Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2020 01 Ran by Dan (19-07-2020 03:11:43) Running from C:\Users\Dan\Downloads Windows 10 Education Version 1803 17134.1550 (X64) (2020-04-26 09:20:01) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-910847060-2977998255-1486674742-500 - Administrator - Disabled) Dan (S-1-5-21-910847060-2977998255-1486674742-1001 - Administrator - Enabled) => C:\Users\Dan DefaultAccount (S-1-5-21-910847060-2977998255-1486674742-503 - Limited - Disabled) defaultuser0 (S-1-5-21-910847060-2977998255-1486674742-1000 - Limited - Enabled) => C:\Users\defaultuser0 Guest (S-1-5-21-910847060-2977998255-1486674742-501 - Limited - Disabled) nx (S-1-5-21-910847060-2977998255-1486674742-1006 - Administrator - Enabled) => C:\Users\nx WDAGUtilityAccount (S-1-5-21-910847060-2977998255-1486674742-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) ABBYY FineReader 14 (HKLM\...\{F14000FE-0001-6400-0000-074957833700}) (Version: 14.7.272 - ABBYY Production LLC) Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 19.010.20098 - Adobe Systems Incorporated) Adobe Bridge 2020 (HKLM-x32\...\KBRG_10_1) (Version: 10.1 - Adobe Inc.) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 5.2.0.436 - Adobe Systems Incorporated) AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version: - ) Epic Games Launcher (HKLM-x32\...\{1D4EB18B-0FEE-444E-B4D1-6F2CFBC363E6}) (Version: 1.1.267.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 83.0.4103.116 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden InfraRecorder 0.53 (x64 edition) (HKLM\...\{2C22EA92-CB30-4932-0053-000001000000}) (Version: 0.53.00.00 - Christian Kindahl) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden LightScribe System Software (HKLM-x32\...\{F132000C-1CBA-458F-BF2F-FD43D59410F9}) (Version: 1.18.27.10 - LightScribe) Microsoft OneDrive (HKU\S-1-5-21-910847060-2977998255-1486674742-1001\...\OneDriveSetup.exe) (Version: 20.114.0607.0002 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.23.27820 (HKLM-x32\...\{852adda4-4c78-4a38-b583-c0b360a329d6}) (Version: 14.23.27820.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820 (HKLM-x32\...\{45231ab4-69fd-486a-859d-7a59fcd11013}) (Version: 14.23.27820.0 - Microsoft Corporation) Microsoft Visual Studio Code (User) (HKU\S-1-5-21-910847060-2977998255-1486674742-1001\...\{771FD6B0-FA20-440A-A002-3B3BAC16DC50}_is1) (Version: 1.45.1 - Microsoft Corporation) MiniTool Partition Wizard Free 12 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Software Limited) MSI Afterburner 4.6.2 (HKLM-x32\...\Afterburner) (Version: 4.6.2 - MSI Co., LTD) Nero 7 Ultra Edition (HKLM-x32\...\{293C9DF5-7669-4826-BBB2-E1F182D71045}) (Version: 7.02.8631 - Nero AG) NoMachine (HKLM-x32\...\NoMachine_is1) (Version: 6.10.12 - NoMachine S.a.r.l.) NordVPN (HKLM-x32\...\{8807BEDC-84ED-4F57-8FBE-EEAA56E01F3A}) (Version: 6.29.9 - NordVPN) Hidden NordVPN (HKLM-x32\...\NordVPN 6.29.9) (Version: 6.29.9 - NordVPN) NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN) NordVPN network TUN (HKLM\...\{77DA107A-7AE4-497D-A84A-B143C3A21676}) (Version: 1.0.0 - NordVPN) qBittorrent 4.2.5 (HKLM-x32\...\qBittorrent) (Version: 4.2.5 - The qBittorrent project) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.) RivaTuner Statistics Server 7.2.3 (HKLM-x32\...\RTSS) (Version: 7.2.3 - Unwinder) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) VLC media player (HKLM\...\VLC media player) (Version: 3.0.10 - VideoLAN) Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22925 - Microsoft Corporation) WonderFox DVD Ripper (Speedy) 14.2 (HKLM-x32\...\WonderFox DVD Ripper (Speedy) ) (Version: 14.2 - WonderFox Soft, Inc.) Packages: ========= Adobe Notification Client -> C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc [2020-07-01] (Adobe Systems Incorporated) Adobe XD -> C:\Program Files\WindowsApps\Adobe.CC.XD_30.2.12.3_x64__adky2gkssdxte [2020-07-01] (Adobe Systems Incorporated) HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_115.1.152.0_x64__v10z8vjag6ke6 [2020-05-28] (HP Inc.) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-04-28] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-04-28] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.5012.0_x64__8wekyb3d8bbwe [2020-05-04] (Microsoft Studios) [MS Ad] MSN Pogoda -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-04-28] (Microsoft Corporation) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-910847060-2977998255-1486674742-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-5C31BD0DDE64} -> [Creative Cloud Files] => C:\Users\Dan\Creative Cloud Files [2020-07-01 13:00] CustomCLSID: HKU\S-1-5-21-910847060-2977998255-1486674742-1001_Classes\CLSID\{8DAFD600-795B-269E-5691-6D5E2684EFAD}\InprocServer32 -> C:\Program Files (x86)\Common Files\System\ole32.dll => No File CustomCLSID: HKU\S-1-5-21-910847060-2977998255-1486674742-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2020-01-07] (Adobe Inc. -> ) ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2020-01-07] (Adobe Inc. -> ) ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2020-01-07] (Adobe Inc. -> ) ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2020-01-07] (Adobe Inc. -> ) ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll [2007-05-04] (Nero AG -> Nero AG) ContextMenuHandlers1: [FineReader14ContextMenu] -> {FB074836-8286-4089-84DC-F504E9EF621C} => C:\Program Files (x86)\ABBYY FineReader 14\x64\FRIntegration.x64.dll [2019-02-13] (ABBYY Production LLC -> ABBYY Production LLC.) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2020-01-07] (Adobe Inc. -> ) ContextMenuHandlers6: [FineReader14ContextMenu] -> {FB074836-8286-4089-84DC-F504E9EF621C} => C:\Program Files (x86)\ABBYY FineReader 14\x64\FRIntegration.x64.dll [2019-02-13] (ABBYY Production LLC -> ABBYY Production LLC.) ==================== Codecs (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Drivers32: [VIDC.RTV1] => C:\WINDOWS\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed] HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed] ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\drumbit.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=mplpmdejoamenolpcojgegminhcnmibo ShortcutWithArgument: C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Floating for YouTube™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=jjphmlaoffndcnecccgemfdaaoighkel ShortcutWithArgument: C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Google Keep – notatki i listy.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki ShortcutWithArgument: C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\TrackingTime _ Time Tracker.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=knailkjkjcfegledhjhcfacdngnicimb ==================== Loaded Modules (Whitelisted) ============= 2013-01-16 11:58 - 2013-01-16 11:58 - 000212992 _____ () [File not signed] C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll 2013-01-16 11:58 - 2013-01-16 11:58 - 002408448 _____ () [File not signed] C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll 2013-01-16 11:58 - 2013-01-16 11:58 - 008626176 _____ () [File not signed] C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll 2020-05-15 14:17 - 2020-05-15 14:18 - 098275328 _____ () [File not signed] E:\Program Files\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll 2020-05-15 14:18 - 2020-05-15 14:18 - 000092672 _____ () [File not signed] E:\Program Files\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll 2020-05-15 14:18 - 2020-05-15 14:18 - 003922432 _____ () [File not signed] E:\Program Files\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll 2019-02-12 18:28 - 2020-07-03 16:08 - 001588328 _____ (ABBYY Production LLC.) [File not signed] C:\Program Files (x86)\ABBYY FineReader 14\Awl.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000031232 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\A4.Foundation\7aaea9cd302e5fb53df3b4eed58cd801\A4.Foundation.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000022528 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Actions5dc83b46#\aa6d4a8d54573252ac764b2ff36ca7d9\AEM.Actions.CCAA.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000013312 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.0a1309f7#\4da8a10aa2efc676d12c73f5bfc6a5cb\AEM.Plugin.EEU.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000017408 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.2b6a6775#\1b1b485064c3cf7a5c5ee31010d25bdc\AEM.Plugin.Hotkeys.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000281600 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.5d945b6b#\6c1f1d517776d47f3bb0e47462b3e60d\AEM.Plugin.Source.Kit.Server.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000014848 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.674d2b8a#\9af9c5a8c13cf7d5ef3d5177eb2e04c3\AEM.Plugin.WinMessages.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000012800 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.88aba5d2#\bd995b2768be63e57e31b4c34b4bfa7b\AEM.Plugin.REG.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000011776 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.GD.Shared\895060e013975bb96cd8ccf2ce7f5e32\AEM.Plugin.GD.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000013312 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Server.Shared\ba9fb8c710400c0e8a0984cd9774985b\AEM.Server.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000267776 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Server\fc1f7a29345f640263cacea3b0a49469\AEM.Server.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000055808 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\APM.Foundation\44f14ab20e5887e92ec4dbb4f4738c9e\APM.Foundation.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000122880 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\ATICCCom\653461d6a4552dc87c0fab475bd82958\ATICCCom.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000204288 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CCC.Implementation\59da30d49f63ff3bc9051ad3fb6b26e0\CCC.Implementation.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000128000 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.3399d0ec#\a1fbd194f1c8b1b9934aab4af163f0ac\CLI.Aspect.CustomFormats.Graphics.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000026112 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.37d3d968#\c0fec41658c578b130dad8e79b83aab5\CLI.Aspect.AMDHome.Graphics.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000045568 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.382a3def#\8c830fdc5e632706cc78debc7e92264e\CLI.Aspect.AMDOverDrive.Platform.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000107008 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.3a6f1658#\9d4bec4dbf85ed146bea97c897838b64\CLI.Aspect.TransCode.Graphics.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000209920 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.4542c692#\fa5b277d3500578c3b52d9d684f869d3\CLI.Aspect.DeviceCRT.Graphics.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000074752 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.4bbb0755#\badd2ac5d209c05398144f21875ca4cf\CLI.Aspect.TransCode.Graphics.Dashboard.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000037888 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.52c6dbaa#\06fa7e9f84b9c3dec3a72a5b7b6bd221\CLI.Aspect.FPS.Graphics.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000263168 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.73911eb5#\b6070c8db42edc76764141a962dd517b\CLI.Aspect.WirelessDisplay.Graphics.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000365056 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.7ec2db45#\42583e8e6494df84e0c62965f6c990b8\CLI.Aspect.DeviceDFP.Graphics.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000064000 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.8350f5c6#\12944236e2da2b7f14e515ea0d3e734a\CLI.Aspect.UpdateNotification.Graphics.Runtime.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000678912 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.846fa813#\33fe114f315dfcea60a66dbbbac63c7c\CLI.Aspect.MMVideo.Graphics.Dashboard.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000745472 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.8d333b6b#\c9dec23867df277388458a9de278ec9e\CLI.Aspect.Radeon3D.Graphics.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000449536 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.8e996306#\415adcf91a0395ff66dea0a4f66ba663\CLI.Aspect.CrossDisplay.Graphics.Dashboard.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000089088 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.9cd1e9e7#\5e7a87e3b4f93caacef08c4e9d163608\CLI.Aspect.FPS.Graphics.Dashboard.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000158208 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.a0ae52bc#\a06e4079c9f6cd6fd5439b9b8e4da182\CLI.Aspect.DeviceLCD.Graphics.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000057856 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.a6cd7fff#\16e2a098ec0e3f0e0a96960244e62a8e\CLI.Aspect.FPS.Graphics.Runtime.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000082944 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.a765109e#\5401fffaf5012cc2038596a11944751e\CLI.Aspect.UpdateNotification.Graphics.Dashboard.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000462336 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.acb9d930#\32a67e47757c0ecd2ea1857f57fb75b4\CLI.Aspect.DeviceProperty.Graphics.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000086528 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.ae5e117c#\8f8b049d055c1d93fc7d21c353476f6c\CLI.Aspect.DisplaysColour2.Graphics.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000067072 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.b0a7c1fb#\e454a07f146d7b4f6eaf22487e3e9341\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000340992 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.c7aaa0f8#\b341fe5f9f01794d671c9d2d7d4b05b3\CLI.Aspect.OverDrive5.Graphics.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000017920 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.c854b457#\52320bc3ad1cf1db4cef532ba1a8b717\CLI.Aspect.HotkeysHandling.Graphics.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000276480 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.e8635fc7#\8d77ba3f6b2f01d14ae603ddf34a1e5b\CLI.Aspect.InfoCentre.Graphics.Dashboard.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 003312640 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.e9fd7406#\0508d52e4659fabdf6b301c3123537e7\CLI.Aspect.Radeon3D.Graphics.Dashboard.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000240640 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.eda8935e#\4e4058c792c1aaeb12f37cae1c21f12e\CLI.Aspect.MMVideo.Graphics.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000047616 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.ef3eaa4d#\69c3eb6ca3a40a63b4047f6b294c0f1b\CLI.Aspect.TransCode.Graphics.Runtime.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000050688 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.f480a2f3#\f629acddfc76376f09e5ef66434b9c34\CLI.Aspect.UpdateNotification.Graphics.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000051200 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.A4.Runtime\8a36ca24562c680c15de9354a4081216\CLI.Caste.A4.Runtime.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000044544 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.A4.Shared\8211f74301f67e03da73ebfa47fee0dd\CLI.Caste.A4.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000027136 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Af820fedc#\acc35936e04a02e21b2a409fec2cb13c\CLI.Caste.A4.Dashboard.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000044544 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.F24de14fe#\dab7a2253f6913af5c853c458da80116\CLI.Caste.Fuel.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000311296 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.F36b07a2b#\868de2450e251c4b729c8c83e60807e1\CLI.Caste.Fuel.Runtime.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000027136 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Ff3085433#\d2315c198e4e32a4ed27dd1ed79ea14e\CLI.Caste.Fuel.Dashboard.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000037376 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.G60338cc0#\16ded18d230450e36f6aff979d3adfd5\CLI.Caste.Graphics.Runtime.Shared.Private.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 001555456 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Gd9d9b43b#\37562726b07e3d14180094c372af3a84\CLI.Caste.Graphics.Dashboard.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000587776 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Gee7d2dbc#\2d29af9ffec9eb0ca96321a8d8aeac9a\CLI.Caste.Graphics.Dashboard.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000045056 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.H18c99613#\489e040fd90e10cf8cb5812a5c965d37\CLI.Caste.HydraVision.Runtime.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000030720 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.H92ba4e46#\308452d9c69c73206e171f9ebc686df3\CLI.Caste.HydraVision.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000025600 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Hbb906c0b#\459c0ec8d4da9c66c7296f41a32eebd2\CLI.Caste.HydraVision.Dashboard.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000030720 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Pac40511b#\8d34d3e2e799f8b77376cbaa83be2a7a\CLI.Caste.Platform.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000044032 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Pdb36d56e#\eaee91d00063f82b06edbb0b4c02d1b5\CLI.Caste.Platform.Runtime.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000024064 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Pfeefa2b6#\a38b96d02958d747e30b6b09012b9e82\CLI.Caste.Platform.Dashboard.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000012288 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone1b4a8c97#\71decf3c2f65970f0338bf2a4e6372da\CLI.Component.Runtime.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000901632 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone26c9c557#\dd02da63ffb5c3aaad115afb4373d9a8\CLI.Component.Systemtray.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000173568 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone29e547cc#\f8aca5db7580378300e70fca51aeaba1\CLI.Component.Dashboard.ProfileManager2.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000151040 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone59f353b4#\d4e7c1f9efd50f860f893949952385c1\CLI.Component.Runtime.Shared.Private.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000017408 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Componeb4d0485c#\1e9901604908dfab0be90d1f2c80fe7b\CLI.Component.Runtime.Extension.EEU.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 001609728 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Componec89c3bec#\f9dd6c9e3a456a884941079977f7f51d\CLI.Component.Dashboard.Shared.Private.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000018432 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Componef1fd67b2#\3b5b46bb9536b82413b4392e93832d65\CLI.Component.Client.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000085504 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Componef4cf054f#\7c4a8677f4b32509ad6c5d82b8c000c3\CLI.Component.Dashboard.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000089600 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Foundat3d5d3945#\fe2c26e6736ef4285cce79064af1b83d\CLI.Foundation.Private.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000061440 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Foundat60cdf5df#\f696fc76e9b95dd45ef86736cfa60b57\CLI.Foundation.XManifest.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000091136 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Foundat619559bd#\f935ebc8b7aa565016c55f886cc9e174\CLI.Foundation.CoreAudioAPI.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 001079808 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Foundatd3771151#\1ca961d05a23df7aa99dbd838732df59\CLI.Foundation.Client.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000301568 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Foundation\41bf6d63ac5a4b9fc72e62d62151b58e\CLI.Foundation.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000025600 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Foundation\f289f8d8d650c55f0b81e60b7f5adcd5\DEM.Foundation.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000115200 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0601\fb778dad37923d0d127bee9dcd38f5ba\DEM.Graphics.I0601.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000015360 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics\67edc7968e1c6e72b008fe5580b75016\DEM.Graphics.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000037376 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Fuel.Foundation\55daa20b6e8b81b2ff35ec340731f69a\Fuel.Foundation.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000296960 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\LOG.Foundat03490438#\a460dd81b0691e70631d0ee5622dcdef\LOG.Foundation.Implementation.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000150016 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\LOG.Foundat5023f8e7#\02e1a3ef5f5fbc4e376b097f92f2d735\LOG.Foundation.Private.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000087552 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\LOG.Foundatcaafa75b#\42c8de577bcf53c3bbfaa464c52a704a\LOG.Foundation.Implementation.Private.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000132608 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\LOG.Foundation\ed2d2c9d00e1e3f227f1ad9e0fb2d605\LOG.Foundation.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000012288 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\MOM.Foundation\7552225947a8780cd4f5b86e28fbcefc\MOM.Foundation.ni.dll 2020-05-16 16:21 - 2020-05-16 16:21 - 000402944 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\MOM.Implementation\da3dfa61e0026c687a5df151368bb238\MOM.Implementation.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000055296 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\NEWAEM.Foundation\6ce31524e2825631a3c0d3ed3d733eb5\NEWAEM.Foundation.ni.dll 2015-11-04 16:40 - 2015-11-04 16:40 - 000004608 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiamenu.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000897024 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\ADL.Foundation\862fd0ef8582db0dca584ff36fa79675\ADL.Foundation.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000256000 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\APM.Server\7ba78c009b29bca88f2422177a6d5738\APM.Server.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000298496 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.9b707b25#\e07cb553710670a8070bfd40c82ea394\CLI.Aspect.DeviceProperty.Graphics.Runtime.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 001654272 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.aa59351a#\ee2ceb26e95cb38bb5d9f1000c8832fb\CLI.Aspect.DeviceProperty.Graphics.Dashboard.Shared.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 006336512 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.e6d9f3a8#\7af29e287985773da4199abaab5ed91a\CLI.Aspect.DeviceDFP.Graphics.Dashboard.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 008027648 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Combine0616f305#\d8b43af171f6ec4980991a073d92bab2\CLI.Combined.Graphics.Aspects1.Dashboard.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 001159680 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Combine7332395e#\92511b18cd201118132b5e74c809db7c\CLI.Combined.Graphics.Aspects2.Runtime.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000136704 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone168638d1#\a607e109f2ff9f1d79bc6061a14591d7\CLI.Component.Client.Shared.Private.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000234496 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone6692ca50#\465c2c1957f3e09e1b2cd2bd639c931e\CLI.Component.Runtime.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000929280 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone6bf88b08#\e920f5e6ad9d4e8e58afad5cbae5e39a\CLI.Component.Dashboard.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000013312 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0706\2e1498b97bf6a03bc9fa20092127d3af\DEM.Graphics.I0706.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000084480 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0709\9ed7debd1872dd6168f4e5b734b74165\DEM.Graphics.I0709.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000012288 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0712\147e20049694132251c2aaa16285ef85\DEM.Graphics.I0712.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000018432 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0804\d995792d611867b4059d0d4b60aa4aa4\DEM.Graphics.I0804.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000010752 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0805\e65f45482b125cbac3eeabade875872f\DEM.Graphics.I0805.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000010752 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0812\91345b7fcaa89f471cd92c346cdfa76b\DEM.Graphics.I0812.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000013312 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0906\ebdcfef53cf5f0c0b84bc99302595693\DEM.Graphics.I0906.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000014336 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0912\71e56a9ed5e19943486f5a5e7d98ac4e\DEM.Graphics.I0912.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 000035840 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I1010\8b8264140ce2ace660218cdf5483fe57\DEM.Graphics.I1010.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 001139200 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Localizatio01dbc1c0#\370b0fd1049e72ae97395f253b49b1f4\Localization.Foundation.Private.ni.dll 2020-05-16 16:21 - 2020-05-16 16:21 - 000244736 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\ResourceMan446ca0e5#\4f0d2aa995b683aefd2ae197313e1529\ResourceManagement.Foundation.Implementation.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000023552 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\ResourceManf163905a#\e56d82290fd3a91ea8677a70e3a3df8e\ResourceManagement.Foundation.Private.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000091648 _____ (Advanced Mirco Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.ec8786e5#\d761a0dc1db7d23b23304eaa0e85b9ce\CLI.Aspect.AMDHome.Graphics.Dashboard.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 002845696 _____ (Advanced Mirco Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.G60a7b4d1#\74934a061bb2c0a10b0962d684dc3841\CLI.Caste.Graphics.Shared.ni.dll 2020-05-16 16:20 - 2020-05-16 16:20 - 003268096 _____ (Advanced Mirco Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.G962aa464#\75c709d60a69bec4488e542838fd7226\CLI.Caste.Graphics.Runtime.ni.dll 2013-01-16 13:15 - 2013-01-16 13:15 - 000033792 _____ (Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\Common Files\LightScribe\LSLog.dll 2013-01-16 13:15 - 2013-01-16 13:15 - 000110592 _____ (Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\Common Files\LightScribe\LSSProxy.dll 2003-03-19 07:14 - 2003-03-19 07:14 - 000499712 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Ahead\Lib\MSVCP71.dll 2003-02-21 15:42 - 2003-02-21 15:42 - 000348160 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Ahead\Lib\MSVCR71.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 000335360 _____ (Microsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Microsoft.W8090224c#\8ee9864a7c1e727d9493b83bea96c8ae\Microsoft.WindowsAPICodePack.ni.dll 2020-05-16 16:19 - 2020-05-16 16:19 - 002546688 _____ (Microsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Microsoft.Wfbf9373c#\ef88a0fd486e282c25c7c6f97e882bd5\Microsoft.WindowsAPICodePack.Shell.ni.dll 2020-05-15 14:17 - 2020-05-15 14:17 - 000547840 _____ (The Chromium Authors) [File not signed] E:\Program Files\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\chrome_elf.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2020-04-26 20:50 - 2020-04-26 20:47 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts 2020-07-02 00:57 - 2020-07-02 01:00 - 000000444 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics 192.168.137.1 DESKTOP-JL222M0.mshome.net # 2025 6 1 30 23 0 20 875 ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-910847060-2977998255-1486674742-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{45B86050-5AE4-4505-A763-8AD367B5125C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{53AE7681-67FB-4D92-81C9-18D779914E96}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{2C43B40F-55D2-419D-903C-651C9A6E5E70}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{B199989B-54A6-466F-B597-F28377BDD70A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{E736022F-BB7E-418D-9146-D81C2F921788}] => (Allow) E:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> ) FirewallRules: [{D769AC05-E7A5-4317-9571-1E2D170F77F9}] => (Allow) E:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> ) FirewallRules: [{8D47B827-DEDC-4668-A1E9-69D70B092D3D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{C0D37D07-15B1-4E5B-95E4-1DEE178963D3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{578D02BF-53A3-4ECA-9C9F-2C2C5123B448}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed] FirewallRules: [{118933A0-B596-4E56-B386-C1CB736B35C3}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed] FirewallRules: [{57B389A7-F2E3-4610-9E4C-00708A24E826}] => (Allow) C:\Program Files (x86)\NoMachine\bin\nxplayer.bin (NoMachine S.a.r.l. -> NoMachine) FirewallRules: [{1214A80B-8A73-45A2-8C21-DFC5B8838DFD}] => (Allow) C:\Program Files (x86)\NoMachine\bin\nxplayer.bin (NoMachine S.a.r.l. -> NoMachine) FirewallRules: [{E2E63B9D-D4F1-4CBC-AF2D-4FF09D18C47E}] => (Allow) C:\Program Files (x86)\NoMachine\bin\nxd.exe (NoMachine S.a.r.l. -> NoMachine) FirewallRules: [{84A717F1-0FF3-4304-8EC6-38B7E0E7644F}] => (Allow) C:\Program Files (x86)\NoMachine\bin\nxd.exe (NoMachine S.a.r.l. -> NoMachine) FirewallRules: [{742DE889-1F0C-45A2-B51C-4BF96837B178}] => (Allow) C:\Program Files (x86)\NoMachine\bin\nxserver.bin (NoMachine S.a.r.l. -> NoMachine) FirewallRules: [{36ADCF51-6574-447D-A39D-0E6C33A9EEF7}] => (Allow) C:\Program Files (x86)\NoMachine\bin\nxserver.bin (NoMachine S.a.r.l. -> NoMachine) FirewallRules: [{5C6C9D07-58E7-4AB4-B152-6B41471770B6}] => (Allow) C:\Program Files (x86)\NoMachine\bin\nxnode.bin (NoMachine S.a.r.l. -> NoMachine) FirewallRules: [{67E90BD0-F5B7-4256-876B-52D11155C83D}] => (Allow) C:\Program Files (x86)\NoMachine\bin\nxnode.bin (NoMachine S.a.r.l. -> NoMachine) FirewallRules: [{323D717B-5DFF-46AE-853D-CB346B80B965}] => (Allow) C:\Program Files (x86)\NoMachine\bin\nxclient.bin (NoMachine S.a.r.l. -> NoMachine) FirewallRules: [{EAF05C14-D7F1-493F-A621-C2A4FEA1315A}] => (Allow) C:\Program Files (x86)\NoMachine\bin\nxclient.bin (NoMachine S.a.r.l. -> NoMachine) FirewallRules: [{73624ECB-FAD3-4512-BC11-7D29050F5E4A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{3188D546-B928-45AA-8596-3557161214A5}] => (Allow) C:\WINDOWS\system32\alg.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{8AE140E3-7FBB-40C1-913A-17BA5D1FE1B5}] => (Allow) C:\WINDOWS\system32\alg.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{70464CF3-9AB9-4E18-9BD6-6E3D671D7A65}] => (Allow) C:\WINDOWS\system32\alg.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{16A0D2DE-811B-4FF9-88C2-2F70D0C6AA7B}] => (Allow) C:\WINDOWS\system32\alg.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{6257E85E-644C-4147-AF6B-863A333CD159}] => (Allow) C:\WINDOWS\system32\alg.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{9861FA63-3E9D-470C-B378-08D8AD4B3675}] => (Allow) C:\WINDOWS\system32\alg.exe (Microsoft Windows -> Microsoft Corporation) ==================== Restore Points ========================= 18-07-2020 23:15:26 Windows Update 18-07-2020 23:16:54 Windows Update ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (07/19/2020 03:06:34 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: updatechecker.exe, version: 0.0.0.0, time stamp: 0x5e4c6e6e Faulting module name: Qt5Core.dll, version: 5.6.2.0, time stamp: 0x58c5ff78 Exception code: 0xc0000005 Fault offset: 0x00000000001b1903 Faulting process id: 0x249c Faulting application start time: 0x01d65d461b81bd72 Faulting application path: C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe Faulting module path: C:\Program Files\MiniTool Partition Wizard 12\Qt5Core.dll Report Id: b9cc1a08-b3e6-4b15-b845-d869419905c5 Faulting package full name: Faulting package-relative application ID: Error: (07/05/2020 03:50:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: AdobeNotificationClient.exe, version: 4.9.0.484, time stamp: 0x5d0b467b Faulting module name: AdobeNotificationClient.exe, version: 4.9.0.484, time stamp: 0x5d0b467b Exception code: 0x80000003 Fault offset: 0x0000b311 Faulting process id: 0x340c Faulting application start time: 0x01d652d33056a411 Faulting application path: C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc\AdobeNotificationClient.exe Faulting module path: C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc\AdobeNotificationClient.exe Report Id: 58b90a1a-6f78-419f-a904-0480172ee2d3 Faulting package full name: AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc Faulting package-relative application ID: App Error: (07/03/2020 03:59:56 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: NordVPN.exe, version: 6.29.9.0, time stamp: 0x5ea93052 Faulting module name: KERNELBASE.dll, version: 10.0.17134.1425, time stamp: 0xb54b6e3b Exception code: 0xe0434352 Fault offset: 0x000000000003a308 Faulting process id: 0x21e0 Faulting application start time: 0x01d651420d17a815 Faulting application path: C:\Program Files (x86)\NordVPN\NordVPN.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report Id: a28da188-28e6-4ee7-87dc-ca68ad92c39d Faulting package full name: Faulting package-relative application ID: Error: (07/03/2020 03:59:53 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: NordVPN.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.Xml.XmlException at System.Xml.XmlTextReaderImpl.Throw(System.Exception) at System.Xml.XmlTextReaderImpl.ParseText(Int32 ByRef, Int32 ByRef, Int32 ByRef) at System.Xml.XmlTextReaderImpl.ParseText() at System.Xml.XmlTextReaderImpl.ParseElementContent() at System.Xml.XmlTextReaderImpl.Skip() at System.Configuration.XmlUtil.StrictSkipToNextElement(System.Configuration.ExceptionAction) at System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) at System.Configuration.BaseConfigurationRecord.ScanSectionsRecursive(System.Configuration.XmlUtil, System.String, Boolean, System.String, System.Configuration.OverrideModeSetting, Boolean) at System.Configuration.BaseConfigurationRecord.ScanSections(System.Configuration.XmlUtil) at System.Configuration.BaseConfigurationRecord.InitConfigFromFile() Exception Info: System.Configuration.ConfigurationErrorsException at System.Configuration.ConfigurationSchemaErrors.ThrowIfErrors(Boolean) at System.Configuration.BaseConfigurationRecord.ThrowIfParseErrors(System.Configuration.ConfigurationSchemaErrors) at System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs) Exception Info: System.Configuration.ConfigurationErrorsException at System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs) at System.Configuration.Internal.InternalConfigRoot.OnConfigRemoved(System.Configuration.Internal.InternalConfigEventArgs) at System.Configuration.Internal.InternalConfigRoot.RemoveConfigImpl(System.String, System.Configuration.BaseConfigurationRecord) at System.Configuration.BaseConfigurationRecord.GetSectionRecursive(System.String, Boolean, Boolean, Boolean, Boolean, System.Object ByRef, System.Object ByRef) at System.Configuration.BaseConfigurationRecord.GetSection(System.String) at System.Configuration.ConfigurationManager.GetSection(System.String) at System.Configuration.ClientSettingsStore.ReadSettings(System.String, Boolean) at System.Configuration.LocalFileSettingsProvider.GetPropertyValues(System.Configuration.SettingsContext, System.Configuration.SettingsPropertyCollection) at System.Configuration.SettingsBase.GetPropertiesFromProvider(System.Configuration.SettingsProvider) at System.Configuration.SettingsBase.GetPropertyValueByName(System.String) at System.Configuration.SettingsBase.get_Item(System.String) at System.Configuration.ApplicationSettingsBase.GetPropertyValue(System.String) at System.Configuration.ApplicationSettingsBase.get_Item(System.String) at WindowsApp.Properties.Settings.get_AppFirstRun() at NordVpn.Infrastructure.Windows.Settings.NetApplicationSettingsRepository.Load() at NordVpn.Infrastructure.Settings.CachedSettingsRepository.Load() at NordVpn.Application.Core.Services.Settings.Storage.AutoCorrectingSettingsDecorator.Load() at NordVpn.Configuration.Ioc.InfrastructureModule+<>c.b__2_6(Autofac.IComponentContext) at Autofac.Builder.RegistrationBuilder+<>c__DisplayClass0_0`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].b__0(Autofac.IComponentContext, System.Collections.Generic.IEnumerable`1) at Autofac.Core.Activators.Delegate.DelegateActivator.ActivateInstance(Autofac.IComponentContext, System.Collections.Generic.IEnumerable`1) at Autofac.Core.Resolving.InstanceLookup.Activate(System.Collections.Generic.IEnumerable`1, System.Object ByRef) Exception Info: Autofac.Core.DependencyResolutionException at Autofac.Core.Resolving.InstanceLookup.Activate(System.Collections.Generic.IEnumerable`1, System.Object ByRef) at Autofac.Core.Lifetime.LifetimeScope.GetOrCreateAndShare(System.Guid, System.Func`1) at Autofac.Core.Resolving.InstanceLookup.Execute() at Autofac.Core.Resolving.ResolveOperation.GetOrCreateInstance(Autofac.Core.ISharingLifetimeScope, Autofac.Core.IComponentRegistration, System.Collections.Generic.IEnumerable`1) at Autofac.Core.Resolving.ResolveOperation.Execute(Autofac.Core.IComponentRegistration, System.Collections.Generic.IEnumerable`1) at Autofac.Builder.StartableManager.StartStartableComponents(Autofac.IComponentContext) Exception Info: Autofac.Core.DependencyResolutionException at Autofac.Builder.StartableManager.StartStartableComponents(Autofac.IComponentContext) at Autofac.ContainerBuilder.Build(Autofac.Builder.ContainerBuildOptions) at NordVpn.Configuration.Ioc.AutofacBootstrapping.AutofacBootstrapper.Configure() at Caliburn.Micro.BootstrapperBase.StartRuntime() at Caliburn.Micro.BootstrapperBase.Initialize() at NordVpn.App+d__4.MoveNext() at System.Runtime.ExceptionServices.ExceptionDispatchInfo.Throw() at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(System.Threading.Tasks.Task) at NordVpn.App.Main(System.String[]) Error: (07/03/2020 02:24:13 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Adobe CEF Helper.exe, version: 5.2.0.436, time stamp: 0x5eee10a3 Faulting module name: libnxdx64.dll, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc000041d Fault offset: 0x0000000000004b7b Faulting process id: 0x2140 Faulting application start time: 0x01d650cad57320c5 Faulting application path: C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe Faulting module path: C:\Program Files (x86)\NoMachine\bin\libnxdx64.dll Report Id: 71156252-57f3-4569-b10f-eb3391acbae2 Faulting package full name: Faulting package-relative application ID: Error: (07/03/2020 02:24:13 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Adobe CEF Helper.exe, version: 5.2.0.436, time stamp: 0x5eee10a3 Faulting module name: libnxdx64.dll, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc000041d Fault offset: 0x0000000000004b7b Faulting process id: 0x778 Faulting application start time: 0x01d650cad9c225f1 Faulting application path: C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe Faulting module path: C:\Program Files (x86)\NoMachine\bin\libnxdx64.dll Report Id: 7812ff0f-e2c3-449d-bb32-0f4283b1aa33 Faulting package full name: Faulting package-relative application ID: Error: (07/03/2020 02:24:11 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Adobe CEF Helper.exe, version: 5.2.0.436, time stamp: 0x5eee10a3 Faulting module name: libnxdx64.dll, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000004b7b Faulting process id: 0x778 Faulting application start time: 0x01d650cad9c225f1 Faulting application path: C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe Faulting module path: C:\Program Files (x86)\NoMachine\bin\libnxdx64.dll Report Id: 5f490344-6a69-4b44-b5d7-32d09aaaa1dd Faulting package full name: Faulting package-relative application ID: Error: (07/03/2020 02:24:11 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Adobe CEF Helper.exe, version: 5.2.0.436, time stamp: 0x5eee10a3 Faulting module name: libnxdx64.dll, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000004b7b Faulting process id: 0x2140 Faulting application start time: 0x01d650cad57320c5 Faulting application path: C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe Faulting module path: C:\Program Files (x86)\NoMachine\bin\libnxdx64.dll Report Id: 1f576e92-a9d6-43fa-a663-2c9477f2c776 Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (07/19/2020 02:05:59 AM) (Source: Disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. Error: (07/19/2020 02:05:56 AM) (Source: Disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. Error: (07/19/2020 12:08:43 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-JL222M0) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-JL222M0\Dan SID (S-1-5-21-910847060-2977998255-1486674742-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (07/19/2020 12:08:15 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-JL222M0) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-JL222M0\Dan SID (S-1-5-21-910847060-2977998255-1486674742-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (07/19/2020 12:08:09 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-JL222M0) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-JL222M0\Dan SID (S-1-5-21-910847060-2977998255-1486674742-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (07/19/2020 12:08:09 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-JL222M0) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-JL222M0\Dan SID (S-1-5-21-910847060-2977998255-1486674742-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (07/19/2020 12:08:09 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-JL222M0) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-JL222M0\Dan SID (S-1-5-21-910847060-2977998255-1486674742-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (07/19/2020 12:08:09 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-JL222M0) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-JL222M0\Dan SID (S-1-5-21-910847060-2977998255-1486674742-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Windows Defender: =================================== Date: 2020-07-03 16:08:39.756 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Occamy.C&threatid=2147726780&enterprise=0 Name: Trojan:Win32/Occamy.C ID: 2147726780 Severity: Severe Category: Trojan Path: file:_C:\Users\Dan\Downloads\ABBYY_FineReader_15.0.110.1875_Corporate_Multilingual +ABBYY_FineReader_Enterprise\ABBYY FineReader 15.0.110.1875 Corporate Multilingual\Crack\PYG.dll Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Program Files\qBittorrent\qbittorrent.exe Signature Version: AV: 1.319.718.0, AS: 1.319.718.0, NIS: 1.319.718.0 Engine Version: AM: 1.1.17200.2, NIS: 1.1.17200.2 Date: 2020-07-03 16:08:37.224 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Tiggre!plock&threatid=2147723626&enterprise=0 Name: Trojan:Win32/Tiggre!plock ID: 2147723626 Severity: Severe Category: Trojan Path: file:_C:\Users\Dan\Downloads\ABBYY_FineReader_15.0.110.1875_Corporate_Multilingual +ABBYY_FineReader_Enterprise\ABBYY FineReader 15.0.110.1875 Corporate Multilingual\Crack\dwmapi.dll Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Program Files\qBittorrent\qbittorrent.exe Signature Version: AV: 1.319.718.0, AS: 1.319.718.0, NIS: 1.319.718.0 Engine Version: AM: 1.1.17200.2, NIS: 1.1.17200.2 Date: 2020-05-15 13:04:58.051 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {F81E44FC-3445-4186-A28E-E30584BA7A59} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-05-14 23:22:09.609 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {CEA4567B-0148-484B-A21B-7E463E5E4004} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-05-14 22:58:56.740 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {4831F367-2635-43DC-A52F-DDDA620421BE} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-07-18 23:12:46.795 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.319.1763.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.17200.2 Error code: 0x80070102 Error description: The wait operation timed out. Date: 2020-07-18 23:04:57.672 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.319.1757.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.17200.2 Error code: 0x8050a003 Error description: This package does not contain up-to-date definition files for this program. For more information, see Help and Support. Date: 2020-07-18 23:04:57.671 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.319.1757.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiSpyware Update Type: Full Current Engine Version: Previous Engine Version: 1.1.17200.2 Error code: 0x8050a003 Error description: This package does not contain up-to-date definition files for this program. For more information, see Help and Support. Date: 2020-07-18 23:04:57.671 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.319.1757.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.17200.2 Error code: 0x8050a003 Error description: This package does not contain up-to-date definition files for this program. For more information, see Help and Support. Date: 2020-07-01 12:47:25.017 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.317.160.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.17100.2 Error code: 0x80072ee7 Error description: The server name or address could not be resolved CodeIntegrity: =================================== Date: 2020-07-18 23:43:39.033 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume1\Program Files (x86)\NoMachine\bin\libnxdx64.dll that did not meet the Microsoft signing level requirements. Date: 2020-07-18 23:43:39.010 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume1\Program Files (x86)\NoMachine\bin\libnxdx64.dll that did not meet the Microsoft signing level requirements. Date: 2020-07-18 23:43:38.986 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume1\Program Files (x86)\NoMachine\bin\libnxdx64.dll that did not meet the Microsoft signing level requirements. Date: 2020-07-18 23:43:38.955 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume1\Program Files (x86)\NoMachine\bin\libnxdx64.dll that did not meet the Microsoft signing level requirements. Date: 2020-07-18 23:43:38.385 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume1\Program Files (x86)\NoMachine\bin\libnxdx64.dll that did not meet the Microsoft signing level requirements. Date: 2020-07-18 23:43:38.367 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume1\Program Files (x86)\NoMachine\bin\libnxdx64.dll that did not meet the Microsoft signing level requirements. Date: 2020-07-18 23:43:38.351 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume1\Program Files (x86)\NoMachine\bin\libnxdx64.dll that did not meet the Microsoft signing level requirements. Date: 2020-07-18 23:43:38.332 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume1\Program Files (x86)\NoMachine\bin\libnxdx64.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== BIOS: American Megatrends Inc. 6.12 07/12/2010 Motherboard: MSI 2A9C Processor: Intel(R) Core(TM) i5 CPU 650 @ 3.20GHz Percentage of memory in use: 58% Total physical RAM: 8119.07 MB Available physical RAM: 3386.99 MB Total Virtual: 9399.07 MB Available Virtual: 3084.88 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:185.57 GB) (Free:27.71 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive e: () (Fixed) (Total:452.09 GB) (Free:86.13 GB) NTFS \\?\Volume{e0ffd3b6-0000-0000-0000-a0642e000000}\ () (Fixed) (Total:0.44 GB) (Free:0.06 GB) NTFS \\?\Volume{e0ffd3b6-0000-0000-0000-d0802e000000}\ () (Fixed) (Total:0.44 GB) (Free:0.12 GB) NTFS ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: E0FFD3B6) Partition 1: (Active) - (Size=185.6 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=450 MB) - (Type=27) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) Partition 4: (Not Active) - (Size=745.1 GB) - (Type=05) ==================== End of Addition.txt =======================