- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2026
- Ran by Shawn (administrator) on DESKTOP-T985JJS (HP OMEN by HP Obelisk Desktop 875-0xxx) (19-03-2026 13:36:12)
- Running from C:\Users\Shawn\Desktop\FRST64.exe
- Loaded Profiles: Shawn
- Platform: Microsoft Windows 11 Home Version 25H2 26200.8037 (X64) Language: English (United States)
- Default browser: Edge
- Boot Mode: Normal
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
- (C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSATray.exe
- (C:\Program Files\Bitdefender Agent\ProductAgentService.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\27.1.1.28\DiscoverySrv.exe
- (C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.16.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityBackground.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.16.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityHost.exe
- (C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyWidgetProvider.exe ->) (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\crashpad_handler.exe
- (Cisco Systems, Inc. -> Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco Secure Client\UI\csc_ui.exe
- (DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\BridgeCommunication.exe
- (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.16.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityBackground.exe
- (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe
- (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <15>
- (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek) C:\Program Files (x86)\REALTEK\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe
- (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Media Network\HPMediaNetwork.exe
- (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
- (services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
- (services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\redline\bdredline.exe
- (services.exe ->) (Cisco Systems, Inc. -> Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco Secure Client\vpnagent.exe
- (services.exe ->) (DTS, Inc. -> ) C:\Windows\System32\DTS\PC\APO3x\DTSAPO3Service.exe
- (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe
- (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
- (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_ef460d1f2a35fc16\x64\TouchpointAnalyticsClientService.exe
- (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\AppHelperCap.exe
- (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\DiagsCap.exe
- (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\NetworkCap.exe
- (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\SysInfoCap.exe
- (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_3c97e435117f8c16\x64\OmenCap\OmenCap.exe
- (services.exe ->) (HP Inc. -> HP Inc; HP Development Company, L.P.) C:\Program Files\HP\HP One Agent\hp-one-agent-service.exe
- (services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
- (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
- (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
- (services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
- (services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe
- (services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe
- (services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
- (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
- (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
- (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpDefenderCoreService.exe
- (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MsMpEng.exe
- (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\NisSrv.exe
- (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvhdc.inf_amd64_1f7c5b9c4ae7ca18\Display.NvContainer\NVDisplay.Container.exe <2>
- (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
- (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
- (sihost.exe ->) (649690DD-9BE8-48E7-8019-88DCA877AF4E -> McAfee, LLC) C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.68.0_x64__wafk5atnkzcwy\Win32\mcafee-security-ft.exe
- (sihost.exe ->) (E2014DE2-35CD-415B-AA3F-BC64B1D1F3B9 -> The NW.js Community) C:\Program Files\WindowsApps\PrivacyBrowse.PrivacyBrowse_1.12.78.0_neutral__hz4wbnfrnhwdr\VFS\AppData\PrivacyBrowse\PrivacyBrowse.exe <8>
- (svchost.exe ->) (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyWidgetProvider.exe
- (svchost.exe ->) (649690DD-9BE8-48E7-8019-88DCA877AF4E -> McAfee LLC) C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.68.0_x64__wafk5atnkzcwy\mcafee-security.exe
- (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
- (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe
- (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\Overlay\OverlayHelper.exe
- (svchost.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe
- (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.241.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe
- ==================== Registry (Whitelisted) ===================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [RtlS5Wake] => C:\Program Files (x86)\Realtek\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe [2097600 2018-04-18] (Realtek Semiconductor Corp. -> Realtek)
- HKLM\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe (No File)
- HKLM-x32\...\Run: [Cisco Secure Client] => C:\Program Files (x86)\Cisco\Cisco Secure Client\UI\csc_ui.exe [3523504 2024-12-04] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
- HKU\S-1-5-19\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe (No File)
- HKU\S-1-5-20\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe (No File)
- HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\Run: [HPSEU_Host_Launcher] => C:\Program Files\HP\HP System Event Utility\Host Launcher\HpseuHostLauncher.exe [545864 2025-11-08] (HP Inc. -> HP Inc.)
- HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Shawn\AppData\Local\Microsoft\Teams\Update.exe [2339472 2020-05-07] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
- HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2589432 2026-03-19] (Wargaming Group Limited -> Wargaming.net)
- HKLM\...\Print\Monitors\HP 7112 Status Monitor: C:\windows\system32\hpinksts7112LM.dll [328704 2014-03-03] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Co.)
- HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [2026-03-02] (Google LLC -> Google LLC)
- HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\146.0.7680.81\Installer\chrmstp.exe [2026-03-19] (Google LLC -> Google LLC)
- HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
- GroupPolicy: Restriction ? <==== ATTENTION
- Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
- ==================== Scheduled Tasks (Whitelisted) =================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- Task: {82642CFF-B009-40CC-81C0-B9FB3E8C3ADE} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\27.1.1.28\WatchDog.exe [1175072 2026-01-16] (Bitdefender SRL -> Bitdefender) -> C:\Program Files\Bitdefender Agent\27.1.1.28\repair
- Task: {CAC2AABD-0908-4615-8B89-4A999597A2CD} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem148.0.7730.0{00D69F7D-BC5F-45C0-8714-6A4FD4E13C0E} => C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe [8459416 2026-03-12] (Google LLC -> Google LLC)
- Task: {F0A06017-791A-4111-A89C-CCF1D215C5E6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [480264 2026-01-27] (HP Inc. -> HP Inc.)
- Task: {E5202BE4-94CB-4CD7-BE84-D0FB3D2F9F88} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPPrinterLowInk => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPPrinterLowInk\HPPrinterLowInk.exe [231944 2026-01-27] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
- Task: {EDBEC2CB-2AFF-43F4-933D-AD862707F133} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1176136 2026-01-27] (HP Inc. -> HP Inc.)
- Task: {9F775904-B062-49E2-9B8E-85FFD366599C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1176136 2026-01-27] (HP Inc. -> HP Inc.)
- Task: {0A38B8A3-BDB6-43DC-85D6-7DEBCC16DFC3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_TH34M7606K => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1176136 2026-01-27] (HP Inc. -> HP Inc.)
- Task: {A3F7C2AB-DABA-46C2-9BE6-4A7BE9E1ECB5} - System32\Tasks\HP\Consent Manager Launcher => C:\windows\system32\sc.exe [102400 2025-07-09] (Microsoft Windows -> Microsoft Corporation) -> start hptouchpointanalyticsservice
- Task: {7E3F116B-8F48-458A-A795-28204FA6090E} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1644472 2019-06-21] (HP Inc. -> HP Inc.)
- Task: {127C1C74-7098-4AAA-BF47-AF34071888D4} - System32\Tasks\HPOneAgentRepairTask => C:\ProgramData\Package Cache\{DD84A52B-8D5B-484F-82D4-5AEA657B6A21}\HPOneAgent.exe [1169792 2026-02-03] (HP Inc. -> HP Inc; HP Development Company, L.P.)
- Task: {6E68B137-A11D-4D27-8EAE-62965CBD181A} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4916640 2024-04-16] (Intel Corporation -> Intel Corporation)
- Task: {79F397F1-6FFE-4A36-BE71-9306E6F44160} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4916640 2024-04-16] (Intel Corporation -> Intel Corporation)
- Task: {DE967047-1A95-44FC-8748-97C4796E0EA9} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
- Task: {A26573A0-1BB8-40DB-A82C-65B0BE820AE4} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16300328 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
- Task: {8859BA4A-4A72-418D-B36C-5156E509780E} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28604744 2026-03-09] (Microsoft Corporation -> Microsoft Corporation)
- Task: {6B87B9B0-026F-4AFE-9AD7-EA9A707E42AA} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\opushutil.exe [73648 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
- Task: {5426B4A9-3CC0-4779-A061-8D4E96CE5A6F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28604744 2026-03-09] (Microsoft Corporation -> Microsoft Corporation)
- Task: {B5A2B915-8201-4D19-A084-FBC26B3D0597} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [427808 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
- Task: {A175F1B3-5A8F-4ABB-8AD0-6D1ABA065005} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [427808 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
- Task: {A1ACDD99-B883-4245-84AE-14169B5A85D3} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [1349992 2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
- Task: {E51E4B6D-2D33-4A23-BCE6-9843F2AAEDAF} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [4448800 2026-03-09] (Microsoft Corporation -> Microsoft Corporation)
- Task: {08735572-E353-45A5-A694-6A24BA2E4607} - System32\Tasks\Microsoft\Office\Office Startup Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16300328 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
- Task: {C2D03A90-5AD1-468D-9440-0B9789844A96} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\OLicenseHeartbeat.exe [83792 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
- Task: {6D425145-C2AE-4FC5-8903-E45610BEA706} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\5D6B03FB-28AC-4DD7-98AC-CC036664F127\PushLaunch => C:\WINDOWS\system32\deviceenroller.exe [569344 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
- Task: {237A7D71-1787-410B-8F3E-C0ECB0CEFEC4} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\5D6B03FB-28AC-4DD7-98AC-CC036664F127\PushUpgrade => C:\WINDOWS\system32\deviceenroller.exe [569344 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
- Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
- Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
- Task: {548E5980-5268-48C9-B303-4E181BBE8574} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
- Task: {D94E6F92-3DEE-47A9-8C28-782403CE8B0F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
- Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
- Task: {EA93F60F-FB87-4793-B140-80581EBC544F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
- Task: {04939E32-5357-4138-AA21-721AE2BC3362} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
- Task: {F0578087-1B53-4624-AB07-99A18D6BE03E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
- Task: {AE95D385-9C2E-47D0-B4C8-5EEAC0E1CABB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
- Task: {D31CA2E4-B1C8-49FB-B424-F885262FA8A6} - System32\Tasks\OmenInstallMonitor => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [77320 2026-03-17] (HP Inc. -> HP Inc.)
- Task: {A3D9C030-41C7-42A2-ABA6-FFD9FEB28803} - System32\Tasks\OmenInstallMonitorCustomEvent => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [77320 2026-03-17] (HP Inc. -> HP Inc.)
- Task: {2357D3C7-37D5-4738-90AF-81920A38B1A0} - System32\Tasks\OmenInstallMonitorCustomEvent-sid-S-1-5-21-2500055725-1674575743-3887293998-1001 => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [77320 2026-03-17] (HP Inc. -> HP Inc.)
- Task: {B0D258CE-073A-4870-8BF5-E23A7D5DDF5B} - System32\Tasks\OmenInstallMonitor-sid-S-1-5-21-2500055725-1674575743-3887293998-1001 => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [77320 2026-03-17] (HP Inc. -> HP Inc.)
- Task: {6C4AC93E-921B-4947-893C-EEC66002FEAD} - System32\Tasks\OmenOverlay => C:\Program Files\HP\Overlay\OverlayHelper.exe [67592 2026-03-17] (HP Inc. -> HP Inc.)
- Task: {95672B0F-EDD0-48EF-A642-833FEDF7BF70} - System32\Tasks\OmenOverlayCustomEvent => C:\Program Files\HP\Overlay\OverlayHelper.exe [67592 2026-03-17] (HP Inc. -> HP Inc.)
- Task: {D2BD748E-9FB0-401B-8620-BF6948491CE6} - System32\Tasks\OmenOverlayCustomEvent-sid-S-1-5-21-2500055725-1674575743-3887293998-1001 => C:\Program Files\HP\Overlay\OverlayHelper.exe [67592 2026-03-17] (HP Inc. -> HP Inc.)
- Task: {6050ED35-CFDD-4DD7-AA03-BCB16A0F79F4} - System32\Tasks\OmenOverlay-sid-S-1-5-21-2500055725-1674575743-3887293998-1001 => C:\Program Files\HP\Overlay\OverlayHelper.exe [67592 2026-03-17] (HP Inc. -> HP Inc.)
- Task: {8842B4C4-5FF5-4E5B-95A2-CE03B49F30C6} - System32\Tasks\RtkAudUService64_BG => C:\WINDOWS\System32\RtkAudUService64.exe [1076000 2020-03-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
- Task: {D51CE681-38D2-4AD2-B1A9-AE16AE8ADD6F} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\WINDOWS\System32\Wscript.exe [200704 2026-03-11] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\//B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
- Task: {7ACDBC07-6B98-4978-B47E-5E30DACD517F} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2500055725-1674575743-3887293998-1001 => C:\Users\Shawn\AppData\Roaming\Zoom\bin\Zoom.exe [507784 2026-03-16] (Zoom Communications, Inc. -> Zoom Communications, Inc.)
- (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
- Tcpip\..\Interfaces\{8583b6f6-ec1f-4e03-997e-eef6103f2be0}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
- Tcpip\..\Interfaces\{e4f87112-93f5-4cc9-9e35-185bea232b8b}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
- FireFox:
- ========
- FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-01-24] (Microsoft Corporation -> Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2026-02-01] (Microsoft Corporation -> Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-12-08] (Microsoft Corporation -> Microsoft Corporation)
- Edge:
- =======
- Edge DefaultProfile: Default
- Edge Profile: C:\Users\Shawn\AppData\Local\Microsoft\Edge\User Data\Default [2026-03-19]
- Edge DownloadDir: C:\Users\Shawn\Downloads
- Edge Notifications: Default -> hxxps://www.facebook.com
- Edge Extension: (Honey: Automated Coupons & Rewards) - C:\Users\Shawn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\amnbcmdbanbkjhnfoeceemmmdiepnbpp [2026-02-27]
- Edge Extension: (Google Docs Offline) - C:\Users\Shawn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-03-10]
- Edge Extension: (Edge relevant text changes) - C:\Users\Shawn\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-29]
- Edge DownloadDir: Default -> C:\Users\Shawn\Downloads
- Chrome:
- =======
- CHR DefaultProfile: Default
- CHR Profile: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Default [2026-03-19]
- CHR Extension: (ClassLink OneClick Extension) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgfbgkjjlonelmpenhpfeeljjlcgnkpe [2026-02-04]
- CHR Extension: (Chrome Web Store Payments) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-09-10]
- CHR Profile: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Guest Profile [2026-01-28]
- CHR Profile: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1 [2021-06-28]
- CHR Extension: (Slides) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-06-28]
- CHR Extension: (Sheets) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-06-28]
- CHR Extension: (Google Docs Offline) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-06-28]
- CHR Extension: (Chrome Web Store Payments) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-06-28]
- CHR Extension: (Chrome Media Router) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-28]
- CHR Profile: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2 [2024-07-24]
- CHR Extension: (Slides) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2022-02-20]
- CHR Extension: (Docs) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2022-02-20]
- CHR Extension: (Google Drive) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2022-02-20]
- CHR Extension: (YouTube) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2022-02-20]
- CHR Extension: (Sheets) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2022-02-20]
- CHR Extension: (Google Docs Offline) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-02-20]
- CHR Extension: (Chrome Web Store Payments) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-02-20]
- CHR Extension: (Gmail) - C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2022-02-20]
- CHR Profile: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\System Profile [2026-01-28]
- ==================== Services (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R2 bdredline_agent; C:\Program Files\Bitdefender Agent\redline\bdredline.exe [2426992 2025-07-03] (Bitdefender SRL -> Bitdefender)
- R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13270328 2026-03-09] (Microsoft Corporation -> Microsoft Corporation)
- R2 csc_vpnagent; C:\Program Files (x86)\Cisco\Cisco Secure Client\vpnagent.exe [1318832 2025-03-03] (Cisco Systems, Inc. -> Cisco Systems, Inc.)
- R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe [133736 2025-08-27] (Intel Corporation -> Intel)
- R2 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe [133224 2025-08-27] (Intel Corporation -> Intel)
- R2 DTSAPO3Service; C:\WINDOWS\System32\DTS\PC\APO3x\DTSAPO3Service.exe [223640 2019-09-03] (DTS, Inc. -> )
- R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1321096 2018-09-28] (HP Inc. -> HP Inc.)
- R2 hp-one-agent-service; C:\Program Files\HP\HP One Agent\hp-one-agent-service.exe [2466912 2025-10-23] (HP Inc. -> HP Inc; HP Development Company, L.P.)
- R2 HPAppHelperCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\AppHelperCap.exe [911560 2026-01-06] (HP Inc. -> HP Inc.)
- R2 HPDiagsCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\DiagsCap.exe [909504 2026-01-06] (HP Inc. -> HP Inc.)
- R2 HPNetworkCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\NetworkCap.exe [905920 2026-01-06] (HP Inc. -> HP Inc.)
- R2 HPOmenCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_3c97e435117f8c16\x64\OmenCap\OmenCap.exe [755248 2024-10-25] (HP Inc. -> HP Inc.)
- R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [244232 2026-01-17] (HP Inc. -> HP Inc.)
- R2 HPSysInfoCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_9112ff0b96dede5a\x64\SysInfoCap.exe [911040 2026-01-06] (HP Inc. -> HP Inc.)
- R2 HpTouchpointAnalyticsService; C:\WINDOWS\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_ef460d1f2a35fc16\x64\TouchpointAnalyticsClientService.exe [639784 2025-10-02] (HP Inc. -> HP Inc.)
- R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpDefenderCoreService.exe [2067464 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
- R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvhdc.inf_amd64_1f7c5b9c4ae7ca18\Display.NvContainer\NVDisplay.Container.exe [1275624 2026-01-28] (NVIDIA Corporation -> NVIDIA Corporation)
- S3 PACSPTISVR-Sound_Organizer; C:\Program Files (x86)\Sony\Sound Organizer\Sony.Earth\PACSPTISVR.exe [99984 2020-09-17] (Sony Home Entertainment & Sound Products Inc. -> Sony Corporation)
- R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [759712 2026-01-16] (Bitdefender SRL -> Bitdefender)
- R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\NisSrv.exe [4435096 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
- R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MsMpEng.exe [290744 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
- R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-15] (Microsoft Corporation -> Microsoft Corporation)
- ===================== Drivers (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R3 acsock; C:\WINDOWS\system32\DRIVERS\acsock64.sys [447072 2025-03-03] (Microsoft Windows Hardware Compatibility Publisher -> Cisco Systems, Inc.)
- R1 BDVEDISK; C:\WINDOWS\system32\DRIVERS\bdvedisk.sys [96616 2020-05-28] (Bitdefender SRL -> BitDefender)
- S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [573440 2025-01-29] (Microsoft Corporation) [File not signed]
- S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [204800 2025-01-29] (Microsoft Corporation) [File not signed]
- S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [110592 2025-01-29] (Microsoft Corporation) [File not signed]
- S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
- R3 HPCustomCapDriver; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [18984 2024-05-07] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.)
- R3 HPOmenCustomCapDriver; C:\WINDOWS\System32\DriverStore\FileRepository\hpomencustomcapdriver.inf_amd64_7a1ef17ecb1f36ce\x64\hpomencustomcapdriver.sys [24968 2024-07-12] (HP Inc. -> HP Inc.)
- R2 HpReadHWData; C:\WINDOWS\system32\drivers\HpReadHWData.sys [60072 2026-02-03] (HP Inc. -> Windows (R) Win 7 DDK provider)
- R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82352 2026-02-10] (Microsoft Windows -> Microsoft Corporation)
- R0 PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [56336 2019-08-27] (Corel Corporation -> Corel Corporation)
- R1 rtf64; C:\WINDOWS\system32\DRIVERS\rtf64x64.sys [70560 2018-09-04] (Realtek Semiconductor Corp. -> Realtek)
- S3 RtkAvrcp; C:\WINDOWS\System32\drivers\RtkAvrcp.sys [88376 2018-10-23] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)
- S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
- R3 ViGEmBus; C:\WINDOWS\System32\DriverStore\FileRepository\vigembus.inf_amd64_8a927fc43d8a7838\x64\ViGEmBus.sys [74264 2018-10-25] (HP Inc. -> Benjamin Hoeglinger-Stelzer)
- S3 vpnva; C:\WINDOWS\System32\drivers\vpnva64-6.sys [54176 2025-03-03] (Microsoft Windows Hardware Compatibility Publisher -> Cisco Systems, Inc.)
- S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21888 2026-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
- S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [25704 2020-09-10] (WDKTestCert user,132375440089837053 -> Western Digital Technologies, Inc.)
- R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [635272 2026-02-10] (Microsoft Windows -> Microsoft Corporation)
- R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102832 2026-02-10] (Microsoft Windows -> Microsoft Corporation)
- R3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2025-01-29] (Microsoft Windows -> Microsoft Corporation)
- R3 WSDScan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_a6dc64e436f22951\WSDScan.sys [61440 2025-09-10] (Microsoft Windows -> Microsoft Corporation)
- ==================== NetSvcs (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== One month (created) (Whitelisted) =========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2026-03-19 13:36 - 2026-03-19 13:36 - 000034089 _____ C:\Users\Shawn\Desktop\FRST.txt
- 2026-03-19 13:35 - 2026-03-19 13:36 - 000000000 ____D C:\FRST
- 2026-03-19 13:34 - 2026-03-19 13:34 - 002445312 _____ (Farbar) C:\Users\Shawn\Desktop\FRST64.exe
- 2026-03-19 13:22 - 2026-03-19 13:22 - 009633776 _____ (Malwarebytes) C:\Users\Shawn\Downloads\adwcleaner.exe
- 2026-03-19 13:22 - 2026-03-19 13:22 - 000000000 ____D C:\AdwCleaner
- 2026-03-19 12:55 - 2026-03-19 12:55 - 000747676 _____ C:\WINDOWS\system32\perfh007.dat
- 2026-03-19 12:55 - 2026-03-19 12:55 - 000531722 _____ C:\WINDOWS\system32\perfh008.dat
- 2026-03-19 12:55 - 2026-03-19 12:55 - 000168170 _____ C:\WINDOWS\system32\perfc007.dat
- 2026-03-19 12:55 - 2026-03-19 12:55 - 000100876 _____ C:\WINDOWS\system32\perfc008.dat
- 2026-03-19 12:51 - 2026-03-19 12:51 - 000000258 __RSH C:\ProgramData\ntuser.pol
- 2026-03-19 12:08 - 2026-03-19 12:08 - 012230443 _____ C:\Users\Shawn\Downloads\IMG_1106.jpeg
- 2026-03-19 12:08 - 2026-03-19 12:08 - 004208360 _____ C:\Users\Shawn\Downloads\IMG_1107.jpeg
- 2026-03-19 12:07 - 2026-03-19 12:07 - 003154772 _____ C:\Users\Shawn\Downloads\IMG_1110.jpeg
- 2026-03-19 12:07 - 2026-03-19 12:07 - 003147959 _____ C:\Users\Shawn\Downloads\IMG_1109.jpeg
- 2026-03-19 12:02 - 2026-03-19 12:03 - 000000000 ____D C:\Users\Shawn\Desktop\Computer Issue
- 2026-03-17 07:52 - 2026-03-17 07:52 - 000078888 _____ C:\Users\Shawn\Desktop\Mail-in Entry Form _ RallyUp.pdf
- 2026-03-16 08:11 - 2026-03-16 08:11 - 000000000 ____D C:\Users\Shawn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
- 2026-03-15 09:50 - 2026-03-19 13:01 - 000000000 ____D C:\WINDOWS\CbsTemp
- 2026-03-14 19:50 - 2026-03-14 19:50 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
- 2026-03-11 19:16 - 2026-03-11 19:16 - 002641215 _____ C:\Users\Shawn\Downloads\Advocacy Project - Final Draft (1).pdf
- 2026-03-11 19:08 - 2026-03-11 19:08 - 000447333 _____ C:\Users\Shawn\Downloads\365-Article Text-1433-1-10-20160227.pdf
- 2026-03-11 19:01 - 2026-03-11 19:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
- 2026-03-11 19:01 - 2026-03-11 19:01 - 000000000 ____D C:\Program Files (x86)\Cisco
- 2026-03-11 17:32 - 2026-03-11 17:32 - 007038788 _____ C:\Users\Shawn\Downloads\IMG_1012.jpeg
- 2026-03-11 12:59 - 2026-03-11 12:59 - 010135681 _____ C:\Users\Shawn\Downloads\IMG_1066.jpeg
- 2026-03-11 12:59 - 2026-03-11 12:59 - 009186068 _____ C:\Users\Shawn\Downloads\IMG_1064.jpeg
- 2026-03-11 11:14 - 2026-03-11 11:14 - 000157059 _____ C:\Users\Shawn\Desktop\The Importance of Music Education in Schools.pdf
- 2026-03-11 11:02 - 2026-03-11 11:02 - 000473549 _____ C:\Users\Shawn\Desktop\business letter.pdf
- 2026-03-11 10:53 - 2026-03-11 10:53 - 000570535 _____ C:\Users\Shawn\Downloads\Gamer_Classroom_Resources.pdf
- 2026-03-10 20:11 - 2026-03-10 20:11 - 000083946 _____ C:\WINDOWS\SysWOW64\ctac.json
- 2026-03-10 20:11 - 2026-03-10 20:11 - 000083946 _____ C:\WINDOWS\system32\ctac.json
- 2026-03-10 20:11 - 2026-03-10 20:11 - 000036382 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
- 2026-03-10 20:11 - 2026-03-10 20:11 - 000036382 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
- 2026-03-09 12:30 - 2026-03-09 12:30 - 000488502 _____ C:\Users\Shawn\Desktop\BusinessLetterExampleandTemplateFreePrintable-1.pdf
- 2026-03-09 12:28 - 2026-03-09 12:28 - 001349625 _____ C:\Users\Shawn\Downloads\BusinessLetterExampleandTemplateFreePrintable-1.pdf
- 2026-03-01 14:01 - 2026-03-01 14:01 - 000157441 _____ C:\Users\Shawn\Downloads\USC 2026_ Silence &--- _Transgression_ Paper Draft #2 (Noah Jerge).pdf
- 2026-03-01 13:03 - 2026-03-01 13:03 - 000726245 _____ C:\Users\Shawn\Downloads\4AMartinez.pdf
- 2026-03-01 12:51 - 2026-03-01 12:51 - 003232223 _____ C:\Users\Shawn\Downloads\79408701900__84BE77E3-34CC-4B21-BD6C-278AE7FDBA8B.jpeg
- 2026-03-01 12:45 - 2026-03-01 12:45 - 002325779 _____ C:\Users\Shawn\Downloads\79408701900__84BE77E3-34CC-4B21-BD6C-278AE7FDBA8B.heic
- 2026-02-24 13:43 - 2026-02-24 13:43 - 000286338 _____ C:\Users\Shawn\Downloads\ASL Speech and Language Assessment_SC.pdf
- 2026-02-21 08:29 - 2026-03-16 08:11 - 000004254 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-2500055725-1674575743-3887293998-1001
- 2026-02-21 08:29 - 2026-03-16 08:11 - 000001958 _____ C:\Users\Shawn\Desktop\Zoom Workplace.lnk
- 2026-02-19 09:12 - 2026-01-27 21:42 - 002421296 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
- 2026-02-19 09:12 - 2026-01-27 21:42 - 002421296 _____ C:\WINDOWS\system32\vulkaninfo.exe
- 2026-02-19 09:12 - 2026-01-27 21:42 - 001923120 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
- 2026-02-19 09:12 - 2026-01-27 21:42 - 001923120 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
- 2026-02-19 09:12 - 2026-01-27 21:42 - 001434672 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
- 2026-02-19 09:12 - 2026-01-27 21:42 - 001434672 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
- 2026-02-19 09:12 - 2026-01-27 21:41 - 001625648 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
- 2026-02-19 09:12 - 2026-01-27 21:41 - 001625648 _____ C:\WINDOWS\system32\vulkan-1.dll
- 2026-02-19 09:12 - 2026-01-27 21:41 - 000478952 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
- 2026-02-19 09:12 - 2026-01-27 21:41 - 000375016 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
- 2026-02-19 09:12 - 2026-01-27 21:38 - 001344744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
- 2026-02-19 09:12 - 2026-01-27 21:38 - 000675048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
- 2026-02-19 09:12 - 2026-01-27 21:38 - 000509160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
- 2026-02-19 09:12 - 2026-01-27 21:37 - 105303272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
- 2026-02-19 09:12 - 2026-01-27 21:37 - 027559656 _____ C:\WINDOWS\system32\nvidia-pcc.exe
- 2026-02-19 09:12 - 2026-01-27 21:37 - 002319080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
- 2026-02-19 09:12 - 2026-01-27 21:37 - 001716968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
- 2026-02-19 09:12 - 2026-01-27 21:37 - 001616104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
- 2026-02-19 09:12 - 2026-01-27 21:37 - 001574632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
- 2026-02-19 09:12 - 2026-01-27 21:37 - 001224936 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
- 2026-02-19 09:12 - 2026-01-27 21:37 - 001055976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
- 2026-02-19 09:12 - 2026-01-27 21:37 - 000812264 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
- 2026-02-19 09:12 - 2026-01-27 21:37 - 000137032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
- 2026-02-19 09:12 - 2026-01-27 21:36 - 022613224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
- 2026-02-19 09:12 - 2026-01-27 21:36 - 018277608 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
- 2026-02-19 09:12 - 2026-01-27 21:36 - 007908072 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
- 2026-02-19 09:12 - 2026-01-27 21:36 - 005586664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
- 2026-02-19 09:12 - 2026-01-27 21:36 - 004288232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
- 2026-02-19 09:12 - 2026-01-27 21:36 - 000469224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
- 2026-02-19 09:12 - 2026-01-27 21:35 - 005923048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
- 2026-02-19 09:12 - 2026-01-27 21:35 - 000853736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
- 2026-02-19 09:12 - 2026-01-27 21:34 - 005687448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
- 2026-02-19 09:12 - 2026-01-27 21:34 - 004975632 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
- 2026-02-19 09:12 - 2026-01-27 20:54 - 000153488 _____ C:\WINDOWS\system32\nvinfo.pb
- 2026-02-17 13:05 - 2026-02-17 13:05 - 006533364 _____ C:\Users\Shawn\Downloads\IMG_1048.jpeg
- 2026-02-17 13:05 - 2026-02-17 13:05 - 005977972 _____ C:\Users\Shawn\Downloads\IMG_1047.jpeg
- 2026-02-17 13:05 - 2026-02-17 13:05 - 005437990 _____ C:\Users\Shawn\Downloads\IMG_1046.jpeg
- 2026-02-17 11:47 - 2026-02-17 11:47 - 004514585 _____ C:\Users\Shawn\Desktop\sidewalk3.pdf
- 2026-02-17 11:46 - 2026-02-17 11:47 - 000000000 _____ C:\Users\Shawn\Desktop\sidewalk2.pdf
- 2026-02-17 11:46 - 2026-02-17 11:46 - 005349817 _____ C:\Users\Shawn\Desktop\sidewalk1.pdf
- 2026-02-17 11:44 - 2026-02-17 11:44 - 003788294 _____ C:\Users\Shawn\Downloads\IMG_1048001 (2).heic
- 2026-02-17 11:44 - 2026-02-17 11:44 - 003466052 _____ C:\Users\Shawn\Downloads\IMG_1047001 (2).heic
- 2026-02-17 11:44 - 2026-02-17 11:44 - 003166169 _____ C:\Users\Shawn\Downloads\IMG_1046 (2).heic
- 2026-02-17 11:38 - 2026-02-17 11:38 - 003788294 _____ C:\Users\Shawn\Downloads\IMG_1048001 (1).heic
- 2026-02-17 11:38 - 2026-02-17 11:38 - 003466052 _____ C:\Users\Shawn\Downloads\IMG_1047001 (1).heic
- 2026-02-17 11:38 - 2026-02-17 11:38 - 003166169 _____ C:\Users\Shawn\Downloads\IMG_1046 (1).heic
- 2026-02-17 11:35 - 2026-02-17 11:35 - 003466052 _____ C:\Users\Shawn\Downloads\IMG_1047001.heic
- 2026-02-17 11:34 - 2026-02-17 11:34 - 003788294 _____ C:\Users\Shawn\Downloads\IMG_1048001.heic
- 2026-02-17 11:34 - 2026-02-17 11:34 - 003166169 _____ C:\Users\Shawn\Downloads\IMG_1046.heic
- ==================== One month (modified) ==================
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2026-03-19 13:22 - 2024-04-01 00:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
- 2026-03-19 13:14 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\AppReadiness
- 2026-03-19 13:02 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SystemTemp
- 2026-03-19 12:55 - 2025-01-28 22:19 - 002371620 _____ C:\WINDOWS\system32\PerfStringBackup.INI
- 2026-03-19 12:55 - 2024-04-01 00:24 - 000000000 ____D C:\WINDOWS\INF
- 2026-03-19 12:52 - 2023-09-13 06:17 - 000000000 ____D C:\Users\Shawn\AppData\Local\OGH
- 2026-03-19 12:51 - 2025-01-28 22:19 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
- 2026-03-19 12:51 - 2025-01-28 22:17 - 000008030 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
- 2026-03-19 12:51 - 2020-09-16 16:14 - 000012288 ___SH C:\DumpStack.log.tmp
- 2026-03-19 12:51 - 2019-07-13 22:38 - 000000000 ____D C:\ProgramData\NVIDIA
- 2026-03-19 12:46 - 2024-04-01 00:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI
- 2026-03-19 08:35 - 2024-04-01 00:26 - 000000000 ___HD C:\Program Files\WindowsApps
- 2026-03-19 07:39 - 2019-07-13 22:38 - 000000000 ____D C:\ProgramData\Package Cache
- 2026-03-18 17:56 - 2019-08-26 02:55 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
- 2026-03-18 07:21 - 2020-05-10 13:42 - 000000000 ____D C:\Users\Shawn\AppData\Local\D3DSCache
- 2026-03-17 17:12 - 2025-01-28 22:19 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2500055725-1674575743-3887293998-1001
- 2026-03-17 17:12 - 2025-01-28 22:19 - 000003576 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2500055725-1674575743-3887293998-1001
- 2026-03-17 17:12 - 2025-01-28 22:19 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2500055725-1674575743-3887293998-1001
- 2026-03-17 17:12 - 2020-09-16 16:15 - 000002390 _____ C:\Users\Shawn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
- 2026-03-17 17:07 - 2025-03-05 14:38 - 000004494 _____ C:\WINDOWS\system32\Tasks\OmenInstallMonitorCustomEvent-sid-S-1-5-21-2500055725-1674575743-3887293998-1001
- 2026-03-17 17:07 - 2025-03-05 14:38 - 000004092 _____ C:\WINDOWS\system32\Tasks\OmenInstallMonitor-sid-S-1-5-21-2500055725-1674575743-3887293998-1001
- 2026-03-17 17:07 - 2025-03-05 14:37 - 000004434 _____ C:\WINDOWS\system32\Tasks\OmenOverlayCustomEvent-sid-S-1-5-21-2500055725-1674575743-3887293998-1001
- 2026-03-17 17:07 - 2025-03-05 14:37 - 000004032 _____ C:\WINDOWS\system32\Tasks\OmenOverlay-sid-S-1-5-21-2500055725-1674575743-3887293998-1001
- 2026-03-17 07:41 - 2020-07-12 08:32 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
- 2026-03-17 07:41 - 2020-07-12 08:32 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
- 2026-03-16 20:28 - 2020-03-12 16:28 - 000000000 ____D C:\Users\Shawn\AppData\Roaming\Zoom
- 2026-03-14 19:49 - 2019-07-13 22:18 - 000000000 ____D C:\Program Files\Microsoft Office
- 2026-03-13 19:32 - 2020-03-28 08:36 - 000000000 ____D C:\Users\Shawn\AppData\Roaming\Microsoft\Teams
- 2026-03-11 21:19 - 2025-01-28 22:16 - 000499808 _____ C:\WINDOWS\system32\FNTCACHE.DAT
- 2026-03-11 21:18 - 2025-01-28 19:59 - 000000000 ____D C:\WINDOWS\InboxApps
- 2026-03-11 21:18 - 2024-04-01 01:08 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ___SD C:\WINDOWS\system32\F12
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\UUS
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SystemResources
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\setup
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\oobe
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\Dism
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\ShellComponents
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\BrowserCore
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\bcastdvr
- 2026-03-11 21:18 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\appcompat
- 2026-03-11 21:18 - 2024-04-01 00:21 - 000000000 ____D C:\WINDOWS\servicing
- 2026-03-11 19:01 - 2024-04-01 00:26 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
- 2026-03-11 19:01 - 2019-10-06 19:01 - 000000000 ____D C:\ProgramData\Cisco
- 2026-03-11 19:01 - 2019-03-18 21:52 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
- 2026-03-11 19:00 - 2019-10-06 19:01 - 000000000 ____D C:\Users\Shawn\AppData\Local\Cisco
- 2026-03-11 10:53 - 2021-08-25 08:06 - 000000000 ____D C:\Users\Shawn\Desktop\literature guides
- 2026-03-11 08:21 - 2024-04-01 00:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
- 2026-03-11 08:21 - 2024-04-01 00:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
- 2026-03-10 21:17 - 2019-08-26 02:50 - 000000000 ____D C:\Users\Shawn\AppData\Local\Packages
- 2026-03-10 20:11 - 2025-01-28 22:17 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
- 2026-03-06 19:08 - 2025-01-28 22:19 - 000003534 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
- 2026-03-06 19:08 - 2025-01-28 22:19 - 000003408 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
- 2026-03-01 10:11 - 2021-03-05 11:30 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
- 2026-02-22 18:10 - 2019-07-13 22:38 - 000000000 ____D C:\ProgramData\Packages
- 2026-02-21 08:29 - 2022-08-27 07:55 - 000000000 ____D C:\Users\Shawn\AppData\Local\Zoom
- ==================== SigCheck ============================
- (There is no automatic fix for files that do not pass verification.)
- ==================== End of FRST.txt ========================
- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2026
- Ran by Shawn (19-03-2026 13:38:24)
- Running from C:\Users\Shawn\Desktop
- Microsoft Windows 11 Home Version 25H2 26200.8037 (X64) (2025-01-29 16:02:57)
- Boot Mode: Normal
- ==========================================================
- ==================== Accounts: =============================
- (If an entry is included in the fixlist, it will be removed.)
- Administrator (S-1-5-21-2500055725-1674575743-3887293998-500 - Administrators - Disabled)
- DefaultAccount (S-1-5-21-2500055725-1674575743-3887293998-503 - Limited - Disabled)
- Guest (S-1-5-21-2500055725-1674575743-3887293998-501 - Limited - Disabled)
- Shawn (S-1-5-21-2500055725-1674575743-3887293998-1001 - Administrators - Enabled) => C:\Users\Shawn
- WDAGUtilityAccount (S-1-5-21-2500055725-1674575743-3887293998-504 - Limited - Disabled)
- ==================== Security Center ========================
- (If an entry is included in the fixlist, it will be removed.)
- AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AV: Bitdefender Antivirus (Enabled - Out of date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318}
- FW: Bitdefender Firewall (Disabled) {362C5A58-E860-6396-9204-BEEEF20CA463}
- ==================== Installed Programs ======================
- (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
- Audacity 2.3.2 (HKLM-x32\...\Audacity_is1) (Version: 2.3.2 - Audacity Team)
- Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 27.1.1.28 - Bitdefender)
- Cisco Secure Client - AnyConnect VPN (HKLM-x32\...\Cisco Secure Client - AnyConnect VPN) (Version: 5.1.8.122 - Cisco Systems, Inc.)
- Cisco Secure Client - AnyConnect VPN (HKLM-x32\...\{151DF30F-CEE5-41EF-BB4A-3E7C128D897E}) (Version: 5.1.8.122 - Cisco Systems, Inc.) Hidden
- Google Chrome (HKLM-x32\...\Google Chrome) (Version: 146.0.7680.81 - Google LLC)
- HP Audio Switch (HKLM-x32\...\{3A5141D4-47DB-4302-9B1C-272BE585BC8A}) (Version: 1.0.179.0 - HP Inc.)
- HP Connection Optimizer (HKLM-x32\...\{6468C4A5-E47E-405F-B675-A70A70983EA6}) (Version: 2.0.15.0 - HP Inc.)
- HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
- HP One Agent (HKLM\...\{5D13F424-BCC0-4AB9-804C-713EE5C9CBAC}) (Version: 1.2.55.3578 - HP Inc.) Hidden
- HP One Agent (HKLM\...\{DD84A52B-8D5B-484F-82D4-5AEA657B6A21}) (Version: 1.2.055.3578 - HP Inc.)
- Intel Driver && Support Assistant (HKLM-x32\...\{90EFD4CC-39A4-4470-AEEB-878CB2BCBC81}) (Version: 25.4.36.6 - Intel) Hidden
- Intel XTU SDK (HKLM-x32\...\{43A58350-CB99-4F4E-9BB6-F058D7B27985}) (Version: 1.0.13 - HP Inc.) Hidden
- Intel(R) Computing Improvement Program (HKLM\...\{2D924248-D4EE-45BA-BDDB-1FA8828CF5CA}) (Version: 2.4.10852 - Intel Corporation)
- Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 17.2.0.1009 - Intel Corporation)
- Intel(R) Rapid Storage Technology (HKLM\...\{6FAD098A-45B9-49CC-AE46-58080ED096D7}) (Version: 17.2.0.1009 - Intel Corporation) Hidden
- Intel® Driver & Support Assistant (HKLM-x32\...\{4152D055-4116-42A3-BC9E-86D0A17B35A5}) (Version: 25.4.36.6 - Intel)
- Microsoft .NET Host - 8.0.14 (x64) (HKLM\...\{04904762-A110-4E46-A728-7EF88DCCA1F1}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
- Microsoft .NET Host - 8.0.14 (x86) (HKLM-x32\...\{CB771E25-82B7-435C-B8CF-1DAF85D9A373}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
- Microsoft .NET Host FX Resolver - 8.0.14 (x64) (HKLM\...\{B2E7F2C8-73CD-4269-B7BC-11B7D8BB7A37}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
- Microsoft .NET Host FX Resolver - 8.0.14 (x86) (HKLM-x32\...\{455AA7CD-6D99-4039-95D2-FF1A437FD444}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
- Microsoft .NET Runtime - 8.0.14 (x64) (HKLM\...\{6C817CE3-32BC-4C6B-8B1A-E6F71EDAFFCC}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
- Microsoft .NET Runtime - 8.0.14 (x64) (HKLM-x32\...\{a6918640-3436-4607-9108-9b6038e680d6}) (Version: 8.0.14.34611 - Microsoft Corporation)
- Microsoft .NET Runtime - 8.0.14 (x86) (HKLM-x32\...\{6E39BE88-1272-4732-A962-9B34A31EE12C}) (Version: 64.56.29490 - Microsoft Corporation) Hidden
- Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.19725.20172 - Microsoft Corporation)
- Microsoft 365 Apps for enterprise - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.19725.20172 - Microsoft Corporation)
- Microsoft ASP.NET Core 8.0.14 - Shared Framework (x86) (HKLM-x32\...\{b4843496-41d3-405c-b4c6-2ff39b7609ed}) (Version: 8.0.14.25112 - Microsoft Corporation)
- Microsoft ASP.NET Core 8.0.14 Shared Framework (x86) (HKLM-x32\...\{BBD33465-6641-37D3-9444-5CCD7FE71A79}) (Version: 8.0.14.25112 - Microsoft Corporation) Hidden
- Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 146.0.3856.62 - Microsoft Corporation)
- Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 146.0.3856.62 - Microsoft Corporation) Hidden
- Microsoft OneDrive (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\OneDriveSetup.exe) (Version: 26.032.0217.0003 - Microsoft Corporation)
- Microsoft Teams (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\Teams) (Version: 1.3.00.12058 - Microsoft Corporation)
- Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.25.28902 - Microsoft)
- Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35211 (HKLM-x32\...\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}) (Version: 14.44.35211.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 (HKLM-x32\...\{0b5169e3-39da-4313-808e-1f9c0407f3bf}) (Version: 14.44.35211.0 - Microsoft Corporation)
- Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 (HKLM\...\{86AB2CC9-08BD-4643-B0F9-F82D006D72FF}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
- Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.44.35211 (HKLM\...\{43B0D101-A022-48F4-9D04-BA404CEB1D53}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
- Microsoft Visual C++ 2022 X86 Additional Runtime - 14.44.35211 (HKLM-x32\...\{C18FB403-1E88-43C8-AD8A-CED50F23DE8B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
- Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.44.35211 (HKLM-x32\...\{922480B5-CAEB-4B1B-AAA4-9716EFDCE26B}) (Version: 14.44.35211 - Microsoft Corporation) Hidden
- Microsoft Windows Desktop Runtime - 8.0.14 (x86) (HKLM-x32\...\{F12CDBC1-172E-4413-829C-B5234E386262}) (Version: 64.56.29521 - Microsoft Corporation) Hidden
- Microsoft Windows Desktop Runtime - 8.0.14 (x86) (HKLM-x32\...\{f70d61fa-5d61-4582-bf8d-07dec8e4fcda}) (Version: 8.0.14.34613 - Microsoft Corporation)
- NVIDIA FrameView SDK 1.1.4923.29968894 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.1.4923.29968894 - NVIDIA Corporation)
- NVIDIA Graphics Driver 591.55 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 591.55 - NVIDIA Corporation)
- NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
- Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.19725.20172 - Microsoft Corporation) Hidden
- Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.19029.20208 - Microsoft Corporation) Hidden
- Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
- REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 1.0.0.100 - REALTEK Semiconductor Corp.)
- Sound Organizer (HKLM-x32\...\{A4054A95-135B-4F0B-879A-28C522770732}) (Version: 1.6.3.09160 - Sony Home Entertainment & Sound Products Inc.)
- Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.3.0.362 - Microsoft Corporation)
- Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{82BD0A1C-815F-487F-9AE7-CE73DA413CFF}) (Version: 4.91.0.0 - Microsoft Corporation)
- Wargaming.net Game Center (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\Wargaming.net Game Center) (Version: 26.1.0.1957 - Wargaming.net)
- Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
- World of Tanks NA (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\740900249) (Version: - Wargaming.net)
- Zoom Workplace (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\ZoomUMX) (Version: 6.7.8 (32670) - Zoom Communications, Inc.)
- Chrome apps:
- ============
- Canvas (HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\5df79f5e9de0655d115e195a7deef125) (Version: 1.0 - Google\Chrome)
- Packages:
- =========
- @{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-12] ()
- 5A894077.McAfeeSecurity -> C:\Program Files\WindowsApps\5A894077.McAfeeSecurity_2.1.68.0_x64__wafk5atnkzcwy [2025-01-16] (McAfee LLC.)
- Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_5.0.0.0_x64__kgqvnymyfvs32 [2026-03-18] (king.com)
- Dropbox promotion -> C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_23.4.36.0_x64__xbfy0k16fey96 [2025-11-22] (Dropbox Inc.)
- Farm Heroes Saga -> C:\Program Files\WindowsApps\king.com.FarmHeroesSaga_6.85.12.0_x64__kgqvnymyfvs32 [2026-03-19] (king.com)
- Honey -> C:\Program Files\WindowsApps\HoneyScienceCorporation.Honey_11.4.2.0_neutral__cbe4c63gm1mzr [2020-06-15] (Honey Science Corporation)
- HP Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.HPAudioControl_1.10.216.0_x64__dt26b99r8h8gj [2020-09-17] (Realtek Semiconductor Corp)
- HP Inc. Energy Star -> C:\Program Files\WindowsApps\AD2F1837.HPInc.EnergyStar_2.0.11.0_x64__v10z8vjag6ke6 [2026-01-27] (HP Inc.)
- HP JumpStarts -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStarts_1.10.1627.0_x64__v10z8vjag6ke6 [2024-02-07] (HP Inc.)
- HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_3.0.0.0_x64__v10z8vjag6ke6 [2026-01-27] (HP Inc.)
- HP Privacy Settings -> C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.4.17.0_x64__v10z8vjag6ke6 [2025-08-22] (HP Inc.)
- HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_163.1.1121.0_x64__v10z8vjag6ke6 [2026-01-17] (HP Inc.)
- HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.51.14.0_x64__v10z8vjag6ke6 [2026-02-11] (HP Inc.)
- HP System Event Utility -> C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.16.0_x64__v10z8vjag6ke6 [2026-02-12] (HP Inc.)
- iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa [2026-03-05] (Apple Inc.) [Startup Task]
- LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_3.0.43.0_x64__w1wdnht996qgy [2025-12-20] (LinkedIn) [Startup Task]
- Local AI Manager for Microsoft 365 -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\AI [2026-03-15] ()
- Microsoft 365 companion apps -> C:\Program Files\WindowsApps\Microsoft.M365Companions_2.2510.30002.0_x64__8wekyb3d8bbwe [2025-11-09] (Microsoft Corporation)
- Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-08-28] (Microsoft Corporation) [MS Ad]
- Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-08-28] (Microsoft Corporation) [MS Ad]
- Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2023-10-08] (Microsoft Corp.)
- Microsoft Office Outlook Desktop Integration -> C:\Program Files\WindowsApps\Microsoft.OutlookDesktopIntegrationServices_16009.11426.10000.0_x64__8wekyb3d8bbwe [2019-08-28] (Microsoft Corporation)
- Microsoft.Office.ActionsServer -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\ActionsServer [2026-03-15] ()
- Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_7.0.8.0_neutral__mcm4njqhnhss8 [2024-10-09] (Netflix, Inc.)
- OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2026-03-15] ()
- OMEN Gaming Hub -> C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6 [2026-03-17] (HP Inc.) [Startup Task]
- Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2022-10-25] (Microsoft Corporation)
- Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-08-24] (Microsoft Corporation)
- PrivacyBrowse -> C:\Program Files\WindowsApps\PrivacyBrowse.PrivacyBrowse_1.12.78.0_neutral__hz4wbnfrnhwdr [2026-01-26] (PrivacyBrowse) [Startup Task]
- SpotifyAB.SpotifyMusic -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0 [2026-03-17] (Spotify AB) [Startup Task]
- Warhammer: Chaos & Conquest -> C:\Program Files\WindowsApps\TiltingPoint.WarhammerChaosConquest_4.9.3.0_x64__85kh3h6wfjavg [2026-01-20] (Tilting Point)
- WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe [2025-01-29] (Microsoft Corp.)
- WinAppRuntime.Main.1.8 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.8_8000.770.947.0_x64__8wekyb3d8bbwe [2026-03-11] (Microsoft Corp.)
- WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_8000.770.947.0_x64__8wekyb3d8bbwe [2026-02-26] (Microsoft Corp.)
- ==================== Custom CLSID (Whitelisted): ==============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- CustomCLSID: HKU\S-1-5-21-2500055725-1674575743-3887293998-1001_Classes\CLSID\{7d043d4e-4259-f459-3630-7b434fd7752c}\localserver32 -> C:\Program Files\HP\HP Media Network\HPMediaNetwork.exe (HP Inc. -> HP Inc.)
- CustomCLSID: HKU\S-1-5-21-2500055725-1674575743-3887293998-1001_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)
- CustomCLSID: HKU\S-1-5-21-2500055725-1674575743-3887293998-1001_Classes\CLSID\{EABAE40C-B27C-455A-B672-F234DD780948}\InprocServer32 -> C:\Users\Shawn\AppData\Local\Microsoft\TeamsMeetingAdd-in\1.25.28902\x64\Microsoft.Teams.MeetingAddin.DLL (Microsoft Corporation -> Microsoft Corporation)
- ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvhdc.inf_amd64_1f7c5b9c4ae7ca18\nvshext.dll [2026-01-28] (NVIDIA Corporation -> NVIDIA Corporation)
- ==================== Codecs (Whitelisted) ====================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Drivers32: [MidisrvTransferComplete] => 1
- HKLM\...\Drivers32: [midi1] => C:\windows\system32\wdmaud2.drv [143360 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
- HKLM\...\Drivers32: [midi1] => C:\Windows\SysWOW64\wdmaud2.drv [91648 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
- ==================== Shortcuts & WMI ========================
- (The entries could be listed to be restored or removed.)
- ShortcutWithArgument: C:\Users\Shawn\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_dllcofknkgglcjbggfompcepknpmfkmn\Canvas.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=dllcofknkgglcjbggfompcepknpmfkmn
- ShortcutWithArgument: C:\Users\Shawn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Canvas.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=dllcofknkgglcjbggfompcepknpmfkmn
- ==================== Loaded Modules (Whitelisted) =============
- 2026-02-19 09:10 - 2026-02-19 09:10 - 000138240 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Interop.IWs06dcaa36#\6e82ef8f4d42ed6f6bb0067709fb22bf\Interop.IWshRuntimeLibrary.ni.dll
- 2026-02-19 09:10 - 2026-02-19 09:10 - 000134656 _____ (hardcodet.net) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Hardcodet.W6cab32f3#\0d4bf7bf8fe17d6c481ab2a2fc5e3a91\Hardcodet.Wpf.TaskbarNotification.ni.dll
- 2026-02-19 09:10 - 2026-02-19 09:10 - 001700864 _____ (Mark Heath & Contributors) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\NAudio\35ded6b5142bf6dd7a4ec2953017231b\NAudio.ni.dll
- 2026-02-19 09:10 - 2026-02-19 09:10 - 003062272 _____ (Newtonsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\75d29f4e30e92bd7812c67ebbcf8704e\Newtonsoft.Json.ni.dll
- 2024-05-23 23:54 - 2024-05-23 23:54 - 003164160 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll
- 2026-02-19 09:10 - 2026-02-19 09:10 - 000793088 _____ (The Apache Software Foundation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\log4net\4c331f508c595b8976e89765f9f04b88\log4net.ni.dll
- ==================== Alternate Data Streams (Whitelisted) ========
- ==================== Safe Mode (Whitelisted) ==================
- ==================== Association (Whitelisted) =================
- ==================== Internet Explorer (Whitelisted) =============
- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
- HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
- HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
- HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
- BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2026-02-01] (Microsoft Corporation -> Microsoft Corporation)
- BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2026-01-27] (HP Inc. -> HP Inc.)
- BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2026-02-01] (Microsoft Corporation -> Microsoft Corporation)
- BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2026-01-27] (HP Inc. -> HP Inc.)
- Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
- Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
- Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
- Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
- Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
- Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
- Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
- Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
- (If an entry is included in the fixlist, it will be removed from the registry.)
- IE trusted site: HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\sharepoint.com -> hxxps://arizonastateu-files.sharepoint.com
- ==================== Hosts content: =========================
- (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
- 2019-03-18 21:49 - 2021-03-15 07:04 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
- 2023-06-30 19:14 - 2023-07-11 19:09 - 000000511 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
- 192.168.137.1 DESKTOP-T985JJS.mshome.net # 2028 7 1 10 2 9 50 33
- 192.168.137.228 tv647f1faca706.mshome.net # 2023 7 3 19 2 9 50 33
- 79
- ==================== Network ===========================
- (Currently there is no automatic fix for this section.)
- DNS Servers: 68.105.28.11 - 68.105.29.11
- Windows Firewall is enabled.
- Network Binding:
- =============
- Bluetooth Network Connection: Bluetooth Device (Personal Area Network) -> bthpan.sys
- Wi-Fi: Realtek RTL8822BE 802.11ac PCIe Adapter -> rtwlane.sys
- Ethernet: Realtek Gaming GbE Family Controller -> rt640x64.sys
- Ethernet 2: Cisco AnyConnect Virtual Miniport Adapter for Windows x64 -> vpnva64-6.sys
- nt_rtf64: Realtek LightWeight Filter (NDIS6.40)
- ==================== Other Areas ===========================
- (Currently there is no automatic fix for this section.)
- HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Shawn\Desktop\Cissy and Colton.JPG
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
- HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
- HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
- ==================== MSCONFIG/TASK MANAGER disabled items ==
- (If an entry is included in the fixlist, it will be removed.)
- HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\StartupApproved\Run: => "OneDrive"
- HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\StartupApproved\Run: => "com.squirrel.Teams.Teams"
- HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\StartupApproved\Run: => "Wargaming.net Game Center"
- HKU\S-1-5-21-2500055725-1674575743-3887293998-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_F4A14294D510213A98E2241942C236B4"
- ==================== FirewallRules (Whitelisted) ================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- FirewallRules: [UDP Query User{13044352-0C1C-4E7A-BB79-A70FF6139A48}C:\games\world_of_tanks_na\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_na\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
- FirewallRules: [TCP Query User{52CB5D8B-3290-4C10-A2B0-ED1675E4F4CF}C:\games\world_of_tanks_na\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_na\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
- FirewallRules: [UDP Query User{0CBE75F1-0B28-4BD9-AEC6-5B22D21F05D9}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
- FirewallRules: [TCP Query User{163FC5C4-F598-4208-962F-A49FA509D605}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Block) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
- FirewallRules: [{0E94816A-7A1F-44EA-A1BD-F9E5A2BA200A}] => (Allow) C:\Users\Shawn\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Communications, Inc. -> Zoom Video Communications, Inc.)
- FirewallRules: [{EE150662-6E3A-4ECA-ACD0-350DC04E091D}] => (Allow) C:\Users\Shawn\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Communications, Inc. -> Zoom Communications, Inc.)
- FirewallRules: [{7344F7E1-FCC0-4122-8907-A31AC04EF4E8}] => (Allow) C:\Users\Shawn\AppData\Local\Temp\7zS5F4C\HPDiagnosticCoreUI.exe => No File
- FirewallRules: [{A8B59A64-2355-439A-A09A-2B3397BBB9D0}] => (Allow) C:\Users\Shawn\AppData\Local\Temp\7zS5F4C\HPDiagnosticCoreUI.exe => No File
- FirewallRules: [{0154D2ED-EDBF-4F22-A88A-A7F8984515EA}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File
- FirewallRules: [{7D675D5C-F673-4574-86AB-F69428132125}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File
- FirewallRules: [TCP Query User{66011213-D03E-47EA-80F9-3263200DA44D}C:\programdata\wargaming.net\gamecenter\dlls\wgc_renderer.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\dlls\wgc_renderer.exe => No File
- FirewallRules: [UDP Query User{ECE8CFFA-E454-4C73-8A40-62E311FFC860}C:\programdata\wargaming.net\gamecenter\dlls\wgc_renderer.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\dlls\wgc_renderer.exe => No File
- FirewallRules: [TCP Query User{83AD16C9-1F68-4BE5-BC88-CB05CCF6927D}C:\games\world_of_tanks_na\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_na\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
- FirewallRules: [UDP Query User{72EDDD56-2930-4A64-8DD6-1E835D0C05AA}C:\games\world_of_tanks_na\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_na\win64\worldoftanks.exe (Wargaming Group Limited -> Wargaming.net)
- FirewallRules: [TCP Query User{B7F020F6-CF25-48BC-B3E2-BE2C36FC39D1}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
- FirewallRules: [UDP Query User{80A3AB49-FF78-4D7B-882B-C3BCAEA1AA0B}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming Group Limited -> Wargaming.net)
- FirewallRules: [TCP Query User{D58F0F94-3FE0-44CB-8EBE-75F689B9A991}C:\logic 2010\jre8\bin\javaw.exe] => (Block) C:\logic 2010\jre8\bin\javaw.exe
- FirewallRules: [UDP Query User{C8DC22FC-F493-4BFF-8D4D-32425D1FD729}C:\logic 2010\jre8\bin\javaw.exe] => (Block) C:\logic 2010\jre8\bin\javaw.exe
- FirewallRules: [{F69F7055-B4FF-4A5C-8D98-E1EFE4243A1A}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
- FirewallRules: [{03624C11-131E-4D56-9FC8-E26CB44A546B}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
- FirewallRules: [{E966BDCF-415B-457D-AF39-4A17932EDF8C}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
- FirewallRules: [{57655C02-FFA5-4AC3-969E-DD82BD539811}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
- FirewallRules: [{0542C740-B058-4323-AA5F-45C6EA0C5E39}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_25240.1702.3948.231_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
- FirewallRules: [{7D4D4B74-D57B-4EA4-9899-DFA3A5754B13}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_25240.1702.3948.231_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
- FirewallRules: [{96548191-CD33-4E3E-A29F-EA0AD86CEEEA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
- FirewallRules: [{678551F3-49B5-487E-95EA-1F802BD3D5F0}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
- FirewallRules: [{E574A48F-E014-4378-BAC1-B7B80612BFBB}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
- FirewallRules: [{7F958B11-2459-46BF-8C1B-96F6284446B2}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
- FirewallRules: [{08676CA1-A23B-4328-AE57-AD8B527074BF}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\iTunes.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
- FirewallRules: [{DE5BF8C8-0810-402F-837B-9BFB27DBDB9C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
- FirewallRules: [{94173872-E621-446C-BB91-480ABEEA7313}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
- FirewallRules: [{09F2BAF3-D12C-4CE0-8B73-A6A0307E1CC7}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
- FirewallRules: [{3ABED116-6E8F-4309-8D6D-D0A15A25F6B7}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12139.10003.61011.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.)
- FirewallRules: [{752204AB-D858-4F2D-B611-7280AFC2C2E4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{7CD4DB78-6142-4108-908D-8FD858EFD465}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{066EA940-90A4-4D82-90C9-5EB958533DC3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{F0E4D8C4-F175-43C7-AE1D-5F9B8D28BD0C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{5B8A2390-DB37-4219-834E-F07AA30BB74A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{81970A32-C50F-4DF0-8162-4948562A8FFE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{154A8714-A6CD-432A-AE5E-BB536A1C4BE9}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{66E07B69-2747-4BBC-9104-EA489F736CAC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{0A1ECAA7-58C0-49C4-8149-98810BA8D4A5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{5E60E86E-DEC9-4CBF-896A-E6FE70DC75E7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{E44D875F-C09B-4F3B-AF80-A5C7CAC55B2F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{258739E2-6BA7-4E01-A74E-6DB935F6A453}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{BDB52DF2-3DAB-4A3C-B1E8-34BECDD2A6A3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
- FirewallRules: [{8191C0CD-297A-44F8-B132-B5458733154D}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{12EF7413-6F32-4F4E-8BA7-EF30B3B3AF2D}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{C8D5693B-01CA-4094-B870-5A1F84D5054E}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{DCF3BC5A-C355-4269-A46C-B64D5AE46C05}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{AFBFB249-EAE8-44D7-8763-A01E0451B8CD}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{226EA912-7F26-4838-A9C5-65E9E6E06A40}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{3BC061BB-E945-4D20-B6CF-0530CD69C272}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{44D64436-098A-4901-8AF2-EAC52FC3B4F0}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{FE04052D-A83D-4961-B3CB-6880CE9B00CE}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{EF29F911-383C-4396-A6C1-7D9C125FAE75}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{74BC21A7-DFC0-4010-85CE-1DD0101026E0}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{14CFE3FE-AFC4-4C82-8735-2799BC8C155F}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{CE9B81AF-C038-4624-ABAE-9A41EBC7EA2A}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{3D36B41D-F256-4FB4-9D6C-293E377BCAB5}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\HP.Omen.OmenCommandCenter.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{7C77C075-9027-4A8B-8C43-F5D0831A1BEF}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{F25CE54F-29DA-46D5-935C-EE73E429E364}] => (Allow) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2602.10.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
- FirewallRules: [{E59D7858-C57C-40EE-9691-878B49E9F54F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
- ==================== Restore Points =========================
- 17-03-2026 08:13:01 Windows Update
- ==================== Faulty Device Manager Devices ============
- Name: Cisco AnyConnect Virtual Miniport Adapter for Windows x64
- Description: Cisco AnyConnect Virtual Miniport Adapter for Windows x64
- Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
- Manufacturer: Cisco Systems
- Service: vpnva
- Problem: : This device is disabled. (Code 22)
- Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
- ==================== Event log errors: ========================
- Application errors:
- ==================
- Error: (03/19/2026 12:52:54 PM) (Source: MsiInstaller) (EventID: 1013) (User: NT AUTHORITY)
- Description: Product: HP Display Control Service -- The device is not a supported system. Aborting installation.
- Error: (03/19/2026 12:52:54 PM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
- Description: Product: HP Display Control Service -- The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2753. The arguments are: DisplayControl, ,
- Error: (03/19/2026 12:51:44 PM) (Source: .NET Runtime) (EventID: 1023) (User: )
- Description: Description: A .NET application failed.
- Application: DSAArcDetect64.exe
- Path: C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe
- Message: You must install or update .NET to run this application.
- App: C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe
- Architecture: x64
- Framework: 'Microsoft.WindowsDesktop.App', version '8.0.0' (x64)
- .NET location: C:\Program Files\dotnet\
- No frameworks were found.
- Learn more:
- https://aka.ms/dotnet/app-launch-failed
- To install missing framework, download:
- https://aka.ms/dotnet-core-applaunch?framework=Microsoft.WindowsDesktop.App&framework_version=8.0.0&arch=x64&rid=win-x64&os=win10
- Error: (03/19/2026 07:41:29 AM) (Source: MsiInstaller) (EventID: 1013) (User: NT AUTHORITY)
- Description: Product: HP Display Control Service -- The device is not a supported system. Aborting installation.
- Error: (03/19/2026 07:41:29 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
- Description: Product: HP Display Control Service -- The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2753. The arguments are: DisplayControl, ,
- Error: (03/19/2026 07:40:43 AM) (Source: MsiInstaller) (EventID: 1013) (User: NT AUTHORITY)
- Description: Product: HP Display Control Service -- The device is not a supported system. Aborting installation.
- Error: (03/19/2026 07:40:42 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
- Description: Product: HP Display Control Service -- The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2753. The arguments are: DisplayControl, ,
- Error: (03/18/2026 06:11:22 PM) (Source: .NET Runtime) (EventID: 1023) (User: )
- Description: Description: A .NET application failed.
- Application: DSAArcDetect64.exe
- Path: C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe
- Message: You must install or update .NET to run this application.
- App: C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAArcDetect64.exe
- Architecture: x64
- Framework: 'Microsoft.WindowsDesktop.App', version '8.0.0' (x64)
- .NET location: C:\Program Files\dotnet\
- No frameworks were found.
- Learn more:
- https://aka.ms/dotnet/app-launch-failed
- To install missing framework, download:
- https://aka.ms/dotnet-core-applaunch?framework=Microsoft.WindowsDesktop.App&framework_version=8.0.0&arch=x64&rid=win-x64&os=win10
- System errors:
- =============
- Error: (03/19/2026 12:54:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The Energy Server Service queencreek service terminated unexpectedly. It has done this 1 time(s).
- Error: (03/17/2026 08:42:08 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
- Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9PC1H9VN18CM-Microsoft.StartExperiencesApp.
- Error: (03/17/2026 08:40:46 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
- Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9NBLGGH4NNS1-Microsoft.DesktopAppInstaller.
- Error: (03/17/2026 08:15:23 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
- Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9NQDW009T0T5-AD2F1837.OMENCommandCenter.
- Error: (03/17/2026 08:13:11 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
- Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9NCBCSZSJRSB-SpotifyAB.SpotifyMusic.
- Error: (03/13/2026 08:15:21 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T985JJS)
- Description: The server Windows.Media.Capture.Internal.AppCaptureShell did not register with DCOM within the required timeout.
- Error: (03/12/2026 09:03:40 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The DTS APO3 Service service terminated unexpectedly. It has done this 1 time(s).
- Error: (03/12/2026 07:50:47 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
- Description: The Energy Server Service queencreek service terminated unexpectedly. It has done this 1 time(s).
- Windows Defender:
- ================
- Date: 2026-03-18 21:07:33
- Description:
- Microsoft Defender Antivirus scan has been stopped before completion.
- Scan Type: Antimalware
- Scan Parameters: Quick Scan
- Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
- Date: 2026-03-17 19:51:53
- Description:
- Microsoft Defender Antivirus scan has been stopped before completion.
- Scan Type: Antimalware
- Scan Parameters: Quick Scan
- Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
- Date: 2026-03-16 21:13:09
- Description:
- Microsoft Defender Antivirus scan has been stopped before completion.
- Scan Type: Antimalware
- Scan Parameters: Quick Scan
- Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
- Date: 2026-03-15 20:10:10
- Description:
- Microsoft Defender Antivirus scan has been stopped before completion.
- Scan Type: Antimalware
- Scan Parameters: Quick Scan
- Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
- Date: 2026-03-14 19:49:11
- Description:
- Microsoft Defender Antivirus scan has been stopped before completion.
- Scan Type: Antimalware
- Scan Parameters: Quick Scan
- Stop Reason: Scheduled scan was skipped because the last successful scan was within the last 7 days
- Event[0]
- Date: 2026-02-18 09:23:58
- Description:
- Microsoft Defender Antivirus has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
- Security intelligence Attempted: Current
- Error Code: 0x80501102
- Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
- Security intelligence Version: 1.445.125.0;1.445.125.0
- Engine Version: 1.1.26010.1
- Date: 2025-11-18 07:43:54
- Description:
- Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
- New security intelligence Version:
- Previous security intelligence Version: 1.441.286.0
- Update Source: Microsoft Update Server
- Security intelligence Type: AntiVirus
- Update Type: Full
- Current Engine Version:
- Previous Engine Version: 1.1.25100.9002
- Error code: 0x80240016
- Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
- ==================== Memory info ===========================
- BIOS: AMI F.33 04/19/2023
- Motherboard: HP 84FD
- Processor: Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
- Percentage of memory in use: 47%
- Total physical RAM: 16255.48 MB
- Available physical RAM: 8574.46 MB
- Total Virtual: 17279.48 MB
- Available Virtual: 7498.26 MB
- ==================== Drives ================================
- Drive c: (Windows) (Fixed) (Total:237.37 GB) (Free:21.08 GB) (Model: WDC PC SN520 SDAPNUW-256G-1006) NTFS
- \\?\Volume{46b82d00-bc80-445b-9d4a-eca6e588ab56}\ () (Fixed) (Total:0.83 GB) (Free:0.07 GB) NTFS
- \\?\Volume{2315f355-5eab-4d2f-ba8c-8fa158686f83}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.16 GB) FAT32
- ==================== MBR & Partition Table ====================
- ==========================================================
- Disk: 0 (Size: 238.5 GB) (Disk ID: C5E07C1B)
- Partition: GPT.
- ==================== End of Addition.txt =======================
