From CupNo2413, 9 Hours ago, written in Plain Text.
This paste will perish in 14 Hours.
Embed
  1. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2026
  2. Ran by Shawn (administrator) on DESKTOP-T985JJS (HP OMEN by HP Obelisk Desktop 875-0xxx) (19-03-2026 13:36:12)
  3. Running from C:\Users\Shawn\Desktop\FRST64.exe
  4. Loaded Profiles: Shawn
  5. Platform: Microsoft Windows 11 Home Version 25H2 26200.8037 (X64) Language: English (United States)
  6. Default browser: Edge
  7. Boot Mode: Normal
  8.  
  9. ==================== Processes (Whitelisted) =================
  10.  
  11. (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
  12.  
  13. (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
  14. (C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSATray.exe
  15. (C:\Program Files\Bitdefender Agent\ProductAgentService.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\27.1.1.28\DiscoverySrv.exe
  16. (C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.16.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityBackground.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.16.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityHost.exe
  17. (C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyWidgetProvider.exe ->) (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\crashpad_handler.exe
  18. (Cisco Systems, Inc. -> Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco Secure Client\UI\csc_ui.exe
  19. (DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\BridgeCommunication.exe
  20. (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.16.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityBackground.exe
  21. (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe
  22. (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <15>
  23. (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek) C:\Program Files (x86)\REALTEK\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe
  24. (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Media Network\HPMediaNetwork.exe
  25. (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
  26. (services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
  27. (services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\redline\bdredline.exe
  28. (services.exe ->) (Cisco Systems, Inc. -> Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco Secure Client\vpnagent.exe
  29. (services.exe ->) (DTS, Inc. -> ) C:\Windows\System32\DTS\PC\APO3x\DTSAPO3Service.exe
  30. (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe
  31. (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
  32. (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_ef460d1f2a35fc16\x64\TouchpointAnalyticsClientService.exe
  33. (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\AppHelperCap.exe
  34. (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\DiagsCap.exe
  35. (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\NetworkCap.exe
  36. (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\SysInfoCap.exe
  37. (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_3c97e435117f8c16\x64\OmenCap\OmenCap.exe
  38. (services.exe ->) (HP Inc. -> HP Inc; HP Development Company, L.P.) C:\Program Files\HP\HP One Agent\hp-one-agent-service.exe
  39. (services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
  40. (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
  41. (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
  42. (services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
  43. (services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe
  44. (services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe
  45. (services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
  46. (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
  47. (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
  48. (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpDefenderCoreService.exe
  49. (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MsMpEng.exe
  50. (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\NisSrv.exe
  51. (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvhdc.inf_amd64_1f7c5b9c4ae7ca18\Display.NvContainer\NVDisplay.Container.exe <2>
  52. (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
  53. (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
  54. (sihost.exe ->) (649690DD-9BE8-48E7-8019-88DCA877AF4E -> McAfee, LLC) C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.68.0_x64__wafk5atnkzcwy\Win32\mcafee-security-ft.exe
  55. (sihost.exe ->) (E2014DE2-35CD-415B-AA3F-BC64B1D1F3B9 -> The NW.js Community) C:\Program Files\WindowsApps\PrivacyBrowse.PrivacyBrowse_1.12.78.0_neutral__hz4wbnfrnhwdr\VFS\AppData\PrivacyBrowse\PrivacyBrowse.exe <8>
  56. (svchost.exe ->) (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyWidgetProvider.exe
  57. (svchost.exe ->) (649690DD-9BE8-48E7-8019-88DCA877AF4E -> McAfee LLC) C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.68.0_x64__wafk5atnkzcwy\mcafee-security.exe
  58. (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
  59. (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe
  60. (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\Overlay\OverlayHelper.exe
  61. (svchost.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe
  62. (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.241.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
  63. (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
  64. (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
  65. (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe
  66.  
  67. ==================== Registry (Whitelisted) ===================
  68.  
  69. (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
  70.  
  71. HKLM\...\Run: [RtlS5Wake] => C:\Program Files (x86)\Realtek\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe [2097600 2018-04-18] (Realtek Semiconductor Corp. -> Realtek)
  72. HKLM\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe (No File)
  73. HKLM-x32\...\Run: [Cisco Secure Client] => C:\Program Files (x86)\Cisco\Cisco Secure Client\UI\csc_ui.exe [3523504 2024-12-04] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
  74. HKU\S-1-5-19\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe (No File)
  75. HKU\S-1-5-20\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe (No File)
  76. HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\Run: [HPSEU_Host_Launcher] => C:\Program Files\HP\HP System Event Utility\Host Launcher\HpseuHostLauncher.exe [545864 2025-11-08] (HP Inc. -> HP Inc.)
  77. HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Shawn\AppData\Local\Microsoft\Teams\Update.exe [2339472 2020-05-07] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
  78. HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2589432 2026-03-19] (Wargaming Group Limited -> Wargaming.net)
  79. HKLM\...\Print\Monitors\HP 7112 Status Monitor: C:\windows\system32\hpinksts7112LM.dll [328704 2014-03-03] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Co.)
  80. HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [2026-03-02] (Google LLC -> Google LLC)
  81. HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\146.0.7680.81\Installer\chrmstp.exe [2026-03-19] (Google LLC -> Google LLC)
  82. HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
  83. GroupPolicy: Restriction ? <==== ATTENTION
  84. Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
  85.  
  86. ==================== Scheduled Tasks (Whitelisted) =================
  87.  
  88. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  89.  
  90. Task: {82642CFF-B009-40CC-81C0-B9FB3E8C3ADE} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\27.1.1.28\WatchDog.exe [1175072 2026-01-16] (Bitdefender SRL -> Bitdefender) -> C:\Program Files\Bitdefender Agent\27.1.1.28\repair
  91. Task: {CAC2AABD-0908-4615-8B89-4A999597A2CD} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem148.0.7730.0{00D69F7D-BC5F-45C0-8714-6A4FD4E13C0E} => C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe [8459416 2026-03-12] (Google LLC -> Google LLC)
  92. Task: {F0A06017-791A-4111-A89C-CCF1D215C5E6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [480264 2026-01-27] (HP Inc. -> HP Inc.)
  93. Task: {E5202BE4-94CB-4CD7-BE84-D0FB3D2F9F88} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPPrinterLowInk => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPPrinterLowInk\HPPrinterLowInk.exe [231944 2026-01-27] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
  94. Task: {EDBEC2CB-2AFF-43F4-933D-AD862707F133} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1176136 2026-01-27] (HP Inc. -> HP Inc.)
  95. Task: {9F775904-B062-49E2-9B8E-85FFD366599C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1176136 2026-01-27] (HP Inc. -> HP Inc.)
  96. Task: {0A38B8A3-BDB6-43DC-85D6-7DEBCC16DFC3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_TH34M7606K => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1176136 2026-01-27] (HP Inc. -> HP Inc.)
  97. Task: {A3F7C2AB-DABA-46C2-9BE6-4A7BE9E1ECB5} - System32\Tasks\HP\Consent Manager Launcher => C:\windows\system32\sc.exe [102400 2025-07-09] (Microsoft Windows -> Microsoft Corporation) -> start hptouchpointanalyticsservice
  98. Task: {7E3F116B-8F48-458A-A795-28204FA6090E} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1644472 2019-06-21] (HP Inc. -> HP Inc.)
  99. Task: {127C1C74-7098-4AAA-BF47-AF34071888D4} - System32\Tasks\HPOneAgentRepairTask => C:\ProgramData\Package Cache\{DD84A52B-8D5B-484F-82D4-5AEA657B6A21}\HPOneAgent.exe [1169792 2026-02-03] (HP Inc. -> HP Inc; HP Development Company, L.P.)
  100. Task: {6E68B137-A11D-4D27-8EAE-62965CBD181A} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4916640 2024-04-16] (Intel Corporation -> Intel Corporation)
  101. Task: {79F397F1-6FFE-4A36-BE71-9306E6F44160} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4916640 2024-04-16] (Intel Corporation -> Intel Corporation)
  102. Task: {DE967047-1A95-44FC-8748-97C4796E0EA9} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe  --automatic (No File)
  103. Task: {A26573A0-1BB8-40DB-A82C-65B0BE820AE4} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16300328 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
  104. Task: {8859BA4A-4A72-418D-B36C-5156E509780E} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28604744 2026-03-09] (Microsoft Corporation -> Microsoft Corporation)
  105. Task: {6B87B9B0-026F-4AFE-9AD7-EA9A707E42AA} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\opushutil.exe [73648 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
  106. Task: {5426B4A9-3CC0-4779-A061-8D4E96CE5A6F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28604744 2026-03-09] (Microsoft Corporation -> Microsoft Corporation)
  107. Task: {B5A2B915-8201-4D19-A084-FBC26B3D0597} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [427808 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
  108. Task: {A175F1B3-5A8F-4ABB-8AD0-6D1ABA065005} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [427808 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
  109. Task: {A1ACDD99-B883-4245-84AE-14169B5A85D3} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [1349992 2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
  110. Task: {E51E4B6D-2D33-4A23-BCE6-9843F2AAEDAF} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [4448800 2026-03-09] (Microsoft Corporation -> Microsoft Corporation)
  111. Task: {08735572-E353-45A5-A694-6A24BA2E4607} - System32\Tasks\Microsoft\Office\Office Startup Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16300328 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
  112. Task: {C2D03A90-5AD1-468D-9440-0B9789844A96} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\OLicenseHeartbeat.exe [83792 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
  113. Task: {6D425145-C2AE-4FC5-8903-E45610BEA706} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\5D6B03FB-28AC-4DD7-98AC-CC036664F127\PushLaunch => C:\WINDOWS\system32\deviceenroller.exe [569344 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
  114. Task: {237A7D71-1787-410B-8F3E-C0ECB0CEFEC4} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\5D6B03FB-28AC-4DD7-98AC-CC036664F127\PushUpgrade => C:\WINDOWS\system32\deviceenroller.exe [569344 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
  115. Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe  (No File)
  116. Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (No File)
  117. Task: {548E5980-5268-48C9-B303-4E181BBE8574} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe  /RunOnAC RebootDialog (No File)
  118. Task: {D94E6F92-3DEE-47A9-8C28-782403CE8B0F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe  /RunOnBattery RebootDialog (No File)
  119. Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
  120. Task: {EA93F60F-FB87-4793-B140-80581EBC544F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
  121. Task: {04939E32-5357-4138-AA21-721AE2BC3362} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
  122. Task: {F0578087-1B53-4624-AB07-99A18D6BE03E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
  123. Task: {AE95D385-9C2E-47D0-B4C8-5EEAC0E1CABB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
  124. Task: {D31CA2E4-B1C8-49FB-B424-F885262FA8A6} - System32\Tasks\OmenInstallMonitor => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [77320 2026-03-17] (HP Inc. -> HP Inc.)
  125. Task: {A3D9C030-41C7-42A2-ABA6-FFD9FEB28803} - System32\Tasks\OmenInstallMonitorCustomEvent => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [77320 2026-03-17] (HP Inc. -> HP Inc.)
  126. Task: {2357D3C7-37D5-4738-90AF-81920A38B1A0} - System32\Tasks\OmenInstallMonitorCustomEvent-sid-S-1-5-21-2500055725-1674575743-3887293998-1001 => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [77320 2026-03-17] (HP Inc. -> HP Inc.)
  127. Task: {B0D258CE-073A-4870-8BF5-E23A7D5DDF5B} - System32\Tasks\OmenInstallMonitor-sid-S-1-5-21-2500055725-1674575743-3887293998-1001 => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [77320 2026-03-17] (HP Inc. -> HP Inc.)
  128. Task: {6C4AC93E-921B-4947-893C-EEC66002FEAD} - System32\Tasks\OmenOverlay => C:\Program Files\HP\Overlay\OverlayHelper.exe [67592 2026-03-17] (HP Inc. -> HP Inc.)
  129. Task: {95672B0F-EDD0-48EF-A642-833FEDF7BF70} - System32\Tasks\OmenOverlayCustomEvent => C:\Program Files\HP\Overlay\OverlayHelper.exe [67592 2026-03-17] (HP Inc. -> HP Inc.)
  130. Task: {D2BD748E-9FB0-401B-8620-BF6948491CE6} - System32\Tasks\OmenOverlayCustomEvent-sid-S-1-5-21-2500055725-1674575743-3887293998-1001 => C:\Program Files\HP\Overlay\OverlayHelper.exe [67592 2026-03-17] (HP Inc. -> HP Inc.)
  131. Task: {6050ED35-CFDD-4DD7-AA03-BCB16A0F79F4} - System32\Tasks\OmenOverlay-sid-S-1-5-21-2500055725-1674575743-3887293998-1001 => C:\Program Files\HP\Overlay\OverlayHelper.exe [67592 2026-03-17] (HP Inc. -> HP Inc.)
  132. Task: {8842B4C4-5FF5-4E5B-95A2-CE03B49F30C6} - System32\Tasks\RtkAudUService64_BG => C:\WINDOWS\System32\RtkAudUService64.exe [1076000 2020-03-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
  133. Task: {D51CE681-38D2-4AD2-B1A9-AE16AE8ADD6F} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\WINDOWS\System32\Wscript.exe [200704 2026-03-11] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\//B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
  134. Task: {7ACDBC07-6B98-4978-B47E-5E30DACD517F} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2500055725-1674575743-3887293998-1001 => C:\Users\Shawn\AppData\Roaming\Zoom\bin\Zoom.exe [507784 2026-03-16] (Zoom Communications, Inc. -> Zoom Communications, Inc.)
  135.  
  136. (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
  137.  
  138.  
  139. ==================== Internet (Whitelisted) ====================
  140.  
  141. (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
  142.  
  143. Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
  144. Tcpip\..\Interfaces\{8583b6f6-ec1f-4e03-997e-eef6103f2be0}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
  145. Tcpip\..\Interfaces\{e4f87112-93f5-4cc9-9e35-185bea232b8b}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
  146.  
  147. FireFox:
  148. ========
  149. FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-01-24] (Microsoft Corporation -> Microsoft Corporation)
  150. FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2026-02-01] (Microsoft Corporation -> Microsoft Corporation)
  151. FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-12-08] (Microsoft Corporation -> Microsoft Corporation)
  152.  
  153. Edge:
  154. =======
  155. Edge DefaultProfile: Default
  156. Edge Profile: C:\Users\Shawn\AppData\Local\Microsoft\Edge\User Data\Default [2026-03-19]
  157. Edge DownloadDir: C:\Users\Shawn\Downloads
  158. Edge Notifications: Default -> hxxps://www.facebook.com
  159. Edge Extension: (Honey: Automated Coupons & Rewards) - C:\Users\Shawn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\amnbcmdbanbkjhnfoeceemmmdiepnbpp [2026-02-27]
  160. Edge Extension: (Google Docs Offline) - C:\Users\Shawn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-03-10]
  161. Edge Extension: (Edge relevant text changes) - C:\Users\Shawn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-29]
  162. Edge DownloadDir: Default -> C:\Users\Shawn\Downloads
  163.  
  164. Chrome:
  165. =======
  166. CHR DefaultProfile: Default
  167. CHR Profile: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Default [2026-03-19]
  168. CHR Extension: (ClassLink OneClick Extension) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgfbgkjjlonelmpenhpfeeljjlcgnkpe [2026-02-04]
  169. CHR Extension: (Chrome Web Store Payments) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-09-10]
  170. CHR Profile: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Guest Profile [2026-01-28]
  171. CHR Profile: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1 [2021-06-28]
  172. CHR Extension: (Slides) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-06-28]
  173. CHR Extension: (Sheets) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-06-28]
  174. CHR Extension: (Google Docs Offline) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-06-28]
  175. CHR Extension: (Chrome Web Store Payments) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-06-28]
  176. CHR Extension: (Chrome Media Router) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-28]
  177. CHR Profile: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2 [2024-07-24]
  178. CHR Extension: (Slides) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2022-02-20]
  179. CHR Extension: (Docs) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2022-02-20]
  180. CHR Extension: (Google Drive) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2022-02-20]
  181. CHR Extension: (YouTube) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2022-02-20]
  182. CHR Extension: (Sheets) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2022-02-20]
  183. CHR Extension: (Google Docs Offline) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-02-20]
  184. CHR Extension: (Chrome Web Store Payments) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-02-20]
  185. CHR Extension: (Gmail) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2022-02-20]
  186. CHR Profile: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\System Profile [2026-01-28]
  187.  
  188. ==================== Services (Whitelisted) ===================
  189.  
  190. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  191.  
  192. R2 bdredline_agent; C:\Program Files\Bitdefender Agent\redline\bdredline.exe [2426992 2025-07-03] (Bitdefender SRL -> Bitdefender)
  193. R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13270328 2026-03-09] (Microsoft Corporation -> Microsoft Corporation)
  194. R2 csc_vpnagent; C:\Program Files (x86)\Cisco\Cisco Secure Client\vpnagent.exe [1318832 2025-03-03] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
  195. R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe [133736 2025-08-27] (Intel Corporation -> Intel)
  196. R2 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe [133224 2025-08-27] (Intel Corporation -> Intel)
  197. R2 DTSAPO3Service; C:\WINDOWS\System32\DTS\PC\APO3x\DTSAPO3Service.exe [223640 2019-09-03] (DTS, Inc. -> )
  198. R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1321096 2018-09-28] (HP Inc. -> HP Inc.)
  199. R2 hp-one-agent-service; C:\Program Files\HP\HP One Agent\hp-one-agent-service.exe [2466912 2025-10-23] (HP Inc. -> HP Inc; HP Development Company, L.P.)
  200. R2 HPAppHelperCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\AppHelperCap.exe [911560 2026-01-06] (HP Inc. -> HP Inc.)
  201. R2 HPDiagsCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\DiagsCap.exe [909504 2026-01-06] (HP Inc. -> HP Inc.)
  202. R2 HPNetworkCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\NetworkCap.exe [905920 2026-01-06] (HP Inc. -> HP Inc.)
  203. R2 HPOmenCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_3c97e435117f8c16\x64\OmenCap\OmenCap.exe [755248 2024-10-25] (HP Inc. -> HP Inc.)
  204. R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [244232 2026-01-17] (HP Inc. -> HP Inc.)
  205. R2 HPSysInfoCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\SysInfoCap.exe [911040 2026-01-06] (HP Inc. -> HP Inc.)
  206. R2 HpTouchpointAnalyticsService; C:\WINDOWS\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_ef460d1f2a35fc16\x64\TouchpointAnalyticsClientService.exe [639784 2025-10-02] (HP Inc. -> HP Inc.)
  207. R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpDefenderCoreService.exe [2067464 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
  208. R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvhdc.inf_amd64_1f7c5b9c4ae7ca18\Display.NvContainer\NVDisplay.Container.exe [1275624 2026-01-28] (NVIDIA Corporation -> NVIDIA Corporation)
  209. S3 PACSPTISVR-Sound_Organizer; C:\Program Files (x86)\Sony\Sound Organizer\Sony.Earth\PACSPTISVR.exe [99984 2020-09-17] (Sony Home Entertainment & Sound Products Inc. -> Sony Corporation)
  210. R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [759712 2026-01-16] (Bitdefender SRL -> Bitdefender)
  211. R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\NisSrv.exe [4435096 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
  212. R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MsMpEng.exe [290744 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
  213. R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-15] (Microsoft Corporation -> Microsoft Corporation)
  214.  
  215. ===================== Drivers (Whitelisted) ===================
  216.  
  217. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  218.  
  219. R3 acsock; C:\WINDOWS\system32\DRIVERS\acsock64.sys [447072 2025-03-03] (Microsoft Windows Hardware Compatibility Publisher -> Cisco Systems, Inc.)
  220. R1 BDVEDISK; C:\WINDOWS\system32\DRIVERS\bdvedisk.sys [96616 2020-05-28] (Bitdefender SRL -> BitDefender)
  221. S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [573440 2025-01-29] (Microsoft Corporation) [File not signed]
  222. S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [204800 2025-01-29] (Microsoft Corporation) [File not signed]
  223. S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [110592 2025-01-29] (Microsoft Corporation) [File not signed]
  224. S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
  225. R3 HPCustomCapDriver; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [18984 2024-05-07] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.)
  226. R3 HPOmenCustomCapDriver; C:\WINDOWS\System32\DriverStore\FileRepository\hpomencustomcapdriver.inf_amd64_7a1ef17ecb1f36ce\x64\hpomencustomcapdriver.sys [24968 2024-07-12] (HP Inc. -> HP Inc.)
  227. R2 HpReadHWData; C:\WINDOWS\system32\drivers\HpReadHWData.sys [60072 2026-02-03] (HP Inc. -> Windows (R) Win 7 DDK provider)
  228. R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82352 2026-02-10] (Microsoft Windows -> Microsoft Corporation)
  229. R0 PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [56336 2019-08-27] (Corel Corporation -> Corel Corporation)
  230. R1 rtf64; C:\WINDOWS\system32\DRIVERS\rtf64x64.sys [70560 2018-09-04] (Realtek Semiconductor Corp. -> Realtek)
  231. S3 RtkAvrcp; C:\WINDOWS\System32\drivers\RtkAvrcp.sys [88376 2018-10-23] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
  232. S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
  233. R3 ViGEmBus; C:\WINDOWS\System32\DriverStore\FileRepository\vigembus.inf_amd64_8a927fc43d8a7838\x64\ViGEmBus.sys [74264 2018-10-25] (HP Inc. -> Benjamin Hoeglinger-Stelzer)
  234. S3 vpnva; C:\WINDOWS\System32\drivers\vpnva64-6.sys [54176 2025-03-03] (Microsoft Windows Hardware Compatibility Publisher -> Cisco Systems, Inc.)
  235. S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21888 2026-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
  236. S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [25704 2020-09-10] (WDKTestCert user,132375440089837053 -> Western Digital Technologies, Inc.)
  237. R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [635272 2026-02-10] (Microsoft Windows -> Microsoft Corporation)
  238. R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102832 2026-02-10] (Microsoft Windows -> Microsoft Corporation)
  239. R3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2025-01-29] (Microsoft Windows -> Microsoft Corporation)
  240. R3 WSDScan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\WSDScan.sys [61440 2025-09-10] (Microsoft Windows -> Microsoft Corporation)
  241.  
  242. ==================== NetSvcs (Whitelisted) ===================
  243.  
  244. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  245.  
  246.  
  247. ==================== One month (created) (Whitelisted) =========
  248.  
  249. (If an entry is included in the fixlist, the file/folder will be moved.)
  250.  
  251. 2026-03-19 13:36 - 2026-03-19 13:36 - 000034089 _____ C:\Users\Shawn\Desktop\FRST.txt
  252. 2026-03-19 13:35 - 2026-03-19 13:36 - 000000000 ____D C:\FRST
  253. 2026-03-19 13:34 - 2026-03-19 13:34 - 002445312 _____ (Farbar) C:\Users\Shawn\Desktop\FRST64.exe
  254. 2026-03-19 13:22 - 2026-03-19 13:22 - 009633776 _____ (Malwarebytes) C:\Users\Shawn\Downloads\adwcleaner.exe
  255. 2026-03-19 13:22 - 2026-03-19 13:22 - 000000000 ____D C:\AdwCleaner
  256. 2026-03-19 12:55 - 2026-03-19 12:55 - 000747676 _____ C:\WINDOWS\system32\perfh007.dat
  257. 2026-03-19 12:55 - 2026-03-19 12:55 - 000531722 _____ C:\WINDOWS\system32\perfh008.dat
  258. 2026-03-19 12:55 - 2026-03-19 12:55 - 000168170 _____ C:\WINDOWS\system32\perfc007.dat
  259. 2026-03-19 12:55 - 2026-03-19 12:55 - 000100876 _____ C:\WINDOWS\system32\perfc008.dat
  260. 2026-03-19 12:51 - 2026-03-19 12:51 - 000000258 __RSH C:\ProgramData\ntuser.pol
  261. 2026-03-19 12:08 - 2026-03-19 12:08 - 012230443 _____ C:\Users\Shawn\Downloads\IMG_1106.jpeg
  262. 2026-03-19 12:08 - 2026-03-19 12:08 - 004208360 _____ C:\Users\Shawn\Downloads\IMG_1107.jpeg
  263. 2026-03-19 12:07 - 2026-03-19 12:07 - 003154772 _____ C:\Users\Shawn\Downloads\IMG_1110.jpeg
  264. 2026-03-19 12:07 - 2026-03-19 12:07 - 003147959 _____ C:\Users\Shawn\Downloads\IMG_1109.jpeg
  265. 2026-03-19 12:02 - 2026-03-19 12:03 - 000000000 ____D C:\Users\Shawn\Desktop\Computer Issue
  266. 2026-03-17 07:52 - 2026-03-17 07:52 - 000078888 _____ C:\Users\Shawn\Desktop\Mail-in Entry Form _ RallyUp.pdf
  267. 2026-03-16 08:11 - 2026-03-16 08:11 - 000000000 ____D C:\Users\Shawn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
  268. 2026-03-15 09:50 - 2026-03-19 13:01 - 000000000 ____D C:\WINDOWS\CbsTemp
  269. 2026-03-14 19:50 - 2026-03-14 19:50 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
  270. 2026-03-11 19:16 - 2026-03-11 19:16 - 002641215 _____ C:\Users\Shawn\Downloads\Advocacy Project - Final Draft  (1).pdf
  271. 2026-03-11 19:08 - 2026-03-11 19:08 - 000447333 _____ C:\Users\Shawn\Downloads\365-Article Text-1433-1-10-20160227.pdf
  272. 2026-03-11 19:01 - 2026-03-11 19:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
  273. 2026-03-11 19:01 - 2026-03-11 19:01 - 000000000 ____D C:\Program Files (x86)\Cisco
  274. 2026-03-11 17:32 - 2026-03-11 17:32 - 007038788 _____ C:\Users\Shawn\Downloads\IMG_1012.jpeg
  275. 2026-03-11 12:59 - 2026-03-11 12:59 - 010135681 _____ C:\Users\Shawn\Downloads\IMG_1066.jpeg
  276. 2026-03-11 12:59 - 2026-03-11 12:59 - 009186068 _____ C:\Users\Shawn\Downloads\IMG_1064.jpeg
  277. 2026-03-11 11:14 - 2026-03-11 11:14 - 000157059 _____ C:\Users\Shawn\Desktop\The Importance of Music Education in Schools.pdf
  278. 2026-03-11 11:02 - 2026-03-11 11:02 - 000473549 _____ C:\Users\Shawn\Desktop\business letter.pdf
  279. 2026-03-11 10:53 - 2026-03-11 10:53 - 000570535 _____ C:\Users\Shawn\Downloads\Gamer_Classroom_Resources.pdf
  280. 2026-03-10 20:11 - 2026-03-10 20:11 - 000083946 _____ C:\WINDOWS\SysWOW64\ctac.json
  281. 2026-03-10 20:11 - 2026-03-10 20:11 - 000083946 _____ C:\WINDOWS\system32\ctac.json
  282. 2026-03-10 20:11 - 2026-03-10 20:11 - 000036382 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
  283. 2026-03-10 20:11 - 2026-03-10 20:11 - 000036382 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
  284. 2026-03-09 12:30 - 2026-03-09 12:30 - 000488502 _____ C:\Users\Shawn\Desktop\BusinessLetterExampleandTemplateFreePrintable-1.pdf
  285. 2026-03-09 12:28 - 2026-03-09 12:28 - 001349625 _____ C:\Users\Shawn\Downloads\BusinessLetterExampleandTemplateFreePrintable-1.pdf
  286. 2026-03-01 14:01 - 2026-03-01 14:01 - 000157441 _____ C:\Users\Shawn\Downloads\USC 2026_ Silence &--- _Transgression_ Paper Draft #2 (Noah Jerge).pdf
  287. 2026-03-01 13:03 - 2026-03-01 13:03 - 000726245 _____ C:\Users\Shawn\Downloads\4AMartinez.pdf
  288. 2026-03-01 12:51 - 2026-03-01 12:51 - 003232223 _____ C:\Users\Shawn\Downloads\79408701900__84BE77E3-34CC-4B21-BD6C-278AE7FDBA8B.jpeg
  289. 2026-03-01 12:45 - 2026-03-01 12:45 - 002325779 _____ C:\Users\Shawn\Downloads\79408701900__84BE77E3-34CC-4B21-BD6C-278AE7FDBA8B.heic
  290. 2026-02-24 13:43 - 2026-02-24 13:43 - 000286338 _____ C:\Users\Shawn\Downloads\ASL Speech and Language Assessment_SC.pdf
  291. 2026-02-21 08:29 - 2026-03-16 08:11 - 000004254 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2500055725-1674575743-3887293998-1001
  292. 2026-02-21 08:29 - 2026-03-16 08:11 - 000001958 _____ C:\Users\Shawn\Desktop\Zoom Workplace.lnk
  293. 2026-02-19 09:12 - 2026-01-27 21:42 - 002421296 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
  294. 2026-02-19 09:12 - 2026-01-27 21:42 - 002421296 _____ C:\WINDOWS\system32\vulkaninfo.exe
  295. 2026-02-19 09:12 - 2026-01-27 21:42 - 001923120 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
  296. 2026-02-19 09:12 - 2026-01-27 21:42 - 001923120 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
  297. 2026-02-19 09:12 - 2026-01-27 21:42 - 001434672 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
  298. 2026-02-19 09:12 - 2026-01-27 21:42 - 001434672 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
  299. 2026-02-19 09:12 - 2026-01-27 21:41 - 001625648 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
  300. 2026-02-19 09:12 - 2026-01-27 21:41 - 001625648 _____ C:\WINDOWS\system32\vulkan-1.dll
  301. 2026-02-19 09:12 - 2026-01-27 21:41 - 000478952 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
  302. 2026-02-19 09:12 - 2026-01-27 21:41 - 000375016 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
  303. 2026-02-19 09:12 - 2026-01-27 21:38 - 001344744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
  304. 2026-02-19 09:12 - 2026-01-27 21:38 - 000675048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
  305. 2026-02-19 09:12 - 2026-01-27 21:38 - 000509160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
  306. 2026-02-19 09:12 - 2026-01-27 21:37 - 105303272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
  307. 2026-02-19 09:12 - 2026-01-27 21:37 - 027559656 _____ C:\WINDOWS\system32\nvidia-pcc.exe
  308. 2026-02-19 09:12 - 2026-01-27 21:37 - 002319080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
  309. 2026-02-19 09:12 - 2026-01-27 21:37 - 001716968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
  310. 2026-02-19 09:12 - 2026-01-27 21:37 - 001616104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
  311. 2026-02-19 09:12 - 2026-01-27 21:37 - 001574632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
  312. 2026-02-19 09:12 - 2026-01-27 21:37 - 001224936 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
  313. 2026-02-19 09:12 - 2026-01-27 21:37 - 001055976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
  314. 2026-02-19 09:12 - 2026-01-27 21:37 - 000812264 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
  315. 2026-02-19 09:12 - 2026-01-27 21:37 - 000137032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
  316. 2026-02-19 09:12 - 2026-01-27 21:36 - 022613224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
  317. 2026-02-19 09:12 - 2026-01-27 21:36 - 018277608 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
  318. 2026-02-19 09:12 - 2026-01-27 21:36 - 007908072 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
  319. 2026-02-19 09:12 - 2026-01-27 21:36 - 005586664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
  320. 2026-02-19 09:12 - 2026-01-27 21:36 - 004288232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
  321. 2026-02-19 09:12 - 2026-01-27 21:36 - 000469224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
  322. 2026-02-19 09:12 - 2026-01-27 21:35 - 005923048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
  323. 2026-02-19 09:12 - 2026-01-27 21:35 - 000853736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
  324. 2026-02-19 09:12 - 2026-01-27 21:34 - 005687448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
  325. 2026-02-19 09:12 - 2026-01-27 21:34 - 004975632 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
  326. 2026-02-19 09:12 - 2026-01-27 20:54 - 000153488 _____ C:\WINDOWS\system32\nvinfo.pb
  327. 2026-02-17 13:05 - 2026-02-17 13:05 - 006533364 _____ C:\Users\Shawn\Downloads\IMG_1048.jpeg
  328. 2026-02-17 13:05 - 2026-02-17 13:05 - 005977972 _____ C:\Users\Shawn\Downloads\IMG_1047.jpeg
  329. 2026-02-17 13:05 - 2026-02-17 13:05 - 005437990 _____ C:\Users\Shawn\Downloads\IMG_1046.jpeg
  330. 2026-02-17 11:47 - 2026-02-17 11:47 - 004514585 _____ C:\Users\Shawn\Desktop\sidewalk3.pdf
  331. 2026-02-17 11:46 - 2026-02-17 11:47 - 000000000 _____ C:\Users\Shawn\Desktop\sidewalk2.pdf
  332. 2026-02-17 11:46 - 2026-02-17 11:46 - 005349817 _____ C:\Users\Shawn\Desktop\sidewalk1.pdf
  333. 2026-02-17 11:44 - 2026-02-17 11:44 - 003788294 _____ C:\Users\Shawn\Downloads\IMG_1048001 (2).heic
  334. 2026-02-17 11:44 - 2026-02-17 11:44 - 003466052 _____ C:\Users\Shawn\Downloads\IMG_1047001 (2).heic
  335. 2026-02-17 11:44 - 2026-02-17 11:44 - 003166169 _____ C:\Users\Shawn\Downloads\IMG_1046 (2).heic
  336. 2026-02-17 11:38 - 2026-02-17 11:38 - 003788294 _____ C:\Users\Shawn\Downloads\IMG_1048001 (1).heic
  337. 2026-02-17 11:38 - 2026-02-17 11:38 - 003466052 _____ C:\Users\Shawn\Downloads\IMG_1047001 (1).heic
  338. 2026-02-17 11:38 - 2026-02-17 11:38 - 003166169 _____ C:\Users\Shawn\Downloads\IMG_1046 (1).heic
  339. 2026-02-17 11:35 - 2026-02-17 11:35 - 003466052 _____ C:\Users\Shawn\Downloads\IMG_1047001.heic
  340. 2026-02-17 11:34 - 2026-02-17 11:34 - 003788294 _____ C:\Users\Shawn\Downloads\IMG_1048001.heic
  341. 2026-02-17 11:34 - 2026-02-17 11:34 - 003166169 _____ C:\Users\Shawn\Downloads\IMG_1046.heic
  342.  
  343. ==================== One month (modified) ==================
  344.  
  345. (If an entry is included in the fixlist, the file/folder will be moved.)
  346.  
  347. 2026-03-19 13:22 - 2024-04-01 00:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
  348. 2026-03-19 13:14 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\AppReadiness
  349. 2026-03-19 13:02 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SystemTemp
  350. 2026-03-19 12:55 - 2025-01-28 22:19 - 002371620 _____ C:\WINDOWS\system32\PerfStringBackup.INI
  351. 2026-03-19 12:55 - 2024-04-01 00:24 - 000000000 ____D C:\WINDOWS\INF
  352. 2026-03-19 12:52 - 2023-09-13 06:17 - 000000000 ____D C:\Users\Shawn\AppData\Local\OGH
  353. 2026-03-19 12:51 - 2025-01-28 22:19 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
  354. 2026-03-19 12:51 - 2025-01-28 22:17 - 000008030 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
  355. 2026-03-19 12:51 - 2020-09-16 16:14 - 000012288 ___SH C:\DumpStack.log.tmp
  356. 2026-03-19 12:51 - 2019-07-13 22:38 - 000000000 ____D C:\ProgramData\NVIDIA
  357. 2026-03-19 12:46 - 2024-04-01 00:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI
  358. 2026-03-19 08:35 - 2024-04-01 00:26 - 000000000 ___HD C:\Program Files\WindowsApps
  359. 2026-03-19 07:39 - 2019-07-13 22:38 - 000000000 ____D C:\ProgramData\Package Cache
  360. 2026-03-18 17:56 - 2019-08-26 02:55 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
  361. 2026-03-18 07:21 - 2020-05-10 13:42 - 000000000 ____D C:\Users\Shawn\AppData\Local\D3DSCache
  362. 2026-03-17 17:12 - 2025-01-28 22:19 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2500055725-1674575743-3887293998-1001
  363. 2026-03-17 17:12 - 2025-01-28 22:19 - 000003576 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2500055725-1674575743-3887293998-1001
  364. 2026-03-17 17:12 - 2025-01-28 22:19 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2500055725-1674575743-3887293998-1001
  365. 2026-03-17 17:12 - 2020-09-16 16:15 - 000002390 _____ C:\Users\Shawn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
  366. 2026-03-17 17:07 - 2025-03-05 14:38 - 000004494 _____ C:\WINDOWS\system32\Tasks\OmenInstallMonitorCustomEvent-sid-S-1-5-21-2500055725-1674575743-3887293998-1001
  367. 2026-03-17 17:07 - 2025-03-05 14:38 - 000004092 _____ C:\WINDOWS\system32\Tasks\OmenInstallMonitor-sid-S-1-5-21-2500055725-1674575743-3887293998-1001
  368. 2026-03-17 17:07 - 2025-03-05 14:37 - 000004434 _____ C:\WINDOWS\system32\Tasks\OmenOverlayCustomEvent-sid-S-1-5-21-2500055725-1674575743-3887293998-1001
  369. 2026-03-17 17:07 - 2025-03-05 14:37 - 000004032 _____ C:\WINDOWS\system32\Tasks\OmenOverlay-sid-S-1-5-21-2500055725-1674575743-3887293998-1001
  370. 2026-03-17 07:41 - 2020-07-12 08:32 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
  371. 2026-03-17 07:41 - 2020-07-12 08:32 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
  372. 2026-03-16 20:28 - 2020-03-12 16:28 - 000000000 ____D C:\Users\Shawn\AppData\Roaming\Zoom
  373. 2026-03-14 19:49 - 2019-07-13 22:18 - 000000000 ____D C:\Program Files\Microsoft Office
  374. 2026-03-13 19:32 - 2020-03-28 08:36 - 000000000 ____D C:\Users\Shawn\AppData\Roaming\Microsoft\Teams
  375. 2026-03-11 21:19 - 2025-01-28 22:16 - 000499808 _____ C:\WINDOWS\system32\FNTCACHE.DAT
  376. 2026-03-11 21:18 - 2025-01-28 19:59 - 000000000 ____D C:\WINDOWS\InboxApps
  377. 2026-03-11 21:18 - 2024-04-01 01:08 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
  378. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ___SD C:\WINDOWS\system32\F12
  379. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
  380. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\UUS
  381. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
  382. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
  383. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
  384. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
  385. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SystemResources
  386. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
  387. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
  388. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\setup
  389. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
  390. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\oobe
  391. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
  392. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\Dism
  393. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
  394. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
  395. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\ShellComponents
  396. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\BrowserCore
  397. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\bcastdvr
  398. 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\appcompat
  399. 2026-03-11 21:18 - 2024-04-01 00:21 - 000000000 ____D C:\WINDOWS\servicing
  400. 2026-03-11 19:01 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
  401. 2026-03-11 19:01 - 2019-10-06 19:01 - 000000000 ____D C:\ProgramData\Cisco
  402. 2026-03-11 19:01 - 2019-03-18 21:52 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
  403. 2026-03-11 19:00 - 2019-10-06 19:01 - 000000000 ____D C:\Users\Shawn\AppData\Local\Cisco
  404. 2026-03-11 10:53 - 2021-08-25 08:06 - 000000000 ____D C:\Users\Shawn\Desktop\literature guides
  405. 2026-03-11 08:21 - 2024-04-01 00:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
  406. 2026-03-11 08:21 - 2024-04-01 00:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
  407. 2026-03-10 21:17 - 2019-08-26 02:50 - 000000000 ____D C:\Users\Shawn\AppData\Local\Packages
  408. 2026-03-10 20:11 - 2025-01-28 22:17 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
  409. 2026-03-06 19:08 - 2025-01-28 22:19 - 000003534 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
  410. 2026-03-06 19:08 - 2025-01-28 22:19 - 000003408 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
  411. 2026-03-01 10:11 - 2021-03-05 11:30 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
  412. 2026-02-22 18:10 - 2019-07-13 22:38 - 000000000 ____D C:\ProgramData\Packages
  413. 2026-02-21 08:29 - 2022-08-27 07:55 - 000000000 ____D C:\Users\Shawn\AppData\Local\Zoom
  414.  
  415. ==================== SigCheck ============================
  416.  
  417. (There is no automatic fix for files that do not pass verification.)
  418.  
  419. ==================== End of FRST.txt ========================
  420.  
  421. Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2026
  422. Ran by Shawn (19-03-2026 13:38:24)
  423. Running from C:\Users\Shawn\Desktop
  424. Microsoft Windows 11 Home Version 25H2 26200.8037 (X64) (2025-01-29 16:02:57)
  425. Boot Mode: Normal
  426. ==========================================================
  427.  
  428.  
  429. ==================== Accounts: =============================
  430.  
  431. (If an entry is included in the fixlist, it will be removed.)
  432.  
  433. Administrator (S-1-5-21-2500055725-1674575743-3887293998-500 - Administrators - Disabled)
  434. DefaultAccount (S-1-5-21-2500055725-1674575743-3887293998-503 - Limited - Disabled)
  435. Guest (S-1-5-21-2500055725-1674575743-3887293998-501 - Limited - Disabled)
  436. Shawn (S-1-5-21-2500055725-1674575743-3887293998-1001 - Administrators - Enabled) => C:\Users\Shawn
  437. WDAGUtilityAccount (S-1-5-21-2500055725-1674575743-3887293998-504 - Limited - Disabled)
  438.  
  439. ==================== Security Center ========================
  440.  
  441. (If an entry is included in the fixlist, it will be removed.)
  442.  
  443. AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
  444. AV: Bitdefender Antivirus (Enabled - Out of date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318}
  445. FW: Bitdefender Firewall (Disabled) {362C5A58-E860-6396-9204-BEEEF20CA463}
  446.  
  447. ==================== Installed Programs ======================
  448.  
  449. (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
  450.  
  451. Audacity 2.3.2 (HKLM-x32\...\Audacity_is1) (Version: 2.3.2 - Audacity Team)
  452. Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 27.1.1.28 - Bitdefender)
  453. Cisco Secure Client - AnyConnect VPN  (HKLM-x32\...\Cisco Secure Client - AnyConnect VPN) (Version: 5.1.8.122 - Cisco Systems, Inc.)
  454. Cisco Secure Client - AnyConnect VPN (HKLM-x32\...\{151DF30F-CEE5-41EF-BB4A-3E7C128D897E}) (Version: 5.1.8.122 - Cisco Systems, Inc.) Hidden
  455. Google Chrome (HKLM-x32\...\Google Chrome) (Version: 146.0.7680.81 - Google LLC)
  456. HP Audio Switch (HKLM-x32\...\{3A5141D4-47DB-4302-9B1C-272BE585BC8A}) (Version: 1.0.179.0 - HP Inc.)
  457. HP Connection Optimizer (HKLM-x32\...\{6468C4A5-E47E-405F-B675-A70A70983EA6}) (Version: 2.0.15.0 - HP Inc.)
  458. HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
  459. HP One Agent (HKLM\...\{5D13F424-BCC0-4AB9-804C-713EE5C9CBAC}) (Version: 1.2.55.3578 - HP Inc.) Hidden
  460. HP One Agent (HKLM\...\{DD84A52B-8D5B-484F-82D4-5AEA657B6A21}) (Version: 1.2.055.3578 - HP Inc.)
  461. Intel Driver && Support Assistant (HKLM-x32\...\{90EFD4CC-39A4-4470-AEEB-878CB2BCBC81}) (Version: 25.4.36.6 - Intel) Hidden
  462. Intel XTU SDK (HKLM-x32\...\{43A58350-CB99-4F4E-9BB6-F058D7B27985}) (Version: 1.0.13 - HP Inc.) Hidden
  463. Intel(R) Computing Improvement Program (HKLM\...\{2D924248-D4EE-45BA-BDDB-1FA8828CF5CA}) (Version: 2.4.10852 - Intel Corporation)
  464. Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 17.2.0.1009 - Intel Corporation)
  465. Intel(R) Rapid Storage Technology (HKLM\...\{6FAD098A-45B9-49CC-AE46-58080ED096D7}) (Version: 17.2.0.1009 - Intel Corporation) Hidden
  466. Intel® Driver & Support Assistant (HKLM-x32\...\{4152D055-4116-42A3-BC9E-86D0A17B35A5}) (Version: 25.4.36.6 - Intel)
  467. Microsoft .NET Host - 8.0.14 (x64) (HKLM\...\{04904762-A110-4E46-A728-7EF88DCCA1F1}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
  468. Microsoft .NET Host - 8.0.14 (x86) (HKLM-x32\...\{CB771E25-82B7-435C-B8CF-1DAF85D9A373}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
  469. Microsoft .NET Host FX Resolver - 8.0.14 (x64) (HKLM\...\{B2E7F2C8-73CD-4269-B7BC-11B7D8BB7A37}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
  470. Microsoft .NET Host FX Resolver - 8.0.14 (x86) (HKLM-x32\...\{455AA7CD-6D99-4039-95D2-FF1A437FD444}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
  471. Microsoft .NET Runtime - 8.0.14 (x64) (HKLM\...\{6C817CE3-32BC-4C6B-8B1A-E6F71EDAFFCC}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
  472. Microsoft .NET Runtime - 8.0.14 (x64) (HKLM-x32\...\{a6918640-3436-4607-9108-9b6038e680d6}) (Version: 8.0.14.34611 - Microsoft Corporation)
  473. Microsoft .NET Runtime - 8.0.14 (x86) (HKLM-x32\...\{6E39BE88-1272-4732-A962-9B34A31EE12C}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
  474. Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.19725.20172 - Microsoft Corporation)
  475. Microsoft 365 Apps for enterprise - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.19725.20172 - Microsoft Corporation)
  476. Microsoft ASP.NET Core 8.0.14 - Shared Framework (x86) (HKLM-x32\...\{b4843496-41d3-405c-b4c6-2ff39b7609ed}) (Version: 8.0.14.25112 - Microsoft Corporation)
  477. Microsoft ASP.NET Core 8.0.14 Shared Framework (x86) (HKLM-x32\...\{BBD33465-6641-37D3-9444-5CCD7FE71A79}) (Version: 8.0.14.25112 - Microsoft Corporation) Hidden
  478. Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 146.0.3856.62 - Microsoft Corporation)
  479. Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 146.0.3856.62 - Microsoft Corporation) Hidden
  480. Microsoft OneDrive (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\OneDriveSetup.exe) (Version: 26.032.0217.0003 - Microsoft Corporation)
  481. Microsoft Teams (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\Teams) (Version: 1.3.00.12058 - Microsoft Corporation)
  482. Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.25.28902 - Microsoft)
  483. Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
  484. Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
  485. Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
  486. Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
  487. Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
  488. Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
  489. Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
  490. Microsoft Windows Desktop Runtime - 8.0.14 (x86) (HKLM-x32\...\{F12CDBC1-172E-4413-829C-B5234E386262}) (Version: 64.56.29521 - Microsoft Corporation) Hidden
  491. Microsoft Windows Desktop Runtime - 8.0.14 (x86) (HKLM-x32\...\{f70d61fa-5d61-4582-bf8d-07dec8e4fcda}) (Version: 8.0.14.34613 - Microsoft Corporation)
  492. NVIDIA FrameView SDK 1.1.4923.29968894 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.1.4923.29968894 - NVIDIA Corporation)
  493. NVIDIA Graphics Driver 591.55 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 591.55 - NVIDIA Corporation)
  494. NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
  495. Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.19725.20172 - Microsoft Corporation) Hidden
  496. Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.19029.20208 - Microsoft Corporation) Hidden
  497. Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
  498. REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 1.0.0.100 - REALTEK Semiconductor Corp.)
  499. Sound Organizer (HKLM-x32\...\{A4054A95-135B-4F0B-879A-28C522770732}) (Version: 1.6.3.09160 - Sony Home Entertainment & Sound Products Inc.)
  500. Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.3.0.362 - Microsoft Corporation)
  501. Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{82BD0A1C-815F-487F-9AE7-CE73DA413CFF}) (Version: 4.91.0.0 - Microsoft Corporation)
  502. Wargaming.net Game Center (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\Wargaming.net Game Center) (Version: 26.1.0.1957 - Wargaming.net)
  503. Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
  504. World of Tanks NA (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\740900249) (Version:  - Wargaming.net)
  505. Zoom Workplace (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\ZoomUMX) (Version: 6.7.8 (32670) - Zoom Communications, Inc.)
  506.  
  507. Chrome apps:
  508. ============
  509. Canvas (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\5df79f5e9de0655d115e195a7deef125) (Version: 1.0 - Google\Chrome)
  510.  
  511. Packages:
  512. =========
  513. @{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-12] ()
  514. 5A894077.McAfeeSecurity -> C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.68.0_x64__wafk5atnkzcwy [2025-01-16] (McAfee LLC.)
  515. Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_5.0.0.0_x64__kgqvnymyfvs32 [2026-03-18] (king.com)
  516. Dropbox promotion -> C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_23.4.36.0_x64__xbfy0k16fey96 [2025-11-22] (Dropbox Inc.)
  517. Farm Heroes Saga -> C:\Program Files\WindowsApps\king.com.FarmHeroesSaga_6.85.12.0_x64__kgqvnymyfvs32 [2026-03-19] (king.com)
  518. Honey -> C:\Program Files\WindowsApps\HoneyScienceCorporation.Honey_11.4.2.0_neutral__cbe4c63gm1mzr [2020-06-15] (Honey Science Corporation)
  519. HP Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.HPAudioControl_1.10.216.0_x64__dt26b99r8h8gj [2020-09-17] (Realtek Semiconductor Corp)
  520. HP Inc. Energy Star -> C:\Program Files\WindowsApps\AD2F1837.HPInc.EnergyStar_2.0.11.0_x64__v10z8vjag6ke6 [2026-01-27] (HP Inc.)
  521. HP JumpStarts -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStarts_1.10.1627.0_x64__v10z8vjag6ke6 [2024-02-07] (HP Inc.)
  522. HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_3.0.0.0_x64__v10z8vjag6ke6 [2026-01-27] (HP Inc.)
  523. HP Privacy Settings -> C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.4.17.0_x64__v10z8vjag6ke6 [2025-08-22] (HP Inc.)
  524. HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_163.1.1121.0_x64__v10z8vjag6ke6 [2026-01-17] (HP Inc.)
  525. HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.51.14.0_x64__v10z8vjag6ke6 [2026-02-11] (HP Inc.)
  526. HP System Event Utility -> C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.16.0_x64__v10z8vjag6ke6 [2026-02-12] (HP Inc.)
  527. iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa [2026-03-05] (Apple Inc.) [Startup Task]
  528. LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_3.0.43.0_x64__w1wdnht996qgy [2025-12-20] (LinkedIn) [Startup Task]
  529. Local AI Manager for Microsoft 365 -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\AI [2026-03-15] ()
  530. Microsoft 365 companion apps -> C:\Program Files\WindowsApps\Microsoft.M365Companions_2.2510.30002.0_x64__8wekyb3d8bbwe [2025-11-09] (Microsoft Corporation)
  531. Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-08-28] (Microsoft Corporation) [MS Ad]
  532. Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-08-28] (Microsoft Corporation) [MS Ad]
  533. Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2023-10-08] (Microsoft Corp.)
  534. Microsoft Office Outlook Desktop Integration -> C:\Program Files\WindowsApps\Microsoft.OutlookDesktopIntegrationServices_16009.11426.10000.0_x64__8wekyb3d8bbwe [2019-08-28] (Microsoft Corporation)
  535. Microsoft.Office.ActionsServer -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\ActionsServer [2026-03-15] ()
  536. Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_7.0.8.0_neutral__mcm4njqhnhss8 [2024-10-09] (Netflix, Inc.)
  537. OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2026-03-15] ()
  538. OMEN Gaming Hub -> C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6 [2026-03-17] (HP Inc.) [Startup Task]
  539. Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2022-10-25] (Microsoft Corporation)
  540. Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-08-24] (Microsoft Corporation)
  541. PrivacyBrowse -> C:\Program Files\WindowsApps\PrivacyBrowse.PrivacyBrowse_1.12.78.0_neutral__hz4wbnfrnhwdr [2026-01-26] (PrivacyBrowse) [Startup Task]
  542. SpotifyAB.SpotifyMusic -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0 [2026-03-17] (Spotify AB) [Startup Task]
  543. Warhammer: Chaos & Conquest -> C:\Program Files\WindowsApps\TiltingPoint.WarhammerChaosConquest_4.9.3.0_x64__85kh3h6wfjavg [2026-01-20] (Tilting Point)
  544. WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe [2025-01-29] (Microsoft Corp.)
  545. WinAppRuntime.Main.1.8 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.8_8000.770.947.0_x64__8wekyb3d8bbwe [2026-03-11] (Microsoft Corp.)
  546. WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_8000.770.947.0_x64__8wekyb3d8bbwe [2026-02-26] (Microsoft Corp.)
  547.  
  548. ==================== Custom CLSID (Whitelisted): ==============
  549.  
  550. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  551.  
  552. CustomCLSID: HKU\S-1-5-21-2500055725-1674575743-3887293998-1001_Classes\CLSID\{7d043d4e-4259-f459-3630-7b434fd7752c}\localserver32 -> C:\Program Files\HP\HP Media Network\HPMediaNetwork.exe (HP Inc. -> HP Inc.)
  553. CustomCLSID: HKU\S-1-5-21-2500055725-1674575743-3887293998-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)
  554. CustomCLSID: HKU\S-1-5-21-2500055725-1674575743-3887293998-1001_Classes\CLSID\{EABAE40C-B27C-455A-B672-F234DD780948}\InprocServer32 -> C:\Users\Shawn\AppData\Local\Microsoft\TeamsMeetingAdd-in\1.25.28902\x64\Microsoft.Teams.MeetingAddin.DLL (Microsoft Corporation -> Microsoft Corporation)
  555. ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvhdc.inf_amd64_1f7c5b9c4ae7ca18\nvshext.dll [2026-01-28] (NVIDIA Corporation -> NVIDIA Corporation)
  556.  
  557. ==================== Codecs (Whitelisted) ====================
  558.  
  559. (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
  560.  
  561. HKLM\...\Drivers32: [MidisrvTransferComplete] => 1
  562. HKLM\...\Drivers32: [midi1] => C:\windows\system32\wdmaud2.drv [143360 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
  563. HKLM\...\Drivers32: [midi1] => C:\Windows\SysWOW64\wdmaud2.drv [91648 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
  564.  
  565. ==================== Shortcuts & WMI ========================
  566.  
  567. (The entries could be listed to be restored or removed.)
  568.  
  569. ShortcutWithArgument: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_dllcofknkgglcjbggfompcepknpmfkmn\Canvas.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=dllcofknkgglcjbggfompcepknpmfkmn
  570. ShortcutWithArgument: C:\Users\Shawn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Canvas.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=dllcofknkgglcjbggfompcepknpmfkmn
  571.  
  572. ==================== Loaded Modules (Whitelisted) =============
  573.  
  574. 2026-02-19 09:10 - 2026-02-19 09:10 - 000138240 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Interop.IWs06dcaa36#\6e82ef8f4d42ed6f6bb0067709fb22bf\Interop.IWshRuntimeLibrary.ni.dll
  575. 2026-02-19 09:10 - 2026-02-19 09:10 - 000134656 _____ (hardcodet.net) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Hardcodet.W6cab32f3#\0d4bf7bf8fe17d6c481ab2a2fc5e3a91\Hardcodet.Wpf.TaskbarNotification.ni.dll
  576. 2026-02-19 09:10 - 2026-02-19 09:10 - 001700864 _____ (Mark Heath & Contributors) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\NAudio\35ded6b5142bf6dd7a4ec2953017231b\NAudio.ni.dll
  577. 2026-02-19 09:10 - 2026-02-19 09:10 - 003062272 _____ (Newtonsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\75d29f4e30e92bd7812c67ebbcf8704e\Newtonsoft.Json.ni.dll
  578. 2024-05-23 23:54 - 2024-05-23 23:54 - 003164160 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll
  579. 2026-02-19 09:10 - 2026-02-19 09:10 - 000793088 _____ (The Apache Software Foundation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\log4net\4c331f508c595b8976e89765f9f04b88\log4net.ni.dll
  580.  
  581. ==================== Alternate Data Streams (Whitelisted) ========
  582.  
  583. ==================== Safe Mode (Whitelisted) ==================
  584.  
  585. ==================== Association (Whitelisted) =================
  586.  
  587. ==================== Internet Explorer (Whitelisted) =============
  588.  
  589. HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
  590. HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
  591. HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
  592. HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
  593. BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2026-02-01] (Microsoft Corporation -> Microsoft Corporation)
  594. BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2026-01-27] (HP Inc. -> HP Inc.)
  595. BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2026-02-01] (Microsoft Corporation -> Microsoft Corporation)
  596. BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2026-01-27] (HP Inc. -> HP Inc.)
  597. Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
  598. Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
  599. Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
  600. Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
  601. Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
  602. Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
  603. Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
  604. Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
  605.  
  606. (If an entry is included in the fixlist, it will be removed from the registry.)
  607.  
  608. IE trusted site: HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\sharepoint.com -> hxxps://arizonastateu-files.sharepoint.com
  609.  
  610. ==================== Hosts content: =========================
  611.  
  612. (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
  613.  
  614. 2019-03-18 21:49 - 2021-03-15 07:04 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
  615.  
  616. 2023-06-30 19:14 - 2023-07-11 19:09 - 000000511 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
  617. 192.168.137.1 DESKTOP-T985JJS.mshome.net # 2028 7 1 10 2 9 50 33
  618. 192.168.137.228 tv647f1faca706.mshome.net # 2023 7 3 19 2 9 50 33
  619. 79
  620.  
  621. ==================== Network ===========================
  622.  
  623. (Currently there is no automatic fix for this section.)
  624.  
  625. DNS Servers: 68.105.28.11 - 68.105.29.11
  626. Windows Firewall is enabled.
  627.  
  628. Network Binding:
  629. =============
  630. Bluetooth Network Connection: Bluetooth Device (Personal Area Network) -> bthpan.sys
  631. Wi-Fi: Realtek RTL8822BE 802.11ac PCIe Adapter -> rtwlane.sys
  632. Ethernet: Realtek Gaming GbE Family Controller -> rt640x64.sys
  633. Ethernet 2: Cisco AnyConnect Virtual Miniport Adapter for Windows x64 -> vpnva64-6.sys
  634.  
  635. nt_rtf64: Realtek LightWeight Filter (NDIS6.40)
  636.  
  637. ==================== Other Areas ===========================
  638.  
  639. (Currently there is no automatic fix for this section.)
  640.  
  641. HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Shawn\Desktop\Cissy and Colton.JPG
  642. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
  643. HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
  644. HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
  645.  
  646.  
  647. ==================== MSCONFIG/TASK MANAGER disabled items ==
  648.  
  649. (If an entry is included in the fixlist, it will be removed.)
  650.  
  651. HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\StartupApproved\Run: => "OneDrive"
  652. HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\StartupApproved\Run: => "com.squirrel.Teams.Teams"
  653. HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\StartupApproved\Run: => "Wargaming.net Game Center"
  654. HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_F4A14294D510213A98E2241942C236B4"
  655.  
  656. ==================== FirewallRules (Whitelisted) ================
  657.  
  658. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  659.  
  660. FirewallRules: [UDP Query User{13044352-0C1C-4E7A-BB79-A70FF6139A48}C:\games\world_of_tanks_na\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_na\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
  661. FirewallRules: [TCP Query User{52CB5D8B-3290-4C10-A2B0-ED1675E4F4CF}C:\games\world_of_tanks_na\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_na\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
  662. FirewallRules: [UDP Query User{0CBE75F1-0B28-4BD9-AEC6-5B22D21F05D9}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
  663. FirewallRules: [TCP Query User{163FC5C4-F598-4208-962F-A49FA509D605}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
  664. FirewallRules: [{0E94816A-7A1F-44EA-A1BD-F9E5A2BA200A}] => (Allow) C:\Users\Shawn\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
  665. FirewallRules: [{EE150662-6E3A-4ECA-ACD0-350DC04E091D}] => (Allow) C:\Users\Shawn\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)
  666. FirewallRules: [{7344F7E1-FCC0-4122-8907-A31AC04EF4E8}] => (Allow) C:\Users\Shawn\AppData\Local\Temp\7zS5F4C\HPDiagnosticCoreUI.exe => No File
  667. FirewallRules: [{A8B59A64-2355-439A-A09A-2B3397BBB9D0}] => (Allow) C:\Users\Shawn\AppData\Local\Temp\7zS5F4C\HPDiagnosticCoreUI.exe => No File
  668. FirewallRules: [{0154D2ED-EDBF-4F22-A88A-A7F8984515EA}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File
  669. FirewallRules: [{7D675D5C-F673-4574-86AB-F69428132125}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File
  670. FirewallRules: [TCP Query User{66011213-D03E-47EA-80F9-3263200DA44D}C:\programdata\wargaming.net\gamecenter\dlls\wgc_renderer.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\dlls\wgc_renderer.exe => No File
  671. FirewallRules: [UDP Query User{ECE8CFFA-E454-4C73-8A40-62E311FFC860}C:\programdata\wargaming.net\gamecenter\dlls\wgc_renderer.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\dlls\wgc_renderer.exe => No File
  672. FirewallRules: [TCP Query User{83AD16C9-1F68-4BE5-BC88-CB05CCF6927D}C:\games\world_of_tanks_na\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_na\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
  673. FirewallRules: [UDP Query User{72EDDD56-2930-4A64-8DD6-1E835D0C05AA}C:\games\world_of_tanks_na\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_na\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
  674. FirewallRules: [TCP Query User{B7F020F6-CF25-48BC-B3E2-BE2C36FC39D1}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
  675. FirewallRules: [UDP Query User{80A3AB49-FF78-4D7B-882B-C3BCAEA1AA0B}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
  676. FirewallRules: [TCP Query User{D58F0F94-3FE0-44CB-8EBE-75F689B9A991}C:\logic 2010\jre8\bin\javaw.exe] => (Block) C:\logic 2010\jre8\bin\javaw.exe
  677. FirewallRules: [UDP Query User{C8DC22FC-F493-4BFF-8D4D-32425D1FD729}C:\logic 2010\jre8\bin\javaw.exe] => (Block) C:\logic 2010\jre8\bin\javaw.exe
  678. FirewallRules: [{F69F7055-B4FF-4A5C-8D98-E1EFE4243A1A}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
  679. FirewallRules: [{03624C11-131E-4D56-9FC8-E26CB44A546B}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
  680. FirewallRules: [{E966BDCF-415B-457D-AF39-4A17932EDF8C}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
  681. FirewallRules: [{57655C02-FFA5-4AC3-969E-DD82BD539811}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
  682. FirewallRules: [{0542C740-B058-4323-AA5F-45C6EA0C5E39}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_25240.1702.3948.231_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
  683. FirewallRules: [{7D4D4B74-D57B-4EA4-9899-DFA3A5754B13}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_25240.1702.3948.231_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
  684. FirewallRules: [{96548191-CD33-4E3E-A29F-EA0AD86CEEEA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
  685. FirewallRules: [{678551F3-49B5-487E-95EA-1F802BD3D5F0}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
  686. FirewallRules: [{E574A48F-E014-4378-BAC1-B7B80612BFBB}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
  687. FirewallRules: [{7F958B11-2459-46BF-8C1B-96F6284446B2}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
  688. FirewallRules: [{08676CA1-A23B-4328-AE57-AD8B527074BF}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
  689. FirewallRules: [{DE5BF8C8-0810-402F-837B-9BFB27DBDB9C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
  690. FirewallRules: [{94173872-E621-446C-BB91-480ABEEA7313}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
  691. FirewallRules: [{09F2BAF3-D12C-4CE0-8B73-A6A0307E1CC7}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
  692. FirewallRules: [{3ABED116-6E8F-4309-8D6D-D0A15A25F6B7}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
  693. FirewallRules: [{752204AB-D858-4F2D-B611-7280AFC2C2E4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  694. FirewallRules: [{7CD4DB78-6142-4108-908D-8FD858EFD465}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  695. FirewallRules: [{066EA940-90A4-4D82-90C9-5EB958533DC3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  696. FirewallRules: [{F0E4D8C4-F175-43C7-AE1D-5F9B8D28BD0C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  697. FirewallRules: [{5B8A2390-DB37-4219-834E-F07AA30BB74A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  698. FirewallRules: [{81970A32-C50F-4DF0-8162-4948562A8FFE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  699. FirewallRules: [{154A8714-A6CD-432A-AE5E-BB536A1C4BE9}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  700. FirewallRules: [{66E07B69-2747-4BBC-9104-EA489F736CAC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  701. FirewallRules: [{0A1ECAA7-58C0-49C4-8149-98810BA8D4A5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  702. FirewallRules: [{5E60E86E-DEC9-4CBF-896A-E6FE70DC75E7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  703. FirewallRules: [{E44D875F-C09B-4F3B-AF80-A5C7CAC55B2F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  704. FirewallRules: [{258739E2-6BA7-4E01-A74E-6DB935F6A453}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  705. FirewallRules: [{BDB52DF2-3DAB-4A3C-B1E8-34BECDD2A6A3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
  706. FirewallRules: [{8191C0CD-297A-44F8-B132-B5458733154D}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  707. FirewallRules: [{12EF7413-6F32-4F4E-8BA7-EF30B3B3AF2D}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  708. FirewallRules: [{C8D5693B-01CA-4094-B870-5A1F84D5054E}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  709. FirewallRules: [{DCF3BC5A-C355-4269-A46C-B64D5AE46C05}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  710. FirewallRules: [{AFBFB249-EAE8-44D7-8763-A01E0451B8CD}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  711. FirewallRules: [{226EA912-7F26-4838-A9C5-65E9E6E06A40}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  712. FirewallRules: [{3BC061BB-E945-4D20-B6CF-0530CD69C272}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  713. FirewallRules: [{44D64436-098A-4901-8AF2-EAC52FC3B4F0}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  714. FirewallRules: [{FE04052D-A83D-4961-B3CB-6880CE9B00CE}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  715. FirewallRules: [{EF29F911-383C-4396-A6C1-7D9C125FAE75}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  716. FirewallRules: [{74BC21A7-DFC0-4010-85CE-1DD0101026E0}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  717. FirewallRules: [{14CFE3FE-AFC4-4C82-8735-2799BC8C155F}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  718. FirewallRules: [{CE9B81AF-C038-4624-ABAE-9A41EBC7EA2A}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  719. FirewallRules: [{3D36B41D-F256-4FB4-9D6C-293E377BCAB5}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  720. FirewallRules: [{7C77C075-9027-4A8B-8C43-F5D0831A1BEF}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  721. FirewallRules: [{F25CE54F-29DA-46D5-935C-EE73E429E364}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
  722. FirewallRules: [{E59D7858-C57C-40EE-9691-878B49E9F54F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
  723.  
  724. ==================== Restore Points =========================
  725.  
  726. 17-03-2026 08:13:01 Windows Update
  727.  
  728. ==================== Faulty Device Manager Devices ============
  729. Name: Cisco AnyConnect Virtual Miniport Adapter for Windows x64
  730. Description: Cisco AnyConnect Virtual Miniport Adapter for Windows x64
  731. Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
  732. Manufacturer: Cisco Systems
  733. Service: vpnva
  734. Problem: : This device is disabled. (Code 22)
  735. Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
  736.  
  737.  
  738. ==================== Event log errors: ========================
  739.  
  740. Application errors:
  741. ==================
  742. Error: (03/19/2026 12:52:54 PM) (Source: MsiInstaller) (EventID: 1013) (User: NT AUTHORITY)
  743. Description: Product: HP Display Control Service -- The device is not a supported system. Aborting installation.
  744.  
  745. Error: (03/19/2026 12:52:54 PM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
  746. Description: Product: HP Display Control Service -- The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2753. The arguments are: DisplayControl, ,
  747.  
  748. Error: (03/19/2026 12:51:44 PM) (Source: .NET Runtime) (EventID: 1023) (User: )
  749. Description: Description: A .NET application failed.
  750. Application: DSAArcDetect64.exe
  751. Path: C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe
  752. Message: You must install or update .NET to run this application.
  753.  
  754. App: C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe
  755. Architecture: x64
  756. Framework: 'Microsoft.WindowsDesktop.App', version '8.0.0' (x64)
  757. .NET location: C:\Program Files\dotnet\
  758.  
  759. No frameworks were found.
  760.  
  761. Learn more:
  762. https://aka.ms/dotnet/app-launch-failed
  763.  
  764. To install missing framework, download:
  765. https://aka.ms/dotnet-core-applaunch?framework=Microsoft.WindowsDesktop.App&framework_version=8.0.0&arch=x64&rid=win-x64&os=win10
  766.  
  767. Error: (03/19/2026 07:41:29 AM) (Source: MsiInstaller) (EventID: 1013) (User: NT AUTHORITY)
  768. Description: Product: HP Display Control Service -- The device is not a supported system. Aborting installation.
  769.  
  770. Error: (03/19/2026 07:41:29 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
  771. Description: Product: HP Display Control Service -- The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2753. The arguments are: DisplayControl, ,
  772.  
  773. Error: (03/19/2026 07:40:43 AM) (Source: MsiInstaller) (EventID: 1013) (User: NT AUTHORITY)
  774. Description: Product: HP Display Control Service -- The device is not a supported system. Aborting installation.
  775.  
  776. Error: (03/19/2026 07:40:42 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
  777. Description: Product: HP Display Control Service -- The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2753. The arguments are: DisplayControl, ,
  778.  
  779. Error: (03/18/2026 06:11:22 PM) (Source: .NET Runtime) (EventID: 1023) (User: )
  780. Description: Description: A .NET application failed.
  781. Application: DSAArcDetect64.exe
  782. Path: C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe
  783. Message: You must install or update .NET to run this application.
  784.  
  785. App: C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe
  786. Architecture: x64
  787. Framework: 'Microsoft.WindowsDesktop.App', version '8.0.0' (x64)
  788. .NET location: C:\Program Files\dotnet\
  789.  
  790. No frameworks were found.
  791.  
  792. Learn more:
  793. https://aka.ms/dotnet/app-launch-failed
  794.  
  795. To install missing framework, download:
  796. https://aka.ms/dotnet-core-applaunch?framework=Microsoft.WindowsDesktop.App&framework_version=8.0.0&arch=x64&rid=win-x64&os=win10
  797.  
  798.  
  799. System errors:
  800. =============
  801. Error: (03/19/2026 12:54:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
  802. Description: The Energy Server Service queencreek service terminated unexpectedly.  It has done this 1 time(s).
  803.  
  804. Error: (03/17/2026 08:42:08 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
  805. Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9PC1H9VN18CM-Microsoft.StartExperiencesApp.
  806.  
  807. Error: (03/17/2026 08:40:46 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
  808. Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller.
  809.  
  810. Error: (03/17/2026 08:15:23 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
  811. Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9NQDW009T0T5-AD2F1837.OMENCommandCenter.
  812.  
  813. Error: (03/17/2026 08:13:11 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
  814. Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9NCBCSZSJRSB-SpotifyAB.SpotifyMusic.
  815.  
  816. Error: (03/13/2026 08:15:21 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T985JJS)
  817. Description: The server Windows.Media.Capture.Internal.AppCaptureShell did not register with DCOM within the required timeout.
  818.  
  819. Error: (03/12/2026 09:03:40 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
  820. Description: The DTS APO3 Service service terminated unexpectedly.  It has done this 1 time(s).
  821.  
  822. Error: (03/12/2026 07:50:47 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
  823. Description: The Energy Server Service queencreek service terminated unexpectedly.  It has done this 1 time(s).
  824.  
  825.  
  826. Windows Defender:
  827. ================
  828. Date: 2026-03-18 21:07:33
  829. Description:
  830. Microsoft Defender Antivirus scan has been stopped before completion.
  831. Scan Type: Antimalware
  832. Scan Parameters: Quick Scan
  833. Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
  834.  
  835. Date: 2026-03-17 19:51:53
  836. Description:
  837. Microsoft Defender Antivirus scan has been stopped before completion.
  838. Scan Type: Antimalware
  839. Scan Parameters: Quick Scan
  840. Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
  841.  
  842. Date: 2026-03-16 21:13:09
  843. Description:
  844. Microsoft Defender Antivirus scan has been stopped before completion.
  845. Scan Type: Antimalware
  846. Scan Parameters: Quick Scan
  847. Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
  848.  
  849. Date: 2026-03-15 20:10:10
  850. Description:
  851. Microsoft Defender Antivirus scan has been stopped before completion.
  852. Scan Type: Antimalware
  853. Scan Parameters: Quick Scan
  854. Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
  855.  
  856. Date: 2026-03-14 19:49:11
  857. Description:
  858. Microsoft Defender Antivirus scan has been stopped before completion.
  859. Scan Type: Antimalware
  860. Scan Parameters: Quick Scan
  861. Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
  862. Event[0]
  863.  
  864. Date: 2026-02-18 09:23:58
  865. Description:
  866. Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
  867. Security intelligence Attempted: Current
  868. Error Code: 0x80501102
  869. Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
  870. Security intelligence Version: 1.445.125.0;1.445.125.0
  871. Engine Version: 1.1.26010.1
  872.  
  873. Date: 2025-11-18 07:43:54
  874. Description:
  875. Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
  876. New security intelligence Version:
  877. Previous security intelligence Version: 1.441.286.0
  878. Update Source: Microsoft Update Server
  879. Security intelligence Type: AntiVirus
  880. Update Type: Full
  881. Current Engine Version:
  882. Previous Engine Version: 1.1.25100.9002
  883. Error code: 0x80240016
  884. Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.  
  885.  
  886. ==================== Memory info ===========================
  887.  
  888. BIOS: AMI F.33 04/19/2023
  889. Motherboard: HP 84FD
  890. Processor: Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
  891. Percentage of memory in use: 47%
  892. Total physical RAM: 16255.48 MB
  893. Available physical RAM: 8574.46 MB
  894. Total Virtual: 17279.48 MB
  895. Available Virtual: 7498.26 MB
  896.  
  897. ==================== Drives ================================
  898.  
  899. Drive c: (Windows) (Fixed) (Total:237.37 GB) (Free:21.08 GB) (Model: WDC PC SN520 SDAPNUW-256G-1006) NTFS
  900.  
  901. \\?\Volume{46b82d00-bc80-445b-9d4a-eca6e588ab56}\ () (Fixed) (Total:0.83 GB) (Free:0.07 GB) NTFS
  902. \\?\Volume{2315f355-5eab-4d2f-ba8c-8fa158686f83}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.16 GB) FAT32
  903.  
  904. ==================== MBR & Partition Table ====================
  905.  
  906. ==========================================================
  907. Disk: 0 (Size: 238.5 GB) (Disk ID: C5E07C1B)
  908.  
  909. Partition: GPT.
  910.  
  911. ==================== End of Addition.txt =======================