FRST:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-07-2023
Ran by tmmrcy (administrator) on LAPTOP-BQN0JE4L (HUAWEI BOD-WXX9) (27-07-2023 19:17:28)
Running from C:\Users\tzahi\Desktop\PC Help Forum Tings\FRST64.exe
Loaded Profiles: tmmrcy
Platform: Microsoft Windows 11 Home Version 22H2 22621.1928 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(C:\Program Files\Huawei\HMS Core\HMSCoreService.exe ->) (Huawei Technologies Co., Ltd. -> Huawei Technologies Co., Ltd.) C:\Program Files\Huawei\HMS Core\HMSCoreContainer.exe
(C:\Program Files\Huawei\PCManager\MateBookService.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\PCManager\HwMdcCenter.exe
(C:\Program Files\Huawei\PCManager\MateBookService.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\PCManager\MBAMessageCenter.exe
(C:\Program Files\Huawei\PCManager\MBAMessageCenter.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\PCManager\DFSSearchService.exe
(C:\Program Files\Huawei\PCManager\MBAMessageCenter.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\PCManager\MessageCenterUI.exe
(C:\Program Files\Huawei\PCManager\MBAMessageCenter.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\PCManager\PerfWndMonHelper.exe
(C:\Program Files\Huawei\PCManager\MBAMessageCenter.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\PCManager\PerfWndMonHelper_x86.exe
(C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.13900.0.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\115.0.1901.183\msedgewebview2.exe <6>
(C:\Users\tzahi\AppData\Local\Kingsoft\WPS Office\11.2.0.11388\office6\wpscloudsvr.exe ->) (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\tzahi\AppData\Local\Kingsoft\WPS Office\11.2.0.11388\office6\wpscenter.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_6673c5322430fc8a\igfxCUIServiceN.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_6673c5322430fc8a\igfxEMN.exe
(explorer.exe ->) (ALCPU -> ALCPU) C:\Program Files\Core Temp\Core Temp.exe
(HWVEAudioService.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\WINDOWS\System32\HWVEAudioSession.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <11>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(RPC\OSD\osdservice.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\Huawei OSD\OSD_Daemon.exe
(services.exe ->) (A-Volute SAS -> Nahimic) C:\WINDOWS\System32\NahimicService.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(services.exe ->) (FOXIT SOFTWARE INC. -> Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\FoxitPhantomPDFUpdateService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\BasicService\BasicService.exe
(services.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\HwLcdEnhancement\LCD_Service.exe
(services.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\PCManager\MateBookService.exe
(services.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\WINDOWS\System32\HWVEAudioService.exe
(services.exe ->) (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.) C:\WINDOWS\System32\RPC\OSD\osdservice.exe
(services.exe ->) (Huawei Technologies Co., Ltd. -> Huawei Device Co., Ltd.) C:\Program Files\Huawei\Hiview\HiviewService.exe
(services.exe ->) (Huawei Technologies Co., Ltd. -> Huawei Technologies Co., Ltd.) C:\Program Files\Huawei\HMS Core\HMSCoreService.exe
(services.exe ->) (Huawei Technologies Co., Ltd. -> Huawei Technologies Co., Ltd.) C:\Program Files\Huawei\wucs\WUCSProxyService.exe
(services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files\Intel\Intel Arc Control\ArcControlService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_6673c5322430fc8a\igfxCUIServiceN.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_f75fa513cf0ccec1\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_a687edda40db3316\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_3b3ce26993cf233b\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\piecomponent.inf_amd64_0570478011758f12\Intel_PIE_Service.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2>
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncHelper.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\WINDOWS\System32\FMService64.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Goodix) C:\WINDOWS\System32\drivers\SessionService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_4b6fe1c4e6f1d68a\RtkAudUService64.exe <3>
(sihost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5131.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe
(svchost.exe ->) (21E1B422-257A-44A2-9C8F-379165856473 -> ) C:\Program Files\WindowsApps\A-Volute.Nahimic_1.9.17.0_x64__w2gh52qy24etm\Nahimic3.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2327.6.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (A-Volute SAS -> Nahimic) C:\WINDOWS\System32\NahimicSvc64.exe
(svchost.exe ->) (A-Volute SAS -> Nahimic) C:\WINDOWS\SysWOW64\NahimicSvc32.exe
(svchost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5131.0_x64__8j3eq9eme6ctt\IGCC.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.3261.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.823.3261.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.13900.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\LocationNotificationWindows.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\SysWOW64\wbem\WmiPrvSE.exe
(svchost.exe ->) (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\tzahi\AppData\Local\Kingsoft\WPS Office\11.2.0.11388\office6\wpscloudsvr.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_4b6fe1c4e6f1d68a\RtkAudUService64.exe [1256520 2021-04-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [739448 2023-03-17] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Intel® Arc™ Control] => C:\Program Files\Intel\Intel Arc Control\ArcControl.exe [1529384 2023-06-08] (Intel Corporation -> Intel Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe"
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\115.0.1901.183\Installer\setup.exe [3663776 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKU\S-1-5-21-516455074-3529725477-31475253-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2607520 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-516455074-3529725477-31475253-1001\...\Run: [MicrosoftEdgeAutoLaunch_2CDA1A8278879F750DEE63BCC2A16BEC] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4088272 2023-07-21] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-516455074-3529725477-31475253-1001\...\Run: [] => [X]
HKLM\...\Print\Monitors\HP E111 Status Monitor: C:\WINDOWS\system32\hpinkstsE111LM.dll [393352 2017-04-14] (Hewlett Packard -> HP Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {89C88217-6FE5-472C-A4A5-BA18A1CA5495} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [5002472 2023-03-28] (Intel Corporation -> Intel Corporation)
Task: {BD2A0C06-9B8F-41A6-A561-6C469C93768F} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [5002472 2023-03-28] (Intel Corporation -> Intel Corporation)
Task: {F6A39165-6DE6-464C-8918-7E05503ED911} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {784AD28D-5B5C-46F3-8AA9-8435056AF512} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26616832 2023-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {974899D4-CE9E-4050-BFDA-3932E40832A1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26616832 2023-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {F3A64BBD-5A2E-424B-9F3C-3C331F2FFBC3} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158664 2023-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {0FA93288-9CC7-449F-A57C-2BC2C433C4AC} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158664 2023-07-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {BACC9B00-4A7C-49EC-BC2E-B3F40DFB999D} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [164752 2023-07-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {A976026E-4D8C-469E-AEFF-3F088580BC8B} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
Task: {E3A30FA9-D4F7-476E-85D1-09C722F93023} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {3C2411E2-875F-4A96-803B-AD1FC43AB975} - System32\Tasks\NahimicSvc32Run => C:\Windows\SysWOW64\NahimicSvc32.exe [829544 2021-07-02] (A-Volute SAS -> Nahimic)
Task: {A848FA44-1C8C-479F-A946-7E1AC9C29A71} - System32\Tasks\NahimicSvc64Run => C:\Windows\system32\NahimicSvc64.exe [1088616 2021-07-02] (A-Volute SAS -> Nahimic)
Task: {636B134F-D6A5-4D69-A9B7-48F3DE123F83} - System32\Tasks\NahimicTask32 => C:\WINDOWS\system32\..\SysWOW64\NahimicSvc32.exe [829544 ] (A-Volute SAS -> Nahimic)
Task: {1D726454-0314-486C-8BA3-4515AB09EC63} - System32\Tasks\NahimicTask64 => C:\WINDOWS\system32\.\NahimicSvc64.exe [1088616 ] (A-Volute SAS -> Nahimic)
Task: {EB1E1C1D-1736-48EA-B249-BF4A5FC2CECA} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4125576 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {D16417EF-0C5E-40D7-821D-FA90EEA2B722} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-516455074-3529725477-31475253-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4125576 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {42FE7CEB-8F85-4C25-95A6-4BD0F736AAC7} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\WINDOWS\System32\Wscript.exe [200704 2023-05-12] (Microsoft Windows -> Microsoft Corporation) -> //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {6DEF4AB9-144A-495D-82D7-9170E5329F5D} - System32\Tasks\Window Update => C:\Users\tzahi\AppData\Local\Updates\Run.vbs [1015 2022-05-09] () [File not signed] <==== ATTENTION
Task: {1EBDEC72-F7EB-4367-A91D-1407EB41AB1F} - System32\Tasks\WpsExternal_tzahi_20221119083148 => C:\Users\tzahi\AppData\Local\Kingsoft\WPS Office\11.2.0.11388\office6\wpscloudsvr.exe [1057928 2022-11-19] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd) -> /wpscloudlaunch /run_plugin /plugin_name=ktaskschdtool /plugin_entry=ktaskschdtool.dll /task=wpsexternal /launchtask /ver=1.0 /start_from=task_external
Task: {8B915058-845F-43C0-A27E-CF36D34D133D} - System32\Tasks\WpsUpdateTask_tmmrcy => C:\Users\tzahi\AppData\Local\Kingsoft\WPS Office\11.2.0.11388\office6\wpsupdate.exe [172168 2022-11-19] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {E48D667A-D43B-41D1-AE87-35C0BBF0EB86} - System32\Tasks\WpsUpdateTask_tzahi => C:\Users\tzahi\AppData\Local\Kingsoft\WPS Office\11.2.0.11388\office6\wpsupdate.exe [172168 2022-11-19] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0e1db6e2-967c-4181-ad20-1a7c8debc340}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f56d216f-17ce-4734-aca7-25767677a9dd}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{f8d21a67-f548-45c5-a7aa-e808c1aba960}: [DhcpNameServer] 40.42.1.13
Edge:
=======
Edge DefaultProfile: Profile 1
Edge Profile: C:\Users\tzahi\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2023-07-27]
Edge Notifications: Profile 1 -> hxxps://pchelpforum.net; hxxps://teams.microsoft.com
Edge Extension: (Adblock Plus - free ad blocker) - C:\Users\tzahi\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2023-07-27]
Edge Extension: (Halo – Arrival) - C:\Users\tzahi\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\ddgdgdmkcagpbibgcilbidjfokdngfld [2022-09-07]
Edge Extension: (Edge relevant text changes) - C:\Users\tzahi\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-07-27]
Edge HKU\S-1-5-21-516455074-3529725477-31475253-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [njjljiblognghfjfpcdpdbpbfcmhgafg]
FireFox:
========
FF HKLM\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi
FF Extension: (Foxit PDF Creator) - C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi [2020-04-22] [Legacy]
FF HKLM\...\Firefox\Extensions: [FireFoxNew-WebExtensions@foxitsoftware.com] - C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FireFoxNew-WebExtensions@foxitsoftware.com.xpi
FF Extension: (Foxit PDF Creator) - C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FireFoxNew-WebExtensions@foxitsoftware.com.xpi [2020-04-22]
FF HKLM-x32\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi
FF HKLM-x32\...\Firefox\Extensions: [FireFoxNew-WebExtensions@foxitsoftware.com] - C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FireFoxNew-WebExtensions@foxitsoftware.com.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-07-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2020-04-29] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2020-04-29] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2020-04-29] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2020-04-29] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2020-04-29] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.371.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2023-03-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.371.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\plugin2\npjp2.dll [2023-03-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-07-06] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2020-04-22]
CHR HKU\S-1-5-21-516455074-3529725477-31475253-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gjgfobnenmnljakmhboildkafdkicala]
CHR HKLM-x32\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2020-04-22]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8885112 2022-07-06] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11851240 2023-07-17] (Microsoft Corporation -> Microsoft Corporation)
R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [43272 2023-07-03] (Intel Corporation -> Intel)
R3 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [212744 2023-07-03] (Intel Corporation -> Intel)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [813032 2022-07-06] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029456 2022-07-15] (Epic Games Inc. -> Epic Games, Inc.)
R3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\23.142.0709.0001\FileSyncHelper.exe [3447736 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
R2 FMAPOService; C:\WINDOWS\System32\FMService64.exe [381312 2020-05-21] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
R2 FoxitPhantomPDFUpdateService; C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\FoxitPhantomPDFUpdateService.exe [1995184 2020-04-29] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
R2 HiviewService; C:\Program Files\Huawei\Hiview\HiviewService.exe [5127064 2022-12-05] (Huawei Technologies Co., Ltd. -> Huawei Device Co., Ltd.)
S3 HmdfsOfficeSvc; C:\Program Files\Huawei\PCManager\hmdfsservice.exe [786312 2022-10-24] (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.)
S3 HmdfsPcSvc; C:\Program Files\Huawei\PCManager\hmdfsservice.exe [786312 2022-10-24] (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.)
S3 HmdfsPhoneSvc; C:\Program Files\Huawei\PCManager\hmdfsservice.exe [786312 2022-10-24] (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.)
R2 HMSCoreService; C:\Program Files\Huawei\HMS Core\HMSCoreService.exe [176712 2022-06-29] (Huawei Technologies Co., Ltd. -> Huawei Technologies Co., Ltd.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [230352 2023-07-18] (HP Inc. -> HP Inc.)
R2 HwPCCoreService; C:\Program Files\Huawei\BasicService\BasicService.exe [629640 2022-10-24] (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.)
R2 HWVEAudioService; C:\WINDOWS\system32\HWVEAudioService.exe [104592 2021-03-27] (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.)
R2 HW_OSDServer; C:\Windows\system32\RPC\OSD\osdservice.exe [252168 2020-12-23] (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.)
R2 IntelArcControlService; C:\Program Files\Intel\Intel Arc Control\ArcControlService.exe [1432104 2023-06-08] (Intel Corporation -> Intel Corporation)
R2 LCD_Service; C:\Program Files\Huawei\HwLcdEnhancement\LCD_Service.exe [44424 2022-10-24] (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.)
R2 MBAMainService; C:\Program Files\Huawei\PCManager\MateBookService.exe [589192 2022-10-24] (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9266864 2023-07-06] (Malwarebytes Inc. -> Malwarebytes)
R2 NahimicService; C:\WINDOWS\system32\NahimicService.exe [1675384 2021-07-02] (A-Volute SAS -> Nahimic)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\23.142.0709.0001\OneDriveUpdaterService.exe [3783544 2023-07-27] (Microsoft Corporation -> Microsoft Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2572096 2023-03-13] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3491144 2023-03-13] (Electronic Arts, Inc. -> Electronic Arts)
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1244144 2023-06-29] (Rockstar Games, Inc. -> Rockstar Games)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182296 2021-06-23] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ucldr_Crowz_ST; C:\Program Files\Common Files\UNCHEATER\ucldr_Crowz_ST.exe [5613296 2022-04-10] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
R2 WUCSProxy; C:\Program Files\HuaWei\wucs\WUCSProxyService.exe [7016008 2022-06-29] (Huawei Technologies Co., Ltd. -> Huawei Technologies Co., Ltd.)
S4 uhssvc; "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe" [X]
S4 WdNisSvc; "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.23050.5-0\NisSrv.exe" [X]
S4 WinDefend; "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MsMpEng.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AcxHdAudio; C:\WINDOWS\System32\drivers\AcxHdAudio.sys [561152 2023-06-28] (Microsoft Windows -> Microsoft Corporation)
R3 ALSysIO; C:\Users\tzahi\AppData\Local\Temp\ALSysIO64.sys [47240 2023-07-27] (ALCPU (Arthur Liberman) -> Arthur Liberman) <==== ATTENTION
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R1 dokan2; C:\Program Files\Huawei\PCManager\dokan2.sys [117176 2021-10-19] (Huawei Device Co., Ltd. -> Dokan Project)
R1 dokan2a; C:\Program Files\Huawei\PCManager\dokan2a.sys [403472 2022-05-03] (Huawei Device Co., Ltd. -> Dokan Project)
R3 DroidCam; C:\WINDOWS\System32\drivers\droidcam.sys [32240 2020-04-11] (Microsoft Windows Hardware Compatibility Publisher -> Dev47Apps)
R3 DroidCamVideo; C:\WINDOWS\System32\DriverStore\FileRepository\droidcamvideo.inf_amd64_47e18363cbf3dfe0\droidcamvideo.sys [33784 2021-04-10] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 iaLPSS2_GPIO2_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_d0e63c4e3754f42f\iaLPSS2_GPIO2_TGL.sys [128152 2020-08-10] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_I2C_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_i2c_tgl.inf_amd64_ab87bf17a571e523\iaLPSS2_I2C_TGL.sys [197272 2020-08-10] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_SPI_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_spi_tgl.inf_amd64_b6ea3d48ee329530\iaLPSS2_SPI_TGL.sys [155816 2020-08-10] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_UART2_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_uart2_tgl.inf_amd64_1a8e964d43720594\iaLPSS2_UART2_TGL.sys [310440 2020-08-10] (Intel Corporation -> Intel Corporation)
R0 IBtRstd; C:\WINDOWS\System32\drivers\ibtrstd.sys [61376 2020-07-15] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-07-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-07-07] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [85592 2020-06-16] (A-Volute -> Windows (R) Win 7 DDK provider)
S3 UniFairy_x64; C:\WINDOWS\system32\drivers\UniFairy_x64.sys [8209904 2022-07-05] (Tencent Technology(Shenzhen) Company Limited -> TENCENT)
S3 unirsdt; C:\WINDOWS\system32\drivers\unirsdt.sys [6166504 2022-09-22] (Tencent Technology(Shenzhen) Company Limited -> TENCENT)
S3 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [239664 2021-07-28] (Oracle Corporation -> Oracle Corporation)
R3 virtbus; C:\WINDOWS\System32\drivers\virtbus.sys [42968 2022-10-23] (Huawei Device Co., Ltd. -> Huawei Device Co., Ltd.)
R3 WDTDrv; C:\WINDOWS\System32\Drivers\WDTDrv.sys [46912 2020-07-15] (Microsoft Windows Hardware Compatibility Publisher -> )
R2 WUCS; C:\WINDOWS\system32\drivers\WUCSDriver.sys [993728 2022-06-29] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Device Co., Ltd.)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [1431256 2022-04-10] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
U4 MsSecFlt; no ImagePath
U4 Sense; no ImagePath
U4 SgrmAgent; no ImagePath
U4 SgrmBroker; no ImagePath
S4 WdBoot; \SystemRoot\system32\drivers\wd\WdBoot.sys [X]
S4 WdFilter; \SystemRoot\system32\drivers\wd\WdFilter.sys [X]
S4 WdNisDrv; system32\drivers\wd\WdNisDrv.sys [X]
S3 WmFilter; \SystemRoot\system32\drivers\WmFilter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-07-21 20:35 - 2023-07-21 20:35 - 000000000 ____D C:\WINDOWS\Minidump
2023-07-21 18:41 - 2023-07-21 18:41 - 000001427 _____ C:\WINDOWS\system32\default_error_stack-000026-000000.txt
2023-07-18 17:00 - 2022-03-22 10:30 - 000000000 ____D C:\Users\tzahi\Downloads\lc500
2023-07-18 16:56 - 2016-11-12 17:06 - 000000000 ____D C:\Users\tzahi\Downloads\lex570
2023-07-18 16:55 - 2023-04-26 17:10 - 000000000 ____D C:\Users\tzahi\Downloads\sc300a
2023-07-18 16:46 - 2022-02-03 16:44 - 000000000 ____D C:\Users\tzahi\Downloads\lx600
2023-07-18 16:46 - 2018-06-07 23:38 - 000000000 ____D C:\Users\tzahi\Downloads\na1
2023-07-18 16:45 - 2016-01-17 02:38 - 000000000 ____D C:\Users\tzahi\Downloads\shonen
2023-07-18 16:23 - 2017-02-18 20:10 - 000000000 ____D C:\Users\tzahi\Downloads\rcf
2023-07-17 18:18 - 2023-07-17 18:18 - 000000000 ____D C:\Program Files\chrome_BITS_5924_1230364416
2023-07-13 21:55 - 2023-07-13 21:55 - 000000000 ____D C:\WINDOWS\SysWOW64\AGEIA
2023-07-13 21:55 - 2023-07-13 21:55 - 000000000 ____D C:\Users\tzahi\Documents\Square Enix
2023-07-13 21:55 - 2023-07-13 21:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2023-07-13 21:55 - 2023-07-13 21:55 - 000000000 ____D C:\Program Files (x86)\AGEIA Technologies
2023-07-13 21:35 - 2023-07-27 17:11 - 000000000 ____D C:\KVRT2020_Data
2023-07-06 14:15 - 2023-07-27 19:15 - 000000000 ____D C:\Users\tzahi\Desktop\PC Help Forum Tings
2023-07-06 13:52 - 2023-07-06 13:52 - 000000000 ____D C:\Users\tzahi\AppData\Local\mbam
2023-07-06 13:51 - 2023-07-07 17:56 - 000000000 ____D C:\Users\tzahi\AppData\Local\Malwarebytes
2023-07-06 13:51 - 2023-07-06 13:51 - 000002040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2023-07-06 13:50 - 2023-07-06 13:50 - 000000000 ____D C:\ProgramData\Malwarebytes
2023-07-06 13:50 - 2023-07-06 13:50 - 000000000 ____D C:\Program Files\Malwarebytes
2023-07-06 13:44 - 2023-07-06 13:44 - 000000000 ____D C:\AdwCleaner
2023-07-06 05:33 - 2023-07-27 19:17 - 000000000 ____D C:\FRST
2023-07-04 10:43 - 2023-07-21 20:35 - 000000000 ___HD C:\Intel
2023-07-04 10:43 - 2023-04-01 09:17 - 000001039 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Telegram.lnk
2023-07-04 10:43 - 2021-09-05 07:39 - 000001109 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photoshop.lnk
2023-07-04 10:43 - 2021-09-05 07:30 - 000001021 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS Pro 16.lnk
2023-07-04 10:43 - 2021-09-05 07:07 - 000002367 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Teams for School.lnk
2023-07-04 10:33 - 2023-07-04 10:49 - 000000000 ___HD C:\$SysReset
2023-07-04 10:33 - 2023-07-03 23:51 - 000000000 ____D C:\$Windows.~BT
2023-07-04 00:10 - 2023-07-04 00:10 - 000000000 ____D C:\Users\tzahi\AppData\Local\GUI
2023-07-03 23:52 - 2023-07-27 16:53 - 000000000 ____D C:\Users\tzahi\AppData\Local\D3DSCache
2023-07-03 23:51 - 2023-07-27 19:13 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-07-03 23:51 - 2023-07-21 20:35 - 002503478 ____N C:\WINDOWS\Minidump\072123-7609-01.dmp
2023-07-03 23:27 - 2023-07-03 23:27 - 000000000 ____D C:\Users\tzahi\AppData\Local\ElevatedDiagnostics
2023-07-03 21:24 - 2023-07-03 21:24 - 000001427 _____ C:\WINDOWS\system32\default_error_stack-000025-000000.txt
2023-07-03 20:58 - 2023-07-27 19:15 - 000000000 ____D C:\Users\tzahi\AppData\Local\Updates
2023-07-03 20:58 - 2023-07-03 21:22 - 000003252 _____ C:\WINDOWS\system32\Tasks\Window Update
2023-07-03 20:58 - 2023-07-03 20:58 - 000014544 _____ (OpenLibSys.org) C:\WINDOWS\system32\WinRing0x64.sys
2023-07-03 20:58 - 2023-07-03 20:58 - 000000000 ____D C:\Program Files (x86)\OceanofGames.ccom
2023-06-29 14:58 - 2023-06-29 14:58 - 000000360 _____ C:\Users\tzahi\Desktop\Grand Theft Auto V.url
2023-06-28 13:44 - 2023-07-03 21:24 - 000000000 ____D C:\Users\tmmrcy
2023-06-28 12:47 - 2023-06-28 12:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2023-06-28 12:44 - 2023-06-20 20:58 - 000515528 _____ (Intel) C:\WINDOWS\system32\libvpl.dll
2023-06-28 12:44 - 2023-06-20 20:58 - 000455664 _____ (Intel) C:\WINDOWS\SysWOW64\libvpl.dll
2023-06-28 12:44 - 2023-06-20 20:57 - 000937504 _____ (Intel Corporation) C:\WINDOWS\system32\libmfxhw64.dll
2023-06-28 12:44 - 2023-06-20 20:56 - 000700360 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\libmfxhw32.dll
2023-06-28 12:44 - 2023-06-20 20:55 - 000586232 _____ (Intel Corporation) C:\WINDOWS\system32\intel_gfx_api-x64.dll
2023-06-28 12:44 - 2023-06-20 20:55 - 000447760 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\intel_gfx_api-x86.dll
2023-06-28 12:44 - 2023-06-20 20:54 - 000488056 _____ C:\WINDOWS\SysWOW64\IntelControlLib32.dll
2023-06-28 12:44 - 2023-06-20 20:51 - 002184128 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2023-06-28 12:44 - 2023-06-20 20:51 - 002184128 _____ C:\WINDOWS\system32\vulkaninfo.exe
2023-06-28 12:44 - 2023-06-20 20:51 - 001618368 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2023-06-28 12:44 - 2023-06-20 20:51 - 001618368 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2023-06-28 12:44 - 2023-06-20 20:51 - 001481672 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2023-06-28 12:44 - 2023-06-20 20:51 - 001481672 _____ C:\WINDOWS\system32\vulkan-1.dll
2023-06-28 12:44 - 2023-06-20 20:51 - 001214400 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2023-06-28 12:44 - 2023-06-20 20:51 - 001214400 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2023-06-28 12:44 - 2023-06-20 20:51 - 000497648 _____ C:\WINDOWS\system32\ze_tracing_layer.dll
2023-06-28 12:44 - 2023-06-20 20:51 - 000437752 _____ C:\WINDOWS\system32\ze_loader.dll
2023-06-28 12:44 - 2023-06-20 20:51 - 000288192 _____ C:\WINDOWS\system32\ze_validation_layer.dll
2023-06-28 12:44 - 2023-06-20 20:50 - 027958720 _____ (Intel Corporation) C:\WINDOWS\system32\mfxplugin64_hw.dll
2023-06-28 12:44 - 2023-06-20 20:50 - 020682736 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\mfxplugin32_hw.dll
2023-06-28 12:44 - 2023-06-20 20:49 - 000274288 _____ C:\WINDOWS\system32\ControlLib.dll
2023-06-28 12:44 - 2023-06-20 20:49 - 000223608 _____ C:\WINDOWS\SysWOW64\ControlLib32.dll
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-07-27 19:16 - 2021-04-14 23:10 - 000000000 ____D C:\ProgramData\Goodix
2023-07-27 19:15 - 2022-05-07 10:17 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2023-07-27 19:13 - 2022-05-07 10:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-07-27 17:12 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-07-27 17:05 - 2022-05-07 10:24 - 000000000 ___HD C:\Program Files\WindowsApps
2023-07-27 17:05 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-07-27 16:36 - 2020-11-19 12:32 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-07-27 16:01 - 2022-05-07 10:22 - 000000000 ____D C:\WINDOWS\INF
2023-07-27 15:58 - 2022-09-22 10:53 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-516455074-3529725477-31475253-1001
2023-07-27 15:58 - 2022-09-22 10:53 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2023-07-27 15:58 - 2022-05-14 14:04 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2023-07-27 15:58 - 2021-09-04 00:17 - 000000000 ___RD C:\Users\tzahi\OneDrive
2023-07-27 15:58 - 2021-09-04 00:14 - 000002139 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-07-27 15:51 - 2021-09-13 23:38 - 000000000 ____D C:\Users\tzahi\AppData\Roaming\PCManager
2023-07-27 15:50 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2023-07-27 15:48 - 2022-09-06 23:45 - 000000000 ____D C:\Users\tzahi\AppData\Roaming\HMSCore
2023-07-21 20:50 - 2022-09-22 10:50 - 000000000 ____D C:\Users\tzahi
2023-07-21 20:49 - 2022-09-22 10:53 - 000003112 _____ C:\WINDOWS\system32\Tasks\NahimicTask32
2023-07-21 20:49 - 2022-09-22 10:53 - 000003092 _____ C:\WINDOWS\system32\Tasks\NahimicTask64
2023-07-21 20:39 - 2022-09-22 10:53 - 000850372 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-07-21 20:35 - 2022-09-22 10:53 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-07-21 20:35 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\ServiceState
2023-07-21 20:35 - 2021-03-09 07:39 - 000012288 ___SH C:\DumpStack.log.tmp
2023-07-21 18:41 - 2022-05-07 10:17 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2023-07-18 17:32 - 2021-10-21 16:44 - 000000000 ____D C:\Users\tzahi\AppData\Local\CrashDumps
2023-07-18 05:11 - 2021-09-05 08:13 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2023-07-18 00:56 - 2022-09-22 10:53 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP
2023-07-17 22:45 - 2022-05-12 10:08 - 000000000 ____D C:\Program Files\Microsoft Office
2023-07-17 18:22 - 2022-05-07 10:17 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-07-13 17:03 - 2021-09-04 06:44 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-07-13 17:01 - 2021-09-04 06:44 - 173351160 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-07-12 21:53 - 2022-09-22 10:53 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-07-12 21:53 - 2022-09-22 10:53 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-07-06 14:03 - 2022-04-27 03:53 - 000000525 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2023-07-06 13:57 - 2021-09-05 07:09 - 000000000 ____D C:\Users\tzahi\AppData\Roaming\uTorrent
2023-07-06 13:51 - 2022-05-07 10:24 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-07-06 13:44 - 2021-09-07 08:19 - 000000000 ____D C:\Users\tzahi\AppData\Local\BitTorrentHelper
2023-07-06 05:55 - 2021-09-05 00:42 - 000000000 ____D C:\Program Files (x86)\Steam
2023-07-06 05:32 - 2023-05-12 12:31 - 000001517 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver & Support Assistant.lnk
2023-07-06 05:32 - 2021-03-09 07:43 - 000000000 ____D C:\ProgramData\Package Cache
2023-07-04 16:29 - 2021-11-25 13:07 - 000000000 ___RD C:\Users\tzahi\Documents\EXCEL Files
2023-07-04 16:15 - 2021-09-04 14:50 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2023-07-04 10:51 - 2023-03-01 23:48 - 000000000 ____D C:\WINDOWS\Panther
2023-07-04 10:50 - 2023-06-13 19:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TLauncher
2023-07-04 10:50 - 2023-02-22 00:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anaconda3 (64-bit)
2023-07-04 10:50 - 2022-09-22 10:51 - 000000000 ____D C:\Users\tzahi\AppData\Roaming\Microsoft\Crypto
2023-07-04 10:50 - 2022-09-22 10:50 - 000000000 ____D C:\Users\tzahi\AppData\Roaming\Microsoft\Windows
2023-07-04 10:50 - 2022-05-12 10:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2023-07-04 10:50 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2023-07-04 10:50 - 2022-03-03 18:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HUAWEI
2023-07-04 10:50 - 2021-09-05 07:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2023-07-04 10:50 - 2020-11-19 12:33 - 000000000 __RHD C:\Users\Public\AccountPictures
2023-07-03 23:51 - 2022-09-22 10:52 - 000015243 _____ C:\WINDOWS\diagwrn.xml
2023-07-03 23:51 - 2022-09-22 10:52 - 000015243 _____ C:\WINDOWS\diagerr.xml
2023-07-03 23:23 - 2022-05-07 10:24 - 000000000 ____D C:\Program Files\Windows Defender
2023-07-03 23:23 - 2022-05-07 10:24 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2023-07-03 23:22 - 2022-09-22 10:49 - 000618256 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-07-03 22:08 - 2021-09-05 07:01 - 000000000 ____D C:\Program Files\TeamViewer
2023-07-03 21:38 - 2022-05-07 10:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-07-03 21:30 - 2021-09-04 00:16 - 000000000 ____D C:\Users\tzahi\AppData\Local\Packages
2023-06-30 16:39 - 2022-10-11 02:20 - 000000000 ____D C:\Users\tzahi\Desktop\Important Documents
2023-06-30 16:39 - 2022-05-12 04:59 - 000000000 ____D C:\Users\tzahi\Documents\Recovery Codes
2023-06-30 16:39 - 2021-09-05 07:41 - 000000000 ____D C:\Users\tzahi\Documents\PDF FIles
2023-06-29 15:33 - 2021-09-04 05:20 - 000000000 ____D C:\Users\tzahi\Documents\Rockstar Games
2023-06-29 15:32 - 2023-02-23 00:46 - 000000000 ____D C:\Users\tzahi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2023-06-29 15:32 - 2021-09-04 05:15 - 000000000 ____D C:\ProgramData\Rockstar Games
2023-06-29 15:32 - 2021-09-04 05:13 - 000000000 ____D C:\Program Files\Rockstar Games
2023-06-29 15:32 - 2021-09-04 05:13 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2023-06-29 11:55 - 2022-11-19 13:05 - 000000000 ____D C:\Users\tzahi\Desktop\English 181-191
2023-06-28 13:43 - 2023-05-12 13:43 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2023-06-28 13:22 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\UUS
2023-06-28 13:22 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\SystemResources
2023-06-28 13:22 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2023-06-28 13:22 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\system32\oobe
2023-06-28 13:22 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\system32\migwiz
2023-06-28 13:22 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\system32\DDFs
2023-06-28 13:22 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\system32\appraiser
2023-06-28 13:22 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\ShellComponents
2023-06-28 13:22 - 2022-05-07 10:24 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-06-28 13:00 - 2022-09-22 10:51 - 003211776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2023-06-28 12:44 - 2021-03-09 07:43 - 000000000 ____D C:\Program Files\Intel
2023-06-28 10:59 - 2021-03-09 07:43 - 000000000 ____D C:\Program Files (x86)\Intel
==================== Files in the root of some directories ========
2021-09-05 07:08 - 2021-09-05 07:08 - 000000128 ____H () C:\Users\tzahi\AppData\Roaming\ecf00c38dc807e105d881c433a6b455dd2c606b6
2021-09-12 12:38 - 2021-12-06 22:52 - 082428480 _____ (Sony) C:\Users\tzahi\AppData\Local\pcc.exe
2021-12-29 23:33 - 2022-01-14 12:15 - 000007597 _____ () C:\Users\tzahi\AppData\Local\Resmon.ResmonCfg
==================== FLock ==============================
2023-06-14 18:31 C:\WINDOWS\system32\smartscreen.exe
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Last edited by a moderator: