Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-10-2025
Ran by Retrogamer87 SSD (18-10-2025 07:04:54)
Running from C:\Users\Retrogamer87 SSD\Desktop
Microsoft Windows 10 Pro Version 22H2 19045.6456 (X64) (2023-09-02 17:44:54)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrador (S-1-5-21-2307758842-2925553095-3651173823-500 - Administrator -
Disabled)
Convidado (S-1-5-21-2307758842-2925553095-3651173823-501 - Limited - Enabled)
DefaultAccount (S-1-5-21-2307758842-2925553095-3651173823-503 - Limited - Disabled)
Retrogamer87 SSD (S-1-5-21-2307758842-2925553095-3651173823-1001 - Administrator -
Enabled) => C:\Users\Retrogamer87 SSD
WDAGUtilityAccount (S-1-5-21-2307758842-2925553095-3651173823-504 - Limited -
Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kaspersky (Disabled - Up to date) {70E35457-C7D9-669C-FEA5-55382EABDC78}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Kaspersky (Enabled - Up to date) {4F76F112-43EB-40E8-11D8-F7BD1853EA23}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to
unhide them. The adware programs should be uninstalled manually.)
7-Zip 25.01 (x64) (HKLM\...\7-Zip) (Version: 25.01 - Igor Pavlov)
AIDA64 Extreme v7.70 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 7.70 - FinalWire
Ltd.)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 22.6.1 - Advanced
Micro Devices, Inc.)
ASRock eXtreme Tuner v0.1.434 (HKLM-x32\...\ASRock eXtreme Tuner_is1) (Version:
0.1.434 - ASRock Inc.)
ASRock XFast RAM v2.0.29 (HKLM\...\ASRock XFast RAM_is1) (Version: - ASRock Inc.)
aTube Catcher versão 10.10.0 (HKLM\...\{363C8C67-92B1-4FC9-BEC0-F5F197EFA07E}_is1)
(Version: 10.10.0 - DsNET Corp. - Diego Uscanga)
balenaEtcher (HKU\S-1-5-21-2307758842-2925553095-3651173823-1001\...\balena_etcher)
(Version: 2.1.4 - Balena Ltd. <hello@[Link]>)
BlueStacks (HKLM\...\BlueStacks_nxt) (Version: 5.22.91.1029 - [Link], Inc.)
BlueStacks Services (HKU\S-1-5-21-2307758842-2925553095-3651173823-1001\...\
BlueStacksServices) (Version: 3.0.9 - [Link], Inc.)
Branding64 (HKLM\...\{0DB6E0DC-607A-42C1-A3CE-7567A9F85AF4}) (Version: 1.00.0008 -
Advanced Micro Devices, Inc.) Hidden
By Click Downloader (HKLM-x32\...\{8BB08C18-6BB5-4CF0-88AB-EA64B9F8992E}) (Version:
2.4.6 - ByClick) Hidden
CCleaner 7 (HKLM\...\CCleaner 7) (Version: 7.0.984.1153 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version:
4.5.8.7128 - CDBurnerXP)
ChomikBox (HKLM-x32\...\{8E4185CC-4FF3-46B9-A4DB-5B850B71ABC4}) (Version: [Link] -
[Link])
CPUID HWMonitor 1.59 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.59 - CPUID, Inc.)
CrystalDiskInfo 9.7.2 (HKLM\...\CrystalDiskInfo_is1) (Version: 9.7.2 - Crystal Dew
World)
CrystalDiskMark 9.0.1 (HKLM\...\CrystalDiskMark9_is1) (Version: 9.0.1 - Crystal Dew
World)
DownloadHelper CoApp (HKLM-x32\...\DownloadHelper CoApp) (Version: [Link] -
ACLAP)
Driver Booster 12 (HKLM-x32\...\Driver Booster_is1) (Version: 12.6.0 - IObit)
ENE_QSI_Loki_HAL (HKLM\...\{BDE43F26-5917-44F8-B86A-F1D9A6B80B32}) (Version:
[Link] - ENE TECHNOLOGY INC.) Hidden
ENE_QSI_Loki_HAL (HKLM-x32\...\{205ef3a8-937b-43cb-90fc-2f58f71408d8}) (Version:
[Link] - ENE TECHNOLOGY INC.) Hidden
Foxit PDF Reader (HKLM\...\{01a75e1e-7567-11f0-b81f-54bf64a63c26}) (Version:
2025.2.1.33197 - Foxit Software Inc.) Hidden
Foxit PDF Reader (HKLM-x32\...\{07076c18-fbda-44e6-81c4-4bf87112af2a}) (Version:
2025.2.1.33197 - Foxit Software Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 141.0.7390.108 - Google LLC)
GSmartControl (HKLM-x32\...\gsmartcontrol) (Version: 2.0.2 - Alexander Shaduri)
HD Tune Pro 5.60 (HKLM-x32\...\HD Tune Pro_is1) (Version: - EFD Software)
HP Deskjet 1510 series Software básico do dispositivo (HKLM\...\{4F67DA9C-821A-
42EA-A23A-AF980EA17E7F}) (Version: 32.4.118.94128 - Hewlett-Packard Co.)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version:
[Link] - Hewlett-Packard)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: [Link] - LIGHTNING UK!)
JDownloader 2 (HKLM-x32\...\jdownloader2) (Version: 2.0.1 - AppWork GmbH)
Malwarebytes version [Link] (HKLM\...\{35065F43-4BB2-439A-BFF7-
0F1014F2E0CD}_is1) (Version: [Link] - Malwarebytes)
Microsoft .NET Core Host - 3.1.32 (x64) (HKLM\...\{8A8E3A04-83BC-4CDE-9259-
893B666C1AB1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Host FX Resolver - 3.1.32 (x64) (HKLM\...\{ABC6B3C2-1A8D-4C5E-
AC16-C2AE44F02743}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM\...\{A741B803-3F0E-4684-81EF-
FC128D15A92C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Host - 5.0.17 (x86) (HKLM-x32\...\{54DE7EA9-E391-4BD2-A373-
3A72A18EBDB5}) (Version: 40.68.31213 - Microsoft Corporation) Hidden
Microsoft .NET Host - 6.0.36 (x86) (HKLM-x32\...\{FBC9D6AE-6396-4FC7-BC18-
00852836F16D}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Host - 7.0.20 (x64) (HKLM\...\{EE5EB03B-D65C-4991-848E-
2C6E024326DB}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 5.0.17 (x86) (HKLM-x32\...\{AF01038B-6523-4EA7-
9D9E-4F1E2927D88B}) (Version: 40.68.31213 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.36 (x86) (HKLM-x32\...\{6F73FE7B-B9C3-4A05-
8138-0E44543D755F}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 7.0.20 (x64) (HKLM\...\{B0FC828F-678C-4868-9B5B-
99639758E6F3}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 5.0.17 (x86) (HKLM-x32\...\{59650A2A-3839-46EC-9D9C-
6B3B1C743C55}) (Version: 40.68.31213 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.36 (x86) (HKLM-x32\...\{89C09E22-01D0-41F6-BAD3-
CA0A8B74AD22}) (Version: 48.144.23141 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 7.0.20 (x64) (HKLM\...\{221BB52A-B763-4C9D-AA62-
4B0B6C9AAD62}) (Version: 56.80.15184 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 141.0.3537.71 - Microsoft
Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version:
141.0.3537.85 - Microsoft Corporation) Hidden
Microsoft GameInput (HKLM\...\{64D0CCB1-329E-D507-0886-47E53D59AE21}) (Version:
10.1.26100.6106 - Microsoft Corporation)
Microsoft GameInput (HKLM-x32\...\{1F2B6AF3-C260-8666-5950-E3FEDBC851D6}) (Version:
10.1.22621.3036 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136})
(Version: [Link] - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-
51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-
C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-
F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\
{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft
Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\
{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft
Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-
B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\
{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft
Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\
{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft
Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\
{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft
Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-
03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-
26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\
{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft
Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-
1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\
{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft
Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\
{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft
Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-
551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-
A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\
{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft
Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-
ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\
{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft
Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\
{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft
Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-
08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-
A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\
{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft
Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\
{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft
Corporation) Hidden
Microsoft Windows Desktop Runtime - 3.1.32 (x64) (HKLM\...\{5BEE5F3E-4D78-4DE8-
A8F3-36D3E9D8868C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 3.1.32 (x64) (HKLM-x32\...\{0eddeab6-01c1-4cf7-
83ba-164ea8974c90}) (Version: 3.1.32.31915 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 5.0.17 (x86) (HKLM-x32\...\{098c6ff7-1af1-4c4a-
b86f-c60608c98e31}) (Version: 5.0.17.31219 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 5.0.17 (x86) (HKLM-x32\...\{0D02D706-44F2-4957-
A448-E7259A0B56B9}) (Version: 40.68.31219 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.36 (x86) (HKLM-x32\...\{9A00C541-6944-4969-
9DFE-A7289215800D}) (Version: 48.144.23186 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 6.0.36 (x86) (HKLM-x32\...\{c37854d7-1852-4785-
82ff-86ff988e4caf}) (Version: 6.0.36.34217 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 7.0.20 (x64) (HKLM\...\{72C29BED-666F-4E5E-
BC49-DF44C890742E}) (Version: 56.80.15245 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.20 (x64) (HKLM-x32\...\{362ea044-f96f-45c7-
b59f-0dbe5ca98ff4}) (Version: 7.0.20.33720 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-
436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
MiniTool Partition Wizard Free 12.9 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-
A7C184A8FAC6}_is1) (Version: 12.9 - MiniTool Software Limited)
MPC-HC 2.5.2 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1)
(Version: 2.5.2 - MPC-HC Team)
OnScreen Control (HKLM-x32\...\{E5C1B339-0E4E-49A5-859E-5E1DE1938706}) (Version:
8.26.0 - LG Electronics Inc)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
qBittorrent (HKLM-x32\...\qBittorrent) (Version: 5.0.2 - The qBittorrent project)
QuickMemoryTestOK (HKLM\...\QuickMemoryTestOK) (Version: - com)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-
958108FE7DBC}) (Version: 6.0.1.7560 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
RetroArch (HKLM-x32\...\RetroArch) (Version: [Link] - Libretro)
SD Card Formatter (HKLM-x32\...\{D02212EA-E02A-4521-9036-5367734FC66E}) (Version:
5.0.2 - SD Association)
SeaTools (HKLM-x32\...\SeaTools 5.1.182) (Version: 5.1.182 - Seagate)
Smart Defrag 11 (HKLM-x32\...\Smart Defrag_is1) (Version: [Link] - IObit)
Speccy (HKLM\...\Speccy) (Version: 1.33 - Piriform)
Telegram Desktop (HKU\S-1-5-21-2307758842-2925553095-3651173823-1001\...\{53F49750-
6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 6.1.3 - Telegram FZ-LLC)
Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-
AFCA-E26563CDFB79}) (Version: [Link] - Microsoft Corporation)
Verificação de integridade do PC Windows (HKLM\...\{2403B2D2-1FDC-497D-B181-
F53D079FEAAA}) (Version: 3.6.2204.08001 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.21 - VideoLAN)
Warsaw [Link] 64 bits (HKLM\...\{20E60725-16C8-4FB9-8BC2-AF92C5F8D06D}_is1)
(Version: [Link] - Topaz)
WifiAutoInstall version [Link] (HKLM\...\{BBADB2D6-0408-42D0-AAF8-
B79D3E8B994C}_is1) (Version: [Link] - Realtek, Inc.)
Win32DiskImager version 1.0.0 (HKLM-x32\...\{3DFFA293-DF2C-4B23-92E5-
3433BDC310E1}}_is1) (Version: 1.0.0 - ImageWriter Developers)
WinRAR 7.13 (64-bit) (HKLM\...\WinRAR archiver) (Version: 7.13.0 - [Link] GmbH)
Wise Folder Hider (HKLM-x32\...\Wise Folder Hider_is1) (Version: 5.0.9 - Lespeed
Technology Co., Ltd.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2307758842-2925553095-3651173823-1001_Classes\CLSID\
{50726f74-6f6e-2e56-504e-000000000000}\localserver32 -> "C:\Program Files\Proton\
VPN\v4.3.4\[Link]" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2307758842-2925553095-3651173823-1001_Classes\CLSID\
{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files\Google\
Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google
LLC -> Google LLC)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524}
=> -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282}
=> -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30}
=> -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A}
=> -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}
=> -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3}
=> -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}
=> -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-
C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-
AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-
2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-
7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-
95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-
24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-
2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\
Program Files\7-Zip\[Link] [2025-08-03] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [Kaspersky Free 21.15] -> {AE81D5A2-A34B-4D93-8DF8-
540DBCE48043} => -> No File
ContextMenuHandlers1: [Kaspersky Free 21.16] -> {AE776072-9FCA-48AF-941C-
5759266BB644} => -> No File
ContextMenuHandlers1: [Kaspersky Free 21.17] -> {0F574355-9FBE-40DB-ACB8-
81F6612BB909} => -> No File
ContextMenuHandlers1: [Kaspersky Standard 21.18] -> {2962565E-CA75-4BF1-B282-
AE912144D3DA} => -> No File
ContextMenuHandlers1: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-
8C76A452CC54} => C:\WINDOWS\System32\[Link] [2025-04-22]
(IObit Information Technology -> IObit)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\
Program Files (x86)\[Link] [2025-07-28] ([Link] GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>
C:\Program Files (x86)\[Link] [2025-07-28] ([Link] GmbH -> Alexander Roshal)
ContextMenuHandlers2: [Kaspersky Free 21.15] -> {AE81D5A2-A34B-4D93-8DF8-
540DBCE48043} => -> No File
ContextMenuHandlers2: [Kaspersky Free 21.16] -> {AE776072-9FCA-48AF-941C-
5759266BB644} => -> No File
ContextMenuHandlers2: [Kaspersky Free 21.17] -> {0F574355-9FBE-40DB-ACB8-
81F6612BB909} => -> No File
ContextMenuHandlers2: [Kaspersky Standard 21.18] -> {2962565E-CA75-4BF1-B282-
AE912144D3DA} => -> No File
ContextMenuHandlers3: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-
D1802487FE2D} => -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\
Program Files\Malwarebytes\Anti-Malware\[Link] [2024-12-07] (Malwarebytes
Inc. -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\
Program Files\7-Zip\[Link] [2025-08-03] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [Kaspersky Free 21.15] -> {AE81D5A2-A34B-4D93-8DF8-
540DBCE48043} => -> No File
ContextMenuHandlers4: [Kaspersky Free 21.16] -> {AE776072-9FCA-48AF-941C-
5759266BB644} => -> No File
ContextMenuHandlers4: [Kaspersky Free 21.17] -> {0F574355-9FBE-40DB-ACB8-
81F6612BB909} => -> No File
ContextMenuHandlers4: [Kaspersky Standard 21.18] -> {2962565E-CA75-4BF1-B282-
AE912144D3DA} => -> No File
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => ->
No File
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} =>
C:\Program Files\Recuva\[Link] [2022-06-15] (Piriform Software Ltd ->
Piriform Software Ltd)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\
WINDOWS\System32\[Link] [2022-08-30] (Advanced Micro Devices Inc. -> Advanced
Micro Devices, Inc.)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => ->
No File
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\
Program Files\7-Zip\[Link] [2025-08-03] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [Kaspersky Free 21.15] -> {AE81D5A2-A34B-4D93-8DF8-
540DBCE48043} => -> No File
ContextMenuHandlers6: [Kaspersky Free 21.16] -> {AE776072-9FCA-48AF-941C-
5759266BB644} => -> No File
ContextMenuHandlers6: [Kaspersky Free 21.17] -> {0F574355-9FBE-40DB-ACB8-
81F6612BB909} => -> No File
ContextMenuHandlers6: [Kaspersky Standard 21.18] -> {2962565E-CA75-4BF1-B282-
AE912144D3DA} => -> No File
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\
Program Files\Malwarebytes\Anti-Malware\[Link] [2024-12-07] (Malwarebytes
Inc. -> Malwarebytes)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => ->
No File
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} =>
C:\Program Files\Recuva\[Link] [2022-06-15] (Piriform Software Ltd ->
Piriform Software Ltd)
ContextMenuHandlers6: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-
8C76A452CC54} => C:\WINDOWS\System32\[Link] [2025-04-22]
(IObit Information Technology -> IObit)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\
Program Files (x86)\[Link] [2025-07-28] ([Link] GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>
C:\Program Files (x86)\[Link] [2025-07-28] ([Link] GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to
default or removed. The file will not be moved.)
HKLM\...\Drivers32: [[Link]] => C:\Windows\SysWOW64\[Link] [77824 2008-08-
18] (Fox Magic Software) [File not signed]
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2021-03-09 19:48 - 2021-03-09 19:48 - 000017920 _____ () [File not signed] C:\
Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 003567616 _____ () [File not signed] C:\
Program Files\AMD\CNext\CNext\[Link]
2024-12-07 20:20 - 2025-08-03 03:00 - 000101888 _____ (Igor Pavlov) [File not
signed] C:\Program Files\7-Zip\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000057856 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\audio\qtaudio_windows.dll
2021-03-09 19:48 - 2021-03-09 19:48 - 000031744 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000039424 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000031744 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000414720 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000025088 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000024576 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000023552 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000532992 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\imageformats\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 001441792 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\platforms\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 001189888 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\sqldrivers\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000134656 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\plugins\styles\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 006184448 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 006867456 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000735232 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000120832 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 001104896 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000325120 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 003668480 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000517120 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000051712 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 004228608 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000171008 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 001085440 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000480256 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000205824 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000329728 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000127488 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000390656 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 095598080 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 005587968 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000462848 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000188928 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 002878464 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000055808 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\private\
[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000059392 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtGraphicalEffects\
[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000262144 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtMultimedia\
declarative_multimedia.dll
2021-03-09 19:48 - 2021-03-09 19:48 - 000017920 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtQml\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000017920 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtQuick.2\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000284160 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls.2\
[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000333824 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\
[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000136704 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000090112 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\
[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000313856 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Templates.2\
[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000017920 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\[Link]
2021-03-09 19:48 - 2021-03-09 19:48 - 000091648 _____ (The Qt Company Ltd.) [File
not signed] C:\Program Files\AMD\CNext\CNext\QtWebEngine\[Link]
==================== Alternate Data Streams (Whitelisted) ========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData:YXVtLmh6aQ [9490]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\[Link]:X5ZN8aDXs4 [3506]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\[Link]:TWluaml1 [4310]
AlternateDataStreams: C:\Users\All Users:YXVtLmh6aQ [9490]
AlternateDataStreams: C:\Users\Todos os Usuários:YXVtLmh6aQ [9490]
AlternateDataStreams: C:\ProgramData\Dados de Aplicativos:YXVtLmh6aQ [9490]
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The
"AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSVC => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 06:14 - 2024-09-29 19:55 - 000001342 _____ C:\WINDOWS\system32\drivers\
etc\hosts
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
[Link] [Link]
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: [Link] - [Link]
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> [Link]
Wi-Fi: Realtek 8811CU Wireless LAN 802.11ac USB NIC -> [Link]
nt_wsddntf: Topaz OFD Network Monitor
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\
Program Files\Smart Projects\IsoBuster;%SystemRoot%\system32;%SystemRoot%;
%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\
v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\dotnet\;C:\Program
Files\dotnet\
HKU\S-1-5-21-2307758842-2925553095-3651173823-1001\Control Panel\Desktop\\Wallpaper
-> C:\WINDOWS\SystemApps\[Link].CBS_cw5n1h2txyewy\
DesktopSpotlight\Assets\Images\image_1.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System =>
(ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1)
(TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Program Files\
qBittorrent
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Users\Retrogamer87
SSD\Desktop\[Link]
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
MSCONFIG\Services: AMD Crash Defender Service => 2
MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: CCleanerPerformanceOptimizerService => 3
MSCONFIG\Services: Fax => 3
MSCONFIG\Services: GameInput Service => 2
MSCONFIG\Services: GameInputSvc => 3
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: GoogleUpdaterInternalService140.0.7273.0 => 2
MSCONFIG\Services: GoogleUpdaterService140.0.7273.0 => 2
MSCONFIG\Services: gupdate => 3
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: ucldr_mirm_gl => 3
MSCONFIG\Services: ucldr_MirTrilogy4_GL => 3
HKLM\...\StartupApproved\StartupFolder: => "~D [Link]"
HKLM\...\StartupApproved\Run: => "Opera Browser Assistant"
HKLM\...\StartupApproved\Run: => "Reader_Sl"
HKLM\...\StartupApproved\Run32: => "VirtualCloneDrive"
HKLM\...\StartupApproved\Run32: => "OnScreen Control"
HKLM\...\StartupApproved\Run32: => "Reader_Sl"
HKU\S-1-5-21-2307758842-2925553095-3651173823-1001\...\StartupApproved\Run: =>
"MicrosoftEdgeAutoLaunch_8EEAEEB46E33F9779E13CFEFDF016B9D"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
FirewallRules: [UDP Query User{6A1A66FE-412F-4DE3-9801-FCE1E3250654}C:\program
files\videolan\vlc\[Link]] => (Allow) C:\program files\videolan\vlc\[Link]
(VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{067B001C-5CE5-4C43-B391-C900B4A0B458}C:\program
files\videolan\vlc\[Link]] => (Allow) C:\program files\videolan\vlc\[Link]
(VideoLAN -> VideoLAN)
FirewallRules: [{A36AC2FC-FF2E-4599-BDCC-BF81F8AC25CA}] => (Allow) C:\Program
Files\HP\HP Deskjet 1510 series\Bin\[Link] (HP Inc. ->
Hewlett-Packard Development Company, LP)
FirewallRules: [{15B2B610-297A-46B3-970A-4BC5C9772622}] => (Allow) C:\Program
Files\HP\HP Deskjet 1510 series\Bin\[Link] (HP Inc. -> Hewlett-Packard
Development Company, LP)
FirewallRules: [{BD6BF039-82F4-499D-8542-EB24C7AF4C1D}] => (Allow) LPort=42305
FirewallRules: [{E5C66399-F9CC-4BF7-B27E-D396C41F6BF5}] => (Allow) LPort=20902
FirewallRules: [{F7FB7F27-44E4-4ECA-81A9-C56908A9637C}] => (Allow) C:\HP\
Diagnostics\PSDR\[Link] (HP Inc. -> HP Development Company, L.P.)
FirewallRules: [{8E1B8727-9805-4076-941B-98AAF3B2EB53}] => (Allow) C:\HP\
Diagnostics\PSDR\[Link] (HP Inc. -> HP Development Company, L.P.)
FirewallRules: [{6BE1F60C-E081-477E-87A0-835E425FFFD5}] => (Allow) C:\Program
Files\Topaz OFD\Warsaw\[Link] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD)
FirewallRules: [{C9E0EEF5-DB55-4797-A5CF-F1E2D9905E60}] => (Allow) LPort=57209
FirewallRules: [{B3ADE6DD-5094-4D97-90CC-ED8A0CB9DB04}] => (Allow) LPort=57210
FirewallRules: [{C99A2F14-DCB6-45D0-ACFC-7E4D49B4B5BB}] => (Allow) LPort=57211
FirewallRules: [{1E46FD90-E282-4D54-AE4E-FA35E776E507}] => (Allow) LPort=57212
FirewallRules: [{9B18E5E9-8016-4BCA-95A0-DE33A71C980B}] => (Allow) LPort=57213
FirewallRules: [{5059AE68-6CD8-482F-9947-DCDF78E80450}] => (Allow) LPort=57214
FirewallRules: [{F10C107E-2FC3-460C-9B72-24ADBE61B5C1}] => (Allow) LPort=57215
FirewallRules: [{B560F0EC-0EC7-419B-81ED-FF6A9B73BE48}] => (Allow) LPort=57216
FirewallRules: [{D7B4AFC3-250C-4753-BDA4-704CE9FA393E}] => (Allow) LPort=57217
FirewallRules: [{D769806C-AAF9-4EA5-8EA9-FE1A4174A759}] => (Allow) LPort=57218
FirewallRules: [{7FB7F3F5-39EF-45D8-92B9-D13D1A1D9C6D}] => (Allow) LPort=57209
FirewallRules: [{AA5FEC70-5E20-40A1-9142-F30ADA239DDD}] => (Allow) LPort=57210
FirewallRules: [{9318F053-71FF-4D71-81A3-0E1AA3EE8E97}] => (Allow) LPort=57211
FirewallRules: [{4BAF74C4-AAD9-4E61-BFCB-174755911ECA}] => (Allow) LPort=57212
FirewallRules: [{D9475071-4577-417E-9077-116182A978AC}] => (Allow) LPort=57213
FirewallRules: [{ADD4DB77-B8DE-4C71-978E-DB395323390C}] => (Allow) LPort=57214
FirewallRules: [{290893F2-6E34-402E-960A-C4F91CAFF9D0}] => (Allow) LPort=57215
FirewallRules: [{8A141AD4-F1B6-4AA6-A133-2A95F3BE1ED9}] => (Allow) LPort=57216
FirewallRules: [{8420F260-B6E9-4FC2-B9B1-E12CB2941B5B}] => (Allow) LPort=57217
FirewallRules: [{63D8635D-5B63-4AB9-9AB7-8E8CE75E83B0}] => (Allow) LPort=57218
FirewallRules: [{AE9DAE80-A1D4-4FA5-8D13-7E7C2D22CA3B}] => (Allow) LPort=23007
FirewallRules: [{0FC5F4B4-40EA-4E4F-9622-46AC24AE030A}] => (Allow) LPort=23008
FirewallRules: [{BA9CA895-3A3F-4A81-A63B-7A026A10540D}] => (Allow) LPort=33009
FirewallRules: [{78527F6F-DBFE-4557-BEF9-4CF7073DB422}] => (Allow) LPort=33010
FirewallRules: [{0ECA6733-D950-4513-9666-C16A18379EE0}] => (Allow) LPort=33011
FirewallRules: [{D514889F-7CBA-4B42-8504-EC2515EFCCE7}] => (Allow) LPort=43012
FirewallRules: [{6B610729-5A59-4D2D-A186-458C65ABDC92}] => (Allow) LPort=43013
FirewallRules: [{5178EC68-E51C-4E10-A5FA-BED072AD437C}] => (Allow) LPort=53014
FirewallRules: [{2411528E-C292-4A27-B557-57C277EA9788}] => (Allow) LPort=53015
FirewallRules: [{DD975457-949F-400A-8D0C-63E79543D8CA}] => (Allow) LPort=53016
FirewallRules: [{8A97C1E7-4B11-47D3-BBC7-8E822533A567}] => (Allow) LPort=23007
FirewallRules: [{85C5D65C-5D6B-4DAF-801C-DA284C785873}] => (Allow) LPort=23008
FirewallRules: [{C9D1A772-F964-422F-B332-98432AB0E25D}] => (Allow) LPort=33009
FirewallRules: [{C84AABC6-42CD-44A0-838F-CAA4DACCEFC1}] => (Allow) LPort=33010
FirewallRules: [{AF9D6D83-AD5D-49FD-A866-64149CD31020}] => (Allow) LPort=33011
FirewallRules: [{C5CE2CE1-74C7-4B49-BD17-4330C7A8A27E}] => (Allow) LPort=43012
FirewallRules: [{FD1C1264-278D-4887-BC14-D30D8A8AA5E2}] => (Allow) LPort=43013
FirewallRules: [{B751B608-A00A-4824-8E87-9C2AA0CD6029}] => (Allow) LPort=53014
FirewallRules: [{B6067CEB-168F-4855-A563-FCEA1DC5280D}] => (Allow) LPort=53015
FirewallRules: [{937A9C2D-C492-43DC-AD73-34EB87112342}] => (Allow) LPort=53016
FirewallRules: [{042D6D10-9718-4552-88F4-59E6CD8C9082}] => (Allow) LPort=50053
FirewallRules: [{ED9287C7-B13A-4137-BB40-393B1572BBBB}] => (Allow) LPort=50053
FirewallRules: [{EC2232BF-F603-4E4C-BB74-A28F1C5153EE}] => (Allow) C:\Program
Files\qBittorrent\[Link] (The qBittorrent Project) [File not signed]
FirewallRules: [{FF0A555D-0273-4A91-A23B-136F3FB11E2A}] => (Allow) C:\Program
Files\qBittorrent\[Link] (The qBittorrent Project) [File not signed]
FirewallRules: [TCP Query User{E855747A-D193-4DCF-9188-2A88FDEF5114}C:\users\
retrogamer87 ssd\appdata\local\jdownloader 2.0\[Link]] => (Allow) C:\
users\retrogamer87 ssd\appdata\local\jdownloader 2.0\[Link] (Appwork GmbH
-> AppWork GmbH)
FirewallRules: [UDP Query User{782E90EC-CA3A-4585-81CF-8E59770EC791}C:\users\
retrogamer87 ssd\appdata\local\jdownloader 2.0\[Link]] => (Allow) C:\
users\retrogamer87 ssd\appdata\local\jdownloader 2.0\[Link] (Appwork GmbH
-> AppWork GmbH)
FirewallRules: [{DDDE2468-9C79-47AD-95B3-F8E923CA4B42}] => (Allow) C:\Program
Files\BlueStacks_nxt\[Link] ([Link], INC -> BlueStack Systems)
FirewallRules: [{6328117D-6D83-4319-AC38-B115161D8344}] => (Allow) C:\Program
Files\BlueStacks_nxt\[Link] ([Link], INC -> The Qt Company
Ltd.)
FirewallRules: [TCP Query User{A61B4F83-EF94-4245-90D7-FCB65147837D}C:\program
files\videolan\vlc\[Link]] => (Allow) C:\program files\videolan\vlc\[Link]
(VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{5D08058E-DB99-4F90-BB25-1F805F9A6E96}C:\program
files\videolan\vlc\[Link]] => (Allow) C:\program files\videolan\vlc\[Link]
(VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{1C3373A2-8EEC-4310-A34E-B700237758A1}C:\users\
retrogamer87 ssd\appdata\local\jdownloader 2.0\[Link]] => (Allow) C:\
users\retrogamer87 ssd\appdata\local\jdownloader 2.0\[Link] (Appwork GmbH
-> AppWork GmbH)
FirewallRules: [UDP Query User{7AE6C5E7-4279-46E9-B2D1-40405CDDD435}C:\users\
retrogamer87 ssd\appdata\local\jdownloader 2.0\[Link]] => (Allow) C:\
users\retrogamer87 ssd\appdata\local\jdownloader 2.0\[Link] (Appwork GmbH
-> AppWork GmbH)
FirewallRules: [TCP Query User{4AC4C7E6-D89F-4129-8F8C-04AD71FD1914}C:\program
files\qbittorrent\[Link]] => (Allow) C:\program files\qbittorrent\
[Link] (The qBittorrent Project) [File not signed]
FirewallRules: [UDP Query User{440DBEAB-4C5E-4DB5-91DB-F4E7E8907819}C:\program
files\qbittorrent\[Link]] => (Allow) C:\program files\qbittorrent\
[Link] (The qBittorrent Project) [File not signed]
FirewallRules: [{038B5B9D-91A6-4567-8D7D-C124D41290ED}] => (Allow) C:\Program
Files\Google\Chrome\Application\[Link] (Google LLC -> Google LLC)
==================== Restore Points =========================
ATTENTION: System Restore is disabled (Total:475.88 GB) (Free:50 GB) (11%)
==================== Faulty Device Manager Devices ============
Name: AMD High Definition Audio Device
Description: AMD High Definition Audio Device
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Advanced Micro Devices
Service: AtiHDAudioService
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This
starts the Enable Device wizard. Follow the instructions.
Name: Realtek High Definition Audio
Description: Realtek High Definition Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: IntcAzAudAddService
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This
starts the Enable Device wizard. Follow the instructions.
Name: AMD Streaming Audio Device
Description: AMD Streaming Audio Device
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: AMD
Service: AMDSAFD
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This
starts the Enable Device wizard. Follow the instructions.
Name: Realtek PCIe GbE Family Controller
Description: Realtek PCIe GbE Family Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: rt640x64
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This
starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: ========================
Application errors:
==================
Error: (10/16/2025 07:09:45 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Erro do serviço de cópias de sombra de volume: erro inesperado ao
chamar a rotina QueryFullProcessImageNameW. hr = 0x80070006, Identificador
inválido..
Operação:
Executando Operação Assíncrona
Contexto:
Estado Atual: DoSnapshotSet
Error: (10/16/2025 07:09:11 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Erro do Serviço de Cópias de Sombra de Volume: erro inesperado ao
consultar a interface IVssWriterCallback. hr = 0x80070005, Acesso negado..Muitas
vezes, isso é causado por configurações de segurança incorretas no processo
gravador ou solicitante.
Operação:
Obtendo Dados do Gravador
Contexto:
Id de Classe de Gravador: {e8132975-6f93-4464-a53e-1050253ae220}
Nome do Gravador: System Writer
ID de Instância de Gravador: {2b2e375d-c327-4dbc-b464-a5ba1a7b1914}
Error: (10/15/2025 09:44:10 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Erro do serviço de cópias de sombra de volume: erro inesperado ao
chamar a rotina CoCreateInstance. hr = 0x8007045b, O sistema está sendo
desligado..
Error: (10/15/2025 09:44:10 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informações sobre o Serviço de Cópias de Sombra de Volume: não é
possível iniciar o Servidor COM com CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} e
nome CEventSystem. [0x8007045b, O sistema está sendo desligado.]
Error: (10/15/2025 09:44:10 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Erro do serviço de cópias de sombra de volume: erro inesperado ao
chamar a rotina CoCreateInstance. hr = 0x8007045b, O sistema está sendo
desligado..
Error: (10/15/2025 09:44:10 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informações sobre o Serviço de Cópias de Sombra de Volume: não é
possível iniciar o Servidor COM com CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} e
nome CEventSystem. [0x8007045b, O sistema está sendo desligado.]
Error: (10/10/2025 09:24:57 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informações sobre o Serviço de Cópias de Sombra de Volume: não é
possível iniciar o Servidor COM com CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} e
nome CEventSystem. [0x8007045b, O sistema está sendo desligado.]
Error: (10/08/2025 03:04:40 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Erro do serviço de cópias de sombra de volume: erro inesperado ao
chamar a rotina CoCreateInstance. hr = 0x8007045b, O sistema está sendo
desligado..
System errors:
=============
Error: (10/18/2025 07:02:22 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801)
(User: AUTORIDADE NT)
Description: As ca/chaves de inicialização segura precisam ser atualizadas. Estas
informações de assinatura do dispositivo estão incluídas aqui.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American
Megatrends Inc.;FirmwareVersion:P1.40;OEMModelNumber:To Be Filled By
O.E.M.;OEMModelBaseBoard:B75M-DGS R2.0;OEMModelSystemFamily:To Be Filled By
O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By
O.E.M.;OSArchitecture:amd64;
BucketId: bf5c92ef20534a7ff87d0dda0a387e1762594bc22c082d64569ead3ae7cb2461
BucketConfidenceLevel:
UpdateType: 0
HResult: 0
Error: (10/18/2025 06:57:21 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: O desligamento do sistema que ocorreu às 06:56:20 do dia 18/10/2025
não era esperado.
Error: (10/18/2025 06:50:21 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801)
(User: AUTORIDADE NT)
Description: As ca/chaves de inicialização segura precisam ser atualizadas. Estas
informações de assinatura do dispositivo estão incluídas aqui.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American
Megatrends Inc.;FirmwareVersion:P1.40;OEMModelNumber:To Be Filled By
O.E.M.;OEMModelBaseBoard:B75M-DGS R2.0;OEMModelSystemFamily:To Be Filled By
O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By
O.E.M.;OSArchitecture:amd64;
BucketId: bf5c92ef20534a7ff87d0dda0a387e1762594bc22c082d64569ead3ae7cb2461
BucketConfidenceLevel:
UpdateType: 0
HResult: 0
Error: (10/18/2025 06:46:43 AM) (Source: Service Control Manager) (EventID: 7034)
(User: )
Description: O serviço Foxit PDF Reader Update Service foi encerrado
inesperadamente. Isso aconteceu 1 vez(es).
Error: (10/18/2025 06:46:43 AM) (Source: Service Control Manager) (EventID: 7034)
(User: )
Description: O serviço Wifi AutoInstall Service foi encerrado inesperadamente.
Isso aconteceu 1 vez(es).
Error: (10/18/2025 06:46:43 AM) (Source: Service Control Manager) (EventID: 7034)
(User: )
Description: O serviço RunSwUSB foi encerrado inesperadamente. Isso aconteceu 1
vez(es).
Error: (10/17/2025 09:06:15 AM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801)
(User: AUTORIDADE NT)
Description: As ca/chaves de inicialização segura precisam ser atualizadas. Estas
informações de assinatura do dispositivo estão incluídas aqui.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American
Megatrends Inc.;FirmwareVersion:P1.40;OEMModelNumber:To Be Filled By
O.E.M.;OEMModelBaseBoard:B75M-DGS R2.0;OEMModelSystemFamily:To Be Filled By
O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By
O.E.M.;OSArchitecture:amd64;
BucketId: bf5c92ef20534a7ff87d0dda0a387e1762594bc22c082d64569ead3ae7cb2461
BucketConfidenceLevel:
UpdateType: 0
HResult: 0
Error: (10/16/2025 07:15:37 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1801)
(User: AUTORIDADE NT)
Description: As ca/chaves de inicialização segura precisam ser atualizadas. Estas
informações de assinatura do dispositivo estão incluídas aqui.
DeviceAttributes: BaseBoardManufacturer:ASRock;FirmwareManufacturer:American
Megatrends Inc.;FirmwareVersion:P1.40;OEMModelNumber:To Be Filled By
O.E.M.;OEMModelBaseBoard:B75M-DGS R2.0;OEMModelSystemFamily:To Be Filled By
O.E.M.;OEMManufacturerName:To Be Filled By O.E.M.;OEMModelSKU:To Be Filled By
O.E.M.;OSArchitecture:amd64;
BucketId: bf5c92ef20534a7ff87d0dda0a387e1762594bc22c082d64569ead3ae7cb2461
BucketConfidenceLevel:
UpdateType: 0
HResult: 0
Windows Defender:
================
Date: 2025-10-16 21:33:18
Description:
Microsoft Defender Antivírus detectou malware ou outro software potencialmente
indesejado.
Para obter mais informações, veja a seguir:
[Link]
ml&threatid=2147780199&enterprise=0
Nome: Trojan:Script/[Link].A!ml
Gravidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Retrogamer87 SSD\Downloads\[Link]
Origem da Detecção: Computador local
Tipo da Detecção: FastPath
Fonte da Detecção: Proteção em Tempo Real
Usuário: DESKTOP-3DM2P71\Retrogamer87 SSD
Nome do Processo: C:\Program Files (x86)\[Link]
Versão da Inteligência de Segurança: AV: [Link], AS: [Link], NIS:
[Link]
Versão do Mecanismo: AM: 1.1.25090.3001, NIS: 1.1.25090.3001
Date: 2025-10-16 21:31:15
Description:
Microsoft Defender Antivírus detectou malware ou outro software potencialmente
indesejado.
Para obter mais informações, veja a seguir:
[Link]
ml&threatid=2147780199&enterprise=0
Nome: Trojan:Script/[Link].A!ml
Gravidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Retrogamer87 SSD\AppData\Roaming\secure\
QBDBSSEGVJKGRXQAMLWXANXBV\[Link]
Origem da Detecção: Computador local
Tipo da Detecção: FastPath
Fonte da Detecção: Proteção em Tempo Real
Usuário: DESKTOP-3DM2P71\Retrogamer87 SSD
Nome do Processo: C:\Program Files (x86)\[Link]
Versão da Inteligência de Segurança: AV: [Link], AS: [Link], NIS:
[Link]
Versão do Mecanismo: AM: 1.1.25090.3001, NIS: 1.1.25090.3001
Date: 2025-10-16 21:25:04
Description:
Microsoft Defender Antivírus detectou malware ou outro software potencialmente
indesejado.
Para obter mais informações, veja a seguir:
[Link]
ml&threatid=2147780199&enterprise=0
Nome: Trojan:Script/[Link].A!ml
Gravidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Retrogamer87 SSD\Downloads\[Link]
Origem da Detecção: Computador local
Tipo da Detecção: FastPath
Fonte da Detecção: Proteção em Tempo Real
Usuário: DESKTOP-3DM2P71\Retrogamer87 SSD
Nome do Processo: C:\Program Files (x86)\[Link]
Versão da Inteligência de Segurança: AV: [Link], AS: [Link], NIS:
[Link]
Versão do Mecanismo: AM: 1.1.25090.3001, NIS: 1.1.25090.3001
Date: 2025-10-16 21:22:31
Description:
Microsoft Defender Antivírus detectou malware ou outro software potencialmente
indesejado.
Para obter mais informações, veja a seguir:
[Link]
ml&threatid=2147780199&enterprise=0
Nome: Trojan:Script/[Link].A!ml
Gravidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Retrogamer87 SSD\AppData\Roaming\secure\
QBDBSSEGVJKGRXQAMLWXANXBV\[Link]
Origem da Detecção: Computador local
Tipo da Detecção: FastPath
Fonte da Detecção: Proteção em Tempo Real
Usuário: DESKTOP-3DM2P71\Retrogamer87 SSD
Nome do Processo: C:\Program Files (x86)\[Link]
Versão da Inteligência de Segurança: AV: [Link], AS: [Link], NIS:
[Link]
Versão do Mecanismo: AM: 1.1.25090.3001, NIS: 1.1.25090.3001
Date: 2025-10-16 21:21:11
Description:
Microsoft Defender Antivírus detectou malware ou outro software potencialmente
indesejado.
Para obter mais informações, veja a seguir:
[Link]
ml&threatid=2147780199&enterprise=0
Nome: Trojan:Script/[Link].A!ml
Gravidade: Grave
Categoria: Cavalo de Tróia
Caminho: file:_C:\Users\Retrogamer87 SSD\AppData\Roaming\secure\
QBDBSSEGVJKGRXQAMLWXANXBV\[Link]
Origem da Detecção: Computador local
Tipo da Detecção: FastPath
Fonte da Detecção: Proteção em Tempo Real
Usuário:
Nome do Processo: Unknown
Versão da Inteligência de Segurança: AV: [Link], AS: [Link], NIS:
[Link]
Versão do Mecanismo: AM: 1.1.25090.3001, NIS: 1.1.25090.3001
CodeIntegrity:
===============
Date: 2025-10-17 09:01:30
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\
[Link]) attempted to load \Device\HarddiskVolume2\Program Files\Topaz OFD\
Warsaw\[Link] that did not meet the Microsoft signing level requirements.
Date: 2025-10-17 09:01:30
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\
[Link]) attempted to load \Device\HarddiskVolume2\Program Files\Topaz OFD\
Warsaw\[Link] that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends Inc. P1.40 10/01/2013
Motherboard: ASRock B75M-DGS R2.0
Processor: Intel(R) Core(TM) i5-3470 CPU @ 3.20GHz
Percentage of memory in use: 61%
Total physical RAM: 16329.95 MB
Available physical RAM: 6364.97 MB
Total Virtual: 29641.95 MB
Available Virtual: 16737.34 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:475.88 GB) (Free:50 GB) (Model: SATA3 512GB SSD) NTFS
Drive g: () (Fixed) (Total:464.7 GB) (Free:186.33 GB) (Model: WDC WD5000BEVT-
00ZAT0) NTFS
\\?\Volume{ec57e732-0000-0000-0000-100000000000}\ (Reservado pelo Sistema) (Fixed)
(Total:0.54 GB) (Free:0.5 GB) NTFS
\\?\Volume{ec57e732-0000-0000-0000-001b77000000}\ () (Fixed) (Total:0.52 GB)
(Free:0.06 GB) NTFS
\\?\Volume{000777b1-0000-0000-0000-404f74000000}\ () (Fixed) (Total:0.52 GB)
(Free:0.08 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 476.9 GB) (Disk ID: EC57E732)
Partition 1: (Active) - (Size=549 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=475.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=528 MB) - (Type=27)
==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 000777B1)
Partition 1: (Not Active) - (Size=464.7 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=534 MB) - (Type=27)
==================== End of [Link] =======================