Fix result of Farbar Recovery Scan Tool (x64) Version: 13-03-2026 01 Ran by hanna (13-03-2026 09:27:49) Run:1 Running from C:\Users\hanna\Downloads Loaded Profiles: hanna Boot Mode: Normal ============================================== fixlist content: ***************** Start:: CreateRestorePoint: CloseProcesses: HKLM\...\Run: [RZTHXHelper] => C:\Windows\system32\RZTHXHelper.exe (No File) HKU\S-1-5-21-3899324243-3341298170-2364891810-1001\...\Winlogon: [Shell] C:\Windows\explorer.exe [6089584 2025-10-17] (Microsoft Windows -> Microsoft Corporation) S2 WslInstaller; C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_2.6.3.0_x64__8wekyb3d8bbwe\wslinstaller.exe [X] S3 EAAntiCheat; system32\drivers\eaanticheat.sys [X] FirewallRules: [{23BC02F7-C9C3-4E42-99BE-BA1E483F6E94}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [{A80C6A9B-DB02-490D-9287-6A73B7C02136}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [TCP Query User{4C013C7E-4EA8-41D0-9880-7CAFF7694A8D}C:\xboxgames\the elder scrolls iv- oblivion remastered\content\oblivionremastered\binaries\wingdk\oblivionremastered-wingdk-shipping.exe] => (Allow) C:\xboxgames\the elder scrolls iv- oblivion remastered\content\oblivionremastered\binaries\wingdk\oblivionremastered-wingdk-shipping.exe => No File FirewallRules: [UDP Query User{2D6E57DF-289E-4B7D-AFFD-90A2E2EDF1E4}C:\xboxgames\the elder scrolls iv- oblivion remastered\content\oblivionremastered\binaries\wingdk\oblivionremastered-wingdk-shipping.exe] => (Allow) C:\xboxgames\the elder scrolls iv- oblivion remastered\content\oblivionremastered\binaries\wingdk\oblivionremastered-wingdk-shipping.exe => No File FirewallRules: [TCP Query User{E29ED08C-46EB-465C-9A37-2D1542292EE2}C:\xboxgames\clair obscur- expedition 33\content\sandfall\binaries\wingdk\sandfall-wingdk-shipping.exe] => (Allow) C:\xboxgames\clair obscur- expedition 33\content\sandfall\binaries\wingdk\sandfall-wingdk-shipping.exe => No File FirewallRules: [UDP Query User{DC0C542E-BA5F-4855-A06F-535CE635C1EC}C:\xboxgames\clair obscur- expedition 33\content\sandfall\binaries\wingdk\sandfall-wingdk-shipping.exe] => (Allow) C:\xboxgames\clair obscur- expedition 33\content\sandfall\binaries\wingdk\sandfall-wingdk-shipping.exe => No File FirewallRules: [TCP Query User{1CF340F8-A470-46F5-AE11-CB2EEE8CB165}C:\xboxgames\the alters\content\thealters\binaries\wingdk\thealters-wingdk-shipping.exe] => (Allow) C:\xboxgames\the alters\content\thealters\binaries\wingdk\thealters-wingdk-shipping.exe => No File FirewallRules: [UDP Query User{C5057A72-F5EE-4D81-B745-3878240A9165}C:\xboxgames\the alters\content\thealters\binaries\wingdk\thealters-wingdk-shipping.exe] => (Allow) C:\xboxgames\the alters\content\thealters\binaries\wingdk\thealters-wingdk-shipping.exe => No File FirewallRules: [{AD4AD392-DFF2-41F5-9E83-CF44AE4C1FC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ready Or Not\Engine\Binaries\Win64\CrashReporter.exe => No File FirewallRules: [{6A40C635-BB1B-43F6-8844-BA0D84E5A3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ready Or Not\Engine\Binaries\Win64\CrashReporter.exe => No File FirewallRules: [{D2495A51-C5BC-4A66-BFB8-CA0C607B52CE}] => (Allow) C:\XboxGames\Splitgate 2\Content\PortalWars2\Binaries\WinGDK\PortalWars2Client-WinGDK-Shipping.exe => No File FirewallRules: [{7C0CF16A-FC7E-489F-96C4-3E244B6BD960}] => (Allow) C:\XboxGames\Splitgate 2\Content\PortalWars2\Binaries\WinGDK\PortalWars2Client-WinGDK-Shipping.exe => No File FirewallRules: [TCP Query User{9302336D-67A6-496E-85CC-0C4D7F02878D}C:\xboxgames\avowed\content\alabama\binaries\wingdk\avowed-wingdk-shipping.exe] => (Allow) C:\xboxgames\avowed\content\alabama\binaries\wingdk\avowed-wingdk-shipping.exe => No File FirewallRules: [UDP Query User{CE626008-BC27-48F3-A0AE-289130ABA4D7}C:\xboxgames\avowed\content\alabama\binaries\wingdk\avowed-wingdk-shipping.exe] => (Allow) C:\xboxgames\avowed\content\alabama\binaries\wingdk\avowed-wingdk-shipping.exe => No File FirewallRules: [TCP Query User{A492C20A-DAC6-4648-B3B5-236B06B1D652}C:\xboxgames\grounded 2\content\augusta\binaries\wingdk\grounded2-wingdk-shipping.exe] => (Allow) C:\xboxgames\grounded 2\content\augusta\binaries\wingdk\grounded2-wingdk-shipping.exe => No File FirewallRules: [UDP Query User{A49CF599-7723-4324-8209-D048C97DEDA7}C:\xboxgames\grounded 2\content\augusta\binaries\wingdk\grounded2-wingdk-shipping.exe] => (Allow) C:\xboxgames\grounded 2\content\augusta\binaries\wingdk\grounded2-wingdk-shipping.exe => No File FirewallRules: [TCP Query User{32AFF1BE-90DD-4427-A459-48792271749C}C:\program files (x86)\steam\steamapps\common\abioticfactor\abioticfactor\binaries\win64\abioticfactor-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\abioticfactor\abioticfactor\binaries\win64\abioticfactor-win64-shipping.exe => No File FirewallRules: [UDP Query User{C4119982-90EB-4A1C-8C3E-6A3A7DAEF8B4}C:\program files (x86)\steam\steamapps\common\abioticfactor\abioticfactor\binaries\win64\abioticfactor-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\abioticfactor\abioticfactor\binaries\win64\abioticfactor-win64-shipping.exe => No File FirewallRules: [{3C8215FC-BC09-4018-9D99-AD791B8BE407}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project Rogueteers\launcher\rs_launcher.exe => No File FirewallRules: [{4A134686-0428-405D-B0F8-B8DD278B2B7A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project Rogueteers\launcher\rs_launcher.exe => No File FirewallRules: [TCP Query User{1016152E-0C69-4544-B851-62CCC4B409C5}C:\program files (x86)\steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe => No File FirewallRules: [UDP Query User{CCACA6F0-EC30-43BC-8F90-ADA45360D12C}C:\program files (x86)\steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe => No File FirewallRules: [TCP Query User{1A82490A-ADA7-47D2-B67A-E3D07DC47F3D}C:\program files (x86)\steam\steamapps\common\glacier events\bf6event.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\glacier events\bf6event.exe => No File FirewallRules: [UDP Query User{585D50CE-254F-45B6-B729-392442C6869E}C:\program files (x86)\steam\steamapps\common\glacier events\bf6event.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\glacier events\bf6event.exe => No File FirewallRules: [TCP Query User{9CB0E7E4-5841-47FA-92A5-F98374F4DFA1}E:\xbox\sea of thieves\content\athena\binaries\wingdk\sotgame.exe] => (Allow) E:\xbox\sea of thieves\content\athena\binaries\wingdk\sotgame.exe => No File FirewallRules: [UDP Query User{F9D7E8B5-3491-4A39-89A3-0BDFDB0381C4}E:\xbox\sea of thieves\content\athena\binaries\wingdk\sotgame.exe] => (Allow) E:\xbox\sea of thieves\content\athena\binaries\wingdk\sotgame.exe => No File FirewallRules: [TCP Query User{590BE86B-6F6F-46F2-B2AF-7AA0D974501B}C:\program files\ea games\skate\skate.exe] => (Allow) C:\program files\ea games\skate\skate.exe => No File FirewallRules: [UDP Query User{2B18D393-3F66-4CE1-B1CA-974F5B05F068}C:\program files\ea games\skate\skate.exe] => (Allow) C:\program files\ea games\skate\skate.exe => No File FirewallRules: [{D5145303-1DDD-402C-AB3E-6922C6DFF88D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SMITE 2\Windows\Hemingway.exe => No File FirewallRules: [{E24511A8-BEF9-4C05-8F5C-FF7B6472F43D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SMITE 2\Windows\Hemingway.exe => No File FirewallRules: [TCP Query User{1BF44B3B-46A7-48F9-B64B-8FAC7C6DB6CC}C:\program files (x86)\steam\steamapps\common\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Block) C:\program files (x86)\steam\steamapps\common\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File FirewallRules: [UDP Query User{CC412032-4C84-4AA4-BF4B-A0600C9AEB13}C:\program files (x86)\steam\steamapps\common\cyberpunk 2077\bin\x64\cyberpunk2077.exe] => (Block) C:\program files (x86)\steam\steamapps\common\cyberpunk 2077\bin\x64\cyberpunk2077.exe => No File FirewallRules: [{81AE87FD-F039-4598-AB06-C530B47215AF}] => (Allow) C:\Program Files\EA Games\Skate\EAAntiCheat.GameServiceLauncher.exe => No File FirewallRules: [{A68513C7-495D-4A6C-A8AB-537BFD12DF91}] => (Allow) C:\Program Files\EA Games\Skate\EAAntiCheat.GameServiceLauncher.exe => No File FirewallRules: [TCP Query User{30A1536B-09A3-4492-BDB3-6282E78D6A06}C:\program files (x86)\steam\steamapps\common\skate\skate.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\skate\skate.exe => No File FirewallRules: [UDP Query User{0BB9B621-7644-43A3-9E9B-C9AAA72E80C5}C:\program files (x86)\steam\steamapps\common\skate\skate.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\skate\skate.exe => No File FirewallRules: [TCP Query User{CD809434-3655-4721-8628-543AF00372A9}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe => No File FirewallRules: [UDP Query User{C06629DE-4912-4795-B372-167D6A1D04DD}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe => No File FirewallRules: [{7C7E8990-4A10-40B7-BBA0-052850E9B1C0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dying Light\DevTools\DyingLightPlayer.exe => No File FirewallRules: [{7E6D06EF-2E9F-47AD-B87B-046339742F7D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dying Light\DevTools\DyingLightPlayer.exe => No File FirewallRules: [TCP Query User{F5878907-147B-4A7F-A1B3-6C2E9561BA88}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe => No File FirewallRules: [UDP Query User{9072456D-928C-4F9A-9E61-B3C869A9B225}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe => No File FirewallRules: [TCP Query User{583A690A-AF6C-486E-97B9-7FCCF29A3B0F}C:\program files (x86)\steam\steamapps\common\battlefield 6\bf6.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\battlefield 6\bf6.exe => No File FirewallRules: [UDP Query User{1D97B5E1-7A5F-41AE-AE4B-8EE37B313FDA}C:\program files (x86)\steam\steamapps\common\battlefield 6\bf6.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\battlefield 6\bf6.exe => No File FirewallRules: [TCP Query User{4A6BE6D1-1B28-4BD7-BD7E-C98F209D6CB6}C:\program files (x86)\steam\steamapps\common\battlefield 6\sp\bf6.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\battlefield 6\sp\bf6.exe => No File FirewallRules: [UDP Query User{2067C151-C9BE-4A4E-9253-2237BF3BA4E6}C:\program files (x86)\steam\steamapps\common\battlefield 6\sp\bf6.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\battlefield 6\sp\bf6.exe => No File FirewallRules: [TCP Query User{FF70E886-0235-4697-81CC-45BFB55ABC35}C:\program files (x86)\steam\steamapps\common\arc raiders playtest\pioneergame\binaries\win64\pioneergame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\arc raiders playtest\pioneergame\binaries\win64\pioneergame.exe => No File FirewallRules: [UDP Query User{2C8F3B00-806A-4BA2-8095-6CA2AFA580CE}C:\program files (x86)\steam\steamapps\common\arc raiders playtest\pioneergame\binaries\win64\pioneergame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\arc raiders playtest\pioneergame\binaries\win64\pioneergame.exe => No File FirewallRules: [TCP Query User{E0518EE6-3D70-4BFC-9AAF-398ECB1D56B0}C:\program files (x86)\steam\steamapps\common\theouterworlds2\arkansas\binaries\win64\theouterworlds2-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\theouterworlds2\arkansas\binaries\win64\theouterworlds2-win64-shipping.exe => No File FirewallRules: [UDP Query User{37DFE1F7-E031-4C17-8CC2-83C85CA9C513}C:\program files (x86)\steam\steamapps\common\theouterworlds2\arkansas\binaries\win64\theouterworlds2-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\theouterworlds2\arkansas\binaries\win64\theouterworlds2-win64-shipping.exe => No File FirewallRules: [{381DA883-2F2D-470B-B766-594D995623A7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DARK SOULS III\Game\DarkSoulsIII.exe => No File FirewallRules: [{B0A90683-9F53-40E2-8D91-3EBF13234F8B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DARK SOULS III\Game\DarkSoulsIII.exe => No File FirewallRules: [{AA10CE62-6C79-4FC5-9666-E806B080B585}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dark Souls II\Game\DarkSoulsII.exe => No File FirewallRules: [{4A6403A6-2F58-438A-A121-A796F619328A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dark Souls II\Game\DarkSoulsII.exe => No File FirewallRules: [{071D870C-2595-41B1-84AE-6942209DDA0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Everything is Crab Playtest\Everything is Crab.exe => No File FirewallRules: [{9C4F24EA-BC1D-4A18-A400-60ED2921B272}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Everything is Crab Playtest\Everything is Crab.exe => No File 2026-02-26 09:07 - 2026-02-26 09:07 - 000129904 _____ C:\ProgramData\agent.uninstall.1772114829.bdinstall.v2.bin 2026-02-26 09:06 - 2026-02-26 09:06 - 000473476 _____ C:\ProgramData\cl.uninstall.1772114644.bdinstall.v2.bin 2026-02-26 08:52 - 2026-02-26 08:52 - 000695912 _____ C:\ProgramData\cl.1772113385.bdinstall.v2.bin 2026-02-26 08:52 - 2026-02-26 08:52 - 000136552 _____ C:\ProgramData\cl.kit.1772113384.bdinstall.v2.bin 2026-02-26 08:51 - 2026-02-26 08:51 - 000000000 ____D C:\ProgramData\48C4687D-9760-4F5B-BAB3-60351B0841E4 2026-02-26 08:50 - 2026-02-26 09:04 - 000000000 ____D C:\ProgramData\BDLogging 2026-02-26 08:46 - 2026-02-26 08:46 - 000000000 ____D C:\Users\hanna\AppData\Roaming\Bitdefender Security App 2026-02-26 08:43 - 2026-03-07 23:36 - 000000000 ____D C:\Program Files\Bitdefender 2026-02-26 08:43 - 2026-02-26 09:06 - 000000000 ____D C:\ProgramData\Bitdefender 2026-02-26 08:41 - 2026-02-26 08:41 - 000223484 _____ C:\ProgramData\agent.1772113297.bdinstall.v2.bin 2026-02-26 08:41 - 2026-02-26 08:41 - 000000000 ____D C:\ProgramData\Bitdefender Agent cmd: reg query HKCU\Software\Classes\CLSID\{18907f3b-9afb-4f87-b764-f9a4e16a21b8} /s StartRegedit: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=dword:00000005 "ConsentPromptBehaviorUser"=dword:00000003 "EnableLUA"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer] "SmartScreenEnabled"="Warn" [-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Extensions] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Processes] [-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction] EndRegedit: StartPowershell: C:\Windows\SysWOW64\lodctr.exe /R C:\Windows\System32\lodctr.exe /R winmgmt.exe /resyncperf Get-MpPreference | fl Get-MpComputerStatus | fl & "C:\Program Files\Windows Defender\MpCmdRun.exe" -SignatureUpdate -MMPC EndPowershell: EmptyTemp: End:: ***************** CreateRestorePoint: Error(1=9%) -> Failed to create a restore point. Processes closed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\RZTHXHelper" => removed successfully "HKU\S-1-5-21-3899324243-3341298170-2364891810-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell" => removed successfully HKLM\System\CurrentControlSet\Services\WslInstaller => removed successfully WslInstaller => service removed successfully HKLM\System\CurrentControlSet\Services\EAAntiCheat => removed successfully EAAntiCheat => service removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{23BC02F7-C9C3-4E42-99BE-BA1E483F6E94}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A80C6A9B-DB02-490D-9287-6A73B7C02136}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{4C013C7E-4EA8-41D0-9880-7CAFF7694A8D}C:\xboxgames\the elder scrolls iv- oblivion remastered\content\oblivionremastered\binaries\wingdk\oblivionremastered-wingdk-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2D6E57DF-289E-4B7D-AFFD-90A2E2EDF1E4}C:\xboxgames\the elder scrolls iv- oblivion remastered\content\oblivionremastered\binaries\wingdk\oblivionremastered-wingdk-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E29ED08C-46EB-465C-9A37-2D1542292EE2}C:\xboxgames\clair obscur- expedition 33\content\sandfall\binaries\wingdk\sandfall-wingdk-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{DC0C542E-BA5F-4855-A06F-535CE635C1EC}C:\xboxgames\clair obscur- expedition 33\content\sandfall\binaries\wingdk\sandfall-wingdk-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1CF340F8-A470-46F5-AE11-CB2EEE8CB165}C:\xboxgames\the alters\content\thealters\binaries\wingdk\thealters-wingdk-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C5057A72-F5EE-4D81-B745-3878240A9165}C:\xboxgames\the alters\content\thealters\binaries\wingdk\thealters-wingdk-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AD4AD392-DFF2-41F5-9E83-CF44AE4C1FC8}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6A40C635-BB1B-43F6-8844-BA0D84E5A3E6}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D2495A51-C5BC-4A66-BFB8-CA0C607B52CE}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7C0CF16A-FC7E-489F-96C4-3E244B6BD960}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{9302336D-67A6-496E-85CC-0C4D7F02878D}C:\xboxgames\avowed\content\alabama\binaries\wingdk\avowed-wingdk-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{CE626008-BC27-48F3-A0AE-289130ABA4D7}C:\xboxgames\avowed\content\alabama\binaries\wingdk\avowed-wingdk-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{A492C20A-DAC6-4648-B3B5-236B06B1D652}C:\xboxgames\grounded 2\content\augusta\binaries\wingdk\grounded2-wingdk-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{A49CF599-7723-4324-8209-D048C97DEDA7}C:\xboxgames\grounded 2\content\augusta\binaries\wingdk\grounded2-wingdk-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{32AFF1BE-90DD-4427-A459-48792271749C}C:\program files (x86)\steam\steamapps\common\abioticfactor\abioticfactor\binaries\win64\abioticfactor-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C4119982-90EB-4A1C-8C3E-6A3A7DAEF8B4}C:\program files (x86)\steam\steamapps\common\abioticfactor\abioticfactor\binaries\win64\abioticfactor-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3C8215FC-BC09-4018-9D99-AD791B8BE407}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4A134686-0428-405D-B0F8-B8DD278B2B7A}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1016152E-0C69-4544-B851-62CCC4B409C5}C:\program files (x86)\steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{CCACA6F0-EC30-43BC-8F90-ADA45360D12C}C:\program files (x86)\steam\steamapps\common\the finals\discovery\binaries\win64\discovery.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1A82490A-ADA7-47D2-B67A-E3D07DC47F3D}C:\program files (x86)\steam\steamapps\common\glacier events\bf6event.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{585D50CE-254F-45B6-B729-392442C6869E}C:\program files (x86)\steam\steamapps\common\glacier events\bf6event.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{9CB0E7E4-5841-47FA-92A5-F98374F4DFA1}E:\xbox\sea of thieves\content\athena\binaries\wingdk\sotgame.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{F9D7E8B5-3491-4A39-89A3-0BDFDB0381C4}E:\xbox\sea of thieves\content\athena\binaries\wingdk\sotgame.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{590BE86B-6F6F-46F2-B2AF-7AA0D974501B}C:\program files\ea games\skate\skate.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2B18D393-3F66-4CE1-B1CA-974F5B05F068}C:\program files\ea games\skate\skate.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D5145303-1DDD-402C-AB3E-6922C6DFF88D}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E24511A8-BEF9-4C05-8F5C-FF7B6472F43D}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1BF44B3B-46A7-48F9-B64B-8FAC7C6DB6CC}C:\program files (x86)\steam\steamapps\common\cyberpunk 2077\bin\x64\cyberpunk2077.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{CC412032-4C84-4AA4-BF4B-A0600C9AEB13}C:\program files (x86)\steam\steamapps\common\cyberpunk 2077\bin\x64\cyberpunk2077.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{81AE87FD-F039-4598-AB06-C530B47215AF}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A68513C7-495D-4A6C-A8AB-537BFD12DF91}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{30A1536B-09A3-4492-BDB3-6282E78D6A06}C:\program files (x86)\steam\steamapps\common\skate\skate.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{0BB9B621-7644-43A3-9E9B-C9AAA72E80C5}C:\program files (x86)\steam\steamapps\common\skate\skate.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{CD809434-3655-4721-8628-543AF00372A9}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C06629DE-4912-4795-B372-167D6A1D04DD}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7C7E8990-4A10-40B7-BBA0-052850E9B1C0}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7E6D06EF-2E9F-47AD-B87B-046339742F7D}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{F5878907-147B-4A7F-A1B3-6C2E9561BA88}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9072456D-928C-4F9A-9E61-B3C869A9B225}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{583A690A-AF6C-486E-97B9-7FCCF29A3B0F}C:\program files (x86)\steam\steamapps\common\battlefield 6\bf6.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{1D97B5E1-7A5F-41AE-AE4B-8EE37B313FDA}C:\program files (x86)\steam\steamapps\common\battlefield 6\bf6.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{4A6BE6D1-1B28-4BD7-BD7E-C98F209D6CB6}C:\program files (x86)\steam\steamapps\common\battlefield 6\sp\bf6.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2067C151-C9BE-4A4E-9253-2237BF3BA4E6}C:\program files (x86)\steam\steamapps\common\battlefield 6\sp\bf6.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FF70E886-0235-4697-81CC-45BFB55ABC35}C:\program files (x86)\steam\steamapps\common\arc raiders playtest\pioneergame\binaries\win64\pioneergame.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2C8F3B00-806A-4BA2-8095-6CA2AFA580CE}C:\program files (x86)\steam\steamapps\common\arc raiders playtest\pioneergame\binaries\win64\pioneergame.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E0518EE6-3D70-4BFC-9AAF-398ECB1D56B0}C:\program files (x86)\steam\steamapps\common\theouterworlds2\arkansas\binaries\win64\theouterworlds2-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{37DFE1F7-E031-4C17-8CC2-83C85CA9C513}C:\program files (x86)\steam\steamapps\common\theouterworlds2\arkansas\binaries\win64\theouterworlds2-win64-shipping.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{381DA883-2F2D-470B-B766-594D995623A7}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B0A90683-9F53-40E2-8D91-3EBF13234F8B}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AA10CE62-6C79-4FC5-9666-E806B080B585}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4A6403A6-2F58-438A-A121-A796F619328A}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{071D870C-2595-41B1-84AE-6942209DDA0D}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9C4F24EA-BC1D-4A18-A400-60ED2921B272}" => removed successfully C:\ProgramData\agent.uninstall.1772114829.bdinstall.v2.bin => moved successfully C:\ProgramData\cl.uninstall.1772114644.bdinstall.v2.bin => moved successfully C:\ProgramData\cl.1772113385.bdinstall.v2.bin => moved successfully C:\ProgramData\cl.kit.1772113384.bdinstall.v2.bin => moved successfully "C:\ProgramData\48C4687D-9760-4F5B-BAB3-60351B0841E4" Folder move: C:\ProgramData\48C4687D-9760-4F5B-BAB3-60351B0841E4 => moved successfully "C:\ProgramData\BDLogging" Folder move: C:\ProgramData\BDLogging => moved successfully "C:\Users\hanna\AppData\Roaming\Bitdefender Security App" Folder move: C:\Users\hanna\AppData\Roaming\Bitdefender Security App => moved successfully "C:\Program Files\Bitdefender" Folder move: C:\Program Files\Bitdefender => moved successfully "C:\ProgramData\Bitdefender" Folder move: C:\ProgramData\Bitdefender => moved successfully C:\ProgramData\agent.1772113297.bdinstall.v2.bin => moved successfully "C:\ProgramData\Bitdefender Agent" Folder move: C:\ProgramData\Bitdefender Agent => moved successfully ========= reg query HKCU\Software\Classes\CLSID\{18907f3b-9afb-4f87-b764-f9a4e16a21b8} /s ========= ERROR: The system was unable to find the specified registry key or value. ========= End of CMD: ========= The operation completed successfully. Registry ====> The operation completed successfully. ========= Powershell: ========= Error: Unable to rebuild performance counter setting from system backup store, error code is 5 Error: Unable to rebuild performance counter setting from system backup store, error code is 5 AllowDatagramProcessingOnWinServer : False AllowNetworkProtectionDownLevel : False AllowNetworkProtectionOnWinServer : False AllowSwitchToAsyncInspection : True ApplyDisableNetworkScanningToIOAV : False AttackSurfaceReductionOnlyExclusions : AttackSurfaceReductionRules_Actions : AttackSurfaceReductionRules_Ids : AttackSurfaceReductionRules_RuleSpecificExclusions : AttackSurfaceReductionRules_RuleSpecificExclusions_Id : BruteForceProtectionAggressiveness : 0 BruteForceProtectionConfiguredState : 0 BruteForceProtectionExclusions : BruteForceProtectionLocalNetworkBlocking : False BruteForceProtectionMaxBlockTime : 0 BruteForceProtectionSkipLearningPeriod : False CheckForSignaturesBeforeRunningScan : False CloudBlockLevel : 0 CloudExtendedTimeout : 0 ComputerID : 56A64B05-1A92-4D29-AE02-A3E7E25877AB ControlledFolderAccessAllowedApplications : ControlledFolderAccessDefaultProtectedFolders : {C:\Users\hanna\Documents, C:\Users\Public\Documents, C:\Users\hanna\Pictures, C:\Users\Public\Pictures...} ControlledFolderAccessProtectedFolders : {C:\Windows} DefinitionUpdatesChannel : 0 DisableArchiveScanning : False DisableAutoExclusions : False DisableBehaviorMonitoring : False DisableBlockAtFirstSeen : False DisableCacheMaintenance : False DisableCatchupFullScan : True DisableCatchupQuickScan : True DisableCoreServiceECSIntegration : False DisableCoreServiceTelemetry : False DisableCpuThrottleOnIdleScans : True DisableDatagramProcessing : False DisableDnsOverTcpParsing : False DisableDnsParsing : False DisableEmailScanning : True DisableFtpParsing : False DisableGradualRelease : False DisableHttpParsing : False DisableInboundConnectionFiltering : False DisableIOAVProtection : False DisableNetworkProtectionPerfTelemetry : False DisablePrivacyMode : False DisableQuicParsing : True DisableRdpParsing : False DisableRealtimeMonitoring : False DisableRemovableDriveScanning : True DisableRestorePoint : True DisableScanningMappedNetworkDrivesForFullScan : True DisableScanningNetworkFiles : False DisableScriptScanning : False DisableSmtpParsing : False DisableSshParsing : False DisableTamperProtection : False DisableTlsParsing : False EnableControlledFolderAccess : 1 EnableConvertWarnToBlock : False EnableDnsSinkhole : True EnableFileHashComputation : False EnableFullScanOnBatteryPower : False EnableLowCpuPriority : False EnableNetworkProtection : 0 EnableUdpReceiveOffload : False EnableUdpSegmentationOffload : False EngineUpdatesChannel : 0 ExclusionExtension : ExclusionIpAddress : ExclusionPath : ExclusionProcess : ForceUseProxyOnly : False HideExclusionsFromLocalUsers : True HighThreatDefaultAction : 0 IntelTDTEnabled : False LowThreatDefaultAction : 0 MAPSReporting : 2 MeteredConnectionUpdates : False ModerateThreatDefaultAction : 0 NetworkProtectionReputationMode : 0 OobeEnableRtpAndSigUpdate : False PerformanceModeStatus : 1 PlatformUpdatesChannel : 0 ProxyBypass : ProxyPacUrl : ProxyServer : PUAProtection : 1 QuarantinePurgeItemsAfterDelay : 90 QuickScanIncludeExclusions : 0 RandomizeScheduleTaskTimes : True RealTimeScanDirection : 0 RemediationScheduleDay : 0 RemediationScheduleTime : 02:00:00 RemoteEncryptionProtectionAggressiveness : 0 RemoteEncryptionProtectionConfiguredState : 0 RemoteEncryptionProtectionExclusions : RemoteEncryptionProtectionMaxBlockTime : 0 RemoveScanningThreadPoolCap : False ReportDynamicSignatureDroppedEvent : False ReportingAdditionalActionTimeOut : 10080 ReportingCriticalFailureTimeOut : 10080 ReportingNonCriticalTimeOut : 1440 ScanAvgCPULoadFactor : 50 ScanOnlyIfIdleEnabled : True ScanParameters : 1 ScanPurgeItemsAfterDelay : 15 ScanScheduleDay : 0 ScanScheduleOffset : 120 ScanScheduleQuickScanTime : 00:00:00 ScanScheduleTime : 02:00:00 SchedulerRandomizationTime : 4 ServiceHealthReportInterval : 60 SevereThreatDefaultAction : 0 SharedSignaturesPath : SharedSignaturesPathUpdateAtScheduledTimeOnly : False SignatureAuGracePeriod : 0 SignatureBlobFileSharesSources : SignatureBlobUpdateInterval : 60 SignatureDefinitionUpdateFileSharesSources : SignatureDisableUpdateOnStartupWithoutEngine : False SignatureFallbackOrder : MicrosoftUpdateServer|MMPC SignatureFirstAuGracePeriod : 120 SignatureScheduleDay : 8 SignatureScheduleTime : 01:45:00 SignatureUpdateCatchupInterval : 1 SignatureUpdateInterval : 0 SubmitSamplesConsent : 1 ThreatIDDefaultAction_Actions : ThreatIDDefaultAction_Ids : ThrottleForScheduledScanOnly : True TrustLabelProtectionStatus : 0 UILockdown : False UnknownThreatDefaultAction : 0 PSComputerName : AMEngineVersion : 1.1.26010.1 AMProductVersion : 4.18.26010.5 AMRunningMode : Normal AMServiceEnabled : True AMServiceVersion : 4.18.26010.5 AntispywareEnabled : True AntispywareSignatureAge : 0 AntispywareSignatureLastUpdated : 3/12/2026 10:54:19 PM AntispywareSignatureVersion : 1.445.511.0 AntivirusEnabled : True AntivirusSignatureAge : 0 AntivirusSignatureLastUpdated : 3/12/2026 10:54:19 PM AntivirusSignatureVersion : 1.445.511.0 BehaviorMonitorEnabled : True ComputerID : 56A64B05-1A92-4D29-AE02-A3E7E25877AB ComputerState : 0 ControlledConfigurationState : 0 DefenderSignaturesOutOfDate : False DeviceControlDefaultEnforcement : DeviceControlPoliciesLastUpdated : 12/31/1600 6:00:00 PM DeviceControlState : Disabled FullScanAge : 19 FullScanEndTime : 2/22/2026 7:16:36 AM FullScanOverdue : False FullScanRequired : False FullScanSignatureVersion : 1.445.186.0 FullScanStartTime : 2/22/2026 5:52:17 AM InitializationProgress : ServiceStartedSuccessfully IoavProtectionEnabled : True IsTamperProtected : True IsVirtualMachine : False LastFullScanSource : 1 LastQuickScanSource : 2 NISEnabled : True NISEngineVersion : 1.1.26010.1 NISSignatureAge : 0 NISSignatureLastUpdated : 3/12/2026 10:54:19 PM NISSignatureVersion : 1.445.511.0 OnAccessProtectionEnabled : True ProductStatus : 524288 QuickScanAge : 0 QuickScanEndTime : 3/12/2026 4:36:03 PM QuickScanOverdue : False QuickScanSignatureVersion : 1.445.496.0 QuickScanStartTime : 3/12/2026 4:26:06 PM RealTimeProtectionEnabled : True RealTimeScanDirection : 0 RebootRequired : False SmartAppControlExpiration : SmartAppControlState : Off TamperProtectionSource : UI TroubleShootingDailyMaxQuota : TroubleShootingDailyQuotaLeft : TroubleShootingEndTime : TroubleShootingExpirationLeft : TroubleShootingMode : TroubleShootingModeSource : TroubleShootingQuotaResetTime : TroubleShootingStartTime : PSComputerName : Signature update started . . . Signature update finished. No updates needed ========= End of Powershell: ========= =========== EmptyTemp: ========== FlushDNS => completed BITS transfer queue => 1310720 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 131210868 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 393877432 B Windows/system/drivers => 0 B Edge => 2950220467 B Firefox => 0 B Opera => 0 B Local\Temp, Local\*.tmp, LocalLow\Temp, Roaming\Temp, Roaming\*.tmp , IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 0 B NetworkService => 0 B hanna => 481450129 B RecycleBin => 18251529299 B EmptyTemp: => 20.7 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 09:29:38 ====