Good afternoon all,
I have been having some issues with windows 11 freezing and a lot of issues have just run the FRST64.exe and need some help reading/ understanding the txt file.
I will add, yes this system is not windows 11 compatible but it was working fine until recently .
I also do not know how to add the log files to this thread, or if its even possible.
I might add them as a reply to this comment one for each file
First being FRST.txt
Second reply will be Additional.txt
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-06-2025
Ran by Maria (administrator) on MSI (Micro-Star International Co., Ltd. GT72VR 7RE) (14-06-2025 13:23:46)
Running from C:\Users\user\Desktop\FRST64.exe
Loaded Profiles: Maria
Platform: Microsoft Windows 11 Home Version 24H2 26100.4202 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.CentralServer.exe
(C:\Program Files\WindowsApps\Microsoft.WindowsTerminal_1.22.11141.0_x64__8wekyb3d8bbwe\WindowsTerminal.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsTerminal_1.22.11141.0_x64__8wekyb3d8bbwe\OpenConsole.exe
(C:\Program Files\WindowsApps\Microsoft.WindowsTerminal_1.22.11141.0_x64__8wekyb3d8bbwe\WindowsTerminal.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
(C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_525.10401.30.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\137.0.3296.68\msedgewebview2.exe <19>
(Dism.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Dism\DismHost.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <21>
(explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsTerminal_1.22.11141.0_x64__8wekyb3d8bbwe\WindowsTerminal.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.OutlookForWindows_1.2025.604.100_x64__8wekyb3d8bbwe\olk.exe
(explorer.exe ->) (Now.gg, INC -> now.gg, Inc.) C:\Users\user\AppData\Local\Programs\bluestacks-services\BlueStacksServices.exe <4>
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_8a3f88e34f6b8385\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_4c8d93c71af1b9d3\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_0ce29d36fc8607e6\WMIRegistrationService.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(services.exe ->) (MEDIATEK INC. -> ) C:\Program Files (x86)\MediatekSwitchUSB\MediatekSwitchUSB.exe
(services.exe ->) (Microsoft Windows -> ) C:\Windows\System32\OpenSSH\ssh-agent.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25040.2-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25040.2-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25040.2-0\NisSrv.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe
(services.exe ->) (Micro-Star International Co., Ltd.) [File not signed] C:\Windows\SysWOW64\MSIService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmii.inf_amd64_8e2b7f872a9cdacc\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Qualcomm Atheros, Inc. -> ) C:\Windows\System32\drivers\QcomWlanSrvx64.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.4193_none_a54a744177310c9b\TiWorker.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.TerminalServer.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Windows\SysWOW64\muachost.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPHelper.exe
(SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe
(WindowsPowerShell\v1.0\powershell.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Dism.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Nahimic2UILauncher] => C:\Program Files\Nahimic\Nahimic2\UserInterface\Nahimic2UILauncher.exe [693432 2016-10-15] (A-Volute -> )
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [301848 2016-10-07] (Micro-Star International CO., LTD. -> ) [File not signed]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9217016 2017-04-12] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [321096 2017-11-09] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-2367702636-586777576-2407885215-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45715776 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-2367702636-586777576-2407885215-1002\...\Run: [MicrosoftEdgeAutoLaunch_8714F0D917266FE3AFB7F8BB98EEBC18] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4141136 2025-06-06] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2367702636-586777576-2407885215-1002\...\Run: [electron.app.BlueStacks Services] => C:\Users\user\AppData\Local\Programs\bluestacks-services\BlueStacksServices.exe [162219656 2024-05-08] (Now.gg, INC -> now.gg, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\137.0.7151.104\Installer\chrmstp.exe [2025-06-13] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1E664BC6-2406-4B3A-811C-27C5590E0E3C} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [302960 2025-05-18] (Now.gg, INC -> BlueStack Systems, Inc.)
Task: {44A40A67-EE7A-40A6-A034-7221C3BEE656} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {836CB427-E81B-4A51-88A6-8468BB860E66} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6139704 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "83209a43-8a19-4099-8cdc-98406a768cc8" --version "6.36.0.11508" --silent
Task: {2980FDFA-1561-4E8D-B7BF-8F6E8706A8C2} - System32\Tasks\CCleanerSkipUAC - Maria => C:\Program Files\CCleaner\CCleaner.exe [39558464 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {3D2A4B61-82D2-49E1-A000-2F1500F2CC15} - System32\Tasks\CCleanerSkipUAC - user => C:\Program Files\CCleaner\CCleaner.exe [39558464 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {4F3C892A-2238-44BC-9072-BE444742EE18} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [2943472 2025-06-01] (Microsoft Windows -> Microsoft Corporation)
Task: {6354CDE6-B7E7-48BE-8A11-36350F04732F} - System32\Tasks\DualSafe Password Manager Init SkipUAC(Maria) => "D:\Program Files (x86)\DualSafe Password Manager\DPMInit.exe" -> D:\Program Files (x86)\DualSafe Password Manager\\/skipuac
Task: {1790BA08-0C96-4798-A10B-8004E25164C7} - System32\Tasks\DualSafe Password Manager Task => "D:\Program Files (x86)\DualSafe Password Manager\DPMInit.exe" -> D:\Program Files (x86)\DualSafe Password Manager\\/startpc
Task: {37A86F4A-952D-4322-A49D-BEE7796A02A6} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{A0C4C783-F2F9-4DE3-AFBD-DDD12EE88690} => C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe [7080032 2025-05-22] (Google LLC -> Google LLC)
Task: {84FB5B87-2E3C-477F-8A03-011671088BCB} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\opushutil.exe /pushregistration (No File)
Task: {85050F75-C908-4368-B7CD-DA76FF20B1F9} - System32\Tasks\Microsoft\Windows\Clip\ClipESU => %SystemRoot%\system32\clipesu.exe (No File)
Task: {9E085A9D-3188-4785-B7DF-E1E973E58BE4} - System32\Tasks\Microsoft\Windows\Hotpatch\Monitoring => C:\WINDOWS\system32\cmd.exe [376832 2025-06-01] (Microsoft Windows -> Microsoft Corporation) -> /d /c %systemroot%\system32\hpatchmonTask.cmd
Task: {E88D9B2C-DDEA-47B2-9582-085153004DB5} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
Task: {3329755D-763E-447D-8D8F-93D4289FD17F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe (No File)
Task: {F05ACCE4-8AA4-4D62-869C-615442DEFDE9} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
Task: {48EC3D40-00B6-4094-9F44-E416E477C819} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
Task: {D2F144B0-1B84-41C0-ACC8-FC15C24FE0E9} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe Display (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {C4F22E21-0342-4153-8A95-675C1785A7F6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25040.2-0\MpCmdRun.exe [1753416 2025-05-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F8699D2E-1EB3-4756-A392-6B2D61F21810} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25040.2-0\MpCmdRun.exe [1753416 2025-05-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {86DA8085-EE50-43F0-BD60-FAC8BFA1CB31} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25040.2-0\MpCmdRun.exe [1753416 2025-05-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {28B445BE-1065-40A4-BA97-542CCF973E70} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25040.2-0\MpCmdRun.exe [1753416 2025-05-31] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6A355AA2-0279-42EA-894B-552667693F4C} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [1692840 2015-08-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
Task: {89AFBD72-C4E7-474E-9B28-AFE971E66889} - System32\Tasks\Nahimic2Svc32Run => C:\Program Files\Nahimic\Nahimic2\UserInterface\Nahimic2Svc32.exe [2024632 2016-10-15] (A-Volute -> )
Task: {BFFB23D5-3780-4DC2-9223-C52BA0D4ACEB} - System32\Tasks\Nahimic2Svc64Run => C:\Program Files\Nahimic\Nahimic2\UserInterface\x64\Nahimic2Svc64.exe [495288 2016-10-15] (A-Volute -> )
Task: {B7743F25-0AEB-40B6-B7C2-E429F9491F0E} - System32\Tasks\Nahimic2UILauncherRun => C:\Program Files\Nahimic\Nahimic2\UserInterface\Nahimic2UILauncher.exe [693432 2016-10-15] (A-Volute -> )
Task: {A65BF612-3109-4D0F-8AC3-FD24790B1E96} - System32\Tasks\Nvbackend_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (No File)
Task: {3F780669-1A6A-4D56-9EA6-DAD0E0AE5777} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3322400 2025-06-02] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9C8E4C6E-72B6-41D3-86BE-34B027E34302} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2367702636-586777576-2407885215-1004 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File) <==== ATTENTION
Task: {9D8E849D-D86D-46DD-B64C-26898AB6B6AE} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2367702636-586777576-2407885215-1004 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (No File) <==== ATTENTION
Task: {053256B5-7013-499F-B1CB-CBCA2F7F3727} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2367702636-586777576-2407885215-1004 => C:\Users\Maria 2\AppData\Local\Microsoft\OneDrive\25.085.0504.0002\OneDriveLauncher.exe /startInstances (No File)
Task: {BEAF9BAB-2471-4DAF-8893-33432BDF0DF5} - System32\Tasks\RNIdle Task => C:\Windows\System32\drivers\RivetNetworks\Killer\RNIdleTask.exe [33224 2025-02-18] (Intel Corporation -> Intel)
Task: {C3C78633-7C1E-4F05-89D1-60F405421489} - System32\Tasks\S-1-5-21-2367702636-586777576-2407885215-1002\DataSenseLiveTileTask => %SystemRoot%\System32\DataUsageLiveTileTask.exe (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\RNIdle Task.job => C:\Windows\System32\drivers\RivetNetworks\Killer\RNIdleTask.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 02 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog5 03 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog9 17 %windir%\system32\vsocklib.dll => No File
Winsock: Catalog9 18 %windir%\system32\vsocklib.dll => No File
Winsock: Catalog5-x64 02 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog5-x64 03 %SystemRoot%\system32\pnrpnsp.dll => No File
Winsock: Catalog9-x64 17 %windir%\system32\vsocklib.dll => No File
Winsock: Catalog9-x64 18 %windir%\system32\vsocklib.dll => No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{07930dfb-22b4-448d-a6f4-06c023153ed6}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{07930dfb-22b4-448d-a6f4-06c023153ed6}: [DhcpDomain] fritz.box
Tcpip\..\Interfaces\{9648ad34-cb12-4ac9-b818-f72d1c83274d}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Profile 2
Edge Profile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default [2025-05-23]
Edge Extension: (DualSafe Password Manager & Digital Vault) - C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bobgdmjpamhpbiobbklajbdkgmmmbcja [2024-08-06]
Edge Extension: (Google Docs Offline) - C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-30]
Edge Extension: (Edge relevant text changes) - C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-03-06]
Edge Profile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Profile 2 [2025-06-14]
Edge Notifications: Profile 2 -> hxxps://www.msn.com
Edge HomePage: Profile 2 -> hxxps://google.com.au/
Edge StartupUrls: Profile 2 -> "hxxps://google.com.au/"
Edge Extension: (Google Docs Offline) - C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-08]
Edge Extension: (Edge relevant text changes) - C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Profile 2\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-03-06]
Edge HKLM\...\Edge\Extension: [bobgdmjpamhpbiobbklajbdkgmmmbcja]
Edge HKU\S-1-5-21-2367702636-586777576-2407885215-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [bobgdmjpamhpbiobbklajbdkgmmmbcja]
Edge HKLM-x32\...\Edge\Extension: [bobgdmjpamhpbiobbklajbdkgmmmbcja]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default [2025-06-14]
CHR Notifications: Default -> hxxps://www.facebook.com
CHR HomePage: Default -> hxxps://google.com.au/
CHR StartupUrls: Default -> "hxxps://google.com.au/"
CHR Extension: (AdGuard AdBlocker) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2025-06-13]
CHR Extension: (Google Docs Offline) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-05-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-03-10]
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-03-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-01-10]
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\System Profile [2024-03-10]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM\...\Chrome\Extension: [lgbjhdkjmpgjgcbcdlhkokkckpjmedgc]
CHR HKU\S-1-5-21-2367702636-586777576-2407885215-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lgbjhdkjmpgjgcbcdlhkokkckpjmedgc]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [lgbjhdkjmpgjgcbcdlhkokkckpjmedgc]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1079608 2025-05-21] (Gen Digital Inc. -> Gen Digital Inc.)
S3 hpatchmon; C:\WINDOWS\system32\hpatchmon.dll [173472 2025-06-01] (Microsoft Windows -> Microsoft Corporation)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [230360 2024-01-06] (HP Inc. -> HP Inc.)
S3 KAPSService; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KAPSService.exe [78272 2025-02-18] (Intel Corporation -> Intel® Corporation)
S3 Killer Analytics Service; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerAnalyticsService.exe [2456008 2025-02-18] (Intel Corporation -> Intel)
S3 Killer Network Service; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerNetworkService.exe [2622920 2025-02-18] (Intel Corporation -> Intel)
S3 Killer Provider Data Helper Service; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerProviderDataHelperService.exe [1211848 2025-02-18] (Intel Corporation -> Intel)
S3 KillerSmartphoneSleepService; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KSPSService.exe [77744 2025-02-18] (Intel Corporation -> Rivet Networks, LLC.)
S3 KNDBWM; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KNDBWMService.exe [78280 2025-02-18] (Intel Corporation -> Intel® Corporation)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25040.2-0\MpDefenderCoreService.exe [2050904 2025-05-31] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 MediatekSwitchUSB; C:\Program Files (x86)\MediatekSwitchUSB\MediatekSwitchUSB.exe [1219704 2023-11-28] (MEDIATEK INC. -> )
R2 Micro Star SCM; C:\Windows\SysWoW64\MSIService.exe [160768 2009-07-09] (Micro-Star International Co., Ltd.) [File not signed]
S3 MSI_ActiveX_Service; C:\Program Files (x86)\MSI\Dragon Center\MSI_ActiveX_Service.exe [58296 2016-08-12] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
R2 MSI_Center_Service; C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe [181776 2025-04-17] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_8e2b7f872a9cdacc\Display.NvContainer\NVDisplay.Container.exe [1275544 2025-05-16] (NVIDIA Corporation -> NVIDIA Corporation)
R2 QcomWlanSrv; C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe [189800 2023-03-19] (Qualcomm Atheros, Inc. -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25040.2-0\NisSrv.exe [4525976 2025-05-31] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25040.2-0\MsMpEng.exe [278304 2025-05-31] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Browser; %SystemRoot%\System32\browser.dll [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BlueStacksDrv_nxt; C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [394312 2025-05-18] (Microsoft Windows Hardware Compatibility Publisher -> Bluestack System Inc.)
S3 KfeCoSvc; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KfeCo11X64.sys [213448 2025-02-18] (Intel Corporation -> Rivet Networks, LLC.)
R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [331168 2025-04-10] (Microsoft Windows -> Microsoft Corporation)
R3 mtkwl6eux; C:\WINDOWS\System32\drivers\mtkwl6eux.sys [1409560 2023-12-13] (Microsoft Windows Hardware Compatibility Publisher -> MediaTek Inc.)
S3 PlutonHeci; C:\WINDOWS\System32\DriverStore\FileRepository\pluton-heci.inf_amd64_f74945e2fcb1d3d7\pluton-heci.sys [75168 2025-06-01] (Microsoft Windows -> Microsoft Corporation)
S3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-18] (Bruce James -> Scarlet.Crush Productions)
S3 ssbthid; C:\WINDOWS\System32\drivers\ssbthid.sys [43888 2017-05-12] (SteelSeries ApS -> SteelSeries ApS)
R3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [46776 2019-05-16] (SteelSeries ApS -> )
R3 ssps2; C:\WINDOWS\System32\drivers\ssps2.sys [41104 2019-08-27] (SteelSeries ApS -> )
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64912 2017-05-18] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated)
S3 ThermalFilter; C:\WINDOWS\System32\DriverStore\FileRepository\c_thermal.inf_amd64_732a53ed1662b707\ThermalFilter.sys [75376 2025-05-31] (Microsoft Windows Hardware Abstraction Layer Publisher -> Microsoft Corporation)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] (Empty Loop -> )
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2015-06-17] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [19984 2025-05-31] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [606568 2025-05-31] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100736 2025-05-31] (Microsoft Windows -> Microsoft Corporation)
R0 WinSetupMon; C:\WINDOWS\System32\DRIVERS\WinSetupMon.sys [169400 2024-09-06] (Microsoft Windows -> Microsoft Corporation)
S3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2024-09-06] (Microsoft Windows -> Microsoft Corporation)
S3 WSDScan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_971c769b103df369\WSDScan.sys [61440 2024-09-06] (Microsoft Windows -> Microsoft Corporation)
U3 aswArDisk; no ImagePath
U3 aswBcc; no ImagePath
U3 Avast Business Console Client Antivirus Service; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-06-14 13:23 - 2025-06-14 13:24 - 000026695 _____ C:\Users\user\Desktop\FRST.txt
2025-06-14 13:18 - 2025-06-14 13:24 - 000000000 ____D C:\FRST
2025-06-14 13:17 - 2025-06-14 13:17 - 002406912 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2025-06-14 13:09 - 2025-06-14 13:10 - 002728228 _____ C:\Users\user\Downloads\chipset_10.1.1.38_public.zip
2025-06-14 13:08 - 2025-06-14 13:08 - 000002306 _____ C:\Users\Public\Desktop\Intel® Rapid Storage Technology.lnk
2025-06-14 13:08 - 2025-06-14 13:08 - 000000092 _____ C:\Users\user\Desktop\MSI Global - The Leading Brand in High-end Gaming & Professional Creation - MSI Global - The Leading Brand in High-end Gaming.url
2025-06-14 13:08 - 2025-06-14 13:08 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2025-06-14 13:08 - 2025-06-14 13:08 - 000000000 ____D C:\Users\user\Downloads\ASMUSBHost_V116381WHQL
2025-06-14 13:00 - 2025-06-14 13:00 - 000000000 ____D C:\Users\user\Downloads\imsm_SetupRST_15.9.0.1015_0x17be985a
2025-06-14 12:59 - 2025-06-14 12:59 - 018265249 _____ C:\Users\user\Downloads\imsm_SetupRST_15.9.0.1015_0x17be985a.zip
2025-06-14 12:58 - 2025-06-14 12:58 - 009887217 _____ C:\Users\user\Downloads\ASMUSBHost_V116381WHQL.zip
2025-06-14 12:54 - 2025-06-14 12:54 - 011833040 _____ (Intel Corporation) C:\Users\user\Downloads\SetupRST (1).exe
2025-06-14 12:53 - 2025-06-14 12:53 - 015118552 _____ (Intel Corporation) C:\Users\user\Downloads\SetupRST.exe
2025-06-14 12:19 - 2025-06-14 12:19 - 004362260 _____ C:\Users\user\Downloads\SAVPP-007899_T1693435.pdf
2025-06-10 20:05 - 2025-06-10 20:05 - 001386096 _____ C:\Users\user\Downloads\NDIS Pricing Arrangements and Price Limits 2024-25 v1.3.pdf
2025-06-06 09:59 - 2025-06-06 10:00 - 000053075 _____ C:\Users\user\Downloads\Invoice (3).pdf
2025-06-05 10:28 - 2025-06-05 10:28 - 000052902 _____ C:\Users\user\Downloads\Invoice (2).pdf
2025-06-02 22:19 - 2025-06-02 22:19 - 000052912 _____ C:\Users\user\Downloads\Invoice (1).pdf
2025-06-02 11:56 - 2025-06-02 11:56 - 000053075 _____ C:\Users\user\Downloads\Invoice.pdf
2025-06-02 09:07 - 2025-06-02 09:08 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2025-06-02 08:51 - 2025-06-02 08:51 - 549949900 _____ C:\Users\user\Downloads\MSI-Center.zip
2025-06-02 08:51 - 2025-06-02 08:51 - 000000000 ____D C:\Users\user\Downloads\MSI-Center
2025-06-01 16:04 - 2025-06-01 16:04 - 000000000 ____D C:\Users\user\AppData\Roaming\NVIDIA
2025-06-01 15:35 - 2025-06-14 12:04 - 000003326 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2025-06-01 15:26 - 2025-06-01 15:26 - 000000000 ___HD C:\$SysReset
2025-06-01 15:22 - 2025-06-14 13:15 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-06-01 14:40 - 2025-06-02 09:11 - 000003088 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2367702636-586777576-2407885215-1004
2025-06-01 14:39 - 2025-06-02 09:11 - 000003062 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2367702636-586777576-2407885215-1004
2025-06-01 14:39 - 2025-06-02 09:11 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2367702636-586777576-2407885215-1004
2025-06-01 14:29 - 2025-06-01 14:30 - 000000000 ____D C:\Program Files\Unlocker
2025-06-01 14:29 - 2025-06-01 14:29 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2025-06-01 13:53 - 2025-06-01 13:53 - 000388465 _____ C:\WINDOWS\Tweaking.com - Windows Repair Setup Log.txt
2025-06-01 13:42 - 2025-06-01 13:42 - 000000000 ____D C:\Users\user\AppData\Local\ASP.NET
2025-06-01 13:41 - 2025-06-11 10:45 - 000000000 ____D C:\Program Files\dotnet
2025-06-01 13:41 - 2025-06-11 10:45 - 000000000 ____D C:\Program Files (x86)\dotnet
2025-06-01 13:06 - 2025-06-01 13:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD Apps
2025-06-01 12:35 - 2025-06-01 12:35 - 000000000 ____D C:\Users\user\Downloads\Autoruns
2025-06-01 12:30 - 2025-06-01 12:30 - 000000000 ____D C:\Users\user\Downloads\Portable
2025-06-01 12:17 - 2025-06-01 12:17 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2025-06-01 12:13 - 2025-05-16 10:47 - 002072448 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2025-06-01 12:13 - 2025-05-16 10:47 - 002072448 _____ C:\WINDOWS\system32\vulkaninfo.exe
2025-06-01 12:13 - 2025-05-16 10:47 - 001614208 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2025-06-01 12:13 - 2025-05-16 10:47 - 001614208 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2025-06-01 12:13 - 2025-05-16 10:47 - 001576832 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2025-06-01 12:13 - 2025-05-16 10:47 - 001576832 _____ C:\WINDOWS\system32\vulkan-1.dll
2025-06-01 12:13 - 2025-05-16 10:47 - 001389952 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2025-06-01 12:13 - 2025-05-16 10:47 - 001389952 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2025-06-01 12:13 - 2025-05-16 10:47 - 000477832 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2025-06-01 12:13 - 2025-05-16 10:47 - 000374936 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2025-06-01 12:12 - 2025-05-16 10:43 - 001259632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2025-06-01 12:12 - 2025-05-16 10:43 - 000674408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll
2025-06-01 12:12 - 2025-05-16 10:43 - 000509056 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll
2025-06-01 12:12 - 2025-05-16 10:42 - 026002056 _____ C:\WINDOWS\system32\nvidia-pcc.exe
2025-06-01 12:12 - 2025-05-16 10:42 - 002313352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2025-06-01 12:12 - 2025-05-16 10:42 - 001713824 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2025-06-01 12:12 - 2025-05-16 10:42 - 001569416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2025-06-01 12:12 - 2025-05-16 10:42 - 001220232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2025-06-01 12:12 - 2025-05-16 10:42 - 001053848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2025-06-01 12:12 - 2025-05-16 10:42 - 000942208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2025-06-01 12:12 - 2025-05-16 10:42 - 000809576 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2025-06-01 12:12 - 2025-05-16 10:42 - 000467056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2025-06-01 12:12 - 2025-05-16 10:41 - 023034480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2025-06-01 12:12 - 2025-05-16 10:41 - 020517528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2025-06-01 12:12 - 2025-05-16 10:41 - 007322760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2025-06-01 12:12 - 2025-05-16 10:41 - 005913736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2025-06-01 12:12 - 2025-05-16 10:41 - 005240480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll
2025-06-01 12:12 - 2025-05-16 10:41 - 003994264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2025-06-01 12:12 - 2025-05-16 10:41 - 000853664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2025-06-01 12:12 - 2025-05-16 10:32 - 005601560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2025-06-01 12:12 - 2025-05-16 10:32 - 004901616 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2025-06-01 12:12 - 2025-05-15 10:45 - 000143016 _____ C:\WINDOWS\system32\nvinfo.pb
2025-06-01 12:12 - 2025-05-15 10:45 - 000125048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2025-06-01 12:10 - 2025-06-01 12:10 - 000000000 ____D C:\NVIDIA
2025-06-01 11:13 - 2025-06-01 11:13 - 000001555 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json
2025-06-01 11:12 - 2025-06-01 11:12 - 000033224 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-06-01 11:12 - 2025-06-01 11:12 - 000033224 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-06-01 10:55 - 2025-06-01 13:08 - 000000000 ____D C:\Program Files (x86)\Belarc
2025-06-01 10:46 - 2011-01-12 13:36 - 001054208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc71u.dll
2025-06-01 10:46 - 2011-01-12 13:19 - 001060864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc71.dll
2025-06-01 10:46 - 2011-01-12 12:53 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atl71.dll
2025-06-01 10:46 - 2007-02-01 22:13 - 000503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp71.dll
2025-06-01 02:05 - 2025-06-01 02:05 - 000000000 ____D C:\WINDOWS\system32\AccountHealthAssets
2025-06-01 02:05 - 2025-06-01 02:05 - 000000000 ____D C:\inetpub
2025-05-31 18:02 - 2025-05-31 18:02 - 000070484 _____ C:\WINDOWS\SysWOW64\ctac.json
2025-05-31 18:02 - 2025-05-31 18:02 - 000070484 _____ C:\WINDOWS\system32\ctac.json
2025-05-31 17:08 - 2025-06-03 11:03 - 000001575 _____ C:\WINDOWS\system32\config\VSMIDK
2025-05-31 16:19 - 2016-11-01 06:46 - 000149888 _____ (ASMedia Technology Inc) C:\WINDOWS\system32\Drivers\asmthub3.sys
2025-05-31 16:16 - 2016-09-02 02:20 - 000453504 _____ (ASMedia Technology Inc) C:\WINDOWS\system32\Drivers\asmtxhci.sys
2025-05-31 15:58 - 2025-05-31 15:58 - 000242724 _____ C:\WINDOWS\ntbtlog.txt
2025-05-31 14:25 - 2025-06-01 08:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2025-05-31 14:25 - 2025-05-31 14:25 - 000000000 ____D C:\Users\user\AppData\Local\VS Revo Group
2025-05-29 09:32 - 2025-05-29 09:32 - 000000000 ____D C:\Users\user\Documents\temp
2025-05-28 12:40 - 2025-05-28 12:40 - 000000000 ____D C:\ProgramData\bst_boost_interprocess
2025-05-28 12:39 - 2025-06-13 16:52 - 000000000 ____D C:\ProgramData\BlueStacks_nxt
2025-05-28 12:39 - 2025-06-01 08:35 - 000000000 ____D C:\Program Files\BlueStacks_nxt
2025-05-28 12:39 - 2025-05-28 12:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Store
2025-05-28 10:44 - 2025-05-28 10:44 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2025-05-28 10:40 - 2025-06-07 11:53 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2025-05-28 10:40 - 2025-06-04 23:04 - 000003834 _____ C:\WINDOWS\system32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2025-05-28 10:40 - 2025-06-03 11:03 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-05-28 10:40 - 2025-06-02 09:11 - 000002972 _____ C:\WINDOWS\system32\Tasks\DualSafe Password Manager Init SkipUAC(Maria)
2025-05-28 10:40 - 2025-06-02 09:11 - 000002930 _____ C:\WINDOWS\system32\Tasks\DualSafe Password Manager Task
2025-05-28 10:40 - 2025-06-02 09:11 - 000002566 _____ C:\WINDOWS\system32\Tasks\Nvbackend_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2025-05-28 10:40 - 2025-06-01 12:38 - 000002396 _____ C:\WINDOWS\system32\Tasks\Nahimic2UILauncherRun
2025-05-28 10:40 - 2025-06-01 12:38 - 000002384 _____ C:\WINDOWS\system32\Tasks\Nahimic2Svc64Run
2025-05-28 10:40 - 2025-06-01 12:38 - 000002376 _____ C:\WINDOWS\system32\Tasks\Nahimic2Svc32Run
2025-05-28 10:40 - 2025-06-01 12:38 - 000002148 _____ C:\WINDOWS\system32\Tasks\MSISW_Host
2025-05-28 10:40 - 2025-05-29 12:23 - 000002956 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper_nxt
2025-05-28 10:40 - 2025-05-28 10:40 - 000003464 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-05-28 10:40 - 2025-05-28 10:40 - 000003238 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-05-28 10:40 - 2025-05-28 10:40 - 000002588 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2025-05-28 10:40 - 2025-05-28 10:40 - 000002252 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Maria
2025-05-28 10:40 - 2025-05-28 10:40 - 000002250 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - user
2025-05-28 10:40 - 2025-05-28 10:40 - 000002070 _____ C:\WINDOWS\system32\Tasks\RNIdle Task
2025-05-28 10:40 - 2025-05-28 10:40 - 000000020 ___SH C:\Users\user\ntuser.ini
2025-05-28 10:40 - 2025-05-28 10:40 - 000000000 ____D C:\WINDOWS\system32\Tasks\S-1-5-21-2367702636-586777576-2407885215-1002
2025-05-28 10:40 - 2025-05-28 10:40 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation
2025-05-28 10:40 - 2025-05-28 10:40 - 000000000 ____D C:\WINDOWS\system32\Tasks\Intel
2025-05-28 10:40 - 2025-05-28 10:40 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleSystem
2025-05-28 10:39 - 2025-06-03 11:07 - 000789742 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-05-28 10:39 - 2025-05-28 10:39 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network
2025-05-28 10:36 - 2025-06-03 11:03 - 000005548 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-05-28 10:35 - 2025-05-28 10:35 - 000000326 _____ C:\WINDOWS\Tasks\RNIdle Task.job
2025-05-28 10:35 - 2025-05-28 10:35 - 000000000 ____D C:\WINDOWS\system32\config\BFS
2025-05-28 10:34 - 2025-06-03 11:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-05-28 10:34 - 2025-06-01 15:56 - 000296880 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-05-28 10:28 - 2025-05-28 10:34 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Crypto
2025-05-28 10:28 - 2025-05-28 10:28 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates
2025-05-28 10:28 - 2025-05-28 10:28 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Network
2025-05-28 10:25 - 2025-05-28 10:43 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows
2025-05-28 10:25 - 2025-05-28 10:40 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Spelling
2025-05-28 10:25 - 2025-05-28 10:34 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2025-05-28 10:24 - 2025-05-28 10:25 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2025-05-28 10:24 - 2025-05-28 10:24 - 000000000 ____D C:\WINDOWS\Firmware
2025-05-28 10:23 - 2025-05-28 10:23 - 000000000 ____D C:\Program Files\Reference Assemblies
2025-05-28 10:23 - 2025-05-28 10:23 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2025-05-28 10:16 - 2025-05-28 10:16 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2025-05-28 10:07 - 2025-06-09 11:27 - 000000000 ___DC C:\WINDOWS\Panther
2025-05-28 09:38 - 2025-05-28 09:38 - 000162025 _____ C:\Users\user\Desktop\Budget Overview.pdf
2025-05-25 12:22 - 2025-05-25 12:22 - 000001347 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2025-05-25 12:22 - 2025-05-25 12:22 - 000000000 ____D C:\Users\user\AppData\Local\PCHealthCheck
2025-05-24 16:59 - 2025-05-24 17:00 - 000000000 ____D C:\Program Files (x86)\mtkwl6eux
2025-05-24 16:59 - 2025-05-24 16:59 - 000000000 ____D C:\Program Files (x86)\NETGEAR_A7500
2025-05-24 16:59 - 2025-05-24 16:59 - 000000000 ____D C:\Program Files (x86)\MTKOEMX
2025-05-24 16:59 - 2025-05-24 16:59 - 000000000 ____D C:\Program Files (x86)\MediatekSwitchUSB
2025-05-23 12:55 - 2025-06-07 18:48 - 000002592 _____ C:\Users\user\Desktop\Homescapes.lnk
2025-05-23 12:55 - 2025-06-07 18:47 - 000002716 _____ C:\Users\user\Desktop\Gardenscapes.lnk
2025-05-23 12:06 - 2025-05-23 12:06 - 000000000 ___HD C:\$AV_ASW
2025-05-23 10:46 - 2025-05-31 16:14 - 000000000 ____D C:\Users\user\AppData\Roaming\Avast Software
2025-05-16 23:07 - 2025-05-16 23:07 - 000002054 _____ C:\Users\user\Desktop\Lilys Garden (1).lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-06-14 13:12 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-06-14 13:08 - 2024-04-01 16:54 - 000000000 ____D C:\WINDOWS\INF
2025-06-14 13:08 - 2016-11-29 02:16 - 000000000 ____D C:\Program Files\Intel
2025-06-14 13:02 - 2016-11-29 02:16 - 000000000 ____D C:\Program Files (x86)\Intel
2025-06-14 12:54 - 2024-04-01 16:56 - 000000000 ___HD C:\Program Files\WindowsApps
2025-06-14 12:54 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-06-14 12:52 - 2024-04-01 16:56 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-06-14 12:27 - 2020-05-21 15:32 - 000000000 ____D C:\Users\user\AppData\Local\CrashDumps
2025-06-14 12:04 - 2024-03-10 10:19 - 000000670 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2025-06-14 11:59 - 2019-08-01 07:17 - 000000000 ____D C:\Users\user\AppData\Local\D3DSCache
2025-06-14 11:52 - 2025-04-12 20:18 - 000000000 ____D C:\Users\user\AppData\Roaming\bluestacks-services
2025-06-14 02:00 - 2019-07-26 12:51 - 000000000 ____D C:\ProgramData\NVIDIA
2025-06-13 11:59 - 2020-05-21 00:23 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-06-12 20:21 - 2025-04-12 20:27 - 000002038 _____ C:\Users\user\Desktop\Heart of Vegas.lnk
2025-06-11 16:00 - 2025-04-12 20:27 - 000002054 _____ C:\Users\user\Desktop\Lightning Link.lnk
2025-06-11 10:45 - 2016-11-29 02:13 - 000000000 ____D C:\ProgramData\Package Cache
2025-06-11 10:44 - 2019-07-31 19:00 - 000000000 ____D C:\WINDOWS\system32\MRT
2025-06-11 10:43 - 2019-07-31 19:00 - 216824056 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2025-06-08 10:59 - 2020-10-27 15:16 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-06-08 10:59 - 2020-10-27 15:16 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-06-07 18:40 - 2021-10-02 15:25 - 000000000 ____D C:\Program Files\CCleaner
2025-06-06 19:17 - 2025-04-12 20:32 - 000002086 _____ C:\Users\user\Desktop\Lightning Link (1).lnk
2025-06-05 13:12 - 2019-07-31 16:10 - 000000000 ____D C:\Users\user\AppData\Local\Packages
2025-06-04 23:04 - 2019-07-26 12:51 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2025-06-04 14:12 - 2025-04-12 20:26 - 000002014 _____ C:\Users\user\Desktop\Lilys Garden.lnk
2025-06-03 11:03 - 2020-10-27 17:34 - 000012288 ___SH C:\DumpStack.log.tmp
2025-06-02 18:50 - 2024-09-07 15:10 - 003175968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2025-06-02 18:50 - 2024-09-07 15:10 - 002522144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2025-06-02 18:50 - 2020-10-27 14:10 - 000271392 _____ C:\WINDOWS\system32\FvSDK_x64.dll
2025-06-02 18:50 - 2020-10-27 14:10 - 000245792 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll
2025-06-02 18:23 - 2016-11-29 02:13 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2025-06-02 18:23 - 2016-11-29 02:13 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2025-06-02 18:21 - 2021-08-29 19:44 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2025-06-02 09:28 - 2024-03-09 12:31 - 000000000 ____D C:\Users\user\AppData\Local\BlueStacks X
2025-06-02 09:00 - 2024-04-01 16:51 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2025-06-02 08:57 - 2020-06-08 20:38 - 000000000 ____D C:\MSI
2025-06-02 08:56 - 2019-07-26 13:04 - 000000000 ____D C:\ProgramData\Packages
2025-06-02 08:56 - 2016-11-29 02:28 - 000000000 ____D C:\Program Files (x86)\MSI
2025-06-01 16:04 - 2020-05-21 12:09 - 000000000 ____D C:\Users\user\AppData\Local\NVIDIA
2025-06-01 15:22 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-06-01 14:47 - 2016-08-03 03:23 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-06-01 14:21 - 2025-04-11 11:05 - 000000000 ____D C:\Users\user\AppData\Local\Malwarebytes
2025-06-01 14:12 - 2024-08-15 11:56 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2025-06-01 13:42 - 2016-11-29 02:16 - 000000000 ____D C:\ProgramData\Intel
2025-06-01 12:17 - 2024-04-01 16:56 - 000000000 ___SD C:\WINDOWS\system32\lxss
2025-06-01 12:17 - 2024-03-05 20:28 - 000000000 ____D C:\Users\user\AppData\LocalLow\NVIDIA
2025-06-01 12:17 - 2019-07-26 12:51 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ___RD C:\Program Files\Windows Defender
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\UUS
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SystemResources
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\setup
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\Com
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\BrowserCore
2025-06-01 11:44 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-06-01 08:35 - 2019-07-31 17:23 - 000000000 ____D C:\Program Files\Common Files\AV
2025-06-01 08:35 - 2016-11-29 02:57 - 000000000 ____D C:\Program Files (x86)\SCM
2025-06-01 08:35 - 2016-11-29 02:29 - 000000000 ____D C:\ProgramData\MSI
2025-06-01 08:35 - 2016-11-29 02:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2025-06-01 08:28 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\registration
2025-06-01 02:05 - 2024-09-06 13:40 - 000000000 ____D C:\WINDOWS\InboxApps
2025-06-01 02:05 - 2024-04-01 17:39 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-06-01 02:05 - 2024-04-01 17:39 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-06-01 02:05 - 2024-04-01 17:38 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-06-01 02:05 - 2024-04-01 17:38 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\Provisioning
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\IME
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\ProgramData\USOPrivate
2025-06-01 02:05 - 2024-04-01 16:56 - 000000000 ____D C:\Program Files\Common Files\System
2025-06-01 02:05 - 2024-04-01 16:51 - 000000000 ____D C:\WINDOWS\servicing
2025-05-31 21:47 - 2024-04-01 16:56 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2025-05-31 21:47 - 2024-04-01 16:56 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2025-05-31 17:07 - 2022-01-12 08:34 - 000002487 _____ C:\Users\user\Desktop\Xbox.lnk
2025-05-31 16:53 - 2024-04-01 16:56 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-05-31 16:41 - 2017-08-31 03:57 - 000047832 _____ (STMicroelectronics) C:\WINDOWS\system32\Drivers\STTub30.sys
2025-05-31 16:36 - 2019-07-31 16:12 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\MMC
2025-05-31 16:18 - 2019-07-26 12:58 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-05-29 11:50 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SystemApps
2025-05-29 10:45 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2025-05-29 10:33 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2025-05-29 10:02 - 2016-11-29 02:30 - 000000000 ____D C:\Program Files\Portrait Displays
2025-05-29 09:35 - 2021-05-02 15:49 - 000000000 ____D C:\Users\user\AppData\Local\Nox
2025-05-28 17:00 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\appcompat
2025-05-28 12:40 - 2025-04-12 20:19 - 000002094 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk
2025-05-28 12:40 - 2025-04-12 20:19 - 000002094 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk
2025-05-28 12:40 - 2025-04-12 20:19 - 000002082 _____ C:\Users\Public\Desktop\BlueStacks Multi-Instance Manager.lnk
2025-05-28 12:40 - 2025-04-12 20:19 - 000001976 _____ C:\Users\Public\Desktop\BlueStacks 5.lnk
2025-05-28 12:39 - 2025-04-12 20:17 - 000000000 ____D C:\Program Files (x86)\BlueStacks X
2025-05-28 12:39 - 2020-11-12 12:44 - 000000000 ____D C:\Users\user\AppData\Local\Bluestacks
2025-05-28 11:02 - 2019-07-31 17:21 - 000000000 ____D C:\Users\user\AppData\Local\PlaceholderTileLogoFolder
2025-05-28 10:41 - 2020-05-21 00:23 - 000002339 _____ C:\Users\user\Desktop\Google Chrome.lnk
2025-05-28 10:36 - 2024-04-01 16:56 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-05-28 10:34 - 2024-09-07 15:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2025-05-28 10:34 - 2024-08-15 11:48 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2025-05-28 10:34 - 2024-04-01 17:36 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2025-05-28 10:34 - 2024-04-01 17:36 - 000000000 ____D C:\WINDOWS\system32\WCN
2025-05-28 10:34 - 2024-04-01 16:56 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2025-05-28 10:34 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2025-05-28 10:34 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\spool
2025-05-28 10:34 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\NDF
2025-05-28 10:34 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\ServiceState
2025-05-28 10:34 - 2021-10-02 15:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2025-05-28 10:34 - 2020-06-01 18:48 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-05-28 10:34 - 2020-06-01 18:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2025-05-28 10:34 - 2020-05-21 00:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2025-05-28 10:34 - 2019-12-07 19:22 - 000000000 ____D C:\WINDOWS\system32\Hydrogen
2025-05-28 10:34 - 2019-12-07 18:44 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2025-05-28 10:34 - 2019-12-07 18:44 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2025-05-28 10:34 - 2019-08-01 06:52 - 000000000 ____D C:\Program Files\UNP
2025-05-28 10:34 - 2019-07-26 13:36 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2025-05-28 10:34 - 2019-07-26 12:51 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2025-05-28 10:34 - 2019-07-26 12:51 - 000000000 ____D C:\WINDOWS\system32\DAX3
2025-05-28 10:34 - 2019-07-26 12:51 - 000000000 ____D C:\WINDOWS\system32\DAX2
2025-05-28 10:34 - 2016-11-29 02:54 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 12
2025-05-28 10:34 - 2016-11-29 02:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2025-05-28 10:34 - 2016-11-29 02:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit
2025-05-28 10:34 - 2016-11-29 02:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nahimic 2
2025-05-28 10:33 - 2024-04-01 16:59 - 000000000 ____D C:\WINDOWS\Setup
2025-05-28 10:28 - 2024-04-01 16:56 - 000000000 __RHD C:\Users\Public\Libraries
2025-05-28 10:27 - 2024-04-01 16:56 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows
2025-05-28 10:26 - 2024-04-01 17:36 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2025-05-28 10:26 - 2024-04-01 17:36 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2025-05-28 10:26 - 2024-04-01 17:36 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2025-05-28 10:26 - 2024-04-01 17:36 - 000000000 ____D C:\WINDOWS\system32\winrm
2025-05-28 10:26 - 2024-04-01 17:36 - 000000000 ____D C:\WINDOWS\system32\slmgr
2025-05-28 10:26 - 2024-04-01 17:36 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2025-05-28 10:26 - 2024-04-01 16:56 - 000000000 ___SD C:\WINDOWS\system32\dsc
2025-05-28 10:26 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2025-05-28 10:26 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\system32\MUI
2025-05-28 10:26 - 2019-12-07 18:44 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2025-05-28 10:26 - 2019-12-07 18:44 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2025-05-28 10:26 - 2019-07-26 12:51 - 000000000 ____D C:\WINDOWS\system32\Drivers\RivetNetworks
2025-05-28 10:26 - 2016-08-03 05:24 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2025-05-28 10:25 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\schemas
2025-05-28 10:25 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\Resources
2025-05-28 10:25 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\OCR
2025-05-28 10:25 - 2024-04-01 16:56 - 000000000 ____D C:\WINDOWS\Help
2025-05-28 10:25 - 2016-11-29 02:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sizing Options
2025-05-28 10:25 - 2016-11-29 02:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteelSeries
2025-05-26 20:51 - 2025-04-12 20:27 - 000002054 _____ C:\Users\user\Desktop\Cashman Casino.lnk
2025-05-26 20:50 - 2025-04-12 20:27 - 000002042 _____ C:\Users\user\Desktop\Mighty Fu Casino.lnk
2025-05-23 10:59 - 2024-05-03 13:46 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Office
2025-05-23 10:59 - 2021-05-02 15:51 - 000000000 ____D C:\Users\user\vmlogs
2025-05-16 10:17 - 2021-10-25 21:13 - 000000295 _____ C:\Users\user\d4ac4633ebd6440fa397b84f1bc94a3c.7z
2025-05-16 10:14 - 2021-05-02 15:51 - 000000000 ____D C:\Users\user\AppData\Local\NoxSrv
2025-05-16 10:14 - 2021-05-02 15:51 - 000000000 ____D C:\Users\user\.android
==================== Files in the root of some directories ========
2025-05-24 16:59 - 2025-05-28 22:06 - 000371894 _____ () C:\Program Files\A7500.log
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================