKLM\...\{C31777DB-51C1-4B19-9F80-38EF5C1D7C89}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.38.33130 (HKLM\...\{1CA7421F-A225-4A9C-B320-A36981A2B789}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33130 (HKLM-x32\...\{5CA9AE7B-2EFC-4F02-81CD-32ABE173C755}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33130 (HKLM-x32\...\{DF1B52DF-C88E-4DDF-956B-6E7A03327F46}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 3.8.2122.37638 - Microsoft Corporation)
Microsoft Visual Studio Setup Configuration (HKLM-x32\...\{C777E5A3-D26A-4F0D-84AC-79ECE7560EA5}) (Version: 3.8.2091.34612 - Microsoft Corporation) Hidden
Microsoft Visual Studio Setup WMI Provider (HKLM-x32\...\{9E0059DE-74E7-49A5-8F2A-C17B5BE58B4C}) (Version: 3.8.2091.34612 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.1 (x64) (HKLM\...\{A46C65AB-B1B1-427F-87D5-1B8F22ACEC50}) (Version: 64.4.5797 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 8.0.1 (x86) (HKLM-x32\...\{B6D7ADDD-3020-47A1-BF6B-200097111909}) (Version: 64.4.5797 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Targeting Pack - 8.0.1 (x64) (HKLM\...\{3277237E-8466-4FCE-B5F4-A82B152DA1F9}) (Version: 64.4.5797 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Targeting Pack - 8.0.1 (x86) (HKLM-x32\...\{80F66075-4AFD-4CC9-8F71-0A39B29F95DB}) (Version: 64.4.5797 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Android.Manifest-8.0.100 (x64) (HKLM\...\{B5A57BF9-FC7A-4FA6-BAEB-46E173986DF3}) (Version: 34.0.43 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.iOS.Manifest-8.0.100 (x64) (HKLM\...\{1949FBD5-3860-4274-AA04-00E0E33C9B11}) (Version: 17.2.8004 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.MacCatalyst.Manifest-8.0.100 (x64) (HKLM\...\{BF0BA430-95E3-4AD1-917A-93C02E2FD1ED}) (Version: 17.2.8004 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.macOS.Manifest-8.0.100 (x64) (HKLM\...\{D7827DB4-FB1C-4A45-9E0B-AC57ECC286E6}) (Version: 14.2.8004 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.Maui.Manifest-8.0.100 (x64) (HKLM\...\{116EF6D0-AE8E-4E6D-B0D8-EFF145CD45DA}) (Version: 8.0.3 - Microsoft Corporation) Hidden
Microsoft.NET.Sdk.tvOS.Manifest-8.0.100 (x64) (HKLM\...\{2D16D57A-929A-42CE-B95A-53889E755F27}) (Version: 17.2.8004 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.Current.Manifest (x64) (HKLM\...\{6B392BFB-F933-478E-8117-047A5316147D}) (Version: 64.4.5649 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net6.Manifest (x64) (HKLM\...\{401CE2E2-3487-4F90-8441-58453E64AF77}) (Version: 64.4.5649 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Emscripten.net7.Manifest (x64) (HKLM\...\{B7026CB6-B219-4E2D-A5F8-5B83A6BA92BC}) (Version: 64.4.5649 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.Current.Manifest (x64) (HKLM\...\{862DF818-B4D9-402D-90BF-D4498ABB7A82}) (Version: 64.4.5765 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net6.Manifest (x64) (HKLM\...\{C072E2E0-93BB-450C-8D4E-D6406DB06DA7}) (Version: 64.4.5765 - Microsoft Corporation) Hidden
Microsoft.NET.Workload.Mono.Toolchain.net7.Manifest (x64) (HKLM\...\{D2E7F6D7-51C8-4C42-8FE0-F2BE9BA64459}) (Version: 64.4.5765 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7931 - Realtek Semiconductor Corp.)
RimWorld - Biotech (HKLM-x32\...\1865538500_is1) (Version: 1.4.3901 rev218 - GOG.com)
RimWorld - Ideology (HKLM-x32\...\1827857764_is1) (Version: 1.4.3901 rev218 - GOG.com)
RimWorld - Royalty (HKLM-x32\...\1233017772_is1) (Version: 1.4.3901 rev218 - GOG.com)
RimWorld (HKLM-x32\...\1094900565_is1) (Version: 1.4.3901 rev218 - GOG.com)
Roblox Player for david (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\roblox-player) (Version: - Roblox Corporation)
Spotify (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\Spotify) (Version: 1.2.33.1042.g26c92729 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.13.20 - Synaptics Incorporated)
Telegram Desktop (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.15.2 - Telegram FZ-LLC)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{B9A7A138-BFD5-4C73-A269-F78CCA28150E}) (Version: 8.94.0.0 - Microsoft Corporation)
vcpp_crt.redist.clickonce (HKLM-x32\...\{4BD69DE8-B66B-4BD4-A502-4E50AB081145}) (Version: 14.38.33130 - Microsoft Corporation) Hidden
Visual Studio Community 2022 (HKLM-x32\...\a45067d3) (Version: 17.8.5 - Microsoft Corporation)
VS Immersive Activate Helper (HKLM-x32\...\{FFFF1EAF-0FE4-4E67-82C2-CA5DB41BB093}) (Version: 17.0.125.0 - Microsoft Corporation) Hidden
VS JIT Debugger (HKLM\...\{C17B72FB-7790-44C0-B897-9BEE0BAD5BA0}) (Version: 17.0.125.0 - Microsoft Corporation) Hidden
VS Script Debugging Common (HKLM\...\{D56DC014-C4C1-4330-B32B-D9785DAE7BCB}) (Version: 17.0.125.0 - Microsoft Corporation) Hidden
vs_BlendMsi (HKLM-x32\...\{F52924D9-B226-488E-96AB-FA5A56722091}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsi (HKLM-x32\...\{4961B6E1-A98B-43A9-BFC0-F2E741B6F998}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsires (HKLM-x32\...\{8B0218E5-A9A0-4C9D-A0F4-442117192AE5}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_clickoncesigntoolmsi (HKLM-x32\...\{72BD9E2C-6B91-40B9-8FCF-FEDAFDD67C18}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_communitymsires (HKLM-x32\...\{3B1E620A-2D84-442A-9E91-3D5B6D4ECAAD}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_communitysharedmsi (HKLM-x32\...\{95F790F1-F8CC-445E-BBCB-C5446EF10C0C}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_communityx64msi (HKLM\...\{9DAFCFF7-0036-4739-A685-5DDF62466E05}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_CoreEditorFonts (HKLM-x32\...\{1851460E-0E63-4117-B5BA-25A2F045801B}) (Version: 17.7.40001 - Microsoft Corporation)
vs_devenvsharedmsi (HKLM-x32\...\{CBF6EE7C-AF9F-4B46-9097-60065588AC55}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_devenx64vmsi (HKLM\...\{3E31A14F-E205-4F3F-9E20-3BAEB97957D1}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_filehandler_amd64 (HKLM-x32\...\{F3214775-93E6-4462-AAAD-5ACFB687CED2}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_filehandler_x86 (HKLM-x32\...\{A749897F-8AD4-4006-B622-7A8CA09FEB2C}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_FileTracker_Singleton (HKLM-x32\...\{87A00560-EABF-4423-A876-F564B14F2499}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_githubprotocolhandlermsi (HKLM-x32\...\{4BD007CE-3471-40DA-9479-506CB09B8FBD}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_minshellinteropsharedmsi (HKLM-x32\...\{E5AF49C9-6FC6-404A-8562-16BDD6CFA531}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_minshellinteropx64msi (HKLM\...\{5F7E78E9-97B3-4CC2-AF61-4E13FFD183B9}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_minshellmsires (HKLM-x32\...\{3A6E1E89-2ED2-4F08-896B-F6F8999AD0F5}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_minshellsharedmsi (HKLM-x32\...\{E3FA95C9-9130-4173-AA94-60A8312A3CFC}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_minshellx64msi (HKLM\...\{C8E7596B-BE87-4C7B-B9A0-EA9BF41090D0}) (Version: 17.8.34205 - Microsoft Corporation) Hidden
vs_SQLClickOnceBootstrappermsi (HKLM-x32\...\{ED1CA098-DB2C-42FF-A9A5-BE564482AC95}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_tipsmsi (HKLM-x32\...\{424D8C15-669A-49BC-9DD4-99322263E41C}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
vs_vswebprotocolselectormsi (HKLM-x32\...\{AFF58319-E812-40D5-8C65-5A311B541716}) (Version: 17.8.34129 - Microsoft Corporation) Hidden
WinRAR 6.24 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.24.0 - win.rar GmbH)
Zoom (HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\...\ZoomUMX) (Version: 5.17.2 (29988) - Zoom Video Communications, Inc.)
Packages:
=========
ibis Paint -> C:\Program Files\WindowsApps\ibisinc.ibisPaint_12.0.4.0_x64__sxbx2qs82h9wr [2024-04-08] (ibis inc.)
Microsoft Copilot -> C:\Program Files\WindowsApps\Microsoft.Windows.Ai.Copilot.Provider_1.0.3.0_neutral__8wekyb3d8bbwe [2024-03-29] (Microsoft Corporation)
Roblox -> C:\Program Files\WindowsApps\ROBLOXCORPORATION.ROBLOX_2.618.546.0_x64__55nm5eh3cm0pr [2024-03-30] (Roblox Corporation)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-02-08] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-10-20] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-02-08] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2ce.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2024-01-15 18:50 - 2024-01-15 18:48 - 000000824 ____C C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1346671777-2945835254-3822528861-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{6CCADE46-6685-4EDF-A529-1E4A2904973A}] => (Allow) C:\Users\david\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{461DD8CC-C32E-4712-B984-F09264F3FF11}] => (Allow) C:\Users\david\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{19D4D2A2-D824-4429-8064-D5CFDE85374E}] => (Allow) C:\Users\david\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{E163F5E2-B4A0-4B0B-A21B-57216ABCA55F}] => (Allow) C:\Program Files\Unity Hub\Unity Hub.exe => No File
FirewallRules: [{BBB93C97-6535-4469-AA72-E2635CD5EEF9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{8FFA2879-1451-4E3F-AE68-15EE686E8DEC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{DFF564AF-B976-444C-B4FF-1CCAA0F9FE18}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{7CFBD9D8-7EEE-4291-940F-1BBDDA0A6BA7}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{C81058DC-6FB6-4BBD-8024-3DDC59C7BC31}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Pirate Plague of the Dead\ThePirate2.exe () [File not signed]
FirewallRules: [{8FB6435F-9943-4009-B366-C0FF42FDFCB1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Pirate Plague of the Dead\ThePirate2.exe () [File not signed]
FirewallRules: [TCP Query User{25B413D0-2794-4125-B178-24F5B73EDA95}C:\users\david\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\david\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{121C4610-59C9-4E64-BA1B-4A4B01D6FC79}C:\users\david\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\david\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{8D22F4CB-1410-4230-B194-64B65F45FEBD}C:\users\david\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\david\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{33466B66-5B49-4929-9199-156E011D2AE1}C:\users\david\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\david\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{778043E1-6AD6-43A3-B8C9-44A27E10AF52}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{7354C07B-7ACA-4407-8720-5546E49B37F0}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\123.0.2420.81\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C4B49B6A-FDDA-4507-AC98-69733CDE8CDC}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{BB9C3A03-6BB6-4AFF-A727-151C19DDAA18}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{AEB8ED22-21BF-45D4-8822-FC4469DA3CFA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1A5D85F7-622B-4906-9FA8-668CA71F3512}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.116.3213.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
==================== Restore Points =========================
ATTENTION: System Restore is disabled (Total:56.95 GB) (Free:8.03 GB) (14%)
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (03/27/2024 08:41:10 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SearchApp.exe version 10.0.19041.4170 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Process ID: 25b0
Start Time: 01da8020d2588ad8
Termination Time: 4294967295
Application Path: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
Report Id: 17126cdb-8461-4cd1-8446-4a7bd05907e0
Faulting package full name: Microsoft.Windows.Search_1.14.13.19041_neutral_neutral_cw5n1h2txyewy
Faulting package-relative application ID: ShellFeedsUI
Hang type: Quiesce
Error: (03/27/2024 07:29:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_cbdhsvc, version: 10.0.19041.3636, time stamp: 0x122dc5a3
Faulting module name: combase.dll, version: 10.0.19041.4123, time stamp: 0x81a292dc
Exception code: 0xc0000005
Fault offset: 0x00000000000339b5
Faulting process id: 0x504
Faulting application start time: 0x01da80201d7382af
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: C:\WINDOWS\System32\combase.dll
Report Id: e88d5c26-7f7e-4635-a6e2-dfd9a95bb5c4
Faulting package full name:
Faulting package-relative application ID:
Error: (03/23/2024 08:02:34 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program RobloxPlayerBeta.exe version 0.617.344.10272 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Process ID: 2df4
Start Time: 01da7cc3af46928c
Termination Time: 19
Application Path: C:\Users\david\AppData\Local\Roblox\Versions\version-2e85a7f050554e83\RobloxPlayerBeta.exe
Report Id: a99efce2-4a1b-43df-a2a0-d1b63466d803
Faulting package full name:
Faulting package-relative application ID:
Hang type: Unknown
Error: (03/23/2024 04:44:30 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program RobloxPlayerBeta.exe version 0.617.344.10272 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Process ID: 34d4
Start Time: 01da7cbda74ac20c
Termination Time: 12
Application Path: C:\Users\david\AppData\Local\Roblox\Versions\version-2e85a7f050554e83\RobloxPlayerBeta.exe
Report Id: ce1bb6b5-b65e-424a-ba6b-284ab75952a9
Faulting package full name:
Faulting package-relative application ID:
Hang type: Unknown
Error: (03/22/2024 12:24:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: malwarebytes_assistant.exe, version: 4.0.0.1747, time stamp: 0x65cbc6c8
Faulting module name: ucrtbase.dll, version: 10.0.19041.3636, time stamp: 0x81cf5d89
Exception code: 0xc0000409
Fault offset: 0x000000000007286e
Faulting process id: 0x383c
Faulting application start time: 0x01da7c3aaf3f9279
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe
Faulting module path: C:\WINDOWS\System32\ucrtbase.dll
Report Id: 98427aa5-33b9-4c5c-a244-691ec9ea84c5
Faulting package full name:
Faulting package-relative application ID:
Error: (03/21/2024 11:11:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: TextInputHost.exe, version: 123.26505.0.0, time stamp: 0x650e209e
Faulting module name: KERNELBASE.dll, version: 10.0.19041.3996, time stamp: 0xb756c9ff
Exception code: 0xc000027b
Fault offset: 0x000000000012d952
Faulting process id: 0x3a7c
Faulting application start time: 0x01da79bfeb3a4a77
Faulting application path: C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: 539ff861-0089-4592-b12e-c8bb45df5e7e
Faulting package full name: MicrosoftWindows.Client.CBS_1000.19054.1000.0_x64__cw5n1h2txyewy
Faulting package-relative application ID: InputApp
Error: (03/21/2024 10:46:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_cbdhsvc, version: 10.0.19041.3636, time stamp: 0x122dc5a3
Faulting module name: cbdhsvc.dll, version: 10.0.19041.3996, time stamp: 0xa3dae9cc
Exception code: 0xc0000005
Fault offset: 0x000000000005138d
Faulting process id: 0x1490
Faulting application start time: 0x01da79bfe4a8df6c
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: c:\windows\system32\cbdhsvc.dll
Report Id: 4ac02289-5e93-4dbd-819f-2fc5ae24cb74
Faulting package full name:
Faulting package-relative application ID:
Error: (03/19/2024 08:41:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: explorer.exe, version: 10.0.19041.4170, time stamp: 0x36e20eb9
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x725881f0
Faulting process id: 0x10dc
Faulting application start time: 0x01da79c00420c1d5
Faulting application path: C:\WINDOWS\SysWOW64\explorer.exe
Faulting module path: unknown
Report Id: 96415d19-00ce-418f-973f-b0252ee1f526
Faulting package full name:
Faulting package-relative application ID:
System errors:
=============
Error: (04/01/2024 03:35:29 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200b: 2024-01 Security Update for Windows 10 Version 22H2 for x64-based Systems (KB5034441).
Error: (03/29/2024 08:52:26 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-OADEFFT)
Description: The server Microsoft.Windows.ContentDeliveryManager_10.0.19041.3636_neutral_neutral_cw5n1h2txyewy!App.AppXwdz8g2fxr36xz0tdtagygnvemf85s7gg.mca did not register with DCOM within the required timeout.
Error: (03/29/2024 08:52:25 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-OADEFFT)
Description: The server Microsoft.MicrosoftOfficeHub_18.2311.1071.0_x64__8wekyb3d8bbwe!Microsoft.MicrosoftOfficeHub.AppXvhez9tbpytkh6zv5q0bx5fj12yay14wg.mca did not register with DCOM within the required timeout.
Error: (03/29/2024 08:52:25 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-OADEFFT)
Description: DCOM got error "1053" attempting to start the service BcastDVRUserService_4fd29 with arguments "Unavailable" in order to run the server:
Windows.Media.Capture.Internal.AppCaptureShell
Error: (03/29/2024 08:52:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The GameDVR and Broadcast User Service_4fd29 service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (03/29/2024 08:52:25 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the GameDVR and Broadcast User Service_4fd29 service to connect.
Error: (03/29/2024 08:35:17 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-OADEFFT)
Description: The server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter did not register with DCOM within the required timeout.
Error: (03/29/2024 03:56:55 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-OADEFFT)
Description: The server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter did not register with DCOM within the required timeout.
Windows Defender:
================
Date: 2024-04-01 19:02:19
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2024-04-01 15:44:56
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2024-03-29 19:34:55
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2024-03-29 19:23:52
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2024-03-28 18:04:54
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]:
Date: 2024-01-20 15:55:47
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.403.2416.0
Previous security intelligence Version: 1.403.2375.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.23110.2
Previous Engine Version: 1.1.23110.2
Error code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
Date: 2024-01-20 15:55:47
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.403.2416.0
Previous security intelligence Version: 1.403.2375.0
Update Source: User
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 1.1.23110.2
Previous Engine Version: 1.1.23110.2
Error code: 0x80501102
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
Date: 2024-01-16 04:22:56
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 0.0.0.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 0.0.0.0
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2024-01-16 04:22:56
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 0.0.0.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 0.0.0.0
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
Date: 2024-01-16 04:22:56
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 0.0.0.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 0.0.0.0
Error code: 0x80072ee7
Error description: The server name or address could not be resolved
CodeIntegrity:
===============
Date: 2024-02-08 01:32:07
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Microsoft signing level requirements.
Date: 2024-02-08 01:32:07
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: FUJITSU // Phoenix Technologies Ltd. Version 1.14 01/13/2015
Motherboard: FUJITSU FJNB270
Processor: Intel® Core i5-4200M CPU @ 2.50GHz
Percentage of memory in use: 73%
Total physical RAM: 8089.84 MB
Available physical RAM: 2180 MB
Total Virtual: 10649.84 MB
Available Virtual: 3710.21 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:56.95 GB) (Free:8.03 GB) (Model: TOSHIBA-TR150) NTFS
\\?\Volume{4b4035a3-2ecd-41a1-89af-809bd0d015be}\ (Відновити) (Fixed) (Total:0.52 GB) (Free:0.5 GB) NTFS
\\?\Volume{2f0c7daf-358d-4e24-867e-5235c9664dc3}\ () (Fixed) (Total:0.67 GB) (Free:0.08 GB) NTFS
\\?\Volume{11965be1-6d9e-4fb9-8343-8292078295e4}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 111.8 GB) (Disk ID: 6E505E75)
Partition: GPT.
==================== End of Addition.txt =======================
Edited by CaptainBlud, 08 April 2024 - 10:02 PM.