Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Alles rund um Windows (https://www.trojaner-board.de/alles-rund-um-windows/)
-   -   Windows fährt nicht mehr hoch (https://www.trojaner-board.de/214992-windows-faehrt-mehr-hoch.html)

bluemooon 26.03.2025 20:45

Windows fährt nicht mehr hoch
 
Hallo in die Runde,

seit einiger Zeit, genau genommen, nachdem mein Mann seine externe Festplatte angeschlossen hatte, um alte Fotos zu sichten, benötigte unser Pc immer recht lange zum hochfahren.
Ich wollte mir das bei Gelegenheit immer mal genauer ansehen, aber wie das immer so ist, kam es dazu nicht.

Heute beim Hochfahren meldete Windows dann, dass bei dem Gerät ein Problem aufgetreten sei, Und einige Fehlerinformationen gesammeln werden würden + Neustart.
Danach klickte mein Mann auf die Win-Reparatur und konnte den PC danach normal starten.
Er dachte, es sei eine gute Idee, nach Updates zu schauen und führte ein Windows Update durch. Nach dem dazugehörigen Neustart ließ sich der PC nicht mehr hochfahren, sondern hängt sich erneut mit dem blauen Bildschirm und besagter Fehlermeldung auf.
Auch im abgesicherten Modus lässt sich keine Wiederherstellung durchführen bzw. bringt keine Änderung.

Daher sind wir nun hier gelandet.
Ich habe bereits eine Dianose per USB Stick und dem FRST Programm durchgeführt. Soll ich die LOG Datei posten (wenn ja wo?).
Ach ja, unser PC läuft mit Win 10 64Bit Version.

Liebe Grüße blue

cosinus 26.03.2025 23:35

FRST ist dafür konzipiert einen Überblick bzgl. Schädlingsbefall zu bekommen. Man kann damit nicht jeden allgemeinen Computer- oder Windows-Fehler damit finden.
Wenn schon eine Windows-Reparatur nötig war und nach einem Update das System nun komplett streikt, dann muss man hier von Hardwarefehlern wie defekte Festplatte/SSD oder zerlegtes Windows ausgehen. FRST kann sowas nicht beheben. Aber poste trotzdem mal die Logs in CODE-Tags.

bluemooon 27.03.2025 21:51

Vielen Dank für die schnelle Antwort.
An einen Hardwaredefekt habe ich tatsächlich so gar nicht gedacht (hatte ich noch nie) -klingt leider plausibel nach deiner Erläuterung.

Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-03-2025
Ran by SYSTEM on MININT-VQ4AKMP (26-03-2025 20:25:52)
Running from h:\\FRST64.exe
Platform: Windows 10 Home Version 22H2 19045.5608 (X64) Language: Deutsch (Deutschland) -> Deutsch (Deutschland)
Boot Mode: Recovery
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.


==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [455976 2025-03-01] (Avast Software s.r.o. -> Gen Digital Inc.)
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\134.0.3124.85\Installer\setup.exe [7548456 2025-03-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\RunOnce: [*Restore] => C:\WINDOWS\system32\rstrui.exe [274432 2024-10-09] (Microsoft Corporation)
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKU\KiezPC\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45452080 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\KiezPC\...\Run: [Opera Browser Assistant] => C:\Users\KiezPC\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3996064 2024-03-04] (Opera Norway AS -> Opera Software)
HKU\KiezPC\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\KiezPC\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
HKU\KiezPC\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\KiezPC\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" [84783440 2025-03-26] (Microsoft Corporation -> Microsoft Corporation)
HKU\KiezPC\...\RunOnce: [Uninstall 25.031.0217.0003] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\KiezPC\AppData\Local\Microsoft\OneDrive\25.031.0217.0003" [0 2025-03-26] () <==== ATTENTION [zero byte File/Folder]
HKLM\...\Print\Monitors\Brother QL-800 Monitor: C:\Windows\system32\bsq16aL6.DLL [100488 2020-02-26] (Microsoft Windows Hardware Compatibility Publisher -> Brother Industries, Ltd.)
HKLM\...\Print\Monitors\HP C611 Status Monitor: C:\Windows\system32\hpinkstsC611LM.dll [333344 2013-04-16] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\Software\...\Authentication\Credential Providers: [{2135f72a-90b5-4ed3-a7f1-8bb705ac276a}] -> C:\Windows\system32\credprovslegacy.dll [2024-05-16] (Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Providers: [{25CBB996-92ED-457e-B28C-4774084BD562}] -> C:\Windows\system32\credprovs.dll [2024-05-16] (Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Providers: [{27FBDB57-B613-4AF2-9D7E-4FA7A66C21AD}] -> C:\Windows\system32\TrustedSignalCredProv.dll [2024-05-16] (Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Providers: [{3dd6bec0-8193-4ffe-ae25-e08e39ea4063}] -> C:\Windows\system32\credprovs.dll [2024-05-16] (Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Providers: [{60b78e88-ead8-445c-9cfd-0b87f74ea6cd}] -> C:\Windows\system32\credprovs.dll [2024-05-16] (Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Providers: [{cb82ea12-9f71-446d-89e1-8d0924e1256e}] -> C:\Windows\system32\credprovslegacy.dll [2024-05-16] (Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Provider Filters: [{DDC0EED2-ADBE-40b6-A217-EDE16A79A0DE}] -> C:\Windows\system32\credprovs.dll [2024-05-16] (Microsoft Corporation)
BootExecute: autocheck autochk * icarus_rvrt.exe

==================== Scheduled Tasks (All) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {E53CFCFE-7D1D-49C7-857A-DA17A327D714} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628160 2020-02-28] (Advanced Micro Devices, Inc.)
Task: {4F339B55-9EB7-40EF-8864-C391D41F5173} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628160 2020-02-28] (Advanced Micro Devices, Inc.)
Task: {B8A77987-512F-4826-B2B7-9CD49845CA53} - System32\Tasks\Avast Software\Avast Antivirus Patcher => C:\Program Files\Common Files\Avast Software\Icarus\avast-av\icarus.exe [8543016 2025-02-26] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {C0F3AF87-B83A-4190-ACD0-98F9527C59DB} - System32\Tasks\Avast Software\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5286696 2025-03-26] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {72E92A0E-316C-4660-B75C-6BE44BFBE628} - System32\Tasks\Avast Software\Avast SecureLine VPN Bug Report => C:\Program Files\Avast Software\SecureLine VPN\AvBugReport.exe [6086440 2025-03-06] (Avast Software s.r.o. -> Gen Digital Inc.) -> --send "dumps|report" --silent --product 11 --programpath "C:\Program Files\Avast Software\SecureLine VPN" --configpath "C:\ProgramData\Avast Software\SecureLine VPN" --path "C:\ProgramData\Avast Software\SecureLine VPN\log" --path "C:\ProgramData\Avast Software\Icarus\Logs" --logpath "C:\ProgramDat (the data entry has 80 more characters).
Task: {D00A6A40-8A98-40D3-905D-0AE0065CEDCD} - System32\Tasks\Avast Software\Avast SecureLine VPN Emergency Update => C:\Program Files\Avast Software\SecureLine VPN\VpnUpdate.exe [3958056 2025-03-06] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {D4C15D7F-43D4-4479-ADE4-2B40F7C9BCB2} - System32\Tasks\Avast Software\Avast SecureLine VPN Update => C:\Program Files\Common Files\Avast Software\Icarus\avast-vpn\icarus.exe [8289064 2025-03-03] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {D890C2D2-DA89-4DE9-ADDD-A5444DE32EDA} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2564904 2025-03-01] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {87E0E667-51D3-43D5-85CF-259AE3091D85} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {9020F274-B0CD-4FEC-9769-05C4FE1361B8} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6139696 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "a5240d26-1b74-4b3f-bc6b-b4bdab7d621d" --version "6.33.0.11465" --silent
Task: {7A857F0E-7704-4345-BC0F-A98A5D61A727} - System32\Tasks\CCleanerSkipUAC - KiezPC => C:\Program Files\CCleaner\CCleaner.exe [39224624 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {2A2F9DD9-1C83-4A41-981F-7BC3B6F74038} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\KiezPC\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe  LOGON (No File)
Task: {4AEA0CF1-3CD5-4DC0-BC8B-51F49D2E15B8} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\KiezPC\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe  SCHED (No File)
Task: {808358E4-2FF0-4A70-9BF5-722FCDC89644} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem136.0.7079.0{3EB0AF55-998B-4ED5-86CD-88A22243BD97} => C:\Program Files (x86)\Google\GoogleUpdater\136.0.7079.0\updater.exe [7017568 2025-03-20] (Google LLC -> Google LLC)
Task: {F21764F6-B531-47C5-BB30-966FF403886E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [479984 2025-02-18] (HP Inc. -> HP Inc.)
Task: {1F3D8B7F-3DFA-45E7-BC66-6046D4790FE7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPPrinterLowInk => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPPrinterLowInk\HPPrinterLowInk.exe [231944 2025-02-18] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {3B367EAE-2CBE-4E2B-B6AF-2ABF0F546573} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1170440 2025-02-18] (HP Inc. -> HP Inc.)
Task: {EEB4344E-E4C2-413E-8D09-DB300C126525} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_TH05BDT02T => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1170440 2025-02-18] (HP Inc. -> HP Inc.)
Task: {DD339A8F-DE60-4B3D-BC30-A7979C43FC3B} - System32\Tasks\HPCustParticipation HP Officejet 4630 series => C:\Program Files\HP\HP Officejet 4630 series\Bin\HPCustPartic.exe [5745672 2014-07-21] (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {E8EB9384-9ABF-4416-A97B-A1C6D771E914} - System32\Tasks\Kamo\KamoStart => C:\Program Files (x86)\Kamo\Kamo.exe [911776 2024-05-29] (PIRIFORM SOFTWARE LIMITED -> Piriform)
Task: {53A655D6-FC88-4B2C-8981-B1BE51A6412E} - System32\Tasks\Microsoft\Office\Office Apps Prewarm => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [314512 2025-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {FD6D8F49-6593-4156-95BD-376DBFDBA422} - System32\Tasks\Microsoft\Office\Office Apps Prewarm Recurring => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [314512 2025-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {7B735B4C-0C50-4CAC-820D-F708FDB9CF1D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28895464 2025-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {52F40022-6E03-4F93-9B5F-646A211787AF} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\opushutil.exe [67256 2025-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {CF06143A-CD77-415B-8720-75703347A117} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28895464 2025-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {6958A9E7-F667-4C0C-AF75-ED084D23954E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [314512 2025-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {CE2E4913-05BE-4F80-9EBA-D02A9B98D263} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [314512 2025-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {C8F25671-E274-41BC-B099-01321FB2E882} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [197256 2025-03-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {BAF4B9A8-1B02-4B38-B231-7EA97230256B} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 => {84F0FAE1-C27B-4F6F-807B-28CF6F96287D} C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentasklauncher.dll [23952 2022-06-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {D5A9F0F2-D7CA-4A2B-8871-C67F2CBEADF1} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 => {429BC048-379E-45E0-80E4-EB1977941B5C} C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentasklauncher.dll [23952 2022-06-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {1D44DA44-C6A2-454A-AD76-389CB7AB7B77} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical => {613FBA38-A3DF-4AB8-9674-5604984A299A} C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentasklauncher.dll [23952 2022-06-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {B750F9BA-94F7-495C-9AA5-9E0BFB0E1F63} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical => {DE434264-8FE9-4C0B-A83B-89EBEEBFF78E} C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentasklauncher.dll [23952 2022-06-25] (Microsoft Corporation -> Microsoft Corporation)
Task: {F346D1E4-9974-4A5D-9E35-FE7079A30555} - System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated) => {CF2CF428-325B-48D3-8CA8-7633E36E5A32} C:\Windows\system32\msdrm.dll [570368 2019-12-07] (Microsoft Corporation)
Task: {8E33F0A3-A31E-4E6C-AFF7-844A27E761B7} - System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual) => {BF5CB148-7C77-4D8A-A53E-D81C70CF743C} C:\Windows\system32\msdrm.dll [570368 2019-12-07] (Microsoft Corporation)
Task: {5B885149-AF43-451C-A12F-0CD1E0A34023} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager => {DECA92E0-AF85-439E-9204-86679978DA08} C:\Windows\System32\AppLockerCsp.dll [391168 2024-11-13] (Microsoft Corporation)
Task: {4EBE9A38-6BE4-429E-8588-B460327DB327} - System32\Tasks\Microsoft\Windows\AppID\PolicyConverter => C:\Windows\system32\appidpolicyconverter.exe [160768 2023-11-15] (Microsoft Corporation)
Task: {7A27D6E9-CB10-42F6-B75D-A53F78486290} - System32\Tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck => C:\Windows\system32\appidcertstorecheck.exe [50176 2024-05-16] (Microsoft Corporation)
Task: {5436C1CF-5459-425A-9596-1FC15EEF6DAE} - System32\Tasks\Microsoft\Windows\Application Experience\MareBackup => Command(1): %windir%\system32\compattelrunner.exe -> -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc
Task: {5436C1CF-5459-425A-9596-1FC15EEF6DAE} - System32\Tasks\Microsoft\Windows\Application Experience\MareBackup => Command(2): %windir%\system32\compattelrunner.exe -> -m:appraiser.dll -f:DoScheduledTelemetryRun
Task: {5436C1CF-5459-425A-9596-1FC15EEF6DAE} - System32\Tasks\Microsoft\Windows\Application Experience\MareBackup => Command(3): %windir%\system32\compattelrunner.exe -> -m:aemarebackup.dll -f:BackupMareData
Task: {7A5AFDB2-56EC-4352-AB44-069E7BF253A8} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattelrunner.exe [255096 2025-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {D0B067B0-6368-47C9-AEED-C02F08EE958C} - System32\Tasks\Microsoft\Windows\Application Experience\PcaPatchDbTask => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> %windir%\system32\PcaSvc.dll,PcaPatchSdbTask
Task: {D9F87EA0-FF40-44DD-B8A8-2E714E0286BB} - System32\Tasks\Microsoft\Windows\Application Experience\PcaWallpaperAppDetect => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> %windir%\system32\PcaSvc.dll,PcaWallpaperAppDetect
Task: {73469C3A-0B60-4A11-AD8A-FC67A901B741} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => C:\Windows\system32\compattelrunner.exe [255096 2025-02-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {3D363385-64B8-4207-AC46-3EE180DD87F2} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> Startupscan.dll,SusRunTask
Task: {B5108B49-C39A-43DE-AC49-06155873BAE9} - System32\Tasks\microsoft\windows\applicationdata\appuriverifierdaily => C:\Windows\system32\AppHostRegistrationVerifier.exe [120320 2024-05-16] (Microsoft Corporation)
Task: {BA366117-6A44-44F3-9BAA-09C4ADA110CC} - System32\Tasks\microsoft\windows\applicationdata\appuriverifierinstall => C:\Windows\system32\AppHostRegistrationVerifier.exe [120320 2024-05-16] (Microsoft Corporation)
Task: {E003BEA4-7D11-4522-9834-25C3F9F93F53} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {F472261A-A57A-465B-A695-5F2E75E37782} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\Windows\system32\dstokenclean.exe [13312 2023-11-15] (Microsoft Corporation)
Task: {62DB5989-6E64-4986-A43D-7F288CCC6263} - System32\Tasks\Microsoft\Windows\AppListBackup\Backup => {E0DCC2CC-3354-45F2-8914-519E07809082} C:\Windows\system32\AppListBackupLauncher.dll [94208 2024-05-16] (Microsoft Corporation)
Task: {04274B6C-80C7-49FC-8BAC-285F2B4204F3} - System32\Tasks\Microsoft\Windows\AppListBackup\BackupNonMaintenance => {E0DCC2CC-3354-45F2-8914-519E07809082} C:\Windows\system32\AppListBackupLauncher.dll [94208 2024-05-16] (Microsoft Corporation)
Task: {C9ABE41C-5E65-4E52-8BAD-4F1BCA3B5715} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {58D0FE59-DC6E-4822-8F47-55402B52E544} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\UCPD velocity => C:\Windows\system32\UCPDMgr.exe [174592 2025-03-12] (Microsoft Corporation)
Task: {36A78C3E-A142-4F86-903E-AE26291F646C} - System32\Tasks\Microsoft\Windows\Autochk\Proxy => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> /d acproxy.dll,PerformAutochkOperations
Task: {34ADEFE8-89DB-43BC-8C0B-14BB34D69F6D} - System32\Tasks\Microsoft\Windows\BitLocker\BitLocker Encrypt All Drives => {61BCD1B9-340C-40EC-9D41-D7F1C0632F05} C:\Windows\System32\edptask.dll [72192 2024-05-16] (Microsoft Corporation)
Task: {87094343-6C1F-4855-A6B9-305BA74AB761} - System32\Tasks\Microsoft\Windows\BitLocker\BitLocker MDM policy Refresh => {61BCD1B9-340C-40EC-9D41-D7F1C0632F05} C:\Windows\System32\edptask.dll [72192 2024-05-16] (Microsoft Corporation)
Task: {AB05B368-13F7-468A-9B30-E553C06B5449} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => C:\Windows\system32\BthUdTask.exe [40448 2019-12-07] (Microsoft Corporation)
Task: {077333D6-06BA-4EA4-BDF4-1CD1439558F2} - System32\Tasks\Microsoft\Windows\BrokerInfrastructure\BgTaskRegistrationMaintenanceTask => {E984D939-0E00-4DD9-AC3A-7ACA04745521}
Task: {F0BE4F3E-F4F0-4B98-88EE-57290DDF6CB2} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask => {47E30D54-DAC1-473A-AFF7-2355BF78881F} C:\Windows\system32\ngctasks.dll [279040 2024-05-16] (Microsoft Corporation)
Task: {F67BF9CD-2696-4F2D-9D78-BB8C84A53C1E} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask => {47E30D54-DAC1-473A-AFF7-2355BF78881F} C:\Windows\system32\ngctasks.dll [279040 2024-05-16] (Microsoft Corporation)
Task: {2F63CF7F-0537-4E2A-9F8A-B763EFE907F5} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask => {47E30D54-DAC1-473A-AFF7-2355BF78881F} C:\Windows\system32\ngctasks.dll [279040 2024-05-16] (Microsoft Corporation)
Task: {50DDDD38-168C-486B-966F-A23226488295} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\SystemTask => {58FB76B9-AC85-4E55-AC04-427593B1D060} C:\Windows\system32\dimsjob.dll [44544 2019-12-07] (Microsoft Corporation)
Task: {0EDEA23A-3DEC-41C3-B03E-BC7A3356D6BC} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\UserTask => {58FB76B9-AC85-4E55-AC04-427593B1D060} C:\Windows\system32\dimsjob.dll [44544 2019-12-07] (Microsoft Corporation)
Task: {78FC1447-DCFF-4832-A268-0ABA89022F48} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\UserTask-Roam => {58FB76B9-AC85-4E55-AC04-427593B1D060} C:\Windows\system32\dimsjob.dll [44544 2019-12-07] (Microsoft Corporation)
Task: {57C76B66-AD3C-4221-81FA-55045859B06F} - System32\Tasks\Microsoft\Windows\Chkdsk\ProactiveScan => {CF4270F5-2E43-4468-83B3-A8C45BB33EA1} C:\Windows\System32\pstask.dll [16384 2019-12-07] (Microsoft Corporation)
Task: {3FC4BE91-4A96-48F5-8858-1628CB88EFB5} - System32\Tasks\Microsoft\Windows\Chkdsk\SyspartRepair => C:\Windows\system32\bcdboot.exe [259584 2025-02-13] (Microsoft Corporation) -> %windir% /sysrepair
Task: {E69C79C6-B286-44AA-A47C-A541CD9B132D} - System32\Tasks\Microsoft\Windows\Clip\ClipESU => C:\Windows\system32\clipesu.exe [274360 2025-03-12] (Microsoft Windows -> Microsoft Corporation)
Task: {5B0ED9ED-6704-45F8-B8C1-93C5A3B5F4FF} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\Windows\system32\ClipUp.exe [1167952 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {12514C9A-1DE5-40CE-B66C-D6838DA9A169} - System32\Tasks\Microsoft\Windows\CloudExperienceHost\CreateObjectTask => {E4544ABA-62BF-4C54-AAB2-EC246342626C} C:\Windows\System32\CloudExperienceHostBroker.exe [70016 2024-05-16] (Microsoft Windows -> Microsoft Corporation)
Task: {FC15907E-6E6B-45D1-B821-6AB71BC5E970} - System32\Tasks\Microsoft\Windows\CloudRestore\Backup => {722D0F89-B69C-4700-AE8C-4A44350E4876} C:\WINDOWS\System32\CloudRestoreLauncher.dll [828416 2025-03-12] (Microsoft Corporation)
Task: {C32F8F9A-AEB0-4076-AAD1-70A43C559CB4} - System32\Tasks\Microsoft\Windows\ConsentUX\UnifiedConsent\UnifiedConsentSyncTask => {82AA0895-198A-4C1B-B2D1-C16894218AFB} C:\Windows\System32\unifiedconsent.dll [350720 2025-03-12] (Microsoft Corporation)
Task: {ED77AEE0-EAFB-4133-B544-9E7C5632D902} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator => C:\Windows\System32\wsqmcons.exe [120320 2024-05-16] (Microsoft Corporation)
Task: {7572B7F9-BE9D-43BF-9A4E-F82023EDBD33} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip => {C27F6B1D-FE0B-45E4-9257-38799FA69BC8} C:\Windows\System32\usbceip.dll [119808 2019-12-07] (Microsoft Corporation)
Task: {304D2127-E6ED-4C82-B9B3-63B3B54A4D66} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Check And Scan => {DCFD3EA8-D960-4719-8206-490AE315F94F} C:\Windows\System32\discan.dll [317440 2024-05-16] (Microsoft Corporation)
Task: {90F68E39-00DE-4159-BCDB-5C5759A5CF53} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan => {DCFD3EA8-D960-4719-8206-490AE315F94F} C:\Windows\System32\discan.dll [317440 2024-05-16] (Microsoft Corporation)
Task: {EAD9ED20-AC69-4E97-8CCB-E8F62CA707B3} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery => {DCFD3EA8-D960-4719-8206-490AE315F94F} C:\Windows\System32\discan.dll [317440 2024-05-16] (Microsoft Corporation)
Task: {5D2F68D7-C5E5-4E83-AEBB-5E22F1AD2040} - System32\Tasks\Microsoft\Windows\Defrag\ScheduledDefrag => C:\Windows\system32\defrag.exe [210432 2023-11-15] (Microsoft Corp.)
Task: {4F41B4A1-8822-4B02-90CD-202A0099FFAE} - System32\Tasks\Microsoft\Windows\Device Information\Device => C:\Windows\system32\devicecensus.exe [82944 2025-02-13] (Microsoft Corporation)
Task: {F278A444-BDB4-4CD1-A2F0-7A2284C32800} - System32\Tasks\Microsoft\Windows\Device Information\Device User => C:\Windows\system32\devicecensus.exe [82944 2025-02-13] (Microsoft Corporation)
Task: {082F4875-D88C-40EA-8706-87480962C446} - System32\Tasks\Microsoft\Windows\Device Setup\Metadata Refresh => {23C1F3CF-C110-4512-ACA9-7B6174ECE888} C:\Windows\System32\DeviceSetupManagerAPI.dll [162816 2024-05-16] (Microsoft Corporation)
Task: {9D87DBE9-E563-4708-A9E9-1A6EE5951EC2} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\HandleCommand => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {0016B09F-CFDA-4F5B-A70B-84A75599B89B} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {61B4D08B-1B23-4CC8-869E-CF0B7996EF5F} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\IntegrityCheck => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {6AAEEF1D-9661-4720-B127-27C975871238} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {9ECD9F35-130A-4C0C-A551-9D3335B165D7} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {EA82AA60-4BB0-41D9-AA1A-D64D739F55DE} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {5E0DF2C3-3D26-4759-9E02-FB7F4DCD159B} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic24 => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {114EC267-55F2-45DA-9AB6-B98CA9DC0D01} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {AF73DAAA-53AE-4CC8-8671-BE29D886B057} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {C660D735-E9F2-4190-9B4E-97ADF1AFFA16} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {65C0DD30-1FE9-43D9-83E6-1D2D4F988689} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceWnsFallback => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {A2FFCE6E-7F06-494A-8C84-6EFCAEB075BB} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice => {AE31B729-D5FD-401E-AF42-784074835AFE} C:\Windows\system32\DeviceDirectoryClient.dll [287744 2024-12-11] (Microsoft Corporation)
Task: {B1C58F3C-E21C-4C03-A579-5D2449AAFCBA} - System32\Tasks\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner => {AD08DCC2-4E35-4486-9D49-547CBD30942D} C:\Windows\System32\MitigationClient.dll [512512 2024-12-11] (Microsoft Corporation)
Task: {C3944556-15CF-467E-89E2-29D4BFD3EC5A} - System32\Tasks\Microsoft\Windows\Diagnosis\Scheduled => {C1F85EF8-BCC2-4606-BB39-70C523715EB3} C:\Windows\System32\sdiagschd.dll [68096 2024-05-16] (Microsoft Corporation)
Task: {55B1C85E-5BEF-4EDB-ADD0-ECEAEF261E7C} - System32\Tasks\Microsoft\Windows\DirectX\DirectXDatabaseUpdater => C:\Windows\system32\directxdatabaseupdater.exe [305664 2025-02-13] (Microsoft Corporation)
Task: {0CBABB27-6DFC-4155-BAE7-AE919B92FEF2} - System32\Tasks\Microsoft\Windows\DirectX\DXGIAdapterCache => C:\Windows\system32\dxgiadaptercache.exe [251392 2025-02-13] (Microsoft Corporation)
Task: {6AA2E298-C47C-45AE-BF6F-E2D9A555345C} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [322560 2025-02-13] (Microsoft Corporation) -> /autoclean /d %systemdrive%
Task: {B97C7632-DD50-4F07-8E4E-F1450795BF78} - System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> dfdts.dll,DfdGetDefaultPolicyAndSMART
Task: {3A4032F6-6063-4D54-BAE3-F8A4A5110CDA} - System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver => C:\Windows\system32\DFDWiz.exe [54784 2019-12-07] (Microsoft Corporation)
Task: {C9EC268B-1D36-4AF0-A1EB-2C1BC3B455D9} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics => C:\Windows\system32\disksnapshot.exe [85504 2023-11-15] (Microsoft Corporation)
Task: {117E2D01-1275-4560-90E9-A34BB4EE69A3} - System32\Tasks\Microsoft\Windows\DiskFootprint\StorageSense => {AB2A519B-03B0-43CE-940A-A73DF850B49A} C:\Windows\system32\StorageUsage.dll [161792 2025-02-13] (Microsoft Corporation)
Task: {69D15B8E-729C-4C1C-A0E7-6DCA5E963E60} - System32\Tasks\Microsoft\Windows\DUSM\dusmtask => C:\Windows\System32\dusmtask.exe [40960 2024-05-16] (Microsoft Corporation)
Task: {EF4B8F07-FA4B-4CD0-84BC-4A758127E3DD} - System32\Tasks\Microsoft\Windows\EDP\EDP App Launch Task => {61BCD1B9-340C-40EC-9D41-D7F1C0632F05} C:\Windows\System32\edptask.dll [72192 2024-05-16] (Microsoft Corporation)
Task: {3789A597-BD62-4A2F-8F57-AE2D504E0E98} - System32\Tasks\Microsoft\Windows\EDP\EDP Auth Task => {61BCD1B9-340C-40EC-9D41-D7F1C0632F05} C:\Windows\System32\edptask.dll [72192 2024-05-16] (Microsoft Corporation)
Task: {0E2DCCB3-7B11-40CF-B973-90F22732E317} - System32\Tasks\Microsoft\Windows\EDP\EDP Inaccessible Credentials Task => {61BCD1B9-340C-40EC-9D41-D7F1C0632F05} C:\Windows\System32\edptask.dll [72192 2024-05-16] (Microsoft Corporation)
Task: {66A3F618-0C70-4F70-9BBA-735CCDB43A09} - System32\Tasks\Microsoft\Windows\EDP\StorageCardEncryption Task => {61BCD1B9-340C-40EC-9D41-D7F1C0632F05} C:\Windows\System32\edptask.dll [72192 2024-05-16] (Microsoft Corporation)
Task: {B9E96119-515B-4D19-8357-D54B747395AD} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask => C:\Windows\system32\MDMAgent.exe [168960 2025-03-12] (Microsoft Corporation)
Task: {F8FEDA28-6261-4385-844A-684E6C988577} - System32\Tasks\Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh => {711001CD-CC1D-4470-9B7E-1EF73849C79E} C:\Windows\System32\MitigationConfiguration.dll [86528 2024-05-16] (Microsoft Corporation)
Task: {92FFE795-C628-4324-AB97-06F804352DB6} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\Windows\system32\dmclient.exe [120832 2024-05-16] (Microsoft Corporation)
Task: {7617E03F-109E-435B-9B4C-0282CD5BE4A9} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload => C:\Windows\system32\dmclient.exe [120832 2024-05-16] (Microsoft Corporation)
Task: {2EE7F450-D2B6-4D5E-AFE0-A8699149E79E} - System32\Tasks\Microsoft\Windows\FileHistory\File History (maintenance mode) => {89917B7C-A1A6-11DF-8BF6-18A90531A85A} C:\Windows\System32\fhtask.dll [61952 2023-11-15] (Microsoft Corporation)
Task: {390D1B87-A132-4ED6-9DCC-2E74ACA236BB} - System32\Tasks\Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures => {59EECBFE-C2F5-4419-9B99-13FE05FF2675} C:\Windows\System32\fcon.dll [472576 2025-02-13] (Microsoft Corporation)
Task: {77BCE1FF-12FC-4F76-A586-1A5BAAA4CC12} - System32\Tasks\Microsoft\Windows\Flighting\FeatureConfig\UsageDataFlushing => {99EFDAD1-0F11-4A6B-A702-4E1C37D1A3EF} C:\Windows\System32\fcon.dll [472576 2025-02-13] (Microsoft Corporation)
Task: {6EB459DE-6885-4D06-8004-BC3B9AC477B4} - System32\Tasks\Microsoft\Windows\Flighting\FeatureConfig\UsageDataReporting => {BBFCD054-8AAC-45DE-A1EB-7B246C9028AF} C:\Windows\System32\fcon.dll [472576 2025-02-13] (Microsoft Corporation)
Task: {589D5E85-0CD4-42DA-B57F-63A124F96411} - System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache => {E07647F7-AED2-48D9-9720-939BC24A8A3C} C:\Windows\System32\wosc.dll [436224 2025-03-12] (Microsoft Corporation)
Task: {12DF3F8A-9612-48CA-AE38-2818FA70CA73} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\Windows\System32\WinBioPlugIns\FaceFodUninstaller.exe [511488 2024-07-10] ()
Task: {CADF1293-5495-426F-8E37-A30F69274AF4} - System32\Tasks\Microsoft\Windows\Input\LocalUserSyncDataAvailable => {8E7C2AFB-72B9-415C-9AC2-5037693309B7} C:\Windows\System32\InputCloudStore.dll [230912 2024-12-11] (Microsoft Corporation)
Task: {DA42085F-11E4-4EE1-A363-1898204812F5} - System32\Tasks\Microsoft\Windows\Input\MouseSyncDataAvailable => {378EAB97-EFD6-4ED5-9AD9-E64A6AA1E6FA} C:\Windows\System32\InputCloudStore.dll [230912 2024-12-11] (Microsoft Corporation)
Task: {4A0DEFDA-A2B8-4736-88E1-A578E00D9704} - System32\Tasks\Microsoft\Windows\Input\PenSyncDataAvailable => {378EAB97-EFD6-4ED5-9AD9-E64A6AA1E6FA} C:\Windows\System32\InputCloudStore.dll [230912 2024-12-11] (Microsoft Corporation)
Task: {7C4733D2-81D6-4CA3-B30C-E00B496B9857} - System32\Tasks\Microsoft\Windows\Input\TouchpadSyncDataAvailable => {378EAB97-EFD6-4ED5-9AD9-E64A6AA1E6FA} C:\Windows\System32\InputCloudStore.dll [230912 2024-12-11] (Microsoft Corporation)
Task: {A08D6A77-C926-4E78-9ED0-09836E2769AE} - System32\Tasks\Microsoft\Windows\InstallService\ScanForUpdates => {A558C6A5-B42B-4C98-B610-BF9559143139} C:\Windows\System32\InstallServiceTasks.dll [249344 2025-03-12] (Microsoft Corporation)
Task: {A2FADBDF-6855-42F7-BDFC-F0C510EDA9BC} - System32\Tasks\Microsoft\Windows\InstallService\ScanForUpdatesAsUser => {DDAFAEA2-8842-4E96-BADE-D44A8D676FDB} C:\Windows\System32\InstallServiceTasks.dll [249344 2025-03-12] (Microsoft Corporation)
Task: {44AF7ADA-1C0D-43B1-A063-9E7581F7730B} - System32\Tasks\Microsoft\Windows\InstallService\SmartRetry => {F3A219C3-2698-4CBF-9C07-037EDB8E72E6} C:\Windows\System32\InstallServiceTasks.dll [249344 2025-03-12] (Microsoft Corporation)
Task: {9B29B882-A95C-438B-BF91-E7C31B1D82D1} - System32\Tasks\Microsoft\Windows\InstallService\WakeUpAndContinueUpdates => {0DC331EE-8438-49D5-A721-E10B937CE459} C:\Windows\System32\InstallServiceTasks.dll [249344 2025-03-12] (Microsoft Corporation)
Task: {EC3EFE4E-A2E4-4C66-975C-CA2EFD0D42CD} - System32\Tasks\Microsoft\Windows\InstallService\WakeUpAndScanForUpdates => {D5A04D91-6FE6-4FE4-A98A-FEB4500C5AF7} C:\Windows\System32\InstallServiceTasks.dll [249344 2025-03-12] (Microsoft Corporation)
Task: {A60D9ECB-A6F4-4FE1-9BD7-B049487A67E7} - System32\Tasks\Microsoft\Windows\International\Synchronize Language Settings => {10D62541-90D0-42FE-848C-0DBC1AC42EDA} C:\Windows\System32\CoreGlobConfig.dll [217616 2024-12-11] (Microsoft Windows -> Microsoft Corporation)
Task: {7A7B60AA-BA42-409F-BC97-7BCFEFAD6308} - System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\Installation => {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE} C:\Windows\System32\LanguageComponentsInstaller.dll [206336 2024-12-11] (Microsoft Corporation)
Task: {A499FA48-7057-4AC1-9702-44C6FD924058} - System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\ReconcileLanguageResources => {D0582E3B-3126-4CAA-9155-AC37C912A489}
Task: {9520602D-5D35-49BC-B397-5251EC6364E8} - System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\Uninstallation => {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE} C:\Windows\System32\LanguageComponentsInstaller.dll [206336 2024-12-11] (Microsoft Corporation)
Task: {A28E2F31-2C6D-426C-A2AC-2F9F6952D916} - System32\Tasks\Microsoft\Windows\License Manager\TempSignedLicenseExchange => {77646A68-AD14-4D53-897D-7BE4DDE5F929} C:\Windows\System32\TempSignedLicenseExchangeTask.dll [74752 2023-11-15] (Microsoft Corporation)
Task: {E88D9B2C-DDEA-47B2-9582-085153004DB5} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\Windows\System32\LocationNotificationWindows.exe [71168 2024-05-16] (Microsoft Corporation)
Task: {E32B86AB-ABAA-45A7-9BE7-9BB2E6B7837D} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\Windows\System32\WindowsActionDialog.exe [62464 2024-05-16] (Microsoft Corporation)
Task: {6F063424-E8AD-40FA-92B9-CD047EC2A92A} - System32\Tasks\Microsoft\Windows\Maintenance\WinSAT => {A9A33436-678B-4C9C-A211-7CC38785E79D} C:\Windows\system32\WinSATAPI.dll [377856 2023-11-15] (Microsoft Corporation)
Task: {BA3321EB-38CE-4B78-9892-3B260CE14444} - System32\Tasks\Microsoft\Windows\Management\Autopilot\DetectHardwareChange => {62B2DD2C-F129-42EE-BF59-55D3FD21C215} C:\WINDOWS\System32\Autopilot.dll [200704 2024-12-11] (Microsoft Corporation)
Task: {68993C94-CE70-4E4D-A96C-B6B978294E5A} - System32\Tasks\Microsoft\Windows\Management\Autopilot\RemediateHardwareChange => {62B2DD2C-F129-42EE-BF59-55D3FD21C215} C:\WINDOWS\System32\Autopilot.dll [200704 2024-12-11] (Microsoft Corporation)
Task: {E38739C8-A84F-4F9B-8913-DCA75BC35C79} - System32\Tasks\Microsoft\Windows\Management\Provisioning\Cellular => C:\Windows\system32\ProvTool.exe [87040 2025-03-12] (Microsoft Corporation)
Task: {80436C26-BC19-4930-9051-F06F0E0BA960} - System32\Tasks\Microsoft\Windows\Management\Provisioning\Logon => C:\Windows\system32\ProvTool.exe [87040 2025-03-12] (Microsoft Corporation)
Task: {2AD5F8AE-8128-49DD-AB67-7D9052D0C609} - System32\Tasks\Microsoft\Windows\Management\Provisioning\Retry => C:\Windows\system32\ProvTool.exe [87040 2025-03-12] (Microsoft Corporation)
Task: {E91D1CC3-09DF-45F0-8208-474AEE6B0A16} - System32\Tasks\Microsoft\Windows\Management\Provisioning\RunOnReboot => C:\Windows\system32\ProvTool.exe [87040 2025-03-12] (Microsoft Corporation)
Task: {701473A3-4C61-4063-AAC6-871E22A29FE7} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask => {9885AEF2-BD9F-41E0-B15E-B3141395E803} C:\Windows\System32\mapstoasttask.dll [54272 2024-05-16] (Microsoft Corporation)
Task: {E577C99D-E5DD-43E8-9E9F-2D291B431572} - System32\Tasks\Microsoft\Windows\Maps\MapsUpdateTask => {B9033E87-33CF-4D77-BC9B-895AFBBA72E4} C:\Windows\System32\mapsupdatetask.dll [45568 2024-05-16] (Microsoft Corporation)
Task: {C207A7CD-C279-4C0F-A05F-C0CADAEDA3A1} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents => {8168e74a-b39f-46d8-adcd-7bed477b80a3} C:\Windows\System32\MemoryDiagnostic.dll [33792 2024-03-13] (Microsoft Corporation)
Task: {A327D266-AF4F-45F3-BE33-03CFDE927DC8} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic => {8168e74a-b39f-46d8-adcd-7bed477b80a3} C:\Windows\System32\MemoryDiagnostic.dll [33792 2024-03-13] (Microsoft Corporation)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\Windows\System32\MbaeParserTask.exe [119296 2019-12-07] (Microsoft Corporation)
Task: {6EE3AFA8-CBB1-4E6E-B0B4-ABFF3127206C} - System32\Tasks\Microsoft\Windows\MUI\LPRemove => C:\Windows\system32\lpremove.exe [96768 2024-12-11] (Microsoft Corporation)
Task: {9486DC81-1119-4559-9110-1A771DEC137A} - System32\Tasks\Microsoft\Windows\Multimedia\SystemSoundsService => {2DEA658F-54C1-4227-AF9B-260AB5FC3543} C:\Windows\System32\PlaySndSrv.dll [90112 2023-11-15] (Microsoft Corporation)
Task: {3A6DB6F9-A355-420A-B6E0-7C54D12F4033} - System32\Tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo => C:\Windows\system32\gatherNetworkInfo.vbs [88781 2019-12-07] ()
Task: {C34E99FC-E9DA-45EE-AF9B-77AAD0B1B25F} - System32\Tasks\Microsoft\Windows\NlaSvc\WiFiTask => C:\Windows\System32\WiFiTask.exe [133608 2023-11-15] (Microsoft Windows -> Microsoft Corporation)
Task: {44729450-CCAF-498F-87DB-E14B564A8EA1} - System32\Tasks\Microsoft\Windows\PI\Secure-Boot-Update => {5014B7C8-934E-4262-9816-887FA745A6C4} C:\Windows\system32\TpmTasks.dll [578560 2025-03-12] (Microsoft Corporation)
Task: {D737597F-4B6D-4CCA-AA9B-09E0F4F74F22} - System32\Tasks\Microsoft\Windows\PI\Sqm-Tasks => {5014B7C8-934E-4262-9816-887FA745A6C4} C:\Windows\system32\TpmTasks.dll [578560 2025-03-12] (Microsoft Corporation)
Task: {C0467AB3-5004-4E13-BD2C-8DDF2AB880B5} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy => {60400283-B242-4FA8-8C25-CAF695B88209} C:\Windows\System32\pnppolicy.dll [91648 2024-05-16] (Microsoft Corporation)
Task: {4E3AEDFB-B76C-4C12-A54F-3BD72A10C434} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required => {48794782-6A1F-47B9-BD52-1D5F95D49C1B} C:\Windows\System32\pnpui.dll [49664 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {DF27E6F5-E07E-4744-981B-BB5BC982261C} - System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers => C:\Windows\System32\drvinst.exe [349696 2025-02-13] (Microsoft Corporation)
Task: {D9353C30-D505-4F11-8F95-55F3DDA1E214} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem => {927EA2AF-1C54-43D5-825E-0074CE028EEE} C:\Windows\System32\energytask.dll [26624 2023-11-15] (Microsoft Corporation)
Task: {35525E8D-FD60-47BF-8D11-FA4F778C57C3} - System32\Tasks\Microsoft\Windows\Printing\EduPrintProv => C:\Windows\system32\eduprintprov.exe [100352 2024-05-16] (Microsoft Corporation)
Task: {6F14D7D2-7ADD-4114-BFDF-8E1571BAD600} - System32\Tasks\Microsoft\Windows\Printing\PrinterCleanupTask => {C56F065E-DE49-4E42-BE7C-305C45609D25} C:\WINDOWS\System32\PrinterCleanupTask.dll [86528 2024-12-11] (Microsoft Corporation)
Task: {772528E0-9B30-4063-A57F-5187253EEB9A} - System32\Tasks\Microsoft\Windows\PushToInstall\LoginCheck => C:\Windows\system32\sc.exe [72192 2019-12-07] (Microsoft Corporation) -> start pushtoinstall login
Task: {E178B5F0-DB3B-4F61-AFF3-21F86A4F12BC} - System32\Tasks\Microsoft\Windows\PushToInstall\Registration => C:\Windows\system32\sc.exe [72192 2019-12-07] (Microsoft Corporation) -> start pushtoinstall registration
Task: {C0E197F6-2E40-46FD-83DA-BE8704EF2CE5} - System32\Tasks\Microsoft\Windows\Ras\MobilityManager => {C463A0FC-794F-4FDF-9201-01938CEACAFA} C:\Windows\system32\rasmbmgr.dll [61952 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {F0FCA53B-F391-48AD-91F6-D1994846E55E} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE => {89D1D0C2-A3CF-490C-ABE3-B86CDE34B047} C:\Windows\System32\ReAgentTask.dll [13824 2019-12-07] (Microsoft Corporation)
Task: {00446CF1-8668-472D-BEDD-D0BB88DBA009} - System32\Tasks\Microsoft\Windows\Registry\RegIdleBackup => {CA767AA8-9157-4604-B64B-40747123D5F2} C:\Windows\System32\regidle.dll [15872 2019-12-07] (Microsoft Corporation)
Task: {CC4F585B-EBBB-4AA6-9BDF-B28C489A9125} - System32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask => C:\Windows\system32\RAServer.exe [135168 2023-11-15] (Microsoft Corporation) -> %windir%\/offerraupdate
Task: {8627F38D-3BB5-45A5-AAE5-B8735A41B62D} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup => {752073A1-23F2-4396-85F0-8FDB879ED0ED} C:\Windows\servicing\TrustedInstaller.exe [192968 2025-03-12] (Microsoft Windows -> Microsoft Corporation)
Task: {E51EADD7-C4F7-43E7-A9CB-FEC8EC1E204F} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask => {59B9640B-3F70-4D1C-B159-F26EEB8A4C87} C:\Windows\system32\SettingSyncCore.dll [1128960 2024-05-16] (Microsoft Corporation)
Task: {7445D17B-89AB-43F3-B904-4DD68B19A6F2} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask => {A4173A49-F373-4475-9A0F-2D615204DC20} C:\Windows\system32\SettingSyncCore.dll [1128960 2024-05-16] (Microsoft Corporation)
Task: {8DB27523-093D-4B93-A00B-68F6317DFAE1} - System32\Tasks\Microsoft\Windows\SharedPC\Account Cleanup => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
Task: {EC95F45C-0486-40E1-8938-20FE3E377E7D} - System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask => {990A9F8F-301F-45F7-8D0E-68C5952DBA43} C:\Windows\system32\shell32.dll [7821960 2025-03-12] (Microsoft Windows -> Microsoft Corporation)
Task: {DFDC1B83-7FD3-4C77-8CD1-7391D1680ACA} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor => C:\Windows\System32\wpcmon.exe [1188048 2024-07-10] (Microsoft Windows -> Microsoft Corporation)
Task: {CD0446AF-D5F6-4616-85CE-058C20FCE9EC} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefreshTask => {C844C79D-AED8-4DCE-AB25-4D359BED84F8} C:\Windows\System32\WpcRefreshTask.dll [1050624 2024-07-10] (Microsoft Corporation)
Task: {C483CE25-B1C5-4BEB-AA31-5CADC8C66692} - System32\Tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance => {3FBA60A6-7BF5-4868-A2CA-6623B3DFFEA6} C:\Windows\System32\srchadmin.dll [234496 2025-01-15] (Microsoft Corporation)
Task: {26B09EE0-27E5-4FB4-B1C0-2C0F98374EC1} - System32\Tasks\Microsoft\Windows\Shell\ThemesSyncedImageDownload => {79F8E185-4E45-4B74-8182-02AA430661E4} C:\WINDOWS\System32\Themes.SsfDownload.ScheduledTask.dll [142336 2024-05-16] (Microsoft Corporation)
Task: {008539BF-83F9-4483-9E0A-EEEE6EAC0A08} - System32\Tasks\Microsoft\Windows\Shell\UpdateUserPictureTask => {09C5DD34-009D-40FA-BCB9-0165AD0C15D4} C:\Windows\System32\Windows.UI.Immersive.dll [1256448 2024-05-16] (Microsoft Corporation)
Task: {2DFC28A5-3035-4555-A9E6-CE6D44EB1DB3} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC} C:\Windows\System32\sppcext.dll [608768 2024-11-13] (Microsoft Corporation)
Task: {892625FE-213B-4B60-95ED-A1CEFCAA365D} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon => {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC} C:\Windows\System32\sppcext.dll [608768 2024-11-13] (Microsoft Corporation)
Task: {3AB082DC-B77E-4487-BB5D-5DCB3A6C2B3C} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork => {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC} C:\Windows\System32\sppcext.dll [608768 2024-11-13] (Microsoft Corporation)
Task: {A9C498D6-046E-407B-A5B5-597DFC8756D9} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask => C:\Windows\system32\SpaceAgent.exe [165888 2024-05-16] (Microsoft Corporation)
Task: {AFEE5D15-0E83-432F-9DB0-58A2702115E1} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceManagerTask => C:\Windows\system32\spaceman.exe [80880 2024-05-16] (Microsoft Windows -> Microsoft Corporation)
Task: {105D676A-D551-4274-81E7-97AC52E4FD87} - System32\Tasks\Microsoft\Windows\Speech\HeadsetButtonPress => C:\Windows\system32\speech_onecore\common\SpeechRuntime.exe [309760 2025-02-13] (Microsoft Corporation)
Task: {4D595DA6-BC59-47AE-A527-EC01FCE2E615} - System32\Tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask => C:\Windows\system32\speech_onecore\common\SpeechModelDownload.exe [221696 2025-02-13] (Microsoft Corporation)
Task: {58CCC4DA-C86D-4E3D-8FAF-A7B24D8F3950} - System32\Tasks\Microsoft\Windows\StateRepository\MaintenanceTasks => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> %windir%\system32\Windows.StateRepositoryClient.dll,StateRepositoryDoMaintenanceTasks
Task: {D777B567-BB3B-4111-881C-0CB741022B0C} - System32\Tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization => {5C9AB547-345D-4175-9AF6-65133463A100} C:\Windows\System32\TieringEngineService.exe [326144 2023-11-15] (Microsoft Corporation)
Task: {FC3767EA-5307-4D11-BA38-EB21A39737D7} - System32\Tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization => C:\Windows\system32\defrag.exe [210432 2023-11-15] (Microsoft Corp.)
Task: {5BC221C3-D323-4B5D-B562-EBAE56AED7FA} - System32\Tasks\Microsoft\Windows\Subscription\EnableLicenseAcquisition => C:\Windows\system32\ClipRenew.exe [182128 2024-05-16] (Microsoft Windows -> Microsoft Corporation)
Task: {77ADF3EA-BCB6-4725-ABAA-84F97626B31D} - System32\Tasks\Microsoft\Windows\Subscription\LicenseAcquisition => C:\Windows\system32\ClipRenew.exe [182128 2024-05-16] (Microsoft Windows -> Microsoft Corporation)
Task: {64614AC8-EA46-476D-A71C-2C0B055C95CC} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate => {17C82257-654E-4C47-8E23-DCA24EAA76A0} C:\Windows\system32\sysmain.dll [1005056 2024-05-16] (Microsoft Corporation)
Task: {236EEE35-EDD5-418B-BCD5-293F6FAD7966} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance => {D44377B8-1F2F-4FAA-9C8E-6C4AD2928E47} C:\Windows\system32\sysmain.dll [1005056 2024-05-16] (Microsoft Corporation)
Task: {051DF697-AF10-4DB6-9B93-E1A4E35F00F7} - System32\Tasks\Microsoft\Windows\Sysmain\ResPriStaticDbSync => {297EE78C-BA95-4E94-81D3-D6E7F089C7B5} C:\Windows\system32\sysmain.dll [1005056 2024-05-16] (Microsoft Corporation)
Task: {638672E6-20F1-499D-BFCC-9EA7935257C4} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> sysmain.dll,PfSvWsSwapAssessmentTask
Task: {20546688-8F7B-4B82-8429-7E7E4F537E96} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe [59392 2023-11-15] (Microsoft Corporation)
Task: {7BE5585E-0190-458B-9CEC-F4076574C717} - System32\Tasks\Microsoft\Windows\Task Manager\Interactive => {855FEC53-D2E4-4999-9E87-3414E9CF0FF4} C:\Windows\system32\wdc.dll [739840 2019-12-07] (Microsoft Corporation)
Task: {88CE6B8C-B14B-499A-8D43-214F06116F07} - System32\Tasks\Microsoft\Windows\TextServicesFramework\MsCtfMonitor => {01575CFE-9A55-4003-A5E1-F38D1EBDCBE1} C:\Windows\system32\MsCtfMonitor.dll [94208 2024-05-16] (Microsoft Corporation)
Task: {F5E862B9-98AE-458E-BC87-3ED25EFBB4D3} - System32\Tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime => {A31AD6C2-FF4C-43D4-8E90-7101023096F9} C:\Windows\system32\TimeSyncTask.dll [15360 2019-12-07] (Microsoft Corporation)
Task: {1FDAEDB1-C8AA-43FA-B046-3CDDDA12661E} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => C:\Windows\system32\sc.exe [72192 2019-12-07] (Microsoft Corporation) -> start w32time task_started
Task: {C4C11C95-C597-4541-B0FF-0FB2C761FC92} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [70144 2019-12-07] (Microsoft Corporation)
Task: {6722F69B-A60E-4BC7-AEB1-85AE7322A1CC} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr => {5014B7C8-934E-4262-9816-887FA745A6C4} C:\Windows\system32\TpmTasks.dll [578560 2025-03-12] (Microsoft Corporation)
Task: {C291FA6A-69CC-4B93-ABE3-3C9C9C07F073} - System32\Tasks\Microsoft\Windows\TPM\Tpm-Maintenance => {5014B7C8-934E-4262-9816-887FA745A6C4} C:\Windows\system32\TpmTasks.dll [578560 2025-03-12] (Microsoft Corporation)
Task: {CAB76809-EDC0-40D2-A888-AD9BEDF4E88A} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => C:\Windows\System32\UNP\UpdateNotificationMgr.exe [463232 2024-05-16] (Microsoft Windows -> Microsoft Corporation)
Task: {59399356-ABAC-4B80-BF59-69B8403C137E} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Backup Scan => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {80DA5EA5-BDFF-4F0E-B9C0-4CE2E38F368C} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {6513856A-4961-4F88-B236-DDE0A6650BD9} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => C:\Windows\system32\MusNotification.exe [697344 2025-02-13] (Microsoft Corporation)
Task: {FC3E442C-6854-4353-BF3B-EDDB1C0490DD} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => C:\Windows\system32\MusNotification.exe [697344 2025-02-13] (Microsoft Corporation)
Task: {7BAB7C98-6188-4247-A3DA-ED0CD4AE62DA} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => C:\Windows\system32\MusNotification.exe [697344 2025-02-13] (Microsoft Corporation)
Task: {70EA2999-165C-4933-9027-250FB8B772F8} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Report policies => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {2C1F714F-DCB2-4842-B10D-B9F5C8DE6FEA} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {738601A4-D6EF-4382-BD1F-51E505462C87} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {309BA321-F7C8-46A4-BA50-5FAC484229CB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan Static Task => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {CA3F17B5-BE41-4D88-BECE-2F3969EA313E} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {CAF4B6AE-C054-4B66-BF3D-685EF4E0236D} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {43339666-A817-4D9E-9AEA-589227820A30} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Start Oobe Expedite Work => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {0FB8B3DB-AC26-4F53-9D91-A9C7183AAE05} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\StartOobeAppsScan_LicenseAccepted => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {6AF98D9C-A592-45B9-AB06-A19933B0432D} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\StartOobeAppsScanAfterUpdate => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {3F7B2EBC-3576-4AC4-B7BD-45E572405456} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Universal Orchestrator Start => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {CB673CE4-960F-462D-AAD7-CDA0CD9FE030} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\UpdateModelTask => C:\Windows\system32\usoclient.exe [240128 2025-03-12] (Microsoft Corporation)
Task: {4671B5C1-A383-4428-A45A-8D348E4CB873} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => C:\Windows\system32\MusNotification.exe [697344 2025-02-13] (Microsoft Corporation)
Task: {57FF06A5-1054-4791-9938-1C3E61F00B07} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => C:\Windows\system32\sc.exe [72192 2019-12-07] (Microsoft Corporation) -> config upnphost start= auto
Task: {C5D47392-881C-422A-9BF8-E4916B55CD22} - System32\Tasks\Microsoft\Windows\USB\Usb-Notifications => {E05BE1C8-92A8-4757-B575-ACAECB4E6A40} C:\Windows\System32\UsbTask.dll [55808 2023-11-15] (Microsoft Corporation)
Task: {3E51A991-10E2-4B16-B5B4-A2F051544BB9} - System32\Tasks\Microsoft\Windows\User Profile Service\HiveUploadTask => {BA677074-762C-444B-94C8-8C83F93F6605} C:\Windows\system32\profsvc.dll [488448 2024-05-16] (Microsoft Corporation)
Task: {0CEC0B91-4AE9-4E8A-ACB2-3B4C811F442C} - System32\Tasks\Microsoft\Windows\WaaSMedic\PerformRemediation => {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32}
Task: {1E334E22-CBC0-4D9C-B830-F1CC1BD6DCFD} - System32\Tasks\Microsoft\Windows\WCM\WiFiTask => C:\Windows\System32\WiFiTask.exe [133608 2023-11-15] (Microsoft Windows -> Microsoft Corporation)
Task: {4D36FC3F-B740-4739-9A9D-C43793F201B8} - System32\Tasks\Microsoft\Windows\WDI\ResolutionHost => {900BE39D-6BE8-461A-BC4D-B0FA71F5ECB1} C:\Windows\System32\wdi.dll [105472 2019-12-07] (Microsoft Corporation)
Task: {AC4AE3CC-3A19-4CC4-AEFE-A345845A2C66} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B7EA6ACB-C1CF-4837-8B45-7D80C24332E0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {18A2AC9E-D4E6-46AC-BD5C-480BF23FFFEC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {93CE7BAB-C21C-4336-A7E7-D7C61378DB4F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpCmdRun.exe [1732816 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {75A35C91-670A-4071-BB93-066651438E14} - System32\Tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting => C:\Windows\system32\wermgr.exe [237424 2024-05-16] (Microsoft Windows -> Microsoft Corporation)
Task: {86158314-60CF-4F3F-85B5-2399327EA496} - System32\Tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange => C:\Windows\system32\rundll32.exe [89600 2024-07-10] (Microsoft Corporation) -> bfe.dll,BfeOnServiceStartTypeChange
Task: {BCD9EED5-1A09-48A4-9F31-39175A3E4BFD} - System32\Tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary => C:\Program Files\Windows Media Player\wmpnscfg.exe [71168 2019-12-06] (Microsoft Corporation)
Task: {AA70A383-6F5D-470B-AA6B-B324620D9C75} - System32\Tasks\Microsoft\Windows\WindowsColorSystem\Calibration Loader => {B210D694-C8DF-490D-9576-9E20CDBC20BD} C:\Windows\System32\mscms.dll [708256 2024-11-13] (Microsoft Windows -> Microsoft Corporation)
Task: {A9EB26FF-A176-414F-9071-BA84E166A1B0} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Refresh Group Policy Cache => {07369A67-07A6-4608-ABEA-379491CB7C46} C:\Windows\System32\UpdatePolicy.dll [250880 2025-02-13] (Microsoft Corporation)
Task: {34CC0D76-359F-46F5-87F6-4778BF8AEC13} - System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler => C:\Program Files\RUXIM\PLUGscheduler.exe [383472 2024-09-27] (Microsoft Windows -> Microsoft Corporation)
Task: {8FF5DE67-C947-4488-997B-4184221E7D50} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start => C:\Windows\System32\sc.exe [72192 2019-12-07] (Microsoft Corporation) -> start wuauserv
Task: {1949073A-8FDA-4EA4-8E59-407CDB02440F} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihpostreboot => C:\Windows\system32\sihclient.exe [402984 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D85F83F5-ED09-49BC-A506-32C837CA0904} - System32\Tasks\Microsoft\Windows\Wininet\CacheTask => {0358B920-0AC7-461F-98F4-58E32CD89148} C:\Windows\system32\wininet.dll [5045248 2025-02-13] (Microsoft Corporation)
Task: {5E351EE7-F0D4-4F41-A05C-907EB1A33CE8} - System32\Tasks\Microsoft\Windows\WlanSvc\CDSSync => {B0D2B535-12E1-439F-86B3-BADA289510F0} C:\Windows\System32\WiFiCloudStore.dll [283136 2024-12-11] (Microsoft Corporation)
Task: {9D7DE09E-3941-4760-8EE6-7579A05A53E1} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management => {B7BFFB5A-EFA8-4D8C-BBDE-C8D5FAAF54A1} C:\Windows\system32\WofTasks.dll [30720 2019-12-07] (Microsoft Corporation)
Task: {A45E4601-8ABA-443A-A656-62D52D5B68E6} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation => {B7BFFB5A-EFA8-4D8C-BBDE-C8D5FAAF54A1} C:\Windows\system32\WofTasks.dll [30720 2019-12-07] (Microsoft Corporation)
Task: {F93E2A44-7E3E-49FE-9F66-12B1F4A037C0} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization => {97D47D56-3777-49FB-8E8F-90D7E30E1A1E} C:\Windows\System32\WorkFoldersShell.dll [230400 2024-05-16] (Microsoft Corporation)
Task: {6440C5E0-A168-4A5F-B84E-F7C8C0A6E933} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work => {63260BCE-A3FB-4A34-AA51-D4D8E877B62B} C:\Windows\System32\WorkFoldersShell.dll [230400 2024-05-16] (Microsoft Corporation)
Task: {4BDB5047-01B7-48D5-AE7E-720EDA7D2049} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\Windows\System32\dsregcmd.exe [468992 2023-11-15] (Microsoft Corporation)
Task: {571A0A5E-B60E-4A25-BEFB-ABB3C6BB6B78} - System32\Tasks\Microsoft\Windows\Workplace Join\Device-Sync => {C662D912-E4D6-44A3-89A0-20550514951D} C:\Windows\System32\dsregtask.dll [52736 2024-08-14] (Microsoft Corporation)
Task: {35D4C945-33D4-43B6-83D3-99034D411E25} - System32\Tasks\Microsoft\Windows\Workplace Join\Recovery-Check => C:\Windows\System32\dsregcmd.exe [468992 2023-11-15] (Microsoft Corporation)
Task: {DF6A7742-913B-4025-B27A-CE65BB343A0D} - System32\Tasks\Microsoft\Windows\WwanSvc\NotificationTask => C:\Windows\System32\WiFiTask.exe [133608 2023-11-15] (Microsoft Windows -> Microsoft Corporation)
Task: {A420D02A-52B4-47AC-99E0-D828A95B6CE7} - System32\Tasks\Microsoft\Windows\WwanSvc\OobeDiscovery => {C93CF9D5-031B-4AAA-AB0B-EF802347B381} C:\Windows\System32\MBMediaManager.dll [746496 2024-05-16] (Microsoft Corporation)
Task: {41F5FC9D-EE65-4CA4-A908-91B3587198E0} - System32\Tasks\Microsoft\XblGameSave\XblGameSaveTask => C:\Windows\System32\XblGameSaveTask.exe [33792 2024-05-16] (Microsoft Corporation)
Task: {BF39633A-CDBE-449D-8F69-6548650BD809} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [214944 2020-11-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {E9C5D9D9-9A8A-4C62-9D1E-41A7C06AF140} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [214944 2020-11-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {07FDA6BE-62E7-49D2-997C-E46A28F872A4} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628160 2020-02-28] (Advanced Micro Devices, Inc.)
Task: {5107776E-7CC4-4989-B4C6-35B180D1415C} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-26] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {1F8838E8-4BB5-4E1C-A82A-BE4525563D57} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1337375207-2760412818-246081271-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-26] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {50E5193D-0CEF-466E-B390-460AA3ACB793} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34880 2025-03-26] (Mozilla Corporation -> Mozilla Foundation)
Task: {A91200C2-5B12-4248-8458-93E5E2141DD2} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => C:\Windows\system32\sc.exe [72192 2019-12-07] (Microsoft Corporation) -> start osppsvc
Task: {9F83CD37-167A-4826-8DFE-247FD0449C66} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1337375207-2760412818-246081271-1001 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  /reporting (No File) <==== ATTENTION
Task: {3544D5F3-0059-4BF8-8EEF-0620DAD29FF5} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1337375207-2760412818-246081271-1001 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (No File) <==== ATTENTION
Task: {80C67B19-9D59-45CA-B3E1-6930C8E3157A} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1337375207-2760412818-246081271-1001 => C:\Users\KiezPC\AppData\Local\Microsoft\OneDrive\25.035.0223.0003\OneDriveLauncher.exe [670528 2025-03-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {317D4BC6-B44A-4FD3-99A8-61E8699FF588} - System32\Tasks\Opera scheduled assistant Autoupdate 1600783937 => C:\Users\KiezPC\AppData\Local\Programs\Opera\launcher.exe  -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\KiezPC\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {216FD3C8-AA94-4423-BA88-F784358438D1} - System32\Tasks\Opera scheduled Autoupdate 1600783933 => C:\Users\KiezPC\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [4815768 2025-02-28] (Opera Norway AS -> Opera Software)
Task: {98440C76-06AC-409C-850B-0FD56BA4A3A9} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [60008 2020-02-28] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {00F2CA3F-427E-4F40-B871-F67B6C969B15} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [67688 2020-02-28] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {ADCE0AC6-DC33-43AD-8F6E-7BCB4F3A07E9} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-1337375207-2760412818-246081271-1001 => C:\Users\KiezPC\AppData\Roaming\Zoom\bin\Zoom.exe [434488 2025-03-07] (Zoom Video Communications, Inc. -> Zoom Communications, Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe


bluemooon 27.03.2025 22:23

Code:

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7498024 2025-03-01] (Avast Software s.r.o. -> AVAST Software)
S2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [805672 2025-03-01] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2428200 2025-03-01] (Avast Software s.r.o. -> Gen Digital Inc.)
S2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [1257256 2025-03-01] (Avast Software s.r.o. -> Gen Digital Inc.)
S2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2025-03-01] (Avast Software s.r.o. -> AVAST Software)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1088816 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
S2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13768912 2025-03-16] (Microsoft Corporation -> Microsoft Corporation)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4507328 2020-04-12] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S2 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [887904 2024-12-17] (HP Inc. -> HP Inc.)
S2 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [886368 2024-12-17] (HP Inc. -> HP Inc.)
S2 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [882296 2024-12-17] (HP Inc. -> HP Inc.)
S2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243664 2025-03-05] (HP Inc. -> HP Inc.)
S2 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [887392 2024-12-17] (HP Inc. -> HP Inc.)
S2 KamoSvc; C:\Program Files (x86)\Kamo\KamoSvc.exe [6709664 2024-05-29] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9483456 2025-02-20] (Malwarebytes Inc. -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-01-10] (Malwarebytes Inc. -> Malwarebytes)
S2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpDefenderCoreService.exe [1926976 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 SecureLine; C:\Program Files\Avast Software\SecureLine VPN\VpnSvc.exe [12997416 2025-03-06] (Avast Software s.r.o. -> Gen Digital Inc.)
S2 SilhouetteLink; C:\Program Files (x86)\Silhouette America\Silhouette Link\Resources\Resources\SPEC_LK\SilhouetteLinkServer.32.exe [897200 2016-12-06] (Silhouette Research & Technology Ltd -> )
S4 ssh-agent; C:\Windows\System32\OpenSSH\ssh-agent.exe [550912 2024-10-09] ()
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\NisSrv.exe [4352456 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MsMpEng.exe [270056 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 PMBDeviceInfoProvider; "C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe" [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AcpiPmi; C:\Windows\System32\drivers\acpipmi.sys [18432 2019-12-07] (Microsoft Corporation)
S3 Acx01000; C:\Windows\System32\drivers\Acx01000.sys [694272 2024-05-16] (Microsoft Corporation)
S1 afunix; C:\Windows\system32\drivers\afunix.sys [44032 2024-05-16] (Microsoft Corporation)
S1 afunix; C:\Windows\SysWOW64\drivers\afunix.sys [30720 2024-05-16] (Microsoft Corporation)
S1 ahcache; C:\Windows\System32\DRIVERS\ahcache.sys [305152 2025-02-13] (Microsoft Corporation)
S3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [54720 2022-10-21] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\amdkmdag.sys [94467928 2023-04-06] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 AmUStor; C:\Windows\system32\drivers\AmUStorU.sys [155744 2024-03-31] (Alcorlink Corp. -> )
S3 applockerfltr; C:\Windows\System32\drivers\applockerfltr.sys [18432 2024-11-13] (Microsoft Corporation)
S0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [20568 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [246880 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [384096 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [296032 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [84576 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswElam; C:\Windows\System32\drivers\aswElam.sys [28280 2025-03-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
S1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [37984 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [278616 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [553568 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [98912 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [69728 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [959064 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswSP; C:\Windows\System32\drivers\aswSP.sys [1427552 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 aswStm; C:\Windows\System32\drivers\aswStm.sys [206904 2025-03-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [389720 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 aswVpnRdr; C:\Windows\System32\drivers\aswVpnRdr.sys [85776 2025-02-07] (Microsoft Windows Hardware Compatibility Publisher -> Avast Software)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [9728 2019-12-07] (Windows (R) Win 7 DDK provider)
S1 Beep; C:\Windows\System32\Drivers\Beep.sys [10240 2019-12-07] (Microsoft Corporation)
S3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [117760 2023-11-15] (Microsoft Corporation)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation)
S3 BthEnum; C:\Windows\System32\drivers\BthEnum.sys [113664 2024-07-10] (Microsoft Corporation)
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation)
S3 BthLEEnum; C:\Windows\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [106496 2023-11-15] (Microsoft Corporation)
S3 BthMini; C:\Windows\System32\drivers\BTHMINI.sys [45568 2024-07-10] (Microsoft Corporation)
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation)
S3 BthPan; C:\Windows\System32\drivers\bthpan.sys [133632 2023-11-15] (Microsoft Corporation)
S3 BTHPORT; C:\Windows\System32\drivers\BTHport.sys [1570304 2024-07-10] (Microsoft Corporation)
S3 BTHUSB; C:\Windows\System32\drivers\BTHUSB.sys [110592 2024-07-10] (Microsoft Corporation)
S4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [100864 2023-11-15] (Microsoft Corporation)
S1 cdrom; C:\Windows\System32\drivers\cdrom.sys [175616 2024-05-16] (Microsoft Corporation)
S1 CimFS; C:\Windows\System32\Drivers\CimFS.sys [95232 2024-06-12] ()
S3 circlass; C:\Windows\System32\drivers\circlass.sys [52224 2019-12-07] (Microsoft Corporation)
S2 CldFlt; C:\Windows\System32\drivers\cldflt.sys [505856 2025-02-13] (Microsoft Corporation)
S3 CsrBtPort; C:\Windows\system32\DRIVERS\CsrBtPort.sys [2784968 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrpan; C:\Windows\System32\drivers\csrpan.sys [39616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrserial; C:\Windows\system32\DRIVERS\csrserial.sys [61128 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrusb; C:\Windows\System32\Drivers\csrusb.sys [47296 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrusbfilter; C:\Windows\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S1 Dfsc; C:\Windows\System32\Drivers\dfsc.sys [154112 2024-10-09] (Microsoft Corporation)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [42256 2020-04-12] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [59360 2020-04-12] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S1 FileCrypt; C:\Windows\System32\drivers\filecrypt.sys [59392 2019-12-07] (Microsoft Corporation)
S1 GpuEnergyDrv; C:\Windows\System32\drivers\gpuenergydrv.sys [8704 2019-12-07] (Microsoft Corporation)
S3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [430080 2023-11-15] (Microsoft Corporation)
S3 HDAudBus; C:\Windows\System32\drivers\HDAudBus.sys [135168 2025-03-12] (Microsoft Corporation)
S3 HidBth; C:\Windows\System32\drivers\hidbth.sys [120320 2023-11-15] (Microsoft Corporation)
S3 HidIr; C:\Windows\System32\drivers\hidir.sys [48640 2019-12-07] (Microsoft Corporation)
S3 hidspi; C:\Windows\System32\drivers\hidspi.sys [104448 2023-11-15] (Microsoft Corporation)
S3 HidSpiCx; C:\Windows\System32\drivers\HidSpiCx.sys [92160 2023-11-15] (Microsoft Corporation)
S3 HidUsb; C:\Windows\System32\drivers\hidusb.sys [44032 2023-11-15] (Microsoft Corporation)
S3 HwNClx0101; C:\Windows\System32\Drivers\mshwnclx.sys [30208 2019-12-07] (Microsoft Corporation)
S3 IndirectKmd; C:\Windows\System32\drivers\IndirectKmd.sys [47104 2023-11-15] (Microsoft Corporation)
S3 intelpmax; C:\Windows\System32\drivers\intelpmax.sys [30720 2019-12-07] (Microsoft Corporation)
S3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [91648 2024-05-16] (Microsoft Corporation)
S3 IPNAT; C:\Windows\System32\drivers\ipnat.sys [228352 2024-05-16] (Microsoft Corporation)
S3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [278944 2025-03-12] (Microsoft Windows -> Microsoft Corporation)
S3 ksthunk; C:\Windows\system32\drivers\ksthunk.sys [37376 2025-03-12] (Microsoft Corporation)
S2 lltdio; C:\Windows\System32\drivers\lltdio.sys [72704 2019-12-07] (Microsoft Corporation)
S2 luafv; C:\Windows\system32\drivers\luafv.sys [143360 2025-03-12] (Microsoft Corporation)
S2 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [234072 2025-02-26] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2025-02-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239568 2024-07-26] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MbbCx; C:\Windows\System32\drivers\MbbCx.sys [399360 2024-12-11] (Microsoft Corporation)
S3 Microsoft_Bluetooth_AvrcpTransport; C:\Windows\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [66048 2024-05-16] (Microsoft Corporation)
S2 MMCSS; C:\Windows\system32\drivers\mmcss.sys [53248 2023-11-15] (Microsoft Corporation)
S3 Modem; C:\Windows\System32\drivers\modem.sys [47104 2023-11-15] (Microsoft Corporation)
S3 monitor; C:\Windows\System32\drivers\monitor.sys [83456 2024-05-16] (Microsoft Corporation)
S3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [165888 2024-05-16] (Microsoft Corporation)
S3 MsBridge; C:\Windows\System32\drivers\bridge.sys [129536 2024-12-11] (Microsoft Corporation)
S3 mshidumdf; C:\Windows\System32\drivers\mshidumdf.sys [12288 2019-12-07] (Microsoft Corporation)
S3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [38400 2025-03-12] (Microsoft Corporation)
S2 MsLldp; C:\Windows\System32\drivers\mslldp.sys [78848 2019-12-07] (Microsoft Corporation)
S3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [758784 2024-11-13] (Microsoft Corporation)
S1 NdisCap; C:\Windows\System32\drivers\ndiscap.sys [54272 2019-12-07] (Microsoft Corporation)
S3 NdisImPlatform; C:\Windows\System32\drivers\NdisImPlatform.sys [135168 2023-11-15] (Microsoft Corporation)
S3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [28672 2023-11-15] (Microsoft Corporation)
S3 NdisWan; C:\Windows\System32\drivers\ndiswan.sys [208384 2024-05-16] (Microsoft Corporation)
S3 ndiswanlegacy; C:\Windows\System32\DRIVERS\ndiswan.sys [208384 2024-05-16] (Microsoft Corporation)
S3 ndproxy; C:\Windows\System32\DRIVERS\NDProxy.sys [93696 2023-11-15] (Microsoft Corporation)
S2 Ndu; C:\Windows\System32\drivers\Ndu.sys [131584 2019-12-07] (Microsoft Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [210944 2024-05-16] (Microsoft Corporation)
S1 NetBT; C:\Windows\System32\DRIVERS\netbt.sys [341504 2023-11-15] (Microsoft Corporation)
S1 netfilter2; C:\Windows\System32\drivers\netfilter2.sys [114104 2024-05-29] (Piriform Software Ltd -> Windows (R) Win 7 DDK provider)
S1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [48640 2023-11-15] (Microsoft Corporation)
S2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [823296 2024-04-09] (Microsoft Corporation)
S3 PNPMEM; C:\Windows\System32\drivers\pnpmem.sys [17408 2019-12-07] (Microsoft Corporation)
S3 PptpMiniport; C:\Windows\System32\drivers\raspptp.sys [105984 2023-11-15] (Microsoft Corporation)
S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [53248 2019-12-07] (Microsoft Corporation)
S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [20480 2023-11-15] (Microsoft Corporation)
S3 RasAgileVpn; C:\Windows\System32\drivers\AgileVpn.sys [115200 2024-05-16] (Microsoft Corporation)
S3 Rasl2tp; C:\Windows\System32\drivers\rasl2tp.sys [112640 2024-05-16] (Microsoft Corporation)
S3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [89088 2024-05-16] (Microsoft Corporation)
S3 RasSstp; C:\Windows\System32\drivers\rassstp.sys [87552 2023-11-15] (Microsoft Corporation)
S3 rdpbus; C:\Windows\System32\drivers\rdpbus.sys [28672 2019-12-07] (Microsoft Corporation)
S3 RDPDR; C:\Windows\System32\drivers\rdpdr.sys [170496 2024-05-16] (Microsoft Corporation)
S3 RFCOMM; C:\Windows\System32\drivers\rfcomm.sys [213504 2024-05-16] (Microsoft Corporation)
S3 rhproxy; C:\Windows\System32\drivers\rhproxy.sys [115712 2019-12-07] (Microsoft Corporation)
S2 rspndr; C:\Windows\System32\drivers\rspndr.sys [89088 2019-12-07] (Microsoft Corporation)
S3 scfilter; C:\Windows\System32\DRIVERS\scfilter.sys [44032 2025-03-12] (Microsoft Corporation)
S3 spaceparser; C:\Windows\System32\drivers\spaceparser.sys [26624 2019-12-07] (Microsoft Corporation)
S3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [786944 2025-03-12] (Microsoft Corporation)
S3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [318976 2024-05-16] (Microsoft Corporation)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 Synth3dVsc; C:\Windows\System32\drivers\Synth3dVsc.sys [6656 2023-11-15] (Microsoft Corporation)
S2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [56320 2024-05-16] (Microsoft Corporation)
S3 TsUsbFlt; C:\Windows\System32\drivers\tsusbflt.sys [66560 2019-12-07] (Microsoft Corporation)
S3 TsUsbGD; C:\Windows\System32\drivers\TsUsbGD.sys [37888 2023-11-15] (Microsoft Corporation)
S3 tunnel; C:\Windows\System32\drivers\tunnel.sys [129024 2023-11-15] (Microsoft Corporation)
S3 UcmCx0101; C:\Windows\System32\Drivers\UcmCx.sys [160256 2023-11-15] (Microsoft Corporation)
S3 UcmTcpciCx0101; C:\Windows\System32\Drivers\UcmTcpciCx.sys [188416 2019-12-07] (Microsoft Corporation)
S3 UcmUcsiAcpiClient; C:\Windows\System32\drivers\UcmUcsiAcpiClient.sys [36864 2019-12-07] (Microsoft Corporation)
S3 UcmUcsiCx0101; C:\Windows\System32\Drivers\UcmUcsiCx.sys [113152 2023-11-15] (Microsoft Corporation)
S1 UCPD; C:\Windows\System32\drivers\UCPD.sys [102400 2025-03-12] (Microsoft Corporation)
S4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [345088 2024-05-16] (Microsoft Corporation)
S3 usbaudio; C:\Windows\system32\drivers\usbaudio.sys [216576 2025-02-13] (Microsoft Corporation)
S3 usbaudio2; C:\Windows\System32\drivers\usbaudio2.sys [260608 2019-12-07] (Microsoft Corporation)
S3 usbcir; C:\Windows\System32\drivers\usbcir.sys [107520 2019-12-07] (Microsoft Corporation)
S3 usbohci; C:\Windows\System32\drivers\usbohci.sys [30208 2024-06-12] (Microsoft Corporation)
S3 usbprint; C:\Windows\System32\drivers\usbprint.sys [43008 2024-10-09] (Microsoft Corporation)
S3 usbser; C:\Windows\System32\drivers\usbser.sys [81408 2023-11-15] (Microsoft Corporation)
S3 usbuhci; C:\Windows\System32\drivers\usbuhci.sys [39424 2024-06-12] (Microsoft Corporation)
S3 VirtualRender; C:\Windows\System32\DriverStore\FileRepository\vrd.inf_amd64_81fbd405ff2470fc\vrd.sys [11264 2019-12-07] (Microsoft Corporation)
S1 vwififlt; C:\Windows\System32\drivers\vwififlt.sys [77824 2023-11-15] (Microsoft Corporation)
S2 wanarp; C:\Windows\System32\DRIVERS\wanarp.sys [93184 2023-11-15] (Microsoft Corporation)
S3 wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [93184 2023-11-15] (Microsoft Corporation)
S3 wcnfs; C:\Windows\system32\drivers\wcnfs.sys [93184 2023-11-15] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [20016 2025-03-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [601520 2025-03-12] (Microsoft Windows -> Microsoft Corporation)
S3 wdiwifi; C:\Windows\System32\DRIVERS\wdiwifi.sys [967168 2024-11-13] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [100768 2025-03-12] (Microsoft Windows -> Microsoft Corporation)
S3 WinNat; C:\Windows\System32\drivers\winnat.sys [261632 2025-03-12] (Microsoft Corporation)
S3 WINUSB; C:\Windows\System32\drivers\WinUsb.sys [107008 2019-12-07] (Microsoft Corporation)
S3 WSDPrintDevice; C:\Windows\System32\drivers\WSDPrint.sys [23552 2023-11-15] (Microsoft Corporation)
S3 WSDScan; C:\Windows\System32\drivers\WSDScan.sys [26112 2023-11-15] (Microsoft Corporation)
S3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [136192 2023-12-13] (Microsoft Corporation)
S3 WUDFRd; C:\Windows\System32\drivers\WUDFRd.sys [315904 2023-12-13] (Microsoft Corporation)
S3 WUDFWpdFs; C:\Windows\System32\drivers\WUDFRd.sys [315904 2023-12-13] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\Windows\System32\drivers\WUDFRd.sys [315904 2023-12-13] (Microsoft Corporation)
S3 xboxgip; C:\Windows\System32\drivers\xboxgip.sys [340480 2024-08-14] (Microsoft Corporation)
S3 xinputhid; C:\Windows\System32\drivers\xinputhid.sys [61952 2024-05-16] (Microsoft Corporation)
UpperFilters: [{4D36E967-E325-11CE-BFC1-08002BE10318}] -> [partmgr aswArDisk]

Code:

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7498024 2025-03-01] (Avast Software s.r.o. -> AVAST Software)
S2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [805672 2025-03-01] (Avast Software s.r.o. -> Gen Digital Inc.)
S3 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2428200 2025-03-01] (Avast Software s.r.o. -> Gen Digital Inc.)
S2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [1257256 2025-03-01] (Avast Software s.r.o. -> Gen Digital Inc.)
S2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2025-03-01] (Avast Software s.r.o. -> AVAST Software)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1088816 2025-02-18] (Gen Digital Inc. -> Gen Digital Inc.)
S2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13768912 2025-03-16] (Microsoft Corporation -> Microsoft Corporation)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4507328 2020-04-12] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S2 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [887904 2024-12-17] (HP Inc. -> HP Inc.)
S2 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [886368 2024-12-17] (HP Inc. -> HP Inc.)
S2 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [882296 2024-12-17] (HP Inc. -> HP Inc.)
S2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243664 2025-03-05] (HP Inc. -> HP Inc.)
S2 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [887392 2024-12-17] (HP Inc. -> HP Inc.)
S2 KamoSvc; C:\Program Files (x86)\Kamo\KamoSvc.exe [6709664 2024-05-29] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9483456 2025-02-20] (Malwarebytes Inc. -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-01-10] (Malwarebytes Inc. -> Malwarebytes)
S2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MpDefenderCoreService.exe [1926976 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 SecureLine; C:\Program Files\Avast Software\SecureLine VPN\VpnSvc.exe [12997416 2025-03-06] (Avast Software s.r.o. -> Gen Digital Inc.)
S2 SilhouetteLink; C:\Program Files (x86)\Silhouette America\Silhouette Link\Resources\Resources\SPEC_LK\SilhouetteLinkServer.32.exe [897200 2016-12-06] (Silhouette Research & Technology Ltd -> )
S4 ssh-agent; C:\Windows\System32\OpenSSH\ssh-agent.exe [550912 2024-10-09] ()
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\NisSrv.exe [4352456 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25010.11-0\MsMpEng.exe [270056 2025-03-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 PMBDeviceInfoProvider; "C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe" [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AcpiPmi; C:\Windows\System32\drivers\acpipmi.sys [18432 2019-12-07] (Microsoft Corporation)
S3 Acx01000; C:\Windows\System32\drivers\Acx01000.sys [694272 2024-05-16] (Microsoft Corporation)
S1 afunix; C:\Windows\system32\drivers\afunix.sys [44032 2024-05-16] (Microsoft Corporation)
S1 afunix; C:\Windows\SysWOW64\drivers\afunix.sys [30720 2024-05-16] (Microsoft Corporation)
S1 ahcache; C:\Windows\System32\DRIVERS\ahcache.sys [305152 2025-02-13] (Microsoft Corporation)
S3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [54720 2022-10-21] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0390451.inf_amd64_39377efdd62734d1\B390182\amdkmdag.sys [94467928 2023-04-06] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 AmUStor; C:\Windows\system32\drivers\AmUStorU.sys [155744 2024-03-31] (Alcorlink Corp. -> )
S3 applockerfltr; C:\Windows\System32\drivers\applockerfltr.sys [18432 2024-11-13] (Microsoft Corporation)
S0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [20568 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [246880 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [384096 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [296032 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [84576 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswElam; C:\Windows\System32\drivers\aswElam.sys [28280 2025-03-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Gen Digital Inc.)
S1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [37984 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [278616 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [553568 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [98912 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [69728 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [959064 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S1 aswSP; C:\Windows\System32\drivers\aswSP.sys [1427552 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 aswStm; C:\Windows\System32\drivers\aswStm.sys [206904 2025-03-01] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [389720 2025-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Gen Digital Inc.)
S3 aswVpnRdr; C:\Windows\System32\drivers\aswVpnRdr.sys [85776 2025-02-07] (Microsoft Windows Hardware Compatibility Publisher -> Avast Software)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [9728 2019-12-07] (Windows (R) Win 7 DDK provider)
S1 Beep; C:\Windows\System32\Drivers\Beep.sys [10240 2019-12-07] (Microsoft Corporation)
S3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [117760 2023-11-15] (Microsoft Corporation)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation)
S3 BthEnum; C:\Windows\System32\drivers\BthEnum.sys [113664 2024-07-10] (Microsoft Corporation)
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation)
S3 BthLEEnum; C:\Windows\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [106496 2023-11-15] (Microsoft Corporation)
S3 BthMini; C:\Windows\System32\drivers\BTHMINI.sys [45568 2024-07-10] (Microsoft Corporation)
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation)
S3 BthPan; C:\Windows\System32\drivers\bthpan.sys [133632 2023-11-15] (Microsoft Corporation)
S3 BTHPORT; C:\Windows\System32\drivers\BTHport.sys [1570304 2024-07-10] (Microsoft Corporation)
S3 BTHUSB; C:\Windows\System32\drivers\BTHUSB.sys [110592 2024-07-10] (Microsoft Corporation)
S4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [100864 2023-11-15] (Microsoft Corporation)
S1 cdrom; C:\Windows\System32\drivers\cdrom.sys [175616 2024-05-16] (Microsoft Corporation)
S1 CimFS; C:\Windows\System32\Drivers\CimFS.sys [95232 2024-06-12] ()
S3 circlass; C:\Windows\System32\drivers\circlass.sys [52224 2019-12-07] (Microsoft Corporation)
S2 CldFlt; C:\Windows\System32\drivers\cldflt.sys [505856 2025-02-13] (Microsoft Corporation)
S3 CsrBtPort; C:\Windows\system32\DRIVERS\CsrBtPort.sys [2784968 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrpan; C:\Windows\System32\drivers\csrpan.sys [39616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrserial; C:\Windows\system32\DRIVERS\csrserial.sys [61128 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrusb; C:\Windows\System32\Drivers\csrusb.sys [47296 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrusbfilter; C:\Windows\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S1 Dfsc; C:\Windows\System32\Drivers\dfsc.sys [154112 2024-10-09] (Microsoft Corporation)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [42256 2020-04-12] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [59360 2020-04-12] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S1 FileCrypt; C:\Windows\System32\drivers\filecrypt.sys [59392 2019-12-07] (Microsoft Corporation)
S1 GpuEnergyDrv; C:\Windows\System32\drivers\gpuenergydrv.sys [8704 2019-12-07] (Microsoft Corporation)
S3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [430080 2023-11-15] (Microsoft Corporation)
S3 HDAudBus; C:\Windows\System32\drivers\HDAudBus.sys [135168 2025-03-12] (Microsoft Corporation)
S3 HidBth; C:\Windows\System32\drivers\hidbth.sys [120320 2023-11-15] (Microsoft Corporation)
S3 HidIr; C:\Windows\System32\drivers\hidir.sys [48640 2019-12-07] (Microsoft Corporation)
S3 hidspi; C:\Windows\System32\drivers\hidspi.sys [104448 2023-11-15] (Microsoft Corporation)
S3 HidSpiCx; C:\Windows\System32\drivers\HidSpiCx.sys [92160 2023-11-15] (Microsoft Corporation)
S3 HidUsb; C:\Windows\System32\drivers\hidusb.sys [44032 2023-11-15] (Microsoft Corporation)
S3 HwNClx0101; C:\Windows\System32\Drivers\mshwnclx.sys [30208 2019-12-07] (Microsoft Corporation)
S3 IndirectKmd; C:\Windows\System32\drivers\IndirectKmd.sys [47104 2023-11-15] (Microsoft Corporation)
S3 intelpmax; C:\Windows\System32\drivers\intelpmax.sys [30720 2019-12-07] (Microsoft Corporation)
S3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [91648 2024-05-16] (Microsoft Corporation)
S3 IPNAT; C:\Windows\System32\drivers\ipnat.sys [228352 2024-05-16] (Microsoft Corporation)
S3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [278944 2025-03-12] (Microsoft Windows -> Microsoft Corporation)
S3 ksthunk; C:\Windows\system32\drivers\ksthunk.sys [37376 2025-03-12] (Microsoft Corporation)
S2 lltdio; C:\Windows\System32\drivers\lltdio.sys [72704 2019-12-07] (Microsoft Corporation)
S2 luafv; C:\Windows\system32\drivers\luafv.sys [143360 2025-03-12] (Microsoft Corporation)
S2 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [234072 2025-02-26] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2025-02-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239568 2024-07-26] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 MbbCx; C:\Windows\System32\drivers\MbbCx.sys [399360 2024-12-11] (Microsoft Corporation)
S3 Microsoft_Bluetooth_AvrcpTransport; C:\Windows\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [66048 2024-05-16] (Microsoft Corporation)
S2 MMCSS; C:\Windows\system32\drivers\mmcss.sys [53248 2023-11-15] (Microsoft Corporation)
S3 Modem; C:\Windows\System32\drivers\modem.sys [47104 2023-11-15] (Microsoft Corporation)
S3 monitor; C:\Windows\System32\drivers\monitor.sys [83456 2024-05-16] (Microsoft Corporation)
S3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [165888 2024-05-16] (Microsoft Corporation)
S3 MsBridge; C:\Windows\System32\drivers\bridge.sys [129536 2024-12-11] (Microsoft Corporation)
S3 mshidumdf; C:\Windows\System32\drivers\mshidumdf.sys [12288 2019-12-07] (Microsoft Corporation)
S3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [38400 2025-03-12] (Microsoft Corporation)
S2 MsLldp; C:\Windows\System32\drivers\mslldp.sys [78848 2019-12-07] (Microsoft Corporation)
S3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [758784 2024-11-13] (Microsoft Corporation)
S1 NdisCap; C:\Windows\System32\drivers\ndiscap.sys [54272 2019-12-07] (Microsoft Corporation)
S3 NdisImPlatform; C:\Windows\System32\drivers\NdisImPlatform.sys [135168 2023-11-15] (Microsoft Corporation)
S3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [28672 2023-11-15] (Microsoft Corporation)
S3 NdisWan; C:\Windows\System32\drivers\ndiswan.sys [208384 2024-05-16] (Microsoft Corporation)
S3 ndiswanlegacy; C:\Windows\System32\DRIVERS\ndiswan.sys [208384 2024-05-16] (Microsoft Corporation)
S3 ndproxy; C:\Windows\System32\DRIVERS\NDProxy.sys [93696 2023-11-15] (Microsoft Corporation)
S2 Ndu; C:\Windows\System32\drivers\Ndu.sys [131584 2019-12-07] (Microsoft Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [210944 2024-05-16] (Microsoft Corporation)
S1 NetBT; C:\Windows\System32\DRIVERS\netbt.sys [341504 2023-11-15] (Microsoft Corporation)
S1 netfilter2; C:\Windows\System32\drivers\netfilter2.sys [114104 2024-05-29] (Piriform Software Ltd -> Windows (R) Win 7 DDK provider)
S1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [48640 2023-11-15] (Microsoft Corporation)
S2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [823296 2024-04-09] (Microsoft Corporation)
S3 PNPMEM; C:\Windows\System32\drivers\pnpmem.sys [17408 2019-12-07] (Microsoft Corporation)
S3 PptpMiniport; C:\Windows\System32\drivers\raspptp.sys [105984 2023-11-15] (Microsoft Corporation)
S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [53248 2019-12-07] (Microsoft Corporation)
S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [20480 2023-11-15] (Microsoft Corporation)
S3 RasAgileVpn; C:\Windows\System32\drivers\AgileVpn.sys [115200 2024-05-16] (Microsoft Corporation)
S3 Rasl2tp; C:\Windows\System32\drivers\rasl2tp.sys [112640 2024-05-16] (Microsoft Corporation)
S3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [89088 2024-05-16] (Microsoft Corporation)
S3 RasSstp; C:\Windows\System32\drivers\rassstp.sys [87552 2023-11-15] (Microsoft Corporation)
S3 rdpbus; C:\Windows\System32\drivers\rdpbus.sys [28672 2019-12-07] (Microsoft Corporation)
S3 RDPDR; C:\Windows\System32\drivers\rdpdr.sys [170496 2024-05-16] (Microsoft Corporation)
S3 RFCOMM; C:\Windows\System32\drivers\rfcomm.sys [213504 2024-05-16] (Microsoft Corporation)
S3 rhproxy; C:\Windows\System32\drivers\rhproxy.sys [115712 2019-12-07] (Microsoft Corporation)
S2 rspndr; C:\Windows\System32\drivers\rspndr.sys [89088 2019-12-07] (Microsoft Corporation)
S3 scfilter; C:\Windows\System32\DRIVERS\scfilter.sys [44032 2025-03-12] (Microsoft Corporation)
S3 spaceparser; C:\Windows\System32\drivers\spaceparser.sys [26624 2019-12-07] (Microsoft Corporation)
S3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [786944 2025-03-12] (Microsoft Corporation)
S3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [318976 2024-05-16] (Microsoft Corporation)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 Synth3dVsc; C:\Windows\System32\drivers\Synth3dVsc.sys [6656 2023-11-15] (Microsoft Corporation)
S2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [56320 2024-05-16] (Microsoft Corporation)
S3 TsUsbFlt; C:\Windows\System32\drivers\tsusbflt.sys [66560 2019-12-07] (Microsoft Corporation)
S3 TsUsbGD; C:\Windows\System32\drivers\TsUsbGD.sys [37888 2023-11-15] (Microsoft Corporation)
S3 tunnel; C:\Windows\System32\drivers\tunnel.sys [129024 2023-11-15] (Microsoft Corporation)
S3 UcmCx0101; C:\Windows\System32\Drivers\UcmCx.sys [160256 2023-11-15] (Microsoft Corporation)
S3 UcmTcpciCx0101; C:\Windows\System32\Drivers\UcmTcpciCx.sys [188416 2019-12-07] (Microsoft Corporation)
S3 UcmUcsiAcpiClient; C:\Windows\System32\drivers\UcmUcsiAcpiClient.sys [36864 2019-12-07] (Microsoft Corporation)
S3 UcmUcsiCx0101; C:\Windows\System32\Drivers\UcmUcsiCx.sys [113152 2023-11-15] (Microsoft Corporation)
S1 UCPD; C:\Windows\System32\drivers\UCPD.sys [102400 2025-03-12] (Microsoft Corporation)
S4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [345088 2024-05-16] (Microsoft Corporation)
S3 usbaudio; C:\Windows\system32\drivers\usbaudio.sys [216576 2025-02-13] (Microsoft Corporation)
S3 usbaudio2; C:\Windows\System32\drivers\usbaudio2.sys [260608 2019-12-07] (Microsoft Corporation)
S3 usbcir; C:\Windows\System32\drivers\usbcir.sys [107520 2019-12-07] (Microsoft Corporation)
S3 usbohci; C:\Windows\System32\drivers\usbohci.sys [30208 2024-06-12] (Microsoft Corporation)
S3 usbprint; C:\Windows\System32\drivers\usbprint.sys [43008 2024-10-09] (Microsoft Corporation)
S3 usbser; C:\Windows\System32\drivers\usbser.sys [81408 2023-11-15] (Microsoft Corporation)
S3 usbuhci; C:\Windows\System32\drivers\usbuhci.sys [39424 2024-06-12] (Microsoft Corporation)
S3 VirtualRender; C:\Windows\System32\DriverStore\FileRepository\vrd.inf_amd64_81fbd405ff2470fc\vrd.sys [11264 2019-12-07] (Microsoft Corporation)
S1 vwififlt; C:\Windows\System32\drivers\vwififlt.sys [77824 2023-11-15] (Microsoft Corporation)
S2 wanarp; C:\Windows\System32\DRIVERS\wanarp.sys [93184 2023-11-15] (Microsoft Corporation)
S3 wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [93184 2023-11-15] (Microsoft Corporation)
S3 wcnfs; C:\Windows\system32\drivers\wcnfs.sys [93184 2023-11-15] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [20016 2025-03-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [601520 2025-03-12] (Microsoft Windows -> Microsoft Corporation)
S3 wdiwifi; C:\Windows\System32\DRIVERS\wdiwifi.sys [967168 2024-11-13] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [100768 2025-03-12] (Microsoft Windows -> Microsoft Corporation)
S3 WinNat; C:\Windows\System32\drivers\winnat.sys [261632 2025-03-12] (Microsoft Corporation)
S3 WINUSB; C:\Windows\System32\drivers\WinUsb.sys [107008 2019-12-07] (Microsoft Corporation)
S3 WSDPrintDevice; C:\Windows\System32\drivers\WSDPrint.sys [23552 2023-11-15] (Microsoft Corporation)
S3 WSDScan; C:\Windows\System32\drivers\WSDScan.sys [26112 2023-11-15] (Microsoft Corporation)
S3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [136192 2023-12-13] (Microsoft Corporation)
S3 WUDFRd; C:\Windows\System32\drivers\WUDFRd.sys [315904 2023-12-13] (Microsoft Corporation)
S3 WUDFWpdFs; C:\Windows\System32\drivers\WUDFRd.sys [315904 2023-12-13] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\Windows\System32\drivers\WUDFRd.sys [315904 2023-12-13] (Microsoft Corporation)
S3 xboxgip; C:\Windows\System32\drivers\xboxgip.sys [340480 2024-08-14] (Microsoft Corporation)
S3 xinputhid; C:\Windows\System32\drivers\xinputhid.sys [61952 2024-05-16] (Microsoft Corporation)
UpperFilters: [{4D36E967-E325-11CE-BFC1-08002BE10318}] -> [partmgr aswArDisk]

Code:

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-03-26 20:20 - 2020-10-10 11:32 - 000008192 ___SH C:\DumpStack.log.tmp
2025-03-26 18:59 - 2024-07-10 21:31 - 000000000 ____D C:\Windows\System32\compatrel
2025-03-26 18:59 - 2023-12-13 17:46 - 000000000 ____D C:\Windows\InboxApps
2025-03-26 18:59 - 2020-10-10 11:33 - 000000000 ____D C:\users\KiezPC
2025-03-26 18:59 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Portable Devices
2025-03-26 18:59 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-03-26 18:59 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2025-03-26 18:59 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2025-03-26 18:59 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-03-26 18:59 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2025-03-26 18:59 - 2019-12-07 15:51 - 000000000 ____D C:\Windows\System32\OpenSSH
2025-03-26 18:59 - 2019-12-07 15:50 - 000000000 ____D C:\Windows\SysWOW64\de
2025-03-26 18:59 - 2019-12-07 15:50 - 000000000 ____D C:\Windows\System32\de
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\SysWOW64\F12
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\System32\UNP
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\System32\F12
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\System32\dsc
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ___SD C:\Windows\System32\DiagSvcs
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\PrintDialog
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\migwiz
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\InstallShield
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\downlevel
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\Com
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemResources
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\WinMetadata
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\WinBioPlugIns
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\SystemResetPlatform
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\Sysprep
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\ShellExperiences
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\setup
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\PerceptionSimulation
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\oobe
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\migwiz
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\downlevel
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\Dism
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\DDFs
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\Com
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\AdvancedInstallers
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellExperiences
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ShellComponents
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\L2Schemas
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\IME
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\bcastdvr
2025-03-26 18:59 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2025-03-26 18:59 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF
2025-03-26 18:59 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\servicing
2025-03-26 18:58 - 2024-10-21 12:02 - 000000000 ____D C:\Program Files\AusweisApp
2025-03-26 18:58 - 2024-05-29 08:31 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2025-03-26 18:58 - 2024-05-29 08:30 - 000000000 ____D C:\Program Files (x86)\Kamo
2025-03-26 18:58 - 2023-10-12 10:26 - 000000000 ____D C:\Program Files\RUXIM
2025-03-26 18:58 - 2021-10-10 15:27 - 000000000 ____D C:\Windows\System32\Tasks\Mozilla
2025-03-26 18:58 - 2021-05-11 14:46 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2025-03-26 18:58 - 2020-09-25 13:55 - 000000000 ____D C:\Program Files\Mozilla Firefox
2025-03-26 18:58 - 2020-08-31 11:06 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2025-03-26 18:58 - 2020-04-14 09:42 - 000000000 ____D C:\Program Files\tiptoi® Manager
2025-03-26 18:58 - 2020-04-12 20:30 - 000000000 ____D C:\Program Files\DAEMON Tools Lite
2025-03-26 18:58 - 2020-04-12 20:29 - 000000000 ____D C:\ProgramData\DAEMON Tools Lite
2025-03-26 18:58 - 2020-04-12 20:27 - 000000000 ____D C:\Program Files\CCleaner
2025-03-26 18:58 - 2020-04-12 19:59 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\MUI
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\InputMethod
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SysWOW64\IME
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\SystemApps
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\MUI
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\InputMethod
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\IME
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\ServiceState
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\schemas
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\Containers
2025-03-26 18:58 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\Branding
2025-03-26 18:58 - 2019-12-07 10:03 - 000000000 ____D C:\Windows\CbsTemp
2025-03-26 18:57 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-03-26 18:56 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\Web
2025-03-26 18:56 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\registration
2025-03-26 18:55 - 2024-05-29 08:31 - 000000000 ____D C:\ProgramData\Avast Software
2025-03-26 18:55 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\System32\spool
2025-03-26 18:54 - 2020-04-12 20:27 - 000000000 ____D C:\Program Files (x86)\Google
2025-03-26 18:54 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-03-26 17:59 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-03-26 17:57 - 2023-05-13 08:10 - 000000000 ____D C:\Users\KiezPC\AppData\Local\Malwarebytes
2025-03-26 17:35 - 2020-04-12 19:55 - 000000000 ____D C:\Users\KiezPC\AppData\Local\D3DSCache
2025-03-26 17:31 - 2020-12-25 16:30 - 000000000 ____D C:\Users\KiezPC\AppData\Local\CrashDumps
2025-03-26 17:12 - 2020-10-10 11:32 - 000000000 ____D C:\Windows\System32\SleepStudy
2025-03-26 14:06 - 2022-06-29 19:05 - 000000000 _____ C:\Users\KiezPC\Documents\HPSmartPrintingPort
2025-03-26 14:06 - 2020-04-12 20:39 - 000000000 ____D C:\Users\KiezPC\AppData\Roaming\Microsoft\Word
2025-03-26 13:56 - 2021-12-17 22:59 - 000000000 ____D C:\Windows\SystemTemp
2025-03-26 13:50 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness
2025-03-26 11:40 - 2022-10-01 09:26 - 000003326 _____ C:\Windows\System32\Tasks\CCleanerCrashReporting
2025-03-26 11:40 - 2022-10-01 09:26 - 000000670 _____ C:\Windows\Tasks\CCleanerCrashReporting.job
2025-03-26 11:20 - 2020-10-10 11:39 - 001713046 _____ C:\Windows\System32\PerfStringBackup.INI
2025-03-26 11:20 - 2019-12-07 15:50 - 000739582 _____ C:\Windows\System32\perfh007.dat
2025-03-26 11:20 - 2019-12-07 15:50 - 000149214 _____ C:\Windows\System32\perfc007.dat
2025-03-26 11:19 - 2020-07-05 09:46 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-03-26 11:17 - 2025-02-07 08:09 - 000003572 _____ C:\Windows\System32\Tasks\OneDrive Startup Task-S-1-5-21-1337375207-2760412818-246081271-1001
2025-03-26 11:17 - 2021-12-11 15:02 - 000003588 _____ C:\Windows\System32\Tasks\OneDrive Reporting Task-S-1-5-21-1337375207-2760412818-246081271-1001
2025-03-26 11:17 - 2020-10-16 16:33 - 000003362 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1337375207-2760412818-246081271-1001
2025-03-26 11:17 - 2020-04-12 19:23 - 000000000 __RDL C:\Users\KiezPC\OneDrive
2025-03-26 11:14 - 2024-05-29 08:31 - 000000000 ____D C:\Windows\System32\Tasks\Kamo
2025-03-26 11:14 - 2024-05-29 08:31 - 000000000 ____D C:\Users\KiezPC\AppData\Local\Kamo
2025-03-26 11:13 - 2024-05-29 08:31 - 000000000 ____D C:\Windows\System32\Tasks\Avast Software
2025-03-26 11:13 - 2020-10-10 11:37 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-03-26 11:13 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\appcompat
2025-03-22 18:50 - 2020-04-12 19:20 - 000000000 ____D C:\Users\KiezPC\AppData\Local\Packages
2025-03-19 22:15 - 2019-12-07 10:03 - 000524288 _____ C:\Windows\System32\config\BBI
2025-03-16 17:42 - 2020-05-17 17:32 - 000000000 ____D C:\Users\KiezPC\AppData\Roaming\Sky Go
2025-03-16 17:24 - 2020-04-12 21:09 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2025-03-16 17:23 - 2020-04-14 15:42 - 000000000 ____D C:\Program Files\Microsoft Office
2025-03-12 22:46 - 2022-12-24 10:39 - 000002198 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-03-12 17:59 - 2020-10-10 11:32 - 000562208 _____ C:\Windows\System32\FNTCACHE.DAT
2025-03-12 17:42 - 2020-10-10 11:32 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2025-03-12 16:24 - 2020-04-12 19:18 - 000000000 ____D C:\Windows\System32\Drivers\wd
2025-03-08 14:19 - 2022-02-11 17:37 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2025-03-08 13:06 - 2020-05-13 17:18 - 000000000 ____D C:\Users\KiezPC\AppData\Roaming\Zoom
2025-03-07 09:48 - 2024-10-22 18:58 - 000004252 _____ C:\Windows\System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-1337375207-2760412818-246081271-1001
2025-03-07 09:48 - 2020-10-10 11:37 - 000003756 _____ C:\Windows\System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-03-07 09:48 - 2020-10-10 11:37 - 000003632 _____ C:\Windows\System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-03-06 21:03 - 2020-04-13 13:22 - 000000000 ____D C:\Users\KiezPC\AppData\Local\HP
2025-03-05 17:12 - 2020-10-28 17:19 - 000000000 ____D C:\Windows\System32\Tasks\HP
2025-03-05 17:08 - 2020-10-10 11:37 - 000004242 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1600783933
2025-03-01 11:44 - 2024-05-29 08:31 - 000055064 _____ (Gen Digital Inc.) C:\Windows\System32\icarus_rvrt.exe
2025-03-01 11:44 - 2024-05-29 08:31 - 000000000 ____D C:\Program Files\Avast Software
2025-03-01 11:40 - 2020-10-10 11:37 - 000003936 _____ C:\Windows\System32\Tasks\CCleaner Update

==================== KnownDLLs (Whitelisted) =========================


==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe
[2025-03-12 17:42] - [2025-03-12 17:42] - 000947200 _____ (Microsoft Corporation) BF603F3431972F06AD872E2EFD094FC7

C:\Windows\System32\wininit.exe
[2025-03-12 17:42] - [2025-03-12 17:42] - 000447912 _____ (Microsoft Corporation) 3D9E9EADD22BC5506CCA695BEB81C025

C:\Windows\explorer.exe
[2025-03-12 17:42] - [2025-03-12 17:42] - 005973416 _____ (Microsoft Corporation) BB2D295107DEF151E66E0F47939EF07A

C:\Windows\SysWOW64\explorer.exe
[2025-03-12 17:42] - [2025-03-12 17:42] - 005250824 _____ (Microsoft Corporation) C4CDCFA9F85B3CDE4198877A1ACE1630

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll
[2025-03-12 17:42] - [2025-03-12 17:42] - 001684400 _____ (Microsoft Corporation) 6D3EC7BBEF43FD3F02B9B6C4B8E0DCCB

C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2025-02-13 12:43] - [2025-02-13 12:43] - 001324032 _____ (Microsoft Corporation) A7F866C93819793188DF044391EA7E85

C:\Windows\System32\dnsapi.dll
[2025-01-15 18:36] - [2025-01-15 18:36] - 000821912 _____ (Microsoft Corporation) 0797A5FE041E8E861F4BFE5DF0A35E6E

C:\Windows\SysWOW64\dnsapi.dll
[2025-01-15 18:36] - [2025-01-15 18:36] - 000583768 _____ (Microsoft Corporation) 7C31C466DB21218EA7E17E9A1A2FE0F1

C:\Windows\System32\dllhost.exe => MD5 is legit
C:\Windows\SysWOW64\dllhost.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Association (Whitelisted) =============


==================== Restore Points  =========================

Restore point date: 2025-03-26 17:24
Restore point date: 2025-03-26 18:56

==================== Memory info ===========================

Percentage of memory in use: 18%
Total physical RAM: 6072.74 MB
Available physical RAM: 4978.36 MB
Total Virtual: 6072.74 MB
Available Virtual: 5028.75 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:237.87 GB) (Free:119.9 GB) (Model: SAMSUNG MZVLB256HAHQ-00000) NTFS
Drive g: (Wiederherstellung) (Fixed) (Total:0.49 GB) (Free:0.05 GB) (Model: SAMSUNG MZVLB256HAHQ-00000) NTFS
Drive h: (INTENSO) (Removable) (Total:14.45 GB) (Free:13.61 GB) exFAT
Drive x: (Boot) (Fixed) (Total:0.5 GB) (Free:0.49 GB) NTFS
Drive y: (Sicherung) (Fixed) (Total:1863 GB) (Free:1072.54 GB) (Model: WDC WD20EZRZ-00Z5HB0) NTFS

\\?\Volume{59ea9296-6720-42f9-b74b-1dff1e12bfbe}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 1863 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Size: 238.5 GB) (Disk ID: 973FCF4E)

Partition: GPT.

==========================================================
Disk: 3 (Protective MBR) (Size: 14.5 GB) (Disk ID: 00000000)

Partition: GPT.
==================== End of FRST.txt ========================


cosinus 27.03.2025 23:51

Also mit Schädlingsbefall hat das Ganze nix zu tun, aber ich sehe da mindestens zwei Programme, die völlig unsinnig sind: avast und ccleaner
Beide Programme haben das Potential, Windows zu zerstören.
Startet Windows noch im abgesicherten Modus?

bluemooon 30.03.2025 21:56

Oh Mist, ich meine, die haben wir schon immer auf dem PC...
Abgesicherter Modus funktioniert leider auch nicht mehr.

cosinus 30.03.2025 22:42

Dann macht das Ganze so keinen Sinn mehr.
Ich würde mal die Festplatte/SSD ausbauen und an einem funktionieren Rechner anschließen, da kann man dann noch ungesicherte Dateien kopieren und auch mal prüfen, ob die Disk überhaupt noch i.O. ist. Geht zB mit Crystal Disk Info.

bluemooon 31.03.2025 18:22

:wtf:Lieber Cosinus,

danke für die Tipps.
Mein Mann sagte, er kommt nun doch ins BIOS :wtf:

Ich meine ich habe den damaligen Windowsschlüssel für zwei Endgeräte gekauft. Solle ich dann vom anderen Endgerät (Laptop) eine Bootdatei auf einen Stick ziehen und es damit versuchen zu reparieren? Oder hast du noch einenanderen Tipp?

cosinus 31.03.2025 20:22

Es wurde doch geschrieben was du machen sollst: Disk ausbauen, versuchen Daten zu sichern und mit Crystal Disk Info schauen ob die Disk überhaupt noch in Ordnung.
Dass du ins BIOS kommt hilft da so genau garnichts, denn dadurch erfährt niemand den Status der Platte.

cosinus 31.03.2025 20:23

Es wurde doch geschrieben was du machen sollst: Disk ausbauen, versuchen Daten zu sichern und mit Crystal Disk Info schauen ob die Disk überhaupt noch in Ordnung.
Dass du ins BIOS kommt hilft da so genau garnichts, denn dadurch erfährt niemand den Status der Platte.


Alle Zeitangaben in WEZ +1. Es ist jetzt 01:38 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131