Evening everyone, it has been a while since I've had to resort to deep cleaning my computer like this so I'm at a lost. The computer is about a year old now and have been bogging down more and more. A restart without any windows update can take upwards of 10 mins. Normally I don't even attempt such a thing unless I'm going to bed, work or something of the sort. Lately even my more resource demanding games have been having mini freezes for a moment or two even 5 to 10 mins. I'm sure I have downloaded something I shouldn't have or it was attached to something I did actually want.
I have never used FRST before. The last tool I used that was similar to this was HIjackthis so you know it has been awhile since I was doing something like that. Anyways, as directed here are the logs. I do see some fishy things in these but I'm no expert. Lastly, if anyone has suggestions on getting rid of any bloatware I'm down to do that as well.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-01-2025
Ran by Wolfe (administrator) on WOLFE-PC (ASUS System Product Name) (16-01-2025 19:12:20)
Running from C:\Users\Wolfe\Downloads\FRST64.exe
Loaded Profiles: Wolfe
Platform: Microsoft Windows 10 Home Version 22H2 19045.5247 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe <6>
(C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe ->) (ASUSTeK COMPUTER INC. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzAppManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzBTLEManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaConnectServer
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzDeviceManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzDiagnostic
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzIoTDeviceManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSmartlightingDeviceManager
(C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.UserSessionHelper.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(C:\Program Files\Corsair\Corsair iCUE5 Software\clink\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\Corsair iCUE5 Software\clink\Corsair.Service.CpuIdRemote64.exe
(C:\Program Files\Corsair\Corsair iCUE5 Software\clink\Corsair.Service.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\Corsair iCUE5 Software\clink\Corsair.Service.DisplayAdapter.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA Overlay.exe <5>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA app\ShadowPlay\nvsphelper64.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Discord Inc. -> Discord Inc.) C:\Users\Wolfe\AppData\Local\Discord\app-1.0.9177\Discord.exe <6>
(explorer.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\Corsair iCUE5 Software\iCUE.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <21>
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUS Inc.) C:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\2.03.20\AsusFanControlService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.02.23\atkexComSvc.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\LightingService.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe
(services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe
(services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\Corsair iCUE5 Software\clink\Corsair.Service.exe
(services.exe ->) (Corsair Memory, Inc. -> Corsair Memory, Inc.) C:\Program Files\Corsair\Corsair iCUE5 Software\CueLLAccessService.exe
(services.exe ->) (Corsair Memory, Inc. -> Corsair) C:\Program Files\Corsair\Corsair iCUE5 Software\iCUEUpdateService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Razer USA Ltd. -> Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS3\GameManagerService3.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\CortexLauncherService.exe
(services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2411.1.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ) C:\Program Files\ASUS\KINGSTON_Aac_DRAM\AacKingstonDramHal_x86.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Compputer Inc.) C:\Program Files\ASUS\AacMB\Aac3572MbHal_x86.exe <2>
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe <5>
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\AacExtCard\extensionCardHal_x86.exe
(svchost.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS_Aac_DRAM\Aac3572DramHal_x86.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Corsair iCUE5 Software] => C:\Program Files\Corsair\Corsair iCUE5 Software\iCUE Launcher.exe [184872 2023-04-21] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
HKLM-x32\...\Run: [RazerCortex] => C:\Program Files (x86)\Razer\Razer Cortex\RazerCortex.exe [546840 2024-12-31] (Razer USA Ltd. -> Razer Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (Canon Inc. -> CANON INC.)
HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [5006904 2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4412512 2024-12-02] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3597064 2024-10-03] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\Run: [Mozilla-Firefox-308046B0AF4A39CB] => "C:\Program Files\Mozilla Firefox\firefox.exe" -os-autostart [672320 2025-01-14] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\Run: [Discord] => C:\Users\Wolfe\AppData\Local\Discord\Update.exe [1525016 2023-03-22] (Discord Inc. -> GitHub)
HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3597064 2024-10-03] (Razer USA Ltd. -> Razer Inc.)
HKLM\...\Windows x64\Print Processors\Canon MG5300 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDAT.DLL [30208 2012-03-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG5300 series: C:\Windows\system32\CNMLMAT.DLL [385024 2012-03-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\Windows\system32\CNMN6PPM.DLL [359936 2012-06-15] (CANON INC.) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\131.0.6778.265\Installer\chrmstp.exe [2025-01-09] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0FF3F855-D977-4263-B965-4010D2C215CF} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [308584 2023-02-02] (ASUSTeK COMPUTER INC. -> ASUS)
Task: {AF9ED637-492A-4127-951E-0B3B862CB112} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe [1860968 2023-02-02] (ASUSTeK COMPUTER INC. -> ASUS)
Task: {45A79F7B-EB90-4F55-AE49-6E004213F628} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore1d97349f784b2a9 => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-04-20] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
Task: {A0DB1531-EE7D-40B1-902C-D2B8456DA60B} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-04-20] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
Task: {1C1147E7-BA0D-4483-81A8-B37A2283E11C} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe [46631024 2023-03-06] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
Task: {22D2A041-24D1-4947-9ECB-598713967BD6} - System32\Tasks\ASUS\NoiseCancelingEngine => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\MBLedSDK\NoiseCancelingEngine.exe [1254760 2023-03-18] (ASUSTeK COMPUTER INC. -> ASUS)
Task: {C34BF41C-D55C-468C-9B27-D2CA4301F5F6} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (No File)
Task: {BD762367-F8F9-4B10-9E4C-611266E98A38} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem132.0.6833.0{C22F08B7-E9DD-4F63-83C5-479F5BB473B1} => C:\Program Files (x86)\Google\GoogleUpdater\132.0.6833.0\updater.exe [5591136 2024-11-11] (Google LLC -> Google LLC)
Task: {32DEA084-B3A4-4CD2-AA96-A5E618EA07F8} - System32\Tasks\Microsoft\Office\Office Apps Prewarm => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312440 2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {8FDDC5C9-3518-454B-95BF-A38BE8C4179F} - System32\Tasks\Microsoft\Office\Office Apps Prewarm Recurring => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312440 2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {7C91E466-9496-468F-9FC6-F3671FFD1814} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28751032 2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {E1D5251E-1BB9-4F6E-90D1-DB61DDC854E7} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28751032 2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {256D53C9-4CB3-4879-B0E3-3411B5F09010} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312440 2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {BD0E4C0C-D308-4C28-90C5-89A4DC7DFACE} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312440 2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {DBAB5D9D-8F79-4239-9A11-8BF97BDD2F67} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [194672 2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {E560720E-FB4C-4B17-8D44-B85B433830E0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CC6DCF69-FBB5-4A3A-92B6-3D38B362ED34} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {57EA1879-CCFE-4CE3-B157-1EA5AD559952} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {27A49626-9027-47FC-81D0-8998B75E6D6D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {69708F82-67BE-4E11-A483-9B4A1E8CC573} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [672320 2025-01-14] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {19E0FDDF-40FC-4860-9F25-D8495705F16A} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-35897006-1549402385-1321927907-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [672320 2025-01-14] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {CAA69DE2-0590-481C-B051-343AAE89C33C} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34368 2025-01-14] (Mozilla Corporation -> Mozilla Foundation)
Task: {22BA612D-4EE9-4F28-9515-C33E3126CDF5} - System32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA app.exe [3333672 2024-12-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D8D9D487-1CC5-4BD2-A8EC-B8174B078C25} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222504 2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {1E262836-4C8A-4593-8BCE-BA297F7612B2} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-35897006-1549402385-1321927907-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4222504 2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {11F42F4D-EE43-4030-B1C6-D6E3DB6E89F1} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2397440 2024-12-23] (Overwolf Ltd -> Overwolf LTD) -> C:\Program Files (x86)\Overwolf\/RunningFrom Schedule
Task: {E85D0753-7D78-42D2-9DD8-199FE04A4689} - System32\Tasks\RazerCortexScheduleClean => C:\Program Files (x86)\Razer\Razer Cortex\RazerCortex.exe [546840 2024-12-31] (Razer USA Ltd. -> Razer Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 64.59.168.15 64.59.150.132
Tcpip\..\Interfaces\{320e9fdb-11a2-4c7f-8dcb-d67e964be400}: [DhcpNameServer] 64.59.168.15 64.59.150.132
Tcpip\..\Interfaces\{320e9fdb-11a2-4c7f-8dcb-d67e964be400}: [DhcpDomain] wk.shawcable.net
Tcpip\..\Interfaces\{320e9fdb-11a2-4c7f-8dcb-d67e964be400}\35841475D263037343: [DhcpNameServer] 64.59.168.15 64.59.150.132
Tcpip\..\Interfaces\{320e9fdb-11a2-4c7f-8dcb-d67e964be400}\35841475D263037343: [DhcpDomain] wk.shawcable.net
Tcpip\..\Interfaces\{320e9fdb-11a2-4c7f-8dcb-d67e964be400}\45F656370277966696D223E243: [DhcpNameServer] 64.59.168.15 64.59.150.132
Tcpip\..\Interfaces\{320e9fdb-11a2-4c7f-8dcb-d67e964be400}\45F656370277966696D223E243: [DhcpDomain] wk.shawcable.net
Tcpip\..\Interfaces\{320e9fdb-11a2-4c7f-8dcb-d67e964be400}\75F6C66656020586F6E656: [DhcpNameServer] 192.168.165.176
Tcpip\..\Interfaces\{e7b5bf8c-4967-4258-828c-e09f60cf482e}: [DhcpNameServer] 64.59.168.15 64.59.150.132
Tcpip\..\Interfaces\{e7b5bf8c-4967-4258-828c-e09f60cf482e}: [DhcpDomain] wk.shawcable.net
HKLM\System\...\Parameters\PersistentRoutes: [169.254.0.0,255.255.0.0,10.0.0.58,1]
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
Edge:
=======
Edge Profile: C:\Users\Wolfe\AppData\Local\Microsoft\Edge\User Data\Default [2025-01-16]
Edge Extension: (Google Docs Offline) - C:\Users\Wolfe\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-11-07]
Edge Extension: (Edge relevant text changes) - C:\Users\Wolfe\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
FireFox:
========
FF DefaultProfile: 4syrh9jm.default
FF ProfilePath: C:\Users\Wolfe\AppData\Roaming\Mozilla\Firefox\Profiles\4syrh9jm.default [2023-04-20]
FF ProfilePath: C:\Users\Wolfe\AppData\Roaming\Mozilla\Firefox\Profiles\dhg2sufo.default-release [2025-01-17]
FF Session Restore: Mozilla\Firefox\Profiles\dhg2sufo.default-release -> is enabled.
FF Notifications: Mozilla\Firefox\Profiles\dhg2sufo.default-release -> hxxps://www.facebook.com
FF Extension: (AdGuard AdBlocker) - C:\Users\Wolfe\AppData\Roaming\Mozilla\Firefox\Profiles\dhg2sufo.default-release\Extensions\[email protected] [2025-01-10]
FF Extension: (Enhancer for YouTube™) - C:\Users\Wolfe\AppData\Roaming\Mozilla\Firefox\Profiles\dhg2sufo.default-release\Extensions\[email protected] [2024-12-03]
FF Extension: (Capital One Shopping: Save Now) - C:\Users\Wolfe\AppData\Roaming\Mozilla\Firefox\Profiles\dhg2sufo.default-release\Extensions\{aff8af88-06a9-4eee-b383-3af08c47b8c8}.xpi [2024-08-23]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Wolfe\AppData\Roaming\Mozilla\Firefox\Profiles\dhg2sufo.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2024-12-17]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-12-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-12-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.18 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.20 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\Wolfe\AppData\Local\Google\Chrome\User Data\Default [2024-04-21]
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Extension: (Chrome Web Store Payments) - C:\Users\Wolfe\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-04-21]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ArmouryCrateService; C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe [399984 2023-05-13] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.23\atkexComSvc.exe [896872 2023-03-28] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-04-20] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [558104 2022-05-19] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\2.03.20\AsusFanControlService.exe [1722216 2023-05-13] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-04-20] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
S2 AsusROGLSLService; C:\Program Files (x86)\ASUS\AsusROGLSLService\AsusROGLSLService.exe [678760 2023-04-20] (ASUSTeK COMPUTER INC. -> ASUS)
S2 AsusUpdateCheck; C:\Windows\System32\AsusUpdateCheck.exe [1132000 2025-01-16] (ASUSTeK COMPUTER INC. -> )
S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [3318400 2025-01-15] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13617896 2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
S3 CorsairDeviceListerService; C:\Program Files\Corsair\Corsair iCUE5 Software\CorsairDeviceListerService.exe [146984 2023-04-21] (Corsair Memory, Inc. -> Corsair)
R2 CorsairLLAService; C:\Program Files\Corsair\Corsair iCUE5 Software\CueLLAccessService.exe [238632 2023-04-21] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
R2 CorsairService; C:\Program Files\Corsair\Corsair iCUE5 Software\clink\Corsair.Service.exe [84008 2023-04-21] (Corsair Memory, Inc. -> Corsair Memory, Inc.)
R2 CortexLauncherService; C:\Program Files (x86)\Razer\Razer Cortex\CortexLauncherService.exe [715736 2024-12-31] (Razer USA Ltd. -> Razer Inc.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncHelper.exe [3530280 2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
R2 GameSDK Service; C:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe [397544 2022-05-31] (ASUSTeK COMPUTER INC. -> ASUS Inc.)
R3 iCUEUpdateService; C:\Program Files\Corsair\Corsair iCUE5 Software\iCUEUpdateService.exe [310824 2023-04-21] (Corsair Memory, Inc. -> Corsair)
R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [4799336 2023-09-13] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe [1447680 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\Display.NvContainer\NVDisplay.Container.exe [1275568 2024-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\24.244.1204.0003\OneDriveUpdaterService.exe [3876392 2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2397440 2024-12-23] (Overwolf Ltd -> Overwolf LTD)
R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [1878448 2024-07-25] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [231856 2024-07-25] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Chroma Stream Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe [1361360 2023-03-06] (Razer USA Ltd. -> Razer Inc.)
S2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [256264 2023-02-10] (Razer USA Ltd. -> Razer Inc)
R2 Razer Game Manager Service 3; C:\Program Files (x86)\Razer\Razer Services\GMS3\GameManagerService3.exe [364800 2024-12-12] (Razer USA Ltd. -> Razer Inc)
S2 Razer Synapse Service; C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe [298248 2024-10-03] (Razer USA Ltd. -> Razer Inc.)
R2 ROG Live Service; C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe [1665648 2023-07-26] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
S2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [538416 2024-11-20] (Razer USA Ltd. -> Razer Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe [3199672 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe [141952 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdgpio3; C:\Windows\System32\drivers\amdgpio3.sys [36928 2022-06-03] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [34384 2022-02-10] (ASUSTeK Computer Inc. -> )
R1 Asusgio3; C:\Windows\system32\drivers\AsIO3.sys [49256 2022-08-16] (ASUSTeK COMPUTER INC. -> )
R2 CorsairLLAccess8F050F5E415C1A5882EB9FF7CE2BC59B7BE3A953; C:\Program Files\Corsair\Corsair iCUE5 Software\CorsairLLAccess64.sys [21752 2023-04-21] (Microsoft Windows Hardware Compatibility Publisher -> Corsair Memory, Inc.)
R3 cpuz154; C:\Windows\temp\cpuz154\cpuz154_x64.sys [40976 2025-01-16] (Microsoft Windows Hardware Compatibility Publisher -> CPUID) <==== ATTENTION
S3 cpuz158; C:\Windows\temp\cpuz158\cpuz158_x64.sys [44592 2025-01-06] (Microsoft Windows Hardware Compatibility Publisher -> CPUID) <==== ATTENTION
R1 CTIAIO; C:\Windows\system32\drivers\CtiAIo64.sys [32320 2023-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 e2fexpress; C:\Windows\System32\DriverStore\FileRepository\e2f.inf_amd64_bf51b653ec31b8ab\e2f.sys [531568 2023-07-02] (Intel Corporation -> Intel Corporation)
R3 MpKsldaf77c69; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D8408A2F-02EC-46C4-9B8E-93DBF71BC9AC}\MpKslDrv.sys [267552 2025-01-17] (Microsoft Windows -> Microsoft Corporation)
R1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [18496 2022-06-09] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd)
R3 MTKBTFilterx64; C:\Windows\System32\drivers\mtkbtfilterx.sys [361472 2022-11-16] (Microsoft Windows Hardware Compatibility Publisher -> MediaTek Inc.)
R3 mtkwlex; C:\Windows\System32\drivers\mtkwl6ex.sys [1617920 2022-11-20] (Microsoft Windows Hardware Compatibility Publisher -> MediaTek Inc.)
R3 RzCommon; C:\Windows\System32\drivers\RzCommon.sys [64168 2022-08-18] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_0084; C:\Windows\System32\drivers\RzDev_0084.sys [54152 2020-08-24] (Razer USA Ltd. -> Razer Inc)
S3 RzDev_021e; C:\Windows\System32\drivers\RzDev_021e.sys [54168 2020-08-24] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_02a1; C:\Windows\System32\drivers\RzDev_02a1.sys [64664 2022-08-18] (Razer USA Ltd. -> Razer Inc)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [22104 2024-10-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [606624 2024-10-30] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105888 2024-10-30] (Microsoft Windows -> Microsoft Corporation)
U4 AppMgmt; no ImagePath
S3 cpuz157; \??\C:\Windows\temp\cpuz157\cpuz157_x64.sys [X] <==== ATTENTION
U4 CscService; no ImagePath
U4 napagent; no ImagePath
S4 NvModuleTracker; \SystemRoot\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys [X]
U4 PeerDistSvc; no ImagePath
S3 SIUSBXP; \??\C:\Windows\system32\drivers\SiUSBXp.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-01-16 19:12 - 2025-01-16 19:15 - 000031747 _____ C:\Users\Wolfe\Downloads\FRST.txt
2025-01-16 19:08 - 2025-01-16 19:08 - 002403328 _____ (Farbar) C:\Users\Wolfe\Downloads\FRST64.exe
2025-01-16 19:08 - 2025-01-16 19:08 - 000000000 ____D C:\Users\Wolfe\Downloads\FRST-OlderVersion
2025-01-16 19:06 - 2025-01-16 19:14 - 000000000 ____D C:\FRST
2025-01-16 19:02 - 2025-01-16 19:02 - 000388608 _____ (Trend Micro Inc.) C:\Users\Wolfe\Downloads\HijackThis.exe
2025-01-16 06:05 - 2025-01-16 06:05 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2025-01-15 01:23 - 2025-01-15 01:23 - 000000000 ___HD C:\$WinREAgent
2025-01-14 22:17 - 2025-01-14 22:17 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2025-01-14 22:17 - 2025-01-14 22:17 - 000002132 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-01-14 10:43 - 2025-01-16 05:35 - 000000000 ____D C:\Program Files\Mozilla Firefox
2025-01-11 19:49 - 2025-01-11 19:49 - 003161705 _____ C:\Users\Wolfe\Downloads\elvui-13.81(2).zip
2025-01-07 20:15 - 2025-01-07 20:15 - 000180264 _____ C:\Users\Wolfe\Downloads\Statement_122024_5998.pdf
2024-12-28 18:06 - 2024-12-04 10:05 - 002060664 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2024-12-28 18:06 - 2024-12-04 10:05 - 002060664 _____ C:\Windows\system32\vulkaninfo.exe
2024-12-28 18:06 - 2024-12-04 10:05 - 001600376 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2024-12-28 18:06 - 2024-12-04 10:05 - 001600376 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2024-12-28 18:06 - 2024-12-04 10:05 - 001452432 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2024-12-28 18:06 - 2024-12-04 10:05 - 001452432 _____ C:\Windows\system32\vulkan-1.dll
2024-12-28 18:06 - 2024-12-04 10:05 - 001301880 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2024-12-28 18:06 - 2024-12-04 10:05 - 001301880 _____ C:\Windows\SysWOW64\vulkan-1.dll
2024-12-28 18:06 - 2024-12-04 10:05 - 000478384 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2024-12-28 18:06 - 2024-12-04 10:05 - 000374432 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2024-12-28 18:06 - 2024-12-04 10:02 - 001114792 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2024-12-28 18:06 - 2024-12-04 10:02 - 000670352 _____ (NVIDIA Corporation) C:\Windows\system32\nvofapi64.dll
2024-12-28 18:06 - 2024-12-04 10:02 - 000505504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvofapi.dll
2024-12-28 18:06 - 2024-12-04 10:01 - 025450120 _____ C:\Windows\system32\nvidia-pcc.exe
2024-12-28 18:06 - 2024-12-04 10:01 - 001554608 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2024-12-28 18:06 - 2024-12-04 10:01 - 001208992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2024-12-28 18:06 - 2024-12-04 10:01 - 000863888 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2024-12-28 18:06 - 2024-12-04 10:00 - 016811696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2024-12-28 18:06 - 2024-12-04 10:00 - 002185360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2024-12-28 18:06 - 2024-12-04 10:00 - 001634464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2024-12-28 18:06 - 2024-12-04 10:00 - 001042072 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2024-12-28 18:06 - 2024-12-04 10:00 - 000801432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2024-12-28 18:06 - 2024-12-04 10:00 - 000462480 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2024-12-28 18:06 - 2024-12-04 09:59 - 017736840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2024-12-28 18:06 - 2024-12-04 09:59 - 006953104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2024-12-28 18:06 - 2024-12-04 09:59 - 005909664 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2024-12-28 18:06 - 2024-12-04 09:59 - 005435544 _____ (NVIDIA Corporation) C:\Windows\system32\nvcudadebugger.dll
2024-12-28 18:06 - 2024-12-04 09:59 - 003807888 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2024-12-28 18:06 - 2024-12-04 09:59 - 000853680 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2024-12-28 18:06 - 2024-12-04 09:58 - 007158560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2024-12-28 18:06 - 2024-12-04 09:58 - 006236264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2024-12-28 18:06 - 2024-12-03 17:11 - 000132703 _____ C:\Windows\system32\nvinfo.pb
2024-12-28 18:06 - 2024-12-03 17:11 - 000125048 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2024-12-28 18:02 - 2024-12-28 18:02 - 000003834 _____ C:\Windows\system32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2024-12-28 18:02 - 2024-12-28 18:02 - 000001434 _____ C:\Users\Public\Desktop\NVIDIA.lnk
2024-12-28 18:02 - 2024-12-28 18:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2024-12-28 18:01 - 2024-12-18 04:26 - 003074088 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2024-12-28 18:01 - 2024-12-18 04:26 - 002369064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2024-12-28 18:01 - 2024-12-18 04:07 - 000180760 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2024-12-28 18:01 - 2024-12-18 04:07 - 000159768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2024-12-28 13:51 - 2024-12-28 19:18 - 000000000 ____D C:\Users\Wolfe\AppData\Roaming\Path of Exile 2
2024-12-28 13:18 - 2024-12-28 13:18 - 000000223 _____ C:\Users\Wolfe\Desktop\Path of Exile 2.url
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-01-16 19:02 - 2023-04-19 21:18 - 000000000 ____D C:\Program Files (x86)\Steam
2025-01-16 19:02 - 2023-04-19 04:45 - 000000000 ____D C:\Users\Wolfe\AppData\Local\VirtualStore
2025-01-16 18:58 - 2024-10-22 18:00 - 000000000 ____D C:\Users\Wolfe\AppData\Local\Discord
2025-01-16 18:52 - 2023-04-19 20:32 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-01-16 18:17 - 2023-04-19 20:34 - 000000000 ____D C:\Windows\system32\MRT
2025-01-16 18:17 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\AppReadiness
2025-01-16 18:17 - 2019-12-07 01:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-01-16 18:14 - 2023-04-19 04:36 - 000000000 ____D C:\Windows\system32\SleepStudy
2025-01-16 17:51 - 2023-04-19 20:34 - 206927936 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2025-01-16 17:38 - 2023-04-19 21:35 - 000000000 ____D C:\Program Files\ASUS
2025-01-16 15:55 - 2023-04-19 21:43 - 000000000 ____D C:\Users\Wolfe\AppData\Roaming\discord
2025-01-16 06:07 - 2023-04-28 21:51 - 000000000 ____D C:\Program Files\Microsoft Office
2025-01-16 06:07 - 2019-12-07 01:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-01-16 05:59 - 2022-09-07 19:13 - 000000000 ____D C:\Windows\SystemTemp
2025-01-16 05:54 - 2023-04-19 04:45 - 000000000 ____D C:\Users\Wolfe\AppData\Local\Packages
2025-01-16 05:53 - 2024-10-22 18:01 - 000002243 _____ C:\Users\Wolfe\Desktop\Discord.lnk
2025-01-16 05:48 - 2023-04-19 04:47 - 000000000 ___RD C:\Users\Wolfe\OneDrive
2025-01-16 05:48 - 2019-12-07 01:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-01-16 05:43 - 2023-04-19 04:46 - 000840602 _____ C:\Windows\system32\PerfStringBackup.INI
2025-01-16 05:43 - 2019-12-07 01:13 - 000000000 ____D C:\Windows\INF
2025-01-16 05:36 - 2023-04-19 20:37 - 000000000 ____D C:\ProgramData\NVIDIA
2025-01-16 05:35 - 2024-09-29 17:02 - 000008192 ___SH C:\DumpStack.log.tmp
2025-01-16 05:35 - 2023-04-29 23:26 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2025-01-16 05:35 - 2023-04-19 20:32 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-01-16 05:35 - 2023-04-19 04:36 - 001180016 _____ () C:\Windows\system32\wpbbin.exe
2025-01-16 05:35 - 2023-04-19 04:36 - 001132000 _____ C:\Windows\system32\AsusUpdateCheck.exe
2025-01-16 05:35 - 2023-04-19 04:36 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-01-16 05:34 - 2019-12-07 01:03 - 000524288 _____ C:\Windows\system32\config\BBI
2025-01-16 05:28 - 2023-04-28 22:00 - 000000000 ____D C:\Users\Wolfe\AppData\Roaming\Microsoft\Excel
2025-01-16 05:25 - 2023-04-19 21:27 - 000000000 ____D C:\Users\Wolfe\AppData\Local\Battle.net
2025-01-15 19:27 - 2023-04-19 20:32 - 000001065 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2025-01-15 19:27 - 2023-04-19 20:32 - 000001053 _____ C:\Users\Public\Desktop\Firefox.lnk
2025-01-15 19:27 - 2023-04-19 20:32 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2025-01-15 18:49 - 2023-04-19 20:42 - 000000000 ____D C:\ProgramData\Package Cache
2025-01-15 01:39 - 2019-12-07 01:03 - 000000000 ____D C:\Windows\CbsTemp
2025-01-14 22:17 - 2023-04-19 21:15 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-35897006-1549402385-1321927907-1001
2025-01-12 02:39 - 2023-04-19 04:37 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-01-12 02:39 - 2023-04-19 04:37 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-01-10 17:01 - 2023-04-19 21:26 - 000000000 ____D C:\Program Files (x86)\Battle.net
2025-01-10 16:47 - 2023-04-19 04:45 - 000000000 ____D C:\ProgramData\Packages
2025-01-10 16:43 - 2023-04-21 18:11 - 000000000 ____D C:\Users\Wolfe\AppData\Local\CrashDumps
2025-01-10 04:30 - 2023-04-19 21:36 - 000000000 ____D C:\Users\Wolfe\AppData\Local\Overwolf
2025-01-09 13:39 - 2023-04-22 20:27 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-01-09 13:39 - 2023-04-22 20:27 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-01-07 00:01 - 2023-04-19 21:37 - 000002325 _____ C:\Users\Wolfe\Desktop\CurseForge.lnk
2025-01-06 20:59 - 2023-04-19 20:37 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-01-06 05:53 - 2023-04-19 21:36 - 000000000 ____D C:\Users\Wolfe\AppData\Local\D3DSCache
2025-01-06 05:51 - 2023-04-19 21:31 - 000003964 _____ C:\Windows\system32\Tasks\RazerCortexScheduleClean
2025-01-06 05:50 - 2023-04-19 20:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer Cortex
2025-01-03 18:09 - 2023-08-06 16:56 - 000002325 _____ C:\Users\Wolfe\Desktop\Warcraft Logs Companion.lnk
2024-12-30 02:25 - 2023-04-19 20:37 - 000000000 ____D C:\Users\Wolfe\AppData\Local\NVIDIA
2024-12-30 02:07 - 2023-04-19 04:44 - 000000000 ____D C:\Users\Wolfe
2024-12-29 01:32 - 2023-04-19 21:26 - 000000000 ____D C:\Users\Wolfe\AppData\Local\Steam
2024-12-28 18:07 - 2023-04-22 20:26 - 000000000 ____D C:\Users\Wolfe\AppData\Local\NVIDIA Corporation
2024-12-28 18:07 - 2023-04-21 19:07 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2024-12-28 18:07 - 2023-04-19 20:37 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2024-12-28 13:51 - 2023-04-21 19:06 - 000000000 ____D C:\Users\Wolfe\Documents\My Games
2024-12-28 13:18 - 2023-05-05 17:56 - 000000000 ____D C:\Users\Wolfe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2024-12-26 14:59 - 2023-04-19 21:37 - 000000000 ____D C:\Program Files (x86)\Overwolf
2024-12-21 15:33 - 2023-04-19 04:37 - 000003536 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-12-21 15:33 - 2023-04-19 04:37 - 000003412 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-12-18 04:26 - 2023-05-13 15:57 - 000270888 _____ C:\Windows\system32\FvSDK_x64.dll
2024-12-18 04:26 - 2023-05-13 15:57 - 000245288 _____ C:\Windows\SysWOW64\FvSDK_x86.dll
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-01-2025
Ran by Wolfe (16-01-2025 19:15:52)
Running from C:\Users\Wolfe\Downloads
Microsoft Windows 10 Home Version 22H2 19045.5247 (X64) (2023-04-19 12:41:42)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-35897006-1549402385-1321927907-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-35897006-1549402385-1321927907-503 - Limited - Disabled)
Guest (S-1-5-21-35897006-1549402385-1321927907-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-35897006-1549402385-1321927907-504 - Limited - Disabled)
Wolfe (S-1-5-21-35897006-1549402385-1321927907-1001 - Administrator - Enabled) => C:\Users\Wolfe
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\uTorrent) (Version: 3.6.0.47142 - BitTorrent Limited)
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 4.07.13.2243 - Advanced Micro Devices, Inc.)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.130 - Advanced Micro Devices, Inc.) Hidden
AMD I2C Driver (HKLM-x32\...\{B31D92D9-2914-46B0-9738-F668A563DE73}) (Version: 1.2.0.119 - Advanced Micro Devices, Inc.) Hidden
AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.89 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.19.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 8.0.0.13 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\{2b787d65-59ec-46d5-9e6b-8b4761e7903c}) (Version: 4.07.13.2243 - Advanced Micro Devices, Inc.) Hidden
AniMe Matrix MB EN (HKLM\...\{399B6DA7-B609-426E-95F8-B9A83FB7D06E}) (Version: 1.0.1 - ASUS)
ARMOURY CRATE Lite Service (HKLM\...\{EF3944FF-2501-4568-B15C-5701E726719E}) (Version: 5.6.3 - ASUS)
ASUS AIOFan HAL (HKLM\...\{EAE80DED-1A39-41C5-9F60-87CC947F6454}) (Version: 1.2.0.0 - ASUSTek COMPUTER INC.) Hidden
ASUS AIOFan HAL (HKLM-x32\...\{45ece30d-a966-424e-9bce-f740797c5348}) (Version: 1.2.0.0 - ASUSTek COMPUTER INC.) Hidden
ASUS AURA Extension Card HAL (HKLM\...\{237E1CAC-1708-4940-AC34-DF15C079AB70}) (Version: 1.1.0.18 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Extension Card HAL (HKLM-x32\...\{4e2b05b0-eb08-41e5-9eb3-cdcc43d6bee0}) (Version: 1.1.0.18 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Motherboard HAL (HKLM\...\{4EBEAC95-76BC-46A8-8644-6E2F1C87CF70}) (Version: 1.3.9.4 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Motherboard HAL (HKLM-x32\...\{39cdaa93-c446-4421-a337-1e52705dd2f8}) (Version: 1.3.9.4 - ASUSTeK COMPUTER INC.) Hidden
ASUS Aura SDK (HKLM\...\{CF8E6E00-9C03-4440-81C0-21FACB921A6B}) (Version: 3.04.39 - ASUSTek COMPUTER INC.) Hidden
ASUS Framework Service (HKLM-x32\...\{339A6383-7862-46DA-8A9D-E84180EF9424}) (Version: 3.2.1.2 - ASUSTeK Computer Inc.)
ASUS Motherboard (HKLM-x32\...\{93795eb8-bd86-4d4d-ab27-ff80f9467b37}) (Version: 4.00.01 - ASUSTek Computer Inc.)
ASUS Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.107.129 - ASUSTeK Computer Inc.) Hidden
AURA DRAM Component (HKLM\...\{6FB66775-BB93-4D0A-9871-4CC9B2E87BF3}) (Version: 1.1.23 - ASUS) Hidden
AURA DRAM Component (HKLM-x32\...\{179f415f-2ff3-4db1-bcc1-d5730f746db8}) (Version: 1.1.23 - ASUS) Hidden
AURA lighting effect add-on (HKLM-x32\...\{1E2EA04B-FCA7-457E-B6F4-F33E1858E859}) (Version: 0.0.29 - ASUS)
AURA lighting effect add-on x64 (HKLM\...\{C5A4A164-4428-4931-B728-96EEF0FA3C44}) (Version: 0.0.29 - ASUS)
AURA Service (HKLM-x32\...\{0fcadbd2-1a6a-4a4a-a56d-fc7163d9b3fa}) (Version: 3.07.25 - ASUSTeK Computer Inc.)
AURA Service (HKLM-x32\...\{56EEEF7D-0AE3-401A-898B-581719D005AE}) (Version: 3.07.25 - ASUSTeK Computer Inc.) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Burning Crusade Classic (HKLM-x32\...\Burning Crusade Classic) (Version: - Blizzard Entertainment)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon MG5300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series) (Version: - Canon Inc.)
Cataclysm Classic (HKLM-x32\...\Cataclysm Classic) (Version: - Blizzard Entertainment)
Corsair iCUE5 Software (HKLM\...\{A9B0B2D7-8C59-4413-A2FB-99EDBE65A608}) (Version: 5.0.146 - Corsair)
CurseForge (HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\Overwolf_cchhcaiapeikjbdbpfplgmpobbcdkdaphclbmkbj) (Version: 1.269.1.2113 - Overwolf app)
Diablo IV (HKLM-x32\...\Diablo IV) (Version: - Blizzard Entertainment)
Discord (HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\Discord) (Version: 1.0.9012 - Discord Inc.)
ENE RGB HAL (HKLM\...\{E050E98C-5524-4AFB-9E53-97700BEF2C02}) (Version: 1.1.40.3 - Ene Tech.) Hidden
ENE RGB HAL (HKLM-x32\...\{7f329536-2468-4b20-88dc-5e2defcd5ff3}) (Version: 1.1.40.3 - Ene Tech.) Hidden
ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.10.1 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM-x32\...\{6b617af3-c8f4-45a8-bf47-b32ffb4da1cc}) (Version: 1.0.10.1 - ENE TECHNOLOGY INC.) Hidden
GameSDK Service (HKLM-x32\...\{021d69c3-d686-4a94-8fb5-fd1ee782fb14}) (Version: 1.0.5.0 - ASUSTek COMPUTER INC.)
GameSDK Service (HKLM-x32\...\{7160DA8D-3F25-4F6E-ABC8-F693551D82FA}) (Version: 1.0.5.0 - ASUSTek COMPUTER INC.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 131.0.6778.265 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
Intel® Network Connections 28.0.0.2 (HKLM\...\{2D8EB790-843E-4825-ABE7-CB1A52F1C5B3}) (Version: 28.0.0.2 - Intel) Hidden
Intel® Network Connections 28.0.0.2 (HKLM\...\PROSetDX) (Version: 28.0.0.2 - Intel)
Kingston AURA DRAM Component (HKLM\...\{965CDF5F-901C-476F-B3A8-7396701B1129}) (Version: 1.1.18 - KINGSTON COMPONENTS INC.) Hidden
Kingston AURA DRAM Component (HKLM-x32\...\{a9913343-8463-4fd2-8a33-ae89cbbfe139}) (Version: 1.1.18 - KINGSTON COMPONENTS INC.) Hidden
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.18429.20044 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 131.0.2903.146 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 131.0.2903.146 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 24.244.1204.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34433 (HKLM-x32\...\{804e7d66-ccc2-4c12-84ba-476da31d103d}) (Version: 14.42.34433.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.42.34433 (HKLM-x32\...\{e7802eac-3305-4da0-9378-e55d1ed05518}) (Version: 14.42.34433.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34433 (HKLM\...\{E1902FC6-C423-4719-AB8A-AC7B2694B367}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34433 (HKLM\...\{382F1166-A409-4C5B-9B1E-85ED538B8291}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.42.34433 (HKLM-x32\...\{84E3E712-6343-484B-8B6C-9F145F019A70}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.42.34433 (HKLM-x32\...\{C2BB95AA-90F3-4891-81C1-A7E565BB836C}) (Version: 14.42.34433 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mozilla Firefox (x64 en-CA) (HKLM\...\Mozilla Firefox 134.0.1 (x64 en-CA)) (Version: 134.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 112.0.1 - Mozilla)
NVIDIA app 11.0.1.189 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NvApp) (Version: 11.0.1.189 - NVIDIA Corporation)
NVIDIA FrameView SDK 1.4.10624.35034762 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.4.10624.35034762 - NVIDIA Corporation)
NVIDIA Graphics Driver 566.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 566.36 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.4.2.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.2.6 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 29.1.3 - OBS Project)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.18429.20044 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.18429.20044 - Microsoft Corporation) Hidden
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.266.1.26 - Overwolf Ltd.)
Patriot Viper DRAM RGB (HKLM\...\{1F9C282E-CCB4-4D8E-A5CB-7B74DFCD8C95}) (Version: 1.0.9.5 - Patriot Memory) Hidden
Patriot Viper DRAM RGB (HKLM-x32\...\{31850f16-ce9f-4dec-81ca-222c617a9115}) (Version: 1.0.9.5 - Patriot Memory) Hidden
Patriot Viper M2 SSD RGB (HKLM\...\{8B4C0A3D-C135-4E1F-98D8-3926494B4D61}) (Version: 1.1.0.2 - Patriot Memory) Hidden
Patriot Viper M2 SSD RGB (HKLM-x32\...\{959e5696-0edd-4896-b1d8-54aaa725f770}) (Version: 1.1.0.2 - Patriot Memory) Hidden
PHISON HAL (HKLM\...\{966E33F0-6786-4B38-AA29-C1B3F6C1955D}) (Version: 1.0.9.0 - PHISON Electronics Corp.) Hidden
PHISON HAL (HKLM-x32\...\{549da357-1b81-456b-83f2-dcc47c41dfff}) (Version: 1.0.9.0 - PHISON Electronics Corp.) Hidden
Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 3.0.0.0 - Advanced Micro Devices, Inc.) Hidden
Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 11.0.46.0 - Razer Inc.)
Razer Synapse (HKLM-x32\...\Razer Synapse) (Version: 3.9.1008.100321 - Razer Inc.)
Reverse1999 (HKLM-x32\...\Reverse1999) (Version: 1.0.1.0 - BLUEPOCH GAMES CO., LIMITED)
Roblox Player for Wolfe (HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\roblox-player) (Version: - Roblox Corporation)
ROG Live Service (HKLM\...\{2D87BFB6-C184-4A59-9BBE-3E20CE797631}) (Version: 2.1.5.0 - ASUSTek COMPUTER INC.)
ROGFontInstaller (HKLM\...\{605108C1-153E-43D8-8A67-7CE326B00ECA}) (Version: 1.0.0 - ASUS)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TradeSkillMaster Application version 1.0 (HKLM-x32\...\{c44da794-b956-4d50-8733-346d56ae63c7}_is1) (Version: 1.0 - TradeSkillMaster)
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 147.0.10965 - Ubisoft)
Universal Holtek RGB DRAM (HKLM\...\{826388E4-E31F-4514-948B-3BB954FB3EAF}) (Version: 1.0.0.4 - PD) Hidden
Universal Holtek RGB DRAM (HKLM-x32\...\{c8b4688a-f5d4-4236-aec4-df260a88ccc4}) (Version: 1.0.0.4 - PD) Hidden
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{DA80A019-4C3B-4DAA-ACA1-6937D7CAAF9E}) (Version: 8.94.0.0 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Voxengo Marvel GEQ (HKLM\...\Voxengo Marvel GEQ_is1) (Version: 1.15 - Voxengo)
Warcraft Logs Companion (HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\Overwolf_ecboebafnpgnolnpgppohegbpjbhffiahodgijdp) (Version: 8.15.14 - Overwolf app)
WD_BLACK AN1500 (HKLM\...\{085E2365-0A70-4230-B664-02D5E4FE7E9C}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
WD_BLACK AN1500 (HKLM-x32\...\{e42c5874-37b0-4977-9e8d-70bf006e1f76}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
WinRAR 6.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.21.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
World of Warcraft Classic Era (HKLM-x32\...\World of Warcraft Classic Era) (Version: - Blizzard Entertainment)
Packages:
=========
ARMOURY CRATE -> C:\Program Files\WindowsApps\B9ECED6F.ArmouryCrate_5.9.13.0_x64__qmba6cd70vzyy [2024-12-18] (ASUSTeK COMPUTER INC.)
AURA Creator -> C:\Program Files\WindowsApps\B9ECED6F.AURACreator_3.9.3.0_x64__qmba6cd70vzyy [2024-06-30] (ASUSTeK COMPUTER INC.)
Disney+ -> C:\Program Files\WindowsApps\Disney.37853FC22B2CE_2024.3.211.0_neutral__6rarf9sa4v8jt [2024-03-27] (Disney)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_157.1.1186.0_x64__v10z8vjag6ke6 [2025-01-14] (HP Inc.)
Microsoft Defender -> C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2412.12001.0_x64__8wekyb3d8bbwe [2025-01-01] (Microsoft Corporation) [Startup Task]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.967.0_x64__56jybvy8sckqj [2024-12-26] (NVIDIA Corp.)
Spotify - Music and Podcasts -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0 [2025-01-16] (Spotify AB) [Startup Task]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-35897006-1549402385-1321927907-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> "C:\Users\Wolfe\AppData\Local\Microsoft\Teams\current\Teams.exe" --toast => No File
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-02-16] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-02-16] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.244.1204.0003\FileSyncShell64.dll [2025-01-15] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvshext.dll [2024-12-04] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2023-02-16] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2023-02-16] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2023-04-19 21:38 - 2023-02-03 16:10 - 000525312 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ac_node_addon\prebuilds\win32-ia32\node.napi.node
2023-04-19 21:38 - 2022-09-01 08:47 - 000520192 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ffi-napi\prebuilds\win32-ia32\node.napi.node
2023-04-19 21:38 - 2022-09-01 08:47 - 000483328 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\node-system-fonts\build\Release\system-fonts.node
2023-04-19 21:38 - 2022-09-01 08:47 - 000510464 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ref-napi\prebuilds\win32-ia32\node.napi.node
2023-04-19 21:38 - 2022-09-27 13:56 - 000319488 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\sharp\prebuilds\win32-ia32\node.napi.node
2023-04-19 21:38 - 2022-09-01 08:47 - 000786432 _____ () [File not signed] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\usb-detection\prebuilds\win32-ia32\node.napi.node
2023-04-19 21:38 - 2022-06-08 09:33 - 000081920 _____ () [File not signed] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\WindowID\WindowID.dll
2024-06-25 17:43 - 2011-01-15 15:45 - 000319488 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNSS_ENU.DLL
2024-06-25 17:41 - 2012-06-14 16:18 - 000359936 _____ (CANON INC.) [File not signed] C:\Windows\System32\CNMN6PPM.DLL
2024-12-05 16:37 - 2024-12-03 12:40 - 005378048 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libavcodec-61.dll
2024-12-05 16:37 - 2024-12-03 12:40 - 000875008 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libavfilter-10.dll
2024-12-05 16:37 - 2024-12-03 12:40 - 001674240 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libavformat-61.dll
2024-12-05 16:37 - 2024-12-03 12:40 - 001640960 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libavutil-59.dll
2024-12-05 16:37 - 2024-12-03 12:40 - 000630272 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libswresample-5.dll
2024-12-05 16:37 - 2024-12-03 12:40 - 001092608 _____ (FFmpeg Project) [File not signed] C:\Program Files (x86)\Steam\libswscale-8.dll
2023-04-20 16:48 - 2023-04-20 16:48 - 000090112 _____ (Silicon Laboratories, Inc.) [File not signed] C:\Program Files\Corsair\Corsair iCUE5 Software\clink\SiUSBXp.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2024-12-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-01-14] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 01:14 - 2019-12-07 01:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Razer\ChromaBroadcast\bin;C:\Program Files\Razer\ChromaBroadcast\bin;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\WindowsApps;C:\Program Files\NVIDIA Corporation\NVIDIA app\NvDLISR
HKU\S-1-5-21-35897006-1549402385-1321927907-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Wolfe\Pictures\Saved Pictures\1132784.png
DNS Servers: 64.59.168.15 - 64.59.150.132
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Intel® Ethernet Controller I225-V -> e2f.sys
Bluetooth Network Connection: Bluetooth Device (Personal Area Network) -> bthpan.sys
Wi-Fi: RZ608 Wi-Fi 6E 80MHz -> mtkwl6ex.sys
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run32: => "RazerCortex"
HKU\S-1-5-21-35897006-1549402385-1321927907-1001\...\StartupApproved\Run: => "Synapse3"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{DA883DF2-91D9-4561-AA1C-FE7B1B6164F6}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{D653137D-8CAC-4219-B1CF-A0D04582F42A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{1D226292-A15A-41C5-B406-61391860FAAC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{1931B891-1E76-47D1-9B54-8AE08D81F017}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{5C81B250-01C7-405C-BF3C-15CC9D27BA56}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{1CFE5603-69BD-4453-8E39-AF0CB7364795}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{DF1F6C59-6D9E-4ADE-80F6-9D615258598B}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.)
FirewallRules: [{209E6CDC-7269-44B8-9A0F-0FAA75EA6528}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmouryHtmlDebugServer.exe (ASUSTeK COMPUTER INC. -> ASUS)
FirewallRules: [{5A92544A-63B8-45C0-BC68-FAC4203C6ABA}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe (ASUSTeK COMPUTER INC. -> ASUS)
FirewallRules: [{E90BA36B-9269-4DB3-A7D5-1D32EE327AD4}] => (Allow) C:\Users\Wolfe\AppData\Local\Packages\B9ECED6F.ArmouryCrate_qmba6cd70vzyy\LocalState\GridUpdateFile\ASUSGCDriverUpdateClient.exe (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
FirewallRules: [TCP Query User{774D426C-26DA-41DE-96DD-D43CE54D81AE}E:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe] => (Allow) E:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe => No File
FirewallRules: [UDP Query User{A41965D4-FB0F-4623-AB06-A3DEE8417817}E:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe] => (Allow) E:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe => No File
FirewallRules: [TCP Query User{0CF257AD-3AC8-4308-A242-EBBC80946D06}D:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe] => (Allow) D:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe (Gearbox Software, L.L.C. -> Gearbox)
FirewallRules: [UDP Query User{FE76C8DB-EF0C-432F-8FA1-C933BDC451A2}D:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe] => (Allow) D:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe (Gearbox Software, L.L.C. -> Gearbox)
FirewallRules: [{7882F540-0EA1-4145-AFDB-271C17B91054}] => (Allow) C:\Users\Wolfe\AppData\Local\Temp\utorrent\utorrent.exe => No File
FirewallRules: [{EB3BFBEC-407B-462F-827B-BBE1559A3062}] => (Allow) C:\Users\Wolfe\AppData\Local\Temp\utorrent\utorrent.exe => No File
FirewallRules: [{4AF4067D-59D3-4203-87BF-14B2E1DC218F}] => (Allow) C:\Users\Wolfe\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{0C259C52-29B2-447B-8F3E-D802B6225F98}] => (Allow) C:\Users\Wolfe\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [TCP Query User{8AC34B37-FAEF-4025-A43D-5635AB2DE31F}C:\users\wolfe\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\wolfe\appdata\local\microsoft\teams\current\teams.exe => No File
FirewallRules: [UDP Query User{6D73BE5C-CDE7-43AF-82E8-E95442356227}C:\users\wolfe\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\wolfe\appdata\local\microsoft\teams\current\teams.exe => No File
FirewallRules: [{CDC41BD3-7DB2-4C24-BA5E-4BBED0F66AF7}] => (Allow) D:\SteamLibrary\steamapps\common\The Past Within\The Past Within.exe (Unity Technologies ApS) [File not signed]
FirewallRules: [{6695E06B-62E5-41CF-BC95-B07695230B8F}] => (Allow) D:\SteamLibrary\steamapps\common\The Past Within\The Past Within.exe (Unity Technologies ApS) [File not signed]
FirewallRules: [TCP Query User{7B79F3BC-DAB1-40E5-B03A-3F812A2181CB}D:\diablo iv - server slam\diablo iv.exe] => (Allow) D:\diablo iv - server slam\diablo iv.exe => No File
FirewallRules: [UDP Query User{035AA948-5ABB-43FB-A02F-F8F60A11D86E}D:\diablo iv - server slam\diablo iv.exe] => (Allow) D:\diablo iv - server slam\diablo iv.exe => No File
FirewallRules: [TCP Query User{37998031-EDA9-4BE6-A363-F8AD712D7758}D:\diablo iv\diablo iv.exe] => (Allow) D:\diablo iv\diablo iv.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [UDP Query User{07A2B34C-1689-447B-8098-E948440E9D39}D:\diablo iv\diablo iv.exe] => (Allow) D:\diablo iv\diablo iv.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{5221235E-D912-494D-96ED-F6E71CFD7E1D}] => (Allow) D:\SteamLibrary\steamapps\common\Quarters\fnaf9.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{271A24FB-0434-4777-A7CE-3AB752F1C3C9}] => (Allow) D:\SteamLibrary\steamapps\common\Quarters\fnaf9.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{09B1E3FF-C467-4F5B-82CC-B4391621AE78}] => (Allow) D:\SteamLibrary\steamapps\common\DREDGE\DREDGE.exe () [File not signed]
FirewallRules: [{BE2AA407-AF40-4821-8CF0-47BA5313FCE9}] => (Allow) D:\SteamLibrary\steamapps\common\DREDGE\DREDGE.exe () [File not signed]
FirewallRules: [{4F4A96FA-8B7A-4083-823A-7EC52E049D5F}] => (Allow) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{D5B941AE-579C-40B8-9CDD-333738F08426}] => (Allow) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{E1B5C579-CEDF-40F1-AA09-E1BDB5E8B5EF}] => (Allow) D:\SteamLibrary\steamapps\common\Evil Genius 2\launcher\eg2.exe (Rebellion) [File not signed]
FirewallRules: [{A959EDD2-DF82-4C3E-8749-EE0D5F0C030E}] => (Allow) D:\SteamLibrary\steamapps\common\Evil Genius 2\launcher\eg2.exe (Rebellion) [File not signed]
FirewallRules: [{95335994-FDED-4A04-9B87-74735B73F529}] => (Allow) D:\SteamLibrary\steamapps\common\Unreal Tournament\System\UnrealTournament.exe () [File not signed]
FirewallRules: [{400FEDF5-DB94-412F-B715-C022490B4FCE}] => (Allow) D:\SteamLibrary\steamapps\common\Unreal Tournament\System\UnrealTournament.exe () [File not signed]
FirewallRules: [{A8998BFB-6B38-4F73-BCA6-0AD37B075B42}] => (Allow) D:\SteamLibrary\steamapps\common\Shadows of Doubt\Shadows of Doubt.exe () [File not signed]
FirewallRules: [{7E6B1ADF-F55B-4EE7-8B9E-E9DF57E7E774}] => (Allow) D:\SteamLibrary\steamapps\common\Shadows of Doubt\Shadows of Doubt.exe () [File not signed]
FirewallRules: [{16DB64DC-474D-4F64-959E-155CFECC01D2}] => (Allow) D:\SteamLibrary\steamapps\common\I'm on Observation Duty 3\I'm on Observation Duty 3.exe () [File not signed]
FirewallRules: [{5776C784-8AD7-44EC-B0CF-22A1FB7043F7}] => (Allow) D:\SteamLibrary\steamapps\common\I'm on Observation Duty 3\I'm on Observation Duty 3.exe () [File not signed]
FirewallRules: [{A05640C3-21F0-4001-A3EC-67B911B4E4C6}] => (Allow) D:\SteamLibrary\steamapps\common\I'm on Observation Duty 3\VR\I'm on Observation Duty 3 VR.exe () [File not signed]
FirewallRules: [{D680E87C-024B-49D0-A192-03FF109D53D2}] => (Allow) D:\SteamLibrary\steamapps\common\I'm on Observation Duty 3\VR\I'm on Observation Duty 3 VR.exe () [File not signed]
FirewallRules: [TCP Query User{407E08F6-05A3-44CD-88B2-1635EC7170AB}C:\program files (x86)\reverse1999_global\reverse1999en\reverse1999.exe] => (Allow) C:\program files (x86)\reverse1999_global\reverse1999en\reverse1999.exe (BLUEPOCH GAMES CO., LIMITED -> )
FirewallRules: [UDP Query User{6C68046C-E080-4DF4-B7D1-5621FE60DC6C}C:\program files (x86)\reverse1999_global\reverse1999en\reverse1999.exe] => (Allow) C:\program files (x86)\reverse1999_global\reverse1999en\reverse1999.exe (BLUEPOCH GAMES CO., LIMITED -> )
FirewallRules: [{F2905DDE-7C96-477B-805E-8A0EA7A08473}] => (Allow) D:\SteamLibrary\steamapps\common\Micro Civilization\Civ.exe () [File not signed]
FirewallRules: [{A25D1D08-2FF5-419C-B55B-B78AE25ADFB2}] => (Allow) D:\SteamLibrary\steamapps\common\Micro Civilization\Civ.exe () [File not signed]
FirewallRules: [{C6070451-CEA9-4490-890A-BD70055558AB}] => (Allow) D:\SteamLibrary\steamapps\common\Scott Pilgrim vs The World\Scott.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{3278A012-75DE-4FCB-B327-8E7EAF3BCC37}] => (Allow) D:\SteamLibrary\steamapps\common\Scott Pilgrim vs The World\Scott.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [TCP Query User{08512535-7EBC-4491-B0BD-8D558FC072FD}D:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe] => (Allow) D:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe (Gearbox Software, L.L.C. -> Gearbox)
FirewallRules: [UDP Query User{0387D246-361A-454E-BB5F-84571BE7EEF6}D:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe] => (Allow) D:\steamlibrary\steamapps\common\tiny tina's wonderlands\oakgame\binaries\win64\wonderlands.exe (Gearbox Software, L.L.C. -> Gearbox)
FirewallRules: [{1144C922-08F8-4220-9B69-304019C7BB07}] => (Allow) D:\SteamLibrary\steamapps\common\Palworld\Palworld.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{1294CD8A-3691-4D1E-B3E8-925827DAACDC}] => (Allow) D:\SteamLibrary\steamapps\common\Palworld\Palworld.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [TCP Query User{89402943-9DB3-4158-9A85-6E42B18804C7}D:\steamlibrary\steamapps\common\palworld\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\palworld\pal\binaries\win64\palworld-win64-shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [UDP Query User{BE4E0628-F774-4F10-B290-36ABD34D3DB6}D:\steamlibrary\steamapps\common\palworld\pal\binaries\win64\palworld-win64-shipping.exe] => (Allow) D:\steamlibrary\steamapps\common\palworld\pal\binaries\win64\palworld-win64-shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{5D203C24-3076-42B5-A21A-3DFEBD75E828}] => (Allow) D:\SteamLibrary\steamapps\common\Horizon Zero Dawn\HorizonZeroDawn.exe () [File not signed]
FirewallRules: [{8161BB70-8DB1-42C6-8A98-0F53CB226740}] => (Allow) D:\SteamLibrary\steamapps\common\Horizon Zero Dawn\HorizonZeroDawn.exe () [File not signed]
FirewallRules: [{2E93B374-1519-4212-9C50-6631C6B34A28}] => (Allow) D:\SteamLibrary\steamapps\common\Horizon Forbidden West Complete Edition\HorizonForbiddenWest.exe (Sony Interactive Entertainment LLC -> Guerrilla B.V.)
FirewallRules: [{C3D1AB2D-3216-4A8D-9EA9-4406C9F114D0}] => (Allow) D:\SteamLibrary\steamapps\common\Horizon Forbidden West Complete Edition\HorizonForbiddenWest.exe (Sony Interactive Entertainment LLC -> Guerrilla B.V.)
FirewallRules: [{3E0E32E5-62B2-4E91-BEA3-20CF35879EC3}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{B9EF66FA-80A3-448F-92E7-3E8991C94A0B}] => (Allow) D:\SteamLibrary\steamapps\common\Baba Is You\Baba Is You.exe (None) [File not signed]
FirewallRules: [{44FA06B8-1B39-40FD-A7C3-C14FDEEA63BF}] => (Allow) D:\SteamLibrary\steamapps\common\Baba Is You\Baba Is You.exe (None) [File not signed]
FirewallRules: [{41BFE508-EF34-4E99-B5BA-B118E09037A8}] => (Allow) D:\SteamLibrary\steamapps\common\The Hauntings Surveillance\Observation.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{DCEEF7D0-9F01-4DF3-AD04-FBBE84FBDC1B}] => (Allow) D:\SteamLibrary\steamapps\common\The Hauntings Surveillance\Observation.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{62B19BB5-0098-45C7-9646-F43371655D83}] => (Allow) E:\SteamLibrary\steamapps\common\WinterBottom\Winterbottom.exe () [File not signed]
FirewallRules: [{5BAB0D5B-071F-45AF-9306-E8F97D93335A}] => (Allow) E:\SteamLibrary\steamapps\common\WinterBottom\Winterbottom.exe () [File not signed]
FirewallRules: [{3437CECE-706C-455B-8028-78FD64378853}] => (Allow) D:\SteamLibrary\steamapps\common\Stardew Valley\Stardew Valley.exe (ConcernedApe) [File not signed]
FirewallRules: [{FF1649F9-F4E1-4D8E-989F-FE8B7DCFEF03}] => (Allow) D:\SteamLibrary\steamapps\common\Stardew Valley\Stardew Valley.exe (ConcernedApe) [File not signed]
FirewallRules: [TCP Query User{95A37DA4-F9F5-4D57-AF1B-63123554517A}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{1FDB8E8F-318D-4FFC-B285-63908E355703}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{1C98DCD3-972A-4CD3-826A-24298DBB7D63}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F567D521-3933-4B8C-A4F7-B8973DC3D358}] => (Allow) D:\SteamLibrary\steamapps\common\TCG Card Shop Simulator\Card Shop Simulator.exe () [File not signed]
FirewallRules: [{DA79E06B-B861-44E2-8C61-C3086A8DF968}] => (Allow) D:\SteamLibrary\steamapps\common\TCG Card Shop Simulator\Card Shop Simulator.exe () [File not signed]
FirewallRules: [{B66FBD8E-6566-46AF-A4AD-0C2B531B77CA}] => (Allow) D:\SteamLibrary\steamapps\common\I'm on Observation Duty 6\I'm on Observation Duty 6.exe () [File not signed]
FirewallRules: [{6CAC0AC3-76B1-45E0-8D45-8B1BE53F28D5}] => (Allow) D:\SteamLibrary\steamapps\common\I'm on Observation Duty 6\I'm on Observation Duty 6.exe () [File not signed]
FirewallRules: [{25F41A83-CAB1-4FC1-B649-B23F646B3788}] => (Allow) D:\SteamLibrary\steamapps\common\I'm on Observation Duty 7\I'm on Observation Duty 7.exe () [File not signed]
FirewallRules: [{E0BE84CD-CC31-4BBC-8C4D-D0BDC574D820}] => (Allow) D:\SteamLibrary\steamapps\common\I'm on Observation Duty 7\I'm on Observation Duty 7.exe () [File not signed]
FirewallRules: [{55F1CDF4-6F93-427B-8621-CDA0B39A79A8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.134.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5D549FC1-23E1-4608-AE4C-102F5091616F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.134.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C7D94706-FEE3-4D91-A4D5-1F958FB227D5}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.134.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{7A0EBA4D-2A62-4CE9-885E-3388225885DA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.134.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{003080B9-062C-4F88-AC6F-4513BC63E127}] => (Allow) C:\Program Files (x86)\Overwolf\0.266.1.25\OverwolfBrowser.exe => No File
FirewallRules: [{83236F6A-93D9-4CB4-9173-33A396554B29}] => (Allow) C:\Program Files (x86)\Overwolf\0.266.1.25\OverwolfBrowser.exe => No File
FirewallRules: [{ECE8C6A5-C7DF-46CD-8430-A4AEB65C3619}] => (Block) C:\Program Files (x86)\Overwolf\0.266.1.25\OverwolfBrowser.exe => No File
FirewallRules: [{B4238B05-ADC9-449B-A993-EFB708BF16CB}] => (Block) C:\Program Files (x86)\Overwolf\0.266.1.25\OverwolfBrowser.exe => No File
FirewallRules: [{0574C29F-2AB9-4A1C-8339-141CCA18792A}] => (Allow) C:\Program Files (x86)\Overwolf\0.263.0.11\OverwolfBrowser.exe => No File
FirewallRules: [{DAC95FEE-E93B-4007-ACCD-98CD008D714C}] => (Allow) C:\Program Files (x86)\Overwolf\0.263.0.11\OverwolfBrowser.exe => No File
FirewallRules: [{FC48F6C8-DA65-4650-B5C2-5DF98C85B0B8}] => (Block) C:\Program Files (x86)\Overwolf\0.263.0.11\OverwolfBrowser.exe => No File
FirewallRules: [{9DC5B6D8-40EA-49FE-B808-F7684802147D}] => (Block) C:\Program Files (x86)\Overwolf\0.263.0.11\OverwolfBrowser.exe => No File
FirewallRules: [{CEDC96D0-B645-4134-BE10-9017C6BDCA77}] => (Allow) C:\Program Files (x86)\Overwolf\0.266.1.26\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{3DF547D9-B6C1-4432-A6F1-0D10EC181DB9}] => (Allow) C:\Program Files (x86)\Overwolf\0.266.1.26\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{F80DA829-E540-476E-9FE8-3E5CA6A298EC}] => (Allow) D:\SteamLibrary\steamapps\common\Path of Exile 2\PathOfExileSteam.exe (Grinding Gear Games Limited -> )
FirewallRules: [{3B980ADB-CF8B-4EA9-8B4B-AEBD151F4C1E}] => (Allow) D:\SteamLibrary\steamapps\common\Path of Exile 2\PathOfExileSteam.exe (Grinding Gear Games Limited -> )
FirewallRules: [{D4E61573-DB04-493C-A548-BDB48659D34D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{B17DD820-B507-4921-AB3E-3342A1FA5A4C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{9D1EE4FB-3B1B-476B-A088-23314B0A5496}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{75694F26-A20D-4DB7-86B4-D3A4ECA2049E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{AC29A348-D3DD-473D-95E6-7435F1C48688}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{8DFFCB98-C2C7-487B-B220-667075FD4AF0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{F7F00682-7CC7-404F-BB5F-FE0756F91FCC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{9DBAFCE8-BAC1-4AC4-856C-88E2BDAC43C5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{6A00E994-7403-4B98-B1F2-2B78DC9C72BB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{1A7D2983-686D-4074-9876-D5FC5A4A4B09}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{FEEFACAA-F778-45FF-8C57-69A29E5C2B5C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.253.440.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{BEA7B195-E9CB-42DA-B062-F590AD85B8F9}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\131.0.2903.146\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Restore Points =========================
05-01-2025 05:00:13 Scheduled Checkpoint
14-01-2025 05:15:48 Scheduled Checkpoint
==================== Faulty Device Manager Devices ============
Name: WD SES Device USB Device
Description: WD SES Device USB Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: ========================
Application errors:
==================
Error: (01/16/2025 05:33:04 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x8007045b, A system shutdown is in progress..
Error: (01/16/2025 05:33:03 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.]
Error: (01/15/2025 06:48:55 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid..
Operation:
Executing Asynchronous Operation
Context:
Current State: DoSnapshotSet
Error: (01/15/2025 06:46:18 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid..
Operation:
Executing Asynchronous Operation
Context:
Current State: DoSnapshotSet
Error: (01/10/2025 04:43:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NVDisplay.Container.exe, version: 1.39.3323.1171, time stamp: 0x64e85748
Faulting module name: nvapi64.dll, version: 32.0.15.6636, time stamp: 0x674f5d87
Exception code: 0xc0000005
Fault offset: 0x000000000004e6b3
Faulting process id: 0xb6a0
Faulting application start time: 0x01db5f71f8b68d35
Faulting application path: C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\Display.NvContainer\NVDisplay.Container.exe
Faulting module path: C:\Windows\SYSTEM32\nvapi64.dll
Report Id: 643ce7c8-5c68-4f4f-80c7-06a788fbd755
Faulting package full name:
Faulting package-relative application ID:
Error: (01/10/2025 05:41:21 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: The storage optimizer couldn't complete retrim on (C:) because: The operation requested is not supported by the hardware backing the volume. (0x8900002A)
Error: (01/06/2025 08:59:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: nvcontainer.exe, version: 1.41.3380.9912, time stamp: 0x65b2727a
Faulting module name: nvapi64.dll, version: 32.0.15.6636, time stamp: 0x674f5d87
Exception code: 0xc0000005
Fault offset: 0x000000000004e6b3
Faulting process id: 0x2070
Faulting application start time: 0x01db5d39a307dca5
Faulting application path: C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
Faulting module path: C:\Windows\SYSTEM32\nvapi64.dll
Report Id: 6b2ffbc9-2428-410d-9c46-f32a0d77759c
Faulting package full name:
Faulting package-relative application ID:
Error: (01/06/2025 05:47:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Razer Synapse Service Process.exe, version: 1.0.0.0, time stamp: 0x66fe5ce6
Faulting module name: KERNELBASE.dll, version: 10.0.19041.5247, time stamp: 0xf6de4130
Exception code: 0xe0434352
Fault offset: 0x00140f62
Faulting process id: 0x3aa8
Faulting application start time: 0x01db5d3a061a5fe6
Faulting application path: C:\Program Files (x86)\Razer\Synapse3\Service\..\UserProcess\Razer Synapse Service Process.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: f751c8cf-663c-4a48-9647-eedfc6e8c755
Faulting package full name:
Faulting package-relative application ID:
System errors:
=============
Error: (01/16/2025 06:17:12 PM) (Source: DCOM) (EventID: 10010) (User: WOLFE-PC)
Description: The server Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter did not register with DCOM within the required timeout.
Error: (01/16/2025 06:13:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The AppX Deployment Service (AppXSVC) service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (01/16/2025 06:12:56 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the AppX Deployment Service (AppXSVC) service to connect.
Error: (01/16/2025 06:12:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The AppX Deployment Service (AppXSVC) service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (01/16/2025 06:12:11 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the AppX Deployment Service (AppXSVC) service to connect.
Error: (01/16/2025 06:07:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The AppX Deployment Service (AppXSVC) service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (01/16/2025 06:07:16 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the AppX Deployment Service (AppXSVC) service to connect.
Error: (01/16/2025 06:06:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The AppX Deployment Service (AppXSVC) service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Windows Defender:
================
Date: 2025-01-16 19:06:27
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft...82&enterprise=0
Name: Ransom:MSIL/Gorf
Severity: Severe
Category: Ransomware
Path: file:_C:\Users\Wolfe\Downloads\FRST.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.421.1388.0, AS: 1.421.1388.0, NIS: 1.421.1388.0
Engine Version: AM: 1.1.24090.11, NIS: 1.1.24090.11
Date: 2025-01-16 19:06:22
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft...82&enterprise=0
Name: Ransom:MSIL/Gorf
Severity: Severe
Category: Ransomware
Path: file:_C:\Users\Wolfe\Downloads\FRST.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.421.1388.0, AS: 1.421.1388.0, NIS: 1.421.1388.0
Engine Version: AM: 1.1.24090.11, NIS: 1.1.24090.11
Date: 2025-01-16 19:06:10
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft...82&enterprise=0
Name: Ransom:MSIL/Gorf
Severity: Severe
Category: Ransomware
Path: file:_C:\Users\Wolfe\Downloads\FRST.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.421.1388.0, AS: 1.421.1388.0, NIS: 1.421.1388.0
Engine Version: AM: 1.1.24090.11, NIS: 1.1.24090.11
Date: 2025-01-16 19:05:34
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft...82&enterprise=0
Name: Ransom:MSIL/Gorf
Severity: Severe
Category: Ransomware
Path: file:_C:\Users\Wolfe\Downloads\FRST.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Program Files\Mozilla Firefox\firefox.exe
Security intelligence Version: AV: 1.421.1388.0, AS: 1.421.1388.0, NIS: 1.421.1388.0
Engine Version: AM: 1.1.24090.11, NIS: 1.1.24090.11
Date: 2025-01-16 19:05:25
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft...82&enterprise=0
Name: Ransom:MSIL/Gorf
Severity: Severe
Category: Ransomware
Path: file:_C:\Users\Wolfe\Downloads\FRST.exe
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Program Files\Mozilla Firefox\firefox.exe
Security intelligence Version: AV: 1.421.1388.0, AS: 1.421.1388.0, NIS: 1.421.1388.0
Engine Version: AM: 1.1.24090.11, NIS: 1.1.24090.11
Event[0]:
Date: 2024-10-08 17:59:02
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.419.396.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.24080.9
Error code: 0x80070102
Error description: The wait operation timed out.
Date: 2024-10-08 17:59:02
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.419.396.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.24080.9
Error code: 0x80070102
Error description: The wait operation timed out.
Date: 2024-10-08 17:38:26
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.419.412.0
Previous security intelligence Version: 1.419.396.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.24080.9
Previous Engine Version: 1.1.24080.9
Error code: 0x80509004
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
Date: 2024-10-08 17:38:26
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.419.412.0
Previous security intelligence Version: 1.419.396.0
Update Source: User
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 1.1.24080.9
Previous Engine Version: 1.1.24080.9
Error code: 0x80509004
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
Date: 2024-10-03 18:34:56
Description:
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.419.338.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.24080.9
Error code: 0x80070102
Error description: The wait operation timed out.
CodeIntegrity:
===============
Date: 2025-01-16 05:58:24
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Users\Wolfe\AppData\Local\Discord\app-1.0.9177\Discord.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Overwolf\0.266.1.26\OWClient.dll that did not meet the Microsoft signing level requirements.
Date: 2025-01-16 05:58:23
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Users\Wolfe\AppData\Local\Discord\app-1.0.9177\Discord.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Overwolf\0.266.1.26\ow-graphics-vulkan.dll that did not meet the Microsoft signing level requirements.
Date: 2025-01-16 05:58:22
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Users\Wolfe\AppData\Local\Discord\app-1.0.9177\Discord.exe) attempted to load \Device\HarddiskVolume5\ProgramData\obs-studio-hook\graphics-hook64.dll that did not meet the Microsoft signing level requirements.
Date: 2025-01-02 09:19:28
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Users\Wolfe\AppData\Local\Discord\app-1.0.9175\Discord.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Overwolf\0.266.1.26\OWClient.dll that did not meet the Microsoft signing level requirements.
Date: 2025-01-02 09:19:27
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Users\Wolfe\AppData\Local\Discord\app-1.0.9175\Discord.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Overwolf\0.266.1.26\ow-graphics-vulkan.dll that did not meet the Microsoft signing level requirements.
Date: 2025-01-02 09:19:27
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Users\Wolfe\AppData\Local\Discord\app-1.0.9175\Discord.exe) attempted to load \Device\HarddiskVolume5\ProgramData\obs-studio-hook\graphics-hook64.dll that did not meet the Microsoft signing level requirements.
Date: 2024-12-18 17:19:07
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Users\Wolfe\AppData\Local\Discord\app-1.0.9174\Discord.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Overwolf\0.263.0.11\OWClient.dll that did not meet the Microsoft signing level requirements.
Date: 2024-12-18 17:19:07
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Users\Wolfe\AppData\Local\Discord\app-1.0.9174\Discord.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Overwolf\0.263.0.11\ow-graphics-vulkan.dll that did not meet the Microsoft signing level requirements.
Date: 2024-12-18 17:19:05
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Users\Wolfe\AppData\Local\Discord\app-1.0.9174\Discord.exe) attempted to load \Device\HarddiskVolume5\ProgramData\obs-studio-hook\graphics-hook64.dll that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends Inc. 2604 02/25/2022
Motherboard: ASUSTeK COMPUTER INC. ROG STRIX B550-F GAMING WIFI II
Processor: AMD Ryzen 7 5800X 8-Core Processor
Percentage of memory in use: 32%
Total physical RAM: 32654.41 MB
Available physical RAM: 22081.83 MB
Total Virtual: 57230.41 MB
Available Virtual: 44391.77 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:3725.39 GB) (Free:3522.28 GB) (Model: ST4000DM004-2U9104) NTFS
Drive d: (SSD) (Fixed) (Total:931.5 GB) (Free:61.64 GB) (Model: Samsung SSD 970 EVO Plus 1TB) NTFS
Drive e: (Elements SE) (Fixed) (Total:3725.99 GB) (Free:3331.19 GB) (Model: WD Elements SE 2623 USB Device) NTFS
\\?\Volume{e7e96fb9-6a4c-4786-8dad-db66cd25c636}\ () (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS
\\?\Volume{ea32604d-50a1-4c09-af34-01b203a00ec2}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 3726 GB) (Disk ID: 00000000)
Partition: GPT.
==========================================================
Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
==========================================================
Disk: 2 (Size: 3726 GB) (Disk ID: 16F2A91F)
Partition: GPT.
==================== End of Addition.txt =======================
Edited by DSWolfe, 16 January 2025 - 09:27 PM.