Hi, I’m seeing that my laptop has started downloading data by itself (lots of GB for no reason) and I suppose it could be a virus. I had a similar problem some time ago and you helped me a lot by writing a specific file to use with FRST tool. I was wondering if I could use the same file in order to solve the problem because it was written for this very laptop?
If not, here are FRST scan results (I scanned my laptop with AdwCleaner and Malwarebytes but they didn’t find anything). I would be very grateful for your help
If not, here are FRST scan results (I scanned my laptop with AdwCleaner and Malwarebytes but they didn’t find anything). I would be very grateful for your help
Code:
FRST.text Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-01-2023 Ran by acco5 (administrator) on LAPTOP-6ODOHNQP (ASUSTeK COMPUTER INC. ROG Strix G513IC_G513IC) (01-02-2023 05:19:32) Running from C:\Users\acco5\Desktop Loaded Profiles: acco5 Platform: Microsoft Windows 10 Home Version 21H2 19044.2486 (X64) Language: English (United Kingdom) Default browser: FF Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ASUSACCI\ArmouryCrateControlInterface.exe ->) (ASUSTEK COMPUTER INCORPORATION → ASUSTeK COMPUTER INC.) C:\Windows\System32\ASUSACCI\ACCIMonitor.exe (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSOptimization\AsusOSD.exe (ASUSTEK COMPUTER INCORPORATION → ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Display Control\ASUSSmartDisplayControl.exe (C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe ->) (ASUSTeK Computer Inc. → ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe (C:\Program Files (x86)\Speedify\SpeedifyUI.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\109.0.1518.70\msedgewebview2.exe <6> (C:\Program Files\ASUS\ARMOURY CRATE Service\ArmouryCrate.Service.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Service\ArmouryCrate.UserSessionHelper.exe (C:\Program Files\ASUS\ARMOURY CRATE Service\ArmouryCrate.UserSessionHelper.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Service\DenoiseAIPlugin\ArmouryCrate.DenoiseAI.exe (C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. → Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSOptimization\AsusOptimization.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSOptimization\AsusOptimizationStartupTask.exe (DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSoftwareManager\AsusSoftwareManager.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSoftwareManager\AsusSoftwareManagerAgent.exe (DriverStore\FileRepository\u0382793.inf_amd64_1c9c9d36a5813460\B384051\atiesrxx.exe ->) (Advanced Micro Devices Inc. → AMD) C:\Windows\System32\DriverStore\FileRepository\u0382793.inf_amd64_1c9c9d36a5813460\B384051\atieclxx.exe (explorer.exe ->) () [File not signed] C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe (explorer.exe ->) (Connectify (Connectify, Inc.) → Connectify) C:\Program Files (x86)\Speedify\SpeedifyUI.exe (Mozilla Corporation → Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <77> (services.exe ->) (Adobe Inc. → Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Advanced Micro Devices Inc. → AMD) C:\Windows\System32\DriverStore\FileRepository\u0382793.inf_amd64_1c9c9d36a5813460\B384051\atiesrxx.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUS Inc.) C:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSLinkRemote\AsusLinkRemote.exe (services.exe ->) (ASUSTeK Computer Inc. → ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\LightingService.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Service\ArmouryCrate.Service.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ASUS MultiAntenna Service\AsusMultiAntennaSvc.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Windows\System32\ASUSACCI\ArmouryCrateControlInterface.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\AsusAppService\AsusAppService.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTek Computer Inc.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSLinkNear\AsusLinkNear.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSOptimization\AsusOptimization.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSoftwareManager\AsusSoftwareManager.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSwitch\AsusSwitch.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSystemAnalysis\AsusSystemAnalysis.exe (services.exe ->) (ASUSTeK COMPUTER INC. → ASUSTek COMPUTER INC.) C:\Windows\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSystemDiagnosis\AsusSystemDiagnosis.exe (services.exe ->) (ASUSTEK COMPUTER INCORPORATION → ASUSTek Computer Inc.) C:\Program Files (x86)\ASUSTeK COMPUTER INC\RefreshRateService\RefreshRateService.exe (services.exe ->) (Connectify (Connectify, Inc.) → Connectify) C:\Program Files (x86)\Speedify\speedify.exe (services.exe ->) (Dolby Laboratories, Inc. → Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_a379f9cda17dd4b1\DAX3API.exe <2> (services.exe ->) (Malwarebytes Inc. → Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (services.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2> (services.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_8.71.12001.0_x64__8wekyb3d8bbwe\gamingservices.exe (services.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_8.71.12001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher → Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe (services.exe ->) (Nvidia Corporation → NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvami.inf_amd64_a6c8d8415ff0e012\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (Realtek Semiconductor Corp. → Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_719a4f3eb3c3c65a\RtkAudUService64.exe <3> (sihost.exe ->) (McAfee LLC.) C:\Program Files\WindowsApps\5a894077.mcafeesecurity_2.1.68.0_x64__wafk5atnkzcwy\Win32\mcafee-security-ft.exe (svchost.exe ->) (ASUSTeK COMPUTER INC. → ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe <2> (svchost.exe ->) (McAfee LLC.) C:\Program Files\WindowsApps\5a894077.mcafeesecurity_2.1.68.0_x64__wafk5atnkzcwy\mcafee-security.exe (svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.BingWeather_4.53.43112.0_x64__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\wlanext.exe (svchost.exe ->) (Realtek Semiconductor Corp) C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.37.275.0_x64__dt26b99r8h8gj\RtkUWP.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM...\Run: [Speedify] => C:\Program Files (x86)\Speedify\SpeedifyLauncher.exe [2198624 2022-12-16] (Connectify (Connectify, Inc.) → Connectify) HKLM-x32...\Run: [ASUS Smart Display Control] => C:\Program Files (x86)\ASUS\ASUS Smart Display Control\ASUSSmartDisplayControl.exe [143960 2021-03-25] (ASUSTEK COMPUTER INCORPORATION → ASUSTeK Computer Inc.) HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION HKU\S-1-5-21-895565649-3931333595-811618271-1001...\Run: [Rainlendar2] => C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe [2433024 2011-08-12] () [File not signed] HKU\S-1-5-21-895565649-3931333595-811618271-1001...\Run: [LilySpeechUtilA] => C:\Users\acco5\AppData\Local\LilySpeechApp\LilySpeechUtilA\assets\engine\LilySpeech64-2a.exe [1332688 2022-11-24] (Vertical Thinking Print & Web Inc → ) HKU\S-1-5-21-895565649-3931333595-811618271-1001...\Run: [LilySpeechUtilB] => C:\Users\acco5\AppData\Local\LilySpeechApp\LilySpeechUtilB\assets\engine\LilySpeech64-2b.exe [1332688 2022-11-24] (Vertical Thinking Print & Web Inc → ) HKU\S-1-5-21-895565649-3931333595-811618271-1001...\Run: [LilySpeechRec] => C:\Users\acco5\AppData\Local\LilySpeechRec\LilySpeechRec.exe [1035216 2022-11-24] (Vertical Thinking Print & Web Inc → ) HKU\S-1-5-21-895565649-3931333595-811618271-1001...\Run: [LilySpeechComms] => C:\Users\acco5\AppData\Local\LilySpeechApp\LilySpeechComms\LilyCommsCli.exe [123856 2022-11-24] (Vertical Thinking Print & Web Inc → CoreCommsCliWTCP) HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0171895D-5195-4597-BF0A-B56970948807} - System32\Tasks\ASUS Update Checker 2.0 => C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSoftwareManager\AsusUpdateChecker.exe [788104 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) Task: {11755330-1251-4CAE-9D10-855C11DA1D85} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Task: {1456FBB7-855A-4361-9232-A6A6496AE261} - System32\Tasks\AsusSystemAnalysis_754F3273-0563-4F20-B12F-826510B07474 => C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSystemAnalysis\AsusSystemAnalysis.exe [3606624 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) Task: {168DD57A-4D2D-4015-9EC3-1A9FA1B7777B} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144288 2023-01-13] (Microsoft Corporation → Microsoft Corporation) Task: {222688D0-243A-4CA6-84F0-CC830769A89B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. → Adobe Inc.) Task: {245A66D6-9C64-4A13-B3C0-9FC3A6E58386} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144288 2023-01-13] (Microsoft Corporation → Microsoft Corporation) Task: {4BA1119B-7D8D-4647-971B-ECC4015857C8} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-08-08] (ASUSTeK Computer Inc. → ASUSTeK Computer Inc.) Task: {5CED5C46-BD93-4367-92AA-276677D5DA9E} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [160696 2023-01-13] (Microsoft Corporation → Microsoft Corporation) Task: {7FE7A185-C3D1-409E-978B-2C0CBB28478A} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26326520 2023-01-13] (Microsoft Corporation → Microsoft Corporation) Task: {98AAEA1D-5A24-4210-8535-3E88E55B91DA} - System32\Tasks\ASUS Optimization 36D18D69AFC3 => C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSOptimization\AsusHotkey.exe [263784 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) Task: {AD74412B-B73B-4515-B286-509B8B2AC5E4} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d8c6df9cf467e6 => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-08-08] (ASUSTeK Computer Inc. → ASUSTeK Computer Inc.) Task: {C19160BB-6AFD-4196-A830-5044D6EE72C5} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task “308046B0AF4A39CB” Task: {C6C0FF51-0027-459B-B893-5A6D2781C979} - System32\Tasks\WaterfoxLimited\Waterfox Default Browser Agent 6F940AC27A98DD61 => C:\Program Files\Waterfox\default-browser-agent.exe [913760 2022-11-14] (WATERFOX LIMITED → Mozilla Foundation) Task: {DB45AA09-EC6D-408B-9A5E-E3E6A023A630} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26326520 2023-01-13] (Microsoft Corporation → Microsoft Corporation) Task: {EB595763-BF8E-4FA0-BD51-254DF4BC1504} - System32\Tasks\RtkAudUService64_BG => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_719a4f3eb3c3c65a\RtkAudUService64.exe [1588040 2022-08-11] (Realtek Semiconductor Corp. → Realtek Semiconductor) Task: {FE320D9D-19CA-4953-840F-18514DDC33CD} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe [43509488 2022-07-08] (ASUSTeK COMPUTER INC. → ASUSTek Computer Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.43.1 Tcpip..\Interfaces{0ac74aa6-98d2-4fa3-852f-3071b9d2dde6}: [DhcpNameServer] 192.168.43.1 Tcpip..\Interfaces{29e692aa-8946-4b4c-b7d7-dcae16a34d82}: [NameServer] 10.202.0.1 [HEADING=1]Edge:[/HEADING] Edge Profile: C:\Users\acco5\AppData\Local\Microsoft\Edge\User Data\Default [2023-01-25] [HEADING=1]FireFox:[/HEADING] FF DefaultProfile: 47lu9k1b.68-edition-default FF DefaultProfile: gvfemib7.default FF ProfilePath: C:\Users\acco5\AppData\Roaming\Waterfox\Profiles\47lu9k1b.68-edition-default [2022-12-09] FF ProfilePath: C:\Users\acco5\AppData\Roaming\Waterfox\Profiles\sv19yli3.default-release [2022-12-10] FF Session Restore: Waterfox\Profiles\sv19yli3.default-release → is enabled. FF ProfilePath: C:\Users\acco5\AppData\Roaming\Mozilla\Firefox\Profiles\gvfemib7.default [2022-09-16] FF ProfilePath: C:\Users\acco5\AppData\Roaming\Mozilla\Firefox\Profiles\h2m6kk2k.default-release [2023-02-01] FF Session Restore: Mozilla\Firefox\Profiles\h2m6kk2k.default-release → is enabled. FF Extension: (uBlock Origin) - C:\Users\acco5\AppData\Roaming\Mozilla\Firefox\Profiles\h2m6kk2k.default-release\Extensions\uBlock0@raymondhill.net.xpi [2022-12-25] FF Extension: (Ecosia - The search engine that plants trees) - C:\Users\acco5\AppData\Roaming\Mozilla\Firefox\Profiles\h2m6kk2k.default-release\Extensions{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2023-01-30] FF Plugin: @microsoft.com/SharePoint,version=14.0 → C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-18] (Microsoft Corporation → Microsoft Corporation) FF Plugin: Adobe Acrobat → C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-01-21] (Adobe Inc. → Adobe Systems Inc.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 → C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-18] (Microsoft Corporation → Microsoft Corporation) ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. → Adobe Inc.) R2 ArmouryCrateControlInterface; C:\WINDOWS\System32\ASUSACCI\ArmouryCrateControlInterface.exe [1181296 2022-08-18] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) R2 ArmouryCrateService; C:\Program Files\ASUS\ARMOURY CRATE Service\ArmouryCrate.Service.exe [394864 2022-11-24] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-08-08] (ASUSTeK Computer Inc. → ASUSTeK Computer Inc.) R2 AsusAppService; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\AsusAppService\AsusAppService.exe [1162376 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [181576 2021-09-30] (ASUSTeK Computer Inc. → ASUSTek COMPUTER INC.) R2 ASUSLinkNear; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSLinkNear\AsusLinkNear.exe [1320072 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTek Computer Inc.) R2 ASUSLinkRemote; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSLinkRemote\AsusLinkRemote.exe [764504 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [167384 2021-08-08] (ASUSTeK Computer Inc. → ASUSTeK Computer Inc.) R2 AsusMultiAntennaSvc; C:\Program Files\ASUS\ASUS MultiAntenna Service\AsusMultiAntennaSvc.exe [949872 2022-09-21] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) R2 ASUSOptimization; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSOptimization\AsusOptimization.exe [394344 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) R2 ASUSSoftwareManager; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSoftwareManager\AsusSoftwareManager.exe [1113176 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) R2 ASUSSwitch; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSwitch\AsusSwitch.exe [635480 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) R2 ASUSSystemAnalysis; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSystemAnalysis\AsusSystemAnalysis.exe [3606624 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) R2 ASUSSystemDiagnosis; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSystemDiagnosis\AsusSystemDiagnosis.exe [791176 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTek COMPUTER INC.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12548520 2023-01-13] (Microsoft Corporation → Microsoft Corporation) R2 DolbyDAXAPI; C:\WINDOWS\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_a379f9cda17dd4b1\DAX3API.exe [2431544 2022-03-09] (Dolby Laboratories, Inc. → Dolby Laboratories) R2 GameSDK Service; C:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe [397544 2022-05-31] (ASUSTeK COMPUTER INC. → ASUS Inc.) R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [3887976 2022-09-26] (ASUSTeK COMPUTER INC. → ASUSTek Computer Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8966256 2023-02-01] (Malwarebytes Inc. → Malwarebytes) R2 RefreshRateService; C:\Program Files (x86)\ASUSTeK COMPUTER INC\RefreshRateService\RefreshRateService.exe [40672 2021-09-10] (ASUSTEK COMPUTER INCORPORATION → ASUSTek Computer Inc.) R2 ROG Live Service; C:\Program Files (x86)\ASUS\ROG Live Service\ROGLiveService.exe [6739056 2022-09-21] (ASUSTeK COMPUTER INC. → ASUSTek COMPUTER INC.) R2 Speedify; C:\Program Files (x86)\Speedify\Speedify.exe [5365344 2022-12-16] (Connectify (Connectify, Inc.) → Connectify) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe [3191264 2022-12-09] (Microsoft Windows Publisher → Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe [133592 2022-12-09] (Microsoft Windows Publisher → Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_a6c8d8415ff0e012\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_a6c8d8415ff0e012\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [25016 2021-10-29] (Microsoft Windows Hardware Compatibility Publisher → Advanced Micro Devices, Inc.) R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0382793.inf_amd64_1c9c9d36a5813460\B384051\amdkmdag.sys [80465832 2022-10-03] (Advanced Micro Devices Inc. → Advanced Micro Devices, Inc.) R1 Asusgio3; C:\WINDOWS\system32\drivers\AsIO3.sys [43168 2021-09-30] (ASUSTeK Computer Inc. → ) R3 AsusPTPDrv; C:\WINDOWS\System32\drivers\AsusPTPFilter.sys [112848 2020-09-27] (ASUSTek Computer Inc. → ASUSTek COMPUTER INC.) R3 AsusSAIO; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSystemAnalysis\AsusSAIO.sys [46736 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) R1 ATKWMIACPIIO; C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSOptimization\AsusWmiAcpi.sys [45248 2022-12-07] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [287232 2022-07-01] (Microsoft Corporation) [File not signed] S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. → Samsung Electronics Co., Ltd.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2022-09-15] (Microsoft Windows Hardware Compatibility Publisher → Malwarebytes) R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [33424 2021-07-18] (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) R3 IGO_VSD; C:\WINDOWS\system32\drivers\igovsd.sys [42344 2021-07-05] (British Cayman Islands Intelligo Technology Inc. Taiwan Branch → Intelligo Technology Inc.) R3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [35344 2022-11-24] (ASUSTEK COMPUTER INC. → ASUSTeK Computer Inc.) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223176 2023-02-01] (Microsoft Windows Hardware Compatibility Publisher → Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2022-09-15] (Microsoft Windows Early Launch Anti-malware Publisher → Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [198088 2023-02-01] (Microsoft Windows Hardware Compatibility Publisher → Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [76216 2023-02-01] (Microsoft Windows Hardware Compatibility Publisher → Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2022-12-11] (Microsoft Windows Hardware Compatibility Publisher → Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [181816 2023-02-01] (Malwarebytes Inc. → Malwarebytes) R3 MTKBTFilterX64; C:\WINDOWS\system32\DRIVERS\mtkbtfilterx.sys [280040 2022-08-17] (Microsoft Windows Hardware Compatibility Publisher → MediaTek Inc.) R3 mtkwlex; C:\WINDOWS\System32\drivers\mtkwl6ex.sys [1403248 2022-04-27] (Microsoft Windows Hardware Compatibility Publisher → MediaTek Inc.) R3 nvpcf; C:\WINDOWS\System32\drivers\nvpcf.sys [234568 2022-06-24] (Nvidia Corporation → NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48552 2021-11-01] (Microsoft Windows Hardware Compatibility Publisher → NVIDIA Corporation) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. → Samsung Electronics Co., Ltd.) S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [65144 2021-10-08] (Samsung Electronics Co., Ltd. → QUALCOMM Incorporated) R3 tap0901cn; C:\WINDOWS\System32\drivers\tap0901cn.sys [47448 2020-07-09] (Connectify (Connectify, Inc.) → The OpenVPN Project) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49568 2022-12-09] (Microsoft Windows Early Launch Anti-malware Publisher → Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [473376 2022-12-09] (Microsoft Windows → Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99616 2022-12-09] (Microsoft Windows → Microsoft Corporation) U1 aswbdisk; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2023-02-01 05:19 - 2023-02-01 05:19 - 000026481 _____ C:\Users\acco5\Desktop\FRST.txt 2023-02-01 05:16 - 2023-02-01 05:16 - 002376704 _____ (Farbar) C:\Users\acco5\Desktop\FRST64.exe 2023-02-01 04:46 - 2023-02-01 04:48 - 000000000 ____D C:\ProgramData\HitmanPro 2023-02-01 04:38 - 2023-02-01 04:43 - 000000000 ____D C:\ProgramData\Ultra Adware Killer 2023-02-01 04:38 - 2023-02-01 04:38 - 001319192 ____H (Carifred) C:\Users\acco5\Downloads\UltraAdwareKiller64.exe 2023-02-01 04:33 - 2023-02-01 04:47 - 000000000 ____D C:\Program Files\9-lab 2023-02-01 04:33 - 2023-02-01 04:33 - 000000000 ____D C:\Users\acco5\AppData\Roaming\9-lab 2023-02-01 04:33 - 2023-02-01 04:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool 2023-02-01 04:33 - 2023-02-01 04:33 - 000000000 ____D C:\ProgramData\9-lab 2023-02-01 02:48 - 2023-02-01 02:48 - 000181816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2023-01-31 08:39 - 2023-01-31 08:39 - 000042211 _____ C:\Users\acco5\Downloads\01356123_doc_htm.htm 2023-01-28 08:48 - 2023-01-28 08:48 - 000002063 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk 2023-01-27 17:15 - 2023-01-27 17:15 - 000055460 _____ C:\Users\acco5\Desktop\Facture SCI Rezo - AB.pdf 2023-01-27 17:03 - 2023-01-27 17:03 - 000180814 _____ C:\Users\acco5\Desktop\Attestation d’hébergement.pdf 2023-01-27 09:34 - 2023-01-27 13:37 - 000016173 _____ C:\Users\acco5\Desktop\Facture SCI Rezo.odt 2023-01-24 06:15 - 2023-01-24 06:15 - 005997079 _____ C:\Users\acco5\Desktop\Eckhart Tolle The Power of Now.pdf 2023-01-23 21:46 - 2023-01-23 21:46 - 000111021 _____ C:\Users\acco5\Downloads\wsmtb_prologue.pdf 2023-01-21 15:23 - 2023-01-28 17:49 - 000002278 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2023-01-20 06:02 - 2023-01-30 09:52 - 000000000 ____D C:\Program Files\Mozilla Firefox 2023-01-16 15:55 - 2023-01-16 15:55 - 000675311 _____ C:\Users\acco5\Desktop\Jeff Foster Membership offers.pdf 2023-01-14 21:09 - 2023-01-10 09:34 - 000000000 ___D C:\Users\acco5\Desktop\Secret Diaries - Manage a Manor 2023-01-14 20:13 - 2023-01-14 21:09 - 341926203 _____ C:\Users\acco5\Downloads\Secret_Diaries-_Manage_a_Manor.rar 2023-01-11 17:10 - 2023-01-11 17:10 - 000000000 ____D C:\Users\acco5\Documents\Zoom 2023-01-11 17:09 - 2023-01-11 17:09 - 000000000 ____D C:\Users\acco5\AppData\Roaming\Zoom 2023-01-11 17:09 - 2023-01-11 17:09 - 000000000 ____D C:\Users\acco5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom 2023-01-11 17:09 - 2023-01-11 17:09 - 000000000 ____D C:\Users\acco5\AppData\Local\Zoom 2023-01-11 12:51 - 2023-01-11 12:51 - 000000000 ___HD C:$WinREAgent 2023-01-11 12:32 - 2023-01-31 23:52 - 000000000 ____D C:\Users\acco5\AppData\Local\CrashDumps 2023-01-11 11:46 - 2023-01-11 12:09 - 000001687 _____ C:\Users\acco5\Desktop\Writings.txt 2023-01-11 11:12 - 2023-01-11 14:04 - 000000000 ____D C:\Users\acco5\AppData\Local\LilySpeechRec 2023-01-11 11:12 - 2023-01-11 11:12 - 000000000 ____D C:\Users\acco5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LilySpeech 2023-01-11 10:56 - 2023-01-11 10:56 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime 2023-01-11 10:53 - 2023-01-11 11:12 - 000000000 ____D C:\Users\acco5\AppData\Local\LilySpeechApp 2023-01-10 15:21 - 2023-01-10 15:21 - 000157357 _____ C:\Users\acco5\Desktop\urssaf-justificatif-declaration-2022-T4-20230110-15h21.pdf 2023-01-08 19:01 - 2023-01-08 19:01 - 009180856 _____ (Connectify) C:\Users\acco5\Downloads\SpeedifyInstaller.exe 2023-01-08 19:01 - 2023-01-08 19:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speedify ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2023-02-01 05:19 - 2022-09-14 13:43 - 000000000 ____D C:\FRST 2023-02-01 04:32 - 2022-09-13 06:17 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-02-01 03:45 - 2022-09-13 06:17 - 000000000 ___HD C:\Program Files\WindowsApps 2023-02-01 03:45 - 2022-09-13 06:17 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-02-01 02:45 - 2022-09-15 09:05 - 000002035 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2023-02-01 02:42 - 2022-09-15 09:04 - 000000000 ____D C:\ProgramData\Malwarebytes 2023-02-01 02:42 - 2022-09-15 09:03 - 000000000 ____D C:\Program Files\Malwarebytes 2023-02-01 01:43 - 2022-09-13 05:33 - 000003752 _____ C:\WINDOWS\system32\Tasks\AsusSystemAnalysis_754F3273-0563-4F20-B12F-826510B07474 2023-02-01 01:39 - 2022-09-12 21:32 - 000000000 ____D C:\Users\acco5\AppData\LocalLow\Mozilla 2023-02-01 01:37 - 2022-11-19 05:04 - 000000000 ____D C:\ProgramData\Speedify 2023-02-01 01:37 - 2022-09-13 06:20 - 000000000 ____D C:\WINDOWS\system32\ASUSACCI 2023-01-31 22:06 - 2022-09-13 05:24 - 000000000 ____D C:\ProgramData\ASUS 2023-01-31 22:06 - 2021-08-08 16:56 - 000000000 ____D C:\Program Files\ASUS 2023-01-31 22:06 - 2021-08-08 16:56 - 000000000 ____D C:\Program Files (x86)\ASUS 2023-01-31 22:06 - 2021-08-08 16:54 - 000000000 ____D C:\ProgramData\Package Cache 2023-01-31 19:29 - 2022-09-13 05:24 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-01-30 09:58 - 2022-09-13 06:17 - 000000000 ____D C:\WINDOWS\INF 2023-01-30 09:58 - 2022-09-13 05:36 - 000333402 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2023-01-30 09:56 - 2022-09-12 20:43 - 000000000 ____D C:\Users\acco5\AppData\Local\D3DSCache 2023-01-30 09:56 - 2022-09-12 20:40 - 000000000 ____D C:\Users\acco5 2023-01-30 09:53 - 2022-09-12 21:32 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2023-01-30 09:52 - 2022-09-12 21:32 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2023-01-30 09:52 - 2022-09-12 21:32 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2023-01-30 09:52 - 2022-09-12 21:32 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2023-01-30 09:51 - 2022-09-13 06:17 - 000000000 ____D C:\WINDOWS\ServiceState 2023-01-30 09:51 - 2022-09-13 05:25 - 000000000 ____D C:\ProgramData\NVIDIA 2023-01-30 09:51 - 2022-09-13 05:24 - 000008192 ___SH C:\DumpStack.log.tmp 2023-01-30 09:51 - 2022-09-13 05:24 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2023-01-30 09:51 - 2022-09-12 22:42 - 000000000 ____D C:\Users\acco5.rainlendar2 2023-01-30 09:50 - 2022-09-13 06:14 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2023-01-30 00:42 - 2022-11-18 17:31 - 000026133 _____ C:\Users\acco5\Desktop\Movies.ods 2023-01-28 17:49 - 2022-09-13 05:25 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-01-28 08:48 - 2022-11-18 17:16 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2023-01-28 08:48 - 2022-11-18 17:16 - 000002075 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk 2023-01-25 20:48 - 2022-09-12 20:47 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-895565649-3931333595-811618271-1001 2023-01-25 20:48 - 2022-09-12 20:44 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-895565649-3931333595-811618271-1001 2023-01-25 20:48 - 2022-09-12 20:40 - 000002381 _____ C:\Users\acco5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2023-01-24 08:16 - 2022-12-20 09:34 - 000000000 ____D C:\Users\acco5\AppData\Local\ElevatedDiagnostics 2023-01-24 08:04 - 2022-09-12 22:02 - 000015042 _____ C:\Users\acco5\Desktop\Life Without Resistance.odt 2023-01-24 05:49 - 2022-09-12 22:02 - 000000000 ____D C:\Users\acco5\Desktop\Newest files from other computer 2023-01-19 13:31 - 2022-09-15 08:30 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2023-01-14 21:09 - 2022-10-29 03:29 - 000000000 ____D C:\Users\acco5\AppData\LocalLow\SQRT3 2023-01-13 18:48 - 2020-11-21 13:43 - 000000000 ____D C:\Program Files\Microsoft Office 2023-01-11 14:47 - 2022-11-18 22:03 - 000009838 _____ C:\GetDeviceStatus.xml 2023-01-11 14:47 - 2022-11-18 22:03 - 000005458 _____ C:\GetDeviceCap.xml 2023-01-11 14:47 - 2022-11-18 22:03 - 000000538 _____ C:\QueryAllDevice.xml 2023-01-11 14:47 - 2022-11-18 22:03 - 000000228 _____ C:\SetMatrixLEDScript.xml 2023-01-11 14:47 - 2022-09-13 05:24 - 000630048 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2023-01-11 14:46 - 2022-09-13 06:17 - 000000000 ____D C:\WINDOWS\SystemResources 2023-01-11 14:46 - 2022-09-13 06:17 - 000000000 ____D C:\WINDOWS\system32\oobe 2023-01-11 14:46 - 2022-09-13 06:17 - 000000000 ____D C:\WINDOWS\system32\migwiz 2023-01-11 14:46 - 2022-09-13 06:17 - 000000000 ____D C:\WINDOWS\bcastdvr 2023-01-11 14:34 - 2022-09-12 23:05 - 000000000 ____D C:\WINDOWS\system32\MRT 2023-01-11 12:55 - 2022-09-13 06:14 - 000000000 ____D C:\WINDOWS\CbsTemp 2023-01-11 12:54 - 2022-09-13 05:26 - 003014656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2023-01-11 09:33 - 2022-09-12 23:05 - 150199536 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2023-01-10 15:30 - 2022-11-18 16:58 - 000000000 ____D C:\Users\acco5\Desktop\Temporary folder for old computer 2023-01-08 19:01 - 2022-11-19 05:06 - 000001233 _____ C:\Users\acco5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Speedify.lnk 2023-01-08 19:01 - 2022-11-19 05:04 - 000001311 _____ C:\Users\Public\Desktop\Speedify.lnk 2023-01-08 19:01 - 2022-11-19 05:04 - 000000000 ____D C:\Program Files (x86)\Speedify 2023-01-08 03:22 - 2022-09-13 05:25 - 000004122 _____ C:\WINDOWS\system32\Tasks\ASUS Update Checker 2.0 2023-01-08 03:22 - 2022-09-13 05:24 - 000003756 _____ C:\WINDOWS\system32\Tasks\ASUS Optimization 36D18D69AFC3 2023-01-04 01:26 - 2022-09-13 05:24 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2023-01-04 01:26 - 2022-09-13 05:24 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore ==================== Files in the root of some directories ======== 2022-12-22 02:38 - 2022-11-15 08:02 - 000000416 ___RH () C:\Users\acco5\AppData\Roaming_fwwin32bk-3DEF-8688.cfg ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ======================== Additional.txt [HEADING=1]Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-01-2023 Ran by acco5 (01-02-2023 05:20:14) Running from C:\Users\acco5\Desktop Microsoft Windows 10 Home Version 21H2 19044.2486 (X64) (2022-09-13 04:33:03) Boot Mode: Normal[/HEADING] ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) acco5 (S-1-5-21-895565649-3931333595-811618271-1001 - Administrator - Enabled) => C:\Users\acco5 Administrator (S-1-5-21-895565649-3931333595-811618271-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-895565649-3931333595-811618271-503 - Limited - Disabled) Guest (S-1-5-21-895565649-3931333595-811618271-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-895565649-3931333595-811618271-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Enabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with “Hidden” flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat (64-bit) (HKLM...{AC76BA86-1033-1033-7760-BC15014EA700}) (Version: 22.003.20314 - Adobe) AI Noise Cancelation Audio Software (HKLM-x32...{ab5f014e-883d-470d-bc2d-127ef91e5611}) (Version: 2.0.3 - ASUSTek Computer Inc.) AI Noise Cancelation Audio Software SDK (HKLM...{9B441197-6389-46FC-BE60-56C8B6E5ADE9}) (Version: 1.0.6 - ASUSTeK COMPUTER INC.) ARMOURY CRATE Service (HKLM...{01378DC3-088F-4F55-AAFA-DC6A9CCA292A}) (Version: 5.3.3 - ASUS) ASUS Aac_GmAcc HAL (HKLM...{998249B1-6913-447E-AA37-F445B8CA33D0}) (Version: 1.0.0.0 - ASUSTek COMPUTER INC.) Hidden ASUS Aac_GmAcc HAL (HKLM-x32...{fd4cf3d0-9937-417e-89b4-56658158819a}) (Version: 1.0.0.0 - ASUSTek COMPUTER INC.) Hidden ASUS Aac_NBDT HAL (HKLM...{01D3B7AA-D078-4506-B460-60877FCDDBD6}) (Version: 2.5.24.0 - ASUSTek COMPUTER INC.) Hidden ASUS Aac_NBDT HAL (HKLM-x32...{ba95a7ce-ede3-4308-a5d6-6c08a15bff04}) (Version: 2.5.24.0 - ASUSTek COMPUTER INC.) Hidden ASUS AURA Display Component (HKLM...{AFD1CF98-FE97-434C-A095-9F27C5BEA53C}) (Version: 1.2.12.0 - ASUSTek COMPUTER INC. ) Hidden ASUS AURA Display Component (HKLM-x32...{fe2996bf-7174-4ad7-af8c-3e8e510c8263}) (Version: 1.2.12.0 - ASUSTek COMPUTER INC. ) Hidden ASUS AURA Headset Component (HKLM...{A3C4120D-8096-4307-91A2-FFE37EBD5A3D}) (Version: 1.3.26.0 - ASUSTek COMPUTER INC.) Hidden ASUS AURA Headset Component (HKLM-x32...{b351ae91-a5dd-4741-8830-883dddd22eb7}) (Version: 1.3.26.0 - ASUSTek COMPUTER INC.) Hidden ASUS Aura SDK (HKLM...{CF8E6E00-9C03-4440-81C0-21FACB921A6B}) (Version: 3.04.19 - ASUSTek COMPUTER INC.) Hidden ASUS Framework Service (HKLM-x32...{339A6383-7862-46DA-8A9D-E84180EF9424}) (Version: 3.1.0.2 - ASUSTeK Computer Inc.) ASUS Framework Service (HKLM-x32...{80f60ecc-98e1-474b-aee2-0c470f02dbbc}) (Version: 2.0.2.6 - ASUSTek COMPUTER INC.) ASUS Framework Service (HKLM-x32...{EA6A87BE-8AD3-40D2-944C-9DF5FBFF4332}) (Version: 2.0.2.6 - ASUSTek COMPUTER INC.) Hidden ASUS Keyboard HAL (HKLM...{0FA0CDEE-5DC8-421E-A97D-C74FA6E66FC3}) (Version: 1.1.48.0 - ASUSTek COMPUTER INC.) Hidden ASUS Keyboard HAL (HKLM-x32...{79497ebd-229a-42ac-9410-87264af2e929}) (Version: 1.1.48.0 - ASUSTek COMPUTER INC.) Hidden ASUS MB Peripheral Products (HKLM...{BFED9861-7D96-4528-89F1-B090ABBF11A7}) (Version: 1.0.35 - ASUSTeK Computer Inc.) Hidden ASUS MB Peripheral Products (HKLM-x32...{193a2068-8738-4276-ab1b-9133f9403487}) (Version: 1.0.35 - ASUSTeK Computer Inc.) Hidden ASUS Mouse HAL (HKLM...{B8F984F2-7887-4DD2-8D96-F9A4BC5A4AC5}) (Version: 1.1.0.45 - ASUSTek COMPUTER INC.) Hidden ASUS Mouse HAL (HKLM-x32...{559342ce-3e0f-4daf-bd9f-dfb67f065c28}) (Version: 1.1.0.45 - ASUSTek COMPUTER INC.) Hidden ASUS MultiAntenna Service (HKLM...{EBB02F2E-0856-4B8A-9E70-980102C90BBA}) (Version: 3.2.2 - ASUSTeK COMPUTER INC.) ASUS Smart Display Control (HKLM-x32...{8714A8D1-0F08-4681-9DF6-A8C4607A58B4}) (Version: 1.2.0 - ASUSTek COMPUTER INC.) ASUS Update Helper (HKLM-x32...{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.107.93 - ASUSTeK Computer Inc.) Hidden AURA lighting effect add-on (HKLM-x32...{1E2EA04B-FCA7-457E-B6F4-F33E1858E859}) (Version: 0.0.24 - ASUS) AURA lighting effect add-on x64 (HKLM...{C5A4A164-4428-4931-B728-96EEF0FA3C44}) (Version: 0.0.24 - ASUS) AURA Service (HKLM-x32...{0760271b-d7d2-407b-a2ec-f17c8ce203c7}) (Version: 3.05.78 - ASUSTeK Computer Inc.) AURA Service (HKLM-x32...{0E536061-3B55-4D45-BF58-0BDA261C94B0}) (Version: 3.05.78 - ASUSTeK Computer Inc.) Hidden FreeWriter (HKLM-x32...{6BB5F8AA-0329-400C-B4B9-82DBE033746F}) (Version: 1.0.7 - Lifestyle Toolbox) GameSDK Service (HKLM-x32...{021d69c3-d686-4a94-8fb5-fd1ee782fb14}) (Version: 1.0.5.0 - ASUSTek COMPUTER INC.) GameSDK Service (HKLM-x32...{7160DA8D-3F25-4F6E-ABC8-F693551D82FA}) (Version: 1.0.5.0 - ASUSTek COMPUTER INC.) Hidden LibreOffice 7.1.3.2 (HKLM...{76B2DBF3-5773-4463-9EEB-D4A099EB6265}) (Version: 7.1.3.2 - The Document Foundation) LilySpeech Version 3 (HKU\S-1-5-21-895565649-3931333595-811618271-1001...\LilySpeech) (Version: 3 - LilySpeech) Malwarebytes version 4.5.21.231 (HKLM...{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.21.231 - Malwarebytes) Microsoft .NET Host - 5.0.14 (x64) (HKLM...{61A6E3A7-F406-418A-B2A6-0606DB55B325}) (Version: 40.56.30907 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 5.0.14 (x64) (HKLM...{8D88F0E2-CE9B-4A6D-8309-FDC562195F5B}) (Version: 40.56.30907 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 5.0.14 (x64) (HKLM...{B810ACDF-1C0C-4108-9B92-12F1674FA444}) (Version: 40.56.30907 - Microsoft Corporation) Hidden Microsoft 365 - en-us (HKLM...\O365HomePremRetail - en-us) (Version: 16.0.15928.20216 - Microsoft Corporation) Microsoft Edge (HKLM-x32...\Microsoft Edge) (Version: 109.0.1518.70 - Microsoft Corporation) Microsoft Edge WebView2 Runtime (HKLM-x32...\Microsoft EdgeWebView) (Version: 109.0.1518.70 - Microsoft Corporation) Microsoft GameInput (HKLM-x32...{6BBE9278-659F-FA16-E4B8-C2D60DE0DCC7}) (Version: 10.1.22621.1863 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-895565649-3931333595-811618271-1001...\OneDriveSetup.exe) (Version: 23.002.0102.0004 - Microsoft Corporation) Microsoft Update Health Tools (HKLM...{89581302-705F-42C5-99B0-E368A845DAD5}) (Version: 3.70.0.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.26.28720 (HKLM-x32...{7d607fb4-7e28-4c7a-a92f-3fcdaf555faf}) (Version: 14.26.28720.3 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.26.28720 (HKLM-x32...{86380aef-fd23-4fc3-8723-a98ccad8f2c6}) (Version: 14.26.28720.3 - Microsoft Corporation) Microsoft Visual C++ 2019 X64 Additional Runtime - 14.26.28720 (HKLM...{CB4A0FDE-1126-4AE2-97C6-A243692C3D95}) (Version: 14.26.28720 - Microsoft Corporation) Hidden Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.26.28720 (HKLM...{DD1EC0FD-3F0A-4740-A05E-1DCD14A6B0D1}) (Version: 14.26.28720 - Microsoft Corporation) Hidden Microsoft Visual C++ 2019 X86 Additional Runtime - 14.26.28720 (HKLM-x32...{2F69FB2B-2C48-491C-B249-22C1BDCE1117}) (Version: 14.26.28720 - Microsoft Corporation) Hidden Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.26.28720 (HKLM-x32...{31C9EB3A-5F0C-49E7-8E6C-D404E48F433D}) (Version: 14.26.28720 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 5.0.14 (x64) (HKLM...{4CD6FFC6-FA14-4016-A7A6-B7E3D6286331}) (Version: 40.56.30911 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 5.0.14 (x64) (HKLM-x32...{d21a4f20-968a-4b0c-bf04-a38da5f06e41}) (Version: 5.0.14.30911 - Microsoft Corporation) Mozilla Firefox (x64 en-US) (HKLM...\Mozilla Firefox 109.0 (x64 en-US)) (Version: 109.0 - Mozilla) Mozilla Maintenance Service (HKLM...\MozillaMaintenanceService) (Version: 104.0.2 - Mozilla) NVIDIA FrameView SDK 1.1.4923.29548709 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.1.4923.29548709 - NVIDIA Corporation) NVIDIA GeForce Experience 3.21.0.36 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.21.0.36 - NVIDIA Corporation) NVIDIA Graphics Driver 462.06 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 462.06 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.38.40 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.40 - NVIDIA Corporation) NVIDIA PhysX System Software 9.20.0221 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.20.0221 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (HKLM...{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.15726.20202 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM...{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.15928.20198 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM...{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.13127.20616 - Microsoft Corporation) Hidden Rainlendar2 (remove only) (HKLM-x32...\Rainlendar2) (Version: - ) RefreshRateService (HKLM-x32...{7E5E84CB-B190-4658-A4DC-166779C329D1}) (Version: 2.1.0 - ASUSTeK COMPUTER INC.) ROG CustomHotkey (HKLM-x32...{374883e6-b31d-4a3c-9c4a-2685a840aed4}) (Version: 1.1.1 - ASUSTek Computer Inc.) ROG Live Service (HKLM-x32...{2D87BFB6-C184-4A59-9BBE-3E20CE797631}) (Version: 1.6.4.0 - ASUSTek COMPUTER INC.) Shotcut (HKLM...\Shotcut) (Version: 21.10.31 - Meltytech, LLC) Speedify (HKLM...\Speedify) (Version: 12.8.0.10689 - Connectify) Undercover - Blood Bonds (HKLM-x32...\Undercover - Blood BondsFinal) (Version: Final - Game Owl) Waterfox (x64 en-US) (HKLM...\Waterfox 102.5.0 (x64 en-US)) (Version: 102.5.0 - WaterfoxLimited) Windows PC Health Check (HKLM...{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation) WinRAR 6.02 (64-bit) (HKLM...\WinRAR archiver) (Version: 6.02.0 - win.rar GmbH) Zoom (HKU\S-1-5-21-895565649-3931333595-811618271-1001...\ZoomUMX) (Version: 5.13.4 (11835) - Zoom Video Communications, Inc.) [HEADING=1]Packages:[/HEADING] AMD Radeon Software → C:\Program Files\WindowsApps\advancedmicrodevicesinc-2.amdradeonsoftware_10.21.30024.0_x64__0a9344xs7nr4m [2022-09-12] (Advanced Micro Devices Inc.) [Startup Task] ARMOURY CRATE → C:\Program Files\WindowsApps\B9ECED6F.ArmouryCrate_5.4.8.0_x64__qmba6cd70vzyy [2023-02-01] (ASUSTeK COMPUTER INC.) AURA Creator → C:\Program Files\WindowsApps\B9ECED6F.AURACreator_3.5.6.0_x64__qmba6cd70vzyy [2023-02-01] (ASUSTeK COMPUTER INC.) Disney+ → C:\Program Files\WindowsApps\Disney.37853FC22B2CE_1.44.2.0_x64__6rarf9sa4v8jt [2022-12-20] (Disney) Dolby Access → C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.16.345.0_x64__rz1tebttyb220 [2023-01-23] (Dolby Laboratories) McAfee® Personal Security → C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.68.0_x64__wafk5atnkzcwy [2022-11-27] (McAfee LLC.) Microsoft Whiteboard → C:\Program Files\WindowsApps\Microsoft.Whiteboard_53.10114.505.0_x64__8wekyb3d8bbwe [2023-01-20] (Microsoft Corporation) MyASUS → C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.13.0_x64__qmba6cd70vzyy [2022-12-23] (ASUSTeK COMPUTER INC.) NVIDIA Control Panel → C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.963.0_x64__56jybvy8sckqj [2022-10-29] (NVIDIA Corp.) Realtek Audio Control → C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.37.275.0_x64__dt26b99r8h8gj [2022-11-14] (Realtek Semiconductor Corp) Solitaire & Casual Games → C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.15.12020.0_x64__8wekyb3d8bbwe [2022-12-08] (Microsoft Studios) [MS Ad] Spotify Music → C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.203.1115.0_x86__zpdnekdrzrea0 [2023-01-20] (Spotify AB) [Startup Task] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ContextMenuHandlers1: [WinRAR] → {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH → Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] → {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH → Alexander Roshal) ContextMenuHandlers3: [MBAMShlExt] → {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-09-15] (Malwarebytes Inc. → Malwarebytes) ContextMenuHandlers5: [ACE] → {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll [2022-10-03] (Advanced Micro Devices Inc. → Advanced Micro Devices, Inc.) ContextMenuHandlers5: [NvCplDesktopContext] → {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_a6c8d8415ff0e012\nvshext.dll [2022-06-24] (Nvidia Corporation → NVIDIA Corporation) ContextMenuHandlers6: [MBAMShlExt] → {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-09-15] (Malwarebytes Inc. → Malwarebytes) ContextMenuHandlers6: [WinRAR] → {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH → Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] → {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH → Alexander Roshal) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2022-09-12 20:48 - 2022-06-20 15:14 - 000520704 _____ () [File not signed] \?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ac_node_addon\prebuilds\win32-ia32\node.napi.node 2022-09-12 20:48 - 2022-06-08 10:33 - 000479744 _____ () [File not signed] \?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ffi-napi\prebuilds\win32-ia32\node.napi.node 2022-09-12 20:48 - 2022-06-08 10:33 - 000470016 _____ () [File not signed] \?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ref-napi\prebuilds\win32-ia32\node.napi.node 2022-09-12 20:48 - 2022-06-08 10:33 - 000832512 _____ () [File not signed] \?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\usb-detection\prebuilds\win32-ia32\node.napi.node 2022-09-12 20:48 - 2022-06-08 10:33 - 000081920 _____ () [File not signed] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\WindowID\WindowID.dll 2010-05-23 19:20 - 2010-05-23 19:20 - 000012288 _____ () [File not signed] C:\Program Files (x86)\Rainlendar2\lfs.dll 2010-05-23 19:20 - 2010-05-23 19:20 - 000126976 _____ () [File not signed] C:\Program Files (x86)\Rainlendar2\lua51.dll 2011-08-12 06:45 - 2011-08-12 06:45 - 000198144 _____ () [File not signed] C:\Program Files (x86)\Rainlendar2\plugins\iCalendarPlugin.dll 2020-11-21 13:17 - 2020-11-21 13:17 - 001165824 _____ () [File not signed] C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.68.0_x64__wafk5atnkzcwy\e_sqlite3.dll 2021-12-24 00:02 - 2021-12-24 00:03 - 016742912 _____ (McAfee LLC) [File not signed] C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.68.0_x64__wafk5atnkzcwy\mcafee-security.dll 2022-09-05 09:18 - 2022-09-05 09:18 - 000023552 _____ (MTK) [File not signed] C:\Program Files\ASUS\ASUS MultiAntenna Service\mtkwlan.dll 2021-08-08 17:02 - 2021-08-08 17:02 - 000023040 _____ (Synaptics Incorporated.) [File not signed] C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.37.275.0_x64__dt26b99r8h8gj\SynAudSrvDll.dll 2011-07-28 19:20 - 2011-07-28 19:20 - 000244736 _____ (The cURL library, hxxp://curl.haxx.se/) [File not signed] C:\Program Files (x86)\Rainlendar2\libcurl.dll 2011-01-29 12:59 - 2011-01-29 12:59 - 001102336 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Rainlendar2\LIBEAY32.dll 2011-01-29 12:59 - 2011-01-29 12:59 - 000237056 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Rainlendar2\SSLEAY32.dll 2010-12-12 11:56 - 2010-12-12 11:56 - 001205760 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Rainlendar2\wxbase28u_vc_rny.dll 2010-12-12 11:58 - 2010-12-12 11:58 - 000131584 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Rainlendar2\wxbase28u_xml_vc_rny.dll 2010-12-12 11:57 - 2010-12-12 11:57 - 000707584 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Rainlendar2\wxmsw28u_adv_vc_rny.dll 2010-12-12 11:57 - 2010-12-12 11:57 - 002633216 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Rainlendar2\wxmsw28u_core_vc_rny.dll 2010-12-12 11:57 - 2010-12-12 11:57 - 000485376 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Rainlendar2\wxmsw28u_html_vc_rny.dll 2010-12-12 11:58 - 2010-12-12 11:58 - 000502784 _____ (wxWidgets development team) [File not signed] C:\Program Files (x86)\Rainlendar2\wxmsw28u_xrc_vc_rny.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The “AlternateShell” will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => “”=“Service” HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => “”=“Service” HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => “”=“Service” HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => “”=“Service” HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => “”=“Service” ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== BHO-x32: Skype for Business Browser Helper → {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} → C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2022-11-18] (Microsoft Corporation → Microsoft Corporation) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-01-13] (Microsoft Corporation → Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-01-13] (Microsoft Corporation → Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-01-13] (Microsoft Corporation → Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-01-13] (Microsoft Corporation → Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-01-13] (Microsoft Corporation → Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-01-13] (Microsoft Corporation → Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-01-13] (Microsoft Corporation → Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-01-13] (Microsoft Corporation → Microsoft Corporation) ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-12-07 10:14 - 2019-12-07 10:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\DefaultUser\Control Panel\Desktop\Wallpaper → C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-21-895565649-3931333595-811618271-1001\Control Panel\Desktop\Wallpaper → C:\Users\acco5\Desktop\white_flowers_nature_plants-21425.jpg!d.jpg DNS Servers: 192.168.43.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM...\StartupApproved\Run: => “Speedify” HKU\S-1-5-21-895565649-3931333595-811618271-1001...\StartupApproved\Run: => “OneDrive” HKU\S-1-5-21-895565649-3931333595-811618271-1001...\StartupApproved\Run: => “LilySpeechRec” HKU\S-1-5-21-895565649-3931333595-811618271-1001...\StartupApproved\Run: => “LilySpeechUtilB” HKU\S-1-5-21-895565649-3931333595-811618271-1001...\StartupApproved\Run: => “LilySpeechUtilA” HKU\S-1-5-21-895565649-3931333595-811618271-1001...\StartupApproved\Run: => “LilySpeechComms” HKU\S-1-5-21-895565649-3931333595-811618271-1001...\StartupApproved\Run: => “MicrosoftEdgeAutoLaunch_96584F32951EA856FAD305C03C256217” ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{17E6E1DB-6811-46A9-9D95-6FF0F770842A}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe (ASUSTeK COMPUTER INC. → ) FirewallRules: [{A476B622-4E44-4FA0-8B1E-3984980C05AF}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe (ASUSTeK Computer Inc. → ASUS) FirewallRules: [{15E5C64C-D0C1-42AC-B54B-87414F296814}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe (ASUSTeK COMPUTER INC. → ASUSTek Computer Inc.) FirewallRules: [{0ABC14FF-2DD3-4306-B489-6815B4D35391}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmouryHtmlDebugServer.exe (ASUSTeK Computer Inc. → ASUS) FirewallRules: [{290CFDAB-452B-4756-8486-CE1697ADB12F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation → NVIDIA Corporation) FirewallRules: [{78223492-85A2-4C09-8B02-8F05A70674EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation → NVIDIA Corporation) FirewallRules: [{221E9954-E8A6-4AD5-B0E2-8305A673B1FE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation → NVIDIA Corporation) FirewallRules: [{2B07C2C0-3BEE-4BE4-A94E-44F581AD28A1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation → NVIDIA Corporation) FirewallRules: [{6D1214D2-3A49-4047-9F79-485FC62A24F9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation → NVIDIA Corporation) FirewallRules: [{ACCA6159-C91A-4E60-AD8B-C49343D5A97D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation → NVIDIA Corporation) FirewallRules: [{74AC523A-DA02-400B-8FFE-84EE96C86817}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe (ASUSTeK COMPUTER INC. → ASUSTek Computer Inc.) FirewallRules: [{86A5642A-2677-4672-B769-FEB907D76DB3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation → Mozilla Corporation) FirewallRules: [{F5432C84-7BAE-4701-8499-B081794565CF}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation → Mozilla Corporation) FirewallRules: [{F5906D05-2716-4053-A7B1-F8FF25C1B060}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation → Microsoft Corporation) FirewallRules: [{CCC6F4B6-A842-46C5-AC07-D18B60F5CA72}] => (Allow) C:\Program Files\Waterfox\waterfox.exe (WATERFOX LIMITED → Waterfox Limited) FirewallRules: [{69B16CF9-2BAB-4881-9E7A-A9A2A9795D47}] => (Allow) C:\Program Files\Waterfox\waterfox.exe (WATERFOX LIMITED → Waterfox Limited) FirewallRules: [{78D4E73B-8CC1-4316-A801-F9A6864A9F3D}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.13.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (ASUSTeK COMPUTER INC.) [File not signed] FirewallRules: [{6FE4EFEC-EF7E-4B8C-A4A6-A8A50FB4096F}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.13.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (ASUSTeK COMPUTER INC.) [File not signed] FirewallRules: [{32023D90-46C2-4406-9AF8-C1837360F049}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.13.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (ASUSTeK COMPUTER INC.) [File not signed] FirewallRules: [{51ABEC01-6DD7-4B6B-A11E-913C9BCD653D}] => (Allow) C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.13.0_x64__qmba6cd70vzyy\MyASUS\AsusMyASUS.exe (ASUSTeK COMPUTER INC.) [File not signed] FirewallRules: [TCP Query User{41BE3A4D-7FB7-4AF0-9846-7C64592E370E}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation → Mozilla Corporation) FirewallRules: [UDP Query User{6108C299-8287-4934-AA62-00727B615DA0}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation → Mozilla Corporation) FirewallRules: [{C06E6B6A-D7FE-4FBE-A3BF-9B391C865022}] => (Allow) C:\Users\acco5\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. → Zoom Video Communications, Inc.) FirewallRules: [{CD530114-8C3F-426A-BE06-942D00940991}] => (Allow) C:\Users\acco5\AppData\Roaming\Zoom\bin\airhost.exe => No File FirewallRules: [{9DDC40A0-6896-455A-946E-C3A40123ADB6}] => (Allow) C:\Users\acco5\AppData\Roaming\Zoom\bin\airhost.exe => No File FirewallRules: [{19D4D41B-BFE7-4646-8A46-1D96B2774A84}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.203.1115.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd) FirewallRules: [{BB093BA8-D1BD-4CED-A108-21162CD5663F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.203.1115.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd) FirewallRules: [{AD8C1482-6FE8-4316-84E0-A99C32B3A718}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.203.1115.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd) FirewallRules: [{81DA57A2-D96A-4B3A-B78E-29E64E9B7D01}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.203.1115.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd) FirewallRules: [{1790F7C7-DD37-458F-93B5-82882983E9BA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.203.1115.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd) FirewallRules: [{261E5A9D-408D-4316-8814-2492E52C7D8D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.203.1115.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd) FirewallRules: [{17064249-E5DC-4A5D-A9D4-3350EF84F61C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.203.1115.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd) FirewallRules: [{2E574DEF-F598-49C3-BCE4-1D156590BCCD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.203.1115.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd) FirewallRules: [{97101B25-F1AD-4053-BE3E-3D1856DDEB70}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl → Skype Technologies S.A.) FirewallRules: [{DD86AD83-562F-4F4D-864B-2B0F79F1D565}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl → Skype Technologies S.A.) FirewallRules: [{0890B265-E172-4B86-A9F6-1FDC30BA1E8E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl → Skype Technologies S.A.) FirewallRules: [{FA74B675-C119-4582-880E-3885FEDCCF75}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl → Skype Technologies S.A.) FirewallRules: [{742607C3-422A-405E-ADEA-8554FACF8239}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\109.0.1518.70\msedgewebview2.exe (Microsoft Corporation → Microsoft Corporation) FirewallRules: [{2BEA612F-9747-450E-875D-702E66E2F0D1}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSSwitch\AsusSwitchNetMDNS.exe (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) FirewallRules: [{F6894205-F7A6-478D-83CC-4E4323E1A89C}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSLinkRemote\AsusLinkRemoteAgent.exe (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) FirewallRules: [{A8E17B48-2DBB-4DBC-95E2-F3B9F9A644BF}] => (Allow) C:\WINDOWS\System32\DriverStore\FileRepository\asussci2.inf_amd64_0100494bef227dd5\ASUSLinkRemote\AsusLinkRemoteAgent.exe (ASUSTeK COMPUTER INC. → ASUSTeK COMPUTER INC.) FirewallRules: [{2C0D1780-3F7F-4845-B623-319CB6BAB8C4}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe (ASUSTeK COMPUTER INC. → ) FirewallRules: [{5B38CA7E-B37E-4E9E-9FB6-80819A278734}] => (Allow) C:\Program Files\ASUS\ARMOURY CRATE Service\MobilePlugin\AutoConnectHelper.exe (ASUSTeK COMPUTER INC. → ) FirewallRules: [{B7FAC268-8A06-4B4C-A84F-2EADFDF5BB4E}] => (Allow) C:\Users\acco5\Downloads\UltraAdwareKiller.exe => No File FirewallRules: [{DF049D3F-3BC7-4030-ACCA-377B05F74DC7}] => (Allow) C:\Users\acco5\Downloads\UltraAdwareKiller.exe => No File FirewallRules: [{B2F7F46A-24A7-4A97-9992-C0A57307950F}] => (Allow) C:\Users\acco5\Downloads\UltraAdwareKiller64.exe (DOS SANTOS DA SILVA ALFREDO → Carifred) FirewallRules: [{3C0125D9-35D0-4E24-90D0-A2330715A42A}] => (Allow) C:\Users\acco5\Downloads\UltraAdwareKiller64.exe (DOS SANTOS DA SILVA ALFREDO → Carifred) ==================== Restore Points ========================= 11-01-2023 12:51:08 Windows Modules Installer 21-01-2023 06:08:22 Scheduled Checkpoint 30-01-2023 08:17:03 Scheduled Checkpoint 31-01-2023 22:06:26 ASUS Aac_NBDT HAL 01-02-2023 04:43:10 Ultra Adware Killer threat removal ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== [HEADING=1]Application errors:[/HEADING] Error: (01/31/2023 11:52:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Microsoft.SharePoint.exe, version: 23.2.102.4, time stamp: 0x9ff405d5 Faulting module name: ucrtbase.dll, version: 10.0.19041.789, time stamp: 0x2bd748bf Exception code: 0xc0000409 Fault offset: 0x000000000007286e Faulting process ID: 0x324c Faulting application start time: 0x01d935c6a582ba85 Faulting application path: C:\Users\acco5\AppData\Local\Microsoft\OneDrive\23.002.0102.0004\Microsoft.SharePoint.exe Faulting module path: C:\WINDOWS\System32\ucrtbase.dll Report ID: fb523a32-eb7a-4b82-9046-fd14f5b883c0 Faulting package full name: Faulting package-relative application ID: Error: (01/31/2023 01:45:52 PM) (Source: Waterfox Default Browser Agent) (EventID: 2) (User: ) Description: Event-ID 2 Error: (01/31/2023 01:45:52 PM) (Source: Waterfox Default Browser Agent) (EventID: 0) (User: ) Description: Event-ID 0 Error: (01/30/2023 11:31:03 PM) (Source: usbperf) (EventID: 2001) (User: ) Description: Unable to read the “First Counter” value under the usbperf\Performance Key. Status codes returned in data. Error: (01/30/2023 11:11:02 PM) (Source: usbperf) (EventID: 2001) (User: ) Description: Unable to read the “First Counter” value under the usbperf\Performance Key. Status codes returned in data. Error: (01/30/2023 10:51:02 PM) (Source: usbperf) (EventID: 2001) (User: ) Description: Unable to read the “First Counter” value under the usbperf\Performance Key. Status codes returned in data. Error: (01/30/2023 10:31:02 PM) (Source: usbperf) (EventID: 2001) (User: ) Description: Unable to read the “First Counter” value under the usbperf\Performance Key. Status codes returned in data. Error: (01/30/2023 10:11:02 PM) (Source: usbperf) (EventID: 2001) (User: ) Description: Unable to read the “First Counter” value under the usbperf\Performance Key. Status codes returned in data. [HEADING=1]System errors:[/HEADING] Error: (12/25/2022 01:45:46 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-6ODOHNQP) Description: The server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} did not register with DCOM within the required timeout. Error: (12/25/2022 01:45:46 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-6ODOHNQP) Description: The server Microsoft.AAD.BrokerPlugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy!Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider did not register with DCOM within the required timeout. Error: (12/18/2022 09:17:48 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone. Error: (12/17/2022 07:33:03 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-6ODOHNQP) Description: The server Microsoft.Windows.ContentDeliveryManager_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy!App.AppXwdz8g2fxr36xz0tdtagygnvemf85s7gg.mca did not register with DCOM within the required timeout. Error: (11/27/2022 02:05:48 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {354FF91B-5E49-4BDC-A8E6-1CB6C6877182} did not register with DCOM within the required timeout. Error: (11/27/2022 02:05:45 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {354FF91B-5E49-4BDC-A8E6-1CB6C6877182} did not register with DCOM within the required timeout. Error: (11/27/2022 02:05:44 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-6ODOHNQP) Description: The server {A463FCB9-6B1C-4E0D-A80B-A2CA7999E25D} did not register with DCOM within the required timeout. Error: (11/27/2022 02:05:44 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-6ODOHNQP) Description: The server {A463FCB9-6B1C-4E0D-A80B-A2CA7999E25D} did not register with DCOM within the required timeout. [HEADING=1]Windows Defender:[/HEADING] Date: 2023-01-31 18:17:46 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2023-01-30 08:15:57 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2023-01-29 18:02:14 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2023-01-27 12:31:00 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2023-01-26 07:52:34 Description: Microsoft Defender Antivirus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Quick Scan [HEADING=1]CodeIntegrity:[/HEADING] Date: 2023-02-01 02:49:01 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Mozilla Firefox\firefox.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. Date: 2023-01-31 18:17:28 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2022-12-17 07:34:37 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Mozilla Firefox\firefox.exe) attempted to load \Device\HarddiskVolume3\Program Files\Mozilla Firefox\mozavcodec.dll that did not meet the Microsoft signing level requirements. Date: 2022-12-17 07:34:37 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Mozilla Firefox\firefox.exe) attempted to load \Device\HarddiskVolume3\Program Files\Mozilla Firefox\mozavutil.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== BIOS: American Megatrends International, LLC. G513IC.314 03/30/2022 Motherboard: ASUSTeK COMPUTER INC. G513IC Processor: AMD Ryzen 7 4800H with Radeon Graphics Percentage of memory in use: 90% Total physical RAM: 15792.36 MB Available physical RAM: 1543.6 MB Total Virtual: 31584.73 MB Available Virtual: 7308.22 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:453.5 GB) (Free:30.76 GB) (Model: HFM512GD3JX013N) (Protected) NTFS \?\Volume{66a3209f-eb4a-4404-8e69-a0688f1f2f8d}\ (RECOVERY) (Fixed) (Total:0.98 GB) (Free:0.09 GB) NTFS \?\Volume{f51f1b4c-8df5-41a8-8f65-bdf58564b60b}\ (RESTORE) (Fixed) (Total:22 GB) (Free:4.52 GB) NTFS \?\Volume{c59d0604-e288-4986-a06e-e17a96ca7a64}\ (MYASUS) (Fixed) (Total:0.19 GB) (Free:0.13 GB) FAT32 \?\Volume{1b46213c-b1f2-4ef0-bf62-3e223d1cbb73}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 476.9 GB) (Disk ID: C0F51CB1) Partition: GPT. ==================== End of Addition.txt =======================
Comment