Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-09-2026 Ran by AUROBINDO (18-09-2026 17:58:02) Running from D:\Setup Microsoft Windows 11 Home Single Language Version 25H2 26200.9457 (X64) (2025-09-04 15:25:32) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-2252253667-2345452436-384743395-500 - Administrators - Disabled) AUROBINDO (DisplayName: A******** ******i) (S-1-5-21-2252253667-2345452436-384743395-1001 - Administrators - Enabled) [MS Account] => C:\Users\AUROBINDO DefaultAccount (S-1-5-21-2252253667-2345452436-384743395-503 - Limited - Disabled) Guest (S-1-5-21-2252253667-2345452436-384743395-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-2252253667-2345452436-384743395-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Brave (HKLM-x32\...\BraveSoftware Brave-Browser) (Version: 153.1.95.102 - Brave Software Inc) Dell Core Services (HKLM\...\{DEBD3D0E-F2B1-43A0-A2A4-530F22FF724A}) (Version: 1.10.33.0 - Dell, Inc.) Dell Digital Delivery Services (HKLM-x32\...\{87310396-FD49-4108-BBBB-28E1C3EA85E9}) (Version: 5.6.3.0 - Dell Inc.) Dell Power Manager Service (HKLM\...\{94F324D2-DEAF-465B-84C8-1F9EB15DBBBE}) (Version: 3.14.0 - Dell Inc.) Dell Update for Windows Universal (HKLM\...\{1405CADB-1E91-4C4E-AC9E-00B733563560}) (Version: 5.5.0 - Dell Inc.) Fusion Service (HKLM\...\{93D141B9-9B5E-485B-8ED1-97DE741EE768}) (Version: 2.2.14.0 - Dell.Inc) Hidden Fusion Service (HKLM-x32\...\{6e578348-d226-4341-a69f-26274feac293}) (Version: 2.2.14.0 - Dell.Inc) Glary Utilities 6.27 (HKLM-x32\...\Glary Utilities) (Version: 6.27.0.31 - Glarysoft Ltd) L.A. Noire (HKLM-x32\...\L.A. Noire_is1) (Version: - ) Lighting Control Agent (HKLM-x32\...\{9DAEEE5E-969D-42B9-81DC-0C3DF2CD0876}) (Version: 1.5 - Corsair Components Inc.) Malwarebytes version 5.6.3.284 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.6.3.284 - Malwarebytes) Microsoft .NET Host - 8.0.11 (x64) (HKLM\...\{362B4D0D-8438-44DA-86B2-FEC44E000FCA}) (Version: 64.44.23191 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 8.0.11 (x64) (HKLM\...\{F59C11F0-D73F-452B-8D1D-8C33B82D8507}) (Version: 64.44.23191 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 8.0.11 (x64) (HKLM\...\{9C80213E-9079-4561-8D57-1FDD0D62251F}) (Version: 64.44.23191 - Microsoft Corporation) Hidden Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 153.0.4234.32 - Microsoft Corporation) Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 153.0.4234.32 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2019 - bn-in (HKLM\...\HomeStudent2019Retail - bn-in) (Version: 16.0.19127.20800 - Microsoft Corporation) Microsoft Office Home and Student 2019 - en-us (HKLM\...\HomeStudent2019Retail - en-us) (Version: 16.0.19127.20800 - Microsoft Corporation) Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 26.158.0816.0003 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.31.31103 (HKLM-x32\...\{41d7b770-418a-43b7-95a5-f925fff05789}) (Version: 14.31.31103.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 (HKLM-x32\...\{410c0ee1-00bb-41b6-9772-e12c2828b02f}) (Version: 14.36.32532.0 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 (HKLM-x32\...\{C2C59CAB-8766-4ABD-A8EF-1151A36C41E5}) (Version: 14.36.32532 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 (HKLM-x32\...\{73F77E4E-5A17-46E5-A5FC-8A061047725F}) (Version: 14.36.32532 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 8.0.11 (x64) (HKLM\...\{C0790AA0-0F40-4836-85B2-677B87625E63}) (Version: 64.44.23253 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 8.0.11 (x64) (HKLM-x32\...\{bd40e761-3e88-4202-9b53-26c6bed3d467}) (Version: 8.0.11.34221 - Microsoft Corporation) nGlide 2.00 (HKLM-x32\...\nGlide) (Version: 2.00 - Zeus Software) NVIDIA PhysX System Software 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.19127.20800 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20800 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20800 - Microsoft Corporation) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) PowerToys (Preview) (HKLM\...\{5FA8E06C-0CF6-4A52-B6AD-3A586ECA2EB6}) (Version: 0.100.1 - Microsoft Corporation) Hidden PowerToys (Preview) x64 (HKU\S-1-5-21-2252253667-2345452436-384743395-1001\...\{47A2088E-45A0-4E07-A9FB-7AD3E517A26E}) (Version: 0.100.1 - Microsoft Corporation) Qualcomm 11ac Wireless LAN&Bluetooth Installer (HKLM-x32\...\{E7086B15-806E-4519-A876-DBA9FDDE9A13}) (Version: 11.0.0.10531 - Qualcomm) Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9268.1 - Realtek Semiconductor Corp.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.22631.31285 - Realtek Semiconductor Corp.) Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 10.57.330.2022 - Realtek) SmartByte Drivers and Services (HKLM\...\{19A754FE-0343-4311-835F-33EAB7ADEA7B}) (Version: 3.1122.728.7 - Rivet Networks) Sniper Elite III Ultimate Edition MULTi9 - ElAmigos version 1.15a (HKLM-x32\...\{1CB07077-D958-4A71-8E1B-277F02081F92}_is1) (Version: 1.15a - Rebellion) UE Prerequisites (x64) (HKLM\...\{C4175120-313E-467B-AAA7-825979CBAEE7}) (Version: 1.0.20.0 - Epic Games, Inc.) Hidden UE Prerequisites (x64) (HKLM-x32\...\{b24cae82-bb64-4ad2-820a-dc2c4031c914}) (Version: 1.0.20.0 - Epic Games, Inc.) Hidden Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation) Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation) WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH) Zoom Workplace (HKU\S-1-5-21-2252253667-2345452436-384743395-1001\...\ZoomUMX) (Version: 7.0.6 (43848) - Zoom Communications, Inc.) Packages: ========= Command Palette -> C:\Program Files\WindowsApps\Microsoft.CommandPalette_0.11.11733.0_x64__8wekyb3d8bbwe [2026-06-24] (Microsoft Corporation) [Startup Task] Dell Power Manager -> C:\Program Files\WindowsApps\DellInc.DellPowerManager_3.14.40.0_x64__htrsf667h5kn2 [2025-06-16] (Dell Inc) Dell Update -> C:\Program Files\WindowsApps\DellInc.DellUpdate_5.5.14.0_x86__htrsf667h5kn2 [2025-05-22] (Dell Inc) Ink.Handwriting.en-US.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.en-US.1.0_0.1346.2034.0_x64__8wekyb3d8bbwe [2026-09-10] (Microsoft Corporation) Ink.Handwriting.en-US.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.en-US.1.0_0.1346.2034.0_x86__8wekyb3d8bbwe [2026-09-10] (Microsoft Corporation) Local AI Manager for Microsoft 365 -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\AI [2026-09-17] () Malwarebytes Anti-Malware -> C:\Program Files\Malwarebytes\Anti-Malware [2026-08-11] () Microsoft Ink Handwriting Recognition (en-US) -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.Main.en-US.1.0.1_0.1346.2034.0_x64__8wekyb3d8bbwe [2026-09-12] (Microsoft Corporation) Microsoft.Office.ActionsServer -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\ActionsServer [2026-09-17] () OfficePushNotificationsUtility -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16 [2026-09-17] () OneNote Virtual Printer -> C:\Program Files\WindowsApps\Microsoft.Office.OneNoteVirtualPrinter_1.0.0.0_x86__8wekyb3d8bbwe [2026-07-24] (Microsoft Corporation) PowerToys.SparseApp -> C:\Users\AUROBINDO\AppData\Local\PowerToys\WinUI3Apps [2026-06-24] (Microsoft) WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2635.100.0_x64__cv1g1gvanyjgm [2026-09-10] (WhatsApp Inc.) [Startup Task] WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_8002.4.0.0_x64__8wekyb3d8bbwe [2026-08-14] (Microsoft Corp.) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{5c93a1e4-99d0-4fb3-991c-6c296a27be21}\InprocServer32 -> C:\Users\AUROBINDO\AppData\Local\PowerToys\PowerToys.BgcodeThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{60789D87-9C3C-44AF-B18C-3DE2C2820ED3}\InprocServer32 -> C:\Users\AUROBINDO\AppData\Local\PowerToys\PowerToys.MarkdownPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{729B72CD-B72E-4FE9-BCBF-E954B33FE699}\InprocServer32 -> C:\Users\AUROBINDO\AppData\Local\PowerToys\PowerToys.QoiPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{77257004-6F25-4521-B602-50ECC6EC62A6}\InprocServer32 -> C:\Users\AUROBINDO\AppData\Local\PowerToys\PowerToys.StlThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{AD856B15-D25E-4008-AFB7-AFAA55586188}\InprocServer32 -> C:\Users\AUROBINDO\AppData\Local\PowerToys\PowerToys.QoiThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{DD5CACDA-7C2E-4997-A62A-04A597B58F76}\localserver32 -> C:\Users\AUROBINDO\AppData\Local\PowerToys\PowerToys.exe (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe => No File CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{F2847CBE-CD03-4C83-A359-1A8052C1B9D5}\InprocServer32 -> C:\Users\AUROBINDO\AppData\Local\PowerToys\PowerToys.GcodeThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{faa4e513-36c8-513a-4f64-2913af7b71d6}\localserver32 -> C:\Users\AUROBINDO\AppData\Local\PowerToys\PowerToys.PowerLauncher.exe (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2252253667-2345452436-384743395-1001_Classes\CLSID\{FCDD4EED-41AA-492F-8A84-31A1546226E0}\InprocServer32 -> C:\Users\AUROBINDO\AppData\Local\PowerToys\PowerToys.SvgPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-08-27] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-08-11] (Malwarebytes Inc -> Malwarebytes) ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.158.0816.0003\FileSyncShell64.dll [2026-09-17] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2026-08-11] (Malwarebytes Inc -> Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-08-27] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-08-27] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2025-05-14 12:09 - 2025-05-14 12:09 - 000000000 ____L () [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\AppVIsvSubsystems32.dll 2025-05-14 12:09 - 2025-05-14 12:09 - 000000000 ____L () [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\c2r32.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= (If an entry is included in the fixlist, the registry item will be restored to default or removed.) HKU\S-1-5-21-2252253667-2345452436-384743395-1001\Software\Classes\regfile: <==== ATTENTION HKU\S-1-5-21-2252253667-2345452436-384743395-1001\Software\Classes\.reg: => <==== ATTENTION HKU\S-1-5-21-2252253667-2345452436-384743395-1001\Software\Classes\.bat: => <==== ATTENTION HKU\S-1-5-21-2252253667-2345452436-384743395-1001\Software\Classes\.cmd: => <==== ATTENTION ==================== Internet Explorer (Whitelisted) ============= BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2026-09-16] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2026-09-16] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2026-09-16] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2026-09-16] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2026-09-16] (Microsoft Corporation -> Microsoft Corporation) ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-12-07 14:44 - 2025-07-16 19:44 - 000003992 _____ C:\WINDOWS\system32\drivers\etc\hosts 109.94.209.70 fitgirlrepacks.in # Fake FitGirl site 109.94.209.70 www.fitgirlrepacks.in # Fake FitGirl site 109.94.209.70 fitgirlrepacks.co # Fake FitGirl site 109.94.209.70 fitgirl-repacks.cc # Fake FitGirl site 109.94.209.70 fitgirl-repacks.to # Fake FitGirl site 109.94.209.70 fitgirl-repack.com # Fake FitGirl site 109.94.209.70 fitgirl-repacks.website # Fake FitGirl site 109.94.209.70 www.fitgirlrepacks.co # Fake FitGirl site 109.94.209.70 www.fitgirl-repacks.cc # Fake FitGirl site 109.94.209.70 www.fitgirl-repacks.to # Fake FitGirl site 109.94.209.70 www.fitgirl-repack.com # Fake FitGirl site 109.94.209.70 www.fitgirl-repacks.website # Fake FitGirl site 109.94.209.70 ww9.fitgirl-repacks.xyz # Fake FitGirl site 109.94.209.70 *.fitgirl-repacks.xyz # Fake FitGirl site 109.94.209.70 fitgirl-repacks.xyz # Fake FitGirl site 109.94.209.70 fitgirl-repack.net # Fake FitGirl site 109.94.209.70 www.fitgirl-repack.net # Fake FitGirl site 109.94.209.70 fitgirlpack.site # Fake FitGirl site 109.94.209.70 www.fitgirlpack.site # Fake FitGirl site 109.94.209.70 fitgirl-repack.org # Fake FitGirl site 109.94.209.70 www.fitgirl-repack.org # Fake FitGirl site 109.94.209.70 fitgirlrepacks.pro # Fake FitGirl site 109.94.209.70 www.fitgirlrepacks.pro # Fake FitGirl site 109.94.209.70 fitgirlrepack.games # Fake FitGirl site 109.94.209.70 www.fitgirlrepack.games # Fake FitGirl site 109.94.209.70 fitgirl-repacks-site.org # Fake FitGirl site 109.94.209.70 www.fitgirl-repacks-site.org # Fake FitGirl site 109.94.209.70 fitgirls-repacks.com # Fake FitGirl site 109.94.209.70 fitgirlrepack.cc # Fake FitGirl site 109.94.209.70 fitgirlrepacks.org # Fake FitGirl site ==================== Network =========================== (Currently there is no automatic fix for this section.) DNS Servers: 172.22.79.129 Windows Firewall is enabled. Network Binding: ============= Bluetooth Network Connection: Bluetooth Device (Personal Area Network) -> bthpan.sys Ethernet: Realtek PCIe FE Family Controller -> rt640x64.sys Wi-Fi: Qualcomm QCA9377 802.11ac Wireless Adapter -> Qcamain10x64.sys ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2252253667-2345452436-384743395-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\AUROBINDO\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\ma_new_1.jpg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5) HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0) ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKU\S-1-5-21-2252253667-2345452436-384743395-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk" HKU\S-1-5-21-2252253667-2345452436-384743395-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_5128E90D98B6033DE1E9A551AC851F0F" HKU\S-1-5-21-2252253667-2345452436-384743395-1001\...\StartupApproved\Run: => "OneDrive" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\WINDOWS\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{66B027BC-9150-40C1-BD19-A3E0966526AF}C:\program files\bravesoftware\brave-browser\application\brave.exe] => (Block) C:\program files\bravesoftware\brave-browser\application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.) FirewallRules: [UDP Query User{8CFCC687-EC0A-4793-86A6-656BA48893F4}C:\program files\bravesoftware\brave-browser\application\brave.exe] => (Block) C:\program files\bravesoftware\brave-browser\application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.) FirewallRules: [TCP Query User{643ACA3E-253A-4324-88BF-17A33C830A56}E:\naught\naught\binaries\win64\naught-win64-shipping.exe] => (Block) E:\naught\naught\binaries\win64\naught-win64-shipping.exe => No File FirewallRules: [UDP Query User{00968EAB-033E-4845-A57F-F685A89DCC8E}E:\naught\naught\binaries\win64\naught-win64-shipping.exe] => (Block) E:\naught\naught\binaries\win64\naught-win64-shipping.exe => No File FirewallRules: [{8DCFDEAA-D11F-47D6-9886-4BE76EB1D7DB}] => (Allow) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.) ==================== Restore Points ========================= 01-09-2026 14:08:58 Windows Modules Installer 04-09-2026 17:28:55 Windows Update 08-09-2026 08:16:35 Windows Update 09-09-2026 19:46:07 Windows Modules Installer 14-09-2026 20:16:15 Windows Update ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (09/17/2026 06:46:03 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1005) (User: NT AUTHORITY) Description: The attempt to locate the Open procedure "OpenLsaPerformanceData" in DLL "C:\Windows\System32\Secur32.dll" for the "Lsa" service failed with Win32 error code 127. Performance data for this service will not be available. Error: (09/15/2026 08:35:22 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1005) (User: NT AUTHORITY) Description: The attempt to locate the Open procedure "OpenLsaPerformanceData" in DLL "C:\Windows\System32\Secur32.dll" for the "Lsa" service failed with Win32 error code 127. Performance data for this service will not be available. Error: (09/15/2026 07:23:03 PM) (Source: Application Error) (EventID: 1000) (User: SAVITRI) Description: Faulting application name: msedge.exe, version: 153.0.4234.32, time stamp: 0x6aa27d5c Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x000002264fd2128f Faulting process id: 0x3124 Faulting application start time: 0x1dd45197f1d7f66 Faulting application path: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Faulting module path: unknown Report Id: 38e60b36-dbed-4d83-89e2-429a3281a9a7 Faulting package full name: Faulting package-relative application ID: Error: (09/15/2026 07:22:11 PM) (Source: Application Error) (EventID: 1000) (User: SAVITRI) Description: Faulting application name: msedge.exe, version: 153.0.4234.32, time stamp: 0x6aa27d5c Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000023fd2ce128f Faulting process id: 0x1960 Faulting application start time: 0x1dd451896d20e35 Faulting application path: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Faulting module path: unknown Report Id: 5e1be7e1-e044-483e-abcc-3d08c0ad3689 Faulting package full name: Faulting package-relative application ID: Error: (09/15/2026 07:16:20 PM) (Source: SideBySide) (EventID: 59) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe".Error in manifest or policy file "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" on line 0. Invalid Xml syntax. Error: (09/09/2026 09:17:59 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1005) (User: NT AUTHORITY) Description: The attempt to locate the Open procedure "OpenLsaPerformanceData" in DLL "C:\Windows\System32\Secur32.dll" for the "Lsa" service failed with Win32 error code 127. Performance data for this service will not be available. Error: (09/01/2026 03:12:20 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1005) (User: NT AUTHORITY) Description: The attempt to locate the Open procedure "OpenLsaPerformanceData" in DLL "C:\Windows\System32\Secur32.dll" for the "Lsa" service failed with Win32 error code 127. Performance data for this service will not be available. Error: (08/15/2026 08:46:52 PM) (Source: Application Error) (EventID: 1000) (User: SAVITRI) Description: Faulting application name: enb.exe, version: 0.0.0.0, time stamp: 0x427101ca Faulting module name: d3d9.dll, version: 1.0.0.1, time stamp: 0x5c26be94 Exception code: 0xc0000005 Fault offset: 0x0002b093 Faulting process id: 0x29cc Faulting application start time: 0x1dd2cc8facd7dd7 Faulting application path: E:\GTA San Andreas\enb.exe Faulting module path: E:\GTA San Andreas\d3d9.dll Report Id: 7972cd08-92e1-49e1-8929-b0b496b79f5f Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (09/17/2026 06:48:16 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Connected Devices Platform Service service hung on starting. Error: (09/17/2026 06:46:51 PM) (Source: DCOM) (EventID: 10010) (User: SAVITRI) Description: The server {34057DFB-FC7C-4476-9AB7-F20D5165945F} did not register with DCOM within the required timeout. Error: (09/17/2026 06:46:48 PM) (Source: DCOM) (EventID: 10010) (User: SAVITRI) Description: The server {284CACFE-B6F2-461A-90C3-A7ACC8353816} did not register with DCOM within the required timeout. Error: (09/16/2026 05:01:10 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9NTXGKQ8P7N0-MicrosoftWindows.CrossDevice. Error: (09/16/2026 05:00:41 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9NMPJ99VJBWV-Microsoft.YourPhone. Error: (09/15/2026 08:31:52 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: The SmartByte Network Service service did not shut down properly after receiving a preshutdown control. Error: (09/10/2026 07:55:00 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9NKSQGP7F2NH-5319275A.WhatsAppDesktop. Error: (09/10/2026 06:58:08 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Background Intelligent Transfer Service service terminated with the following service-specific error: %%(2147943515 = A system shutdown is in progress.) Windows Defender: ================ CodeIntegrity: =============== Date: 2026-09-18 17:28:54 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.3-0\DefenderSessionHelper.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2026-09-15 18:46:07 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe) attempted to load \Device\HarddiskVolume3\Program Files\BraveSoftware\Brave-Browser\Application\153.1.95.101\vulkan-1.dll that did not meet the Microsoft signing level requirements. Date: 2026-09-15 18:46:07 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe) attempted to load \Device\HarddiskVolume3\Program Files\BraveSoftware\Brave-Browser\Application\153.1.95.101\vk_swiftshader.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== BIOS: Dell Inc. 1.30.0 03/10/2025 Motherboard: Dell Inc. 0FFDF9 Processor: AMD Ryzen 3 3250U with Radeon Graphics Percentage of memory in use: 46% Total physical RAM: 14222.26 MB Available physical RAM: 7630.58 MB Total Virtual: 17038.26 MB Available Virtual: 10573.68 MB ==================== Drives ================================ Disk 0 - Drive c: () (Fixed) (Total:193.88 GB GB) (Free:95.17 GB GB) (Model: Seagate BarraCuda Q5 ZP1000CV30001) NTFS Disk 0 - Drive d: () (Fixed) (Total:390.62 GB GB) (Free:356.04 GB GB) (Model: Seagate BarraCuda Q5 ZP1000CV30001) NTFS Disk 0 - Drive e: () (Fixed) (Total:344.15 GB GB) (Free:292.57 GB GB) (Model: Seagate BarraCuda Q5 ZP1000CV30001) NTFS Disk 0 - \\?\Volume{6a134bbd-4066-4d75-97f4-5f25b15c5ed6}\ () (Fixed) (Total:1.32 GB) (Free:0.08 GB) NTFS Disk 0 - \\?\Volume{5c7439a5-c395-4481-b133-3a4759ede454}\ (DELLSUPPORT) (Fixed) (Total:1.41 GB) (Free:0.39 GB) NTFS Disk 0 - \\?\Volume{6c77a350-3e06-4aa1-b1c2-d1058bdfa534}\ () (Fixed) (Total:0.09 GB) (Free:0.01 GB) FAT32 ==================== MBR & Partition Table ==================== ============================================================ Disk: 0 (Protective MBR) (Size: 931.51 GB) Partitions: =========== Partition Style : GPT Partition Count : 7 Disk ID : {A57BC176-892D-4B6D-9D06-76E0311B0DC3} Usable Offset : 0.02 MB Usable Length : 931.51 GB Max Partitions : 128 Partition 1 Type : EFI System Partition Size : 100 MB Offset : 1 MB Type GUID : {C12A7328-F81F-11D2-BA4B-00A0C93EC93B} Partition GUID : {6C77A350-3E06-4AA1-B1C2-D1058BDFA534} GPT Name : EFI system partition Attributes : 0x8000000000000000 Attribute Flags : No Default Drive Letter Hidden : Yes Platform Required: No ------------------------------------------------------------ Partition 2 Type : Microsoft Reserved (MSR) Size : 16 MB Offset : 101 MB Type GUID : {E3C9E316-0B5C-4DB8-817D-F92DF00215AE} Partition GUID : {72CDE07E-FD1D-4436-98BB-D934B3083C9B} GPT Name : Microsoft reserved partition Attributes : 0x8000000000000000 Attribute Flags : No Default Drive Letter Hidden : Yes Platform Required: No ------------------------------------------------------------ Partition 3 Type : Basic Data Partition Size : 193.88 GB Offset : 117 MB Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7} Partition GUID : {C005D587-310A-4CE3-9D8A-6A266EEA7811} GPT Name : Basic data partition Attributes : 0x0000000000000000 Attribute Flags : None Hidden : No Platform Required: No ------------------------------------------------------------ Partition 4 Type : Windows Recovery Size : 1.32 GB Offset : 198648 MB Type GUID : {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC} Partition GUID : {6A134BBD-4066-4D75-97F4-5F25B15C5ED6} Attributes : 0x8000000000000001 Attribute Flags : Platform Required, No Default Drive Letter Hidden : Yes Platform Required: Yes ------------------------------------------------------------ Partition 5 Type : Basic Data Partition Size : 390.63 GB Offset : 200000 MB Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7} Partition GUID : {EC072DEA-2ED1-4D39-B8F9-145101270141} GPT Name : Basic data partition Attributes : 0x0000000000000000 Attribute Flags : None Hidden : No Platform Required: No ------------------------------------------------------------ Partition 6 Type : Basic Data Partition Size : 344.15 GB Offset : 600000 MB Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7} Partition GUID : {D0BC6C75-26B9-4382-A2A2-94B43E09BDBC} GPT Name : Basic data partition Attributes : 0x0000000000000000 Attribute Flags : None Hidden : No Platform Required: No ------------------------------------------------------------ Partition 7 Type : Windows Recovery Size : 1.41 GB Offset : 952410 MB Type GUID : {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC} Partition GUID : {5C7439A5-C395-4481-B133-3A4759EDE454} GPT Name : Basic data partition Attributes : 0x8000000000000000 Attribute Flags : No Default Drive Letter Hidden : Yes Platform Required: No ------------------------------------------------------------ ============================================================ ==================== End of Addition.txt =======================