Solved Hundreds of rundll32.exe running

  • Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
Status
Not open for further replies.
C:\Windows\Installer\SandboxieInstall64.exe\SandboxieWUAU.exe - infected with Trojan.Siggen29.2294

Then install Everything search.
Right Click on the VoidTools application and Run As Administrator.
Type Sandboxie into the Everything Search Window.
Now Click on Edit Then Select all.
Right click highlighted items.
Copy, then paste here.




 
  • Like
Reactions: maxim123
Look in the Autologger folder and drag out the CheckBrowsersLNK file.
To your desktop.

AutoLogger\CheckBrowserLnk
Drag and drop onto the ClearLNK utility .
After saving ClearLNK to desktop.
move.gif


Remove also Sandboxie 5.67.9 with geek uninstaller "C:\Windows\Installer\SandboxieInstall64.exe" /remove



ZHP cleaner Scan.


Please download Zhp Cleaner to your desktop. Right Click the icon and select run as administrator.
Once you have started the program, you will need to click the scanner button.
The program will close all open browsers!
Once the scan is completed, the you will want to click the Repair button.
At the end of the process you may be asked to reboot your machine.
After you reboot a report will open on your desktop.
Attach the report here in your next reply.
 
  • Like
Reactions: maxim123
C:\Windows\Installer\SandboxieInstall64.exe\SandboxieWUAU.exe - infected with Trojan.Siggen29.2294

Then install Everything search.
Right Click on the VoidTools application and Run As Administrator.
Type Sandboxie into the Everything Search Window.
Now Click on Edit Then Select all.
Right click highlighted items.
Copy, then paste here.




Code:
C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
D:\Program Files\Sandboxie
D:\software\Sandboxie-Classic-x64-v5.67.9.exe
D:\software\Sandboxie-Plus-x64-v1.12.9.exe
C:\Windows\Sandboxie.ini
C:\Windows\Prefetch\SANDBOXIECRYPTO.EXE-E4FFD057.pf
C:\Windows\Prefetch\SANDBOXIEDCOMLAUNCH.EXE-CA6875F0.pf
C:\Windows\Prefetch\SANDBOXIERPCSS.EXE-B24149E1.pf
 
Copy the content of the code box below.
Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.


Code:
start::
SystemRestore: On
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
HKU\S-1-5-19\...\RunOnce: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe /background /setautostart (No File)
HKU\S-1-5-20\...\RunOnce: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe /background /setautostart (No File)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
S2 IDMWFP; \SystemRoot\System32\drivers\idmwfp.sys [X]
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
D:\Program Files\Sandboxie\SbieSvc.exe
d:\Program Files\Sandboxie\SbieDrv.sys
C:\WINDOWS\Sandboxie.ini
C:\WINDOWS\system32\prfh0804.dat
C:\WINDOWS\system32\prfc0804.dat
R2 SbieSvc; d:\Program Files\Sandboxie\SbieSvc.exe [410576 2024-02-06] (Tonalio GmbH -> Sandboxie-Plus.com)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
AlternateDataStreams: C:\ProgramData\autoclickconfig.ini:07021500A6 [5162]
AlternateDataStreams: C:\ProgramData\empty.ico:8C1C1B484F [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk:A1B76439FE [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk:088221F38A [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk:FE00AE19CB [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:41964AA945 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk:B96E9B8455 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk:C5112377E0 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk:980850BA8A [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk:C5D586BE93 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk:E77773B271 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk:60EC9648C0 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk:5465085A2F [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk:1DC1525F34 [5162]
FirewallRules: [UDP Query User{40B857EF-FDFA-46C0-8ECB-B7155F5BFFB9}C:\users\ripple\appdata\local\discord\app-1.0.9153\discord.exe] => (Block) C:\users\ripple\appdata\local\discord\app-1.0.9153\discord.exe => No File
FirewallRules: [TCP Query User{5F082408-619B-4016-9E24-368A236AC45F}C:\users\ripple\appdata\local\discord\app-1.0.9153\discord.exe] => (Block) C:\users\ripple\appdata\local\discord\app-1.0.9153\discord.exe => No File
FirewallRules: [UDP Query User{F61ACD2C-ED51-4C09-908D-87EF7B26E99A}D:\games\lysfanga - the time shift warrior\lysfanga the time shift warrior.exe] => (Allow) D:\games\lysfanga - the time shift warrior\lysfanga the time shift warrior.exe => No File
FirewallRules: [TCP Query User{97C07BDA-EA0D-4E94-B850-C891A7F18930}D:\games\lysfanga - the time shift warrior\lysfanga the time shift warrior.exe] => (Allow) D:\games\lysfanga - the time shift warrior\lysfanga the time shift warrior.exe => No File
FirewallRules: [{B5F1EAB2-E29C-4A5B-9360-446DC2EF1197}] => (Allow) C:\Users\Ripple\AppData\Roaming\Zoom\bin\Zoom.exe => No File
FirewallRules: [UDP Query User{7C19BB32-A3DD-4A37-8437-9882847C9D6B}D:\games\baldur's gate 3\bin\bg3_dx11.exe] => (Allow) D:\games\baldur's gate 3\bin\bg3_dx11.exe => No File
FirewallRules: [TCP Query User{3BAA4325-7379-43B5-AE1E-83C16CC8F3BF}D:\games\baldur's gate 3\bin\bg3_dx11.exe] => (Allow) D:\games\baldur's gate 3\bin\bg3_dx11.exe => No File
FirewallRules: [{9F4DD023-8D55-432D-B836-373C55A682C2}] => (Allow) C:\Program Files\OEM\Control Center\UniwillService\GCUBridge.exe => No File
FirewallRules: [{9208502E-6687-40E3-8CC5-9884A5F94918}] => (Allow) C:\Program Files\OEM\Control Center\UniwillService\GCUBridge.exe => No File
C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
D:\Program Files\Sandboxie
D:\software\Sandboxie-Classic-x64-v5.67.9.exe
D:\software\Sandboxie-Plus-x64-v1.12.9.exe
C:\Windows\Sandboxie.ini
C:\Windows\Prefetch\SANDBOXIECRYPTO.EXE-E4FFD057.pf
C:\Windows\Prefetch\SANDBOXIEDCOMLAUNCH.EXE-CA6875F0.pf
C:\Windows\Prefetch\SANDBOXIERPCSS.EXE-B24149E1.pf
CMD: dism /online /cleanup-image /restorehealth
CMD: sfc /scannow
Hosts:
RemoveProxy:
CMD: del /s /q C:\Windows\SoftwareDistribution\download\*.*
CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
C:\Windows\Temp\*.*
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
emptytemp:
Reboot:
End::

 
  • Like
Reactions: maxim123
Look in the Autologger folder and drag out the CheckBrowsersLNK file.
To your desktop.


Drag and drop onto the ClearLNK utility .
After saving ClearLNK to desktop.
move.gif


Remove also Sandboxie 5.67.9 with geek uninstaller "C:\Windows\Installer\SandboxieInstall64.exe" /remove



ZHP cleaner Scan.


Please download Zhp Cleaner to your desktop. Right Click the icon and select run as administrator.
Once you have started the program, you will need to click the scanner button.
The program will close all open browsers!
Once the scan is completed, the you will want to click the Repair button.
At the end of the process you may be asked to reboot your machine.
After you reboot a report will open on your desktop.
Attach the report here in your next reply.
removed sandboxie with geek earlier.

here is the zhpcleaner log:

Code:
~ ZHPCleaner v2024.7.16.22 by Nicolas Coolman (2024/07/16)
~ Run by Max (Administrator)  (17/07/2024 14:58:29)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\Ripple\Desktop\ZHPCleaner (R).txt
~ Quarantine : C:\Users\Ripple\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point : OK
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 11, 64-bit  (Build 22631)


---\\  Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)


---\\  Hosts file (1)
~ The hosts file is legitimate (1)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (11)
MOVED file: C:\Users\Ripple\AppData\Local\Google\Chrome\User Data\Default\History    =>.SUP.BrowserHistoric
MOVED file^: C:\Users\Ripple\AppData\Local\Microsoft\Edge\User Data\Default\History    =>.SUP.BrowserHistoric
MOVED file: C:\Users\Ripple\Desktop\Goose Goose Duck.url    =>.SUP.MaxStart
MOVED file: C:\Users\Ripple\Downloads\DiscordSetup.exe [Discord Inc. - Discord - https://discord.com/]  =>.SUP.Discord
MOVED file: C:\Users\Ripple\Downloads\Programs\DiscordSetup.exe [Discord Inc. - Discord - https://discord.com/]  =>.SUP.Discord
MOVED file: C:\Users\Ripple\Downloads\Programs\DiscordSetup_2.exe [Discord Inc. - Discord - https://discord.com/]  =>.SUP.Discord
MOVED folder: C:\Users\Ripple\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data  =>.SUP.BrowserCache
MOVED folder: C:\Users\Ripple\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data  =>.SUP.BrowserCache
MOVED folder: C:\Users\Ripple\AppData\Local\Mozilla\Firefox\Profiles\g5q70h39.default\Cache2  =>.SUP.BrowserCache
MOVED folder: C:\Users\Ripple\AppData\Local\Mozilla\Firefox\Profiles\10706u2g.default-release\Cache2  =>.SUP.BrowserCache
MOVED folder: C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc  =>.SUP.Discord


---\\  Registry ( Key, Value, Data) (9)
DELETED key*: HKEY_USERS\S-1-5-21-2515384590-1499498081-2273501178-1001\SOFTWARE\Discord []  =>.SUP.Discord
DELETED key*: HKEY_USERS\S-1-5-21-2515384590-1499498081-2273501178-1001\SOFTWARE\Classes\AppXq0pwa73vfcn2qdexp8cexcc6qk87xh1r []  =>Adware.Navipromo
DELETED key*: HKEY_USERS\S-1-5-21-2515384590-1499498081-2273501178-1001\SOFTWARE\Classes\Discord [URL:Discord Protocol]  =>.SUP.Discord
DELETED key*: HKEY_USERS\S-1-5-21-2515384590-1499498081-2273501178-1001\SOFTWARE\Classes\discord-668664413363896342 [URL:Run game 668664413363896342 protocol]  =>.SUP.Discord
DELETED key*: HKEY_USERS\S-1-5-21-2515384590-1499498081-2273501178-1001\SOFTWARE\Classes\discord-712465656758665259 [URL:Run game 712465656758665259 protocol]  =>.SUP.Discord
DELETED key**: HKCU\Software\Discord []  =>.SUP.Discord
DELETED key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Discord [Discord Inc.]  =>.SUP.Discord
DELETED key*: HKCU\SOFTWARE\A21E65384510C8D70C21 []  =>Hijacker.Browser
DELETED value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Discord ["C:\Users\Ripple\AppData\Local\Discord\Update.exe"]  =>.SUP.Discord


---\\  Summary of the elements found (6)
https://nicolascoolman.eu/2023/07/18/les-caches-et-historiques-de-navigateurs/  =>.SUP.BrowserHistoric
https://nicolascoolman.eu/forum/Topic/logiciels-potentiellement-superflus-lps/  =>.SUP.MaxStart
https://nicolascoolman.eu/forum/Topic/Discord-logiciel-potentiellement-superflu-lps/  =>.SUP.Discord
https://nicolascoolman.eu/2023/07/18/les-caches-et-historiques-de-navigateurs/  =>.SUP.BrowserCache
https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/  =>Adware.Navipromo
https://nicolascoolman.eu/2017/11/10/hijacker-browser-3/  =>Hijacker.Browser


---\\  Other deletions. (19)
~ Registry Keys Tracing deleted (19)
~ Remove the old reports ZHPCleaner. (0)


---\\ Result of repair
~ Repair carried out successfully
~ Google Chrome OK
~ Microsoft Edge OK
~ Mozilla Firefox OK
~ Microsoft Internet Explorer OK
~ The system has been restarted.


---\\ Statistics
~ Items scanned : 1871
~ Items found : 0
~ Items cancelled : 0
~ Space saving (bytes) : 0
~ Items options : 10/18


---\\ OPTIONS NOT ACTIVES
~ Temporary file analysis
~ Temporary folder analysis
~ Empty Folder CLSID Analysis
~ Empty Other Folder Analysis
~ Empty LocalLow Folder Analysis
~ Empty Local Folder Analysis
~ Obsolete Installer File Analysis
~ Start browsers with extensions removed





~ End of clean in 00h00mn35s

---\\  Reports (2)
ZHPCleaner-[S]-17072024-14_56_27.txt
ZHPCleaner-[R]-17072024-14_59_04.txt
 
Copy the content of the code box below.
Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.
Fixlog

Code:
Fix result of Farbar Recovery Scan Tool (x64) Version: 16.07.2024
Ran by Max (17-07-2024 15:13:50) Run:2
Running from C:\Users\Ripple\Desktop
Loaded Profiles: Max
Boot Mode: Normal
==============================================

fixlist content:
*****************
start::
SystemRestore: On
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
HKU\S-1-5-19\...\RunOnce: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe /background /setautostart (No File)
HKU\S-1-5-20\...\RunOnce: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe /background /setautostart (No File)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
S2 IDMWFP; \SystemRoot\System32\drivers\idmwfp.sys [X]
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
D:\Program Files\Sandboxie\SbieSvc.exe
d:\Program Files\Sandboxie\SbieDrv.sys
C:\WINDOWS\Sandboxie.ini
C:\WINDOWS\system32\prfh0804.dat
C:\WINDOWS\system32\prfc0804.dat
R2 SbieSvc; d:\Program Files\Sandboxie\SbieSvc.exe [410576 2024-02-06] (Tonalio GmbH -> Sandboxie-Plus.com)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001_1\amd64\FileSyncShell64.dll -> No File
AlternateDataStreams: C:\ProgramData\autoclickconfig.ini:07021500A6 [5162]
AlternateDataStreams: C:\ProgramData\empty.ico:8C1C1B484F [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk:A1B76439FE [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk:088221F38A [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk:FE00AE19CB [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:41964AA945 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk:B96E9B8455 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk:C5112377E0 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk:980850BA8A [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk:C5D586BE93 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk:E77773B271 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk:60EC9648C0 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk:5465085A2F [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk:1DC1525F34 [5162]
FirewallRules: [UDP Query User{40B857EF-FDFA-46C0-8ECB-B7155F5BFFB9}C:\users\ripple\appdata\local\discord\app-1.0.9153\discord.exe] => (Block) C:\users\ripple\appdata\local\discord\app-1.0.9153\discord.exe => No File
FirewallRules: [TCP Query User{5F082408-619B-4016-9E24-368A236AC45F}C:\users\ripple\appdata\local\discord\app-1.0.9153\discord.exe] => (Block) C:\users\ripple\appdata\local\discord\app-1.0.9153\discord.exe => No File
FirewallRules: [UDP Query User{F61ACD2C-ED51-4C09-908D-87EF7B26E99A}D:\games\lysfanga - the time shift warrior\lysfanga the time shift warrior.exe] => (Allow) D:\games\lysfanga - the time shift warrior\lysfanga the time shift warrior.exe => No File
FirewallRules: [TCP Query User{97C07BDA-EA0D-4E94-B850-C891A7F18930}D:\games\lysfanga - the time shift warrior\lysfanga the time shift warrior.exe] => (Allow) D:\games\lysfanga - the time shift warrior\lysfanga the time shift warrior.exe => No File
FirewallRules: [{B5F1EAB2-E29C-4A5B-9360-446DC2EF1197}] => (Allow) C:\Users\Ripple\AppData\Roaming\Zoom\bin\Zoom.exe => No File
FirewallRules: [UDP Query User{7C19BB32-A3DD-4A37-8437-9882847C9D6B}D:\games\baldur's gate 3\bin\bg3_dx11.exe] => (Allow) D:\games\baldur's gate 3\bin\bg3_dx11.exe => No File
FirewallRules: [TCP Query User{3BAA4325-7379-43B5-AE1E-83C16CC8F3BF}D:\games\baldur's gate 3\bin\bg3_dx11.exe] => (Allow) D:\games\baldur's gate 3\bin\bg3_dx11.exe => No File
FirewallRules: [{9F4DD023-8D55-432D-B836-373C55A682C2}] => (Allow) C:\Program Files\OEM\Control Center\UniwillService\GCUBridge.exe => No File
FirewallRules: [{9208502E-6687-40E3-8CC5-9884A5F94918}] => (Allow) C:\Program Files\OEM\Control Center\UniwillService\GCUBridge.exe => No File
C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
D:\Program Files\Sandboxie
D:\software\Sandboxie-Classic-x64-v5.67.9.exe
D:\software\Sandboxie-Plus-x64-v1.12.9.exe
C:\Windows\Sandboxie.ini
C:\Windows\Prefetch\SANDBOXIECRYPTO.EXE-E4FFD057.pf
C:\Windows\Prefetch\SANDBOXIEDCOMLAUNCH.EXE-CA6875F0.pf
C:\Windows\Prefetch\SANDBOXIERPCSS.EXE-B24149E1.pf
CMD: dism /online /cleanup-image /restorehealth
CMD: sfc /scannow
Hosts:
RemoveProxy:
CMD: del /s /q C:\Windows\SoftwareDistribution\download\*.*
CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
C:\Windows\Temp\*.*
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
emptytemp:
Reboot:
End::
*****************

SystemRestore: On => completed
Restore point was successfully created.
Processes closed successfully.
"HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\OneDrive" => removed successfully
"HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\OneDrive" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
HKLM\System\CurrentControlSet\Services\IDMWFP => removed successfully
IDMWFP => service removed successfully
HKLM\System\CurrentControlSet\Services\WinSetupMon => removed successfully
WinSetupMon => service removed successfully
C:\ProgramData\NTUSER.pol => moved successfully
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\SOFTWARE\Policies\Microsoft\Edge => removed successfully
"D:\Program Files\Sandboxie\SbieSvc.exe" => not found
"d:\Program Files\Sandboxie\SbieDrv.sys" => not found
C:\WINDOWS\Sandboxie.ini => moved successfully
C:\WINDOWS\system32\prfh0804.dat => moved successfully
C:\WINDOWS\system32\prfc0804.dat => moved successfully
HKLM\System\CurrentControlSet\Services\SbieSvc => removed successfully
SbieSvc => service removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
HKLM\Software\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
HKLM\Software\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
HKLM\Software\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
HKLM\Software\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
HKLM\Software\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
HKLM\Software\Classes\CLSID\{9AA2F32D-362A-42D9-9328-24A483E2CCC3} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
HKLM\Software\Classes\CLSID\{C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
C:\ProgramData\autoclickconfig.ini => ":07021500A6" ADS removed successfully
C:\ProgramData\empty.ico => ":8C1C1B484F" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini => ":B1DA6C571C" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk => ":A1B76439FE" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk => ":088221F38A" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk => ":FE00AE19CB" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini => ":41964AA945" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk => ":B96E9B8455" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk => ":C5112377E0" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk => ":980850BA8A" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk => ":C5D586BE93" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk => ":E77773B271" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk => ":60EC9648C0" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk => ":5465085A2F" ADS removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk => ":1DC1525F34" ADS removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{40B857EF-FDFA-46C0-8ECB-B7155F5BFFB9}C:\users\ripple\appdata\local\discord\app-1.0.9153\discord.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5F082408-619B-4016-9E24-368A236AC45F}C:\users\ripple\appdata\local\discord\app-1.0.9153\discord.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{F61ACD2C-ED51-4C09-908D-87EF7B26E99A}D:\games\lysfanga - the time shift warrior\lysfanga the time shift warrior.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{97C07BDA-EA0D-4E94-B850-C891A7F18930}D:\games\lysfanga - the time shift warrior\lysfanga the time shift warrior.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B5F1EAB2-E29C-4A5B-9360-446DC2EF1197}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{7C19BB32-A3DD-4A37-8437-9882847C9D6B}D:\games\baldur's gate 3\bin\bg3_dx11.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{3BAA4325-7379-43B5-AE1E-83C16CC8F3BF}D:\games\baldur's gate 3\bin\bg3_dx11.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9F4DD023-8D55-432D-B836-373C55A682C2}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9208502E-6687-40E3-8CC5-9884A5F94918}" => removed successfully

"C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie" Folder move:

C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie => moved successfully
"D:\Program Files\Sandboxie" => not found
D:\software\Sandboxie-Classic-x64-v5.67.9.exe => moved successfully
D:\software\Sandboxie-Plus-x64-v1.12.9.exe => moved successfully
"C:\Windows\Sandboxie.ini" => not found
C:\Windows\Prefetch\SANDBOXIECRYPTO.EXE-E4FFD057.pf => moved successfully
C:\Windows\Prefetch\SANDBOXIEDCOMLAUNCH.EXE-CA6875F0.pf => moved successfully
C:\Windows\Prefetch\SANDBOXIERPCSS.EXE-B24149E1.pf => moved successfully

========= dism /online /cleanup-image /restorehealth =========


Deployment Image Servicing and Management tool
Version: 10.0.22621.2792

Image Version: 10.0.22631.3880


[==                         3.8%                           ]

[==                         4.6%                           ]

[===                        5.6%                           ]

[===                        6.6%                           ]

[====                       7.1%                           ]

[====                       8.1%                           ]

[=====                      9.1%                           ]

[=====                      10.0%                          ]

[======                     11.0%                          ]

[======                     12.0%                          ]

[=======                    13.0%                          ]

[========                   14.0%                          ]

[========                   14.9%                          ]

[========                   15.5%                          ]

[=========                  16.2%                          ]

[=========                  16.4%                          ]

[==========                 17.4%                          ]

[==========                 18.3%                          ]

[===========                19.3%                          ]

[===========                20.3%                          ]

[============               21.3%                          ]

[============               22.3%                          ]

[=============              23.2%                          ]

[==============             24.2%                          ]

[==============             25.2%                          ]

[===============            26.2%                          ]

[===============            27.2%                          ]

[================           28.2%                          ]

[================           29.1%                          ]

[=================          29.4%                          ]

[=================          30.1%                          ]

[=================          30.7%                          ]

[==================         31.7%                          ]

[==================         31.9%                          ]

[==================         32.7%                          ]

[===================        33.4%                          ]

[===================        34.3%                          ]

[====================       35.0%                          ]

[====================       36.0%                          ]

[=====================      37.0%                          ]

[=====================      37.8%                          ]

[======================     38.8%                          ]

[======================     38.9%                          ]

[=======================    39.9%                          ]

[=======================    40.6%                          ]

[========================   41.6%                          ]

[========================   42.6%                          ]

[=========================  43.5%                          ]

[=========================  44.5%                          ]

[========================== 45.5%                          ]

[========================== 46.5%                          ]

[===========================47.5%                          ]

[===========================48.5%                          ]

[===========================49.4%                          ]

[===========================50.4%                          ]

[===========================51.4%                          ]

[===========================51.6%                          ]

[===========================51.7%                          ]

[===========================51.8%                          ]

[===========================51.9%                          ]

[===========================52.2%                          ]

[===========================52.2%                          ]

[===========================52.3%                          ]

[===========================52.4%                          ]

[===========================52.4%                          ]

[===========================52.5%                          ]

[===========================52.6%                          ]

[===========================52.7%                          ]

[===========================52.7%                          ]

[===========================52.8%                          ]

[===========================52.8%                          ]

[===========================52.9%                          ]

[===========================53.0%                          ]

[===========================53.1%                          ]

[===========================53.1%                          ]

[===========================53.2%                          ]

[===========================53.3%                          ]

[===========================53.4%                          ]

[===========================53.5%                          ]

[===========================53.8%                          ]

[===========================54.0%                          ]

[===========================54.0%                          ]

[===========================54.1%                          ]

[===========================54.2%                          ]

[===========================54.2%                          ]

[===========================54.3%                          ]

[===========================54.3%                          ]

[===========================54.5%                          ]

[===========================54.5%                          ]

[===========================54.5%                          ]

[===========================54.6%                          ]

[===========================54.6%                          ]

[===========================54.6%                          ]

[===========================54.7%                          ]

[===========================54.8%                          ]

[===========================54.8%                          ]

[===========================54.9%                          ]

[===========================54.9%                          ]

[===========================54.9%                          ]

[===========================55.0%                          ]

[===========================55.1%                          ]

[===========================55.2%                          ]

[===========================55.4%                          ]

[===========================55.5%                          ]

[===========================55.5%                          ]

[===========================55.8%                          ]

[===========================55.9%                          ]

[===========================56.0%                          ]

[===========================56.1%                          ]

[===========================56.2%                          ]

[===========================56.2%                          ]

[===========================56.3%                          ]

[===========================56.5%                          ]

[===========================56.5%                          ]

[===========================56.6%                          ]

[===========================56.7%                          ]

[===========================57.1%=                         ]

[===========================58.1%=                         ]

[===========================59.1%==                        ]

[===========================59.2%==                        ]

[===========================59.2%==                        ]

[===========================59.2%==                        ]

[===========================60.2%==                        ]

[===========================62.3%====                      ]

[===========================84.9%=================         ]

[==========================100.0%==========================]
The restore operation completed successfully.
The operation completed successfully.


========= End of CMD: =========


========= sfc /scannow =========


Beginning system scan.  This process will take some time.

Beginning verification phase of system scan.

Verification 0% complete.
Verification 1% complete.
Verification 1% complete.
Verification 2% complete.
Verification 2% complete.
Verification 3% complete.
Verification 3% complete.
Verification 4% complete.
Verification 4% complete.
Verification 5% complete.
Verification 5% complete.
Verification 6% complete.
Verification 6% complete.
Verification 7% complete.
Verification 7% complete.
Verification 8% complete.
Verification 8% complete.
Verification 9% complete.
Verification 9% complete.
Verification 10% complete.
Verification 10% complete.
Verification 11% complete.
Verification 11% complete.
Verification 12% complete.
Verification 12% complete.
Verification 13% complete.
Verification 13% complete.
Verification 14% complete.
Verification 14% complete.
Verification 15% complete.
Verification 15% complete.
Verification 16% complete.
Verification 16% complete.
Verification 17% complete.
Verification 17% complete.
Verification 18% complete.
Verification 18% complete.
Verification 19% complete.
Verification 19% complete.
Verification 20% complete.
Verification 20% complete.
Verification 21% complete.
Verification 21% complete.
Verification 22% complete.
Verification 22% complete.
Verification 23% complete.
Verification 23% complete.
Verification 24% complete.
Verification 24% complete.
Verification 25% complete.
Verification 25% complete.
Verification 26% complete.
Verification 26% complete.
Verification 27% complete.
Verification 27% complete.
Verification 28% complete.
Verification 28% complete.
Verification 29% complete.
Verification 29% complete.
Verification 30% complete.
Verification 30% complete.
Verification 31% complete.
Verification 31% complete.
Verification 32% complete.
Verification 32% complete.
Verification 33% complete.
Verification 33% complete.
Verification 34% complete.
Verification 34% complete.
Verification 35% complete.
Verification 35% complete.
Verification 36% complete.
Verification 37% complete.
Verification 37% complete.
Verification 38% complete.
Verification 38% complete.
Verification 39% complete.
Verification 39% complete.
Verification 40% complete.
Verification 40% complete.
Verification 41% complete.
Verification 41% complete.
Verification 42% complete.
Verification 42% complete.
Verification 43% complete.
Verification 43% complete.
Verification 44% complete.
Verification 44% complete.
Verification 45% complete.
Verification 45% complete.
Verification 46% complete.
Verification 46% complete.
Verification 47% complete.
Verification 47% complete.
Verification 48% complete.
Verification 48% complete.
Verification 49% complete.
Verification 49% complete.
Verification 50% complete.
Verification 50% complete.
Verification 51% complete.
Verification 51% complete.
Verification 52% complete.
Verification 52% complete.
Verification 53% complete.
Verification 53% complete.
Verification 54% complete.
Verification 54% complete.
Verification 55% complete.
Verification 55% complete.
Verification 56% complete.
Verification 56% complete.
Verification 57% complete.
Verification 57% complete.
Verification 58% complete.
Verification 58% complete.
Verification 59% complete.
Verification 59% complete.
Verification 60% complete.
Verification 60% complete.
Verification 61% complete.
Verification 61% complete.
Verification 62% complete.
Verification 62% complete.
Verification 63% complete.
Verification 63% complete.
Verification 64% complete.
Verification 64% complete.
Verification 65% complete.
Verification 65% complete.
Verification 66% complete.
Verification 66% complete.
Verification 67% complete.
Verification 67% complete.
Verification 68% complete.
Verification 68% complete.
Verification 69% complete.
Verification 69% complete.
Verification 70% complete.
Verification 70% complete.
Verification 71% complete.
Verification 71% complete.
Verification 72% complete.
Verification 73% complete.
Verification 73% complete.
Verification 74% complete.
Verification 74% complete.
Verification 75% complete.
Verification 75% complete.
Verification 76% complete.
Verification 76% complete.
Verification 77% complete.
Verification 77% complete.
Verification 78% complete.
Verification 78% complete.
Verification 79% complete.
Verification 79% complete.
Verification 80% complete.
Verification 80% complete.
Verification 81% complete.
Verification 81% complete.
Verification 82% complete.
Verification 82% complete.
Verification 83% complete.
Verification 83% complete.
Verification 84% complete.
Verification 84% complete.
Verification 85% complete.
Verification 85% complete.
Verification 86% complete.
Verification 86% complete.
Verification 87% complete.
Verification 87% complete.
Verification 88% complete.
Verification 88% complete.
Verification 89% complete.
Verification 89% complete.
Verification 90% complete.
Verification 90% complete.
Verification 91% complete.
Verification 91% complete.
Verification 92% complete.
Verification 92% complete.
Verification 93% complete.
Verification 93% complete.
Verification 94% complete.
Verification 94% complete.
Verification 95% complete.
Verification 95% complete.
Verification 96% complete.
Verification 96% complete.
Verification 97% complete.
Verification 97% complete.
Verification 98% complete.
Verification 98% complete.
Verification 99% complete.
Verification 99% complete.
Verification 100% complete.

Windows Resource Protection did not find any integrity violations.


========= End of CMD: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========


========= del /s /q C:\Windows\SoftwareDistribution\download\*.* =========

Deleted file - C:\Windows\SoftwareDistribution\download\2518cd1138e195279f647863a1a9d13e7e5a012c
Deleted file - C:\Windows\SoftwareDistribution\download\5dffc91b03da53bf4ebd454653d8d4a8622b98b8
Deleted file - C:\Windows\SoftwareDistribution\download\853c86cbbaf786a39b96a50053f0fcd7a5aad317
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\ActionList.xml
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\compdb.xml.cab
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\DownloadList.xml
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\DownloadList_old.xml
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\ExeUpdateAgentDeployment.cab
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\unifiedinstaller.exe
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\UpdHealthTools.cab
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\windlp.state-old.xml
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\windlp.state.xml
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\Logs\CapsulePublishRemediation.001.etl
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\Metadata\compdb.xml
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\Metadata\compdb.xml.cab
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\Metadata\DeviceInventory.xml
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\Metadata\Dpx.dll
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\Metadata\ExeUpdateAgent.dll
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\Metadata\Mitigation.dll
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\Metadata\UAOneSettings.dll
Deleted file - C:\Windows\SoftwareDistribution\download\f7cc17caa467f0c3b07f11c47d32f169\Metadata\UpdateAgent.dll
Deleted file - C:\Windows\SoftwareDistribution\download\Install\AM_Delta_Patch_1.415.134.0.exe
Deleted file - C:\Windows\SoftwareDistribution\download\SharedFileCache\19e4f9365b8516a76b888cd9200e5c8408fc5a6010ed3660db90297faf1a1e94
Deleted file - C:\Windows\SoftwareDistribution\download\SharedFileCache\833330f1d54e841940dd80b39c44357fdd364957e1e3027c588f71d7d08e80a7


========= End of CMD: =========


========= del /s /q "%userprofile%\AppData\Local\temp\*.*" =========

Deleted file - C:\Users\Ripple\AppData\Local\temp\003eb541-a966-460f-81ac-396269a0cc12.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\005a3c12-139f-4550-b300-a5b85bd47c26.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\019ac896-d141-420d-8107-217e82e2b2b6.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\01b07b59-b9e7-458e-a3c5-d2e45c109b83.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\01e2a49d-e8f8-47b5-82f7-c6d5601b990a.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\024018f0-9318-4775-9645-f94b1ade2ba9.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\02626ded-a9bb-44bf-aa96-c454ced5b870.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\029e886b-7c84-4fbe-93ec-4919ed08206a.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\02c2e0b8-188b-4565-8c0b-a10e39524268.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\031d60b2-1cda-47a7-ac5d-0dde5d81afc7.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\036a03fa-809e-43cc-b534-f1f47b308213.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\037752fc-d95e-4857-91c1-036242d9728c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\03f842e0-f88a-4932-ad9b-6cae4cd66783.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\0429bacc-ab87-4c1d-aa68-a6e70eacd5e2.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\04504585-efd3-4694-806c-0da2794620cf.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\047df0d1-5124-4001-a5bb-191593ddf58a.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\04e8c5f0-959d-4466-a563-6dce491f0a65.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\05605cdb-9497-4730-90f1-75e1ffdbc7d5.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\059528d2-aaf4-4199-bac9-80cbecef69bb.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\05d40249-0c4e-4539-a9c8-82460305b2ce.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\0611509e-7982-4349-881d-89697c089fa7.tmp.svg
Deleted file - C:\Users\Ripple\AppData\Local\temp\063f285e-5608-486e-99a5-bc5d8ff4af62.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\07459f9d-c140-4394-bcaf-842a11ef1e72.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\076029fe-c81c-42a1-a381-d6d0fe132f07.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\07a1af0d-1e9a-4d6e-b15e-24ef3230de07.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\07adb232-b93b-4386-95d6-872648226870.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\07e6702b-7451-4b30-a6eb-ccbb8480616c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\082aff2d-912c-44a9-8240-eaf6bb4b9b31.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\0830aaa4-c33e-496b-874a-a7fe3518fe8a.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\089857a2-ffbc-4f09-89f7-fe3802beca79.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\09aac134-13df-40a5-94c8-3853dc15c5dd.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\09f14809-39c0-4402-9d5f-19e14210ac1d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\09fd09ba-ce33-473a-8259-7218c02a73ef.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\0a7ac88e-ea44-4730-92e8-6d5f6502a957.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\0ae607d1-4471-4380-831f-f8a0e9f46312.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\0b1f4e91-fa01-4d59-9e93-b48a60d35741.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\0b468539-b7ee-4deb-a98e-6feb3fda7d9c.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\0d0b965a-ab86-4f73-ad1b-1bc83b5c56ba.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\0d596088-5653-43a6-9c96-e1c96ab06c90.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\0da99965-a5bd-4c27-826c-491a90014eb1.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\0db00c9e-6ac1-4f0a-86ef-0b9610c196cc.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\0e39bfd5-1a11-46b8-b66a-a8f568857134.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\0e6c105b-1e68-46da-9321-6ab2d4d92b65.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\0eefa285-00b4-47f7-9f1b-eaa795b4262a.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\0f135c3b-59e8-4b08-b485-c8c07ea2fc6f.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\0f2f4093-50eb-4105-9902-0d1b7b02b8d0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\0fa3451b-a4f8-458b-93c4-6ffb1a4f97ae.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\10179917-0521-47e7-a5f2-9e746b2dae69.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\10a4176c-789e-42aa-8b5b-eebbfbf13b9b.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\10cf9291-727c-4f94-b7f4-8c339e991fed.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\113d2a83-9651-4c21-8922-a848b059cd95.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\1147a097-6530-41d0-bb4a-4ec258009991.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\117d37d8-6ce2-4b8b-abc6-ecfd26eaa42b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\11f6ccb3-88af-4170-a971-14eb6362f864.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\1203c3e9-b74d-4715-97a9-3e79a3f209ce.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\12bf6cff-f03b-41f6-8e7f-f9a76c0aa362.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\13cde356-2243-4aed-acd1-c8548cb1bae9.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\143a632d-2690-4c49-a2e3-5ac47e4e52e1.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\144930ba-164f-4995-b83a-310f9b9a494e.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\14e3a8a5-e56e-4987-bbe2-ee63e45ad9ee.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\157e6f8c-eb9a-4f77-bb31-041dc6535787.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\1590054b-4f99-48ca-9ce8-f790ee5c1e5b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\164ce79a-ab64-4e02-9124-37705005162b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\16a73302-2937-4b2d-9801-abc490e1f9b7.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\16c81514-efc0-4795-9156-40d8aef9da5d.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\173593c8-924b-4c12-90d2-b59711d94b12.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\1788209e-e0bc-434a-9e3b-7a6b6d105b43.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\17a6f636-77c0-4bda-a949-865fb0c8c81a.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\17b4aef1-32ae-4caa-a8a8-b357ef65ec3d.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\1830c2a7-d99d-4d7b-9eef-3683ec8d94fb.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\18f76ec6-923b-442f-a17a-dc019c877cc7.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\19381b49-4f0b-4fc2-b6b6-ac1a54644703.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\1973e854-1387-4ba0-bf36-c2097da67697.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\199d5029-c328-4e73-b24e-27839b6bdb15.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\19c78513-edd0-4a7b-97f5-c21bded7fdb0.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\19d5c154-f2d3-4c3f-913f-e28acea2953d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\1a071c21-dd87-47b9-aa20-4c019664db62.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\1a3ab241-7f81-4ed1-a627-ae3378fe7db8.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\1afa2405-3e34-41b8-b255-456d50f3103d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\1d344908-fb37-44f5-b90e-ba8c0d7fdd20.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\1df4ad26-5381-47aa-8737-3c6baac9ce48.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\1e8f868f-4cd2-4420-ab80-caf5b2aec00d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\1e956f60-921e-4c58-8a37-7cfc62af9942.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\1f1bf8d7-1726-410d-a93f-82e4085f3d5a.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\1fe18d7d-5d11-466a-a635-63fc9ad046db.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\206a0286-b890-4137-9c1c-62d75fa92d47.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\20aac82b-0b5d-418a-aedb-95ab2971bd45.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\2161e680-65cb-498b-bf08-f60d56f351b3.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\21c8a1e1-c31e-4c13-be85-7939828719d2.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\23a7855d-5e02-4fdf-80a1-1d0ee14e1745.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\2412c3dc-d3b1-4a16-901a-9dbb65a8fd87.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\241de311-4b6e-4088-b423-30e947386e0d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\243147a6-fab3-4dee-9169-2d5090999a35.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\24e2b0dc-c45f-4963-ab3b-012094954d8c.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\25a23d6e-6e80-4a80-aac8-0718fbd23fba.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\25a6a94c-2e89-4af3-92ae-a29923c7c543.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\265ed909-195f-4c71-9c94-3399169690a5.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\2661c0fc-85dd-4714-ab95-741929f48685.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\267973cb-a28f-49e4-affc-b14d4f71fcf1.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\26b15155-b1a5-4fd9-81d9-b2068d944596.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\273eb7b2-3604-42e5-9bc1-3b8a51e96c95.tmp.ico
Deleted file - C:\Users\Ripple\AppData\Local\temp\27559abe-fe93-4106-8b67-ef009c729bc9.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\2756551c-b6a9-40cb-bcb9-bca2e1bb19ea.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\27cc8c44-5de2-4741-9d47-d02465060239.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\27d1ed5f-6952-4df7-af17-b024455d046e.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\27d8df68-7f74-430c-9b72-d577cf6b4c39.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\28458f8c-4fb0-4bad-8dba-fa8ba8f365d7.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\2857d348-5373-4df1-8bd1-30b1502c5de0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\286fb2db-1ca0-46f2-97c2-c54d110aa53f.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\28a2e636-6b54-4074-b001-7639620c9513.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\29034127-b4b8-4f3e-8109-1d2824714b9a.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\297d1e83-f1ab-4b4f-b79e-949a45d517f5.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\29d3f69a-5778-447d-a7ad-10583dbe3883.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\2a25e01a-012e-465e-acf2-232dbc8a23a5.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\2ab6df6a-d7a8-49e7-a85c-b0a7f9a83c35.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\2afc757c-ff33-4aef-ae9d-206e6dee6ba1.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\2aff49a0-c701-4f2d-9df4-d868ef807df8.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\2b12a94c-5969-4857-8b90-504c735c04ef.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\2b7e7ecc-b9be-4b3d-bdba-0dca93b1ab9d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\2be78618-5402-43a4-963f-eabafce066f0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\2bfc8d61-964a-4f44-831d-993b1c8ccc70.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\2c306a4f-57f4-4963-8744-e3d6a5aa59b2.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\2cac0803-0de7-4c88-9a06-c57206d94242.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\2cf2b254-9f3a-4910-8c38-352792e8283a.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\2d5bacc5-65db-4eff-ab85-57240a180e34.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\2d6a2921-e6f6-4bd5-b062-1f5c0168d6f0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\2d9acd39-f432-425a-b271-4b4ae47183c5.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\2e1bf239-df48-40e8-b5c0-ef83bde077cc.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\2e213299-2c4c-496b-b202-edfd69ea7df2.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\2e597e34-beca-4251-a033-b649d1657982.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\2ea7ccdc-1338-4dbf-8b67-406ba920b3c0.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\2f9f261b-5627-4f8e-866d-f240a6ef8c65.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\30295e0b-7326-49f3-993f-faf987b589ca.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\3089c07b-da89-482a-b8c1-2954dfa34829.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\30c3583b-cc6e-4f1f-8fe4-9ef440550ef6.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\30f0226e-d4a3-41c9-9294-434deb0edb51.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\3151ad49-2514-4b19-aa30-ea1955dcf043.tmp.ico
Deleted file - C:\Users\Ripple\AppData\Local\temp\316457b4-30da-43c9-94a0-b611d25b45b2.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\32844caf-1121-4ed6-bfcd-f9e4f70aa0c3.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\3332b928-188f-401c-a32f-37be8d07be9b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\33c26a28-1a5c-4e07-8570-5a6510caa2ae.tmp.svg
Deleted file - C:\Users\Ripple\AppData\Local\temp\33fdd48d-8501-4167-b295-419ec8aa7d0d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\341dfe60-1ae8-45c3-85f3-aa144812f799.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\3428010a-175b-4221-b7ac-33c0f084d5dc.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\34e634b4-8ab1-42a2-8ef8-52860fe6dcad.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\34fe491c-b2aa-4ce6-a8d3-3d75fa08cc5d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\3629ef5c-2035-4d0f-93b6-8929ed49d60d.tmp.ico
Deleted file - C:\Users\Ripple\AppData\Local\temp\363e6b48-ea8b-4ca1-8295-d443ab313b34.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\366f3c32-d5f3-4ab6-b2ac-dfe6ec6ff96e.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\369c179d-b09f-4638-a993-c89e7c3b3c66.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\373f7d1e-579e-4ab4-bbe8-55eb601af7fa.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\37790829-0853-48c1-a338-fc43275c198b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\37ae6b9b-c4a5-4e87-8b6c-161d055fedf0.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\37ecc1b0-d844-4448-8ad0-3d52c803c8a1.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\38982ace-3431-4cfe-9c1e-66f38775c236.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\38d3e6b2-99cd-4c7f-ac05-94c62561cc60.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\39b3fe1d-fa8a-47f0-b173-30f640650867.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\39b549f2-b519-4d5b-9cff-d08c2a935c07.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\39e4fece-39ee-4bfa-83b4-c51c97eb33a2.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\39ef228b-9721-466a-9960-9a84c9e67230.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\3a4d315e-9284-4666-b6c9-95a90daefc21.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\3a6703b9-4c08-47c7-8d19-448ee284605f.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\3aaca767-6c5d-4699-9d0a-218601723405.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\3af8e048-fbcd-4bc7-a9d5-c781b8eb234d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\3b1fafd9-6387-49f8-b6ed-2d0866f8e90f.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\3b7aca3a-3de2-4f30-814b-ccc55a09d40f.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\3b822b78-b2ef-4c7a-971a-77e67e518f90.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\3ba3015d-79e7-4338-b574-7dc14c89b4dc.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\3bf43bc8-7412-4686-9eaf-6b6c492d8460.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\3cb8386d-a6db-40d4-a6f5-f1a3e0afb7d1.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\3d077e02-4f18-4e51-8672-288c96f8d5d3.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\3d7bcf47-b920-4269-be0c-2a48c9c025d8.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\3d7c336e-b7ee-463d-b524-d8e4bab3dc63.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\3d847023-4136-4045-8fe6-b702cbc55a7b.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\3d9ed460-8c2b-4a37-b339-454dd2772ef1.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\3e76abd1-fc19-4989-ab9d-0fdcec6f9b2c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\3eccf010-332b-4fe1-a566-cda93b7686cf.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\3f94e818-4fa8-43f2-b3ee-f179fdcd08dc.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\3fd33541-38d0-492e-817a-87044b1e8d94.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\3fed6ad6-f060-4176-bc5c-5dfca7497509.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\41014186-4fc8-437b-80b8-98850cee6d04.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\4140a3d4-5a11-4817-8a21-77aba4e105d4.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\4173d826-2cc2-482e-b9a0-6112535a3990.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\41e19c26-aa4b-46eb-aab0-74211041602a.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\42624982-c51d-470b-b166-91a358257841.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\428c10dc-feeb-4c80-858a-c43ea9c06fbf.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\42f22406-ec9b-4fa3-8bab-26b1e3358d3b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\434056d8-cf12-4e5a-ad64-d325a6d2d8f1.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\43c1a98b-4589-40a9-bf60-933729b45717.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\43c34a3e-e503-4f8a-bbe8-1f10912d2906.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\444e20aa-5566-4b5d-be92-c7df6e6f4c57.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\44b89d79-b974-4031-bde2-48fdfea58ad0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\45216001-079c-4fe0-9826-00d6d60baa6b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\4542df36-f5f2-467a-80f7-1572f266b06e.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\4565e20b-e8bb-47ab-92e1-d0e0b99417db.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\456ef5d9-3738-4e6e-8292-4e227e9fff57.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\45bd0683-f994-48e6-943d-02299d59003c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\45c6de90-2997-48ff-8f1c-69d34569a88c.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\45fd2f4c-f409-44f3-9de3-498e27dadd47.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\4618063e-b689-4f15-8ad8-d84752726b96.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\4640a815-df64-4472-8ca5-0cde9971cbd1.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\464edfbe-8500-4781-86ea-125d45380b61.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\472d00eb-fc31-4c5e-8064-f6f713918735.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\47785cae-835a-49c1-ad05-4e92e7e71e06.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\47fa4731-1af6-42b1-84dc-279ca5e043e1.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\47fbcd4d-3668-471e-9ed3-e4b81981e33b.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\48efead1-0ca5-4284-842f-367cd96a9b89.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\48f67d7b-3163-4f9a-ad85-64441d48bfd1.tmp.svg
Deleted file - C:\Users\Ripple\AppData\Local\temp\4923f003-dda7-4749-86dd-0d93c2a0d522.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\498442ee-1340-49b3-b480-75e505b5776a.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\499098fe-6ae6-43e9-9b57-e9b05459b450.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\49caf826-4fa9-45bc-9283-dcfda63f3ab3.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\49e1640c-6d78-43ca-a881-9c3caa5724a0.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\4a8e62ee-2edd-4b69-b9ed-b99a938a4663.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\4ad97462-ea9d-4c4e-826d-6949fe6673be.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\4b315a54-7729-4af7-bd67-ba32f2a89634.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\4b51320f-0fa2-498d-a002-f51d3f1d9f29.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\4b9e7088-537d-4a99-a07a-ae4e3d5976aa.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\4bb402fd-6fb8-43cc-ae53-54b22f99ae6f.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\4bed9a90-4854-41fd-9a88-77ff69a63175.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\4c944418-59f3-4df1-aaff-15ee068fc14b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\4cf94f42-c0db-43a3-8104-2c73bef1f67c.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\4d111e80-1373-4af7-8498-2cb7f9a93dda.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\4de6aa24-4879-4644-8f41-77a5e67d0dac.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\4e0000dc-7539-4245-afa6-03d1894cbdbc.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\4e095964-5dd6-4687-98ce-d3b44b8b79b6.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\4e2d01fc-ae96-49cd-a907-b2a71b2fecdf.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\4e4af33b-a350-4601-85a3-50e1b5215d6f.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\4e506f03-634f-4f39-b088-d15a50055217.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\4eae2f1e-2b7f-4420-81e4-e85d2e6be7d6.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\4ebd8e9e-2403-433e-86c8-b4fb9254af96.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\4f3b4adb-ad2b-4c87-bedb-ca5623605f86.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\4f89f988-81ee-4b9e-8125-ec91b9d0639d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\5022bf3e-67b6-42ec-a98c-bedfd02e6122.tmp.ico
Deleted file - C:\Users\Ripple\AppData\Local\temp\502e5b75-4c17-42ba-8414-148f322fe8a9.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\504eda25-69a4-4887-b908-66895d34bb73.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\50dda961-37fa-454b-908e-f21420e2ad1e.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\5124265b-9e70-4dc7-a8ed-1baac407bc20.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\518f0a55-88d5-4d48-b486-c3704b38589b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\519a9852-c89b-4f9e-9c36-207c536a851f.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\51be7b0c-7fae-42e1-afaa-a4f4fce04df7.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\5238c261-ae32-4a58-aa16-3f0888f9e92e.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\53a13084-585d-4f95-bc05-6cc57a6c536a.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\54416631-1db2-4858-bf63-c7e2db580f17.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\54863040-bee8-42a4-a4f9-69152d737087.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\54aba3af-0395-41cc-89e0-41a4280910b8.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\551345ae-726f-4c5d-95e2-dde1ae2f1e45.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\55b36ea0-045f-4f13-aac7-73b9c13f37a4.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\55ca8bd7-8d81-42a9-a509-996d33ab33e8.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\565847a0-671e-48dc-bbc9-1dcdd1e29d85.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\5659ff4c-eff5-4f5f-b0af-37c9bf2c0b9a.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\56a6b997-9016-4507-8905-228730574230.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\56c93dce-5c2f-4924-a4a7-9d914b4547ac.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\5733e9c4-530a-4864-a444-a9289b762da8.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\574c14b6-277f-4c3f-8cfc-5cf3d6eb6c34.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\57614182-52be-43c5-8dfe-917d79603ca3.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\57699259-5e09-4ec9-95ef-a90e6adab495.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\57951e64-09ff-4390-bfb7-544b954ad786.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\57f6ad32-2c18-44b4-aa0c-de1f3d6072f9.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\57ff867b-04d2-4cf1-8375-1d7a2a1a2ec3.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\580cde7e-7102-48c5-994f-286ca3843414.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\588f8953-a62f-477c-bb58-16c2407c4ae1.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\58ffa0c6-d874-43a1-bf8c-aae6ad178aa8.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\595757fe-be6f-47c1-a332-03008f801f35.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\5a05a8a4-2dab-46b1-afba-b4c875ffe3d5.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\5a698f39-76ab-4534-9c71-df120d1b0d9e.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\5ba5ccff-ea4d-4c53-baa6-4aed7b697a01.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\5bb78b42-646b-48e5-809b-384f7dd3e9ef.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\5bce1fc8-3dea-40b0-abf0-79c29e49e850.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\5c121c3a-21b1-4fed-9121-962832511df6.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\5cb6886b-58a0-43a2-8d5e-f35e88a32288.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\5cf633f6-4f0e-4150-a63e-384b06502320.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\5cfcbf70-5d8f-4668-9888-b0303fdc1334.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\5dcdb072-9f04-4a58-9e75-d5a4d0af8687.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\5dd79829-139b-404d-8026-1ce233134ccd.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\5eceb56e-8af7-41ff-8a6a-1713c6dab909.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\5f40aa29-9729-49b7-8abd-f0d2b2895719.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\5fb21583-a4e7-4b01-8a42-3b8370b5a273.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\5fb754f9-1f88-4b9c-ba26-a6bbc938d473.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\60e40b08-dbb4-4d9b-83bb-ec17269761d1.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\61f04a2f-3e58-4a0a-b976-635a5aed18c4.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\6236b8f7-3182-480e-9d45-70af3ba4cd3d.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\6279d0f7-6011-493c-a212-d176f1410ee1.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\627c8db1-47da-42a6-ab1e-25357c63cc25.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\627f8d98-56bd-49ef-8e79-d78c1c747fed.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\62d1c47c-b536-4007-96fb-a6d8daf3966e.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\62dc4f6f-fbc6-4b42-91b0-9876a7dfe77d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\62fd7943-26b4-4bef-9ceb-961d4cb48a69.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\633470b7-8dc9-48f4-af8b-f1c3667f16ce.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\634f0d5f-8a63-4009-8b30-04c1999bad50.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\63e7a11e-c418-4872-9342-162d9b1e196c.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\641a5d0c-4b8c-4418-806a-16ab0c0e9be2.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\644b20b6-ca5e-48ba-b200-388f4bdd289c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\6486b9b7-4357-4297-b016-467d817a14de.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\64fe9966-1a1d-4e98-bbf9-f1715042b59b.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\652bb2ae-ed4b-4dae-8ded-6bb92dab3573.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\654a67e9-08af-42e3-967f-899fb9eadee7.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\6555f417-9025-46ac-b0d7-e74c59f9e56d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\6578f341-bb51-4733-9307-878d439dab31.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\65d50a59-6190-4d7c-b8af-c853e2d1171a.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\6603da85-6608-4cb4-ae4e-97dd9fbefa64.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\66e2b786-897b-4adb-9764-6a38be9f21e7.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\670f0402-d9f4-446d-8f69-504d0b265f87.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\676e5640-a3a8-4546-b430-71bd46b16c55.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\6802c079-8317-4ff1-8901-b57f2b25f6c7.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\68ce763c-b182-44b5-87f2-177e37f7da3f.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\690fbfb3-9c9f-452e-9868-c1fda9d2d94c.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\691cd410-9d68-4531-ac4c-c069942e805b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\695fae03-32a8-4ce5-a2f1-faa20b502641.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\696c7bd8-d419-4586-85e4-d77fcb42bf6b.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\69be776b-f1c8-4c58-94f0-4341f053fa34.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\69ec42df-7185-425a-8baa-f0f6c747b4d8.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\69ef0a5b-589e-402d-b26f-e77ffeb1cf6c.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\6ad1a2a9-1bb4-4364-918d-854e56b57cd8.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\6b165f2a-c79c-42c0-b192-f805dee9d07f.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\6b9f7f99-ff2e-4e92-9a4b-ddd4ba495a37.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\6bd2608e-942e-49b3-b4c9-773a99778975.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\6bf4424a-560f-4e16-831f-63a99e4b2f2c.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\6c86e006-dc0d-4830-ba6e-85e3a31c97ae.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\6c980397-182a-49fa-b68d-39dda97024cb.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\6d04d8bb-03ea-4218-84f7-5c0ec8f53ad2.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\6d1363eb-c0fc-4198-8ed4-62f96b1d15a0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\6d2ee2db-24d3-4221-8261-ff39650b1fee.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\6da910ba-872d-41f3-882d-f184a19d80aa.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\6df7d22c-f385-4690-877b-4f5deb14b44c.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\6edc58d2-cfa5-43c2-93b9-14aad2d807e4.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\6f56f94f-04cf-4866-9754-da762b84c626.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\6f6ac1a6-1675-4495-b683-1e15ec8fdfd2.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\70dd9f1c-3041-470e-a9ed-46d56475110c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7105814b-f57d-4d16-aac3-4b3e42c7d284.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\711b001c-b7f8-439e-b8ab-12cf81df98f4.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7154ef8a-8511-442a-ab66-cd84a3e68647.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\71b652b8-6072-4ea6-a972-1a3654e5c13d.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\71ed6f4b-b564-4de7-8099-7cd52b8b140e.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7218292b-2367-469c-8f55-32da53fc10df.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\72d5391b-649f-4738-9a27-cae02e3c3993.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\72d92750-9144-4084-a4f6-1dd7db5cd03b.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\73039fc4-3dcf-40e7-8379-ed6ad6094174.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\73503183-bf8f-4ffc-8aa7-b6390368dc46.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\736b6ca2-edfc-4856-baac-a4e57b09af31.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\73baf4ea-645d-4e6a-8cb0-2a345e7c89c6.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\73ec159d-cee9-4335-ac9c-47a7556521f6.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\74012522-7697-4261-ae4a-666f8ca13c9a.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\7419f7e7-5ac5-4c7e-ad75-d9fb5cccb868.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\74f7e434-6d4f-449a-8ad2-3ea19a213d07.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\756c35b4-d4b1-4b92-a36e-8470205b529b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\756d3161-1b1f-4bd2-aa0f-7bcd7cde02a4.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\756d50dc-2bee-4cd8-a702-0b0338d50d9f.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\75bb8587-c97b-46c5-8de2-a2e4035e4cb3.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\75c315a3-549b-4e05-864d-f55c27165d2b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\76e3a528-018d-474a-9daa-7f81020133c1.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\76f56abf-6340-418e-b0db-51ab28287467.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\78b352ab-43fd-449c-aceb-da40a727e846.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\78bdd064-1f90-46d0-8622-3a64bcedcf61.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\78d67b72-5cf3-4ab3-b126-3481b7fc8858.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\79538306-159c-4c78-b395-3f864bc1bd42.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\79a16db4-21d3-48dc-af15-f388180e6daf.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\7a48f37f-be2b-4263-9830-d124edfad119.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\7aeac18b-1b26-4055-b0d4-b948a920090d.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\7af81a98-ce2c-42f7-ad34-ecb99af3bf1a.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\7b2d6c60-6f1a-4da6-8350-799675eee8af.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7b35d29e-ad54-4740-8477-de34ff83c7bf.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\7b3b8bd6-a53a-460b-9a64-4b679133df63.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7b4cca9e-8124-4c5f-b40b-4368e427ff69.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\7b72c514-d2d7-4d59-8642-c938e83d1392.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7c421d72-d234-4686-b7bb-4929f8b1e2e2.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7d1835e4-a0e5-47d7-8c2a-3296cf8fed09.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\7da9921b-2e78-473f-8fa7-fb23e7e1177b.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\7dfd6a06-f897-494f-8866-fa644ab30abe.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7e11b780-7caf-4c03-be60-1567ab8d987f.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7eab5252-d947-4840-90fb-5d299c669a3f.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\7f0a30ee-324f-4cab-994a-beae6f871fce.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\7f0e975a-f04f-4246-9d2b-5976b175f7e1.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7f56bab1-7ea1-4c41-9039-3eddd61ae6a0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\7f6b724d-85f8-4747-aa85-bdfb2af5aae0.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\7fcda4bc-4dd7-4f73-88d3-fa999c8fd482.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\80050384-2151-4f5c-89ee-183c606088cd.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\800b8b3f-cba9-4e1d-9969-2cad0f6e1854.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\80106817-e123-424d-8817-7df82e685484.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\80c7666f-3445-4a20-9f33-4388542d7b89.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\80da3499-da95-4d3a-b520-db96bba2fd38.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\80f5210f-5c1c-468e-a386-b6086edbb09a.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\81561d9b-526d-44db-a4ec-358aa7a7b499.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\81f9f0d3-9491-44f1-9b13-3573f37dbdf2.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\82c876b2-2d18-4994-a46a-91862d26c69c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\82eed291-a499-42d9-98c4-c583e07f8a4b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\837473f2-750b-42cd-9e5d-6dbb5c2eed9b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\842cd801-6791-4a59-bdfd-2eaf5d74cf85.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\84ef7acc-58de-4e42-a81d-d26a83b9b0d9.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\85336b42-04a1-429f-bf1c-d1086c4df744.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\856439f5-b52f-4da7-bbb1-362f49019d35.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\85654533-7680-409c-8f6f-4748c6e1365d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\85ea0ce7-c61f-4422-9c71-a73b598aae6c.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\86429444-6739-4968-bac6-c911e45ac647.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\86ab8030-90b3-4011-955d-85abc6b67797.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\86f38f81-a4df-4d18-805f-a756b0a3f948.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\870a2f15-e3b3-46ce-904d-11d5dce77781.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\8752721b-ab4c-485e-9e57-4382deea6161.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\8790a3e0-7fa8-4d9e-ae7a-22c4bd1411d0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\881d22af-ba1d-480e-8ae7-f2fd4c56c4c2.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\88457d11-046c-4a5b-a5c7-f3aad30bdad9.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\889e6e3e-f9d7-4bfe-b44d-437979e8b0cd.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\88c1526d-1454-40fa-88be-3030846a41b8.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\88fe851c-520f-4f75-bc20-506e7becf68e.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\89554e9a-0354-4e1e-bd1d-a14ddac26b79.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\8959d99d-c50a-4145-9ec8-8b5b0f9b087a.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\8a2f14ad-c69b-4aed-870d-c370cd082e3d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\8aef2c0c-2512-4a4f-88d3-5cb2c040e784.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\8b0a7d14-cad2-4966-b235-6b7fa2c2d84c.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\8b0bc9e7-349b-404b-804b-7145b807fc16.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\8b4848cf-db19-478c-991a-76fc81fe16be.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\8c2f057b-d63a-4b89-8350-2c504c2d105d.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\8c3b0453-cd01-4fe8-a741-0994cc0a04fe.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\8c6c2fb4-562e-4b70-a530-8d4633e25c28.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\8cbc9994-31de-475f-8f93-3c3521259d48.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\8cd3cf14-0b5a-49b5-93f6-0b0f16d06383.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\8cfdbcf5-fef9-4d60-9874-4923e2536844.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\8d4c3301-4c3d-4a81-9ee9-708a0af02dd0.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\8db4388e-a7c3-4bf9-be2f-872e290cc980.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\8e7c048f-6fff-45a7-8318-0c00f281de5c.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\8ee3ba9b-540c-4a93-838a-a1b9c619ab40.tmp.svg
Deleted file - C:\Users\Ripple\AppData\Local\temp\90a17095-d531-4d21-9713-c027e36565cf.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\90dfb5e1-7344-4d6e-a328-31111b230974.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\90dff491-b21b-4be0-9464-8a4915c59d68.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\910da194-e2a6-4f5e-9772-6331594d2c4c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\918bcc03-6489-4112-9e98-566e54f05618.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\921c8dd5-c17c-4858-aadc-ab735a162028.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\9275742c-9818-49ec-a96a-0c4719ceb7a0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\929a14c3-58e0-4461-9287-8c992eee10f3.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\93111f1a-06b9-4e45-b597-07c8893c07a0.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\932c4b3a-3b19-485a-97ef-6641630a7517.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\935bcec7-38c4-49a2-b405-9ca0c131defd.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\9381b2b5-b6fc-4427-b8c5-380c1a67c8a0.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\93983ea5-f32b-45a6-b367-faec40744049.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\93e6c01a-6eec-42dc-a286-4fc775f0099d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\943b65ac-06ad-4a6d-8ca7-c80e7b982866.tmp.svg
Deleted file - C:\Users\Ripple\AppData\Local\temp\949c916e-ddbf-4184-a389-256f92d920c5.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\94a6522e-acde-45fe-b542-5287886f9f05.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\952ef479-da4f-4609-a8b6-2e9ad85b8637.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\9575eec1-d299-4816-8c6d-0e905aed26a6.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\959eb417-b7a2-4270-9bb5-0aef8aba2c05.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\95f7f25b-dc4d-4ce9-8d3f-f27cc130de6e.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\962c6e2d-fcc3-4b6d-b00c-c162afb6b436.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\96bdb506-5cff-4885-98db-45ee0d655b19.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\97267fd4-f2a5-4508-bef5-031d37bc6ab5.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\97578e85-692c-44e3-9ad9-62df5e91e13e.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\97a813f0-6ec2-4bd1-87ca-afe0f564327c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\97b1c48c-bb55-4654-bb74-463c0eef6563.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\97b28c01-abc2-4aaf-8cd9-eae147108117.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\97bb5c93-1f14-4f4e-ad32-e6a3cd220358.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\9820bd91-5f52-4df0-ab54-9c5ef11d5194.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\983147f4-88cc-4407-b370-fd609917dfe2.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\98644467-9fa0-4db5-9f79-cbf3a7700763.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\988876cd-0013-4868-8bc2-e0cf5c352318.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\99e69d9f-419e-4c96-b933-1231f285e577.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\9a1086ec-7500-4cae-826e-47f56f59c191.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\9a6b3d26-72b2-4d0b-a5d0-e3089bdcf14f.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\9a947518-b662-42d6-8459-5ee2cdfd4d00.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\9b7626c3-2f10-4936-8baa-062af8aab9d2.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\9c5b8f5e-3b46-4bd4-99a7-a8b1069a229d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\9ccb1f2c-4908-4923-8efe-ca15c16bea4b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\9cf75308-cc72-4a0c-9874-0e9556c4a98f.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\9dd8770e-3bf4-4a86-a7c3-289371409e75.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\9df7176a-9115-4a12-bc5f-e6f7cca17fa1.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\9e39a802-b4d9-4904-b08b-a8f73ffe67b4.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\9e634194-efbd-4216-8064-01b2eacff658.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\9eaf8c56-1bd1-4303-9a1e-ffd0a17b0025.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\9f25eb6e-3cc8-4b90-8b85-7c1246c99270.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\9f497dec-fc14-400c-93b8-0214b467b9d3.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\9f969779-a0e5-4cd6-a48c-42ad1e297fa7.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\9fb295c1-16ad-43ce-9659-1150fe5ff56d.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\9fdd3bf3-89db-4b10-a102-3990ae6cf941.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\a00290ae-4ba1-48d8-828f-10d2e7da3b36.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\a02b5299-36ab-4e01-ba92-d092d52e0e31.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\a034ab84-5e5b-4a10-872e-2ed3637b95cd.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\a06b29a0-a4e2-42d6-8fee-53913532a1fb.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\a0e8b2ad-d1fc-4113-9d06-405221a160d0.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\a11baf33-7cda-4fa2-8630-b5e505a1cf94.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\a180abc6-b3af-4c27-be6a-0273c079f131.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\a1a0140c-5b2f-4f4e-8717-9d6ffc5edf70.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\a2085b18-ac56-45fc-8e8f-bcdb79b36dfb.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\a2dca50c-9d65-4274-826a-52a38dc8b462.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\a36a2369-a05f-4712-b829-f32683d807a5.tmp.ico
Deleted file - C:\Users\Ripple\AppData\Local\temp\a3b4f02a-a0f9-41a1-a787-718f0b6425ed.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\a423b169-d2fc-45a6-bbfd-c7355b52edf5.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\a49ae5e1-f370-4845-8837-86949283cdbd.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\a573c7db-460c-4618-973e-afd9a35fa160.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\a5c88948-5266-4a0a-ad80-01c0fbd1d770.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\a5cb8eb7-b808-467b-8119-8a0bd38bcbac.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\a5e2f239-f006-4718-bd59-8f3c70ee1ba9.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\a6cd8f2c-ce12-46c1-8859-f9155485db9f.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\a71ee69e-c2b8-4b3c-87b5-77fbbd2c2c20.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\a744402b-6992-480c-bf58-de3243d87b12.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\a7843be7-2ebe-4a62-af5e-a048a822ad7a.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\a78e1b40-136c-42e9-8633-d2986f5adbeb.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\a8b07e11-0517-4527-9c8e-c7a634fd345b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\a8bc3cb3-2d63-4651-98c9-2f247a2670d2.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\a91e2d3d-f0cd-42f9-8e4e-439c7552b23e.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\a923b485-1481-4625-acaa-a33fe23fbb1f.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\a9e33781-7ed0-46c0-8efb-028ad6ab8803.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\aa6c1882-2578-45b1-85e6-839c72b8cab6.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\aa7c951d-315d-4321-aadb-b50aa4ebd499.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\aaf1f61a-5150-4c1c-8bd7-e9357a394bbc.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\abe38cc4-8fc4-49ac-8652-e62702857048.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\ac63c232-ace9-418b-a554-21eb8621f55f.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\ac6f8b6b-8240-4022-8bd7-044c89f25642.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\ac76daad-d4a8-46db-857c-53d64164827b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\ac7e46fd-5a1b-4a2d-ab54-fc2ef908717d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\ac94e092-1518-47a5-9a91-75a8a84d6888.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\acb7b21f-329a-474f-aa11-5ee94e891d62.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ace439b3-3619-488c-a20f-3c00b7c4b8b5.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ad27d905-bcc5-4ece-9b6a-a85b160096c6.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\ad3d3561-cdd6-4199-a897-36c9bc041635.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\ad9e5866-73cf-44ce-be3c-9fbf9ddea079.tmp.ico
Deleted file - C:\Users\Ripple\AppData\Local\temp\ade7efe7-7c1f-4d93-a956-0d3e0c830652.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\ae8d0097-75a4-4dc7-a82a-8bec40a14ae2.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\af5f3b8f-684a-4557-87f0-32a1f9659e56.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\af84829e-5837-4300-b19d-6f9e1c8d35dd.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\af9932ec-aa08-4337-8501-195d6adcc28f.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\afedbddd-6e6d-4bfc-8b60-0f2c4f8c1498.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.09p9_wxopt3vuvu46_oh3au1h.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.1v54jnh22ntd3xw6r8_96x5zb.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.34qs1g0ms_5zpzrhvpsf91fad.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.3yapfrg6wevyy6q9izvh3uoy.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.7tw8zflrmk2vd031og8a_3v1f.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.8el22ompj7clcho1qs1urgucf.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.9xgbcxz_misa8fk15ogk5e_6d.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.jj4atg_yazoxcol0ndr_2xfnc.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.kk7xfk_acstqrwo2accdz_tsf.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.l43u59knecvx7rcu_d3ausfae.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.mewgfs7w4jlvj6_wiaomfrpqd.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.mol55uv7udv_8kaik0e6ym74b.tmp
C:\Users\Ripple\AppData\Local\temp\APPX.mt50exybpmhnvppy0i1qybfgd.tmp
C:\Users\Ripple\AppData\Local\temp\APPX.n61cg4h6a1dma32q39qtyt0sh.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.obbbmsp7d648b1w98439v4qp.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.ubru7jm5cc0w938zqicj1_acb.tmp
C:\Users\Ripple\AppData\Local\temp\APPX.v57p2_ppu6a18iwkf227emw6f.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\APPX.ygiscnzni6ajk4zcdhrso82vb.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\b04ee56f-32cb-4ce4-af23-99534d7bbbb5.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\b0fa5fc6-48aa-4533-8a5c-550dd7d32e91.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\b15b78b9-ce76-4638-be8d-98d7a65ceb96.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\b1a6fbfc-895b-4695-87aa-ef2d66eb0046.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\b21f005d-e8ba-4bdc-a881-9d5d1e6f9c4e.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\b24bf3b6-6abd-4c2c-bbc8-8fe520cbf448.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\b2a70187-b966-4b1c-ab9c-6591b907eb65.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\b2b5522e-cae8-4f15-a0f7-1e08e92dedd5.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\b2f056e4-c625-491d-aab1-e1a923ea9c0b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\b31338cc-3d92-48d0-a9c5-88eba8debb8b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\b4180bf1-e07b-4c73-89c4-6c25157d3a41.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\b43e7436-5faa-466b-9cd2-b75445608804.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\b5309942-9646-4109-9dc3-fbe9a7e9eb9e.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\b5664772-0478-42c0-ab11-0793c6f1185a.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\b5b48f1a-2ca4-40af-a7e4-9ae1cb80c90b.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\b65d444b-718b-4520-b4fb-730a6545d3f6.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\b6a350ae-16e9-4ea0-8fc0-963d9001bca0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\b6b3e7da-18ca-45fa-9058-c3b1545cf4c3.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\b6c0df72-1c03-4488-a1c3-3bc718537fee.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\b71353ac-fcf9-4145-942e-6ee2a8cda9eb.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\b7560e58-3569-41f3-92bc-176b029c3b9d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\b7dbd50c-4221-4c8e-93d5-d110794c58de.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\b8155c14-4d45-4e76-b1fc-8660a2a39d67.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\b947aa9f-afba-4c77-b8a5-df69e21fa23f.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\ba333036-e1ba-4977-b67b-8ba24d2d0c90.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ba3e5a49-bb81-454a-9a66-0b3b7cc486bd.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\ba7aa84b-74a7-4851-8ace-301d6fa40480.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\bab135cc-792f-4484-91ea-140307f2912d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\bab898c7-269b-4e8d-88d0-a960da9d6420.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\badb385a-0c41-4d79-8c73-f5b7f1590488.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\baf23ca8-90c1-4b7a-9b13-182dc2a1637b.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\bb5bf1b6-ce98-4792-ae34-e733ffe6479d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\bb89b8e7-2804-467d-8cd7-b1d57d4f9f81.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\bc222ac2-dd52-446f-9039-06eb8e990022.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\bc24dae1-675a-477a-840d-2403b50dcb48.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\bc2a5b6a-6e2f-462d-85d6-09f06cb88bbe.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\bc30dcae-f2a8-40ec-8da3-a1ab3e070505.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\bc945457-92fb-4068-8a47-b423cf87e065.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\bccb5832-bcbe-445b-987c-d3a801b94d98.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\be4dcd9a-6ce3-41b3-9513-deb292bc7bca.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\be62b63d-3d4c-4e5f-838f-a56ff0d56620.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\be854b0e-1cd5-48bc-b961-efbe3f85de9e.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\beaec20d-37c7-4a8a-b2f4-c7ad35399374.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\bef00ec6-63b9-40b9-b926-9d254b7508da.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\bf8bc245-2ed7-4458-a26a-9570f4f376a2.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\bf8da1ce-6165-4ef2-b388-55cfc4def55f.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR5609.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR5668.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR56C7.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR5725.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR5746.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR5756.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR5786.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR5843.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR595D.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR598D.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR599D.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR59DD.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR59ED.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR59FE.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR5A1E.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR6D56.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR6DA5.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR6DF4.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR6E53.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR6E83.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR6EC2.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR6EF2.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR6FAF.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR7039.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR7098.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR70AA.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR70DA.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR70EA.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR70F7.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR712A.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR713A.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR7146.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR714B.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR715C.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR7166.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR71E4.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR73C9.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR76B1.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR7710.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR776F.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR77BE.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR77DE.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR782D.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR79F4.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR7ACF.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR7AFF.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR8C46.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR8C66.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR8C77.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\BR8C97.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\c0862202-f21b-4e29-9fe2-6f8483be4b8c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c0d92e9a-07d7-4ae3-a5a6-46ceb5a65ca6.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\c11e0398-408a-4588-9011-c90cea022e63.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\c1579d72-ecfb-4ccd-bd49-85e1c698fe06.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\c176f004-1bee-451a-bdaa-c58cfbd8069a.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\c1812288-3aad-451e-a6eb-7dc18959a66d.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\c1b57913-6b3d-4bad-9b1c-bd026711b997.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c24bcfbe-dfcd-4d39-9460-437adfb6e0b9.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c2bace452413230a505b65c1d241e36f-{87A94AB0-E370-4cde-98D3-ACC110C5967D}
Deleted file - C:\Users\Ripple\AppData\Local\temp\c353e446-d473-40d0-bb39-14b7ec147563.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\c39e24f9-be74-4db4-b640-4be97e2cda21.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\c3cdad9b-38b4-43fc-9132-b0c7156921e0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c443fadf-b306-41e7-ac25-adc6aa1b9234.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\c47ed052-982c-4e76-9bd3-4619a9c1cb8c.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\c497ba33-ae4a-4f33-91c3-cb4693d13f0e.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\c4dc19bd-5b54-44a2-a21c-1c06c6e381f5.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\c4f032a9-8064-4c80-b1f9-665b77b135ae.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c4f93c03-bc6e-4ddc-ac08-b8ec67370d58.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\c4fc8eaf-b9bf-44b1-9b3e-d4a3a36db681.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\c5703c7c-079a-48f6-a233-15dd3ba0ffc9.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\c63018ca-68a5-4443-a360-ab364ffe8154.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c65e41a9-7f89-4050-959c-0d3fd9b9dac9.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\c6b3c3a5-e872-4a0e-8400-46f5c5fd5608.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\c76bd96f-3e9b-477f-b27a-c7ed60d74f0d.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\c78a93d6-96bd-4bb0-900f-65d6cc5049e0.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\c7ed1f29-52f6-4be1-b849-3db3464ce361.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c87bd622-3d22-4701-927e-53446ac0d994.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c87bfb21-dc0f-449e-ac14-a1f562cdf1c7.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\c8aae4b3-6a09-4119-a8e3-40183e20d3eb.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c9caba1b-55f9-401d-8144-a77bd2173bd4.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c9d0c511-d46d-408c-af22-5c68eaca8b92.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\c9f39f48-ce78-45a3-9f4e-95404183b8d4.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\cb80d0b1-a2a6-4c48-9b99-1052092170c8.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\cbeb7548-669f-434a-9300-187f0564879d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\cc9603c1-a61b-417f-9fa6-27665ca6f0aa.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\ccfa80e2-3c97-4162-80ca-225a9d317f86.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\cd161b1c-8034-4e38-b57c-525c12caf556.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\cda2a01b-e18e-4851-aecc-445b2dd4cd26.tmp.ico
Deleted file - C:\Users\Ripple\AppData\Local\temp\cdd3df55-9aee-4e5e-b8d6-b22f0b1c2b94.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\ce16c79c-20ec-4e7f-8b6a-431e50c25c8c.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\cf02060b-b7ab-4ee4-abe8-e29c5dfebd36.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\cf224f1c-f023-45f9-8116-dedcc168ad25.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\cf291c51-e0dc-45e2-be6d-72c6ad231668.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\cfde259a-7e84-4ec4-99b2-defcaf029e77.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\ClearLNK.ini
Deleted file - C:\Users\Ripple\AppData\Local\temp\cv_debug.log
Deleted file - C:\Users\Ripple\AppData\Local\temp\d0774d3e-b8bf-4462-8e20-57d518e7571c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\d15e1fe6-2bb3-4401-9a5e-4f3687d12a7a.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\d170da55-c6c0-449d-9530-709b057bc9eb.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\d19cca45-6114-4798-a67c-78707a985e87.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\d1ad0a3f-5834-46f6-8c58-40f5df1c7055.tmp.ico
Deleted file - C:\Users\Ripple\AppData\Local\temp\d2063665-051b-473d-973a-2bc1ab11f54f.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\d233a3ef-2863-4a78-9317-f0acf9cd951d.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\d26b1571-01a7-4911-8972-9f88e095b735.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\d3026123-9a21-47e0-9de8-f6d385141e00.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\d30acdf2-d00b-4236-8f03-179e0ece0771.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\d310c8a4-8e45-406b-8848-1d1f63f7b62d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\d32c996e-1ddf-48ba-9de1-e2c5bf602365.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\d34bb68f-79f2-409c-baf0-f8cb7b55678e.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\d359452e-4071-4dca-bfe4-012efd8fe958.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\d4386c7f-9f51-42d9-9aff-a84981a17b3e.tmp.ico
Deleted file - C:\Users\Ripple\AppData\Local\temp\d4cbbc1f-3409-4ed0-8717-25fcd1eff8c6.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\d5332b28-b088-4a7e-953c-1f9e8436a75c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\d542038e-38ef-49a7-a5ea-4a0f28d681c2.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\d60525f1-8a5c-453b-b306-fa772c85a9d9.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\d614e269-9014-4716-afac-a9a7e4343716.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\d6b56647-0f78-4222-8b8f-04177561d445.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\d6b7c8df-843a-480d-bb0c-3ff1654b983c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\d745fc8e-d5d5-4b78-8e92-e6bd774f7aa9.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\d8061ad0-e957-47de-a2fb-2dfe7462ffd4.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\d8be63e7-8b19-4f74-8257-6cb4288164fc.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\d93caec4-bf16-4681-a4c3-eb9ad82bb249.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\d984a6a2-e320-45d8-8ab4-087ca005c9e6.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\da48bc9d-27fe-4c3b-ada2-6b153f48c87d.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\da4c6570-fab2-4e11-b1b7-2d3ba8255abd.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\daa628ca-a177-4391-9266-1dd68d73175b.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\daae87fd-4127-4f52-b08d-e24d2239265c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\dad20ece-ad63-4df2-b1c5-cad63babea92.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\daf9a3f9-fad7-44a9-a6c7-b9da99d8e961.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\db3438c0-1323-498b-84a7-43f5e86c8068.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\dcb2e0de-0fd9-4210-8a97-64415a861813.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\dcdd9ee0-a1c1-4bb1-ba03-51e9e6f5be35.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\dd6d88fa-0476-443b-b1ff-585ba764828c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ddc5e351-aa1f-4e27-be6b-e5c7fa52846e.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ddf840eb-1409-49df-8a77-ae20377180f2.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\de3c5aaa-cb4f-488d-8099-cd7544d2cbb4.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\de492a66-c693-40f7-ac2e-95b55c765430.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\ded9a324-1481-4061-92ee-b3ae8efde333.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\e0657388-e1fc-4ff6-8c33-60f09653f019.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\e07a9afa-992e-4023-ad45-6637adfc974d.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\e083b263-5a14-494c-a2e6-e9cf2549e85b.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\e097450c-9be5-4955-ad79-497e827f2e9e.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\e0ae8528-e310-4b79-819b-30d2744f388a.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\e0b04fce-96cb-4d96-9db3-2e69aaefbb36.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\e0bc1dcd-6b3c-468b-bcb5-5a62b5d9a551.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\e1164d9b-8bfa-4460-b605-7b07a5786d02.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\e12bd4e7-b9bd-41aa-b0a1-c29b532427c5.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\e188e51a-3a0f-4064-8821-fad8ab1c14e7.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\e1b87d4f-ee86-4c24-9fdc-aebfbd84a215.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\e2ae73a7-2692-4889-9fda-e35aecf22117.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\e2cd45fa-1244-46e6-820f-3160dfe5d49c.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\e2fc992e-5440-4f04-bfe0-6fad548e0283.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\e35f5008-8865-4ba6-818d-7d7c136ca143.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\e3e2faf6-53a8-49e1-8011-9cc3a51c86f5.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\e415fb4a-d648-4635-be4a-0b6e7d44b300.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\e4247ca2-00f9-47bf-88e0-71d0de91d174.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\e47cc2c4-d175-4cca-ab08-632af8aa959d.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\e4daa7c6-da66-4e4f-8eb7-824068a43cc6.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\e54e93ae-8fbc-4125-b55d-fe0c1c9a5250.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\e55df656-b3dc-44e1-b1fd-34a85551cce4.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\e602606b-4d6b-4a37-8911-c7f417beab25.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\e677316a-5257-4f34-9106-7a79ae98a268.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\e6fd33c6-9eb1-4b7f-aaaa-c5c899b0170b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\e72fa3e8-51bd-49d8-bb6b-b5abf1b945a5.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\e7b09627-ba00-4f56-9b6c-77388f34fa0b.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\e7e1eadf-7a69-4d88-8eff-888df17f9494.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\e901af71-d0fd-4cc8-97bd-0d677745f5ce.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\e98df5a0-5f2a-4b16-9212-517692b36079.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\e9d4392e-f550-45a7-9d71-983c42c3e95d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\e9f3252f-252e-4e39-9445-d41bdb14d603.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\ea6a905f-e23f-4299-974c-ebe8ba00f802.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\ea792b6f-7134-4af9-a42f-ae7f793155c1.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\eaf15bc3-b787-4561-8516-37cee3150fda.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\ebb5f549-38c1-45be-9ea6-5fbd77479f21.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ebe18daa-b0e8-4f54-b609-bbb71d250988.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\ec4882d3-25ae-4f06-b274-4af2453ec3d8.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\ecc82fe9-72ca-4064-8303-8f3793276d40.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ed9e490e-295c-419e-bb6d-fe5182306d42.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\edc57dc9-0355-47f7-af02-ccaa7e375fb4.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\edc5913d-82a2-4b09-adec-91fc48c7c6b8.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\edf581d3-75ef-4937-8f2e-f4ea844b5071.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ee021a83-f5ce-4232-aaa0-26d0bd81c783.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\ee34be92-d088-4a97-b9b2-8a3cfd1d7ca4.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ee5878b5-36c0-41a3-a8cd-16b6117cd234.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\ee6014a4-8fdb-4627-a9a1-aaa43c10fcda.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\ee8b744d-9db6-4992-a4ca-47db7cf49381.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\eec3d88b-78ef-4be6-822c-b47443281834.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\eef3d0d6-cca2-44b8-a810-07318a2c171a.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ef60f6fb-1f84-4f67-9438-7b2c74ba0ec3.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\ef6eba1e-2100-4368-8bce-08b8d47ea1cb.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ef7e5d7b-2621-49e2-b1bc-d05618a248d0.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ef9391ae-9e67-4c69-8c58-e73885250408.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\efe5b8a7-d80b-4c76-ac86-752922e3af62.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f060737a-d755-41f8-93ae-878c8d4e8ce6.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\f0e9d3f9-3ffc-40b6-ba9e-a22e4467952b.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\f145524f-fbff-46cb-b864-42d7d47a076d.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\f14f1b17-302c-412d-a226-8da3b90a8ec0.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\f1a2c175-ceeb-4cd5-a278-d31292627ff9.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f23a92ee-82c3-4ed1-a14d-b62c17c9368e.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f28d2eb5-5afd-484d-a32a-adc15f3c16b9.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\f2a4c573-f738-458d-84ff-9f673dd08749.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\f394dafe-6380-46af-ab1c-e982bb0444fe.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f43b4041-3723-4f88-9598-9694613c9caf.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\f447f890-39e4-4e8c-9133-9b213554456a.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f4fa4dfc-3072-43ae-9f3c-a86d6d2718c8.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\f53437f7-f8b0-435e-8abf-9bb6dcf669bd.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\f5d31baf-ca69-4503-902b-36a9c845ebe9.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\f61cb0b6-00cb-42b6-85a4-05aef92f5e2f.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\f659c8a6-2622-4a15-8e80-01eb4898a68d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f66a4d9a-541c-4939-be47-1a1e9e1ac00f.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f6f84e3e-578a-4015-a397-e5df6e1d93ec.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\f7ad0cbc-06d4-4797-9f34-87a1ea51b2cf.tmp.css
Deleted file - C:\Users\Ripple\AppData\Local\temp\f7db505b-620c-4b35-855b-fd70a08837ee.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\f86072e3-4de7-4640-a8ef-b0175ad5da89.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f871a02d-1e17-4da3-b1ff-09a996e66c0d.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\f8904035-f8e7-412f-bd8d-fb9956233781.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f8c5a7dd-f68a-4c13-87db-ae75b45f9133.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f8cb4785-373b-45d1-865b-58240c5d52f7.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f8e1c2a8-492a-41ee-8c5e-0ce6c746e928.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\f98108bd-cc49-4d6e-a6f0-986c3ece7b35.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\fa0af870-8cf4-4703-8ac1-d05aec057411.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\fa21966a-8267-4419-9d1e-a0dfb8ac87b9.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\fa99305f-8c3d-4aa3-add5-829cc6a5e344.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\faa01de8-66ee-40f4-a1c4-b674d3d2814e.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\fac3fcc6-8037-43ad-ae00-3ff1554c1cc2.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\fb4d8831-6d42-4cd5-83b4-dd3b620d7664.tmp.ttf
Deleted file - C:\Users\Ripple\AppData\Local\temp\fbcd0f84-9cee-488c-80bf-d28cc3de097d.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\fce6c75a-f990-4b8d-aa69-d3a33c9f8aa4.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\fd80fdab-9486-44a8-957b-d3014d7d4f10.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\fd8b5e17-adaf-46eb-a727-9a65344efe87.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\fdb1024c-7436-4192-89cb-067375cef646.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\fdf187a8-0db0-478b-afb5-5144d5454c0e.tmp.html
Deleted file - C:\Users\Ripple\AppData\Local\temp\fe86589e-c5f7-4e3c-8288-0fa9fa4411fb.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\fedf4dbb-b799-4ec4-b824-e83bd64eb3c6.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\fefaf0fb-189a-4586-91ff-691a1f6d989e.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\ff45c1bb-4c74-4dfc-aff3-81dad7dd76df.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\ff477f3f-880e-4d63-ba8a-576fb186d8b2.tmp.ico
Deleted file - C:\Users\Ripple\AppData\Local\temp\ff5b3e2b-c19c-475b-b0a3-dc1392106206.tmp.woff2
Deleted file - C:\Users\Ripple\AppData\Local\temp\ffa62048-fb9b-46ad-a59f-c828a60f10fa.tmp.js
Deleted file - C:\Users\Ripple\AppData\Local\temp\ffb6d1f6-8fa2-4b86-963f-eeca62997ffc.tmp.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\geek64.exe
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna11309173174810533437.hunspell-win-x86-64.dll
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna11811301413503362853.hunspell-win-x86-64.dll
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna1232128769666004973.hunspell-win-x86-64.dll
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna13684749441922982248.hunspell-win-x86-64.dll
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna14917467050436688614.hunspell-win-x86-64.dll
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna17044614939546011431.hunspell-win-x86-64.dll
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna4101609854121766903.hunspell-win-x86-64.dll
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna7477610178925801608.hunspell-win-x86-64.dll
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna7830394222954009196.hunspell-win-x86-64.dll
Deleted file - C:\Users\Ripple\AppData\Local\temp\NotifyIconGeneratedAumid_2270376632787914086.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\PreMiD-release.zip
Deleted file - C:\Users\Ripple\AppData\Local\temp\SteelSeriesGGWebInstaller-1.3.2.exe
Deleted file - C:\Users\Ripple\AppData\Local\temp\StructuredQuery.log
Deleted file - C:\Users\Ripple\AppData\Local\temp\tmp1721044457.bat
Deleted file - C:\Users\Ripple\AppData\Local\temp\tmp1721048281.bat
Deleted file - C:\Users\Ripple\AppData\Local\temp\wctF478.tmp
Deleted file - C:\Users\Ripple\AppData\Local\temp\wmsetup.log
Deleted file - C:\Users\Ripple\AppData\Local\temp\{28C63251-B2EC-4DA4-AB37-4F31248EBCD3} - OProcSessId.dat
Deleted file - C:\Users\Ripple\AppData\Local\temp\{3FBAC7BA-C2D4-4F38-BD3D-B7D51A11BEA1} - OProcSessId.dat
Deleted file - C:\Users\Ripple\AppData\Local\temp\{67C5713B-2181-4BBE-A67C-3700CC0C0A98} - OProcSessId.dat
Deleted file - C:\Users\Ripple\AppData\Local\temp\{7113B3C2-FC9D-4B03-9EDB-2AD399DC8163} - OProcSessId.dat
Deleted file - C:\Users\Ripple\AppData\Local\temp\{9422733A-8B9C-4913-9FBF-B4A6F0A70CD6} - OProcSessId.dat
Deleted file - C:\Users\Ripple\AppData\Local\temp\{9D7A7FE2-77AD-4ED9-8D51-F72BD3105627} - OProcSessId.dat
Deleted file - C:\Users\Ripple\AppData\Local\temp\{B3EE1568-F734-4AD9-AC7B-1755610EF559} - OProcSessId.dat
Deleted file - C:\Users\Ripple\AppData\Local\temp\{C25BF13A-D3D3-453F-AFFD-0913FEC398A7} - OProcSessId.dat
Deleted file - C:\Users\Ripple\AppData\Local\temp\{EDACDF1B-33BE-45B6-AC9E-C7C8FE84F080} - OProcSessId.dat
Deleted file - C:\Users\Ripple\AppData\Local\temp\{F5722B86-11D9-41F6-A0FF-7CB42746EBC1} - OProcSessId.dat
Deleted file - C:\Users\Ripple\AppData\Local\temp\~DF0270C4BB8870D113.TMP
Deleted file - C:\Users\Ripple\AppData\Local\temp\~DF32C60D44F6EA99FD.TMP
Deleted file - C:\Users\Ripple\AppData\Local\temp\~DF48D59528EA4C808F.TMP
Deleted file - C:\Users\Ripple\AppData\Local\temp\~DF52737D8E3EBC4400.TMP
Deleted file - C:\Users\Ripple\AppData\Local\temp\~DF56C50B1AC39B5C2F.TMP
Deleted file - C:\Users\Ripple\AppData\Local\temp\~DF66C063E0A77CB40F.TMP
Deleted file - C:\Users\Ripple\AppData\Local\temp\~DF6F2E5BD1A7C730CB.TMP
Deleted file - C:\Users\Ripple\AppData\Local\temp\~DF74F2D00A36D5585D.TMP
Deleted file - C:\Users\Ripple\AppData\Local\temp\~DFB0E528B3F473D3FE.TMP
Deleted file - C:\Users\Ripple\AppData\Local\temp\~DFED0C3D49A7C30FA9.TMP
C:\Users\Ripple\AppData\Local\temp\067fa55c-3712-4f05-b90b-195b5d5708bc_geek.7z.8bc\geek.exe
C:\Users\Ripple\AppData\Local\temp\2dcb20a8-f772-4e23-8b34-eff9b60ed3ba_geek.7z.3ba\geek.exe
C:\Users\Ripple\AppData\Local\temp\cda5c39c-2390-4a6e-bceb-a83239ddae30_geek.7z.e30\geek.exe
Deleted file - C:\Users\Ripple\AppData\Local\temp\Diagnostics\EXCEL\Primary1721132847740432900_1F7D9DA8-7B11-4622-9D0F-1685045BE238.log
Deleted file - C:\Users\Ripple\AppData\Local\temp\Diagnostics\EXCEL\Primary1721198842254487600_75E7285C-9DC4-4556-A86D-19C941283F8F.log
Deleted file - C:\Users\Ripple\AppData\Local\temp\Diagnostics\EXCEL\Primary1721198842254811800_75E7285C-9DC4-4556-A86D-19C941283F8F.log
Deleted file - C:\Users\Ripple\AppData\Local\temp\Diagnostics\EXCEL\Additional\Additional1721132847742384600_1F7D9DA8-7B11-4622-9D0F-1685045BE238.log
Deleted file - C:\Users\Ripple\AppData\Local\temp\Diagnostics\EXCEL\Additional\Additional1721198842255402300_75E7285C-9DC4-4556-A86D-19C941283F8F.log
Deleted file - C:\Users\Ripple\AppData\Local\temp\Diagnostics\EXCEL\Additional\Additional1721198842255741700_75E7285C-9DC4-4556-A86D-19C941283F8F.log
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna-77124\jna16503602735776529953.dll
Deleted file - C:\Users\Ripple\AppData\Local\temp\jna-77124\jna16503602735776529953.dll.x
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir1420_592117597\152e62d4ee7d5d04173db4948b9fe88c.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir1420_592117597\2c5e76d11b0db9f511dfa44d4e39e741.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir1420_592117597\3000504e0e12f3e27f78c4be52ecfaa2.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir1420_592117597\84d4e23663500c265a42412358bbb81e.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir1420_592117597\9ca96a04433e09b636f147003631330d.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir1420_592117597\a0df42cc9edc6f9eb5d2d0b78d287790.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir1420_592117597\aae956e1ce94eb51634c41e312fad554.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir1420_592117597\de99dc7c3dd658f382a1850e1b439e7c.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir1420_592117597\e2d70704e675aa97740ae5d4012622e6.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir15036_896862500\a0df42cc9edc6f9eb5d2d0b78d287790.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir15036_896862500\de99dc7c3dd658f382a1850e1b439e7c.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir18256_807762058\69301dc170c3af297f65b85e5e39e6c1.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir18256_807762058\de99dc7c3dd658f382a1850e1b439e7c.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir72676_288981840\de99dc7c3dd658f382a1850e1b439e7c.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir8160_892652393\de99dc7c3dd658f382a1850e1b439e7c.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir9444_1073407461\36ef7675f4919a6d1ca29722f68047d3.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir9444_1073407461\a0df42cc9edc6f9eb5d2d0b78d287790.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir9444_1073407461\c651043b8d21e2c054e38597e6eecf77.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir9444_1073407461\ca7300b352a09d1fa44864da6f46dcab.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir9444_1073407461\de99dc7c3dd658f382a1850e1b439e7c.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir9660_1491964563\1a5590aa9f3d4f34f30548489be74fb0.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\scoped_dir9660_1491964563\b8e6d1a5e8a307e7a2a5601107b2c420.png
Deleted file - C:\Users\Ripple\AppData\Local\temp\SmartScreen\RemoteData\LastPing
Deleted file - C:\Users\Ripple\AppData\Local\temp\SmartScreen\RemoteData\windowsSettings
Deleted file - C:\Users\Ripple\AppData\Local\temp\SmartScreen\RemoteData\windowsSettings_1.0-7e3544113374bc2769af5f67e125ab81de1b4b64c07fe68e2a7bc03646c85dfc
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.NET.Native.Framework.1.6_1.6.27413.0_x64__8wekyb3d8bbwe.appx
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.NET.Native.Framework.1.6_1.6.27413.0_x86__8wekyb3d8bbwe.appx
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.NET.Native.Framework.2.2_2.2.29512.0_x64__8wekyb3d8bbwe.appx
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.NET.Native.Framework.2.2_2.2.29512.0_x86__8wekyb3d8bbwe.appx
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.NET.Native.Runtime.1.6_1.6.24903.0_x64__8wekyb3d8bbwe.Appx
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.NET.Native.Runtime.1.6_1.6.24903.0_x86__8wekyb3d8bbwe.Appx
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.NET.Native.Runtime.2.2_2.2.28604.0_x64__8wekyb3d8bbwe.appx
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.NET.Native.Runtime.2.2_2.2.28604.0_x86__8wekyb3d8bbwe.appx
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.Services.Store.Engagement_10.0.23012.0_x64__8wekyb3d8bbwe.appx
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.Services.Store.Engagement_10.0.23012.0_x86__8wekyb3d8bbwe.appx
Deleted file - C:\Users\Ripple\AppData\Local\temp\StoreDownloads\Microsoft.Todos_1.48.21892.0_neutral_~_8wekyb3d8bbwe.appxbundle
Deleted file - C:\Users\Ripple\AppData\Local\temp\_uninstall\_uninstall36096


========= End of CMD: =========


=========== "C:\Windows\Temp\*.*" ==========

C:\Windows\Temp\.ses => moved successfully
C:\Windows\Temp\6109eb7f67.cgv => moved successfully
C:\Windows\Temp\77de87cf28.cgv => moved successfully
C:\Windows\Temp\8634883e6e.cgv => moved successfully
C:\Windows\Temp\ASPNETSetup_00000.log => moved successfully
C:\Windows\Temp\ASPNETSetup_00001.log => moved successfully
C:\Windows\Temp\bb3a785178f443fda931098a5a9a306b.db.ses => moved successfully
C:\Windows\Temp\chrome_installer.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1149.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1156.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1202.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1203.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1205.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1205a.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1206.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1210.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1211.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1216.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1244.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1251.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1302.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1704.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1706.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-1711.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240712-2145.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1041.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1054.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1059.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1101.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1101a.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1619.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1619a.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1738.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1742.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1855.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240713-1904.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240714-1008.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240714-1010.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240714-1015.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240714-1020.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240714-1020a.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240714-1022.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240714-1033.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240715-0931.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240715-0932.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240715-0937.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240715-0941.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240715-0941a.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240715-0942.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240715-1846.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240715-1851.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240716-1002.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240716-1003.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240716-1008.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240716-1012.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240716-1012a.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240716-1018.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240716-1128.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1131.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1136.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1140.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1140a.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1141.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1251.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1256.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1502.log => moved successfully
C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1506.log => moved successfully
Could not move "C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1514.log" => Scheduled to move on reboot.
C:\Windows\Temp\f9cf60754f.cgv => moved successfully
C:\Windows\Temp\fxh0hog1.rvt.xml => moved successfully
C:\Windows\Temp\mat-debug-3316.log => moved successfully
C:\Windows\Temp\mat-debug-5616.log => moved successfully
C:\Windows\Temp\mat-debug-5808.log => moved successfully
C:\Windows\Temp\mat-debug-5948.log => moved successfully
C:\Windows\Temp\mat-debug-6016.log => moved successfully
C:\Windows\Temp\mat-debug-6020.log => moved successfully
C:\Windows\Temp\mat-debug-6140.log => moved successfully
C:\Windows\Temp\mat-debug-6188.log => moved successfully
C:\Windows\Temp\mat-debug-6508.log => moved successfully
C:\Windows\Temp\mat-debug-6664.log => moved successfully
C:\Windows\Temp\mat-debug-6700.log => moved successfully
C:\Windows\Temp\mat-debug-6704.log => moved successfully
C:\Windows\Temp\mat-debug-6768.log => moved successfully
C:\Windows\Temp\mat-debug-6796.log => moved successfully
C:\Windows\Temp\mat-debug-864.log => moved successfully
C:\Windows\Temp\MpSigStub.log => moved successfully
C:\Windows\Temp\msedge_installer.log => moved successfully
C:\Windows\Temp\perfboost.exe_c2rdll(20240712120516221C).log => moved successfully
C:\Windows\Temp\temp.01DAD4236CA95E85.sdb => moved successfully
C:\Windows\Temp\temp.01DAD4236CAA866E.sdb => moved successfully
C:\Windows\Temp\temp.01DAD4246BD79C2D.sdb => moved successfully
C:\Windows\Temp\temp.01DAD4246BE5844A.sdb => moved successfully
C:\Windows\Temp\temp.01DAD4246D5AEB9C.sdb => moved successfully
C:\Windows\Temp\temp.01DAD4246D5D4E03.sdb => moved successfully
C:\Windows\Temp\TS_C033.tmp => moved successfully
C:\Windows\Temp\TS_C043.tmp => moved successfully
C:\Windows\Temp\TS_C044.tmp => moved successfully
C:\Windows\Temp\TS_C055.tmp => moved successfully
C:\Windows\Temp\TS_C056.tmp => moved successfully
C:\Windows\Temp\TS_C076.tmp => moved successfully
C:\Windows\Temp\TS_C096.tmp => moved successfully
C:\Windows\Temp\TS_C0A7.tmp => moved successfully
C:\Windows\Temp\TS_C0C7.tmp => moved successfully

========= End -> "C:\Windows\Temp\*.*" ========


=========== "C:\WINDOWS\system32\*.tmp" ==========

not found

========= End -> "C:\WINDOWS\system32\*.tmp" ========


=========== "C:\WINDOWS\syswow64\*.tmp" ==========

not found

========= End -> "C:\WINDOWS\syswow64\*.tmp" ========


=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 15945118 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 551910185 B
Windows/system/drivers => 54 B
Edge => 0 B
Chrome => 2367420 B
Firefox => 289693527 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 867 B
LocalService => 867 B
NetworkService => 6717 B
Ripple => 23618061 B

RecycleBin => 0 B
EmptyTemp: => 843.9 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 17-07-2024 15:18:16)

C:\Windows\Temp\DESKTOP-NLBF3N2-20240717-1514.log => Is moved successfully

==== End of Fixlog 15:18:16 ====
 
Look in the Autologger folder and drag out the CheckBrowsersLNK file.
To your desktop.

AutoLogger\CheckBrowserLnk
Drag and drop onto the ClearLNK utility .
After saving ClearLNK to desktop.
move.gif


After this please update on laptop performance, let me know if there are anymore issues.
 
  • Like
Reactions: maxim123
We ran the autologger tool earlier in the thread, there you will find CheckBrowsersLNK file.
 
  • Like
Reactions: maxim123
Look in the Autologger folder and drag out the CheckBrowsersLNK file.
To your desktop.


Drag and drop onto the ClearLNK utility .
After saving ClearLNK to desktop.
move.gif


After this please update on laptop performance, let me know if there are anymore issues.
sorry, I did the process, but thought the log wasn't saved. looked at the folder and the log is there:

Code:
ClearLNK by Alex Dragokas                                 ver. 2.9.0.18

OS:       x64 Windows 10 Pro, 10.0.22631.3880, Service Pack: 0
Time:     17.07.2024 - 14:44
Language: OS: EN (0x409). Display: EN (0x409). Non-Unicode: EN (0x409)
Elevated: Yes
User:     Max    (group: Administrator)

_____________________________ Begin of Log ______________________________
.
[ OK ] 3  "C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\VoiceAccess.lnk"    -> [ "C:\WINDOWS\system32\voiceaccess.exe" ]   (icon has been recovered)
[ OK ] 4  "C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk"    -> [ "C:\WINDOWS\system32\osk.exe" ]   (icon has been recovered)
[ OK ] 5  "C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk"    -> [ "C:\WINDOWS\system32\narrator.exe" ]   (icon has been recovered)
[ OK ] 6  "C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\LiveCaptions.lnk"    -> [ "C:\WINDOWS\system32\LiveCaptions.exe" ]   (icon has been recovered)
.
[DEL ] 1  "C:\Users\Ripple\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\2dc42b586666853c\League of Legends.lnk"    (target was not recovered)
[DEL ] 2  "C:\Users\Ripple\Desktop\loan - Shortcut.lnk"    (target was not recovered)
.
[WARN] 7  "C:\Users\Ripple\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk"    -> [ "C:\WINDOWS\system32\mblctr.exe" ]   (already cured)
.
____________________________ Icons location _____________________________
.
[ OK ] "C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\VoiceAccess.lnk"     ->     [ ".", index=1 ]  (Method: 3)
[ OK ] "C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk"     ->     [ ".", index=1 ]  (Method: 3)
[ OK ] "C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk"     ->     [ ".", index=1 ]  (Method: 3)
[ OK ] "C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\LiveCaptions.lnk"     ->     [ ".", index=1 ]  (Method: 3)
.
______________________________ Statistics _______________________________
Cure ran per today: 1 times.

  Total processed:  7

         Cured:     4
         Deleted:   2
         Warnings:  1
______________________________ End of Log _______________________________
 
Ok. post fresh FRST logs and test the machine, update the thread when you have ran the computer as usual for a while.
 
  • Like
Reactions: maxim123
Ok. post fresh FRST logs and test the machine, update the thread when you have ran the computer as usual for a while.
FRST
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16.07.2024
Ran by Max (administrator) on DESKTOP-NLBF3N2 (Standard Standard) (17-07-2024 16:35:18)
Running from C:\Users\Ripple\Desktop\FRST64.exe
Loaded Profiles: Max
Platform: Microsoft Windows 11 Pro Version 23H2 22631.3880 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(C:\Program Files\SteelSeries\GG\apps\engine\SteelSeriesEngine.exe ->) (SteelSeries ApS -> SteelSeries ApS) C:\Program Files\SteelSeries\GG\apps\engine\prism\SteelSeriesPrism.exe
(C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe ->) (SteelSeries ApS -> SteelSeries ApS) C:\Program Files\SteelSeries\GG\apps\engine\SteelSeriesEngine.exe
(D:\Riot Games\League of Legends\LeagueClient.exe ->) (Riot Games, Inc. -> ) D:\Riot Games\League of Legends\LeagueCrashHandler64.exe
(D:\Riot Games\League of Legends\LeagueClient.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) D:\Riot Games\League of Legends\LeagueClientUx.exe
(D:\Riot Games\League of Legends\LeagueClientUx.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) D:\Riot Games\League of Legends\LeagueClientUxRender.exe <6>
(D:\Riot Games\Riot Client\RiotClientServices.exe ->) () [File not signed] D:\Riot Games\Riot Client\RiotClientCrashHandler.exe
(D:\Riot Games\Riot Client\RiotClientServices.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) D:\Riot Games\League of Legends\LeagueClient.exe
(D:\Riot Games\Riot Client\RiotClientServices.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) D:\Riot Games\Riot Client\RiotClientElectron\Riot Client.exe <5>
(Discord Inc. -> Discord Inc.) C:\Users\Ripple\AppData\Local\Discord\app-1.0.9154\Discord.exe <6>
(DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2dc21f242486f9\ipf_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2dc21f242486f9\ipf_helper.exe
(Eclipse.org Foundation, Inc. -> Eclipse Adoptium) D:\Program Files\OmegaT\jre\bin\javaw.exe
(explorer.exe ->) (GitHub, Inc.) [File not signed] C:\Users\Ripple\AppData\Roaming\PreMiD\PreMiD.exe <3>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <10>
(explorer.exe ->) (Matthew Malensek) [File not signed] D:\Program Files (x86)\3RVX\3RVX.exe
(explorer.exe ->) (OBS Project, LLC -> OBS) D:\Program Files\obs-studio\bin\64bit\obs64.exe
(explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgtray.exe
(explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) D:\Riot Games\Riot Client\RiotClientServices.exe
(explorer.exe ->) (Spotify Ltd) [File not signed] E:\Program Files (x86)\spotify portable\App\Spotify\Spotify.exe <5>
(explorer.exe ->) (SteelSeries ApS -> SteelSeries ApS) C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe
(Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2405.13.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <19>
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(services.exe ->) (Creative Technology Ltd -> Creative Technology Ltd) C:\Windows\SysWOW64\Creative.UWPRPCService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_a687edda40db3316\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_faf3bcecf744f99a\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2dc21f242486f9\ipf_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvtfi.inf_amd64_4cd94d3ab4900da6\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_19d333f59f2c41d3\RtkAudUService64.exe <2>
(services.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgc.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_19d333f59f2c41d3\RtkAudUService64.exe [3496528 2021-12-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [SteelSeriesGG] => C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe [15941968 2024-07-09] (SteelSeries ApS -> SteelSeries ApS)
HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [3023152 2024-06-28] (Riot Games, Inc. -> Riot Games, Inc.)
HKLM\...\Policies\Explorer: [NoInstrumentation] 1
HKLM\Software\Policies\...\system: [EnableActivityFeed] 0
HKLM\Software\Policies\...\system: [PublishUserActivities] 0
HKLM\Software\Policies\...\system: [UploadUserActivities] 0
HKLM\Software\Policies\...\system: [AllowClipboardHistory] 0
HKLM\Software\Policies\...\system: [AllowCrossDeviceClipboard] 0
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Run: [3RVX] => D:\Program Files (x86)\3RVX\3RVX.exe [649216 2016-06-04] (Matthew Malensek) [File not signed]
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Run: [electron.app.BlueStacks Services] => C:\Users\Ripple\AppData\Local\Programs\bluestacks-services\BlueStacksServices.exe [162219656 2024-01-25] (Now.gg, INC -> now.gg, Inc.)
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Run: [PreMiD] => C:\Users\Ripple\AppData\Roaming\PreMiD\PreMiD.exe [126285312 2021-02-21] (GitHub, Inc.) [File not signed]
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Policies\Explorer: [NoWinkeys] 0
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Policies\Explorer: [NoViewContextMenu] 0
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\126.0.6478.128\Installer\chrmstp.exe [2024-07-17] (Google LLC -> Google LLC)
Startup: C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FANTECH X4S MACRO Gaming Mouse.lnk [2023-12-06]
ShortcutTarget: FANTECH X4S MACRO Gaming Mouse.lnk -> D:\Program Files (x86)\FANTECH X4S MACRO Gaming Mouse\GM_Management.exe () [File not signed]

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {EA42CB3B-5A39-4AC0-8A5A-68CE8D0FB14A} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [302968 2024-01-18] (Now.gg, INC -> BlueStack Systems, Inc.)
Task: {37657D15-4F3E-4E41-926D-71EDD111C55C} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [5513520 2024-07-12] (Microsoft Windows -> Microsoft Corporation)
Task: {D3499911-9F5B-4754-92D3-B6E135AE3417} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem128.0.6537.0{C0EACB23-DDAF-459F-A287-CF96749DBEA5} => C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe [4623976 2024-06-14] (Google LLC -> Google LLC)
Task: {87086893-B424-4430-86D3-EE498B4BE3D6} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28512336 2024-07-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {67C10FB8-60E4-41A7-9758-CAD507917BC6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28512336 2024-07-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {CD4CC5AA-A4A1-4A44-ACB3-6C7B38A52BEE} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309936 2024-07-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {A89F3999-EEC5-427E-A763-8BA09B4403D1} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309936 2024-07-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {9656D819-62AF-4D69-B699-8C68A4310E22} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [169408 2024-06-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {79A20CC3-B704-460F-A061-E00C0679642C} - System32\Tasks\Microsoft\Windows\Application Experience\PcaWallpaperAppDetect => C:\WINDOWS\system32\rundll32.exe [90112 2024-07-12] (Microsoft Windows -> Microsoft Corporation) -> %windir%\system32\PcaSvc.dll,PcaWallpaperAppDetect
Task: {3F888CBC-7594-4699-B4B5-1D9B2D37404D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpCmdRun.exe [1678960 2024-07-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {10518597-5D30-4221-8753-6F0E711E0D2B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpCmdRun.exe [1678960 2024-07-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A422DBD1-3901-4C9A-865A-A668DFD2D395} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpCmdRun.exe [1678960 2024-07-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A098E4CD-4193-4C33-8398-EF1F827C4E87} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpCmdRun.exe [1678960 2024-07-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F67F9D95-F233-4101-915E-4DC4980112E0} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [676936 2024-06-28] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {098670C3-842F-4331-9869-89EE208595EE} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34888 2024-06-28] (Mozilla Corporation -> Mozilla Foundation)
Task: {176762D5-9B28-46D7-91E9-1F49E28C8B2D} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [815 2022-11-23] () [File not signed]
Task: {3B68BE5D-1D28-4A37-9060-3479C160F4C6} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1277480 2024-06-12] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {FFA705B0-F0F3-4335-AC88-F752BDDBD4D2} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3347496 2024-06-12] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {665F3518-8591-4EB9-A1D1-C1A0D3523F3A} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646696 2024-06-12] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {94532462-E8CA-4A59-BB70-F974E4F927CA} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-12] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {BE6011F2-46D2-46B4-ACFB-D7C02DF44EA2} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-12] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {792583C0-E4F1-48F8-AC01-3428F7492A6A} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-12] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C22467B7-99F2-406A-801A-0519DDE2288A} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-12] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {69A8279C-3C72-440E-B9EA-89391F80871A} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-12] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6603C4FF-A81E-46DB-A480-B0561102DFE4} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1673768 2024-06-12] (NVIDIA Corporation -> NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.101.1 8.8.8.8 4.4.4.4
Tcpip\..\Interfaces\{78d68de6-b91f-4ad0-b2d5-9d46d5172317}: [DhcpNameServer] 192.168.101.1 8.8.8.8 4.4.4.4

Edge:
=======
Edge Profile: C:\Users\Ripple\AppData\Local\Microsoft\Edge\User Data\Default [2024-07-17]
Edge Extension: (Google Docs Offline) - C:\Users\Ripple\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-15]
Edge Extension: (Edge relevant text changes) - C:\Users\Ripple\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-03-22]

FireFox:
========
FF DefaultProfile: g5q70h39.default
FF ProfilePath: C:\Users\Ripple\AppData\Roaming\Mozilla\Firefox\Profiles\g5q70h39.default [2024-07-17]
FF ProfilePath: C:\Users\Ripple\AppData\Roaming\Mozilla\Firefox\Profiles\10706u2g.default-release [2024-07-17]
FF DownloadDir: C:\Users\Ripple\Desktop
FF Homepage: Mozilla\Firefox\Profiles\10706u2g.default-release -> about:blank
FF Session Restore: Mozilla\Firefox\Profiles\10706u2g.default-release -> is enabled.
FF Notifications: Mozilla\Firefox\Profiles\10706u2g.default-release -> hxxps://pomofocus.io
FF Extension: (Tampermonkey) - C:\Users\Ripple\AppData\Roaming\Mozilla\Firefox\Profiles\10706u2g.default-release\Extensions\firefox@tampermonkey.net.xpi [2024-05-11]
FF Extension: (FoxyProxy) - C:\Users\Ripple\AppData\Roaming\Mozilla\Firefox\Profiles\10706u2g.default-release\Extensions\foxyproxy@eric.h.jung.xpi [2024-01-31]
FF Extension: (Web Paint) - C:\Users\Ripple\AppData\Roaming\Mozilla\Firefox\Profiles\10706u2g.default-release\Extensions\jid1-0dhOSYKGj326og@jetpack.xpi [2024-04-26]
FF Extension: (IDM Integration Module) - C:\Users\Ripple\AppData\Roaming\Mozilla\Firefox\Profiles\10706u2g.default-release\Extensions\mozilla_cc3@internetdownloadmanager.com.xpi [2024-07-10]
FF Extension: (PreMiD) - C:\Users\Ripple\AppData\Roaming\Mozilla\Firefox\Profiles\10706u2g.default-release\Extensions\support@premid.app.xpi [2024-07-16] [UpdateUrl:hxxps://api.premid.app/firefox/updates]
FF Extension: (uBlock Origin) - C:\Users\Ripple\AppData\Roaming\Mozilla\Firefox\Profiles\10706u2g.default-release\Extensions\uBlock0@raymondhill.net.xpi [2024-05-25]
FF Extension: (Inkah: Chinese & Korean Pop-up Dictionary) - C:\Users\Ripple\AppData\Roaming\Mozilla\Firefox\Profiles\10706u2g.default-release\Extensions\{de5bbbad-7c53-468e-9d8d-9d737cf5ba81}.xpi [2023-12-06]
FF Extension: (Zhongwen: The Popular Chinese Learning Tool) - C:\Users\Ripple\AppData\Roaming\Mozilla\Firefox\Profiles\10706u2g.default-release\Extensions\{dedb3663-6f13-4c6c-bf0f-5bd111cb2c79}.xpi [2023-12-31]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-04-04] (Microsoft Corporation -> Microsoft Corporation)

Chrome:
=======
CHR Profile: C:\Users\Ripple\AppData\Local\Google\Chrome\User Data\Default [2024-07-17]
CHR Extension: (uBlock Origin) - C:\Users\Ripple\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2024-06-26]
CHR Extension: (Google Docs Offline) - C:\Users\Ripple\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-07-01]
CHR Extension: (Zhongwen: Chinese-English Dictionary) - C:\Users\Ripple\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkmlkkjojmombglmlpbpapmhcaljjkde [2024-03-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ripple\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-12-07]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [15044872 2024-01-27] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14023752 2024-06-26] (Microsoft Corporation -> Microsoft Corporation)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [935344 2024-05-25] (EasyAntiCheat Oy -> Epic Games, Inc.)
S2 Intel(R) Platform License Manager Service; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\PlatformLicenseManagerService.exe [741488 2023-12-14] (Intel Corporation -> Intel(R) Corporation)
R2 ipfsvc; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2dc21f242486f9\ipf_uf.exe [2751664 2022-03-27] (Intel Corporation -> Intel Corporation)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8901528 2024-07-02] (Malwarebytes Inc. -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [3073888 2024-07-02] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpDefenderCoreService.exe [1377416 2024-07-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvtfi.inf_amd64_4cd94d3ab4900da6\Display.NvContainer\NVDisplay.Container.exe [1274888 2024-06-25] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [522184 2024-07-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 SteelSeriesGGUpdateServiceProxy; C:\Program Files\SteelSeries\GG\SteelSeriesGGUpdateServiceProxy.exe [1500608 2023-09-19] (SteelSeries ApS -> )
R2 UWPService; C:\WINDOWS\SysWOW64\Creative.UWPRPCService.exe [364616 2022-08-03] (Creative Technology Ltd -> Creative Technology Ltd)
R3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [9705560 2024-06-28] (Riot Games, Inc. -> Riot Games, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\NisSrv.exe [3236728 2024-07-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MsMpEng.exe [133688 2024-07-16] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 BlueStacksDrv_nxt; C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [394176 2024-01-18] (Microsoft Windows Hardware Compatibility Publisher -> Bluestack System Inc.)
R3 iaLPSS2_GPIO2_ADL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_adl.inf_amd64_0e92b4646ab70162\iaLPSS2_GPIO2_ADL.sys [150624 2022-06-02] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_I2C_ADL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_i2c_adl.inf_amd64_35ed2fd5a51c2bc2\iaLPSS2_I2C_ADL.sys [220256 2022-06-02] (Intel Corporation -> Intel Corporation)
R3 IntelGNA; C:\WINDOWS\System32\DriverStore\FileRepository\gna.inf_amd64_04d4eecc5838a558\gna.sys [88760 2023-07-02] (Intel Corporation -> Intel Corporation)
R3 ipf_cpu; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2dc21f242486f9\ipf_cpu.sys [80560 2022-03-27] (Intel Corporation -> Intel Corporation)
R3 ipf_lf; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_fe2dc21f242486f9\ipf_lf.sys [432800 2022-03-27] (Intel Corporation -> Intel Corporation)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2024-07-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-07-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBfilt; C:\WINDOWS\system32\drivers\MBfilt64.sys [37528 2022-08-03] (WDKTestCert ctl_avpbuild,132732627431976536 -> Creative Technology Ltd.)
R3 MpKsl5e6d9a26; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{644462FA-CB6F-4EA9-9945-1813D3122690}\MpKslDrv.sys [271640 2024-07-17] (Microsoft Windows -> Microsoft Corporation)
R1 npcap; C:\WINDOWS\system32\DRIVERS\npcap.sys [77792 2023-10-20] (Nmap Software LLC -> Insecure.Com LLC.)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys [47240 2024-04-03] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvpcf; C:\WINDOWS\System32\drivers\nvpcf.sys [236576 2024-06-25] (NVIDIA Corporation -> NVIDIA Corporation)
R3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_516e5c9b75c49dc2\rtcx21x64.sys [539648 2022-05-06] (Microsoft Windows -> Realtek)
R3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [43568 2024-06-11] (Microsoft Windows Hardware Compatibility Publisher -> SteelSeries ApS)
R3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [54408 2024-06-11] (Microsoft Windows Hardware Compatibility Publisher -> SteelSeries ApS)
R3 SteelSeries_Sonar_VAD; C:\WINDOWS\System32\DriverStore\FileRepository\steelseries-sonar-vad.inf_amd64_da15ab44a6216a8e\SteelSeries-Sonar-VAD.sys [95440 2023-03-18] (SteelSeries ApS -> Windows (R) Win 7 DDK provider)
R3 UWACPIDriver; C:\WINDOWS\System32\drivers\UWACPIDriver.sys [43776 2022-09-14] (Uniwill Technology Inc. -> )
R1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [40415320 2024-06-28] (Riot Games, Inc. -> Riot Games, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21968 2024-07-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [602520 2024-07-16] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105864 2024-07-16] (Microsoft Windows -> Microsoft Corporation)
S3 SbieDrv; \??\d:\Program Files\Sandboxie\SbieDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-07-17 15:13 - 2024-07-17 15:18 - 000128740 _____ C:\Users\Ripple\Desktop\Fixlog.txt
2024-07-17 14:59 - 2024-07-17 14:59 - 000004833 _____ C:\Users\Ripple\Desktop\ZHPCleaner (R).txt
2024-07-17 14:56 - 2024-07-17 14:56 - 000004603 _____ C:\Users\Ripple\Desktop\ZHPCleaner (S).txt
2024-07-17 14:50 - 2024-07-17 14:50 - 003365064 _____ (Nicolas Coolman) C:\Users\Ripple\Desktop\ZHPCleaner(1).exe
2024-07-17 14:50 - 2024-07-17 14:50 - 000000920 _____ C:\Users\Ripple\Desktop\ZHPCleaner.lnk
2024-07-17 14:44 - 2024-07-17 15:26 - 000000000 ____D C:\Users\Ripple\Desktop\LOG
2024-07-17 14:43 - 2024-07-17 14:43 - 000481552 _____ C:\Users\Ripple\Desktop\ClearLNK.zip
2024-07-17 14:39 - 2024-07-17 14:42 - 000000000 ____D C:\Users\Ripple\Desktop\AutoLogger
2024-07-17 14:36 - 2024-07-17 14:36 - 018503564 _____ (Company © regist & Drongo) C:\Users\Ripple\Desktop\AutoLogger.exe
2024-07-17 14:31 - 2024-07-17 14:37 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Everything
2024-07-17 14:31 - 2024-07-17 14:37 - 000000000 ____D C:\Users\Ripple\AppData\Local\Everything
2024-07-17 14:31 - 2024-07-17 14:31 - 000001062 _____ C:\Users\Public\Desktop\Everything.lnk
2024-07-17 14:31 - 2024-07-17 14:31 - 000000000 ____D C:\Program Files\Everything
2024-07-17 13:57 - 2024-07-17 13:58 - 000104601 _____ C:\Users\Ripple\Desktop\Addition.txt
2024-07-17 13:56 - 2024-07-17 16:35 - 000027053 _____ C:\Users\Ripple\Desktop\FRST.txt
2024-07-17 12:27 - 2024-07-17 12:27 - 000055142 _____ C:\Users\Ripple\Desktop\1503.pdf
2024-07-17 11:39 - 2024-07-17 12:46 - 000000000 ____D C:\Users\Ripple\Doctor Web
2024-07-17 11:38 - 2024-07-17 11:38 - 288453352 _____ C:\Users\Ripple\Desktop\qs76k3x5.exe
2024-07-15 18:42 - 2024-07-17 15:18 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\PreMiD
2024-07-15 18:42 - 2024-07-15 18:42 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PreMiD
2024-07-15 17:39 - 2024-07-15 17:39 - 000001148 _____ C:\Users\Ripple\Desktop\PreMiD.lnk
2024-07-15 12:43 - 2024-07-15 12:43 - 000000028 _____ C:\Users\Ripple\Desktop\Netflix pass.txt
2024-07-14 19:30 - 2024-07-14 19:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\obs-backgroundremoval
2024-07-14 19:02 - 2024-07-17 15:40 - 000000016 _____ C:\Users\Ripple\AppData\Roaming\obs-virtualcam.txt
2024-07-14 19:00 - 2024-07-17 13:09 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\obs-studio
2024-07-14 19:00 - 2024-07-14 19:00 - 000000913 _____ C:\Users\Public\Desktop\OBS Studio.lnk
2024-07-14 19:00 - 2024-07-14 19:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
2024-07-13 17:38 - 2024-07-13 17:38 - 000000000 ____D C:\WINDOWS\system32\SteelSeries
2024-07-13 14:14 - 2024-07-13 14:14 - 004880964 _____ C:\Users\Ripple\Desktop\抖音2024713-486756 (1).mp4
2024-07-13 14:13 - 2024-07-13 14:15 - 027895393 _____ C:\Users\Ripple\Desktop\抖音2024713-486756.mp4
2024-07-12 12:06 - 2024-07-12 12:06 - 000025684 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-07-12 12:05 - 2024-07-12 12:05 - 000025684 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2024-07-12 11:55 - 2024-07-17 15:25 - 000850316 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-07-12 11:53 - 2023-06-16 07:33 - 000161920 _____ (Razer Inc) C:\WINDOWS\system32\RazerS3CoinstallerEx.dll
2024-07-12 11:52 - 2024-07-12 11:52 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2024-07-12 11:51 - 2024-07-17 15:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-07-12 11:51 - 2024-07-12 11:51 - 000003462 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-07-12 11:51 - 2024-07-12 11:51 - 000003398 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-12 11:51 - 2024-07-12 11:51 - 000003238 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-07-12 11:51 - 2024-07-12 11:51 - 000003152 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-12 11:51 - 2024-07-12 11:51 - 000002984 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-12 11:51 - 2024-07-12 11:51 - 000002956 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper_nxt
2024-07-12 11:51 - 2024-07-12 11:51 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-12 11:51 - 2024-07-12 11:51 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-12 11:51 - 2024-07-12 11:51 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-12 11:51 - 2024-07-12 11:51 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-12 11:51 - 2024-07-12 11:51 - 000002914 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-12 11:51 - 2024-07-12 11:51 - 000002744 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-07-12 11:51 - 2024-07-12 11:51 - 000002590 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2024-07-12 11:51 - 2024-07-12 11:51 - 000002160 _____ C:\WINDOWS\system32\Tasks\npcapwatchdog
2024-07-12 11:51 - 2024-07-12 11:51 - 000000020 ___SH C:\Users\Ripple\ntuser.ini
2024-07-12 11:51 - 2024-07-12 11:51 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2024-07-12 11:51 - 2024-07-12 11:51 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2024-07-12 11:50 - 2024-07-12 11:51 - 000011433 _____ C:\WINDOWS\diagwrn.xml
2024-07-12 11:50 - 2024-07-12 11:51 - 000011433 _____ C:\WINDOWS\diagerr.xml
2024-07-12 11:50 - 2024-07-12 11:50 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network
2024-07-12 11:49 - 2024-07-17 12:51 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-07-12 11:49 - 2024-07-17 11:31 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2024-07-12 11:49 - 2024-07-12 12:10 - 000500856 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-07-12 11:49 - 2024-07-12 11:51 - 000000000 ____D C:\Windows.old
2024-07-12 11:39 - 2024-07-12 11:49 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Microsoft\Crypto
2024-07-12 11:39 - 2024-07-12 11:39 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Microsoft\SystemCertificates
2024-07-12 11:39 - 2024-07-12 11:39 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Microsoft\Network
2024-07-12 11:36 - 2024-07-12 11:49 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2024-07-12 11:35 - 2024-07-17 15:01 - 000000000 ____D C:\Users\Ripple
2024-07-12 11:35 - 2024-07-12 11:52 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Microsoft\Windows
2024-07-12 11:35 - 2024-07-12 11:49 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Microsoft\Spelling
2024-07-12 11:34 - 2024-07-12 11:34 - 000000000 ____D C:\WINDOWS\system32\DTS
2024-07-12 11:33 - 2024-07-12 11:35 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2024-07-12 11:31 - 2024-07-12 12:09 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2024-07-12 11:31 - 2024-07-12 11:31 - 000000000 ____D C:\WINDOWS\SysWOW64\DDFs
2024-07-12 11:31 - 2024-07-12 11:31 - 000000000 ____D C:\WINDOWS\system32\Drivers\mde
2024-07-12 11:27 - 2024-07-12 11:27 - 000060462 _____ C:\WINDOWS\SysWOW64\ctac.json
2024-07-12 11:26 - 2024-07-12 11:26 - 000060462 _____ C:\WINDOWS\system32\ctac.json
2024-07-12 11:23 - 2024-07-12 11:23 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2024-07-12 11:23 - 2024-07-12 11:23 - 000000000 ____D C:\Program Files\Reference Assemblies
2024-07-12 11:23 - 2024-07-12 11:23 - 000000000 ____D C:\Program Files\MSBuild
2024-07-12 11:23 - 2024-07-12 11:23 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2024-07-12 11:23 - 2024-07-12 11:23 - 000000000 ____D C:\Program Files (x86)\MSBuild
2024-07-12 11:22 - 2024-07-12 11:31 - 000000000 ____D C:\WINDOWS\SysWOW64\zh-HANS
2024-07-12 11:22 - 2024-07-12 11:31 - 000000000 ____D C:\WINDOWS\system32\zh-HANS
2024-07-12 11:10 - 2024-07-12 11:10 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2024-07-12 10:50 - 2024-07-12 11:51 - 000000000 ___DC C:\WINDOWS\Panther
2024-07-12 10:28 - 2024-07-12 10:38 - 000000000 ____D C:\Users\Ripple\Desktop\AV_block_remover
2024-07-12 10:27 - 2024-07-12 10:27 - 000000535 _____ C:\Users\Ripple\Desktop\rules.txt
2024-07-11 16:12 - 2024-07-11 16:12 - 010485760 _____ C:\Users\Ripple\Desktop\抖音2024711-341350.mp4
2024-07-11 12:14 - 2024-07-11 12:14 - 009763745 _____ C:\Users\Ripple\Desktop\AVbr.zip
2024-07-10 12:09 - 2024-07-17 15:48 - 000000000 ____D C:\Users\Ripple\OutsideOfTime2
2024-07-08 17:20 - 2024-07-08 17:20 - 000000000 ____D C:\Users\Ripple\AppData\Local\AeternoBlade2
2024-07-06 23:28 - 2024-07-06 23:28 - 032304119 _____ C:\Users\Ripple\Desktop\抖音202476-821595.mp4
2024-07-06 22:42 - 2024-07-06 22:42 - 002998270 _____ C:\Users\Ripple\Desktop\抖音202476-343052.mp4
2024-07-06 14:49 - 2024-07-06 14:49 - 003854180 _____ C:\Users\Ripple\Desktop\抖音202476-054518.mp4
2024-07-04 22:51 - 2024-07-04 22:51 - 000000917 _____ C:\Users\Ripple\Desktop\cslol-manager - Shortcut.lnk
2024-07-04 20:57 - 2024-07-12 11:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2024-07-04 20:54 - 2024-07-04 20:54 - 000000000 ____D C:\Users\Ripple\AppData\Local\moonshadow565
2024-07-04 16:47 - 2024-07-04 16:47 - 000000757 _____ C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AutoLogger.lnk
2024-07-03 10:07 - 2024-07-03 10:07 - 000087973 _____ C:\Users\Ripple\Desktop\b9995525a52dc58aecf5.svg
2024-07-02 16:32 - 2024-07-02 16:32 - 000456648 _____ C:\Users\Ripple\Desktop\ZHPDiag.txt
2024-07-02 16:28 - 2024-07-02 16:28 - 000000911 _____ C:\Users\Ripple\Desktop\ZHPSuite.lnk
2024-07-02 16:27 - 2024-07-17 14:59 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\ZHP
2024-07-02 16:27 - 2024-07-17 14:48 - 000000000 ____D C:\Users\Ripple\AppData\Local\ZHP
2024-07-02 16:27 - 2024-07-02 16:27 - 003539144 _____ (Nicolas Coolman) C:\Users\Ripple\Desktop\ZHPSuite.exe
2024-07-02 13:23 - 2024-07-17 16:09 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2024-07-02 13:23 - 2024-07-02 13:31 - 000000000 ____D C:\Users\Ripple\AppData\Local\Malwarebytes
2024-07-02 13:23 - 2024-07-02 13:23 - 000000000 ____D C:\ProgramData\Malwarebytes
2024-07-02 13:22 - 2024-07-02 13:23 - 000000000 ____D C:\Program Files\Malwarebytes
2024-07-02 10:18 - 2024-07-02 10:18 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\NVIDIA
2024-07-01 22:38 - 2024-06-25 14:39 - 000236576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpcf.sys
2024-07-01 22:38 - 2024-06-25 14:39 - 000121872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2024-07-01 22:36 - 2024-06-25 22:11 - 002031464 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2024-07-01 22:36 - 2024-06-25 22:11 - 002031464 _____ C:\WINDOWS\system32\vulkaninfo.exe
2024-07-01 22:36 - 2024-06-25 22:11 - 001578752 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2024-07-01 22:36 - 2024-06-25 22:11 - 001578752 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2024-07-01 22:36 - 2024-06-25 22:11 - 001445120 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2024-07-01 22:36 - 2024-06-25 22:11 - 001445120 _____ C:\WINDOWS\system32\vulkan-1.dll
2024-07-01 22:36 - 2024-06-25 22:11 - 001295104 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2024-07-01 22:36 - 2024-06-25 22:11 - 001295104 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2024-07-01 22:36 - 2024-06-25 22:11 - 000477816 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2024-07-01 22:36 - 2024-06-25 22:11 - 000374392 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2024-07-01 22:36 - 2024-06-25 22:08 - 001068664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2024-07-01 22:36 - 2024-06-25 22:08 - 000670344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
2024-07-01 22:36 - 2024-06-25 22:08 - 000505992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
2024-07-01 22:36 - 2024-06-25 22:07 - 001549320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2024-07-01 22:36 - 2024-06-25 22:07 - 001204744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2024-07-01 22:36 - 2024-06-25 22:07 - 000847880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2024-07-01 22:36 - 2024-06-25 22:06 - 002180728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2024-07-01 22:36 - 2024-06-25 22:06 - 001631368 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2024-07-01 22:36 - 2024-06-25 22:06 - 001033352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2024-07-01 22:36 - 2024-06-25 22:06 - 000795656 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2024-07-01 22:36 - 2024-06-25 22:06 - 000460936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2024-07-01 22:36 - 2024-06-25 22:05 - 016119432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2024-07-01 22:36 - 2024-06-25 22:05 - 013009032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2024-07-01 22:36 - 2024-06-25 22:05 - 006914696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2024-07-01 22:36 - 2024-06-25 22:05 - 005914144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2024-07-01 22:36 - 2024-06-25 22:05 - 005867656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2024-07-01 22:36 - 2024-06-25 22:05 - 003788936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2024-07-01 22:36 - 2024-06-25 22:04 - 000853536 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2024-07-01 22:36 - 2024-06-25 22:03 - 007061880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2024-07-01 22:36 - 2024-06-25 22:03 - 006142632 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2024-07-01 22:36 - 2024-06-25 14:39 - 000123973 _____ C:\WINDOWS\system32\nvinfo.pb
2024-07-01 22:31 - 2024-07-12 11:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2024-07-01 22:31 - 2024-07-02 10:18 - 000000000 ____D C:\Users\Ripple\AppData\Local\NVIDIA
2024-07-01 22:31 - 2024-07-01 22:31 - 131655600 _____ (NVIDIA Corporation) C:\Users\Ripple\Desktop\GeForce_Experience_v3.28.0.417.exe
2024-07-01 22:31 - 2024-07-01 22:31 - 000001447 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2024-07-01 22:31 - 2024-06-12 01:30 - 002900520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2024-07-01 22:31 - 2024-06-12 01:30 - 002231336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2024-07-01 22:31 - 2024-06-12 01:29 - 001296936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvRtmpStreamer64.dll
2024-07-01 22:31 - 2024-03-27 00:56 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2024-07-01 22:31 - 2024-03-27 00:56 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2024-07-01 22:31 - 2024-03-26 23:06 - 000060240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2024-07-01 16:53 - 2024-07-01 16:55 - 000000000 ____D C:\Users\Ripple\Documents\The Riftbreaker
2024-07-01 16:53 - 2024-07-01 16:53 - 000000000 ____D C:\Users\Ripple\AppData\Local\mod.io
2024-07-01 16:53 - 2024-07-01 16:53 - 000000000 ____D C:\Users\Public\mod.io
2024-07-01 10:38 - 2024-07-17 16:35 - 000000000 ____D C:\FRST
2024-07-01 10:37 - 2024-07-17 13:56 - 002395648 _____ (Farbar) C:\Users\Ripple\Desktop\FRST64.exe
2024-06-29 11:25 - 2024-06-29 11:25 - 000000639 _____ C:\Users\Public\Desktop\The Riftbreaker.lnk
2024-06-25 21:42 - 2024-06-25 21:42 - 000000000 ____D C:\Users\Ripple\AppData\Local\MSAR
2024-06-24 15:34 - 2024-07-14 19:00 - 000000000 ____D C:\ProgramData\obs-studio
2024-06-22 17:36 - 2024-06-22 17:41 - 946240506 _____ C:\Users\Ripple\Downloads\Chhorii (2021) 720p 10bit AMZN WEBRip x265 HEVC Hindi AAC 5.1 ESub ~ Immortal.mkv
2024-06-20 20:35 - 2024-06-28 15:01 - 000000000 ____D C:\Program Files\Mozilla Firefox

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2024-07-17 16:30 - 2024-05-01 15:56 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat
2024-07-17 16:30 - 2024-02-11 22:16 - 000000124 _____ C:\ProgramData\autoclickconfig.ini
2024-07-17 16:30 - 2024-01-21 19:25 - 000001301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk
2024-07-17 16:30 - 2023-12-25 11:25 - 000000000 ____D C:\ProgramData\Riot Games
2024-07-17 16:30 - 2023-12-25 11:23 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2024-07-17 16:30 - 2023-12-25 11:23 - 000002413 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2024-07-17 16:30 - 2023-12-25 11:23 - 000002407 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2024-07-17 16:30 - 2023-12-25 11:23 - 000002393 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk
2024-07-17 16:30 - 2023-12-07 17:45 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-07-17 16:30 - 2023-12-06 13:33 - 000002038 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk
2024-07-17 16:30 - 2023-12-06 13:33 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2024-07-17 16:30 - 2023-12-06 06:52 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-07-17 16:24 - 2023-12-16 08:59 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Spotify
2024-07-17 16:19 - 2024-06-03 10:05 - 000000000 ____D C:\Users\Ripple\AppData\Local\Discord
2024-07-17 16:09 - 2024-01-21 19:25 - 000002097 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk
2024-07-17 16:09 - 2023-12-25 11:23 - 000002414 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2024-07-17 16:08 - 2024-02-22 09:44 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\riot-client-ux
2024-07-17 15:47 - 2023-12-16 08:59 - 000000000 ____D C:\Users\Ripple\AppData\Local\Spotify
2024-07-17 15:33 - 2023-12-26 23:17 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Microsoft\Excel
2024-07-17 15:28 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-07-17 15:25 - 2022-05-07 11:07 - 000000000 ____D C:\WINDOWS\INF
2024-07-17 15:20 - 2024-06-03 10:05 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\discord
2024-07-17 15:20 - 2023-12-06 13:33 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-07-17 15:18 - 2023-12-06 06:52 - 000012288 ___SH C:\DumpStack.log.tmp
2024-07-17 15:18 - 2023-12-06 06:52 - 000000000 ____D C:\ProgramData\NVIDIA
2024-07-17 15:18 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\ServiceState
2024-07-17 15:18 - 2022-05-07 11:09 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-07-17 15:17 - 2022-05-07 11:02 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2024-07-17 15:16 - 2022-05-07 11:02 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-07-17 15:00 - 2023-12-08 22:42 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\qBittorrent
2024-07-17 14:30 - 2023-12-06 16:56 - 000000000 ____D C:\Users\Ripple\Downloads\Compressed
2024-07-17 11:40 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-07-17 11:35 - 2023-12-07 10:43 - 000000000 ____D C:\Users\Ripple\AppData\Local\CrashDumps
2024-07-17 11:35 - 2023-12-06 07:02 - 000000000 ____D C:\Temp
2024-07-17 11:35 - 2023-12-06 06:56 - 000000000 ____D C:\Users\Ripple\AppData\Local\Packages
2024-07-17 11:35 - 2023-12-06 06:55 - 000000000 ____D C:\ProgramData\Packages
2024-07-17 11:33 - 2023-12-07 17:45 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-07-17 01:45 - 2024-06-03 10:05 - 000002297 _____ C:\Users\Ripple\Desktop\Discord.lnk
2024-07-17 00:18 - 2023-12-07 23:24 - 000000000 ____D C:\Users\Ripple\Downloads\Telegram Desktop
2024-07-16 20:10 - 2023-12-15 11:19 - 000000000 ____D C:\Users\Ripple\AppData\Local\ElevatedDiagnostics
2024-07-16 16:30 - 2023-12-06 21:13 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\vlc
2024-07-16 10:14 - 2023-12-06 06:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-07-15 20:47 - 2022-05-07 11:09 - 000000000 ___HD C:\Program Files\WindowsApps
2024-07-15 12:22 - 2023-12-06 21:35 - 000000000 ____D C:\Users\Ripple\AppData\Local\PlaceholderTileLogoFolder
2024-07-15 09:34 - 2023-12-06 13:52 - 000000718 _____ C:\Users\Public\Desktop\Speccy.lnk
2024-07-14 19:39 - 2024-02-23 11:33 - 000000000 ___RD C:\Sandbox
2024-07-14 19:03 - 2023-12-10 12:51 - 000000000 ____D C:\Users\Ripple\AppData\Local\D3DSCache
2024-07-13 14:15 - 1986-05-23 21:32 - 000000000 _____ C:\Users\Ripple\Desktop\抖音2024713-486756 (2).mp4
2024-07-12 22:17 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\appcompat
2024-07-12 12:26 - 2022-05-07 11:09 - 000000000 ____D C:\ProgramData\USOPrivate
2024-07-12 12:11 - 2024-06-11 12:09 - 000000000 ____D C:\Program Files (x86)\Razer
2024-07-12 12:09 - 2022-05-07 13:24 - 000000000 ____D C:\WINDOWS\InboxApps
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\UUS
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SystemResources
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\ShellComponents
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\Provisioning
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2024-07-12 12:09 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-07-12 12:07 - 2022-05-07 11:09 - 000000000 ___RD C:\WINDOWS\PrintDialog
2024-07-12 12:05 - 2023-12-25 11:20 - 000000000 ____D C:\Program Files\Microsoft Office
2024-07-12 11:51 - 2023-12-06 06:56 - 000000000 __RHD C:\Users\Public\AccountPictures
2024-07-12 11:51 - 2022-05-07 11:09 - 000000000 ____D C:\Program Files\Windows Defender
2024-07-12 11:50 - 2023-12-06 06:52 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-07-12 11:50 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\Media
2024-07-12 11:49 - 2024-05-24 18:37 - 000000000 ____D C:\WINDOWS\SysWOW64\Npcap
2024-07-12 11:49 - 2024-05-24 18:37 - 000000000 ____D C:\WINDOWS\system32\Npcap
2024-07-12 11:49 - 2024-03-22 22:14 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Stremio
2024-07-12 11:49 - 2024-01-28 17:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2024-07-12 11:49 - 2024-01-21 19:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks X
2024-07-12 11:49 - 2023-12-25 11:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2024-07-12 11:49 - 2023-12-13 11:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2024-07-12 11:49 - 2023-12-12 19:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MetaTrader 4 EXNESS
2024-07-12 11:49 - 2023-12-07 19:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3RVX
2024-07-12 11:49 - 2023-12-06 14:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
2024-07-12 11:49 - 2023-12-06 14:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\FANTECH X4S MACRO Gaming Mouse
2024-07-12 11:49 - 2023-12-06 07:02 - 000000000 ____D C:\Program Files\Intel
2024-07-12 11:49 - 2023-12-06 06:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2024-07-12 11:49 - 2023-12-05 15:25 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-07-12 11:49 - 2022-05-07 11:09 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2024-07-12 11:49 - 2022-05-07 11:09 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2024-07-12 11:49 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2024-07-12 11:49 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2024-07-12 11:49 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\spool
2024-07-12 11:49 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2024-07-12 11:49 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2024-07-12 11:49 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2024-07-12 11:49 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2024-07-12 11:49 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2024-07-12 11:49 - 2022-05-07 11:09 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2024-07-12 11:44 - 2022-05-07 11:13 - 000000000 ____D C:\WINDOWS\Setup
2024-07-12 11:36 - 2024-02-20 18:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteelSeries
2024-07-12 11:36 - 2023-12-12 14:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2024-07-12 11:36 - 2023-12-05 15:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geeks3D
2024-07-12 11:31 - 2022-05-07 13:24 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2024-07-12 11:31 - 2022-05-07 13:24 - 000000000 ___SD C:\WINDOWS\system32\AppV
2024-07-12 11:31 - 2022-05-07 13:24 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ___SD C:\WINDOWS\system32\UNP
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ___SD C:\WINDOWS\system32\F12
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\WUModels
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SystemApps
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\setup
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\id-ID
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\et-EE
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\es-MX
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\DDFs
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\appraiser
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\Globalization
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\DiagTrack
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\BrowserCore
2024-07-12 11:31 - 2022-05-07 11:09 - 000000000 ____D C:\Program Files\Common Files\System
2024-07-12 11:31 - 2022-05-07 11:02 - 000000000 ____D C:\WINDOWS\servicing
2024-07-12 11:30 - 2022-05-07 13:24 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2024-07-12 11:30 - 2022-05-07 13:24 - 000024383 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2024-07-12 11:30 - 2022-05-07 11:10 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2024-07-12 11:30 - 2022-05-07 11:09 - 000249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2024-07-12 11:24 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\OCR
2024-07-12 11:23 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2024-07-12 11:23 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\MUI
2024-07-12 11:22 - 2022-05-07 13:24 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2024-07-12 11:22 - 2022-05-07 13:24 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2024-07-12 11:22 - 2022-05-07 13:15 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2024-07-12 11:22 - 2022-05-07 13:15 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2024-07-12 11:22 - 2022-05-07 13:15 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2024-07-12 11:22 - 2022-05-07 13:15 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2024-07-12 11:22 - 2022-05-07 13:15 - 000000000 ____D C:\WINDOWS\system32\winrm
2024-07-12 11:22 - 2022-05-07 13:15 - 000000000 ____D C:\WINDOWS\system32\WCN
2024-07-12 11:22 - 2022-05-07 13:15 - 000000000 ____D C:\WINDOWS\system32\slmgr
2024-07-12 11:22 - 2022-05-07 13:15 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2024-07-12 11:22 - 2022-05-07 11:09 - 000000000 ___SD C:\WINDOWS\system32\dsc
2024-07-12 11:22 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2024-07-12 11:22 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2024-07-12 11:22 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\system32\Com
2024-07-12 11:22 - 2022-05-07 11:09 - 000000000 ____D C:\WINDOWS\IME
2024-07-12 11:22 - 2022-05-07 11:09 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2024-07-12 10:45 - 2023-12-05 15:25 - 194135240 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-07-11 11:58 - 2024-06-11 12:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2024-07-11 11:58 - 2024-06-11 12:08 - 000000000 ____D C:\ProgramData\Razer
2024-07-10 17:55 - 2024-03-22 10:23 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\Anki2
2024-07-09 18:25 - 2024-06-15 11:00 - 000000000 ____D C:\Users\Ripple\OutsideOfTime
2024-07-08 17:20 - 2024-06-05 18:49 - 000000000 ____D C:\Users\Ripple\Documents\Player
2024-07-08 01:52 - 2024-02-20 18:33 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\steelseries-gg-client
2024-07-06 12:28 - 2024-01-15 18:10 - 000000000 ____D C:\Users\Ripple\AppData\Local\UnrealEngine
2024-07-05 12:49 - 2024-03-08 15:32 - 000001290 _____ C:\Users\Ripple\Desktop\loan.txt
2024-07-03 10:29 - 2023-12-25 11:43 - 000000000 ____D C:\KVRT2020_Data
2024-07-03 10:14 - 2023-12-06 16:38 - 000002182 _____ C:\Users\Ripple\Desktop\mod-2-.txt
2024-07-02 10:41 - 2024-03-02 11:10 - 000000000 ____D C:\Users\Ripple\AppData\LocalLow\Temp
2024-07-01 22:44 - 2023-12-25 11:23 - 000002401 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2024-07-01 22:38 - 2023-12-06 06:52 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2024-07-01 22:33 - 2023-12-06 07:01 - 000000000 ____D C:\Users\Ripple\AppData\Local\NVIDIA Corporation
2024-07-01 22:31 - 2023-12-06 07:00 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2024-07-01 22:31 - 2023-12-06 06:59 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2024-06-30 09:56 - 2024-05-01 15:55 - 000000000 ____D C:\Program Files\Riot Vanguard
2024-06-28 15:01 - 2023-12-06 13:33 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2024-06-26 15:21 - 2023-12-06 13:45 - 000000000 ____D C:\Users\Ripple\AppData\Roaming\AnyDesk
2024-06-19 22:38 - 2024-01-28 17:13 - 000000000 ____D C:\Users\Ripple\AppData\Local\Steam

==================== Files in the root of some directories ========

2024-07-14 19:02 - 2024-07-17 15:40 - 000000016 _____ () C:\Users\Ripple\AppData\Roaming\obs-virtualcam.txt

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Addition
Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16.07.2024
Ran by Max (17-07-2024 16:36:40)
Running from C:\Users\Ripple\Desktop
Microsoft Windows 11 Pro Version 23H2 22631.3880 (X64) (2024-07-12 06:06:13)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-2515384590-1499498081-2273501178-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2515384590-1499498081-2273501178-503 - Limited - Disabled)
Guest (S-1-5-21-2515384590-1499498081-2273501178-501 - Limited - Disabled)
Max (S-1-5-21-2515384590-1499498081-2273501178-1001 - Administrator - Enabled) => C:\Users\Ripple
WDAGUtilityAccount (S-1-5-21-2515384590-1499498081-2273501178-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Malwarebytes (Disabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3RVX (HKLM-x32\...\{400A8514-5440-410A-B318-44061BD7EE8E}) (Version: 2.9.2.0 - Matthew Malensek)
7-Zip 22.01 (x64) (HKLM\...\7-Zip) (Version: 22.01 - Igor Pavlov)
AeternoBlade II: Infinity (HKLM-x32\...\AeternoBlade II: Infinity_is1) (Version:  - )
Anki (HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Anki) (Version: 23.12.1 - )
AutoHotkey (user) (HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\AutoHotkey) (Version: 2.0.10 - AutoHotkey Foundation LLC)
BlueStacks App Player (HKLM\...\BlueStacks_nxt) (Version: 5.20.10.1003 - now.gg, Inc.)
BlueStacks Services (HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\BlueStacksServices) (Version: 3.0.8 - now.gg, Inc.)
BlueStacks X (HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\BlueStacks X) (Version: 10.10.1.1001 - now.gg, Inc.)
Dynamic Application Loader Host Interface Service (HKLM\...\{3FD9F3E6-059D-4E4D-8B5B-EBAE90CA882E}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Everything 1.4.1.1024 (x64) (HKLM\...\Everything) (Version: 1.4.1.1024 - voidtools)
FANTECH X4S MACRO Gaming Mouse (HKLM-x32\...\{7587581E-9DAD-412D-9AA4-8541FCBCCAF6}) (Version: 1.00.0000 - FANTECH)
FIFA 16 (HKLM-x32\...\FIFA 16_is1) (Version:  - )
Geeks3D FurMark 1.36.0.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: 1.36.0.0 - Geeks3D)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 126.0.6478.128 - Google LLC)
Intel(R) Chipset Device Software (HKLM\...\{BB1E910B-7D2D-4FC8-A87C-5A53CAC2D5A8}) (Version: 10.1.19159.8331 - Intel Corporation) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{a8ed3a4b-8ec2-4b7d-b0f6-0f4db00ea2ce}) (Version: 10.1.19159.8331 - Intel(R) Corporation)
Intel(R) LMS (HKLM\...\{B76FE067-1B6B-416E-9A99-C1BF5E9A2FC1}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2149.16.0.2602 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{3EE91568-6FE3-43AA-9BFC-7496A56D272C}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Driver (HKLM\...\{E4924222-0A39-4EEE-8F7E-8C95BDFDCFCE}) (Version: 1.0.0.0 - Intel Corporation) Hidden
League of Legends (HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Riot Game league_of_legends.live) (Version:  - Riot Games, Inc)
Malwarebytes version 5.1.6.117 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.1.6.117 - Malwarebytes)
MetaTrader 4 EXNESS (HKLM-x32\...\MetaTrader 4 EXNESS) (Version: 4.00 - MetaQuotes Ltd.)
Microsoft .NET Host - 6.0.25 (x64) (HKLM\...\{C7141A99-592B-4226-A4E9-B767C1D0FBAF}) (Version: 48.100.4028 - Microsoft Corporation) Hidden
Microsoft .NET Host - 7.0.7 (x64) (HKLM\...\{E914E975-A0B1-49F7-AB71-28DACD495C44}) (Version: 56.31.61636 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.25 (x64) (HKLM\...\{AE86D888-1404-47CC-A7BB-8D86C0503E58}) (Version: 48.100.4028 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 7.0.7 (x64) (HKLM\...\{62A9DE14-DB7A-41D9-9D7E-ED494E6FCBAF}) (Version: 56.31.61636 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.25 (x64) (HKLM\...\{3544B2EE-E62F-4D11-B79C-3DDEACE94DA5}) (Version: 48.100.4028 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 7.0.7 (x64) (HKLM\...\{ECCA3DB0-6DEF-42CD-A21A-F2F7B918FB59}) (Version: 56.31.61636 - Microsoft Corporation) Hidden
Microsoft ASP.NET Core 7.0.7 - Shared Framework (x64) (HKLM-x32\...\{4a749a1a-b799-41b4-a328-33a7b2355e76}) (Version: 7.0.7.23274 - Microsoft Corporation)
Microsoft ASP.NET Core 7.0.7 Shared Framework (x64) (HKLM\...\{5ECA54B7-62F2-39EE-9514-31F7DFFFC968}) (Version: 7.0.7.23274 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 126.0.2592.102 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 126.0.2592.102 - Microsoft Corporation)
Microsoft Office Professional Plus 2021 - en-us (HKLM\...\ProPlus2021Retail - en-us) (Version: 16.0.17726.20160 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33810 (HKLM-x32\...\{5af95fd8-a22e-458f-acee-c61bd787178e}) (Version: 14.40.33810.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810 (HKLM-x32\...\{47109d57-d746-4f8b-9618-ed6a17cc922b}) (Version: 14.40.33810.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.40.33810 (HKLM\...\{59CED48F-EBFE-480C-8A38-FC079C2BEC0F}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.40.33810 (HKLM\...\{B8B3BB4A-A10D-4F51-91B7-A64FFAC31EA7}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.40.33810 (HKLM-x32\...\{5EA6C998-D5AC-4ED9-89C3-9F25B17CCD3D}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.40.33810 (HKLM-x32\...\{0C3457A0-3DCE-4A33-BEF0-9B528C557771}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.25 (x64) (HKLM\...\{E016F2B9-01FE-4FAA-882E-ECC43FA49751}) (Version: 48.100.4037 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.25 (x64) (HKLM-x32\...\{fb0500c1-f968-4621-a48b-985b52884c49}) (Version: 6.0.25.33020 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 7.0.7 (x64) (HKLM\...\{593F16DC-C2D3-4740-ABD4-A171B4E32B06}) (Version: 56.31.61651 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.7 (x64) (HKLM-x32\...\{e875fc20-9a37-4344-b046-0bb037cb2d57}) (Version: 7.0.7.32525 - Microsoft Corporation)
Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 127.0.2 (x64 en-US)) (Version: 127.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 120.0.1 - Mozilla)
Npcap (HKLM-x32\...\NpcapInst) (Version: 1.78 - Nmap Project)
NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.28.0.417 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.28.0.417 - NVIDIA Corporation)
NVIDIA Graphics Driver 556.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 556.12 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.4.0.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.0.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 30.2.0 - OBS Project)
obs-backgroundremoval version 1.1.13 (HKLM-x32\...\{1527c9ec-2638-4e3b-94d7-cc25d27cd725}_is1) (Version: 1.1.13 - Roy Shilkrot)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.17628.20110 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.17726.20108 - Microsoft Corporation) Hidden
OmegaT version 6.0.0 (HKLM\...\org.omegat_is1) (Version: 6.0.0 - OmegaT)
PreMiD (HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\PreMiD latest) (Version: latest - Timeraa)
Prince of Persia: The Lost Crown (HKLM-x32\...\Prince of Persia: The Lost Crown_is1) (Version:  - )
qBittorrent (HKLM-x32\...\qBittorrent) (Version: 4.6.5 - The qBittorrent project)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9289.1 - Realtek Semiconductor Corp.)
Riot Client  (HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Riot Game Riot_Client.) (Version:  - Riot Games, Inc)
Riot Vanguard (HKLM\...\Riot Vanguard) (Version:  - Riot Games, Inc.)
Speccy (HKLM\...\Speccy) (Version: 1.33 - Piriform)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SteelSeries GG 66.0.0 (HKLM\...\SteelSeries GG) (Version: 66.0.0 - SteelSeries ApS)
Stremio (HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Stremio) (Version: 4.4.165 - Smart Code Ltd)
Svarog's Dream (HKLM-x32\...\Svarog's Dream_is1) (Version:  - )
Telegram Desktop (HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 5.2.3 - Telegram FZ-LLC)
The Riftbreaker (HKLM-x32\...\The Riftbreaker_is1) (Version:  - )
VALORANT (HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\Riot Game valorant.live) (Version:  - Riot Games, Inc)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Warm Snow (HKLM-x32\...\Warm Snow_is1) (Version:  - )
Wireshark 4.2.5 x64 (HKLM-x32\...\Wireshark) (Version: 4.2.5 - The Wireshark developer community, hxxps://www.wireshark.org)

Packages:
=========

AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5536.0_x64__8j3eq9eme6ctt [2024-06-16] (INTEL CORP) [Startup Task]
MicrosoftWindows.CrossDevice -> C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.24061.40.0_x64__cw5n1h2txyewy [2024-07-14] (Microsoft Windows) [Startup Task]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_7.0.8.0_neutral__mcm4njqhnhss8 [2024-07-15] (Netflix, Inc.)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.966.0_x64__56jybvy8sckqj [2024-07-01] (NVIDIA Corp.)
Photos -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2024.11070.3017.0_x64__8wekyb3d8bbwe [2024-07-12] (Microsoft Corporation) [Startup Task]
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.40.287.0_x64__dt26b99r8h8gj [2023-12-07] (Realtek Semiconductor Corp)
Sound Blaster Cinema 6+ -> C:\Program Files\WindowsApps\CreativeTechnologyLtd.52058C5BB174B_1.0.9.0_x86__13fcda18mhdz2 [2023-12-07] (Creative Technology Ltd.)
WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.178.1908.0_x64__8wekyb3d8bbwe [2024-07-11] (Microsoft Corp.)
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_5001.178.1908.0_x64__8wekyb3d8bbwe [2024-07-11] (Microsoft Corp.)
Windows Feature Experience Pack -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.LKG_cw5n1h2txyewy [2024-07-12] (Microsoft Windows)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => d:\Program Files\7-Zip\7-zip.dll [2022-07-15] (Igor Pavlov) [File not signed]
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-07-02] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => d:\Program Files\7-Zip\7-zip.dll [2022-07-15] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvtfi.inf_amd64_4cd94d3ab4900da6\nvshext.dll [2024-06-25] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => d:\Program Files\7-Zip\7-zip.dll [2022-07-15] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2024-07-02] (Malwarebytes Inc. -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Public\Desktop\Prince of Persia - The Lost Crown.lnk -> D:\games\Prince of Persia - The Lost Crown\Ryujinx.bat ()

==================== Loaded Modules (Whitelisted) =============

2024-07-15 18:42 - 2021-02-21 06:18 - 002823680 _____ () [File not signed] C:\Users\Ripple\AppData\Roaming\PreMiD\ffmpeg.dll
2024-07-15 18:42 - 2021-02-21 06:18 - 000449024 _____ () [File not signed] C:\Users\Ripple\AppData\Roaming\PreMiD\libegl.dll
2024-07-15 18:42 - 2021-02-21 06:18 - 007620096 _____ () [File not signed] C:\Users\Ripple\AppData\Roaming\PreMiD\libglesv2.dll
2024-02-06 10:26 - 2024-02-06 10:26 - 002525184 _____ () [File not signed] D:\Riot Games\Riot Client\RiotClientElectron\ffmpeg.dll
2024-02-06 10:26 - 2024-02-06 10:26 - 000384000 _____ () [File not signed] D:\Riot Games\Riot Client\RiotClientElectron\libegl.dll
2024-02-06 10:26 - 2024-02-06 10:26 - 006728704 _____ () [File not signed] D:\Riot Games\Riot Client\RiotClientElectron\libglesv2.dll
2024-02-06 10:26 - 2024-02-06 10:26 - 004486656 _____ () [File not signed] D:\Riot Games\Riot Client\RiotClientElectron\vk_swiftshader.dll
2024-02-06 10:26 - 2024-02-06 10:26 - 000793088 _____ () [File not signed] D:\Riot Games\Riot Client\RiotClientElectron\vulkan-1.dll
2024-07-17 15:48 - 2024-07-17 15:48 - 000457216 _____ (hxxp://hunspell.sourceforge.net/) [File not signed] C:\Users\Ripple\AppData\Local\Temp\jna8232274705723621799.hunspell-win-x86-64.dll
2023-12-13 11:23 - 2022-07-15 19:45 - 000094720 _____ (Igor Pavlov) [File not signed] d:\Program Files\7-Zip\7-zip.dll
2024-07-17 15:48 - 2024-07-17 15:48 - 000246784 ____N (Java(TM) Native Access (JNA)) [File not signed] C:\Users\Ripple\AppData\Local\Temp\jna-77124\jna2032668114730611574.dll
2023-12-25 11:23 - 2023-12-25 11:23 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\Root\Office16\AppVIsvSubsystems64.dll
2023-12-25 11:23 - 2023-12-25 11:23 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\Root\Office16\c2r64.dll
2024-07-14 19:30 - 2024-03-21 16:13 - 020066304 _____ (Roy Shilkrot) [File not signed] D:\Program Files\obs-studio\obs-plugins\64bit\obs-backgroundremoval.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\autoclickconfig.ini:07021500A6 [5162]
AlternateDataStreams: C:\ProgramData\empty.ico:8C1C1B484F [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk:A1B76439FE [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk:088221F38A [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk:FE00AE19CB [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:41964AA945 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk:B96E9B8455 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk:C5112377E0 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk:980850BA8A [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk:8096E45125 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk:C5D586BE93 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk:E77773B271 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk:60EC9648C0 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk:5465085A2F [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk:1DC1525F34 [5162]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2024-04-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-06-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-06-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-06-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-06-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-06-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-06-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-06-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-06-29] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2022-05-07 11:09 - 2024-07-17 15:17 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1       localhost

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Ripple\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.101.1 - 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)
Bluetooth Network Connection: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)
Wi-Fi: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled)

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\StartupApproved\StartupFolder: => "Rainmeter.lnk"
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\StartupApproved\StartupFolder: => "FANTECH X4S MACRO Gaming Mouse.lnk"
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\StartupApproved\Run: => "electron.app.BlueStacks Services"
HKU\S-1-5-21-2515384590-1499498081-2273501178-1001\...\StartupApproved\Run: => "Synapse3"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{B1388D79-300F-4315-844B-292919CD30DF}] => (Allow) D:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{B5DCB7E9-21B7-4C4C-8B0A-B2EF766F3C6B}] => (Allow) D:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]
FirewallRules: [{6CA7F345-FF05-43B2-BF10-5831B4520D0E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{4022EE6D-0B77-4513-9DD9-25C9D056050C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{56ADD3A6-37EC-4D2A-A243-BABD2D169818}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{51AC4C50-176A-41D8-BCAB-B15040C509C3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{B347B7AB-BEB9-43E4-9941-792DF19EADB9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{325DD4ED-6F9D-493C-AE17-A055E11A4FEF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{169EEA74-BED1-474A-BB2F-E063CDDFC2D5}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BA1231DA-1D80-4035-AD45-0EB6E6A55494}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Goose Goose Duck\GGDLauncher.exe (EasyAntiCheat Oy -> Epic Games, Inc.)
FirewallRules: [{97C3EA04-81DD-49F7-8A13-D2A519798908}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Goose Goose Duck\GGDLauncher.exe (EasyAntiCheat Oy -> Epic Games, Inc.)
FirewallRules: [UDP Query User{CC23B56B-2A83-4768-BBD9-D55BD4419C29}C:\users\ripple\downloads\programs\anydesk.exe] => (Allow) C:\users\ripple\downloads\programs\anydesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [TCP Query User{C91DBFE7-9784-4424-ABCA-4D8EB36FD3D2}C:\users\ripple\downloads\programs\anydesk.exe] => (Allow) C:\users\ripple\downloads\programs\anydesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [UDP Query User{28AE1875-1272-41B1-8FCD-1F12EAB8F7D6}E:\program files (x86)\spotify portable\app\spotify\spotify.exe] => (Allow) E:\program files (x86)\spotify portable\app\spotify\spotify.exe (Spotify Ltd) [File not signed]
FirewallRules: [TCP Query User{5BC17E74-AD75-401E-A0CB-17114F9A0451}E:\program files (x86)\spotify portable\app\spotify\spotify.exe] => (Allow) E:\program files (x86)\spotify portable\app\spotify\spotify.exe (Spotify Ltd) [File not signed]
FirewallRules: [UDP Query User{704AB798-101F-4BB7-9AC6-BDDB84C6E0F5}C:\users\ripple\appdata\local\programs\lnv\stremio-4\stremio-runtime.exe] => (Allow) C:\users\ripple\appdata\local\programs\lnv\stremio-4\stremio-runtime.exe (Smart Code OOD -> Node.js)
FirewallRules: [TCP Query User{2E9572A8-2A0C-4021-8B40-9485725D49BD}C:\users\ripple\appdata\local\programs\lnv\stremio-4\stremio-runtime.exe] => (Allow) C:\users\ripple\appdata\local\programs\lnv\stremio-4\stremio-runtime.exe (Smart Code OOD -> Node.js)
FirewallRules: [UDP Query User{604854D9-3687-459C-833F-8739A8FFAC66}D:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) D:\riot games\riot client\riotclientelectron\riot client.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [TCP Query User{777C2B56-FB3A-44FB-BEFC-D6867A6998D1}D:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) D:\riot games\riot client\riotclientelectron\riot client.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{3C2F7EB2-1A4A-4908-A9BA-2D3344892EB5}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{8B97F87C-A5F5-4FAE-88F4-473E46FB5C55}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{87615D40-2B9D-42A4-B248-805C0F323734}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{4B31C6B9-8EEC-4DCB-900B-EC1CB842431B}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{8E0FB278-2C49-41C2-A298-22FC33EDAF2A}] => (Allow) C:\Program Files\BlueStacks_nxt\BlueStacksAppplayerWeb.exe (Now.gg, INC -> The Qt Company Ltd.)
FirewallRules: [{20B9EC59-31AF-4CDF-B390-DE54030493B1}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe (Now.gg, INC -> BlueStack Systems)
FirewallRules: [{6B2E1BAF-0CF0-433D-B5E9-9B17F30E338E}] => (Allow) D:\bluestacks\BlueStacks X\Cloud Game.exe (Now.gg, INC -> COMPANY NAME)
FirewallRules: [{B50707B5-D9BD-4AB6-950A-C793EF7372D0}] => (Allow) D:\bluestacks\BlueStacks X\BlueStacksWeb.exe (Now.gg, INC -> Bluestack Systems, Inc.)
FirewallRules: [UDP Query User{1E2F09D9-E731-46F2-A39B-354DDD55DDAA}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{278B6E8B-AF7F-401E-B30D-F09BBC36F812}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{232F6D0B-CFC4-4ACC-8C86-EA6A1B930100}D:\riot games\riot client\riotclientservices.exe] => (Allow) D:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [TCP Query User{78993BF2-4E28-48BA-AC5E-D73EDF569880}D:\riot games\riot client\riotclientservices.exe] => (Allow) D:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [UDP Query User{02530C5B-5B1B-4446-9DC0-F3A969751CCD}D:\games\warm snow\warmsnow.exe] => (Allow) D:\games\warm snow\warmsnow.exe () [File not signed]
FirewallRules: [TCP Query User{C1E7C675-4134-4C24-99DB-9FAC4106CB41}D:\games\warm snow\warmsnow.exe] => (Allow) D:\games\warm snow\warmsnow.exe () [File not signed]
FirewallRules: [UDP Query User{1C85AB8F-22E8-44AF-95F9-47D53B4C3BF0}D:\software\anydesk.exe] => (Allow) D:\software\anydesk.exe (philandro Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [TCP Query User{5FF45AEE-EA35-4940-BA99-745F9C4EA5BB}D:\software\anydesk.exe] => (Allow) D:\software\anydesk.exe (philandro Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [UDP Query User{08BE5B52-AEA9-4C4C-ADF3-433CF487F3FC}C:\users\ripple\downloads\anydesk.exe] => (Allow) C:\users\ripple\downloads\anydesk.exe (philandro Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [TCP Query User{81CB5DC2-4EBF-416E-84AB-EFC2F29DC677}C:\users\ripple\downloads\anydesk.exe] => (Allow) C:\users\ripple\downloads\anydesk.exe (philandro Software GmbH -> AnyDesk Software GmbH)
FirewallRules: [{EF12C5DC-DD87-4E89-ABC5-329ED525DC23}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{B79EE3E6-201C-4024-BFD4-B731AAF98003}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{E844D0A2-98DE-4486-973D-41A6E6F744AE}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.102\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{A4B2A573-0A52-4E1F-AB08-F28B434A0EC9}C:\users\ripple\appdata\roaming\premid\premid.exe] => (Allow) C:\users\ripple\appdata\roaming\premid\premid.exe (GitHub, Inc.) [File not signed]
FirewallRules: [UDP Query User{732A3963-A223-4269-8378-307E396E62A2}C:\users\ripple\appdata\roaming\premid\premid.exe] => (Allow) C:\users\ripple\appdata\roaming\premid\premid.exe (GitHub, Inc.) [File not signed]
FirewallRules: [{8956EEBE-7CAE-483C-9727-DCE3E380914E}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

15-07-2024 12:22:46 Windows Update
17-07-2024 14:57:47 ZHPcleaner
17-07-2024 15:14:03 Restore Point Created by FRST

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (07/17/2024 03:18:27 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: SteelSeriesSonar.exe
CoreCLR Version: 6.0.1222.56807
.NET Version: 6.0.12
Description: The process was terminated due to an unhandled exception.
Exception Info: System.Runtime.InteropServices.COMException (0x80040154): Retrieving the COM class factory for component with CLSID {DEA05346-7BE3-4DB0-AE9F-14423648EA7B} failed due to the following error: 80040154 Class not registered (0x80040154 (REGDB_E_CLASSNOTREG)).
   at SoundStage.Interop.Services.Services.BasicControl.ControlInteropService..ctor(ILogger logger)
   at System.RuntimeMethodHandle.InvokeMethod(Object target, Span`1& arguments, Signature sig, Boolean constructor, Boolean wrapExceptions)
   at System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.Resolve(ServiceCallSite callSite, ServiceProviderEngineScope scope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.CreateServiceAccessor(ServiceIdentifier serviceIdentifier)
   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(ServiceIdentifier serviceIdentifier, ServiceProviderEngineScope serviceProviderEngineScope)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.ServiceProviderEngineScope.GetService(Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.ConstructorInfoEx.GetService(IServiceProvider serviceProvider, Int32 parameterIndex)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.ConstructorMatcher.CreateInstance(IServiceProvider provider)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.CreateInstance(IServiceProvider provider, Type instanceType, Object[] parameters)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.CreateInstance[T](IServiceProvider provider, Object[] parameters)
   at SoundStage.IoC.Extensions.IServiceCollectionExtensions.<>c__DisplayClass2_0`2.<AddSingletonFromActivator>b__0(IServiceProvider provider)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitFactory(FactoryCallSite factoryCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitIEnumerable(IEnumerableCallSite enumerableCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.Resolve(ServiceCallSite callSite, ServiceProviderEngineScope scope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.CreateServiceAccessor(ServiceIdentifier serviceIdentifier)
   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(ServiceIdentifier serviceIdentifier, ServiceProviderEngineScope serviceProviderEngineScope)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.ServiceProviderEngineScope.GetService(Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ServiceProviderServiceExtensions.GetRequiredService(IServiceProvider provider, Type serviceType)
   at SoundStage.IoC.Extensions.IServiceCollectionExtensions.<>c__DisplayClass1_1.<AddSonarByConventions>b__13(IServiceProvider provider)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitFactory(FactoryCallSite factoryCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.Resolve(ServiceCallSite callSite, ServiceProviderEngineScope scope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.CreateServiceAccessor(ServiceIdentifier serviceIdentifier)
   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(ServiceIdentifier serviceIdentifier, ServiceProviderEngineScope serviceProviderEngineScope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ServiceProviderServiceExtensions.GetRequiredService(IServiceProvider provider, Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ServiceProviderServiceExtensions.GetRequiredService[T](IServiceProvider provider)
   at Program.<>c__DisplayClass0_0.<<Main>$>g__RegisterVolumeService|47(IShutdownStackService shutdownService)
   at Program.<>c__DisplayClass0_0.<<Main>$>b__11()
   at Program.<Main>$(String[] args)

Error: (07/17/2024 03:18:26 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: SteelSeriesSonar.exe
CoreCLR Version: 6.0.1222.56807
.NET Version: 6.0.12
Description: The process was terminated due to an unhandled exception.
Exception Info: System.Runtime.InteropServices.COMException (0x80040154): Retrieving the COM class factory for component with CLSID {DEA05346-7BE3-4DB0-AE9F-14423648EA7B} failed due to the following error: 80040154 Class not registered (0x80040154 (REGDB_E_CLASSNOTREG)).
   at SoundStage.Interop.Services.Services.BasicControl.ControlInteropService..ctor(ILogger logger)
   at System.RuntimeMethodHandle.InvokeMethod(Object target, Span`1& arguments, Signature sig, Boolean constructor, Boolean wrapExceptions)
   at System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.Resolve(ServiceCallSite callSite, ServiceProviderEngineScope scope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.CreateServiceAccessor(ServiceIdentifier serviceIdentifier)
   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(ServiceIdentifier serviceIdentifier, ServiceProviderEngineScope serviceProviderEngineScope)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.ServiceProviderEngineScope.GetService(Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.ConstructorInfoEx.GetService(IServiceProvider serviceProvider, Int32 parameterIndex)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.ConstructorMatcher.CreateInstance(IServiceProvider provider)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.CreateInstance(IServiceProvider provider, Type instanceType, Object[] parameters)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.CreateInstance[T](IServiceProvider provider, Object[] parameters)
   at SoundStage.IoC.Extensions.IServiceCollectionExtensions.<>c__DisplayClass2_0`2.<AddSingletonFromActivator>b__0(IServiceProvider provider)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitFactory(FactoryCallSite factoryCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitIEnumerable(IEnumerableCallSite enumerableCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.Resolve(ServiceCallSite callSite, ServiceProviderEngineScope scope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.CreateServiceAccessor(ServiceIdentifier serviceIdentifier)
   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(ServiceIdentifier serviceIdentifier, ServiceProviderEngineScope serviceProviderEngineScope)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.ServiceProviderEngineScope.GetService(Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ServiceProviderServiceExtensions.GetRequiredService(IServiceProvider provider, Type serviceType)
   at SoundStage.IoC.Extensions.IServiceCollectionExtensions.<>c__DisplayClass1_1.<AddSonarByConventions>b__13(IServiceProvider provider)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitFactory(FactoryCallSite factoryCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.Resolve(ServiceCallSite callSite, ServiceProviderEngineScope scope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.CreateServiceAccessor(ServiceIdentifier serviceIdentifier)
   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(ServiceIdentifier serviceIdentifier, ServiceProviderEngineScope serviceProviderEngineScope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ServiceProviderServiceExtensions.GetRequiredService(IServiceProvider provider, Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ServiceProviderServiceExtensions.GetRequiredService[T](IServiceProvider provider)
   at Program.<>c__DisplayClass0_0.<<Main>$>g__RegisterVolumeService|47(IShutdownStackService shutdownService)
   at Program.<>c__DisplayClass0_0.<<Main>$>b__11()
   at Program.<Main>$(String[] args)

Error: (07/17/2024 03:18:23 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: SteelSeriesSonar.exe
CoreCLR Version: 6.0.1222.56807
.NET Version: 6.0.12
Description: The process was terminated due to an unhandled exception.
Exception Info: System.Runtime.InteropServices.COMException (0x80040154): Retrieving the COM class factory for component with CLSID {DEA05346-7BE3-4DB0-AE9F-14423648EA7B} failed due to the following error: 80040154 Class not registered (0x80040154 (REGDB_E_CLASSNOTREG)).
   at SoundStage.Interop.Services.Services.BasicControl.ControlInteropService..ctor(ILogger logger)
   at System.RuntimeMethodHandle.InvokeMethod(Object target, Span`1& arguments, Signature sig, Boolean constructor, Boolean wrapExceptions)
   at System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.Resolve(ServiceCallSite callSite, ServiceProviderEngineScope scope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.CreateServiceAccessor(ServiceIdentifier serviceIdentifier)
   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(ServiceIdentifier serviceIdentifier, ServiceProviderEngineScope serviceProviderEngineScope)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.ServiceProviderEngineScope.GetService(Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.ConstructorInfoEx.GetService(IServiceProvider serviceProvider, Int32 parameterIndex)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.ConstructorMatcher.CreateInstance(IServiceProvider provider)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.CreateInstance(IServiceProvider provider, Type instanceType, Object[] parameters)
   at Microsoft.Extensions.DependencyInjection.ActivatorUtilities.CreateInstance[T](IServiceProvider provider, Object[] parameters)
   at SoundStage.IoC.Extensions.IServiceCollectionExtensions.<>c__DisplayClass2_0`2.<AddSingletonFromActivator>b__0(IServiceProvider provider)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitFactory(FactoryCallSite factoryCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitIEnumerable(IEnumerableCallSite enumerableCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.Resolve(ServiceCallSite callSite, ServiceProviderEngineScope scope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.CreateServiceAccessor(ServiceIdentifier serviceIdentifier)
   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(ServiceIdentifier serviceIdentifier, ServiceProviderEngineScope serviceProviderEngineScope)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.ServiceProviderEngineScope.GetService(Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ServiceProviderServiceExtensions.GetRequiredService(IServiceProvider provider, Type serviceType)
   at SoundStage.IoC.Extensions.IServiceCollectionExtensions.<>c__DisplayClass1_1.<AddSonarByConventions>b__13(IServiceProvider provider)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitFactory(FactoryCallSite factoryCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitConstructor(ConstructorCallSite constructorCallSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSiteMain(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.VisitRootCache(ServiceCallSite callSite, RuntimeResolverContext context)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteVisitor`2.VisitCallSite(ServiceCallSite callSite, TArgument argument)
   at Microsoft.Extensions.DependencyInjection.ServiceLookup.CallSiteRuntimeResolver.Resolve(ServiceCallSite callSite, ServiceProviderEngineScope scope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.CreateServiceAccessor(ServiceIdentifier serviceIdentifier)
   at System.Collections.Concurrent.ConcurrentDictionary`2.GetOrAdd(TKey key, Func`2 valueFactory)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(ServiceIdentifier serviceIdentifier, ServiceProviderEngineScope serviceProviderEngineScope)
   at Microsoft.Extensions.DependencyInjection.ServiceProvider.GetService(Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ServiceProviderServiceExtensions.GetRequiredService(IServiceProvider provider, Type serviceType)
   at Microsoft.Extensions.DependencyInjection.ServiceProviderServiceExtensions.GetRequiredService[T](IServiceProvider provider)
   at Program.<>c__DisplayClass0_0.<<Main>$>g__RegisterVolumeService|47(IShutdownStackService shutdownService)
   at Program.<>c__DisplayClass0_0.<<Main>$>b__11()
   at Program.<Main>$(String[] args)

Error: (07/17/2024 03:17:33 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress..

Error: (07/17/2024 03:17:33 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]

Error: (07/17/2024 03:17:33 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress..

Error: (07/17/2024 03:17:33 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]

Error: (07/17/2024 03:13:51 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied..This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {f4c1f4a5-5013-45f7-95fc-6556ae7dc266}


System errors:
=============
Error: (07/17/2024 04:30:20 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-NLBF3N2)
Description: The server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter did not register with DCOM within the required timeout.

Error: (07/17/2024 04:13:07 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-NLBF3N2)
Description: The server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter did not register with DCOM within the required timeout.

Error: (07/17/2024 04:09:13 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-NLBF3N2)
Description: The server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter did not register with DCOM within the required timeout.

Error: (07/17/2024 03:17:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\WINDOWS\system32\IntelIHVRouter12.dll

Error: (07/17/2024 03:17:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\WINDOWS\system32\IntelIHVRouter12.dll

Error: (07/17/2024 03:14:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (07/17/2024 03:14:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The NVIDIA LocalSystem Container service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 6000 milliseconds: Restart the service.

Error: (07/17/2024 03:14:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Microsoft Office Click-to-Run Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.


Windows Defender:
================
Date: 2024-07-17 11:50:59
Description:
Microsoft Defender Antivirus has detected potentially unwanted application(PUA).
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=PUA:Win32/Packunwan&threatid=298189&enterprise=0
Name: PUA:Win32/Packunwan
Severity: Low
Category: Potentially Unwanted Software
Path: file:_C:\FRST\Quarantine\C\Users\Ripple\AppData\Local\WinRAR\Rar64.exe.xBAD
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Users\Ripple\AppData\Local\Temp\62AAE2-5AC3A3D8-A8B2470-1BCF3FDC\N2NIMhe1.exe
Security intelligence Version: AV: 1.415.134.0, AS: 1.415.134.0, NIS: 1.415.134.0
Engine Version: AM: 1.1.24060.5, NIS: 1.1.24060.5

Date: 2024-07-17 11:50:59
Description:
Microsoft Defender Antivirus has detected potentially unwanted application(PUA).
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=PUA:Win32/Packunwan&threatid=298189&enterprise=0
Name: PUA:Win32/Packunwan
Severity: Low
Category: Potentially Unwanted Software
Path: file:_C:\FRST\Quarantine\C\Users\Ripple\AppData\Local\WinRAR\Rar64.exe.xBAD
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Users\Ripple\AppData\Local\Temp\62AAE2-5AC3A3D8-A8B2470-1BCF3FDC\N2NIMhe1.exe
Security intelligence Version: AV: 1.415.134.0, AS: 1.415.134.0, NIS: 1.415.134.0
Engine Version: AM: 1.1.24060.5, NIS: 1.1.24060.5

Date: 2024-07-16 11:42:11
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2024-07-16 10:24:54
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2024-07-16 10:24:34
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

CodeIntegrity:
===============
Date: 2024-07-17 15:19:24
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Users\Ripple\AppData\Local\Discord\app-1.0.9154\Discord.exe) attempted to load \Device\HarddiskVolume3\ProgramData\obs-studio-hook\graphics-hook64.dll that did not meet the Microsoft signing level requirements.

Date: 2024-07-17 01:45:37
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Users\Ripple\AppData\Local\Discord\app-1.0.9153\Discord.exe) attempted to load \Device\HarddiskVolume3\ProgramData\obs-studio-hook\graphics-hook64.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends International, LLC. N.1.14STD00 09/15/2022
Motherboard: Standard Standard
Processor: 12th Gen Intel(R) Core(TM) i7-12700H
Percentage of memory in use: 43%
Total physical RAM: 32508.54 MB
Available physical RAM: 18301.61 MB
Total Virtual: 34556.54 MB
Available Virtual: 17370.6 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:247.07 GB) (Free:88.41 GB) (Model: CT1000P3PSSD8) NTFS
Drive d: (Max) (Fixed) (Total:683.59 GB) (Free:439.32 GB) (Model: CT1000P3PSSD8) NTFS
Drive e: (PortableSSD) (Fixed) (Total:931.51 GB) (Free:203.19 GB) (Model: SanDisk Portable SSD SCSI Disk Device) NTFS
Drive f: (portable movies & games) (Fixed) (Total:953.85 GB) (Free:780.37 GB) (Model: JMicron Tech SCSI Disk Device) NTFS

\\?\Volume{32397118-47cf-4961-8f00-d29de02ab434}\ () (Fixed) (Total:0.74 GB) (Free:0.13 GB) NTFS
\\?\Volume{4cd4fb91-1125-4d65-a761-2c4f675a5ae6}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 16F2A91F)

Partition: GPT.

==========================================================
Disk: 2 (Protective MBR) (Size: 953.9 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================
 
Also, if there is something that is chewing a lot of resources when the computer hangs or just in general...

Monitor things with this and report anything suspicious to me please.
To view this content we will need your consent to set third party cookies.
For more detailed information, see our cookies page.



 
  • Like
Reactions: maxim123
the explorer is actually hanging even now. Its not responding. when this happens, I can't alt tab through other apps, can't open start or search there.

i have take screenshot in fn key + p, but even that took a while to run.

1721214257660.png
 



What is the make and model of your laptop?

Turn off fast start.




For now please remove SteelSeries GG 66.0.0 it is showing multiple errors in your logs,. you can reinstall later.



Download DDU follow all directions to remove the Nvidia drivers.
Re-install Nvidia drivers with this tool, NVCleaninstall. Uncheck everything except the drivers.



I suggest using this tool to regain privacy and turn off unneeded settings.
https://github.com/builtbybel/Winpilot/releases/download/2024.6.1/Winpilot.zip



Download Autoruns and Autorunsc Unzip it to your desktop and then right click
Capture.PNG

Run as Admin.
After the scan is finished then click on File----Then click----Save
The default name will be autoruns.arn make sure to leave it this way.
Attach the file in your next reply.
If the file is too large, then use catbox.moe or Ufile.io and send the link in your next reply.
 
Last edited:
  • Like
Reactions: maxim123
Hi,
Its a custom model. Ripple Device Nova Pro.
I did all of the above. when going to safe mode to remove nvidia drivers, I encountered an issue of ctfmon
The exact letter by letter error. "ctfmon.exe - System Error: The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application."

it kept on showing up in safe mode even after i kept on closing it, but I was able to uninstall the graphics driver. the error doesn't come in normal mode.

Autoruns64 didn't save the file as autoruns.arn. It saved as my desktop id or number. here is the file.
 
Start autoruns as admin uncheck the items with a blue mark next to them and reboot the computer.

1721278984422.png
1721279056442.png
1721279212898.png


For now disable windows updte, you can update later when we are done here.


Copy the content of the code box below.
Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.


Code:
start::
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
EmptyEventLogs:
S3 SbieDrv; \??\d:\Program Files\Sandboxie\SbieDrv.sys [X]
C:\Users\Ripple\AppData\Roaming\obs-virtualcam.txt
AlternateDataStreams: C:\ProgramData\autoclickconfig.ini:07021500A6 [5162]
AlternateDataStreams: C:\ProgramData\empty.ico:8C1C1B484F [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk:A1B76439FE [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk:088221F38A [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk:FE00AE19CB [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:41964AA945 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk:B96E9B8455 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk:C5112377E0 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk:980850BA8A [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk:8096E45125 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk:C5D586BE93 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk:E77773B271 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk:60EC9648C0 [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk:5465085A2F [5162]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk:1DC1525F34 [5162]
Folder: C:\Windows\System32\Tasks

StartBatch:
WMIC SERVICE WHERE Name="dcomlaunch" set startmode="auto"
WMIC SERVICE WHERE Name="nsi" set startmode="auto"
WMIC SERVICE WHERE Name="dhcp" set startmode="auto"
WMIC SERVICE WHERE Name="rpcss" set startmode="auto"
WMIC SERVICE WHERE Name="rpceptmapper" set startmode="auto"
WMIC SERVICE WHERE Name="winmgmt" set startmode="auto"
WMIC SERVICE WHERE Name="sdrsvc" set startmode="manual"
WMIC SERVICE WHERE Name="vss" set startmode="manual"
WMIC SERVICE WHERE Name="eventlog" set startmode="auto"
WMIC SERVICE WHERE Name="bfe" set startmode="auto"
WMIC SERVICE WHERE Name="eventsystem" set startmode="auto"
WMIC SERVICE WHERE Name="msiserver" set startmode="manual"
WMIC SERVICE WHERE Name="sstpsvc" set startmode="manual"
WMIC SERVICE WHERE Name="rasman" set startmode="manual"
WMIC SERVICE WHERE Name="trustedinstaller" set startmode="auto"
net start sdrsvc
net start vss
net start rpcss
net start eventsystem
net start winmgmt
net start msiserver
net start bfe
net start trustedinstaller
"%WINDIR%\SYSTEM32\lodctr.exe" /R
"%WINDIR%\SysWOW64\lodctr.exe" /R
"%WINDIR%\SYSTEM32\lodctr.exe" /R
"%WINDIR%\SysWOW64\lodctr.exe" /R
NETSH winsock reset catalog
NETSH int ipv4 reset reset.log
NETSH int ipv6 reset reset.log
ipconfig /release
ipconfig /renew
ipconfig /flushdns
ipconfig /registerdns
netsh winhttp reset proxy
bitsadmin /list /allusers
bitsadmin /reset /allusers
Winmgmt /salvagerepository
Winmgmt /resetrepository
Winmgmt /resyncperf
netsh advfirewall reset
netsh advfirewall set allprofiles state on
del /f /s /q %windir%\prefetch\*.*
sc stop sysmain
sc config sysmain start= disabled
sc stop DiagTrack
sc config DiagTrack start= disabled
sc stop dmwappushservice
sc config dmwappushservice start= disabled
sc stop WSearch
sc config WSearch start= disabled
sc stop lfsvc
sc config lfsvc start= disabled
Endbatch:
CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
ExportKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\TurnOffAnonymousBlock
ExportKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ExportKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
ExportKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
ExportKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32
ExportKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
emptytemp:
Reboot:
End::







Security Check Scan.



  • Download Security Check to your desktop.
  • Right click it run as administrator.
  • When the program completes, the tool will automatically open a log file.
  • Please Copy and paste that log here in your next post.
  • There will be items listed in red when you post this log, those items need to be updated.

 
Last edited:
  • Like
Reactions: maxim123
Download and run Privazer to clean up your system. This cleaner can take a while, but removes the most amount of crap....



Then download AVZ4 save the file to your desktop, unzip it there.
Double click the folder and find AVZ.exe right click and run as admin.
Do not drag this file out of the folder, it must be ran from within.


Then go to file, then database update.
Make sure and update.
Then go to file troubleshooting wizard.
Then under issue type go to system issues, should be there by default.
Then under dangerousness level select all issues,

Then hit the start button.
Allow that scan to complete.
Do not change any settings on your own.
Screen shot that for me an attach the result.

Do the same under privacy.
 
Last edited:
  • Like
Reactions: maxim123
Status
Not open for further replies.