Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-09-2023
Ran by User (administrator) on HP (HP HP EliteBook 830 G5) (18-09-2023 18:02:03)
Running from C:\Users\User\Downloads\FRST64.exe
Loaded Profiles: User
Platform: Microsoft Windows 11 Pro Version 22H2 22621.2283 (X64) Language: English (United Kingdom)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\BridgeCommunication.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <15>
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_2a3519c52621d0fe\HotKeyServiceUWP.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_2a3519c52621d0fe\LanWlanWwanSwitchingServiceUWP.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-21-281276394-282352661-3837250378-1001\...\Run: [MicrosoftEdgeAutoLaunch_C46CFC0629905CC775E70B50EA8A519C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4219448 2023-09-15] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-281276394-282352661-3837250378-1001\...\Run: [GlassWire] => C:\Program Files (x86)\GlassWire\glasswire.exe [11788168 2023-09-12] (GlassWire -> SecureMix LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {F5A1E4F8-EB25-4A8F-98C3-0B260B55E1A1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [703536 2023-08-25] (HP Inc. -> HP Inc.)
Task: {FA0C4456-DDAD-4B64-B26D-F7E742EAA530} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [138328 2023-08-25] (HP Inc. -> HP Inc.)
Task: {71456468-3137-47A3-A931-ADC5594CA9A1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1145904 2023-08-25] (HP Inc. -> HP Inc.)
Task: {E453CAE4-C8A4-43CE-8B3F-16EDB76CAE2F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1145904 2023-08-25] (HP Inc. -> HP Inc.)
Task: {75C3C2C1-17A5-4C88-B5E2-E6027DBA58BA} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\UCPD velocity => C:\Windows\system32\UCPDMgr.exe [58880 2023-09-16] (Microsoft Windows -> Microsoft Corporation)
Task: {C7527511-AC45-40CE-B83E-E2669C7BE5EF} - System32\Tasks\Microsoft\Windows\Conexant\MicTray => C:\Windows\System32\MicTray64.exe [2938448 2020-07-02] (Conexant Systems LLC -> Conexant)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {9C0E05F0-F5CF-4726-9974-302365B74FDA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-09-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {640EBE39-2321-4BF4-A6CD-6BDF7443EE95} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-09-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CAB9C22B-1D80-4996-8319-5C08544A933C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-09-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {72FBEB3E-11FD-4B36-BB56-213AA72C604F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe [1596304 2023-09-16] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {47EDFDE5-EEE5-4DA8-BAA6-4F63D0278819} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [815 2022-08-18] () [File not signed]
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.255.10
Tcpip\..\Interfaces\{208a38a5-a28e-438c-a567-51a50df2e0b0}: [DhcpNameServer] 192.168.255.10
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default [2023-09-18]
Edge Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-09-16]
Edge Extension: (Edge relevant text changes) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-16]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 ApHidMonitorService; C:\Windows\system32\Alps\GlidePoint\HidMonitorSvc.exe [573520 2020-08-23] (ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.)
S2 CxAudioSvc; C:\Windows\CxSvc\CxAudioSvc.exe [81408 2021-08-25] (Conexant Systems LLC.) [File not signed]
S2 CxUtilSvc; C:\Windows\CxSvc\CxUtilSvc.exe [173880 2021-08-25] (Synaptics Incorporated -> Conexant Systems LLC.)
S2 GlassWire; C:\Program Files (x86)\GlassWire\GWCtlSrv.exe [8217992 2023-09-12] (GlassWire -> SecureMix LLC)
R2 HotKeyServiceUWP; C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_2a3519c52621d0fe\HotKeyServiceUWP.exe [1536456 2023-04-26] (HP Inc. -> HP Inc.)
R2 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [888768 2023-08-25] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [887184 2023-08-25] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [883088 2023-08-25] (HP Inc. -> HP Inc.)
R2 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [887696 2023-08-25] (HP Inc. -> HP Inc.)
R2 LanWlanWwanSwitchingServiceUWP; C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_2a3519c52621d0fe\LanWlanWwanSwitchingServiceUWP.exe [606664 2023-04-26] (HP Inc. -> HP Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402352 2023-09-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe [3121008 2023-09-16] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe [133688 2023-09-16] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 WindscribeService; C:\Program Files\Windscribe\WindscribeService.exe [1085280 2023-09-17] (Windscribe Limited -> Windscribe Limited)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ApPTPFilterService; C:\Windows\System32\drivers\ApPtpFiltr.sys [350424 2020-08-23] (ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.)
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [106496 2022-05-07] (Microsoft Corporation) [File not signed]
R1 gwdrv; C:\Windows\system32\DRIVERS\gwdrv.sys [33152 2023-09-12] (GlassWire -> SecureMix LLC)
R3 MpKsl7b2abe6b; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{583D85D1-DFC0-49F3-A408-8C501142A7AA}\MpKslDrv.sys [222464 2023-09-18] (Microsoft Windows -> Microsoft Corporation)
R1 npcap; C:\Windows\system32\DRIVERS\npcap.sys [77336 2022-08-19] (Insecure.Com LLC -> Insecure.Com LLC.)
R3 tapwindscribe0901; C:\Windows\System32\drivers\tapwindscribe0901.sys [57768 2023-09-17] (Windscribe Limited -> The OpenVPN Project)
S4 UCPD; C:\Windows\System32\drivers\UCPD.sys [29184 2023-09-16] (Microsoft Windows -> Microsoft Corporation)
S3 USBPcap; C:\Windows\system32\DRIVERS\USBPcap.sys [52872 2020-05-22] (Tomasz Moń -> USBPcap)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [55872 2023-09-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [574872 2023-09-16] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105864 2023-09-16] (Microsoft Windows -> Microsoft Corporation)
S3 WindscribeSplitTunnel; C:\Windows\system32\DRIVERS\WindscribeSplitTunnel.sys [38152 2023-09-17] (Windscribe Limited -> )
R3 windtun420; C:\Windows\System32\drivers\windtun420.sys [47544 2023-09-17] (Windscribe Limited -> WireGuard LLC)
S3 WireGuard; C:\Windows\System32\drivers\wireguard.sys [489368 2023-09-17] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
R3 WirelessButtonDriver64; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [40104 2022-06-17] (HP Inc. -> HP)
U4 npcap_wifi; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Three months (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-09-18 18:02 - 2023-09-18 18:02 - 000011859 _____ C:\Users\User\Downloads\FRST.txt
2023-09-18 18:01 - 2023-09-18 18:02 - 000000000 ____D C:\FRST
2023-09-18 18:01 - 2023-09-18 18:01 - 002382848 _____ (Farbar) C:\Users\User\Downloads\FRST64 (1).exe
2023-09-18 18:00 - 2023-09-18 18:01 - 002382848 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2023-09-18 17:57 - 2023-09-18 17:58 - 000000000 ____D C:\AdwCleaner
2023-09-18 17:56 - 2023-09-18 17:57 - 008791352 _____ (Malwarebytes) C:\Users\User\Downloads\adwcleaner.exe
2023-09-18 17:56 - 2023-09-18 17:56 - 000003460 _____ C:\Windows\system32\Tasks\npcapwatchdog
2023-09-18 17:56 - 2023-09-18 17:56 - 000001827 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark.lnk
2023-09-18 17:56 - 2023-09-18 17:56 - 000000000 ____D C:\Windows\SysWOW64\Npcap
2023-09-18 17:56 - 2023-09-18 17:56 - 000000000 ____D C:\Windows\system32\Npcap
2023-09-18 17:56 - 2023-09-18 17:56 - 000000000 ____D C:\Program Files\USBPcap
2023-09-18 17:55 - 2023-09-18 17:56 - 000000000 ____D C:\Program Files\Wireshark
2023-09-18 17:55 - 2023-09-18 17:56 - 000000000 ____D C:\Program Files\Npcap
2023-09-18 17:50 - 2023-09-18 17:54 - 079164216 _____ (Wireshark development team) C:\Users\User\Downloads\Wireshark-win64-4.0.8.exe
2023-09-17 15:48 - 2023-09-17 23:48 - 000000000 ____D C:\Users\User\AppData\Local\CrashDumps
2023-09-17 08:10 - 2023-09-17 08:10 - 000000000 ____D C:\Users\User\AppData\Local\PeerDistRepub
2023-09-17 07:30 - 2023-09-17 07:30 - 000007611 _____ C:\Users\User\AppData\Local\Resmon.ResmonCfg
2023-09-17 07:02 - 2023-09-17 14:18 - 000000000 ____D C:\Program Files\Windscribe
2023-09-17 07:02 - 2023-09-17 07:02 - 000057768 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\tapwindscribe0901.sys
2023-09-17 07:02 - 2023-09-17 07:02 - 000047544 _____ (WireGuard LLC) C:\Windows\system32\Drivers\windtun420.sys
2023-09-17 07:02 - 2023-09-17 07:02 - 000038152 _____ C:\Windows\system32\Drivers\WindscribeSplitTunnel.sys
2023-09-17 07:02 - 2023-09-17 07:02 - 000001058 _____ C:\Users\Public\Desktop\Windscribe.lnk
2023-09-17 07:02 - 2023-09-17 07:02 - 000000000 ____D C:\Users\User\AppData\Local\Windscribe
2023-09-17 07:02 - 2023-09-17 07:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windscribe
2023-09-16 18:21 - 2023-09-16 18:22 - 000000000 ____D C:\Program Files (x86)\REALTEK
2023-09-16 18:20 - 2019-11-01 02:33 - 000004096 _____ (Hewlett-Packard Company) C:\Windows\SysWOW64\SigFile.exe
2023-09-16 18:17 - 2023-09-16 18:20 - 000000000 ____D C:\Program Files\Intel
2023-09-16 18:17 - 2023-09-16 18:18 - 000000000 ____D C:\ProgramData\Intel Package Cache {1CEAC85D-2590-4760-800F-8DE5E91F3700}
2023-09-16 18:17 - 2023-09-16 18:17 - 000000000 ____D C:\Windows\system32\Tasks\HP
2023-09-16 18:17 - 2023-09-16 18:17 - 000000000 ____D C:\Program Files (x86)\Intel
2023-09-16 17:53 - 2023-09-16 17:53 - 000000000 ____D C:\hp
2023-09-16 17:43 - 2023-09-16 17:48 - 000000000 ____D C:\Users\User\Downloads\HP Downloads
2023-09-16 17:41 - 2023-09-16 19:22 - 000000000 ____D C:\Program Files\HP
2023-09-16 17:41 - 2023-09-16 18:23 - 000000000 ____D C:\SWSetup
2023-09-16 17:41 - 2023-09-16 17:53 - 000000000 ____D C:\ProgramData\HP
2023-09-16 17:41 - 2023-09-16 17:41 - 000000000 ____D C:\Users\User\AppData\Roaming\HP
2023-09-16 17:41 - 2023-09-16 17:41 - 000000000 ____D C:\system.sav
2023-09-16 17:41 - 2023-09-16 17:41 - 000000000 ____D C:\Program Files (x86)\HP
2023-09-16 17:34 - 2023-09-18 17:58 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2023-09-16 17:33 - 2023-09-17 14:19 - 000000000 ____D C:\Windows\system32\Tasks\Hewlett-Packard
2023-09-16 17:32 - 2023-09-16 17:41 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
2023-09-16 17:32 - 2023-09-16 17:32 - 006434896 _____ (Oleg N. Scherbakov) C:\Users\User\Downloads\HPSupportSolutionsFramework-12.19.53.13.exe
2023-09-16 17:31 - 2023-09-16 17:40 - 179214832 _____ (HP Inc.) C:\Users\User\Downloads\sp148716.exe
2023-09-16 14:19 - 2023-09-16 14:19 - 000000000 ____D C:\Users\User\AppData\Local\PlaceholderTileLogoFolder
2023-09-16 14:02 - 2023-09-16 14:03 - 020803424 _____ (Windscribe Limited) C:\Users\User\Downloads\Windscribe_2.6.14.exe
2023-09-16 11:17 - 2023-09-16 11:17 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\MMC
2023-09-16 11:15 - 2023-09-16 11:16 - 000000000 ____D C:\Users\User\AppData\Local\glasswire
2023-09-16 11:15 - 2023-09-16 11:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GlassWire
2023-09-16 11:15 - 2023-09-16 11:15 - 000000000 ____D C:\ProgramData\glasswire
2023-09-16 11:15 - 2023-09-16 11:15 - 000000000 ____D C:\Program Files (x86)\GlassWire
2023-09-16 11:15 - 2023-09-12 12:04 - 000033152 _____ (SecureMix LLC) C:\Windows\system32\Drivers\gwdrv.sys
2023-09-16 11:15 - 2023-09-12 12:04 - 000008392 _____ C:\Windows\system32\Drivers\gwdrv.cat
2023-09-16 11:14 - 2023-09-18 17:55 - 000000000 ____D C:\ProgramData\Package Cache
2023-09-16 11:05 - 2023-09-16 11:09 - 083300104 _____ (SecureMix LLC) C:\Users\User\Downloads\GlassWireSetup.exe
2023-09-16 10:17 - 2022-06-22 15:30 - 011829616 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtwlane.sys
2023-09-16 09:53 - 2023-09-16 09:55 - 000000000 ___HD C:\$WinREAgent
2023-09-16 09:52 - 2023-09-16 17:33 - 000000000 ____D C:\Users\User\AppData\Local\HP
2023-09-16 09:52 - 2020-08-25 23:40 - 048039808 _____ (Intel Corporation) C:\Windows\system32\IntelSSTPreprocStreamer.dll
2023-09-16 09:52 - 2020-08-25 23:40 - 001678920 _____ (Intel Corporation) C:\Windows\system32\MultiChannelWoV.dll
2023-09-16 09:52 - 2020-08-25 23:40 - 000870272 _____ (Intel Corporation) C:\Windows\system32\IntelWovSDK.dll
2023-09-16 09:52 - 2020-08-25 23:40 - 000499568 _____ (Intel Corporation) C:\Windows\system32\MultichannelWoVCfg.dll
2023-09-16 09:51 - 2023-09-16 09:51 - 000000000 ____D C:\Windows\CxSvc
2023-09-16 09:51 - 2023-09-16 09:51 - 000000000 ____D C:\Users\User\AppData\Local\Conexant
2023-09-16 09:51 - 2023-09-16 09:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
2023-09-16 09:51 - 2021-08-25 20:13 - 000177976 _____ (Synaptics Incorporated) C:\Windows\system32\SynaMonApp.exe
2023-09-16 09:51 - 2021-08-25 20:13 - 000002988 _____ C:\Windows\system32\SynaMonApp.xml
2023-09-16 09:49 - 2023-09-16 09:49 - 000000000 ____D C:\Windows\system32\cAVS
2023-09-16 09:49 - 2020-08-25 23:40 - 000844384 _____ (Intel(R) Corporation) C:\Windows\system32\Drivers\IntcOED.sys
2023-09-16 09:46 - 2023-09-16 09:46 - 000000000 ____D C:\Windows\UCI
2023-09-16 09:46 - 2023-09-16 09:46 - 000000000 ____D C:\ProgramData\Conexant
2023-09-16 09:46 - 2020-07-02 23:43 - 002938448 _____ (Conexant) C:\Windows\system32\MicTray64.exe
2023-09-16 09:46 - 2020-07-02 23:43 - 000002988 _____ C:\Windows\system32\MicTray64.xml
2023-09-16 09:46 - 2019-07-19 18:05 - 000008668 _____ C:\Windows\system32\cxapo.prop
2023-09-16 09:45 - 2023-09-16 09:51 - 001705080 _____ (TODO: <Company name>) C:\Windows\SysWOW64\RebootPrompt.exe
2023-09-16 09:45 - 2023-09-16 09:51 - 000000000 ____D C:\Program Files\CONEXANT
2023-09-16 09:45 - 2023-09-16 09:45 - 000000000 ____D C:\ProgramData\UIU
2023-09-16 09:45 - 2023-09-16 09:45 - 000000000 ____D C:\ProgramData\SoundResearch
2023-09-16 09:45 - 2021-12-21 23:18 - 007438976 _____ (Conexant Systems, Inc.) C:\Windows\system32\UCI64A231.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 002521920 _____ (Conexant Systems Inc.) C:\Windows\system32\Drivers\CHDRT64ISST.sys
2023-09-16 09:45 - 2021-12-21 23:18 - 001554592 _____ (Synaptics Incorporated) C:\Windows\system32\CX64APOMIX.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 001542728 _____ (Synaptics Inc.) C:\Windows\system32\CX64Proxy.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 001518448 _____ (Synaptics Incorporated.) C:\Windows\system32\CX64APO.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 001421056 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDHF64.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 001420840 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN64.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 001318416 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO64.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 001213912 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA64.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 001079640 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SEHDHF32.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 001062528 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SECOMN32.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 000969248 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SEAPO32.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 000914928 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SEHDRA32.dll
2023-09-16 09:45 - 2021-12-21 23:18 - 000716344 _____ (Conexant Systems, Inc.) C:\Windows\system32\CX64APO2.dll
2023-09-16 09:45 - 2016-09-20 13:51 - 000004664 _____ C:\Windows\system32\Drivers\CxSfPt.dat
2023-09-16 09:32 - 2020-08-25 23:40 - 000270200 _____ (Intel(R) Corporation) C:\Windows\system32\Drivers\IntcAudioBus.sys
2023-09-16 09:21 - 2023-09-16 09:21 - 000000000 ____D C:\Users\User\AppData\Local\OneDrive
2023-09-16 09:20 - 2023-09-16 09:20 - 000000000 ____D C:\Users\User\AppData\Local\VirtualStore
2023-09-16 09:11 - 2021-01-20 23:58 - 019816336 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPRes.dll
2023-09-16 09:11 - 2021-01-20 23:58 - 004287888 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPEnh.exe
2023-09-16 09:11 - 2021-01-20 23:58 - 000762256 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys
2023-09-16 09:11 - 2021-01-20 23:58 - 000342416 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPEnhService.exe
2023-09-16 09:11 - 2021-01-20 23:58 - 000275344 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll
2023-09-16 09:11 - 2021-01-20 23:57 - 000810384 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll
2023-09-16 09:08 - 2023-09-17 18:33 - 000000000 __SHD C:\Users\User\IntelGraphicsProfiles
2023-09-16 09:08 - 2023-09-17 18:33 - 000000000 ____D C:\Intel
2023-09-16 09:08 - 2023-09-16 18:18 - 000000000 ____D C:\ProgramData\Intel
2023-09-16 09:08 - 2023-09-16 09:08 - 000000000 ____D C:\Windows\Firmware
2023-09-16 09:08 - 2023-09-16 09:08 - 000000000 ____D C:\Users\User\AppData\LocalLow\Intel
2023-09-16 09:08 - 2023-09-16 09:08 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2023-09-16 09:08 - 2023-09-16 09:08 - 000000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2023-09-16 09:07 - 2023-04-26 04:44 - 001452272 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2023-09-16 09:07 - 2023-04-26 04:44 - 001452272 _____ C:\Windows\system32\vulkan-1.dll
2023-09-16 09:07 - 2023-04-26 04:44 - 001165552 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2023-09-16 09:07 - 2023-04-26 04:44 - 001165552 _____ C:\Windows\SysWOW64\vulkan-1.dll
2023-09-16 09:04 - 2023-09-16 09:49 - 000000000 ____D C:\Windows\system32\Intel
2023-09-16 09:04 - 2019-05-09 19:49 - 000185232 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaLPSS2_I2C.sys
2023-09-16 09:04 - 2019-05-09 19:49 - 000095632 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaLPSS2_GPIO2.sys
2023-09-16 09:04 - 2018-12-14 13:47 - 000403440 _____ (Intel Corporation) C:\Windows\system32\Drivers\esif_lf.sys
2023-09-16 09:04 - 2018-12-14 13:47 - 000075248 _____ (Intel Corporation) C:\Windows\system32\Drivers\dptf_cpu.sys
2023-09-16 08:46 - 2023-09-16 08:46 - 000000000 ____D C:\ProgramData\Realtek
2023-09-16 08:43 - 2019-10-24 21:42 - 005291976 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RsDMFT64.dll
2023-09-16 08:42 - 2018-12-14 13:47 - 000078832 _____ (Intel Corporation) C:\Windows\system32\Drivers\dptf_acpi.sys
2023-09-16 08:38 - 2023-09-18 08:33 - 000000000 ____D C:\Windows\Panther
2023-09-16 08:34 - 2023-09-16 08:34 - 000000000 ____D C:\Windows\system32\Alps
2023-09-16 08:34 - 2020-08-23 22:45 - 000350424 _____ (ALPSALPINE CO., LTD.) C:\Windows\system32\Drivers\ApPtpFiltr.sys
2023-09-16 08:28 - 2023-09-16 08:29 - 000000000 ____D C:\Windows\system32\MRT
2023-09-16 08:27 - 2023-09-16 08:27 - 000000000 ____D C:\Users\User\AppData\Local\Comms
2023-09-16 08:16 - 2023-09-16 09:17 - 000000000 ____D C:\Users\User\AppData\Local\Publishers
2023-09-16 08:01 - 2023-09-16 08:12 - 000003584 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-281276394-282352661-3837250378-1001
2023-09-16 08:01 - 2023-09-16 08:12 - 000003348 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-281276394-282352661-3837250378-1001
2023-09-16 08:01 - 2023-09-16 08:12 - 000002376 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-09-16 08:01 - 2023-09-16 08:01 - 000000000 ___RD C:\Users\User\OneDrive
2023-09-16 08:01 - 2023-09-16 08:01 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2023-09-16 08:00 - 2023-09-16 08:00 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Vault
2023-09-16 07:59 - 2023-09-16 19:22 - 000000000 ____D C:\Users\User\AppData\Local\Packages
2023-09-16 07:59 - 2023-09-16 14:01 - 000000000 ___SD C:\Users\User\AppData\Roaming\Microsoft\Protect
2023-09-16 07:59 - 2023-09-16 08:08 - 000000000 ____D C:\Users\User\AppData\Local\D3DSCache
2023-09-16 07:59 - 2023-09-16 07:59 - 000000020 ___SH C:\Users\User\ntuser.ini
2023-09-16 07:59 - 2023-09-16 07:59 - 000000000 __RHD C:\Users\Public\AccountPictures
2023-09-16 07:59 - 2023-09-16 07:59 - 000000000 ___SD C:\Users\User\AppData\Roaming\Microsoft\SystemCertificates
2023-09-16 07:59 - 2023-09-16 07:59 - 000000000 ___SD C:\Users\User\AppData\Roaming\Microsoft\Crypto
2023-09-16 07:59 - 2023-09-16 07:59 - 000000000 ___SD C:\Users\User\AppData\Roaming\Microsoft\Credentials
2023-09-16 07:59 - 2023-09-16 07:59 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Network
2023-09-16 07:59 - 2023-09-16 07:59 - 000000000 ____D C:\Users\User\AppData\Roaming\Adobe
2023-09-16 07:59 - 2023-09-16 07:59 - 000000000 ____D C:\Users\User\AppData\Local\ConnectedDevicesPlatform
2023-09-16 07:58 - 2023-09-16 14:01 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Spelling
2023-09-16 07:58 - 2023-09-16 07:59 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows
2023-09-16 07:50 - 2023-09-17 18:41 - 000804932 _____ C:\Windows\system32\PerfStringBackup.INI
2023-09-16 07:44 - 2023-09-16 07:44 - 000000000 ____D C:\Windows\CSC
2023-09-16 07:42 - 2023-09-16 19:24 - 000000000 ____D C:\ProgramData\Packages
2023-09-16 07:42 - 2023-09-16 11:04 - 000001575 _____ C:\Windows\system32\config\VSMIDK
2023-09-16 07:42 - 2023-09-16 07:42 - 000000000 _SHDL C:\Documents and Settings
2023-09-16 07:39 - 2023-09-16 08:50 - 000003536 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-09-16 07:39 - 2023-09-16 08:50 - 000003412 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-09-16 07:39 - 2023-09-16 08:15 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-09-16 07:39 - 2023-09-16 08:15 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2023-09-16 07:39 - 2023-09-16 07:39 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2023-09-16 07:38 - 2023-09-18 17:31 - 000000000 ____D C:\Windows\system32\SleepStudy
2023-09-16 07:38 - 2023-09-17 18:33 - 000326832 _____ C:\Windows\system32\FNTCACHE.DAT
2023-09-16 07:38 - 2023-09-17 18:33 - 000012288 ___SH C:\DumpStack.log.tmp
2023-09-16 07:38 - 2023-09-17 18:33 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2023-09-16 07:38 - 2023-09-16 10:20 - 000000000 ____D C:\Windows\system32\Drivers\wd
2023-09-16 07:38 - 2023-09-16 07:38 - 000000000 ____D C:\Windows\system32\config\BFS
2023-09-16 07:38 - 2023-09-16 07:38 - 000000000 ____D C:\Windows\ServiceProfiles
==================== Three months (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2023-09-18 17:56 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SystemTemp
2023-09-18 17:56 - 2022-05-07 06:22 - 000000000 ____D C:\Windows\INF
2023-09-18 08:33 - 2022-05-07 06:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-09-17 18:34 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\LiveKernelReports
2023-09-17 18:33 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\ServiceState
2023-09-17 18:27 - 2022-05-07 06:17 - 000524288 _____ C:\Windows\system32\config\BBI
2023-09-17 08:25 - 2022-05-07 06:24 - 000000000 ____D C:\ProgramData\USOPrivate
2023-09-17 08:10 - 2022-05-07 06:17 - 000000000 ____D C:\Windows\CbsTemp
2023-09-16 19:27 - 2022-05-07 06:24 - 000000000 ___HD C:\Program Files\WindowsApps
2023-09-16 19:27 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\AppReadiness
2023-09-16 10:20 - 2022-05-07 06:24 - 000000000 ____D C:\Program Files\Windows Defender
2023-09-16 10:14 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\AppLocker
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\WUModels
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\UUS
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\vi-VN
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\setup
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\id-ID
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\gl-ES
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\eu-ES
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\es-MX
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\Dism
2023-09-16 10:11 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SysWOW64\ca-ES
2023-09-16 10:10 - 2022-05-07 11:16 - 000000000 ___SD C:\Windows\system32\AppV
2023-09-16 10:10 - 2022-05-07 11:16 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ___RD C:\Windows\PrintDialog
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SystemResources
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\SystemApps
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\WinMetadata
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\vi-VN
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\Sgrm
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\setup
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\oobe
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\migwiz
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\lv-LV
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\lt-LT
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\id-ID
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\HealthAttestationClient
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\gl-ES
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\eu-ES
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\et-EE
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\es-MX
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\Dism
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\DDFs
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\ca-ES
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\appraiser
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\ShellExperiences
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\ShellComponents
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\Provisioning
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\PolicyDefinitions
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\bcastdvr
2023-09-16 10:10 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\appcompat
2023-09-16 10:10 - 2022-05-07 06:17 - 000000000 ____D C:\Windows\servicing
2023-09-16 09:51 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2023-09-16 09:50 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\Drivers\DriverData
2023-09-16 08:37 - 2022-05-07 06:24 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2023-09-16 08:26 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\SecurityHealth
2023-09-16 07:44 - 2022-05-07 06:24 - 000000000 ____D C:\Windows\system32\spool
2023-09-16 07:39 - 2022-05-07 06:17 - 000032768 _____ C:\Windows\system32\config\ELAM
==================== Files in the root of some directories ========
2023-09-17 07:30 - 2023-09-17 07:30 - 000007611 _____ () C:\Users\User\AppData\Local\Resmon.ResmonCfg
==================== SigCheckExt =========================
2022-12-08 10:02 - 2022-12-08 10:02 - 000012704 _____ (Intel(R) Corporation) C:\Windows\SysWOW64\IusEventLog.dll
2023-09-16 18:20 - 2019-11-01 02:33 - 000004096 _____ (Hewlett-Packard Company) C:\Windows\SysWOW64\SigFile.exe
2023-09-18 18:01 - 2023-09-18 18:01 - 002382848 _____ (Farbar) C:\Users\User\Downloads\FRST64 (1).exe
2023-09-18 18:00 - 2023-09-18 18:01 - 002382848 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== BCD ================================
Firmware Boot Manager
---------------------
identifier {fwbootmgr}
displayorder {bootmgr}
{9480dd72-5463-11ee-a89f-dfb01e53c0e7}
{9480dd64-5463-11ee-a89f-dfb01e53c0e7}
{9480dd65-5463-11ee-a89f-dfb01e53c0e7}
{9480dd66-5463-11ee-a89f-dfb01e53c0e7}
{9480dd67-5463-11ee-a89f-dfb01e53c0e7}
{9480dd68-5463-11ee-a89f-dfb01e53c0e7}
{9480dd69-5463-11ee-a89f-dfb01e53c0e7}
{9480dd6a-5463-11ee-a89f-dfb01e53c0e7}
{9480dd6b-5463-11ee-a89f-dfb01e53c0e7}
{9480dd6c-5463-11ee-a89f-dfb01e53c0e7}
{9480dd6d-5463-11ee-a89f-dfb01e53c0e7}
{9480dd6e-5463-11ee-a89f-dfb01e53c0e7}
timeout 0
Windows Boot Manager
--------------------
identifier {bootmgr}
device partition=\Device\HarddiskVolume1
path \EFI\Microsoft\Boot\bootmgfw.efi
description Windows Boot Manager
locale en-GB
inherit {globalsettings}
default {current}
resumeobject {9480dd73-5463-11ee-a89f-dfb01e53c0e7}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 30
Firmware Application (101fffff)
-------------------------------
identifier {9480dd64-5463-11ee-a89f-dfb01e53c0e7}
description Startup Menu
Firmware Application (101fffff)
-------------------------------
identifier {9480dd65-5463-11ee-a89f-dfb01e53c0e7}
description System Information
Firmware Application (101fffff)
-------------------------------
identifier {9480dd66-5463-11ee-a89f-dfb01e53c0e7}
description Bios Setup
Firmware Application (101fffff)
-------------------------------
identifier {9480dd67-5463-11ee-a89f-dfb01e53c0e7}
description 3rd Party Option ROM Management
Firmware Application (101fffff)
-------------------------------
identifier {9480dd68-5463-11ee-a89f-dfb01e53c0e7}
description System Diagnostics
Firmware Application (101fffff)
-------------------------------
identifier {9480dd69-5463-11ee-a89f-dfb01e53c0e7}
description System Diagnostics
Firmware Application (101fffff)
-------------------------------
identifier {9480dd6a-5463-11ee-a89f-dfb01e53c0e7}
description System Diagnostics
Firmware Application (101fffff)
-------------------------------
identifier {9480dd6b-5463-11ee-a89f-dfb01e53c0e7}
description System Diagnostics
Firmware Application (101fffff)
-------------------------------
identifier {9480dd6c-5463-11ee-a89f-dfb01e53c0e7}
description Boot Menu
Firmware Application (101fffff)
-------------------------------
identifier {9480dd6d-5463-11ee-a89f-dfb01e53c0e7}
description HP Recovery
Firmware Application (101fffff)
-------------------------------
identifier {9480dd6e-5463-11ee-a89f-dfb01e53c0e7}
description Network Boot
Firmware Application (101fffff)
-------------------------------
identifier {9480dd6f-5463-11ee-a89f-dfb01e53c0e7}
description IPV6 Network
Firmware Application (101fffff)
-------------------------------
identifier {9480dd70-5463-11ee-a89f-dfb01e53c0e7}
description IPV6 Network - Intel(R) Ethernet Connection (4) I219-LM
Firmware Application (101fffff)
-------------------------------
identifier {9480dd72-5463-11ee-a89f-dfb01e53c0e7}
description USB:
Windows Boot Loader
-------------------
identifier {current}
device partition=C:
path \Windows\system32\winload.efi
description Windows 11
locale en-GB
inherit {bootloadersettings}
recoverysequence {9480dd75-5463-11ee-a89f-dfb01e53c0e7}
displaymessageoverride Recovery
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \Windows
resumeobject {9480dd73-5463-11ee-a89f-dfb01e53c0e7}
nx OptIn
bootmenupolicy Standard
Windows Boot Loader
-------------------
identifier {9480dd75-5463-11ee-a89f-dfb01e53c0e7}
device ramdisk=[\Device\HarddiskVolume4]\Recovery\WindowsRE\Winre.wim,{9480dd76-5463-11ee-a89f-dfb01e53c0e7}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-gb
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[\Device\HarddiskVolume4]\Recovery\WindowsRE\Winre.wim,{9480dd76-5463-11ee-a89f-dfb01e53c0e7}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Resume from Hibernate
---------------------
identifier {9480dd73-5463-11ee-a89f-dfb01e53c0e7}
device partition=C:
path \Windows\system32\winresume.efi
description Windows Resume Application
locale en-GB
inherit {resumeloadersettings}
recoverysequence {9480dd75-5463-11ee-a89f-dfb01e53c0e7}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
custom:21000026 partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Windows Memory Tester
---------------------
identifier {memdiag}
device partition=\Device\HarddiskVolume1
path \EFI\Microsoft\Boot\memtest.efi
description Windows Memory Diagnostic
locale en-GB
inherit {globalsettings}
badmemoryaccess Yes
EMS Settings
------------
identifier {emssettings}
bootems No
Debugger Settings
-----------------
identifier {dbgsettings}
debugtype Local
RAM Defects
-----------
identifier {badmemory}
Global Settings
---------------
identifier {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}
Boot Loader Settings
--------------------
identifier {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}
Hypervisor Settings
-------------------
identifier {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Resume Loader Settings
----------------------
identifier {resumeloadersettings}
inherit {globalsettings}
Device options
--------------
identifier {9480dd76-5463-11ee-a89f-dfb01e53c0e7}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume4
ramdisksdipath \Recovery\WindowsRE\boot.sdi
==================== End of FRST.txt ========================