CloseProcesses: SystemRestore: On CreateRestorePoint: HKU\S-1-5-21-300123369-1054550141-1832530446-1005\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HPSEU\HpseuHostLauncher.exe (No File) HKU\S-1-5-21-300123369-1054550141-1832530446-1005\...\RunOnce: [OMENCC_InstallationBooster] => C:\system.sav\util\OMENCC_InstallationBooster.exe (No File) Task: {B7A50682-C3CA-441A-9E7C-49EF2B9FD9C2} - \GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem149.0.7814.0{B213C7E4-42AB-4922-9B49-4C122C6ED6D8} -> No File <==== ATTENTION Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File) Task: {36D561AE-1CAC-4802-B0D3-CE66E577335B} - System32\Tasks\OmenInstallMonitor => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe (No File) Task: {11D7A753-E174-4E45-8C09-C717FDD87A64} - System32\Tasks\OmenInstallMonitorCustomEvent => C:\Program Files\HP\OmenInstallMonitor\OmenInstallMonitor.exe (No File) Task: {2597B978-F2A1-461C-B9E0-0656D19880DB} - System32\Tasks\OmenOverlay => C:\Program Files\HP\Overlay\OverlayHelper.exe (No File) Task: {553931B1-B605-4650-B03E-8C527EE0FC13} - System32\Tasks\OmenOverlayCustomEvent => C:\Program Files\HP\Overlay\OverlayHelper.exe (No File) S2 efwd; "C:\Program Files\ESET\ESET Security\efwd.exe" (No File) S2 ekrn; "C:\Program Files\ESET\ESET Security\ekrn.exe" (No File) S3 ekrnEpfw; "C:\Program Files\ESET\ESET Security\ekrn.exe" (No File) S2 GoogleUpdaterInternalService149.0.7814.0; "C:\Program Files (x86)\Google\GoogleUpdater\149.0.7814.0\updater.exe" --system --windows-service --service=update-internal (No File) S2 GoogleUpdaterService149.0.7814.0; "C:\Program Files (x86)\Google\GoogleUpdater\149.0.7814.0\updater.exe" --system --windows-service --service=update (No File) R1 eamonm; C:\windows\System32\DRIVERS\eamonm.sys [220520 2024-10-28] (ESET, spol. s r.o. -> ESET) S0 eelam; C:\windows\System32\DRIVERS\eelam.sys [16336 2024-10-23] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET) S1 ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [268568 2024-10-28] (ESET, spol. s r.o. -> ESET) R1 epfw; C:\windows\system32\DRIVERS\epfw.sys [87784 2024-10-28] (ESET, spol. s r.o. -> ESET) R1 epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [128552 2024-10-28] (ESET, spol. s r.o. -> ESET) S4 hardlock; C:\windows\system32\drivers\hardlock.sys [331608 2015-04-14] (SafeNet, Inc. -> SafeNet Inc.) ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File FirewallRules: [{06CF1882-A27B-497F-B753-B7188FA8F87C}] => (Allow) C:\Program Files\Google\Play Games\current\emulator\crosvm.exe => No File FirewallRules: [{FD61C7D8-C282-40FA-BE66-7E32F825C26B}] => (Allow) C:\Program Files\Google\Play Games\current\emulator\crosvm.exe => No File FirewallRules: [{8883ADE3-64EB-458D-B7EF-1E00853D0A57}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [{759ED9AD-2A8A-41C7-9BED-7CD592C98D0D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File FirewallRules: [{C8EADA3F-EA33-4B03-9463-9D79CA1AAA8A}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe => No File FirewallRules: [{69E0CC2F-5869-46A3-8D1E-F25FFB076FD6}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe => No File AV: McAfee (Disabled - Up to date) {0BE13B34-492A-21C0-AE43-C1742279CCB6} StartPowerShell: md C:\Downloaded Invoke-webrequest https://download.microsoft.com/download/3/7/5/3754cbaa-4dff-469a-a9f0-ca501f3c0421/hvciscan_amd64.exe -OutFile C:\Downloaded\hvciscan_amd64.exe EndPowerShell: StartBatch: md C:\DrvStore PnpUtil /export-driver * C:\DrvStore rundll32.exe c:\windows\system32\pnpclean.dll,RunDLL_PnpClean /DRIVERS /MAXCLEAN rundll32.exe c:\windows\system32\pnpclean.dll,RunDLL_PnpClean /DEVICES /MAXCLEAN DISM /online /get-drivers /format:table C:\Downloaded\hvciscan_amd64.exe del /a C:\Downloaded\hvciscan_amd64.exe rd C:\Downloaded c:\windows\system32\wbem\wmic.exe sysdriver get Name, PathName, Caption, State, StartMode fltmc reg query "HKLM\SYSTEM\CurrentControlSet\Control\Class" /f *erfilters* /s EndBatch: