The following problem description is copied from my original post at https://www.bleepingcomputer.com/forums/t/811209/problem-booting-from-dvdrw/ Suggestion from that was to repost here.
I have left a lot of info out of this post because it would be way to long so some steps I've taken are missing.
For a week or so I've been having problems booting my HP TouchSmart 520-1030, running Win10/Win11 dual boot, from bootable DVD's. This PC is not Win11 compliant but has been working seemingly OK since the dual boot was created. I had to convert the HDD from Dynamic to Basic and Legacy BIOS to UEFI so I could install Win11.
The initial problem was booting from its own latest W10 System Repair Disk following a change of the Win10 Product Key and failure of MS Word to load, which has now resolved itself but the booting problem still exists.
The issue grew to inconsistent booting from any bootable DVD/CD to no booting from any DVD/CD, Windows created or otherwise. However, all but the latest HP System Repair Disk would boot another dual boot W10/W11 PC (Acer XC-215 also non-Win11 compliant), which suggest all but one DVD/CD's are not in themselves faulty (though possibly had become incompatible if that is possible).
I tried several times to create a new System Repair Disk on the HP using both new and over-writing existing DVD’s but all attempts failed.
I tried several times to reset/rebuild the WBM/EFI but not really being sure of what I was doing I gave up with this. In desperation I reset the Win10 installation on the HP, keeping both files and Apps. This improved matters but did not resolve them completely. I got more consistent booting depending on the disk used but not as it should be and not at all with the latest HP System Repair Disk.
I swapped the DVDRW drive from the Acer into the HP and this improved the issue still further. I was now able to get consistent booting from all but the latest HP System Repair Disk. I was also able to create a new System Repair Disk on a new DVD and by over-writing the previous ‘latest HP System Repair Disk’ both of which booted the PC. They also booted the Acer now using the DVDRW drive from the HP. I tried all the DVDs in both PC’s and they all work, well almost. This suggests the DVD’s and Drives are OK albeit not always fully compatible.
This morning, I successfully booted the Acer using the HP DVDRW drive and very latest HP System Repair Disk 3 times, however, when I tried to boot the HP using the Acer DVDRW drive and very latest HP System Repair Disk it would not work but had done yesterday. Grrrrrrr
When I look at the boot options under Legacy Boot Sources on the HP a new entry has recently appeared that says ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿ ÿoPtrbae1U 0.
Would this indicate some sort of malware? See photo. If not what else could be at fault.
The DVD/CDs contain:
- Win10 Installation media of various versions both 32 & 64bit
- Win10 System Repair media from the TouchSmart and other Win10 PCs both 32 & 64bit
- Macrium Reflect rescue media from the TouchSmart
- SeaTools4DOS
- Hiren's BootCD for Win10
And are either Verbatim 4.7GB 4x DVD-RW, Verbatim 4.7GB 16x DVD +R RW or Maxell CD-R 52x.
I'm aware that Recovery USB drives are the better more reliable option but at the time my only option was the DVD route.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-10-2025
Ran by KAA (administrator) on TOUCHSMART (Hewlett-Packard 520-1030uk) (08-10-2025 22:13:50)
Running from C:\Users\KAA\Downloads\FRST64.exe
Loaded Profiles: KAA
Platform: Microsoft Windows 10 Pro Version 22H2 19045.6332 (X64) Language: English (United Kingdom)
Default browser: C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.exe
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12138.3.59016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(C:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Mirics Semiconductor) C:\Program Files\MiricsFlexiTV\Driver\MSiBdaDemodWrapper.exe
(C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.exe ->) (Duck Duck Go, Inc. -> Microsoft Corporation) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\WebView2\msedgewebview2.exe <20>
(explorer.exe ->) (Duck Duck Go, Inc. -> DuckDuckGo) C:\Program Files\WindowsApps\DuckDuckGo.DesktopBrowser_0.130.2.0_x64__ya2fgkz3nks94\WindowsBrowser\DuckDuckGo.exe
(explorer.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(explorer.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(explorer.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Andrea Electronics Corporation) [File not signed] C:\Program Files\IDT\WDM\AESTSr64.exe
(services.exe ->) (IDT, Inc.) [File not signed] C:\Program Files\IDT\WDM\stacsv64.exe
(services.exe ->) (Lenovo -> Motorola) C:\Program Files\Lenovo\Ready For Assistant\ReadyForService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Mirics Ltd.) C:\Program Files\MiricsFlexiTV\DVBT\DVBservice.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Mirics Semiconductor) C:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\NisSrv.exe
(services.exe ->) (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(services.exe ->) (Seraph Secure Inc. -> Seraph Secure Inc.) C:\Program Files\Seraph Secure\SeraphSecure.Desktop.Service.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(svchost.exe ->) (Seraph Secure Inc. -> Seraph Secure Inc.) C:\Program Files\Seraph Secure\SeraphSecure.Desktop.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2012-10-18] (Integrated Device Technology Inc. -> Hewlett-Packard) [File not signed]
HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [11859680 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-10-18] (IDT, Inc.) [File not signed]
HKLM-x32\...\Run: [EKStatusMonitor] => C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe [2750840 2013-12-11] (Eastman Kodak Company -> Eastman Kodak Company)
HKLM-x32\...\Run: [Nero BackItUp] => C:\Program Files (x86)\Nero\Nero 2017\Nero BackItup\BackItUp.exe [1150320 2016-11-08] (Nero AG -> Nero AG)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [41579480 2025-09-29] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1004\...\Run: [MicrosoftEdgeAutoLaunch_70F5C52BE9DF1358C7250A17068A79C5] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2603899380-3263017511-4129809722-1007\...\Run: [MicrosoftEdgeAutoLaunch_0312593BFFDB8261C1676A58C7A72931] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4265000 2025-10-02] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Print\Monitors\KODAK All-in-One Printer: C:\WINDOWS\system32\EKAiO2MON.dll [1649664 2013-11-19] (Microsoft Windows Hardware Compatibility Publisher -> Eastman Kodak Company)
Startup: C:\Users\KAA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2022-04-09]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2025-10-06]
GroupPolicy: Restriction - Edge <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {4E3227A3-D76B-48C7-9FBA-2F6ADC701346} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1581568 2025-08-24] (Adobe Inc. -> Adobe Inc.)
Task: {A2FFEC02-982C-4D11-A8EE-42CA7FCA65DB} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem131.0.6776.0{F668BBEF-823D-4D83-8CD3-495C7587B595} => C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\updater.exe [5507168 2024-10-14] (Google LLC -> Google LLC)
Task: {BF3C8C90-BED3-40C3-AD45-BB50418E301E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001Core{D220553E-E54C-4CD1-BC37-1A56E28B2CD4} => C:\Users\KAA\AppData\Local\Google\Update\GoogleUpdate.exe /c (No File)
Task: {A3BE9F3C-ECCA-4213-A7D3-A174A2CC35D7} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001UA{99C2A8AA-F663-43F3-A707-6DECB4586918} => C:\Users\KAA\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler (No File)
Task: {93EFB0AA-12D5-4C09-BC7C-81DCB73A5BFD} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ABO => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://ABO
Task: {CEC80FA8-A7F9-4DAB-95BF-60017DE39D86} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusError => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BatteryStatusError
Task: {8AEC054E-DC44-4E8D-8BE5-00507F16F1BB} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BCF => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BCF
Task: {92379D3F-DF65-4F74-9DA2-79406E4B59E0} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM1 => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM1
Task: {022BA1A8-53F1-4EA0-AFFA-5EFE02716F56} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM2 => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM2
Task: {8A4D5CFD-883D-4534-9FA2-B184B7ACC79D} - System32\Tasks\Hewlett-Packard\HP Diagnostics\LaunchUI => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://LaunchUI
Task: {A2B0BEEF-A0D1-4D51-BE1B-2331B82FB757} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ShowUI => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags:
Task: {444882E0-CD7F-42ED-9C3F-96A9A619F77F} - System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckError => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://SmartCheckError
Task: {96E4B330-552D-45DB-B776-B1D8D30EA8CA} - System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckTest => C:\WINDOWS\system32\cmd.exe [289792 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://SmartCheckTest
Task: {628AA9AA-4E54-4FBB-B888-064564A0EC10} - System32\Tasks\Hewlett-Packard\HP Diagnostics\Uninstall-FastSystemTests => c:\Windows\System32\schtasks.exe [268800 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /Change /Disable /tn "\Hewlett-Packard\HP Diagnostics\FastSystemTests"
Task: {05A0D43D-AFF2-4EB1-8DF1-FDC18D7AD460} - System32\Tasks\Hewlett-Packard\HP Diagnostics\Uninstall-SmartCheckTest => c:\Windows\System32\schtasks.exe [268800 2025-10-06] (Microsoft Windows -> Microsoft Corporation) -> /Change /Disable /tn "\Hewlett-Packard\HP Diagnostics\SmartCheckTest"
Task: {12442B10-DE8C-4BE5-B15D-10BB9F5FF93B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [702512 2023-07-25] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {AE9B1D97-834B-4138-ACD1-3073213B353A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [138328 2023-07-25] (HP Inc. -> HP Inc.)
Task: {F364CD9A-6B1B-4BAA-AC6B-6B4B51AF1734} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1145896 2023-07-25] (HP Inc. -> HP Inc.)
Task: {91604C30-3E13-47D9-83B7-AF74218CBD6E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1145896 2023-07-25] (HP Inc. -> HP Inc.)
Task: {101F31C9-B2DA-4D18-88AC-D52D8C7B3B4D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24610408 2020-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {EB1C9E76-8A74-4CEA-9C91-8F650066ED4D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24610408 2020-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {608D509D-EAE9-45F5-8EEF-472D00EBCDB8} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158544 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {052A3942-A1A4-41AB-97BC-2CEF3A3EC94D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158544 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {B84D226A-D7FA-4FE9-8EA3-5EC0908E9E3B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6160272 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {02EFE719-1F90-4B92-8C7F-3E512AF95D37} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6160272 2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {99B55C99-93FF-45E3-9638-E0AC18708487} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C0110507-D81F-4D41-AA6B-E3EFE5F10DD1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9782ACAD-18B9-47D6-9496-1EBDB3C493E8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AE20B3B6-A636-48BF-8A9E-69701D03DB33} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25080.5-0\MpCmdRun.exe [1778248 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D077ECA5-A77E-4C78-9405-CBABF61E1C84} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [674208 2023-12-05] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {5BC61FCA-DA32-4D1B-AF59-FE3A0A59901D} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [35232 2023-12-05] (Mozilla Corporation -> Mozilla Foundation)
Task: {73DBA20C-8F44-47BD-8CFC-39ADEB169B81} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [3867928 2020-11-15] (Nero AG -> Nero AG)
Task: {D35E1681-4F4F-4E55-8C51-D4662DBD7792} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1001 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) <==== ATTENTION
Task: {0FD11B6C-5F37-4811-89DB-3A5544C4ED9C} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1004 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) <==== ATTENTION
Task: {82878F6A-228B-4376-9E76-CFED67A17606} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1006 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) <==== ATTENTION
Task: {BB7E1583-913A-4D86-B22A-50A8D088323F} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1007 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) <==== ATTENTION
Task: {7A9F3BA0-E8AA-44E0-901E-7938721972B5} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1001 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {E0414E31-C2B4-4716-A4D8-9283C4443227} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1002 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {C6BA1144-34CC-4FE4-9F2C-C164840D2A0D} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1003 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {3D0A3660-29F7-4E00-9984-02CAFCDC653B} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1004 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {60703B05-F41E-4B4E-873D-5D16113BB983} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1006 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {0D1E8BFF-AA7E-4737-82E1-4F192A32500E} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1007 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {9C9B0D04-4B26-4776-A5FB-8B4AC424759D} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {D149F916-0061-4A21-9B7D-A8AFC26DC624} - System32\Tasks\SeraphSecureLogon => C:\Program Files\Seraph Secure\SeraphSecure.Desktop.exe [16031344 2025-08-28] (Seraph Secure Inc. -> Seraph Secure Inc.) -> C:\Program Files\Seraph Secure\\--startup
Task: {3502994E-7C1F-4E6D-A912-FEC7DCCAD126} - System32\Tasks\SeraphSecureVerify => C:\Program Files\Seraph Secure\SeraphSecure.Setup.exe [1115328 2025-08-28] (Seraph Secure Inc. -> ) -> C:\Program Files\Seraph Secure\\/silent /verify
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1a98b6d1-90ba-4524-9b29-f01366eec3f9}: [DhcpNameServer] 192.168.22.22 192.168.22.23
Tcpip\..\Interfaces\{46ce57af-c84e-4ff6-94bc-0638ec221f1e}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{46ce57af-c84e-4ff6-94bc-0638ec221f1e}: [DhcpDomain] powerhub
Tcpip\..\Interfaces\{72285048-0945-41a4-8a20-6a8203986e5b}: [DhcpNameServer] 192.168.22.22 192.168.22.23
Tcpip\..\Interfaces\{eebba993-4062-402b-807d-57da6dbf6c56}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f4242fa3-05f8-47aa-81a2-c748dd49e1cf}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default [2025-10-06]
Edge HomePage: Default -> hxxps://html.duckduckgo.com/html?q=duckduckgo
Edge StartupUrls: Default -> "hxxps://www.btwifi.com:8443/home","hxxps://html.duckduckgo.com/html?q=duckduckgo"
Edge NewTab: Default -> Active:"chrome-extension://eimldjabijllelicbnieiomiaeekbodl/index.html", Active:"chrome-extension://jonikckfpolfcdcgdficelkfffkloemh/n.html"
Edge DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
Edge DefaultSearchKeyword: Default -> duckduckgo.com
Edge DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab
Edge DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
Edge Extension: (Trocker) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjojfeillmmoeadgobbcknkgdkngbcdb [2024-08-08]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2025-09-27]
Edge Extension: (DuckDuckGo) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caoacbimdbbljakfhgikoodekdnlcgpk [2025-08-31]
Edge Extension: (NoScript) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\debdhlbmgmkkfjpcglcbjadbhhekgfjh [2022-06-09]
Edge Extension: (Windscribe VPN - Privacy & Ad Block Suite) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dkkdbpgldnmkhcliffjpajcfdjkcaddf [2025-09-27]
Edge Extension: (VT4Browsers) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\efbjojhplkelaegfbieplglfidafgoka [2024-04-19]
Edge Extension: (New Tab DuckDuckGo Redirect) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\eimldjabijllelicbnieiomiaeekbodl [2023-02-04]
Edge Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\elhekieabhbkpmcefcoobjddigjcaadp [2025-09-30]
Edge Extension: (Google Analytics Opt-out Add-on (by Google)) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2024-05-10]
Edge Extension: (Google Docs Offline) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-09-27]
Edge Extension: (APK Downloader) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\glngapejbnmnicniccdcemghaoaopdji [2025-03-15]
Edge Extension: (WOT: Website Security & Safety Checker) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\iiclaphjclecagpkkaacljnpcppnoibi [2025-03-15]
Edge Extension: (Edge relevant text changes) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge Extension: (PixelBlock) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmpmfcjnflbcoidlgapblgpgbilinlem [2024-03-12]
Edge Extension: (Blank New Tab Page) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jonikckfpolfcdcgdficelkfffkloemh [2021-01-21]
Edge Extension: (Zune Software Download [Window 10] Guide) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mbgchiachcmhdeicjkpnjifgddendfph [2022-11-01]
Edge Extension: (uBlock Origin) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2025-09-27]
Edge Extension: (AdGuard AdBlocker) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pdffkfellgipmhklpdmokmckkkfcopbh [2025-08-26]
Edge Extension: (Privacy Badger) - C:\Users\KAA\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pkehgijcmpdhfbdbbnkijodmdjhbjlgp [2025-09-27]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF DefaultProfile: rpjp5gd5.default
FF ProfilePath: C:\Users\KAA\AppData\Roaming\Mozilla\Firefox\Profiles\rpjp5gd5.default [2021-09-14]
FF ProfilePath: C:\Users\KAA\AppData\Roaming\Mozilla\Firefox\Profiles\79xfahfv.default-release-1631788129756 [2025-08-31]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\KAA\AppData\Roaming\Mozilla\Firefox\Profiles\79xfahfv.default-release-1631788129756\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2023-12-05]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-09-29] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-11-03] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174584 2025-08-24] (Adobe Inc. -> Adobe Inc.)
R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2012-10-18] (Andrea Electronics Corporation) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11109232 2020-04-09] (Microsoft Corporation -> Microsoft Corporation)
S3 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [43784 2024-03-27] (Intel Corporation -> Intel)
S3 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [291592 2024-03-27] (Intel Corporation -> Intel)
S3 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [888208 2023-07-25] (HP Inc. -> HP Inc.)
S3 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [887192 2023-07-25] (HP Inc. -> HP Inc.)
S3 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [883088 2023-07-25] (HP Inc. -> HP Inc.)
S3 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [887696 2023-07-25] (HP Inc. -> HP Inc.)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [13004248 2023-11-30] (PARAMOUNT SOFTWARE UK LIMITED -> Paramount Software UK Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [8965728 2024-12-08] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.25080.5-0\MpDefenderCoreService.exe [2009656 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 msi2500scan; c:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe [229376 2011-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Mirics Semiconductor)
R2 MSiDVBT; c:\Program Files\MiricsFlexiTV\DVBT\DVBService.exe [2715648 2011-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Mirics Ltd.)
S3 MSSQL$ACCUCHEK360; C:\Program Files (x86)\Microsoft SQL Server\MSSQL12.ACCUCHEK360\MSSQL\Binn\sqlservr.exe [199352 2017-07-06] (Microsoft Corporation -> Microsoft Corporation)
S3 NeroBackItUpBackgroundService; C:\Program Files (x86)\Nero\Nero 2017\Nero BackItUp\NBService.exe [287088 2016-11-08] (Nero AG -> Nero AG)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [918456 2025-10-06] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SeraphSecure; C:\Program Files\Seraph Secure\SeraphSecure.Desktop.Service.exe [6331304 2025-08-28] (Seraph Secure Inc. -> Seraph Secure Inc.)
R2 SmartConnect; C:\Program Files\Lenovo\Ready For Assistant\ReadyForService.exe [2641400 2025-02-24] (Lenovo -> Motorola)
S3 SQLAgent$ACCUCHEK360; C:\Program Files (x86)\Microsoft SQL Server\MSSQL12.ACCUCHEK360\MSSQL\Binn\SQLAGENT.EXE [454848 2017-07-06] (Microsoft Corporation -> Microsoft Corporation)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2012-10-18] (IDT, Inc.) [File not signed]
S3 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [9216 2011-03-29] (Vodafone) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.25080.5-0\NisSrv.exe [4414464 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.25080.5-0\MsMpEng.exe [282480 2025-09-18] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ewusbnet; C:\WINDOWS\System32\drivers\ewusbnet.sys [413696 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 ew_hwusbdev; C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys [117248 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 ew_usbenumfilter; C:\WINDOWS\System32\drivers\ew_usbenumfilter.sys [13952 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 huawei_enumerator; C:\WINDOWS\System32\drivers\ew_jubusenum.sys [85504 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 hwdatacard; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [219008 2011-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 ITECIRfilter; C:\WINDOWS\system32\DRIVERS\ITECIRfilter.sys [36560 2015-11-24] (ITE Tech. Inc. -> ITE Tech. Inc.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333216 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
R3 lenovoDriverBus; C:\WINDOWS\System32\drivers\lenovoDriverBus.sys [103152 2025-02-24] (Lenovo -> Lenovo Inc.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2022-07-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239568 2024-12-08] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MDA_NTDRV; C:\WINDOWS\system32\MDA_NTDRV.sys [43664 2025-08-29] (Chongqing NIUBI Technology Co., Ltd. -> )
R2 Mrvdp; C:\WINDOWS\system32\drivers\mrvdp.sys [58112 2021-10-13] (Paramount Software UK Ltd -> Windows ® Win 7 DDK provider)
R3 MSi2500BDA; C:\WINDOWS\system32\DRIVERS\AVerMsiBDA.sys [228352 2011-12-12] (Microsoft Windows Hardware Compatibility Publisher -> AVerMedia TECHNOLOGIES, Inc.)
R3 NWVoltron; C:\WINDOWS\System32\drivers\NWVoltron.sys [28920 2015-07-09] (NextWindow -> )
S3 NWWakeFilterV; C:\WINDOWS\System32\drivers\NWWakeFilterV.sys [16632 2015-07-09] (NextWindow -> n/a)
S3 PSMounterEx; C:\Windows\system32\drivers\psmounterex.sys [140720 2023-10-02] (Microsoft Windows Hardware Compatibility Publisher -> Windows ® Win 7 DDK provider)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2021-03-26] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2021-03-26] (MiniTool Solution Ltd -> )
R2 RFDriveFs2; C:\Program Files\Lenovo\Ready For Assistant\drivers\FileSystem\RFDriveFs2.sys [412984 2025-02-24] (Lenovo -> Motorola)
S3 s116bus; C:\WINDOWS\System32\drivers\s116bus.sys [108296 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116mdfl; C:\WINDOWS\system32\DRIVERS\s116mdfl.sys [19720 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116mdm; C:\WINDOWS\system32\DRIVERS\s116mdm.sys [144648 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116mgmt; C:\WINDOWS\system32\DRIVERS\s116mgmt.sys [126216 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116nd5; C:\WINDOWS\System32\drivers\s116nd5.sys [31496 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116obex; C:\WINDOWS\system32\DRIVERS\s116obex.sys [123656 2007-04-03] (MCCI Corporation -> MCCI Corporation)
S3 s116unic; C:\WINDOWS\System32\drivers\s116unic.sys [130824 2007-04-03] (MCCI Corporation -> MCCI Corporation)
R3 STHDA; C:\WINDOWS\system32\DRIVERS\stwrt64.sys [543744 2012-10-18] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
R3 tilfilter; C:\WINDOWS\System32\drivers\TIxHCIlfilter.sys [34424 2016-08-20] (Texas Instruments, Inc. -> Texas Instruments, Inc.)
R3 tiufilter; C:\WINDOWS\System32\drivers\TIxHCIufilter.sys [39032 2016-08-20] (Texas Instruments, Inc. -> Texas Instruments, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20880 2025-09-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [627104 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [159936 2020-06-17] (NGO -> MBB)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102816 2025-09-18] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-10-08 22:13 - 2025-10-08 22:16 - 000033549 _____ C:\Users\KAA\Downloads\FRST.txt
2025-10-08 22:12 - 2025-10-08 22:15 - 000000000 ____D C:\FRST
2025-10-08 22:10 - 2025-10-08 22:10 - 002442752 _____ (Farbar) C:\Users\KAA\Downloads\FRST64.exe
2025-10-08 20:19 - 2025-10-08 20:19 - 002134016 _____ (Farbar) C:\Users\KAA\Downloads\FRST.exe
2025-10-07 17:37 - 2025-10-07 17:37 - 000000000 ___HD C:\$SysReset
2025-10-07 13:39 - 2025-10-07 13:39 - 000000762 _____ C:\Users\KAA\Documents\Win10 Reagentc info results.txt
2025-10-07 08:19 - 2025-10-07 16:41 - 000000000 _____ C:\Recovery.txt
2025-10-06 13:22 - 2025-10-06 13:22 - 000002782 _____ C:\Users\KAA\Documents\Chkdsk results.txt
2025-10-06 12:31 - 2025-10-06 12:31 - 000000000 ____D C:\WINDOWS\pss
2025-10-06 12:17 - 2025-10-06 12:17 - 000053013 _____ C:\WINDOWS\system32\sfclogs.txt
2025-10-06 11:07 - 2025-10-06 11:07 - 000000000 ____D C:\inetpub
2025-10-06 09:44 - 2025-10-06 09:44 - 000023734 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-10-06 09:37 - 2025-10-06 09:37 - 000023734 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-10-06 08:36 - 2025-10-06 08:36 - 000001036 __RSH C:\ProgramData\ntuser.pol
2025-10-06 08:04 - 2025-10-06 08:04 - 000003189 _____ C:\WINDOWS\system32\wrapperMap.json
2025-10-06 01:10 - 2025-10-06 00:54 - 000000000 ____D C:\Windows.old
2025-10-06 01:06 - 2025-10-06 01:06 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2025-10-06 01:03 - 2025-10-06 01:10 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2025-10-06 01:03 - 2025-10-06 01:03 - 000000020 ___SH C:\Users\KAA\ntuser.ini
2025-10-06 01:00 - 2025-10-06 01:02 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2025-10-06 01:00 - 2025-10-06 01:00 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2025-10-06 00:55 - 2025-10-06 11:07 - 000000000 ____D C:\Program Files\Hyper-V
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ___SD C:\WINDOWS\system32\containers
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\WINDOWS\system32\BestPractices
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files\Reference Assemblies
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files\MSBuild
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2025-10-06 00:55 - 2025-10-06 00:55 - 000000000 ____D C:\Program Files (x86)\MSBuild
2025-10-06 00:52 - 2025-10-08 18:14 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-10-06 00:52 - 2025-10-06 08:02 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-10-06 00:52 - 2025-10-06 08:02 - 000003410 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-10-06 00:52 - 2025-10-06 00:53 - 000003598 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001UA{99C2A8AA-F663-43F3-A707-6DECB4586918}
2025-10-06 00:52 - 2025-10-06 00:53 - 000003330 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-2603899380-3263017511-4129809722-1001Core{D220553E-E54C-4CD1-BC37-1A56E28B2CD4}
2025-10-06 00:52 - 2025-10-06 00:53 - 000003126 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1004
2025-10-06 00:52 - 2025-10-06 00:53 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1007
2025-10-06 00:52 - 2025-10-06 00:53 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1006
2025-10-06 00:52 - 2025-10-06 00:53 - 000003066 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2603899380-3263017511-4129809722-1001
2025-10-06 00:52 - 2025-10-06 00:53 - 000002976 _____ C:\WINDOWS\system32\Tasks\SeraphSecureVerify
2025-10-06 00:52 - 2025-10-06 00:53 - 000002922 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1004
2025-10-06 00:52 - 2025-10-06 00:53 - 000002922 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1003
2025-10-06 00:52 - 2025-10-06 00:53 - 000002922 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1002
2025-10-06 00:52 - 2025-10-06 00:53 - 000002918 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-500
2025-10-06 00:52 - 2025-10-06 00:53 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1007
2025-10-06 00:52 - 2025-10-06 00:53 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1006
2025-10-06 00:52 - 2025-10-06 00:53 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2603899380-3263017511-4129809722-1001
2025-10-06 00:52 - 2025-10-06 00:53 - 000002446 _____ C:\WINDOWS\system32\Tasks\SeraphSecureLogon
2025-10-06 00:52 - 2025-10-06 00:52 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\PowerToys
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Nero
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Hewlett-Packard
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2025-10-06 00:52 - 2025-10-06 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
2025-10-06 00:48 - 2025-10-06 00:52 - 000019053 _____ C:\WINDOWS\diagwrn.xml
2025-10-06 00:48 - 2025-10-06 00:52 - 000019053 _____ C:\WINDOWS\diagerr.xml
2025-10-06 00:33 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\SystemCertificates
2025-10-06 00:33 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\Network
2025-10-06 00:33 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\Crypto
2025-10-06 00:31 - 2025-10-07 16:21 - 000982820 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-10-06 00:30 - 2025-10-06 00:30 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\SystemCertificates
2025-10-06 00:30 - 2025-10-06 00:30 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Network
2025-10-06 00:30 - 2025-10-06 00:30 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Crypto
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\SystemCertificates
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\Network
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\Crypto
2025-10-06 00:29 - 2025-10-06 00:29 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network
2025-10-06 00:21 - 2025-10-06 00:21 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\CLR Security Config
2025-10-06 00:18 - 2025-10-06 00:18 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\CLR Security Config
2025-10-06 00:18 - 2025-10-06 00:18 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\CLR Security Config
2025-10-06 00:17 - 2025-10-07 13:49 - 000000000 ____D C:\Users\Anne
2025-10-06 00:17 - 2025-10-06 15:31 - 000000000 ____D C:\Users\KAA
2025-10-06 00:17 - 2025-10-06 01:04 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Windows
2025-10-06 00:17 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\AppData\Roaming\Microsoft\Windows
2025-10-06 00:17 - 2025-10-06 00:33 - 000000000 ____D C:\Users\Anne\Administrator
2025-10-06 00:17 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin\AppData\Roaming\Microsoft\Windows
2025-10-06 00:17 - 2025-10-06 00:29 - 000000000 ____D C:\Users\NonStoreLogin
2025-10-06 00:11 - 2025-10-08 18:14 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-10-06 00:11 - 2025-10-06 11:19 - 000491000 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-10-06 00:11 - 2025-10-06 00:11 - 000001162 _____ C:\WINDOWS\system32\config\VSMIDK
2025-10-05 21:53 - 2025-10-05 21:55 - 000000000 ____D C:\Users\KAA\Documents\Thunderbird Profiles copy
2025-10-05 21:33 - 2025-10-06 01:03 - 000000000 ___DC C:\WINDOWS\Panther
2025-10-03 20:43 - 2025-10-03 20:50 - 3291686912 _____ C:\Users\KAA\Downloads\HBCD_PE_x64.iso
2025-10-03 13:48 - 2025-10-03 13:48 - 001936744 _____ (Akeo Consulting) C:\Users\KAA\Downloads\rufus-4.11.exe
2025-10-01 22:34 - 2025-10-01 22:34 - 000000000 ___HD C:\$Windows.~WS
2025-09-30 17:12 - 2025-09-30 17:12 - 000182308 _____ C:\Users\KAA\Documents\xfgfx.pdf
2025-09-30 16:53 - 2025-09-30 16:53 - 000248032 _____ C:\Users\KAA\Documents\XPension docs to Guy.pdf
2025-09-28 12:26 - 2025-09-28 12:26 - 000000000 ____D C:\ProgramData\Apple Computer
2025-09-28 12:26 - 2025-09-28 12:26 - 000000000 ____D C:\ProgramData\Apple
2025-09-27 14:40 - 2025-09-27 14:41 - 000000422 _____ C:\Users\KAA\Documents\Windows 10 Pro Key from ShowKeyPlus.txt
2025-09-27 12:48 - 2025-09-27 12:49 - 000270638 _____ C:\Users\KAA\Downloads\Win10 licence_Screenshot_27-9-2025_124857_www.electronicfirst.com.jpeg
2025-09-27 11:27 - 2025-09-27 11:27 - 000000000 ____D C:\ProgramData\Office Genuine Advantage
2025-09-25 15:34 - 2025-09-25 15:34 - 000048173 _____ C:\Users\KAA\Downloads\24169 - Hive V4 Wireless Heating Hot Water Smart Thermostat.pdf
2025-09-24 16:09 - 2025-09-25 17:43 - 000012028 _____ C:\Users\KAA\Documents\Win10 licence sites.xlsx
2025-09-21 12:26 - 2025-09-21 12:23 - 001587098 _____ C:\Users\KAA\Documents\Churchill Motor policy-booklet-1124.pdf
2025-09-15 12:32 - 2025-09-15 12:32 - 000021554 _____ C:\Users\KAA\Downloads\Letter.odt
2025-09-14 16:43 - 2025-09-14 16:48 - 000000812 _____ C:\Users\KAA\Desktop\Consumer ESU Enrollment.txt
2025-09-14 16:07 - 2025-09-14 16:10 - 000000000 ____D C:\Users\KAA\Downloads\Consumer ESU Enrollment
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-10-08 20:11 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-10-08 20:10 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-10-08 20:10 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-10-08 19:25 - 2020-03-04 18:13 - 000000000 ____D C:\Users\KAA\AppData\Local\Packages
2025-10-08 18:21 - 2020-03-26 10:45 - 000001076 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2025-10-08 18:15 - 2024-12-18 17:25 - 000000000 ____D C:\Program Files\Seraph Secure
2025-10-08 18:14 - 2020-06-06 12:18 - 000008192 ___SH C:\DumpStack.log.tmp
2025-10-08 13:26 - 2023-12-04 03:51 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-10-08 13:14 - 2020-10-22 19:00 - 000000000 ____D C:\Users\KAA\AppData\Roaming\Microsoft\Word
2025-10-07 16:21 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2025-10-07 16:10 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-10-07 13:05 - 2025-08-29 16:29 - 000001347 _____ C:\Users\KAA\Desktop\NIUBI Partition Editor Free Edition.lnk
2025-10-07 11:45 - 2020-03-04 18:31 - 000000000 ____D C:\ProgramData\Packages
2025-10-07 00:05 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-10-06 15:33 - 2024-02-01 14:05 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2025-10-06 12:21 - 2025-08-27 23:16 - 000053013 _____ C:\Users\KAA\Desktop\sfcdetails.txt
2025-10-06 11:39 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-10-06 11:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-10-06 11:09 - 2019-12-07 15:46 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemApps
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-10-06 11:09 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-10-06 11:08 - 2024-07-09 19:35 - 000000000 ____D C:\WINDOWS\system32\compatrel
2025-10-06 11:08 - 2019-12-07 15:49 - 000000000 ___SD C:\WINDOWS\system32\AppV
2025-10-06 11:08 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-10-06 11:08 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-10-06 11:07 - 2023-12-04 03:51 - 000000000 ____D C:\WINDOWS\InboxApps
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Portable Devices
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2025-10-06 11:07 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2025-10-06 11:07 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\en-GB
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\USOPrivate
2025-10-06 11:07 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2025-10-06 11:07 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2025-10-06 10:50 - 2020-03-04 18:16 - 000000000 ____D C:\Users\KAA\AppData\Local\PlaceholderTileLogoFolder
2025-10-06 08:39 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-10-06 08:28 - 2019-12-07 10:14 - 000000000 __RSD C:\WINDOWS\Media
2025-10-06 08:28 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2025-10-06 08:03 - 2020-05-06 17:30 - 000000000 ____D C:\Users\KAA\AppData\Local\HP
2025-10-06 08:02 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\appcompat
2025-10-06 02:46 - 2024-10-27 13:43 - 000000000 ___RD C:\Users\KAA\Documents\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe!App
2025-10-06 01:10 - 2025-03-08 20:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Connect
2025-10-06 01:10 - 2024-12-10 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2025-10-06 01:10 - 2023-12-19 15:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium
2025-10-06 01:10 - 2023-10-22 00:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SP Driver
2025-10-06 01:10 - 2023-02-04 00:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 2017
2025-10-06 01:10 - 2023-02-04 00:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
2025-10-06 01:10 - 2022-11-03 16:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2025-10-06 01:10 - 2022-07-22 21:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zune
2025-10-06 01:10 - 2022-07-14 15:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerToys (Preview)
2025-10-06 01:10 - 2021-03-21 20:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vodafone
2025-10-06 01:10 - 2021-03-04 17:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-10-06 01:10 - 2021-02-26 14:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2025-10-06 01:10 - 2020-11-03 14:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2025-10-06 01:10 - 2020-08-23 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak
2025-10-06 01:10 - 2020-08-23 17:57 - 000000000 ____D C:\WINDOWS\SysWOW64\kodak
2025-10-06 01:10 - 2020-08-18 00:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACCU-CHEK 360
2025-10-06 01:10 - 2020-08-17 23:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2014
2025-10-06 01:10 - 2020-08-17 23:35 - 000000000 ____D C:\WINDOWS\SysWOW64\1033
2025-10-06 01:10 - 2020-08-17 23:35 - 000000000 ____D C:\WINDOWS\system32\1033
2025-10-06 01:10 - 2020-08-17 22:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\diasend® Uploader
2025-10-06 01:10 - 2020-05-29 10:32 - 000000000 ____D C:\Program Files\UNP
2025-10-06 01:10 - 2020-05-06 21:04 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2025-10-06 01:10 - 2020-05-05 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2025-10-06 01:10 - 2020-03-04 18:26 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-10-06 01:10 - 2020-03-04 18:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
2025-10-06 01:10 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2025-10-06 01:10 - 2019-12-07 15:45 - 000000000 ____D C:\WINDOWS\system32\WCN
2025-10-06 01:10 - 2019-12-07 10:18 - 000000000 ____D C:\WINDOWS\Setup
2025-10-06 01:10 - 2019-12-07 10:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\spool
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Registration
2025-10-06 01:10 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-10-06 01:10 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2025-10-06 01:10 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2025-10-06 01:09 - 2019-12-07 10:14 - 000000000 __RHD C:\Users\Public\Libraries
2025-10-06 01:05 - 2020-03-28 23:29 - 000000000 ____D C:\WINDOWS\system32\kodak
2025-10-06 01:03 - 2022-12-30 18:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verbatim
2025-10-06 01:03 - 2022-11-05 18:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2025-10-06 01:03 - 2022-07-22 21:35 - 000000000 ___RD C:\Users\KAA\Podcasts
2025-10-06 01:03 - 2022-07-12 13:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2025-10-06 01:03 - 2020-08-17 23:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008
2025-10-06 01:03 - 2020-03-04 18:13 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-10-06 01:03 - 2020-03-04 18:13 - 000000000 ___RD C:\Users\KAA\3D Objects
2025-10-06 01:03 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-10-06 01:03 - 2019-12-07 15:49 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-10-06 01:03 - 2019-12-07 15:47 - 000000000 ____D C:\WINDOWS\OCR
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2025-10-06 00:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2025-10-06 00:55 - 2023-12-04 03:46 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\HgsClientWmi.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000130544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdp4vs.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000110560 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmwpevents.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000062448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pvhdparser.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000059880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\l2bridge.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000037352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocketcontrol.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000029160 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmsifproxystub.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000022400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hnswfpdriver.sys
2025-10-06 00:55 - 2023-12-04 03:46 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmComputeProxy.dll
2025-10-06 00:55 - 2023-12-04 03:46 - 000014848 _____ C:\WINDOWS\system32\hnsproxy.dll
2025-10-06 00:55 - 2023-12-04 03:43 - 000207216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpcivsp.sys
2025-10-06 00:55 - 2023-12-04 03:43 - 000042472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vkrnlintvsc.sys
2025-10-06 00:55 - 2023-12-04 03:43 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Synth3dVsp.sys
2025-10-06 00:55 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\schemas
2025-10-06 00:55 - 2019-12-07 10:10 - 001579818 _____ C:\WINDOWS\system32\WindowsVirtualization.V2.mof
2025-10-06 00:55 - 2019-12-07 10:10 - 001152064 _____ C:\WINDOWS\system32\WindowsHyperVCluster.V2.mof
2025-10-06 00:55 - 2019-12-07 10:10 - 000182560 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmsp.exe
2025-10-06 00:55 - 2019-12-07