Rat infection

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • puki
    PCHF Member
    • Sep 2022
    • 29

    #16
    Someone is controlling my pc :
    -closing apps
    -hide tray icons
    -change my passwords
    -delete files
    -my internet is so slow at moments (i never shared my Wifi password with anyone)

    Also i have already tried to reset the router to default settings. (i’m sure i don’t have malware in the router).
    I also tryed to flash my BIOS (without success of course).
    And have have checked my HDD firmware for viruses(none there).
    I even paid for virus removal and when back at home the virus just wasn’t removed.
    I have read a lot about those viruses,but don’t know how it’s remain.
    What information maybe useful for you?
    I will post fresh FRST log in the next post.

    Comment

    • puki
      PCHF Member
      • Sep 2022
      • 29

      #17
      Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-08-2022 (ATTENTION: ====> FRST version is 34 days old and could be outdated)
      Ran by TeaTang (administrator) on DESKTOP-GRKBJ8K (Gigabyte Technology Co., Ltd. GA-MA770T-UD3) (03-10-2022 14:54:41)
      Running from C:\Users\TeaTang\Desktop
      Loaded Profiles: TeaTang
      Platform: Microsoft Windows 10 Pro Version 1803 17134.165 (X64) Language: English (United States)
      Default browser: Edge
      Boot Mode: Normal

      ==================== Processes (Whitelisted) =================

      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

      (explorer.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
      (Mozilla Corporation) [File not signed] C:\Program Files\LibreWolf\librewolf.exe <12>
      (services.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
      (services.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
      (services.exe ->) (NVIDIA Corporation → NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe <2>
      (svchost.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wek yb3d8bbwe\MicrosoftEdge.exe
      (svchost.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wek yb3d8bbwe\MicrosoftEdgeCP.exe <2>
      (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Program Files\rempl\sedlauncher.exe
      (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\browser_broker.exe
      (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
      (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\smartscreen.exe
      (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.PeopleExpe rienceHost_cw5n1h2txyewy\PeopleExperienceHost.exe

      ==================== Registry (Whitelisted) ===================

      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

      HKLM...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Windows → Microsoft Corporation)
      HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4230544 2022-07-26] (Valve Corp. → Valve Corporation)
      HKLM...\Print\Monitors\IppMon: C:\Windows\system32\IPPMon.dll [251392 2018-04-12] (Microsoft Windows → Microsoft Corporation)

      ==================== Scheduled Tasks (Whitelisted) ============

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - \Microsoft\Windows\HelloFace\FODCleanupTask → No File <==== ATTENTION
      Task: {908F9503-D38F-4136-A58B-23CF5653F9EC} - \Microsoft\Windows\RemoteAssistance\RemoteAssistan ceTask → No File <==== ATTENTION

      (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

      Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask .job => C:\Windows\explorer.exe

      ==================== Internet (Whitelisted) ====================

      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

      Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
      Tcpip..\Interfaces{2631d501-1595-41ba-a828-60c54973e613}: [DhcpNameServer] 192.168.1.1
      [HEADING=1]FireFox:[/HEADING]
      FF DefaultProfile: 6lexpgnm.default
      FF ProfilePath: C:\Users\TeaTang\AppData\Roaming\librewolf\Profile s\6lexpgnm.default [2022-08-08]
      FF ProfilePath: C:\Users\TeaTang\AppData\Roaming\librewolf\Profile s\zgx2jz41.default-default [2022-10-03]
      FF Notifications: librewolf\Profiles\zgx2jz41.default-default → hxxps://bazar.bg; hxxps://pchelpforum.net
      FF Extension: (DuckDuckGo Privacy Essentials) - C:\Users\TeaTang\AppData\Roaming\librewolf\Profile s\zgx2jz41.default-default\Extensionsjid1-ZAdIEUB7XOzOJw@jetpack.xpi [2022-08-25]
      FF Extension: (uBlock Origin) - C:\Users\TeaTang\AppData\Roaming\librewolf\Profile s\zgx2jz41.default-default\ExtensionsuBlock0@raymondhill.net.xpi [2022-09-21]
      FF Plugin-x32: @nvidia.com/3DVision → C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation PE Sign v2016 → NVIDIA Corporation) [File not signed]
      FF Plugin-x32: @nvidia.com/3DVisionStreaming → C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation PE Sign v2016 → NVIDIA Corporation) [File not signed]
      [HEADING=1]Chrome:[/HEADING]
      CHR HKLM-x32...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
      CHR HKLM-x32...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
      CHR HKLM-x32...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]

      ==================== Services (Whitelisted) ===================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8680192 2022-08-08] (Malwarebytes Inc. → Malwarebytes)
      S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Windows Publisher → Microsoft Corporation)
      S3 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [748664 2022-07-19] (Oracle Corporation → Oracle Corporation)
      R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4451616 2018-04-12] (Microsoft Corporation → Microsoft Corporation)
      R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105344 2018-04-12] (Microsoft Corporation → Microsoft Corporation)

      ===================== Drivers (Whitelisted) ===================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      S3 BALLOON; C:\Windows\System32\drivers\balloon.sys [47176 2017-07-20] (Red Hat, Inc. → Red Hat, Inc.)
      R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [42616 2017-05-14] (Microsoft Windows Hardware Compatibility Publisher → Elaborate Bytes AG)
      S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [21480 2022-08-08] (Microsoft Windows Early Launch Anti-malware Publisher → Malwarebytes)
      S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239544 2022-08-09] (Microsoft Windows Hardware Compatibility Publisher → Malwarebytes)
      R3 MpKslb35b7e59; C:\ProgramData\Microsoft\Windows Defender\Definition Updates{EA699008-FFDF-44EA-A645-1BA87D13D780}\MpKslDrv.sys [50424 2022-10-03] (Microsoft Windows → Microsoft Corporation)
      R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [8287464 2019-02-26] (Realtek Semiconductor Corp. → Realtek Semiconductor Corporation)
      R3 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [242656 2022-07-19] (Oracle Corporation → Oracle Corporation)
      R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [252560 2022-07-19] (Oracle Corporation → Oracle Corporation)
      R1 VBoxSup; C:\Windows\system32\DRIVERS\VBoxSup.sys [1081592 2022-07-19] (Oracle Corporation → Oracle Corporation)
      S3 VClone; C:\Windows\System32\drivers\VClone.sys [44544 2020-02-22] (Microsoft Windows Hardware Compatibility Publisher → Elaborate Bytes AG)
      S0 viostor; C:\Windows\System32\drivers\viostor.sys [40008 2017-07-20] (Red Hat, Inc. → Red Hat, Inc.)
      S3 VirtRng; C:\Windows\System32\drivers\viorng.sys [43080 2017-07-20] (Red Hat, Inc. → Red Hat, Inc.)
      S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44616 2018-04-12] (Microsoft Windows Early Launch Anti-malware Publisher → Microsoft Corporation)
      R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [331680 2018-04-12] (Microsoft Windows → Microsoft Corporation)
      R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [44032 2018-04-12] (Microsoft Windows → Microsoft Corporation)
      S3 trufos; system32\drivers\trufos.sys

      ==================== NetSvcs (Whitelisted) ===================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      ==================== One month (created) (Whitelisted) =========

      (If an entry is included in the fixlist, the file/folder will be moved.)

      2022-10-03 10:21 - 2022-10-03 10:37 - 000000000 ___RD C:\Users\TeaTang\Downloads\325289AEDD75.TorrentRTF REE_qtx9tqphctw9r!App
      2022-10-02 21:58 - 2022-10-02 21:58 - 000000000 ____D C:\Users\TeaTang\Desktop\LOG
      2022-10-02 21:57 - 2022-10-02 21:58 - 000000000 ____D C:\Users\TeaTang\Desktop\ClearLNK
      2022-10-02 21:57 - 2022-10-02 21:57 - 000481552 _____ C:\Users\TeaTang\Desktop\ClearLNK.zip
      2022-10-02 21:43 - 2022-10-02 21:43 - 000010758 _____ C:\Users\TeaTang\Desktop\ZHPCleaner (R).html
      2022-10-02 21:43 - 2022-10-02 21:43 - 000003639 _____ C:\Users\TeaTang\Desktop\ZHPCleaner (R).txt
      2022-10-02 21:38 - 2022-10-02 21:54 - 000003675 _____ C:\Users\TeaTang\Desktop\ZHPCleaner (S).txt
      2022-10-02 21:38 - 2022-10-02 21:38 - 000010779 _____ C:\Users\TeaTang\Desktop\ZHPCleaner (S).html
      2022-10-02 21:30 - 2022-10-02 21:43 - 000000000 ____D C:\Users\TeaTang\AppData\Roaming\ZHP
      2022-10-02 21:30 - 2022-10-02 21:30 - 000000877 _____ C:\Users\TeaTang\Desktop\ZHPCleaner.lnk
      2022-10-02 21:30 - 2022-10-02 21:30 - 000000000 ____D C:\Users\TeaTang\AppData\Local\ZHP
      2022-10-02 21:26 - 2022-10-02 21:26 - 000000008 __RSH C:\ProgramData\ntuser.pol
      2022-10-02 21:24 - 2022-10-02 21:46 - 000200524 _____ C:\Users\TeaTang\Desktop\Fixlog.txt
      2022-10-02 21:23 - 2022-10-02 21:23 - 003303624 _____ (Nicolas Coolman) C:\Users\TeaTang\Desktop\ZHPCleaner.exe
      2022-10-01 16:18 - 2022-10-01 16:15 - 000035647 _____ C:\Users\TeaTang\Desktop\CollectionLog-2022.10.01-16.15.zip
      2022-10-01 16:11 - 2022-10-01 16:12 - 000000000 ____D C:\Users\TeaTang\Desktop\AutoLogger
      2022-10-01 16:11 - 2022-10-01 16:11 - 016270606 _____ C:\Users\TeaTang\Desktop\AutoLogger.zip
      2022-10-01 16:06 - 2022-10-01 16:06 - 000000000 ____D C:\Users\TeaTang\Desktop\AVbr
      2022-10-01 15:57 - 2022-10-01 15:58 - 009190923 _____ C:\Users\TeaTang\Desktop\AVbr.zip
      2022-10-01 15:51 - 2022-10-01 15:51 - 012360488 _____ (McAfee, LLC) C:\Users\TeaTang\Desktop\MCPR.exe
      2022-10-01 15:51 - 2022-10-01 15:51 - 000000000 ____D C:\Windows\system32\Tasks\Avira
      2022-10-01 15:49 - 2022-10-01 15:49 - 002789978 _____ C:\Users\TeaTang\Desktop\geek.zip
      2022-10-01 15:49 - 2022-10-01 15:49 - 000000000 ____D C:\Users\TeaTang\Desktop\geek
      2022-10-01 15:49 - 2022-10-01 15:49 - 000000000 ____D C:\Users\TeaTang\AppData\Roaming\Geek Uninstaller
      2022-10-01 11:25 - 2022-10-01 11:58 - 1946138624 _____ C:\Users\TeaTang\Desktop\avira-rescue-system.iso
      2022-09-30 19:35 - 2022-09-30 19:39 - 000024390 _____ C:\Users\TeaTang\Desktop\Addition.txt
      2022-09-30 19:31 - 2022-10-03 14:55 - 000008421 _____ C:\Users\TeaTang\Desktop\FRST.txt
      2022-09-30 19:30 - 2022-10-03 14:55 - 000000000 ____D C:\FRST
      2022-09-30 19:28 - 2022-09-30 19:28 - 002371072 _____ (Farbar) C:\Users\TeaTang\Desktop\FRST64.exe
      2022-09-30 18:24 - 2022-09-30 18:25 - 000000015 _____ C:\Users\TeaTang\Desktop\path of exile.txt
      2022-09-30 16:41 - 2022-09-30 16:41 - 000000000 ____D C:\Users\Public\Security Sessions
      2022-09-30 16:36 - 2022-10-01 15:50 - 000544032 _____ C:\Windows\system32\rtp.db
      2022-09-30 16:36 - 2022-09-30 16:36 - 000000000 ____D C:\Windows\SysWOW64\statReporter
      2022-09-30 16:35 - 2022-10-01 15:54 - 000000000 ____D C:\Users\TeaTang\AppData\Local\Avira
      2022-09-30 16:31 - 2022-10-01 15:53 - 000000000 ____D C:\ProgramData\Avira
      2022-09-30 16:31 - 2022-09-30 16:31 - 000003612 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskM achineUA{8741D5E3-698C-47D5-9C40-62B1F84D6852}
      2022-09-30 16:31 - 2022-09-30 16:31 - 000003488 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskM achineCore{81B2E53F-38D0-4F41-9FA3-936A1C5AC20F}
      2022-09-30 13:35 - 2022-09-30 13:35 - 000000015 _____ C:\Users\TeaTang\Desktop\spybot forums.txt
      2022-09-23 03:15 - 2022-09-30 17:16 - 000000000 ____D C:\Users\TeaTang\AppData\Roaming\vlc
      2022-09-23 03:15 - 2022-09-23 03:15 - 000000916 _____ C:\Users\Public\Desktop\VLC media player.lnk
      2022-09-23 03:15 - 2022-09-23 03:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
      2022-09-23 03:14 - 2022-09-23 03:14 - 000000000 ____D C:\Program Files\VideoLAN
      2022-09-23 03:11 - 2022-09-23 03:12 - 043524776 _____ C:\Users\TeaTang\Downloads\vlc-3.0.17.4-win64.exe
      2022-09-23 02:11 - 2022-09-23 02:11 - 000000112 _____ C:\ProgramData\Microsoft.SqlServer.Compact.400.32. bc
      2022-09-23 02:08 - 2022-09-23 02:08 - 000000118 ___RH C:\Users\TeaTang\Downloads\Stinger.opt
      2022-09-23 02:05 - 2022-09-23 02:05 - 000000000 ___HD C:$WINDOWS.~BT
      2022-09-23 02:03 - 2022-09-27 09:47 - 000000054 _____ C:\Windows\Lic.***
      2022-09-23 02:02 - 2022-09-23 02:02 - 000632064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr80.dll
      2022-09-23 02:02 - 2022-09-23 02:02 - 000554240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp80.dll
      2022-09-23 02:01 - 2022-09-23 02:01 - 000000000 ___HD C:$WinREAgent
      2022-09-22 13:42 - 2022-09-23 03:05 - 000000000 ____D C:\Program Files\FreeFixer
      2022-09-22 13:42 - 2022-09-22 13:46 - 000000000 ____D C:\Users\TeaTang\AppData\Roaming\FreeFixer
      2022-09-22 13:42 - 2022-09-22 13:46 - 000000000 ____D C:\Users\TeaTang\AppData\Local\FreeFixer
      2022-09-15 19:34 - 2022-09-15 19:34 - 000000000 ____D C:\Users\TeaTang\Desktop\FuguIta-7.1-amd64-202209131.iso
      2022-09-15 19:06 - 2022-09-15 19:31 - 346159575 _____ C:\Users\TeaTang\Desktop\FuguIta-7.1-amd64-202209131.iso.gz
      2022-09-15 18:56 - 2022-09-15 18:56 - 001575742 _____ (Igor Pavlov) C:\Users\TeaTang\Downloads\7z2201-x64.exe
      2022-09-15 18:56 - 2022-09-15 18:56 - 000000000 ____D C:\Users\TeaTang\Desktop\FuguIta-7.1-amd64-202209131.img
      2022-09-15 18:56 - 2022-09-15 18:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
      2022-09-15 18:56 - 2022-09-15 18:56 - 000000000 ____D C:\Program Files\7-Zip
      2022-09-15 02:46 - 2022-09-15 18:55 - 353521575 _____ C:\Users\TeaTang\Desktop\FuguIta-7.1-amd64-202209131.img.gz
      2022-09-14 20:53 - 2022-09-15 18:57 - 000000000 ____D C:\Users\TeaTang\VirtualBox VMs
      2022-09-14 20:52 - 2022-09-16 02:19 - 000000000 ____D C:\Users\TeaTang.VirtualBox
      2022-09-14 20:52 - 2022-09-16 01:50 - 000000000 ____D C:\ProgramData\VirtualBox
      2022-09-14 20:51 - 2022-09-14 20:51 - 000001149 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
      2022-09-14 20:51 - 2022-09-14 20:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
      2022-09-14 20:51 - 2022-07-19 15:50 - 001081592 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxSup.sys
      2022-09-14 20:51 - 2022-07-19 15:50 - 000191184 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
      2022-09-14 20:50 - 2022-09-14 21:00 - 592398336 _____ C:\Users\TeaTang\Desktop\install12.iso
      2022-09-14 20:50 - 2022-09-14 20:50 - 000000000 ____D C:\Program Files\Oracle
      2022-09-14 20:48 - 2022-09-14 20:49 - 111496224 _____ (Oracle Corporation) C:\Users\TeaTang\Downloads\VirtualBox-6.1.36-152435-Win.exe
      2022-09-14 20:19 - 2022-09-14 20:19 - 000000335 _____ C:\Users\TeaTang\Desktop\computer.lnk
      2022-09-14 19:12 - 2022-09-14 19:12 - 000000050 _____ C:\Users\TeaTang\Desktop\discord.txt
      2022-09-14 19:09 - 2022-09-15 18:51 - 000000000 ____D C:\Users\TeaTang\AppData\Roaming\discord
      2022-09-14 19:09 - 2022-09-14 19:09 - 000002241 _____ C:\Users\TeaTang\Desktop\Discord.lnk
      2022-09-14 19:08 - 2022-09-15 18:50 - 000000000 ____D C:\Users\TeaTang\AppData\Local\Discord
      2022-09-14 19:08 - 2022-09-14 19:09 - 000000000 ____D C:\Users\TeaTang\AppData\Local\SquirrelTemp
      2022-09-10 22:48 - 2022-09-10 22:50 - 000000038 _____ C:\Users\TeaTang\Desktop\microsoft account.txt

      ==================== One month (modified) ==================

      (If an entry is included in the fixlist, the file/folder will be moved.)

      2022-10-03 14:53 - 2022-08-08 18:08 - 000000000 ____D C:\Windows\system32\SleepStudy
      2022-10-03 14:53 - 2018-04-12 02:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
      2022-10-03 11:09 - 2022-08-08 18:53 - 000000000 ____D C:\ProgramData\NVIDIA
      2022-10-03 10:26 - 2018-04-12 02:38 - 000000000 ____D C:\Windows\AppReadiness
      2022-10-03 10:20 - 2022-08-08 18:39 - 000000000 ____D C:\Users\TeaTang\AppData\Local\PlaceholderTileLogo Folder
      2022-10-03 10:20 - 2022-08-08 18:30 - 000000000 ____D C:\Users\TeaTang\AppData\Local\Packages
      2022-10-03 10:17 - 2018-04-12 02:38 - 000000000 ___HD C:\Program Files\WindowsApps
      2022-10-03 10:12 - 2022-08-08 18:44 - 000000000 ____D C:\Users\TeaTang\AppData\LocalLow\Mozilla
      2022-10-02 22:04 - 2022-08-08 18:11 - 000000006 ____H C:\Windows\Tasks\SA.DAT
      2022-10-02 22:03 - 2018-04-12 00:04 - 000524288 _____ C:\Windows\system32\config\BBI
      2022-10-02 21:57 - 2020-07-25 14:06 - 001029112 _____ (Alex Dragokas) C:\Users\TeaTang\Desktop\ClearLNK.exe
      2022-10-02 21:29 - 2018-04-12 02:30 - 000000000 ____D C:\Windows\CbsTemp
      2022-10-02 21:24 - 2022-08-26 16:19 - 000000000 ____D C:\Windows\system32\Tasks\KpRm-quarantines
      2022-10-02 21:24 - 2018-04-12 02:38 - 000000000 ___HD C:\Windows\system32\GroupPolicy
      2022-10-01 15:50 - 2018-04-12 02:38 - 000000000 ___HD C:\Windows\ELAMBKUP
      2022-10-01 12:42 - 2022-08-11 13:48 - 000000000 ____D C:\Program Files (x86)\Steam
      2022-10-01 12:15 - 2022-08-08 18:29 - 000000000 ____D C:\Users\TeaTang
      2022-10-01 12:15 - 2022-08-08 18:08 - 000233880 _____ C:\Windows\system32\FNTCACHE.DAT
      2022-09-30 17:55 - 2018-04-12 02:38 - 000000000 ____D C:\Windows\LiveKernelReports
      2022-09-30 17:12 - 2022-08-12 21:52 - 000000000 ____D C:\Program Files (x86)\Mplayer
      2022-09-30 16:55 - 2022-08-08 19:13 - 000000000 ____D C:\ProgramData\TEMP
      2022-09-30 16:31 - 2018-04-12 00:04 - 000032768 _____ C:\Windows\system32\config\ELAM
      2022-09-30 13:47 - 2022-08-09 19:18 - 000000000 ____D C:\Users\TeaTang\AppData\Local\CrashDumps
      2022-09-27 18:55 - 2022-08-10 10:45 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3407470762-2713599730-1590247004-1001
      2022-09-27 18:55 - 2022-08-10 10:45 - 000003384 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3407470762-2713599730-1590247004-1001
      2022-09-27 18:55 - 2022-08-08 18:29 - 000002389 _____ C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\OneDrive.lnk
      2022-09-27 09:46 - 2018-04-12 02:38 - 000000545 _____ C:\Windows\win.ini
      2022-09-23 02:06 - 2022-08-09 05:08 - 000000000 ____D C:\Windows\Panther
      2022-09-14 20:52 - 2018-04-12 02:36 - 000000000 ____D C:\Windows\INF
      2022-09-06 20:00 - 2022-08-10 12:59 - 000000000 ____D C:\Users\TeaTang\AppData\Roaming\CC
      2022-09-06 19:57 - 2022-08-10 12:19 - 000000000 ____D C:\Program Files (x86)\Cyber Hunter

      ==================== SigCheck ============================

      (There is no automatic fix for files that do not pass verification.)

      ==================== End of FRST.txt ========================
      [HEADING=1]Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-08-2022
      Ran by TeaTang (03-10-2022 14:56:23)
      Running from C:\Users\TeaTang\Desktop
      Microsoft Windows 10 Pro Version 1803 17134.165 (X64) (2022-08-08 15:25:29)
      Boot Mode: Normal[/HEADING]
      ==================== Accounts: =============================

      (If an entry is included in the fixlist, it will be removed.)

      Administrator (S-1-5-21-3407470762-2713599730-1590247004-500 - Administrator - Disabled)
      DefaultAccount (S-1-5-21-3407470762-2713599730-1590247004-503 - Limited - Disabled)
      Guest (S-1-5-21-3407470762-2713599730-1590247004-501 - Limited - Disabled)
      TeaTang (S-1-5-21-3407470762-2713599730-1590247004-1001 - Administrator - Enabled) => C:\Users\TeaTang
      WDAGUtilityAccount (S-1-5-21-3407470762-2713599730-1590247004-504 - Limited - Disabled)

      ==================== Security Center ========================

      (If an entry is included in the fixlist, it will be removed.)

      AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

      ==================== Installed Programs ======================

      (Only the adware programs with “Hidden” flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

      7-Zip 22.01 (x64) (HKLM...\7-Zip) (Version: 22.01 - Igor Pavlov)
      AnyBurn (HKLM-x32...\AnyBurn) (Version: 5.4 - Power Software Ltd)
      LibreWolf (HKLM-x32...\LibreWolf LibreWolf) (Version: 102.0.1-1 - LibreWolf)
      Malwarebytes version 4.5.12.204 (HKLM...{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.12.204 - Malwarebytes)
      Microsoft Edge WebView2 Runtime (HKLM-x32...\Microsoft EdgeWebView) (Version: 105.0.1343.53 - Microsoft Corporation)
      Microsoft OneDrive (HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\OneDriveSetup.exe) (Version: 22.186.0904.0001 - Microsoft Corporation)
      Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32...{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
      Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.32.31332 (HKLM-x32...{3746f21b-c990-4045-bb33-1cf98cff7a68}) (Version: 14.32.31332.0 - Microsoft Corporation)
      Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332 (HKLM...{F4499EE3-A166-496C-81BB-51D1BCDC70A9}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
      Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332 (HKLM...{3407B900-37F5-4CC2-B612-5CD5D580A163}) (Version: 14.32.31332 - Microsoft Corporation) Hidden
      NVIDIA 3D Vision Driver 388.13 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 388.13 - NVIDIA Corporation)
      NVIDIA Graphics Driver 388.13 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.13 - NVIDIA Corporation)
      NVIDIA HD Audio Driver 1.3.35.1 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.35.1 - NVIDIA Corporation)
      NVIDIA Stereoscopic 3D Driver (HKLM-x32...\NVIDIAStereo) (Version: 7.17.13.7500 - NVIDIA Corporation) Hidden
      Oracle VM VirtualBox 6.1.36 (HKLM...{8B78A2AB-34B5-4546-8CCF-B78C916BBD98}) (Version: 6.1.36 - Oracle Corporation)
      Steam (HKLM-x32...\Steam) (Version: 2.10.91.91 - Valve Corporation)
      TP-Link TL-WN722N Driver (HKLM-x32...{F9C15685-38A9-46A1-9826-97204015C19C}) (Version: 2.1.0 - TP-Link)
      Update for Windows 10 for x64-based Systems (KB4023057) (HKLM...{8F2D6CEB-BC98-4B69-A5C1-78BED238FE77}) (Version: 2.71.0.0 - Microsoft Corporation) Hidden
      Update for Windows 10 for x64-based Systems (KB4480730) (HKLM...{0746492E-47B6-4251-940C-44462DFD74BB}) (Version: 2.55.0.0 - Microsoft Corporation)
      VLC media player (HKLM...\VLC media player) (Version: 3.0.17.4 - VideoLAN)
      Vulkan Run Time Libraries 1.0.61.0 (HKLM...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
      [HEADING=1]Packages:[/HEADING]
      Adobe Photoshop Express → C:\Program Files\WindowsApps\AdobeSystemsIncorporated.AdobePh otoshopExpress_3.7.403.0_x64__ynb6jyjzte8ga [2022-10-02] (Adobe Inc.)
      Microsoft Advertising SDK for XAML → C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.18 11.1.0_x64__8wekyb3d8bbwe [2022-09-10] (Microsoft Corporation) [MS Ad]
      Microsoft Advertising SDK for XAML → C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.18 11.1.0_x86__8wekyb3d8bbwe [2022-09-10] (Microsoft Corporation) [MS Ad]
      Microsoft Solitaire Collection → C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireColl ection_4.0.1301.0_x86__8wekyb3d8bbwe [2022-08-08] (Microsoft Studios) [MS Ad]
      Torrent RT FREE → C:\Program Files\WindowsApps\325289AEDD75.TorrentRTFREE_1.1.1 1.0_x64__qtx9tqphctw9r [2022-10-03] (Vlasenko Bros.) [MS Ad]

      ==================== Custom CLSID (Whitelisted): ==============

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      ContextMenuHandlers1: [7-Zip] → {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2022-07-15] (Igor Pavlov) [File not signed]
      ContextMenuHandlers3: [MBAMShlExt] → {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-08-08] (Malwarebytes Inc. → Malwarebytes)
      ContextMenuHandlers4: [7-Zip] → {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2022-07-15] (Igor Pavlov) [File not signed]
      ContextMenuHandlers5: [NvCplDesktopContext] → {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2017-10-27] (NVIDIA Corporation → NVIDIA Corporation)
      ContextMenuHandlers6: [7-Zip] → {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2022-07-15] (Igor Pavlov) [File not signed]
      ContextMenuHandlers6: [MBAMShlExt] → {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-08-08] (Malwarebytes Inc. → Malwarebytes)

      ==================== Codecs (Whitelisted) ====================

      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

      HKLM...\Drivers32-x32: [vidc.XVID] => xvidvfw.dll
      HKLM...\Drivers32-x32: [VIDC.VP80] => vp8vfw.dll

      ==================== Shortcuts & WMI ========================

      ==================== Loaded Modules (Whitelisted) =============

      2010-01-01 02:00 - 2010-01-01 02:00 - 000030208 _____ () [File not signed] C:\Program Files\LibreWolf\libEGL.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 004983808 _____ () [File not signed] C:\Program Files\LibreWolf\libGLESv2.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 000751104 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\freebl3.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 000199168 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\ipcclientcerts.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 000035328 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\lgpllibs.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 002123776 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\mozavcodec.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 000202752 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\mozavutil.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 000657920 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\mozglue.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 002446848 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\nss3.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 000415232 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\nssckbi.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 000383488 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\osclientcerts.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 000267776 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\softokn3.dll
      2010-01-01 02:00 - 2010-01-01 02:00 - 124348416 _____ (Mozilla Foundation) [File not signed] C:\Program Files\LibreWolf\xul.dll
      2022-08-08 18:54 - 2017-10-27 19:06 - 000874368 _____ (NVIDIA Corporation PE Sign v2016 → NVIDIA Corporation) [File not signed] C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPI64.dll
      2022-08-08 18:54 - 2017-10-27 19:06 - 000339256 _____ (NVIDIA Corporation PE Sign v2016 → NVIDIA Corporation) [File not signed] C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSyste m\NvStereo_nvstapisvr64.dll

      ==================== Alternate Data Streams (Whitelisted) ========

      ==================== Safe Mode (Whitelisted) ==================

      (If an entry is included in the fixlist, it will be removed from the registry. The “AlternateShell” will be restored.)

      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal\MBAMService => “”=“Service”
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Net work\MBAMService => “”=“Service”

      ==================== Association (Whitelisted) =================

      ==================== Internet Explorer (Whitelisted) ==========

      (If an entry is included in the fixlist, it will be removed from the registry.)

      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\008i.com → 008i.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\008k.com → 008k.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\00hq.com → 00hq.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\0190-dialers.com → 0190-dialers.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\01i.info → 01i.info
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\02pmnzy5eo29bfk4.com → 02pmnzy5eo29bfk4.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\0411dd.com → 0411dd.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\0511zfhl.com → 0511zfhl.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\05p.com → 05p.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\0632qyw.com → 0632qyw.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\07ic5do2myz3vzpk.com → 07ic5do2myz3vzpk.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\08nigbmwk43i01y6.com → 08nigbmwk43i01y6.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\093qpeuqpmz6ebfa.com → 093qpeuqpmz6ebfa.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\0calories.net → 0calories.net
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\0cj.net → 0cj.net
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\0scan.com → 0scan.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\1-britney-spears-nude.com → 1-britney-spears-nude.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\1-domains-registrations.com → 1-domains-registrations.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\1-se.com → 1-se.com
      IE restricted site: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\1001movie.com → 1001movie.com

      There are 6091 more sites.

      ==================== Hosts content: =========================

      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

      2018-04-12 02:38 - 2022-09-23 03:04 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

      ==================== Other Areas ===========================

      (Currently there is no automatic fix for this section.)

      HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Control Panel\Desktop\Wallpaper → C:\Windows\web\wallpaper\Windows\img0.jpg
      DNS Servers: 192.168.1.1
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer => (SmartScreenEnabled: )
      Windows Firewall is enabled.
      [HEADING=1]Network Binding:[/HEADING]
      VirtualBox Host-Only Network: VirtualBox NDIS6 Bridged Networking Driver → oracle_VBoxNetLwf (enabled)
      Ethernet: VirtualBox NDIS6 Bridged Networking Driver → oracle_VBoxNetLwf (enabled)
      Wi-Fi: VirtualBox NDIS6 Bridged Networking Driver → oracle_VBoxNetLwf (enabled)

      ==================== MSCONFIG/TASK MANAGER disabled items ==

      (If an entry is included in the fixlist, it will be removed.)

      HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\StartupApproved\Run: => “OneDrive”
      HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\StartupApproved\Run: => “Steam”
      HKU\S-1-5-21-3407470762-2713599730-1590247004-1001...\StartupApproved\Run: => “Discord”

      ==================== FirewallRules (Whitelisted) ================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      FirewallRules: [{AF477CB3-E0D6-4864-AAC4-D8CE3CD48B35}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. → Valve Corporation)
      FirewallRules: [{A24850F9-C9A9-4126-855B-6C139A99C1A6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. → Valve Corporation)
      FirewallRules: [{5FD1BC2B-ABD7-4896-80C2-E1EE08088A1F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. → Valve Corporation)
      FirewallRules: [{097601F0-855B-4DFB-BC38-A43DF1473A6F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. → Valve Corporation)
      FirewallRules: [{58F07124-0DB4-4FFA-9F30-04AE79C293DB}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\105.0.1343 .53\msedgewebview2.exe (Microsoft Corporation → Microsoft Corporation)

      ==================== Restore Points =========================

      18-09-2022 22:25:35 Windows Update
      01-10-2022 11:35:04 Scheduled Checkpoint
      02-10-2022 21:41:35 ZHPcleaner

      ==================== Faulty Device Manager Devices ============

      Name: Unknown USB Device (Device Descriptor Request Failed)
      Description: Unknown USB Device (Device Descriptor Request Failed)
      Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
      Manufacturer: (Standard USB Host Controller)
      Service:
      Problem: : Windows has stopped this device because it has reported problems. (Code 43)
      Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.

      ==================== Event log errors: ========================
      [HEADING=1]Application errors:[/HEADING]
      Error: (10/03/2022 02:52:24 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: svchost.exe_UsoSvc, version: 10.0.17134.1, time stamp: 0xa38b9ab2
      Faulting module name: WaaSAssessment.dll, version: 10.0.17134.1, time stamp: 0xb7ab6594
      Exception code: 0xc0000005
      Fault offset: 0x0000000000008ee5
      Faulting process id: 0x360
      Faulting application start time: 0x01d8d71e99497243
      Faulting application path: c:\windows\system32\svchost.exe
      Faulting module path: C:\Windows\System32\WaaSAssessment.dll
      Report Id: 242e485d-94be-4916-b965-4a7de95ff849
      Faulting package full name:
      Faulting package-relative application ID:

      Error: (10/03/2022 02:42:23 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: svchost.exe_UsoSvc, version: 10.0.17134.1, time stamp: 0xa38b9ab2
      Faulting module name: WaaSAssessment.dll, version: 10.0.17134.1, time stamp: 0xb7ab6594
      Exception code: 0xc0000005
      Fault offset: 0x0000000000008ee5
      Faulting process id: 0x22b0
      Faulting application start time: 0x01d8d71bf67a7200
      Faulting application path: c:\windows\system32\svchost.exe
      Faulting module path: C:\Windows\System32\WaaSAssessment.dll
      Report Id: 57c9875b-a761-436b-95a3-43afef2cc7d0
      Faulting package full name:
      Faulting package-relative application ID:

      Error: (10/03/2022 02:32:23 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: svchost.exe_UsoSvc, version: 10.0.17134.1, time stamp: 0xa38b9ab2
      Faulting module name: WaaSAssessment.dll, version: 10.0.17134.1, time stamp: 0xb7ab6594
      Exception code: 0xc0000005
      Fault offset: 0x0000000000008ee5
      Faulting process id: 0x19f4
      Faulting application start time: 0x01d8d71bcd0c3b9a
      Faulting application path: c:\windows\system32\svchost.exe
      Faulting module path: C:\Windows\System32\WaaSAssessment.dll
      Report Id: 2609fb96-b966-4ac1-bbfa-012a27654de5
      Faulting package full name:
      Faulting package-relative application ID:

      Error: (10/03/2022 02:22:22 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: svchost.exe_UsoSvc, version: 10.0.17134.1, time stamp: 0xa38b9ab2
      Faulting module name: WaaSAssessment.dll, version: 10.0.17134.1, time stamp: 0xb7ab6594
      Exception code: 0xc0000005
      Fault offset: 0x0000000000008ee5
      Faulting process id: 0x1f88
      Faulting application start time: 0x01d8d71a29e3fb5a
      Faulting application path: c:\windows\system32\svchost.exe
      Faulting module path: C:\Windows\System32\WaaSAssessment.dll
      Report Id: ce12e3e6-33b0-4280-a40c-777c01f75bc2
      Faulting package full name:
      Faulting package-relative application ID:

      Error: (10/03/2022 11:04:16 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: svchost.exe_UsoSvc, version: 10.0.17134.1, time stamp: 0xa38b9ab2
      Faulting module name: WaaSAssessment.dll, version: 10.0.17134.1, time stamp: 0xb7ab6594
      Exception code: 0xc0000005
      Fault offset: 0x0000000000008ee5
      Faulting process id: 0x338
      Faulting application start time: 0x01d8d6feba105c75
      Faulting application path: c:\windows\system32\svchost.exe
      Faulting module path: C:\Windows\System32\WaaSAssessment.dll
      Report Id: 29668a18-b070-4cac-8276-bf79589a67c5
      Faulting package full name:
      Faulting package-relative application ID:

      Error: (10/03/2022 10:54:14 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: svchost.exe_UsoSvc, version: 10.0.17134.1, time stamp: 0xa38b9ab2
      Faulting module name: WaaSAssessment.dll, version: 10.0.17134.1, time stamp: 0xb7ab6594
      Exception code: 0xc0000005
      Fault offset: 0x0000000000008ee5
      Faulting process id: 0x2224
      Faulting application start time: 0x01d8d6fd53d0395e
      Faulting application path: c:\windows\system32\svchost.exe
      Faulting module path: C:\Windows\System32\WaaSAssessment.dll
      Report Id: 42b19171-cead-464c-ac17-5fae3a407eec
      Faulting package full name:
      Faulting package-relative application ID:

      Error: (10/03/2022 10:46:09 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: svchost.exe_UsoSvc, version: 10.0.17134.1, time stamp: 0xa38b9ab2
      Faulting module name: WaaSAssessment.dll, version: 10.0.17134.1, time stamp: 0xb7ab6594
      Exception code: 0xc0000005
      Fault offset: 0x0000000000008ee5
      Faulting process id: 0x2384
      Faulting application start time: 0x01d8d6fc2b46135e
      Faulting application path: c:\windows\system32\svchost.exe
      Faulting module path: C:\Windows\System32\WaaSAssessment.dll
      Report Id: a3a3c6ef-3c94-4c7a-b303-98e2552f29b5
      Faulting package full name:
      Faulting package-relative application ID:

      Error: (10/03/2022 10:44:13 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: svchost.exe_UsoSvc, version: 10.0.17134.1, time stamp: 0xa38b9ab2
      Faulting module name: WaaSAssessment.dll, version: 10.0.17134.1, time stamp: 0xb7ab6594
      Exception code: 0xc0000005
      Fault offset: 0x0000000000008ee5
      Faulting process id: 0x15c4
      Faulting application start time: 0x01d8d6fbed86f71c
      Faulting application path: c:\windows\system32\svchost.exe
      Faulting module path: C:\Windows\System32\WaaSAssessment.dll
      Report Id: c00ec74c-5564-48ce-baa0-0e5f6abaf7b0
      Faulting package full name:
      Faulting package-relative application ID:
      [HEADING=1]System errors:[/HEADING]
      Error: (10/03/2022 02:59:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-GRKBJ8K)
      Description: The server {4BD3E4E1-7BD4-4A2B-9964-496400DE5193} did not register with DCOM within the required timeout.

      Error: (10/03/2022 02:52:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Windows Update service terminated unexpectedly. It has done this 17 time(s).

      Error: (10/03/2022 02:52:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Update Orchestrator Service service terminated unexpectedly. It has done this 17 time(s).

      Error: (10/03/2022 02:42:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Windows Update service terminated unexpectedly. It has done this 16 time(s).

      Error: (10/03/2022 02:42:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Update Orchestrator Service service terminated unexpectedly. It has done this 16 time(s).

      Error: (10/03/2022 02:32:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Windows Update service terminated unexpectedly. It has done this 15 time(s).

      Error: (10/03/2022 02:32:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Update Orchestrator Service service terminated unexpectedly. It has done this 15 time(s).

      Error: (10/03/2022 02:22:26 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Windows Update service terminated unexpectedly. It has done this 14 time(s).
      [HEADING=1]Windows Defender:[/HEADING]
      Date: 2022-10-03 11:01:24.160
      Description:
      Windows Defender Antivirus scan has been stopped before completion.
      Scan Type: Antimalware
      Scan Parameters: Quick Scan
      Event[0]:

      Date: 2022-10-01 16:09:59.575
      Description:
      Windows Defender Antivirus has encountered an error trying to update signatures.
      New Signature Version:
      Previous Signature Version: 1.263.48.0
      Update Source: Microsoft Malware Protection Center
      Signature Type: AntiVirus
      Update Type: Full
      Current Engine Version:
      Previous Engine Version: 1.1.14600.4
      Error code: 0x80072ee7
      Error description: The server name or address could not be resolved

      Date: 2022-10-01 16:09:59.575
      Description:
      Windows Defender Antivirus has encountered an error trying to update signatures.
      New Signature Version:
      Previous Signature Version: 1.263.48.0
      Update Source: Microsoft Malware Protection Center
      Signature Type: AntiSpyware
      Update Type: Full
      Current Engine Version:
      Previous Engine Version: 1.1.14600.4
      Error code: 0x80072ee7
      Error description: The server name or address could not be resolved

      Date: 2022-10-01 16:09:59.574
      Description:
      Windows Defender Antivirus has encountered an error trying to update signatures.
      New Signature Version:
      Previous Signature Version: 1.263.48.0
      Update Source: Microsoft Malware Protection Center
      Signature Type: AntiVirus
      Update Type: Full
      Current Engine Version:
      Previous Engine Version: 1.1.14600.4
      Error code: 0x80072ee7
      Error description: The server name or address could not be resolved

      Date: 2022-10-01 16:09:59.128
      Description:
      Windows Defender Antivirus has encountered an error trying to update signatures.
      New Signature Version:
      Previous Signature Version: 1.263.48.0
      Update Source: Microsoft Update Server
      Signature Type: AntiVirus
      Update Type: Full
      Current Engine Version:
      Previous Engine Version: 1.1.14600.4
      Error code: 0x80240438
      Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

      Date: 2022-08-10 22:50:14.430
      Description:
      Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
      Feature: Behavior Monitoring
      Error Code: 0x80508023
      Error description: The program could not find the malware and other potentially unwanted software on this device.
      Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

      ==================== Memory info ===========================

      BIOS: Award Software International, Inc. F10 03/22/2011
      Motherboard: Gigabyte Technology Co., Ltd. GA-MA770T-UD3
      Processor: AMD Athlon™ II X4 645 Processor
      Percentage of memory in use: 23%
      Total physical RAM: 12285.55 MB
      Available physical RAM: 9356.54 MB
      Total Virtual: 14141.55 MB
      Available Virtual: 10900.14 MB

      ==================== Drives ================================

      Drive c: () (Fixed) (Total:930.97 GB) (Free:814.69 GB) (Model: TOSHIBA HDWD110 ATA Device) NTFS

      \?\Volume{922c79a0-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.54 GB) (Free:0.16 GB) NTFS

      ==================== MBR & Partition Table ====================

      ================================================== ========
      Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 922C79A0)
      Partition 1: (Active) - (Size=549 MB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)

      ==================== End of Addition.txt =======================

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #18
        What is this torrent you downloaded?

        325289AEDD75.TorrentRTFREE_qtx9tqphctw9r!App



        FRST Fix.

        Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.



        Adware Cleaner

        [ul]
        [li]Download AdwCleaner and save it to your Desktop[/li][li]Right-click on AdwCleaner.exeand select [IMG alt=“Spcusrh.png”]https://i.imgur.com/Spcusrh.png Run as Administrator[/li][li]Accept the EULA (I accept), then click on Scan Now[/li][li]Let the scan complete[/li][li]Once the scan completes, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button[/li][li]Subsequently you may be asked to Run Basic Repair. This is optional. I would suggest holding off on this for now.[/li][li]Once the cleaning process is complete, AdwCleaner will ask you to restart your computer[/li][li]Close all other open windows and allow it to restart[/li][li]After the restart, Notepad will open with the AdwCleaner cleaning log[/li][li]Please Attach the contents of that log into your next reply to me[/li][/ul]


        Adware Removal Tool Scan.

        Download Adware removal tool to your desktop, right click the icon and select Run as Administrator.
        Click Scan
        Hit Ok.
        Hit next make sure to leave all items checked, for removal.
        Click Next
        The Program will close all open programs to complete the removal, so save any work and hit OK.
        Then hit OK after the removal process is complete, thenOK again to finish up.
        Post the log generated.


        Download Process Explorer.
        Unzip to your desktop.
        [COLOR=rgb(184, 49, 47)]Right click and run as admin.
        Go to options.
        Virus Total.
        Make sure Check At virusTotal is ticked.
        Now screen shot everything, no matter how many screen shots it takes, upload them all here so that I can see everything.
        Also, in process explorer, slide the bar that I highlighted so that I can see the virus total results for your processes, same as I have done on my machine in picture provided.

        [ATTACH type=“full”]10640[/ATTACH]


        Download KillEmAll to your desktop and unzip it there.
        Right click KillEmAll run as admin.
        Click enter button.
        Then click L
        Then hit enter key on your keyboard.
        A log file will appear.
        Copy and paste that into your reply here.[/IMG]

        Comment

        • puki
          PCHF Member
          • Sep 2022
          • 29

          #19
          I wanted to download an linux iso.
          Here are the logs :
          [HEADING=1]-------------------------------[/HEADING]
          [HEADING=1]Malwarebytes AdwCleaner 8.4.0.0[/HEADING]
          [HEADING=1]-------------------------------[/HEADING]
          [HEADING=1]Build: 08-30-2022[/HEADING]
          [HEADING=1]Database: 2022-08-22.1 (Cloud)[/HEADING]
          [HEADING=1]Support: https://www.malwarebytes.com/support[/HEADING]
          [HEADING=1]-------------------------------[/HEADING]
          [HEADING=1]Mode: Scan[/HEADING]
          [HEADING=1]-------------------------------[/HEADING]
          [HEADING=1]Start: 10-04-2022[/HEADING]
          [HEADING=1]Duration: 00:00:07[/HEADING]
          [HEADING=1]OS: Windows 10 (Build 17134.165)[/HEADING]
          [HEADING=1]Scanned: 32099[/HEADING]
          [HEADING=1]Detected: 0[/HEADING]
          ***** [ Services ] *****

          No malicious services found.

          ***** [ Folders ] *****

          No malicious folders found.

          ***** [ Files ] *****

          No malicious files found.

          ***** [ DLL ] *****

          No malicious DLLs found.

          ***** [ WMI ] *****

          No malicious WMI found.

          ***** [ Shortcuts ] *****

          No malicious shortcuts found.

          ***** [ Tasks ] *****

          No malicious tasks found.

          ***** [ Registry ] *****

          No malicious registry entries found.

          ***** [ Chromium (and derivatives) ] *****

          No malicious Chromium entries found.

          ***** [ Chromium URLs ] *****

          No malicious Chromium URLs found.

          ***** [ Firefox (and derivatives) ] *****

          No malicious Firefox entries found.

          ***** [ Firefox URLs ] *****

          No malicious Firefox URLs found.

          ***** [ Hosts File Entries ] *****

          No malicious hosts file entries found.

          ***** [ Preinstalled Software ] *****

          No Preinstalled Software found.

          AdwCleaner[S00].txt - [1419 octets] - [04/10/2022 11:46:28]
          AdwCleaner[S01].txt - [1480 octets] - [04/10/2022 11:47:04]

          ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S02].txt ##########
          Process CPU Private Bytes Working Set PID Description Company Name VirusTotal
          Registry 1,828 K 23,676 K 104 The system cannot find the file specified.
          System Idle Process 87.60 52 K 8 K 0
          System < 0.01 240 K 22,416 K 4
          Interrupts 1.17 0 K 0 K n/a Hardware Interrupts and DPCs
          smss.exe 480 K 988 K 396 The system cannot find the file specified.
          csrss.exe 1,788 K 5,368 K 560 The system cannot find the file specified.
          wininit.exe 1,704 K 7,056 K 652 The system cannot find the file specified.
          services.exe 4,952 K 9,424 K 724 The system cannot find the file specified.
          svchost.exe 984 K 3,780 K 932 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe < 0.01 12,760 K 26,524 K 980 Host Process for Windows Services Microsoft Corporation 0/75
          RuntimeBroker.exe 7,424 K 27,008 K 1056 Runtime Broker Microsoft Corporation 0/75
          RuntimeBroker.exe 8,176 K 26,988 K 4380 Runtime Broker Microsoft Corporation 0/75
          dllhost.exe 2,924 K 10,356 K 7212 COM Surrogate Microsoft Corporation 0/75
          WmiPrvSE.exe 2,380 K 7,772 K 1636 The system cannot find the file specified.
          WmiPrvSE.exe 2,852 K 9,516 K 7968 The system cannot find the file specified.
          SearchUI.exe Suspended 77,696 K 132,156 K 900 Search and Cortana application Microsoft Corporation 0/76
          ShellExperienceHost.exe Suspended 30,148 K 71,672 K 5240 Windows Shell Experience Host Microsoft Corporation 0/75
          smartscreen.exe 17,356 K 26,760 K 8436 Windows Defender SmartScreen Microsoft Corporation 0/74
          backgroundTaskHost.exe Suspended 4,828 K 18,368 K 2464 Background Task Host Microsoft Corporation 0/74
          svchost.exe < 0.01 7,452 K 12,932 K 496 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 3,108 K 8,496 K 648 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,828 K 10,628 K 1204 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,308 K 9,428 K 1212 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 6,944 K 15,084 K 1220 Host Process for Windows Services Microsoft Corporation 0/75
          taskhostw.exe 26,316 K 39,848 K 1876 The system cannot find the file specified.
          taskhostw.exe 8,848 K 17,652 K 4576 Host Process for Windows Tasks Microsoft Corporation 0/75
          svchost.exe 3,068 K 9,412 K 1324 Host Process for Windows Services Microsoft Corporation 0/75
          sihost.exe 6,304 K 26,112 K 4484 Shell Infrastructure Host Microsoft Corporation 0/75
          svchost.exe 2,160 K 11,180 K 1368 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe < 0.01 10,576 K 19,944 K 1384 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 16,088 K 19,416 K 1532 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 1,404 K 5,616 K 1660 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 4,348 K 8,248 K 1668 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,224 K 7,720 K 1676 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,364 K 7,524 K 1748 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,072 K 8,016 K 1824 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,088 K 7,848 K 1888 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,084 K 9,160 K 1900 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 5,176 K 12,328 K 1928 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 3,256 K 9,328 K 1444 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 3,484 K 12,908 K 2104 Host Process for Windows Services Microsoft Corporation 0/75
          audiodg.exe 6,192 K 10,972 K 7416 The system cannot find the file specified.
          svchost.exe 3,324 K 8,472 K 2200 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe < 0.01 5,284 K 12,992 K 2224 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 1,824 K 6,468 K 2300 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 3,828 K 12,952 K 2312 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,348 K 7,200 K 2352 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe < 0.01 5,924 K 17,176 K 2380 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 6,468 K 15,752 K 2760 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 5,212 K 15,932 K 2784 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,904 K 13,168 K 2844 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 4,084 K 12,208 K 2920 Host Process for Windows Services Microsoft Corporation 0/75
          spoolsv.exe 5,416 K 14,748 K 2952 Spooler SubSystem App Microsoft Corporation 0/75
          svchost.exe 2,116 K 7,764 K 2280 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 1,372 K 5,952 K 3172 Host Process for Windows Services Microsoft Corporation 0/75
          dasHost.exe 1,108 K 4,936 K 3528 The system cannot find the file specified.
          svchost.exe < 0.01 4,748 K 13,752 K 3180 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 9,748 K 20,216 K 3188 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,688 K 7,504 K 3200 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,420 K 8,472 K 3236 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 1,368 K 5,564 K 3260 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 1,628 K 6,336 K 3268 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 4,932 K 20,496 K 3284 Host Process for Windows Services Microsoft Corporation 0/75
          SecurityHealthService.exe 5,480 K 17,008 K 3296 Windows Security Health Service Microsoft Corporation 0/76
          MsMpEng.exe < 0.01 364,848 K 303,664 K 3412 Antimalware Service Executable Microsoft Corporation 0/74
          svchost.exe 1,736 K 6,016 K 3468 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 3,576 K 11,892 K 3680 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,204 K 7,180 K 4068 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 1,860 K 7,620 K 4416 Host Process for Windows Services Microsoft Corporation 0/75
          ctfmon.exe 0.39 4,884 K 15,452 K 500 The system cannot find the file specified.
          svchost.exe 4,028 K 20,580 K 4968 Host Process for Windows Services Microsoft Corporation 0/75
          NisSrv.exe 13,856 K 13,016 K 5160 Microsoft Network Realtime Inspection Service Microsoft Corporation 0/73
          svchost.exe < 0.01 5,508 K 18,764 K 5812 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,488 K 8,356 K 7280 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,612 K 10,516 K 7772 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 4,064 K 9,688 K 7972 Host Process for Windows Services Microsoft Corporation 0/75
          SgrmBroker.exe 2,824 K 4,976 K 4900 System Guard Runtime Monitor Broker Service Microsoft Corporation 0/74
          svchost.exe 1,852 K 10,188 K 3420 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,368 K 8,780 K 876 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 1,496 K 5,608 K 5168 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 2,724 K 11,404 K 9036 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 4,724 K 21,292 K 2492 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 6,276 K 9,764 K 2340 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 1,952 K 7,328 K 4976 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 1,440 K 6,048 K 7172 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 3,516 K 10,860 K 9348 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 7,552 K 25,420 K 3900 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 6,476 K 27,384 K 1332 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 3,232 K 14,876 K 5996 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 6,048 K 20,936 K 2828 Host Process for Windows Services Microsoft Corporation 0/75
          svchost.exe 1,580 K 6,724 K 4940 Host Process for Windows Services Microsoft Corporation 0/75
          NVDisplay.Container.exe 4,508 K 12,980 K 6312 NVIDIA Container NVIDIA Corporation 0/74
          NVDisplay.Container.exe < 0.01 22,332 K 38,068 K 5840 The system cannot find the file specified.
          SearchIndexer.exe 26,372 K 33,528 K 1280 Microsoft Windows Search Indexer Microsoft Corporation 2/75
          SearchProtocolHost.exe 1,884 K 7,668 K 9260 Microsoft Windows Search Protocol Host Microsoft Corporation 0/74
          SearchFilterHost.exe 2,100 K 8,452 K 888 The system cannot find the file specified.
          SearchProtocolHost.exe 2,812 K 12,752 K 964 The system cannot find the file specified.
          lsass.exe < 0.01 6,864 K 16,972 K 732 Local Security Authority Process Microsoft Corporation 0/75
          fontdrvhost.exe 1,400 K 3,940 K 960 The system cannot find the file specified.
          csrss.exe < 0.01 2,172 K 4,964 K 9600 The system cannot find the file specified.
          winlogon.exe 2,300 K 8,548 K 3756 The system cannot find the file specified.
          fontdrvhost.exe 6,804 K 13,496 K 9492 The system cannot find the file specified.
          dwm.exe 1.95 52,652 K 58,876 K 8344 The system cannot find the file specified.
          explorer.exe < 0.01 81,416 K 152,668 K 6988 Windows Explorer Microsoft Corporation 0/72
          MSASCuiL.exe 2,028 K 9,116 K 3776 Windows Defender notification icon Microsoft Corporation 0/75
          KillEmAll.exe 3,632 K 14,328 K 5444 The system cannot find the file specified.
          conhost.exe 6,112 K 13,840 K 784 The system cannot find the file specified.
          procexp64.exe 8.57 27,728 K 57,964 K 4272 Sysinternals Process Explorer Sysinternals - www.sysinternals.com 0/76
          librewolf.exe < 0.01 133,576 K 205,796 K 3324 LibreWolf Mozilla Corporation 0/73
          librewolf.exe < 0.01 150,172 K 65,120 K 4624 LibreWolf Mozilla Corporation 0/73
          librewolf.exe 19,624 K 15,700 K 1632 LibreWolf Mozilla Corporation 0/73
          librewolf.exe 31,816 K 47,544 K 4876 LibreWolf Mozilla Corporation 0/73
          librewolf.exe 90,652 K 110,008 K 6924 LibreWolf Mozilla Corporation 0/73
          librewolf.exe 29,988 K 39,340 K 6968 LibreWolf Mozilla Corporation 0/73
          librewolf.exe 88,252 K 124,980 K 5348 LibreWolf Mozilla Corporation 0/73
          librewolf.exe 26,744 K 32,608 K 3140 LibreWolf Mozilla Corporation 0/73
          librewolf.exe 26,732 K 32,580 K 8096 LibreWolf Mozilla Corporation 0/73
          librewolf.exe 26,768 K 32,608 K 1448 LibreWolf Mozilla Corporation 0/73
          Started on DESKTOP-GRKBJ8K at 10/4/2022 12:09:46 PM… (Running as Standard User)

          Terminated=FALSE “nvdisplay.container.exe”
          Terminated=FALSE “nvdisplay.container.exe”
          Terminated=True “c:\windows\systemapps\microsoft.windows.cortana_c w5n1h2txyewy\searchui.exe”
          Terminated=True “c:\windows\systemapps\shellexperiencehost_cw5n1h2 txyewy\shellexperiencehost.exe”
          Terminated=FALSE “searchindexer.exe”
          Terminated=True “c:\program files\librewolf\librewolf.exe”
          Terminated=True “c:\program files\librewolf\librewolf.exe”
          Terminated=True “c:\program files\librewolf\librewolf.exe”
          Terminated=True “c:\program files\librewolf\librewolf.exe”
          Terminated=True “c:\program files\librewolf\librewolf.exe”
          Terminated=True “c:\program files\librewolf\librewolf.exe”
          Terminated=True “c:\users\teatang\desktop\processexplorer\procexp6 4.exe”
          Terminated=True “c:\windows\system32\applicationframehost.exe”
          Terminated=True “c:\program files\librewolf\librewolf.exe”
          Terminated=True “c:\program files\librewolf\librewolf.exe”
          Terminated=FALSE “mpcmdrun.exe”
          Terminated=FALSE “mpcmdrun.exe”
          Terminated=FALSE “sedlauncher.exe”
          Terminated=True “librewolf.exe”
          Terminated=True “c:\windows\system32\smartscreen.exe”
          Terminated=True “librewolf.exe”
          Terminated=True “librewolf.exe”
          Terminated=True “searchprotocolhost.exe”
          Terminated=FALSE “searchfilterhost.exe”
          Terminated=FALSE “searchprotocolhost.exe”
          Terminated=True “c:\program files\windowsapps\microsoft.windowscommunicationsa pps_16005.14326.20970.0_x64__8wekyb3d8bbwe\hxtsr.e xe”


          Adware Removal Tool 5.1
          Time: 2022_10_04_11_54_42
          OS: Windows 10 Enterprise - x64 Bit
          Account Name: TeaTang
          Adware Definition: 10012022
          Elapsed time: 12:31
          Scan Status:- Automatic Done

          \\\\\\\\\\\\ Scan Logs \\\\\\\\\\\

          No results found
          [HEADING=1]Fix result of Farbar Recovery Scan Tool (x64) Version: 30-08-2022
          Ran by TeaTang (04-10-2022 12:14:55) Run:1
          Running from C:\Users\TeaTang\Desktop
          Loaded Profiles: TeaTang
          Boot Mode: Normal[/HEADING]
          fixlist content:


          Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - \Microsoft\Windows\HelloFace\FODCleanupTask → No File <==== ATTENTION
          Task: {908F9503-D38F-4136-A58B-23CF5653F9EC} - \Microsoft\Windows\RemoteAssistance\RemoteAssistan ceTask → No File <==== ATTENTION
          S3 trufos; system32\drivers\trufos.sys
          Torrent RT FREE → C:\Program Files\WindowsApps\325289AEDD75.TorrentRTFREE_1.1.1 1.0_x64__qtx9tqphctw9r [2022-10-03] (Vlasenko Bros.) [MS Ad]
          C:\Program Files\WindowsApps\325289AEDD75.TorrentRTFREE_1.1.1 1.0_x64__qtx9tqphctw9r


          “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{65B85F6 F-35B3-4459-A179-28255D5B7B25}” => not found
          “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsof t\Windows\HelloFace\FODCleanupTask” => not found
          “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{908F950 3-D38F-4136-A58B-23CF5653F9EC}” => not found
          “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsof t\Windows\RemoteAssistance\RemoteAssistanceTask” => not found
          trufos => service not found.
          Torrent RT FREE → C:\Program Files\WindowsApps\325289AEDD75.TorrentRTFREE_1.1.1 1.0_x64__qtx9tqphctw9r [2022-10-03] (Vlasenko Bros.) [MS Ad] => Error: No automatic fix found for this entry.
          “C:\Program Files\WindowsApps\325289AEDD75.TorrentRTFREE_1.1.1 1.0_x64__qtx9tqphctw9r” => not found

          ==== End of Fixlog 12:14:55 ====

          Comment

          • Malnutrition
            PCHF Moderator
            • Jul 2016
            • 7041

            #20
            I need screenshots not text from process explorer. Use the snipping tool.

            Comment

            • Malnutrition
              PCHF Moderator
              • Jul 2016
              • 7041

              #21
              ZHP Diag Scan Click here to download.
              Save to your desktop.
              Right Click Run as Admin.
              Click the Options button.
              Click on Check All
              Then click close.
              Click the Scanner button.
              When complete please push the report button.
              A notepad will open… attach the report in your next reply.

              Comment

              • puki
                PCHF Member
                • Sep 2022
                • 29

                #22
                [ATTACH type=“full”]10642[/ATTACH]

                Comment

                • puki
                  PCHF Member
                  • Sep 2022
                  • 29

                  #23
                  [HEADING=2]ZHPDiag Diagnostic Report[/HEADING]
                  ~ ZHPDiag v2022.10.4.79 By Nicolas Coolman (2022/10/04)
                  ~ Run by TeaTang (Administrator) (2022/10/04 16:05:24)
                  ~ Web: https://www.nicolascoolman.com
                  ~ Blog: https://nicolascoolman.eu/
                  ~ Facebook: ZHP
                  ~ Certificate ZHPDiag: Legal
                  ~ State version: Version KO
                  ~ Mode: Scan
                  ~ Report: C:\Users\TeaTang\Desktop\ZHPDiag.txt
                  ~ Report: C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPDiag.txt
                  ~ UAC: Activate
                  ~ System startup: Normal (Normal boot)
                  Windows 10 Pro, 64-bit (Build 17134) =>.Microsoft Corporation

                  —\ Internet Browsers (1) - 0s
                  ~ MSIE: Internet Explorer v11.165.17134.0

                  —\ Windows Product Information (3) - 0s
                  ~ Windows Server License Manager Script : OK
                  ~ Licence Script File Génération : OK
                  Windows Automatic Updates : OK

                  —\ System protection software (2) - 2s
                  Windows Defender W10 (Activate) (Protection)
                  Malwarebytes version 4.5.12.204 v4.5.12.204 (Protection)

                  —\ Informations on the system (7) - 0s
                  ~ Operating System: AMD64 Family 16 Model 5 Stepping 3, AuthenticAMD
                  ~ Operating System: 64-bit
                  ~ Boot mode: Normal (Normal boot)
                  Total RAM: 12580.404 MB (77% free) : OK =>.RAM Value
                  System Restore: Activé (Enable)
                  System drive C: has 834 GB (87%) free of 953 GB : OK =>.Disk Space
                  Total RAM: 12580.404 MB (75% free) : OK =>.RAM Value

                  —\ Connection to the system mode (3) - 0s
                  ~ Computer Name: DESKTOP-GRKBJ8K
                  ~ User Name: TeaTang
                  ~ Logged in as Administrator

                  —\ Enumeration of the disk units (1) - 5s
                  ~ Drive C: has 834 GB free of 953 GB (System)

                  —\ SYSTEM DISK MAIN FEATURES (27) - 22s
                  ~ Model: TOSHIBA HDWD110 ATA Device vMS2OA8J0 (953 Gb )
                  ~ Media Type: HDD Fixed Disk ( Bus: ATA)

                  —\ SYSTEM DISK GENERAL ATTRIBUTES
                  OK - N0 - Indicateur d’usure du périphérique de stockage (Storage Device Wear Indicator) (%): 0
                  OK - N1 - Temps de latence maximal de vidage (Maximum Flash latency) (ms): 0.466
                  OK - N2 - Temps de latence maximal d’écriture (Maximum write latency) (ms): 9.033
                  OK - N3 - Temps de latence maximal de lecture (Maximum read latency) (ms): 7.177

                  —\ S.M.A.R.T. PARAMETERS - [Flag][Value][Worst] [Threshold][Raw Value]
                  OK - 01 - Taux d’erreur de lecture (Raw Read Error Rate) - [11][100][100] [16][0]
                  OK - 02 - Performance de débit (Throughput Performance) - [5][141][141] [54][73]
                  OK - 03 - Temps moyen de mise en rotation (ms) (Spin-Up Time) - [7][121][121] [24][190]
                  OK - 04 - Nombre de démarrages/arrêts (Start/Stop Count) - [18][99][99] [0][5859]
                  OK - 05 - Nombre de secteurs réalloués (Reallocated Sector Count) - [51][100][100] [5][0]
                  OK - 07 - Taux d’erreurs de recherche (Seek Error Rate) - [11][100][100] [67][0]
                  OK - 08 - Recherche de performance de temps (Seek Time Performance) - [5][115][115] [20][34]
                  OK - 09 - Heures de fonctionnement (Power-On Hours Count (POH) - [18][100][100] [0][4334]
                  OK - 0A - Nombre d’essai de relance de rotation (Spin Retry Count) - [19][100][100] [60][0]
                  OK - 0C - Nombre total de cycles d’alimentation (Power Cycle Count) - [50][99][99] [0][4322]
                  OK - C0 - Nombre de Rétractation d’armature magnétique (Power-off Retract Count) - [50][96][96] [0][5893]
                  OK - C1 - Cycles de charge/décharge (Load/Unload Cycle Count) - [18][96][96] [0][5898]
                  OK - C2 - Température interne actuelle (Enclosure Temperature) - [2][162][162] [0][37]
                  OK - C4 - Nombre d’opérations de réallocations (remap) (Reallocation Event Count) - [50][100][100] [0][0]
                  OK - C5 - Nombre de secteurs instables (Current Pending Sector Count) - [34][100][100] [0][0]
                  OK - C6 - Total d’erreurs incorrigibles d’un secteur (Off-Line Uncorrectable Sector Count) - [8][100][100] [0][0]
                  OK - C7 - Nombre d’erreurs dans le transfert de données (Ultra ATA CRC Error Rate) - [10][200][200] [0][967]

                  —\ State of the Windows Security Center (7) - 0s
                  [HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
                  [HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\policies\system] EnableLUA: OK
                  [HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
                  [HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
                  [HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Explorer\Associations] Application: OK
                  [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
                  [HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

                  —\ Search Generic System Files (25) - 3s
                  [MD5.E4A81EDDFF8B844D85C8B45354E4144E] - 12/07/2018 - (.Microsoft Corporation - Windows Explorer.) – C:\Windows\Explorer.exe [3932672] =>.Microsoft Windows®
                  [MD5.73C519F050C20580F8A62C849D49215A] - 12/04/2018 - (.Microsoft Corporation - Windows host process (Rundll32).) – C:\Windows\System32\rundll32.exe [69632] [Unsigned] =>.Microsoft Corporation
                  [MD5.A58B0CB069DA7840B935872ADCD7F0C2] - 12/04/2018 - (.Microsoft Corporation - Windows Start-Up Application.) – C:\Windows\System32\Wininit.exe [366792] [Unsigned] =>.Microsoft Corporation
                  [MD5.73FF1844030943E6D81A405FF419A245] - 12/07/2018 - (.Microsoft Corporation - Internet Extensions for Win32.) – C:\Windows\System32\wininet.dll [3440128] [Unsigned] =>.Microsoft Corporation
                  [MD5.3E56F9D58EBBB1B33E31B86267DBECFC] - 12/07/2018 - (.Microsoft Corporation - Windows Logon Application.) – C:\Windows\System32\Winlogon.exe [677376] [Unsigned] =>.Microsoft Corporation
                  [MD5.7A377800FF15426B7D89768A8727CFEF] - 12/04/2018 - (.Microsoft Corporation - Software Licensing Library.) – C:\Windows\System32\sppcomapi.dll [415232] [Unsigned] =>.Microsoft Corporation
                  [MD5.F4B9F200B9D7EBC8BD4C8E39F02A44E3] - 12/07/2018 - (.Microsoft Corporation - DNS Client API DLL.) – C:\Windows\System32\dnsapi.dll [766608] =>.Microsoft Windows®
                  [MD5.BE663A3C8E4F3ED2E8404A808614BCE3] - 12/07/2018 - (.Microsoft Corporation - DNS Client API DLL.) – C:\Windows\Syswow64\dnsapi.dll [573904] =>.Microsoft Windows®
                  [MD5.63C79AD0202728F4608757340B7D602B] - 12/07/2018 - (.Microsoft Corporation - Windows Update Agent.) – C:\Windows\System32\wuaueng.dll [2903040] [Unsigned] =>.Microsoft Corporation
                  [MD5.4DCCC3E02A22ED4A4ADB11386F226071] - 12/04/2018 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) – C:\Windows\System32\drivers\AFD.sys [626592] [Unsigned] =>.Microsoft Corporation
                  [MD5.90AB4ED8EBD72A1C096A40CC35404B91] - 12/04/2018 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) – C:\Windows\System32\drivers\atapi.sys [28568] [Unsigned] =>.Microsoft Corporation
                  [MD5.D3CBC6DE5955D014407C7BD1FFE80F00] - 12/04/2018 - (.Microsoft Corporation - CD-ROM File System Driver.) – C:\Windows\System32\drivers\Cdfs.sys [93696] [Unsigned] =>.Microsoft Corporation
                  [MD5.6834DBBA2A1DBA5B9B6360D0B9A3CBB5] - 12/07/2018 - (.Microsoft Corporation - SCSI CD-ROM Driver.) – C:\Windows\System32\drivers\Cdrom.sys [159744] [Unsigned] =>.Microsoft Corporation
                  [MD5.8A1C10410FDA4287A76EC5A64371E221] - 12/07/2018 - (.Microsoft Corporation - DFS Namespace Client Driver.) – C:\Windows\System32\drivers\DfsC.sys [141312] [Unsigned] =>.Microsoft Corporation
                  [MD5.DED74127C7A2266715C0B8EA2EE75214] - 12/04/2018 - (.Microsoft Corporation - High Definition Audio Bus Driver.) – C:\Windows\System32\drivers\HDAudBus.sys [86016] [Unsigned] =>.Microsoft Corporation
                  [MD5.DA179667B8CEC22E4ECBBF4210DC0E35] - 12/04/2018 - (.Microsoft Corporation - i8042 Port Driver.) – C:\Windows\System32\drivers\i8042prt.sys [105984] [Unsigned] =>.Microsoft Corporation
                  [MD5.7408B83959A4B8271EF67FD06A6B366B] - 12/04/2018 - (.Microsoft Corporation - IP Network Address Translator.) – C:\Windows\System32\drivers\IpNat.sys [214528] [Unsigned] =>.Microsoft Corporation
                  [MD5.3C0FA2ED75875481D00F3D77B1A3E336] - 12/04/2018 - (.Microsoft Corporation - Windows NT SMB Minirdr.) – C:\Windows\System32\drivers\MRxSmb.sys [500632] [Unsigned] =>.Microsoft Corporation
                  [MD5.045A018E0BA5F9B75C5928A31C0E822C] - 12/04/2018 - (.Microsoft Corporation - MBT Transport driver.) – C:\Windows\System32\drivers\netBT.sys [311296] [Unsigned] =>.Microsoft Corporation
                  [MD5.FCEFE8F8E6F5D46BB4BFA6DDEF6392E6] - 12/07/2018 - (.Microsoft Corporation - NT File System Driver.) – C:\Windows\System32\drivers\ntfs.sys [2420632] [Unsigned] =>.Microsoft Corporation
                  [MD5.13B175715A4391E4E5D2AB2EBC8CDBB5] - 12/04/2018 - (.Microsoft Corporation - Parallel Port Driver.) – C:\Windows\System32\drivers\Parport.sys [98816] [Unsigned] =>.Microsoft Corporation
                  [MD5.775ED7E51B58CF9EB415A1DBA540DACF] - 12/04/2018 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) – C:\Windows\System32\drivers\Rasl2tp.sys [106496] [Unsigned] =>.Microsoft Corporation
                  [MD5.3DE4216324BE32FC3AF7667AE2406EE5] - 12/07/2018 - (.Microsoft Corporation - Microsoft RDP Device redirector.) – C:\Windows\System32\drivers\rdpdr.sys [182784] [Unsigned] =>.Microsoft Corporation
                  [MD5.16071C42E21CE3378FA449322FB9AB1D] - 12/04/2018 - (.Microsoft Corporation - TDI Translation Driver.) – C:\Windows\System32\drivers\tdx.sys [121248] [Unsigned] =>.Microsoft Corporation
                  [MD5.F0EE4E6028CCA58BEA9A04E7BEAB7DB4] - 12/04/2018 - (.Microsoft Corporation - Volume Shadow Copy driver.) – C:\Windows\System32\drivers\volsnap.sys [398240] [Unsigned] =>.Microsoft Corporation

                  —\ No disabled Windows Services (56) - 3s
                  O23 - Service: C:\Windows\System32\AudioEndpointBuilder.dll (AudioEndpointBuilder) . (.Microsoft Corporation - Windows Audio Endpoint Builder.) - C:\Windows\System32\AudioEndpointBuilder.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\audiosrv.dll (Audiosrv) . (.Microsoft Corporation - Windows Audio Service.) - C:\Windows\System32\Audiosrv.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\bfe.dll (BFE) . (.Microsoft Corporation - Base Filtering Engine.) - C:\Windows\System32\bfe.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\system32\bisrv.dll (BrokerInfrastructure) . (.Microsoft Corporation - Background Tasks Infrastructure Service.) - C:\Windows\System32\bisrv.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\cdpusersvc.dll (CDPUserSvc) . (.Microsoft Corporation - Microsoft (R) CDP User Components.) - C:\Windows\System32\CDPUserSvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: Connected Devices Platform User Service_1725c86 (CDPUserSvc_1725c86) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
                  O23 - Service: C:\Windows\System32\coremessaging.dll (CoreMessagingRegistrar) . (.Microsoft Corporation - Microsoft CoreMessaging Dll.) - C:\Windows\System32\coremessaging.dll =>.Microsoft Windows®
                  O23 - Service: C:\Windows\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) - C:\Windows\System32\cryptsvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\das.dll (DeviceAssociationService) . (.Microsoft Corporation - Device Association Service.) - C:\Windows\System32\das.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - DHCP Client Service.) - C:\Windows\System32\dhcpcore.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - DNS Caching Resolver Service.) - C:\Windows\System32\dnsrslvr.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\dosvc.dll (DoSvc) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
                  O23 - Service: C:\Windows\System32\dusmsvc.dll (DusmSvc) . (.Microsoft Corporation - Data Usage Service.) - C:\Windows\System32\dusmsvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: Microsoft Edge Update Service (edgeupdate) (edgeupdate) . (.Microsoft Corporation - Microsoft Edge Update.) - C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe =>.Microsoft®
                  O23 - Service: C:\Windows\System32\wevtsvc.dll (EventLog) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
                  O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Windows Font Cache Service.) - C:\Windows\System32\FntCache.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - Group Policy Client.) - C:\Windows\System32\gpsvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\ikeext.dll (IKEEXT) . (.Microsoft Corporation - IKE extension.) - C:\Windows\System32\ikeext.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) - C:\Windows\System32\iphlpsvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) - C:\Windows\System32\srvsvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) - C:\Windows\System32\wkssvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\system32\lsm.dll (LSM) . (.Microsoft Corporation - Local Session Manager Service.) - C:\Windows\System32\lsm.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\moshost.dll (MapsBroker) . (.Microsoft Corporation - Downloaded Maps Manager.) - C:\Windows\System32\moshost.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\FirewallAPI.dll (mpssvc) . (.Microsoft Corporation - Microsoft Protection Service.) - C:\Windows\System32\mpssvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Network Location Awareness 2.) - C:\Windows\System32\nlasvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Network Store Interface RPC server.) - C:\Windows\System32\nsisvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe =>.NVIDIA Corporation®
                  O23 - Service: C:\Windows\System32\APHostRes.dll (OneSyncSvc) . (.Microsoft Corporation - Accounts Host Service.) - C:\Windows\System32\APHostService.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: Sync Host_1725c86 (OneSyncSvc_1725c86) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
                  O23 - Service: C:\Windows\System32\umpo.dll (Power) . (.Microsoft Corporation - User-mode Power Service.) - C:\Windows\System32\umpo.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\Windows\System32\profsvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\rasmans.dll (RasMan) . (.Microsoft Corporation - Remote Access Connection Manager.) - C:\Windows\System32\rasmans.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\system32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - RPC Endpoint Mapper.) - C:\Windows\System32\RpcEpMap.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: @combase.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\Windows\System32\rpcss.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - Task Scheduler Service.) - C:\Windows\System32\schedsvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\SecurityHealthAgent.dll (SecurityHealthService) . (.Microsoft Corporation - Windows Security Health Service.) - C:\Windows\System32\SecurityHealthService.exe [Unsigned] =>.Microsoft Corporation
                  O23 - Service: Windows Remediation Service (sedsvc) . (.Microsoft Corporation - sedsvc.) - C:\Program Files\rempl\sedsvc.exe =>.Microsoft®
                  O23 - Service: C:\Windows\System32\Sens.dll (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) - C:\Windows\System32\sens.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\SgrmBroker.exe,-100 (SgrmBroker) . (.Microsoft Corporation - System Guard Runtime Monitor Broker Service.) - C:\Windows\System32\SgrmBroker.exe [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) - C:\Windows\System32\shsvcs.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Spooler SubSystem App.) - C:\Windows\System32\spoolsv.exe [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - Microsoft Software Protection Platform Serv.) - C:\Windows\System32\sppsvc.exe [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\system32\SystemEventsBrokerServer.dll (SystemEventsBroker) . (.Microsoft Corporation - System Events Broker.) - C:\Windows\System32\SystemEventsBrokerServer.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\themeservice.dll (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) - C:\Windows\System32\themeservice.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\usermgr.dll (UserManager) . (.Microsoft Corporation - UserMgr.) - C:\Windows\System32\usermgr.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\usocore.dll (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) - C:\Windows\System32\usocore.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\wcmsvc.dll (Wcmsvc) . (.Microsoft Corporation - Windows Connection Manager Service DLL.) - C:\Windows\System32\wcmsvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) . (.Microsoft Corporation - Antimalware Service Executable.) - C:\Program Files\Windows Defender\MsMpEng.exe =>.Microsoft Corporation®
                  O23 - Service: C:\Windows\System32\wbem\wmisvc.dll (Winmgmt) . (.Microsoft Corporation - WMI.) - C:\Windows\System32\wbem\WMIsvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\wlansvc.dll (WlanSvc) . (.Microsoft Corporation - Windows WLAN AutoConfig Service DLL.) - C:\Windows\System32\wlansvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\wpnservice.dll (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) - C:\Windows\System32\WpnService.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\WpnUserService.dll (WpnUserService) . (.Microsoft Corporation - Windows Push Notification User Service.) - C:\Windows\System32\WpnUserService.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: Windows Push Notifications User Service_1725c86 (WpnUserService_1725c86) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Windows Publisher®
                  O23 - Service: C:\Windows\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) - C:\Windows\System32\wscsvc.dll [Unsigned] =>.Microsoft Corporation
                  O23 - Service: C:\Windows\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Microsoft Windows Search Indexer.) - C:\Windows\System32\SearchIndexer.exe [Unsigned] =>.Microsoft Corporation

                  —\ Services not Microsoft (SR=Run, SS=Stop) (65) - 8s
                  SR - Boot [12/04/2018] [ 107416] (3ware) . (.LSI.) - C:\Windows\System32\drivers\3ware.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 1135520] (ADP80XX) . (.PMC-Sierra.) - C:\Windows\System32\drivers\ADP80XX.SYS =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 83360] (amdsata) . (.Advanced Micro Devices.) - C:\Windows\System32\drivers\amdsata.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 259480] (amdsbs) . (.AMD Technologies Inc..) - C:\Windows\System32\drivers\amdsbs.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 27032] (amdxata) . (.Advanced Micro Devices.) - C:\Windows\System32\drivers\amdxata.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 132000] Adaptec SAS/SATA-II RAID S (arcsas) . (.PMC-Sierra, Inc..) - C:\Windows\System32\drivers\arcsas.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 533912] QLogic Network Adapter VBD (b06bdrv) . (.QLogic Corporation.) - C:\Windows\System32\drivers\bxvbda.sys =>.Microsoft Windows®
                  SR - Demand [20/07/2017] [ 47176] VirtIO Balloon Service (BALLOON) . (.Red Hat, Inc..) - C:\Windows\System32\drivers\balloon.sys {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
                  SR - Demand [12/04/2018] [ 9728] bcmfn2 Service (bcmfn2) . (…) - C:\Windows\System32\drivers\bcmfn2.sys [Unsigned] =>.Broadcom Corporation
                  SR - Boot [12/04/2018] [ 321432] (cht4iscsi) . (.Chelsio Communications.) - C:\Windows\System32\drivers\cht4sx64.sys =>.Microsoft Windows®
                  SR - Demand [12/04/2018] [ 1836952] Chelsio Virtual Bus Driver (cht4vbd) . (.Chelsio Communications.) - C:\Windows\System32\drivers\cht4vx64.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 3419032] QLogic 10 Gigabit Ethernet Ada (ebdrv) . (.QLogic Corporation.) - C:\Windows\System32\drivers\evbda.sys =>.Microsoft Windows®
                  SR - System [14/05/2017] [ 42616] ElbyCDIO Driver (ElbyCDIO) . (.Elaborate Bytes AG.) - C:\Windows\System32\Drivers\ElbyCDIO.sys =>.Microsoft Windows Hardware Compatibility Publisher®
                  SR - Boot [12/04/2018] [ 64408] (HpSAMD) . (.Hewlett-Packard Company.) - C:\Windows\System32\drivers\HpSAMD.sys =>.Microsoft Windows®
                  SR - Demand [12/04/2018] [ 36864] Intel Serial IO GPIO Controlle (iagpio) . (.Intel(R) Corporation.) - C:\Windows\System32\drivers\iagpio.sys [Unsigned] =>.Intel(R) Corporation
                  SR - Demand [12/04/2018] [ 91648] Intel(R) Serial IO I2C Host Cont (iai2c) . (.Intel(R) Corporation.) - C:\Windows\System32\drivers\iai2c.sys [Unsigned] =>.Intel(R) Corporation
                  SR - Demand [12/04/2018] [ 79360] Intel(R) S (iaLPSS2i_GPIO2) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [Unsigned] =>.Intel Corporation
                  SR - Demand [12/04/2018] [ 88576] In (iaLPSS2i_GPIO2_BXT_P) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSS2i_GPIO2_BXT_P.s ys [Unsigned] =>.Intel Corporation
                  SR - Demand [12/04/2018] [ 171520] Intel(R) Seria (iaLPSS2i_I2C) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [Unsigned] =>.Intel Corporation
                  SR - Demand [12/04/2018] [ 174592] Intel( (iaLPSS2i_I2C_BXT_P) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [Unsigned] =>.Intel Corporation
                  SR - Demand [12/04/2018] [ 38128] Intel(R) Serial IO (iaLPSSi_GPIO) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSSi_GPIO.sys =>.Intel Corporation - Client Components Group®
                  SR - Demand [12/04/2018] [ 113152] Intel(R) Serial IO I (iaLPSSi_I2C) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaLPSSi_I2C.sys [Unsigned] =>.Intel Corporation
                  SR - Boot [12/04/2018] [ 885144] Intel Chipset SATA RAI (iaStorAVC) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaStorAVC.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 412064] Intel RAID Controller Wi (iaStorV) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaStorV.sys =>.Microsoft Windows®
                  SR - Demand [12/04/2018] [ 526232] Mellanox InfiniBand Bus/A (ibbus) . (.Mellanox.) - C:\Windows\System32\drivers\ibbus.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 145816] (ItSas35i) . (.Avago Technologies.) - C:\Windows\System32\drivers\ItSas35i.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 108952] (LSI_SAS) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sas.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 124312] (LSI_SAS2i) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sas2i.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 128408] (LSI_SAS3i) . (.Avago Technologies.) - C:\Windows\System32\drivers\lsi_sas3i.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 82848] (LSI_SSS) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sss.sys =>.Microsoft Windows®
                  SR - Boot [08/08/2022] [ 21480] MbamElam (MbamElam) . (.Malwarebytes.) - C:\Windows\System32\DRIVERS\MbamElam.sys =>.Microsoft®
                  SS - Demand [08/08/2022] [ 8680192] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe =>.Malwarebytes Inc.®
                  SR - Demand [09/08/2022] [ 239544] MBAMSwissArmy (MBAMSwissArmy) . (.Malwarebytes.) - C:\Windows\System32\Drivers\mbamswissarmy.sys =>.Microsoft®
                  SR - Boot [12/04/2018] [ 59800] (megasas) . (.Avago Technologies.) - C:\Windows\System32\drivers\megasas.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 75160] (megasas2i) . (.Avago Technologies.) - C:\Windows\System32\drivers\MegaSas2i.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 82328] (megasas35i) . (.Avago Technologies.) - C:\Windows\System32\drivers\megasas35i.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 575896] (megasr) . (.LSI Corporation, Inc..) - C:\Windows\System32\drivers\megasr.sys =>.Microsoft Windows®
                  SR - Demand [12/04/2018] [ 842648] Mellanox ConnectX Bus E (mlx4_bus) . (.Mellanox.) - C:\Windows\System32\drivers\mlx4_bus.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 63904] (mvumis) . (.Marvell Semiconductor, Inc..) - C:\Windows\System32\drivers\mvumis.sys =>.Microsoft Windows®
                  SR - Demand [12/04/2018] [ 108952] NetworkDirect Service (ndfltr) . (.Mellanox.) - C:\Windows\System32\drivers\ndfltr.sys =>.Microsoft Windows®
                  SR - Auto [27/10/2017] [ 462968] NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe =>.NVIDIA Corporation®
                  SR - Demand [09/11/2017] [ 233904] Service for NVIDIA High Definiti (NVHDA) . (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvhda64v.sys =>.NVIDIA Corporation®
                  SR - Demand [09/11/2017] [16936048] (nvlddmkm) . (.NVIDIA Corporation.) - C:\Windows\System32\DriverStore\FileRepository\nv_ ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys =>.NVIDIA Corporation®
                  SR - Boot [12/04/2018] [ 150424] (nvraid) . (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvraid.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 166304] (nvstor) . (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvstor.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 58776] (percsas2i) . (.Avago Technologies.) - C:\Windows\System32\drivers\percsas2i.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 61848] (percsas3i) . (.Avago Technologies.) - C:\Windows\System32\drivers\percsas3i.sys =>.Microsoft Windows®
                  SR - Demand [12/04/2018] [ 604160] Realtek RT640 NT Dri (rt640x64) . (.Realtek.) - C:\Windows\System32\drivers\rt640x64.sys [Unsigned] =>.Realtek
                  SR - Demand [26/02/2019] [ 8287464] Realtek Wireless L (RtlWlanu) . (.Realtek Semiconductor Corporation.) - C:\Windows\System32\drivers\rtwlanu.sys =>.Realtek Semiconductor Corp.®
                  SR - Boot [12/04/2018] [ 44952] (SiSRaid2) . (.Silicon Integrated Systems Corp..) - C:\Windows\System32\drivers\SiSRaid2.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 81816] (SiSRaid4) . (.Silicon Integrated Systems.) - C:\Windows\System32\drivers\sisraid4.sys =>.Microsoft Windows®
                  SS - Demand [26/07/2022] [ 2663312] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\steamservice.exe =>.Valve Corp.®
                  SR - Boot [12/04/2018] [ 31128] (stexstor) . (.Promise Technology, Inc..) - C:\Windows\System32\drivers\stexstor.sys =>.Microsoft Windows®
                  SR - Demand [19/07/2022] [ 242656] VirtualBox NDIS 6.0 Miniport Service (VBoxNetAdp) . (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys =>.Oracle Corporation®
                  SR - System [19/07/2022] [ 252560] VirtualBox NDIS6 Bridge (VBoxNetLwf) . (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxNetLwf.sys =>.Oracle Corporation®
                  SS - Demand [19/07/2022] [ 748664] VirtualBox system service (VBoxSDS) . (.Oracle Corporation.) - C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe =>.Oracle Corporation®
                  SR - System [19/07/2022] [ 1081592] VirtualBox Service (VBoxSup) . (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxSup.sys =>.Oracle Corporation®
                  SR - System [19/07/2022] [ 191184] VirtualBox USB Monitor Service (VBoxUSBMon) . (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxUSBMon.sys =>.Oracle Corporation®
                  SR - Demand [22/02/2020] [ 44544] (VClone) . (.Elaborate Bytes AG.) - C:\Windows\System32\drivers\VClone.sys =>.Microsoft®
                  SR - Boot [20/07/2017] [ 40008] (viostor) . (.Red Hat, Inc..) - C:\Windows\System32\drivers\viostor.sys {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
                  SR - Demand [20/07/2017] [ 43080] VirtIO RNG Service (VirtRng) . (.Red Hat, Inc..) - C:\Windows\System32\drivers\viorng.sys {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
                  SR - Boot [12/04/2018] [ 166808] (vsmraid) . (.VIA Technologies Inc.,Ltd.) - C:\Windows\System32\drivers\vsmraid.sys =>.Microsoft Windows®
                  SR - Boot [12/04/2018] [ 305560] VIA StorX Storage RAID Co (VSTXRAID) . (.VIA Corporation.) - C:\Windows\System32\drivers\vstxraid.sys =>.Microsoft Windows®
                  SR - Demand [12/04/2018] [ 32152] WinMad Service (WinMad) . (.Mellanox.) - C:\Windows\System32\drivers\winmad.sys =>.Microsoft Windows®
                  SR - Demand [12/04/2018] [ 64920] WinVerbs Service (WinVerbs) . (.Mellanox.) - C:\Windows\System32\drivers\winverbs.sys =>.Microsoft Windows®

                  —\ Auto loading programs from Registry and folders (9) - 1s
                  O4 - HKLM..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Defender notification icon.) – C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Windows®
                  O4 - HKCU..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) – C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\ OneDrive.exe =>.Microsoft®
                  O4 - HKCU..\Run: [Steam] . (.Valve Corporation - Steam.) – C:\Program Files (x86)\Steam\steam.exe =>.Valve Corp.®
                  O4 - HKUS\S-1-5-19..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) – C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
                  O4 - HKUS\S-1-5-20..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) – C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
                  O4 - HKUS\S-1-5-19..\StartupApproved\Run: [OneDriveSetup] . (. - .) – 0x020000000000000000000000 =>.SUP.Orphan
                  O4 - HKUS\S-1-5-20..\StartupApproved\Run: [OneDriveSetup] . (. - .) – 0x020000000000000000000000 =>.SUP.Orphan
                  O4 - HKUS\S-1-5-21-3407470762-2713599730-1590247004-1001..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) – C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\ OneDrive.exe =>.Microsoft®
                  O4 - HKUS\S-1-5-21-3407470762-2713599730-1590247004-1001..\Run: [Steam] . (.Valve Corporation - Steam.) – C:\Program Files (x86)\Steam\steam.exe =>.Valve Corp.®

                  —\ Process running (17) - 3s
                  [MD5.025D6E81F4BF7E57FFDFCE132C98B8BA] - (.NVIDIA Corporation - NVIDIA Container.) – C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe [462968] [PID.6312] =>.NVIDIA Corporation®
                  [MD5.025D6E81F4BF7E57FFDFCE132C98B8BA] - (.NVIDIA Corporation - NVIDIA Container.) – C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe [462968] [PID.9316] =>.NVIDIA Corporation®
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.7948] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.9356] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.8072] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.6804] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.2564] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.744] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.9380] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.7696] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.9240] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.912] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.5500] [Unsigned] =>.Mozilla Corporation
                  [MD5.B026CE833592C42C8839BD784EA92463] - (.Nicolas Coolman - ZHPDiag.) – C:\Users\TeaTang\Desktop\ZHPDiag3.exe [3310792] [PID.6552] [Unsigned] =>.Nicolas Coolman
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.9748] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.1956] [Unsigned] =>.Mozilla Corporation
                  [MD5.065C52A5033EBE5521C704B5A9E001F4] - (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [660992] [PID.2084] [Unsigned] =>.Mozilla Corporation

                  —\ Internet Explorer Extensions, Start, Search (15) - 1s
                  R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
                  R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
                  R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
                  R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
                  R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
                  R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
                  R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
                  R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
                  R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
                  R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
                  R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
                  R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
                  R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
                  R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
                  R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Browser.) (11.00.17134.1 (WinBuild.160101.0800)) – C:\Windows\System32\ieframe.dll =>.Microsoft Corporation

                  —\ INTERNET EXPLORER, trusted site and sensitive site (100) - 1s
                  ~ IE Restricted Site Potentially Unwanted: 008i.com
                  ~ IE Restricted Site Potentially Unwanted: 008k.com
                  ~ IE Restricted Site Potentially Unwanted: 00hq.com
                  ~ IE Restricted Site Potentially Unwanted: 0190-dialers.com
                  ~ IE Restricted Site Potentially Unwanted: 01i.info
                  ~ IE Restricted Site Potentially Unwanted: 02pmnzy5eo29bfk4.com
                  ~ IE Restricted Site Potentially Unwanted: 0411dd.com
                  ~ IE Restricted Site Potentially Unwanted: 0511zfhl.com
                  ~ IE Restricted Site Potentially Unwanted: 05p.com
                  ~ IE Restricted Site Potentially Unwanted: 0632qyw.com
                  ~ IE Restricted Site Potentially Unwanted: 07ic5do2myz3vzpk.com
                  ~ IE Restricted Site Potentially Unwanted: 08nigbmwk43i01y6.com
                  ~ IE Restricted Site Potentially Unwanted: 093qpeuqpmz6ebfa.com
                  ~ IE Restricted Site Potentially Unwanted: 0calories.net
                  ~ IE Restricted Site Potentially Unwanted: 0cj.net
                  ~ IE Restricted Site Potentially Unwanted: 0scan.com
                  ~ IE Restricted Site Potentially Unwanted: 1-britney-spears-nude.com
                  ~ IE Restricted Site Potentially Unwanted: 1-domains-registrations.com
                  ~ IE Restricted Site Potentially Unwanted: 1-se.com
                  ~ IE Restricted Site Potentially Unwanted: 1001movie.com
                  ~ IE Restricted Site Potentially Unwanted: 1001night.biz
                  ~ IE Restricted Site Potentially Unwanted: 100gal.net
                  ~ IE Restricted Site Potentially Unwanted: 100sexlinks.com
                  ~ IE Restricted Site Potentially Unwanted: 101hotteens.com
                  ~ IE Restricted Site Potentially Unwanted: 101lottery.com
                  ~ IE Restricted Site Potentially Unwanted: 110hobart.com
                  ~ IE Restricted Site Potentially Unwanted: 114anhui.com
                  ~ IE Restricted Site Potentially Unwanted: 123expressview.com
                  ~ IE Restricted Site Potentially Unwanted: 123found.com
                  ~ IE Restricted Site Potentially Unwanted: 123keno.com
                  ~ IE Restricted Site Potentially Unwanted: 12don.info
                  ~ IE Restricted Site Potentially Unwanted: 1331675235.com
                  ~ IE Restricted Site Potentially Unwanted: 143fuck.com
                  ~ IE Restricted Site Potentially Unwanted: 17gamo.com
                  ~ IE Restricted Site Potentially Unwanted: 17webplace.com
                  ~ IE Restricted Site Potentially Unwanted: 180solutions.com
                  ~ IE Restricted Site Potentially Unwanted: 1autocity.com
                  ~ IE Restricted Site Potentially Unwanted: 1ive.net
                  ~ IE Restricted Site Potentially Unwanted: 1se.ru
                  ~ IE Restricted Site Potentially Unwanted: 1sexparty.com
                  ~ IE Restricted Site Potentially Unwanted: 1stfind.com
                  ~ IE Restricted Site Potentially Unwanted: 1stpagehere.com
                  ~ IE Restricted Site Potentially Unwanted: 1traff.us
                  ~ IE Restricted Site Potentially Unwanted: 1ze.net
                  ~ IE Restricted Site Potentially Unwanted: 2-antispyware.com
                  ~ IE Restricted Site Potentially Unwanted: 2004search.cc
                  ~ IE Restricted Site Potentially Unwanted: 2004synchronationals.org
                  ~ IE Restricted Site Potentially Unwanted: 2009download-best-soft.com
                  ~ IE Restricted Site Potentially Unwanted: 2019wyt.com
                  ~ IE Restricted Site Potentially Unwanted: 2020search.com
                  ~ IE Restricted Site Potentially Unwanted: 20health.com
                  ~ IE Restricted Site Potentially Unwanted: 20x2p.com
                  ~ IE Restricted Site Potentially Unwanted: 23drf.com
                  ~ IE Restricted Site Potentially Unwanted: 24-7find.com
                  ~ IE Restricted Site Potentially Unwanted: 24kstudio.net
                  ~ IE Restricted Site Potentially Unwanted: 24qas.info
                  ~ IE Restricted Site Potentially Unwanted: 24teen.com
                  ~ IE Restricted Site Potentially Unwanted: 2828hfdy.com
                  ~ IE Restricted Site Potentially Unwanted: 2pursuit.com
                  ~ IE Restricted Site Potentially Unwanted: 30search.com
                  ~ IE Restricted Site Potentially Unwanted: 31234.com
                  ~ IE Restricted Site Potentially Unwanted: 3344g.com
                  ~ IE Restricted Site Potentially Unwanted: 33search.cc
                  ~ IE Restricted Site Potentially Unwanted: 34f.com
                  ~ IE Restricted Site Potentially Unwanted: 34yo.com
                  ~ IE Restricted Site Potentially Unwanted: 356563.net
                  ~ IE Restricted Site Potentially Unwanted: 366ent.com
                  ~ IE Restricted Site Potentially Unwanted: 36site.com
                  ~ IE Restricted Site Potentially Unwanted: 3bomb.com
                  ~ IE Restricted Site Potentially Unwanted: 3d-downloadportal.net
                  ~ IE Restricted Site Potentially Unwanted: 3dxxx3d.com
                  ~ IE Restricted Site Potentially Unwanted: 3xpowered.com
                  ~ IE Restricted Site Potentially Unwanted: 4-counter.com
                  ~ IE Restricted Site Potentially Unwanted: 404dnserror.com
                  ~ IE Restricted Site Potentially Unwanted: 404dnspage.com
                  ~ IE Restricted Site Potentially Unwanted: 404dnswebsite.com
                  ~ IE Restricted Site Potentially Unwanted: 404mispage.com
                  ~ IE Restricted Site Potentially Unwanted: 4buy.net
                  ~ IE Restricted Site Potentially Unwanted: 4corn.net
                  ~ IE Restricted Site Potentially Unwanted: 4ourtraff.com
                  ~ IE Restricted Site Potentially Unwanted: 4pokertips.com
                  ~ IE Restricted Site Potentially Unwanted: 4uiokwnbe.com
                  ~ IE Restricted Site Potentially Unwanted: 50plus-login.com
                  ~ IE Restricted Site Potentially Unwanted: 515515.net
                  ~ IE Restricted Site Potentially Unwanted: 53ia49772x7r16ks.com
                  ~ IE Restricted Site Potentially Unwanted: 53t3ghkjksd.com
                  ~ IE Restricted Site Potentially Unwanted: 5foot.org
                  ~ IE Restricted Site Potentially Unwanted: 5hvx2m8sixttkn8a.com
                  ~ IE Restricted Site Potentially Unwanted: 5wheel.org
                  ~ IE Restricted Site Potentially Unwanted: 600pics.com
                  ~ IE Restricted Site Potentially Unwanted: 680130.net
                  ~ IE Restricted Site Potentially Unwanted: 69teenage.com
                  ~ IE Restricted Site Potentially Unwanted: 6bdsm.com
                  ~ IE Restricted Site Potentially Unwanted: 700xxx.com
                  ~ IE Restricted Site Potentially Unwanted: 75tz.com
                  ~ IE Restricted Site Potentially Unwanted: 76text-crypt.net
                  ~ IE Restricted Site Potentially Unwanted: 772123.com
                  ~ IE Restricted Site Potentially Unwanted: 777search.com
                  ~ IE Restricted Site Potentially Unwanted: 777top.com
                  ~ Microsoft Internet Explorer Restricted Site(s) Domains: 0(Good) / 6084(Bad)

                  —\ Internet Explorer, Proxy Management (3) - 0s
                  R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyEnable = 0 =>.Default.Value
                  R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,MigrateProxy = 1 =>.Default.Value
                  R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Para meters\Internet\ManualProxies =>.Microsoft

                  —\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
                  F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
                  F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
                  F2 - REG:system.ini: VMApplet=

                  —\ Hosts file redirection (2) - 0s
                  ~ Le fichier hôte est sain (The hosts file is clean) (21)
                  ~ Nombre lignes détournées ou corrompues 0/21 (Hosts file redirected or corrupted)

                  —\ Global shortcuts Startup (53) - 7s
                  O4 - GS\Desktop [Administrator]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Desktop [Administrator]: Discord.lnk . (.GitHub - Update.) C:\Users\TeaTang\AppData\Local\Discord\Update.exe --processStart Discord.exe =>.SUP.Discord
                  O4 - GS\Desktop [Administrator]: LibreWolf.lnk . (.Mozilla Corporation - LibreWolf.) C:\Program Files\LibreWolf\librewolf.exe [Unsigned] =>.Mozilla Corporation
                  O4 - GS\Desktop [Administrator]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPCleaner.ex e [Unsigned] =>.Nicolas Coolman
                  O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman
                  O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - Transfers files between device.) C:\Windows\System32\fsquirt.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Programs [Administrator]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Programs [Administrator]: Cyber Hunteruninstall.lnk . (.Netease - Cyber Hunter Uninstaller.) C:\Program Files (x86)\Cyber Hunter\uninstall.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Programs [Administrator]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\ OneDrive.exe =>.Microsoft®
                  O4 - GS\Desktop [Guest]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Desktop [Guest]: Discord.lnk . (.GitHub - Update.) C:\Users\TeaTang\AppData\Local\Discord\Update.exe --processStart Discord.exe =>.SUP.Discord
                  O4 - GS\Desktop [Guest]: LibreWolf.lnk . (.Mozilla Corporation - LibreWolf.) C:\Program Files\LibreWolf\librewolf.exe [Unsigned] =>.Mozilla Corporation
                  O4 - GS\Desktop [Guest]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPCleaner.ex e [Unsigned] =>.Nicolas Coolman
                  O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman
                  O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - Transfers files between device.) C:\Windows\System32\fsquirt.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Programs [Guest]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Programs [Guest]: Cyber Hunteruninstall.lnk . (.Netease - Cyber Hunter Uninstaller.) C:\Program Files (x86)\Cyber Hunter\uninstall.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Programs [Guest]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\ OneDrive.exe =>.Microsoft®
                  O4 - GS\Desktop [TeaTang]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Desktop [TeaTang]: Discord.lnk . (.GitHub - Update.) C:\Users\TeaTang\AppData\Local\Discord\Update.exe --processStart Discord.exe =>.SUP.Discord
                  O4 - GS\Desktop [TeaTang]: LibreWolf.lnk . (.Mozilla Corporation - LibreWolf.) C:\Program Files\LibreWolf\librewolf.exe [Unsigned] =>.Mozilla Corporation
                  O4 - GS\Desktop [TeaTang]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPCleaner.ex e [Unsigned] =>.Nicolas Coolman
                  O4 - GS\Desktop [TeaTang]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman
                  O4 - GS\sendTo [TeaTang]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - Transfers files between device.) C:\Windows\System32\fsquirt.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\sendTo [TeaTang]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Programs [TeaTang]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Programs [TeaTang]: Cyber Hunteruninstall.lnk . (.Netease - Cyber Hunter Uninstaller.) C:\Program Files (x86)\Cyber Hunter\uninstall.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Programs [TeaTang]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\ OneDrive.exe =>.Microsoft®
                  O4 - GS\CommonDesktop [Public]: 3D Vision Photo Viewer.lnk . (.NVIDIA Corporation - NVIDIA 3D Vision Photo Viewer.) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe =>.NVIDIA Corporation®
                  O4 - GS\CommonDesktop [Public]: AnyBurn.lnk . (.Power Software Ltd - AnyBurn.) C:\Program Files\AnyBurn\AnyBurn.exe {19EA4DAF089570861408E9F05EFD9B89}. =>.Power Software Ltd
                  O4 - GS\CommonDesktop [Public]: Malwarebytes.lnk . (.Malwarebytes - .) C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbam.exe [Unsigned] =>.Malwarebytes
                  O4 - GS\CommonDesktop [Public]: Oracle VM VirtualBox.lnk . (.Oracle Corporation - Oracle VM VirtualBox.) C:\Program Files (x86)\Oracle\VirtualBox\VirtualBox.exe [Unsigned] =>.Oracle Corporation
                  O4 - GS\CommonDesktop [Public]: Steam.lnk . (.Valve Corporation - Steam.) C:\Program Files (x86)\Steam\Steam.exe =>.Valve Corp.®
                  O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN®
                  O4 - GS\Programs [Public]: Cyber Hunter.lnk . (.NetEase - Cyber Hunter.) C:\Program Files (x86)\Cyber Hunter\launcher.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Programs [Public]: Cyber Hunteruninstall.lnk . (.Netease - Cyber Hunter Uninstaller.) C:\Program Files (x86)\Cyber Hunter\uninstall.exe {0A399503A667F69C5AFA53B47EDCC135}.
                  O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TeaTang\AppData\Local\Microsoft\OneDrive\ OneDrive.exe =>.Microsoft®
                  O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\internet explorer\iexplore.exe =>.Microsoft Corporation®
                  O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\Windows\system32\quickassist.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Steps Recorder.) C:\Windows\system32\psr.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 [Unsigned] =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\Windows\system32\charmap.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\Windows\System32\Control.exe [Unsigned] =>.Microsoft Corporation
                  O4 - GS\ProgramsCommon [Public]: Malwarebytes.lnk . (.Malwarebytes - .) C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbam.exe [Unsigned] =>.Malwarebytes

                  —\ Lop.com/Domain Hijackers (2) - 0s
                  O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
                  O17 - HKLM\System\CCS\Services\Tcpip..{2631d501-1595-41ba-a828-60c54973e613}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress

                  —\ Extra protocols (22) - 1s
                  O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) – C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) – C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) – C:\Windows\System32\inetcomm.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) – C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) – C:\Windows\System32\tbauth.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) – C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) – C:\Windows\System32\tbauth.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation
                  O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\System32\mscoree.dll [Unsigned] =>.Microsoft Corporation

                  —\ AppInit_DLLs Registry value Autorun (1) - 0s
                  O20 - Winlogon : UserInit . (.Microsoft Corporation - Userinit Logon Application.) - C:\Windows\system32\userinit.exe =>.Microsoft Corporation

                  —\ List of key exploring StartupApproved (8) - 0s
                  [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run]:OneDrive =>.Microsoft Corporation
                  [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run]:Steam =>.Valve
                  [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run]iscord =>.SUP.Discord
                  [HKEY_USERS\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run]:OneDrive =>.Microsoft Corporation
                  [HKEY_USERS\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run]:Steam =>.Valve
                  [HKEY_USERS\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run]iscord =>.SUP.Discord
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run]:SecurityHealth =>.Microsoft Corporation
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run]:AvastUI.exe =>.Avast Software s.r.o

                  —\ ASIC (ActiveSetup Installed Components) (5) - 1s
                  O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utilit.) – C:\Windows\System32\unregmp2.exe [Unsigned] =>.Microsoft Corporation
                  O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) – C:\Windows\System32\wmpdxm.dll [Unsigned] =>.Microsoft Corporation
                  O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utilit.) – C:\Windows\System32\unregmp2.exe [Unsigned] =>.Microsoft Corporation
                  O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe [Unsigned] =>.Microsoft Corporation
                  O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) – C:\Windows\System32\mscories.dll =>.Microsoft Corporation®

                  —\ Software installed (30) - 9s
                  O42 - Logiciel: 7-Zip 22.01 (x64) - (.Igor Pavlov.) [HKLM][64Bits] – 7-Zip [Unsigned] =>.Igor Pavlov
                  O42 - Logiciel: AnyBurn - (.Power Software Ltd.) [HKLM][64Bits] – AnyBurn [Unsigned] =>.Power Software Ltd
                  O42 - Logiciel: LibreWolf - (.LibreWolf.) [HKLM][64Bits] – LibreWolf LibreWolf [Unsigned]
                  O42 - Logiciel: Malwarebytes version 4.5.12.204 - (.Malwarebytes.) [HKLM][64Bits] – {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Inc.®
                  O42 - Logiciel: Microsoft Edge Update - (.Microsoft Corporation.) [HKLM][64Bits] – Microsoft Edge Update [Unsigned] =>.Microsoft Corporation
                  O42 - Logiciel: Microsoft Edge WebView2 Runtime - (.Microsoft Corporation.) [HKLM][64Bits] – Microsoft EdgeWebView =>.Microsoft®
                  O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] – OneDriveSetup.exe =>.Microsoft®
                  O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 - (.Microsoft Corporation.) [HKLM][64Bits] – {196BB40D-1578-3D01-B289-BEFC77A11A1E} [Unsigned] =>.Microsoft Corporation
                  O42 - Logiciel: Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.32.31332 - (.Microsoft Corporation.) [HKLM][64Bits] – {3746f21b-c990-4045-bb33-1cf98cff7a68} =>.Microsoft®
                  O42 - Logiciel: Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332 - (.Microsoft Corporation.) [HKLM][64Bits] – {F4499EE3-A166-496C-81BB-51D1BCDC70A9} [Unsigned] =>.Microsoft Corporation (Hidden)
                  O42 - Logiciel: Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332 - (.Microsoft Corporation.) [HKLM][64Bits] – {3407B900-37F5-4CC2-B612-5CD5D580A163} [Unsigned] =>.Microsoft Corporation (Hidden)
                  O42 - Logiciel: NVIDIA 3D Vision Driver 388.13 - (.NVIDIA Corporation.) [HKLM][64Bits] – {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision [Unsigned] =>.NVIDIA Corporation
                  O42 - Logiciel: NVIDIA Ansel - (.NVIDIA Corporation.) [HKLM][64Bits] – {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel [Unsigned] =>.NVIDIA Corporation (Hidden)
                  O42 - Logiciel: NVIDIA Control Panel 388.13 - (.NVIDIA Corporation.) [HKLM][64Bits] – {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel [Unsigned] =>.NVIDIA Corporation (Hidden)
                  O42 - Logiciel: NVIDIA Display Container - (.NVIDIA Corporation.) [HKLM][64Bits] – {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer [Unsigned] =>.NVIDIA Corporation (Hidden)
                  O42 - Logiciel: NVIDIA Display Container LS - (.NVIDIA Corporation.) [HKLM][64Bits] – {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS [Unsigned] =>.NVIDIA Corporation (Hidden)
                  O42 - Logiciel: NVIDIA Display Session Container - (.NVIDIA Corporation.) [HKLM][64Bits] – {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplaySessionContainer [Unsigned] =>.NVIDIA Corporation (Hidden)
                  O42 - Logiciel: NVIDIA Display Watchdog Plugin - (.NVIDIA Corporation.) [HKLM][64Bits] – {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayPluginWatchdog [Unsigned] =>.NVIDIA Corporation (Hidden)
                  O42 - Logiciel: NVIDIA Graphics Driver 388.13 - (.NVIDIA Corporation.) [HKLM][64Bits] – {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver [Unsigned] =>.NVIDIA Corporation
                  O42 - Logiciel: NVIDIA HD Audio Driver 1.3.35.1 - (.NVIDIA Corporation.) [HKLM][64Bits] – {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver [Unsigned] =>.NVIDIA Corporation
                  O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] – {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer [Unsigned] =>.NVIDIA Corporation (Hidden)
                  O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM][64Bits] – NVIDIAStereo =>.NVIDIA Corporation® (Hidden)
                  O42 - Logiciel: Oracle VM VirtualBox 6.1.36 - (.Oracle Corporation.) [HKLM][64Bits] – {8B78A2AB-34B5-4546-8CCF-B78C916BBD98} [Unsigned] =>.Oracle Corporation
                  O42 - Logiciel: Quake Champions - (.id Software.) [HKLM][64Bits] – Steam App 611500 =>.Valve Corp.®
                  O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM][64Bits] – Steam =>.Valve Corp.®
                  O42 - Logiciel: TP-Link TL-WN722N Driver - (.TP-Link.) [HKLM][64Bits] – {F9C15685-38A9-46A1-9826-97204015C19C} [Unsigned] =>.TP-LINK
                  O42 - Logiciel: Update for Windows 10 for x64-based Systems (KB4023057) - (.Microsoft Corporation.) [HKLM][64Bits] – {8F2D6CEB-BC98-4B69-A5C1-78BED238FE77} [Unsigned] =>.Microsoft Corporation (Hidden)
                  O42 - Logiciel: Update for Windows 10 for x64-based Systems (KB4480730) - (.Microsoft Corporation.) [HKLM][64Bits] – {0746492E-47B6-4251-940C-44462DFD74BB} [Unsigned] =>.Microsoft Corporation
                  O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] – VLC media player [Unsigned] =>.VideoLAN
                  O42 - Logiciel: Vulkan Run Time Libraries 1.0.61.0 - (.LunarG, Inc..) [HKLM][64Bits] – VulkanRT1.0.61.0 =>.LunarG, Inc.® (Hidden)

                  —\ HKCU & HKLM Software Keys (97) - 9s
                  HKLM\SOFTWARE\7-Zip =>.Igor Pavlov
                  HKLM\SOFTWARE\Avast Software =>.AVAST Software
                  HKLM\SOFTWARE\COMODO =>.Comodo
                  HKLM\SOFTWARE\Google =>.Google
                  HKLM\SOFTWARE\HitmanPro =>.EIDOS hitman Game
                  HKLM\SOFTWARE\Intel =>.Intel
                  HKLM\SOFTWARE\Khronos =>.Khronos
                  HKLM\SOFTWARE\KPRM
                  HKLM\SOFTWARE\Macromedia =>.Macromedia
                  HKLM\SOFTWARE\Malwarebytes =>.Malwarebytes
                  HKLM\SOFTWARE\Mozilla =>.Mozilla
                  HKLM\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
                  HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
                  HKLM\SOFTWARE\OEM =>.OEM
                  HKLM\SOFTWARE\Oracle =>.Oracle
                  HKLM\SOFTWARE\Partner =>.Google Inc.
                  HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
                  HKLM\SOFTWARE\TrendMicro =>.TrendMicro
                  HKLM\SOFTWARE\VideoLAN =>.VideoLan Team
                  HKLM\SOFTWARE\WOW6432Node =>.Microsoft Corporation
                  HKLM\SOFTWARE\WOW6432Node\Adware Removal Tool by TSA =>.TSA Softwares
                  HKLM\SOFTWARE\WOW6432Node\AMD =>.AMD
                  HKLM\SOFTWARE\WOW6432Node\AnyBurn
                  HKLM\SOFTWARE\WOW6432Node\Avast Software =>.AVAST Software
                  HKLM\SOFTWARE\WOW6432Node\Google =>.Google
                  HKLM\SOFTWARE\WOW6432Node\Id
                  HKLM\SOFTWARE\WOW6432Node\Intel =>.Intel
                  HKLM\SOFTWARE\WOW6432Node\Khronos =>.Khronos
                  HKLM\SOFTWARE\WOW6432Node\Licenses =>.Microsoft Corporation
                  HKLM\SOFTWARE\WOW6432Node\Macromedia =>.Macromedia
                  HKLM\SOFTWARE\WOW6432Node\Malwarebytes Anti-Rootkit =>.Malwarebytes
                  HKLM\SOFTWARE\WOW6432Node\MCPR
                  HKLM\SOFTWARE\WOW6432Node\MicroWorld =>.MicroWorld Technologies Inc.
                  HKLM\SOFTWARE\WOW6432Node\Mozilla =>.Mozilla
                  HKLM\SOFTWARE\WOW6432Node\MozillaPlugins =>.MozillaPlugins
                  HKLM\SOFTWARE\WOW6432Node\NVIDIA Corporation =>.nVidia Corporation
                  HKLM\SOFTWARE\WOW6432Node\ODBC =>.DB Connectivity Solutions
                  HKLM\SOFTWARE\WOW6432Node\TP-Link =>.TP-LINK
                  HKLM\SOFTWARE\WOW6432Node\TrendMicro =>.TrendMicro
                  HKLM\SOFTWARE\WOW6432Node\Valve =>.Valve
                  HKLM\SOFTWARE\WOW6432Node\RegisteredApplications =>.Microsoft Corporation
                  HKCU\SOFTWARE\7-Zip =>.Igor Pavlov
                  HKCU\SOFTWARE\AnyBurn
                  HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
                  HKCU\SOFTWARE\AVAST Software =>.AVAST Software
                  HKCU\SOFTWARE\Chromium =>.Chromium
                  HKCU\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes
                  HKCU\SOFTWARE\Geek Uninstaller =>.Geek Uninstaller
                  HKCU\SOFTWARE\GNU =>.GNU
                  HKCU\SOFTWARE\Google =>.Google
                  HKCU\SOFTWARE\LibreWolf
                  HKCU\SOFTWARE\Licenses =>.Microsoft Corporation
                  HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes
                  HKCU\SOFTWARE\MicroWorld =>.MicroWorld Technologies Inc.
                  HKCU\SOFTWARE\Netease
                  HKCU\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
                  HKCU\SOFTWARE\nwjs =>.NW.js
                  HKCU\SOFTWARE\Oracle =>.Oracle
                  HKCU\SOFTWARE\QtProject =>.QtProject
                  HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
                  HKCU\SOFTWARE\Smart Code ltd
                  HKCU\SOFTWARE\Sysinternals =>.Sysinternals
                  HKCU\SOFTWARE\The Silicon Realms Toolworks =>.The Silicon Realms Toolworks
                  HKCU\SOFTWARE\Trolltech =>.Trolltech
                  HKCU\SOFTWARE\Valve =>.Valve
                  HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
                  HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
                  HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
                  HKU.DEFAULT\SOFTWARE\Malwarebytes =>.Malwarebytes
                  HKU.DEFAULT\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
                  HKU.DEFAULT\SOFTWARE\SetID =>.Bitdefender
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\7-Zip =>.Igor Pavlov
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\AnyBurn
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\AppDataLow =>.Microsoft Corporation
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\AVAST Software =>.AVAST Software
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Chromium =>.Chromium
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Geek Uninstaller =>.Geek Uninstaller
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\GNU =>.GNU
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Google =>.Google
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\LibreWolf
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Licenses =>.Microsoft Corporation
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Malwarebytes =>.Malwarebytes
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\MicroWorld =>.MicroWorld Technologies Inc.
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Netease
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\nwjs =>.NW.js
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Oracle =>.Oracle
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\QtProject =>.QtProject
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Smart Code ltd
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Sysinternals =>.Sysinternals
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\The Silicon Realms Toolworks =>.The Silicon Realms Toolworks
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Trolltech =>.Trolltech
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Valve =>.Valve
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Wow6432Node =>.Microsoft Corporation
                  HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\ZHP =>.Nicolas Coolman

                  —\ Packages (1) - 0s
                  C:\Program Files (x86)\WindowsApps\325289AEDD75.TorrentRTFREE_1.1.1 1.0_x64__qtx9tqphctw9r - (.Vlasenko Bros..) [Torrent RT FREE]

                  —\ Contents of the Common Files folders (177) - 4s
                  O43 - CFD: 15/09/2022 - D – C:\Program Files\7-Zip =>.Igor Pavlov
                  O43 - CFD: 09/08/2022 - D – C:\Program Files\AnyBurn =>.Power Software Limited®
                  O43 - CFD: 01/10/2022 - D – C:\Program Files\Common Files =>.Microsoft Corporation
                  O43 - CFD: 09/08/2022 - D – C:\Program Files\CUAssistant
                  O43 - CFD: 23/09/2022 - D – C:\Program Files\FreeFixer
                  O43 - CFD: 09/08/2022 - D – C:\Program Files\internet explorer =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Program Files\LibreWolf [Unsigned]
                  O43 - CFD: 08/08/2022 - D – C:\Program Files\Malwarebytes =>.Malwarebytes
                  O43 - CFD: 12/07/2018 - D – C:\Program Files\MSBuild =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Program Files\NVIDIA Corporation =>.nVidia Corporation
                  O43 - CFD: 14/09/2022 - D – C:\Program Files\Oracle =>.Oracle
                  O43 - CFD: 12/07/2018 - D – C:\Program Files\Reference Assemblies =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Program Files\rempl =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Program Files\ruxim =>.Microsoft®
                  O43 - CFD: 08/08/2022 - [0] HD – C:\Program Files\Uninstall Information =>.Microsoft Corporation
                  O43 - CFD: 09/08/2022 - D – C:\Program Files\UNP =>.Microsoft Corporation
                  O43 - CFD: 23/09/2022 - D – C:\Program Files\VideoLAN =>.VideoLan Team
                  O43 - CFD: 09/08/2022 - RD – C:\Program Files\Windows Defender =>.Microsoft Corporation
                  O43 - CFD: 09/08/2022 - D – C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files\Windows Mail =>.Microsoft Corporation
                  O43 - CFD: 09/08/2022 - D – C:\Program Files\Windows Media Player =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files\windows nt =>.Microsoft Corporation
                  O43 - CFD: 09/08/2022 - D – C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files\Windows Security =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - SHD – C:\Program Files\Windows Sidebar =>.Microsoft Corporation
                  O43 - CFD: 04/10/2022 - HD – C:\Program Files\WindowsApps =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
                  O43 - CFD: 04/10/2022 - D – C:\Program Files (x86)\Adware Removal Tool by TSA =>.TSA Softwares
                  O43 - CFD: 23/09/2022 - D – C:\Program Files (x86)\Common Files =>.Microsoft Corporation
                  O43 - CFD: 06/09/2022 - D – C:\Program Files (x86)\Cyber Hunter {0A399503A667F69C5AFA53B47EDCC135}.
                  O43 - CFD: 12/08/2022 - [0] D – C:\Program Files (x86)\Elaborate Bytes =>.Elaborate Bytes
                  O43 - CFD: 08/08/2022 - HD – C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
                  O43 - CFD: 09/08/2022 - D – C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
                  O43 - CFD: 30/09/2022 - D – C:\Program Files (x86)\Microsoft =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
                  O43 - CFD: 30/09/2022 - D – C:\Program Files (x86)\Mplayer =>.Arpad Gereoffy
                  O43 - CFD: 12/07/2018 - D – C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Program Files (x86)\NVIDIA Corporation =>.nVidia Corporation
                  O43 - CFD: 12/07/2018 - D – C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
                  O43 - CFD: 01/10/2022 - D – C:\Program Files (x86)\Steam =>.Steam Games
                  O43 - CFD: 08/08/2022 - D – C:\Program Files (x86)\TP-Link =>.TP-LINK
                  O43 - CFD: 08/08/2022 - D – C:\Program Files (x86)\VulkanRT =>.LunarG, Inc
                  O43 - CFD: 09/08/2022 - D – C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
                  O43 - CFD: 09/08/2022 - D – C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files (x86)\windows nt =>.Microsoft Corporation
                  O43 - CFD: 09/08/2022 - D – C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - SHD – C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
                  O43 - CFD: 15/09/2022 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov
                  O43 - CFD: 12/04/2018 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
                  O43 - CFD: 12/07/2018 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
                  O43 - CFD: 09/08/2022 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyBurn
                  O43 - CFD: 12/04/2018 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation =>.nVidia Corporation
                  O43 - CFD: 14/09/2022 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox =>.Oracle
                  O43 - CFD: 12/04/2018 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
                  O43 - CFD: 11/08/2022 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games
                  O43 - CFD: 12/04/2018 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-Link =>.TP-LINK
                  O43 - CFD: 23/09/2022 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\ProgramData\Application Data =>.Microsoft Corporation
                  O43 - CFD: 01/10/2022 - D – C:\ProgramData\Avira =>.Avira Software
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\ProgramData\Desktop =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\ProgramData\Documents =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\Licenses =>.Microsoft Corporation
                  O43 - CFD: 09/08/2022 - D – C:\ProgramData\Malwarebytes =>.Malwarebytes
                  O43 - CFD: 09/08/2022 - [0] D – C:\ProgramData\Malwarebytes’ Anti-Malware (portable) =>.Malwarebytes
                  O43 - CFD: 30/09/2022 - SD – C:\ProgramData\Microsoft =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 =>.Mozilla Corporation
                  O43 - CFD: 04/10/2022 - D – C:\ProgramData\NVIDIA =>.nVidia Corporation
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\NVIDIA Corporation =>.nVidia Corporation
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\Package Cache =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\Packages =>.Microsoft Corporation
                  O43 - CFD: 04/10/2022 - D – C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - [0] D – C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\ProgramData\Start Menu =>.Microsoft Corporation
                  O43 - CFD: 30/09/2022 - [0] AD – C:\ProgramData\TEMP =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\ProgramData\Templates =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\TP-Link =>.TP-LINK
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\USOPrivate =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\ProgramData\USOShared =>.Microsoft Corporation
                  O43 - CFD: 16/09/2022 - D – C:\ProgramData\VirtualBox =>.Oracle
                  O43 - CFD: 12/04/2018 - D – C:\ProgramData\WindowsHolographicDevices =>.Microsoft Corporation
                  O43 - CFD: 17/08/2022 - D – C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
                  O43 - CFD: 23/09/2022 - [0] D – C:\Program Files (x86)\Common Files\MicroWorld =>.MicroWorld Technologies Inc.
                  O43 - CFD: 12/04/2018 - D – C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
                  O43 - CFD: 06/09/2022 - D – C:\Program Files (x86)\Common Files\Steam =>.Steam Games
                  O43 - CFD: 09/08/2022 - D – C:\Program Files (x86)\Common Files\system =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Roaming\Adobe =>.Adobe
                  O43 - CFD: 09/08/2022 - D – C:\Users\TeaTang\AppData\Roaming\anyburn
                  O43 - CFD: 06/09/2022 - D – C:\Users\TeaTang\AppData\Roaming\CC
                  O43 - CFD: 15/09/2022 - D – C:\Users\TeaTang\AppData\Roaming\discord
                  O43 - CFD: 22/09/2022 - D – C:\Users\TeaTang\AppData\Roaming\FreeFixer
                  O43 - CFD: 01/10/2022 - D – C:\Users\TeaTang\AppData\Roaming\Geek Uninstaller =>.Geek Uninstaller
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Roaming\librewolf
                  O43 - CFD: 16/09/2022 - SD – C:\Users\TeaTang\AppData\Roaming\Microsoft =>.Microsoft Corporation
                  O43 - CFD: 10/08/2022 - D – C:\Users\TeaTang\AppData\Roaming\Netease
                  O43 - CFD: 30/09/2022 - D – C:\Users\TeaTang\AppData\Roaming\vlc =>.VideoLan Team
                  O43 - CFD: 12/08/2022 - D – C:\Users\TeaTang\AppData\Roaming\Warsow 2.1
                  O43 - CFD: 04/10/2022 - D – C:\Users\TeaTang\AppData\Roaming\ZHP =>.Nicolas Coolman
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\Users\TeaTang\AppData\Local\Application Data =>.Microsoft Corporation
                  O43 - CFD: 01/10/2022 - D – C:\Users\TeaTang\AppData\Local\Avira =>.Avira Software
                  O43 - CFD: 11/08/2022 - D – C:\Users\TeaTang\AppData\Local\cache =>.Legitimate
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Local\CEF =>.CEF
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Local\Comms =>.Microsoft Corporation
                  O43 - CFD: 13/08/2022 - D – C:\Users\TeaTang\AppData\Local\ConnectedDevicesPla tform =>.Microsoft Corporation
                  O43 - CFD: 30/09/2022 - D – C:\Users\TeaTang\AppData\Local\CrashDumps =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Local\D3DSCache =>.Legitimate
                  O43 - CFD: 09/08/2022 - [0] D – C:\Users\TeaTang\AppData\Local\DBG =>.DBG
                  O43 - CFD: 14/09/2022 - D – C:\Users\TeaTang\AppData\Local\Diagnostics =>.Microsoft Corporation
                  O43 - CFD: 15/09/2022 - D – C:\Users\TeaTang\AppData\Local\Discord
                  O43 - CFD: 22/09/2022 - D – C:\Users\TeaTang\AppData\Local\FreeFixer
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\Users\TeaTang\AppData\Local\History =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Local\librewolf
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Local\mbam =>.Malwarebytes
                  O43 - CFD: 04/10/2022 - D – C:\Users\TeaTang\AppData\Local\Microsoft =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
                  O43 - CFD: 12/08/2022 - D – C:\Users\TeaTang\AppData\Local\NVIDIA =>.nVidia Corporation
                  O43 - CFD: 12/08/2022 - D – C:\Users\TeaTang\AppData\Local\OneDrive =>.Microsoft Corporation
                  O43 - CFD: 03/10/2022 - D – C:\Users\TeaTang\AppData\Local\Packages =>.Microsoft Corporation
                  O43 - CFD: 15/08/2022 - [0] D – C:\Users\TeaTang\AppData\Local\PeerDistRepub =>.Microsoft Corporation
                  O43 - CFD: 03/10/2022 - [0] D – C:\Users\TeaTang\AppData\Local\PlaceholderTileLogo Folder =>.Microsoft Corporation
                  O43 - CFD: 11/08/2022 - D – C:\Users\TeaTang\AppData\Local\Programs =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Local\Publishers =>.Microsoft Corporation
                  O43 - CFD: 14/09/2022 - D – C:\Users\TeaTang\AppData\Local\SquirrelTemp =>.Squirrels
                  O43 - CFD: 11/08/2022 - D – C:\Users\TeaTang\AppData\Local\Steam =>.Steam Games
                  O43 - CFD: 04/10/2022 - D – C:\Users\TeaTang\AppData\Local\Temp =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\Users\TeaTang\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Local\TP-Link =>.TP-LINK
                  O43 - CFD: 10/08/2022 - D – C:\Users\TeaTang\AppData\Local\UniCompactView
                  O43 - CFD: 10/08/2022 - D – C:\Users\TeaTang\AppData\Local\UniSDK
                  O43 - CFD: 12/08/2022 - D – C:\Users\TeaTang\AppData\Local\VirtualStore =>.Microsoft Corporation
                  O43 - CFD: 04/10/2022 - D – C:\Users\TeaTang\AppData\Local\ZHP =>.Nicolas Coolman
                  O43 - CFD: 08/08/2022 - [0] D – C:\Users\TeaTang\AppData\Local\Programs\Common =>.Microsoft Corporation
                  O43 - CFD: 29/08/2022 - [0] D – C:\Users\TeaTang\AppData\Local\Programs\LNV
                  O43 - CFD: 28/08/2022 - SD – C:\Users\TeaTang\AppData\LocalLow\Microsoft =>.Microsoft Corporation
                  O43 - CFD: 04/10/2022 - D – C:\Users\TeaTang\AppData\LocalLow\Mozilla =>.Mozilla Corporation
                  O43 - CFD: 01/10/2022 - D – C:\Users\TeaTang\Desktop\AutoLogger
                  O43 - CFD: 01/10/2022 - D – C:\Users\TeaTang\Desktop\AVbr
                  O43 - CFD: 02/10/2022 - [0] D – C:\Users\TeaTang\Desktop\ClearLNK
                  O43 - CFD: 15/09/2022 - D – C:\Users\TeaTang\Desktop\FuguIta-7.1-amd64-202209131.img
                  O43 - CFD: 15/09/2022 - D – C:\Users\TeaTang\Desktop\FuguIta-7.1-amd64-202209131.iso
                  O43 - CFD: 01/10/2022 - D – C:\Users\TeaTang\Desktop\geek
                  O43 - CFD: 28/08/2022 - D – C:\Users\TeaTang\Desktop\How to disable the AutoRun feature in Windows 10_files
                  O43 - CFD: 04/10/2022 - D – C:\Users\TeaTang\Desktop\KillEmAll
                  O43 - CFD: 02/10/2022 - D – C:\Users\TeaTang\Desktop\LOG =>.Unknown
                  O43 - CFD: 04/10/2022 - D – C:\Users\TeaTang\Desktop\New folder
                  O43 - CFD: 04/10/2022 - D – C:\Users\TeaTang\Desktop\ProcessExplorer
                  O43 - CFD: 28/08/2022 - D – C:\Users\TeaTang\Desktop\Three Methods to Disable AutoRun in Windows 10_files
                  O43 - CFD: 12/04/2018 - RD – C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessibility =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - RD – C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - RD – C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Administrative Tools =>.Administrative Tools
                  O43 - CFD: 08/08/2022 - D – C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\LibreWolf
                  O43 - CFD: 12/04/2018 - D – C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Maintenance =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - RD – C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Startup =>.Microsoft Corporation
                  O43 - CFD: 13/08/2022 - D – C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Steam =>.Steam Games
                  O43 - CFD: 12/04/2018 - RD – C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\System Tools =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - RD – C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - [0] D – C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - D – C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
                  O43 - CFD: 12/04/2018 - [0] D – C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - [0] SHD – C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
                  O43 - CFD: 08/08/2022 - D – C:\Windows\System32\Config\systemprofile\AppData\L ocal\Microsoft =>.Microsoft Corporation
                  O43 - CFD: 01/10/2022 - – C:\Windows\System32\Config\systemprofile\AppData\L ocal\Programs =>.Microsoft Corporation

                  —\ ShellIconOverlayIdentifiers (SIOI) (2) - 0s
                  O106 - SIOI: [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) – C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation
                  O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - Client Side Caching UI.) – C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation

                  —\ Search Context Menu Handlers (SCMH) (31) - 3s
                  O108 - CMH1: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) – C:\Program Files\7-Zip\7-zip.dll [Unsigned] =>.Igor Pavlov
                  O108 - CMH1: EPP [64Bits] - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Microsoft Security Client Shell Extension.) – C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows®
                  O108 - CMH1: ModernSharing [64Bits] - {e2bf9676-5f8f-435c-97eb-11607a5bedf7} . (.Microsoft Corporation - Shell extensions for sharing.) – C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
                  O108 - CMH1: Open With [64Bits] - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - Windows Shell Common Dll.) – C:\Windows\System32\shell32.dll =>.Microsoft Windows®
                  O108 - CMH1: Open With EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - Windows Shell Common Dll.) – C:\Windows\System32\shell32.dll =>.Microsoft Windows®
                  O108 - CMH1: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) – C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
                  O108 - CMH1: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Microsoft (C) Work Folders Shell Extension.) – C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
                  O108 - CMH2: NvAppShExt [64Bits] - {A929C4CE-FD36-4270-B4F5-34ECAC5BD63C} . (.NVIDIA Corporation - NVIDIA Shell Extensions.) – C:\Windows\system32\nv3dappshext.dll [Unsigned] =>.NVIDIA Corporation
                  O108 - CMH2: OpenContainingFolderMenu [64Bits] - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - Windows Shell Common Dll.) – C:\Windows\System32\shell32.dll =>.Microsoft Windows®
                  O108 - CMH2: OpenGLShExt [64Bits] - {E97DEC16-A50D-49bb-AE24-CF682282E08D} . (.NVIDIA Corporation - NVIDIA Shell Extensions.) – C:\Windows\system32\nv3dappshext.dll [Unsigned] =>.NVIDIA Corporation
                  O108 - CMH3: CopyAsPathMenu [64Bits] - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - Windows Shell Common Dll.) – C:\Windows\System32\shell32.dll =>.Microsoft Windows®
                  O108 - CMH3: MBAMShlExt [64Bits] - {57CE581A-0CB6-4266-9CA0-19364C90A0B3} . (.Malwarebytes - Malwarebytes.) – C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll =>.Malwarebytes Inc.®
                  O108 - CMH3: SendTo [64Bits] - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - Windows Shell Common Dll.) – C:\Windows\System32\shell32.dll =>.Microsoft Windows®
                  O108 - CMH4: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) – C:\Program Files\7-Zip\7-zip.dll [Unsigned] =>.Igor Pavlov
                  O108 - CMH4: EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - Windows Shell Common Dll.) – C:\Windows\System32\shell32.dll =>.Microsoft Windows®
                  O108 - CMH4: EPP [64Bits] - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Microsoft Security Client Shell Extension.) – C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows®
                  O108 - CMH4: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - Client Side Caching UI.) – C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation
                  O108 - CMH4: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) – C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
                  O108 - CMH4: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Microsoft (C) Work Folders Shell Extension.) – C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
                  O108 - CMH5: New [64Bits] - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - Windows Shell Common Dll.) – C:\Windows\System32\shell32.dll =>.Microsoft Windows®
                  O108 - CMH5: NvCplDesktopContext [64Bits] - {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} . (.NVIDIA Corporation - NVIDIA Display Shell Extension.) – C:\Windows\System32\nvshext.dll [Unsigned] =>.NVIDIA Corporation
                  O108 - CMH5: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) – C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation
                  O108 - CMH5: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Microsoft (C) Work Folders Shell Extension.) – C:\Windows\System32\WorkfoldersShell.dll [Unsigned] =>.Microsoft Corporation
                  O108 - CMH6: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) – C:\Program Files\7-Zip\7-zip.dll [Unsigned] =>.Igor Pavlov
                  O108 - CMH6: Library Location [64Bits] - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - Windows Shell Common Dll.) – C:\Windows\System32\shell32.dll =>.Microsoft Windows®
                  O108 - CMH6: MBAMShlExt [64Bits] - {57CE581A-0CB6-4266-9CA0-19364C90A0B3} . (.Malwarebytes - Malwarebytes.) – C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll =>.Malwarebytes Inc.®
                  O108 - CMH6: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - Client Side Caching UI.) – C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation
                  O108 - CMH6: PintoStartScreen [64Bits] - {470C0EBD-5D73-4d58-9CED-E91E22E23282} . (.Microsoft Corporation - App Resolver.) – C:\Windows\System32\appresolver.dll =>.Microsoft Windows®
                  O108 - CMH7: EnhancedStorageShell [64Bits] - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) – C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation
                  O108 - CMH7: EPP [64Bits] - {09A47860-11B0-4DA5-AFA5-26D86198A780} . (.Microsoft Corporation - Microsoft Security Client Shell Extension.) – C:\Program Files\Windows Defender\shellext.dll =>.Microsoft Windows®
                  O108 - CMH7: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) – C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation

                  —\ Image File Execution Options (11) - 0s
                  O50 - IFEO:C:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - IE Per-User Initialization Utility.) [MitigationOptions\256] [Unsigned] =>.Microsoft Corporation
                  O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - IE 7.0 Unattended Install Utility.) [MitigationOptions\256] [Unsigned] =>.Microsoft Corporation
                  O50 - IFEO:C:\Windows\System32\MRT.exe - (.Microsoft Corporation - Microsoft Windows Malicious Software Remova.) [CFGOptions\1] [Unsigned] =>.Microsoft Corporation
                  O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\256] [Unsigned] =>.Microsoft Corporation
                  O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Microsoft (R) HTML Application host.) [MitigationOptions\256] [Unsigned] =>.Microsoft Corporation
                  O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\1118481] [Unsigned] =>.Microsoft Corporation
                  O50 - IFEO:C:\Windows\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\2097152] [Unsigned] =>.Microsoft Corporation
                  O50 - IFEO:C:\Windows\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\4294967296] [Unsigned] =>.Microsoft Corporation
                  O50 - IFEO:C:\Windows\System32\spoolsv.exe - (.Microsoft Corporation - Spooler SubSystem App.) [MitigationOptions\2097152] [Unsigned] =>.Microsoft Corporation
                  O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Host Process for Windows Services.) [MinimumStackCommitInBytes\32768] =>.Microsoft Windows Publisher®
                  O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Host Process for Windows Services.) [MitigationAuditOptions\17660905521152] =>.Microsoft Windows Publisher®

                  —\ System Drivers List (415) - 16s
                  O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - 1394 OpenHCI Driver.) – C:\Windows\System32\drivers\1394ohci.sys [237568] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.LSI - LSI 3ware SCSI Storport Driver.) – C:\Windows\System32\drivers\3ware.sys [107416] =>.Microsoft Windows®
                  O58 - SDL:2022/08/09 17:03:49 A . (.Malwarebytes - Malwarebytes SwissArmy.) – C:\Windows\System32\drivers\6247C596.sys [255928] =>.Malwarebytes Corporation®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ACPI Driver for NT.) – C:\Windows\System32\drivers\acpi.sys [654232] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - ACPI Devices Driver.) – C:\Windows\System32\drivers\AcpiDev.sys [20480] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - ACPIEx Driver.) – C:\Windows\System32\drivers\acpiex.sys [127904] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ACPI Processor Aggregator Device Driver.) – C:\Windows\System32\drivers\acpipagr.sys [12800] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - ACPI Power Metering Driver.) – C:\Windows\System32\drivers\acpipmi.sys [14848] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ACPI Wake Alarm.) – C:\Windows\System32\drivers\acpitime.sys [13824] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) – C:\Windows\System32\drivers\adp80xx.sys [1135520] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) – C:\Windows\System32\drivers\afd.sys [626592] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - AF_UNIX socket provider.) – C:\Windows\System32\drivers\afunix.sys [39424] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - RAS Agile Vpn Miniport Call Manager.) – C:\Windows\System32\drivers\agilevpn.sys [108032] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:28 A . (.Microsoft Corporation - Application Compatibility Cache.) – C:\Windows\System32\drivers\ahcache.sys [254464] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Processor Device Driver.) – C:\Windows\System32\drivers\amdk8.sys [181760] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Processor Device Driver.) – C:\Windows\System32\drivers\amdppm.sys [179712] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) – C:\Windows\System32\drivers\amdsata.sys [83360] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) – C:\Windows\System32\drivers\amdsbs.sys [259480] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.Advanced Micro Devices - Storage Filter Driver.) – C:\Windows\System32\drivers\amdxata.sys [27032] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:19 A . (.Microsoft Corporation - AppID Driver.) – C:\Windows\System32\drivers\appid.sys [192928] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:19 A . (.Microsoft Corporation - Applocker Filter.) – C:\Windows\System32\drivers\applockerfltr.sys [18432] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 12:20:20 A . (.Microsoft Corporation - Microsoft Application Virtualization Stream.) – C:\Windows\System32\drivers\AppVStrm.sys [127384] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 12:20:20 A . (.Microsoft Corporation - Microsoft Application Virtualization VE Man.) – C:\Windows\System32\drivers\AppvVemgr.sys [162712] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 12:20:20 A . (.Microsoft Corporation - Microsoft Application Virtualization VFS Fi.) – C:\Windows\System32\drivers\AppvVfs.sys [143768] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) – C:\Windows\System32\drivers\arcsas.sys [132000] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - MS Remote Access serial network driver.) – C:\Windows\System32\drivers\asyncmac.sys [28672] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ATAPI IDE Miniport Driver.) – C:\Windows\System32\drivers\atapi.sys [28568] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ATAPI Driver Extension.) – C:\Windows\System32\drivers\ataport.sys [194976] =>.Microsoft Windows®
                  O58 - SDL:2017/07/20 05:46:00 A . (.Red Hat, Inc. - Red Hat VirtIO Balloon driver.) – C:\Windows\System32\drivers\balloon.sys [47176] {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
                  O58 - SDL:2018/04/12 02:34:40 A . (.Microsoft Corporation - BAM Kernel Driver.) – C:\Windows\System32\drivers\bam.sys [60320] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft Basic Display Driver.) – C:\Windows\System32\drivers\BasicDisplay.sys [63488] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft Basic Render Driver.) – C:\Windows\System32\drivers\BasicRender.sys [34816] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Battery Class Driver.) – C:\Windows\System32\drivers\battc.sys [39840] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (. - BCM Function 2 Device Driver.) – C:\Windows\System32\drivers\bcmfn2.sys [9728] [Unsigned] =>.Broadcom Corporation
                  O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - BEEP Driver.) – C:\Windows\System32\drivers\beep.sys [10240] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - Windows Bind Filter Driver.) – C:\Windows\System32\drivers\bindflt.sys [92056] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:58 A . (.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) – C:\Windows\System32\drivers\bowser.sys [101888] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - MAC Bridge Driver.) – C:\Windows\System32\drivers\bridge.sys [116736] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Microsoft Bluetooth Audio Multiprofile Mana.) – C:\Windows\System32\drivers\BtaMPM.sys [33792] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Bluetooth Hands-Free Audio and Call Control.) – C:\Windows\System32\drivers\bthhfenum.sys [112128] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - Bluetooth Communications Driver.) – C:\Windows\System32\drivers\bthmodem.sys [67072] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - VHD BTT Filter Driver.) – C:\Windows\System32\drivers\bttflt.sys [38304] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Button Converter Driver.) – C:\Windows\System32\drivers\buttonconverter.sys [39936] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) – C:\Windows\System32\drivers\bxvbda.sys [533912] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - Charge Arbiration Driver.) – C:\Windows\System32\drivers\CAD.sys [60320] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - CapImg HID Driver.) – C:\Windows\System32\drivers\capimg.sys [123392] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - CD-ROM File System Driver.) – C:\Windows\System32\drivers\cdfs.sys [93696] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - SCSI CD-ROM Driver.) – C:\Windows\System32\drivers\cdrom.sys [159744] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - Event Aggregation Kernel Mode Library.) – C:\Windows\System32\drivers\CEA.sys [78752] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) – C:\Windows\System32\drivers\cht4dx64.sys [143768] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) – C:\Windows\System32\drivers\cht4sx64.sys [321432] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Chelsio Communications - VF library for Chelsio ® T5/T6 Chipset.) – C:\Windows\System32\drivers\cht4vfx.sys [29184] [Unsigned] =>.Chelsio Communications
                  O58 - SDL:2018/04/12 02:33:49 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T5/T6 Chip.) – C:\Windows\System32\drivers\cht4vx64.sys [1836952] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - Consumer IR Class Driver for eHome.) – C:\Windows\System32\drivers\circlass.sys [49152] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - SCSI Class System Dll.) – C:\Windows\System32\drivers\Classpnp.sys [413600] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Cloud Files Mini Filter Driver.) – C:\Windows\System32\drivers\cldflt.sys [414208] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:22 A . (.Microsoft Corporation - Common Log File System Driver.) – C:\Windows\System32\drivers\clfs.sys [382872] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - CLIP Service.) – C:\Windows\System32\drivers\ClipSp.sys [1018784] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Control Method Battery Driver.) – C:\Windows\System32\drivers\CmBatt.sys [32256] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Kernel Configuration Manager Initial Config.) – C:\Windows\System32\drivers\cmimcext.sys [28576] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:22 A . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) – C:\Windows\System32\drivers\cng.sys [709824] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - CNG Hardware Assist algorithm provider.) – C:\Windows\System32\drivers\cnghwassist.sys [39328] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - Console Driver.) – C:\Windows\System32\drivers\condrv.sys [55200] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:51 A . (.Microsoft Corporation - Crash Dump Driver.) – C:\Windows\System32\drivers\crashdmp.sys [88472] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 12:20:19 A . (.Microsoft Corporation - Windows Client Side Caching Driver.) – C:\Windows\System32\drivers\csc.sys [561152] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:40 A . (.Microsoft Corporation - DAM Kernel Driver.) – C:\Windows\System32\drivers\dam.sys [91544] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Xbox Device Authentication Driver.) – C:\Windows\System32\drivers\devauthe.sys [45568] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - DFS Namespace Client Driver.) – C:\Windows\System32\drivers\dfsc.sys [141312] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - PnP Disk Driver.) – C:\Windows\System32\drivers\disk.sys [94112] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - Crash Dump Disk Driver.) – C:\Windows\System32\drivers\Diskdump.sys [39328] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Boot Over USB Dump Driver.) – C:\Windows\System32\drivers\Dmpusbstor.sys [15360] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Dynamic Memory.) – C:\Windows\System32\drivers\dmvsc.sys [47104] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:46 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) – C:\Windows\System32\drivers\drmk.sys [98304] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:46 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) – C:\Windows\System32\drivers\drmkaud.sys [16232] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - ATAPI Dump Driver.) – C:\Windows\System32\drivers\Dumpata.sys [36256] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:35:21 A . (.Microsoft Corporation - Bitlocker Drive Encryption Crashdump Filter.) – C:\Windows\System32\drivers\dumpfve.sys [91664] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - SD Crashdump Port Driver.) – C:\Windows\System32\drivers\dumpsd.sys [188832] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - SD Host Controller Crashdump Port Driver.) – C:\Windows\System32\drivers\dumpsdport.sys [32256] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Storport Dump Driver.) – C:\Windows\System32\drivers\Dumpstorport.sys [25600] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:33 A . (.Microsoft Corporation - DirectX Graphics Kernel.) – C:\Windows\System32\drivers\dxgkrnl.sys [2830240] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:33 A . (.Microsoft Corporation - DirectX Graphics MMS.) – C:\Windows\System32\drivers\dxgmms1.sys [413080] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:33 A . (.Microsoft Corporation - DirectX Graphics MMS.) – C:\Windows\System32\drivers\dxgmms2.sys [792984] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:25 A . (.Microsoft Corporation - Enhanced Storage Class driver for IEEE 1667.) – C:\Windows\System32\drivers\EhStorClass.sys [88472] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - Microsoft driver for storage devices suppor.) – C:\Windows\System32\drivers\EhStorTcgDrv.sys [118680] =>.Microsoft Windows®
                  O58 - SDL:2017/05/14 19:29:02 A . (.Elaborate Bytes AG - ElbyCD Windows x64 I/O driver.) – C:\Windows\System32\drivers\ElbyCDIO.sys [42616] =>.Microsoft Windows Hardware Compatibility Publisher®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Error Device Driver.) – C:\Windows\System32\drivers\errdev.sys [13824] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.QLogic Corporation - QLogic 10 GigE VBD.) – C:\Windows\System32\drivers\evbda.sys [3419032] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - Microsoft Extended FAT File System.) – C:\Windows\System32\drivers\exfat.sys [357888] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - Fast FAT File System Driver.) – C:\Windows\System32\drivers\fastfat.sys [375200] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Floppy Disk Controller Driver.) – C:\Windows\System32\drivers\fdc.sys [32768] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Windows sandboxing and encryption filter.) – C:\Windows\System32\drivers\filecrypt.sys [55808] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - FileInfo Filter Driver.) – C:\Windows\System32\drivers\fileinfo.sys [86432] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - File Trace Filter Driver.) – C:\Windows\System32\drivers\filetrace.sys [36352] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Floppy Driver.) – C:\Windows\System32\drivers\flpydisk.sys [26624] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Microsoft Filesystem Filter Manager.) – C:\Windows\System32\drivers\fltMgr.sys [402848] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - File System Dependency Manager Mini Filter.) – C:\Windows\System32\drivers\fsdepends.sys [62872] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - File System Recognizer Driver.) – C:\Windows\System32\drivers\fs_rec.sys [34208] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:35:21 A . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) – C:\Windows\System32\drivers\fvevol.sys [744864] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) – C:\Windows\System32\drivers\FWPKCLNT.SYS [466840] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Generic USB Function Class Driver.) – C:\Windows\System32\drivers\genericusbfn.sys [20992] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - GPU Energy Kernel Driver.) – C:\Windows\System32\drivers\gpuenergydrv.sys [8192] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - High Definition Audio Bus Driver.) – C:\Windows\System32\drivers\hdaudbus.sys [86016] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - High Definition Audio Function Driver.) – C:\Windows\System32\drivers\HdAudio.sys [436736] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Hid Battery Driver.) – C:\Windows\System32\drivers\hidbatt.sys [38304] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Bluetooth Miniport Driver for HID Devices.) – C:\Windows\System32\drivers\hidbth.sys [115200] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Hid Class Library.) – C:\Windows\System32\drivers\hidclass.sys [173568] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - I2C HID Miniport Driver.) – C:\Windows\System32\drivers\hidi2c.sys [54272] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - HID Button over Interrupt Driver.) – C:\Windows\System32\drivers\hidinterrupt.sys [50592] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - Infrared Miniport Driver for Input Devices.) – C:\Windows\System32\drivers\hidir.sys [47104] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Hid Parsing Library.) – C:\Windows\System32\drivers\hidparse.sys [46080] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) – C:\Windows\System32\drivers\hidusb.sys [42496] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) – C:\Windows\System32\drivers\HpSAMD.sys [64408] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:22 A . (.Microsoft Corporation - HTTP Protocol Stack.) – C:\Windows\System32\drivers\http.sys [1026464] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Hyper-V Crashdump.) – C:\Windows\System32\drivers\hvcrash.sys [33184] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Hypervisor Boot Driver.) – C:\Windows\System32\drivers\hvservice.sys [73632] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Microsoft Hyper-V Socket Provider.) – C:\Windows\System32\drivers\hvsocket.sys [130456] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Hardware Policy Driver.) – C:\Windows\System32\drivers\hwpolicy.sys [29592] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft VMBus Synthetic Keyboard Driver.) – C:\Windows\System32\drivers\hyperkbd.sys [16896] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft VMBus Video Device Miniport Drive.) – C:\Windows\System32\drivers\HyperVideo.sys [28672] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - i8042 Port Driver.) – C:\Windows\System32\drivers\i8042prt.sys [105984] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:45 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) – C:\Windows\System32\drivers\iagpio.sys [36864] [Unsigned] =>.Intel(R) Corporation
                  O58 - SDL:2018/04/12 02:33:45 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) – C:\Windows\System32\drivers\iai2c.sys [91648] [Unsigned] =>.Intel(R) Corporation
                  O58 - SDL:2018/04/12 02:33:45 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) – C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [79360] [Unsigned] =>.Intel Corporation
                  O58 - SDL:2018/04/12 02:33:45 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) – C:\Windows\System32\drivers\iaLPSS2i_GPIO2_BXT_P.s ys [88576] [Unsigned] =>.Intel Corporation
                  O58 - SDL:2018/04/12 02:33:45 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) – C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [171520] [Unsigned] =>.Intel Corporation
                  O58 - SDL:2018/04/12 02:33:45 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) – C:\Windows\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [174592] [Unsigned] =>.Intel Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) – C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
                  O58 - SDL:2018/04/12 02:33:45 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) – C:\Windows\System32\drivers\iaLPSSi_I2C.sys [113152] [Unsigned] =>.Intel Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) – C:\Windows\System32\drivers\iaStorAVC.sys [885144] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) – C:\Windows\System32\drivers\iaStorV.sys [412064] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Mellanox - InfiniBand Fabric Bus Driver.) – C:\Windows\System32\drivers\ibbus.sys [526232] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Indirect displays kernel-mode filter driver.) – C:\Windows\System32\drivers\IndirectKmd.sys [38912] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Intel PCI IDE Driver.) – C:\Windows\System32\drivers\intelide.sys [19360] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - Intel Power Engine Plugin.) – C:\Windows\System32\drivers\intelpep.sys [177192] =>.Microsoft Windows Hardware Abstraction Layer Publisher®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Processor Device Driver.) – C:\Windows\System32\drivers\intelppm.sys [200704] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - I/O rate control Filter.) – C:\Windows\System32\drivers\iorate.sys [58272] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - IP FILTER DRIVER.) – C:\Windows\System32\drivers\ipfltdrv.sys [85504] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - WMI IPMI DRIVER.) – C:\Windows\System32\drivers\IPMIDrv.sys [92064] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - IP Network Address Translator.) – C:\Windows\System32\drivers\ipnat.sys [214528] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - IPT Driver.) – C:\Windows\System32\drivers\ipt.sys [32256] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - IRDA Protocol Driver.) – C:\Windows\System32\drivers\irda.sys [119808] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:41 A . (.Microsoft Corporation - Infra-Red Bus Enumerator.) – C:\Windows\System32\drivers\irenum.sys [19968] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - PNP ISA Bus Driver.) – C:\Windows\System32\drivers\isapnp.sys [22944] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.Avago Technologies - Avago SAS Gen3.5 Driver (StorPort).) – C:\Windows\System32\drivers\ItSas35i.sys [145816] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Keyboard Class Driver.) – C:\Windows\System32\drivers\kbdclass.sys [63904] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - HID Keyboard Filter Driver.) – C:\Windows\System32\drivers\kbdhid.sys [40448] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Microsoft Kernel Debugger Network Miniport.) – C:\Windows\System32\drivers\kdnic.sys [23040] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - Network Power Dependency Broker.) – C:\Windows\System32\drivers\KNetPwrDepBroker.sys [13824] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:52 A . (.Microsoft Corporation - Kernel CSA Library.) – C:\Windows\System32\drivers\ks.sys [401920] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) – C:\Windows\System32\drivers\ksecdd.sys [139672] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:22 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) – C:\Windows\System32\drivers\ksecpkg.sys [170912] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:26 A . (.Microsoft Corporation - Kernel Streaming WOW Thunk Service.) – C:\Windows\System32\drivers\ksthunk.sys [27136] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) – C:\Windows\System32\drivers\lltdio.sys [65024] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) – C:\Windows\System32\drivers\lsi_sas.sys [108952] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) – C:\Windows\System32\drivers\lsi_sas2i.sys [124312] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) – C:\Windows\System32\drivers\lsi_sas3i.sys [128408] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) – C:\Windows\System32\drivers\lsi_sss.sys [82848] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:27 A . (.Microsoft Corporation - LUA File Virtualization Filter Driver.) – C:\Windows\System32\drivers\luafv.sys [128000] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - MA-USB Host Controller Driver.) – C:\Windows\System32\drivers\mausbhost.sys [505240] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - MA-USB IP Driver.) – C:\Windows\System32\drivers\mausbip.sys [56736] =>.Microsoft Windows®
                  O58 - SDL:2022/08/08 18:55:22 A . (.Malwarebytes - Malwarebytes Anti-Exploit.) – C:\Windows\System32\drivers\mbae64.sys [158640] =>.Microsoft®
                  O58 - SDL:2022/08/08 18:54:45 A . (.Malwarebytes - Malwarebytes Early Launch Anti-Malware Driv.) – C:\Windows\System32\drivers\MbamElam.sys [21480] =>.Microsoft®
                  O58 - SDL:2022/08/09 09:56:19 A . (.Malwarebytes - Malwarebytes SwissArmy.) – C:\Windows\System32\drivers\mbamswissarmy.sys [239544] =>.Microsoft®
                  O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - Medium changer class driver.) – C:\Windows\System32\drivers\mcd.sys [23552] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\Windows\System32\drivers\megasas.sys [59800] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\Windows\System32\drivers\MegaSas2i.sys [75160] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\Windows\System32\drivers\megasas35i.sys [82328] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) – C:\Windows\System32\drivers\megasr.sys [575896] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Mellanox - MLX4 Bus Driver.) – C:\Windows\System32\drivers\mlx4_bus.sys [842648] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - MMCSS Driver.) – C:\Windows\System32\drivers\mmcss.sys [43520] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:38 A . (.Microsoft Corporation - Modem Device Driver.) – C:\Windows\System32\drivers\modem.sys [42496] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:47 A . (.Microsoft Corporation - Monitor Driver.) – C:\Windows\System32\drivers\monitor.sys [44544] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Mouse Class Driver.) – C:\Windows\System32\drivers\mouclass.sys [56728] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - HID Mouse Filter Driver.) – C:\Windows\System32\drivers\mouhid.sys [33280] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Mount Point Manager.) – C:\Windows\System32\drivers\mountmgr.sys [104352] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:34 A . (.Microsoft Corporation - Microsoft Protection Service Driver.) – C:\Windows\System32\drivers\mpsdrv.sys [75776] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:57:00 A . (.Microsoft Corporation - Windows NT WebDav Minirdr.) – C:\Windows\System32\drivers\mrxdav.sys [144384] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Windows NT SMB Minirdr.) – C:\Windows\System32\drivers\mrxsmb.sys [500632] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) – C:\Windows\System32\drivers\mrxsmb20.sys [226208] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Mailslot driver.) – C:\Windows\System32\drivers\msfs.sys [31232] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - GPIO Class Extension Driver.) – C:\Windows\System32\drivers\msgpioclx.sys [169368] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - GPIO Button Driver.) – C:\Windows\System32\drivers\msgpiowin32.sys [50592] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Pass-through HID to KMDF Filter Driver.) – C:\Windows\System32\drivers\mshidkmdf.sys [8704] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Pass-through Driver for HID-UMDF Interface.) – C:\Windows\System32\drivers\mshidumdf.sys [11776] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Hardware Notification Class Extension Drive.) – C:\Windows\System32\drivers\mshwnclx.sys [27136] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - ISA Driver.) – C:\Windows\System32\drivers\msisadrv.sys [18848] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) – C:\Windows\System32\drivers\msiscsi.sys [280984] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:52 A . (.Microsoft Corporation - MS KS Server.) – C:\Windows\System32\drivers\mskssrv.sys [32256] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - Microsoft Link-Layer Discovery Protocol Dri.) – C:\Windows\System32\drivers\mslldp.sys [84480] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:25 A . (.Microsoft Corporation - MS Proxy Clock.) – C:\Windows\System32\drivers\mspclock.sys [10752] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:25 A . (.Microsoft Corporation - MS Proxy Quality Manager.) – C:\Windows\System32\drivers\mspqm.sys [10752] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - Kernel Remote Procedure Call Provider.) – C:\Windows\System32\drivers\msrpc.sys [375712] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 12:20:26 A . (.Microsoft Corporation - Microsoft Security Events Component file sy.) – C:\Windows\System32\drivers\mssecflt.sys [304032] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - System Management BIOS Driver.) – C:\Windows\System32\drivers\mssmbios.sys [40864] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:25 A . (.Microsoft Corporation - WDM Tee/Communication Transform Filter.) – C:\Windows\System32\drivers\mstee.sys [12800] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - Microsoft Multi-Touch HID Driver.) – C:\Windows\System32\drivers\MTConfig.sys [16896] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Multiple UNC Provider Driver.) – C:\Windows\System32\drivers\mup.sys [124832] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) – C:\Windows\System32\drivers\mvumis.sys [63904] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Mellanox - NetworkDirect Support Filter Driver.) – C:\Windows\System32\drivers\ndfltr.sys [108952] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Network Driver Interface Specification (NDI.) – C:\Windows\System32\drivers\ndis.sys [1285536] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:38 A . (.Microsoft Corporation - Microsoft NDIS Packet Capture Filter Driver.) – C:\Windows\System32\drivers\ndiscap.sys [53760] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - Microsoft Network Adapter Multiplexor.) – C:\Windows\System32\drivers\NdisImPlatform.sys [128512] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) – C:\Windows\System32\drivers\ndistapi.sys [27136] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - NDIS User mode I/O driver.) – C:\Windows\System32\drivers\ndisuio.sys [65024] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - Microsoft Virtual Network Adapter Enumerato.) – C:\Windows\System32\drivers\NdisVirtualBus.sys [20992] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) – C:\Windows\System32\drivers\ndiswan.sys [192512] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - NDIS Proxy.) – C:\Windows\System32\drivers\ndproxy.sys [63488] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - Windows Network Data Usage Monitoring Drive.) – C:\Windows\System32\drivers\Ndu.sys [128000] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Network Adapter Class Extension for WDF.) – C:\Windows\System32\drivers\NetAdapterCx.sys [175104] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - NetBIOS interface driver.) – C:\Windows\System32\drivers\netbios.sys [58264] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - MBT Transport driver.) – C:\Windows\System32\drivers\netbt.sys [311296] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Network I/O Subsystem.) – C:\Windows\System32\drivers\netio.sys [536472] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual NDIS Miniport.) – C:\Windows\System32\drivers\netvsc.sys [197632] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - NPFS Driver.) – C:\Windows\System32\drivers\npfs.sys [73216] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Named pipe service triggers.) – C:\Windows\System32\drivers\npsvctrig.sys [26112] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - NSI Proxy.) – C:\Windows\System32\drivers\nsiproxy.sys [44544] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - NT File System Driver.) – C:\Windows\System32\drivers\ntfs.sys [2420632] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:28 A . (.Microsoft Corporation - NTOS extension host driver.) – C:\Windows\System32\drivers\ntosext.sys [19872] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - NULL Driver.) – C:\Windows\System32\drivers\null.sys [7168] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - NVDIMM device driver.) – C:\Windows\System32\drivers\nvdimm.sys [104448] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2017/11/09 04:38:54 A . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) – C:\Windows\System32\drivers\nvhda64v.sys [233904] =>.NVIDIA Corporation®
                  O58 - SDL:2018/04/12 02:33:48 A . (.NVIDIA Corporation - NVIDIA® nForce™ RAID Driver.) – C:\Windows\System32\drivers\nvraid.sys [150424] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:48 A . (.NVIDIA Corporation - NVIDIA® nForce™ Sata Performance Driver.) – C:\Windows\System32\drivers\nvstor.sys [166304] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:44 A . (.Microsoft Corporation - NativeWiFi Miniport Driver.) – C:\Windows\System32\drivers\nwifi.sys [528384] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - QoS Packet Scheduler.) – C:\Windows\System32\drivers\pacer.sys [152984] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Parallel Port Driver.) – C:\Windows\System32\drivers\parport.sys [98816] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Partition driver.) – C:\Windows\System32\drivers\partmgr.sys [166816] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - NT Plug and Play PCI Enumerator.) – C:\Windows\System32\drivers\pci.sys [375712] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Generic PCI IDE Bus Driver.) – C:\Windows\System32\drivers\pciide.sys [16288] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - PCI IDE Bus Driver Extension.) – C:\Windows\System32\drivers\pciidex.sys [53656] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:45 A . (.Microsoft Corporation - PCMCIA Bus Driver.) – C:\Windows\System32\drivers\pcmcia.sys [120216] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Performance Counters for Windows Driver.) – C:\Windows\System32\drivers\pcw.sys [53152] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Power Dependency Coordinator Driver.) – C:\Windows\System32\drivers\pdc.sys [140192] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - Protected Environment Authentication and Au.) – C:\Windows\System32\drivers\PEAuth.sys [726528] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\Windows\System32\drivers\percsas2i.sys [58776] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\Windows\System32\drivers\percsas3i.sys [61848] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Persistent memory driver.) – C:\Windows\System32\drivers\pmem.sys [105984] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - Plug and Play Memory Driver.) – C:\Windows\System32\drivers\pnpmem.sys [16896] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:46 A . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport.) – C:\Windows\System32\drivers\portcls.sys [379392] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Processor Device Driver.) – C:\Windows\System32\drivers\processr.sys [178176] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - Microsoft Quality Windows Audio Video Exper.) – C:\Windows\System32\drivers\qwavedrv.sys [49152] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - RAM Disk Driver.) – C:\Windows\System32\drivers\ramdisk.sys [39840] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - RAS Automatic Connection Driver.) – C:\Windows\System32\drivers\rasacd.sys [17408] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) – C:\Windows\System32\drivers\rasl2tp.sys [106496] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - RAS PPPoE mini-port/call-manager driver.) – C:\Windows\System32\drivers\raspppoe.sys [82944] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - Peer-to-Peer Tunneling Protocol.) – C:\Windows\System32\drivers\raspptp.sys [97280] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - RAS SSTP Miniport Call Manager.) – C:\Windows\System32\drivers\rassstp.sys [78848] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) – C:\Windows\System32\drivers\rdbss.sys [433560] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 12:20:20 A . (.Microsoft Corporation - Microsoft RDP Bus Device driver.) – C:\Windows\System32\drivers\rdpbus.sys [27136] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:57:34 A . (.Microsoft Corporation - Microsoft RDP Device redirector.) – C:\Windows\System32\drivers\rdpdr.sys [182784] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 12:20:22 A . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) – C:\Windows\System32\drivers\rdpvideominiport.sys [30616] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - ReadyBoost Driver.) – C:\Windows\System32\drivers\rdyboost.sys [284064] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:49 A . (.Microsoft Corporation - NT ReFS FS Driver.) – C:\Windows\System32\drivers\refs.sys [1921944] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:49 A . (.Microsoft Corporation - NT ReFS FS Driver.) – C:\Windows\System32\drivers\refsv1.sys [945568] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft RemoteFX VM Transport.) – C:\Windows\System32\drivers\RfxVmt.sys [43008] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - ResourceHub Proxy Driver.) – C:\Windows\System32\drivers\rhproxy.sys [104448] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2022/08/11 15:51:38 N . (.AVG Technologies - Remover Driver.) – C:\Windows\System32\drivers\rm.sys [55248] =>.AVG Technologies CZ, s.r.o.®
                  O58 - SDL:2018/04/12 02:34:29 A . (.Microsoft Corporation - Reliable Multicast Transport.) – C:\Windows\System32\drivers\rmcast.sys [150016] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - Remote NDIS Miniport.) – C:\Windows\System32\drivers\RNDISMP.sys [35328] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:38 A . (.Microsoft Corporation - Legacy Non-Pnp Modem Device Driver.) – C:\Windows\System32\drivers\rootmdm.sys [13312] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) – C:\Windows\System32\drivers\rspndr.sys [81920] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.40 64-bit Dri.) – C:\Windows\System32\drivers\rt640x64.sys [604160] [Unsigned] =>.Realtek
                  O58 - SDL:2018/04/12 02:33:53 RA . (.Realtek - Realtek PCIe GBE Family Controller Flight.) – C:\Windows\System32\drivers\rteth.sys [65536] [Unsigned] =>.Realtek
                  O58 - SDL:2019/02/26 19:50:01 A . (.Realtek Semiconductor Corporation - Realtek WLAN USB NDIS Driver 66263.) – C:\Windows\System32\drivers\rtwlanu.sys [8287464] =>.Realtek Semiconductor Corp.®
                  O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - SBP-2 Protocol Driver.) – C:\Windows\System32\drivers\sbp2port.sys [109984] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:37 A . (.Microsoft Corporation - Microsoft Smart Card Reader Filter Driver.) – C:\Windows\System32\drivers\scfilter.sys [43008] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Storage Class Memory Bus Driver.) – C:\Windows\System32\drivers\scmbus.sys [128416] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - SCSI Port Driver.) – C:\Windows\System32\drivers\scsiport.sys [176032] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - SecureDigital Bus Driver.) – C:\Windows\System32\drivers\sdbus.sys [287128] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - SDF Reflector.) – C:\Windows\System32\drivers\SDFRd.sys [33176] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - SD Host Controller Port Driver.) – C:\Windows\System32\drivers\sdport.sys [97696] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - SD Storage Class Driver.) – C:\Windows\System32\drivers\sdstor.sys [97176] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Serial Class Extension.) – C:\Windows\System32\drivers\SerCx.sys [75680] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Serial Class Extension V2.) – C:\Windows\System32\drivers\SerCx2.sys [154528] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Serial Port Enumerator.) – C:\Windows\System32\drivers\serenum.sys [25088] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Serial Device Driver.) – C:\Windows\System32\drivers\serial.sys [84992] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Serial Mouse Filter Driver.) – C:\Windows\System32\drivers\sermouse.sys [28160] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - SCSI Floppy Driver.) – C:\Windows\System32\drivers\sfloppy.sys [17920] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:04 A . (.Microsoft Corporation - System Guard Runtime Monitor Agent Driver.) – C:\Windows\System32\drivers\SgrmAgent.sys [63896] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) – C:\Windows\System32\drivers\sisraid2.sys [44952] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) – C:\Windows\System32\drivers\sisraid4.sys [81816] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Sleep Study Helper.) – C:\Windows\System32\drivers\SleepStudyHelper.sys [34208] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 12:20:26 A . (.Microsoft Corporation - SMB Network Direct Driver.) – C:\Windows\System32\drivers\smbdirect.sys [152064] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - Smart Card Driver Library.) – C:\Windows\System32\drivers\smclib.sys [21504] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Storage Spaces Dump Driver.) – C:\Windows\System32\drivers\spacedump.sys [175008] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Storage Spaces Driver.) – C:\Windows\System32\drivers\spaceport.sys [611232] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 12:20:24 A . (.Microsoft Corporation - Holographic Spatial Graph Filter.) – C:\Windows\System32\drivers\SpatialGraphFilter.sys [57752] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - SPB Class Extension.) – C:\Windows\System32\drivers\SpbCx.sys [82328] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - Smb 2.0 Server driver.) – C:\Windows\System32\drivers\srv2.sys [737792] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - Server Network driver.) – C:\Windows\System32\drivers\srvnet.sys [266752] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) – C:\Windows\System32\drivers\stexstor.sys [31128] =>.Microsoft Windows®
                  O58 - SDL:2011/08/24 11:56:28 A . (. - Spyware Terminator 2012 driver.) – C:\Windows\System32\drivers\stflt.sys [51496] =>.Crawler, LLC®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - MS AHCI Storport Miniport Driver.) – C:\Windows\System32\drivers\storahci.sys [156056] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Microsoft NVM Express Storport Miniport Dri.) – C:\Windows\System32\drivers\stornvme.sys [105368] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:22 A . (.Microsoft Corporation - Microsoft Storage Port Driver.) – C:\Windows\System32\drivers\storport.sys [562080] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - Storage QoS Filter.) – C:\Windows\System32\drivers\storqosflt.sys [82432] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - MS UFS Storport Miniport Driver.) – C:\Windows\System32\drivers\storufs.sys [48544] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Storage VSC Driver.) – C:\Windows\System32\drivers\storvsc.sys [40352] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - WDM CODEC Class Device Driver 2.0.) – C:\Windows\System32\drivers\stream.sys [75264] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft RemoteFX Synth3D Video VSC.) – C:\Windows\System32\drivers\Synth3dVsc.sys [64512] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:36 A . (.Microsoft Corporation - SCSI Tape Class Driver.) – C:\Windows\System32\drivers\tape.sys [31232] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Export driver for kernel mode TPM API.) – C:\Windows\System32\drivers\tbs.sys [27544] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:50 A . (.Microsoft Corporation - TCP/IP Driver.) – C:\Windows\System32\drivers\tcpip.sys [2712992] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) – C:\Windows\System32\drivers\tcpipreg.sys [51712] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - TDI Wrapper.) – C:\Windows\System32\drivers\tdi.sys [40352] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - TDI Translation Driver.) – C:\Windows\System32\drivers\tdx.sys [121248] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 12:20:28 A . (.Microsoft Corporation - Terminal Server Input Driver.) – C:\Windows\System32\drivers\terminpt.sys [37280] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Kernel Transaction Manager Driver.) – C:\Windows\System32\drivers\tm.sys [128920] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - TPM Device Driver.) – C:\Windows\System32\drivers\tpm.sys [232352] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Remote Desktop USB Hub Filter Driver.) – C:\Windows\System32\drivers\TsUsbFlt.sys [63488] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Remote Desktop Generic USB Driver.) – C:\Windows\System32\drivers\TsUsbGD.sys [35328] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 12:20:19 A . (.Microsoft Corporation - Remote Desktop USB Hub.) – C:\Windows\System32\drivers\tsusbhub.sys [126464] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:32 A . (.Microsoft Corporation - Microsoft Tunnel Interface Driver.) – C:\Windows\System32\drivers\tunnel.sys [119296] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft Uasp Driver.) – C:\Windows\System32\drivers\uaspstor.sys [79776] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - USB Connector Manager KMDF Class Extension.) – C:\Windows\System32\drivers\UcmCx.sys [128512] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - UCM-TCPCI KMDF Class Extension.) – C:\Windows\System32\drivers\UcmTcpciCx.sys [152576] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB Connector Manager UCSI Client.) – C:\Windows\System32\drivers\UcmUcsi.sys [57856] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:35 A . (.Microsoft Corporation - USB Controller Extension.) – C:\Windows\System32\drivers\Ucx01000.sys [226720] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - ‘udecx.DRIVER’.) – C:\Windows\System32\drivers\Udecx.sys [45056] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:38 A . (.Microsoft Corporation - UDF File System Driver.) – C:\Windows\System32\drivers\udfs.sys [324608] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - UEFI Driver for NT.) – C:\Windows\System32\drivers\uefi.sys [29600] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 12:20:25 A . (.Microsoft Corporation - Microsoft User Experience Virtualization Ag.) – C:\Windows\System32\drivers\UevAgentDriver.sys [40344] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - USB Function Driver Class Extension.) – C:\Windows\System32\drivers\ufx01000.sys [282008] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - UFX Chipidea Client Driver.) – C:\Windows\System32\drivers\UfxChipidea.sys [98200] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - UFX Synopsys Client Driver.) – C:\Windows\System32\drivers\ufxsynopsys.sys [144288] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - User-Mode Bus Enumerator.) – C:\Windows\System32\drivers\umbus.sys [56832] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - Generic pass-through driver.) – C:\Windows\System32\drivers\umpass.sys [14336] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - USB Role-Switch Driver for Chipidea Core.) – C:\Windows\System32\drivers\urschipidea.sys [29088] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - USB Role-Switch Class Extension.) – C:\Windows\System32\drivers\urscx01000.sys [67992] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:51 A . (.Microsoft Corporation - USB Role-Switch Driver for Synopsys Core.) – C:\Windows\System32\drivers\urssynopsys.sys [28064] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:34 A . (.Microsoft Corporation - Remote NDIS USB Driver.) – C:\Windows\System32\drivers\usb8023.sys [22016] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:40 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) – C:\Windows\System32\drivers\USBCAMD2.sys [37376] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) – C:\Windows\System32\drivers\usbccgp.sys [168864] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:46 A . (.Microsoft Corporation - USB Consumer IR Driver for eHome.) – C:\Windows\System32\drivers\usbcir.sys [102912] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Universal Serial Bus Driver.) – C:\Windows\System32\drivers\usbd.sys [32152] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) – C:\Windows\System32\drivers\usbehci.sys [95648] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Default Hub Driver for USB.) – C:\Windows\System32\drivers\usbhub.sys [514464] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - USB3 HUB Driver.) – C:\Windows\System32\drivers\USBHUB3.SYS [565152] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - OHCI USB Miniport Driver.) – C:\Windows\System32\drivers\usbohci.sys [30208] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:14 A . (…) – C:\Windows\System32\drivers\UsbPmApi.sys [39936] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB 1.1 & 2.0 Port Driver.) – C:\Windows\System32\drivers\usbport.sys [412576] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:47 A . (.Microsoft Corporation - USB Printer driver.) – C:\Windows\System32\drivers\usbprint.sys [27136] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - USB Serial Driver.) – C:\Windows\System32\drivers\usbser.sys [72192] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB Mass Storage Class Driver.) – C:\Windows\System32\drivers\USBSTOR.SYS [131488] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - UHCI USB Miniport Driver.) – C:\Windows\System32\drivers\usbuhci.sys [35328] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - USB XHCI Driver.) – C:\Windows\System32\drivers\USBXHCI.SYS [434592] =>.Microsoft Windows®
                  O58 - SDL:2022/07/19 15:50:14 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Host-Only Network Adapt.) – C:\Windows\System32\drivers\VBoxNetAdp6.sys [242656] =>.Oracle Corporation®
                  O58 - SDL:2022/07/19 15:50:18 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Lightweight Filter Driv.) – C:\Windows\System32\drivers\VBoxNetLwf.sys [252560] =>.Oracle Corporation®
                  O58 - SDL:2022/07/19 15:50:22 A . (.Oracle Corporation - VirtualBox Support Driver.) – C:\Windows\System32\drivers\VBoxSup.sys [1081592] =>.Oracle Corporation®
                  O58 - SDL:2022/07/19 15:50:28 A . (.Oracle Corporation - VirtualBox USB Monitor Driver.) – C:\Windows\System32\drivers\VBoxUSBMon.sys [191184] =>.Oracle Corporation®
                  O58 - SDL:2020/02/22 11:43:04 A . (.Elaborate Bytes AG - Virtual CloneDrive storage miniport.) – C:\Windows\System32\drivers\VClone.sys [44544] =>.Microsoft®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual Drive Root Enumerator.) – C:\Windows\System32\drivers\vdrvroot.sys [56224] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Driver Verifier Extension.) – C:\Windows\System32\drivers\VerifierExt.sys [217496] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - VHD Miniport Driver.) – C:\Windows\System32\drivers\vhdmp.sys [705440] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Virtual HID Framework (VHF) Driver.) – C:\Windows\System32\drivers\vhf.sys [35328] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - Video Port Driver.) – C:\Windows\System32\drivers\videoprt.sys [44544] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2017/07/20 05:46:11 A . (.Red Hat, Inc. - Red Hat VirtIO RNG Driver.) – C:\Windows\System32\drivers\viorng.sys [43080] {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
                  O58 - SDL:2017/07/20 05:46:14 A . (.Red Hat, Inc. - Red Hat VirtIO SCSI driver.) – C:\Windows\System32\drivers\viostor.sys [40008] {56C6D267ADE07F72EEB4603BBF84CEA5}. =>.Red Hat, Inc.
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Hyper-V VMBus KMCL.) – C:\Windows\System32\drivers\vmbkmcl.sys [81824] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:08 A . (.Microsoft Corporation - Hyper-V VMBus Root KMCL.) – C:\Windows\System32\drivers\vmbkmclr.sys [82432] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft Hyper-V Virtual Machine Bus Child.) – C:\Windows\System32\drivers\vmbus.sys [114080] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft VMBus HID Miniport.) – C:\Windows\System32\drivers\VMBusHID.sys [25088] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual Machine Generation Counter.) – C:\Windows\System32\drivers\vmgencounter.sys [13312] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual Machine Guest Infrastructure Driver.) – C:\Windows\System32\drivers\vmgid.sys [10240] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Microsoft S3 Emulated Device Cap Driver.) – C:\Windows\System32\drivers\vms3cap.sys [9216] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual Storage Filter Driver.) – C:\Windows\System32\drivers\vmstorfl.sys [47520] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Volume Manager Driver.) – C:\Windows\System32\drivers\volmgr.sys [83360] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:24 A . (.Microsoft Corporation - Volume Manager Extension Driver.) – C:\Windows\System32\drivers\volmgrx.sys [373144] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:39 A . (.Microsoft Corporation - Volume Shadow Copy driver.) – C:\Windows\System32\drivers\volsnap.sys [398240] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Volume driver.) – C:\Windows\System32\drivers\volume.sys [16288] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Virtual PCI Bus.) – C:\Windows\System32\drivers\vpci.sys [75168] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) – C:\Windows\System32\drivers\vsmraid.sys [166808] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) – C:\Windows\System32\drivers\VSTXRAID.SYS [305560] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - Virtual Wireless Bus Driver.) – C:\Windows\System32\drivers\vwifibus.sys [27136] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - Virtual WiFi Filter Driver.) – C:\Windows\System32\drivers\vwififlt.sys [76288] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:43 A . (.Microsoft Corporation - Virtual WiFi Miniport Driver.) – C:\Windows\System32\drivers\vwifimp.sys [44544] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:48 A . (.Microsoft Corporation - Wacom Serial Pen Tablet HID Driver.) – C:\Windows\System32\drivers\wacompen.sys [30720] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:33 A . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) – C:\Windows\System32\drivers\wanarp.sys [81920] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:08 A . (.Microsoft Corporation - Watchdog Driver.) – C:\Windows\System32\drivers\watchdog.sys [56320] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Windows Container Isolation FS Filter Drive.) – C:\Windows\System32\drivers\wcifs.sys [151960] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:14 A . (.Microsoft Corporation - Windows Container Name Virtualization FS Fi.) – C:\Windows\System32\drivers\wcnfs.sys [82944] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:58 A . (.Microsoft Corporation - Microsoft antimalware boot driver.) – C:\Windows\System32\drivers\WdBoot.sys [44616] =>.Microsoft Windows Early Launch Anti-malware Publisher®
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) – C:\Windows\System32\drivers\Wdf01000.sys [924856] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:58 A . (.Microsoft Corporation - Microsoft antimalware file system filter dr.) – C:\Windows\System32\drivers\WdFilter.sys [331680] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - Kernel Mode Driver Framework Loader.) – C:\Windows\System32\drivers\WdfLdr.sys [61624] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:57:00 A . (.Microsoft Corporation - WDI Driver Framework Driver.) – C:\Windows\System32\drivers\WdiWiFi.sys [781824] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:15 A . (.Microsoft Corporation - WDM Companion Filter.) – C:\Windows\System32\drivers\WdmCompanionFilter.sys [21408] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:58 A . (.Microsoft Corporation - Windows Defender Network Stream Filter.) – C:\Windows\System32\drivers\WdNisDrv.sys [44032] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:23 A . (.Microsoft Corporation - Windows Error Reporting Kernel Driver.) – C:\Windows\System32\drivers\werkernel.sys [45984] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:34 A . (.Microsoft Corporation - WFP NDIS 6.30 Lightweight Filter Driver.) – C:\Windows\System32\drivers\wfplwfs.sys [164768] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Wim file system Driver.) – C:\Windows\System32\drivers\wimmount.sys [35744] =>.Microsoft Windows®
                  O58 - SDL:2018/07/12 15:56:34 A . (.Microsoft Corporation - Windows Trusted Runtime Interface Driver.) – C:\Windows\System32\drivers\WindowsTrustedRT.sys [72768] =>.Microsoft Windows Hardware Abstraction Layer Publisher®
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Windows Trusted Runtime Service Proxy Drive.) – C:\Windows\System32\drivers\WindowsTrustedRTProxy. sys [18472] =>.Microsoft Windows Hardware Abstraction Layer Publisher®
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Windows Hypervisor Interface Driver.) – C:\Windows\System32\drivers\winhv.sys [31640] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Windows Hypervisor Root Interface Driver.) – C:\Windows\System32\drivers\winhvr.sys [68096] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Mellanox - Kernel WinMad.) – C:\Windows\System32\drivers\winmad.sys [32152] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:54 A . (.Microsoft Corporation - Windows NAT Driver.) – C:\Windows\System32\drivers\winnat.sys [227840] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - Windows WinUSB Class Driver.) – C:\Windows\System32\drivers\winusb.sys [92672] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:49 A . (.Mellanox - Kernel WinVerbs.) – C:\Windows\System32\drivers\winverbs.sys [64920] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:49 A . (.Microsoft Corporation - Windows Management Interface for ACPI.) – C:\Windows\System32\drivers\wmiacpi.sys [18432] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - WMILIB WMI support library Dll.) – C:\Windows\System32\drivers\wmilib.sys [20384] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:20 A . (.Microsoft Corporation - Windows Overlay Filter.) – C:\Windows\System32\drivers\wof.sys [209816] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:33:58 A . (.Microsoft Corporation - Windows Portable Device Upper Class Filter.) – C:\Windows\System32\drivers\WpdUpFltr.sys [30112] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:22 A . (.Microsoft Corporation - WPP Trace Recorder.) – C:\Windows\System32\drivers\WppRecorder.sys [33184] =>.Microsoft Windows®
                  O58 - SDL:2018/04/12 02:34:39 A . (.Microsoft Corporation - Winsock2 IFS Layer.) – C:\Windows\System32\drivers\ws2ifsl.sys [23040] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:28 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) – C:\Windows\System32\drivers\WUDFPf.sys [125440] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:28 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) – C:\Windows\System32\drivers\WUDFRd.sys [264192] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Game Input Protocol Driver.) – C:\Windows\System32\drivers\xboxgip.sys [295424] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:33:52 A . (.Microsoft Corporation - XINPUT filter driver for HID.) – C:\Windows\System32\drivers\xinputhid.sys [46592] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2019/02/26 19:50:01 A . (.Realtek Semiconductor Corporation - Realtek WLAN USB NDIS Driver 66263.) – C:\Windows\System32\rtwlanu.sys [8287464] =>.Realtek Semiconductor Corp.®
                  O58 - SDL:2018/04/12 02:34:12 A . (.Microsoft Corporation - Full/Desktop Multi-User Win32 Driver.) – C:\Windows\System32\win32k.sys [482304] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:33 A . (.Microsoft Corporation - Base Win32k Kernel Driver.) – C:\Windows\System32\win32kbase.sys [2236928] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:35 A . (.Microsoft Corporation - Full/Desktop Win32k Kernel Driver.) – C:\Windows\System32\win32kfull.sys [3652608] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/04/12 02:34:48 A . (.Microsoft Corporation - Full/Desktop Multi-User Win32 Driver.) – C:\Windows\SysWOW64\win32k.sys [315904] [Unsigned] =>.Microsoft Corporation
                  O58 - SDL:2018/07/12 15:56:21 A . (.Microsoft Corporation - Full/Desktop Win32k Kernel Driver.) – C:\Windows\SysWOW64\win32kfull.sys [2895360] [Unsigned] =>.Microsoft Corporation

                  —\ Last modified or created user files (11) - 11s
                  O61 - LFC: 2022/10/04 11:54:36 A . (..) – C:\Users\TeaTang\Desktop\adware-removal-tool-by-tsa.exe [752296] {317DD1C55F51AC2756D9C93C060C6FA5}.
                  O61 - LFC: 2022/10/01 16:11:40 A . (.Company © regist & Drongo.) – C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger.exe [16439448] [Unsigned]
                  O61 - LFC: 2022/10/01 05:30:02 A . (..) – C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\AV\ av_z.exe [1605632] [Unsigned]
                  O61 - LFC: 2022/10/01 05:30:06 A . (.Alex Dragokas.) – C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\Che ckBrowsersLNK\Check Browsers LNK.exe [1504328] {31F8F5FB790C592476CE0F3320DC4AF1}.
                  O61 - LFC: 2022/10/01 05:30:06 A . (.Stanislav Polshyn & Trend Micro Inc..) – C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\HiJ ackThis\HiJackThis.exe [7482296] {31F8F5FB790C592476CE0F3320DC4AF1}.
                  O61 - LFC: 2022/10/01 05:30:06 A . (.© random/random.) – C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\RSI T\RSIT.exe [1206272] [Unsigned]
                  O61 - LFC: 2022/10/01 05:30:06 A . (.© random/random.) – C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\RSI T\RSITx64.exe [1329152] [Unsigned]
                  O61 - LFC: 2022/10/01 05:05:02 A . (..) – C:\Users\TeaTang\Desktop\AVbr\AV_block_remover\tas khostw.exe [9281536] [Unsigned]
                  O61 - LFC: 2022/10/01 16:06:21 A . (.Company © regist.) – C:\Users\TeaTang\Desktop\AVbr\AVbr.exe [9322315] [Unsigned]
                  O61 - LFC: 2022/10/02 21:57:29 A . (.Alex Dragokas.) – C:\Users\TeaTang\Desktop\ClearLNK.exe [1029112] {31F8F5FB790C592476CE0F3320DC4AF1}.
                  O61 - LFC: 2022/10/04 11:50:20 A . (.d7xTech, Inc..) – C:\Users\TeaTang\Desktop\KillEmAll\KillEmAll.exe [1693312] {1877A57C210DBBD1CCE4B4424F5D2F9F}.

                  —\ File Associations Shell Spawning (10) - 0s
                  O67 - Shell Spawning: <.bat> [HKLM..\open\Command] (…) – ‘%1’ %* =>.Default.Value
                  O67 - Shell Spawning: <.cpl> [HKLM..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) – C:\Windows\System32\control.exe [Unsigned] =>.Microsoft Corporation
                  O67 - Shell Spawning: <.cmd> [HKLM..\open\Command] (…) – ‘%1’ %* =>.Default.Value
                  O67 - Shell Spawning: <.com> [HKLM..\open\Command] (…) – ‘%1’ %* =>.Default.Value
                  O67 - Shell Spawning: <.evt> [HKLM..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) – C:\Windows\System32\eventvwr.exe [Unsigned] =>.Microsoft Corporation
                  O67 - Shell Spawning: <.exe> [HKLM..\open\Command] (…) – ‘%1’ %* =>.Default.Value
                  O67 - Shell Spawning: <.html> [HKLM..\open\Command] (.Microsoft Corporation - Internet Explorer.) – C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                  O67 - Shell Spawning: <.js> [HKLM..\open\Command] (…) – C:\Windows\System32\WScript.exe ‘%1’ %* =>.Default.Value
                  O67 - Shell Spawning: <.reg> [HKLM..\open\Command] (.Microsoft Corporation - Registry Editor.) – C:\Windows\regedit.exe [Unsigned] =>.Microsoft Corporation
                  O67 - Shell Spawning: <.scr> [HKLM..\open\Command] (…) – ‘%1’ /S =>.Default.Value

                  —\ Start Menu Internet (5) - 0s
                  O68 - StartMenuInternet: [64Bits][HKLM..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) – C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                  O68 - StartMenuInternet: [64Bits][HKLM..\Shell\open\Command] (.Mozilla Corporation - LibreWolf.) – C:\Program Files\LibreWolf\librewolf.exe [Unsigned] =>.Mozilla Corporation
                  O68 - StartMenuInternet: [64Bits][HKLM..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
                  O68 - StartMenuInternet: [64Bits][HKLM..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
                  O68 - StartMenuInternet: [64Bits][HKLM..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

                  —\ Search Browser Infection (3) - 0s
                  O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
                  O69 - SBI: SearchScopes [HKCU] [64Bits]{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - (Google) - http://www.google.com/ =>.Google Inc.
                  O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

                  —\ Search Svchost Services (49) - 2s
                  O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) – C:\Windows\System32\certprop.dll [188928] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) – C:\Windows\System32\certprop.dll [188928] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) – C:\Windows\System32\srvsvc.dll [271360] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) – C:\Windows\System32\gpsvc.dll [1267712] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) – C:\Windows\System32\IKEEXT.DLL [990208] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) – C:\Windows\System32\iphlpsvc.dll [786432] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) – C:\Windows\System32\seclogon.dll [30720] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) – C:\Windows\System32\iscsiexe.dll [150528] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) – C:\Windows\System32\eapsvc.dll [109568] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) – C:\Windows\System32\schedsvc.dll [889344] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) – C:\Windows\System32\wbem\WMIsvc.dll [224256] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) – C:\Windows\System32\profsvc.dll [394240] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) – C:\Windows\System32\SessEnv.dll [397312] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) – C:\Windows\System32\wercplsupport.dll [119808] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: InstallService (InstallService) . (.Microsoft Corporation - InstallService.) – C:\Windows\System32\InstallService.dll [1487360] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: LxpSvc (LxpSvc) . (.Microsoft Corporation - Provides infrastructure support for deployi.) – C:\Windows\System32\LanguageOverlayServer.dll [199680] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) – C:\Windows\System32\Windows.SharedPC.AccountManage r.dll [195584] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: PushToInstall (PushToInstall) . (.Microsoft Corporation - PushToInstall.) – C:\Windows\System32\PushToInstall.dll [262144] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) – C:\Windows\System32\XblGameSave.dll [1308672] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) – C:\Windows\System32\NcaSvc.dll [167936] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) – C:\Windows\System32\Windows.Internal.Management.dl l [827392] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) – C:\Windows\System32\XblAuthManager.dll [1115648] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) – C:\Windows\System32\bdesvc.dll [402944] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Natural Authentication Service.) – C:\Windows\System32\NaturalAuth.dll [824832] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) – C:\Windows\System32\NetSetupSvc.dll [335360] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) – C:\Windows\System32\wlidsvc.dll [2248192] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) – C:\Windows\System32\DeviceSetupManager.dll [235520] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) – C:\Windows\System32\usermgr.dll [1027584] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) – C:\Windows\System32\themeservice.dll [69632] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) – C:\Windows\System32\XboxGipSvc.dll [58880] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) – C:\Windows\System32\appinfo.dll [166912] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Token Broker.) – C:\Windows\System32\TokenBroker.dll [1395712] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) – C:\Windows\System32\lfsvc.dll [44544] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Infrared Monitor.) – C:\Windows\System32\irmon.dll [24576] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) – C:\Windows\System32\rasauto.dll [104960] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) – C:\Windows\System32\rasmans.dll [932352] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) – C:\Windows\System32\mprdim.dll [497664] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) – C:\Windows\System32\Sens.dll [73216] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) – C:\Windows\System32\ipnathlp.dll [604672] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows™ Telephony Server.) – C:\Windows\System32\tapisrv.dll [308224] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) – C:\Windows\System32\wuaueng.dll [2903040] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) – C:\Windows\System32\qmgr.dll [1374208] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) – C:\Windows\System32\shsvcs.dll [613376] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) – C:\Windows\System32\dmwappushsvc.dll [57856] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Flight Settings.) – C:\Windows\System32\flightsettings.dll [858112] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) – C:\Windows\System32\WpnService.dll [280576] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) – C:\Windows\System32\XboxNetApiSvc.dll [1148928] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) – C:\Windows\System32\usocore.dll [1374208] [Unsigned] =>.Microsoft Corporation
                  O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) – C:\Windows\System32\appmgmts.dll [197120] [Unsigned] =>.Microsoft Corporation

                  —\ Firewall Active Exception List (4) - 1s
                  O87 - FAEL: ‘{AF477CB3-E0D6-4864-AAC4-D8CE3CD48B35}’ [In-None-P6-TRUE] .(.Valve Corporation - Steam.) – C:\Program Files (x86)\Steam\Steam.exe =>.Valve Corp.®
                  O87 - FAEL: ‘{A24850F9-C9A9-4126-855B-6C139A99C1A6}’ [In-None-P17-TRUE] .(.Valve Corporation - Steam.) – C:\Program Files (x86)\Steam\Steam.exe =>.Valve Corp.®
                  O87 - FAEL: ‘{5FD1BC2B-ABD7-4896-80C2-E1EE08088A1F}’ [In-None-P6-TRUE] .(.Valve Corporation - Steam Client WebHelper.) – C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe =>.Valve Corp.®
                  O87 - FAEL: ‘{097601F0-855B-4DFB-BC38-A43DF1473A6F}’ [In-None-P17-TRUE] .(.Valve Corporation - Steam Client WebHelper.) – C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe =>.Valve Corp.®

                  —\ Product Upgrade Codes (6) - 0s
                  O90 - PUC: ‘009B70435F732CC46B21C55D5D081A36’ [HKLM] . (.Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332.) =>.Microsoft Corporation
                  O90 - PUC: ‘3EE9944F661AC69418BB151DCBCD079A’ [HKLM] . (.Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332.) =>.Microsoft Corporation
                  O90 - PUC: ‘BA2A87B85B436454C8FC7BC819B6DB89’ [HKLM] . (.Oracle VM VirtualBox 6.1.36.) – C:\Windows\Installer{8B78A2AB-34B5-4546-8CCF-B78C916BBD98}\IconVirtualBox =>.Oracle
                  O90 - PUC: ‘BEC6D2F889CB96B45A1C87EB2D83EF77’ [HKLM] . (.Update for Windows 10 for x64-based Systems (KB4023057).) =>.Microsoft Corporation
                  O90 - PUC: ‘D04BB691875110D32B98EBCF771AA1E1’ [HKLM] . (.Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319.) =>.bl.org
                  O90 - PUC: ‘E29464706B74152449C04464D2DF47BB’ [HKLM] . (.Update for Windows 10 for x64-based Systems (KB4480730).) =>.Microsoft Corporation

                  —\ Windows Installer Scan (1) - 1s
                  [MD5.CC9E931DA9620ED5D79DADF653A85292] [WIS][2022/09/14 20:49:38] (.Oracle Corporation - Oracle VM VirtualBox 6.1.36 installation pa.) – C:\Windows\Installer\1642052f.msi [110116864] =>.Oracle Corporation

                  —\ FEATURE CONTROL. (128) - 0s
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPUR POSEDETECTION]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEM ENT]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEM ENT]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEM ENT]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_P ROMPTS]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_P ROMPTS]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJ ECT]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJ ECT]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCR IPT]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCR IPT]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULA TION]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULA TION]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULA TION]:KMPlayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGAC Y_COMPRESSION]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PR OTOCOL]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PR OTOCOL]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PR OTOCOL]:SAPfewgsrv.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PR OTOCOL]:SAPGUI.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PR OTOCOL]:SAPGuiIT.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PR OTOCOL]:SAPLgPad.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PR OTOCOL]:SAPLOGON.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PR OTOCOL]:Scale_for_R3.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PR OTOCOL]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_U PLOAD_FOR_APP]:ieuser.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_U PLOAD_FOR_APP]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNE T_PROTOCOL]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNE T_PROTOCOL]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICO DE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMP ATIBLE_MODE]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT _PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT _PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT _PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT _PASTE_URLACTION_IF_PROMPT]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AN D_STATUS]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AN D_STATUS]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME _PASSWORD_DISABLE]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME _PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PR OLOG]:msiexec.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_A RT]:cs.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_A RT]:waol.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_A RT]:wm.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHEL L_FOLDERS]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPA RAMS]:helppane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONT ROL_BEHAVIORS]:wlmail.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_ LOCKDOWN]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_ LOCKDOWN]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_ LOCKDOWN]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_ LOCKDOWN]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_ LOCKDOWN]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_ LOCKDOWN]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTION SPER1_0SERVER]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTION SPERSERVER]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLO AD_IEFRAME]:mshta.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLO AD_IEFRAME]utlook.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLO AD_IEFRAME]:sidebar.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHIN G]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHIN G]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHIN G]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCK DOWN]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCK DOWN]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCK DOWN]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLB ACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOU T_PROTOCOL_IE7]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOU T_PROTOCOL_IE7]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOU T_PROTOCOL_IE7]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTI VEXINSTALL]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTI VEXINSTALL]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTI VEXINSTALL]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILE DOWNLOAD]:msimn.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILE DOWNLOAD]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILE DOWNLOAD]:winmail.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILE DOWNLOAD]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJE CT_DATA_ATTRIBUTE]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_ TO_LMZ]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_ TO_LMZ]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_ TO_LMZ]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOB JECT]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOB JECT]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOB JECT]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOB JECT]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_C OMBINE]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_C OMBINE]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROT OCOL_WARN_DIALOG]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_L OCKDOWN]:msimn.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_L OCKDOWN]utlook.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_L OCKDOWN]:winmail.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILE CHECK]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILE CHECK]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDS ELECTCONTROL]:excel.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDS ELECTCONTROL]:infopath.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDS ELECTCONTROL]owerpnt.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDS ELECTCONTROL]:winword.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVI GATE_URL]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVI GATE_URL]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVI GATE_URL]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEB OC_IS_UNSAFE]:HelpPane.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZ ECHILD]:msn.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMA NAGEMENT]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMA NAGEMENT]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMA NAGEMENT]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRI CTIONS]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRI CTIONS]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRI CTIONS]:wmplayer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATIO N]:explorer.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATIO N]:iexplore.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATIO N]:PresentationHost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATIO N]revhost.exe =>.Legitimate
                  [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATIO N]:wmplayer.exe =>.Legitimate

                  —\ Observer Of Events (108) - 55s
                  Application.Error: Application Error (159)
                  ~Numéro: 7832
                  ~Date: 10/04/2022 03:57:40 PM
                  ~ID: 1000
                  ~Description: Faulting application name: %1, version: %2, time stamp: 0xa38b9ab2 Faulting module name: %4, version: %5, time stamp: 0xb7ab6594 Exception code: 0xc0000005 Fault offset: 0x0000000000008ee5 Faulting process id: 0x2024 Faulting application start time:
                  ~Suggestion: Réparer ou réinstaller l’application.
                  Application.Warning: ESENT (46)
                  ~Numéro: 7383
                  ~Date: 10/02/2022 09:29:16 PM
                  ~ID: 636
                  ~Description: %1 (%2) %3Flush map file ‘%4’ will be deleted. Reason: %5.
                  ~Suggestion: Aucune
                  Application.Error: VSS (2)
                  ~Numéro: 7335
                  ~Date: 10/02/2022 09:24:44 PM
                  ~ID: 8193
                  ~Description: Volume Shadow Copy Service error: Unexpected error calling routine %1. hr = %2. Operation: Executing Asynchronous OperationContext: Current State: DoSnapshotSet
                  ~Suggestion: Utiliser la procédure de reconstruction du VSS
                  Application.Error: Application Hang (8)
                  ~Numéro: 6972
                  ~Date: 10/01/2022 12:44:50 PM
                  ~ID: 1002
                  ~Description: The program %1 version %2 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 2010 Start Time: 01d8d57a360e
                  ~Suggestion: Essayer les commandes suivantes ipconfig /release et ipconfig / renew.
                  Application.Error: Microsoft-Windows-CAPI2 (20)
                  ~Numéro: 6728
                  ~Date: 10/01/2022 11:35:08 AM
                  ~ID: 513
                  ~Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.%1.
                  Application.Error: Perflib (2)
                  ~Numéro: 6007
                  ~Date: 09/30/2022 04:39:56 PM
                  ~ID: 1023
                  ~Description: rdyboost4
                  Application.Error: COM (8)
                  ~Numéro: 5463
                  ~Date: 09/23/2022 03:00:21 AM
                  ~ID: 10031
                  ~Description: {41FD88F7-F295-4D39-91AC-A85F3149A05B}
                  System.Error: Service Control Manager (282)
                  ~Numéro: 5977
                  ~Date: 10/04/2022 03:57:41 PM
                  ~ID: 7034
                  ~Description: The %1 service terminated unexpectedly. It has done this %2 time(s).
                  System.Error: Microsoft-Windows-Kernel-Power (158)
                  ~Numéro: 5969
                  ~Date: 10/04/2022 03:36:55 PM
                  ~ID: 137
                  ~Description: 4
                  System.Error: DCOM (167)
                  ~Numéro: 5953
                  ~Date: 10/04/2022 12:29:46 PM
                  ~ID: 10010
                  ~Description: Microsoft.Windows.ContentDeliveryManager_10.0.1713 4.1_neutral_neutral_cw5n1h2txyewy!App.AppXwdz8g2fx r36xz0tdtagygnvemf85s7gg.mca
                  System.Warning: Microsoft-Windows-Time-Service (39)
                  ~Numéro: 5899
                  ~Date: 10/04/2022 07:03:07 AM
                  ~ID: 134
                  ~Description: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on ‘%3’. NtpClient will try again in %2 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
                  ~Suggestion: Resynchroniser le client avec l’homologue de source de temps
                  System.Warning: Microsoft-Windows-DNS-Client (11)
                  ~Numéro: 5846
                  ~Date: 10/03/2022 02:33:14 PM
                  ~ID: 1014
                  ~Description: Name resolution for the name %1 timed out after none of the configured DNS servers responded.
                  ~Suggestion: Event ID 1014: Microsoft Windows DNS Client | Microsoft Learn
                  System.Error: cdrom (43)
                  ~Numéro: 5378
                  ~ID: 7
                  ~Description: The device, %1, has a bad block.
                  System.Error: EventLog (5)
                  ~Numéro: 5244
                  ~Date: 10/01/2022 12:14:31 PM
                  ~ID: 6008
                  ~Description: The previous system shutdown at %1 on %2 was unexpected.
                  System.Error: Schannel (66)
                  ~Numéro: 5171
                  ~Date: 10/01/2022 11:22:02 AM
                  ~ID: 4103
                  ~Description: A fatal error occurred while creating a TLS %1 credential. The internal error state is %2.
                  System.Warning: Display (2)
                  ~Numéro: 4690
                  ~Date: 09/27/2022 12:58:33 AM
                  ~ID: 4101
                  ~Description: Display driver %1 stopped responding and has successfully recovered.
                  System.Warning: mfehidk (2)
                  ~Numéro: 4591
                  ~Date: 09/23/2022 02:05:17 AM
                  ~ID: 512
                  ~Description: \Device\mfehidk**\stinger64.exe1312
                  System.Error: Microsoft-Windows-WindowsUpdateClient (195)
                  ~Numéro: 4438
                  ~Date: 09/21/2022 02:07:28 AM
                  ~ID: 20
                  ~Description: Installation Failure: Windows failed to install the following update with error %1: %2.
                  ~Suggestion: EventTracker KB --Event Id: 20 Source: Microsoft-Windows-WindowsUpdateClient
                  System.Warning: Disk (5)
                  ~Numéro: 4068
                  ~Date: 09/14/2022 08:16:31 PM
                  ~ID: 158
                  ~Description: Disk %2 has the same disk identifiers as one or more disks connected to the system. Go to Microsoft’s support website ( http://support.microsoft.com ) and search for KB2983588 to resolve the issue.
                  ~Suggestion: Event ID 158 for identical disk GUIDs - Windows Client | Microsoft Learn
                  System.Warning: Microsoft-Windows-Kernel-PnP (15)
                  ~Numéro: 1144
                  ~Date: 08/09/2022 09:53:46 AM
                  ~ID: 219
                  ~Description: The driver %5 failed to load for the device %2.
                  ~Suggestion: Vérifier que le pilote a bien été chargé dans les informations système

                  —\ Additional Scan (O88) (20) - 5s
                  [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.FriendlyAppName =>.SUP.Orphan.MUICache
                  [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.ApplicationCompa ny =>.SUP.Orphan.MUICache
                  [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\KMPlayer\KMPlayer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
                  [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\KMPlayer\KMPlayer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
                  [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\qbittorrent_4.4.4_x64_se tup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
                  [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\qbittorrent_4.4.4_x64_se tup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
                  [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\VirtualBox-6.1.36-152435-Win.exe.FriendlyAppName =>.SUP.Orphan.MUICache
                  [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\VirtualBox-6.1.36-152435-Win.exe.ApplicationCompany =>.SUP.Orphan.MUICache
                  [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\AppData\Local\Popcorn-Time\Popcorn-Time.exe.FriendlyAppName =>.SUP.Orphan.MUICache
                  [HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\AppData\Local\Popcorn-Time\Popcorn-Time.exe.ApplicationCompany =>.SUP.Orphan.MUICache
                  [HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.FriendlyAppName =>.SUP.Orphan.MUICache
                  [HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\qBittorrent\qbittorrent.exe.ApplicationCompa ny =>.SUP.Orphan.MUICache
                  [HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\KMPlayer\KMPlayer.exe.FriendlyAppName =>.SUP.Orphan.MUICache
                  [HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\KMPlayer\KMPlayer.exe.ApplicationCompany =>.SUP.Orphan.MUICache
                  [HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\qbittorrent_4.4.4_x64_se tup.exe.FriendlyAppName =>.SUP.Orphan.MUICache
                  [HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\qbittorrent_4.4.4_x64_se tup.exe.ApplicationCompany =>.SUP.Orphan.MUICache
                  [HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\VirtualBox-6.1.36-152435-Win.exe.FriendlyAppName =>.SUP.Orphan.MUICache
                  [HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\Desktop\VirtualBox-6.1.36-152435-Win.exe.ApplicationCompany =>.SUP.Orphan.MUICache
                  [HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\AppData\Local\Popcorn-Time\Popcorn-Time.exe.FriendlyAppName =>.SUP.Orphan.MUICache
                  [HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Users\TeaTang\AppData\Local\Popcorn-Time\Popcorn-Time.exe.ApplicationCompany =>.SUP.Orphan.MUICache

                  —\ Summary of the elements found (5) - 0s
                  Zone Anti-Malware - ZAM =>.SUP.Orphan
                  Zone Anti-Malware - ZAM =>.SUP.Discord
                  Zone Anti-Malware - ZAM =>Warning.EventLogApp
                  Zone Anti-Malware - ZAM =>Warning.EventLogSys
                  Zone Anti-Malware - ZAM =>.SUP.Orphan.MUICache

                  ~ Unselected Options: WR,
                  ~ End of the scan, 13270 items in 03mn01s (1727)(0)

                  [HEADING=2]Serial Number[/HEADING]
                  [00A657F778B31AE523D667131718D16EB2] [04/10/2022] (.Malwarebytes Inc..) - C:\Users\TeaTang\Desktop\adwcleaner.exe
                  [00A657F778B31AE523D667131718D16EB2] [08/08/2022] (.Malwarebytes Inc..) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
                  [00A657F778B31AE523D667131718D16EB2] [08/08/2022] (.Malwarebytes Inc..) - C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll
                  [00A657F778B31AE523D667131718D16EB2] [08/08/2022] (.Malwarebytes Inc..) - C:\Program Files\Malwarebytes\Anti-Malware\mbuns.exe
                  [00A657F778B31AE523D667131718D16EB2] [13/09/2022] (.Malwarebytes Inc..) - C:\ProgramData\Malwarebytes\MBAMService\lkg_db\Act ions.dll
                  [00A657F778B31AE523D667131718D16EB2] [13/09/2022] (.Malwarebytes Inc..) - C:\ProgramData\Malwarebytes\MBAMService\lkg_db\Bro wserSDKDLL.dll
                  [00A657F778B31AE523D667131718D16EB2] [13/09/2022] (.Malwarebytes Inc..) - C:\ProgramData\Malwarebytes\MBAMService\lkg_db\ig. exe
                  [00A657F778B31AE523D667131718D16EB2] [13/09/2022] (.Malwarebytes Inc..) - C:\ProgramData\Malwarebytes\MBAMService\lkg_db\MBA MCore.dll
                  [00A657F778B31AE523D667131718D16EB2] [13/09/2022] (.Malwarebytes Inc..) - C:\ProgramData\Malwarebytes\MBAMService\lkg_db\sam ple.dll
                  [00C82FAC5D4F7288471464A39982A0D37F] [01/10/2022] (.CrystalBit Solutions.) - C:\Users\TeaTang\Desktop\geek\geek.exe
                  [00C82FAC5D4F7288471464A39982A0D37F] [03/10/2022] (.CrystalBit Solutions.) - C:\Users\TeaTang\AppData\Local\Temp\geek64.exe
                  [01993E38970DE6088DE6B6CB39BBEE24] [08/09/2022] (.Cisco WebEx LLC.) - C:\Users\TeaTang\AppData\Local\Discord\app-1.0.9006\modules\discord_voice-2\discord_voice\openh264-2.2.0-win32.dll
                  [01E20D5BE0B5190B1DBFDE9BEF380D9A] [08/08/2022] (.Discord Inc..) - C:\Users\TeaTang\AppData\Local\Discord\Update.exe =>.SUP.Discord
                  [01E20D5BE0B5190B1DBFDE9BEF380D9A] [12/09/2022] (.Discord Inc..) - C:\Users\TeaTang\AppData\Local\Discord\app-1.0.9006\modules\discord_voice-2\discord_voice\capture_helper.exe =>.SUP.Discord
                  [01E20D5BE0B5190B1DBFDE9BEF380D9A] [12/09/2022] (.Discord Inc..) - C:\Users\TeaTang\AppData\Local\Discord\app-1.0.9006\modules\discord_voice-2\discord_voice\mediapipe.dll =>.SUP.Discord
                  [0320BE3EB866526927F999B97B04346E] [26/02/2019] (.Realtek Semiconductor Corp..) - C:\Windows\System32\drivers\rtwlanu.sys
                  [0320BE3EB866526927F999B97B04346E] [26/02/2019] (.Realtek Semiconductor Corp..) - C:\Windows\System32\rtwlanu.sys
                  [0407ABB64E9990180789EACB81F5F914] [24/03/2022] (.VideoLAN.) - C:\Program Files\VideoLAN\VLC\vlc.exe
                  [044E3BF58976880FFD074448A8F7A058] [09/08/2022] (.Malwarebytes Corporation.) - C:\Windows\System32\drivers\6247C596.sys
                  [0689B3BCEB4409890A32D71976B132A4] [22/03/2022] (.Valve Corp..) - C:\Program Files (x86)\Steam\uninstall.exe
                  [0689B3BCEB4409890A32D71976B132A4] [26/07/2022] (.Valve Corp..) - C:\Program Files (x86)\Common Files\Steam\steamservice.exe
                  [0689B3BCEB4409890A32D71976B132A4] [26/07/2022] (.Valve Corp..) - C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
                  [0689B3BCEB4409890A32D71976B132A4] [26/07/2022] (.Valve Corp..) - C:\Program Files (x86)\Steam\steam.exe
                  [09268FAA1AD6894D179E5B87A2F06462] [14/09/2017] (.LunarG, Inc..) - C:\Program Files (x86)\VulkanRT\1.0.61.0\UninstallVulkanRT.exe
                  [0A399503A667F69C5AFA53B47EDCC135] [07/06/2021] (.NetEase(Hangzhou) Network Co. Ltd..) - C:\Program Files (x86)\Cyber Hunter\launcher.exe =>.Not verified
                  [0A399503A667F69C5AFA53B47EDCC135] [07/06/2021] (.NetEase(Hangzhou) Network Co. Ltd..) - C:\Program Files (x86)\Cyber Hunter\uninstall.exe =>.Not verified
                  [14781BC862E8DC503A559346F5DCC518] [09/11/2017] (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvhda64v.sys
                  [14781BC862E8DC503A559346F5DCC518] [09/11/2017] (.NVIDIA Corporation.) - C:\Windows\System32\DriverStore\FileRepository\nv_ ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys
                  [14781BC862E8DC503A559346F5DCC518] [27/10/2017] (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe
                  [14781BC862E8DC503A559346F5DCC518] [27/10/2017] (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe
                  [14781BC862E8DC503A559346F5DCC518] [27/10/2017] (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe
                  [1535EDA3C8F2FED30D4497572760F240] [24/08/2011] (.Crawler, LLC.) - C:\Windows\System32\drivers\stflt.sys
                  [1877A57C210DBBD1CCE4B4424F5D2F9F] [04/10/2022] (.d7xTech, Inc.) - C:\Users\TeaTang\Desktop\KillEmAll\KillEmAll.exe =>.Not verified
                  [19EA4DAF089570861408E9F05EFD9B89] [13/07/2022] (.Power Software Limited.) - C:\Program Files\AnyBurn\AnyBurn.exe =>.Not verified
                  [266D333EDE17A8B472053E4FA3934572] [11/08/2022] (.AVG Technologies CZ, s.r.o..) - C:\Windows\System32\drivers\rm.sys
                  [317DD1C55F51AC2756D9C93C060C6FA5] [04/10/2022] (.Pawan Kumar.) - C:\Users\TeaTang\Desktop\adware-removal-tool-by-tsa.exe =>.Not verified
                  [31F8F5FB790C592476CE0F3320DC4AF1] [01/10/2022] (.Stanislav Polshyn.) - C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\Che ckBrowsersLNK\Check Browsers LNK.exe =>.Not verified
                  [31F8F5FB790C592476CE0F3320DC4AF1] [01/10/2022] (.Stanislav Polshyn.) - C:\Users\TeaTang\Desktop\AutoLogger\AutoLogger\HiJ ackThis\HiJackThis.exe =>.Not verified
                  [31F8F5FB790C592476CE0F3320DC4AF1] [02/10/2022] (.Stanislav Polshyn.) - C:\Users\TeaTang\Desktop\ClearLNK.exe =>.Not verified
                  [51CA009816FDBD80F120E015EE75823E] [19/07/2022] (.Oracle Corporation.) - C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe
                  [51CA009816FDBD80F120E015EE75823E] [19/07/2022] (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys
                  [51CA009816FDBD80F120E015EE75823E] [19/07/2022] (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxNetLwf.sys
                  [51CA009816FDBD80F120E015EE75823E] [19/07/2022] (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxSup.sys
                  [51CA009816FDBD80F120E015EE75823E] [19/07/2022] (.Oracle Corporation.) - C:\Windows\System32\DRIVERS\VBoxUSBMon.sys
                  [56C6D267ADE07F72EEB4603BBF84CEA5] [20/07/2017] (.Red Hat, Inc..) - C:\Windows\System32\drivers\balloon.sys =>.Not verified
                  [56C6D267ADE07F72EEB4603BBF84CEA5] [20/07/2017] (.Red Hat, Inc..) - C:\Windows\System32\drivers\viorng.sys =>.Not verified
                  [56C6D267ADE07F72EEB4603BBF84CEA5] [20/07/2017] (.Red Hat, Inc..) - C:\Windows\System32\drivers\viostor.sys =>.Not verified
                  [58ED019DDA867257493E61E5F18DFAF4] [16/10/2017] (.Power Software Limited.) - C:\Program Files\AnyBurn\abcmd.exe
                  [7D9E9888D0F97A5432827A5E] [01/10/2022] (.McAfee, LLC.) - C:\Users\TeaTang\Desktop\MCPR.exe =>.Not verified

                  Comment

                  • Malnutrition
                    PCHF Moderator
                    • Jul 2016
                    • 7041

                    #24
                    OK I’ll have a look when I return home from work.

                    Comment

                    • Malnutrition
                      PCHF Moderator
                      • Jul 2016
                      • 7041

                      #25
                      FRST Fix.

                      Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.



                      Download GlassWire Firewall.
                      Install on your machine.
                      Then Run kill em all.
                      Then restart Glasswire.
                      Go to firewall icon click it within the program.
                      Then start your browser.
                      You will get an alert from Glasswire.
                      Then click Analyze.
                      Under Virus Total.
                      Click enable virustotal, in Glasswire settings.
                      Unlock the feature then click enable manual file analysis
                      Then click auto analysis of all apps.
                      Click ok.

                      Now you will be able to see anything and everything that is connected inbound or outbound on your machine, if there is a rat then this will tell you without a doubt.

                      Comment

                      • puki
                        PCHF Member
                        • Sep 2022
                        • 29

                        #26
                        By the way after i done the ‘‘fix’’ using FRST.
                        I was unable to login only in this site.
                        So i downloaded and installed another browser.
                        [HEADING=1]Fix result of Farbar Recovery Scan Tool (x64) Version: 30-08-2022
                        Ran by TeaTang (05-10-2022 16:07:58) Run:1
                        Running from C:\Users\TeaTang\Desktop
                        Loaded Profiles: TeaTang
                        Boot Mode: Normal[/HEADING]
                        fixlist content:


                        Start::
                        CloseProcesses:
                        SystemRestore: On
                        CreateRestorePoint:
                        RemoveProxy:
                        DeleteKey: HKLM\SOFTWARE\Avast Software
                        DeleteKey: HKLM\SOFTWARE\COMODO
                        DeleteKey: HKLM\SOFTWARE\HitmanPro
                        DeleteKey: HKLM\SOFTWARE\TrendMicro
                        DeleteKey: HKLM\SOFTWARE\WOW6432Node\Adware Removal Tool by TSA
                        DeleteKey: HKLM\SOFTWARE\WOW6432Node\Avast Software
                        DeleteKey: HKLM\SOFTWARE\WOW6432Node\MCPR
                        DeleteKey: HKLM\SOFTWARE\WOW6432Node\MicroWorld
                        DeleteKey: HKLM\SOFTWARE\WOW6432Node\TrendMicro
                        DeleteKey: HKCU\SOFTWARE\AVAST Software
                        DeleteKey: HKCU\SOFTWARE\MicroWorld
                        DeleteKey: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\AVAST Software
                        DeleteKey: HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\MicroWorld
                        VirusTotal: c:\program files\windowsapps\microsoft.windowscommunicationsa pps_16005.14326.20970.0_x64__8wekyb3d8bbwe\hxtsr.e xe
                        C:\ProgramData\Avira
                        C:\Program Files (x86)\Common Files\MicroWorld
                        C:\Users\TeaTang\AppData\Local\Avira
                        C:\Windows\System32\drivers\rm.sys
                        C:\Windows\System32\drivers\stflt.sys
                        CMD: wmic nicconfig where (IPEnabled=TRUE) call SetDNSServerSearchOrder (“76.76.19.19”, “94.140.15.15”)
                        CMD: sc stop WSearch
                        CMD: sc config WSearch start= disabled
                        CMD: sc stop lfsvc
                        CMD: sc config lfsvc start= disabled
                        CMD: del /s /q %ProgramData%\Microsoft\Diagnosis\ETLLogs\AutoLogg er\AutoLogger-Diagtrack-Listener.etl
                        CMD: reg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQM Client\parameters /v DisabledComponents /t REG_DWORD /d 0xFFFFFFFF
                        CMD: reg add hklm\system\currentcontrolset\services\tcpip6\para meters /v DisabledComponents /t REG_DWORD /d 0xFFFFFFFF
                        CMD: ipconfig /flushdns
                        C:\Windows\Temp*.*
                        C:\WINDOWS\system32*.tmp
                        C:\WINDOWS\syswow64*.tmp
                        emptytemp:
                        Reboot:
                        End::


                        Processes closed successfully.
                        SystemRestore: On => completed
                        Restore point was successfully created.

                        ========= RemoveProxy: =========

                        “HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVer sion\Internet Settings\Connections\DefaultConnectionSettings” => removed successfully
                        “HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\DefaultConnectionSettings” => removed successfully
                        “HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\SavedLegacySettings” => removed successfully

                        ========= End of RemoveProxy: =========

                        HKLM\SOFTWARE\Avast Software => removed successfully
                        HKLM\SOFTWARE\COMODO => removed successfully
                        HKLM\SOFTWARE\HitmanPro => removed successfully
                        HKLM\SOFTWARE\TrendMicro => removed successfully
                        HKLM\SOFTWARE\WOW6432Node\Adware Removal Tool by TSA => removed successfully
                        RegLink Found. Source: “” => Target: “HKLM\SOFTWARE\Avast Software”
                        “HKLM\SOFTWARE\WOW6432Node\Avast Software” => removed successfully
                        HKLM\SOFTWARE\WOW6432Node\MCPR => removed successfully
                        HKLM\SOFTWARE\WOW6432Node\MicroWorld => removed successfully
                        HKLM\SOFTWARE\WOW6432Node\TrendMicro => removed successfully
                        HKCU\SOFTWARE\AVAST Software => removed successfully
                        HKCU\SOFTWARE\MicroWorld => removed successfully
                        HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\AVAST Software => not found
                        HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\MicroWorld => not found
                        VirusTotal: c:\program files\windowsapps\microsoft.windowscommunicationsa pps_16005.14326.20970.0_x64__8wekyb3d8bbwe\hxtsr.e xe => VirusTotal
                        C:\ProgramData\Avira => moved successfully
                        C:\Program Files (x86)\Common Files\MicroWorld => moved successfully
                        C:\Users\TeaTang\AppData\Local\Avira => moved successfully
                        C:\Windows\System32\drivers\rm.sys => moved successfully
                        C:\Windows\System32\drivers\stflt.sys => moved successfully

                        ========= wmic nicconfig where (IPEnabled=TRUE) call SetDNSServerSearchOrder (“76.76.19.19”, “94.140.15.15”) =========

                        Executing (\DESKTOP-GRKBJ8K\ROOT\CIMV2:Win32_NetworkAdapterConfigurati on.Index=10)->SetDNSServerSearchOrder()

                        Method execution successful.

                        Out Parameters:
                        instance of __PARAMETERS
                        {
                        ReturnValue = 0;
                        };
                        Executing (\DESKTOP-GRKBJ8K\ROOT\CIMV2:Win32_NetworkAdapterConfigurati on.Index=13)->SetDNSServerSearchOrder()

                        Method execution successful.

                        Out Parameters:
                        instance of __PARAMETERS
                        {
                        ReturnValue = 0;
                        };

                        ========= End of CMD: =========

                        ========= sc stop WSearch =========

                        SERVICE_NAME: WSearch
                        TYPE : 10 WIN32_OWN_PROCESS
                        STATE : 3 STOP_PENDING
                        (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
                        WIN32_EXIT_CODE : 0 (0x0)
                        SERVICE_EXIT_CODE : 0 (0x0)
                        CHECKPOINT : 0x1
                        WAIT_HINT : 0x7530

                        ========= End of CMD: =========

                        ========= sc config WSearch start= disabled =========

                        [SC] ChangeServiceConfig SUCCESS

                        ========= End of CMD: =========

                        ========= sc stop lfsvc =========

                        SERVICE_NAME: lfsvc
                        TYPE : 30 WIN32
                        STATE : 3 STOP_PENDING
                        (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
                        WIN32_EXIT_CODE : 0 (0x0)
                        SERVICE_EXIT_CODE : 0 (0x0)
                        CHECKPOINT : 0x2
                        WAIT_HINT : 0x2710

                        ========= End of CMD: =========

                        ========= sc config lfsvc start= disabled =========

                        [SC] ChangeServiceConfig SUCCESS

                        ========= End of CMD: =========

                        ========= del /s /q %ProgramData%\Microsoft\Diagnosis\ETLLogs\AutoLogg er\AutoLogger-Diagtrack-Listener.etl =========

                        Could Not Find C:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLog ger\AutoLogger-Diagtrack-Listener.etl

                        ========= End of CMD: =========

                        ========= reg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQM Client\parameters /v DisabledComponents /t REG_DWORD /d 0xFFFFFFFF =========

                        The operation completed successfully.

                        ========= End of CMD: =========

                        ========= reg add hklm\system\currentcontrolset\services\tcpip6\para meters /v DisabledComponents /t REG_DWORD /d 0xFFFFFFFF =========

                        The operation completed successfully.

                        ========= End of CMD: =========

                        ========= ipconfig /flushdns =========

                        Windows IP Configuration

                        Successfully flushed the DNS Resolver Cache.

                        ========= End of CMD: =========

                        =========== “C:\Windows\Temp*.*” ==========

                        C:\Windows\Temp\HighPerformancePlan.log => moved successfully
                        Could not move “C:\Windows\Temp\MpCmdRun.log” => Scheduled to move on reboot.
                        C:\Windows\Temp\MpSigStub.log => moved successfully
                        C:\Windows\Temp\PowerPlan.log => moved successfully
                        C:\Windows\Temp\sa.9WZDNCRFHW41_0__.Public.Install Agent.dat => moved successfully
                        C:\Windows\Temp\sa.9WZDNCRFJ27N_0__.Public.Install Agent.dat => moved successfully
                        C:\Windows\Temp\UsoStoreFile.xml => moved successfully

                        ========= End → “C:\Windows\Temp*.*” ========

                        =========== “C:\WINDOWS\system32*.tmp” ==========

                        not found

                        ========= End → “C:\WINDOWS\system32*.tmp” ========

                        =========== “C:\WINDOWS\syswow64*.tmp” ==========

                        not found

                        ========= End → “C:\WINDOWS\syswow64*.tmp” ========

                        =========== EmptyTemp: ==========

                        FlushDNS => completed
                        BITS transfer queue => 786432 B
                        DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10611814 B
                        Java, Discord, Steam htmlcache => 0 B
                        Windows/system/drivers => 40960 B
                        Edge => 14534675 B
                        Firefox => 0 B
                        Opera => 0 B

                        Temp, IE cache, history, cookies, recent:
                        Default => 0 B
                        ProgramData => 0 B
                        Public => 0 B
                        systemprofile => 0 B
                        systemprofile32 => 0 B
                        LocalService => 0 B
                        NetworkService => 12096 B
                        TeaTang => 7108396 B

                        RecycleBin => 0 B
                        EmptyTemp: => 31.6 MB temporary data Removed.

                        ================================

                        Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 05-10-2022 16:10:21)

                        C:\Windows\Temp\MpCmdRun.log => Is moved successfully

                        ==== End of Fixlog 16:10:21 ====

                        Comment

                        • puki
                          PCHF Member
                          • Sep 2022
                          • 29

                          #27
                          Don’t know what was wrong,but i was unable to enter only in this site.
                          Originally posted by Malnutrition
                          Then Run kill em all.
                          How to do that?

                          Comment

                          • Malnutrition
                            PCHF Moderator
                            • Jul 2016
                            • 7041

                            #28
                            The kill em all program you used earlier.

                            As far as not being able to log into the site, I’m not sure on that. There was nothing in the fix related to chrome or Firefox. Only redundant files.

                            Comment

                            • puki
                              PCHF Member
                              • Sep 2022
                              • 29

                              #29
                              Aha,i done it.

                              Comment

                              • Malnutrition
                                PCHF Moderator
                                • Jul 2016
                                • 7041

                                #30
                                Ok now test for a while and see if any unusual connection attempts are made, you will be able to see with glassware, if anyone is attempting to connect.

                                Also, how is your internet now, and better, what symptoms have you had today?

                                Comment

                                Working...