Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Инсталирах .exe ,което показва зараза infostealer ("Lumma" or "Stealerc") § а Banking Trojan

Featured Replies

Здравейте!

Това е редит поста , от където моя приятел изтегли exe файла и го инсталира на компютъра https://www.reddit.com/r/cracked_soft/comments/1t2hnx4/capcut_pro_activator/

Резултатите от VirusTotal са доста категорични https://www.virustotal.com/gui/file/1fb48c154f634687d2a01319fc603c53d4793eca94472c6f95afce662024ca46

Какво мога да направя по въпроса?

Благодаря !

post-851775-0-04244800-1780771330.png

post-851775-0-06133500-1780771352.png

post-851775-0-08779000-1780771343.png

  • Автор

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-06-2026
Ran by User (administrator) on DESKTOP-J190OJ1 (LENOVO 81Y8) (07-06-2026 11:33:14)
Running from C:\Users\testa\Downloads\FRST64.exe
Loaded Profiles: User & testa
Platform: Microsoft Windows 10 Pro Version 22H2 19045.6456 (X64) Language: English (United States)
Default browser: "C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe" --single-argument %1
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSATray.exe
(C:\Program Files\AVG\Antivirus\AVGSvc.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\DDSHelper.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2620.102.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe <13>
(DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_925ded1d9428eaee\DAX3API.exe ->) (Dolby Laboratories, Inc. -> ) C:\ProgramData\Dolby\DAX3\RADARHOST\DSRHost.exe
(DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_925ded1d9428eaee\DAX3API.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\DAX3_S~1.INF\DAX3API.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\LenovoUtilityService.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\FnHotkeyCapsLKNumLK.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\LenovoUtilityService.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\FnHotkeyUtility.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <9>
(explorer.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> WhatsApp.Root) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2620.102.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <36>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(explorer.exe ->) (Open Source Developer, Robin Krom -> Greenshot) C:\Users\testa\AppData\Local\Greenshot\Greenshot.exe
(explorer.exe ->) (The qBittorrent Project) [File not signed] C:\Program Files\qBittorrent\qbittorrent.exe
(explorer.exe ->) (Viber Media S.a r.l. -> Viber Media S.à r.l.) C:\Users\testa\AppData\Local\Viber\Viber.exe
(explorer.exe ->) (Windscribe Limited -> Windscribe Limited) C:\Program Files\Windscribe\Windscribe.exe
(Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\AVGUI.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe
(services.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_925ded1d9428eaee\DAX3API.exe
(services.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(services.exe ->) (FOXIT SOFTWARE INC. -> Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\aswidsagent.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\avgToolsSvc.exe
(services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_82b77f8c4618e2d0\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_9cf4db1a1fd1b22d\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_0b214be229a13e84\jhi_service.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_c98d5e0dfc88ac2f\RstMwService.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\LenovoUtilityService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvltig.inf_amd64_c81552b0afd57b24\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(services.exe ->) (Windscribe Limited -> Windscribe Limited) C:\Program Files\Windscribe\WindscribeService.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [1099944 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2264704 2022-05-20] (voidtools -> voidtools)
HKLM\...\Run: [Seagull Drivers V3] => C:\Program Files\Seagull\Printer Drivers\Common\Seagull_DriverStartup.exe [533776 2019-06-13] (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [1084704 2020-05-27] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [211046848 2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.)
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\Installer\setup.exe [5324144 2026-05-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\RunOnce: [msedge_cleanup_{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}] => C:\Program Files (x86)\Microsoft\Edge\Application\149.0.4022.52\Installer\setup.exe [5346672 2026-06-06] (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45227312 2024-10-15] (Gen Digital Inc. -> Piriform Software Ltd)
HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\RunOnce: [NetworkResetPostReboot] => netsh.exe trace postreset (No File)
HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\Policies\Explorer: [ConfirmFileDelete] 1
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Run: [AVGBrowserAutoLaunch_8F351DF0CEE308805CB145B9E3DA56ED] => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [4364960 2026-05-12] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Run: [Greenshot] => C:\Users\testa\AppData\Local\Greenshot\Greenshot.exe [527792 2017-08-09] (Open Source Developer, Robin Krom -> Greenshot)
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45227312 2024-10-15] (Gen Digital Inc. -> Piriform Software Ltd)
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Run: [Viber] => C:\Users\testa\AppData\Local\Viber\Viber.exe [82619800 2026-05-26] (Viber Media S.a r.l. -> Viber Media S.à r.l.)
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [116060056 2022-04-12] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Run: [qBittorrent] => C:\Program Files\qBittorrent\qbittorrent.exe [29060608 2022-03-23] (The qBittorrent Project) [File not signed]
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Run: [Discord] => C:\Users\testa\AppData\Local\Discord\Update.exe [1516408 2025-05-05] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Run: [Windscribe] => C:\Program Files\Windscribe\Windscribe.exe [43349160 2025-07-24] (Windscribe Limited -> Windscribe Limited)
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Run: [electron.app.LM Studio] => C:\Users\testa\AppData\Local\Programs\LM Studio\LM Studio.exe [204007096 2025-10-08] (Element Labs Inc. -> LM Studio)
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Run: [MicrosoftEdgeAutoLaunch_D9BC01DA7EE888E155CFF65CFCDDE7EC] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5257584 2026-06-04] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Policies\Explorer: [ConfirmFileDelete] 1
HKLM\...\Print\Monitors\Seagull V3 Network Monitor: C:\Windows\system32\Seagull_V3_NetMonDispatcher.dll [594704 2019-06-13] (Seagull Scientific, Inc -> Seagull Scientific, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{48F69C39-1356-4A7B-A899-70E3539D4982}] -> C:\Program Files (x86)\AVG\Browser\Application\147.0.34598.118\Installer\chrmstp.exe [6090560 2026-05-22] (Gen Digital Inc. -> Gen Digital Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4033688 2026-06-02] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\148.0.7778.217\Installer\chrmstp.exe [7617688 2026-06-02] (Google LLC -> Google LLC)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2022-06-16]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
GroupPolicy\User: Restriction ? <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {634C565F-32C4-47FA-B0DC-647EE76D66FA} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [561984 2011-06-01] (Apple Inc. -> Apple Inc.)
Task: {C0D5277D-8FEF-4D57-A618-3EC0F69EC6AE} - System32\Tasks\AVG Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [4364960 2026-05-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {1C693B3F-63F7-40B4-BCAD-05D635CA3C10} - System32\Tasks\AVG Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [4364960 2026-05-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {EAD48F90-6D10-4BAB-BDAC-CC787C601923} - System32\Tasks\AVG Secure Browser VPS Differential Update => C:\Program Files (x86)\AVG\Browser\Application\vps_helper.exe [2481240 2026-05-12] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {AB234897-72DE-4E26-A9F7-626AC804D1D7} - System32\Tasks\AVG\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [5827240 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {BE3948DE-4F80-4620-8032-FD0463CC1A0A} - System32\Tasks\AVG\AVG Antivirus Patcher => C:\Program Files\Common Files\AVG\Icarus\avg-av\icarus.exe [9736416 2026-05-20] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {83EA3F33-1B8C-47E1-8B90-666259ADD01C} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [3763936 2026-05-28] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {B55FAF5E-565F-4BB5-9E3E-7A00579DF3C9} - System32\Tasks\AVGBrowserProtectS-1-5-21-9367388-606531772-2301354866-1001 => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowserProtect.exe [1764576 2026-04-02] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {CD14A1A6-17D5-4213-A933-9EE761BB56F5} - System32\Tasks\AVGUpdateTaskMachineCore => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2023-05-19] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {78BCCD93-3F8A-498B-B865-430AB7943FD7} - System32\Tasks\AVGUpdateTaskMachineUA => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2023-05-19] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {396CC801-C14F-4B9C-9DD6-6EFE05824C93} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [829408 2024-10-15] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {3C86DF9E-34B7-4D8D-ACE6-8BAB3F1B3EED} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5983536 2024-10-15] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "c7f686ee-a268-4c7d-b8e5-2d8a7d9099dd" --version "6.29.11342" --silent
Task: {8CE869C2-6A99-43FA-94B1-E40F77772E85} - System32\Tasks\CCleanerSkipUAC - User => C:\Program Files\CCleaner\CCleaner.exe [39090480 2024-10-15] (Gen Digital Inc. -> Piriform Software Ltd)
Task: {B3BA7B1A-DC8D-4157-B84F-0B45AD288815} - System32\Tasks\DropboxSystem\DropboxUpdater\DropboxUpdaterTaskSystem123.0.6299.144{9958E817-42C2-4985-A005-322CBF3AB0C7} => C:\Program Files\Dropbox\DropboxUpdater\123.0.6299.144\updater.exe [5898168 2025-12-16] (Dropbox, Inc -> Dropbox, Inc.)
Task: {5B389CBB-78B1-4699-8708-6543CA3B45BB} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem150.0.7863.0{2E11A38E-7D51-445A-8704-91FF13756B73} => C:\Program Files (x86)\Google\GoogleUpdater\150.0.7863.0\updater.exe [8728216 2026-05-28] (Google LLC -> Google LLC)
Task: {9A8FD2CD-66F4-47C2-961C-7835B337DE7D} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4033688 2026-06-02] (Google LLC -> Google LLC)
Task: {0A17129C-7C73-40C4-B378-22C15A65C0DE} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Metrics => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4033688 2026-06-02] (Google LLC -> Google LLC)
Task: {586BE744-E431-4A6E-904C-C4B1A24FA6D1} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelperOnUnlock => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4033688 2026-06-02] (Google LLC -> Google LLC)
Task: {E2510761-1F11-4E58-8375-202587811726} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4916640 2024-04-15] (Intel Corporation -> Intel Corporation)
Task: {4F962BD0-74A9-4E36-BC5B-B4478499559B} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4916640 2024-04-15] (Intel Corporation -> Intel Corporation)
Task: {06F1EC9C-7EC5-45D7-B5FF-137E985C0F18} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {2D14BF68-7F8C-40B3-AA2C-4C219ACFFCE4} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2113024 2022-04-15] () [File not signed]
Task: {8AB8E64C-D47E-4F82-88DD-71F1A6A0903A} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-9367388-606531772-2301354866-1005 => C:\Users\testa\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe [94032 2026-04-29] (Lenovo (Beijing) Limited -> Lenovo Group Limited)
Task: {BF5B3D35-AAF4-4D8A-ABA7-6ACFF8AF0C6D} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705152 2026-06-06] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {7241C0B4-4C2D-45AA-9427-CBB2582A4F45} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-9367388-606531772-2301354866-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705152 2026-06-06] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {DEEF224B-8BDB-4394-B6EA-9C613E80788D} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-9367388-606531772-2301354866-1005 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705152 2026-06-06] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {BCAB20F2-7664-4180-92A0-AE2A886AE17B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-06-06] (Mozilla Corporation -> Mozilla Foundation)
Task: {73690E59-63B3-4245-A1A9-7BC2AD2C328F} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1005096 2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {6188A0C0-46C3-4DD2-BC3D-87ADD30A06B2} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3345448 2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E0B95895-178B-4871-A418-9D3F126B20CD} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649256 2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {34E5C82F-22A6-43CE-A19F-AB9815A99FF9} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5C94F3B8-3983-4487-BDB1-8E53C5924A02} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {18B92C9C-3709-4044-892B-2E3F90C4E1A2} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F0609488-4C1C-46EF-A11C-8D5179DCC060} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1EE3C2F5-1AF7-424A-884E-4BBBDCB186DB} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D2DAE55D-0B54-4877-83BC-FCBA056E9F37} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {51A0C015-3385-457C-94E3-352CD0FEAECC} - System32\Tasks\oCamTask => C:\Program Files (x86)\oCam\oCamTask.exe [156336 2023-12-16] (OORT Inc. -> oh!soft)
Task: {C5F104B2-9692-4F46-B15B-605BAB7BE1BD} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\Windows\System32\Wscript.exe [181760 2026-01-17] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\//B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {50112070-96EE-4BD3-A939-28047AB317D3} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-9367388-606531772-2301354866-1005 => C:\Users\testa\AppData\Roaming\Zoom\bin\Zoom.exe [507784 2026-03-16] (Zoom Communications, Inc. -> Zoom Communications, Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{132483ed-a77c-4224-8e09-e5cff261415f}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{26eb249c-fde6-4aa7-b938-05cf13de4c18}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3cfc511c-8d6c-4ebc-a231-6f591fd10b2e}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3cfc511c-8d6c-4ebc-a231-6f591fd10b2e}\552424F534C69656E64737: [DhcpNameServer] 10.134.191.1 212.39.90.42 212.39.90.43
Tcpip\..\Interfaces\{3cfc511c-8d6c-4ebc-a231-6f591fd10b2e}\77562623E203: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{b86c7a23-6e7a-4fbc-9d18-44bd537da6a1}: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: rqmt5x1d.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\66q57shh.default [2022-06-08]
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\rqmt5x1d.default-release [2024-11-26]
FF Plugin: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-04-20] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-04-20] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-04-20] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-04-20] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2022-04-20] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=3 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1634.4\npAvgBrowserUpdate3.dll [2023-05-19] (AVG Technologies USA, LLC -> AVG Technologies)
FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=9 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1634.4\npAvgBrowserUpdate3.dll [2023-05-19] (AVG Technologies USA, LLC -> AVG Technologies)

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default [2026-01-15]
Edge Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-12-25]
Edge Extension: (Online Security) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl [2025-12-25]
Edge Extension: (Edge relevant text changes) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-08-31]
Edge HKU\S-1-5-21-9367388-606531772-2301354866-1005\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [jcpgbnbdnakoblgfkbgggankeidkfcdl]
Edge HKLM-x32\...\Edge\Extension: [jcpgbnbdnakoblgfkbgggankeidkfcdl]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 avg; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2023-05-19] (AVG Technologies USA, LLC -> AVG Technologies)
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [1079464 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
R2 AVG Tools; C:\Program Files\AVG\Antivirus\avgToolsSvc.exe [1131688 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [8054440 2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)
S3 avgm; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [209224 2023-05-19] (AVG Technologies USA, LLC -> AVG Technologies)
S3 AVGSecureBrowserElevationService; C:\Program Files (x86)\AVG\Browser\Application\147.0.34598.118\elevation_service.exe [3733200 2026-05-12] (Gen Digital Inc. -> Gen Digital Inc.)
R2 AvgWscReporter; C:\Program Files\AVG\Antivirus\wsc_proxy.exe [109480 2022-06-06] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1087792 2024-10-15] (Gen Digital Inc. -> Piriform Software Ltd)
R2 DbxSvc; C:\WINDOWS\System32\DbxSvc.exe [59048 2026-02-09] (Dropbox, Inc -> Dropbox, Inc.)
R2 DolbyDAXAPI; C:\WINDOWS\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_925ded1d9428eaee\DAX3API.exe [2205144 2020-12-22] (Dolby Laboratories, Inc. -> Dolby Laboratories)
S3 DropboxElevationService; C:\Program Files (x86)\Dropbox\Client\254.4.2518\DropboxElevationService.exe [1659336 2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)
S2 DropboxUpdaterInternalService123.0.6299.144; C:\Program Files\Dropbox\DropboxUpdater\123.0.6299.144\updater.exe [5898168 2025-12-16] (Dropbox, Inc -> Dropbox, Inc.)
S2 DropboxUpdaterService123.0.6299.144; C:\Program Files\Dropbox\DropboxUpdater\123.0.6299.144\updater.exe [5898168 2025-12-16] (Dropbox, Inc -> Dropbox, Inc.)
R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe [133736 2026-03-24] (Intel Corporation -> Intel)
R2 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe [133224 2026-03-24] (Intel Corporation -> Intel)
S4 Everything; C:\Program Files\Everything\Everything.exe [2264704 2022-05-20] (voidtools -> voidtools)
R2 FMAPOService; C:\WINDOWS\System32\FMService64.exe [390400 2020-05-21] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
R2 FoxitReaderUpdateService; C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [2361576 2022-04-20] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
R2 LenovoFnAndFunctionKeys; C:\WINDOWS\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fa50a878363b0cec\LenovoUtilityService.exe [182272 2025-02-20] (Lenovo -> Lenovo)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11506480 2026-06-06] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-06-06] (Malwarebytes Inc -> Malwarebytes)
S4 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [945320 2025-06-19] (McAfee, LLC -> McAfee, LLC)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvltig.inf_amd64_c81552b0afd57b24\Display.NvContainer\NVDisplay.Container.exe [1275424 2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2026-01-17] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [16360768 2022-08-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\NisSrv.exe [3116848 2022-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2203.5-0\MsMpEng.exe [133544 2022-05-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WindscribeService; C:\Program Files\Windscribe\WindscribeService.exe [10156712 2025-07-24] (Windscribe Limited -> Windscribe Limited)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 avgArDisk; C:\WINDOWS\System32\drivers\avgArDisk.sys [21088 2026-05-06] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [259160 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [451168 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [315488 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [87136 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [29144 2025-08-09] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [34912 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [294496 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgNetHub; C:\WINDOWS\System32\drivers\avgNetHub.sys [636512 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [100960 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [71768 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [911456 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [1292896 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R3 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [250464 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [472672 2026-06-02] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae.sys [159296 2026-06-06] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [235624 2026-06-06] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2026-06-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\Drivers\farflt.sys [215656 2026-06-06] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [81000 2026-06-07] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [245864 2026-06-06] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [190096 2026-06-07] (Malwarebytes Inc -> Malwarebytes)
S3 MEMSWEEP2; C:\Windows\system32\BA6C.tmp [6144 2010-05-26] (Sophos Plc) [File not signed]
S3 mvusbews; C:\WINDOWS\System32\Drivers\ptusbews.sys [76280 2022-03-30] (WDKTestCert han.yu,130842677139774357 -> Zhuhai Pantum Electronics Co.,Ltd.)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2024-03-13] (Nvidia Corporation -> NVIDIA Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49600 2022-05-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [14464 2008-05-06] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [443664 2022-05-13] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [90384 2022-05-13] (Microsoft Windows -> Microsoft Corporation)
S3 WindscribeSplitTunnel; C:\WINDOWS\system32\DRIVERS\WindscribeSplitTunnel.sys [39280 2025-07-24] (Windscribe Limited -> )

==================== SvcHost (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-06-07 11:33 - 2026-06-07 11:34 - 000037817 _____ C:\Users\testa\Downloads\FRST.txt
2026-06-07 11:32 - 2026-06-07 11:33 - 000000000 ____D C:\FRST
2026-06-07 11:32 - 2026-06-07 11:32 - 000000000 ____D C:\Users\User\AppData\Local\Malwarebytes
2026-06-07 11:31 - 2026-06-07 11:32 - 002646016 _____ (Farbar) C:\Users\testa\Downloads\FRST64.exe
2026-06-07 11:29 - 2026-06-07 11:29 - 000190096 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2026-06-07 11:29 - 2026-06-07 11:29 - 000000000 ____D C:\Users\testa\AppData\LocalLow\IGDump
2026-06-07 00:05 - 2026-06-07 00:05 - 002450800 _____ C:\Users\testa\Downloads\AOCno.mp4
2026-06-06 21:39 - 2026-06-07 11:34 - 000000000 ____D C:\Users\testa\AppData\Local\Malwarebytes
2026-06-06 21:39 - 2026-06-06 21:39 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2026-06-06 21:39 - 2026-06-06 21:39 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2026-06-06 21:39 - 2026-06-06 21:39 - 000000000 ____D C:\Users\testa\AppData\Local\Sentry
2026-06-06 21:34 - 2026-06-06 21:34 - 000000000 ____D C:\ProgramData\Malwarebytes
2026-06-06 21:34 - 2026-06-06 21:34 - 000000000 ____D C:\Program Files\Malwarebytes
2026-06-06 21:33 - 2026-06-06 21:33 - 002852480 _____ (Malwarebytes) C:\Users\testa\Downloads\MBSetup-3.3.exe
2026-06-06 17:53 - 2026-06-06 17:52 - 010085901 _____ C:\Users\testa\Downloads\The Driven Man - Elon Musk's answer to why he's still working, despite being worth ove....mp4
2026-06-06 13:07 - 2026-06-06 13:07 - 039093251 _____ C:\Users\testa\Downloads\Video by newathlete.mp4
2026-06-06 11:57 - 2026-06-06 11:57 - 006552242 _____ C:\Users\testa\Downloads\Helen Casanova | Seduction Palace - 9. Make her work for it. When she asks you for more details or tries....mp4
2026-06-06 11:57 - 2026-06-06 11:57 - 001948418 _____ C:\Users\testa\Downloads\hyz - Hunter Schafer reveals some CIS women she hooked up with specifically....mp4
2026-06-06 10:49 - 2026-06-06 20:29 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-06-06 00:43 - 2026-06-06 22:49 - 000001692 _____ C:\Users\testa\Downloads\x.com_cookies.txt
2026-06-05 23:03 - 2026-06-05 23:03 - 002804488 _____ C:\Users\testa\Downloads\Investment Wisdom - Warren Buffett: "The secret to life is weak competition…" "'How do ....mp4
2026-06-05 22:11 - 2026-06-05 22:11 - 013803275 _____ C:\Users\testa\Downloads\𝕲𝖇𝖊𝖓𝖌𝖆 ☮️🕊️️ - The top assassin tapped an egg with a spoon but through the spoon's r....mp4
2026-06-05 15:23 - 2026-06-05 15:23 - 000141704 _____ C:\Users\testa\Downloads\Ford Festiva Hb 5d 1994-2001 2.webp
2026-06-05 12:15 - 2026-06-05 12:15 - 021229909 _____ C:\Users\testa\Downloads\video_2026-06-05_12-15-42.mp4
2026-06-05 12:04 - 2026-06-05 12:04 - 001770091 _____ C:\Users\testa\Downloads\AQPGONi5Wyujyxi7cIu0vp_qUug_b9Dapg9JpkMNbdfXbxFaVxI_plSfAaE7I5w.mp4
2026-06-04 18:14 - 2026-06-04 18:15 - 000145036 _____ C:\Users\testa\Downloads\Proforma-0000000491-Original-2026-06-04-18-14-52.pdf
2026-06-04 12:18 - 2026-06-04 12:18 - 005738974 _____ C:\Users\testa\Downloads\125 reactions · 68 comments | Game changer fr #youtubeautomation #sidehustle #youtubemoney #ai #internetmoney | EarnwithGerald.mp4
2026-06-04 04:46 - 2026-06-04 04:46 - 001924323 _____ C:\Users\testa\Downloads\video_2026-06-04_04-46-17.mp4
2026-06-04 04:31 - 2026-06-04 04:31 - 006872686 _____ C:\Users\testa\Downloads\moms approval 1.mp4
2026-06-03 23:05 - 2026-06-06 16:27 - 000000000 ____D C:\Users\testa\Downloads\psychopaths
2026-06-03 22:56 - 2026-06-03 22:56 - 000876786 _____ C:\Users\testa\Downloads\Elena Stoicheva.mp4
2026-06-03 22:53 - 2026-06-03 22:53 - 003304226 _____ C:\Users\testa\Downloads\King’s Fitness niggas birthday.mp4
2026-06-03 21:41 - 2026-06-03 21:41 - 015713537 _____ C:\Users\testa\Downloads\107K views · 1.1K reactions | My brain hurts now | Dylansnyder.mp4
2026-06-03 16:50 - 2026-06-03 16:50 - 001189491 _____ C:\Users\testa\Downloads\san antonio.mp4
2026-06-03 14:20 - 2026-06-03 14:20 - 000000000 ____D C:\Users\testa\Downloads\и
2026-06-03 11:13 - 2026-06-03 11:13 - 000000000 _____ C:\WINDOWS\system32\wmic
2026-06-03 05:10 - 2026-06-03 05:10 - 006949566 _____ C:\Users\testa\Downloads\ahegao potato.mp4
2026-06-02 18:37 - 2026-06-02 18:37 - 003403908 _____ C:\Users\testa\Downloads\video_2026-06-02_18-37-58.mp4
2026-06-02 18:12 - 2026-06-02 18:12 - 033680068 _____ C:\Users\testa\Downloads\12K views · 163K reactions | @unchained.earth was banned by OpenAI. For the full interview check out my YouTube channel. | Certified Health Nut.mp4
2026-06-02 18:04 - 2026-06-02 18:04 - 001802629 _____ C:\Users\testa\Downloads\video_2026-06-02_18-04-20.mp4
2026-06-02 17:59 - 2026-06-03 18:34 - 000063682 _____ C:\Users\testa\Downloads\orders-2026-06-02-17-59-42.xlsx
2026-06-02 13:34 - 2026-06-02 13:34 - 018120939 _____ C:\Users\testa\Downloads\5.8K views · 2.1K reactions | UK Study: Most young women don’t like MEN! Watch the FULL episode. Just search OTHER SODE AUSTRALIA Ep 516 on YouTube | Other Side.mp4
2026-06-02 13:19 - 2026-06-03 17:59 - 000000000 ____D C:\Users\testa\Downloads\triangle
2026-06-02 12:11 - 2026-06-02 12:11 - 006309068 _____ C:\Users\testa\Downloads\IMG_6006.MOV
2026-06-02 10:44 - 2026-06-02 10:44 - 007816025 _____ C:\Users\testa\Downloads\6.6K reactions · 720 shares | Instagram 101… Follow for more social media marketing education. | Personal Brand Launch.mp4
2026-06-02 10:13 - 2026-06-02 10:13 - 000324264 _____ (Gen Digital Inc.) C:\WINDOWS\system32\avgBoot.exe
2026-06-02 04:11 - 2026-06-02 04:11 - 000000000 ____D C:\theoccult free
2026-06-01 22:30 - 2026-06-01 22:30 - 000000000 ____D C:\Users\testa\Downloads\commitment
2026-06-01 22:06 - 2026-06-01 22:06 - 005602632 _____ C:\Users\testa\Downloads\Impressed by Arya, Jaqen H'ghar restores her sight #gameofthrones.mp4
2026-06-01 14:54 - 2026-06-01 14:54 - 000000000 ____D C:\Users\testa\Downloads\bjj
2026-06-01 10:45 - 2026-06-01 10:45 - 009245238 _____ C:\Users\testa\Downloads\3808767944092151433.mp4
2026-06-01 05:18 - 2026-06-01 05:18 - 004503742 _____ C:\Users\testa\Downloads\video_2026-06-01_05-18-36.mp4
2026-06-01 05:14 - 2026-06-01 05:14 - 011103672 _____ C:\Users\testa\Downloads\Wzmjg-7fJiUr9-Z6.mp4
2026-05-31 17:59 - 2026-05-31 17:59 - 000000000 ____D C:\Users\testa\Downloads\wrestling
2026-05-31 00:24 - 2026-05-31 00:24 - 014150494 _____ C:\Users\testa\Downloads\228K views · 5.5K reactions | Мухит Амантаев on Reels.mp4
2026-05-30 23:20 - 2026-05-30 23:20 - 001797331 _____ C:\Users\testa\Downloads\Bird song.mp4
2026-05-30 23:18 - 2026-05-30 23:18 - 000833913 _____ C:\Users\testa\Downloads\video_2026-05-30_23-18-54.mp4
2026-05-30 20:38 - 2026-05-30 20:38 - 002863062 _____ C:\Users\testa\Downloads\Janet - With his explanation the man is trying to say that the confident resp....mp4
2026-05-30 19:24 - 2026-05-30 19:24 - 016276596 _____ C:\Users\testa\Downloads\nail on a womans forehead.mp4
2026-05-30 19:22 - 2026-05-30 19:22 - 001838675 _____ C:\Users\testa\Downloads\video_2026-05-30_19-22-51.mp4
2026-05-30 17:00 - 2026-05-30 17:00 - 004243601 _____ C:\Users\testa\Downloads\🧬Maxpein🧬 - This Is What You Need To Know About Cancer!.mp4
2026-05-30 16:52 - 2026-05-30 16:52 - 001074206 _____ C:\Users\testa\Downloads\Gabriel 🌩️ - He might run like Napoleon Dynamite but he fights like Chuck Norris..mp4
2026-05-30 16:49 - 2026-05-30 16:49 - 020756003 _____ C:\Users\testa\Downloads\Giga Based Dad - She gets it.mp4
2026-05-29 23:37 - 2026-05-29 23:37 - 006851870 _____ C:\Users\testa\Downloads\Bxtches aint shxt They have no free will.mp4
2026-05-29 12:17 - 2026-05-29 12:17 - 009877218 _____ C:\Users\testa\Downloads\video_2026-05-29_12-17-38.mp4
2026-05-29 10:25 - 2026-05-29 10:25 - 008413380 _____ C:\Users\testa\Downloads\video_2026-05-29_10-24-58.mp4
2026-05-29 03:37 - 2026-05-29 03:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2026-05-28 22:40 - 2026-05-28 22:40 - 012003023 _____ C:\Users\testa\Downloads\YTDown_YouTube_Michael-W-Smith-Awesome-God_Media_38V8jnN1Kpw_001_360p.mp4
2026-05-28 22:22 - 2026-05-28 22:22 - 044344500 _____ C:\Users\testa\Downloads\YTDown_YouTube_Michael-W-Smith-Above-All-Live_Media_TdhIz3SKAp8_001_1080p.mp4
2026-05-28 22:20 - 2026-05-28 22:21 - 137041283 _____ C:\Users\testa\Downloads\YTDown_YouTube_AWESOME-GOD-Worship-Forever-2021-Michael_Media_sEZDuMGp3WY_001_1080p.mp4
2026-05-28 22:11 - 2026-05-28 22:11 - 001760252 _____ C:\Users\testa\Downloads\video_2026-05-28_22-11-54.mp4
2026-05-28 18:16 - 2026-05-28 18:16 - 000000000 ____D C:\Users\testa\AppData\Local\Viber
2026-05-28 17:53 - 2026-05-28 17:53 - 010392207 _____ C:\Users\testa\Downloads\video_2026-05-27_18-51-52.mp4
2026-05-28 16:06 - 2026-05-28 16:06 - 000430643 _____ C:\Users\testa\Downloads\video_2026-05-28_16-06-34.mp4
2026-05-28 13:57 - 2026-05-28 13:57 - 006473191 _____ C:\Users\testa\Downloads\1K reactions · 325 shares | Can’t believe this #creator #socialmediagrowth #creatortips #socialmediamarketingtips #creatorinsights | yorby.ai.mp4
2026-05-28 11:34 - 2026-05-28 11:34 - 006702752 _____ C:\Users\testa\Downloads\oA0A1iEyjQBwABA4IQECASgRVqiiIC2i1G7BfZ.mp4
2026-05-28 00:37 - 2026-05-28 00:37 - 021023203 _____ C:\Users\testa\Downloads\2_Glenn_Greenwald_on_X_There_was_only_one_thing_that_surprised_m.mp4
2026-05-27 13:51 - 2026-05-27 13:51 - 002723951 _____ C:\Users\testa\Downloads\probably retarded.mp4
2026-05-26 23:15 - 2026-05-26 23:15 - 038641809 _____ C:\Users\testa\Downloads\Deviate__the_science_of_seeing_differently_-_Beau_Lotto (1).pdf
2026-05-26 23:15 - 2026-05-26 23:15 - 038484068 _____ C:\Users\testa\Downloads\Deviate__the_science_of_seeing_differently_-_Beau_Lotto (1).epub
2026-05-26 12:37 - 2026-05-26 12:37 - 002076328 _____ C:\Users\testa\Downloads\video_2026-05-26_12-37-45.mp4
2026-05-26 11:53 - 2026-05-26 11:54 - 000000000 ____D C:\Users\testa\Downloads\eye fat
2026-05-26 10:11 - 2026-05-26 10:11 - 003286471 _____ C:\Users\testa\Downloads\video_2026-05-26_10-11-55.mp4
2026-05-25 22:42 - 2026-05-25 22:43 - 025025337 _____ C:\Users\testa\Downloads\When the nonchalant gimmick works... #usa #mma #fighting #bjj #jiujitsu #wrestling - VelcrumMMA (1080p, h264).mp4
2026-05-25 15:29 - 2026-05-25 15:29 - 000000090 _____ C:\Users\testa\Downloads\female rejection.txt
2026-05-25 14:44 - 2026-05-25 16:17 - 000122848 _____ C:\Users\testa\Downloads\orders-2026-05-25-13-02-21 1.xlsx
2026-05-25 13:03 - 2026-05-25 13:03 - 000000165 ____H C:\Users\testa\Downloads\~$orders-2026-05-25-13-02-21.xlsx
2026-05-25 13:02 - 2026-05-25 14:07 - 000122698 _____ C:\Users\testa\Downloads\orders-2026-05-25-13-02-21.xlsx
2026-05-25 12:01 - 2026-05-25 12:01 - 002160700 _____ C:\Users\testa\Downloads\Water creates a bridge when you run current through it, polarity at work.mp4
2026-05-25 05:45 - 2026-05-25 05:47 - 006399920 _____ C:\Users\testa\Downloads\Shock and awe _ achieving rapid dominance -- Harlan K_ Ullman, James P_ Wade, L_ A_ Edney, National -- Washington, DC, District of Columbia, 1996 -- isbn13 9781579060305 -- 1678981279d288f61af9c1f8986cd4ef -- Anna’.pdf
2026-05-25 05:40 - 2026-05-25 05:40 - 001065605 _____ C:\Users\testa\Downloads\N3180.pdf
2026-05-25 05:35 - 2026-05-25 05:35 - 020769549 _____ C:\Users\testa\Downloads\video_2026-05-25_05-35-34.mp4
2026-05-25 05:33 - 2026-05-25 05:33 - 098952388 _____ C:\Users\testa\Downloads\video_2026-05-25_05-33-00.mp4
2026-05-24 20:25 - 2026-05-24 20:25 - 001605017 _____ C:\Users\testa\Downloads\crab 1.mp4
2026-05-24 18:04 - 2026-05-24 18:04 - 002111818 _____ C:\Users\testa\Downloads\My secret talent 😋.mp4
2026-05-24 01:13 - 2026-05-24 19:13 - 006623493 _____ C:\Users\testa\Downloads\3 second look.mp4
2026-05-24 00:57 - 2026-05-24 00:57 - 002523990 _____ C:\Users\testa\Downloads\rapidsave_com_girl_attacks_dude_and_soon_regrets_it_h3qrdpvc71sd1.mp4
2026-05-23 21:21 - 2026-05-23 21:21 - 014515699 _____ C:\Users\testa\Downloads\Gordon Ramsay Gives The Best Compliment Possible.webm
2026-05-23 20:45 - 2026-05-23 20:45 - 012265241 _____ C:\Users\testa\Downloads\fake bitch 1.mp4
2026-05-23 20:42 - 2026-05-23 20:42 - 000000000 ____D C:\Users\testa\Downloads\Brandon Briggs
2026-05-23 17:38 - 2026-05-23 17:39 - 001785827 _____ C:\Users\testa\Downloads\Song name “dopamine (split brain version)” by Madelline.mp4
2026-05-23 17:27 - 2026-05-23 17:27 - 015633871 _____ C:\Users\testa\Downloads\The Telegraph should remain outdated.mp4
2026-05-23 17:11 - 2026-05-23 17:11 - 004839249 _____ C:\Users\testa\Downloads\127K views · 2.4K reactions | This move is ILLEGAL in 47 states. #selfdefense #mma #boxing | Lori Harvey.mp4
2026-05-22 13:49 - 2026-05-22 13:49 - 045291673 _____ C:\Users\testa\Downloads\385K views · 15K reactions | Do you agree with this about Christianity & wealth? | Lewis Howes.mp4
2026-05-22 12:00 - 2026-05-22 12:00 - 004115220 _____ C:\Users\testa\Downloads\8fd30519-5acb-4.mp4
2026-05-20 14:02 - 2026-05-21 13:40 - 000000000 ____D C:\Users\testa\Downloads\trevor
2026-05-20 12:22 - 2026-05-20 14:02 - 000000000 ____D C:\Users\testa\Downloads\Teal Swan
2026-05-19 23:27 - 2026-05-19 23:27 - 002932051 _____ C:\Users\testa\Downloads\video_2026-05-19_23-27-46.mp4
2026-05-19 16:50 - 2026-05-19 16:50 - 000270502 _____ C:\Users\testa\Downloads\[email protected]
2026-05-19 15:06 - 2026-05-19 15:06 - 008459087 _____ C:\Users\testa\Downloads\29K views · 445 reactions | This maths meme | Meme for mathematicians.mp4
2026-05-18 23:51 - 2026-05-18 23:51 - 020023227 _____ C:\Users\testa\Downloads\510K views · 19K reactions | Are "generational curses" REAL?! Allow me to blow your mind and answer this question with some absolutely incredible Bible history 🙏 🙌 | Josh Howerton.mp4
2026-05-18 23:48 - 2026-05-18 23:48 - 001323602 _____ C:\Users\testa\Downloads\42K views · 2K reactions | BalkansKnow on Reels.mp4
2026-05-18 18:30 - 2026-05-18 18:30 - 006396844 _____ C:\Users\testa\Downloads\5K views · 11K reactions | Comment “host” and I’ll send it to you. | Command Traffic.mp4
2026-05-17 21:01 - 2026-05-17 21:01 - 007326136 _____ C:\Users\testa\Downloads\173K views · 882 reactions | Comment CLASS for a free training 💰 | The Millionaire Nanny.mp4
2026-05-16 15:12 - 2026-05-16 15:12 - 009252295 _____ C:\Users\testa\Downloads\1M views · 18K reactions | We have some trust to earn with this one. #catsoftiktok #catlover #catlife | Soccercatmom.mp4
2026-05-16 11:36 - 2026-05-16 11:36 - 001021248 _____ C:\Users\testa\Downloads\AQNv7fqAYQgXyJ4sY9VVjIwHfP5jg8KxK_KJ_k9QlAnD57MUhDkVv3C7CzPvTRWtF89.mp4
2026-05-16 10:38 - 2026-05-16 10:38 - 002407787 _____ C:\Users\testa\Downloads\video_2026-05-16_10-38-22.mp4
2026-05-16 02:23 - 2026-05-16 02:23 - 000000000 ____D C:\Users\testa\Downloads\ascension
2026-05-14 12:57 - 2026-05-25 12:58 - 000000000 ____D C:\Users\testa\Downloads\horse
2026-05-14 12:20 - 2026-05-14 12:20 - 009552787 _____ C:\Users\testa\Downloads\v1uLqELRqlBrjNX7.mp4
2026-05-14 12:20 - 2026-05-14 12:20 - 006659879 _____ C:\Users\testa\Downloads\jNLSYLIe-S-6JPYk.mp4
2026-05-14 12:20 - 2026-05-14 12:20 - 003578935 _____ C:\Users\testa\Downloads\eKdm7tulVxH9LWbb.mp4
2026-05-14 12:20 - 2026-05-14 12:20 - 002353992 _____ C:\Users\testa\Downloads\5xiv2_E9fmAps8H9.mp4
2026-05-14 10:08 - 2026-05-14 10:08 - 000000000 ____D C:\Users\testa\AppData\Local\LenovoServiceBridge
2026-05-13 23:51 - 2026-05-14 12:55 - 000000000 ____D C:\Users\testa\Downloads\stinger
2026-05-13 14:50 - 2026-05-13 14:50 - 000000000 ____D C:\Users\testa\Downloads\mind control
2026-05-12 20:59 - 2026-05-12 20:59 - 013499858 _____ C:\Users\testa\Downloads\Luiza Jarovsky, PhD - This is what happens when people use AI frequently and uncritically (....mp4
2026-05-12 20:55 - 2026-05-12 20:55 - 038145982 _____ C:\Users\testa\Downloads\Johnny St.Pete - 🔥 UNREAL… Once AGAIN in Hollywood it’s ALL OF THEM. Just like Stephen....mp4
2026-05-12 16:13 - 2026-05-12 16:13 - 003875783 _____ C:\Users\testa\Downloads\Magnetic_Flux_Gyroscope_kinetic_art_on_a_stand_or_on_a_chain_physics.mp4
2026-05-12 11:00 - 2026-05-12 11:00 - 014315766 _____ C:\Users\testa\Downloads\garfield fat.mp4
2026-05-12 11:00 - 2026-05-12 11:00 - 004123105 _____ C:\Users\testa\Downloads\AQPyM3nQGFFO7gJLu6B7ebPJrhKYkwhEVGCSMJ4BoTyTu6dk86pzpsPcDynObP_ovCZJzMmqLlIyRSjWN59mWYeUmG8G1rfPXcyrLDhcTICYhg.mp4
2026-05-12 10:40 - 2026-05-12 10:40 - 000000000 ____D C:\Users\testa\Downloads\unemployed
2026-05-09 17:13 - 2026-05-09 17:14 - 000000000 ____D C:\Users\testa\Downloads\censorship
2026-05-09 17:04 - 2026-05-09 17:04 - 005395246 _____ C:\Users\testa\Downloads\3.4K views · 25K reactions | Which is your favorite color?😁 | GreekwithDimitris.mp4
2026-05-09 16:12 - 2026-05-09 16:12 - 004238177 _____ C:\Users\testa\Downloads\Experts never procrastinate#SmoothMoves #SilkySkills #FlowMoments #ImpressiveSkills #ViralClips.mp4
2026-05-09 14:26 - 2026-05-09 14:26 - 012104917 _____ C:\Users\testa\Downloads\you_can_t_control_other_people_excerpt_from_honour_your_father_a.mp4
2026-05-08 18:07 - 2026-05-08 18:07 - 000145009 _____ C:\Users\testa\Downloads\Proforma-0000000486-Original-2026-05-08-18-07-00.pdf
2026-05-08 13:19 - 2026-05-08 13:19 - 001637770 _____ C:\Users\testa\Downloads\triple point of water begins to boil, melt, and freeze at the same time.mp4
2026-05-08 12:40 - 2026-05-08 12:40 - 027358424 _____ C:\Users\testa\Downloads\usakinotelegram_gmesptxx.mp4
2026-05-08 11:25 - 2026-05-08 11:25 - 006345480 _____ C:\Users\testa\Downloads\IMG_8984.MP4
2026-05-08 05:46 - 2026-05-08 06:11 - 000000000 ____D C:\Users\testa\Downloads\book
2026-05-08 05:35 - 2026-05-08 05:35 - 001302909 _____ C:\Users\testa\Downloads\video_2026-05-08_05-35-58.mp4

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-06-07 11:34 - 2023-12-04 05:56 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-06-07 11:30 - 2023-06-30 16:31 - 000000000 ____D C:\Users\testa\AppData\Roaming\qBittorrent
2026-06-07 11:30 - 2023-06-29 08:12 - 000000000 ____D C:\Users\testa\AppData\Roaming\Dropbox
2026-06-07 11:30 - 2023-06-28 08:42 - 000000000 ____D C:\Users\testa\AppData\Roaming\ViberPC
2026-06-07 11:30 - 2023-06-28 08:32 - 000000000 ____D C:\Users\testa\AppData\Local\Dropbox
2026-06-07 11:29 - 2022-05-11 09:51 - 000000000 ____D C:\ProgramData\NVIDIA
2026-06-07 11:29 - 2019-12-07 12:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-06-07 11:28 - 2026-01-15 15:35 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-06-07 11:28 - 2025-08-23 13:22 - 000000000 ____D C:\Program Files\Windscribe
2026-06-07 11:28 - 2022-06-06 17:14 - 000000000 ____D C:\ProgramData\AVG
2026-06-07 11:28 - 2022-05-11 09:48 - 000000000 ____D C:\Intel
2026-06-07 11:28 - 2022-05-11 08:30 - 000008192 ___SH C:\DumpStack.log.tmp
2026-06-07 11:28 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\ServiceState
2026-06-07 00:16 - 2019-12-07 12:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2026-06-07 00:15 - 2023-06-29 17:11 - 000000000 ____D C:\Users\testa\AppData\Local\CrashDumps
2026-06-07 00:14 - 2023-06-30 16:51 - 000000000 ____D C:\Users\testa\AppData\Roaming\vlc
2026-06-06 23:37 - 2026-01-15 15:35 - 000003462 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-06-06 23:37 - 2026-01-15 15:35 - 000003344 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-9367388-606531772-2301354866-1005
2026-06-06 23:37 - 2026-01-15 15:35 - 000003236 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-06-06 23:37 - 2026-01-15 15:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2026-06-06 23:03 - 2026-01-15 15:44 - 000000000 ____D C:\Users\testa\AppData\Local\D3DSCache
2026-06-06 22:39 - 2023-10-16 03:47 - 000000000 ____D C:\Users\testa\AppData\Roaming\Telegram Desktop
2026-06-06 22:32 - 2025-07-01 15:02 - 004216342 _____ C:\WINDOWS\ntbtlog.txt
2026-06-06 22:26 - 2026-01-15 15:29 - 000000000 ____D C:\Users\testa
2026-06-06 22:12 - 2026-01-15 15:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-06-06 21:36 - 2019-12-07 12:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2026-06-06 21:36 - 2019-12-07 12:13 - 000000000 ____D C:\WINDOWS\INF
2026-06-06 21:19 - 2023-06-28 08:30 - 000000000 ____D C:\Users\testa\AppData\Local\AVG
2026-06-06 20:29 - 2022-05-11 09:39 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-06-06 19:38 - 2020-11-19 10:46 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-06-06 19:38 - 2020-11-19 10:46 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-06-06 18:06 - 2026-01-15 15:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2026-06-06 18:06 - 2022-05-11 09:39 - 000001065 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-06-06 16:36 - 2019-12-07 12:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-06-06 16:36 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-06-06 16:34 - 2025-09-20 23:01 - 000000000 ____D C:\Users\testa\AppData\Roaming\obs-studio
2026-06-06 16:34 - 2024-01-20 19:12 - 000000000 ____D C:\Users\testa\AppData\Roaming\discord
2026-06-06 16:33 - 2022-06-08 16:00 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-06-06 16:24 - 2025-05-12 21:53 - 000000000 ____D C:\Users\testa\AppData\Local\Discord
2026-06-05 16:19 - 2025-12-11 11:10 - 000000000 ____D C:\Users\testa\AppData\Roaming\AnyDesk
2026-06-05 15:31 - 2022-05-13 14:09 - 000000000 ____D C:\Users\User\AppData\Local\CrashDumps
2026-06-05 13:45 - 2023-07-06 15:15 - 000000000 ___RD C:\Users\testa\Dropbox
2026-06-04 22:23 - 2019-12-07 12:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2026-06-03 21:49 - 2026-03-16 13:09 - 000000000 ____D C:\Users\testa\Downloads\telegram books
2026-06-03 18:34 - 2023-06-28 08:35 - 000000000 ____D C:\Users\testa\AppData\Roaming\Microsoft\Excel
2026-06-03 10:02 - 2026-01-15 15:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleUserPEH
2026-06-02 13:41 - 2020-11-19 10:48 - 000000000 ____D C:\ProgramData\Packages
2026-06-02 10:13 - 2026-01-15 15:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVG
2026-06-02 10:13 - 2022-06-06 17:14 - 001292896 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgSP.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000911456 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgSnx.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000636512 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgNetHub.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000472672 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000451168 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgbidsdriver.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000315488 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgbidsh.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000294496 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000259160 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgArPot.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000100960 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000087136 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgbuniv.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000071768 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2026-06-02 10:13 - 2022-06-06 17:14 - 000034912 _____ (Gen Digital Inc.) C:\WINDOWS\system32\Drivers\avgKbd.sys
2026-06-02 03:32 - 2025-12-27 18:52 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-06-02 03:32 - 2025-12-27 18:52 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2026-05-30 20:38 - 2023-06-29 16:32 - 000000000 ____D C:\Users\testa\AppData\Roaming\Microsoft\Word
2026-05-29 04:47 - 2025-03-28 15:38 - 000000000 ____D C:\Program Files\Dropbox
2026-05-29 03:38 - 2022-05-13 17:29 - 000000000 ____D C:\ProgramData\Dropbox
2026-05-29 03:37 - 2022-05-13 17:29 - 000000000 ____D C:\Program Files (x86)\Dropbox
2026-05-28 09:55 - 2023-07-14 07:24 - 000000000 ____D C:\Users\testa\AppData\Local\Greenshot
2026-05-27 04:53 - 2019-12-07 12:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-05-22 03:35 - 2026-01-15 15:35 - 000003628 _____ C:\WINDOWS\system32\Tasks\AVG Secure Browser VPS Differential Update
2026-05-22 03:35 - 2023-05-19 14:44 - 000002375 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Secure Browser.lnk
2026-05-22 03:35 - 2023-05-19 14:44 - 000002340 _____ C:\Users\Public\Desktop\AVG Secure Browser.lnk
2026-05-14 12:55 - 2026-05-03 16:44 - 000000000 ____D C:\Users\testa\Downloads\ai
2026-05-14 12:13 - 2022-05-11 09:41 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-05-14 12:09 - 2022-05-11 09:41 - 220340424 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2026-05-08 16:25 - 2022-05-11 09:39 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\MMC

==================== Files in the root of some directories ========

2022-05-26 14:52 - 2022-05-26 14:52 - 000007597 _____ () C:\Users\User\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

  • Автор

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-06-2026

Ran by User (07-06-2026 11:35:33)

Running from C:\Users\testa\Downloads

Microsoft Windows 10 Pro Version 22H2 19045.6456 (X64) (2026-01-15 12:36:32)

Boot Mode: Normal

==========================================================

==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

$BarTender_Security$ (S-1-5-21-9367388-606531772-2301354866-1002 - Limited - Enabled)

Administrator (S-1-5-21-9367388-606531772-2301354866-500 - Administrators - Disabled)

DefaultAccount (S-1-5-21-9367388-606531772-2301354866-503 - Limited - Disabled)

Guest (S-1-5-21-9367388-606531772-2301354866-501 - Limited - Disabled)

testa (S-1-5-21-9367388-606531772-2301354866-1005 - Limited - Enabled) => C:\Users\testa

User (S-1-5-21-9367388-606531772-2301354866-1001 - Administrators - Enabled) => C:\Users\User

WDAGUtilityAccount (S-1-5-21-9367388-606531772-2301354866-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Malwarebytes (Enabled - Up to date) {A537353A-1D6A-F6B5-9153-CE1CF80FBE66}

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AV: AVG Antivirus (Enabled - Up to date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

AdiIRC (HKLM-x32\...\AdiIRC) (Version: 4.4 - Per Amundsen)

AllDup (HKLM-x32\...\AllDup_is1) (Version: 4.5.72 - MTSD)

Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)

Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)

AVG AntiVirus Free (HKLM\...\AVG Antivirus) (Version: 26.5.10994.3659 - Gen Digital Inc.)

AVG Secure Browser (HKLM-x32\...\AVG Secure Browser) (Version: 147.0.34598.118 - Gen Digital Inc.)

AVG Update Helper (HKLM-x32\...\{EDB7AEE7-E932-4836-AE50-D3B0B7766CB5}) (Version: 1.8.1634.4 - AVG Technologies) Hidden

BarTender 2016 R3 UltraLite (HKLM\...\BarTender UltraLite) (Version: 11.0.3094 - Seagull Scientific)

BarTender 2016 R3 UltraLite (HKLM-x32\...\{9B3CA58E-EE90-46E9-8038-EB7753C29703}) (Version: 11.0.3094 - Seagull Scientific) Hidden

CapCut (HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\CapCut) (Version: 4.8.0.1820 - Bytedance Pte. Ltd.)

CapCut (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\CapCut) (Version: 8.2.0.3462 - Bytedance Pte. Ltd.)

CCleaner (HKLM\...\CCleaner) (Version: 6.29 - Piriform)

Discord (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Discord) (Version: 1.0.9240 - Discord Inc.)

Documentation Manager (HKLM\...\{43F79AB0-9ECF-4039-9855-6E930B41A500}) (Version: 24.30.1.1 - Intel Corporation) Hidden

DownloadHelper CoApp (HKLM-x32\...\DownloadHelper CoApp) (Version: 2.0.19.0 - ACLAP)

Dropbox (HKLM-x32\...\Dropbox) (Version: 254.4.2518 - Dropbox, Inc.)

Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.983.1 - Dropbox, Inc.) Hidden

eMule (HKLM-x32\...\eMule) (Version: - )

Everything 1.4.1.1017 (x64) (HKLM\...\Everything) (Version: 1.4.1.1017 - voidtools)

EXScan Pro 3.7.3.0 (HKLM\...\EXScan Pro) (Version: 3.7.3.0 - shining3d, Inc.)

Foxit PDF Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 11.2.2.53575 - Foxit Software Inc.)

GOM Player (HKLM-x32\...\GOM Player) (Version: 2.3.14.5270 - Gretech Corporation)

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 148.0.7778.217 - Google LLC)

Greenshot 1.2.10.6 (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Greenshot_is1) (Version: 1.2.10.6 - Greenshot)

Intel Driver && Support Assistant (HKLM-x32\...\{D2AEE0A6-F202-4C62-BE2B-AC0C9E00A941}) (Version: 26.1.0.2 - Intel) Hidden

Intel(R) Computing Improvement Program (HKLM\...\{2D924248-D4EE-45BA-BDDB-1FA8828CF5CA}) (Version: 2.4.10852 - Intel Corporation)

Intel(R) Graphics Driver Software (HKLM-x32\...\{0703311b-31d5-4c17-9668-c48dee4b7749}) (Version: 3.11.1.0 - Intel) Hidden

Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00001030-0240-1033-84C8-B8D95FA3C8C3}) (Version: 24.30.1.1 - Intel Corporation)

Intel® Driver & Support Assistant (HKLM-x32\...\{C8093AA3-B113-4F81-9A87-B1C41929B346}) (Version: 26.1.0.2 - Intel)

Intel® Software Installer (HKLM\...\{0C6E54F1-6FA0-407F-AB3F-D97A116078D3}) (Version: 24.30.1.1 - Intel Corporation) Hidden

Intel® Software Installer (HKLM-x32\...\{85cb0eee-e264-4335-ac48-f589f2d69657}) (Version: 22.130.0.5 - Intel Corporation) Hidden

K-Lite Codec Pack 16.9.8 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 16.9.8 - KLCP)

Lenovo Legion Toolkit version 2.26.1 (HKLM\...\{0C37B9AC-9C3D-4302-8ABB-125C7C7D83D5}_is1) (Version: 2.26.1 - Bartosz Cichecki)

Lenovo Service Bridge (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1) (Version: 5.0.2.21 - Lenovo)

LINE (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\LINE) (Version: 8.7.0.3302 - LY Corporation)

Malwarebytes version 5.5.7.255 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.5.7.255 - Malwarebytes)

Microsoft .NET Host - 6.0.36 (x64) (HKLM\...\{D6932D97-36F1-40B8-9CDC-CA8365B21000}) (Version: 48.144.23141 - Microsoft Corporation) Hidden

Microsoft .NET Host - 8.0.14 (x86) (HKLM-x32\...\{CB771E25-82B7-435C-B8CF-1DAF85D9A373}) (Version: 64.56.29490 - Microsoft Corporation) Hidden

Microsoft .NET Host - 8.0.15 (x64) (HKLM\...\{4C903F19-B4C3-4D0C-8CC9-D444C511AF1C}) (Version: 64.60.31149 - Microsoft Corporation) Hidden

Microsoft .NET Host FX Resolver - 6.0.36 (x64) (HKLM\...\{A9E32B25-994B-4856-A12B-0EBED3050410}) (Version: 48.144.23141 - Microsoft Corporation) Hidden

Microsoft .NET Host FX Resolver - 8.0.14 (x64) (HKLM\...\{B2E7F2C8-73CD-4269-B7BC-11B7D8BB7A37}) (Version: 64.56.29490 - Microsoft Corporation) Hidden

Microsoft .NET Host FX Resolver - 8.0.14 (x86) (HKLM-x32\...\{455AA7CD-6D99-4039-95D2-FF1A437FD444}) (Version: 64.56.29490 - Microsoft Corporation) Hidden

Microsoft .NET Host FX Resolver - 8.0.15 (x64) (HKLM\...\{11CCC9F6-77AA-4421-9EAC-BAEC36D96817}) (Version: 64.60.31149 - Microsoft Corporation) Hidden

Microsoft .NET Runtime - 6.0.36 (x64) (HKLM\...\{C912E33F-956A-4921-9F55-CC11AE8F09AF}) (Version: 48.144.23141 - Microsoft Corporation) Hidden

Microsoft .NET Runtime - 8.0.14 (x64) (HKLM\...\{6C817CE3-32BC-4C6B-8B1A-E6F71EDAFFCC}) (Version: 64.56.29490 - Microsoft Corporation) Hidden

Microsoft .NET Runtime - 8.0.14 (x64) (HKLM-x32\...\{a6918640-3436-4607-9108-9b6038e680d6}) (Version: 8.0.14.34611 - Microsoft Corporation)

Microsoft .NET Runtime - 8.0.14 (x86) (HKLM-x32\...\{6E39BE88-1272-4732-A962-9B34A31EE12C}) (Version: 64.56.29490 - Microsoft Corporation) Hidden

Microsoft .NET Runtime - 8.0.15 (x64) (HKLM\...\{8731E6E3-AF96-4515-ACEC-DBFB3DF55292}) (Version: 64.60.31149 - Microsoft Corporation) Hidden

Microsoft ASP.NET Core 8.0.14 - Shared Framework (x86) (HKLM-x32\...\{b4843496-41d3-405c-b4c6-2ff39b7609ed}) (Version: 8.0.14.25112 - Microsoft Corporation)

Microsoft ASP.NET Core 8.0.14 Shared Framework (x86) (HKLM-x32\...\{BBD33465-6641-37D3-9444-5CCD7FE71A79}) (Version: 8.0.14.25112 - Microsoft Corporation) Hidden

Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 149.0.4022.52 - Microsoft Corporation)

Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 148.0.3967.96 - Microsoft Corporation) Hidden

Microsoft Office Access MUI (English) 2007 (HKLM-x32\...\{90120000-0015-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Access Setup Metadata MUI (English) 2007 (HKLM-x32\...\{90120000-0117-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Enterprise 2007 (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)

Microsoft Office Excel MUI (English) 2007 (HKLM-x32\...\{90120000-0016-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Groove MUI (English) 2007 (HKLM-x32\...\{90120000-00BA-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Groove Setup Metadata MUI (English) 2007 (HKLM-x32\...\{90120000-0114-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office InfoPath MUI (English) 2007 (HKLM-x32\...\{90120000-0044-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office OneNote MUI (English) 2007 (HKLM-x32\...\{90120000-00A1-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Outlook MUI (English) 2007 (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office PowerPoint MUI (English) 2007 (HKLM-x32\...\{90120000-0018-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Proof (French) 2007 (HKLM-x32\...\{90120000-001F-040C-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Proof (Spanish) 2007 (HKLM-x32\...\{90120000-001F-0C0A-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Proofing (English) 2007 (HKLM-x32\...\{90120000-002C-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Publisher MUI (English) 2007 (HKLM-x32\...\{90120000-0019-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Shared 64-bit MUI (English) 2007 (HKLM\...\{90120000-002A-0409-1000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (HKLM\...\{90120000-0116-0409-1000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Shared MUI (English) 2007 (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Shared Setup Metadata MUI (English) 2007 (HKLM-x32\...\{90120000-0115-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft Office Word MUI (English) 2007 (HKLM-x32\...\{90120000-001B-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden

Microsoft OneDrive (HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\OneDriveSetup.exe) (Version: 25.105.0601.0002 - Microsoft Corporation)

Microsoft OneDrive (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\OneDriveSetup.exe) (Version: 25.127.0701.0006 - Microsoft Corporation)

Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)

Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)

Microsoft SQL Server Compact 4.0 x64 ENU (HKLM\...\{8424B163-D1E0-48B7-88A2-C7A61767B3D7}) (Version: 4.0.8482.1 - Microsoft Corporation)

Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)

Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden

Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden

Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden

Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden

Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33810 (HKLM-x32\...\{5af95fd8-a22e-458f-acee-c61bd787178e}) (Version: 14.40.33810.0 - Microsoft Corporation)

Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810 (HKLM-x32\...\{47109d57-d746-4f8b-9618-ed6a17cc922b}) (Version: 14.40.33810.0 - Microsoft Corporation)

Microsoft Visual C++ 2022 X64 Additional Runtime - 14.40.33810 (HKLM\...\{59CED48F-EBFE-480C-8A38-FC079C2BEC0F}) (Version: 14.40.33810 - Microsoft Corporation) Hidden

Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.40.33810 (HKLM\...\{B8B3BB4A-A10D-4F51-91B7-A64FFAC31EA7}) (Version: 14.40.33810 - Microsoft Corporation) Hidden

Microsoft Visual C++ 2022 X86 Additional Runtime - 14.40.33810 (HKLM-x32\...\{5EA6C998-D5AC-4ED9-89C3-9F25B17CCD3D}) (Version: 14.40.33810 - Microsoft Corporation) Hidden

Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.40.33810 (HKLM-x32\...\{0C3457A0-3DCE-4A33-BEF0-9B528C557771}) (Version: 14.40.33810 - Microsoft Corporation) Hidden

Microsoft Windows Desktop Runtime - 6.0.36 (x64) (HKLM\...\{61D4736B-3325-4D4A-BD41-8BD206C6A86E}) (Version: 48.144.23186 - Microsoft Corporation) Hidden

Microsoft Windows Desktop Runtime - 6.0.36 (x64) (HKLM-x32\...\{0532b8f2-12d7-43de-95fc-7b87006758a8}) (Version: 6.0.36.34217 - Microsoft Corporation)

Microsoft Windows Desktop Runtime - 8.0.14 (x86) (HKLM-x32\...\{F12CDBC1-172E-4413-829C-B5234E386262}) (Version: 64.56.29521 - Microsoft Corporation) Hidden

Microsoft Windows Desktop Runtime - 8.0.14 (x86) (HKLM-x32\...\{f70d61fa-5d61-4582-bf8d-07dec8e4fcda}) (Version: 8.0.14.34613 - Microsoft Corporation)

Microsoft Windows Desktop Runtime - 8.0.15 (x64) (HKLM\...\{0E4A7820-FDA4-4250-B7AC-E7A2F7B43B64}) (Version: 64.60.31203 - Microsoft Corporation) Hidden

Microsoft Windows Desktop Runtime - 8.0.15 (x64) (HKLM-x32\...\{5625bb48-295c-4113-bc92-d6a69b19b04c}) (Version: 8.0.15.34718 - Microsoft Corporation)

Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox) (Version: 151.0.3 - Mozilla)

Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 100.0 - Mozilla)

Node.js (HKLM\...\{1B257839-6CC3-4882-B2C2-E4C0E70B97EF}) (Version: 24.14.1 - Node.js Foundation)

Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 8.8.8 - Notepad++ Team)

NVIDIA FrameView SDK 1.3.8513.32290073 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8513.32290073 - NVIDIA Corporation)

NVIDIA GeForce Experience 3.27.0.120 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.27.0.120 - NVIDIA Corporation)

NVIDIA Graphics Driver 551.86 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 551.86 - NVIDIA Corporation)

NVIDIA HD Audio Driver 1.3.40.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.40.14 - NVIDIA Corporation)

NVIDIA PhysX System Software 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation)

OBS Studio (HKLM-x32\...\OBS Studio) (Version: 32.0.4 - OBS Project)

oCam version 550.0 (HKLM-x32\...\oCam_is1) (Version: 550.0 - hxxp://ohsoft.net/)

Python 3.12.0 (64-bit) (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\{cf9c4d97-48a7-4a27-b9fc-91b88a803c40}) (Version: 3.12.150.0 - Python Software Foundation)

Python 3.12.0 Add to Path (64-bit) (HKLM\...\{380DEEDA-4227-4F0E-9F7C-34C75649DE59}) (Version: 3.12.150.0 - Python Software Foundation) Hidden

Python 3.12.0 Core Interpreter (64-bit) (HKLM\...\{6B58F6F9-656A-4CC4-8BAB-22177BFFA45F}) (Version: 3.12.150.0 - Python Software Foundation) Hidden

Python 3.12.0 Development Libraries (64-bit) (HKLM\...\{225BAA2C-BDCA-4D63-9D72-D92CE5E2421D}) (Version: 3.12.150.0 - Python Software Foundation) Hidden

Python 3.12.0 Documentation (64-bit) (HKLM\...\{5DF0B8D8-4E7F-43EB-AD16-30FFA931A905}) (Version: 3.12.150.0 - Python Software Foundation) Hidden

Python 3.12.0 Executables (64-bit) (HKLM\...\{575EC8EB-A481-4CF1-BAB0-3C1DBD2E50A7}) (Version: 3.12.150.0 - Python Software Foundation) Hidden

Python 3.12.0 pip Bootstrap (64-bit) (HKLM\...\{24B8988D-E785-4124-BF77-1DC6A3E62050}) (Version: 3.12.150.0 - Python Software Foundation) Hidden

Python 3.12.0 Standard Library (64-bit) (HKLM\...\{14BBD330-AA3F-4F7A-8A39-DFB28AECFA82}) (Version: 3.12.150.0 - Python Software Foundation) Hidden

Python 3.12.0 Tcl/Tk Support (64-bit) (HKLM\...\{6EAF677E-4EE8-4A22-9781-9131C5298D26}) (Version: 3.12.150.0 - Python Software Foundation) Hidden

Python 3.12.0 Test Suite (64-bit) (HKLM\...\{0A9B38A7-D393-44A5-A94E-9FEC927DC39C}) (Version: 3.12.150.0 - Python Software Foundation) Hidden

Python 3.13.7 (64-bit) (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\{9a46f6d0-8f11-4f8f-a23d-d617db01bbb6}) (Version: 3.13.7150.0 - Python Software Foundation)

Python 3.13.7 Add to Path (64-bit) (HKLM\...\{235C9435-3313-4658-881D-5A7E559A5A41}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden

Python 3.13.7 Core Interpreter (64-bit) (HKLM\...\{BE75E968-78F4-411D-92E4-73EC3043F7E4}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden

Python 3.13.7 Development Libraries (64-bit) (HKLM\...\{96A23710-E014-4A5B-96A1-DE64AC37251B}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden

Python 3.13.7 Documentation (64-bit) (HKLM\...\{CFAAA24B-16EF-4D9D-80A5-F67798771571}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden

Python 3.13.7 Executables (64-bit) (HKLM\...\{E4047598-558F-4468-8B53-9FCEF7F86E0D}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden

Python 3.13.7 pip Bootstrap (64-bit) (HKLM\...\{CD31E178-F872-466B-A231-9C8AA53A89FD}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden

Python 3.13.7 Standard Library (64-bit) (HKLM\...\{A139F43E-8105-465D-AC80-28F349CBE08D}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden

Python 3.13.7 Tcl/Tk Support (64-bit) (HKLM\...\{A65B1339-6492-4CA4-AEB5-2B25A83A20B9}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden

Python 3.13.7 Test Suite (64-bit) (HKLM\...\{6BD2B618-9A2B-47D9-B24B-2F05BD2768E4}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden

Python Launcher (HKLM-x32\...\{3182A195-B671-44A8-B0C7-7876B916BA5A}) (Version: 3.12.150.0 - Python Software Foundation)

qBittorrent 4.4.2 (HKLM-x32\...\qBittorrent) (Version: 4.4.2 - The qBittorrent project)

QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)

Revo Uninstaller 2.6.5 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.6.5 - VS Revo Group, Ltd.)

Skype version 8.83 (HKLM-x32\...\Skype_is1) (Version: 8.83 - Skype Technologies S.A.)

Sophos Anti-Rootkit 1.5.4 (HKLM-x32\...\Sophos-AntiRootkit) (Version: 1.5.4 - Sophos Plc)

SumatraPDF (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\SumatraPDF) (Version: 3.4.6 - Krzysztof Kowalczyk)

TC2000 (HKLM-x32\...\{A6A526E4-A376-4772-897D-508FB2473C91}) (Version: 1.0.0 - Worden Brothers, Inc.) Hidden

TC2000 (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\TC2000 1.0.0) (Version: 1.0.0 - Worden Brothers, Inc.)

TeamSpeak (HKLM\...\{B7D44529-BA9C-41B4-9060-84E9B1BDA99E}) (Version: 5.0.0 - TeamSpeak)

TeamViewer (HKLM\...\TeamViewer) (Version: 15.33.7 - TeamViewer)

Telegram Desktop (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 6.8.2 - Telegram FZ-LLC)

Telegram Desktop version 4.1.1 (HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.1.1 - Telegram FZ-LLC)

Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)

Viber (HKLM\...\{EF02950C-232E-4FD6-BF1A-9CAD88151CE2}) (Version: 23.5.1.0 - 2010-2024 Viber Media S.a.r.l) Hidden

Viber (HKLM-x32\...\{4A0AF314-75C4-4744-9238-4E4C57A2AA43}) (Version: 17.5.1.11 - Viber Media S.a.r.l) Hidden

Viber (HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\{11d4fb26-38b2-4224-982d-241fedf611e4}) (Version: 17.5.1.11 - 2010-2022 Viber Media S.a.r.l)

Viber (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\{05077BC6-E842-48C1-BDB5-2D7233F677E3}) (Version: 28.0.0.0 - 2010-2024 Viber Media S.a.r.l)

VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)

Waterfox Classic 56.6 (x64 en-US) (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\Waterfox Classic 56.6 (x64 en-US)) (Version: 56.6 - Waterfox Ltd)

WebAdvisor by McAfee (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.1054 - McAfee, LLC)

Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)

Windscribe (HKLM\...\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1) (Version: 2.16.14 - Windscribe Limited)

WinMerge 2.16.48.2 x64 (HKLM\...\WinMerge_is1) (Version: 2.16.48.2 - Thingamahoochie Software)

WinRAR 6.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH)

Zoom Workplace (HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\ZoomUMX) (Version: 6.7.8 (32670) - Zoom Communications, Inc.)

Packages:

=========

Dolby Atmos for Gaming -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAtmosforGaming_3.20800.804.0_x64__rz1tebttyb220 [2024-09-08] (Dolby Laboratories)

Dropbox -> C:\Program Files (x86)\Dropbox\Client\PackageAssets [2026-05-29] (Dropbox Inc.)

Intel® Graphics Command Center -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2025-12-25] (INTEL CORP) [Startup Task]

NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2025-12-25] (NVIDIA Corp.)

Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.12.219.0_x64__dt26b99r8h8gj [2024-09-08] (Realtek Semiconductor Corp)

Spotify - Music and Podcasts -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0 [2025-12-25] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1001_Classes\CLSID\{72F6A03F-7B17-4E65-AE37-666FC9024FA2}\InprocServer32 -> C:\ProgramData\AllDup\KuShellExtension64.dll (Michael Thummerer -> )

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\User\Dropbox [2022-05-13 17:30]

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{5C4D8D77-5B87-40CA-884E-F56858227E5C}\localserver32 -> C:\Users\testa\AppData\Local\Programs\TeamSpeak\notification_helper.exe => No File

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\testa\Dropbox [2023-07-06 15:15]

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{F92F1811-5523-4EEC-B5A6-FE628430400C}\localserver32 -> "C:\Program Files\Cavalry\Cavalry.exe" -ToastActivated => No File

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{F991C179-01ED-4BF3-9192-45994D0C7F0B} -> [Dropbox] => C:\Users\testa\Dropbox [2023-07-06 15:15]

ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2210608 2006-10-26] (Microsoft Corporation -> Microsoft Corporation)

ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)

ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP3\System\aimp_menu64.dll -> No File

ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)

ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ContextMenuHandlers1: [WinMerge] -> {4E716236-AA30-4C65-B225-D68BBA81E9C2} => C:\Program Files\WinMerge\ShellExtensionX64.dll [2023-02-27] (Takashi Sawanaka -> hxxps://winmerge.org)

ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)

ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)

ContextMenuHandlers2: [WinMerge] -> {4E716236-AA30-4C65-B225-D68BBA81E9C2} => C:\Program Files\WinMerge\ShellExtensionX64.dll [2023-02-27] (Takashi Sawanaka -> hxxps://winmerge.org)

ContextMenuHandlers3: [00avg] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)

ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-06-06] (Malwarebytes Inc -> Malwarebytes)

ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP3\System\aimp_menu64.dll -> No File

ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ContextMenuHandlers4: [WinMerge] -> {4E716236-AA30-4C65-B225-D68BBA81E9C2} => C:\Program Files\WinMerge\ShellExtensionX64.dll [2023-02-27] (Takashi Sawanaka -> hxxps://winmerge.org)

ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.93.0.dll [2026-05-27] (Dropbox, Inc -> Dropbox, Inc.)

ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvltig.inf_amd64_c81552b0afd57b24\nvshext.dll [2024-03-13] (NVIDIA Corporation -> NVIDIA Corporation)

ContextMenuHandlers5: [WinMerge] -> {4E716236-AA30-4C65-B225-D68BBA81E9C2} => C:\Program Files\WinMerge\ShellExtensionX64.dll [2023-02-27] (Takashi Sawanaka -> hxxps://winmerge.org)

ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShell.dll [2026-06-02] (Gen Digital Inc. -> Gen Digital Inc.)

ContextMenuHandlers6: [Fast Explorer] -> {693BE9C0-BEC3-11D2-B4C1-C33BBD3AD64B} => C:\ProgramData\AllDup\FEShlExt.dll [2008-08-20] (Alex Yakovlev) [File not signed]

ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-06-06] (Malwarebytes Inc -> Malwarebytes)

ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)

ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2022-03-03] (win.rar GmbH -> Alexander Roshal)

ContextMenuHandlers1_S-1-5-21-9367388-606531772-2301354866-1001: [!!KuShellExtension-{72F6A03F-7B17-4E65-AE37-666FC9024FA2}] -> {72F6A03F-7B17-4E65-AE37-666FC9024FA2} => C:\ProgramData\AllDup\KuShellExtension64.dll [2023-03-04] (Michael Thummerer -> )

ContextMenuHandlers2_S-1-5-21-9367388-606531772-2301354866-1001: [!!KuShellExtension-{72F6A03F-7B17-4E65-AE37-666FC9024FA2}] -> {72F6A03F-7B17-4E65-AE37-666FC9024FA2} => C:\ProgramData\AllDup\KuShellExtension64.dll [2023-03-04] (Michael Thummerer -> )

ContextMenuHandlers4_S-1-5-21-9367388-606531772-2301354866-1001: [!!KuShellExtension-{72F6A03F-7B17-4E65-AE37-666FC9024FA2}] -> {72F6A03F-7B17-4E65-AE37-666FC9024FA2} => C:\ProgramData\AllDup\KuShellExtension64.dll [2023-03-04] (Michael Thummerer -> )

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\User\Dropbox\__For watermark\Нов пряк път.lnk -> [LF^R1SPSOh+'!Bobi@y] <==== Cyrillic

==================== Loaded Modules (Whitelisted) =============

2017-03-02 15:19 - 2017-03-02 15:19 - 000310272 ____N (easyhook.codeplex.com) [File not signed] C:\ProgramData\Dolby\DAX3\RADARHOST\EasyHook64.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\testa\Downloads\FRST64.exe:MBAM.Zone.Identifier [225]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\avgSP.sys => ""="Driver"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avgSP.sys => ""="Driver"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-12-07 12:14 - 2019-12-07 12:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.0.1

Windows Firewall is enabled.

Network Binding:

=============

Bluetooth Network Connection: Bluetooth Device (Personal Area Network) -> bthpan.sys

Wi-Fi: Intel(R) Wi-Fi 6 AX201 160MHz -> Netwtw10.sys

Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-9367388-606531772-2301354866-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\11396683874064380313\133769848703065549.jpg

HKU\S-1-5-21-9367388-606531772-2301354866-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\testa\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\12135839608905123712\134144089068284814.jpg

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)

HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)

HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "Everything"

HKLM\...\StartupApproved\Run32: => "GrooveMonitor"

HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\StartupApproved\Run: => "OneDrive"

HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"

HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\StartupApproved\Run: => "NoxMultiPlayer"

HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\StartupApproved\Run: => "AVGBrowserAutoLaunch_8F351DF0CEE308805CB145B9E3DA56ED"

HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\StartupApproved\Run: => "OneDrive"

HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\StartupApproved\Run: => "CCleaner Smart Cleaning"

HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_D9BC01DA7EE888E155CFF65CFCDDE7EC"

HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\StartupApproved\Run: => "Discord"

HKU\S-1-5-21-9367388-606531772-2301354866-1005\...\StartupApproved\Run: => "Skype for Desktop"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{670A445C-7CFC-468F-9059-1528833CC866}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{64B1C219-4B8B-4202-9510-894FDF440D18}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{93761A40-C8C3-46D6-B137-776764D8AAC2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{CD050A3C-02CF-45D0-90DC-029F0E4A1621}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{B4710D89-1D4D-48FE-B03B-018B1A4A6E11}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{C2049493-AC1A-46A1-8B63-D752CD69A538}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{FC52AC97-0177-4C18-8D8B-4C07846132B8}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{EDA98328-A6E4-47AE-BAA6-D8C7E9E3B8DA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{D4EBDD53-0975-42F3-8351-8BFB20C6EDBC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{FF54DEAD-9767-4755-97FB-17A5ED29F9B2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{7974CC06-F8B4-4BB8-B0EC-0F55BACB0C2F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{A0B2D2A4-CF8A-4E35-A5AD-BCF7BF205A05}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{9E15055C-2D51-4C72-9131-49C2CD25C882}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.279.427.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [UDP Query User{0DB0CCA0-1FBF-4EBF-A438-47C067C57AFC}C:\users\testa\downloads\anydesk.exe] => (Allow) C:\users\testa\downloads\anydesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)

FirewallRules: [TCP Query User{818BA730-41C1-4169-B0E6-85C65D71E6CF}C:\users\testa\downloads\anydesk.exe] => (Allow) C:\users\testa\downloads\anydesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)

FirewallRules: [UDP Query User{300CE609-4861-4642-950B-E8A3BC19AA3C}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)

FirewallRules: [TCP Query User{26376489-B372-4B71-A5B3-A2412EFE429E}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)

FirewallRules: [UDP Query User{2D035788-F4F9-4D90-9797-8D9AFF62736E}C:\users\testa\appdata\roaming\telegram desktop\telegram.exe] => (Allow) C:\users\testa\appdata\roaming\telegram desktop\telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)

FirewallRules: [TCP Query User{1BA35CFC-2DA2-4C53-AAD4-F5225AF4F763}C:\users\testa\appdata\roaming\telegram desktop\telegram.exe] => (Allow) C:\users\testa\appdata\roaming\telegram desktop\telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)

FirewallRules: [UDP Query User{7576C5FC-2309-42F6-82DB-3F3C0C7EAEC8}C:\program files\adiirc\adiirc.exe] => (Allow) C:\program files\adiirc\adiirc.exe (AdiIRC.com) [File not signed]

FirewallRules: [TCP Query User{49CA66E1-2421-444F-A9B8-93ACB8DF98C2}C:\program files\adiirc\adiirc.exe] => (Allow) C:\program files\adiirc\adiirc.exe (AdiIRC.com) [File not signed]

FirewallRules: [UDP Query User{78E16DEC-4DE0-4431-AC36-0E2383A9BD96}C:\program files (x86)\mirc\mirc.exe] => (Allow) C:\program files (x86)\mirc\mirc.exe => No File

FirewallRules: [TCP Query User{8E7868B4-80FD-4B55-9750-8B271868ED86}C:\program files (x86)\mirc\mirc.exe] => (Allow) C:\program files (x86)\mirc\mirc.exe => No File

FirewallRules: [{D8FF8BE4-E3EE-4F49-8610-E1436A9D71DF}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe (Apple Inc. -> Apple Inc.)

FirewallRules: [UDP Query User{9C5A0112-156D-4F22-88F3-7779450AABAE}C:\program files (x86)\blackmagic design\davinci control panels\setup utility\davinci control panels setup.exe] => (Allow) C:\program files (x86)\blackmagic design\davinci control panels\setup utility\davinci control panels setup.exe => No File

FirewallRules: [TCP Query User{82E8F5BD-3891-4826-9A84-1AE9B1E3C17D}C:\program files (x86)\blackmagic design\davinci control panels\setup utility\davinci control panels setup.exe] => (Allow) C:\program files (x86)\blackmagic design\davinci control panels\setup utility\davinci control panels setup.exe => No File

FirewallRules: [UDP Query User{6F2D42F5-14BB-48E2-9C0C-DA64F34BFAB4}C:\users\testa\appdata\local\discord\app-1.0.9153\discord.exe] => (Block) C:\users\testa\appdata\local\discord\app-1.0.9153\discord.exe => No File

FirewallRules: [TCP Query User{E9CAE959-E682-44CC-9A81-07BEF8EA6461}C:\users\testa\appdata\local\discord\app-1.0.9153\discord.exe] => (Block) C:\users\testa\appdata\local\discord\app-1.0.9153\discord.exe => No File

FirewallRules: [UDP Query User{E3C0F183-5CAB-4B40-B076-C8AEADFFE486}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)

FirewallRules: [TCP Query User{FCC4E01B-2CC6-46FF-8FAC-7EDACD6EDB51}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)

FirewallRules: [{680B3DEC-82F2-46A6-95CB-00D4812EFBC0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)

FirewallRules: [{40261F03-F9A0-4528-BC4A-997CC596E0DE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)

FirewallRules: [{DA7F71A2-FAE0-4B84-9779-BA039C3FF6A3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)

FirewallRules: [{08508FC5-C9F3-4846-9C93-D3DBFC062D1A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)

FirewallRules: [{CEB81090-1E74-44AE-85A2-C0BE3027D810}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)

FirewallRules: [{8223F70A-B947-4422-B6BA-3820E72649F0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)

FirewallRules: [UDP Query User{19663960-9EA3-4C0A-86B7-E99133A3D604}C:\users\testa\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\testa\appdata\roaming\zoom\bin\zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)

FirewallRules: [TCP Query User{0119FF4A-52EA-467A-B284-A07ABE9C07B6}C:\users\testa\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\testa\appdata\roaming\zoom\bin\zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)

FirewallRules: [{E27AABC4-A13D-4AE2-A5B6-1F375B16A857}] => (Allow) C:\Program Files (x86)\Bignox\BigNoxVM\RT\NoxVMHandle.exe => No File

FirewallRules: [{724120F6-284C-42ED-856A-A13E70B6F8A5}] => (Allow) D:\Program Files\Nox\bin\Nox.exe => No File

FirewallRules: [UDP Query User{29F75DC7-1B48-4EB0-B0C0-2FE6A3D6CB9E}C:\users\testa\appdata\local\viber\viber.exe] => (Block) C:\users\testa\appdata\local\viber\viber.exe (Viber Media S.a r.l. -> Viber Media S.à r.l.)

FirewallRules: [TCP Query User{E012015C-0C37-4118-8292-170D44C75397}C:\users\testa\appdata\local\viber\viber.exe] => (Block) C:\users\testa\appdata\local\viber\viber.exe (Viber Media S.a r.l. -> Viber Media S.à r.l.)

FirewallRules: [{A0619E64-AB00-41D2-80AF-CE266F78F622}] => (Allow) LPort=5130

FirewallRules: [{EEA5ABC4-B9C7-4C82-983C-B4BE2572D482}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)

FirewallRules: [{193CE2A7-2156-4B34-A719-C8569AF4E0A2}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)

FirewallRules: [{1F3F9732-D6B8-4F13-9F35-C17F3583C025}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)

FirewallRules: [{A063B207-F4E6-48D7-BE4F-D61730EA4509}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)

FirewallRules: [{E2C7F66F-644D-4DE6-9D0F-DE6AE30F0929}] => (Allow) C:\Program Files\AVG\Antivirus\AVGUI.exe (Gen Digital Inc. -> Gen Digital Inc.)

FirewallRules: [{5C46B461-5B49-48AC-8484-A11A26A30088}] => (Allow) C:\Program Files\AVG\Antivirus\AVGUI.exe (Gen Digital Inc. -> Gen Digital Inc.)

FirewallRules: [UDP Query User{8CB210AD-F52C-41B5-84DA-D367257BC9B3}C:\shining3d\exscanpro\sn3dcommunity.exe] => (Allow) C:\shining3d\exscanpro\sn3dcommunity.exe (先临三维科技股份有限公司 -> )

FirewallRules: [TCP Query User{E57663E1-75DD-4281-84B4-7E33D1F10C4C}C:\shining3d\exscanpro\sn3dcommunity.exe] => (Allow) C:\shining3d\exscanpro\sn3dcommunity.exe (先临三维科技股份有限公司 -> )

FirewallRules: [UDP Query User{11F4C91E-981D-4B01-85C0-E62FFFBCDD2C}C:\shining3d\exscanpro\scanhub.exe] => (Allow) C:\shining3d\exscanpro\scanhub.exe (先临三维科技股份有限公司 -> )

FirewallRules: [TCP Query User{59B9A3BB-2B85-4245-83BB-44274EFB48DB}C:\shining3d\exscanpro\scanhub.exe] => (Allow) C:\shining3d\exscanpro\scanhub.exe (先临三维科技股份有限公司 -> )

FirewallRules: [{CA8D6D15-AA8A-43B6-8D66-017FD4B7654B}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)

FirewallRules: [{8F0E8812-48A9-4271-ACA5-CDB836111678}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)

FirewallRules: [{D31ECAE9-499A-4DA1-871D-F777B3AD9F33}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]

FirewallRules: [{9AD9E227-D5A8-4152-AACA-CBCF9D16817C}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe (The qBittorrent Project) [File not signed]

FirewallRules: [{FED373F5-7A77-4157-83D4-356FA7E4EF06}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)

FirewallRules: [{63597FE6-C783-4E35-801E-68B124FBE88C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)

FirewallRules: [TCP Query User{0ECB10D4-1200-4972-BEFA-E3359F3D05E2}C:\program files (x86)\emule\emule.exe] => (Allow) C:\program files (x86)\emule\emule.exe (hxxp://www.emule-project.net) [File not signed]

FirewallRules: [UDP Query User{3A0C58C1-532F-4C37-A235-F7D6214367B1}C:\program files (x86)\emule\emule.exe] => (Allow) C:\program files (x86)\emule\emule.exe (hxxp://www.emule-project.net) [File not signed]

FirewallRules: [{4BA1E0CA-9390-4F86-9CCA-3FC2E5E74C31}] => (Allow) C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe (Gen Digital Inc. -> Gen Digital Inc.)

FirewallRules: [{2AD2E2C9-27BF-449C-9E03-1409B4178EBB}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)

FirewallRules: [{0027D026-01E3-4929-A636-7F91ECCD48F2}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)

FirewallRules: [{7279FC7F-B05F-490A-A549-8DCBCD7AF90C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{0450A2F1-16C4-40AA-8642-78C2DEAD70B5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{AAEFA480-9F10-49C2-B9E6-E56D168CB290}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{ABD42412-694F-458D-8D4C-52526CFB94D3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{8EE0F9E2-E953-46E6-8249-7728D11E921F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{6E1771C1-D19A-4370-924B-BB9FA0E610FB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{0CFA0C70-34EF-45B3-91A5-763F368E1C5E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{DF82D0AC-7254-4B39-97C7-A693378537A4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{FC5E750F-AB9D-4749-BBA9-109082D2DC3F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{EA6A1795-C4B3-403D-A26B-DDB1A2595568}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{4975AF8E-AAD2-440F-AED2-464495CD9A8B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{07FDF77D-8C3C-4B49-9F7E-461156B61BC5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{31698AF8-A3EF-4320-B5B0-17B6C04DC4A7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.290.451.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

FirewallRules: [{9A04AEB7-FF4F-4AFD-9FC2-C474277C27D9}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

01-06-2026 14:11:21 Scheduled Checkpoint

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:

==================

Error: (06/07/2026 12:16:06 AM) (Source: VSS) (EventID: 8193) (User: )

Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x8007045b, A system shutdown is in progress..

Error: (06/07/2026 12:16:06 AM) (Source: VSS) (EventID: 13) (User: )

Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]

Error: (06/07/2026 12:14:38 AM) (Source: Application Hang) (EventID: 1002) (User: )

Description: The program chrome.exe version 148.0.7778.217 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 9b0

Start Time: 01dcf5ebfd514f81

Termination Time: 4294967295

Application Path: C:\Program Files\Google\Chrome\Application\chrome.exe

Report Id: 0a78327e-b2c4-4063-ad26-425641017707

Faulting package full name:

Faulting package-relative application ID:

Hang type: Top level window is idle

Error: (06/06/2026 10:26:23 PM) (Source: VSS) (EventID: 13) (User: )

Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]

Error: (06/06/2026 08:28:16 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: Telegram.exe, version: 6.8.2.0, time stamp: 0x6a02e11c

Faulting module name: Telegram.exe, version: 6.8.2.0, time stamp: 0x6a02e11c

Exception code: 0xc0000005

Fault offset: 0x00000000003d0975

Faulting process id: 0x27cc

Faulting application start time: 0x01dcf5d961dde3a3

Faulting application path: C:\Users\testa\AppData\Roaming\Telegram Desktop\Telegram.exe

Faulting module path: C:\Users\testa\AppData\Roaming\Telegram Desktop\Telegram.exe

Report Id: 67acd41e-2882-44ed-9540-99e0f43e6fe3

Faulting package full name:

Faulting package-relative application ID:

Error: (06/06/2026 08:25:20 PM) (Source: DbxSvc) (EventID: 322) (User: )

Description: Failed to get driver message: (-2147024890) The handle is invalid.

Error: (06/06/2026 08:20:47 PM) (Source: Application Hang) (EventID: 1002) (User: )

Description: The program chrome.exe version 148.0.7778.217 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: c34

Start Time: 01dcf5cbccbfa326

Termination Time: 4294967295

Application Path: C:\Program Files\Google\Chrome\Application\chrome.exe

Report Id: b90d736d-f9fc-468f-9ee3-7b4e431d4269

Faulting package full name:

Faulting package-relative application ID:

Hang type: Top level window is idle

Error: (06/06/2026 06:14:44 PM) (Source: DbxSvc) (EventID: 322) (User: )

Description: Failed to get driver message: (-2147024890) The handle is invalid.

System errors:

=============

Error: (06/07/2026 11:33:55 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801) (User: NT AUTHORITY)

Description: Secure Boot CA/keys need to be updated. This device signature information is included here.

DeviceAttributes: FirmwareVersion:EFCN52WW;OEMManufacturerName:LENOVO;OEMModelSKU:LENOVO_MT_81Y8_BU_idea_FM_Legion 5 17IMH05H;OSArchitecture:amd64;

BucketId: 0de0d255ce44f11a247a3bf8329c706d8fce6367eb7c85295bf165ace16eac75

BucketConfidenceLevel:

UpdateType: 0

HResult: 0

Error: (06/07/2026 11:28:54 AM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The cplspcon service terminated with the following error:

Unspecified error

Error: (06/07/2026 11:28:48 AM) (Source: ACPI) (EventID: 13) (User: )

Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

Error: (06/07/2026 11:28:48 AM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY)

Description: The device driver for the Trusted Platform Module (TPM) encountered a non-recoverable error in the TPM hardware, which prevents TPM services (such as data encryption) from being used. For further help, please contact the computer manufacturer.

Error: (06/07/2026 12:16:01 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-J190OJ1)

Description: The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.

Error: (06/07/2026 12:05:38 AM) (Source: disk) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Harddisk1\DR1.

Error: (06/06/2026 11:46:53 PM) (Source: Netwtw10) (EventID: 5005) (User: )

Description: Intel(R) Wi-Fi 6 AX201 160MHz : Has encountered an internal error and has failed.

5005 - Driver internal error

Error: (06/06/2026 11:46:53 PM) (Source: Netwtw10) (EventID: 5002) (User: )

Description: Intel(R) Wi-Fi 6 AX201 160MHz : Has determined that the network adapter is not functioning properly.

5002 - uCode SW error (SysAssert, NMI)

CodeIntegrity:

===============

Date: 2026-06-07 11:36:56

Description:

Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.

==================== Memory info ===========================

BIOS: LENOVO EFCN52WW 07/27/2021

Motherboard: LENOVO LNVNB161216

Processor: Intel(R) Core(TM) i7-10750H CPU @ 2.60GHz

Percentage of memory in use: 73%

Total physical RAM: 16291.79 MB

Available physical RAM: 4382.99 MB

Total Virtual: 24113.3 MB

Available Virtual: 10377.14 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:243.28 GB) (Free:6.14 GB) (Model: UMIS RPITJ512VME2OWD) NTFS

Drive d: () (Fixed) (Total:232.8 GB) (Free:2.44 GB) (Model: UMIS RPITJ512VME2OWD) NTFS

Drive e: (My Book) (Fixed) (Total:3725.99 GB) (Free:40.23 GB) (Model: WD My Book 1230 USB Device) NTFS

\\?\Volume{d9fa2484-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.05 GB) (Free:0.02 GB) NTFS

\\?\Volume{d9fa2484-0000-0000-0000-f0d43c000000}\ () (Fixed) (Total:0.81 GB) (Free:0.08 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================

Disk: 0 (MBR Code: Windows 7/8/10) (Size: 476.9 GB) (Disk ID: D9FA2484)

Partition 1: (Active) - (Size=50 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=243.3 GB) - (Type=07 NTFS)

Partition 3: (Not Active) - (Size=833 MB) - (Type=27)

Partition 4: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)

Attempted reading MBR returned 0 bytes.

Could not read MBR for disk 1.

==================== End of Addition.txt =======================

Проблема в случая е, че диск 1 вероятно си занимава. Силно препоръчвам бекъп на данните от този диск. (Май е този My Book).

Attempted reading MBR returned 0 bytes.
Could not read MBR for disk 1.

Самите лог файлове не съдържат активни зловредни програми. Но има остатъци за почистване.

Отворете Edge. Въведете в адресната лента: edge://settings/profiles/sync

Временно спрете синхронизацията за Extensions като преместите плъзгача наляво.

Сега въведете edge://extensions

Премахнете добавката

Online Security

Затворете Edge.

Деинсталирайте McAfee WebAdvisor и Sophos Anti-Rootkit 1.5.4

Изтеглете прикачения файл. fixlist.txt

Копирайте го в папката в която се намира FRST64.exe.

Стартирайте FRST64.exe и натиснете бутона FIX веднъж.

Инструмента ще започне работа (също ще изтегли и сканира системата с AdwCleaner, Hitman Pro и Emsisoft Emergency Kit). Това е преднамерено!

След като приключи, системата ще се рестартира. След рестарта ще се появи лог файла в папката, в която се съхранява FRST64.exe (би трябвало да се отвори веднага след стартиране на Windows). Прикачете лог файла с името Fixlog.txt.

Поздрави!

  • Автор

Деинсталирах McAfee WebAdvisor и Sophos Anti-Rootkit 1.5.4

Не виждам добавка в EDGE , на името Online Security.

Синхронизацията си беше изцяло спряна от начало, и няма toggle който да плъзна в edge://settings/profiles/sync

2026-06-07 21_26_35-WebAdvisor Uninstaller.png

Странно, защото се вижда в логовете, но така или иначе аз съм го въвел за премахване в скрипта.

Edge Extension: (Online Security) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl [2025-12-25]

На Reason е:

https://microsoftedge.microsoft.com/addons/detail/online-security/jcpgbnbdnakoblgfkbgggankeidkfcdl

Този файл, ако си го стартирал, може да ти е 'откраднал' паролите от браузърите. Ако дефендър или антивирусната не го е спряла, най-добре си смени всички пароли на всички акаунти и си активирай двуфакторната аутентикация. На мен наскоро едно подобно ми открадна паролите и постоянно получавах мейли за различни акаунти, че няко е влязал или се опитва да влезе някъде.

преди 3 часа, Raze написа:

Този файл, ако си го стартирал, може да ти е 'откраднал' паролите от браузърите. Ако дефендър или антивирусната не го е спряла, най-добре си смени всички пароли на всички акаунти и си активирай двуфакторната аутентикация. На мен наскоро едно подобно ми открадна паролите и постоянно получавах мейли за различни акаунти, че няко е влязал или се опитва да влезе някъде.

Това се казва прави при заключителните думи, защото пароли се сменят при почистена система иначе файда от смяната им. Разбира се може да се сменят и от друга чиста система, но така или иначе щях да го спомена. А и най-вероятно вече щяха да са се усетили и да има опити за логвания и известия от доставчиците на съответните услуги. То в момента други бацили освен крадци на данни, троянци за отдалечен достъп, криптиращи изнудвачи, миньори/копачи и чат пак някой адуер няма. В смисъл по-малко са червеите, usb заразите и файловите инфектори. 99% са infostealers/rats/backdoors.

  • 2 седмици по-късно...
  • Автор

Fix result of Farbar Recovery Scan Tool (x64) Version: 16-06-2026

Ran by User (17-06-2026 20:54:03) Run:1

Running from C:\Users\testa\Downloads

Loaded Profiles: User & testa

Boot Mode: Normal

==============================================

fixlist content:

*****************

Start

CreateRestorePoint:

CloseProcesses:

C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl

Edge HKLM-x32\...\Edge\Extension: [jcpgbnbdnakoblgfkbgggankeidkfcdl]

S4 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [945320 2025-06-19] (McAfee, LLC -> McAfee, LLC)

C:\Program Files\McAfee

HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION

HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION

GroupPolicy\User: Restriction ? <==== ATTENTION

HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{5C4D8D77-5B87-40CA-884E-F56858227E5C}\localserver32 -> C:\Users\testa\AppData\Local\Programs\TeamSpeak\notification_helper.exe => No File

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{F92F1811-5523-4EEC-B5A6-FE628430400C}\localserver32 -> "C:\Program Files\Cavalry\Cavalry.exe" -ToastActivated => No File

ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP3\System\aimp_menu64.dll -> No File

ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP3\System\aimp_menu64.dll -> No File

AlternateDataStreams: C:\Users\testa\Downloads\FRST64.exe:MBAM.Zone.Identifier [225]

HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\RunOnce: [NetworkResetPostReboot] => netsh.exe trace postreset (No File)

Task: {06F1EC9C-7EC5-45D7-B5FF-137E985C0F18} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)

S3 MEMSWEEP2; C:\Windows\system32\BA6C.tmp [6144 2010-05-26] (Sophos Plc) [File not signed]

C:\Windows\system32\BA6C.tmp

Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo

Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }

Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" }

C:\WINDOWS\Temp\*

C:\WINDOWS\SystemTemp\*

C:\Users\User\AppData\Local\Temp\*

StartPowerShell:

# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console

# Does not clean preinstalled objects, only PUP/Adware

# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument

# If you would like to only scan with it, change the argument from /clean to /scan

New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null

Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"

Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden

$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"

Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile

Get-Content $logFile -Encoding Unicode

Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue

EndPowerShell:

StartPowershell:

# Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it

$hmpExe = "$env:TEMP\HitmanPro_x64.exe"

$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"

Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing

$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log"$logFile"","/logtype=txt" -Wait -PassThru

if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }

Get-Content $logFile -Encoding Unicode

EndPowershell:

StartPowerShell:

# This snippet downloads Emsisoft Emergency Kit (EEK) from the Emsisoft's official site, updates it, scans with it.

# Do note that the executable is 300MB and may take some time to download.

# ---

# This will scan for malware and PUP's in 1) system memory 2) important folders as documentation says

# It will scan in compressed archives, in mail archives, in NTFS alternate data streams and use cloud requests

# ---

# You can use argument "/delete" to delete found objects including references but this is permanent and irreversible.

# You can remove the "/quick" argument to do a full scan but that may take longer than what FRST can handle.

# You can use argument "/quarantine="[folder]"" to put found malware into quarantine, but I personally prefer first verifying the detections.

$downloadUrl = "https://dl.emsisoft.com/EmsisoftEmergencyKit.exe"

$systemDrive = $env:SystemDrive

$frstPath = "$systemDrive\FRST"

$savePath = "$frstPath\EEK.exe"

$extractPath = "$frstPath\EEK"

if (-not (Test-Path $frstPath)) {

New-Item -Path $frstPath -ItemType Directory -Force | Out-Null

}

if (-not (Test-Path $extractPath)) {

New-Item -Path $extractPath -ItemType Directory -Force | Out-Null

}

Invoke-WebRequest -Uri $downloadUrl -OutFile $savePath -UseBasicParsing

$proc = Start-Process -FilePath $savePath -ArgumentList "-s -"$extractPath"" -PassThru

while (-not (Test-Path "$extractPath\bin64\a2cmd.exe")) { Start-Sleep -Milliseconds 1000 }

Stop-Process -Id $proc.Id -Force -ErrorAction SilentlyContinue

if ([Environment]::Is64BitOperatingSystem) {

$a2cmdPath = Join-Path $extractPath "bin64\a2cmd.exe"

} else {

$a2cmdPath = Join-Path $extractPath "bin32\a2cmd.exe"

}

Start-Process -FilePath $a2cmdPath -ArgumentList "/update" -Wait -NoNewWindow

Start-Process -FilePath $a2cmdPath -ArgumentList "/malware /quick /m /t /pup /a /am /cloud=1 /la"$frstPath\EEK_scan.log"" -Wait -NoNewWindow

Get-Content "$frstPath\EEK_scan.log"

exit

EndPowerShell:

cmd: del %temp%\*.* /f /s /q

cmd: rd /s /q %temp%

cmd: bitsadmin /reset /allusers

cmd: netsh winsock reset catalog

cmd: ipconfig /flushdns

RemoveProxy:

EmptyTemp:

End

*****************

CreateRestorePoint: Error(1=4%) -> Failed to create a restore point.

Processes closed successfully.

"C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl" Folder move:

C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl => moved successfully

HKLM\SOFTWARE\Wow6432Node\Microsoft\Edge\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl => removed successfully

McAfee WebAdvisor => service not found.

"C:\Program Files\McAfee" => not found

HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully

HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully

"C:\WINDOWS\system32\GroupPolicy\User" Folder move:

C:\WINDOWS\system32\GroupPolicy\User => moved successfully

HKLM\SOFTWARE\Policies\Mozilla => removed successfully

HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{5C4D8D77-5B87-40CA-884E-F56858227E5C} => removed successfully

HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{F92F1811-5523-4EEC-B5A6-FE628430400C} => removed successfully

HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\AIMP => removed successfully

HKLM\Software\Classes\CLSID\{1F77B17B-F531-44DB-ACA4-76ABB5010A28} => removed successfully

HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\AIMP => removed successfully

C:\Users\testa\Downloads\FRST64.exe => ":MBAM.Zone.Identifier" ADS removed successfully

"HKU\S-1-5-21-9367388-606531772-2301354866-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\NetworkResetPostReboot" => not found

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06F1EC9C-7EC5-45D7-B5FF-137E985C0F18}" => not found

"C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473" => not found

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473" => not found

HKLM\System\CurrentControlSet\Services\MEMSWEEP2 => removed successfully

MEMSWEEP2 => service removed successfully

C:\Windows\system32\BA6C.tmp => moved successfully

========= Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo =========

LastRunTime : 17.6.2026 г. 12:16:16

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : .NET Framework NGEN v4.0.30319 64

TaskPath : \Microsoft\Windows\.NET Framework\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : PolicyConverter

TaskPath : \Microsoft\Windows\AppID\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : CreateExplorerShellUnelevatedTask

TaskPath : \

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : AD RMS Rights Policy Template Management (Manual)

TaskPath : \Microsoft\Windows\Active Directory Rights Management Services Client\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime : 18.6.2026 г. 15:48:48

NumberOfMissedRuns : 0

TaskName : CCleanerCrashReporting

TaskPath : \

PSComputerName :

LastRunTime : 19.1.2026 г. 1:31:31

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : .NET Framework NGEN v4.0.30319 Critical

TaskPath : \Microsoft\Windows\.NET Framework\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : VerifiedPublisherCertStoreCheck

TaskPath : \Microsoft\Windows\AppID\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime : 18.6.2026 г. 3:18:18

NumberOfMissedRuns : 0

TaskName : AD RMS Rights Policy Template Management (Automated)

TaskPath : \Microsoft\Windows\Active Directory Rights Management Services Client\

PSComputerName :

LastRunTime : 17.6.2026 г. 12:16:16

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : .NET Framework NGEN v4.0.30319

TaskPath : \Microsoft\Windows\.NET Framework\

PSComputerName :

LastRunTime : 17.6.2026 г. 20:22:22

LastTaskResult : 0

NextRunTime : 18.6.2026 г. 11:14:14

NumberOfMissedRuns : 0

TaskName : MicrosoftEdgeUpdateTaskMachineCore{9024C6E2-CB66-4870-9387-85B14E3FE43A}

TaskPath : \

PSComputerName :

LastRunTime : 17.6.2026 г. 20:44:44

LastTaskResult : 0

NextRunTime : 17.6.2026 г. 21:44:44

NumberOfMissedRuns : 0

TaskName : MicrosoftEdgeUpdateTaskMachineUA{F5C68833-A222-4C16-B8C3-A82702F7371A}

TaskPath : \

PSComputerName :

LastRunTime : 13.6.2026 г. 11:59:59

LastTaskResult : 0

NextRunTime : 20.6.2026 г. 11:59:59

NumberOfMissedRuns : 0

TaskName : AppleSoftwareUpdate

TaskPath : \Apple\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime : 19.6.2026 г. 12:00:00

NumberOfMissedRuns : 0

TaskName : PcaWallpaperAppDetect

TaskPath : \Microsoft\Windows\Application Experience\

PSComputerName :

LastRunTime : 17.6.2026 г. 15:12:12

LastTaskResult : 0

NextRunTime : 18.6.2026 г. 4:17:17

NumberOfMissedRuns : 0

TaskName : PcaPatchDbTask

TaskPath : \Microsoft\Windows\Application Experience\

PSComputerName :

LastRunTime : 14.6.2026 г. 14:03:03

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : CleanupTemporaryState

TaskPath : \Microsoft\Windows\ApplicationData\

PSComputerName :

LastRunTime : 19.1.2026 г. 1:31:31

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : .NET Framework NGEN v4.0.30319 64 Critical

TaskPath : \Microsoft\Windows\.NET Framework\

PSComputerName :

LastRunTime : 17.1.2026 г. 12:47:47

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : Pre-staged app cleanup

TaskPath : \Microsoft\Windows\AppxDeploymentClient\

PSComputerName :

LastRunTime : 17.6.2026 г. 18:33:33

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : UCPD velocity

TaskPath : \Microsoft\Windows\AppxDeploymentClient\

PSComputerName :

LastRunTime : 17.6.2026 г. 16:23:23

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : Backup

TaskPath : \Microsoft\Windows\AppListBackup\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : BitLocker Encrypt All Drives

TaskPath : \Microsoft\Windows\BitLocker\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : BitLocker MDM policy Refresh

TaskPath : \Microsoft\Windows\BitLocker\

PSComputerName :

LastRunTime : 17.6.2026 г. 19:13:13

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : Proxy

TaskPath : \Microsoft\Windows\Autochk\

PSComputerName :

LastRunTime : 15.6.2026 г. 3:34:34

LastTaskResult : 0

NextRunTime : 18.6.2026 г. 1:53:53

NumberOfMissedRuns : 0

TaskName : BackupNonMaintenance

TaskPath : \Microsoft\Windows\AppListBackup\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : UninstallDeviceTask

TaskPath : \Microsoft\Windows\Bluetooth\

PSComputerName :

LastRunTime : 13.6.2026 г. 16:40:40

LastTaskResult : 268435456

NextRunTime :

NumberOfMissedRuns : 0

TaskName : BgTaskRegistrationMaintenanceTask

TaskPath : \Microsoft\Windows\BrokerInfrastructure\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : CryptoPolicyTask

TaskPath : \Microsoft\Windows\CertificateServicesClient\

PSComputerName :

LastRunTime : 17.6.2026 г. 20:22:22

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : AikCertEnrollTask

TaskPath : \Microsoft\Windows\CertificateServicesClient\

PSComputerName :

LastRunTime : 17.6.2026 г. 20:22:22

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : SystemTask

TaskPath : \Microsoft\Windows\CertificateServicesClient\

PSComputerName :

LastRunTime : 17.6.2026 г. 20:22:22

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : UserTask

TaskPath : \Microsoft\Windows\CertificateServicesClient\

PSComputerName :

LastRunTime : 17.6.2026 г. 20:22:22

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : KeyPreGenTask

TaskPath : \Microsoft\Windows\CertificateServicesClient\

PSComputerName :

========= End of Powershell: =========

========= @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) } =========

========= End of Powershell: =========

========= (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" } =========

========= End of Powershell: =========

=========== "C:\WINDOWS\Temp\*" ==========

C:\WINDOWS\Temp\BIT4EB3.tmp => moved successfully

C:\WINDOWS\Temp\BITD9ED.tmp => moved successfully

C:\WINDOWS\Temp\D566D7D7-DCD6-471C-8109-BE0AD33199E3 => moved successfully

C:\WINDOWS\Temp\F07D8C6A-04B6-4025-869C-70A788D7B5C0 => moved successfully

C:\WINDOWS\Temp\FXSAPIDebugLogFile.txt => moved successfully

C:\WINDOWS\Temp\FXSTIFFDebugLogFile.txt => moved successfully

C:\WINDOWS\Temp\WER1038.tmp => moved successfully

========= End -> "C:\WINDOWS\Temp\*" ========

=========== "C:\WINDOWS\SystemTemp\*" ==========

not found

========= End -> "C:\WINDOWS\SystemTemp\*" ========

=========== "C:\Users\User\AppData\Local\Temp\*" ==========

C:\Users\User\AppData\Local\Temp\000 => moved successfully

C:\Users\User\AppData\Local\Temp\000rdy => moved successfully

C:\Users\User\AppData\Local\Temp\001 => moved successfully

C:\Users\User\AppData\Local\Temp\001b => moved successfully

C:\Users\User\AppData\Local\Temp\001brdy => moved successfully

C:\Users\User\AppData\Local\Temp\001_rdy => moved successfully

C:\Users\User\AppData\Local\Temp\002 => moved successfully

C:\Users\User\AppData\Local\Temp\002rdy => moved successfully

C:\Users\User\AppData\Local\Temp\003 => moved successfully

C:\Users\User\AppData\Local\Temp\003rdy => moved successfully

C:\Users\User\AppData\Local\Temp\004 => moved successfully

C:\Users\User\AppData\Local\Temp\004rdy => moved successfully

C:\Users\User\AppData\Local\Temp\006 => moved successfully

C:\Users\User\AppData\Local\Temp\006b => moved successfully

C:\Users\User\AppData\Local\Temp\006d => moved successfully

C:\Users\User\AppData\Local\Temp\006rdy => moved successfully

C:\Users\User\AppData\Local\Temp\007 => moved successfully

C:\Users\User\AppData\Local\Temp\007rdy => moved successfully

C:\Users\User\AppData\Local\Temp\10231 => moved successfully

C:\Users\User\AppData\Local\Temp\10274 => moved successfully

C:\Users\User\AppData\Local\Temp\10362 => moved successfully

C:\Users\User\AppData\Local\Temp\10921 => moved successfully

C:\Users\User\AppData\Local\Temp\109a9bf9-6a07-485d-a699-b795319ab45b.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\11026 => moved successfully

C:\Users\User\AppData\Local\Temp\11524 => moved successfully

C:\Users\User\AppData\Local\Temp\11531 => moved successfully

C:\Users\User\AppData\Local\Temp\11534 => moved successfully

C:\Users\User\AppData\Local\Temp\11735 => moved successfully

C:\Users\User\AppData\Local\Temp\11804 => moved successfully

C:\Users\User\AppData\Local\Temp\11858 => moved successfully

C:\Users\User\AppData\Local\Temp\11906 => moved successfully

C:\Users\User\AppData\Local\Temp\1290 => moved successfully

C:\Users\User\AppData\Local\Temp\12cd12c0-7d8d-4f90-86bb-d609c637605d.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\1303 => moved successfully

C:\Users\User\AppData\Local\Temp\13097 => moved successfully

C:\Users\User\AppData\Local\Temp\13137 => moved successfully

C:\Users\User\AppData\Local\Temp\13977 => moved successfully

C:\Users\User\AppData\Local\Temp\14435 => moved successfully

C:\Users\User\AppData\Local\Temp\14598 => moved successfully

C:\Users\User\AppData\Local\Temp\1497 => moved successfully

C:\Users\User\AppData\Local\Temp\15132ae7-4e6b-4586-8920-c4b988e76c5b.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\15551 => moved successfully

C:\Users\User\AppData\Local\Temp\15565 => moved successfully

C:\Users\User\AppData\Local\Temp\162701da-25ae-4f6f-ad49-99af9e84c403.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\17024 => moved successfully

C:\Users\User\AppData\Local\Temp\17054 => moved successfully

C:\Users\User\AppData\Local\Temp\17328 => moved successfully

C:\Users\User\AppData\Local\Temp\1750 => moved successfully

C:\Users\User\AppData\Local\Temp\18744 => moved successfully

C:\Users\User\AppData\Local\Temp\18791 => moved successfully

C:\Users\User\AppData\Local\Temp\18855 => moved successfully

C:\Users\User\AppData\Local\Temp\19438 => moved successfully

C:\Users\User\AppData\Local\Temp\19597 => moved successfully

C:\Users\User\AppData\Local\Temp\19657 => moved successfully

C:\Users\User\AppData\Local\Temp\19707 => moved successfully

C:\Users\User\AppData\Local\Temp\19743 => moved successfully

C:\Users\User\AppData\Local\Temp\19807 => moved successfully

C:\Users\User\AppData\Local\Temp\19941 => moved successfully

C:\Users\User\AppData\Local\Temp\20565 => moved successfully

C:\Users\User\AppData\Local\Temp\2073 => moved successfully

C:\Users\User\AppData\Local\Temp\21042 => moved successfully

C:\Users\User\AppData\Local\Temp\212 => moved successfully

C:\Users\User\AppData\Local\Temp\21351 => moved successfully

C:\Users\User\AppData\Local\Temp\22147 => moved successfully

C:\Users\User\AppData\Local\Temp\22890 => moved successfully

C:\Users\User\AppData\Local\Temp\22959 => moved successfully

C:\Users\User\AppData\Local\Temp\23320 => moved successfully

C:\Users\User\AppData\Local\Temp\23418 => moved successfully

C:\Users\User\AppData\Local\Temp\2354 => moved successfully

C:\Users\User\AppData\Local\Temp\23841 => moved successfully

C:\Users\User\AppData\Local\Temp\24052 => moved successfully

C:\Users\User\AppData\Local\Temp\24218 => moved successfully

C:\Users\User\AppData\Local\Temp\24380 => moved successfully

C:\Users\User\AppData\Local\Temp\2465 => moved successfully

C:\Users\User\AppData\Local\Temp\24799 => moved successfully

C:\Users\User\AppData\Local\Temp\24cb30a0-ce5b-4b2d-a669-1923642c92ff.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\25088 => moved successfully

C:\Users\User\AppData\Local\Temp\25400 => moved successfully

C:\Users\User\AppData\Local\Temp\25403 => moved successfully

C:\Users\User\AppData\Local\Temp\25992 => moved successfully

C:\Users\User\AppData\Local\Temp\26140 => moved successfully

C:\Users\User\AppData\Local\Temp\26480 => moved successfully

C:\Users\User\AppData\Local\Temp\26548 => moved successfully

C:\Users\User\AppData\Local\Temp\26673 => moved successfully

C:\Users\User\AppData\Local\Temp\2674 => moved successfully

C:\Users\User\AppData\Local\Temp\26983 => moved successfully

C:\Users\User\AppData\Local\Temp\26995 => moved successfully

C:\Users\User\AppData\Local\Temp\27130 => moved successfully

C:\Users\User\AppData\Local\Temp\27312 => moved successfully

C:\Users\User\AppData\Local\Temp\27375 => moved successfully

C:\Users\User\AppData\Local\Temp\27417 => moved successfully

C:\Users\User\AppData\Local\Temp\27428 => moved successfully

C:\Users\User\AppData\Local\Temp\27711 => moved successfully

C:\Users\User\AppData\Local\Temp\27837 => moved successfully

C:\Users\User\AppData\Local\Temp\281002a3-f39d-459f-9e11-bcffd64916d9.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\28185 => moved successfully

C:\Users\User\AppData\Local\Temp\28304 => moved successfully

C:\Users\User\AppData\Local\Temp\28538 => moved successfully

C:\Users\User\AppData\Local\Temp\28543 => moved successfully

C:\Users\User\AppData\Local\Temp\29220 => moved successfully

C:\Users\User\AppData\Local\Temp\29228 => moved successfully

C:\Users\User\AppData\Local\Temp\2994 => moved successfully

C:\Users\User\AppData\Local\Temp\29975 => moved successfully

C:\Users\User\AppData\Local\Temp\30517 => moved successfully

C:\Users\User\AppData\Local\Temp\30903 => moved successfully

C:\Users\User\AppData\Local\Temp\30963 => moved successfully

C:\Users\User\AppData\Local\Temp\31585 => moved successfully

C:\Users\User\AppData\Local\Temp\31793 => moved successfully

C:\Users\User\AppData\Local\Temp\32039 => moved successfully

C:\Users\User\AppData\Local\Temp\32228 => moved successfully

C:\Users\User\AppData\Local\Temp\32363 => moved successfully

C:\Users\User\AppData\Local\Temp\32559 => moved successfully

C:\Users\User\AppData\Local\Temp\3644 => moved successfully

C:\Users\User\AppData\Local\Temp\3795 => moved successfully

C:\Users\User\AppData\Local\Temp\3a9a6347-fe7c-4198-b575-0242f8c3956e.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\3b3c9d79-7caa-4c17-810c-f5a5763bc38c.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\4125 => moved successfully

C:\Users\User\AppData\Local\Temp\4177 => moved successfully

C:\Users\User\AppData\Local\Temp\4303 => moved successfully

C:\Users\User\AppData\Local\Temp\4411 => moved successfully

C:\Users\User\AppData\Local\Temp\445e9663-63a9-4316-9a20-a4d49422aaaa.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\446 => moved successfully

C:\Users\User\AppData\Local\Temp\4546 => moved successfully

C:\Users\User\AppData\Local\Temp\4693 => moved successfully

C:\Users\User\AppData\Local\Temp\4987265f-339b-41f2-8193-6feba369fdf0.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\50b8a418-0a24-4355-9b7f-cc5beea7f3e0.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\5145 => moved successfully

C:\Users\User\AppData\Local\Temp\5338 => moved successfully

C:\Users\User\AppData\Local\Temp\5487 => moved successfully

C:\Users\User\AppData\Local\Temp\561 => moved successfully

C:\Users\User\AppData\Local\Temp\5685 => moved successfully

C:\Users\User\AppData\Local\Temp\5732 => moved successfully

C:\Users\User\AppData\Local\Temp\5748 => moved successfully

C:\Users\User\AppData\Local\Temp\5954 => moved successfully

C:\Users\User\AppData\Local\Temp\597 => moved successfully

C:\Users\User\AppData\Local\Temp\5ab21485-7f88-4d03-b194-f6d802905dde.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\607d4b43-9b88-475b-ba9f-a41ab3fecc8a.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\6468 => moved successfully

C:\Users\User\AppData\Local\Temp\6475 => moved successfully

C:\Users\User\AppData\Local\Temp\6505b0ab-ae78-4f78-a85a-989ae116e2f8.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\6780 => moved successfully

C:\Users\User\AppData\Local\Temp\6980 => moved successfully

C:\Users\User\AppData\Local\Temp\72 => moved successfully

C:\Users\User\AppData\Local\Temp\725c1575-df85-411a-ab66-2dc3aadba953.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\7502 => moved successfully

C:\Users\User\AppData\Local\Temp\7571 => moved successfully

C:\Users\User\AppData\Local\Temp\7e90a2b6-f98e-4cc9-a1df-2e628d51d267.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\8121 => moved successfully

C:\Users\User\AppData\Local\Temp\8144 => moved successfully

C:\Users\User\AppData\Local\Temp\8928 => moved successfully

C:\Users\User\AppData\Local\Temp\8c06415d-e053-4fa8-b8f2-e97d3fd228b6.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\8f8c1d21-a4b8-4bdc-9b7a-d738b0f65e5c.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\9217 => moved successfully

C:\Users\User\AppData\Local\Temp\9268 => moved successfully

C:\Users\User\AppData\Local\Temp\93229ddb-3326-4b07-8e2c-83e40eefc0fc.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\9555 => moved successfully

C:\Users\User\AppData\Local\Temp\982550a9-3428-47f1-a64e-3301906b19d3.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\9952 => moved successfully

C:\Users\User\AppData\Local\Temp\9ac5f124-6d0c-447f-a492-15824e7816bd.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\9c6d074f-2a6b-4e5c-8cab-fb1f4eddf267.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\aib.nrb => moved successfully

C:\Users\User\AppData\Local\Temp\b3727394-7ee6-433e-9f3e-e10370d8a507.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\battery-report.xml => moved successfully

C:\Users\User\AppData\Local\Temp\bd40a424-d400-4530-9913-7d8635a3e068.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\bf57a4ea-15f2-4b30-898a-1636aecc7b44.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\bl00 => moved successfully

C:\Users\User\AppData\Local\Temp\bl01 => moved successfully

C:\Users\User\AppData\Local\Temp\Bol3_4.zip => moved successfully

C:\Users\User\AppData\Local\Temp\cdumps00 => moved successfully

C:\Users\User\AppData\Local\Temp\chtpb.nrb => moved successfully

C:\Users\User\AppData\Local\Temp\d38f5aef-b620-464b-aa53-4ecb46c76491.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\DDInstall.cpccLog.txt => moved successfully

C:\Users\User\AppData\Local\Temp\dd_vcredistMSI4E85.txt => moved successfully

C:\Users\User\AppData\Local\Temp\dd_vcredistUI4E85.txt => moved successfully

C:\Users\User\AppData\Local\Temp\dd_vcredist_amd64_20260316131446.log => moved successfully

C:\Users\User\AppData\Local\Temp\dd_vcredist_amd64_20260316131447.log => moved successfully

C:\Users\User\AppData\Local\Temp\dd_vcredist_amd64_20260617195214.log => moved successfully

C:\Users\User\AppData\Local\Temp\dd_vcredist_x86_20260617195219.log => moved successfully

C:\Users\User\AppData\Local\Temp\Disk_Drill_6.3.1397.0_20260617195138.elevated.log => moved successfully

C:\Users\User\AppData\Local\Temp\dndlogcl.txt => moved successfully

C:\Users\User\AppData\Local\Temp\dndlogh.txt => moved successfully

C:\Users\User\AppData\Local\Temp\dndlogh2.txt => moved successfully

C:\Users\User\AppData\Local\Temp\DoesNotBelong.txt => moved successfully

C:\Users\User\AppData\Local\Temp\Dokan_Library_2.3.1.1000_Bundle_20260617195230.elevated.log => moved successfully

C:\Users\User\AppData\Local\Temp\e038ea8c-d75d-4b7a-ba83-0768a8796e8e.tmp => moved successfully

C:\Users\User\AppData\Local\Temp\F07D8C6A-04B6-4025-869C-70A788D7B5C0 => moved successfully

C:\Users\User\AppData\Local\Temp\Intel®_Software_Installer_20260418174837.log => moved successfully

C:\Users\User\AppData\Local\Temp\Intel®_Software_Installer_20260418174837_000_Pre_Install.log => moved successfully

C:\Users\User\AppData\Local\Temp\Intel®_Software_Installer_20260418174837_001_WIFI_Driver.log => moved successfully

C:\Users\User\AppData\Local\Temp\Intel®_Software_Installer_20260418174837_002_DocsManager.log => moved successfully

C:\Users\User\AppData\Local\Temp\Intel®_Software_Installer_20260418174847.elevated.log => moved successfully

C:\Users\User\AppData\Local\Temp\mbsetup.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_.NET_Core_Runtime_-_3.1.28_(x64)_20260301230223.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_.NET_Core_Runtime_-_3.1.28_(x64)_20260301230223_000_dotnet_host_3.1.28_win_x64.msi.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_.NET_Core_Runtime_-_3.1.28_(x64)_20260301230223_001_dotnet_hostfxr_3.1.28_win_x64.msi.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_.NET_Core_Runtime_-_3.1.28_(x64)_20260301230223_002_dotnet_runtime_3.1.28_win_x64.msi.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_8.0.14_(x86)_20260301230253.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_8.0.14_(x86)_20260301230253_000_windowsdesktop_runtime_8.0.14_win_x86.msi.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_8.0.14_(x86)_20260301230253_000_windowsdesktop_runtime_8.0.14_win_x86.msi_rollback.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_8.0.14_(x86)_20260301230253_001_dotnet_host_8.0.14_win_x86.msi.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_8.0.14_(x86)_20260301230253_001_dotnet_host_8.0.14_win_x86.msi_rollback.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_8.0.14_(x86)_20260301230253_002_dotnet_hostfxr_8.0.14_win_x86.msi.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_9.0.12_(x64)_20260617195220.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_9.0.12_(x64)_20260617195220_000_dotnet_runtime_9.0.12_win_x64.msi.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_9.0.12_(x64)_20260617195220_001_dotnet_hostfxr_9.0.12_win_x64.msi.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_9.0.12_(x64)_20260617195220_002_dotnet_host_9.0.12_win_x64.msi.log => moved successfully

C:\Users\User\AppData\Local\Temp\Microsoft_Windows_Desktop_Runtime_-_9.0.12_(x64)_20260617195220_003_windowsdesktop_runtime_9.0.12_win_x64.msi.log => moved successfully

C:\Users\User\AppData\Local\Temp\MSIa2a7c.LOG => moved successfully

C:\Users\User\AppData\Local\Temp\Setup Log 2026-02-11 #001.txt => moved successfully

C:\Users\User\AppData\Local\Temp\Setup Log 2026-02-11 #002.txt => moved successfully

C:\Users\User\AppData\Local\Temp\smtchb.nrb => moved successfully

C:\Users\User\AppData\Local\Temp\uinpb.nrb => moved successfully

C:\Users\User\AppData\Local\Temp\WiFi-24.30.1-Driver64-Win10-Win11_20260418174836.log => moved successfully

========= End -> "C:\Users\User\AppData\Local\Temp\*" ========

========= Powershell: =========

AdwCleaner v8.8.1.639

Destroys adware, restores performance!

Initializing modules Scanning Process 0% Completed

Checking database updates Scanning Process 0% Completed

Loading modules Scanning Process 15% Completed

Scanning Scanning Process 15% Completed

Scanning Scanning Process 30% Completed

Scanning Scanning Process 36% Completed

Scanning Scanning Process 40% Completed

Scanning Scanning Process 44% Completed

Scanning Scanning Process 47% Completed

Scanning Scanning Process 50% Completed

Scanning Scanning Process 54% Completed

Scanning Scanning Process 57% Completed

Scanning Scanning Process 60% Completed

Scanning Scanning Process 62% Completed

Scanning Scanning Process 65% Completed

Scanning Scanning Process 68% Completed

Scanning Scanning Process 72% Completed

Scanning Scanning Process 75% Completed

Scanning Scanning Process 79% Completed

Scanning Scanning Process 82% Completed

Scanning Scanning Process 85% Completed

Scanning Scanning Process 88% Completed

Scanning Scanning Process 91% Completed

Scanning Scanning Process 92% Completed

Scanning Scanning Process 93% Completed

Scanning Scanning Process 94% Completed

Scanning Scanning Process 95% Completed

Scanning Scanning Process 97% Completed

Scanning Scanning Process 98% Completed

Scanning Scanning Process 99% Completed

Writing log Scanning Process 100% Completed

Processing results Scanning Process 100% Completed

Scanning finished.

32070 total objects scanned.

Bundleware items found:

Family Type Name

Preinstalled.LenovoServiceBridge Folder C:\Users\testa\AppData\Local\PROGRAMS\LENOVO\LENOVO SERVICE BRIDGE

Preinstalled.LenovoServiceBridge Registry key HKU\S-1-5-21-9367388-606531772-2301354866-1005\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1

Total preinstalled software items found: 2

Nothing to clean.

========= End of Powershell: =========

========= Powershell: =========

[code]

HitmanPro 3.8.50.346

www.hitmanpro.com

Computer name . . . . : DESKTOP-J190OJ1

Windows . . . . . . . : 10.0.0.19045.X64/12

User name . . . . . . : DESKTOP-J190OJ1\User

UAC . . . . . . . . . : Enabled

License . . . . . . . : Free

Scan date . . . . . . : 2026-06-17 20:54:54

Scan mode . . . . . . : EWS

Scan duration . . . . : 4m 3s

Disk access mode . . : Direct disk access (SRB)

Cloud . . . . . . . . : Internet

Reboot . . . . . . . : No

Close Browser . . . . : No

Close Remember . . . : No

Edge Sync key . . . . : Not Found

Threats . . . . . . . : 0

Traces . . . . . . . : 36

Objects scanned . . . : 4 779 232

Files scanned . . . . : 466 095

Remnants scanned . . : 2 155 565 files / 2 157 572 keys

Suspicious files ____________________________________________________________

C:\Program Files\qBittorrent\qbittorrent.exe

Size . . . . . . . : 29 060 608 bytes

Age . . . . . . . : 1498.5 days (2022-05-11 09:44:46)

Entropy . . . . . : 7.0

SHA-256 . . . . . : 5B0A213083EC566DA02297A7EFAC3927C08DAAE69310671E6C1E167AF6CCE3F7

Product . . . . . : qBittorrent

Publisher . . . . : The qBittorrent Project

Description . . . : qBittorrent - A Bittorrent Client

Version . . . . . : v4.4.2

Copyright . . . . : Copyright ©2006-2022 The qBittorrent Project

LanguageID . . . . : 1033

Fuzzy . . . . . . : 23.0

The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

Uses the Windows Registry to run each time the user logs on.

Program starts automatically without user intervention.

Startup

HKU\S-1-5-21-9367388-606531772-2301354866-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qBittorrent

References

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent\qBittorrent.lnk

C:\Users\Public\Desktop\qBittorrent.lnk

C:\Users\testa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\qBittorrent.lnk

Early Warning Scoring _______________________________________________________

C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe

Size . . . . . . . : 4 625 784 bytes

Age . . . . . . . : 5.0 days (2026-06-12 20:50:19)

Entropy . . . . . : 6.2

SHA-256 . . . . . : B9E1DB395A9F59C53F85CF04A73A41A62A5D03232CCC6C476F4E371206C7C471

Product . . . . . : AVG Secure Browser

Publisher . . . . : Gen Digital Inc.

Description . . . : AVG Secure Browser

Version . . . . . : 148.0.34771.218

Copyright . . . . : (C) 2017-2024 Gen Digital Inc.

RSA Key Size . . . : 4096

LanguageID . . . . : 1033

Authenticode . . . : Valid

Fuzzy . . . . . . : 6.0

The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

Uses the Windows Registry to run each time the user logs on.

Program starts automatically without user intervention.

Time indicates that the file appeared recently on this computer.

Program is code signed with a valid Authenticode certificate.

The file appears to be part of an installation package or setup program. This is typical for most programs.

Startup

HKLM\SOFTWARE\Clients\StartMenuInternet\AVG Secure Browser\shell\open\command\

HKLM\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\AVG Secure Browser\shell\open\command\

HKU\S-1-5-21-9367388-606531772-2301354866-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AVGBrowserAutoLaunch_8F351DF0CEE308805CB145B9E3DA56ED

References

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Secure Browser.lnk

C:\Users\Public\Desktop\AVG Secure Browser.lnk

C:\Users\testa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AVG Secure Browser.lnk

C:\Users\testa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\AVG Secure Browser.lnk

C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AVG Secure Browser.lnk

C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\AVG Secure Browser.lnk

Forensic Cluster

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Extensions\

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\IwaKeyDistribution\

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\VisualElements\

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\MEIPreload\

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\148.0.34771.218.manifest

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\PrivacySandboxAttestationsPreloaded\

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\aswengineconnector.dll

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\AVGBrowser.exe.sig

-4.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\browser_crash_reporter.exe

-3.9s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\chrome.dll

-1.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\chrome.dll.sig

-1.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\chrome_100_percent.pak

-1.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\chrome_200_percent.pak

-1.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\chrome_elf.dll

-1.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\chrome_pwa_launcher.exe

-1.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\chrome_wer.dll

-1.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\config.def

-1.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\d3dcompiler_47.dll

-1.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\dxcompiler.dll

-1.4s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\dxil.dll

-1.4s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\elevation_service.exe

-1.1s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\eventlog_provider.dll

-1.1s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Extensions\external_extensions.json

-1.1s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\ffmpeg.dll

-1.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\icudtl.dat

-1.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\IwaKeyDistribution\iwa-key-distribution.pb

-1.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\libegl.dll

-1.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\IwaKeyDistribution\manifest.json

-1.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\libglesv2.dll

-0.9s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\af.pak

-0.9s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\am.pak

-0.9s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\ar.pak

-0.9s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\bg.pak

-0.9s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\bn.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\ca.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\cs.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\da.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\de.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\el.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\en-GB.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\en-US.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\es-419.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\es.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\et.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\fa.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\fi.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\fil.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\fr.pak

-0.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\gu.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\he.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\hi.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\hr.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\hu.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\id.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\it.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\ja.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\kn.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\ko.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\lt.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\lv.pak

-0.7s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\ml.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\mr.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\ms.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\nb.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\nl.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\pl.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\pt-BR.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\pt-PT.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\ro.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\ru.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\sk.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\sl.pak

-0.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\sr.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\sv.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\sw.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\ta.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\te.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\th.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\tr.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\uk.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\ur.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\vi.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\zh-CN.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Locales\zh-TW.pak

-0.5s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\MEIPreload\manifest.json

-0.4s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\MEIPreload\preloaded_data.pb

-0.4s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\mimic.dll

-0.4s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\notification_helper.exe

-0.3s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\PrivacySandboxAttestationsPreloaded\manifest.json

-0.3s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\PrivacySandboxAttestationsPreloaded\privacy-sandbox-attestations.dat

-0.3s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\resources.pak

-0.1s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\v8_context_snapshot.bin

-0.1s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\VisualElements\logo.png

-0.1s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\VisualElements\smalllogo.png

-0.1s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\vk_swiftshader.dll

-0.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\vk_swiftshader_icd.json

-0.0s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\vulkan-1.dll

0.0s C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe

0.1s C:\Program Files (x86)\AVG\Browser\Application\browser_proxy.exe

1.3s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Installer\

1.6s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Installer\setup.exe

1.8s C:\Program Files (x86)\AVG\Browser\Application\148.0.34771.218\Installer\chrmstp.exe

2.7s C:\Users\testa\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\DiagOutputDir\WinGetCOM-2026-06-12-20-50-22.175.log

C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe

Size . . . . . . . : 5 227 848 bytes

Age . . . . . . . : 101.8 days (2026-03-08 00:35:14)

Entropy . . . . . : 6.5

SHA-256 . . . . . : A0806567FA2E180CBB281E8F47D15B316527BDD58165F60769FB46BFF91EC565

Product . . . . . : Microsoft Edge

Publisher . . . . : Microsoft Corporation

Description . . . : Microsoft Edge

Version . . . . . : 149.0.4022.69

Copyright . . . . : Copyright Microsoft Corporation. All rights reserved.

RSA Key Size . . . : 2048

LanguageID . . . . : 1033

Authenticode . . . : Valid

Fuzzy . . . . . . : 8.0

The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

Uses the Windows Registry to run each time the user logs on.

Program starts automatically without user intervention.

Program is code signed with a valid Authenticode certificate.

The file appears to be part of an installation package or setup program. This is typical for most programs.

Startup

HKLM\SOFTWARE\Clients\StartMenuInternet\Microsoft Edge\shell\open\command\

HKLM\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\Microsoft Edge\shell\open\command\

HKU\S-1-5-21-9367388-606531772-2301354866-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MicrosoftEdgeAutoLaunch_D9BC01DA7EE888E155CFF65CFCDDE7EC

References

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk

C:\Users\Public\Desktop\Microsoft Edge.lnk

C:\Users\testa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk

C:\Users\testa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Edge.lnk

C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Microsoft Edge.lnk

C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk

C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Edge.lnk

C:\Users\testa\AppData\Local\Discord\Update.exe

Size . . . . . . . : 1 516 408 bytes

Age . . . . . . . : 401.0 days (2025-05-12 21:53:59)

Entropy . . . . . : 5.9

SHA-256 . . . . . : 7E5231D5862B30C35CCAD81FC4B1A2C5BC3CE25A63482F456FFE6D1EF71AA3FA

Product . . . . . : Update

Publisher . . . . : Discord Inc.

Description . . . : Update

Version . . . . . : 1.1.1.0

RSA Key Size . . . : 4096

LanguageID . . . . : 0

Authenticode . . . : Valid

Fuzzy . . . . . . : 16.0

The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

Uses the Windows Registry to run each time the user logs on.

Program starts automatically without user intervention.

Program is code signed with a valid Authenticode certificate.

Startup

HKU\S-1-5-21-9367388-606531772-2301354866-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Discord

C:\Users\testa\AppData\Local\Greenshot\Greenshot.exe

Size . . . . . . . : 527 792 bytes

Age . . . . . . . : 1069.6 days (2023-07-14 07:24:09)

Entropy . . . . . : 6.1

SHA-256 . . . . . : FDC3900DA9CF5B4B7F4B461EB54F2F7ABF2AF104DE8BFDD0B7F6A46F092F9CC6

Product . . . . . : Greenshot

Publisher . . . . : Greenshot

Description . . . : Greenshot

Version . . . . . : 1.2.10.6

RSA Key Size . . . : 2048

LanguageID . . . . : 0

Authenticode . . . : Valid

Fuzzy . . . . . . : 16.0

The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

Uses the Windows Registry to run each time the user logs on.

Program starts automatically without user intervention.

Program is code signed with a valid Authenticode certificate.

Startup

HKU\S-1-5-21-9367388-606531772-2301354866-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Greenshot

C:\Users\testa\AppData\Local\Microsoft\OneDrive\OneDrive.exe

Size . . . . . . . : 4 968 296 bytes

Age . . . . . . . : 1085.5 days (2023-06-28 08:32:16)

Entropy . . . . . : 5.8

SHA-256 . . . . . : 2607501EF9C3A29A58C8AEC96F501286D3566DE3687089153C5EAC8E81EBD3A1

Product . . . . . : Microsoft OneDrive

Publisher . . . . : Microsoft Corporation

Description . . . : Microsoft OneDrive

Version . . . . . : 25.127.0701.0006

Copyright . . . . : © Microsoft Corporation. All rights reserved.

RSA Key Size . . . : 4096

LanguageID . . . . : 1033

Authenticode . . . : Valid

Fuzzy . . . . . . : 16.0

The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

Uses the Windows Registry to run each time the user logs on.

Program starts automatically without user intervention.

Program is code signed with a valid Authenticode certificate.

Startup

HKU\S-1-5-21-9367388-606531772-2301354866-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OneDrive

Cookies _____________________________________________________________________

C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies:adnxs.com

C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies:casalemedia.com

C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies:crwdcntrl.net

C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies:scorecardresearch.com

[/code]

========= End of Powershell: =========

========= Powershell: =========

  • Автор

Fix result of Farbar Recovery Scan Tool (x64) Version: 16-06-2026

Ran by User (17-06-2026 21:08:58) Run:2

Running from C:\Users\testa\Downloads

Loaded Profiles: User & testa

Boot Mode: Normal

==============================================

fixlist content:

*****************

Start

CreateRestorePoint:

CloseProcesses:

C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl

Edge HKLM-x32\...\Edge\Extension: [jcpgbnbdnakoblgfkbgggankeidkfcdl]

S4 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [945320 2025-06-19] (McAfee, LLC -> McAfee, LLC)

C:\Program Files\McAfee

HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION

HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION

GroupPolicy\User: Restriction ? <==== ATTENTION

HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{5C4D8D77-5B87-40CA-884E-F56858227E5C}\localserver32 -> C:\Users\testa\AppData\Local\Programs\TeamSpeak\notification_helper.exe => No File

CustomCLSID: HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{F92F1811-5523-4EEC-B5A6-FE628430400C}\localserver32 -> "C:\Program Files\Cavalry\Cavalry.exe" -ToastActivated => No File

ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP3\System\aimp_menu64.dll -> No File

ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP3\System\aimp_menu64.dll -> No File

AlternateDataStreams: C:\Users\testa\Downloads\FRST64.exe:MBAM.Zone.Identifier [225]

HKU\S-1-5-21-9367388-606531772-2301354866-1001\...\RunOnce: [NetworkResetPostReboot] => netsh.exe trace postreset (No File)

Task: {06F1EC9C-7EC5-45D7-B5FF-137E985C0F18} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)

S3 MEMSWEEP2; C:\Windows\system32\BA6C.tmp [6144 2010-05-26] (Sophos Plc) [File not signed]

C:\Windows\system32\BA6C.tmp

Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo

Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) }

Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" }

C:\WINDOWS\Temp\*

C:\WINDOWS\SystemTemp\*

C:\Users\User\AppData\Local\Temp\*

StartPowerShell:

# Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console

# Does not clean preinstalled objects, only PUP/Adware

# If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument

# If you would like to only scan with it, change the argument from /clean to /scan

New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null

Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe"

Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden

$logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt"

Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile

Get-Content $logFile -Encoding Unicode

Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue

EndPowerShell:

StartPowershell:

# Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it

$hmpExe = "$env:TEMP\HitmanPro_x64.exe"

$logFile = "$env:TEMP\HitmanPro_ScanLog.txt"

Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing

$proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log"$logFile"","/logtype=txt" -Wait -PassThru

if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 }

Get-Content $logFile -Encoding Unicode

EndPowershell:

StartPowerShell:

# This snippet downloads Emsisoft Emergency Kit (EEK) from the Emsisoft's official site, updates it, scans with it.

# Do note that the executable is 300MB and may take some time to download.

# ---

# This will scan for malware and PUP's in 1) system memory 2) important folders as documentation says

# It will scan in compressed archives, in mail archives, in NTFS alternate data streams and use cloud requests

# ---

# You can use argument "/delete" to delete found objects including references but this is permanent and irreversible.

# You can remove the "/quick" argument to do a full scan but that may take longer than what FRST can handle.

# You can use argument "/quarantine="[folder]"" to put found malware into quarantine, but I personally prefer first verifying the detections.

$downloadUrl = "https://dl.emsisoft.com/EmsisoftEmergencyKit.exe"

$systemDrive = $env:SystemDrive

$frstPath = "$systemDrive\FRST"

$savePath = "$frstPath\EEK.exe"

$extractPath = "$frstPath\EEK"

if (-not (Test-Path $frstPath)) {

New-Item -Path $frstPath -ItemType Directory -Force | Out-Null

}

if (-not (Test-Path $extractPath)) {

New-Item -Path $extractPath -ItemType Directory -Force | Out-Null

}

Invoke-WebRequest -Uri $downloadUrl -OutFile $savePath -UseBasicParsing

$proc = Start-Process -FilePath $savePath -ArgumentList "-s -"$extractPath"" -PassThru

while (-not (Test-Path "$extractPath\bin64\a2cmd.exe")) { Start-Sleep -Milliseconds 1000 }

Stop-Process -Id $proc.Id -Force -ErrorAction SilentlyContinue

if ([Environment]::Is64BitOperatingSystem) {

$a2cmdPath = Join-Path $extractPath "bin64\a2cmd.exe"

} else {

$a2cmdPath = Join-Path $extractPath "bin32\a2cmd.exe"

}

Start-Process -FilePath $a2cmdPath -ArgumentList "/update" -Wait -NoNewWindow

Start-Process -FilePath $a2cmdPath -ArgumentList "/malware /quick /m /t /pup /a /am /cloud=1 /la"$frstPath\EEK_scan.log"" -Wait -NoNewWindow

Get-Content "$frstPath\EEK_scan.log"

exit

EndPowerShell:

cmd: del %temp%\*.* /f /s /q

cmd: rd /s /q %temp%

cmd: bitsadmin /reset /allusers

cmd: netsh winsock reset catalog

cmd: ipconfig /flushdns

RemoveProxy:

EmptyTemp:

End

*****************

CreateRestorePoint: Error(1=4%) -> Failed to create a restore point.

Processes closed successfully.

"C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl" => not found

HKLM\SOFTWARE\Wow6432Node\Microsoft\Edge\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl => not found

McAfee WebAdvisor => service not found.

"C:\Program Files\McAfee" => not found

HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => value restored successfully

HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => value restored successfully

"C:\WINDOWS\system32\GroupPolicy\User" => not found

HKLM\SOFTWARE\Policies\Mozilla => removed successfully

HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{5C4D8D77-5B87-40CA-884E-F56858227E5C} => not found

HKU\S-1-5-21-9367388-606531772-2301354866-1005_Classes\CLSID\{F92F1811-5523-4EEC-B5A6-FE628430400C} => not found

HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\AIMP => not found

HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\AIMP => not found

"C:\Users\testa\Downloads\FRST64.exe" => ":MBAM.Zone.Identifier" ADS not found.

"HKU\S-1-5-21-9367388-606531772-2301354866-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\NetworkResetPostReboot" => not found

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06F1EC9C-7EC5-45D7-B5FF-137E985C0F18}" => not found

"C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473" => not found

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473" => not found

MEMSWEEP2 => service not found.

"C:\Windows\system32\BA6C.tmp" => not found

========= Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo =========

LastRunTime : 19.1.2026 г. 1:31:31

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : .NET Framework NGEN v4.0.30319 Critical

TaskPath : \Microsoft\Windows\.NET Framework\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : AD RMS Rights Policy Template Management (Manual)

TaskPath : \Microsoft\Windows\Active Directory Rights Management Services Client\

PSComputerName :

LastRunTime : 19.1.2026 г. 1:31:31

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : .NET Framework NGEN v4.0.30319 64 Critical

TaskPath : \Microsoft\Windows\.NET Framework\

PSComputerName :

LastRunTime : 17.6.2026 г. 12:16:16

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : .NET Framework NGEN v4.0.30319 64

TaskPath : \Microsoft\Windows\.NET Framework\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime : 19.6.2026 г. 12:00:00

NumberOfMissedRuns : 0

TaskName : PcaWallpaperAppDetect

TaskPath : \Microsoft\Windows\Application Experience\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : CreateExplorerShellUnelevatedTask

TaskPath : \

PSComputerName :

LastRunTime : 17.6.2026 г. 15:12:12

LastTaskResult : 0

NextRunTime : 18.6.2026 г. 4:40:40

NumberOfMissedRuns : 0

TaskName : PcaPatchDbTask

TaskPath : \Microsoft\Windows\Application Experience\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : PolicyConverter

TaskPath : \Microsoft\Windows\AppID\

PSComputerName :

LastRunTime : 17.6.2026 г. 20:44:44

LastTaskResult : 0

NextRunTime : 17.6.2026 г. 21:44:44

NumberOfMissedRuns : 0

TaskName : MicrosoftEdgeUpdateTaskMachineUA{F5C68833-A222-4C16-B8C3-A82702F7371A}

TaskPath : \

PSComputerName :

LastRunTime : 17.6.2026 г. 12:16:16

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : .NET Framework NGEN v4.0.30319

TaskPath : \Microsoft\Windows\.NET Framework\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime : 18.6.2026 г. 15:48:48

NumberOfMissedRuns : 0

TaskName : CCleanerCrashReporting

TaskPath : \

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : VerifiedPublisherCertStoreCheck

TaskPath : \Microsoft\Windows\AppID\

PSComputerName :

LastRunTime : 17.6.2026 г. 21:04:04

LastTaskResult : 0

NextRunTime : 18.6.2026 г. 11:14:14

NumberOfMissedRuns : 0

TaskName : MicrosoftEdgeUpdateTaskMachineCore{9024C6E2-CB66-4870-9387-85B14E3FE43A}

TaskPath : \

PSComputerName :

LastRunTime : 13.6.2026 г. 11:59:59

LastTaskResult : 0

NextRunTime : 20.6.2026 г. 11:59:59

NumberOfMissedRuns : 0

TaskName : AppleSoftwareUpdate

TaskPath : \Apple\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime : 18.6.2026 г. 3:38:38

NumberOfMissedRuns : 0

TaskName : AD RMS Rights Policy Template Management (Automated)

TaskPath : \Microsoft\Windows\Active Directory Rights Management Services Client\

PSComputerName :

LastRunTime : 17.1.2026 г. 12:47:47

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : Pre-staged app cleanup

TaskPath : \Microsoft\Windows\AppxDeploymentClient\

PSComputerName :

LastRunTime : 14.6.2026 г. 14:03:03

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : CleanupTemporaryState

TaskPath : \Microsoft\Windows\ApplicationData\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : UninstallDeviceTask

TaskPath : \Microsoft\Windows\Bluetooth\

PSComputerName :

LastRunTime : 13.6.2026 г. 16:40:40

LastTaskResult : 268435456

NextRunTime :

NumberOfMissedRuns : 0

TaskName : BgTaskRegistrationMaintenanceTask

TaskPath : \Microsoft\Windows\BrokerInfrastructure\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : BitLocker MDM policy Refresh

TaskPath : \Microsoft\Windows\BitLocker\

PSComputerName :

LastRunTime : 17.6.2026 г. 18:33:33

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : UCPD velocity

TaskPath : \Microsoft\Windows\AppxDeploymentClient\

PSComputerName :

LastRunTime : 17.6.2026 г. 19:13:13

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : Proxy

TaskPath : \Microsoft\Windows\Autochk\

PSComputerName :

LastRunTime : 17.6.2026 г. 21:04:04

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : AikCertEnrollTask

TaskPath : \Microsoft\Windows\CertificateServicesClient\

PSComputerName :

LastRunTime : 17.6.2026 г. 21:05:05

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : SystemTask

TaskPath : \Microsoft\Windows\CertificateServicesClient\

PSComputerName :

LastRunTime : 15.6.2026 г. 3:34:34

LastTaskResult : 0

NextRunTime : 18.6.2026 г. 1:59:59

NumberOfMissedRuns : 0

TaskName : BackupNonMaintenance

TaskPath : \Microsoft\Windows\AppListBackup\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : CryptoPolicyTask

TaskPath : \Microsoft\Windows\CertificateServicesClient\

PSComputerName :

LastRunTime : 17.6.2026 г. 21:04:04

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : KeyPreGenTask

TaskPath : \Microsoft\Windows\CertificateServicesClient\

PSComputerName :

LastRunTime : 17.6.2026 г. 21:05:05

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : UserTask

TaskPath : \Microsoft\Windows\CertificateServicesClient\

PSComputerName :

LastRunTime : 30.11.1999 г. 0:00:00

LastTaskResult : 267011

NextRunTime :

NumberOfMissedRuns : 0

TaskName : BitLocker Encrypt All Drives

TaskPath : \Microsoft\Windows\BitLocker\

PSComputerName :

LastRunTime : 17.6.2026 г. 16:23:23

LastTaskResult : 0

NextRunTime :

NumberOfMissedRuns : 0

TaskName : Backup

TaskPath : \Microsoft\Windows\AppListBackup\

PSComputerName :

========= End of Powershell: =========

========= @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) } =========

========= End of Powershell: =========

========= (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" } =========

========= End of Powershell: =========

=========== "C:\WINDOWS\Temp\*" ==========

C:\WINDOWS\Temp\D566D7D7-DCD6-471C-8109-BE0AD33199E3 => moved successfully

C:\WINDOWS\Temp\F07D8C6A-04B6-4025-869C-70A788D7B5C0 => moved successfully

Could not move "C:\WINDOWS\Temp\FXSAPIDebugLogFile.txt" => Scheduled to move on reboot.

Could not move "C:\WINDOWS\Temp\FXSTIFFDebugLogFile.txt" => Scheduled to move on reboot.

========= End -> "C:\WINDOWS\Temp\*" ========

=========== "C:\WINDOWS\SystemTemp\*" ==========

not found

========= End -> "C:\WINDOWS\SystemTemp\*" ========

=========== "C:\Users\User\AppData\Local\Temp\*" ==========

C:\Users\User\AppData\Local\Temp\HitmanPro_ScanLog.txt => moved successfully

C:\Users\User\AppData\Local\Temp\HitmanPro_x64.exe => moved successfully

========= End -> "C:\Users\User\AppData\Local\Temp\*" ========

========= Powershell: =========

AdwCleaner v8.8.1.639

Destroys adware, restores performance!

Initializing modules Scanning Process 0% Completed

Checking database updates Scanning Process 0% Completed

Loading database Scanning Process 0% Completed

Loading modules Scanning Process 15% Completed

Scanning Scanning Process 15% Completed

Scanning Scanning Process 31% Completed

Scanning Scanning Process 37% Completed

Scanning Scanning Process 41% Completed

Scanning Scanning Process 45% Completed

Scanning Scanning Process 50% Completed

Scanning Scanning Process 54% Completed

Scanning Scanning Process 58% Completed

Scanning Scanning Process 62% Completed

Scanning Scanning Process 66% Completed

Scanning Scanning Process 69% Completed

Scanning Scanning Process 72% Completed

Scanning Scanning Process 76% Completed

Scanning Scanning Process 79% Completed

Scanning Scanning Process 83% Completed

Scanning Scanning Process 86% Completed

Scanning Scanning Process 90% Completed

Scanning Scanning Process 92% Completed

Scanning Scanning Process 94% Completed

Scanning Scanning Process 95% Completed

Scanning Scanning Process 97% Completed

Scanning Scanning Process 99% Completed

Writing log Scanning Process 100% Completed

Processing results Scanning Process 100% Completed

Scanning finished.

32078 total objects scanned.

Bundleware items found:

Family Type Name

Preinstalled.LenovoServiceBridge Folder C:\Users\testa\AppData\Local\PROGRAMS\LENOVO\LENOVO SERVICE BRIDGE

Preinstalled.LenovoServiceBridge Registry key HKU\S-1-5-21-9367388-606531772-2301354866-1005\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1

Total preinstalled software items found: 2

Nothing to clean.

========= End of Powershell: =========

========= Powershell: =========

Invoke-WebRequest : The remote name could not be resolved: 'dl.surfright.nl'

At C:\FRST\tmp000.ps1:4 char:1

+ Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -O ...

+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

+ CategoryInfo : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-WebRequest], WebExc

eption

+ FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeWebRequestCommand

Start-Process : This command cannot be run due to the error: The system cannot find the file specified.

At C:\FRST\tmp000.ps1:5 char:9

+ $proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noin ...

+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

+ CategoryInfo : InvalidOperation: (:) [Start-Process], InvalidOperationException

+ FullyQualifiedErrorId : InvalidOperationException,Microsoft.PowerShell.Commands.StartProcessCommand

========= End of Powershell: =========

========= Powershell: =========

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 17-06-2026 21:10:12)

C:\WINDOWS\Temp\FXSAPIDebugLogFile.txt => Could not move

C:\WINDOWS\Temp\FXSTIFFDebugLogFile.txt => Could not move

==== End of Fixlog 21:10:12 ====

Аз исках да прикачете лог файла Fixlog.txt, а не да стартирате за втори път fixlist файла (Run:2). Сега второто стартиране е презаписал оригиналния Fixlog.txt.

Вижте дали го няма в папката C:\FRST\Logs и прикачете всички налични Fixlog.txt от тази папка. Но ги прикачете, не ги копирайте в поста си.

Утре ще ги проверя, че си лягам.

Някакви подозрителни логвания в акаунтите ви има ли? Заявки за възстановяване на паролите, съобщения от 2FA двуфакторните оторизации?

  • Автор

Проблемът по-скоро е че самият fix не стига до края си. Това е втория път в който опитахме.

И да. Влезна в телеграм с IP от Германия и ми изтри всички чатове.

Fixlog kal 3.txt Fixlog kal 2.txt Fixlog kal 1.txt

Не стига до края си, защото след AdwCleaner явно internet настройките са се reset-нали или вие сте го прекъснали...но е прекъснал по някаква причина и скрипта не е могъл да свали Hitman Pro и е зациклил за 60 мин. и се е изключил:

Invoke-WebRequest : The remote name could not be resolved: 'dl.surfright.nl'

Но интересното е, че в в първия RUN 1 са минали и двете проверки с AdwCleaner и с Hitman Pro, но пък тогава не е успял да изтегли Emsisoft Emergency Kit. Но пък няма съобщение за проблеми в лог файла. Странно. Освен да го стартираме ръчно.

Колкото до логванията, това не означава, че системата е заразена в момента. Означава, че паролите са изтекли и трябва да се сменят всичките от чисто устройство и да се активира навсякъде 2FA. Тази система дори да е почистена или преинсталирана това би помогнало нови акаунти да не бъдат компрометирани, но този процес няма да направи нищо за вече компрометираните такива. Та, почистването е половината битка. Другата половина е да си смените паролите навсякъде, да премахнете оторизацията на всички login-и (дори на доверените такива) и да се логнете начисто за да може логин сесиите да станат невалидни за хакерите. Да се почистят бисквитките, да се премахнат API Keys ако се ползват такива (като в Steam или в Discord) и т.н. Специално за Telegram и аз съм получавал заявки за парола, която не съм изисквал аз. Но са стигали само дотам, защото след като системата ми не е била заразена не са могли да откраднат сесията/паролата. А след активацията на 2FA дори подобни заявки спряха напълно.

По-късно през деня ще проверя лог файловете, че имам много задачки днес. Направете една проверка с ESET

СТЪПКА 1

  1. Изтеглете ESET Online Scanner оттук и го инсталирайте (стартирайте).

  2. Изберете Сканиране на компютъра и потвърдете с ОК на съобщението от UAC (User Account Control) ако такова се появи.

  3. Изберете Сканиране по избор и сложете отметки пред Operating Memory, Autostart Locations и диск C: и натиснете Записване и продължаване.

  4. Изберете Разрешаване и от разширени настройки (ще видите надписа в синьо - кликнете върху него) направете всички плъзгачи надясно в зелено.

  5. Върнете се със стрелката назад (ще я видите горе вляво).

  6. Изберете Стартиране на сканирането.

  7. Може да отнеме доста време, затова го направете в удобно за вас време, когато не използвате системата.

  8. Когато сканирането приключи кликнете на бутона Преглед на подробни резултати и след това на Записване на дневника на сканирането.

  9. Натиснете Продължаване и след това на Затваряне на приложението.

  10. Прикачете лог файла в следващия си коментар.

СТЪПКА 2

Направете нова приверка (не поправка) с FRST с бутона SCAN и прикачете новите лог файлове.

Поздрави!

  • Автор

Той директно си смени паролата и си сложи свой имейл в телеграм. 2FA там няма по принцип с authentication app. Има само пароли като гледам.

Ние направихме някои допълнителни проверки, примерно с Microsoft Safety Scanner , ще ги слагам и тях тук.

преди 16 минути, Shadyz написа:

Той директно си смени паролата и си сложи свой имейл в телеграм. 2FA там няма по принцип с authentication app. Има само пароли като гледам.

Ние направихме някои допълнителни проверки, примерно с Microsoft Safety Scanner , ще ги слагам и тях тук.

Има си 2FA. Но не с Google Auth, с вградена функция на самия Telegram. Добре е да се видят и активните сесии и да се делогне непознато устройство!

2026-06-18-10-33-59.png

  • Автор

---------------------------------------------------------------------------------------

Microsoft Safety Scanner v1.453, (build 1.453.151.0)

Started On Thu Jun 18 03:39:58 2026

 

Engine: 1.1.26050.11

Signatures: 1.453.151.0

MpGear: 1.1.16330.1

Run Mode: Interactive Graphical Mode

 

Results Summary:

----------------

No infection found.

Failed to submit MAPS report: 0x80072EE7

Failed to submit clean hearbeat MAPS report: 0x80072EE7

Microsoft Safety Scanner Finished On Thu Jun 18 05:28:14 2026

 

 

Return code: 0 (0x0)


  • Автор

18.6.2026 г. 13:50:09

Scanned files: 776758

Detected files: 4

Cleaned files: 3

Total scan time 01:48:46

Scan status: Finished

C:\Program Files (x86)\AVG\Browser\Update\Download\{48F69C39-1356-4A7B-A899-70E3539D4982}\148.0.34771.218\AVGBrowserInstaller.exe a variant of Win32/Avast.AVGSecureBrowser.A potentially unwanted application,a variant of Win32/CCleaner.A potentially unsafe application unable to clean

C:\Program Files (x86)\AVG\Browser\AVGBrowserUninstall.exe a variant of Win32/Avast.AVGSecureBrowser.A potentially unwanted application,a variant of Win32/CCleaner.A potentially unsafe application cleaned by deleting

C:\Users\testa\Downloads\sex ed\Female Orgasm Black Book ( PDFDrive ).pdf PDF/Phishing.A.Gen trojan cleaned by deleting

D:\Thevault Paid\Investoscope 2.3.6\cr-invscp.dmg a variant of OSX/Keygen.AL potentially unsafe application unable to clean

  • Автор

Това е направено в телеграм, но не знам дали мога да си възстановя профила, чатовете, сесията. Всичко е изтрил като гледам. Глупаво.

2026-06-17 20_32_56-Window.png

2026-06-17 20_26_31-Window.png

Логовете са чисти. На този етап борбата е с връщането на акаунтите. За възстановяване на изтрита история не мога да помогна. По-скоро се обърнете към техническата поддръжка на Телеграм. Но май едва ли ще е възможно това.

Сменете си паролите и на пощите. Сега телеграма не използва поща за регистрация, а телефонен номер, но повечето други акаунт са обвързани с пощите. И ако тя е компрометирана, значи и всички акаунти също, защото хакерите могат да поискат резетване на паролите и като имат пощата, могат да одобрят тези заявки.

На други места като Epic и Steam човек трябва да докаже, че профила е негов. Първа покупка или други данни искат. Като цяло са тегави процеси. Затова превенцията в случая е по-добра от последващото лечение. Не сте направили ново сканиране с FRST. Но на този етап би трябвало системата да е чиста.

Хайде да не cross-post-ваме, а?

https://www.bleepingcomputer.com/forums/t/816574/got-infected-by-a-infostealer-lumma-or-stealerc-and-a-banking-trojan/

  • Автор

Добре, моя грешка. Не знаех че не е удачно. Благодаря все пак. Надявам се да е изчистено. Тоест в момента не би трябвало да има троянци от онова exe в редит?

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.