Here is the FRST LOG
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-09-2023 Ran by john (administrator) on DESKTOP-THSFR3B (HP HP Desktop M01-F3xxx) (27-09-2023 14:26:02) Running from C:\Users\john\Downloads\FRST64.exe Loaded Profiles: john Platform: Microsoft Windows 11 Home Version 22H2 22621.2283 (X64) Language: English (United States) Default browser: Edge Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe ->) (EXPRSVPN LLC β ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe (C:\Program Files\WindowsApps\MicrosoftTeams_23231.411.2342.9597_x64__8wekyb3d8bbwe\msteams.exe ->) (Microsoft Corporation β Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.36\msedgewebview2.exe <12> (DriverStore\FileRepository\u0392596.inf_amd64_6b8c540dc585ffa4\B392262\atiesrxx.exe ->) (Advanced Micro Devices Inc. β AMD) C:\Windows\System32\DriverStore\FileRepository\u0392596.inf_amd64_6b8c540dc585ffa4\B392262\atieclxx.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 β HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_1.3.35.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityHost.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 β HP Inc.) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2309.1.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe (explorer.exe ->) (Microsoft Corporation β Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <17> (EXPRSVPN LLC β ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationService.exe (HP Inc. β ) C:\Program Files\HP\Overlay\OMENOverlay.exe (Mozilla Corporation β Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <9> (SECOMN64.exe ->) (Sound Research Corporation β Sound Research, Corp.) C:\Windows\System32\SECOCL64.exe (services.exe ->) (Advanced Micro Devices Inc. β AMD) C:\Windows\System32\DriverStore\FileRepository\u0392596.inf_amd64_6b8c540dc585ffa4\B392262\atiesrxx.exe (services.exe ->) (EXPRSVPN LLC β ExpressVPN) C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe (services.exe ->) (HON HAI PRECISION INDUSTRY CO.LTD. β ) C:\Program Files\FanControlApp\FanControlApp.exe (services.exe ->) (HP Inc. β HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe (services.exe ->) (HP Inc. β HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_43e3600968234e87\x64\TouchpointAnalyticsClientService.exe (services.exe ->) (HP Inc. β HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\AppHelperCap.exe (services.exe ->) (HP Inc. β HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\DiagsCap.exe (services.exe ->) (HP Inc. β HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\NetworkCap.exe (services.exe ->) (HP Inc. β HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\SysInfoCap.exe (services.exe ->) (Microsoft Corporation β Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher β Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher β Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe (services.exe ->) (Microsoft Windows Publisher β Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher β Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe (services.exe ->) (Realtek Semiconductor Corp. β Realtek Semiconductor Corp.) C:\Windows\RtkWiFiManServ.exe (services.exe ->) (Realtek Semiconductor Corp. β Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0c755fff65745edd\RtkAudUService64.exe <2> (services.exe ->) (Sound Research Corporation β Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe (sihost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 β ) C:\Program Files\WindowsApps\AD2F1837.myHP_25.52334.606.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe (sihost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 β HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPEnhance_1.3.5.0_x64__v10z8vjag6ke6\Win32\HPEnhancedLighting.Bg.exe (svchost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 β ) C:\Program Files\WindowsApps\AD2F1837.myHP_25.52334.606.0_x64__v10z8vjag6ke6\HP.myHP.exe (svchost.exe ->) (HP Inc. β HP Inc.) C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe (svchost.exe ->) (HP Inc. β HP Inc.) C:\Program Files\HP\Overlay\OverlayHelper.exe (svchost.exe ->) (Microsoft Corporation β Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftTeams_23231.411.2342.9597_x64__8wekyb3d8bbwe\msteamsupdate.exe (svchost.exe ->) (Microsoft Windows β ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe (svchost.exe ->) (Microsoft Windows β Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows β Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows β Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32...\Run: [ExpressVPNNotificationService] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationServiceStarter.exe [380816 2022-08-04] (EXPRSVPN LLC β ExpressVPN) HKU\S-1-5-21-1867205174-823180755-3576545642-1001...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HPSEU\HpseuHostLauncher.exe [537136 2023-08-14] (HP Inc. β HP Inc.) HKU\S-1-5-21-1867205174-823180755-3576545642-1001...\Run: [MicrosoftEdgeAutoLaunch_45D944CC36A69C479BF3C348604E81F2] => βC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeβ --no-startup-window --win-session-start /prefetch:5 [4210112 2023-09-25] (Microsoft Corporation β Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {5190F5B8-9F34-460B-B763-B429A0159410} - \McAfee\DAD.Execute.Updates β No File <==== ATTENTION Task: {F4FA67D7-5D83-4AAB-B39E-A8BFB942847C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [703536 2023-09-15] (HP Inc. β HP Inc.) Task: {2BCB33C1-8EAA-47CD-A25F-3B97694B9B47} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [138328 2023-09-15] (HP Inc. β HP Inc.) Task: {E4433F47-91AB-4DFC-BEB8-9DADF24E5724} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1161264 2023-09-15] (HP Inc. β HP Inc.) Task: {3AC03B8B-FC7B-4B62-AEBD-470A57062CD1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1161264 2023-09-15] (HP Inc. β HP Inc.) Task: {14AC54B9-F75B-4EFD-AB67-10C84ED0DECF} - System32\Tasks\HP\Consent Manager Launcher => C:\windows\system32\sc.exe [98304 2022-05-07] (Microsoft Windows β Microsoft Corporation) β start hptouchpointanalyticsservice Task: {00D4FB00-9FD1-4675-947C-F263C6CDC349} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26913760 2023-09-01] (Microsoft Corporation β Microsoft Corporation) Task: {069EA780-6129-41B5-B9AF-537B8A98090F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26913760 2023-09-01] (Microsoft Corporation β Microsoft Corporation) Task: {5503D4E0-7C38-42F6-8BEE-BC0256BA22B5} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158664 2023-09-17] (Microsoft Corporation β Microsoft Corporation) Task: {C0B5A6DB-2936-4BCE-BFD0-90269963DFAA} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158664 2023-09-17] (Microsoft Corporation β Microsoft Corporation) Task: {F66CE3EA-2BB8-44A5-B053-D170C4398BAA} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [167864 2023-08-01] (Microsoft Corporation β Microsoft Corporation) Task: {74D6A48C-DFF2-4331-B2BA-E3B048420FD3} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\UCPD velocity => C:\windows\system32\UCPDMgr.exe [58880 2023-09-12] (Microsoft Windows β Microsoft Corporation) Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File) Task: {14C2CE4A-1092-4618-871C-289B29B806D0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-31] (Microsoft Windows Publisher β Microsoft Corporation) Task: {CA3EBC08-3FC6-4CF0-BA75-731510213B14} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-31] (Microsoft Windows Publisher β Microsoft Corporation) Task: {6B45F2EF-EA3E-488A-AFF2-98C6674D6601} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-31] (Microsoft Windows Publisher β Microsoft Corporation) Task: {E3063D3E-2308-4359-98BD-5862F4AFBB1A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-31] (Microsoft Windows Publisher β Microsoft Corporation) Task: {32FD51C1-47BB-4DE2-BCCD-F588395820CC} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [675232 2023-09-12] (Mozilla Corporation β Mozilla Corporation) β --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Task: {6863F2A9-37E1-45ED-A870-22B760EF45F5} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [722336 2023-09-12] (Mozilla Corporation β Mozilla Foundation) Task: {E86E1369-7512-406E-B77C-0AB423F2EF73} - System32\Tasks\OmenInstallMonitor => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [58352 2023-09-19] (HP Inc. β HP Inc.) Task: {E54FD9E5-74BF-4BCC-A4E6-A199E55D066C} - System32\Tasks\OmenOverlay => C:\Program Files\HP\Overlay\OverlayHelper.exe [59888 2023-09-19] (HP Inc. β HP Inc.) Task: {2F7EBAED-882C-4AB8-B623-226B05736234} - System32\Tasks\RtkAudUService64_BG => C:\windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0c755fff65745edd\RtkAudUService64.exe [1923384 2023-09-06] (Realtek Semiconductor Corp. β Realtek Semiconductor) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12 Tcpip..\Interfaces{fed75b1f-821c-4c33-a838-025763bcbc5d}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12 [HEADING=1]Edge:[/HEADING] Edge DefaultProfile: Default Edge Profile: C:\Users\john\AppData\Local\Microsoft\Edge\User Data\Default [2023-09-27] Edge Notifications: Default β hxxps://pchelpforum.net; hxxps://politicalhotwire.com; hxxps://www.facebook.com; hxxps://www.instagram.com; hxxps://www.youtube.com Edge Session Restore: Default β is enabled. Edge Extension: (Google Docs Offline) - C:\Users\john\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-08-30] Edge Extension: (Edge relevant text changes) - C:\Users\john\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-14] [HEADING=1]FireFox:[/HEADING] FF DefaultProfile: ujse8sqr.default FF ProfilePath: C:\Users\john\AppData\Roaming\Mozilla\Firefox\Profiles\ujse8sqr.default [2023-05-26] FF ProfilePath: C:\Users\john\AppData\Roaming\Mozilla\Firefox\Profiles\6sjtp7l0.default-release [2023-09-27] FF Notifications: Mozilla\Firefox\Profiles\6sjtp7l0.default-release β hxxps://www.instagram.com FF Plugin: @microsoft.com/SharePoint,version=14.0 β C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-08-01] (Microsoft Corporation β Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 β C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-08-01] (Microsoft Corporation β Microsoft Corporation) ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11817040 2023-09-01] (Microsoft Corporation β Microsoft Corporation) R2 ExpressVPNService; C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe [439696 2022-08-04] (EXPRSVPN LLC β ExpressVPN) R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [893984 2022-08-15] (HP Inc. β HP Inc.) R2 HPAppHelperCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\AppHelperCap.exe [888272 2023-08-29] (HP Inc. β HP Inc.) R2 HPDiagsCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\DiagsCap.exe [886736 2023-08-29] (HP Inc. β HP Inc.) R2 HPNetworkCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\NetworkCap.exe [883152 2023-08-29] (HP Inc. β HP Inc.) R2 HPSysInfoCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\SysInfoCap.exe [886840 2023-08-29] (HP Inc. β HP Inc.) R2 HpTouchpointAnalyticsService; C:\windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_43e3600968234e87\x64\TouchpointAnalyticsClientService.exe [497744 2023-08-02] (HP Inc. β HP Inc.) R2 ID19 HP Fan Control Service; C:\Program Files\FanControlApp\FanControlApp.exe [283168 2020-04-28] (HON HAI PRECISION INDUSTRY CO.LTD. β ) R2 RtkWiFiManServ; C:\windows\RtkWiFiManServ.exe [821632 2023-06-27] (Realtek Semiconductor Corp. β Realtek Semiconductor Corp.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe [3121008 2023-08-31] (Microsoft Windows Publisher β Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe [133688 2023-08-31] (Microsoft Windows Publisher β Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 amdfendrmgr; C:\windows\System32\drivers\amdfendrmgr.sys [25560 2023-04-12] (Microsoft Windows Hardware Compatibility Publisher β Advanced Micro Devices, Inc.) R3 amdgpio3; C:\windows\System32\drivers\amdgpio3.sys [36928 2022-07-07] (ASMedia Technology Inc. β Advanced Micro Devices, Inc) R3 amdwddmg; C:\windows\System32\DriverStore\FileRepository\u0392596.inf_amd64_6b8c540dc585ffa4\B392262\amdkmdag.sys [100372792 2023-06-06] (Advanced Micro Devices Inc. β Advanced Micro Devices, Inc.) R3 expressvpntun; C:\windows\System32\drivers\expressvpn-tun.sys [56536 2022-08-04] (Express VPN International Ltd. β ExpressVPN) R0 fse; C:\windows\System32\drivers\fse.sys [218464 2023-05-05] (Microsoft Windows β Microsoft Corporation) R3 HPCustomCapDriver; C:\windows\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_a955fa431e522f5e\x64\hpcustomcapdriver.sys [26648 2022-06-23] (HP Inc. β HP Inc.) R2 HpReadHWData; C:\windows\system32\drivers\HpReadHWData.sys [52176 2023-08-15] (HP Inc. β Windows (R) Win 7 DDK provider) S3 rtcx21; C:\windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_516e5c9b75c49dc2\rtcx21x64.sys [539648 2022-05-06] (Microsoft Windows β Realtek) S4 UCPD; C:\windows\System32\drivers\UCPD.sys [29184 2023-09-12] (Microsoft Windows β Microsoft Corporation) S3 vmbusproxy; C:\windows\system32\drivers\vmbusproxy.sys [94208 2023-05-05] (Microsoft Windows β ) S0 WdBoot; C:\windows\System32\drivers\wd\WdBoot.sys [55872 2023-08-31] (Microsoft Windows Early Launch Anti-malware Publisher β Microsoft Corporation) U5 WdDevFlt; C:\Windows\System32\Drivers\WdDevFlt.sys [169232 2022-05-07] (Microsoft Windows β Microsoft Corporation) R0 WdFilter; C:\windows\System32\drivers\wd\WdFilter.sys [574872 2023-08-31] (Microsoft Windows β Microsoft Corporation) R3 WdNisDrv; C:\windows\System32\drivers\wd\WdNisDrv.sys [105864 2023-08-31] (Microsoft Windows β Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2023-09-27 14:26 - 2023-09-27 14:26 - 000018801 _____ C:\Users\john\Downloads\FRST.txt 2023-09-27 14:25 - 2023-09-27 14:26 - 000000000 ____D C:\FRST 2023-09-27 12:35 - 2023-09-27 12:35 - 002382848 _____ (Farbar) C:\Users\john\Downloads\FRST64(1).exe 2023-09-27 12:32 - 2023-09-27 12:32 - 002382848 _____ (Farbar) C:\Users\john\Downloads\FRST64.exe 2023-09-27 10:10 - 2023-09-27 10:10 - 003387256 _____ (Getscreen.me) C:\Users\john\Downloads\getscreen-759730529.exe 2023-09-27 10:10 - 2023-09-27 10:10 - 000000000 ____D C:\Users\john\AppData\Local\Getscreen.me 2023-09-27 10:10 - 2023-09-27 10:10 - 000000000 ____D C:\ProgramData\Getscreen.me 2023-09-26 15:36 - 2023-09-06 02:09 - 006527960 _____ (Realtek Semiconductor Corp.) C:\windows\system32\Drivers\RTKVHD64.sys 2023-09-14 08:02 - 2023-09-27 09:57 - 000000000 ____D C:\Users\john\AppData\Local\OGH 2023-09-14 08:02 - 2023-09-22 06:56 - 000003764 _____ C:\windows\system32\Tasks\OmenInstallMonitor 2023-09-14 08:02 - 2023-09-22 06:56 - 000003706 _____ C:\windows\system32\Tasks\OmenOverlay 2023-09-12 21:36 - 2023-09-16 03:06 - 000000000 ____D C:\Program Files\Mozilla Firefox 2023-09-12 17:07 - 2023-09-12 17:08 - 000000000 ___HD C:$WinREAgent 2023-09-05 20:46 - 2023-09-05 20:46 - 002364011 _____ C:\Users\john\Downloads\23SC189192 - CRIMINAL INDICTMENT.pdf 2023-08-28 03:58 - 2023-06-06 02:30 - 002194792 _____ C:\windows\system32\vulkaninfo-1-999-0-0-0.exe 2023-08-28 03:58 - 2023-06-06 02:30 - 002194792 _____ C:\windows\system32\vulkaninfo.exe 2023-08-28 03:58 - 2023-06-06 02:30 - 001629032 _____ C:\windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2023-08-28 03:58 - 2023-06-06 02:30 - 001629032 _____ C:\windows\SysWOW64\vulkaninfo.exe 2023-08-28 03:58 - 2023-06-06 02:30 - 001510056 _____ C:\windows\system32\vulkan-1-999-0-0-0.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 001510056 _____ C:\windows\system32\vulkan-1.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 001241168 _____ C:\windows\SysWOW64\vulkan-1-999-0-0-0.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 001241168 _____ C:\windows\SysWOW64\vulkan-1.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000948072 _____ (AMD) C:\windows\system32\atieclxx.exe 2023-08-28 03:58 - 2023-06-06 02:30 - 000801168 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\Rapidfire64.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000678288 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\Rapidfire.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000606104 _____ C:\windows\system32\GameManager64.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000547688 _____ C:\windows\system32\libsmi_guest.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000542056 _____ C:\windows\system32\dgtrayicon.exe 2023-08-28 03:58 - 2023-06-06 02:30 - 000541080 _____ C:\windows\system32\libsmi_host.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000535448 _____ C:\windows\system32\atieah64.exe 2023-08-28 03:58 - 2023-06-06 02:30 - 000502160 _____ C:\windows\system32\EEURestart.exe 2023-08-28 03:58 - 2023-06-06 02:30 - 000459672 _____ C:\windows\SysWOW64\GameManager32.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000360856 _____ C:\windows\system32\clinfo.exe 2023-08-28 03:58 - 2023-06-06 02:30 - 000266088 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atig6txx.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000226704 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atigktxx.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000195944 _____ (AMD) C:\windows\system32\atimuixx.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000183656 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atisamu64.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000146792 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atisamu32.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000051048 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\RapidFireServer64.dll 2023-08-28 03:58 - 2023-06-06 02:30 - 000048016 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\RapidFireServer.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 100654440 _____ C:\windows\system32\amd_comgr.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 084675944 _____ C:\windows\SysWOW64\amd_comgr32.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 007200136 _____ C:\windows\system32\amdsmi.exe 2023-08-28 03:58 - 2023-06-06 02:29 - 002266984 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdsasrv64.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 001547624 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atiadlxy.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 001547624 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atiadlxx.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 001320296 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdsacli64.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 001048936 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdsacli32.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000942992 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdlvr64.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000524136 _____ (Khronos Group) C:\windows\system32\OpenCL.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000472984 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atidemgy.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000404328 _____ C:\windows\SysWOW64\atieah32.exe 2023-08-28 03:58 - 2023-06-06 02:29 - 000389480 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000210112 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\aticfx64.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000172968 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\aticfx32.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000142184 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amfrt64.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000138088 _____ C:\windows\system32\amdxc64.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000118120 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amfrt32.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000113560 _____ C:\windows\SysWOW64\amdxc32.dll 2023-08-28 03:58 - 2023-06-06 02:29 - 000074600 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\ati2erec.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 016174392 _____ (Advanced Micro Devices Inc.) C:\windows\system32\amdhip64.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 004364136 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdadlx64.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 004170088 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdadlx32.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 001725480 _____ (AMD) C:\windows\system32\amf-mft-mjpeg-decoder64.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 001399944 _____ (AMD) C:\windows\SysWOW64\amf-mft-mjpeg-decoder32.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000770872 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdlvr32.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000568168 _____ C:\windows\system32\amdgfxinfo64.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000567688 _____ C:\windows\system32\amdmiracast.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000470888 _____ C:\windows\system32\amdlogum.exe 2023-08-28 03:58 - 2023-06-06 02:28 - 000431976 _____ C:\windows\SysWOW64\amdgfxinfo32.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000187352 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdihk32.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000176856 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdave64.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000166984 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atimpc64.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000166936 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdpcom64.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000156448 _____ C:\windows\system32\atidxx64.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000151000 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdave32.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000136416 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atimpc32.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000136416 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdpcom32.dll 2023-08-28 03:58 - 2023-06-06 02:28 - 000129568 _____ C:\windows\SysWOW64\atidxx32.dll 2023-08-28 03:58 - 2023-06-06 01:56 - 094947424 _____ C:\windows\system32\amdxc64.so ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2023-09-27 14:24 - 2022-05-07 01:24 - 000000000 ____D C:\windows\SystemTemp 2023-09-27 14:20 - 2022-06-30 21:01 - 000000000 ____D C:\windows\system32\SleepStudy 2023-09-27 12:24 - 2022-05-07 01:24 - 000000000 ___HD C:\Program Files\WindowsApps 2023-09-27 12:24 - 2022-05-07 01:24 - 000000000 ____D C:\windows\AppReadiness 2023-09-27 12:23 - 2022-05-07 01:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-09-27 11:59 - 2023-05-25 07:01 - 000000000 ____D C:\Users\john\AppData\Local\D3DSCache 2023-09-27 11:57 - 2022-05-07 01:22 - 000000000 ____D C:\windows\INF 2023-09-27 11:56 - 2023-05-26 20:19 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2023-09-27 10:41 - 2023-05-25 06:40 - 000000000 ____D C:\Users\john 2023-09-27 10:27 - 2022-06-30 21:07 - 000855938 _____ C:\windows\system32\PerfStringBackup.INI 2023-09-27 10:23 - 2022-06-30 21:01 - 000012288 ___SH C:\DumpStack.log.tmp 2023-09-27 10:23 - 2022-06-30 21:01 - 000000006 ____H C:\windows\Tasks\SA.DAT 2023-09-27 09:57 - 2023-05-05 07:34 - 000000000 ____D C:\Program Files\AMD 2023-09-27 09:57 - 2023-05-05 07:01 - 000001607 _____ C:\windows\system32\config\VSMIDK 2023-09-27 02:42 - 2022-06-30 21:01 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-09-27 02:42 - 2022-06-30 21:01 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2023-09-26 15:36 - 2023-05-05 07:33 - 000003366 _____ C:\windows\system32\Tasks\RtkAudUService64_BG 2023-09-26 03:35 - 2023-05-25 07:53 - 000003588 _____ C:\windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1867205174-823180755-3576545642-1001 2023-09-26 03:35 - 2023-05-25 07:03 - 000003376 _____ C:\windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1867205174-823180755-3576545642-1001 2023-09-26 03:35 - 2023-05-25 07:03 - 000002383 _____ C:\Users\john\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2023-09-25 23:25 - 2023-05-25 06:40 - 000000000 ____D C:\Users\john\AppData\Local\Packages 2023-09-22 07:36 - 2023-05-25 07:18 - 000000000 ____D C:\windows\system32\Tasks\Hewlett-Packard 2023-09-22 06:56 - 2023-05-05 07:05 - 000000000 ____D C:\Program Files\HP 2023-09-17 11:12 - 2023-05-05 07:07 - 000000000 ____D C:\Program Files\Microsoft Office 2023-09-16 03:22 - 2022-05-07 01:24 - 000000000 ____D C:\ProgramData\USOPrivate 2023-09-16 03:06 - 2023-05-26 20:19 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2023-09-16 03:06 - 2022-06-30 21:01 - 000504272 _____ C:\windows\system32\FNTCACHE.DAT 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ___RD C:\windows\ImmersiveControlPanel 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\UUS 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\SysWOW64\WinMetadata 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\SysWOW64\Dism 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\SystemResources 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\system32\WinMetadata 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\system32\oobe 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\system32\Dism 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\system32\appraiser 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\ShellExperiences 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\ShellComponents 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\Provisioning 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\PolicyDefinitions 2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\bcastdvr 2023-09-16 03:06 - 2022-05-07 01:17 - 000524288 _____ C:\windows\system32\config\BBI 2023-09-14 08:06 - 2023-05-26 20:19 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2023-09-12 17:21 - 2022-05-07 01:17 - 000000000 ____D C:\windows\CbsTemp 2023-09-12 17:11 - 2022-06-30 21:04 - 003210752 _____ (Microsoft Corporation) C:\windows\SysWOW64\PrintConfig.dll 2023-09-12 17:05 - 2023-05-25 03:59 - 000000000 ____D C:\windows\system32\MRT 2023-09-12 17:04 - 2023-05-25 03:59 - 177941912 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe 2023-08-31 09:37 - 2022-06-30 21:01 - 000000000 ____D C:\windows\system32\Drivers\wd 2023-08-29 21:23 - 2023-05-25 04:06 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================
Comment