And not i fell like the system is actin different, weird delays, mouse pointer jumping at time. I'm worried something has infected the system. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-07-2026 Ran by Admin (administrator) on OPTIPLEX7050 (Dell Inc. OptiPlex 7050) (19-07-2026 10:24:24) Running from C:\Users\Brando\Desktop\FRST64.exe Loaded Profiles: Admin & Brando Platform: Microsoft Windows 10 Pro Version 22H2 19045.7548 (X64) Language: English (United States) Default browser: FF Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe ->) (Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\SARemediation\audit\TelemetryUtility.exe (C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.UserProcess.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> ) C:\Program Files (x86)\Dell\UpdateService\DCF\Dell.Update.SubAgent.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> ) C:\Program Files\Dell\DTP\DiagnosticsSubAgent\Dell.TechHub.Diagnostics.SubAgent.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell) C:\Program Files\Dell\TechHub\Dell.CoreServices.Client.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\AnalyticsSubAgent\Dell.TechHub.Analytics.SubAgent.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\DataManagerSubAgent\Dell.TechHub.DataManager.SubAgent.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe (C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe (C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe (C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2> (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe (DriverStore\FileRepository\cui_dch.inf_amd64_bd81469b51147524\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_bd81469b51147524\igfxEM.exe (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo75de.inf_amd64_5ff36f834a6d461a\WavesSvc64.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.108.0607.0002\OneDrive.Sync.Service.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <19> (services.exe ->) (BACKBLAZE, INC. -> ) C:\Program Files (x86)\Backblaze\bzserv.exe (services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe (services.exe ->) (Dell Technologies Inc. -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe (services.exe ->) (Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe (services.exe ->) (Dell Technologies Inc. -> Dell) C:\Program Files\Dell\TechHub\Dell.TechHub.exe (services.exe ->) (FOXIT SOFTWARE INC. -> Foxit Software Inc.) C:\Program Files\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_bd81469b51147524\igfxCUIService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_99f6bd58bfe82726\RstMwService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_47d3698a1c94c55a\OneApp.IGCC.WinService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b8e80a9b8772ee40\IntelCpHDCPSvc.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b8e80a9b8772ee40\IntelCpHeciSvc.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_ece153ca769ec179\aesm_service.exe (services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\SocketHeciServer.exe (services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\TPMProvisioningService.exe (services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo75de.inf_amd64_5ff36f834a6d461a\WavesSysSvc64.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registry (Whitelisted) =================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269088 2020-08-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506144 2020-08-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [11859680 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [3831808 2021-08-31] (Microsoft Windows Hardware Compatibility Publisher -> Logitech) HKLM\...\Run: [WavesSvc] => C:\WINDOWS\System32\DriverStore\FileRepository\wavesapo75de.inf_amd64_5ff36f834a6d461a\WavesSvc64.exe [1222536 2018-12-05] (Waves Inc -> Waves Audio Ltd.) HKLM\...\Run: [Logi Download Assistant] => C:\Program Files\LogiDownloadAssistant\bin\logi_download_assistant.exe [18838016 2025-05-15] (Logitech, Inc.) [File not signed] HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [271496 2017-11-02] (Canon Inc. -> CANON INC.) HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" (No File) HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File) HKLM\...\RunOnce: [msedge_cleanup_{C50565E9-CCCF-44B4-BA15-5AC5C6569197}] => C:\Program Files (x86)\Microsoft\Copilot\Application\150.0.4078.65\Installer\setup.exe [5379912 2026-07-10] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-1797482264-3094360332-3849169840-1004\...\Run: [MicrosoftEdgeAutoLaunch_5EFC0ECB77A7585FE9DCDD0B2E946A2B] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-17] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-1797482264-3094360332-3849169840-1004\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4751720 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-1797482264-3094360332-3849169840-1004\...\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [1885944 2025-10-10] (BACKBLAZE, INC. -> ) HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4751720 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIZEE.EXE [485976 2020-09-11] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\Run: [Proton VPN] => C:\Program Files\Proton\VPN\ProtonVPN.Launcher.exe [18728080 2026-07-02] (Proton AG -> ProtonVPN) HKU\S-1-5-18\...\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [1885944 2025-10-10] (BACKBLAZE, INC. -> ) HKLM\...\Windows x64\Print Processors\Canon G6000 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDFJ.DLL [482816 2019-02-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Windows x64\Print Processors\Canon TS6000 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDDE.DLL [30720 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Canon BJ Language Monitor G6000 series: C:\WINDOWS\system32\CNMLMFJ.DLL [1309696 2019-02-20] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Canon BJ Language Monitor TS6000 series: C:\WINDOWS\system32\CNMLMDE.DLL [485376 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\EPSON ET-2400 Series 64MonitorBE: C:\WINDOWS\system32\E_YLMBZEE.DLL [187392 2018-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Seiko Epson Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\150.0.7871.128\Installer\chrmstp.exe [7681176 2026-07-17] (Google LLC -> Google LLC) GroupPolicy: Restriction ? <==== ATTENTION Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {BC73BAA3-515F-4EE5-876F-A84FFD11BD31} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe [1317528 2026-04-28] (Dell Technologies Inc. -> Dell Inc.) -> C:\Program Files\Dell\SupportAssistAgent\bin\AutoUpdate Task: {67AF3F52-EFF7-4384-A4EC-C0E435767F16} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem152.0.7933.0{2F9667D8-7DE5-460D-A3C7-8FBF21E98F6B} => C:\Program Files (x86)\Google\GoogleUpdater\152.0.7933.0\updater.exe [9512088 2026-07-05] (Google LLC -> Google LLC) Task: {451B1ACE-F79C-4A2E-827F-7A9B32A2EDB2} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC) Task: {7A0AA0CF-2017-4C99-91E1-61635FEB3ED9} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Metrics => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC) Task: {B167B95E-9C95-4FA0-BD43-E89E51AE90F0} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelperOnUnlock => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC) Task: {DA286A26-4BC7-4390-954E-D0B06029AB55} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [11419480 2025-10-14] (Microsoft Corporation -> Microsoft Corporation) Task: {0796F477-E323-4916-AF96-F695BFB72B9D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-08] (Microsoft Corporation -> Microsoft Corporation) Task: {0CC7517E-ADB2-4E3F-B808-4D9DD20EF72A} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonx86\Microsoft Shared\OFFICE16\opushutil.exe [61280 2025-10-14] (Microsoft Corporation -> Microsoft Corporation) Task: {E97A2C73-C529-4941-B9CF-CEFDE4DF9F5D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-08] (Microsoft Corporation -> Microsoft Corporation) Task: {36A52A9F-E57E-460D-B6B6-D4DF880ED98C} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-14] (Microsoft Corporation -> Microsoft Corporation) Task: {24B60E36-7490-4995-8E96-A9282D3406A3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-14] (Microsoft Corporation -> Microsoft Corporation) Task: {6B07340D-4941-4C97-A1C2-49DD91BABD82} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {C5FAF728-4335-45DC-A933-0CB928AF1386} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {058F872A-C16E-425E-AEC7-9C7C4731814A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {DA6DF3E1-B671-4A0C-82A4-886CF359118F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {DA9EEBD9-2F43-48AB-BFB8-6793D386F175} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1797482264-3094360332-3849169840-1004 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705152 2026-07-14] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters). Task: {AB5BCBB2-1374-4C1F-8DCA-DBCADBDB56AA} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1797482264-3094360332-3849169840-1005 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705152 2026-07-14] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters). Task: {A0B5B479-9717-422B-B4B0-470726DDB49E} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-07-14] (Mozilla Corporation -> Mozilla Foundation) Task: {4D55FBF9-CBCD-4EB6-BBC0-B6FCF37153ED} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407144 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) Task: {9571F9E9-1A07-4DF1-994B-B5A9015E49BF} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1797482264-3094360332-3849169840-1003 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407144 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) Task: {461F371D-1832-47F2-B0F3-D7F1186D2F1F} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1797482264-3094360332-3849169840-1004 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407144 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) Task: {C59E8C9E-2D79-44AD-BA4B-867152E5A542} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1797482264-3094360332-3849169840-1005 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407144 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) Task: {63041660-0F39-4C1A-9871-DCA0E1408301} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1797482264-3094360332-3849169840-500 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4407144 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) Task: {94D3187E-93F1-4509-BF46-A566B69DAA10} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1797482264-3094360332-3849169840-1004 => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\OneDriveLauncher.exe [761192 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) Task: {5CDF826B-3FF9-4A98-9A76-8E159E754E12} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1797482264-3094360332-3849169840-1005 => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\OneDriveLauncher.exe [761192 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) Task: {7F513273-A53D-4C9C-BCD9-D2CC820FEA31} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-1797482264-3094360332-3849169840-1004 => C:\Users\Admin\AppData\Roaming\Zoom\bin\Zoom.exe [507784 2026-05-22] (Zoom Communications, Inc. -> Zoom Communications, Inc.) Task: {FF128940-8231-4D04-AF76-242D0ED3396C} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-1797482264-3094360332-3849169840-1005 => C:\Users\Brando\AppData\Roaming\Zoom\bin\Zoom.exe [511872 2026-06-26] (Zoom Communications, Inc. -> Zoom Communications, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{2e8d39b4-e03a-4f87-9d7d-a64e747d9c35}: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{2e8d39b4-e03a-4f87-9d7d-a64e747d9c35}: [DhcpDomain] attlocal.net FireFox: ======== FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox FF DefaultProfile: p6pm2ppe.default-release-1766262285627 -> 308046B0AF4A39CB FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\dehkj2xs.default [2024-12-19] FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\p6pm2ppe.default-release-1766262285627 [2026-05-22] FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2026-04-10] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2026-04-10] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2026-04-10] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2026-04-10] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2026-04-10] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT PDF READER\plugins\npFoxitPDFReaderPlugin.dll [No File] FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT PDF READER\plugins\npFoxitPDFReaderPlugin.dll [No File] FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT PDF READER\plugins\npFoxitPDFReaderPlugin.dll [No File] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2025-07-05] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-08-29] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.20 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN) Edge: ======= Edge Profile: C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default [2025-10-07] Edge Extension: (Google Docs Offline) - C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-12-19] Edge Extension: (Edge relevant text changes) - C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-12-19] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 bzserv; C:\Program Files (x86)\Backblaze\bzserv.exe [1016056 2025-10-10] (BACKBLAZE, INC. -> ) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13288288 2025-10-08] (Microsoft Corporation -> Microsoft Corporation) R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [50464 2026-04-25] (Dell Technologies Inc. -> ) R2 DellTechHub; C:\Program Files\Dell\TechHub\Dell.TechHub.exe [149704 2026-03-27] (Dell Technologies Inc. -> Dell) S4 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncHelper.exe [3619176 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) R2 FoxitReaderUpdateService; C:\Program Files\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe [3226720 2026-04-10] (FOXIT SOFTWARE INC. -> Foxit Software Inc.) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460992 2025-04-18] (Canon Inc. -> ) S4 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [13004248 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11514232 2026-07-02] (Malwarebytes Inc -> Malwarebytes) S4 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [4291576 2026-06-06] (Malwarebytes Inc -> Malwarebytes) R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe [2100520 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) S4 MyMediaForAlexa; C:\Program Files\MyMediaForAlexa\MyMediaForAlexa.exe [3021488 2022-01-30] (BIZMODELLER LTD -> bizmodeller Ltd) S4 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.108.0607.0002\OneDriveUpdaterService.exe [4030312 2026-07-07] (Microsoft Corporation -> Microsoft Corporation) S3 ProtonVPN Service; C:\Program Files\Proton\VPN\v5.1.5\ProtonVPNService.exe [477704 2026-07-02] (Proton AG -> ProtonVPN) S3 ProtonVPN WireGuard; C:\Program Files\Proton\VPN\v4.3.9\ProtonVPN.WireGuardService.exe [476912 2025-11-29] (Proton AG -> ProtonVPN) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [877528 2026-07-14] (Microsoft Windows Publisher -> Microsoft Corporation) R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [149656 2026-04-28] (Dell Technologies Inc. -> Dell Inc.) S4 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [25617264 2025-09-11] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe [4769792 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe [290704 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed] R3 CyUcmClient_Device; C:\WINDOWS\System32\drivers\CyUcmClient.sys [124800 2017-04-24] (Cypress Semiconductor Corporation -> Cypress Semiconductor Corporation) R3 DellInstrumentation; C:\WINDOWS\System32\drivers\DellInstrumentation.sys [33336 2025-11-15] (Microsoft Windows Hardware Compatibility Publisher -> Dell) R2 Dokan2; C:\WINDOWS\system32\drivers\dokan2.sys [398480 2025-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Dokan Project) R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-21] (Microsoft Windows -> Microsoft Corporation) R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [235624 2026-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2025-03-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [246376 2026-07-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S3 ProtonVPNCallout; C:\Program Files\Proton\VPN\v5.1.5\Resources\ProtonVPN.CalloutDriver.sys [41416 2026-04-30] (Proton AG -> Proton AG) R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2025-08-29] (MiniTool Solution Ltd -> ) S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2025-08-29] (MiniTool Solution Ltd -> ) S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [50568 2026-07-08] (Microsoft Windows -> Microsoft Corporation) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21928 2026-07-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [25704 2024-07-09] (WDKTestCert user,132375440089837053 -> Western Digital Technologies, Inc.) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [616880 2026-07-08] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [110984 2026-07-08] (Microsoft Windows -> Microsoft Corporation) S3 wintun; C:\WINDOWS\System32\drivers\wintun.sys [29592 2025-11-17] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2025-10-29] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) ==================== SvcHost (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2026-07-19 10:24 - 2026-07-19 10:25 - 000030254 _____ C:\Users\Brando\Desktop\FRST.txt 2026-07-19 10:23 - 2026-07-19 10:24 - 000000000 ____D C:\FRST 2026-07-19 10:22 - 2026-07-19 10:22 - 002452992 _____ (Farbar) C:\Users\Brando\Desktop\FRST64.exe 2026-07-16 19:41 - 2026-07-16 19:45 - 000000000 ___HD C:\$WinREAgent 2026-07-12 19:49 - 2026-07-12 19:49 - 000029156 _____ C:\Users\Brando\Downloads\Brandons Toke Sheet - Sheet1-5.pdf 2026-07-12 19:17 - 2026-07-12 19:17 - 000042919 _____ C:\Users\Brando\Downloads\Biweekly Regular 04_10_2026 9800187 Regular.pdf 2026-07-12 19:14 - 2026-07-12 19:14 - 000057594 _____ C:\Users\Brando\Downloads\Biweekly Regular 06_05_2026 9800187 Regular-1.pdf 2026-07-12 19:13 - 2026-07-12 19:13 - 000042749 _____ C:\Users\Brando\Downloads\Biweekly Regular 05_08_2026 9800187 Regular-2.pdf 2026-07-12 19:05 - 2026-07-12 19:05 - 000028894 _____ C:\Users\Brando\Downloads\Sandys Toke Sheet - Sheet1-3.pdf 2026-07-12 19:02 - 2026-07-12 19:02 - 000042749 _____ C:\Users\Brando\Downloads\Biweekly Regular 05_08_2026 9800187 Regular-1.pdf 2026-07-12 19:00 - 2026-07-12 19:00 - 000057595 _____ C:\Users\Brando\Downloads\Biweekly Regular 06_05_2026 9800187 Regular.pdf 2026-07-12 18:59 - 2026-07-12 18:59 - 000057577 _____ C:\Users\Brando\Downloads\Biweekly Regular 06_18_2026 9800187 Manual.pdf 2026-07-12 18:58 - 2026-07-12 18:58 - 000057842 _____ C:\Users\Brando\Downloads\Biweekly Regular 07_03_2026 9800187 Regular.pdf 2026-07-12 18:52 - 2026-07-12 18:52 - 000043401 _____ C:\Users\Brando\Downloads\Biweekly Regular 07_03_2026 9800209 Regular.pdf 2026-07-10 11:42 - 2026-07-10 11:42 - 019578151 _____ C:\Users\Brando\Desktop\Brz Mounts vid.mp4 2026-07-07 10:19 - 2026-07-07 10:19 - 000308201 _____ C:\Users\Brando\Desktop\Annual Credit Report - Transunion July 26.pdf 2026-07-07 10:14 - 2026-07-07 10:14 - 002558897 _____ C:\Users\Brando\Desktop\Annual Credit Report - Experian July 2026.pdf 2026-07-07 10:06 - 2026-07-07 10:06 - 000173092 _____ C:\Users\Brando\Desktop\Credit Report Exquifax July 2026.pdf 2026-07-03 08:12 - 2026-07-03 08:12 - 007856866 _____ C:\Users\Brando\Downloads\DetailedBillJun2025-1.pdf 2026-07-03 08:12 - 2026-07-03 08:12 - 007275275 _____ C:\Users\Brando\Downloads\DetailedBillJul2025-1.pdf 2026-07-03 08:12 - 2026-07-03 08:12 - 006536054 _____ C:\Users\Brando\Downloads\DetailedBillSep2025.pdf 2026-07-03 08:12 - 2026-07-03 08:12 - 006255809 _____ C:\Users\Brando\Downloads\DetailedBillAug2025-1.pdf 2026-07-03 08:11 - 2026-07-03 08:11 - 007585462 _____ C:\Users\Brando\Downloads\DetailedBillApr2025-1.pdf 2026-07-03 08:11 - 2026-07-03 08:11 - 006152422 _____ C:\Users\Brando\Downloads\DetailedBillMay2025-1.pdf 2026-06-30 16:05 - 2026-06-30 16:05 - 020400664 _____ (Audacity Team ) C:\Users\Brando\Downloads\audacity-win-3.7.8-64bit.exe 2026-06-30 01:24 - 2026-06-30 01:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi Download Assistant 2026-06-30 01:24 - 2026-06-30 01:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi 2026-06-30 01:24 - 2026-06-30 01:24 - 000000000 ____D C:\ProgramData\Logi 2026-06-30 01:24 - 2026-06-30 01:24 - 000000000 ____D C:\Program Files\LogiDownloadAssistant 2026-06-29 10:58 - 2026-06-29 10:58 - 000028722 _____ C:\Users\Brando\Downloads\Sandys Toke Sheet - Sheet1-2.pdf 2026-06-29 10:57 - 2026-06-29 10:57 - 000029088 _____ C:\Users\Brando\Downloads\Brandons Toke Sheet - Sheet1-4.pdf 2026-06-26 03:42 - 2026-06-26 03:42 - 000000000 ____D C:\Users\Brando\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom 2026-06-25 14:18 - 2026-06-25 14:18 - 000165593 _____ C:\Users\Brando\Desktop\Marlenes Kohl's eGift Card.pdf 2026-06-24 08:56 - 2026-06-24 08:56 - 000105232 _____ C:\Users\Brando\Desktop\att3.jpeg 2026-06-22 12:52 - 2026-06-22 12:52 - 000043339 _____ C:\Users\Brando\Downloads\Biweekly Regular 06_18_2026 9800209 Regular.pdf ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2026-07-19 10:20 - 2025-03-28 14:39 - 000000000 ____D C:\Users\Brando\AppData\Local\Malwarebytes 2026-07-19 10:06 - 2025-10-10 13:27 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2026-07-19 08:20 - 2019-12-07 02:14 - 000000000 ___HD C:\Program Files\WindowsApps 2026-07-19 08:20 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2026-07-19 08:20 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2026-07-19 05:03 - 2023-12-03 19:56 - 000000000 ____D C:\WINDOWS\SystemTemp 2026-07-18 21:24 - 2024-12-19 13:00 - 000000000 ____D C:\Users\Brando\AppData\Local\D3DSCache 2026-07-18 21:19 - 2022-11-07 15:03 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2026-07-18 12:45 - 2024-12-19 11:42 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2026-07-18 00:12 - 2025-10-10 13:36 - 000003534 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2026-07-18 00:12 - 2025-10-10 13:36 - 000003408 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2026-07-16 19:45 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2026-07-16 18:15 - 2025-02-06 02:23 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2026-07-15 12:10 - 2025-08-16 08:57 - 000000000 ____D C:\Users\Brando\AppData\Roaming\Microsoft\Publisher Building Blocks 2026-07-15 12:10 - 2025-08-16 08:57 - 000000000 ____D C:\Users\Brando\AppData\Roaming\Microsoft\Publisher 2026-07-14 17:03 - 2025-10-10 13:35 - 000840602 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2026-07-14 17:03 - 2019-12-07 02:13 - 000000000 ____D C:\WINDOWS\INF 2026-07-14 17:00 - 2024-12-19 12:59 - 000000000 __SHD C:\Users\Brando\IntelGraphicsProfiles 2026-07-14 16:58 - 2025-10-10 13:36 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2026-07-14 16:58 - 2023-07-25 09:09 - 000000000 ____D C:\Intel 2026-07-14 16:58 - 2022-11-07 15:03 - 000008192 ___SH C:\DumpStack.log.tmp 2026-07-14 16:58 - 2019-12-07 02:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2026-07-14 16:57 - 2025-10-10 13:27 - 000436320 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2026-07-14 16:56 - 2025-10-04 14:20 - 000000000 ____D C:\Program Files\Mozilla Firefox 2026-07-14 16:56 - 2024-12-19 11:42 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2026-07-14 16:56 - 2023-07-25 08:55 - 000000000 ____D C:\Program Files\Microsoft OneDrive 2026-07-14 16:54 - 2019-12-07 02:54 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2026-07-14 16:54 - 2019-12-07 02:54 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2026-07-14 16:54 - 2019-12-07 02:54 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\PrintDialog 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SystemResources 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\setup 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ShellExperiences 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2026-07-14 16:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2026-07-14 16:53 - 2025-11-11 16:56 - 000392320 _____ (Mozilla Foundation) C:\Users\Brando\Desktop\Firefox.exe 2026-07-14 16:53 - 2024-12-19 11:42 - 000001072 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2026-07-14 10:34 - 2025-10-10 13:30 - 003016704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2026-07-14 10:23 - 2023-07-25 09:13 - 000000000 ____D C:\WINDOWS\system32\MRT 2026-07-14 10:19 - 2023-07-25 09:13 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2026-07-13 03:14 - 2025-10-29 08:26 - 000001057 _____ C:\Users\Public\Desktop\Proton VPN.lnk 2026-07-13 03:14 - 2025-10-29 08:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Proton 2026-07-09 12:01 - 2025-10-10 13:36 - 000004256 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-1797482264-3094360332-3849169840-1005 2026-07-08 00:27 - 2022-11-07 15:03 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2026-07-07 05:03 - 2025-10-10 13:36 - 000003596 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1797482264-3094360332-3849169840-1005 2026-07-07 05:03 - 2025-10-10 13:36 - 000003596 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1797482264-3094360332-3849169840-1004 2026-07-07 05:03 - 2025-10-10 13:36 - 000003552 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-1797482264-3094360332-3849169840-1005 2026-07-07 05:03 - 2025-10-10 13:36 - 000003552 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-1797482264-3094360332-3849169840-1004 2026-07-07 05:03 - 2025-10-10 13:36 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task 2026-07-07 05:03 - 2022-11-07 13:26 - 000002030 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2026-07-03 09:49 - 2024-12-22 14:02 - 000000000 ____D C:\Users\Brando\Documents\Bookmarks emails network settings 2026-07-03 09:44 - 2024-12-22 17:16 - 000000000 ____D C:\Users\Brando\AppData\Roaming\Microsoft\Word 2026-07-03 09:40 - 2024-12-19 12:59 - 000000000 ____D C:\Users\Brando\AppData\Local\Packages 2026-07-03 09:32 - 2026-06-11 15:41 - 000000000 ____D C:\Users\Brando\Desktop\Moline Tmo Bill 2026-07-02 14:06 - 2025-03-28 14:38 - 000246376 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2026-07-01 11:59 - 2025-10-11 13:38 - 000000000 ____D C:\ProgramData\CanonIJPLM 2026-06-30 16:28 - 2025-06-13 10:42 - 000000000 ____D C:\Users\Brando\Documents\Audacity 2026-06-30 16:28 - 2025-06-13 09:51 - 000000000 ____D C:\Users\Brando\AppData\Roaming\audacity 2026-06-30 16:26 - 2025-07-02 16:39 - 000000000 ____D C:\Users\Brando\Desktop\Animal Sounds 2026-06-30 16:06 - 2025-06-04 16:49 - 000000872 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk 2026-06-30 16:06 - 2025-06-04 16:49 - 000000860 _____ C:\Users\Public\Desktop\Audacity.lnk 2026-06-30 16:06 - 2025-06-04 16:49 - 000000000 ____D C:\Program Files\Audacity 2026-06-29 11:25 - 2024-12-22 13:57 - 000000000 ____D C:\Users\Brando\Desktop\Misc crapola 2026-06-26 15:55 - 2025-07-07 10:05 - 000000000 ____D C:\Users\Brando\AppData\Roaming\Zoom ==================== Files in the root of some directories ======== 2025-12-27 17:01 - 2026-01-26 09:34 - 000000018 _____ () C:\Users\Admin\AppData\Roaming\.cache9050425797200915815.dat ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ======================== Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-07-2026 Ran by Admin (19-07-2026 10:26:54) Running from C:\Users\Brando\Desktop Microsoft Windows 10 Pro Version 22H2 19045.7548 (X64) (2025-10-10 20:37:06) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Admin (DisplayName: ) (S-1-5-21-1797482264-3094360332-3849169840-1004 - Administrators - Enabled) => C:\Users\Admin Administrator (S-1-5-21-1797482264-3094360332-3849169840-500 - Administrators - Disabled) Brando (DisplayName: ) (S-1-5-21-1797482264-3094360332-3849169840-1005 - Limited - Enabled) => C:\Users\Brando DefaultAccount (S-1-5-21-1797482264-3094360332-3849169840-503 - Limited - Disabled) Guest (S-1-5-21-1797482264-3094360332-3849169840-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-1797482264-3094360332-3849169840-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 24.09 (x64) (HKLM\...\7-Zip) (Version: 24.09 - Igor Pavlov) Amazon Photos (HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\Amazon Photos) (Version: 10.11.0 - Amazon.com, Inc.) Audacity 3.7.8 (HKLM\...\Audacity_is1) (Version: 3.7.8 - Audacity Team) Backblaze (HKLM-x32\...\{63654DE4-6924-4A08-BB9F-E7BA98A11BD4}) (Version: 9.2.2.897 - Backblaze, Inc) Canon G6000 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_G6000_series) (Version: 1.02 - Canon Inc.) Canon IJ Network Scanner Selector EX2 (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.10.2 - Canon Inc.) Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.20.1.51 - Canon Inc.) Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 2.2.0.5 - Canon Inc.) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.7.0 - Canon Inc.) Canon TS6000 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS6000_series) (Version: 1.02 - Canon Inc.) Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 150.0.4078.65 - Microsoft Corporation) Core FTP LE (x64) (HKLM-x32\...\CoreFTP(x64)) (Version: - ) CrystalDiskInfo 9.6.3 (HKLM\...\CrystalDiskInfo_is1) (Version: 9.6.3 - Crystal Dew World) Dell SupportAssist (HKLM\...\{5E5B7C3B-96BE-4A47-B28D-CAA7D87F95A8}) (Version: 5.1.1.3567 - Dell Inc.) Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM\...\{BE92A615-4964-403F-B965-827881C7CE4D}) (Version: 5.5.16.1 - Dell Inc.) Hidden Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM-x32\...\{ab1ff183-69f3-4a2e-8a62-dba1aacc18c9}) (Version: 5.5.16.1 - Dell Inc.) Dokan Library 2.3.0.1000 (x64) (HKLM\...\{9A7325EA-D3C9-0203-0000-250419162816}) (Version: 2.3.0.1000 - Dokany Project) Hidden Dokan Library 2.3.0.1000 Bundle (HKLM-x32\...\{2794038D-3BD4-45C0-989E-4DE47CEB22BC}) (Version: 2.3.0.1000 - Dokany Project) Foxit PDF Reader (HKLM\...\{01A75E1E-7567-11F0-B81F-54BF64A63C26}) (Version: 2026.1.1.36485 - Foxit Software Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 150.0.7871.128 - Google LLC) Logi Download Assistant (HKLM-x32\...\LogiDownloadAssistant) (Version: 2.0.529 - Logitech) Macrium Reflect Free (HKLM\...\{A302C59F-C733-4DA0-9611-1286A9051D15}) (Version: 8.0.7783 - Paramount Software (UK) Ltd.) Hidden Macrium Reflect Free (HKLM\...\MacriumReflect) (Version: v8.0.7783 - Paramount Software (UK) Ltd.) Malwarebytes version 5.6.1.257 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.6.1.257 - Malwarebytes) Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.7.9434.5 - Waves Audio Ltd.) Hidden Microsoft .NET Host - 8.0.13 (x64) (HKLM\...\{6CD2C0A9-55E7-4133-BC19-205CCF2B64C9}) (Version: 64.52.27977 - Microsoft Corporation) Hidden Microsoft .NET Host - 9.0.11 (x64) (HKLM\...\{CF6D52E0-F74C-4C62-8A86-F870C5FE8770}) (Version: 72.44.42384 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 8.0.13 (x64) (HKLM\...\{BB5AC4BC-A263-43DA-A530-9CB56342D6B8}) (Version: 64.52.27977 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 9.0.11 (x64) (HKLM\...\{EABD407D-A4D7-426F-BCEB-2BD0C34B63AA}) (Version: 72.44.42384 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 8.0.13 (x64) (HKLM\...\{C7FB4EEE-D481-4AC1-B113-120A9124FE50}) (Version: 64.52.27977 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 9.0.11 (x64) (HKLM\...\{15A74731-6EA1-4EDD-9A78-2E1A0BCBE573}) (Version: 72.44.42384 - Microsoft Corporation) Hidden Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 150.0.4078.83 - Microsoft Corporation) Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 150.0.4078.83 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.19127.20302 - Microsoft Corporation) Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 26.108.0607.0002 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35208 (HKLM-x32\...\{e90abaf0-d749-437b-ba99-cda1c84b6754}) (Version: 14.44.35208.0 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.50.35719 (HKLM\...\{AECD4ED0-8A3B-41E9-92D1-6BEE0374CCAF}) (Version: 14.50.35719 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.50.35719 (HKLM\...\{61B44572-8722-4DAF-8ACF-8E742D30BCC5}) (Version: 14.50.35719 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35208 (HKLM-x32\...\{5A76FFAE-36C5-4648-80BD-4BB5B6E971F0}) (Version: 14.44.35208 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35208 (HKLM-x32\...\{491C67BA-2F2F-4A90-B9DD-4C76BFDBEA02}) (Version: 14.44.35208 - Microsoft Corporation) Hidden Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 (HKLM-x32\...\{91ee571b-0e8a-4c65-9eaf-2e2f5fc60c00}) (Version: 14.50.35719.0 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 8.0.13 (x64) (HKLM\...\{852F821B-340A-4473-BA94-8FAFD5AFFE85}) (Version: 64.52.27986 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 8.0.13 (x64) (HKLM-x32\...\{e882eb81-b18c-4676-88f0-9a6ea9db6090}) (Version: 8.0.13.34517 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 9.0.11 (x64) (HKLM\...\{1291A37E-2C01-4CA2-BD4B-490B42279CB6}) (Version: 72.44.42433 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 9.0.11 (x64) (HKLM-x32\...\{59a5723a-dcf6-43d8-a8bb-a14466c9d3ca}) (Version: 9.0.11.35420 - Microsoft Corporation) Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox) (Version: 152.0.6 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 135.0.1 - Mozilla) My Media for Alexa (64-bit) (HKLM\...\{F60BA704-7DAB-4E4C-8E27-09460686A2E7}) (Version: 1.3.148.998 - bizmodeller) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20302 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.12527.22270 - Microsoft Corporation) Hidden PDFgear 2.1.16 (HKLM\...\{7DACF63A-4EE4-4837-9AF9-C65D4509FFB4}_is1) (Version: 2.1.16 - PDFgear) Printer Registration (HKLM-x32\...\Canon EISRegistration) (Version: 1.9.3 - Canon Inc.) Proton VPN (HKLM\...\Proton VPN_is1) (Version: 5.1.5 - Proton AG) Realtek Audio COM Components (HKLM-x32\...\{2355B503-9B11-4449-861D-1C1748B26320}) (Version: 1.0.2 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8555 - Realtek Semiconductor Corp.) Stremio (HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\Stremio) (Version: 4.4.181 - Smart Code Ltd) TeamViewer (HKLM\...\TeamViewer) (Version: 15.70.3 - TeamViewer) Uninstalr (HKLM-x32\...\Uninstalr) (Version: 2.8 - Great Software Company) Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.20 - VideoLAN) Windows PC Health Check (HKLM\...\{B008D72C-0326-421E-BB2F-98BA5F9DDE9C}) (Version: 4.0.2410.23001 - Microsoft Corporation) Zoom Workplace (HKU\S-1-5-21-1797482264-3094360332-3849169840-1004\...\ZoomUMX) (Version: 6.7.8 (32670) - Zoom Communications, Inc.) Zoom Workplace (HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\ZoomUMX) (Version: 7.0.5 (38856) - Zoom Communications, Inc.) Packages: ========= Canon PRINT -> C:\Program Files\WindowsApps\34791E63.CanonInkjetSmartConnect_1.11.1.0_x64__6e5tt8cgb93ep [2025-10-10] (Canon Inc.) [Startup Task] Intel® Management and Security Status -> C:\Program Files\WindowsApps\AppUp.IntelManagementandSecurityStatus_2537.8.7.0_x64__8j3eq9eme6ctt [2026-05-22] (INTEL CORP) [Startup Task] Intel® Graphics Command Center -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2026-04-27] (INTEL CORP) [Startup Task] Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1042.0_x64__8j3eq9eme6ctt [2026-04-27] (INTEL CORP) Local Artificial Intelligence Manager -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\AI [2025-10-15] () Microsoft.Office.ActionsServer -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\ActionsServer [2025-10-15] () OfficePushNotificationsUtility -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16 [2025-10-15] () Waves MaxxAudio Pro for Dell -> C:\Program Files\WindowsApps\WavesAudio.WavesMaxxAudioProforDell_1.1.131.0_x64__fh4rh281wavaa [2024-12-19] (Waves Audio) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1797482264-3094360332-3849169840-1004_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) CustomCLSID: HKU\S-1-5-21-1797482264-3094360332-3849169840-1005_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> C:\Program Files\Macrium\Common\ReflectMonitor.exe (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) CustomCLSID: HKU\S-1-5-21-1797482264-3094360332-3849169840-1005_Classes\CLSID\{50726f74-6f6e-2e56-504e-000000000000}\localserver32 -> C:\Program Files\Proton\VPN\v4.3.9\ProtonVPN.Client.exe (Proton AG -> ProtonVPN) CustomCLSID: HKU\S-1-5-21-1797482264-3094360332-3849169840-1005_Classes\CLSID\{a9872fee-5a55-4ecb-9b0f-b06fedcf14d1}\localserver32 -> C:\Windows\System32\DriverStore\FileRepository\wavesapo75de.inf_amd64_5ff36f834a6d461a\MaxxAudioPro.exe (Waves Inc -> Waves Audio Ltd) CustomCLSID: HKU\S-1-5-21-1797482264-3094360332-3849169840-1005_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-11-29] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-04-22] (Malwarebytes Inc -> Malwarebytes) ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-11-29] (Igor Pavlov) [File not signed] ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.108.0607.0002\FileSyncShell64.dll [2026-07-07] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2024-11-29] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-04-22] (Malwarebytes Inc -> Malwarebytes) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox Web Apps\Ccleaner.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "-taskbar-tab" "6d6b76cd-a841-49a3-8ee6-62b324196efb" "-new-window" "hxxps://www.ccleaner.com" "-profile" "C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\p6pm2ppe.default-release-1766262285627" "-container" "0" ==================== Loaded Modules (Whitelisted) ============= 2024-12-20 13:18 - 2024-12-20 13:18 - 000000000 ____L ( ( (Microsoft Windows Software Compatibility Publisher -> Microsoft Corporation)) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems32.dll]) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\c2r32.dll 2024-12-20 13:18 - 2024-12-20 13:18 - 000000000 ____L ( (Microsoft Windows Software Compatibility Publisher -> Microsoft Corporation)) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\AppVIsvSubsystems32.dll 2026-05-22 13:05 - 2016-10-21 16:06 - 000318976 _____ (CANON INC) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\scchmpm.dll 2026-05-22 13:05 - 2017-06-27 10:59 - 000219648 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\cnmpu2.dll 2026-05-22 13:05 - 2017-11-02 15:36 - 000008192 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_ENU.DLL 2026-05-22 13:05 - 2017-11-02 15:36 - 000104960 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_IMG.dll 2025-03-14 01:42 - 2024-11-29 11:00 - 000101376 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ============= BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2025-08-29] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2025-08-29] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-08-29] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-08-29] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-08-29] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-08-29] (Microsoft Corporation -> Microsoft Corporation) ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-12-07 02:14 - 2019-12-07 02:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Network =========================== (Currently there is no automatic fix for this section.) DNS Servers: 192.168.1.254 Windows Firewall is enabled. Network Binding: ============= Ethernet: Intel® Ethernet Connection (5) I219-LM -> e1d68x64.sys ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1797482264-3094360332-3849169840-1004\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5) HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0) ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) MSCONFIG\Services: AESMService => 2 MSCONFIG\Services: AJRouter => 3 MSCONFIG\Services: ALG => 3 MSCONFIG\Services: AppMgmt => 3 MSCONFIG\Services: AppReadiness => 3 MSCONFIG\Services: AssignedAccessManagerSvc => 3 MSCONFIG\Services: AudioEndpointBuilder => 2 MSCONFIG\Services: Audiosrv => 2 MSCONFIG\Services: autotimesvc => 3 MSCONFIG\Services: AxInstSV => 3 MSCONFIG\Services: BDESVC => 3 MSCONFIG\Services: BITS => 2 MSCONFIG\Services: BTAGService => 3 MSCONFIG\Services: BthAvctpSvc => 3 MSCONFIG\Services: bthserv => 3 MSCONFIG\Services: bzserv => 2 MSCONFIG\Services: camsvc => 3 MSCONFIG\Services: CDPSvc => 2 MSCONFIG\Services: CertPropSvc => 3 MSCONFIG\Services: ClickToRunSvc => 2 MSCONFIG\Services: cloudidsvc => 3 MSCONFIG\Services: COMSysApp => 3 MSCONFIG\Services: cphs => 3 MSCONFIG\Services: cplspcon => 2 MSCONFIG\Services: CryptSvc => 2 MSCONFIG\Services: CscService => 3 MSCONFIG\Services: dcsvc => 3 MSCONFIG\Services: DDVCollectorSvcApi => 2 MSCONFIG\Services: DDVDataCollector => 2 MSCONFIG\Services: DDVRulesProcessor => 2 MSCONFIG\Services: defragsvc => 3 MSCONFIG\Services: DellClientManagementService => 2 MSCONFIG\Services: DellTechHub => 2 MSCONFIG\Services: DeviceAssociationService => 2 MSCONFIG\Services: DeviceInstall => 3 MSCONFIG\Services: DevQueryBroker => 3 MSCONFIG\Services: Dhcp => 2 MSCONFIG\Services: diagnosticshub.standardcollector.service => 3 MSCONFIG\Services: diagsvc => 3 MSCONFIG\Services: DiagTrack => 2 MSCONFIG\Services: DispBrokerDesktopSvc => 2 MSCONFIG\Services: DisplayEnhancementService => 3 MSCONFIG\Services: DmEnrollmentSvc => 3 MSCONFIG\Services: dmwappushservice => 3 MSCONFIG\Services: dot3svc => 3 MSCONFIG\Services: DPS => 2 MSCONFIG\Services: DsmSvc => 3 MSCONFIG\Services: DsSvc => 3 MSCONFIG\Services: DusmSvc => 2 MSCONFIG\Services: Eaphost => 3 MSCONFIG\Services: edgeupdate => 2 MSCONFIG\Services: edgeupdatem => 3 MSCONFIG\Services: EFS => 3 MSCONFIG\Services: EventLog => 2 MSCONFIG\Services: EventSystem => 2 MSCONFIG\Services: Fax => 3 MSCONFIG\Services: fdPHost => 3 MSCONFIG\Services: FDResPub => 3 MSCONFIG\Services: fhsvc => 3 MSCONFIG\Services: FileSyncHelper => 3 MSCONFIG\Services: FontCache => 2 MSCONFIG\Services: FontCache3.0.0.0 => 3 MSCONFIG\Services: FoxitReaderUpdateService => 2 MSCONFIG\Services: FrameServer => 3 MSCONFIG\Services: GameInputSvc => 3 MSCONFIG\Services: GoogleChromeElevationService => 3 MSCONFIG\Services: GoogleUpdaterInternalService142.0.7416.0 => 2 MSCONFIG\Services: GoogleUpdaterService142.0.7416.0 => 2 MSCONFIG\Services: GraphicsPerfSvc => 3 MSCONFIG\Services: hidserv => 3 MSCONFIG\Services: HvHost => 3 MSCONFIG\Services: icssvc => 3 MSCONFIG\Services: igccservice => 2 MSCONFIG\Services: igfxCUIService2.0.0.0 => 2 MSCONFIG\Services: IJPLMSVC => 2 MSCONFIG\Services: IKEEXT => 3 MSCONFIG\Services: InstallService => 3 MSCONFIG\Services: Intel® Capability Licensing Service TCP IP Interface => 3 MSCONFIG\Services: Intel® TPM Provisioning Service => 2 MSCONFIG\Services: iphlpsvc => 2 MSCONFIG\Services: IpxlatCfgSvc => 3 MSCONFIG\Services: jhi_service => 2 MSCONFIG\Services: KeyIso => 3 MSCONFIG\Services: KtmRm => 3 MSCONFIG\Services: LanmanServer => 2 MSCONFIG\Services: LanmanWorkstation => 2 MSCONFIG\Services: lfsvc => 3 MSCONFIG\Services: LicenseManager => 3 MSCONFIG\Services: lltdsvc => 3 MSCONFIG\Services: lmhosts => 3 MSCONFIG\Services: LMS => 2 MSCONFIG\Services: LxpSvc => 3 MSCONFIG\Services: MacriumService => 2 MSCONFIG\Services: MapsBroker => 2 MSCONFIG\Services: MBVpnTunnelService => 3 MSCONFIG\Services: McpManagementService => 3 MSCONFIG\Services: MicrosoftEdgeElevationService => 3 MSCONFIG\Services: MixedRealityOpenXRSvc => 3 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: MSDTC => 3 MSCONFIG\Services: MSiSCSI => 3 MSCONFIG\Services: MyMediaForAlexa => 2 MSCONFIG\Services: NaturalAuthentication => 3 MSCONFIG\Services: NcaSvc => 3 MSCONFIG\Services: NcbService => 3 MSCONFIG\Services: NcdAutoSetup => 3 MSCONFIG\Services: Netlogon => 3 MSCONFIG\Services: Netman => 3 MSCONFIG\Services: netprofm => 3 MSCONFIG\Services: NetSetupSvc => 3 MSCONFIG\Services: NlaSvc => 2 MSCONFIG\Services: nsi => 2 MSCONFIG\Services: OneDrive Updater Service => 3 MSCONFIG\Services: ose => 3 MSCONFIG\Services: p2pimsvc => 3 MSCONFIG\Services: p2psvc => 3 MSCONFIG\Services: PcaSvc => 3 MSCONFIG\Services: PeerDistSvc => 3 MSCONFIG\Services: perceptionsimulation => 3 MSCONFIG\Services: PerfHost => 3 MSCONFIG\Services: PhoneSvc => 3 MSCONFIG\Services: pla => 3 MSCONFIG\Services: PlugPlay => 3 MSCONFIG\Services: PNRPAutoReg => 3 MSCONFIG\Services: PNRPsvc => 3 MSCONFIG\Services: PolicyAgent => 3 MSCONFIG\Services: Power => 2 MSCONFIG\Services: PrintNotify => 3 MSCONFIG\Services: PushToInstall => 3 MSCONFIG\Services: QWAVE => 3 MSCONFIG\Services: RasAuto => 3 MSCONFIG\Services: RasMan => 2 MSCONFIG\Services: RetailDemo => 3 MSCONFIG\Services: RmSvc => 3 MSCONFIG\Services: RpcLocator => 3 MSCONFIG\Services: RstMwService => 2 MSCONFIG\Services: RtkAudioService => 2 MSCONFIG\Services: SamSs => 2 MSCONFIG\Services: SCardSvr => 3 MSCONFIG\Services: ScDeviceEnum => 3 MSCONFIG\Services: SCPolicySvc => 3 MSCONFIG\Services: SDRSVC => 3 MSCONFIG\Services: seclogon => 3 MSCONFIG\Services: SEMgrSvc => 3 MSCONFIG\Services: SENS => 2 MSCONFIG\Services: SensorDataService => 3 MSCONFIG\Services: SensorService => 3 MSCONFIG\Services: SensrSvc => 3 MSCONFIG\Services: SessionEnv => 3 MSCONFIG\Services: SharedAccess => 3 MSCONFIG\Services: SharedRealitySvc => 3 MSCONFIG\Services: ShellHWDetection => 2 MSCONFIG\Services: smphost => 3 MSCONFIG\Services: SmsRouter => 3 MSCONFIG\Services: SNMPTRAP => 3 MSCONFIG\Services: spectrum => 3 MSCONFIG\Services: Spooler => 2 MSCONFIG\Services: SSDPSRV => 3 MSCONFIG\Services: SstpSvc => 3 MSCONFIG\Services: stisvc => 2 MSCONFIG\Services: StorSvc => 2 MSCONFIG\Services: SupportAssistAgent => 2 MSCONFIG\Services: svsvc => 3 MSCONFIG\Services: swprv => 3 MSCONFIG\Services: SysMain => 2 MSCONFIG\Services: TabletInputService => 3 MSCONFIG\Services: TapiSrv => 3 MSCONFIG\Services: TeamViewer => 2 MSCONFIG\Services: TermService => 3 MSCONFIG\Services: Themes => 2 MSCONFIG\Services: TieringEngineService => 3 MSCONFIG\Services: TokenBroker => 3 MSCONFIG\Services: TrkWks => 2 MSCONFIG\Services: TroubleshootingSvc => 3 MSCONFIG\Services: TrustedInstaller => 3 MSCONFIG\Services: UmRdpService => 3 MSCONFIG\Services: upnphost => 3 MSCONFIG\Services: UsoSvc => 2 MSCONFIG\Services: VacSvc => 3 MSCONFIG\Services: VaultSvc => 3 MSCONFIG\Services: vds => 3 MSCONFIG\Services: vmicguestinterface => 3 MSCONFIG\Services: vmicheartbeat => 3 MSCONFIG\Services: vmickvpexchange => 3 MSCONFIG\Services: vmicrdv => 3 MSCONFIG\Services: vmicshutdown => 3 MSCONFIG\Services: vmictimesync => 3 MSCONFIG\Services: vmicvmsession => 3 MSCONFIG\Services: vmicvss => 3 MSCONFIG\Services: VSS => 3 MSCONFIG\Services: W32Time => 2 MSCONFIG\Services: WalletService => 3 MSCONFIG\Services: WarpJITSvc => 3 MSCONFIG\Services: WavesSysSvc => 2 MSCONFIG\Services: wbengine => 3 MSCONFIG\Services: WbioSrvc => 3 MSCONFIG\Services: Wcmsvc => 2 MSCONFIG\Services: wcncsvc => 3 MSCONFIG\Services: WDDriveService => 2 MSCONFIG\Services: WdiServiceHost => 3 MSCONFIG\Services: WdiSystemHost => 3 MSCONFIG\Services: WebClient => 3 MSCONFIG\Services: Wecsvc => 3 MSCONFIG\Services: WEPHOSTSVC => 3 MSCONFIG\Services: wercplsupport => 3 MSCONFIG\Services: WerSvc => 3 MSCONFIG\Services: WFDSConMgrSvc => 3 MSCONFIG\Services: WiaRpc => 3 MSCONFIG\Services: Winmgmt => 2 MSCONFIG\Services: WinRM => 3 MSCONFIG\Services: wisvc => 3 MSCONFIG\Services: WlanSvc => 3 MSCONFIG\Services: wlidsvc => 3 MSCONFIG\Services: wlpasvc => 3 MSCONFIG\Services: WManSvc => 3 MSCONFIG\Services: wmiApSrv => 3 MSCONFIG\Services: WMIRegistrationService => 2 MSCONFIG\Services: WMPNetworkSvc => 3 MSCONFIG\Services: workfolderssvc => 3 MSCONFIG\Services: WpcMonSvc => 3 MSCONFIG\Services: WPDBusEnum => 3 MSCONFIG\Services: WpnService => 2 MSCONFIG\Services: WSearch => 2 MSCONFIG\Services: wuauserv => 3 MSCONFIG\Services: WwanSvc => 3 MSCONFIG\Services: XblAuthManager => 3 MSCONFIG\Services: XblGameSave => 3 MSCONFIG\Services: XboxGipSvc => 3 MSCONFIG\Services: XboxNetApiSvc => 3 HKLM\...\StartupApproved\Run: => "Reflect UI" HKLM\...\StartupApproved\Run32: => "EEventManager" HKLM\...\StartupApproved\Run32: => "TeamsMachineUninstallerLocalAppData" HKLM\...\StartupApproved\Run32: => "Reader_Sl" HKU\S-1-5-21-1797482264-3094360332-3849169840-1004\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_5EFC0ECB77A7585FE9DCDD0B2E946A2B" HKU\S-1-5-21-1797482264-3094360332-3849169840-1004\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1797482264-3094360332-3849169840-1004\...\StartupApproved\Run: => "com.squirrel.Teams.Teams" HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_64E73B26A71396A00281960DBC9BDD37" HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\StartupApproved\Run: => "com.squirrel.Teams.Teams" HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\StartupApproved\Run: => "Amazon Photos" HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\StartupApproved\Run: => "EPLTarget\P0000000000000000" HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\StartupApproved\Run: => "Speech Recognition" HKU\S-1-5-21-1797482264-3094360332-3849169840-1005\...\StartupApproved\Run: => "Proton VPN" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{46F5E11B-A474-445F-BB6F-5182511D424E}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{32473B89-E9D7-4BC8-876D-F7DAB133978E}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{A628BFC2-A832-4ED4-B7F9-5D5592B2B2F7}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{0AC6BCEB-73BC-4908-A070-B356BFCE0C72}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{1175E3BF-88D6-418F-B03D-24D764AD3162}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{873C5AA2-68C5-4FCE-95CC-492C2C98EBD4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{C91C4C94-5695-463B-BC92-95AB5A82D784}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [UDP Query User{2106E3B0-F557-487A-82BF-385BCA4C0922}C:\users\brando\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\brando\appdata\roaming\zoom\bin\zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.) FirewallRules: [TCP Query User{E6CE0D26-2277-463F-BCC0-B6CB361FD984}C:\users\brando\appdata\roaming\zoom\bin\zoom.exe] => (Allow) C:\users\brando\appdata\roaming\zoom\bin\zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.) FirewallRules: [{306B48D3-9F57-4EA0-885E-6F39C62BC827}] => (Allow) LPort=52051 FirewallRules: [{CF83FB2B-BB13-47D5-9418-F381BBEBCD40}] => (Allow) LPort=52051 FirewallRules: [{E5037B80-EED7-44E5-9DC7-94227DF944BE}] => (Allow) LPort=52051 FirewallRules: [{3896856E-2A91-4191-8DC5-0A8A309543BD}] => (Allow) LPort=52050 FirewallRules: [{C47BCEC9-90AD-490C-93F8-0C172F84C006}] => (Allow) LPort=52050 FirewallRules: [{8C24B527-B404-4230-B318-CB059A0BE9A3}] => (Allow) LPort=52050 FirewallRules: [UDP Query User{36E2108A-746B-4278-B452-0D58EC172622}C:\users\brando\appdata\local\programs\lnv\stremio-4\stremio-runtime.exe] => (Allow) C:\users\brando\appdata\local\programs\lnv\stremio-4\stremio-runtime.exe (Smart Code OOD -> Node.js) FirewallRules: [TCP Query User{5CA4F302-347F-45A1-B86D-C16DD895F803}C:\users\brando\appdata\local\programs\lnv\stremio-4\stremio-runtime.exe] => (Allow) C:\users\brando\appdata\local\programs\lnv\stremio-4\stremio-runtime.exe (Smart Code OOD -> Node.js) FirewallRules: [{16AD2B57-56C9-422E-86D9-8A6B78B075D0}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{4BCDEC1E-DEFF-4304-B5A2-708ED015517A}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{CA8DE97B-6D46-411B-957E-9AAB03C3DCC1}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{89A6858E-29F3-4D81-B347-FBB2034572F2}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{13113497-C866-4CC5-9671-A6ED855C4412}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{150FD1F8-27AF-484B-8333-48CB69E8E459}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{6010C175-C63D-49A7-A466-F41E32A6906B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{BDFF40F4-EE01-4EFB-BFDD-4ED95E1C2116}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{A01BA601-0492-43CA-8BE5-9202A4918DEF}] => (Allow) C:\Program Files\MiniTool ShadowMaker\AgentService.exe => No File FirewallRules: [{BDB36076-FAA0-4195-8CB3-25D364C639C3}] => (Allow) C:\Program Files\MiniTool ShadowMaker\AgentService.exe => No File FirewallRules: [TCP Query User{04B1AD75-651F-41C7-9A0D-035B82BE7AFD}C:\program files\cleverfiles\disk drill\dd.exe] => (Allow) C:\program files\cleverfiles\disk drill\dd.exe => No File FirewallRules: [UDP Query User{BA88203C-B32B-4A9F-A50A-E3B3D830704F}C:\program files\cleverfiles\disk drill\dd.exe] => (Allow) C:\program files\cleverfiles\disk drill\dd.exe => No File FirewallRules: [{CEC69B18-5DB3-4FF0-8C05-B1ACB79383A5}] => (Allow) C:\Program Files\MiniTool ShadowMaker\AgentService.exe => No File FirewallRules: [{AB8901AF-6CD6-4528-B352-8A8BC7B1353B}] => (Allow) C:\Program Files\MiniTool ShadowMaker\AgentService.exe => No File FirewallRules: [{1FB2D064-2B93-483B-B3AF-E8EB18CB1832}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{C749945F-918F-4CE8-B21F-5B87AE32FB31}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= 30-06-2026 01:23:50 Windows Update 09-07-2026 16:53:08 Scheduled Checkpoint 13-07-2026 03:14:09 Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 14-07-2026 10:23:31 Windows Modules Installer 16-07-2026 19:44:46 Windows Modules Installer ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (07/17/2026 10:20:54 AM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.0 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2508. Message ID: [0x2509]. Error: (07/14/2026 04:58:02 PM) (Source: VSS) (EventID: 13) (User: ) Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.] Error: (07/14/2026 04:53:08 PM) (Source: Firefox Default Browser Agent) (EventID: 5) (User: ) Description: Event-ID 5 Error: (07/12/2026 06:56:34 PM) (Source: Firefox Default Browser Agent) (EventID: 5) (User: ) Description: Event-ID 5 Error: (07/01/2026 12:03:22 PM) (Source: Firefox Default Browser Agent) (EventID: 5) (User: ) Description: Event-ID 5 Error: (06/29/2026 10:54:50 AM) (Source: Firefox Default Browser Agent) (EventID: 5) (User: ) Description: Event-ID 5 Error: (06/19/2026 04:48:25 PM) (Source: Firefox Default Browser Agent) (EventID: 5) (User: ) Description: Event-ID 5 Error: (06/18/2026 05:36:29 PM) (Source: Firefox Default Browser Agent) (EventID: 5) (User: ) Description: Event-ID 5 System errors: ============= Error: (07/19/2026 10:23:17 AM) (Source: DCOM) (EventID: 10001) (User: OPTIPLEX7050) Description: Unable to start a DCOM Server: {ED215C26-C810-49CE-929E-31D7E83A82E9} as Unavailable/Unavailable. The error: "2147942852" Happened while starting this command: "C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot_proxy.exe" -Embedding Error: (07/19/2026 10:23:17 AM) (Source: DCOM) (EventID: 10001) (User: OPTIPLEX7050) Description: Unable to start a DCOM Server: {ED215C26-C810-49CE-929E-31D7E83A82E9} as Unavailable/Unavailable. The error: "2147942852" Happened while starting this command: "C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot_proxy.exe" -Embedding Error: (07/19/2026 08:20:42 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error (0x80073cf9 = Install failed. Please contact your software vendor.): 9NHT9RB2F4HD-Microsoft.Copilot. Error: (07/19/2026 05:03:38 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1795) (User: NT AUTHORITY) Description: The system firmware returned an error (-2147024809 = The parameter is incorrect.) when attempting to update a Secure Boot variable KEK 2023. This device signature information is included here. DeviceAttributes: FirmwareManufacturer:Dell Inc.;FirmwareVersion:1.27.0;OEMManufacturerName:Dell Inc.;OEMModelSKU:07A1;OSArchitecture:amd64; BucketId: e8477d150b1be66e46f6cb52e25b79134cc81e7702db335503ea6ac90cb3fa07 BucketConfidenceLevel: High Confidence. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931 Error: (07/18/2026 10:53:28 PM) (Source: DCOM) (EventID: 10001) (User: OPTIPLEX7050) Description: Unable to start a DCOM Server: {CB3B0003-8088-4EDE-8769-8B354AB2FF8C} as Unavailable/Unavailable. The error: "2147958031" Happened while starting this command: "C:\WINDOWS\system32\DllHost.exe" /Processid:{CB3B0003-8088-4EDE-8769-8B354AB2FF8C} Error: (07/18/2026 10:53:28 PM) (Source: DCOM) (EventID: 10001) (User: OPTIPLEX7050) Description: Unable to start a DCOM Server: {CB3B0003-8088-4EDE-8769-8B354AB2FF8C} as Unavailable/Unavailable. The error: "2147958031" Happened while starting this command: "C:\WINDOWS\system32\DllHost.exe" /Processid:{CB3B0003-8088-4EDE-8769-8B354AB2FF8C} Error: (07/18/2026 10:52:34 PM) (Source: DCOM) (EventID: 10001) (User: OPTIPLEX7050) Description: Unable to start a DCOM Server: {CB3B0003-8088-4EDE-8769-8B354AB2FF8C} as Unavailable/Unavailable. The error: "2147958031" Happened while starting this command: "C:\WINDOWS\system32\DllHost.exe" /Processid:{CB3B0003-8088-4EDE-8769-8B354AB2FF8C} Error: (07/18/2026 10:52:26 PM) (Source: DCOM) (EventID: 10001) (User: OPTIPLEX7050) Description: Unable to start a DCOM Server: {CB3B0003-8088-4EDE-8769-8B354AB2FF8C} as Unavailable/Unavailable. The error: "2147958031" Happened while starting this command: "C:\WINDOWS\system32\DllHost.exe" /Processid:{CB3B0003-8088-4EDE-8769-8B354AB2FF8C} Windows Defender: ================ TimeCreated : 7/18/2026 9:24:00 PM (Message : Microsoft Defender Antivirus scan has been stopped before completion.) (Scan Type: Antimalware) (Scan Parameters: Quick Scan) (Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days) TimeCreated : 7/18/2026 10:50:27 AM (Message : Microsoft Defender Antivirus scan has been stopped before completion.) (Scan Type: Antimalware) (Scan Parameters: Quick Scan) (Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days) TimeCreated : 7/16/2026 6:58:36 PM (Message : Microsoft Defender Antivirus scan has been stopped before completion.) (Scan Type: Antimalware) (Scan Parameters: Quick Scan) (Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days) TimeCreated : 7/15/2026 6:58:36 PM (Message : Microsoft Defender Antivirus scan has been stopped before completion.) (Scan Type: Antimalware) (Scan Parameters: Quick Scan) (Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days) TimeCreated : 7/14/2026 10:02:50 AM (Message : Microsoft Defender Antivirus scan has been stopped before completion.) (Scan Type: Antimalware) (Scan Parameters: Quick Scan) (Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days) TimeCreated : 7/12/2026 7:27:24 PM (Message : Microsoft Defender Antivirus scan has been stopped before completion.) (Scan Type: Antimalware) (Scan Parameters: Quick Scan) (Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days) TimeCreated : 7/12/2026 10:35:45 AM (Message : Microsoft Defender Antivirus scan has been stopped before completion.) (Scan Type: Antimalware) (Scan Parameters: Quick Scan) (Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days) TimeCreated : 7/9/2026 6:49:29 PM (Message : Microsoft Defender Antivirus scan has been stopped before completion.) (Scan Type: Antimalware) (Scan Parameters: Quick Scan) (Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days) CodeIntegrity: =============== Date: 2026-07-19 10:10:13 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\dokannp2.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2025-11-04 01:07:22 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements. ==================== Memory info =========================== BIOS: Dell Inc. 1.27.0 09/18/2023 Motherboard: Dell Inc. 0NW6H5 Processor: Intel® Core™ i7-7700 CPU @ 3.60GHz Percentage of memory in use: 28% Total physical RAM: 32591.53 MB Available physical RAM: 23182.33 MB Total Virtual: 37455.53 MB Available Virtual: 28499.14 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:952.88 GB) (Free:208.16 GB) (Model: P3-1TB) NTFS \\?\Volume{b651a4c5-e5d2-4a6c-a3a9-024aad44133e}\ (Recovery) (Fixed) (Total:0.88 GB) (Free:0.19 GB) NTFS \\?\Volume{637bded3-aeba-4882-9ad2-e1cdf4a4e1ff}\ (SYSTEM) (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 953.9 GB) (Disk ID: D59F80FF) Partition: GPT. ==================== End of Addition.txt =======================
