Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-05-2021
Ran by cstar (administrator) on CHARLIE-LAPTOP (HP HP Pavilion Laptop 15-cc5xx) (11-05-2021 13:08:58)
Running from C:\Users\charl\OneDrive\Desktop
Loaded Profiles: cstar & charl
Platform: Windows 10 Home Version 20H2 19042.928 (X64) Language: English (United Kingdom)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <12>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(HP Inc. -> HP Development Company, L.P.) C:\Program Files (x86)\HP\HP CoolSense\CoolSense.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
(HP Inc. -> HP Inc.) C:\Program Files\HP\HP Orbit Service\HPOrbitService.exe
(HP Inc.) [File not signed] C:\Program Files\HPCommRecovery\HPCommRecovery.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel Corporation -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\igfxCUIService.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\igfxEM.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\IntelCpHDCPSvc.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki126950.inf_amd64_fa7f56314967630d\IntelCpHeciSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel® Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\charl\AppData\Local\Microsoft\OneDrive\21.062.0328.0001\FileCoAuth.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\charl\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\charl\AppData\Local\Microsoft\Teams\current\Teams.exe <9>
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_2.2103.17603.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WpcMon.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.10-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.10-0\NisSrv.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
0 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21022.215.0_x64__8wekyb3d8bbwe\YourPhone.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3657408 2017-06-05] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [321096 2017-06-09] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [1062392 2017-03-15] (HP Inc. -> HP Inc.)
HKU\S-1-5-21-3915671219-3013150676-4290985535-1003\...\Run: [SmileboxTray] => C:\Users\charl\AppData\Roaming\Smilebox\SmileboxTray.exe [378760 2019-03-12] (Smilebox,Inc. -> Smilebox, Inc.)
HKU\S-1-5-21-3915671219-3013150676-4290985535-1003\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3144760 2021-04-25] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-3915671219-3013150676-4290985535-1003\...\Run: [com.squirrel.Teams.Teams] => C:\Users\charl\AppData\Local\Microsoft\Teams\Update.exe [2453728 2021-04-10] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.93\Installer\chrmstp.exe [2021-05-05] (Google LLC -> Google LLC)
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
HKU\S-1-5-21-3915671219-3013150676-4290985535-1001\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {05B86CAC-2314-457B-99EC-0E833D039DC5} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-01] (Dropbox, Inc -> Dropbox, Inc.)
Task: {0AD985B1-F1E9-4E44-B965-50FFBCE95AD1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1148448 2016-12-07] (HP Inc. -> HP Inc.)
Task: {178AAA41-6024-45B4-9E3A-2A64A5C8CAF2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.10-0\MpCmdRun.exe [591160 2021-05-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1A6A18B7-CFC9-4463-B65A-3A6C403A79F0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-13] (Google LLC -> Google LLC)
Task: {2016191B-2CA7-443D-8B86-BC24D0C8D78E} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23103392 2021-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {2040C6E8-2D26-455B-A212-8AEE31B561BF} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269296 2018-10-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {3F1A6EBD-2800-426F-A597-EC97E2DC4776} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.10-0\MpCmdRun.exe [591160 2021-05-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4A0FD709-4370-4927-835C-9CBF9914A474} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [621600 2016-12-06] (HP Inc. -> HP Inc.)
Task: {4E46D38D-CED5-4255-BF62-8B8D2DEBA87D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [114048 2021-05-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {56C4C716-A684-4337-9869-A07B2C38AB4D} - System32\Tasks\HP\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\HP\HP CoolSense\CoolSense.exe [1356648 2017-01-12] (HP Inc. -> HP Development Company, L.P.)
Task: {576C991C-0FD7-43D1-A9D3-15AED1C4C74B} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [114048 2021-05-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {694185E9-B992-479C-832C-247A08E795F4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1075744 2016-12-06] (HP Inc. -> HP Inc.)
Task: {6FC5439A-7EFB-40AC-8B07-CE88EC2A0CFE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1148448 2016-12-07] (HP Inc. -> HP Inc.)
Task: {6FD64561-B55B-4489-BA69-896572DA9E1F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Active Health Launcher => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2016-12-06] (HP Inc. -> HP Inc.)
Task: {74B67022-ABA8-4E40-820F-4EFFB6A41A9E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [196968 2016-12-06] (HP Inc. -> HP Inc.)
Task: {98365D60-770B-4518-A637-340FB6B62A9B} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2016-12-06] (HP Inc. -> HP Inc.)
Task: {B39562A4-B3D9-423C-B250-0693CCA6341C} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1120696 2021-05-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {B4982C01-F36E-4221-BD47-B79A0989D4E3} - System32\Tasks\DropboxUpdateTaskMachineCore1d489842837318d => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-01] (Dropbox, Inc -> Dropbox, Inc.)
Task: {B79E59FF-8948-4D6B-A9FF-90632A1DA9A0} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1644960 2017-02-02] (HP Inc. -> HP Inc.)
Task: {BF32C9A9-EAED-41FC-82BA-445F26E691C2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.10-0\MpCmdRun.exe [591160 2021-05-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CEEFC064-686E-4C3D-997E-73D6C60FF5C5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.10-0\MpCmdRun.exe [591160 2021-05-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D9D1092E-C075-47B9-AC56-5C1FB63A7EDA} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-01] (Dropbox, Inc -> Dropbox, Inc.)
Task: {E188EA89-2509-4E6D-A53B-42D425C32727} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [616232 2016-11-28] (Dropbox, Inc -> DropboxOEM)
Task: {E3479766-BD70-4ACB-AF62-3D99ECC63565} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1075744 2016-12-06] (HP Inc. -> HP Inc.)
Task: {F24BD4FC-7511-48E4-81F2-1495D6DA6BD4} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23103392 2021-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {F57A4491-280A-4EC6-9750-B9D8AB5E3A67} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-01-13] (Google LLC -> Google LLC)
Task: {F952D223-6C14-4777-AEAF-AAC5395CEB64} - System32\Tasks\HPEA3JOBS => C:\Program [Argument = Files\HP\HP ePrint\hpeprint.exe /CheckJobs]
Task: {FAD7AE50-AF1D-4B4A-9F9C-9FDEE072976D} - System32\Tasks\HPJumpStartLaunch => C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe [459264 2017-02-01] (HP Inc. -> )
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore1d489842837318d.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{075670c8-69b9-4fd9-90fd-de7e9764d89f}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge Notifications: HKU\S-1-5-21-3915671219-3013150676-4290985535-1003 -> hxxps://blox.land
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\cstar\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-04]
FireFox:
========
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-03-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2016-11-23] (WildTangent Inc -> )
FF Plugin HKU\S-1-5-21-3915671219-3013150676-4290985535-1003: @zoom.us/ZoomVideoPlugin -> C:\Users\charl\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-12] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
Chrome:
=======
CHR Profile: C:\Users\cstar\AppData\Local\Google\Chrome\User Data\Default [2021-05-05]
CHR Extension: (Slides) - C:\Users\cstar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-01-13]
CHR Extension: (Docs) - C:\Users\cstar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-01-13]
CHR Extension: (Google Drive) - C:\Users\cstar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-05-05]
CHR Extension: (YouTube) - C:\Users\cstar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-01-13]
CHR Extension: (Sheets) - C:\Users\cstar\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-01-13]
CHR Extension: (Google Docs Offline) - C:\Users\cstar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-05-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\cstar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-05-05]
CHR Extension: (Gmail) - C:\Users\cstar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-05-05]
CHR Extension: (Chrome Media Router) - C:\Users\cstar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-05-05]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8469592 2020-03-31] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8798600 2021-04-21] (Microsoft Corporation -> Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-01] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-01] (Dropbox, Inc -> Dropbox, Inc.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811120 2020-03-31] (EasyAntiCheat Oy -> Epic Games, Inc)
S2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [350064 2016-11-23] (WildTangent Inc -> WildTangent)
R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1309184 2016-10-07] (HP Inc.) [File not signed]
R2 HP Orbit Service; C:\Program Files\HP\HP Orbit Service\HPOrbitService.exe [3394072 2017-03-01] (HP Inc. -> HP Inc.)
R2 HPJumpStartBridge; c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe [471040 2017-04-03] (HP Inc. -> HP Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (Hewlett-Packard Company -> HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc. -> HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [630776 2017-02-06] (HP Inc. -> HP Inc.)
S3 iaStorAfsService; C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe [2397816 2017-04-27] (Intel Corporation - pGFX -> Intel Corporation)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2545752 2021-04-25] (Electronic Arts, Inc. -> Electronic Arts)
S4 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3485784 2021-04-25] (Electronic Arts, Inc. -> Electronic Arts)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.10-0\NisSrv.exe [2599312 2021-05-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.10-0\MsMpEng.exe [128376 2021-05-10] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R3 MpKsla08532db; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1E2E2A17-62F5-4FAB-85BD-D5144F11FFE7}\MpKslDrv.sys [107744 2021-05-11] (Microsoft Windows -> Microsoft Corporation)
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [26368 2020-08-21] (Daniel Terhell -> Resplendence Software Projects Sp.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2021-05-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [421112 2021-05-10] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [73960 2021-05-10] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [35392 2020-06-08] (HP Inc. -> HP)
U3 aspnet_state; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-11 12:58 - 2021-05-11 12:58 - 000000000 ___HD C:\ProgramData\temp
2021-05-07 10:24 - 2021-05-07 10:24 - 000000738 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 Update Assistant.lnk
2021-05-07 10:24 - 2021-05-07 10:24 - 000000726 _____ C:\Users\cstar\Desktop\Windows 10 Update Assistant.lnk
2021-05-07 10:24 - 2021-05-07 10:24 - 000000000 ____D C:\Windows10Upgrade
2021-05-05 16:32 - 2021-05-05 16:32 - 000000000 ____D C:\Users\cstar\AppData\Local\OO Software
2021-05-05 16:31 - 2021-05-05 16:32 - 001403760 _____ (O&O Software GmbH) C:\Users\charl\Downloads\OOSU10.exe
2021-05-05 16:28 - 2021-05-05 16:28 - 000000000 ____D C:\Users\charl\AppData\Roaming\Intel Corporation
2021-05-05 16:22 - 2021-05-05 16:22 - 000002346 _____ C:\Users\Public\Desktop\Intel® Rapid Storage Technology.lnk
2021-05-05 16:22 - 2021-05-05 16:22 - 000002346 _____ C:\ProgramData\Desktop\Intel® Rapid Storage Technology.lnk
2021-05-05 16:22 - 2021-05-05 16:22 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2021-05-05 16:22 - 2021-05-05 16:22 - 000000000 ____D C:\Users\cstar\AppData\Roaming\Intel Corporation
2021-05-05 16:21 - 2021-05-05 16:21 - 000000000 ____D C:\Users\cstar\Intel
2021-05-05 16:18 - 2021-05-05 16:20 - 017936232 _____ (HP Inc.) C:\Users\charl\Downloads\sp81262.exe
2021-05-05 15:15 - 2021-05-05 15:15 - 000000414 _____ C:\Users\charl\Downloads\fixlist (1).txt
2021-05-05 13:37 - 2021-05-10 16:52 - 000000000 ____D C:\Users\charl\AppData\Local\CrashDumps
2021-05-05 13:13 - 2021-05-05 13:13 - 002252096 _____ (Resplendence Software Projects Sp. ) C:\Users\charl\Downloads\LatencyMon.exe
2021-05-05 13:13 - 2021-05-05 13:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon
2021-05-05 13:13 - 2021-05-05 13:13 - 000000000 ____D C:\Program Files\LatencyMon
2021-05-05 13:13 - 2020-08-21 09:36 - 000026368 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspLLL64.sys
2021-05-05 12:22 - 2021-05-05 12:21 - 000136843 _____ C:\Users\cstar\Documents\Speccy.txt
2021-05-05 12:21 - 2021-05-05 12:29 - 000136796 _____ C:\Users\cstar\Desktop\Speccy.txt
2021-05-05 12:18 - 2021-05-05 12:18 - 000000844 _____ C:\Users\Public\Desktop\Speccy.lnk
2021-05-05 12:18 - 2021-05-05 12:18 - 000000844 _____ C:\ProgramData\Desktop\Speccy.lnk
2021-05-05 12:18 - 2021-05-05 12:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2021-05-05 12:18 - 2021-05-05 12:18 - 000000000 ____D C:\Program Files\Speccy
2021-05-05 12:16 - 2021-05-05 12:16 - 008234296 _____ (Piriform Software Ltd) C:\Users\charl\Downloads\spsetup132.exe
2021-05-05 11:34 - 2021-05-05 11:34 - 000016688 _____ C:\junk.txt
2021-05-05 11:30 - 2021-05-05 11:30 - 000023613 _____ C:\Users\cstar\Desktop\procexp.txt
2021-05-05 11:28 - 2021-05-05 11:28 - 000024645 _____ C:\Users\cstar\Desktop\Registry.txt
2021-05-05 11:25 - 2021-05-05 11:25 - 000036200 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2021-05-05 10:43 - 2021-05-05 10:43 - 000000414 _____ C:\Users\charl\Downloads\fixlist.txt
2021-05-04 22:05 - 2021-05-04 22:05 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-05-04 22:02 - 2021-05-04 22:02 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-05-04 22:01 - 2021-05-04 22:01 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-05-04 21:10 - 2021-05-04 21:10 - 000000000 ____D C:\Users\cstar\AppData\LocalLow\IGDump
2021-05-04 19:37 - 2021-05-04 19:37 - 000000000 ____D C:\Users\charl\AppData\Local\mbam
2021-05-04 19:24 - 2021-05-04 19:24 - 002078632 _____ (Malwarebytes) C:\Users\charl\Downloads\MBSetup.exe
2021-05-04 19:01 - 2021-05-04 19:18 - 000039566 _____ C:\Users\cstar\Desktop\Addition.txt
2021-05-04 18:47 - 2021-05-04 19:18 - 000028799 _____ C:\Users\cstar\Desktop\FRST.txt
2021-05-04 18:44 - 2021-05-11 13:10 - 000000000 ____D C:\FRST
2021-05-04 18:43 - 2021-05-04 18:42 - 002298368 _____ (Farbar) C:\Users\cstar\Desktop\FRST64.exe
2021-05-04 18:42 - 2021-05-04 18:42 - 002298368 _____ (Farbar) C:\Users\cstar\Downloads\FRST64.exe
2021-05-04 18:15 - 2021-05-04 18:15 - 000000020 ___SH C:\Users\cstar\ntuser.ini
2021-04-15 20:54 - 2021-04-15 21:14 - 087628984 _____ C:\Users\charl\Downloads\Taylor Swift-1989 World Tour (3).zip
2021-04-15 20:53 - 2021-04-15 21:11 - 087910734 _____ C:\Users\charl\Downloads\Taylor Swift-1989 World Tour (4).zip
2021-04-15 20:49 - 2021-04-15 21:15 - 083020536 _____ C:\Users\charl\Downloads\Taylor Swift-1989 World Tour (1).zip
2021-04-15 20:43 - 2021-04-15 21:14 - 082168861 _____ C:\Users\charl\Downloads\Taylor Swift-1989 World Tour.zip
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-05-11 13:06 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-05-11 13:05 - 2017-12-26 13:54 - 000000000 ___RD C:\Users\charl\OneDrive
2021-05-11 13:04 - 2017-12-26 13:43 - 000000000 __SHD C:\Users\charl\IntelGraphicsProfiles
2021-05-11 13:00 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-05-11 12:58 - 2021-02-10 20:23 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-05-11 12:58 - 2021-02-10 19:05 - 000008192 ___SH C:\DumpStack.log.tmp
2021-05-11 12:58 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-05-11 12:56 - 2019-12-07 10:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2021-05-10 18:54 - 2021-02-10 19:06 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-05-10 15:50 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-05-10 15:43 - 2019-02-02 14:50 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-05-09 15:07 - 2020-06-26 09:06 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-05-09 15:07 - 2020-06-26 09:06 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-05-09 15:07 - 2020-06-26 09:06 - 000002283 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2021-05-06 18:19 - 2017-12-26 15:47 - 000000000 ____D C:\Users\charl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2021-05-06 16:20 - 2019-07-06 07:47 - 000000000 ____D C:\Users\charl\AppData\Local\D3DSCache
2021-05-06 16:03 - 2018-12-02 10:03 - 000000000 ____D C:\Users\charl\AppData\Local\Packages
2021-05-05 16:40 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2021-05-05 16:22 - 2018-12-01 15:03 - 000000000 ____D C:\Program Files\Intel
2021-05-05 16:21 - 2021-02-10 19:15 - 000000000 ____D C:\Users\cstar
2021-05-05 16:21 - 2017-06-13 16:07 - 000000000 ____D C:\SWSetup
2021-05-05 15:46 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-05-05 14:13 - 2021-02-10 19:14 - 000885796 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-05-05 13:36 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-05-05 11:23 - 2021-02-10 19:15 - 000000000 ____D C:\Users\defaultuser1.CHARLIE-LAPTOP
2021-05-05 10:55 - 2018-12-01 15:43 - 000000942 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore1d489842837318d.job
2021-05-05 10:55 - 2017-06-13 07:30 - 000000948 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2021-05-05 10:31 - 2021-02-10 20:23 - 000004008 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachineUA
2021-05-05 10:31 - 2021-02-10 20:23 - 000003804 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachineCore1d489842837318d
2021-05-05 08:22 - 2020-01-13 20:55 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-05-05 08:22 - 2020-01-13 20:55 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-05-05 08:22 - 2020-01-13 20:55 - 000002267 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2021-05-05 08:18 - 2021-02-10 19:06 - 000342056 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-05-05 08:12 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-05-05 07:05 - 2021-02-10 19:15 - 000000000 ____D C:\Users\charl
2021-05-04 22:00 - 2021-02-10 19:10 - 002877440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2021-05-04 21:09 - 2020-09-30 16:30 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-05-04 20:46 - 2019-07-06 12:29 - 000000000 ____D C:\Users\cstar\AppData\Local\packages
2021-05-04 20:44 - 2020-01-13 20:42 - 000000000 ____D C:\Users\cstar\AppData\Local\Publishers
2021-05-04 19:32 - 2020-03-31 19:20 - 000000000 ____D C:\Users\charl\AppData\Local\NVIDIA Corporation
2021-05-04 19:19 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2021-05-04 19:14 - 2020-03-31 19:08 - 000000000 ____D C:\Users\cstar\AppData\Local\NVIDIA Corporation
2021-05-04 19:04 - 2017-06-13 07:30 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2021-05-04 18:59 - 2020-05-05 18:44 - 000000000 ____D C:\ProgramData\Origin
2021-05-04 18:57 - 2020-05-05 18:44 - 000000000 ____D C:\Users\charl\AppData\Roaming\Origin
2021-05-04 18:53 - 2020-05-05 18:44 - 000000000 ____D C:\Users\charl\AppData\Local\Origin
2021-05-04 18:40 - 2021-02-10 20:23 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3915671219-3013150676-4290985535-1001
2021-05-04 18:40 - 2021-02-10 19:15 - 000002374 _____ C:\Users\cstar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-05-04 18:40 - 2017-12-26 12:53 - 000000000 ___RD C:\Users\cstar\OneDrive
2021-05-04 18:33 - 2020-03-31 13:04 - 000000000 ____D C:\Users\cstar\AppData\Local\D3DSCache
2021-05-04 18:20 - 2020-01-13 20:41 - 000000000 ___RD C:\Users\cstar\3D Objects
2021-05-04 18:20 - 2017-03-18 04:53 - 000000000 __RHD C:\Users\Public\AccountPictures
2021-05-04 18:16 - 2017-12-26 12:48 - 000000000 __SHD C:\Users\cstar\IntelGraphicsProfiles
2021-05-02 14:29 - 2021-02-10 19:15 - 000002374 _____ C:\Users\charl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-05-02 14:01 - 2021-03-04 09:48 - 000003386 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d6ffda8fc60eaf
2021-05-02 14:01 - 2021-02-10 20:23 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-04-25 21:12 - 2018-12-17 17:35 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-04-25 20:33 - 2020-05-05 18:45 - 000000000 ____D C:\Program Files (x86)\Origin
2021-04-25 20:31 - 2018-12-17 17:28 - 131963968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-04-21 15:45 - 2021-02-10 20:23 - 000003418 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-04-21 15:45 - 2021-02-10 20:23 - 000003294 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-04-13 21:21 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================