When I tried to attach them, the interface said no files had been selected.
FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-07-2025
Ran by ebber (administrator) on KBENEBBERLY (HP HP ENVY Laptop 17-cr1xxx) (05-07-2025 01:55:26)
Running from C:\Users\ebber\OneDrive\Desktop\FRST64.exe
Loaded Profiles: ebber
Platform: Microsoft Windows 11 Home Version 24H2 26100.4484 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(BF1EBE36-CE63-490E-9764-7C90171096C0 -> Portrait Displays, Inc.) C:\Program Files\WindowsApps\PortraitDisplays.HPDisplayControl_4.9.25.0_x64__2dgmkzkw4h30c\win32\DisplayControl.exe
(C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <9>
(C:\Program Files (x86)\ScreenHunter 7 Free\ScreenHunter7Free.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\Portrait Displays\HP Display Control Service\DisplayControlService.exe ->) (Portrait Displays, Inc. -> Portrait Displays) C:\Program Files\Portrait Displays\HP Display Control Service\CTHelper.exe
(C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.1.40.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityBackground.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.1.40.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityHost.exe
(C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\SpotifyWidgetProvider.exe ->) (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\crashpad_handler.exe
(DriverStore\FileRepository\hpanalyticscomp.inf_amd64_bdc4c744cf4529f4\x64\TouchpointAnalyticsClientService.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_bdc4c744cf4529f4\x64\TouchpointGpuInfo.exe
(DriverStore\FileRepository\ipf_cpu.inf_amd64_7b0f1310c58d1db9\ipf_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_7b0f1310c58d1db9\ipf_helper.exe
(ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPEnhance_1.4.4.0_x64__v10z8vjag6ke6\Win32\HPEnhancedLighting.Bg.exe
(ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.1.40.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityBackground.exe
(ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2506.8.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <31>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corp.) C:\Users\ebber\AppData\Local\Temp\bwp2924e372-2c15-4632-8e4c-38ac6c56fe9f\UnInstDaemon.exe
(explorer.exe ->) (Open Source Developer, Robin Krom -> Greenshot) C:\Program Files\Greenshot\Greenshot.exe
(explorer.exe ->) (Wisdom Software Inc. -> Wisdom Software Inc.) C:\Program Files (x86)\ScreenHunter 7 Free\ScreenHunter7Free.exe
(Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2025.11040.23001.0_x64__8wekyb3d8bbwe\Photos.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_25153.1010.3727.5483_x64__8wekyb3d8bbwe\ms-teams.exe
(SECOMN64.exe ->) (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOCL64.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_bdc4c744cf4529f4\x64\TouchpointAnalyticsClientService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1466604327697633\x64\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1466604327697633\x64\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1466604327697633\x64\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1466604327697633\x64\SysInfoCap.exe
(services.exe ->) (HP Inc. -> HP Inc; HP Development Company, L.P.) C:\Program Files\HP\HP One Agent\hp-one-agent-service.exe
(services.exe ->) (Intel Corporation -> ) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_3de31b09a0024837\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_3befaa646f991169\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dtt_sw.inf_amd64_3ea1838906a8645a\ipfsvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_d00a882b6000b511\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_7b0f1310c58d1db9\ipf_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_f3c201b4c28c14d0\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_33284f5d2f7b1562\AS\IAS\IntelAudioService.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvhm.inf_amd64_5c197d2d97068bef\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Portrait Displays, Inc. -> HP Inc.) C:\Program Files\Portrait Displays\HP Display Control Service\DisplayControlService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_807802da47ae00a3\RtkAudUService64.exe <3>
(services.exe ->) (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
(sihost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> DesktopExtension) C:\Program Files\WindowsApps\AD2F1837.myHP_46.52524.4209.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe
(sihost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPThermalControl_1.11.60.0_x64__v10z8vjag6ke6\Win32Process\HPCC.Bg.BackgroundApp.exe
(sihost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2505.23002.0_x64__8wekyb3d8bbwe\MicrosoftSecurityApp\MicrosoftSecurityApp.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.BingWallpaper_1.1.416.0_x86__8wekyb3d8bbwe\BingWallpaper.exe
(sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.25061.25.0_x64__cw5n1h2txyewy\CrossDeviceService.exe
(sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\CrossDeviceResume.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2526.2.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.266.447.0_x64__zpdnekdrzrea0\SpotifyWidgetProvider.exe
(svchost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> ) C:\Program Files\WindowsApps\AD2F1837.myHP_46.52524.4209.0_x64__v10z8vjag6ke6\HP.myHP.exe
(svchost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPThermalControl_1.11.60.0_x64__v10z8vjag6ke6\HpSystemManagement.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\Overlay\OverlayHelper.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.26.400.0_x64__8wekyb3d8bbwe\WindowsPackageManagerServer.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\ebber\AppData\Local\Microsoft\OneDrive\25.105.0601.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (VS REVO GROUP OOD -> VS Revo Group Ltd.) C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUninHelper.exe
(SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_807802da47ae00a3\RtkAudUService64.exe [1971496 2024-02-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [527792 2017-08-09] (Open Source Developer, Robin Krom -> Greenshot)
HKU\S-1-5-19\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HPSEU\HpseuHostLauncher.exe [545288 2025-03-13] (HP Inc. -> HP Inc.)
HKU\S-1-5-19\...\Run: [HPCC_InstallationBooster] => C:\System.sav\util\HPCC\HpccLauncher.exe [458248 2020-12-29] (HP Inc. -> HP Inc.)
HKU\S-1-5-19\...\RunOnce: [OMENCC_InstallationBooster] => C:\system.sav\util\OMENCC_InstallationBooster.exe [16424 2020-03-07] (HP Inc. -> )
HKU\S-1-5-20\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HPSEU\HpseuHostLauncher.exe [545288 2025-03-13] (HP Inc. -> HP Inc.)
HKU\S-1-5-20\...\Run: [HPCC_InstallationBooster] => C:\System.sav\util\HPCC\HpccLauncher.exe [458248 2020-12-29] (HP Inc. -> HP Inc.)
HKU\S-1-5-20\...\RunOnce: [OMENCC_InstallationBooster] => C:\system.sav\util\OMENCC_InstallationBooster.exe [16424 2020-03-07] (HP Inc. -> )
HKU\S-1-5-21-3824051874-4122554679-839923353-1001\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HPSEU\HpseuHostLauncher.exe [545288 2025-03-13] (HP Inc. -> HP Inc.)
HKU\S-1-5-21-3824051874-4122554679-839923353-1001\...\Run: [MicrosoftEdgeAutoLaunch_250CBDCFE7A16A0711E03CEAFFB8F27D] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start [4113464 2025-07-01] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3824051874-4122554679-839923353-1001\...\Run: [ScreenHunter 7 Free] => C:\Program Files (x86)\ScreenHunter 7 Free\ScreenHunter7Free.exe [35355360 2023-01-30] (Wisdom Software Inc. -> Wisdom Software Inc.)
HKU\S-1-5-21-3824051874-4122554679-839923353-1001\...\Run: [BingWallpaperDaemon] => C:\Users\ebber\AppData\Local\Temp\bwp2924e372-2c15-4632-8e4c-38ac6c56fe9f\UnInstDaemon.exe [51256 2025-07-01] (Microsoft Corporation -> Microsoft Corp.) <==== ATTENTION
HKU\S-1-5-18\...\RunOnce: [Application Restart #2] => C:\Program Files\WindowsApps\AD2F1837.HPThermalControl_1.11.60.0_x64__v10z8vjag6ke6\SysWin32Process\HPCC.Bg.BackgroundSys.exe [198672 2024-06-14] (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
HKU\S-1-5-18\...\RunOnce: [Application Restart #3] => C:\Program Files\WindowsApps\AD2F1837.HPThermalControl_1.11.60.0_x64__v10z8vjag6ke6\SysWin32Process\HPCC.Bg.BackgroundSys.exe [198672 2024-06-14] (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
HKU\S-1-5-18\...\RunOnce: [Application Restart #4] => C:\Program Files\WindowsApps\AD2F1837.HPThermalControl_1.11.60.0_x64__v10z8vjag6ke6\SysWin32Process\HPCC.Bg.BackgroundSys.exe [198672 2024-06-14] (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
HKU\S-1-5-18\...\RunOnce: [Application Restart #5] => C:\Program Files\WindowsApps\AD2F1837.HPThermalControl_1.11.60.0_x64__v10z8vjag6ke6\SysWin32Process\HPCC.Bg.BackgroundSys.exe [198672 2024-06-14] (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.)
HKLM\...\Print\Monitors\PDF-XChange Lite Port Monitor: C:\windows\system32\pxcpmL.dll [840024 2024-06-17] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\138.0.7204.97\Installer\chrmstp.exe [2025-06-30] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files\BraveSoftware\Brave-Browser\Application\138.1.80.115\Installer\chrmstp.exe [2025-07-01] (Brave Software, Inc. -> Brave Software, Inc.)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {75100218-8908-472D-8733-A87F27B41719} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore{8F703643-4FF8-47FE-B994-D8C83F222E6A} => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [167440 2024-10-28] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {F1A645B1-C505-4FA9-BFB5-7FB13B0337A1} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA{1B25F4C3-C003-4697-ADE3-DC3C7DA38D02} => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [167440 2024-10-28] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {A7E7E491-9208-4AB0-B881-DF8372507A61} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem132.0.6833.0{1559089A-7DD1-494A-BCAE-4C00F5586A59} => C:\Program Files (x86)\Google\GoogleUpdater\132.0.6833.0\updater.exe [5591136 2024-11-11] (Google LLC -> Google LLC)
Task: {86C58079-973F-49A8-A84C-B585C904847E} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{CA2A62C3-23A4-4D83-871D-75FB1E662CF0} => C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe [7080032 2025-05-22] (Google LLC -> Google LLC)
Task: {08E626D2-CA20-4977-97EF-45C137954578} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [1004040 2025-06-19] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {A48115E6-D91F-4C2A-BE9E-2DB0D3ED1171} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [480264 2025-06-19] (HP Inc. -> HP Inc.)
Task: {68504BF1-9966-4BBA-A284-CB8A55ABAD91} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1174536 2025-06-19] (HP Inc. -> HP Inc.)
Task: {604B3123-09C7-4960-80F5-D80B9A49A1C0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1174536 2025-06-19] (HP Inc. -> HP Inc.)
Task: {B0191D3C-7DAC-43B1-857A-77CB669A59B9} - System32\Tasks\HP\Consent Manager Launcher => C:\windows\system32\sc.exe [102400 2025-06-27] (Microsoft Windows -> Microsoft Corporation) -> start hptouchpointanalyticsservice
Task: {476A3BF9-C894-4402-83C1-07146AE0DFB8} - System32\Tasks\HPOneAgentRepairTask => C:\ProgramData\Package Cache\{20A9EF5E-995B-4CA0-B028-79FBDCD99773}\HPOneAgent.exe [1169752 2025-07-04] (HP Inc. -> HP Inc; HP Development Company, L.P.)
Task: {B54F3794-BD5A-4035-8A2E-DC3A26A13CC1} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28952664 2025-06-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {2E17FB5B-53B7-4052-A9DD-BECAFD7AF14B} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\opushutil.exe [69128 2025-07-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {0798B3EB-3706-4130-8CDD-DA879C062349} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28952664 2025-06-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {C10C9FF7-90A9-4E81-8DA0-E56D6870F459} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [310752 2025-07-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {00B9CC0C-C592-4ADD-A161-556345078AC1} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [310752 2025-07-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {2A364FE7-48B3-47CD-BF4B-EEFD4A730795} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [225992 2025-06-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {C511E62C-994A-4991-992D-757B313008C7} - System32\Tasks\Microsoft\Office\Office Startup Boost => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [310752 2025-07-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {DF4B7E13-9524-4054-AC95-AA652B010211} - System32\Tasks\Microsoft\Office\Office Startup Boost Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [310752 2025-07-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {844140EC-E35C-490F-B175-859B13C21AF5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpCmdRun.exe [1757568 2025-06-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {26486E04-AAE5-480A-9B7C-B2055BE06ECF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpCmdRun.exe [1757568 2025-06-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B9CB35C4-B321-46F6-8AFA-00AA1F1EA6D3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpCmdRun.exe [1757568 2025-06-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {372FBB97-56BA-4D20-811A-6C7F694DF3B7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpCmdRun.exe [1757568 2025-06-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {04BFA4D5-3962-47DA-A001-47C8E8E7756F} - System32\Tasks\Microsoft\Windows\WindowsAI\Settings\InitialConfiguration => {2886e5fb-4f01-4a89-9a0e-5d6a9c8048ac} C:\WINDOWS\system32\SettingsConfigTask.dll [200704 2025-06-27] (Microsoft Windows -> Microsoft Corporation)
Task: {55DC37A4-8F4C-4843-B0D0-CD3D67C3F4EC} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1005096 2023-11-02] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\NvContainer\-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {379DD0EE-3F5B-4320-BF8E-F7E6D55C2B4B} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3345448 2023-11-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F22DC5DC-4B50-4618-9926-D05A5D0404A4} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649256 2023-11-02] (NVIDIA Corporation -> NVIDIA Corporation) -> C:\Program Files (x86)\NVIDIA Corporation\NvNode\--launcher=TaskScheduler
Task: {00AAC600-499B-464C-A66A-833E717C7263} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-11-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {636BFAEC-20EF-41EF-96A3-14A2520A6E9A} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-11-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D6F2C9A6-04C8-4CFF-8DB5-8D09D32E7212} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-11-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FA9E95E3-0BBD-4C19-A08B-B18F79CBAA96} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-11-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {338F16D1-C077-4F22-9FDB-74DD5B053136} - System32\Tasks\OmenInstallMonitor => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [73168 2025-07-02] (HP Inc. -> HP Inc.)
Task: {81971C4D-99B8-4B7E-A9F9-6714782718AD} - System32\Tasks\OmenInstallMonitorCustomEvent => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [73168 2025-07-02] (HP Inc. -> HP Inc.)
Task: {81725292-2995-4721-8A02-7111F8115E86} - System32\Tasks\OmenInstallMonitorCustomEvent-sid-S-1-5-21-3824051874-4122554679-839923353-1001 => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [73168 2025-07-02] (HP Inc. -> HP Inc.)
Task: {B7AEFF1F-AE64-4EEE-B4AA-68D8AACF3A79} - System32\Tasks\OmenInstallMonitor-sid-S-1-5-21-3824051874-4122554679-839923353-1001 => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [73168 2025-07-02] (HP Inc. -> HP Inc.)
Task: {3872364E-56AA-421C-9B99-2F8BD68B6543} - System32\Tasks\OmenOverlay => C:\Program Files\HP\Overlay\OverlayHelper.exe [67536 2025-07-02] (HP Inc. -> HP Inc.)
Task: {32A7438F-4F10-475B-AE98-84156A2B0F42} - System32\Tasks\OmenOverlayCustomEvent => C:\Program Files\HP\Overlay\OverlayHelper.exe [67536 2025-07-02] (HP Inc. -> HP Inc.)
Task: {90E2D82D-23A7-4053-A066-61DBCEAF4554} - System32\Tasks\OmenOverlayCustomEvent-sid-S-1-5-21-3824051874-4122554679-839923353-1001 => C:\Program Files\HP\Overlay\OverlayHelper.exe [67536 2025-07-02] (HP Inc. -> HP Inc.)
Task: {B778ACA1-6076-4420-820E-128521C4F1A6} - System32\Tasks\OmenOverlay-sid-S-1-5-21-3824051874-4122554679-839923353-1001 => C:\Program Files\HP\Overlay\OverlayHelper.exe [67536 2025-07-02] (HP Inc. -> HP Inc.)
Task: {CCBE387B-F788-47E9-9984-44CCA994F7FB} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3824051874-4122554679-839923353-1001 => C:\Users\ebber\AppData\Local\Microsoft\OneDrive\25.105.0601.0002\OneDriveLauncher.exe [684352 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {D9B65B78-1838-4FEF-83D2-4819B966CB60} - System32\Tasks\VS Revo Group\RevoHelperFreeStartup => C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUninHelper.exe [4053672 2024-12-10] (VS REVO GROUP OOD -> VS Revo Group Ltd.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{8c304686-c335-4604-95ee-09a6056609cc}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{8c304686-c335-4604-95ee-09a6056609cc}: [DhcpDomain] lan1
Tcpip\..\Interfaces\{8c304686-c335-4604-95ee-09a6056609cc}\D49735075636472757D6759664969333D22374: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{8c304686-c335-4604-95ee-09a6056609cc}\D49735075636472757D6759664969333D22374: [DhcpDomain] lan1
Edge:
=======
Edge Profile: C:\Users\ebber\AppData\Local\Microsoft\Edge\User Data\Default [2025-07-05]
Edge Extension: (Honey: Automatic Coupons & Rewards) - C:\Users\ebber\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\amnbcmdbanbkjhnfoeceemmmdiepnbpp [2025-03-05]
Edge Extension: (Google Docs Offline) - C:\Users\ebber\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-11]
Edge Extension: (Edge relevant text changes) - C:\Users\ebber\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-06-13]
Edge Extension: (Capital One Shopping: Save Now) - C:\Users\ebber\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kiiaghlmeikbpmeabhilfphikfcefljn [2025-06-27]
Edge Extension: (Similarweb - Website Traffic & SEO Checker) - C:\Users\ebber\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\lgecefcjlholabgliikbfdifhdfbfnma [2025-07-03]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-06-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2024-06-17] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2024-06-17] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2024-06-17] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-06-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2024-06-17] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2024-06-17] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2024-06-17] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin HKU\S-1-5-21-3824051874-4122554679-839923353-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2024-06-17] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin HKU\S-1-5-21-3824051874-4122554679-839923353-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2024-06-17] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin HKU\S-1-5-21-3824051874-4122554679-839923353-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2024-06-17] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
Chrome:
=======
CHR Profile: C:\Users\ebber\AppData\Local\Google\Chrome\User Data\Default [2025-07-05]
CHR Notifications: Default -> hxxps://mail.google.com; hxxps://push.getbeamer.com; hxxps://truthsocial.com; hxxps://www.freelancer.com
CHR HomePage: Default -> hxxps://www.google.com/
CHR Extension: (Honey: Automatic Coupons & Rewards) - C:\Users\ebber\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2025-06-11]
CHR Extension: (TweetPeek AI - Grow Twitter with Real People!) - C:\Users\ebber\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlilfchmnodlgipheijbmpbonmlfgaml [2025-07-03]
CHR Extension: (Trust Wallet) - C:\Users\ebber\AppData\Local\Google\Chrome\User Data\Default\Extensions\egjidjbpglichdcondbcbdnbeeppgdph [2025-06-27]
CHR Extension: (Supernova) - C:\Users\ebber\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegpgpjbmbggplclldecdbpcmopmlbll [2024-06-14]
CHR Extension: (Google Docs Offline) - C:\Users\ebber\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-27]
CHR Extension: (Coinbase Wallet extension) - C:\Users\ebber\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnfanknocfeofbddgcijnmhnfnkdnaad [2025-07-03]
CHR Extension: (Similarweb - Website Traffic & SEO Checker) - C:\Users\ebber\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoklmmgfnpapgjgcpechhaamimifchmp [2025-06-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ebber\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-06-14]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
Brave:
=======
BRA Profile: C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2025-06-16]
BRA Extension: (Honey: Automatic Coupons & Rewards) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2025-06-16]
BRA Extension: (Similarweb - Website Traffic & SEO Checker) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\hoklmmgfnpapgjgcpechhaamimifchmp [2025-06-16]
BRA Extension: (Capital One Shopping: Save Now) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\nenlahapcbofgnanklpelkaejcehkggg [2025-06-16]
BRA Extension: (Brave Ad Block Updater (Brave Ad Block First Party Filters (plaintext))) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\adcocjohghhfpidemphmcmlmhnfgikei [2025-06-16]
BRA Extension: (Brave Local Data Files Updater) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2025-06-16]
BRA Extension: (Brave NTP background images) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2025-06-16]
BRA Extension: (Brave Ad Block Updater (Fanboy's Mobile Notifications (plaintext))) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\bfpgedeaaibpoidldhjcknekahbikncb [2025-06-16]
BRA Extension: (Brave Ad Block Updater (EasyList Cookie (plaintext))) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\cdbbhgbmjhfnhnmgeddbliobbofkgdhe [2025-06-16]
BRA Extension: (Brave NTP sponsored images) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\gccbbckogglekeggclmmekihdgdpdgoe [2025-06-16]
BRA Extension: (Brave Ad Block Updater (Regional Catalog)) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\gkboaolpopklhgplhaaiboijnklogmbc [2025-06-16]
BRA Extension: (Brave NTP Super Referrer mapping table) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\heplpbhjcbmiibdlchlanmdenffpiibo [2024-10-28]
BRA Extension: (Brave Ads Resources) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\iblokdlgekdjophgeonmanpnjihcjkjj [2025-06-16]
BRA Extension: (Brave Ad Block Updater (Brave Ad Block Updater (plaintext))) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\iodkpdagapdfkphljnddpjlldadblomo [2025-06-16]
BRA Extension: (Brave Ad Block Updater (Resources)) - C:\Users\ebber\AppData\Local\BraveSoftware\Brave-Browser\User Data\mfddibmblmbccpadfndgakiopmmhebop [2025-06-16]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [167440 2024-10-28] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 BraveElevationService; C:\Program Files\BraveSoftware\Brave-Browser\Application\138.1.80.115\elevation_service.exe [3186704 2025-07-01] (Brave Software, Inc. -> Brave Software, Inc.)
S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [167440 2024-10-28] (Brave Software, Inc. -> BraveSoftware Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13725240 2025-06-20] (Microsoft Corporation -> Microsoft Corporation)
R2 dptftcs; C:\WINDOWS\System32\DriverStore\FileRepository\dtt_sw.inf_amd64_3ea1838906a8645a\ipfsvc.exe [546416 2023-06-13] (Intel Corporation -> Intel Corporation)
R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [475680 2023-04-14] (HP Inc. -> HP Inc.)
R2 hp-one-agent-service; C:\Program Files\HP\HP One Agent\hp-one-agent-service.exe [2435112 2025-06-10] (HP Inc. -> HP Inc; HP Development Company, L.P.)
R2 HPAppHelperCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1466604327697633\x64\AppHelperCap.exe [930424 2025-06-19] (HP Inc. -> HP Inc.)
R2 HPDCService; C:\Program Files\Portrait Displays\HP Display Control Service\DisplayControlService.exe [375072 2022-10-31] (Portrait Displays, Inc. -> HP Inc.)
R2 HPDiagsCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1466604327697633\x64\DiagsCap.exe [928864 2025-06-19] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1466604327697633\x64\NetworkCap.exe [924792 2025-06-19] (HP Inc. -> HP Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243664 2025-05-01] (HP Inc. -> HP Inc.)
R2 HPSysInfoCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1466604327697633\x64\SysInfoCap.exe [929376 2025-06-19] (HP Inc. -> HP Inc.)
R2 HpTouchpointAnalyticsService; C:\WINDOWS\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_bdc4c744cf4529f4\x64\TouchpointAnalyticsClientService.exe [631448 2025-03-27] (HP Inc. -> HP Inc.)
S2 Intel® Platform License Manager Service; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\PlatformLicenseManagerService.exe [741488 2023-12-14] (Intel Corporation -> Intel® Corporation)
R2 IntelAudioService; C:\WINDOWS\System32\DriverStore\FileRepository\intcoed.inf_amd64_33284f5d2f7b1562\AS\IAS\IntelAudioService.exe [531800 2023-07-25] (Intel Corporation -> Intel)
R2 ipfsvc; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_7b0f1310c58d1db9\ipf_uf.exe [3006560 2023-12-08] (Intel Corporation -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9577376 2025-07-03] (Malwarebytes Inc -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-07-03] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpDefenderCoreService.exe [2071592 2025-06-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvhm.inf_amd64_5c197d2d97068bef\Display.NvContainer\NVDisplay.Container.exe [1275016 2024-12-12] (NVIDIA Corporation -> NVIDIA Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\NisSrv.exe [4513624 2025-06-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MsMpEng.exe [278328 2025-06-16] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 csaudio; C:\WINDOWS\System32\DriverStore\FileRepository\csaudio.inf_amd64_cb776c844df61367\csaudio.sys [376728 2023-10-06] (Cirrus Logic Inc -> Windows ® Win 7 DDK provider)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2025-07-03] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R0 fse; C:\WINDOWS\System32\drivers\fse.sys [222528 2025-02-09] (Microsoft Windows -> Microsoft Corporation)
R3 HPCustomCapDriver; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [18984 2024-05-07] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.)
R2 HpReadHWData; C:\WINDOWS\system32\drivers\HpReadHWData.sys [58952 2025-03-05] (HP Inc. -> Windows ® Win 7 DDK provider)
R3 HpSpsNotification; C:\WINDOWS\System32\DriverStore\FileRepository\hpspsnotification.inf_amd64_15be15983f897eb1\HpSpsNotification.sys [57232 2022-11-22] (HP Inc. -> HP Development Company, L.P.)
R3 iaLPSS2_GPIO2_ADL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_adl.inf_amd64_f138ad86bb3bd676\iaLPSS2_GPIO2_ADL.sys [141400 2024-02-20] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_I2C_ADL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_i2c_adl.inf_amd64_f860ba3068379bd3\iaLPSS2_I2C_ADL.sys [211544 2024-01-01] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_UART2_ADL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_uart2_adl.inf_amd64_f164184a7c0fc2ae\iaLPSS2_UART2_ADL.sys [319472 2024-01-01] (Intel Corporation -> Intel Corporation)
R3 IntelGNA; C:\WINDOWS\System32\DriverStore\FileRepository\gna.inf_amd64_6f93b7542fd3ead9\gna.sys [88656 2023-08-28] (Intel Corporation -> Intel Corporation)
R3 ipf_acpi; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_acpi.inf_amd64_21b95771f6ee4839\ipf_acpi.sys [88160 2023-12-08] (Intel Corporation -> Intel Corporation)
R3 ipf_cpu; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_7b0f1310c58d1db9\ipf_cpu.sys [85600 2023-12-08] (Intel Corporation -> Intel Corporation)
R3 ipf_lf; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_7b0f1310c58d1db9\ipf_lf.sys [484960 2023-12-08] (Intel Corporation -> Intel Corporation)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [330112 2025-06-16] (Microsoft Windows -> Microsoft Corporation)
S2 l1vhlwf; C:\WINDOWS\System32\drivers\l1vhlwf.sys [140688 2025-06-27] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234072 2025-07-03] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [22120 2025-07-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\Drivers\farflt11.sys [241872 2025-07-03] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [80960 2025-07-04] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [242752 2025-07-03] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [190136 2025-07-04] (Malwarebytes Inc -> Malwarebytes)
R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2023-06-21] (Nvidia Corporation -> NVIDIA Corporation)
R3 nvpcf; C:\WINDOWS\System32\drivers\nvpcf.sys [246504 2024-12-12] (NVIDIA Corporation -> NVIDIA Corporation)
R3 RevoProcessDetector; C:\WINDOWS\System32\DRIVERS\RevoProcessDetector.sys [19504 2024-03-28] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group)
R1 rtf64; C:\WINDOWS\system32\DRIVERS\rtf64x64.sys [67496 2022-07-29] (Realtek Semiconductor Corp. -> Realtek)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [51192 2024-11-26] (OpenVPN Inc. -> The OpenVPN Project)
S3 ThermalFilter; C:\WINDOWS\System32\DriverStore\FileRepository\c_thermal.inf_amd64_732a53ed1662b707\ThermalFilter.sys [75376 2025-03-28] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
S3 usb-platformdetection; C:\WINDOWS\System32\DriverStore\FileRepository\usb-platformdetection.inf_amd64_0f001fe089215073\usb-platformdetection.sys [53248 2025-06-27] (Microsoft Windows -> )
S3 vmbusproxy; C:\WINDOWS\system32\drivers\vmbusproxy.sys [98304 2025-05-29] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20032 2025-06-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [612768 2025-06-16] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-06-16] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-07-05 01:54 - 2025-07-05 01:54 - 000000000 ___RD C:\Users\ebber\OneDrive\Desktop\FRST-OlderVersion
2025-07-04 01:23 - 2025-07-04 01:23 - 000190136 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2025-07-04 01:18 - 2025-07-04 01:18 - 000001435 _____ C:\Users\ebber\OneDrive\Desktop\Malwarebytes Scan Report 2025-07-03 050326.txt
2025-07-03 04:21 - 2025-07-03 04:21 - 000000000 ____D C:\Users\Default\AppData\Local\Malwarebytes
2025-07-02 23:19 - 2025-07-02 23:20 - 000000000 ____D C:\AdwCleaner
2025-07-02 23:18 - 2025-07-02 23:19 - 009566696 _____ (Malwarebytes) C:\Users\ebber\OneDrive\Desktop\AdwCleaner.exe
2025-07-02 22:56 - 2025-07-02 22:57 - 000241872 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt11.sys
2025-07-02 22:55 - 2025-07-05 01:45 - 000000000 ____D C:\Users\ebber\AppData\Local\Malwarebytes
2025-07-02 22:55 - 2025-07-02 22:55 - 000002100 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2025-07-02 22:54 - 2025-07-02 22:54 - 000000000 ____D C:\ProgramData\Malwarebytes
2025-07-02 22:54 - 2025-07-02 22:54 - 000000000 ____D C:\Program Files\Malwarebytes
2025-07-02 22:52 - 2025-07-02 22:53 - 002827496 _____ (Malwarebytes) C:\Users\ebber\OneDrive\Desktop\MBSetup.exe
2025-06-28 19:47 - 2025-06-28 19:47 - 003029796 _____ C:\Users\ebber\OneDrive\Desktop\ancient_egypt_dictionary.pdf
2025-06-28 19:47 - 2025-06-28 19:47 - 003029796 _____ C:\Users\ebber\OneDrive\Desktop\ancient_egypt_dictionary (6).pdf
2025-06-28 19:47 - 2025-06-28 19:47 - 003029796 _____ C:\Users\ebber\OneDrive\Desktop\ancient_egypt_dictionary (5).pdf
2025-06-28 19:47 - 2025-06-28 19:47 - 003029796 _____ C:\Users\ebber\OneDrive\Desktop\ancient_egypt_dictionary (4).pdf
2025-06-28 19:47 - 2025-06-28 19:47 - 003029796 _____ C:\Users\ebber\OneDrive\Desktop\ancient_egypt_dictionary (3).pdf
2025-06-28 19:47 - 2025-06-28 19:47 - 003029796 _____ C:\Users\ebber\OneDrive\Desktop\ancient_egypt_dictionary (2).pdf
2025-06-28 19:47 - 2025-06-28 19:47 - 003029796 _____ C:\Users\ebber\OneDrive\Desktop\ancient_egypt_dictionary (1).pdf
2025-06-27 05:31 - 2025-06-27 05:31 - 000000000 ____D C:\WINDOWS\system32\ruxim
2025-06-27 00:35 - 2025-07-04 18:40 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-06-27 00:22 - 2025-06-27 00:22 - 005878177 _____ C:\Users\ebber\OneDrive\Desktop\27ed82c9-a18b-4d89-b1e9-c3b5378d9e8e Owned vs Rented Land.pdf
2025-06-26 23:06 - 2025-06-26 23:06 - 184882257 _____ C:\Users\ebber\OneDrive\Desktop\Ancient_Egypt_Transformed_The_Middle_Kingdom (9).pdf
2025-06-26 23:06 - 2025-06-26 23:06 - 184882257 _____ C:\Users\ebber\OneDrive\Desktop\Ancient_Egypt_Transformed_The_Middle_Kingdom (8).pdf
2025-06-26 23:06 - 2025-06-26 23:06 - 184882257 _____ C:\Users\ebber\OneDrive\Desktop\Ancient_Egypt_Transformed_The_Middle_Kingdom (7).pdf
2025-06-26 23:06 - 2025-06-26 23:06 - 184882257 _____ C:\Users\ebber\OneDrive\Desktop\Ancient_Egypt_Transformed_The_Middle_Kingdom (6).pdf
2025-06-26 23:06 - 2025-06-26 23:06 - 184882257 _____ C:\Users\ebber\OneDrive\Desktop\Ancient_Egypt_Transformed_The_Middle_Kingdom (5).pdf
2025-06-26 23:06 - 2025-06-26 23:06 - 184882257 _____ C:\Users\ebber\OneDrive\Desktop\Ancient_Egypt_Transformed_The_Middle_Kingdom (4).pdf
2025-06-26 23:06 - 2025-06-26 23:06 - 184882257 _____ C:\Users\ebber\OneDrive\Desktop\Ancient_Egypt_Transformed_The_Middle_Kingdom (3).pdf
2025-06-26 23:05 - 2025-06-26 23:06 - 184882257 _____ C:\Users\ebber\OneDrive\Desktop\Ancient_Egypt_Transformed_The_Middle_Kingdom (2).pdf
2025-06-26 23:05 - 2025-06-26 23:05 - 184882257 _____ C:\Users\ebber\OneDrive\Desktop\Ancient_Egypt_Transformed_The_Middle_Kingdom.pdf
2025-06-26 23:05 - 2025-06-26 23:05 - 184882257 _____ C:\Users\ebber\OneDrive\Desktop\Ancient_Egypt_Transformed_The_Middle_Kingdom (1).pdf
2025-06-26 22:53 - 2025-06-26 22:53 - 000560960 _____ C:\Users\ebber\OneDrive\Desktop\p16028coll12_14073 (7).pdf
2025-06-26 22:53 - 2025-06-26 22:53 - 000560960 _____ C:\Users\ebber\OneDrive\Desktop\p16028coll12_14073 (6).pdf
2025-06-26 22:52 - 2025-06-26 22:52 - 000560960 _____ C:\Users\ebber\OneDrive\Desktop\p16028coll12_14073.pdf
2025-06-26 22:52 - 2025-06-26 22:52 - 000560960 _____ C:\Users\ebber\OneDrive\Desktop\p16028coll12_14073 (5).pdf
2025-06-26 22:52 - 2025-06-26 22:52 - 000560960 _____ C:\Users\ebber\OneDrive\Desktop\p16028coll12_14073 (4).pdf
2025-06-26 22:52 - 2025-06-26 22:52 - 000560960 _____ C:\Users\ebber\OneDrive\Desktop\p16028coll12_14073 (3).pdf
2025-06-26 22:52 - 2025-06-26 22:52 - 000560960 _____ C:\Users\ebber\OneDrive\Desktop\p16028coll12_14073 (2).pdf
2025-06-26 22:52 - 2025-06-26 22:52 - 000560960 _____ C:\Users\ebber\OneDrive\Desktop\p16028coll12_14073 (1).pdf
2025-06-26 21:36 - 2025-06-26 21:36 - 000033519 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-06-26 21:36 - 2025-06-26 21:36 - 000033519 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-06-26 21:35 - 2025-06-26 21:35 - 000073956 _____ C:\WINDOWS\SysWOW64\ctac.json
2025-06-26 21:35 - 2025-06-26 21:35 - 000073956 _____ C:\WINDOWS\system32\ctac.json
2025-06-25 22:22 - 2025-06-25 22:22 - 000042466 _____ C:\Users\ebber\OneDrive\Desktop\Tips to Write a Good Essay.pdf
2025-06-25 22:16 - 2025-06-25 22:16 - 005878177 _____ C:\Users\ebber\OneDrive\Desktop\27ed82c9-a18b-4d89-b1e9-c3b5378d9e8e Owned vs rented land ebook.pdf
2025-06-18 04:12 - 2025-07-05 01:50 - 000000000 ___RD C:\Users\ebber\OneDrive\Desktop\screenshots Apr17 2025
2025-06-17 20:54 - 2025-06-17 21:09 - 000000000 ___RD C:\Users\ebber\OneDrive\Desktop\Roman
2025-06-17 20:47 - 2025-06-17 21:03 - 000000000 ___RD C:\Users\ebber\OneDrive\Desktop\Egyptian Hieroglyphs
2025-06-16 17:21 - 2025-07-03 00:17 - 000014495 _____ C:\Users\ebber\OneDrive\Desktop\Fixlog.txt
2025-06-16 04:44 - 2025-06-16 04:44 - 000006740 _____ C:\Users\ebber\AppData\LocalLow\c082cf647b6b0746ccb5a2004a30f16c4332bb28069bc7c4b5d5f45c53ee525e
2025-06-15 22:47 - 2025-06-15 22:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\VS Revo Group
2025-06-15 22:47 - 2025-06-15 22:47 - 000000000 ____D C:\Users\ebber\AppData\Local\VS Revo Group
2025-06-15 22:47 - 2025-06-15 22:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2025-06-15 22:47 - 2025-06-15 22:47 - 000000000 ____D C:\Program Files\VS Revo Group
2025-06-15 22:45 - 2025-06-15 22:45 - 011511496 _____ (VS Revo Group ) C:\Users\ebber\OneDrive\Desktop\revosetup.exe
2025-06-14 17:59 - 2025-06-15 23:10 - 000041148 _____ C:\Users\ebber\OneDrive\Desktop\Addition.txt
2025-06-14 17:58 - 2025-07-05 01:56 - 000043290 _____ C:\Users\ebber\OneDrive\Desktop\FRST.txt
2025-06-14 17:58 - 2025-07-05 01:55 - 000000000 ____D C:\FRST
2025-06-14 17:56 - 2025-07-05 01:54 - 002407936 _____ (Farbar) C:\Users\ebber\OneDrive\Desktop\FRST64.exe
2025-06-11 13:37 - 2025-06-11 13:37 - 000011216 _____ C:\Users\ebber\AppData\LocalLow\ccbecb1b7187d410eed62fbaf3d3604906b456a9fbf866b988b9354e7636b8cd
2025-06-11 13:37 - 2025-06-11 13:37 - 000000026 _____ C:\Users\ebber\AppData\LocalLow\cb966a040e4f47ee4eb860912631db29d96f8690dcbb1911c18735388d584fec
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-07-05 01:55 - 2024-06-14 04:16 - 000000000 ____D C:\Users\ebber\AppData\Local\OGH
2025-07-05 01:52 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-07-05 01:51 - 2024-06-14 15:31 - 000000298 _____ C:\Users\ebber\AppData\LocalLow\0d8ce0cf35aa7c7d3119ff805ea411913e9063dbbfde48d90472b24757f677cb
2025-07-05 01:50 - 2024-06-14 15:31 - 000381469 _____ C:\Users\ebber\AppData\LocalLow\d7ab55b136db7af61d358961466174c44b88e0abcf74413efc14283cf253191f
2025-07-05 01:48 - 2024-04-01 02:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-07-05 00:37 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2025-07-04 23:52 - 2024-06-14 04:17 - 001671301 _____ C:\Users\ebber\AppData\LocalLow\5fc18818885154e2f8f5ba65eec1eefad757bab62ecbde0aab33b042f4d9d547
2025-07-04 21:49 - 2025-02-10 17:43 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-07-04 18:40 - 2024-04-01 02:24 - 000000000 ____D C:\WINDOWS\INF
2025-07-04 18:23 - 2024-06-14 04:17 - 000000130 _____ C:\Users\ebber\AppData\LocalLow\9561ed9a0b78144747fa26e4c4fd2a49defb5e38fac37da7863fcf98aeb7cb48
2025-07-04 16:34 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-07-04 16:10 - 2023-10-27 11:17 - 000000000 ____D C:\ProgramData\NVIDIA
2025-07-04 16:07 - 2025-04-13 14:12 - 000000130 _____ C:\Users\ebber\AppData\LocalLow\4af974a5b3cbccf9299e0cf1a4759e9648b7915a15ad536112578cebabd900bc
2025-07-04 16:05 - 2025-04-13 14:12 - 000241467 _____ C:\Users\ebber\AppData\LocalLow\fed02538cf65e1ba11b1d2090b3d63048ca4335e270fb637b60c7640091dd69e
2025-07-04 16:05 - 2024-06-14 04:15 - 000093452 _____ C:\Users\ebber\AppData\LocalLow\d9ec534cb2b823c433950a0b29f3bf43af91d7e4baf3bdf47287f351b9b522df
2025-07-04 16:05 - 2024-06-13 21:51 - 000000000 ____D C:\Users\ebber\OneDrive\Desktop\ScreenHunter
2025-07-04 16:04 - 2025-04-08 22:27 - 000011216 _____ C:\Users\ebber\AppData\LocalLow\23d447464b4fc860c55866c9014cfe65cae751636972d516a4c65a579a72e8ae
2025-07-04 16:04 - 2024-06-13 18:49 - 000000000 ___RD C:\Users\ebber\OneDrive
2025-07-04 02:04 - 2024-06-14 04:54 - 000000130 _____ C:\Users\ebber\AppData\LocalLow\aae5869fa0bec4d8d27610345766f7ef02e2889cb0620366db786ae3c9e60f86
2025-07-04 01:29 - 2025-02-10 17:47 - 000842280 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-07-04 01:28 - 2024-06-14 04:54 - 000032382 _____ C:\Users\ebber\AppData\LocalLow\96b4e09f9d106d02c2df9d25efab0623acb10b2aa352982ff915d2fb958abe41
2025-07-04 01:23 - 2025-02-10 17:47 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-07-04 01:23 - 2025-02-10 17:46 - 000004234 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-07-04 01:23 - 2025-02-10 17:43 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2025-07-04 01:23 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\ServiceState
2025-07-04 01:23 - 2022-11-02 23:32 - 000012288 ___SH C:\DumpStack.log.tmp
2025-07-04 01:22 - 2024-04-01 02:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2025-07-03 20:29 - 2025-02-10 17:47 - 000003842 _____ C:\WINDOWS\system32\Tasks\HPOneAgentRepairTask
2025-07-03 20:29 - 2023-10-27 11:17 - 000000000 ____D C:\ProgramData\Package Cache
2025-07-03 20:28 - 2024-06-13 21:54 - 000000000 ____D C:\Users\ebber\AppData\Local\CrashDumps
2025-07-03 18:29 - 2024-06-13 18:48 - 000000000 ____D C:\Users\ebber\AppData\Local\D3DSCache
2025-07-03 15:56 - 2022-11-02 23:32 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-07-03 04:24 - 2024-04-01 02:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-07-03 04:23 - 2025-03-05 18:17 - 000004482 _____ C:\WINDOWS\system32\Tasks\OmenInstallMonitorCustomEvent-sid-S-1-5-21-3824051874-4122554679-839923353-1001
2025-07-03 04:23 - 2025-03-05 18:17 - 000004422 _____ C:\WINDOWS\system32\Tasks\OmenOverlayCustomEvent-sid-S-1-5-21-3824051874-4122554679-839923353-1001
2025-07-03 04:23 - 2025-03-05 18:17 - 000004080 _____ C:\WINDOWS\system32\Tasks\OmenInstallMonitor-sid-S-1-5-21-3824051874-4122554679-839923353-1001
2025-07-03 04:23 - 2025-03-05 18:17 - 000004020 _____ C:\WINDOWS\system32\Tasks\OmenOverlay-sid-S-1-5-21-3824051874-4122554679-839923353-1001
2025-07-03 04:22 - 2024-06-14 04:15 - 000035813 _____ C:\Users\ebber\AppData\LocalLow\1dc6c00a8ccb1ba456966b5f470493e9b53380f303883ce5012e6c64eb5a9a36
2025-07-02 22:55 - 2024-06-13 18:39 - 000000000 ____D C:\Users\ebber\AppData\Local\Packages
2025-07-02 22:55 - 2024-04-01 02:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-07-02 22:55 - 2022-11-02 23:35 - 000000000 ____D C:\ProgramData\Packages
2025-07-02 20:21 - 2024-06-13 19:08 - 000000000 ____D C:\Users\ebber\AppData\Local\HP
2025-07-02 04:41 - 2023-07-07 05:29 - 000000000 ____D C:\Program Files\Microsoft Office
2025-07-01 18:23 - 2024-10-28 16:47 - 000002371 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2025-06-30 16:55 - 2024-06-13 19:01 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-06-29 11:36 - 2024-06-14 00:15 - 000016811 _____ C:\Users\ebber\AppData\LocalLow\ef54eddb2ded8674d924a92863f229125f4b7962e4f7fe0c46c7682970b66a1d
2025-06-27 18:22 - 2025-03-14 22:55 - 000002386 _____ C:\Users\ebber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-06-27 18:22 - 2025-02-10 17:47 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3824051874-4122554679-839923353-1001
2025-06-27 18:22 - 2025-02-10 17:47 - 000003570 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3824051874-4122554679-839923353-1001
2025-06-27 18:22 - 2025-02-10 17:47 - 000003370 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3824051874-4122554679-839923353-1001
2025-06-27 14:44 - 2024-06-16 04:54 - 000000130 _____ C:\Users\ebber\AppData\LocalLow\10a4dca5d4e4c061e5be589b05c7453a289bc5897d5dfde751f9ade306a1ddcc
2025-06-27 14:40 - 2025-02-10 17:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\Hewlett-Packard
2025-06-27 05:32 - 2025-02-10 17:43 - 000493432 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\SystemResources
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\Provisioning
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-06-27 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-06-27 05:31 - 2024-04-01 02:21 - 000000000 ____D C:\WINDOWS\servicing
2025-06-26 21:35 - 2025-02-10 17:47 - 003384320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2025-06-24 22:11 - 2025-03-18 06:45 - 000403832 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy_8.dll
2025-06-24 22:11 - 2024-11-22 21:59 - 002918800 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2025-06-24 22:11 - 2024-11-22 21:59 - 000817528 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2025-06-24 22:11 - 2024-11-22 21:59 - 000272784 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2025-06-24 22:11 - 2024-11-22 21:59 - 000244088 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2025-06-24 22:11 - 2024-11-22 21:59 - 000166264 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2025-06-24 22:11 - 2024-11-22 21:59 - 000121232 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2025-06-24 22:11 - 2024-11-22 21:59 - 000076152 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2025-06-18 14:29 - 2024-06-28 17:10 - 000000000 ____D C:\Users\ebber\OneDrive\Desktop\keb
2025-06-16 18:50 - 2022-11-02 23:32 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-06-16 12:39 - 2024-06-13 21:09 - 000000000 ____D C:\Users\ebber\AppData\Local\Greenshot
2025-06-11 05:31 - 2025-02-09 15:03 - 000000000 ____D C:\Users\ebber
2025-06-11 05:31 - 2024-04-01 03:08 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-06-11 05:31 - 2024-04-01 02:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-06-10 14:25 - 2024-06-13 22:36 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-06-10 14:20 - 2024-06-13 22:36 - 216824056 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories ========
2025-04-30 00:55 - 2025-04-30 00:55 - 000067389 _____ () C:\Users\ebber\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================