Here is the FRST LOG
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-09-2023
Ran by john (administrator) on DESKTOP-THSFR3B (HP HP Desktop M01-F3xxx) (27-09-2023 14:26:02)
Running from C:\Users\john\Downloads\FRST64.exe
Loaded Profiles: john
Platform: Microsoft Windows 11 Home Version 22H2 22621.2283 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe ->) (EXPRSVPN LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe
(C:\Program Files\WindowsApps\MicrosoftTeams_23231.411.2342.9597_x64__8wekyb3d8bbwe\msteams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.36\msedgewebview2.exe <12>
(DriverStore\FileRepository\u0392596.inf_amd64_6b8c540dc585ffa4\B392262\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0392596.inf_amd64_6b8c540dc585ffa4\B392262\atieclxx.exe
(ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_1.3.35.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityHost.exe
(ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.OMENCommandCenter_1101.2309.1.0_x64__v10z8vjag6ke6\OmenCommandCenterApp\OmenCommandCenterBackground.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <17>
(EXPRSVPN LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationService.exe
(HP Inc. -> ) C:\Program Files\HP\Overlay\OMENOverlay.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <9>
(SECOMN64.exe ->) (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOCL64.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0392596.inf_amd64_6b8c540dc585ffa4\B392262\atiesrxx.exe
(services.exe ->) (EXPRSVPN LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe
(services.exe ->) (HON HAI PRECISION INDUSTRY CO.LTD. -> ) C:\Program Files\FanControlApp\FanControlApp.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_43e3600968234e87\x64\TouchpointAnalyticsClientService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\SysInfoCap.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkWiFiManServ.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0c755fff65745edd\RtkAudUService64.exe <2>
(services.exe ->) (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe
(sihost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> ) C:\Program Files\WindowsApps\AD2F1837.myHP_25.52334.606.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe
(sihost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPEnhance_1.3.5.0_x64__v10z8vjag6ke6\Win32\HPEnhancedLighting.Bg.exe
(svchost.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> ) C:\Program Files\WindowsApps\AD2F1837.myHP_25.52334.606.0_x64__v10z8vjag6ke6\HP.myHP.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe
(svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\Overlay\OverlayHelper.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftTeams_23231.411.2342.9597_x64__8wekyb3d8bbwe\msteamsupdate.exe
(svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [ExpressVPNNotificationService] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationServiceStarter.exe [380816 2022-08-04] (EXPRSVPN LLC -> ExpressVPN)
HKU\S-1-5-21-1867205174-823180755-3576545642-1001\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HPSEU\HpseuHostLauncher.exe [537136 2023-08-14] (HP Inc. -> HP Inc.)
HKU\S-1-5-21-1867205174-823180755-3576545642-1001\...\Run: [MicrosoftEdgeAutoLaunch_45D944CC36A69C479BF3C348604E81F2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4210112 2023-09-25] (Microsoft Corporation -> Microsoft Corporation)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {5190F5B8-9F34-460B-B763-B429A0159410} - \McAfee\DAD.Execute.Updates -> No File <==== ATTENTION
Task: {F4FA67D7-5D83-4AAB-B39E-A8BFB942847C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [703536 2023-09-15] (HP Inc. -> HP Inc.)
Task: {2BCB33C1-8EAA-47CD-A25F-3B97694B9B47} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [138328 2023-09-15] (HP Inc. -> HP Inc.)
Task: {E4433F47-91AB-4DFC-BEB8-9DADF24E5724} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1161264 2023-09-15] (HP Inc. -> HP Inc.)
Task: {3AC03B8B-FC7B-4B62-AEBD-470A57062CD1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1161264 2023-09-15] (HP Inc. -> HP Inc.)
Task: {14AC54B9-F75B-4EFD-AB67-10C84ED0DECF} - System32\Tasks\HP\Consent Manager Launcher => C:\windows\system32\sc.exe [98304 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> start hptouchpointanalyticsservice
Task: {00D4FB00-9FD1-4675-947C-F263C6CDC349} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26913760 2023-09-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {069EA780-6129-41B5-B9AF-537B8A98090F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26913760 2023-09-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {5503D4E0-7C38-42F6-8BEE-BC0256BA22B5} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158664 2023-09-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {C0B5A6DB-2936-4BCE-BFD0-90269963DFAA} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158664 2023-09-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {F66CE3EA-2BB8-44A5-B053-D170C4398BAA} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [167864 2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {74D6A48C-DFF2-4331-B2BA-E3B048420FD3} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\UCPD velocity => C:\windows\system32\UCPDMgr.exe [58880 2023-09-12] (Microsoft Windows -> Microsoft Corporation)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {14C2CE4A-1092-4618-871C-289B29B806D0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CA3EBC08-3FC6-4CF0-BA75-731510213B14} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6B45F2EF-EA3E-488A-AFF2-98C6674D6601} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E3063D3E-2308-4359-98BD-5862F4AFBB1A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-08-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {32FD51C1-47BB-4DE2-BCCD-F588395820CC} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [675232 2023-09-12] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {6863F2A9-37E1-45ED-A870-22B760EF45F5} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [722336 2023-09-12] (Mozilla Corporation -> Mozilla Foundation)
Task: {E86E1369-7512-406E-B77C-0AB423F2EF73} - System32\Tasks\OmenInstallMonitor => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe [58352 2023-09-19] (HP Inc. -> HP Inc.)
Task: {E54FD9E5-74BF-4BCC-A4E6-A199E55D066C} - System32\Tasks\OmenOverlay => C:\Program Files\HP\Overlay\OverlayHelper.exe [59888 2023-09-19] (HP Inc. -> HP Inc.)
Task: {2F7EBAED-882C-4AB8-B623-226B05736234} - System32\Tasks\RtkAudUService64_BG => C:\windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0c755fff65745edd\RtkAudUService64.exe [1923384 2023-09-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{fed75b1f-821c-4c33-a838-025763bcbc5d}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\john\AppData\Local\Microsoft\Edge\User Data\Default [2023-09-27]
Edge Notifications: Default -> hxxps://pchelpforum.net; hxxps://politicalhotwire.com; hxxps://www.facebook.com; hxxps://www.instagram.com; hxxps://www.youtube.com
Edge Session Restore: Default -> is enabled.
Edge Extension: (Google Docs Offline) - C:\Users\john\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-08-30]
Edge Extension: (Edge relevant text changes) - C:\Users\john\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-14]
FireFox:
========
FF DefaultProfile: ujse8sqr.default
FF ProfilePath: C:\Users\john\AppData\Roaming\Mozilla\Firefox\Profiles\ujse8sqr.default [2023-05-26]
FF ProfilePath: C:\Users\john\AppData\Roaming\Mozilla\Firefox\Profiles\6sjtp7l0.default-release [2023-09-27]
FF Notifications: Mozilla\Firefox\Profiles\6sjtp7l0.default-release -> hxxps://www.instagram.com
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-08-01] (Microsoft Corporation -> Microsoft Corporation)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11817040 2023-09-01] (Microsoft Corporation -> Microsoft Corporation)
R2 ExpressVPNService; C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe [439696 2022-08-04] (EXPRSVPN LLC -> ExpressVPN)
R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [893984 2022-08-15] (HP Inc. -> HP Inc.)
R2 HPAppHelperCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\AppHelperCap.exe [888272 2023-08-29] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\DiagsCap.exe [886736 2023-08-29] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\NetworkCap.exe [883152 2023-08-29] (HP Inc. -> HP Inc.)
R2 HPSysInfoCap; C:\windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f1a9bf9a59c52b11\x64\SysInfoCap.exe [886840 2023-08-29] (HP Inc. -> HP Inc.)
R2 HpTouchpointAnalyticsService; C:\windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_43e3600968234e87\x64\TouchpointAnalyticsClientService.exe [497744 2023-08-02] (HP Inc. -> HP Inc.)
R2 ID19 HP Fan Control Service; C:\Program Files\FanControlApp\FanControlApp.exe [283168 2020-04-28] (HON HAI PRECISION INDUSTRY CO.LTD. -> )
R2 RtkWiFiManServ; C:\windows\RtkWiFiManServ.exe [821632 2023-06-27] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe [3121008 2023-08-31] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe [133688 2023-08-31] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdfendrmgr; C:\windows\System32\drivers\amdfendrmgr.sys [25560 2023-04-12] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdgpio3; C:\windows\System32\drivers\amdgpio3.sys [36928 2022-07-07] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
R3 amdwddmg; C:\windows\System32\DriverStore\FileRepository\u0392596.inf_amd64_6b8c540dc585ffa4\B392262\amdkmdag.sys [100372792 2023-06-06] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 expressvpntun; C:\windows\System32\drivers\expressvpn-tun.sys [56536 2022-08-04] (Express VPN International Ltd. -> ExpressVPN)
R0 fse; C:\windows\System32\drivers\fse.sys [218464 2023-05-05] (Microsoft Windows -> Microsoft Corporation)
R3 HPCustomCapDriver; C:\windows\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_a955fa431e522f5e\x64\hpcustomcapdriver.sys [26648 2022-06-23] (HP Inc. -> HP Inc.)
R2 HpReadHWData; C:\windows\system32\drivers\HpReadHWData.sys [52176 2023-08-15] (HP Inc. -> Windows (R) Win 7 DDK provider)
S3 rtcx21; C:\windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_516e5c9b75c49dc2\rtcx21x64.sys [539648 2022-05-06] (Microsoft Windows -> Realtek)
S4 UCPD; C:\windows\System32\drivers\UCPD.sys [29184 2023-09-12] (Microsoft Windows -> Microsoft Corporation)
S3 vmbusproxy; C:\windows\system32\drivers\vmbusproxy.sys [94208 2023-05-05] (Microsoft Windows -> )
S0 WdBoot; C:\windows\System32\drivers\wd\WdBoot.sys [55872 2023-08-31] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
U5 WdDevFlt; C:\Windows\System32\Drivers\WdDevFlt.sys [169232 2022-05-07] (Microsoft Windows -> Microsoft Corporation)
R0 WdFilter; C:\windows\System32\drivers\wd\WdFilter.sys [574872 2023-08-31] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\windows\System32\drivers\wd\WdNisDrv.sys [105864 2023-08-31] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-09-27 14:26 - 2023-09-27 14:26 - 000018801 _____ C:\Users\john\Downloads\FRST.txt
2023-09-27 14:25 - 2023-09-27 14:26 - 000000000 ____D C:\FRST
2023-09-27 12:35 - 2023-09-27 12:35 - 002382848 _____ (Farbar) C:\Users\john\Downloads\FRST64(1).exe
2023-09-27 12:32 - 2023-09-27 12:32 - 002382848 _____ (Farbar) C:\Users\john\Downloads\FRST64.exe
2023-09-27 10:10 - 2023-09-27 10:10 - 003387256 _____ (Getscreen.me) C:\Users\john\Downloads\getscreen-759730529.exe
2023-09-27 10:10 - 2023-09-27 10:10 - 000000000 ____D C:\Users\john\AppData\Local\Getscreen.me
2023-09-27 10:10 - 2023-09-27 10:10 - 000000000 ____D C:\ProgramData\Getscreen.me
2023-09-26 15:36 - 2023-09-06 02:09 - 006527960 _____ (Realtek Semiconductor Corp.) C:\windows\system32\Drivers\RTKVHD64.sys
2023-09-14 08:02 - 2023-09-27 09:57 - 000000000 ____D C:\Users\john\AppData\Local\OGH
2023-09-14 08:02 - 2023-09-22 06:56 - 000003764 _____ C:\windows\system32\Tasks\OmenInstallMonitor
2023-09-14 08:02 - 2023-09-22 06:56 - 000003706 _____ C:\windows\system32\Tasks\OmenOverlay
2023-09-12 21:36 - 2023-09-16 03:06 - 000000000 ____D C:\Program Files\Mozilla Firefox
2023-09-12 17:07 - 2023-09-12 17:08 - 000000000 ___HD C:\$WinREAgent
2023-09-05 20:46 - 2023-09-05 20:46 - 002364011 _____ C:\Users\john\Downloads\23SC189192 - CRIMINAL INDICTMENT.pdf
2023-08-28 03:58 - 2023-06-06 02:30 - 002194792 _____ C:\windows\system32\vulkaninfo-1-999-0-0-0.exe
2023-08-28 03:58 - 2023-06-06 02:30 - 002194792 _____ C:\windows\system32\vulkaninfo.exe
2023-08-28 03:58 - 2023-06-06 02:30 - 001629032 _____ C:\windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2023-08-28 03:58 - 2023-06-06 02:30 - 001629032 _____ C:\windows\SysWOW64\vulkaninfo.exe
2023-08-28 03:58 - 2023-06-06 02:30 - 001510056 _____ C:\windows\system32\vulkan-1-999-0-0-0.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 001510056 _____ C:\windows\system32\vulkan-1.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 001241168 _____ C:\windows\SysWOW64\vulkan-1-999-0-0-0.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 001241168 _____ C:\windows\SysWOW64\vulkan-1.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000948072 _____ (AMD) C:\windows\system32\atieclxx.exe
2023-08-28 03:58 - 2023-06-06 02:30 - 000801168 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\Rapidfire64.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000678288 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\Rapidfire.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000606104 _____ C:\windows\system32\GameManager64.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000547688 _____ C:\windows\system32\libsmi_guest.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000542056 _____ C:\windows\system32\dgtrayicon.exe
2023-08-28 03:58 - 2023-06-06 02:30 - 000541080 _____ C:\windows\system32\libsmi_host.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000535448 _____ C:\windows\system32\atieah64.exe
2023-08-28 03:58 - 2023-06-06 02:30 - 000502160 _____ C:\windows\system32\EEURestart.exe
2023-08-28 03:58 - 2023-06-06 02:30 - 000459672 _____ C:\windows\SysWOW64\GameManager32.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000360856 _____ C:\windows\system32\clinfo.exe
2023-08-28 03:58 - 2023-06-06 02:30 - 000266088 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atig6txx.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000226704 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atigktxx.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000195944 _____ (AMD) C:\windows\system32\atimuixx.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000183656 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atisamu64.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000146792 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atisamu32.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000051048 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\RapidFireServer64.dll
2023-08-28 03:58 - 2023-06-06 02:30 - 000048016 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\RapidFireServer.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 100654440 _____ C:\windows\system32\amd_comgr.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 084675944 _____ C:\windows\SysWOW64\amd_comgr32.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 007200136 _____ C:\windows\system32\amdsmi.exe
2023-08-28 03:58 - 2023-06-06 02:29 - 002266984 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdsasrv64.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 001547624 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atiadlxy.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 001547624 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atiadlxx.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 001320296 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdsacli64.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 001048936 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdsacli32.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000942992 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdlvr64.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000524136 _____ (Khronos Group) C:\windows\system32\OpenCL.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000472984 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atidemgy.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000404328 _____ C:\windows\SysWOW64\atieah32.exe
2023-08-28 03:58 - 2023-06-06 02:29 - 000389480 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000210112 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\aticfx64.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000172968 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\aticfx32.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000142184 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amfrt64.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000138088 _____ C:\windows\system32\amdxc64.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000118120 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amfrt32.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000113560 _____ C:\windows\SysWOW64\amdxc32.dll
2023-08-28 03:58 - 2023-06-06 02:29 - 000074600 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\ati2erec.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 016174392 _____ (Advanced Micro Devices Inc.) C:\windows\system32\amdhip64.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 004364136 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdadlx64.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 004170088 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdadlx32.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 001725480 _____ (AMD) C:\windows\system32\amf-mft-mjpeg-decoder64.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 001399944 _____ (AMD) C:\windows\SysWOW64\amf-mft-mjpeg-decoder32.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000770872 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdlvr32.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000568168 _____ C:\windows\system32\amdgfxinfo64.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000567688 _____ C:\windows\system32\amdmiracast.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000470888 _____ C:\windows\system32\amdlogum.exe
2023-08-28 03:58 - 2023-06-06 02:28 - 000431976 _____ C:\windows\SysWOW64\amdgfxinfo32.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000187352 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdihk32.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000176856 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdave64.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000166984 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atimpc64.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000166936 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdpcom64.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000156448 _____ C:\windows\system32\atidxx64.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000151000 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdave32.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000136416 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atimpc32.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000136416 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdpcom32.dll
2023-08-28 03:58 - 2023-06-06 02:28 - 000129568 _____ C:\windows\SysWOW64\atidxx32.dll
2023-08-28 03:58 - 2023-06-06 01:56 - 094947424 _____ C:\windows\system32\amdxc64.so
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-09-27 14:24 - 2022-05-07 01:24 - 000000000 ____D C:\windows\SystemTemp
2023-09-27 14:20 - 2022-06-30 21:01 - 000000000 ____D C:\windows\system32\SleepStudy
2023-09-27 12:24 - 2022-05-07 01:24 - 000000000 ___HD C:\Program Files\WindowsApps
2023-09-27 12:24 - 2022-05-07 01:24 - 000000000 ____D C:\windows\AppReadiness
2023-09-27 12:23 - 2022-05-07 01:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-09-27 11:59 - 2023-05-25 07:01 - 000000000 ____D C:\Users\john\AppData\Local\D3DSCache
2023-09-27 11:57 - 2022-05-07 01:22 - 000000000 ____D C:\windows\INF
2023-09-27 11:56 - 2023-05-26 20:19 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-09-27 10:41 - 2023-05-25 06:40 - 000000000 ____D C:\Users\john
2023-09-27 10:27 - 2022-06-30 21:07 - 000855938 _____ C:\windows\system32\PerfStringBackup.INI
2023-09-27 10:23 - 2022-06-30 21:01 - 000012288 ___SH C:\DumpStack.log.tmp
2023-09-27 10:23 - 2022-06-30 21:01 - 000000006 ____H C:\windows\Tasks\SA.DAT
2023-09-27 09:57 - 2023-05-05 07:34 - 000000000 ____D C:\Program Files\AMD
2023-09-27 09:57 - 2023-05-05 07:01 - 000001607 _____ C:\windows\system32\config\VSMIDK
2023-09-27 02:42 - 2022-06-30 21:01 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-09-27 02:42 - 2022-06-30 21:01 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-09-26 15:36 - 2023-05-05 07:33 - 000003366 _____ C:\windows\system32\Tasks\RtkAudUService64_BG
2023-09-26 03:35 - 2023-05-25 07:53 - 000003588 _____ C:\windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1867205174-823180755-3576545642-1001
2023-09-26 03:35 - 2023-05-25 07:03 - 000003376 _____ C:\windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1867205174-823180755-3576545642-1001
2023-09-26 03:35 - 2023-05-25 07:03 - 000002383 _____ C:\Users\john\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-09-25 23:25 - 2023-05-25 06:40 - 000000000 ____D C:\Users\john\AppData\Local\Packages
2023-09-22 07:36 - 2023-05-25 07:18 - 000000000 ____D C:\windows\system32\Tasks\Hewlett-Packard
2023-09-22 06:56 - 2023-05-05 07:05 - 000000000 ____D C:\Program Files\HP
2023-09-17 11:12 - 2023-05-05 07:07 - 000000000 ____D C:\Program Files\Microsoft Office
2023-09-16 03:22 - 2022-05-07 01:24 - 000000000 ____D C:\ProgramData\USOPrivate
2023-09-16 03:06 - 2023-05-26 20:19 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2023-09-16 03:06 - 2022-06-30 21:01 - 000504272 _____ C:\windows\system32\FNTCACHE.DAT
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ___RD C:\windows\ImmersiveControlPanel
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\UUS
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\SysWOW64\WinMetadata
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\SysWOW64\Dism
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\SystemResources
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\system32\WinMetadata
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\system32\oobe
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\system32\Dism
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\system32\appraiser
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\ShellExperiences
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\ShellComponents
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\Provisioning
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\PolicyDefinitions
2023-09-16 03:06 - 2022-05-07 01:24 - 000000000 ____D C:\windows\bcastdvr
2023-09-16 03:06 - 2022-05-07 01:17 - 000524288 _____ C:\windows\system32\config\BBI
2023-09-14 08:06 - 2023-05-26 20:19 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2023-09-12 17:21 - 2022-05-07 01:17 - 000000000 ____D C:\windows\CbsTemp
2023-09-12 17:11 - 2022-06-30 21:04 - 003210752 _____ (Microsoft Corporation) C:\windows\SysWOW64\PrintConfig.dll
2023-09-12 17:05 - 2023-05-25 03:59 - 000000000 ____D C:\windows\system32\MRT
2023-09-12 17:04 - 2023-05-25 03:59 - 177941912 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2023-08-31 09:37 - 2022-06-30 21:01 - 000000000 ____D C:\windows\system32\Drivers\wd
2023-08-29 21:23 - 2023-05-25 04:06 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Last edited by a moderator: